Substrate management controller user password configuration method and device and electronic equipment
By verifying the validity of BMC user passwords and splitting them into protocol standard passwords and extended passwords, the problem of limited password length is solved, and longer password support and security enhancement is achieved, while maintaining compatibility with existing protocols.
Patent Information
- Application Number
- CN202510421092.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, the length of the user password of the substrate management controller BMC is limited, which cannot meet the increasingly high security needs of users, resulting in restrictions in actual use.
After verifying the validity of the BMC user password, it is split into protocol standard password and extended password, and stored separately, which realizes the extension of the BMC user password length, while maintaining compatibility with the existing BMC management protocol.
The extension of the BMC user password length is achieved, security is enhanced, and the number of code changes is small, which avoids changes to existing data and maintains the stability and compatibility of the system.
Smart Images

Figure CN120277655A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular, to a method, device, and electronic device for configuring a user password of a baseboard management controller. Background Art
[0002] As a core component of hardware management, the security of the Baseboard Management Controller (BMC) is of crucial importance. The management of the BMC user password is a key link to ensure the security of the BMC system. In related technologies, BMC management protocols such as the Intelligent Platform Management Interface (IPMI) protocol have limitations on the number of bytes of the BMC user password. As users' requirements for security are getting higher and higher, the password length limitation poses many restrictions in actual use, and the BMC needs to support user passwords with more byte lengths. Summary of the Invention
[0003] The present application provides a method, device, and electronic device for configuring a user password of a baseboard management controller, so as to at least solve the problem in related technologies that as users' requirements for security are getting higher and higher, the password length limitation poses many restrictions in actual use, and how to enable the baseboard management controller (BMC) to support user passwords with more byte lengths.
[0004] The present application provides a method for configuring a BMC user password, including:
[0005] Obtaining the BMC user password input by the BMC user;
[0006] When the number of bytes of the BMC user password is greater than the number of password bytes limited by the BMC management protocol, performing password validity verification on the BMC user password;
[0007] When the password validity verification passes, splitting the BMC user password to obtain a protocol standard password and an extended password;
[0008] Storing the protocol standard password and the extended password respectively.
[0009] The present application further provides a BMC user password configuration device, including:
[0010] An obtaining module, configured to obtain the BMC user password input by the BMC user;
[0011] A validity verification module, configured to perform password validity verification on the BMC user password when the number of bytes of the BMC user password is greater than the number of password bytes limited by the BMC management protocol;
[0012] A splitting module, configured to split the BMC user password to obtain a protocol standard password and an extended password when the password validity check passes.
[0013] A storage module, configured to store the protocol standard password and the extended password respectively.
[0014] The present application further provides an electronic device, including: a memory, configured to store a computer program; a processor, configured to implement the steps of any of the above BMC user password configuration methods when executing the computer program.
[0015] The present application further provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of any of the above BMC user password configuration methods are implemented.
[0016] The present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of any of the above BMC user password configuration methods are implemented.
[0017] Through the present application, when the number of bytes of the BMC user password is greater than the number of password bytes defined by the BMC management protocol, the password validity check is performed on the BMC user password, and when the password validity check passes, the BMC user password is split to obtain a protocol standard password and an extended password and stored respectively, realizing the extension of the length of the BMC user password, while supporting BMC user passwords with a number of bytes greater than the number of password bytes defined by the BMC management protocol, maintaining compatibility with the existing BMC management protocol, with a small amount of code modification and strong practicability. Description of the Drawings
[0018] To more clearly illustrate the embodiments of the present application, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0019] Figure 1 One of the schematic diagrams of the BMC user password configuration method provided by some embodiments of the present application;
[0020] Figure 2 Another schematic diagram of the BMC user password configuration method provided by some embodiments of the present application;
[0021] Figure 3 Another schematic diagram of the BMC user password configuration method provided by some embodiments of the present application;
[0022] Figure 4 Schematic diagram of BMC user password verification provided by some embodiments of the present application;
[0023] Figure 5 Schematic structural diagram of a BMC user password configuration device provided by some embodiments of the present application.
[0024] Explanation of reference numerals:
[0025] 500: BMC user password configuration device; 501: acquisition module; 502: validity verification module; 503: splitting module; 504: storage module. Detailed implementation manners
[0026] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0027] It should be noted that in the description of the present application, the terms "including", "comprising" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0028] A Baseboard Management Controller (BMC) user refers to an account used to log in to the BMC to implement the use of BMC-related functions. The BMC supports multi-account login and manages users by assigning different permissions. BMC users are used in all aspects of the BMC, including but not limited to IPMI out-of-band commands, SNMP, SSH, Web, and Redfish, etc. In the IPMI specification, the maximum length of the user password does not exceed 20 bytes. As users' requirements for security are getting higher and higher, the password length limit has many restrictions in actual use, and the BMC needs to support user passwords with more byte lengths.
