Server management control chip, data processing method, server and storage medium

By introducing an address protection module and a memory self-test module into the server management control chip, the problem of malicious modification of video information during writing is solved, ensuring that the operating system interface seen by remote users is authentic and reliable, and improving the server management and control security.

CN120264008AActive Publication Date: 2025-07-04SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510740184.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-07-04
Estimated Expiration
2045-06-05

AI Technical Summary

Technical Problem

The real-time video information of the server operating system is at risk of malicious modification by the software during and after writing to the memory of the server management control chip, resulting in the unreal video interface seen by remote users, which affects management and control, and may even cause misoperation and endanger the security of the system.

Method used

The original video space security control module is introduced into the server management control chip, including the address protection module. By performing key verification of write operation requests, the security of video information during the writing and reading process is ensured, and potential malicious attacks are monitored and handled in real time through the memory self-test module and the alarm management module.

Benefits of technology

It effectively prevents video information from being maliciously modified during writing and reading, ensures that the operating system interface seen by remote users is real and reliable, avoids misoperation, and improves the system security of the server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120264008A_ABST
    Figure CN120264008A_ABST
Patent Text Reader

Abstract

The invention discloses a server management control chip, a data processing method, a server and a storage medium, and is applied to the technical field of servers. The server management control chip comprises a video interface, a video capture module, a compression configuration module, a core compression module and a compressed video write-in control module which are connected in sequence, and further comprises an original video space safety control module; the original video space security control module comprises an address protection module; the address protection module is used for verifying a first operation type and a first key in a write operation request sent by the video interface; under the condition that the verification is passed, first response information is sent to the video interface, and the state of the address protection module is controlled to be a first state; the address protection module is also used for controlling the state of the address protection module to be a second state based on a first indication signal sent by the video interface. Therefore, the video information is not maliciously modified in the process of writing the video information into the memory and after the video information is written into the memory.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of servers, and particularly to a server management control chip, a data processing method, a server, and a storage medium. Background Art

[0002] As a control chip for a server, a server management control chip is used to compress the real-time video information of a server operating system and transmit it over a network to a remote end through compression, so that users at the remote end can view it in a timely manner and remotely manage the operating system of the server. Currently, during the process of writing the real-time video information of the server operating system into the memory of the server management control chip and after writing into the memory, there is a risk of being maliciously modified by software. As a result, the video interface seen by the remote end user is not the real operating system interface, which further affects the management and control of the server by the remote end user. In severe cases, it may even cause misoperations and affect the system security of the server. Summary of the Invention

[0003] In view of this, embodiments of this application provide a server management control chip, a data processing method, a server, and a storage medium.

[0004] According to the first aspect of this application, embodiments of this application provide a server management control chip, including a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module that are connected in sequence, and further including: An original video space security control module; the original video space security control module includes an address protection module; The video interface is used to obtain the video information of the server operating system and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; The address protection module is used to verify the first operation type and the first key in the write operation request; and in the case of confirming that the first operation type and the first key meet the first verification condition, send a first response message to the video interface and control the state of the address protection module to be a first state; when the address protection module is in the first state, only the video interface is allowed to write to the video information cache unit; The video interface is further used to convert the video information into video information in a first format based on the first response message, write the video information in the first format into the video information cache unit, and send a first indication signal to the address protection module after completing the writing of the video information in the first format; The address protection module is further used to control the state of the address protection module to be a second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information cache unit.

[0005] Optionally, the original video space security control module further includes a memory self-checking module; The memory self-checking module is used to control the video interface to generate test information according to a preset period, and write the test information into the video information cache unit; The memory self-checking module is further used to read the data in the video information cache unit according to a preset period, and generate a first warning message when it is confirmed that a write attack has occurred in the video information cache unit based on the data and the test information.

[0006] Optionally, the original video space security control module further includes a reading management module; The reading management module is used to monitor the status of the address protection module, and send a second indication signal to the video capture module when it is determined that the status of the address protection module is the second status; The video capture module is used to send a read operation request to the address protection module based on the second indication signal; The address protection module is further used to verify the second operation type and the second key in the read operation request; and send a second response message to the video capture module when it is confirmed that the second operation type and the second key meet the second verification condition; The video capture module is further used to read the video information in the first format from the video information cache unit based on the second response message.

[0007] Optionally, the original video space security control module further includes a first warning management module; The first warning management module is used to obtain the warning messages generated by the address protection module, the memory self-checking module and the reading management module, send the warning messages to the central processing unit of the server management control chip, and receive the first processing result message fed back by the central processing unit based on the warning messages, and feed back the first processing result message to the address protection module, the memory self-checking module and the reading management module, so that the processing flow in the address protection module, the memory self-checking module and the reading management module continues.

[0008] Optionally, the server management control chip further includes a compression process security control module, and the compression process security control module includes an information table local cache module, a remote information table cache module and an information table verification module; The information table local cache module is used to cache the first configuration information when the core compression module compresses the video information in the first format; the first configuration information is configured by the compression configuration module; The remote information table cache module is used to initiate a request to read configuration information from the remote end according to a second preset time period, and read the second configuration information sent by the remote end to the configuration information cache unit from the configuration information cache unit; The information table verification module is used to obtain the first configuration information in the local cache module of the information table and the second configuration information in the remote information table cache module; and when it is determined based on the first configuration information and the second configuration information that the first configuration information when compressing video information in the first format has not been illegally modified, send a third indication signal to the core compression module, where the third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified.

[0009] Optionally, the compression process security control module further includes a configuration update verification module; The configuration update verification module is used to monitor the first change information of the first configuration information in the local cache module of the information table, and when it is determined based on the first change information that the first configuration information has changed, send a first confirmation request to the central processing unit of the server management control chip, and receive the first confirmation result information fed back by the central processing unit based on the first confirmation request, and when it is determined based on the first confirmation result information that the change of the first configuration information does not meet the requirements, generate a second warning message.

[0010] Optionally, the compression process security control module further includes a second warning management module; The second warning management module is used to obtain the warning information generated by the information table verification module and the configuration update verification module, and send the warning information to the central processing unit of the server management control chip, and receive the second processing result information fed back by the central processing unit based on the warning information, and feed back the second processing result information to the information table verification module and the configuration update verification module, so that the processing flow in the information table verification module and the configuration update verification module continues.

[0011] Optionally, the server management control chip further includes a compressed video security control module; the compressed video security control module includes an address management module; The address management module is used to obtain the write address corresponding to the write operation of the compressed video information by the compressed video write control module, and obtain the read address when the network driver reads the compressed video information; and when it is confirmed that the write address is the same as the read address, send a fourth indication signal to the compressed video write control module, where the fourth indication signal indicates that the write address has not been illegally modified.

