Server, data interaction method, device, storage medium and program product
Through complex programmable logic devices, serial port access is controlled, serial port authorization identification and read and write switch circuits are used to solve the problem of low security of server information, and fine permission management and data interaction control of target devices are achieved.
Patent Information
- Application Number
- CN202510715834.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-05-30
AI Technical Summary
The serial communication protocol of existing servers lacks an effective identity authentication mechanism, which makes it easy for unauthorized personnel to access the server, obtain data information or tamper with configurations, and the information security is low.
Complex programmable logic devices are used to control serial port access, determine the access rights of the target device through serial port authorization identification, and control data interaction based on this permission, including read and write operations, and set up read and write switch circuits to achieve fine control.
Improves the information security of the server, prevents unauthorized personnel from obtaining data or tampering with configurations, and achieves fine control of serial port access rights of different target devices.
Smart Images

Figure CN120234841B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of server technology, and in particular to a server, a data interaction method, a device, a storage medium, and a program product. Background Art
[0002] As one of the key interfaces for communicating with external devices, the server's serial port is widely used in scenarios such as device debugging, configuration management, and emergency maintenance. However, some current serial communication protocols lack effective identity authentication mechanisms, making it easy for unauthorized personnel to access the server through the serial port, obtain data, or tamper with the server configuration, resulting in relatively low server security. Summary of the Invention
[0003] The present application provides a server, a data interaction method, an electronic device, a computer-readable storage medium, and a computer program product to at least solve the problem of relatively low server information security in related technologies.
[0004] This application provides a server, including:
[0005] at least one server component;
[0006] A complex programmable logic device includes a device port and at least one serial port, wherein the device port is used to connect to a target device, and each serial port is used to connect to one of the server components. The complex programmable logic device is used to receive a serial port authorization identifier of the target device, and determine, based on the serial port authorization identifier, a target serial port that the target device is allowed to access and the access rights of the target serial port, and connect the target device to the target serial port, and control the target device to perform data interaction with the target server component connected to the target serial port according to the access rights of the target serial port, wherein the access rights represent the data interaction operations that the target device is allowed to perform through the target serial port.
[0007] This application also provides a data interaction method, including:
[0008] Receive a serial port authorization identifier of a target device, where the serial port authorization identifier is used to represent the scope of authority of the target device when accessing the serial port;
[0009] Determining, based on the serial port authorization identifier, a target serial port that the target device is allowed to access and access rights to the target serial port, wherein the access rights represent data interaction operations that the target device is allowed to perform through the target serial port;
[0010] Connecting the target device to the target serial port, the target serial port being connected to a target server component, wherein when the target device is connected to the target serial port, the target device is connected to the target server component;
[0011] According to the access rights of the target serial port, the target device is controlled to perform data interaction with the target server component.
[0012] The present application also provides an electronic device, which includes a processor and a memory, wherein the memory is used to store a computer program, and when the computer program is executed by the processor, the steps of the above-mentioned data interaction method are implemented.
[0013] The present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned data interaction method when executed by a processor.
[0014] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned data interaction method are implemented.
[0015] In the technical solutions of some embodiments of the present application, when determining the target serial port that the target device is allowed to access and the access rights of the target serial port based on the serial port authorization identifier, one or more serial port authorization identifiers can be set, and the permission ranges of at least some of the serial port authorization identifiers can be different. Furthermore, a serial port authorization identifier can be assigned to each target device according to actual needs, so that the serial port access rights of different target devices can be finely controlled, preventing unauthorized personnel from obtaining data information in the server or tampering with the server configuration through the serial port. In this way, the information security of the server can be improved, solving the problem of relatively low server information security in the related art. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0017] Figure 1 Schematic diagram designed for server serial ports in some technologies;
[0018] Figure 2 A schematic diagram of the server architecture provided for some embodiments of the present application;
[0019] Figure 3A specific switch circuit diagram between one of the serial ports and the device port provided in some embodiments of the present application;
[0020] Figure 4 A schematic diagram of a connection between a server and a target device provided in some embodiments of the present application;
[0021] Figure 5 A flowchart of a data interaction method provided in some embodiments of the present application;
[0022] Figure 6 A schematic diagram of a module of an electronic device provided for some embodiments of the present application. DETAILED DESCRIPTION
[0023] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0024] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements but also other elements not explicitly listed, or also includes elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or precedence.
