Method and system for realizing internal secure communication of BMC (Baseboard Management Controller) based on desktop bus

By introducing the National Secret algorithm to encrypt DBus data, generating and managing public and private keys, the security problem of data transmission in the BMC system is solved, the permission isolation and encryption processing of data transmission is realized, and the security of the system is improved.

CN120277692APending Publication Date: 2025-07-08JIANGSU ZHUOYI INFORMATION TECH CO LTD +2
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510363713.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The internal process communication scheme based on DBus in the existing BMC has not been encrypted in data, and there are problems such as data resource exposure and insufficient permission isolation.

Method used

The national secret algorithm is used to encrypt the data on DBus, and the public and private keys are generated and managed through the key center to ensure that only authorization can decrypt the data.

Benefits of technology

It realizes data transmission permission isolation and ciphertext processing on DBus, prevents unauthorized parties from accessing plaintext data, and improves the security of the BMC system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277692A_ABST
    Figure CN120277692A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for realizing internal secure communication of a BMC (Baseboard Management Controller) based on a desktop bus, and belongs to the technical field of computer security. According to the method, by introducing a key center and combining a national cryptographic algorithm encryption technology, the problems that in an existing BMC system, a desktop bus data transmission plaintext is exposed, and permission isolation is insufficient are solved. The method comprises the following specific steps: a data sender submits own and receiver identifiers to a key center to apply for public keys; the key center generates a national cryptographic algorithm public and private key pair bound with identifiers of the two parties and issues a public key; the data sender submits to-be-sent data and the public key to the desktop bus daemon process for encryption transmission; and the data receiver obtains the private key after passing the authority verification, and decrypts the private key to obtain the plaintext service data. Through dynamic key generation, public and private key binding verification and forced ciphertext transmission, authority isolation of a data sender and a data receiver is realized, illegal processes are prevented from stealing or tampering BMC service data, and the system communication security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a method and system for realizing internal secure communication of BMC based on a desktop bus. Background Art

[0002] In a BMC (Baseboard Management Controller), inter-process communication (IPC) is an important component, and DBus (Desktop Bus) is widely adopted as a lightweight and efficient IPC mechanism.

[0003] DBus is an advanced inter-process communication mechanism widely used in the Linux operating system. It allows software applications to communicate synchronously or asynchronously, send and receive messages across processes. Compared with traditional IPC mechanisms (such as PIPE / FIFO / Socket / shared memory / SysvIpc), DBus provides a low-latency, low-overhead, and highly available IPC mechanism, hiding the complexity of the underlying IPC mechanism and providing developers with more advanced and user-friendly interfaces.

[0004] The inventors found during the implementation of the present invention that in the existing internal process communication scheme of BMC based on DBus, the transmitted data on DBus is not securely encrypted. Users or programs of the BMC system can read any information on DBus in plain text through the command tools exposed by DBus, and the data sender and data receiver interact with data in plain text, resulting in security risks such as data resource exposure and lack of permission isolation for data resources. Summary of the Invention

[0005] In view of this, embodiments of the present invention provide a method and system for realizing internal secure communication of BMC based on a desktop bus to solve the above technical problems.

[0006] To achieve the above object, in a first aspect, a method for realizing internal secure communication of BMC based on a desktop bus is provided, which includes the following steps:

[0007] A data sender submits its own identifier and the identifier of a data receiver to a key center of a baseboard management controller BMC system to apply for generating a public key of a national cryptography algorithm.

[0008] The key center generates a pair of public and private keys of a national cryptography algorithm corresponding to the identifier of the data sender and the identifier of the data receiver, and sends the public key to the data sender.

[0009] The data sender submits the data to be sent and the public key to the desktop bus daemon process;

[0010] The desktop bus daemon process uses the public key to perform national cryptography algorithm encryption processing on the data to be sent, and generates encrypted transmission data;

[0011] The data receiver submits its own identifier to the key center and applies to obtain the private key of the national cryptography algorithm paired with the public key;

[0012] After verifying the access permission of the identifier of the data receiver, the key center issues the corresponding private key to the data receiver;

[0013] The data receiver requests the desktop bus daemon process to obtain the encrypted transmission data, and uses the private key to perform decryption processing to obtain the plaintext service data.

[0014] In a second aspect, another method for implementing secure communication inside the BMC based on the desktop bus is provided. The method includes:

[0015] The data sender and the data receiver respectively apply to the physical unclonable function of the baseboard management controller (BMC) chip for their respective identifiers;

[0016] The data sender and the data receiver upload their respective identifiers to the BMC secure storage area, and allow the data sender to query the identifier of the data receiver through the program name;

[0017] The data sender submits the identifier of the data sender and the identifier of the data receiver to the key center and requests to generate a public key;

[0018] The key center calls the national cryptography algorithm library to generate a key pair including a public key and a private key with an expiration date, and stores the key pair and the expiration date in the BMC secure storage area;

[0019] The key center issues the public key to the data sender;

[0020] The data sender submits the data to be sent and the public key to the desktop bus daemon process;

[0021] The desktop bus daemon process calls the national cryptography algorithm library to verify whether the public key is within the expiration date. If the public key is within the expiration date, it calls the national cryptography algorithm library to perform encryption processing on the data to be sent;

[0022] After the data receiver obtains the encrypted data through the desktop bus daemon process, it applies to the key center for the corresponding private key according to the identifier of the data receiver;

[0023] The data recipient calls the national cryptography algorithm library to verify whether the private key is within the validity period. If the private key is within the validity period, the national cryptography algorithm library is called to decrypt the encrypted data to obtain the decrypted data.