[0012] Optionally, the compressed video security control module further includes an information update control module; The information update control module is used to monitor the second change information of the write address corresponding to the write operation of the compressed video write control module on the compressed video information, and when it is determined that the write address has changed based on the second change information, send a second confirmation request to the central processing unit of the server management control chip, and receive the second confirmation result information fed back by the central processing unit based on the second confirmation request, and when it is determined that the change of the write address does not meet the requirements based on the second confirmation result information, generate a third warning message.

[0013] Optionally, the compressed video security control module further includes a third warning management module; The third warning module is used to obtain the warning information of the address management module and the information update control module, and send the warning information to the central processing unit of the server management control chip, and receive the third processing result information fed back by the central processing unit based on the warning information, and feed back the third processing result information to the address management module and the information update control module, so that the processing flow in the address management module and the information update control module can continue.

[0014] Optionally, the address management module is further used to obtain the write request sent by the server hardware status management software driver, and verify the third operation type and the third key in the write request; and when it is confirmed that the third operation type and the third key meet the third verification condition, send a third response information to the server hardware status management software driver and control the status of the address management module to be the first state; when the address management module is in the first state, only the server hardware status management software driver is allowed to perform a write operation on the hardware status information cache unit; The address management module is further used to obtain the fifth indication signal sent by the server hardware status management software driver, and the address management module is further used to control the status of the address management module to be the second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to perform a read operation on the hardware status information cache unit; The address management module is further used to obtain the read request sent by the network driver, and verify the fourth operation type and the fourth key in the read request; and when it is confirmed that the fourth operation type and the fourth key meet the fourth verification condition, send a fourth response information to the network driver, and the fourth response information indicates that the network driver is allowed to read data from the hardware status information cache unit.

[0015] According to the second aspect of the present application, an embodiment of the present application provides a data processing method, which is applied to a server management control chip. The server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module connected in sequence, and further includes an original video space security control module; the original video space security control module includes an address protection module; the method includes: The video interface obtains the video information of the server operating system and sends a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; The address protection module verifies the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification condition, the address protection module sends a first response message to the video interface and controls the state of the address protection module to be the first state; when the address protection module is in the first state, only the video interface is allowed to write to the video information cache unit; The video interface converts the video information into video information in a first format based on the first response message, writes the video information in the first format into the video information cache unit, and after completing the writing of the video information in the first format, sends a first indication signal to the address protection module; The address protection module controls the state of the address protection module to be the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read from the video information cache unit.

[0016] Optionally, the server management control chip further includes a compression process security control module, and the compression process security control module includes an information table local cache module, a remote information table cache module, and an information table verification module; the method further includes: The remote information table cache module initiates a request to read configuration information from the remote end according to a second preset time period, and reads second configuration information sent by the remote end to the configuration information cache unit from the configuration information cache unit; The information table verification module obtains the first configuration information cached in the information table local cache module and the second configuration information in the remote information table cache module; and when it is determined based on the first configuration information and the second configuration information that the first configuration information for compressing the video information in the first format has not been illegally modified, the information table verification module sends a third indication signal to the core compression module, and the third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified; the first configuration information is obtained by configuring the compression configuration module; The core compression module compresses the video information in the first format sent by the video capture module to the core compression module through the compression configuration module based on the third indication signal and the first configuration information to obtain compressed video information.

[0017] Optionally, the server management control chip further includes a compressed video security control module; the compressed video security control module includes an address management module; the method further includes: The address management module obtains the write address corresponding to the write operation of the compressed video writing control module for the compressed video information, and obtains the read address when the network driver reads the compressed video information; and when it is confirmed that the write address is the same as the read address, it sends a fourth indication signal to the compressed video writing control module, and the fourth indication signal indicates that the write address has not been illegally modified. Based on the fourth indication signal, the compressed video security control module writes the compressed video information sent by the core compression module to the compressed video security control module to the write address.

[0018] Optionally, the method further includes: The address management module obtains the write request sent by the server hardware status management software driver, and verifies the third operation type and the third key in the write request; and when it is confirmed that the third operation type and the third key meet the third verification condition, it sends a third response message to the server hardware status management software driver and controls the status of the address management module to be the first state; when the address management module is in the first state, only the server hardware status management software driver is allowed to perform a write operation on the hardware status information cache unit. The address management module obtains the fifth indication signal sent by the server hardware status management software driver, and controls the status of the address management module to be the second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to perform a read operation on the hardware status information cache unit. The address management module obtains the read request sent by the network driver, and verifies the fourth operation type and the fourth key in the read request; and when it is confirmed that the fourth operation type and the fourth key meet the fourth verification condition, it sends a fourth response message to the network driver, and the fourth response message indicates that the network driver is allowed to read data from the hardware status information cache unit.

[0019] According to the third aspect of the present application, an embodiment of the present application provides a server, including: A server host; A server management control chip, the server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, a compressed video writing control module connected in sequence, and further includes an original video space security control module; the original video space security control module includes an address protection module. The video interface is used to obtain the server host operating system video information, and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key. The address protection module is used to verify the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification condition, send the first response information to the video interface and control the state of the address protection module to the first state; when the address protection module is in the first state, only the video interface is allowed to perform a write operation on the video information cache unit. The video interface is further used to convert the video information into video information of the first format based on the first response information, write the video information of the first format into the video information cache unit, and after completing the writing of the video information of the first format, send a first indication signal to the address protection module. The address protection module is further used to control the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to perform a read operation on the video information cache unit.

[0020] According to a fourth aspect of the present application, an embodiment of the present application provides a computer-readable storage medium, which stores computer instructions for causing a computer to execute the data processing method in the second aspect or any implementation manner of the second aspect.

[0021] According to a fifth aspect of the present application, an embodiment of the present application provides a computer program product, including a computer program or instruction, which when executed by a processor, implements the data processing method in the second aspect or any implementation manner of the second aspect.

[0022] The server management control chip, data processing method, server, storage medium, and computer program product provided by the embodiments of the present application add an original video space security control module on the basis of the original hardware modules of the server management control chip. The original video space security control module includes an address protection module; the video interface is used to obtain the video information of the server operating system and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; the address protection module is used to verify the first operation type and the first key in the write operation request; and in the case of confirming that the first operation type and the first key meet the first verification condition, send a first response information to the video interface and control the state of the address protection module to be the first state; when the address protection module is in the first state, only the video interface is allowed to write to the video information cache unit; the video interface is also used to convert the video information into video information in a first format based on the first response information, write the video information in the first format into the video information cache unit, and after completing the writing of the video information in the first format, send a first indication signal to the address protection module; the address protection module is also used to control the state of the address protection module to be the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read from the video information cache unit; in this way, during and after the process of writing the video information of the server operating system into the video information cache unit through the interface module, the content of the video information cache unit will not be maliciously modified by software running on the central processing unit, so that the video interface of the operating system seen by the remote user will not be an untrue operating system interface, and it will not affect the management and control of the server by the remote user; and by verifying the write operation request sent by the video interface, it can be ensured that the video interface is not maliciously hijacked by software.