[0025] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0026] See also Figure 1 , a schematic diagram of the server serial port design in some technologies. Figure 1In the example, target device 13 is an external device connected to the server (such as a laptop used by maintenance personnel). The server may include a central processing unit (CPU) 12, a baseboard management controller (BMC) 11, a management serial port 111, a system serial port 121, a system serial port connector 14, a management serial port connector 15, an eSPI (Embedded Serial Peripheral Interface) line 122, a first UART (Universal Asynchronous Receiver / Transmitter) line 141, and a second UART line 151. The system serial port connector 14 is connected to the baseboard management controller 11 via the first UART line 141, and the baseboard management controller 11 is connected to the system serial port 121 via the eSPI line 122. The management serial port connector 15 is connected to the management serial port 111 via the second UART line 151.
[0027] System serial port connector 14 and management serial port connector 15 can be used to transmit UART data. Since target device 13 typically includes a USB (Universal Serial Bus) interface but not a UART interface, target device 13 can connect to system serial port connector 14 and management serial port connector 15 via a serial port converter 16. Serial port converter 16 converts USB data output by target device 13 into UART data, or converts UART data sent by a server to target device 13 into USB data.
[0028] The central processing unit 12 can be used to run a basic input / output system (BIOS) or an operating system. The system serial port 121 can serve as a channel for the central processing unit 12 to communicate with the outside world. For example, serial port data (such as device debugging information, configuration instructions, etc.) generated during the operation of the BIOS or operating system can be transmitted to the baseboard management controller 11 via the system serial port 121. After parsing this serial port data, the baseboard management controller 11 can send the parsed data to the system serial port connector 14, which then sends the data to the target device 13 via the system serial port connector 14. Conversely, during the operation of the BIOS or operating system, the target device 13 can also send data to the BIOS or operating system via the system serial port connector 14, the baseboard management controller 11, and the system serial port 121.
[0029] The management serial port 111 serves as a communication channel for the baseboard management controller 11, primarily for remote server management and monitoring. For example, after connecting the target device 13 to the serial port converter 16, maintenance personnel can issue commands to the baseboard management controller 11 through the management serial port connector 15 and the management serial port 111, thereby performing remote server configuration, fault diagnosis, and other operations.
[0030] exist Figure 1 In the technology shown, the UART protocol, as a serial port protocol, lacks an effective identity authentication mechanism. This allows unauthorized individuals to easily access the server through system serial port 121 or management serial port 111, obtain data from the server, or tamper with the server configuration, resulting in a relatively low level of server security. For example, in some enterprise intranets that lack strict security measures, unauthorized individuals can exploit the convenience of the serial port's physical connection to bypass complex network security systems and directly attack the server, seriously threatening the server's information security.
[0031] In other technologies, although serial port access control policies are set in the server, these control policies are usually set based on the IP (Internet Protocol) address or MAC (Media Access Control) address of the target device 13. They are relatively rough and cannot perform fine-grained division of serial port access rights for different users using the same target device 13. Therefore, there are also problems such as data leakage or system failure due to excessive user permissions or user abuse of permissions.
[0032] In order to improve the information security of the server and solve the problem of low information security of the server in the related art, the present application first provides a server 200. Figure 2 , which is a schematic diagram of the architecture of the server 200 provided in some embodiments of the present application. Figure 2 In the example, server 200 includes a complex programmable logic device 27 and at least one server component 29. The server component 29 refers to a component that needs to exchange data with the target device 23, such as a baseboard management controller 21, a central processing unit 22, an OCP (Open Compute Project) network card (not shown), or a smart network card (not shown).
[0033] The complex programmable logic device 27 includes a device port 272 and at least one serial port 271. The device port 272 is used to connect to the target device 23. Figure 1Similarly, target device 23 refers to an external device connected to server 200. Target device 23 can be connected to device port 272 via serial port converter 26. Each serial port 271 is used to connect to one of the server components 29. For example, serial ports P1 and P2 are connected to baseboard management controller 21, and serial port P3 is connected to a smart network card.
[0034] Specifically, Figure 2 Taking the central processing unit 22 and baseboard management controller 21 in FIG as an example, server 200 may include a management serial port 211, a system serial port 221, a system serial port connector 24, a management serial port connector 25, an eSPI line 222, a first UART line 241, and a second UART line 251. The central processing unit 22 is connected to the baseboard management controller 21 via the system serial port 221 and the eSPI line 222. The baseboard management controller 21 is connected to the system serial port connector 24 via the first UART line 241. The system serial port connector 24 is connected to one serial port 271 (for example, serial port P2) of the complex programmable logic device 27. This establishes a connection between serial port P2 and the central processing unit 22. Furthermore, the baseboard management controller 21 is connected to the management serial port connector 25 via the management serial port 211 and the second UART line 251. The management serial port connector 25 is connected to another serial port 271 (for example, serial port P1) of the complex programmable logic device 27. This establishes a connection between serial port P1 and the baseboard management controller 21.