[0024] Thirdly, a system for implementing secure internal communication of BMC based on a desktop bus is provided, which includes:

[0025] A key center, deployed in the Baseboard Management Controller (BMC), is used to receive the self-identifier of the data sender and the identifier of the data recipient, and generate a corresponding pair of public and private keys of the national cryptography algorithm; and verify the access permission of the identifier of the data recipient, and control the distribution of the private key;

[0026] The data sender is configured to submit its own identifier and the identifier of the data recipient to the key center to apply for a public key, and submit the data to be sent and the public key to the desktop bus daemon process;

[0027] The desktop bus daemon process is configured to perform national cryptography algorithm encryption processing on the data to be sent using the public key to generate encrypted transmission data;

[0028] The data recipient is configured to submit its own identifier to the key center to apply for a private key, request to obtain the encrypted transmission data from the desktop bus daemon process, and decrypt it using the private key to obtain the plaintext service data.

[0029] Fourthly, a system for implementing secure internal communication of BMC based on a desktop bus is provided. The system includes:

[0030] A key center is used to generate a key pair including a public key and a private key with a validity period according to the identifier of the data sender and the identifier of the data recipient, store the key pair and the validity period in the BMC secure storage area, and distribute the public key to the data sender;

[0031] The data sender is used to apply for its own identifier from the Physical Unclonable Function (PUF) module of the BMC chip, and submit the identifier and the data to be sent associated with the public key to the desktop bus daemon process;

[0032] The data recipient is used to apply for its own identifier from the Physical Unclonable Function (PUF) module of the BMC chip, and after obtaining the encrypted data through the desktop bus daemon process, apply for the corresponding private key from the key center and decrypt it;

[0033] The Physical Unclonable Function (PUF) module of the BMC chip is used to generate the respective identifiers of the data sender and the data recipient;

[0034] The BMC secure storage area is used to store the respective identifiers of the data sender and the data receiver, the mapping relationship between the program name and the identifier of the data receiver, and the key pair including the public key and the private key with an expiration date;

[0035] The desktop bus daemon is used to receive the public key and the data to be sent submitted by the data sender, call the national cryptography algorithm library to verify the expiration date of the public key, and perform encryption processing on the data to be sent after passing the verification to obtain encrypted data, and transmit the encrypted data to the data receiver;

[0036] The national cryptography algorithm library is used to generate a key pair including the public key and the private key of the national cryptography algorithm, verify whether the public key or the private key is within the expiration date, perform data encryption processing on the data to be sent according to the public key after passing the verification, and perform data decryption processing on the encrypted data according to the private key.

[0037] The above technical solution has the following beneficial technical effects:

[0038] In the BMC system adopting the above recording method and software, the data carried and transmitted on the DBus is subjected to permission isolation and ciphertext processing through the national cryptography algorithm.

[0039] Each data sender process in the BMC system can specify the data receiver process. Only the data receiver with the private key can decrypt and use the data. Non-specified data receivers cannot decrypt and use the transmitted BMC data, achieving the effect of permission isolation. Description of the Drawings

[0040] The drawings are used to better understand the present invention and do not constitute an improper limitation to the present invention. Among them:

[0041] Figure 1 is the overall flowchart of a method for realizing internal secure communication of BMC based on the desktop bus in Embodiment 1 of the present invention;

[0042] Figure 2 is the flowchart of a software application as an example in Embodiment 1 of the present invention;

[0043] Figure 3 is the overall flowchart of another method for realizing internal secure communication of BMC based on the desktop bus in Embodiment 2 of the present invention;

[0044] Figure 4 is the flowchart of a software application as an example in Embodiment 2 of the present invention;

[0045] Figure 5 is the functional block diagram of a system for realizing internal secure communication of BMC based on the desktop bus in Embodiment 3 of the present invention;

[0046] Figure 6It is a functional block diagram of a system for implementing secure communication inside BMC based on the desktop bus in Embodiment 4 of the present invention. Detailed implementation manners

[0047] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, descriptions of well-known functions and structures are omitted below for clarity and conciseness.

[0048] The embodiments of the present invention belong to the field of computer technology, and particularly relate to a method for securely encrypting data on DBus through national cryptographic algorithms to achieve secure communication inside BMC.

[0049] In BMC, DBus is widely used in scenarios such as sensor data collection, hardware fault management, and remote management interfaces. It makes communication between different components simple and efficient, providing a strong guarantee for the stable operation of the system.

[0050] In the DBus system, there is a resident process daemon, and all inter-process interactions are distributed and managed through it. All processes that wish to use DBus for communication must first connect to the daemon and register their names with the daemon. After that, the daemon will send messages and data to the corresponding processes as needed.