[0023] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically given below. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 It is a schematic structural diagram of the current server management control chip; Figure 2 It is a schematic structural diagram of the server management control chip in the embodiments of the present application; Figure 3 It is a schematic structural diagram of the original video space security control module in the embodiments of the present application; Figure 4 It is a schematic diagram of the state adjustment process of the state machine in the embodiments of the present application; Figure 5 It is a schematic structural diagram of another server management and control chip in the embodiment of the present application; Figure 6 It is a schematic structural diagram of the compression process security control module in the embodiment of the present application; Figure 7 It is a schematic structural diagram of the compressed video security control module in the embodiment of the present application; Figure 8 It is a schematic flowchart of a data processing method in the embodiment of the present application; Figure 9 It is a schematic hardware structure diagram of a server in the embodiment of the present application. Detailed implementation manners

[0025] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0026] The current server management and control chip is as Figure 1 shown, and includes a video interface (VGA), a video capture module, a compression configuration module, a core compression module, and a compressed video write control module that are connected in sequence; it also includes a network driver (Ethernet module), a memory module (DDR), a system bus, and a central processing unit (CPU); the memory module includes a video information cache unit A, a compressed video information cache unit B, a hardware status information cache unit D, and a target cache unit C corresponding when the network driver reads the video information and the hardware status information.

[0027] The processing process of the current server management control chip is as follows: 1. The video information (real-time operating system interface information) of the server host operating system is transmitted to the VGA inside the server management control chip. The VGA generates video information in the first format, such as RGB format video information. During the process of generating RGB format video information, the VGA needs to interact with area A in the external DDR. 2. The video capture module obtains video information in two ways. One is to passively receive the output of the VGA, and the other is to actively read from area A and perform corresponding format processing, such as color space conversion, etc., to convert the RGB format video information into YUV format video information. 3. The compression configuration module, the function of this module is to configure the register functions for compression. The most important configurations are video resolution, luminance table, chrominance table, etc. 4. The core compression module receives the YUV format video information and performs video compression in the corresponding format and configuration according to the register function configuration of the compression configuration module to obtain compressed video information. Common video compression formats include H.264, JPEG, etc. 5. The compressed video writing control module receives the compressed video information and writes it into area B in the external DDR. 6. The hardware interface of the server management control chip obtains the server hardware status information (such as CPU temperature, motherboard voltage, fan speed, etc.), and after being processed by the corresponding functional software, writes the hardware status information into area D in the DDR. 7. The network driver reads the compressed video information and hardware status information cached in areas B and D in the DDR, moves them to area C in the DDR, and sends the compressed video information and hardware status information to the remote end through the network. In this way, the remote end software parses the network data packet, receives the compressed video information, decompresses the compressed video information, and then displays the server operating system interface; the remote end software parses the network data packet, receives the server hardware status information, and displays it.

[0028] However, during the process of writing the real-time video information of the server operating system into area A of the server management control chip and after writing into area A, there is a risk of being maliciously modified by software. The result is that the video interface seen by the remote end user is not the real operating system interface, which further affects the management and control of the server by the remote end user. In serious cases, it may even cause misoperations and affect the system security of the server.

[0029] Therefore, the embodiment of the present application provides a server management control chip, as Figure 2 shown, including a video interface (VGA), a video capture module, a compression configuration module, a core compression module, a compressed video writing control module connected in sequence, and also including an original video space security control module; the original video space security control module includes an address protection module.

[0030] The video interface is used to obtain the video information of the server operating system and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key.

[0031] The address protection module is used to verify the first operation type and the first key in the write operation request; and in the case where it is confirmed that the first operation type and the first key meet the first verification condition, send a first response message to the video interface and control the state of the address protection module to be the first state; when the address protection module is in the first state, only the video interface is allowed to perform a write operation on the video information cache unit.

[0032] The video interface is also used to convert the video information into video information in a first format based on the first response message, write the video information in the first format into the video information cache unit, and after completing the writing of the video information in the first format, send a first indication signal to the address protection module.

[0033] The address protection module is also used to control the state of the address protection module to be the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to perform a read operation on the video information cache unit.

[0034] In this embodiment, as Figure 2 shown, the management control chip may further include a network driver (Ethernet module), a memory module (DDR), a system bus, and a central processing unit (CPU); the memory module includes a video information cache unit A, a compressed video information cache unit B, a hardware status information cache unit D, and a target cache unit C corresponding when the network driver reads the video information and the hardware status information.

[0035] In this embodiment, the video information (operating system real-time interface information) of the server host operating system is transmitted to the video interface (VGA) inside the server management control chip. The video interface obtains the video information of the server operating system and sends a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key. The first operation type is a write operation, and it can be agreed that the first operation type = 01. Regarding the generation of the first key, it can be the responsibility of the address protection module to generate it according to the key generation algorithm agreed with the VGA.

[0036] In this embodiment, the address protection module can verify the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification condition, send the first response information to the video interface and control the state of the address protection module to the first state; when the address protection module is in the first state, only the video interface is allowed to perform write operations on the video information cache unit. When it is confirmed that the first operation type and the first key do not meet the first verification condition, an alarm signal error_wr_request = 1 can be generated.

[0037] In this embodiment, the video interface converts the video information into video information of the first format, such as RGB format video information, based on the first response information, and writes the video information of the first format into the video information cache unit, and after completing the writing of the video information of the first format, sends the first indication signal to the address protection module. The first indication signal indicates that the video interface has completed the writing of the video information of the first format.

[0038] In some embodiments, during the process of writing the video information of the first format by the video interface, when the address protection module detects that in addition to the video interface, the system bus has a write or read request to access the video information cache unit, it means that there is malware attempting to write or read the video information cache unit at this time. At this time, the address protection module returns to the third state and generates an alarm signal attempt_wr_rd = 1. When the address protection module is in the third state, access to the read and write operations of the video information cache unit is prohibited.

[0039] The address protection module controls the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to perform read operations on the video information cache unit.

[0040] In one embodiment, after the VGA sends the first indication signal to the address protection module, it can send a first read operation request to the address protection module. The first read operation request includes the fifth operation type and the fifth key. The fifth operation type is a read operation, and it can be agreed that the fifth operation type = 10. Regarding the generation of the fifth key, it is the responsibility of the address protection module to generate it according to the key generation algorithm agreed with the VGA. And the key generation algorithms used for write operations and read operations are different, and the generated keys are different.