[0035] Based on the above serial port design architecture, a serial port authorization identifier can be pre-assigned to the target device 23 according to the serial port access rights allowed to the maintenance personnel using the target device 23. The serial port authorization identifier is used to represent the scope of authority of the target device 23 when accessing the serial port. The scope of authority represents the serial port 271 that the device with each serial port authorization identifier is allowed to access and the access rights of the serial port 271. Among them, access refers to the target device 23 interacting with the server component 29 connected to the serial port 271 through the serial port 271 to perform data interaction. The access rights represent the data interaction operations that the target device 23 is allowed to perform through the target serial port 271. Data interaction operations include reading data from the target server component 29 and writing data to the target server component 29. For example, if the serial port authorization identifier of the target device 23 is AA1, it can indicate that the target device 23 is allowed to access serial ports P1 and P2, but not serial ports P3 and P4. Furthermore, when accessing serial port P1, the target device 23 is only allowed to read data from the target server component 29 connected to serial port P1. And when accessing serial port P2, the target device 23 is allowed to read and write data from the target server component 29 connected to serial port P2. For another example, if the serial port authorization identifier of the target device 23 is AA2, it can indicate that the target device 23 is allowed to access serial port P1, but not serial ports P2, P3, and P4. Furthermore, when accessing serial port P1, the target device 23 is allowed to read and write data from the server component 29 connected to serial port P1.
[0036] When maintenance personnel connect the target device 23 to the device port 272, the complex programmable logic device 27 can, by default, control each serial port 271 to be disconnected from the device port 272. After the maintenance personnel enter the assigned serial port authorization identifier into the target device 23, the target device 23 can send the serial port authorization identifier to the complex programmable logic device 27. The complex programmable logic device 27 is used to receive the serial port authorization identifier of the target device 23 and, based on the serial port authorization identifier, determine the target serial port 271 that the target device 23 is allowed to access and the access rights of the target serial port 271, connect the target device 23 to the target serial port 271, and control data exchange between the target device 23 and the target server component 29 connected to the target serial port 271 according to the access rights of the target serial port 271. In this way, fine-grained control can be exercised over the serial port access rights of the target device 23, thereby improving the information security of the server 200.
[0037] Continue reading Figure 1In some embodiments, a switch circuit 274 is included between the device port 272 of the complex programmable logic device 27 and each serial port 271. By controlling the switch circuit 274 between the device port 272 and the target serial port 271 to close or open, the complex programmable logic device 27 can control the connection or disconnection between the target device 23 and the target serial port 271, thereby controlling the server component 29 that exchanges data with the target device 23.
[0038] for example, Figure 2 In the example, when the complex programmable logic device 27 controls the switch circuit 274 to connect serial port P2 with the device port 272, the device port 272 of the complex programmable logic device 27, serial port P2, the system serial port connector 24, the first UART line 241, the baseboard management controller 21, the eSPI line 222, and the system serial port 221 can form a first communication line. The target device 23 can exchange data with the central processing unit 22 via the first communication line, such as reading or writing data in the central processing unit 22. Conversely, when the complex programmable logic device 27 controls the switch circuit 274 to disconnect serial port P2 from the device port 272, the target device 23 cannot exchange data with the central processing unit 22.
[0039] Similarly, when the complex programmable logic device 27 controls the switch circuit 274 to connect serial port P1 with the device port 272, the device port 272, serial port P1, management serial port connector 25, second UART line 251, and management serial port 211 of the complex programmable logic device 27 can form a second communication line. The target device 23 can exchange data with the baseboard management controller 21 via the second communication line, for example, by issuing instructions to the baseboard management controller 21 to remotely configure or diagnose faults on the server 200. Conversely, when the complex programmable logic device 27 controls the switch circuit 274 to disconnect serial port P1 from the device port 272, the target device 23 cannot exchange data with the baseboard management controller 21.
[0040] Further, see Figure 3 , which is a specific circuit diagram of one of the switch circuits 274 provided in some embodiments of the present application. Figure 3In the example, the switch circuit 274 includes a write switch circuit 2741 and a read switch circuit 2742. When the complex programmable logic device 27 controls the read switch circuit 2742 between the device port 272 and the target serial port 271 to be closed, the target device 23 reads data from the target server component 29 via the read switch circuit 2742. When the complex programmable logic device 27 controls the write switch circuit 2741 between the device port 272 and the target serial port 271 to be closed, the target device 23 writes data to the target server component 29 via the write switch circuit 2741. Specifically, when the access rights of the target serial port 271 include read rights, the complex programmable logic device 27 can control the read switch circuit 2742 between the device port 272 and the target serial port 271 to be closed. In this way, the target device 23 can read data from the target server component 29 via the read switch circuit 2742. Similarly, when the access rights of the target serial port 271 include write permission, the complex programmable logic device 27 can control the write switch circuit 2741 between the device port 272 and the target serial port 271 to be closed. In this way, the target device 23 can write data to the target server component 29 through the write switch circuit 2741.