[0051] National cryptographic algorithms refer to national commercial cryptographic algorithms.

[0052] Embodiment 1

[0053] Figure 1 It is an overall flowchart of a method for implementing secure communication inside BMC based on the desktop bus. As Figure 1 shown, it includes the following steps:

[0054] S10: The data sender submits its own identifier and the identifier of the data receiver to the key center of the baseboard management controller (BMC) system to apply for generating a public key of the national cryptographic algorithm;

[0055] S20: The key center generates a pair of public and private keys of the national cryptographic algorithm corresponding to the identifier of the data sender and the identifier of the data receiver, and sends the public key to the data sender;

[0056] S30: The data sender submits the data to be sent and the public key to the desktop bus daemon;

[0057] S40: The desktop bus daemon processes the data to be sent using the public key through a national cryptography algorithm to generate encrypted transmission data;

[0058] S50: The data receiver submits its own identifier to the key center to apply for obtaining the private key of the national cryptography algorithm paired with the public key;

[0059] S60: After verifying the access permission of the identifier of the data receiver, the key center issues the corresponding private key to the data receiver;

[0060] S70: The data receiver requests the encrypted transmission data from the desktop bus daemon and decrypts it using the private key to obtain the plaintext service data.

[0061] In some embodiments, the key center is used to maintain a key mapping relationship table including the identifier of the data sender, the identifier of the data receiver, the public key of the national cryptography algorithm, and the corresponding private key of the national cryptography algorithm.

[0062] In some embodiments, when generating the public-private key pair in step S20, the key center uses a dynamic key generation algorithm to create an independent public-private key pair for each data sender and data receiver. In a specific embodiment, when generating the public-private key pair, the key center performs the following operations: The data sender submits its own identifier and the identifier of the target receiver to the key center; The key center performs a hash binding on the two identifiers to generate a unique identification code, and based on this identification code, calls the national cryptography SM2 algorithm to generate an independent public-private key pair, and stores the mapping relationship between the public key, private key, and the two identifiers in the key table; When the data receiver requests the private key, the key center verifies that its identifier is consistent with the receiver identifier in the key table and then issues the private key. This solution achieves the following effects through dynamic key binding: Each sender-receiver communication link uses an exclusive key to prevent data leakage caused by key reuse; The private key distribution strictly depends on identifier matching to ensure that unauthorized processes cannot obtain decryption permissions.

[0063] In another alternative embodiment, when generating the public-private key pair, the key center adopts a randomized key derivation strategy, that is, when receiving the public key application request from the data sender, the key center calls a cryptographically secure random number generator to generate a 256-bit random number as the private key seed, calculates the corresponding public key based on the national cryptography SM2 elliptic curve parameters, and binds and stores the public-private key pair with the sender and receiver identifiers. Compared with the hash binding method, this solution ensures the unpredictability of the key through enhanced randomness, effectively resists speculation attacks against identifier patterns, and is also compatible with the standard SM2 key generation interface, facilitating integration into existing BMC security modules.

[0064] In some embodiments, when the desktop bus daemon performs encryption processing in step S40, it only accepts data transmission requests carrying the public key issued by the key center and prohibits the transmission of unencrypted plaintext data.

[0065] In some embodiments, the desktop bus daemon in step S40 only performs the encryption operation on the public key verified by the key center for the data to be sent and rejects external public keys that have not been verified.

[0066] In some embodiments, step S40 specifically includes:

[0067] The desktop bus daemon receives the data to be sent and the public key submitted by the data sender through the desktop bus interface;

[0068] The desktop bus daemon calls the national cryptography algorithm library to perform encryption operations to obtain encrypted transmission data;

[0069] The desktop bus daemon encapsulates the encrypted transmission data into the standard desktop bus protocol format for transmission.

[0070] This technical solution has the following advantages by integrating national cryptography algorithm encryption and protocol encapsulation operations at the desktop bus daemon layer: The encryption process is deeply coupled with the bus protocol stack, enabling encrypted data to directly reuse the message routing and queue management mechanisms of the standard desktop bus, while ensuring security and completely avoiding protocol compatibility issues caused by traditional application-layer encryption (such as DBus message header verification failures or format conflicts); Utilizing the system-level permissions of the daemon to directly call the national cryptography algorithm hardware acceleration engine reduces the CPU computing overhead compared to traditional user-state encryption solutions, especially meeting the real-time encryption requirements of high-concurrency sensor data in the low-power BMC environment.

[0071] In an alternative embodiment, in a non-national cryptography algorithm implementation scenario, AES-GCM (combining encryption and integrity verification) or NIST standard algorithms based on elliptic curves (such as ECDSA+ECDH) can be used to replace the SM2 algorithm, and the same protocol compatibility and performance advantages can still be achieved through the encryption architecture of the daemon layer of this solution.

[0072] In some embodiments, the key center in step S60 performs permission verification by comparing the identifier of the data receiver with the identifiers pre-stored in the key mapping table.

[0073] In some embodiments, the data receiver decrypting the data needs to meet the following conditions simultaneously:

[0074] Holding the valid private key issued by the key center;

[0075] The private key has a key pair binding relationship with the public key used for encrypting the transmitted data;

[0076] The identifier of the data recipient has been registered in the key mapping table of the key center.

