Server management control chip, data processing method, server and storage medium
By introducing an address protection module into the server management control chip to verify the writing and reading of video information, the problem of malicious modification of video information in the server operating system is solved, ensuring the accuracy of remote management and system security.
Patent Information
- Application Number
- CN202510740184.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-06-05
AI Technical Summary
The real-time video information of the server operating system is at risk of being maliciously modified by software during and after the process of writing it into the memory of the server management and control chip. This could result in the video interface seen by remote users not being the actual operating system interface, affecting the management and control of the server by remote users, and even causing misoperation and endangering system security.
An original video space security control module, including an address protection module, is introduced into the server management control chip. By verifying write operation requests and controlling the state of the address protection module after successful verification, the write and read operations of video information are allowed or prohibited, ensuring that the video information in the cache unit is not maliciously modified.
It effectively prevents malicious modification of video information in the cache unit, ensures that the operating system video interface seen by remote users is real, avoids accidental operation and system security risks, and improves the reliability of remote management.
Smart Images

Figure CN120264008B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of server technology, and in particular to a server management control chip, a data processing method, a server, and a storage medium. Background Technology
[0002] The server management and control chip, acting as the server's control chip, is used to compress and transmit real-time video information from the server's operating system over a network to a remote location, allowing remote users to view and manage the server's operating system in real time. Currently, there is a risk that the real-time video information of the server's operating system can be maliciously modified by software during and after being written to the server management and control chip's memory. This could result in the remote user seeing a video interface that is not the actual operating system interface, thus affecting the remote user's management and control of the server, and in severe cases, even causing erroneous operations and compromising server system security. Summary of the Invention
[0003] In view of this, embodiments of this application provide a server management control chip, a data processing method, a server, and a storage medium.
[0004] According to a first aspect of this application, embodiments of this application provide a server management control chip, including a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module connected in sequence, and further including:
[0005] Original video space security control module; the original video space security control module includes an address protection module;
[0006] The video interface is used to obtain video information from the server's operating system and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key;
[0007] The address protection module is used to verify the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification conditions, it sends a first response message to the video interface and controls the state of the address protection module to the first state; when the address protection module is in the first state, it only allows the video interface to perform write operations on the video information cache unit;
[0008] The video interface is also used to convert video information into video information in a first format based on the first response information, write the video information in the first format into the video information buffer unit, and send a first indication signal to the address protection module after completing the writing of the video information in the first format.
[0009] The address protection module is also used to control the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information buffer unit.
[0010] Optionally, the original video space security control module also includes a memory self-test module;
[0011] The memory self-test module is used to control the video interface to generate test information according to a preset cycle and write the test information into the video information cache unit;
[0012] The memory self-test module is also used to read data from the video information cache unit according to a preset period, and to generate the first alarm message when a write attack is confirmed to have occurred in the video information cache unit based on the data and test information.
[0013] Optionally, the original video space security control module also includes a read management module;
[0014] The read management module is used to monitor the status of the address protection module, and when it determines that the status of the address protection module is the second status, it sends a second indication signal to the video capture module.
[0015] The video capture module is used to send a read operation request to the address protection module based on the second indication signal;
[0016] The address protection module is also used to verify the second operation type and the second key in the read operation request; and to send a second response message to the video capture module when it is confirmed that the second operation type and the second key meet the second verification conditions.
[0017] The video capture module is also used to read video information in a first format from the video information buffer unit based on the second response information.
[0018] Optionally, the original video space security control module also includes a first alarm management module;
[0019] The first alarm management module is used to acquire alarm information generated by the address protection module, memory self-test module and read management module, send the alarm information to the central processing unit of the server management control chip, and receive the first processing result information fed back by the central processing unit based on the alarm information. The first processing result information is then fed back to the address protection module, memory self-test module and read management module so that the processing flow in the address protection module, memory self-test module and read management module can continue.
[0020] Optionally, the server management control chip also includes a compression process security control module, which includes a local information table cache module, a remote information table cache module, and an information table verification module.
[0021] The local cache module for the information table is used to cache the first configuration information when the core compression module compresses video information in the first format; the first configuration information is obtained by the compression configuration module.
[0022] The remote information table cache module is used to initiate a read configuration information request to the remote end according to the second preset time period, and read the second configuration information sent by the remote end to the configuration information cache unit based on the read configuration information request from the configuration information cache unit;
[0023] The information table verification module is used to obtain the first configuration information in the local information table cache module and the second configuration information in the remote information table cache module; and when it is determined, based on the first configuration information and the second configuration information, that the first configuration information has not been illegally modified when compressing the video information of the first format, it sends a third indication signal to the core compression module. The third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified.
[0024] Optionally, the compression process safety control module also includes a configuration update verification module;
[0025] The configuration update verification module is used to monitor the first change information of the first configuration information in the local cache module of the information table, and when it is determined that the first configuration information has changed based on the first change information, it sends a first confirmation request to the central processing unit of the server management control chip and receives the first confirmation result information fed back by the central processing unit based on the first confirmation request, and generates a second alarm information when it is determined that the change of the first configuration information does not meet the requirements based on the first confirmation result information.
[0026] Optionally, the compression process safety control module also includes a second alarm management module;
[0027] The second alarm management module is used to obtain alarm information generated by the information table verification module and the configuration update verification module, and send the alarm information to the central processing unit of the server management control chip. It also receives the second processing result information fed back by the central processing unit based on the alarm information, and feeds back the second processing result information to the information table verification module and the configuration update verification module so that the processing flow in the information table verification module and the configuration update verification module can continue.
[0028] Optionally, the server management control chip also includes a compressed video security control module; the compressed video security control module includes an address management module;
[0029] The address management module is used to obtain the write address corresponding to the write operation of the compressed video write control module when writing compressed video information, and to obtain the read address when the network driver reads compressed video information; and when it is confirmed that the write address and the read address are the same, it sends a fourth indication signal to the compressed video write control module, the fourth indication signal indicating that the write address has not been illegally modified.
[0030] Optionally, the compressed video security control module also includes an information update control module;
[0031] The information update control module is used to monitor the second change information of the write address corresponding to the write operation of the compressed video information by the compressed video write control module, and when the write address change is determined based on the second change information, it sends a second confirmation request to the central processing unit of the server management control chip and receives the second confirmation result information fed back by the central processing unit based on the second confirmation request, and generates a third alarm information when the change of the write address is determined based on the second confirmation result information.
[0032] Optionally, the compressed video security control module also includes a third alarm management module;
[0033] The third alarm module is used to acquire alarm information from the address management module and the information update control module, send the alarm information to the central processing unit of the server management control chip, receive the third processing result information fed back by the central processing unit based on the alarm information, and feed back the third processing result information to the address management module and the information update control module so that the processing flow in the address management module and the information update control module can continue.