[0029] To solve this problem, the solution adopted in the related art is that, at the software level, the original 20-byte array variable is extended to 32 bytes or even larger to meet the requirements. However, the disadvantages of this are as follows: First, the amount of code modification is large. It is necessary to traverse the entire code library to replace the length of the array variable, and it is easy to miss modifications or cause logical confusion. Second, it is not conducive to maintaining the existing products in the maintenance stage. When upgrading from the existing 20-byte machine to the multi-byte version, the original files need to be deleted and stored again. If upgrading from the multi-byte version to the 20-byte version, problems such as password loss will occur.
[0030] To this end, the embodiments of the present application propose a method, device, and electronic device for configuring the user password of the baseboard management controller. To enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0031] The embodiments of the present application provide a method for configuring the BMC user password, and the method will be described in detail below.
[0032] Specifically, Figure 1 is one of the schematic diagrams of the BMC user password configuration method provided by some embodiments of the present application. As Figure 1 shown, the BMC user password configuration method includes: step 110, step 120, step 130, and step 140.
[0033] Step 110: Obtain the BMC user password input by the BMC user.
[0034] The BMC is an independent management module of the server hardware, used to implement the monitoring and remote management of the server, independent of the server's operating system, and is usually integrated on the server motherboard or a board card connected to the motherboard.
[0035] The BMC user is an account used to log in to the BMC to implement the use of BMC-related functions. The BMC supports multiple user logins, and manages the BMC users by assigning different permissions to the BMC users. The BMC user password configuration method provided by the embodiments of the present application is used to configure the BMC user password. After the configuration is completed, the BMC user password can be used as a credential for the BMC user to log in to the BMC and perform identity verification.
[0036] Step 120: When the number of bytes of the BMC user password is greater than the number of password bytes limited by the BMC management protocol, perform password validity verification on the BMC user password.
[0037] The BMC management protocol can be considered as a collection of a series of communication protocols for monitoring and managing server hardware, enabling the BMC (Baseboard Management Controller) to monitor and remotely manage the server independently of the server's operating system. For example, the BMC is usually designed and implemented based on the Intelligent Platform Management Interface (IPMI) protocol and can be considered a specific implementation form of the IPMI protocol. In some application scenarios, the BMC also supports other BMC management protocols, such as the Simple Network Management Protocol (SNMP), the Redfish protocol, etc.
[0038] Figure 2 This is the second schematic diagram of the BMC user password configuration method provided by some embodiments of this application. As Figure 2 shown, the BMC user can monitor and remotely manage the server through different methods such as Redfish protocol commands, network Web protocol commands, IPMI commands, and basic input / output system BIOS commands. When the BMC is designed and implemented based on the IPMI protocol, these above commands will be converted into IPMI original equipment manufacturer (OEM) commands to control the BMC to implement corresponding actions. In the embodiments of this application, these actions can be to verify the BMC user password, split the BMC user password, or store the BMC user password, etc.
[0039] However, since different BMC management protocols usually have different limitations on the number of bytes of the BMC user password, there may be a situation where the number of bytes of the BMC user password is greater than the number of password bytes limited by the BMC management protocol. Taking the IPMI protocol as the BMC management protocol as an example, the IPMI protocol limits the maximum length of the user password to no more than 20 bytes. With the increasing requirement for security, there may be a situation where the number of bytes of the BMC user password is greater than the number of password bytes limited by the IPMI protocol.
[0040] In the embodiments of this application, when the number of bytes of the BMC user password is greater than the number of password bytes limited by the BMC management protocol, the password validity verification of the BMC user password refers to verifying the complete BMC user password, rather than only verifying the part within the number of password bytes limited by the BMC management protocol. The password validity verification includes verifying whether the complexity of the BMC user password meets the requirements, such as whether the BMC user password meets the requirements of uppercase and lowercase letters, numbers, legal characters, and weak password requirements, etc. In some scenarios, the password validity verification also includes verifying based on the historical password of this BMC user, such as limiting that the BMC user password cannot be the same as the historical password, etc.
[0041] Step 130: When the password validity check passes, split the BMC user password to obtain a protocol standard password and an extended password.
[0042] After the password validity check passes, if the number of bytes of the BMC user password exceeds the number of bytes limited by the BMC management protocol (such as the 20 bytes limited by the IPMI protocol), the password needs to be split to obtain a protocol standard password and an extended password. It can be understood that the protocol standard password is the part of the BMC user password that conforms to the protocol-limited length, and the extended password can be the part of the BMC user password that exceeds the protocol-limited length, or the complete BMC user password, depending on how the BMC user password is split.
[0043] Step 140: Store the protocol standard password and the extended password separately.