[0041] Conversely, if the access rights of the target serial port 271 do not include read permission, the complex programmable logic device 27 can control the read switch circuit 2742 between the target serial port 271 and the device port 272 to be disconnected. In this way, the target device 23 cannot read data from the target server component 29. Similarly, if the access rights of the target serial port 271 do not include write permission, the complex programmable logic device 27 can control the write switch circuit 2741 between the target serial port 271 and the device port 272 to be disconnected. In this way, the target device 23 cannot write data to the target server component 29.
[0042] Figure 3 In the embodiment, a write switch circuit 2741 and a read switch circuit 2742 are set between the target serial port 271 and the device port 272, and the on and off of the write switch circuit 2741 and the read switch circuit 2742 are controlled based on the access rights of the target serial port 271, which can effectively prevent the target device 23 from performing data interaction operations outside the permission in the target server component 29, thereby improving the information security of the server 200.
[0043] In some embodiments, if the target device 23 is allowed to access at least one target serial port 271, the complex programmable logic device 27 can display the target serial ports 271 that the target device 23 is allowed to access via a display device. A maintenance person can select one of the displayed target serial ports 271 to access. In response to the target serial port selection operation, the complex programmable logic device 27 determines the selected target serial port 271 and connects the target device 23 to the selected target serial port 271. In this way, when the target device 23 is allowed to access multiple target serial ports 271, data conflicts on the device port 272 can be avoided.
[0044] Continue to refer to Figure 2 . In this embodiment, the complex programmable logic device 27 also includes a storage port 273. The storage port 273 is used to connect to the memory 28. The memory 28 includes a permission storage area, and the permission storage area is used to store at least one serial port authorization identifier and the permission range corresponding to each serial port authorization identifier. After receiving the serial port authorization identifier of the target device 23, the complex programmable logic device 27 can determine the permission range of the target device 23 based on the information in the permission storage area, that is, determine the target serial port 271 that the target device 23 is allowed to access and the access rights of the target serial port 271. Specifically, the serial port authorization identifier sent by the target device 23 can be used as the first serial port authorization identifier, and the first serial port authorization identifier can be compared with the serial port authorization identifier in the permission storage area. If there is a second serial port authorization identifier that is the same as the first serial port authorization identifier in the permission storage area, the permission range corresponding to the second serial port authorization identifier can be used as the permission range of the target device 23. If the second serial port authorization identifier that is identical to the first serial port authorization identifier does not exist in the permission storage area, it indicates that the target device 23 is not authorized to access any serial port 271 of the complex programmable logic device 27. In this case, each serial port 271 can be controlled to remain disconnected from the device port 272. This prevents data leakage or tampering of the server configuration in the server 200, thereby improving information security.
[0045] For example, assume that the serial port authorization identifier and permission range stored in the permission storage area are as shown in Table 1.
[0046] Table 1 Serial port authorization identifier and permission range
[0047]
[0048] Based on Table 1, assume that maintenance personnel a1 connects target device 23 to device port 272 and enters serial port authorization identifier AA1 into target device 23. Since serial port authorization identifier AA1 exists in the permission storage area, the write switch circuit 2741 and read switch circuit 2742 between serial port P1 and device port 272 can be controlled to connect, and the read switch circuit 2742 between serial port P2 and device port 272 can be controlled to connect, while the write switch circuit 2741 between serial port P2 and device port 272 can be controlled to disconnect, according to the permission range corresponding to serial port authorization identifier AA1 in the permission storage area. In this way, the serial port access rights of target device 23 can be precisely controlled, preventing data leakage or server configuration tampering of server 200.
[0049] Conversely, suppose maintenance personnel a2 connects target device 23 to device port 272 and enters serial port authorization identifier AA4 into target device 23. Since serial port authorization identifier AA4 does not exist in the permission storage area, each serial port 271 can be controlled to remain disconnected from device port 272. This prevents unauthorized maintenance personnel from accessing server 200 through the serial port, ensuring the information security of server 200.
[0050] In some embodiments, the memory 28 further includes a restricted instruction storage area for storing restricted instructions for each serial port 271. Restricted instructions for a serial port 271 refer to instructions that the target device 23 cannot send through the serial port 271. The complex programmable logic device 27 is further configured to determine the target restricted instruction for the target serial port 271 based on the information in the restricted instruction storage area. Upon detecting that the target device 23 sends the target restricted instruction through the target serial port 271, the complex programmable logic device 27 controls the write switch circuit 2741 and the read switch circuit 2742 between the target device 23 and the target serial port 271 to disconnect. For example, a restricted instruction 1 may be set for the target serial port 271, and a storage address d1 may be specified in restricted instruction 1 to restrict the target device 23 from writing data at storage address d1. In response to the target device 23 sending restricted instruction 1 through the target serial port 271, the complex programmable logic device 27 controls the write switch circuit 2741 and the read switch circuit 2742 between the target device 23 and the target serial port 271 to disconnect. Thus, on the one hand, by disconnecting the write switch circuit 2741, the data write operation of the target device 23 can be interrupted, thereby ensuring the information security of the server 200. On the other hand, by disconnecting the read switch circuit 2742, the target device 23 can be prevented from continuing to send restricted instructions through the read switch circuit 2742, thereby maximally ensuring the information security of the server 200.