[0034] Optionally, the address management module is also used to obtain the write request sent by the server hardware status management software driver, verify the third operation type and the third key in the write request; and, if it is confirmed that the third operation type and the third key meet the third verification conditions, send the third response information to the server hardware status management software driver and control the state of the address management module to the first state; when the address management module is in the first state, only the server hardware status management software driver is allowed to perform write operations on the hardware status information cache unit.
[0035] The address management module is also used to obtain the fifth indication signal sent by the server hardware status management software driver. The address management module is also used to control the state of the address management module to the second state based on the fifth indication signal. When the address management module is in the second state, only the network driver is allowed to read the hardware status information cache unit.
[0036] The address management module is also used to obtain the read request sent by the network driver, verify the fourth operation type and the fourth key in the read request; and, if it is confirmed that the fourth operation type and the fourth key meet the fourth verification conditions, send the fourth response information to the network driver, the fourth response information indicating that the network driver is allowed to read data from the hardware status information cache unit.
[0037] According to a second aspect of this application, embodiments of this application provide a data processing method applied to a server management control chip. The server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video writing control module connected in sequence, and also includes an original video space security control module; the original video space security control module includes an address protection module; the method includes:
[0038] The video interface obtains video information from the server operating system and sends a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key.
[0039] The address protection module verifies the first operation type and the first key in the write operation request; and when it confirms that the first operation type and the first key meet the first verification conditions, it sends a first response message to the video interface and controls the state of the address protection module to the first state; when the address protection module is in the first state, it only allows the video interface to perform write operations on the video information buffer unit;
[0040] The video interface converts the video information into video information in a first format based on the first response information, writes the video information in the first format into the video information buffer unit, and sends a first indication signal to the address protection module after completing the writing of the video information in the first format.
[0041] The address protection module controls the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information buffer unit.
[0042] Optionally, the server management control chip also includes a compression process security control module, which includes a local information table cache module, a remote information table cache module, and an information table verification module; the method further includes:
[0043] The remote information table cache module initiates a read configuration information request to the remote end according to the second preset time period, and reads the second configuration information sent by the remote end to the configuration information cache unit based on the read configuration information request from the configuration information cache unit;
[0044] The information table verification module obtains the first configuration information cached in the local information table cache module and the second configuration information from the remote information table cache module; and when it determines, based on the first and second configuration information, that the first configuration information has not been illegally modified when compressing the video information of the first format, it sends a third indication signal to the core compression module. The third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified; the first configuration information is obtained by the compression configuration module.
[0045] Based on the third indication signal and the first configuration information, the core compression module compresses the first format video information sent by the video capture module to the core compression module through the compression configuration module to obtain compressed video information.
[0046] Optionally, the server management control chip further includes a compressed video security control module; the compressed video security control module includes an address management module; the method further includes:
[0047] The address management module obtains the write address corresponding to the write operation of the compressed video write control module on the compressed video information, and obtains the read address when the network driver reads the compressed video information; and when it confirms that the write address and the read address are the same, it sends a fourth indication signal to the compressed video write control module, the fourth indication signal indicating that the write address has not been illegally modified;
[0048] Based on the fourth indication signal, the compressed video security control module sends the compressed video information from the core compression module to the compressed video security control module and writes it to the write address.
[0049] Optionally, the method further includes:
[0050] The address management module receives a write request from the server hardware status management software driver, verifies the third operation type and third key in the write request, and, if it confirms that the third operation type and third key meet the third verification conditions, sends a third response message to the server hardware status management software driver and controls the address management module to the first state; when the address management module is in the first state, it only allows the server hardware status management software driver to perform write operations on the hardware status information cache unit.
[0051] The address management module receives the fifth indication signal sent by the server hardware status management software driver, and controls the address management module to the second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to read the hardware status information cache unit;
[0052] The address management module receives a read request sent by the network driver, verifies the fourth operation type and the fourth key in the read request, and sends a fourth response message to the network driver if it confirms that the fourth operation type and the fourth key meet the fourth verification conditions. The fourth response message indicates that the network driver is allowed to read data from the hardware status information cache unit.
[0053] According to a third aspect of this application, embodiments of this application provide a server, including:
[0054] Server host;
[0055] The server management and control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module connected in sequence. It also includes an original video space security control module, which includes an address protection module.
[0056] The video interface is used to obtain video information from the server host operating system and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key;
[0057] The address protection module is used to verify the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification conditions, it sends a first response information to the video interface and controls the state of the address protection module to the first state; when the address protection module is in the first state, it only allows the video interface to perform write operations on the video information cache unit;
[0058] The video interface is also used to convert video information into video information in a first format based on the first response information, write the video information in the first format into the video information buffer unit, and send a first indication signal to the address protection module after completing the writing of the video information in the first format.
[0059] The address protection module is also used to control the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information buffer unit.
[0060] According to a fourth aspect of this application, embodiments of this application provide a computer-readable storage medium storing computer instructions for causing a computer to perform a data processing method as described in the second aspect or any embodiment of the second aspect.
[0061] According to a fifth aspect of this application, an embodiment of this application provides a computer program product, including a computer program or instructions, which, when executed by a processor, implement the data processing method of the second aspect or any embodiment of the second aspect.
[0062] The server management control chip, data processing method, server, storage medium, and computer program product provided in this application embodiment add an original video space security control module to the original hardware module of the server management control chip. The original video space security control module includes an address protection module. A video interface is used to obtain video information from the server operating system and send a write operation request to the address protection module based on the video information. The write operation request includes a first operation type and a first key. The address protection module is used to verify the first operation type and the first key in the write operation request. And, if it confirms that the first operation type and the first key meet the first verification condition, it sends a first response information to the video interface and controls the address protection module to a first state. In the first state, the address protection module only allows the video interface to perform write operations on the video information cache unit. The video interface is also used to transfer the video information based on the first response information. The video information is converted to a first format and written to the video information cache unit. After writing the first format video information, a first indication signal is sent to the address protection module. The address protection module is also used to control the state of the address protection module to a second state based on the first indication signal. In the second state, the address protection module only allows the video interface and video capture module to read the video information cache unit. In this way, during and after the process of writing the video information of the server operating system to the video information cache unit through the interface module, the video information cache unit will not be maliciously modified by software running on the central processing unit. This will prevent the operating system video interface seen by the remote user from being a fake operating system interface and will not affect the remote user's management and control of the server. Furthermore, by verifying the write operation request sent by the video interface, it can be ensured that the video interface has not been maliciously hijacked by software.