[0044] By splitting the password into a protocol standard password and an extended password, and storing the protocol standard password and the extended password separately, the configuration of the BMC user password is completed, enabling the BMC to support BMC user passwords with more bytes while still being compatible with existing BMC management protocols.
[0045] Optionally, for the protocol standard password, since the split protocol standard password will not exceed the number of password bytes limited by the BMC management protocol, it can be stored without disrupting the original password storage mechanism.
[0046] Optionally, for the extended password, it is stored separately in a newly created file. For example, it is stored according to the manufacturer's design. If encryption storage is involved, it can be encrypted and then stored separately in this newly created file. In this way, on the one hand, there is no need to traverse the entire code library to replace the length of the array variable, and the amount of code changes is small. On the other hand, since the extended password is stored in a newly created file, when upgrading the configuration of a BMC that does not support more byte lengths, the original file will not be deleted, and the existing user password information will not be lost, which is highly practical.
[0047] The BMC user password with more bytes enables the BMC user to monitor and remotely manage the server through the methods provided by different BMC management protocols on the one hand, and enhances the security of the BMC user password on the other hand.
[0048] Taking the BMC management protocol as the IPMI protocol as an example, in the IPMI protocol, the length of the user password is limited to a maximum of 20 bytes. The existing BMC user passwords with the number of bytes not greater than 20 bytes can be stored as the protocol standard passwords, avoiding large-scale changes to the existing data. For the BMC user passwords with the number of bytes greater than 20 bytes, the part that meets the protocol-defined length is stored as the protocol standard password, achieving compatibility with the BMC management protocol. The remaining part exceeding the protocol-defined length is stored as an extended password, achieving support for BMC user passwords with more bytes.
[0049] In the above technical solution, when the number of bytes of the BMC user password is greater than the number of password bytes defined by the BMC management protocol, the password validity of the BMC user password is verified. After the password validity verification passes, the BMC user password is split to obtain the protocol standard password and the extended password, and the protocol standard password and the extended password are stored separately, achieving the extension of the length of the BMC user password. While supporting BMC user passwords with the number of bytes greater than the number of password bytes defined by the BMC management protocol, it maintains compatibility with the existing BMC management protocol, with a small amount of code changes and strong practicability.
[0050] In some embodiments of the present application, the splitting of the BMC user password includes:
[0051] Performing lossy splitting on the BMC user password: taking the first N bytes of the BMC user password as the protocol standard password, and the remaining part outside the first N bytes of the BMC user password as the extended password;
[0052] Alternatively, performing lossless splitting on the BMC user password: taking the first N bytes of the BMC user password as the protocol standard password, and the BMC user password as the extended password;
[0053] wherein, the N is the number of password bytes defined by the BMC management protocol.
[0054] In the embodiments of the present application, two feasible implementation methods are provided for the splitting of the BMC user password.
[0055] Lossy splitting of the BMC user password means taking the first N bytes of the BMC user password as the protocol standard password and the part of the BMC user password beyond the first N bytes as the extended password. For example, if the BMC management protocol limits the password byte count to 20, the protocol standard password is the first 20 bytes of the BMC user password, and the remaining bytes of the BMC user password are the extended password. When performing user password verification later, the protocol standard password and the extended password obtained based on lossy splitting are compared with the password to be verified. The process of lossy splitting of the BMC user password is intuitive, and the two parts of the protocol standard password and the extended password can be clearly distinguished.
[0056] Lossless splitting of the BMC user password means taking the first N bytes of the BMC user password as the protocol standard password and the entire BMC user password as the extended password. For example, if the BMC management protocol limits the password byte count to 20, the protocol standard password is the first 20 bytes of the BMC user password, and the extended password is the complete BMC user password. When performing lossless splitting of the BMC user password and later performing user password verification, the extended password obtained based on lossless splitting can be directly compared with the password to be verified, without the need to split the password to be verified or recombine the BMC user password.
[0057] In the above technical solution, lossy splitting of the BMC user password means taking the first N bytes of the BMC user password as the protocol standard password and the remaining part beyond the first N bytes as the extended password, and lossless splitting of the BMC user password means taking the first N bytes of the BMC user password as the protocol standard password and the BMC user password as the extended password, where N is the password byte count limited by the BMC management protocol. For BMC user passwords with a byte count greater than the password byte count limited by the BMC management protocol, the splitting method of the BMC user password can be selected according to the actual application scenario, improving the flexibility of BMC user password configuration.
[0058] In some embodiments of the present application, the separately storing the protocol standard password and the extended password includes:
[0059] Storing the protocol standard password based on the BMC management protocol;
[0060] Writing the identification information ID and username of the BMC user and the extended password into the extended password file.