[0041] After the address protection module verifies the fifth operation type and the fifth key, it sends the fifth response information to the VGA. The fifth response information indicates that the VGA is allowed to perform read operations on the video information cache unit. When the address protection module fails to verify the fifth operation type and the fifth key, an alarm signal error_rd_request = 2 can be generated.

[0042] Based on the fifth response information, the VGA reads the video information in the first format from the video information cache unit and sends it to the video capture module. During the process of the VGA reading the video information in the first format, the address protection module detects that in addition to the VGA, there is a write or read request from the system bus to access the video information cache unit, indicating that there is malware attempting to write to or read from the video information cache unit at this time. At this time, the address protection module returns to the third state and generates an alarm signal attempt_wr_rd = 2.

[0043] In another implementation, as Figure 3 shown, the original video space security control module further includes a reading management module.

[0044] The reading management module is used to monitor the state of the address protection module and, when determining that the state of the address protection module is the second state, send a second indication signal to the video capture module.

[0045] The video capture module is used to send a read operation request to the address protection module based on the second indication signal.

[0046] The address protection module is further used to verify the second operation type and the second key in the read operation request; and, when confirming that the second operation type and the second key meet the second verification condition, send a second response information to the video capture module.

[0047] The video capture module is further used to read the video information in the first format from the video information cache unit based on the second response information.

[0048] In this implementation, the second indication signal indicates that the video capture module can perform a read operation. The read operation request includes a second operation type and a second key. The second operation type is a read operation, and it can be agreed that the operation type = 11. Regarding the generation of the second key, it is the responsibility of the address protection module and is generated according to the key generation algorithm agreed upon with the video capture module.

[0049] In some implementations, the reading management module is further used to determine that the video capture module is hijacked by malware when it monitors that the address protection module is in a non-CAN_RD state and the video capture module initiates a read operation request. At this time, an alarm signal attempt_wr_rd = 4 needs to be output.

[0050] In some implementations, after the video capture module obtains the video information in the first format, corresponding format processing can be performed, such as color space conversion, etc., to convert the video information in the RGB format into the video information in the YUV format.

[0051] In some implementations, as Figure 3As shown, the original video space security control module further includes a memory self-check module.

[0052] The memory self-check module is used to control the video interface to generate test information according to a preset period, and write the test information into the video information cache unit; the memory self-check module is also used to read the data in the video information cache unit according to a preset period, and when it is confirmed that a write attack has occurred in the video information cache unit based on the data and the test information, generate a first warning message.

[0053] In this embodiment, the memory self-check module is a functional enhancement of the address protection module function, preventing the overall security management function from being abnormal after the address protection module function fails. The enabling of the memory self-check module is set regularly, and the function of this module is enabled once according to the agreed interval time T. When the function of this module is enabled, the VGA generates test information, such as a test image, and writes it into the video information cache unit, and then the module reads it out and performs verification. If the read data is different from the written test image data value, it means that malware has performed a write attack on the video information cache unit at this time, generating an alarm signal attempt_wr_rd = 3, that is, the first warning message. At the same time, the test image should change continuously, that is, in two consecutive memory self-checks, the test images should be different, preventing malware from affecting the normal function goal of this memory self-check module after learning the test image.

[0054] In some embodiments, as Figure 3 shown, the original video space security control module further includes a first warning management module. The first warning management module is also the warning management module 1.

[0055] The first warning management module is used to obtain the warning information generated by the address protection module, the memory self-check module, and the reading management module, send the warning information to the central processing unit of the server management control chip, and receive the first processing result information fed back by the central processing unit based on the warning information, and feedback the first processing result information to the address protection module, the memory self-check module, and the reading management module, so that the processing flow in the address protection module, the memory self-check module, and the reading management module can continue.

[0056] In this embodiment, the function of the first alarm management module is to collect the alarm signals attempt_wr_rd (=1, 2, 3, 4) and error_wr_request (=1, 2) output by the address protection module, the memory self-check module, and the read management module, and report them to the CPU. The CPU adds a software driver corresponding to the security management control function, receives the interrupt corresponding to the above alarm signal, and processes it. After the processing is completed, the first alarm management module is notified. At the same time, the first alarm management module feeds back the processing results of the software to the address protection module, the memory self-check module, and the read management module, so that the processing flow inside these modules can continue.

[0057] In this embodiment, the first alarm management module can ensure that when a malware attack is received, it can be processed immediately, and after the processing is completed, the normal function of the server management control chip can be restored as soon as possible, thereby improving the efficiency of exception processing.

[0058] In some embodiments, a state machine can be set in the address protection module, and the state machine includes three states: FREEZE, CAN_WR, and CAN_RD. The state of the state machine is also the state of the address protection module. The default state of the state machine is the FREEZE state. In this state, any read and write operations to the video information cache unit are prohibited. In the CAN_WR state, only VGA is allowed to write to the video information cache unit, and other modules are prohibited from writing to this space. In the CAN_RD state, only VGA and the subsequent video capture module are allowed to read the video information cache unit. The first state is the CAN_WR state, and the second state is CAN_WR. The FREEZE state is the third state. The flowchart of the state machine state adjustment is shown in FIG. Figure 4 shown.

[0059] State jump 1: jump from FREEZE state to CAN_WR state. The condition for this state to occur is that VGA initiates a write request to the address protection module. Or after the abnormal alarm reported to the CPU by the first alarm management module is processed, the CPU sends an indication signal to the address protection module according to the corresponding alarm type, and the state machine of the address protection module starts to jump again.

[0060] State transition 2: Transition from the CAN_WR state to the FREEZE state. This state transition occurs when, during the VGA write process, the address protection module detects that, in addition to the VGA, there are write or read requests from the system bus to access the video information cache unit. This indicates that malware is attempting to write to or read from the original video space at this time. In this case, the state machine must immediately return to the FREEZE state and send an indication signal attempt_wr_rd = 1 to the first alarm management module; or the first type of write operation request sent by the VGA or the first key is different from the agreed one. In this case, the state machine must also return to the FREEZE state and send an indication signal error_wr_request = 1 to the alarm management module 1.

[0061] State transition 3: Transition from the CAN_WR state to the CAN_RD state. This state transition occurs when the VGA has completed writing 1 frame. After the write is completed, the VGA sends a completion indication signal to the address protection module. State transition 4: Transition from the CAN_RD state to the CAN_WR state. This state transition occurs when the VGA has completed reading 1 frame. After the read is completed, the VGA sends a completion indication signal to the address protection module, and the VGA initiates a write operation request to the address protection module.