[0063] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0064] Figure 1 This is a schematic diagram of the current server management and control chip structure;
[0065] Figure 2 This is a schematic diagram of the server management control chip in an embodiment of this application;
[0066] Figure 3 This is a schematic diagram of the original video space security control module in the embodiments of this application;
[0067] Figure 4 This is a schematic diagram of the state adjustment process of the state machine in the embodiments of this application;
[0068] Figure 5 This is a schematic diagram of the structure of another server management control chip in an embodiment of this application;
[0069] Figure 6 This is a schematic diagram of the structure of the compression process safety control module in the embodiments of this application;
[0070] Figure 7 This is a schematic diagram of the compressed video security control module in an embodiment of this application;
[0071] Figure 8 This is a flowchart illustrating a data processing method according to an embodiment of this application;
[0072] Figure 9 This is a schematic diagram of the hardware structure of a server according to an embodiment of this application. Detailed Implementation
[0073] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0074] Current server management and control chips such as Figure 1 As shown, it includes a video interface (VGA), a video capture module, a compression configuration module, a core compression module, and a compressed video write control module connected in sequence; it also includes a network driver (Ethernet module), a memory module (DDR), a system bus, and a central processing unit (CPU); the memory module includes a video information cache unit A, a compressed video information cache unit B, a hardware status information cache unit D, and a target cache unit C corresponding to the network driver reading video information and hardware status information.
[0075] The current processing flow of the server management control chip is as follows: 1. Video information from the server host operating system (real-time interface information) is transmitted to the VGA inside the server management control chip. The VGA generates video information in a first format, such as RGB format. During the generation of RGB format video information, the VGA needs to interact with the A area in the external DDR. 2. The video capture module obtains video information in two ways: passively receiving the output from the VGA and actively reading from the A area and performing corresponding format processing, such as color space conversion, to convert the RGB format video information to YUV format video information. 3. The compression configuration module configures the compression registers, with the most important configurations being video resolution, luminance table, and chrominance table. 4. The core compression module receives the YUV format video information and performs corresponding format and configuration video compression according to the register function configuration of the compression configuration module to obtain compressed video information. Common video compression formats include H.264 and JPEG. 5. The compressed video write control module receives the compressed video information and writes it to the B area in the external DDR. 6. The server management control chip's hardware interface obtains server hardware status information (such as CPU temperature, motherboard voltage, fan speed, etc.), and after processing by the corresponding functional software, writes the hardware status information into the D area of the DDR. 7. The network driver reads the compressed video information and hardware status information cached in the B and D areas of the DDR and moves them to the C area of the DDR, then sends the compressed video information and hardware status information to the remote end via the network. Thus, the remote end software parses the network data packets, receives the compressed video information, decompresses the compressed video information, and then displays it on the server operating system interface; the remote end software also parses the network data packets, receives the server's hardware status information, and displays it.
[0076] However, the real-time video information of the server operating system is at risk of being maliciously modified by software during and after the process of writing it into area A of the server management and control chip. As a result, the video interface seen by the remote user is not the real operating system interface, which affects the remote user's management and control of the server. In severe cases, it may even cause misoperation and affect the server's system security.
[0077] Therefore, embodiments of this application provide a server management control chip, such as... Figure 2 As shown, it includes a video interface (VGA), a video capture module, a compression configuration module, a core compression module, and a compressed video write control module connected in sequence, as well as an original video space security control module; the original video space security control module includes an address protection module.
[0078] The video interface is used to obtain video information from the server operating system and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key.
[0079] The address protection module is used to verify the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification conditions, it sends the first response information to the video interface and controls the state of the address protection module to the first state; when the address protection module is in the first state, it only allows the video interface to perform write operations on the video information cache unit.
[0080] The video interface is also used to convert video information into video information in a first format based on the first response information, write the video information in the first format into the video information buffer unit, and send a first indication signal to the address protection module after completing the writing of the video information in the first format.
[0081] The address protection module is also used to control the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information buffer unit.
[0082] In this embodiment, as Figure 2 As shown, the management and control chip may also include a network driver (Ethernet module), a memory module (DDR), a system bus, and a central processing unit (CPU); the memory module includes a video information cache unit A, a compressed video information cache unit B, a hardware status information cache unit D, and a target cache unit C corresponding to the network driver reading video information and hardware status information.
[0083] In this embodiment, the video information (real-time interface information of the operating system) of the server host operating system is transmitted to the video interface (VGA) inside the server management and control chip. The video interface obtains the server operating system video information and sends a write operation request to the address protection module based on this information. The write operation request includes a first operation type and a first key. The first operation type is a write operation, which can be agreed upon as 01. The generation of the first key can be handled by the address protection module, based on a key generation algorithm agreed upon with the VGA.
[0084] In this embodiment, the address protection module can verify the first operation type and the first key in the write operation request; and if it confirms that the first operation type and the first key meet the first verification condition, it sends a first response message to the video interface and controls the state of the address protection module to a first state; in the first state, the address protection module only allows the video interface to perform write operations on the video information cache unit. If it confirms that the first operation type and the first key do not meet the first verification condition, an alarm signal error_wr_request=1 can be generated.
[0085] In this embodiment, the video interface converts the video information into video information in a first format, such as RGB format, based on the first response information, and writes the video information in the first format into the video information buffer unit. After completing the writing of the video information in the first format, it sends a first indication signal to the address protection module. The first indication signal indicates that the video interface has completed writing the video information in the first format.
[0086] In some implementations, during the writing of video information in the first format by the video interface, if the address protection module detects a write or read request to the video information buffer unit from the system bus (other than the video interface), it indicates that malicious software is attempting to write to or read the video information buffer unit. At this point, the address protection module returns to the third state and generates an alarm signal `attempt_wr_rd=1`. In the third state, the address protection module prohibits read and write operations on the video information buffer unit.
[0087] The address protection module controls the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information buffer unit.
[0088] In one implementation, after the VGA sends a first indication signal to the address protection module, it can send a first read operation request to the address protection module. The first read operation request includes a fifth operation type and a fifth key. The fifth operation type is a read operation, and it can be agreed that the fifth operation type = 10. The generation of the fifth key is the responsibility of the address protection module, which generates it according to the key generation algorithm agreed upon with the VGA. Furthermore, the key generation algorithms used for write operations and read operations are different, resulting in different keys.
[0089] After the address protection module verifies the fifth operation type and the fifth key, it sends a fifth response message to the VGA, indicating that the VGA is allowed to read the video information buffer unit. If the address protection module fails to verify the fifth operation type and the fifth key, it can generate an alarm signal error_rd_request=2.