[0061] It can be understood that among the protocol standard password and the extended password obtained by splitting the BMC user password, the protocol standard password is the part of the BMC user password that conforms to the password byte count limited by the BMC management protocol.
[0062] Protocol standard passwords are usually stored in the built-in database or configuration file of the BMC based on the BMC management protocol, which is specifically preset by the BMC management protocol to ensure compatibility with the existing BMC management protocol. Taking the BMC management protocol as the IPMI protocol as an example, if the limited number of password bytes is 20 bytes, then the protocol standard password is the first 20 bytes of the BMC user password. The protocol standard password will be stored in a specific location of the BMC, such as the user management database or user password file of the BMC, according to the requirements of the IPMI protocol.
[0063] In some embodiments, writing the identification information ID, username of the BMC user, and the extended password into the extended password file includes:
[0064] Determining the extended information structure of the BMC user according to the identification information ID, username of the BMC user, and the extended password;
[0065] Writing the extended information structure of the BMC user into the extended password file.
[0066] The extended information structure includes ID, username, and extended password, and can be in the following form:
[0067]
[0068] Determining the extended information structure and writing it into the extended password file according to the ID, username, and extended password of the BMC user realizes the storage of the extended password. By defining a unified extended information structure, it is convenient to manage and operate the extended information of the BMC user. The ID of the BMC user can be used to uniquely identify the BMC user. According to the ID of the BMC user, during the subsequent user password verification process, the extended password of the BMC in the extended password file can be quickly located. In some embodiments, when the BMC management protocol is the Simple Network Management Protocol version 3 (SNMP v3), the extended password of the BMC in the extended password file can also be located based on the username of the BMC user.
[0069] In the above technical solution, the protocol standard password is stored based on the BMC management protocol, and the identification information ID, username, and extended password of the BMC user are written into the extended password file, realizing the separate storage of the protocol standard password and the extended password. The storage method of the protocol standard password follows the requirements of the BMC management protocol, which helps to improve the compatibility with the existing BMC management protocol. By storing the extended password in the extended password file, when configuring and upgrading a BMC that does not support a longer byte length, the original file will not be deleted, and the existing user password information will not be lost, realizing the support for the BMC user password with a larger number of bytes configured. Subsequently, the complete BMC user password verification can be performed by combining the protocol standard password and the extended password.
[0070] In some embodiments of the present application, the method further includes:
[0071] When the number of bytes of the BMC user password is not greater than the number of password bytes defined by the BMC management protocol, perform password validity verification on the BMC user password;
[0072] When the password validity verification passes, store the BMC user password based on the BMC management protocol;
[0073] Write the identification information ID and username of the BMC user into the extended password file.
[0074] In the embodiments of the present application, when the number of bytes of the BMC user password is not greater than the number of password bytes defined by the BMC management protocol, it can be considered that the BMC user password is completely stored as the protocol standard password, and the extended password of the BMC user is empty. However, it is still necessary to write the identification information ID and username of the BMC user into the extended password file.
[0075] In some embodiments, writing the identification information ID and username of the BMC user into the extended password file includes:
[0076] Determine the extended information structure of the BMC user according to the identification information ID and username of the BMC user;
[0077] Write the extended information structure of the BMC user into the extended password file.
[0078] The extended information structure can be the same as that in the foregoing embodiments. The extended password field included in the extended information structure is set to empty, and the extended information structure is written into the extended password file. In this way, when a user logs in to this user and enters the password to be verified, the BMC will read the protocol standard password according to the user ID and username, and at the same time, it will also read the password from the extended file according to the user ID and username, and splice the two parts of the password together for comparison with the password to be verified entered by the user. It should be noted that it is necessary to read both parts of the file password and compare them with the input password to prevent boundary problems.
[0079] It can be understood that if the number of bytes of the BMC user password is not greater than the number of password bytes defined by the BMC management protocol, and the identification information ID and username of the BMC user are not written into the extended password file, there may be boundary problems in the subsequent BMC user password verification process. For example: During the BMC user password configuration process, there is a user with the username "user" and the BMC user password "ABCDEFGHIJ1234567890" (20 bytes). Since its password meets the 20-byte limit of the IPMI protocol, it is stored as the protocol standard password in its entirety. If the identification information ID and username of this user are not written into the extended password file and directly enter the subsequent BMC user password verification, the BMC user with the username "user" enters the password to be verified "ABCDEFGHIJ12345678901" (21 bytes). However, since the extended password file does not contain the information of this BMC user, and the user password verification is based on the protocol standard password, the first 20 bytes are the same. Even if the password to be verified has one more byte "1", it will still be regarded as the user password verification passed, which is incorrect.
[0080] Writing the extended information structure in the above form into the extended password file can effectively solve the boundary problems in the subsequent BMC user password verification process and improve the security of the subsequent BMC user password verification.