[0051] Based on restricted instructions, when the target device 23 has data read and write permissions in the target server component 29, more precise control can be exercised over the specific properties of reading and writing (such as data write / read areas), thereby greatly improving the information security of the server 200.
[0052] In some embodiments, after the write switch circuit 2741 and the read switch circuit 2742 are controlled to be disconnected, if the serial port authorization identifier of the target device 23 is received again, the read switch circuit 2742 is controlled to be closed if the access rights of the target serial port 271 are determined to include read permission based on the serial port authorization identifier, and the write switch circuit 2741 is controlled to be closed if the access rights of the target serial port 271 are determined to include write permission. In this way, the target device 23 can read and write data normally.
[0053] Specifically, in some embodiments, the restricted instructions may be divided according to the serial port authorization identifier and the target serial port. For example, the serial port authorization identifier and the restricted instructions stored in the restricted instruction storage area may be as shown in Table 2.
[0054] Table 2 Serial port authorization identifiers and restricted instructions
[0055]
[0056] By dividing restricted instructions according to the dimensions of serial port authorization identifier and target serial port, restricted instructions can be divided in a more fine-grained manner, thereby enabling more precise control over serial port access and improving information security.
[0057] In some embodiments, the memory 28 further includes a log storage area, which is used to store a data interaction log of the target device 23. The data interaction log includes one or more of the following information:
[0058] The connection time between the target device 23 and the target serial port 271;
[0059] The time when the target device 23 is disconnected from the target serial port 271;
[0060] The data interaction operations performed by the target device 23 through the target serial port 271 and the operation time;
[0061] The target restricted instruction sent by the target device 23 through the target serial port 271 and the sending time of the target restricted instruction.
[0062] In this way, the data interaction operation of the target device 23 can be traced back, and when a problem occurs in the server 200, the problem can be located based on the data interaction log.
[0063] In some embodiments, the baseboard management controller 21 is connected to a complex programmable logic device 27. When the target device 23 is connected to the target serial port 271, the complex programmable logic device 27 can obtain a first current time from the baseboard management controller 21 as the connection time. When the target device 23 is disconnected from the target serial port 271, the complex programmable logic device 27 can obtain a second current time from the baseboard management controller 21 as the disconnection time. When the target device 23 performs a data interaction operation through the target serial port 271, the complex programmable logic device 27 can obtain a third current time from the baseboard management controller 21 as the operation time. When the target device 23 sends a target restricted instruction through the target serial port 271, the complex programmable logic device 27 can obtain a fourth current time from the baseboard management controller 21 as the sending time of the target restricted instruction. The baseboard management controller 21 typically has a real-time clock, and obtaining time from the baseboard management controller 21 can be relatively accurate.
[0064] Based on the above description, this application provides a permission setting method. Specifically, according to the serial port authorization identifier and the serial port dimension, 8 bits of data can be allocated to each serial port under each serial port authorization identifier. In these 8 bits of data, the meaning of each data bit can be as follows:
[0065] bit 0: indicates whether the target device 23 is allowed to read data from the server component 29 connected to the serial port 271. For example, a value of 0 indicates permission, and a value of 1 indicates non-permission.
[0066] Bits 1 and 2: Indicate whether the target device 23 is allowed to write data to the server component 29 connected to the serial port 271, and whether there are any restricted instructions when writing data is allowed. For example, a value of 00 indicates that writing data is allowed, a value of 01 indicates that writing data is allowed but with restricted instructions, and a value of 11 indicates that writing data is not allowed.
[0067] Bits 3 and 4: Indicate whether data interaction logs with target device 23 need to be recorded, and if so, what the log contents should include. For example, a value of 00 indicates that only the connection time between target device 23 and serial port 271 is recorded; a value of 01 indicates that the connection time between target device 23 and serial port 271 and restricted commands sent by target device 23 through target serial port 271 are recorded; a value of 11 indicates that data interaction logs are not recorded.
[0068] Bit5~7: Reserved, the default value is 0.