[0090] Based on the fifth response information, the VGA reads the first format video information from the video information buffer unit and sends it to the video capture module. During the process of the VGA reading the first format video information, the address protection module detects that, in addition to the VGA, there are write or read requests on the system bus to access the video information buffer unit. This indicates that malicious software is attempting to write or read the video information buffer unit. At this time, the address protection module should return to the third state and generate an alarm signal attempt_wr_rd=2.
[0091] In another implementation, such as Figure 3 As shown, the original video space security control module also includes a read management module.
[0092] The read management module is used to monitor the status of the address protection module, and when it determines that the status of the address protection module is the second state, it sends a second indication signal to the video capture module.
[0093] The video capture module is used to send a read operation request to the address protection module based on the second indication signal.
[0094] The address protection module is also used to verify the second operation type and the second key in the read operation request; and to send a second response message to the video capture module when it is confirmed that the second operation type and the second key meet the second verification conditions.
[0095] The video capture module is also used to read video information in a first format from the video information buffer unit based on the second response information.
[0096] In this embodiment, the second indication signal indicates that the video capture module can perform a read operation. The read operation request includes a second operation type and a second key. The second operation type is a read operation, and it can be agreed that operation type = 11. The generation of the second key is the responsibility of the address protection module, which generates it according to the key generation algorithm agreed upon with the video capture module.
[0097] In some implementations, the read management module is also used to detect that the address protection module is in a non-CAN_RD state and the video capture module initiates a read operation request. If this is the case, it is determined that the video capture module has been hijacked by malicious software, and an alarm signal attempt_wr_rd=4 should be output.
[0098] In some implementations, after acquiring video information in the first format, the video capture module can perform corresponding format processing, such as color space conversion, to convert the RGB format video information into the YUV format video information.
[0099] In some implementations, such as Figure 3As shown, the original video space security control module also includes a memory self-test module.
[0100] The memory self-test module is used to control the video interface to generate test information according to a preset period and write the test information to the video information cache unit; the memory self-test module is also used to read the data in the video information cache unit according to a preset period, and generate the first alarm information when it is confirmed that a write attack has occurred in the video information cache unit based on the data and test information.
[0101] In this embodiment, the memory self-test module enhances the address protection module's functionality, preventing overall security management anomalies caused by the address protection module's failure. The memory self-test module is enabled periodically, once at an agreed interval T. When enabled, the VGA generates test information, such as a test image, which is written to the video information buffer unit. This information is then read and verified by the module. If the read data differs from the written test image data, it indicates that malware has performed a write attack on the video information buffer unit, generating an alarm signal `attempt_wr_rd=3`, i.e., the first alarm message. Simultaneously, the test image must change continuously; that is, the test image must be different in consecutive memory self-tests to prevent malware from obtaining the test image and affecting the normal functioning of the memory self-test module.
[0102] In some implementations, such as Figure 3 As shown, the original video space security control module also includes a first alarm management module. The first alarm management module is also known as alarm management module 1.
[0103] The first alarm management module is used to acquire alarm information generated by the address protection module, memory self-test module and read management module, send the alarm information to the central processing unit of the server management control chip, and receive the first processing result information fed back by the central processing unit based on the alarm information. The first processing result information is then fed back to the address protection module, memory self-test module and read management module so that the processing flow in the address protection module, memory self-test module and read management module can continue.
[0104] In this embodiment, the function of the first alarm management module is to collect alarm signals attempt_wr_rd (=1, 2, 3, 4) and error_wr_request (=1, 2) output by the address protection module, memory self-test module, and read management module, and report them to the CPU. The CPU adds a software driver corresponding to the security management and control function, receives the interrupts corresponding to the above alarm signals, processes them, and notifies the first alarm management module after processing. At the same time, the first alarm management module feeds back the processing results of the software to the address protection module, memory self-test module, and read management module so that the internal processing flow of these modules can continue.
[0105] In this embodiment, the first alarm management module can ensure that when a malicious software attack is received, it can be handled immediately. After the attack is completed, the normal function of the server management control chip can be restored as soon as possible, thus improving the efficiency of anomaly handling.
[0106] In some implementations, a state machine can be set in the address protection module, including three states: FREEZE, CAN_WR, and CAN_RD. The state of the state machine is also the state of the address protection module. The default state of the state machine is FREEZE, in which any read or write operation to the video information buffer unit is prohibited. In the CAN_WR state, only the VGA is allowed to write to the video information buffer unit, and other modules are prohibited from writing to this space. In the CAN_RD state, only the VGA and the subsequent video capture module are allowed to read from the video information buffer unit. The first state is CAN_WR, the second state is CAN_WR, and the third state is FREEZE. A flowchart illustrating the state machine state adjustment process is shown below. Figure 4 As shown.
[0107] State transition 1: The state transitions from FREEZE to CAN_WR. This state occurs when the VGA initiates a write request to the address protection module, or when the CPU completes the processing of an abnormal alarm reported by the first alarm management module. Based on the corresponding alarm type, the CPU then sends an indication signal to the address protection module, and the address protection module's state machine restarts its transition.
[0108] State transition 2: Transition from CAN_WR state to FREEZE state. This state occurs when, during the VGA write process, the address protection module detects a write or read request from the system bus other than the VGA to access the video information buffer unit, indicating that malware is attempting to write or read the original video space. In this case, the state machine must immediately return to the FREEZE state and send an indication signal attempt_wr_rd=1 to the first alarm management module. Alternatively, if the first type or first key of the write operation request sent by the VGA is different from the agreed one, the state machine must also return to the FREEZE state and send an indication signal error_wr_request=1 to the alarm management module 1.
[0109] State transition 3: Transition from CAN_WR state to CAN_RD state. This state occurs when the VGA has completed writing one frame. After writing is complete, the VGA sends a completion indication signal to the address protection module.
[0110] State transition 4: Transition from CAN_RD state to CAN_WR state. This state occurs when the VGA has completed reading 1 frame. After reading, the VGA sends a completion indication signal to the address protection module and initiates a write operation request to the address protection module.
[0111] State transition 5: Transition from CAN_RD state to FREEZE state. This state occurs when, during VGA reading, the address protection module detects a write or read request from the system bus other than VGA to access the video information buffer unit, indicating that malware is attempting to write or read the video information buffer unit. In this case, the state machine must immediately return to the FREEZE state and send an indication signal attempt_wr_rd=2 to the first alarm management module. Alternatively, if the fifth type or fifth key of the read request sent by VGA is different from the agreed one, the state machine must also return to the FREEZE state and send an indication signal error_rd_request=2 to the first alarm management module.