[0081] In the above technical solution, when the number of bytes of the BMC user password is not greater than the number of password bytes defined by the BMC management protocol, the password validity of the BMC user password is verified. If the password validity verification passes, the BMC user password is stored based on the BMC management protocol, and the identification information ID and username of the BMC user are written into the extended password file to complete the configuration of the BMC user password, which can effectively avoid the boundary problems in the subsequent BMC user password verification process and improve the security of the subsequent BMC user password verification.
[0082] In some embodiments of the present application, before obtaining the BMC user password input by the BMC user, the method further includes:
[0083] Initializing the BMC default user password;
[0084] The initialized BMC default user password includes:
[0085] Read the information of the BMC default user in the image file, where the information of the BMC default user includes the ID, username, and BMC user password of the BMC default user;
[0086] In the case where the number of bytes of the BMC user password is greater than the number of password bytes defined by the BMC management protocol, split the BMC user password to obtain a protocol standard password and an extended password;
[0087] Store the protocol standard password and the extended password separately;
[0088] Clear the information of the BMC default user in the image file.
[0089] An image file is a file that contains a complete copy of a disk or file system. In the embodiments of the present application, the image file contains the information of the BMC default user, such as the user ID, username, and password. During the BMC initialization or recovery process, this information can be used to quickly configure the BMC user account.
[0090] If the number of password bytes of the read BMC default user is greater than the number of password bytes defined by the BMC management protocol, split the password to achieve compatibility with the existing BMC management protocol while supporting a larger number of bytes for the BMC user password.
[0091] After completing the password configuration for the BMC default user, clearing the information of the BMC default user in the image file can prevent unauthorized access and data leakage, reduce potential security risks, and improve the security of the BMC.
[0092] In the above technical solution, before obtaining the BMC user password input by the BMC user, it further includes reading the information of the BMC default user in the image file and completing the configuration of the BMC default user password based on the information of the BMC default user, achieving the configuration of the BMC default user password in the case where the number of bytes of the BMC default user password is greater than the number of password bytes defined by the BMC management protocol, and deleting the information of the BMC default user in the image file after the configuration is completed, improving the security of the BMC.
[0093] Figure 3 This is the third schematic diagram of the BMC user password configuration method provided by some embodiments of the present application. As Figure 3 described, the BMC user password configuration method includes: Step 300, Step 310, Step 320, Step 330, Step 340, Step 350, Step 360, Step 370, Step 380, and Step 390.
[0094] Step 300: Initialize the BMC default user password.
[0095] Step 310: Obtain the BMC user password entered by the BMC user.
[0096] Step 320: When the number of bytes of the BMC user password is greater than the number of password bytes defined by the BMC management protocol, perform password validity verification on the BMC user password.
[0097] Step 330: When the password validity verification passes, split the BMC user password to obtain a protocol standard password and an extended password; when the password validity verification fails, jump to Step 390.
[0098] Step 340: Store the protocol standard password based on the BMC management protocol.
[0099] Step 350: Write the identification information ID and user name of the BMC user and the extended password into the extended password file.
[0100] Step 360: When the number of bytes of the BMC user password is not greater than the number of password bytes defined by the BMC management protocol, perform password validity verification on the BMC user password.
[0101] Step 370: When the password validity verification passes, store the BMC user password based on the BMC management protocol; when the password validity verification fails, jump to Step 390.
[0102] Step 380: Write the identification information ID and user name of the BMC user into the extended password file.
[0103] Step 390: Delete the information of the BMC user, where the information of the BMC user includes the ID and user name of the BMC user.
[0104] In the above technical solution, after initializing the default user password of the BMC, obtain the BMC user password input by the BMC user, and determine whether the number of bytes of the BMC user password is greater than the number of password bytes defined by the BMC management protocol. Further, verify the validity of the password. When the number of bytes of the BMC user password is greater than the number of password bytes defined by the BMC management protocol and the password validity verification passes, store the protocol standard password and the extended password. When the number of bytes of the BMC user password is not greater than the number of password bytes defined by the BMC management protocol and the password validity verification passes, store the protocol standard password, and write the identification information ID and the user name of the BMC user into the extended password file, realizing the extension of the BMC user password length. While supporting BMC user passwords with a number of bytes greater than the number of password bytes defined by the BMC management protocol, it maintains compatibility with the existing BMC management protocol.
[0105] In some embodiments of the present application, the method further includes:
[0106] Obtain the password to be verified input by the BMC user;
[0107] When the protocol standard password and the extended password are obtained by lossy splitting of the BMC user password, verify the password to be verified based on the protocol standard password and the extended password;
[0108] When the protocol standard password and the extended password are obtained by lossless splitting of the BMC user password, perform user password verification on the password to be verified based on the extended password.