[0077] In some embodiments, the above further includes:

[0078] When the desktop bus command line tool displays the transmitted data, the encrypted transmission data based on the national cryptography algorithm is forced to be displayed in ciphertext format, and the original plaintext content is masked.

[0079] Figure 2 It is a flowchart as an example of an embodiment of the present invention. As Figure 2 shown, in this specific example, the working process of a method for implementing secure communication inside BMC based on the national cryptography algorithm DBus includes the following steps:

[0080] S1: The data sender in the BMC system applies to the key center in the BMC system to generate a pair of SM2 public keys according to the data sender's UUID (Universally Unique Identifier), and at the same time reports the UUID of the data recipient that can receive data.

[0081] S2: The key center calls the national cryptography algorithm library to generate a corresponding pair of public and private keys, and the key center transmits the public key to the data sender.

[0082] S3: The data sender reports or uploads the data to be sent and the public key to the desktop bus daemon DBusDaemon.

[0083] S4: DBus Daemon calls the national cryptography algorithm library to encrypt the data to be sent according to the received public key to obtain encrypted data for transmission.

[0084] S5: The data recipient applies to the key center for an accessible private key using its own UUID.

[0085] S6: The data recipient applies to DBus Daemon for the required encrypted data.

[0086] S7: The data recipient decrypts and uses the obtained encrypted data by calling the national cryptography algorithm library according to the private key.

[0087] Furthermore, the above method may further include step S8: When other data requesters other than the target data recipient query data from DBus Daemon using the DBus command line tool, DBus Daemon returns the encrypted data to the data requester, masking the plaintext display of the data.

[0088] In the embodiment of the present invention, a key center is added to the BMC system to uniformly manage the public and private keys of the national cryptographic algorithms, control the permissions to access the public and private keys, and prevent the abuse of the public and private keys.

[0089] In the embodiment of the present invention, in the DBus Daemon, the encryption process of the national cryptographic SM2 algorithm is added. The data sender cannot directly submit plaintext data. After the public key is carried, the DBus Daemon performs encrypted transmission.

[0090] In the embodiment of the present invention, at the DBus command tool layer, the data is displayed in an encrypted form, shielding the scenario of displaying plaintext data.

[0091] In the data receiver in the BMC system of the embodiment of the present invention, the private key permission readable by the key center needs to be satisfied simultaneously, and the data applied to the DBus Daemon is decrypted by the private key.

[0092] The beneficial technical effects of the above technical solutions are as follows:

[0093] For the BMC system adopting the above recording method and software, the data carried and transmitted on the DBus is subject to permission isolation and ciphertext processing through the national cryptographic algorithms.

[0094] Each data sender process in the BMC system can specify the data receiver process. Only the data receiver with the private key can decrypt and use the data. The non-specified data receiver cannot decrypt and use the transmitted BMC data, achieving the effect of permission isolation.

[0095] In the BMC system, the non-data receiver cannot use the traditional DBus command line tool to directly read the plaintext data, and all are displayed in ciphertext, preventing the possibility of illegal intrusion programs directly stealing and maliciously tampering with the BMC service data.

[0096] Embodiment 2

[0097] Figure 3 It is a flowchart of another method for implementing internal secure communication of BMC based on the desktop bus in the embodiment of the present invention. As Figure 3 shown, the method includes the following steps:

[0098] S1’: The data sender and the data receiver respectively apply for their own identifiers to the physical unclonable function of the baseboard management controller BMC chip;

[0099] S2’: The data sender and the data receiver upload their respective identifiers to the BMC secure storage area, and allow the data sender to query the identifier of the data receiver by the program name; in an example, the data sender is called "SendBackPanelInfo", and the data sender can go to the BMC secure storage area to find the identifier of the program called "RecvBackPanelInfo".

[0100] S3’: The data sender submits the identifier of the data sender and the identifier of the data receiver to the key center, requesting to generate a public key.

[0101] S4’: The key center calls the national cryptography algorithm library to generate a key pair including a public key and a private key with a validity period, and stores the key pair and the validity period in the BMC secure storage area.

[0102] S5’: The key center distributes the public key to the data sender.

[0103] S6’: The data sender submits the data to be sent and the public key to the desktop bus daemon process.

[0104] S7’: The desktop bus daemon process calls the national cryptography algorithm library to verify whether the public key is within the validity period. If the public key is within the validity period, it calls the national cryptography algorithm library to encrypt the data to be sent.

[0105] S8’: After the data receiver obtains the encrypted data through the desktop bus daemon process, it applies to the key center for the corresponding private key according to the identifier of the data receiver.

[0106] S9’: The data receiver calls the national cryptography algorithm library to verify whether the private key is within the validity period. If the private key is within the validity period, it calls the national cryptography algorithm library to decrypt the encrypted data to obtain the decrypted data.

[0107] In a further embodiment, the method further includes the following steps:

[0108] The desktop bus daemon process calls the national cryptography algorithm library to verify whether the public key is within the validity period. If the public key is not within the validity period, it notifies the data sender to re-apply to the key center for a public key.