[0112] State transition 6: The state transitions from FREEZE to CAN_RD. This state occurs when the abnormal alarm reported by the first alarm management module to the CPU has been processed. Based on the corresponding alarm type, the CPU sends an indication signal to the address protection module, and the state machine of the address protection module restarts the transition.
[0113] In this embodiment, the compression configuration module receives the YUV format video information sent by the video capture module and performs register function configuration. The most important configurations are video resolution, luminance table, and chrominance table. The core compression module receives the YUV format video information and performs corresponding format and configuration video compression according to the register function configuration of the compression configuration module to obtain compressed video information. Common video compression formats include H.264 and JPEG. The compressed video write control module receives the compressed video information and writes it to area B in the external DDR. The network driver reads the compressed video information cached in area B of the DDR and moves it to area C of the DDR, and then sends the compressed video information to the remote end via the network. Thus, the remote end software parses the network data packets, receives the compressed video information, decompresses the compressed video information, and then displays it on the server operating system interface.
[0114] The server management control chip provided in this application embodiment adds an original video space security control module to the original hardware module of the server management control chip. The original video space security control module includes an address protection module. The video interface is used to obtain video information from the server operating system and send a write operation request to the address protection module based on the video information. The write operation request includes a first operation type and a first key. The address protection module is used to verify the first operation type and the first key in the write operation request. And when it is confirmed that the first operation type and the first key meet the first verification condition, it sends a first response information to the video interface and controls the state of the address protection module to a first state. When the address protection module is in the first state, it only allows the video interface to perform write operations on the video information cache unit. The video interface is also used to convert the video information into video information of a first format based on the first response information. The system writes video information in the first format into the video information cache unit, and after completing the writing of the video information in the first format, sends a first indication signal to the address protection module. The address protection module is also used to control the state of the address protection module to a second state based on the first indication signal. In the second state, the address protection module only allows the video interface and the video capture module to read the video information cache unit. In this way, during and after the process of writing the video information of the server operating system into the video information cache unit through the interface module, the video information cache unit will not be maliciously modified by software running on the central processing unit, so that the operating system video interface seen by the remote user will not be a real operating system interface, and will not affect the remote user's management and control of the server. Furthermore, by verifying the write operation request sent by the video interface, it can be ensured that the video interface has not been maliciously hijacked by software.
[0115] In an optional embodiment, such as Figure 5As shown, the server management control chip also includes a compression process security control module, which includes a local information table cache module, a remote information table cache module, and an information table verification module.
[0116] The local cache module of the information table is used to cache the first configuration information when the core compression module compresses video information of the first format; the first configuration information is obtained by the compression configuration module.
[0117] The remote information table caching module is used to initiate a read configuration information request to the remote end according to the second preset time period, and read the second configuration information sent by the remote end to the configuration information caching unit based on the read configuration information request from the configuration information caching unit.
[0118] The information table verification module is used to obtain the first configuration information in the local information table cache module and the second configuration information in the remote information table cache module; and when it is determined, based on the first configuration information and the second configuration information, that the first configuration information has not been illegally modified when compressing the video information of the first format, it sends a third indication signal to the core compression module. The third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified.
[0119] In this embodiment, the first configuration information includes the luminance table and chrominance table used for compressing video information in the first format. Because the luminance table and chrominance table are accessible through registers, malicious software could illegally obtain the register addresses of these two critical configuration tables, thereby illegally modifying their content and damaging the compressed video information. To ensure that the video information in the first format can be compressed correctly, it is necessary to verify whether the first configuration information has been illegally modified.
[0120] In this embodiment, before formally compressing the video information in the first format, the second configuration information used for compression, such as the contents of the chromaticity table and luminance table, is written into the DDR and then sent to the remote end by the Ethernet module for temporary storage. When the compression process security control module initiates a request to read the configuration information from the remote end via the network, the software on the remote end sends the second configuration information cached on the remote end to the DDR of the server management control chip, and then the compression process security control module reads it back to the remote information table cache module. It is worth noting that the remote information table cache module sends a request to read the configuration information from the remote end at intervals of T1. T1 can use a default value or be configured by the software.
[0121] In this embodiment, because the second configuration information sent from the remote end is cached in the remote end's information table, malicious software cannot illegally modify it. Therefore, if the verification module finds that the contents of the local information table cache module and the remote information table cache module are inconsistent, it determines that the malicious software has illegally modified the local first configuration information. If the luminance table is illegally modified, an alarm signal error_mdy_compress_config=1 is generated; if the chrominance table is illegally modified, an alarm signal error_mdy_compress_config=2 is generated.
[0122] In this embodiment, if it is determined that the local first configuration information has not been illegally modified, a third indication signal is sent to the core compression module, causing the core compression module to respond to the third indication signal and perform compression operation to obtain compressed video information.
[0123] In some implementations, such as Figure 6 As shown, the compression process security control module also includes a configuration update verification module; the configuration update verification module is used to monitor the first change information of the first configuration information in the local cache module of the information table, and when it is determined that the first configuration information has changed based on the first change information, it sends a first confirmation request to the central processing unit of the server management control chip, and receives the first confirmation result information fed back by the central processing unit based on the first confirmation request, and generates a second alarm information when it is determined that the change of the first configuration information does not meet the requirements based on the first confirmation result information.
[0124] In this embodiment, the second alarm message can be error_mdy_compress_config=3.
[0125] In some implementations, such as Figure 6 As shown, the compression process safety control module also includes a second alarm management module; that is, alarm management module 2. The second alarm management module is used to obtain alarm information generated by the information table verification module and the configuration update verification module, and send the alarm information to the central processing unit of the server management control chip. It also receives the second processing result information fed back by the central processing unit based on the alarm information, and feeds back the second processing result information to the information table verification module and the configuration update verification module so that the processing flow in the information table verification module and the configuration update verification module can continue.
[0126] In this embodiment, a compression process security control module is further configured, which includes a local information table cache module, a remote information table cache module, and an information table verification module. This ensures that the content within the video information cache module is not maliciously modified by the software, and also ensures that the content of the luminance and chrominance tables used during video information compression is not maliciously modified by the software, thus achieving normal compression of video information. This allows remote users to stably and accurately obtain video footage from the local server's operating system interface.
[0127] In an optional embodiment, such as Figure 5 As shown, the server management control chip also includes a compressed video security control module; the compressed video security control module includes an address management module; the address management module is used to obtain the write address corresponding to the compressed video write control module's write operation on compressed video information, and to obtain the read address when the network driver reads compressed video information; and when it is confirmed that the write address and the read address are the same, it sends a fourth indication signal to the compressed video write control module, the fourth indication signal indicating that the write address has not been illegally modified.