[0109] After completing the configuration of the BMC user password, the BMC user password can be used to perform user password verification when the BMC user logs in, obtain the password to be verified input by the BMC user, and verify the password to be verified based on the BMC user password.
[0110] As described in the foregoing embodiments, lossy splitting of the BMC user password means taking the first N bytes of the BMC user password as the protocol standard password, and taking the part of the BMC user password beyond the first N bytes as the extended password; lossless splitting of the BMC user password means taking the first N bytes of the BMC user password as the protocol standard password, and taking the entire BMC user password as the extended password.
[0111] It can be understood that when the BMC user password is obtained by lossy splitting of the protocol standard password and the extended password, the BMC user password is split and it is necessary to verify the password to be verified based on both the protocol standard password and the extended password; while when the protocol standard password and the extended password are obtained by lossless splitting of the BMC user password, the extended password is the complete BMC user password, and the user password verification can be performed on the password to be verified only based on the extended password.
[0112] Figure 4 This is a schematic diagram of BMC user password verification provided by some embodiments of the present application. As Figure 4 shown, the BMC user can monitor and remotely manage the server through different methods such as Redfish protocol commands, network Web protocol commands, Secure Shell (SSH) protocol commands, and SOL (Serial Over LAN) commands. In the embodiments of the present application, these operations can be splitting the password to be verified, verifying the protocol standard password, or verifying the extended password, etc.
[0113] In the above technical solution, when the protocol standard password and the extended password are obtained by lossy splitting of the BMC user password, the password to be verified is verified based on the protocol standard password and the extended password; when the protocol standard password and the extended password are obtained by lossless splitting of the BMC user password, the user password verification is performed on the password to be verified based on the extended password, realizing the determination of the verification method of the password to be verified according to the splitting method of the BMC user password, being able to adapt to different security requirements and application scenarios, and improving the flexibility of BMC user password verification.
[0114] In some embodiments of the present application, the verifying the password to be verified based on the protocol standard password and the extended password includes:
[0115] Performing lossy splitting on the password to be verified to obtain a protocol standard password to be verified and an extended password to be verified;
[0116] Obtaining the protocol standard password of the BMC user based on the BMC management protocol;
[0117] Obtaining the extended password of the BMC user from the extended password file according to the ID and username of the BMC user;
[0118] When the protocol standard password to be verified of the BMC user is the same as the protocol standard password, and the extended password to be verified of the BMC user is the same as the extended password, it is determined that the user password verification passes;
[0119] Perform lossy splitting on the password to be verified: Use the first N bytes of the password to be verified as the protocol standard password to be verified, and the remaining part outside the first N bytes of the password to be verified as the extended password to be verified, where N is the number of password bytes defined by the BMC management protocol.
[0120] It can be understood that since the protocol standard password and the extended password are obtained by lossy splitting of the BMC user password, during the process of verifying the password to be verified, it is also necessary to perform lossy splitting on the password to be verified to obtain the protocol standard password to be verified and the extended password to be verified, and compare them with the corresponding parts of the BMC user password respectively. In some embodiments, it is also possible to choose not to perform lossy splitting on the password to be verified, but to combine the protocol standard password and the extended password of the BMC user to obtain the BMC user password, and directly perform user password verification on the password to be verified based on the combined BMC user password.
[0121] Since the protocol standard password is usually stored in the built-in database or configuration file of the BMC based on the BMC management protocol, and is specifically preset by the BMC management protocol to ensure compatibility with the existing BMC management protocol. Therefore, during the user password verification process, the protocol standard password is also obtained based on the BMC management protocol.
[0122] The extended password file stores the ID and username of the BMC user and the extended password. In some embodiments, the extended password file includes an extended information structure, which can be used to quickly locate the extended password of the BMC user according to the ID and username of the BMC user.
[0123] Since lossy splitting is performed on both the BMC user password and the password to be verified, as described in the foregoing embodiments, boundary problems may occur if only the protocol standard password or the extended password is compared separately. Therefore, in the embodiments of the present application, the user password verification is determined to pass only when the protocol standard password to be verified of the BMC user is the same as the protocol standard password, and the extended password to be verified of the BMC user is the same as the extended password.
[0124] In the above technical solution, lossy splitting is performed on the password to be verified to obtain the protocol standard password to be verified and the extended password to be verified. When the protocol standard password to be verified of the BMC user is the same as the protocol standard password, and the extended password to be verified of the BMC user is the same as the extended password, the user password verification is determined to pass, realizing the verification of the BMC user password with the number of bytes greater than the number of password bytes defined by the BMC management protocol.
[0125] In some embodiments of the present application, the user password verification based on the extended password for the password to be verified includes:
[0126] Obtain the extended password of the BMC user from the extended password file according to the ID and username of the BMC user;
[0127] When the password to be verified of the BMC user is the same as the extended password, determine that the user password verification passes.