[0062] State transition 5: Transition from the CAN_RD state to the FREEZE state. This state transition occurs when, during the VGA read process, the address protection module detects that, in addition to the VGA, there are write or read requests from the system bus to access the video information cache unit. This indicates that malware is attempting to write to or read from the video information cache unit at this time. In this case, the state machine must immediately return to the FREEZE state and send an indication signal attempt_wr_rd = 2 to the first alarm management module; or the fifth type of read request sent by the VGA or the fifth key is different from the agreed one. In this case, the state machine must also return to the FREEZE state and send an indication signal error_rd_request = 2 to the first alarm management module.

[0063] State transition 6: Transition from the FREEZE state back to the CAN_RD state. This state transition occurs after the abnormal alarm reported by the first alarm management module to the CPU has been processed. According to the corresponding alarm type, the CPU issues an indication signal to the address protection module, and the state machine of the address protection module resumes jumping.

[0064] In this embodiment, the compression configuration module obtains the video information in YUV format sent by the video capture module and performs register function configuration. The most important configurations are video resolution, luminance table, chrominance table, etc. The core compression module receives the video information in YUV format and performs video compression of the corresponding format and configuration according to the register function configuration of the compression configuration module to obtain compressed video information. Common video compression formats include H.264, JPEG, etc. The compressed video writing control module receives the compressed video information and writes it into area B of the external DDR. The network driver reads the compressed video information cached in area B of the DDR, moves it to area C of the DDR, and sends the compressed video information to the remote end through the network. In this way, the remote end software parses the network data packet, receives the compressed video information, decompresses the compressed video information, and then displays it on the server operating system interface.

[0065] The server management and control chip provided by the embodiment of the present application, by adding an original video space security control module on the basis of the original hardware module of the server management and control chip, the original video space security control module includes an address protection module; the video interface is used to obtain the server operating system video information and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; the address protection module is used to verify the first operation type and the first key in the write operation request; and in the case where it is confirmed that the first operation type and the first key meet the first verification condition, send a first response information to the video interface and control the state of the address protection module to be the first state; when the address protection module is in the first state, only the video interface is allowed to write to the video information cache unit; the video interface is also used to convert the video information into video information of the first format based on the first response information, write the video information of the first format into the video information cache unit, and after completing the writing of the video information of the first format, send a first indication signal to the address protection module; the address protection module is also used to control the state of the address protection module to be the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information cache unit; in this way, during the process of writing the server operating system video information into the video information cache unit through the interface module and after writing, the content of the video information cache unit will not be maliciously modified by software running on the central processing unit, etc., so that the operating system video interface seen by the remote end user is not the real operating system interface, and it will not affect the management and control of the server by the remote end user; and, by verifying the write operation request sent by the video interface, it can be ensured that the video interface is not maliciously hijacked by software.

[0066] In an alternative embodiment, as Figure 5As shown, the server management control chip further includes a compression process security control module, which includes an information table local cache module, a remote information table cache module, and an information table verification module.

[0067] The information table local cache module is used to cache the first configuration information when the core compression module compresses the video information in the first format; the first configuration information is configured by the compression configuration module.

[0068] The remote information table cache module is used to initiate a request to read configuration information from the remote end according to a second preset time period, and read the second configuration information sent by the remote end to the configuration information cache unit based on the request to read configuration information from the configuration information cache unit.

[0069] The information table verification module is used to obtain the first configuration information in the information table local cache module and the second configuration information in the remote information table cache module; and when it is determined based on the first configuration information and the second configuration information that the first configuration information for compressing the video information in the first format has not been illegally modified, a third indication signal is sent to the core compression module, and the third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified.

[0070] In this embodiment, the first configuration information includes the luminance table and the chrominance table when the video information in the first format is compressed. Since the luminance table and the chrominance table can be accessed by registers, malware may illegally obtain the register addresses of these two key configuration tables and then modify the content illegally, resulting in damage to the compressed video information. In order to ensure that the video information in the first format can be compressed normally, it is necessary to verify whether the first configuration information has been illegally modified.

[0071] In this embodiment, before formally compressing the video information in the first format, the second configuration information used for compression, such as the content of the chrominance table and the luminance table, is first written into the DDR and then sent to the remote end by the Ethernet module for temporary storage at the remote end. When the compression process security control module initiates a request to read configuration information from the remote end through the network, the software at the remote end sends the second configuration information cached at the remote end to the DDR of the server management control chip, and then the compression process security control module reads it back to the remote information table cache module. It should be noted that the remote information table cache module will send a request to read configuration information to the remote end at intervals of the T1 time period. T1 can adopt the default value or can be configured by software.

[0072] In this embodiment, since the second configuration information sent by the remote end is cached in the remote end information table, malware cannot modify it illegally. Therefore, if the verification module determines that the contents of the local cache module of the information table and the remote information table cache module are inconsistent, it is determined that malware has illegally modified the local first configuration information. If the luminance table is illegally modified, an alarm signal error_mdy_compress_config = 1 is generated. If the chrominance table is illegally modified, an alarm signal error_mdy_compress_config = 2 is generated.

[0073] In this embodiment, if it is determined that the local first configuration information has not been illegally modified, a third indication signal is sent to the core compression module, so that the core compression module responds to the third indication signal and performs a compression operation to obtain compressed video information.

[0074] In some embodiments, as Figure 6 shown, the compression process security control module further includes a configuration update verification module; the configuration update verification module is used to monitor the first change information of the first configuration information in the local cache module of the information table, and when it is determined that the first configuration information has changed based on the first change information, send a first confirmation request to the central processing unit of the server management control chip, and receive the first confirmation result information fed back by the central processing unit based on the first confirmation request, and when it is determined that the change of the first configuration information does not meet the requirements based on the first confirmation result information, generate a second alarm information.

[0075] In this embodiment, the second alarm information may be error_mdy_compress_config = 3.

[0076] In some embodiments, as Figure 6 shown, the compression process security control module further includes a second alarm management module; that is, the alarm management module 2. The second alarm management module is used to obtain the alarm information generated by the information table verification module and the configuration update verification module, send the alarm information to the central processing unit of the server management control chip, and receive the second processing result information fed back by the central processing unit based on the alarm information, and feed back the second processing result information to the information table verification module and the configuration update verification module, so that the processing flow in the information table verification module and the configuration update verification module continues.

[0077] In this embodiment, by further setting up a compression process security control module, the compression process security control module includes an information table local cache module, a remote information table cache module, and an information table verification module; in this way, it can not only ensure that the content in the video information cache module is not maliciously modified by software, but also ensure that the content of the luminance table and chrominance table used in the video information compression process is not maliciously modified by software, realizing the normal compression of video information; enabling remote users to stably and truly obtain the video picture of the local server operating system interface.