[0128] In this embodiment, the read address when the network driver reads compressed video information is the read address of the compressed video information cached in DDR that the network driver initiates a DMA operation to read. A DMA operation refers to first moving the compressed video information from region B to region C, then having the network driver initiate a descriptor operation to read it from region C, and finally sending it to the remote end via the network. Because the read address used in the DMA operation is configured at the software level, it cannot be modified by malicious software. However, the write address corresponding to the compressed video information write operation can be modified through the system bus, and there is a possibility that it can be illegally modified by malicious software. If the verification result is consistent, a fourth indication signal is sent to the compressed video write control module, causing the compressed video write control module to write the compressed video information to region B of DDR. If the verification result is inconsistent, it indicates that the write address has been illegally modified by malicious software, and an alarm signal error_mdy_compress_data_addr=1 is generated.
[0129] In some implementations, the address management module can ensure that the server's hardware status information is not modified by malware during the process of writing it into memory and after it is written, and during the transmission to the remote end.
[0130] Specifically, the address management module is used to obtain the write request sent by the server hardware status management software driver, verify the third operation type and the third key in the write request; and, if it is confirmed that the third operation type and the third key meet the third verification conditions, send the third response information to the server hardware status management software driver and control the state of the address management module to the first state; when the address management module is in the first state, only the server hardware status management software driver is allowed to perform write operations on the hardware status information cache unit.
[0131] The address management module is also used to obtain the fifth indication signal sent by the server hardware status management software driver. The address management module is also used to control the state of the address management module to the second state based on the fifth indication signal. When the address management module is in the second state, only the network driver is allowed to read the hardware status information cache unit.
[0132] The address management module is also used to obtain the read request sent by the network driver, verify the fourth operation type and the fourth key in the read request; and, if it is confirmed that the fourth operation type and the fourth key meet the fourth verification conditions, send the fourth response information to the network driver, the fourth response information indicating that the network driver is allowed to read data from the hardware status information cache unit.
[0133] In this embodiment, the specific implementation of the address management module is similar to that of the address protection module, and will not be repeated here. The differences are: 1. The address management module allows writing to the server hardware status management software driver, not the VGA. 2. The address management module allows reading from the network driver, not the VGA and video capture modules. 3. The "operation type + key" and the parsing mechanism used are different.
[0134] In some implementations, such as Figure 7 As shown, the compressed video security control module also includes an information update control module; the information update control module is used to monitor the second change information of the write address corresponding to the write operation of the compressed video write control module on the compressed video information, and when the write address change is determined based on the second change information, to send a second confirmation request to the central processing unit of the server management control chip, and to receive the second confirmation result information fed back by the central processing unit based on the second confirmation request, and to generate a third alarm information when the change of the write address is determined based on the second confirmation result information to be inconsistent with the requirements.
[0135] In some implementations, such as Figure 7As shown, the compressed video security control module also includes a third alarm management module; namely, alarm management module 3. The third alarm module is used to obtain alarm information from the address management module and the information update control module, and send the alarm information to the central processing unit of the server management control chip. It also receives the third processing result information fed back by the central processing unit based on the alarm information, and feeds back the third processing result information to the address management module and the information update control module so that the processing flow within the address management module and the information update control module can continue.
[0136] In this embodiment, secure management and control of the video information caching unit of the server management and control chip are implemented to ensure that the content of the video information caching unit is not maliciously modified by software. At the same time, secure management and control of the video compression process are implemented to ensure that the content of the luminance and chrominance tables used in the compression process is not maliciously modified by software, and to achieve normal compression of video information. On the compressed video information output side, a secure management mechanism for the compressed video information storage space is implemented to ensure that the network driver can read the compressed video information normally and stably, thereby ensuring that remote users can stably and realistically obtain the video screen of the local server operating system interface.
[0137] This application provides a data processing method applied to a server management control chip. The server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module connected in sequence, and also includes an original video space security control module; the original video space security control module includes an address protection module; as shown below. Figure 8 As shown, the method includes:
[0138] S801, the video interface obtains the server operating system video information, and sends a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key.
[0139] S802, the address protection module verifies the first operation type and the first key in the write operation request; and when it is confirmed that the first operation type and the first key meet the first verification conditions, it sends a first response information to the video interface and controls the state of the address protection module to the first state; when the address protection module is in the first state, it only allows the video interface to perform write operations on the video information cache unit.
[0140] S803, the video interface converts the video information into video information in a first format based on the first response information, writes the video information in the first format into the video information buffer unit, and sends a first indication signal to the address protection module after completing the writing of the video information in the first format.
[0141] S804, the address protection module controls the state of the address protection module to the second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information buffer unit.
[0142] In this embodiment, the specific implementation method is detailed in the description of the server management control chip in the above embodiment, and will not be repeated here.
[0143] In some embodiments, the server management control chip further includes a compression process security control module, which includes a local information table cache module, a remote information table cache module, and an information table verification module; the method further includes:
[0144] The remote information table caching module initiates a read configuration information request to the remote end according to the second preset time period, and reads the second configuration information sent by the remote end to the configuration information caching unit based on the read configuration information request from the configuration information caching unit; the information table verification module obtains the first configuration information cached in the local information table caching module and the second configuration information in the remote information table caching module; and when it is determined, based on the first configuration information and the second configuration information, that the first configuration information for compressing the first format video information has not been illegally modified, it sends a third indication signal to the core compression module. The third indication signal indicates that the first configuration information configured by the compression configuration module has not been illegally modified; the first configuration information is configured by the compression configuration module; the core compression module compresses the first format video information sent by the video capture module to the core compression module through the compression configuration module based on the third indication signal and the first configuration information to obtain compressed video information.
[0145] In some embodiments, the server management control chip further includes a compressed video security control module; the compressed video security control module includes an address management module; the method further includes:
[0146] The address management module obtains the write address corresponding to the write operation of the compressed video write control module on the compressed video information, and obtains the read address when the network driver reads the compressed video information; and when it confirms that the write address and the read address are the same, it sends a fourth indication signal to the compressed video write control module, the fourth indication signal indicating that the write address has not been illegally modified; based on the fourth indication signal, the compressed video security control module writes the compressed video information sent by the core compression module to the compressed video security control module to the write address.