[0109] The data recipient calls the national cryptography algorithm library to verify whether the private key is within the valid period. If the private key is not within the valid period, the national cryptography algorithm library notifies the data recipient that the private key has expired. The data recipient reports the expiration of the private key to the key center. The key center notifies the data sender to reapply for a public key. After receiving the request to reapply for a public key, the key center calls the national cryptography algorithm library to regenerate a new key pair including a public key and a private key with a new valid period, and stores the new key pair and the new valid period in the BMC secure storage area.

[0110] In a further embodiment, the method further includes the following steps: During the key generation and use process, the application, generation, and use of the key are recorded through the BMC system event log.

[0111] In a further embodiment, the BMC secure storage area is used to: store the identifiers of the data sender and the recipient, the generated key pair, and the corresponding validity period information; establish a corresponding query relationship between the program name and the recipient identifier.

[0112] In a further embodiment, the method further includes: when a non-target data recipient requests data through the DBus command-line tool, the desktop bus daemon returns the encrypted data and prohibits plaintext display.

[0113] This embodiment constructs a device identity authentication system based on the unique identifier generated by the BMC chip PUF technology, fundamentally eliminating the risk of identity fraud; through the key center, the whole life cycle management of the national cryptography algorithm key is implemented, and a dynamic validity period control mechanism is adopted to effectively prevent security vulnerabilities caused by long-term exposure of the key; relying on the desktop bus daemon to implement forced encryption and access control at the transport layer, a double verification mechanism (public key validity period verification + national cryptography algorithm library encryption) is used to build a double insurance for transport security during the data encryption stage, and a linkage mechanism of private key validity period verification and key automatic update is implemented during the data decryption stage to form a closed-loop security protection; through the BMC secure storage area, sensitive data is isolated and stored and associated queries with programs are realized, improving the key retrieval efficiency while preventing unauthorized access; the full-process operation audit function of the system event log meets the requirements of the third-level information security protection for security audit, forming a full-link security protection system covering all links of key generation, distribution, use, update, and destruction. Compared with the traditional static key management scheme, this scheme can improve security and reduce the risk of key leakage.

[0114] Figure 4 is a specific flowchart of a method for realizing internal secure communication of BMC based on the desktop bus in an embodiment of the present invention. As Figure 4 shown, the method includes the following steps:

[0115] S11: The PUF (Physical Unclonable Function) in the BMC chip in the data sending direction of the BMC system applies for its own unique UUID.

[0116] S12: The PUF (Physical Unclonable Function) in the BMC chip in the data receiving direction of the BMC system applies for a unique UUID.

[0117] S13: The data sending direction uploads its own UUID to the BMC secure storage area. The data sender can query the UUID of the data receiver in the BMC secure storage area according to the program name.

[0118] S14: The data receiving direction uploads its own UUID to the BMC secure storage area.

[0119] S15: The data sending direction applies to the key center in the BMC system to generate an SM2 public key according to the UUID of the data sender, and at the same time reports the UUID of the data receiver that can receive data.

[0120] S16: The key center applies to the national cryptography algorithm library in the BMC system to generate a public key and a private key with an expiration date.

[0121] S17: The national cryptography algorithm library returns the public key-private key pair and the corresponding expiration date to the key center. The key center stores the public key-private key pair and the corresponding expiration date in the BMC secure storage area.

[0122] S18: The key center passes the public key to the data sender.

[0123] S19: The data sender reports the data to be sent and the public key to the Desktop Bus Daemon (DBus Daemon).

[0124] S20: The DBus Daemon transmits the data to be sent to the national cryptography algorithm library according to the received public key, requests to verify whether the public key is within the expiration date, and requests the BMC national cryptography algorithm library to encrypt the data to be transmitted based on the public key within the expiration date. If the national cryptography algorithm library finds that the public key has expired, it notifies the DBus Daemon that the encryption has failed. Then the DBus Daemon notifies the data sender that the data upload has failed, triggering the data sender to re-apply for a public key from the key center.

[0125] S21: The data receiver applies to the key center for an accessible private key using its own UUID.

[0126] S22: The data receiver applies to the DBus Daemon for the encrypted data required.

[0127] S23: The data recipient requests the national cryptography algorithm library to verify whether the private key is within the valid period, and decrypts the encrypted data using the private key within the valid period. If the national cryptography algorithm library finds that the key has expired, it notifies the data recipient that the private key has expired. The data recipient reports the expired private key to the key center, and the key center notifies the data sender to re-apply for the public key and private key. If the national cryptography algorithm library finds that the key has not expired, it uses the key within the valid period to decrypt the encrypted data to obtain the decrypted data, and returns the decrypted data to the data recipient.

[0128] S24: During the process of the key center applying for the public key and private key, and during the encryption and decryption processes of the national cryptography algorithm library using the public key and private key, the system event log BMC SEL (System Event Log) of the baseboard management controller records security logs for these processes.

[0129] S25: When other data requesters other than the target data recipient query data from the DBus Daemon using the DBus command-line tool, the DBus Daemon returns encrypted data to the data requester, masking the display of plaintext data.