[0128] It can be understood that since the lossless splitting of the BMC user password means taking the first N bytes of the BMC user password as the protocol standard password and taking the entire BMC user password as the extended password, in this embodiment, if the password to be verified is the same as the extended password, it can be considered that the password to be verified is the same as the BMC user password, and the user password verification is determined to pass.
[0129] In the above technical solution, since the BMC user password is losslessly split, the extended password is the BMC user password. When the password to be verified of the BMC user is the same as the extended password, the user password verification is determined to pass, realizing the verification of the BMC user password whose number of bytes is greater than the password byte number limited by the BMC management protocol.
[0130] In some embodiments of the present application, the method further includes:
[0131] When the password validity verification fails, delete the information of the BMC user, and the information of the BMC user includes the ID and username of the BMC user.
[0132] In the above technical solution, deleting the information of the BMC user whose password validity verification fails avoids the storage of invalid user information such as the ID and username of the BMC user in the BMC, which helps to maintain the stability of the BMC operation.
[0133] In some embodiments of the present application, the BMC management protocol includes one or more of the Intelligent Platform Management Interface IPMI protocol, the Network Web protocol, the Simple Network Management SNMP protocol, the Secure Shell SSH protocol, and the Redfish protocol;
[0134] The BMC user password configuration method is implemented based on the IPMI original equipment manufacturer OEM command of the BMC.
[0135] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0136] Figure 5 It is a schematic structural diagram of a BMC user password configuration device provided for some embodiments of the present application. AsFigure 5 As shown in Figure 5 , an embodiment of the present application further provides a BMC user password configuration device 500, including:
[0137] An acquisition module 501, configured to acquire the BMC user password input by the BMC user;
[0138] A validity verification module 502, configured to perform password validity verification on the BMC user password when the number of bytes of the BMC user password is greater than the number of password bytes defined by the BMC management protocol;
[0139] A splitting module 503, configured to split the BMC user password to obtain a protocol standard password and an extended password when the password validity verification passes;
[0140] A storage module 504, configured to store the protocol standard password and the extended password respectively.
[0141] Optionally, the splitting module 503 is configured to:
[0142] Perform lossy splitting on the BMC user password: use the first N bytes of the BMC user password as the protocol standard password, and the remaining part other than the first N bytes of the BMC user password as the extended password;
[0143] Or, perform lossless splitting on the BMC user password: use the first N bytes of the BMC user password as the protocol standard password, and the BMC user password as the extended password;
[0144] Wherein, N is the number of password bytes defined by the BMC management protocol.
[0145] Optionally, the storage module 504 is configured to:
[0146] Store the protocol standard password based on the BMC management protocol;
[0147] Write the identification information ID and user name of the BMC user and the extended password into an extended password file.
[0148] Optionally, the BMC user password configuration device 500 further includes a first processing unit, and the first processing unit is configured to:
[0149] Perform password validity verification on the BMC user password when the number of bytes of the BMC user password is not greater than the number of password bytes defined by the BMC management protocol;
[0150] Store the BMC user password based on the BMC management protocol when the password validity verification passes;
[0151] Write the identification information ID and username of the BMC user into the extended password file.
[0152] Optionally, the BMC user password configuration device 500 further includes a second processing unit, and the second processing unit is configured to:
[0153] Obtain the password to be verified input by the BMC user;
[0154] When the protocol standard password and the extended password are obtained by lossy splitting of the BMC user password, verify the password to be verified based on the protocol standard password and the extended password;
[0155] When the protocol standard password and the extended password are obtained by lossless splitting of the BMC user password, perform user password verification on the password to be verified based on the extended password.
[0156] Optionally, the second processing unit is configured to:
[0157] Perform lossy splitting on the password to be verified to obtain a protocol standard password to be verified and an extended password to be verified;
[0158] Obtain the protocol standard password of the BMC user based on the BMC management protocol;
[0159] Obtain the extended password of the BMC user from the extended password file according to the ID and username of the BMC user;
[0160] When the protocol standard password to be verified of the BMC user is the same as the protocol standard password, and the extended password to be verified of the BMC user is the same as the extended password, determine that the user password verification passes;
[0161] The lossy splitting of the password to be verified: Use the first N bytes of the password to be verified as the protocol standard password to be verified, and the remaining part of the password to be verified except the first N bytes as the extended password to be verified, where N is the number of password bytes defined by the BMC management protocol.
[0162] Optionally, the second processing unit is configured to:
[0163] Obtain the extended password of the BMC user from the extended password file according to the ID and username of the BMC user;
[0164] When the password to be verified of the BMC user is the same as the extended password, determine that the user password verification passes.