[0147] In some embodiments, the method further includes:
[0148] The address management module receives a write request from the server hardware status management software driver, verifies the third operation type and third key in the write request, and, if the third operation type and third key meet the third verification conditions, sends a third response message to the server hardware status management software driver and controls the address management module to the first state. In the first state, the address management module only allows the server hardware status management software driver to perform write operations on the hardware status information cache unit. The address management module receives a fifth indication signal from the server hardware status management software driver, and controls the address management module to the second state based on the fifth indication signal. In the second state, the address management module only allows the network driver to perform read operations on the hardware status information cache unit. The address management module receives a read request from the network driver, verifies the fourth operation type and fourth key in the read request, and, if the fourth operation type and fourth key meet the fourth verification conditions, sends a fourth response message to the network driver, indicating that the network driver is allowed to read data from the hardware status information cache unit.
[0149] According to embodiments of this application, this application also provides a server, such as... Figure 9 As shown, it includes:
[0150] The server host and server management control chip. The server management control chip includes, in sequence, a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module, and also includes an original video space security control module; the original video space security control module includes an address protection module. The video interface is used to obtain video information from the server host operating system and send a write operation request to the address protection module based on the video information. The write operation request includes a first operation type and a first key. The address protection module is used to verify the first operation type and the first key in the write operation request. If the first operation type and the first key meet the first verification conditions, the address protection module sends a first response message to the video interface and controls the state of the address protection module to a first state. In the first state, the address protection module only allows the video interface to perform write operations on the video information buffer unit. The video interface is also used to convert the video information into video information of a first format based on the first response message, write the video information of the first format to the video information buffer unit, and send a first indication signal to the address protection module after completing the writing of the video information of the first format. The address protection module is also used to control the state of the address protection module to a second state based on the first indication signal. In the second state, the address protection module only allows the video interface and the video capture module to perform read operations on the video information buffer unit.
[0151] This application provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the data processing method described in this application.
[0152] This application provides a computer-readable storage medium storing executable instructions, wherein the executable instructions are executed by a processor, causing the processor to execute the data processing method provided in this application.
[0153] In some embodiments, a computer-readable storage medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may be a machine-readable signal medium or a machine-readable storage medium. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of computer-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0154] In some embodiments, executable instructions may take the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.
[0155] As an example, executable instructions may, but do not necessarily, correspond to files in a file system. They may be stored as part of a file that holds other programs or data, for example, in one or more scripts in a Hyper Text Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple collaborating files (e.g., a file that stores one or more modules, subroutines, or code sections).
[0156] As an example, executable instructions can be deployed to execute on a single computing device, or on multiple computing devices located in one location, or on multiple computing devices distributed across multiple locations and interconnected via a communication network.
[0157] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0158] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0159] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.
[0160] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this application can be achieved, and this is not limited herein.
[0161] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "a plurality of" means two or more, unless otherwise explicitly specified.
[0162] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A server management control chip, comprising a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module connected in sequence, characterized in that, Also includes: Original video space security control module, compression process security control module; The original video space security control module includes an address protection module; the compression process security control module includes a local information table cache module, a remote information table cache module, and an information table verification module. The video interface is used to obtain video information from the server operating system and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; The address protection module is used to verify the first operation type and the first key in the write operation request; And upon confirming that the first operation type and the first key meet the first verification conditions, send the first response information to the video interface and control the state of the address protection module to the first state; When the address protection module is in the first state, it only allows the video interface to write to the video information cache unit; The video interface is also used to convert the video information into video information in a first format based on the first response information, write the video information in the first format into the video information cache unit, and send a first indication signal to the address protection module after completing the writing of the video information in the first format. The address protection module is also configured to control the state of the address protection module to a second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information cache unit; The local information table caching module is used to cache the first configuration information when the core compression module compresses the video information of the first format; the first configuration information is configured by the compression configuration module. The remote information table caching module is used to initiate a read configuration information request to the remote end according to a second preset time period, and read the second configuration information sent by the remote end to the configuration information caching unit based on the read configuration information request from the configuration information caching unit; The information table verification module is used to obtain the first configuration information in the local information table cache module and the second configuration information in the remote information table cache module; When the first configuration information for compressing the video information in the first format is determined to be unauthorized based on the first configuration information and the second configuration information, a third indication signal is sent to the core compression module. The third indication signal indicates that the first configuration information configured by the compression configuration module has not been unauthorized.
2. The server management and control chip according to claim 1, characterized in that, The original video space security control module also includes a memory self-test module; The memory self-test module is used to control the video interface to generate test information according to a preset period, and write the test information into the video information cache unit; The memory self-test module is also used to read data in the video information cache unit according to a preset period, and to generate a first alarm message when it is confirmed that a write attack has occurred in the video information cache unit based on the data and the test information.
3. The server management and control chip according to claim 2, characterized in that, The original video space security control module also includes a read management module; The read management module is used to monitor the status of the address protection module, and when it is determined that the status of the address protection module is the second status, it sends a second indication signal to the video capture module. The video capture module is used to send a read operation request to the address protection module based on the second indication signal; The address protection module is also used to verify the second operation type and the second key in the read operation request; and to send a second response message to the video capture module when it is confirmed that the second operation type and the second key meet the second verification conditions. The video capture module is also used to read video information in the first format from the video information cache unit based on the second response information.
4. The server management and control chip according to claim 3, characterized in that, The original video space security control module also includes a first alarm management module; The first alarm management module is used to acquire alarm information generated by the address protection module, the memory self-test module, and the read management module, send the alarm information to the central processing unit of the server management control chip, and receive the first processing result information fed back by the central processing unit based on the alarm information. The first processing result information is then fed back to the address protection module, the memory self-test module, and the read management module so that the processing flow within the address protection module, the memory self-test module, and the read management module can continue.
5. The server management and control chip according to claim 1, characterized in that, The compression process safety control module also includes a configuration update verification module; The configuration update verification module is used to monitor the first change information of the first configuration information in the local cache module of the information table, and when it is determined that the first configuration information has changed based on the first change information, it sends a first confirmation request to the central processing unit of the server management control chip and receives the first confirmation result information fed back by the central processing unit based on the first confirmation request, and generates a second alarm information when it is determined that the change of the first configuration information does not meet the requirements based on the first confirmation result information.
6. The server management and control chip according to claim 5, characterized in that, The compression process safety control module also includes a second alarm management module; The second alarm management module is used to obtain alarm information generated by the information table verification module and the configuration update verification module, send the alarm information to the central processing unit of the server management control chip, and receive the second processing result information fed back by the central processing unit based on the alarm information. The second processing result information is fed back to the information table verification module and the configuration update verification module so that the processing flow in the information table verification module and the configuration update verification module can continue.