[0078] In an alternative embodiment, as Figure 5 shown, the server management control chip further includes a compressed video security control module; the compressed video security control module includes an address management module; the address management module is used to obtain the write address corresponding to the write operation of the compressed video information by the compressed video write control module, and obtain the read address when the network driver reads the compressed video information; and when it is confirmed that the write address is the same as the read address, a fourth indication signal is sent to the compressed video write control module, and the fourth indication signal indicates that the write address has not been illegally modified.

[0079] In this embodiment, the read address when the network driver reads the compressed video information is the read address for the network driver to initiate a DMA operation to read the compressed video information cached in the DDR. The DMA operation refers to first moving the compressed video information from area B to area C, and then the network driver initiates a descriptor operation to read from area C and send it to the remote end through the network. Since the read address used in the DMA operation is configured at the software level and there is no situation of being modified by malicious software, while the write address corresponding to the write operation of the compressed video information can be modified through the system bus and there is a possibility of being illegally modified by malicious software. If the verification result is consistent, a fourth indication signal is sent to the compressed video write control module, enabling the compressed video write control module to write the compressed video information into area B of the DDR. If the verification result is inconsistent, it means that the write address has been illegally modified by malicious software, and an alarm signal error_mdy_compress_data_addr = 1 is generated.

[0080] In some embodiments, the address management module can ensure that the hardware status information of the server is not modified by malicious software during and after being written into the memory and during the transmission to the remote end.

[0081] Specifically, the address management module is used to obtain the write request sent by the server hardware status management software driver, and verify the third operation type and the third key in the write request; and when it is confirmed that the third operation type and the third key meet the third verification condition, send the third response information to the server hardware status management software driver and control the status of the address management module to the first state; when the address management module is in the first state, only the server hardware status management software driver is allowed to perform write operations on the hardware status information cache unit.

[0082] The address management module is further used to obtain the fifth indication signal sent by the server hardware status management software driver, and the address management module is further used to control the status of the address management module to the second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to perform read operations on the hardware status information cache unit.

[0083] The address management module is further used to obtain the read request sent by the network driver, and verify the fourth operation type and the fourth key in the read request; and when it is confirmed that the fourth operation type and the fourth key meet the fourth verification condition, send the fourth response information to the network driver, and the fourth response information indicates that the network driver is allowed to read data from the hardware status information cache unit.

[0084] In this embodiment, the specific implementation of the address management module is similar to that of the address protection module, and will not be elaborated here. The differences are as follows: 1. The source allowed to write by the address management module is the server hardware status management software driver, rather than the VGA. 2. The address management module allows the network driver to read, rather than the VGA and the video capture module. 3. The "operation type + key" used is different, and the parsing mechanism is different.

[0085] In some embodiments, as Figure 7 shown, the compressed video security control module further includes an information update control module; the information update control module is used to monitor the second change information of the write address corresponding to the write operation of the compressed video write control module on the compressed video information, and when it is determined that the write address changes based on the second change information, send a second confirmation request to the central processing unit of the server management control chip, and receive the second confirmation result information fed back by the central processing unit based on the second confirmation request, and when it is determined that the change of the write address does not meet the requirements based on the second confirmation result information, generate the third warning information.

[0086] In some embodiments, as Figure 7As shown in the figure, the compressed video security control module further includes a third alarm management module, that is, the alarm management module 3. The third alarm module is used to obtain the alarm information of the address management module and the information update control module, send the alarm information to the central processing unit of the server management control chip, and receive the third processing result information fed back by the central processing unit based on the alarm information, and feed back the third processing result information to the address management module and the information update control module, so that the processing flow in the address management module and the information update control module can continue.

[0087] In this embodiment, the security management and control of the video information cache unit of the server management control chip are realized, ensuring that the content of the video information cache unit is not maliciously modified by software; at the same time, the security management and control of the video compression process are realized, ensuring that the content of the luminance table and chrominance table used in the compression process is not maliciously modified by software, and realizing the normal compression of video information; on the output side of the compressed video information, a security management mechanism for the storage space of the compressed video information is realized, ensuring that the network driver can read the compressed video information normally and stably, so that the remote user can obtain the video picture of the local server operating system interface stably and truly.

[0088] An embodiment of the present application provides a data processing method, which is applied to a server management control chip. The server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video writing control module connected in sequence, and further includes an original video space security control module; the original video space security control module includes an address protection module; as Figure 8 shown, the method includes: S801, the video interface obtains the video information of the server operating system, and sends a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key. S802, the address protection module verifies the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification condition, the address protection module sends a first response information to the video interface and controls the state of the address protection module to be the first state; when the address protection module is in the first state, only the video interface is allowed to write to the video information cache unit.

[0089] S803, the video interface converts the video information into video information of the first format based on the first response information, writes the video information of the first format into the video information cache unit, and after completing the writing of the video information of the first format, sends a first indication signal to the address protection module.

[0090] S804, the address protection module controls the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information cache unit.

[0091] In this embodiment, for the specific implementation details, refer to the description of the server management control chip in the above embodiment, which will not be elaborated here.

[0092] In some embodiments, the server management control chip further includes a compression process security control module, and the compression process security control module includes an information table local cache module, a remote information table cache module, and an information table verification module; the method further includes: The remote information table cache module initiates a request to read the configuration information from the remote end according to the second preset time period, and reads the second configuration information sent by the remote end to the configuration information cache unit from the configuration information cache unit; the information table verification module obtains the first configuration information cached in the information table local cache module and the second configuration information in the remote information table cache module; and when it is determined based on the first configuration information and the second configuration information that the first configuration information when compressing the video information in the first format has not been illegally modified, a third indication signal is sent to the core compression module, and the third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified; the first configuration information is configured by the compression configuration module; the core compression module compresses the video information in the first format sent by the video capture module to the core compression module through the compression configuration module based on the third indication signal and the first configuration information to obtain the compressed video information.

[0093] In some embodiments, the server management control chip further includes a compressed video security control module; the compressed video security control module includes an address management module; the method further includes: The address management module obtains the write address corresponding to the write operation of the compressed video write control module on the compressed video information, and obtains the read address when the network driver reads the compressed video information; and when it is confirmed that the write address is the same as the read address, a fourth indication signal is sent to the compressed video write control module, and the fourth indication signal indicates that the write address has not been illegally modified; the compressed video security control module writes the compressed video information sent by the core compression module to the compressed video security control module to the write address based on the fourth indication signal.