[0130] In the above Figure 3 corresponding embodiment, a key center is added to the BMC system to uniformly manage the public key and private key of the national cryptography algorithm, control the permissions to access the public and private keys, and prevent the abuse of the public and private keys. In the DBus Daemon, the encryption process of the national cryptography SM2 algorithm is added. The data sender cannot directly submit plaintext data. After bringing the public key, the DBus Daemon encrypts and transmits it. At the DBus command tool layer, the data is displayed in encrypted form, masking the scenario of displaying plaintext data. The data recipient in the BMC system needs to simultaneously meet the permission to read the private key of the key center and decrypt the data applied to the DBus Daemon using the private key. During the data transmission process, lifecycle management is carried out on the valid periods of the public key and private key to prevent the risk of leakage of the public key and private key due to reasons such as time. The UUIDs of the data sender and data recipient are generated using the PUF technology of the BMC chip to ensure uniqueness. The UUID, public key, private key, and valid period, etc., are stored in the BMC secure storage area.

[0131] Embodiment III

[0132] Figure 5 is a functional block diagram of a system for implementing secure communication inside the BMC based on the desktop bus in an embodiment of the present invention. As Figure 5 shown, the system includes:

[0133] The key center is deployed in the Baseboard Management Controller (BMC) and is used to receive the self-identifier of the data sender and the identifier of the data recipient, and generate the corresponding public-private key pair of the national cryptography algorithm; and verify the access right of the data recipient identifier and control the distribution of the private key.

[0134] The data sender is configured to submit its own identifier and the identifier of the data recipient to the key center to apply for a public key, and submit the data to be sent and the public key to the Desktop Bus Daemon.

[0135] The Desktop Bus Daemon is configured to perform national cryptography algorithm encryption processing on the data to be sent using the public key to generate encrypted transmission data.

[0136] The data recipient is configured to submit its own identifier to the key center to apply for a private key, request the encrypted transmission data from the Desktop Bus Daemon, and decrypt it using the private key to obtain the plaintext service data.

[0137] In some embodiments, the key center includes:

[0138] The key mapping relationship storage unit is used to store the mapping relationship table containing the data sender identifier, data recipient identifier, public key of the national cryptography algorithm and the corresponding private key.

[0139] The key generation unit is configured to dynamically generate an independent public-private key pair of the national cryptography algorithm according to the identifiers of the data sender and the data recipient.

[0140] In some embodiments, the key generation unit adopts a dynamic key generation algorithm to create a unique public-private key pair for the communication relationship between each data sender and data recipient.

[0141] In some embodiments, the Desktop Bus Daemon includes:

[0142] The public key verification unit is configured to only accept the data sending request carrying the public key signed by the key center.

[0143] The encryption execution unit is configured to call the national cryptography algorithm library to perform encryption operations on the data to be sent and prohibit the transmission of unencrypted plaintext data.

[0144] In some embodiments, the encryption execution unit further includes: a protocol encapsulation unit configured to encapsulate the encrypted data into the standard Desktop Bus protocol format for transmission.

[0145] In some embodiments, the key center further includes: a permission verification unit configured to implement access control by comparing the identifier of the data recipient with the pre-stored identifier in the key mapping relationship table.

[0146] In some embodiments, the data receiver includes a decryption verification unit configured to verify the following conditions during decryption:

[0147] The private key held is a valid private key issued by the key center;

[0148] There is a binding relationship between the private key and the public key used for encrypting the transmission data;

[0149] The data receiver identifier has been registered in the key mapping table.

[0150] In some embodiments, the system further includes a desktop bus command line tool module configured to, when presenting the transmission data, force the transmission data encrypted by the national cryptography algorithm to be displayed in ciphertext format and mask the original plaintext content.

[0151] Through the forced ciphertext display mechanism, this desktop bus command line tool module completely eliminates the risk of sensitive data in the BMC system being exposed in plaintext through the command line tool, effectively preventing malicious users or intrusion programs from directly stealing service data using traditional DBus command line tools (such as dbus-send, dbus-monitor). At the same time, the ciphertext display format (such as Base64 encoding or hexadecimal string) is strictly consistent with the original encrypted data, which not only meets the needs of operation and maintenance personnel to verify the integrity of data transmission but also avoids the leakage of keys or plaintext caused by misoperations, enhancing the anti-attack ability of the BMC system in high-risk scenarios such as penetration testing and remote debugging.

[0152] The working process of this module is as follows: First, by intercepting the data output stream of the command line tool, it captures in real-time the desktop bus data transmission requests initiated by users through tools such as dbus-monitor, and receives the original data packet containing the encryption identification bit and the transmission content; then it enters the processing stage, determines whether the data is encrypted by the national cryptography algorithm by detecting the encryption identification bit, calls the ciphertext conversion function for the encrypted data to convert the binary ciphertext into hexadecimal string format, and synchronously deletes the plaintext copy in the memory. For the unencrypted data, it maintains the standard plaintext protocol format; finally, it outputs the processed ciphertext or plaintext to the command line interface, and at the same time, through the output stream filtering mechanism, ensures that the plaintext content of the encrypted data will not be written into the log file, realizing the shielding of plaintext information in the entire link from data acquisition to display.