7. The server management and control chip according to claim 1, characterized in that, It also includes a compressed video security control module; the compressed video security control module includes an address management module; The address management module is used to obtain the write address corresponding to the write operation of the compressed video write control module on the compressed video information, and to obtain the read address when the network driver reads the compressed video information; and when it is confirmed that the write address is the same as the read address, it sends a fourth indication signal to the compressed video write control module, the fourth indication signal indicating that the write address has not been illegally modified.
8. The server management and control chip according to claim 7, characterized in that, The compressed video security control module also includes an information update control module; The information update control module is used to monitor the second change information of the write address corresponding to the write operation of the compressed video information by the compressed video write control module, and when the write address change is determined based on the second change information, to send a second confirmation request to the central processing unit of the server management control chip, and to receive the second confirmation result information fed back by the central processing unit based on the second confirmation request, and to generate a third alarm information when the change of the write address does not meet the requirements based on the second confirmation result information.
9. The server management and control chip according to claim 8, characterized in that, The compressed video security control module also includes a third alarm management module; The third alarm management module is used to acquire alarm information from the address management module and the information update control module, send the alarm information to the central processing unit of the server management control chip, receive the third processing result information fed back by the central processing unit based on the alarm information, and feed back the third processing result information to the address management module and the information update control module so that the processing flow within the address management module and the information update control module can continue.
10. The server management and control chip according to claim 7, characterized in that, The address management module is also used to obtain the write request sent by the server hardware status management software driver, and to verify the third operation type and third key in the write request; And if it is confirmed that the third operation type and the third key meet the third verification conditions, the third response information is sent to the server hardware state management software driver and the state of the address management module is controlled to the first state; when the address management module is in the first state, the server hardware state management software driver is only allowed to perform write operations on the hardware state information cache unit. The address management module is also used to obtain a fifth indication signal sent by the server hardware status management software driver, and the address management module is also used to control the state of the address management module to a second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to read the hardware status information cache unit; The address management module is also used to obtain the read request sent by the network driver and verify the fourth operation type and the fourth key in the read request; And if it is confirmed that the fourth operation type and the fourth key meet the fourth verification conditions, a fourth response information is sent to the network driver, the fourth response information indicating that the network driver is allowed to read data from the hardware status information cache unit.
11. A data processing method, characterized in that, The method is applied to a server management and control chip, which includes, in sequence, a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video write control module, and further includes an original video space security control module and a compression process security control module; the original video space security control module includes an address protection module; the compression process security control module includes an information table local cache module, a remote information table cache module, and an information table verification module; the method includes: The video interface obtains video information from the server operating system and sends a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; The address protection module verifies the first operation type and the first key in the write operation request; and when it confirms that the first operation type and the first key meet the first verification condition, it sends a first response message to the video interface and controls the state of the address protection module to a first state; when the address protection module is in the first state, it only allows the video interface to perform write operations on the video information cache unit. The video interface converts the video information into video information in a first format based on the first response information, writes the video information in the first format into the video information cache unit, and sends a first indication signal to the address protection module after completing the writing of the video information in the first format. The address protection module controls its state to a second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information cache unit. The remote information table caching module initiates a read configuration information request to the remote end according to the second preset time period, and reads the second configuration information sent by the remote end to the configuration information caching unit based on the read configuration information request from the configuration information caching unit; The information table verification module obtains the first configuration information cached in the local information table cache module and the second configuration information in the remote information table cache module; and when it determines, based on the first configuration information and the second configuration information, that the first configuration information used for compressing the video information of the first format has not been illegally modified, it sends a third indication signal to the core compression module, the third indication signal indicating that the first configuration information configured by the compression configuration module has not been illegally modified; the first configuration information is configured by the compression configuration module. The core compression module compresses the video information in the first format sent by the video capture module to the core compression module through the compression configuration module based on the third indication signal and the first configuration information, to obtain compressed video information.
12. The data processing method according to claim 11, characterized in that, The server management and control chip further includes a compressed video security control module; the compressed video security control module includes an address management module; the method further includes: The address management module obtains the write address corresponding to the write operation of the compressed video writing control module on the compressed video information, and obtains the read address when the network driver reads the compressed video information; and when it confirms that the write address is the same as the read address, it sends a fourth indication signal to the compressed video writing control module, the fourth indication signal indicating that the write address has not been illegally modified. Based on the fourth indication signal, the compressed video security control module writes the compressed video information sent by the core compression module to the compressed video security control module to the write address.
13. The data processing method according to claim 12, characterized in that, The method further includes: The address management module receives a write request sent by the server hardware status management software driver, verifies the third operation type and third key in the write request, and, if it confirms that the third operation type and the third key meet the third verification conditions, sends a third response message to the server hardware status management software driver and controls the address management module to a first state; when the address management module is in the first state, it only allows the server hardware status management software driver to perform write operations on the hardware status information cache unit. The address management module receives a fifth indication signal sent by the server hardware status management software driver, and controls the address management module to a second state based on the fifth indication signal; when the address management module is in the second state, only the network driver is allowed to read the hardware status information cache unit; The address management module receives a read request sent by the network driver, verifies the fourth operation type and the fourth key in the read request, and sends a fourth response message to the network driver if it confirms that the fourth operation type and the fourth key meet the fourth verification conditions. The fourth response message indicates that the network driver is allowed to read data from the hardware status information cache unit.
14. A server, characterized in that, include: Server host; A server management control chip is used to implement the data processing method as described in claim 11. The server management control chip includes a video interface, a video capture module, a compression configuration module, a core compression module, and a compressed video writing control module connected in sequence, and also includes an original video space security control module; the original video space security control module includes an address protection module. The video interface is used to obtain video information of the server host operating system, and send a write operation request to the address protection module based on the video information; the write operation request includes a first operation type and a first key; The address protection module is used to verify the first operation type and the first key in the write operation request; And upon confirming that the first operation type and the first key meet the first verification conditions, send the first response information to the video interface and control the state of the address protection module to the first state; When the address protection module is in the first state, it only allows the video interface to write to the video information cache unit; The video interface is also used to convert the video information into video information in a first format based on the first response information, write the video information in the first format into the video information cache unit, and send a first indication signal to the address protection module after completing the writing of the video information in the first format. The address protection module is also used to control the state of the address protection module to a second state based on the first indication signal; when the address protection module is in the second state, only the video interface and the video capture module are allowed to read the video information cache unit.
15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to perform the data processing method as described in any one of claims 11-13.
16. A computer program product comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by the processor, they implement the data processing method according to any one of claims 11-13.
Citation Information
Patent Citations
Data security protection method, device and system, security control framework and storage medium
CN117396872A
Video data transmission method and device, equipment, medium and product
CN118921503A
Memory protection method and system, computer equipment, storage medium and product
CN119293863A