[0094] In some embodiments, the method further includes: The address management module receives the write request sent by the server hardware status management software driver, and verifies the third operation type and the third key in the write request; and when it is confirmed that the third operation type and the third key meet the third verification condition, the address management module sends the third response information to the server hardware status management software driver and controls the status of the address management module to the first state; when the address management module is in the first state, only the server hardware status management software driver is allowed to perform write operations on the hardware status information cache unit; the address management module receives the fifth indication signal sent by the server hardware status management software driver, and controls the status of the address management module to the second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to perform read operations on the hardware status information cache unit; the address management module receives the read request sent by the network driver, and verifies the fourth operation type and the fourth key in the read request; and when it is confirmed that the fourth operation type and the fourth key meet the fourth verification condition, the address management module sends the fourth response information to the network driver, and the fourth response information indicates that the network driver is allowed to read data from the hardware status information cache unit.

[0095] According to an embodiment of the present application, the present application further provides a server, as Figure 9 shown, including: A server host and a server management control chip. The server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module connected in sequence, and also includes an original video space security control module; the original video space security control module includes an address protection module. The video interface is used to obtain the video information of the server host operating system and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; the address protection module is used to verify the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification condition, the address protection module sends the first response information to the video interface and controls the status of the address protection module to the first state; when the address protection module is in the first state, only the video interface is allowed to perform write operations on the video information cache unit; the video interface is also used to convert the video information into video information of the first format based on the first response information, write the video information of the first format into the video information cache unit, and after completing the writing of the video information of the first format, send a first indication signal to the address protection module; the address protection module is also used to control the status of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to perform read operations on the video information cache unit.

[0096] An embodiment of the present application provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the data processing method in the above embodiment of the present application.

[0097] An embodiment of the present application provides a computer-readable storage medium storing executable instructions, where the executable instructions are stored, and when the executable instructions are executed by a processor, the processor will be caused to execute the data processing method provided by the embodiment of the present application.

[0098] In some embodiments, the computer-readable storage medium may be a tangible medium that may contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium may be a machine-readable signal medium or a machine-readable storage medium. The computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of the computer-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0099] In some embodiments, the executable instructions may be in the form of a program, software, a software module, a script, or code, written in any form of programming language (including a compiled or interpreted language, or a declarative or procedural language), and may be deployed in any form, including being deployed as a stand-alone program or being deployed as a module, a component, a subroutine, or other unit suitable for use in a computing environment.

[0100] As an example, the executable instructions may or may not correspond to a file in a file system, may be stored as part of a file that stores other programs or data, for example, stored in one or more scripts in a HyperText Markup Language (HTML) document, stored in a single file dedicated to the program being discussed, or stored in multiple cooperating files (for example, files that store one or more modules, subroutines, or portions of code).

[0101] As an example, the executable instructions may be deployed to execute on one computing device, or on multiple computing devices located at one location, or on multiple computing devices distributed across multiple locations and interconnected by a communication network.

[0102] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0103] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0104] A computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, a server of a distributed system, or a server incorporating blockchain.

[0105] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this application can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this application can be achieved, and no limitation is imposed herein.

[0106] In addition, the terms "first" and "second" are for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In the description of this application, "a plurality of" means two or more unless otherwise specifically defined.

[0107] As described above, the above are only specific embodiments of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the said claims.

Claims

1. A server management control chip, comprising a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video writing control module connected in sequence, characterized in that, Further included are: An original video space security control module; The original video space security control module includes an address protection module; The video interface is used to obtain server operating system video information and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; The address protection module is used to verify the first operation type and the first key in the write operation request; And in the case of confirming that the first operation type and the first key meet the first verification condition, send a first response information to the video interface and control the state of the address protection module to be a first state; When the address protection module is in the first state, only the video interface is allowed to perform a write operation on the video information cache unit; The video interface is further used to convert the video information into video information in a first format based on the first response information, write the video information in the first format into the video information cache unit, and after completing the writing of the video information in the first format, send a first indication signal to the address protection module; The address protection module is further used to control the state of the address protection module to be a second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to perform a read operation on the video information cache unit.

2. The server management control chip according to claim 1, wherein The original video space security control module further includes a memory self-check module; The memory self-check module is used to control the video interface to generate test information according to a preset period and write the test information into the video information cache unit; The memory self-check module is further used to read the data in the video information cache unit according to a preset period, and generate a first warning information when it is confirmed that a write attack has occurred on the video information cache unit based on the data and the test information.

3. The server management control chip according to claim 2, wherein The original video space security control module further includes a read management module; The read management module is used to monitor the state of the address protection module, and send a second indication signal to the video capture module when it is determined that the state of the address protection module is the second state; The video capture module is used to send a read operation request to the address protection module based on the second indication signal; The address protection module is further used to verify the second operation type and the second key in the read operation request; and in the case of confirming that the second operation type and the second key meet the second verification condition, send a second response information to the video capture module; The video capture module is further used to read the video information in the first format from the video information cache unit based on the second response information.

4. The server management control chip according to claim 3, characterized in that, The original video space security control module further includes a first warning management module; The first alarm management module is used to obtain the alarm information generated by the address protection module, the memory self-check module, and the reading management module, send the alarm information to the central processing unit of the server management control chip, and receive the first processing result information fed back by the central processing unit based on the alarm information, and feed back the first processing result information to the address protection module, the memory self-check module, and the reading management module, so that the processing flows in the address protection module, the memory self-check module, and the reading management module can continue.

5. The server management control chip according to claim 1, wherein It further includes a compression process security control module, and the compression process security control module includes an information table local cache module, a remote information table cache module, and an information table verification module; The information table local cache module is used to cache the first configuration information when the core compression module compresses the video information in the first format; the first configuration information is obtained by configuring the compression configuration module; The remote information table cache module is used to initiate a request to read configuration information to the remote end according to a second preset time period, and read the second configuration information sent by the remote end to the configuration information cache unit from the configuration information cache unit; The information table verification module is used to obtain the first configuration information in the information table local cache module and the second configuration information in the remote information table cache module; And when it is determined based on the first configuration information and the second configuration information that the first configuration information when compressing the video information in the first format has not been illegally modified, a third indication signal is sent to the core compression module, and the third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified.

6. The server management control chip according to claim 5, wherein The compression process security control module further includes a configuration update verification module; The configuration update verification module is used to monitor the first change information of the first configuration information in the information table local cache module, and when it is determined based on the first change information that the first configuration information has changed, send a first confirmation request to the central processing unit of the server management control chip, and receive the first confirmation result information fed back by the central processing unit based on the first confirmation request, and when it is determined based on the first confirmation result information that the change of the first configuration information does not meet the requirements, generate a second alarm information.

7. The server management control chip according to claim 6, characterized in that The compression process security control module further includes a second alarm management module; The second alarm management module is used to obtain the alarm information generated by the information table verification module and the configuration update verification module, send the alarm information to the central processing unit of the server management control chip, and receive the second processing result information fed back by the central processing unit based on the alarm information, and feed back the second processing result information to the information table verification module and the configuration update verification module, so that the processing flows in the information table verification module and the configuration update verification module can continue.