[0069] Thus, under each serial port authorization identifier, there is an 8-bit permission setting. The permission setting can be stored in the permission storage area of the memory 28. For example, the serial port authorization identifier, target serial port, and permission setting stored in the permission storage area can be as shown in Table 3.
[0070] Table 3 Permission settings
[0071]
[0072] Setting permissions by bits can reduce the storage space consumption of permission settings.
[0073] exist Figure 3 In the embodiment shown, the device port 272 is directly connected to the target device 23 . In this case, the target device 23 can send a serial port authorization identifier to the complex programmable logic device 27 .
[0074] See also Figure 4 , which is a connection diagram between a server 300 and a target device 33 provided in some other embodiments of the present application. Figure 4 In the example, the device port 372 of the complex programmable logic device 37 is connected to the target device 33 through the trusted device 41. The trusted device 41 includes a preset serial port authorization identifier. The preset serial port authorization identifier can be considered as the serial port authorization identifier of the target device 33. When the device port 372 is connected to the target device 33 through the trusted device 41, the trusted device 41 sends the serial port authorization identifier of the target device to the complex programmable logic device 37. In short, in Figure 4 In the solution shown, if the maintenance personnel want to access the serial port 371 through the target device 33, they need to first obtain the corresponding trusted device 41. In this way, the information security of the server 300 can be further improved.
[0075] Specifically, the server 300 may include a third connector 39. The third connector 39 is connected between the complex programmable logic device 37 and the trusted device 41. The third connector 39 also includes a first power supply terminal P3V3_STBY and a ground segment GND. The trusted device 41 may include a controller 414, a switch 412, a first connector 411, and a second connector 413. The first connector 411 is used to connect to the complex programmable logic device 37, and the second connector 413 is used to connect to the target device 33. The switch 412 connects the controller 414, the first connector 411, and the second connector 413. When the switch 412 is in the first switching state, the first connector 411 is connected to the controller 414, and the controller 414 sends a preset serial port authorization identifier to the complex programmable logic device 37. When the switch 412 is in the second switching state, the first connector 411 is connected to the second connector 413, so that the target device 23 is connected to the complex programmable logic device 37.
[0076] Specifically, a first line FM_UART_SW and a second line UART_MCU are connected between the controller 414 and the switch 412. When the first connector 411 is connected to the complex programmable logic device 37 and the second connector 413 is connected to the target device 33, the controller 414 controls the switch 412 to the first switch state via the first line FM_UART_SW, thereby connecting the first connector 411 to the controller 414. When the first connector 411 and the controller 414 are connected, the controller 414 sends a preset serial port authorization identifier to the complex programmable logic device 37 via the second line UART_MCU. When the complex programmable logic device 37 returns a response to the controller 414 indicating that the target device 33 is allowed to access one or more target serial ports 371, the controller 414 controls the switch 412 to the second switch state via the first line FM_UART_SW, thereby connecting the first connector 411 to the second connector 413. In this way, serial port access permission control based on the trusted device 41 is implemented.
[0077] Furthermore, the first connector 411 includes a second power supply terminal P3V3_INPUT. When the first connector 411 is connected to the third connector 39, the first power supply terminal P3V3_STBY is connected to the second power supply terminal P3V3_INPUT. In this way, the trusted device 41 can be powered by the first power supply terminal P3V3_STBY, ensuring the normal operation of the trusted device 41.
[0078] In summary, this application also provides a data interaction method. The data interaction method can be applied to Figure 2 Complex programmable logic devices 27 or Figure 4 Complex programmable logic devices 37. Figure 5 , which is a flow chart of the data interaction method provided in some embodiments of the present application. Figure 5 In the data interaction method, the following steps are included:
[0079] Step S501: Receive a serial port authorization identifier of a target device, where the serial port authorization identifier is used to represent the scope of authority of the target device when accessing the serial port.
[0080] Step S502 : determining the target serial port that the target device is allowed to access and the access rights of the target serial port according to the serial port authorization identifier. The access rights represent the data interaction operations that the target device is allowed to perform through the target serial port.
[0081] Step S503: connect the target device to the target serial port, the target serial port is connected to the target server component. When the target device is connected to the target serial port, the target device is connected to the target server component.
[0082] Step S504: Control the target device to perform data interaction with the target server component according to the access rights of the target serial port.
[0083] In some embodiments, a write switch circuit and a read switch circuit are provided between the target device and the target serial port; connecting the target device to the target serial port includes:
[0084] When the access rights of the target serial port include read rights, controlling the read switch circuit to be closed so that the target device reads data from the target server component through the read switch circuit;
[0085] When the access rights of the target serial port include write permission, the write switch circuit is controlled to be closed, so that the target device writes data into the target server component through the write switch circuit.
[0086] In some embodiments, the access rights further represent restricted commands that the target device is not allowed to send through the target serial port;
[0087] In response to the target device sending a target restricted instruction through the target serial port, the target device is controlled to be disconnected from the target serial port.