[0165] For the description of the features in the corresponding embodiments of the BMC user password configuration device, reference can be made to the relevant description in the corresponding embodiments of the BMC user password configuration method, which will not be elaborated here one by one.
[0166] An embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above embodiments of the BMC user password configuration method.
[0167] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any one of the above embodiments of the BMC user password configuration method when running.
[0168] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: USB flash drive, read-only memory (ROM for short), random access memory (RAM for short), mobile hard disk, magnetic disk or optical disc, etc., various media that can store computer programs.
[0169] An embodiment of the present application further provides a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any one of the above embodiments of the BMC user password configuration method.
[0170] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any one of the above embodiments of the BMC user password configuration method.
[0171] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0172] The above has introduced in detail a method, device, and electronic device for configuring a user password of a baseboard management controller provided by this application. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and modifications can still be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A method for configuring a user password of a baseboard management controller, characterized in that, Including: Obtain the BMC user password input by the baseboard management controller; When the number of bytes of the BMC user password is greater than the password byte number defined by the BMC management protocol, perform password validity verification on the BMC user password; When the password validity verification passes, split the BMC user password to obtain a protocol standard password and an extended password; Store the protocol standard password and the extended password respectively.
2. The method for configuring the user password of the baseboard management controller according to claim 1, wherein The splitting of the BMC user password includes: Perform lossy splitting on the BMC user password: use the first N bytes of the BMC user password as the protocol standard password, and the remaining part other than the first N bytes of the BMC user password as the extended password; Alternatively, perform lossless splitting on the BMC user password: use the first N bytes of the BMC user password as the protocol standard password, and the BMC user password as the extended password; Wherein, the N is the password byte number defined by the BMC management protocol.
3. The method for configuring the user password of the baseboard management controller according to claim 1 or 2, wherein The storing the protocol standard password and the extended password respectively includes: Store the protocol standard password based on the BMC management protocol; Write the identification information and user name of the BMC user and the extended password into an extended password file.
4. The method for configuring the user password of the baseboard management controller according to claim 1, wherein The method further includes: When the number of bytes of the BMC user password is not greater than the password byte number defined by the BMC management protocol, perform password validity verification on the BMC user password; When the password validity verification passes, store the BMC user password based on the BMC management protocol; Write the identification information and user name of the BMC user into the extended password file.
5. The method for configuring the user password of the baseboard management controller according to claim 3, wherein, The method further includes: Obtain the password to be verified input by the BMC user; When the protocol standard password and the extended password are obtained by lossy splitting of the BMC user password, verify the password to be verified based on the protocol standard password and the extended password; When the protocol standard password and the extended password are obtained by lossless splitting of the BMC user password, perform user password verification on the password to be verified based on the extended password.
6. The method for configuring the user password of the baseboard management controller according to claim 5, wherein, The verifying the password to be verified based on the protocol standard password and the extended password includes: Perform lossy splitting on the password to be verified to obtain a protocol standard password to be verified and an extended password to be verified; Obtain the protocol standard password of the BMC user based on the BMC management protocol; Obtain the extended password of the BMC user from the extended password file according to the identification information and user name of the BMC user; When the to-be-verified protocol standard password of the baseboard management controller user is the same as the protocol standard password, and the to-be-verified extended password of the baseboard management controller user is the same as the extended password, it is determined that the user password verification passes. Perform lossy splitting on the to-be-verified password: Use the first N bytes of the to-be-verified password as the to-be-verified protocol standard password, and the remaining part outside the first N bytes of the to-be-verified password as the to-be-verified extended password, where N is the number of password bytes defined by the baseboard management controller management protocol.
7. The method for configuring the user password of the baseboard management controller according to claim 5, wherein The user password verification based on the extended password for the to-be-verified password includes: According to the identification information and user name of the baseboard management controller user, obtain the extended password of the baseboard management controller user from the extended password file. When the to-be-verified password of the baseboard management controller user is the same as the extended password, it is determined that the user password verification passes.
8. A substrate management controller user password configuration device, characterized in that, Includes: An acquisition module, configured to acquire the baseboard management controller user password input by the baseboard management controller user. A validity verification module, configured to perform password validity verification on the baseboard management controller user password when the number of bytes of the baseboard management controller user password is greater than the number of password bytes defined by the baseboard management controller management protocol. A splitting module, configured to split the baseboard management controller user password to obtain a protocol standard password and an extended password when the password validity verification passes. A storage module, configured to store the protocol standard password and the extended password respectively.
9. An electronic device, characterized in that, Includes: A memory, configured to store a computer program. A processor, configured to implement the steps of the baseboard management controller user password configuration method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, where the computer program implements the steps of the baseboard management controller user password configuration method according to any one of claims 1 to 7 when executed by a processor.