8. The server management control chip according to claim 1, characterized in that, It further includes a compressed video security control module; the compressed video security control module includes an address management module; The address management module is used to obtain the write address corresponding to the write operation of the compressed video information by the compressed video write control module, and obtain the read address when the network driver reads the compressed video information; and when it is confirmed that the write address is the same as the read address, send a fourth indication signal to the compressed video write control module, and the fourth indication signal indicates that the write address has not been illegally modified.

9. The server management control chip according to claim 8, characterized in that The compressed video security control module further includes an information update control module; The information update control module is used to monitor the second change information of the write address corresponding to the write operation of the compressed video information by the compressed video write control module, and when it is determined that the write address has changed based on the second change information, send a second confirmation request to the central processing unit of the server management control chip, and receive the second confirmation result information fed back by the central processing unit based on the second confirmation request, and when it is determined that the change of the write address does not meet the requirements based on the second confirmation result information, generate a third warning information.

10. The server management control chip according to claim 9, wherein, The compressed video security control module further includes a third warning management module; The third warning module is used to obtain the warning information of the address management module and the information update control module, and send the warning information to the central processing unit of the server management control chip, and receive the third processing result information fed back by the central processing unit based on the warning information, and feed back the third processing result information to the address management module and the information update control module, so that the processing flow in the address management module and the information update control module continues.

11. The server management control chip according to claim 8, wherein The address management module is further used to obtain a write request sent by the server hardware status management software driver, and verify the third operation type and the third key in the write request; And when it is confirmed that the third operation type and the third key meet the third verification condition, send a third response information to the server hardware status management software driver and control the status of the address management module to be the first state; when the address management module is in the first state, only the server hardware status management software driver is allowed to perform a write operation on the hardware status information cache unit; The address management module is further used to obtain a fifth indication signal sent by the server hardware status management software driver, and the address management module is further used to control the status of the address management module to be the second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to perform a read operation on the hardware status information cache unit; The address management module is further used to obtain a read request sent by the network driver, and verify the fourth operation type and the fourth key in the read request; And when it is confirmed that the fourth operation type and the fourth key meet the fourth verification condition, send fourth response information to the network driver, where the fourth response information indicates that the network driver is allowed to read data from the hardware status information cache unit.

12. A data processing method, characterized in that, Applied to a server management control chip, the server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video writing control module connected in sequence, and also includes an original video space security control module; The original video space security control module includes an address protection module; the method includes: The video interface obtains server operating system video information, and sends a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; The address protection module verifies the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification condition, send first response information to the video interface and control the state of the address protection module to be a first state; when the address protection module is in the first state, only the video interface is allowed to write to the video information cache unit; The video interface converts the video information into video information in a first format based on the first response information, writes the video information in the first format into the video information cache unit, and after finishing writing the video information in the first format, sends a first indication signal to the address protection module; The address protection module controls the state of the address protection module to be a second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read from the video information cache unit.

13. The data processing method according to claim 12, wherein The server management control chip further includes a compression process security control module, and the compression process security control module includes an information table local cache module, a remote information table cache module, and an information table verification module; The method further includes: The remote information table cache module initiates a request to read configuration information from a remote end according to a second preset time period, and reads second configuration information sent by the remote end to the configuration information cache unit from the configuration information cache unit; The information table verification module obtains the first configuration information cached in the information table local cache module and the second configuration information in the remote information table cache module; And when it is determined, based on the first configuration information and the second configuration information, that the first configuration information for compressing the video information in the first format has not been illegally modified, send a third indication signal to the core compression module, where the third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified; the first configuration information is configured by the compression configuration module. The core compression module compresses the video information in the first format sent by the video capture module to the core compression module through the compression configuration module based on the third indication signal and the first configuration information, to obtain compressed video information.

14. The data processing method according to claim 12, wherein The server management control chip further includes a compressed video security control module; the compressed video security control module includes an address management module; the method further includes: The address management module obtains the write address corresponding to the write operation of the compressed video write control module on the compressed video information, and obtains the read address when the network driver reads the compressed video information; and when confirming that the write address is the same as the read address, sends a fourth indication signal to the compressed video write control module, where the fourth indication signal indicates that the write address has not been illegally modified; The compressed video security control module writes the compressed video information sent by the core compression module to the compressed video security control module to the write address based on the fourth indication signal.

15. The data processing method according to claim 14, wherein The method further includes: The address management module obtains a write request sent by the server hardware status management software driver, and verifies the third operation type and the third key in the write request; and when confirming that the third operation type and the third key meet the third verification condition, sends a third response message to the server hardware status management software driver and controls the status of the address management module to be the first state; when the address management module is in the first state, only the server hardware status management software driver is allowed to perform a write operation on the hardware status information cache unit; The address management module obtains a fifth indication signal sent by the server hardware status management software driver, and controls the status of the address management module to be the second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to perform a read operation on the hardware status information cache unit; The address management module obtains a read request sent by the network driver, and verifies the fourth operation type and the fourth key in the read request; and when confirming that the fourth operation type and the fourth key meet the fourth verification condition, sends a fourth response message to the network driver, where the fourth response message indicates that the network driver is allowed to read data from the hardware status information cache unit.

16. A server, characterized in that, Including: A server host; A server management control chip, the server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module that are connected in sequence, and further includes an original video space security control module; the original video space security control module includes an address protection module; The video interface is used to obtain server host operating system video information, and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; The address protection module is used to verify the first operation type and the first key in the write operation request; And when it is confirmed that the first operation type and the first key meet the first verification condition, send the first response information to the video interface and control the state of the address protection module to be the first state; When the address protection module is in the first state, only the video interface is allowed to perform a write operation on the video information cache unit; The video interface is further configured to convert the video information into video information in a first format based on the first response information, write the video information in the first format into the video information cache unit, and after completing the writing of the video information in the first format, send a first indication signal to the address protection module; The address protection module is further configured to control the state of the address protection module to be the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to perform a read operation on the video information cache unit.

17. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to execute the data processing method according to any one of claims 12-15.

18. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instruction is executed by a processor, the data processing method according to any one of claims 12-15 is implemented.

Citation Information

Patent Citations

  • Illegal boarding and alighting detection method and system based on deep learning and storage medium

    CN111160213A

  • Server control method and device and medium

    CN113852564A

  • Video data processing debugging system and method based on FPGA prototype verification

    CN115617593A

  • Screen combination conference video processing method and device, electronic equipment and readable medium

    CN116074468A

  • Method and device for reading and writing data and security chip

    CN117216813A