[0153] Embodiment 4

[0154] Figure 6 is a functional block diagram of a system for implementing secure internal communication of BMC based on the desktop bus according to an embodiment of the present invention. As Figure 6 shown, the system includes:

[0155] The key center is used to generate a key pair including a public key and a private key with an expiration date by calling the national cryptographic algorithm library according to the identifier of the data sender and the identifier of the data receiver, store the key pair and the expiration date in the BMC secure storage area, and distribute the public key to the data sender;

[0156] The data sender is used to apply for its own identifier from the physical unclonable function module of the BMC chip, and submit the identifier and the public key associated with the data to be sent to the desktop bus daemon process;

[0157] The data receiver is used to apply for its own identifier from the physical unclonable function module of the BMC chip, obtain the encrypted data through the desktop bus daemon process, and apply for the corresponding private key from the key center for decryption;

[0158] The physical unclonable function module of the BMC chip is used to generate the identifiers of the data sender and the data receiver respectively;

[0159] The BMC secure storage area is used to store the identifiers of the data sender and the data receiver respectively, the mapping relationship between the program name and the identifier of the data receiver, and the key pair including the public key and the private key with an expiration date;

[0160] The desktop bus daemon process is used to receive the public key and the data to be sent submitted by the data sender, call the national cryptographic algorithm library to verify the expiration date of the public key, and perform encryption processing on the data to be sent after passing the verification to obtain encrypted data, and transmit the encrypted data to the data receiver;

[0161] The national cryptographic algorithm library is used to generate a key pair including a public key and a private key of the national cryptographic algorithm, verify whether the public key or the private key is within the expiration date, perform data encryption processing on the data to be sent according to the public key after passing the verification, and perform data decryption processing on the encrypted data according to the private key.

[0162] In a further embodiment, the system may further include: a system event log module, which is used to record the operation logs during the key application, key generation, and key usage processes.

[0163] In a further embodiment, the desktop bus daemon process is further used to call the national cryptographic algorithm library to verify whether the public key is within the expiration date, and if the public key is not within the expiration date, notify the data sender to re-apply for the public key from the key center;

[0164] The data receiver is further used to call the national cryptographic algorithm library to verify whether the private key is within the expiration date, and if the private key is not within the expiration date, report to the key center that the private key has expired;

[0165] The key center is further configured to notify the data sender to re - apply for a public key. After receiving the request for re - applying for a public key, the key center calls the national cryptography algorithm library to regenerate a new key pair including a public key and a private key with a new validity period, and stores the new key pair and the new validity period in the BMC secure storage area.

[0166] In a further embodiment, the BMC secure storage area realizes secure storage in the following manner: establish an identifier storage area to store the identifiers of the data sender and the data receiver generated by the physically unclonable function module; construct a key mapping table to associate the program name, the identifier of the data receiver, and the corresponding key pair; set a validity period index to record the effective time and expiration time of each key pair.

[0167] In a further embodiment, the desktop bus daemon is further configured to: when receiving a data query request from a non - target data receiver, only return encrypted data and mask the plain - text display; query the identifier of the target data receiver in the BMC secure storage area according to the program name.

[0168] Those skilled in the art can clearly understand that, for the sake of convenience and brevity of description, only the above - mentioned division of each functional unit and module is used as an example. In actual applications, the above - mentioned functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above - mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in the above - mentioned system can refer to the corresponding process in the foregoing method embodiment and will not be elaborated herein.

[0169] The embodiment of the present invention also provides a computer - readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements any one of the above - mentioned methods for realizing secure communication inside the BMC based on the desktop bus.

[0170] When the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of the present invention, it can also be completed by instructing related hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc. Of course, there are other ways of readable storage media, such as quantum memory, graphene memory, and so on. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice within the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0171] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0172] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutively shown blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0173] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for implementing secure communication inside BMC based on desktop bus, characterized in that It includes the following steps: The data sender submits its own identifier and the identifier of the data receiver to the key center of the baseboard management controller (BMC) system to apply for generating a public key of the national cryptographic algorithm; The key center generates a pair of public and private keys of the national cryptographic algorithm corresponding to the identifier of the data sender and the identifier of the data receiver, and sends the public key to the data sender; The data sender submits the data to be sent and the public key to the desktop bus daemon process; The desktop bus daemon process uses the public key to perform encryption processing on the data to be sent by the national cryptographic algorithm to generate encrypted transmission data; The data receiver submits its own identifier to the key center to apply for obtaining the private key of the national cryptographic algorithm paired with the public key; After verifying the access permission of the identifier of the data receiver, the key center issues the corresponding private key to the data receiver; The data receiver requests the desktop bus daemon process to obtain the encrypted transmission data and uses the private key for decryption processing to obtain the plaintext service data.

2. The method according to claim 1, characterized in that, The key center is used to maintain a key mapping relationship table including the identifier of the data sender, the identifier of the data receiver, the public key of the national cryptographic algorithm, and the corresponding private key of the national cryptographic algorithm.

3. The method according to claim 1, characterized in that When performing encryption processing, the desktop bus daemon process only accepts data sending requests carrying the public key signed by the key center and prohibits the transmission of unencrypted plaintext data; The desktop bus daemon process only performs encryption processing on the data to be sent using the public key verified by the key center and rejects external public keys that have not been verified.