[0088] In some embodiments, the method further comprises:
[0089] Based on the serial port authorization identifier, determine whether it is necessary to record the data interaction log of the target device. If so, record the data interaction log of the target device. The data interaction log includes one or more of the following information:
[0090] The connection time between the target device and the target serial port;
[0091] The time when the target device is disconnected from the target serial port;
[0092] The data interaction operations performed by the target device through the target serial port and the operation time;
[0093] The target restricted command sent by the target device through the target serial port and the time when the restricted command was sent.
[0094] In some embodiments, the method is applied to a complex programmable logic device in a server, the server further comprising a baseboard management controller; the method further comprising:
[0095] When the target device is connected to the target serial port, obtaining a first current time in the baseboard management controller as the connection time;
[0096] When the target device is disconnected from the target serial port, obtaining a second current time in the baseboard management controller as the disconnection time;
[0097] When the target device performs a data interaction operation through the target serial port, obtaining a third current time in the baseboard management controller as the operation time;
[0098] In the case where the target device sends the target restricted instruction through the target serial port, a fourth current time in the baseboard management controller is acquired as the sending time of the target restricted instruction.
[0099] In some embodiments, when the target device is allowed to access at least one target serial port, connecting the target device to the target serial port includes:
[0100] Display the target serial port that the target device is allowed to access;
[0101] In response to a target serial port selection operation, determining a selected target serial port;
[0102] Connect the target device to the selected target serial port.
[0103] For a description of data interaction methods, see Figures 2 to 4 The relevant description is not repeated here.
[0104] In summary, in the technical solutions of some embodiments of the present application, when determining the target serial port that the target device is allowed to access and the access rights of the target serial port based on the serial port authorization identifier, one or more serial port authorization identifiers can be set, and the scope of authority of at least some of the serial port authorization identifiers can be different. Furthermore, a serial port authorization identifier can be assigned to each target device according to actual needs, so that the serial port access rights of different target devices can be finely controlled to prevent unauthorized personnel from obtaining data information in the server or tampering with the server configuration through the serial port. In this way, the information security of the server can be improved, solving the problem of relatively low server information security in the related art.
[0105] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method.
[0106] See also Figure 6 An embodiment of the present application further provides an electronic device, comprising a memory 10 and a processor 20, wherein the memory 10 stores a computer program, and the processor 20 is configured to run the computer program to execute the steps in any one of the above-mentioned data interaction method embodiments.
[0107] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above-mentioned data interaction method embodiments when running.
[0108] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.
[0109] An embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in any of the above-mentioned data interaction method embodiments are implemented.
[0110] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above-mentioned data interaction method embodiments are implemented.
[0111] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0112] The above is a detailed introduction to a data interaction method, server, and storage medium provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only intended to help understand the method and core ideas of the present application. It should be pointed out that, for those skilled in the art, without departing from the principles of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the claims of the present application.
Claims
1. A server, characterized in that: The server includes: at least one server component; A complex programmable logic device, comprising a device port and at least one serial port, wherein the device port is connected to a target device via a trusted device, each serial port being used to connect to one of the server components, the complex programmable logic device being used to receive a serial port authorization identifier of the target device, and determine, based on the serial port authorization identifier, a target serial port that the target device is allowed to access and an access permission for the target serial port, connect the target device to the target serial port, and control the target device to perform data interaction with a target server component connected to the target serial port according to the access permission for the target serial port, wherein the access permission represents a data interaction operation that the target device is allowed to perform through the target serial port; The trusted device includes a controller, a switch, a first connector, and a second connector, wherein the first connector is used to connect to the device port of the complex programmable logic device, the second connector is used to connect to the target device, and the switch connects the controller, the first connector, and the second connector; The controller includes a preset serial port authorization identifier. When the switching switch is in a first switching state, the first connector is connected to the controller, and the controller sends the preset serial port authorization identifier to the complex programmable logic device. When the switching switch is in a second switching state, the first connector is connected to the second connector to connect the target device to the complex programmable logic device.
2. The server according to claim 1, wherein: The complex programmable logic device includes a switching circuit between the device port and each serial port. The complex programmable logic device controls the target device to be connected or disconnected from the target serial port by controlling the switching circuit between the device port and the target serial port to be closed or opened.
3. The server according to claim 2, wherein: The switch circuit includes a write switch circuit and a read switch circuit; When the complex programmable logic device controls the read switch circuit between the device port and the target serial port to be closed, the target device reads data from the target server component through the read switch circuit; When the complex programmable logic device controls the write switch circuit between the device port and the target serial port to be closed, the target device writes data into the target server component through the write switch circuit.
4. The server according to any one of claims 1 to 3, characterized in that: The complex programmable logic device further includes a storage port, the storage port is used to connect to a memory, the memory includes a permission storage area, the permission storage area is used to store at least one serial port authorization identifier and a permission range corresponding to each serial port authorization identifier; And / or, the memory further includes a restricted instruction storage area, wherein the restricted instruction storage area is used to store restricted instructions of each of the serial ports; And / or, the memory further includes a log storage area, and the log storage area is used to store the data interaction log of the target device.
5. The server according to claim 1, wherein: A first line and a second line are provided between the controller and the switch. When the first connector is connected to the complex programmable logic device and the second connector is connected to the target device, the controller controls the switch to be in the first switch state via the first line to connect the first connector to the controller. When the first connector is connected to the controller, the controller sends the preset serial port authorization identifier to the complex programmable logic device via the second line. When the response returned by the complex programmable logic device to the controller indicates that the target device is allowed to access one or more target serial ports, the controller controls the switch to be in the second switch state through the first line to connect the first connector to the second connector.
6. A data interaction method, characterized in that: Applied to a complex programmable logic device, the method comprises: Receive a serial port authorization identifier of a target device, where the serial port authorization identifier is used to represent the scope of authority of the target device when accessing the serial port; Determining, based on the serial port authorization identifier, a target serial port that the target device is allowed to access and access rights to the target serial port, wherein the access rights represent data interaction operations that the target device is allowed to perform through the target serial port; Connecting the target device to the target serial port, the target serial port being connected to a target server component, wherein when the target device is connected to the target serial port, the target device is connected to the target server component; Controlling data interaction between the target device and the target server component according to the access rights of the target serial port; The complex programmable logic device includes a device port, the device port is connected to the target device through a trusted device, the trusted device includes a controller, a switch, a first connector, and a second connector, the first connector is used to connect to the device port of the complex programmable logic device, the second connector is used to connect to the target device, and the switch connects the controller, the first connector, and the second connector; The controller includes a preset serial port authorization identifier. When the switching switch is in a first switching state, the first connector is connected to the controller, and the controller sends the preset serial port authorization identifier to the complex programmable logic device. When the switching switch is in a second switching state, the first connector is connected to the second connector to connect the target device to the complex programmable logic device.
7. The method according to claim 6, characterized in that A write switch circuit and a read switch circuit are included between the target device and the target serial port; Connecting the target device to the target serial port includes: When the access permission of the target serial port includes read permission, controlling the read switch circuit to be closed, so that the target device reads data from the target server component through the read switch circuit; When the access permission of the target serial port includes write permission, the write switch circuit is controlled to be closed, so that the target device writes data to the target server component through the write switch circuit.
8. The method according to claim 6 or 7, characterized in that The access permission further represents the target restricted instructions of the target serial port; the method further includes: In response to the target device sending the target restricted instruction through the target serial port, the target device is controlled to be disconnected from the target serial port.
9. The method according to claim 8, characterized in that The method further comprises: If it is determined, based on the serial port authorization identifier, that a data interaction log of the target device needs to be recorded, the data interaction log of the target device is recorded, wherein the data interaction log includes one or more of the following information: The connection time between the target device and the target serial port; The disconnection time between the target device and the target serial port; The data interaction operation performed by the target device through the target serial port and the operation time; The target restricted instruction sent by the target device through the target serial port and the sending time of the target restricted instruction.
10. The method according to claim 9, characterized in that The method is applied to a complex programmable logic device in a server, wherein the server further includes a baseboard management controller; the method further includes: When the target device is connected to the target serial port, obtaining a first current time in the baseboard management controller as the connection time; When the target device is disconnected from the target serial port, obtaining a second current time in the baseboard management controller as the disconnection time; When the target device performs a data interaction operation through the target serial port, obtaining a third current time in the baseboard management controller as the operation time; In a case where the target device sends a target restricted instruction through the target serial port, a fourth current time in the baseboard management controller is acquired as a sending time of the target restricted instruction.
11. The method according to claim 6, characterized in that In a case where the target device is allowed to access at least one target serial port, connecting the target device to the target serial port includes: Display the target serial port that the target device is allowed to access; In response to a target serial port selection operation, determining a selected target serial port; Connect the target device to the selected target serial port.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, the method according to any one of claims 6 to 11 is implemented.
13. An electronic device, characterized in that: The electronic device includes a processor and a memory, wherein the memory is used to store a computer program, and when the computer program is executed by the processor, the method according to any one of claims 6 to 11 is implemented.
14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 6 to 11 is implemented.
Citation Information
Patent Citations
Serial port path selection method and system based on BMC, terminal and storage medium
CN113760800A
Data transmission method and device, equipment and storage medium
CN116303176A