4. The method according to claim 1, wherein The desktop bus daemon process uses the public key to perform encryption processing on the data to be sent by the national cryptographic algorithm to generate encrypted transmission data, specifically including: The desktop bus daemon process receives the data to be sent and the public key submitted by the data sender through the desktop bus interface; The desktop bus daemon process calls the national cryptographic algorithm library to perform encryption operations to obtain encrypted transmission data; The desktop bus daemon encapsulates the encrypted transmission data into the standard desktop bus protocol format for transmission.

5. A method for implementing secure communication inside BMC based on desktop bus, characterized in that The method includes: The data sender and the data receiver respectively apply for their own identifiers to the physical unclonable function of the baseboard management controller (BMC) chip; The data sender and the data receiver upload their respective identifiers to the BMC secure storage area and allow the data sender to query the identifier of the data receiver by the program name; The data sender submits the identifier of the data sender and the identifier of the data receiver to the key center to request the generation of a public key; The key center calls the national cryptographic algorithm library to generate a key pair including a public key and a private key with an expiration date, and stores the key pair and the expiration date in the BMC secure storage area; The key center issues the public key to the data sender; The data sender submits the data to be sent and the public key to the desktop bus daemon process; The desktop bus daemon process calls the national cryptographic algorithm library to verify whether the public key is within the expiration date. If the public key is within the expiration date, the desktop bus daemon process calls the national cryptographic algorithm library to perform encryption processing on the data to be sent; After the data recipient obtains the encrypted data through the desktop bus daemon, it applies for the corresponding private key from the key center according to the identifier of the data recipient; The data recipient calls the national cryptographic algorithm library to verify whether the private key is within the valid period. If the private key is within the valid period, it calls the national cryptographic algorithm library to decrypt the encrypted data to obtain the decrypted data.

6. The method according to claim 5, wherein The method further includes: The desktop bus daemon calls the national cryptographic algorithm library to verify whether the public key is within the valid period. If the public key is not within the valid period, it notifies the data sender to re-apply for the public key from the key center; The data recipient calls the national cryptographic algorithm library to verify whether the private key is within the valid period. If the private key is not within the valid period, the national cryptographic algorithm library informs the data recipient that the private key has expired. The data recipient reports the expiration of the private key to the key center. The key center notifies the data sender to re-apply for the public key. After receiving the request for re-applying for the public key, the key center calls the national cryptographic algorithm library to re-generate a new key pair including the public key and the private key with a new valid period, and stores the new key pair and the new valid period in the BMC secure storage area.

7. The method according to claim 5, wherein The method further includes: During the key generation and usage process, the application, generation, and usage of the key are recorded through the BMC system event log.

8. The method according to claim 5, characterized in that The BMC secure storage area is used for: Storing the identifiers of the data sender and the recipient, the generated key pair, and the corresponding valid period information; Establishing a corresponding query relationship between the program name and the recipient identifier.

9. A system for implementing secure internal communication of BMC based on a desktop bus, characterized in that It includes: A key center, deployed in the baseboard management controller (BMC), for receiving the self-identifier of the data sender and the identifier of the data recipient, and generating a corresponding national cryptographic algorithm public-private key pair; And verifying the access permission of the identifier of the data recipient, and controlling the distribution of the private key; A data sender, configured to submit its own identifier and the identifier of the data recipient to the key center to apply for the public key, and submit the data to be sent and the public key to the desktop bus daemon; A desktop bus daemon, configured to perform national cryptographic algorithm encryption processing on the data to be sent using the public key to generate encrypted transmission data; A data recipient, configured to submit its own identifier to the key center to apply for the private key, request to obtain the encrypted transmission data from the desktop bus daemon, and use the private key for decryption to obtain the plaintext service data.

10. A system for realizing secure communication inside BMC based on desktop bus, characterized in that, The system includes: A key center, for generating a key pair including the public key and the private key with a valid period according to the identifier of the data sender and the identifier of the data recipient, storing the key pair and the valid period in the BMC secure storage area, and issuing the public key to the data sender; A data sender, for applying for its own identifier from the physical unclonable function module of the BMC chip, and submitting the identifier and the data to be sent associated with the public key to the desktop bus daemon; The data receiver is used to apply for its own identifier from the physical unclonable function module of the BMC chip, and after obtaining the encrypted data through the desktop bus daemon, apply for the corresponding private key from the key center and decrypt it. The physical unclonable function module of the BMC chip is used to generate the identifiers of the data sender and the data receiver respectively. The BMC secure storage area is used to store the identifiers of the data sender and the data receiver respectively, the mapping relationship between the program name and the identifier of the data receiver, and the key pair including the public key and the private key with a validity period. The desktop bus daemon is used to receive the public key and the data to be sent submitted by the data sender, call the national cryptography algorithm library to verify the validity period of the public key, and after the verification passes, perform encryption processing on the data to be sent to obtain the encrypted data, and transmit the encrypted data to the data receiver. The national cryptography algorithm library is used to generate the key pair including the public key and the private key of the national cryptography algorithm, verify whether the public key or the private key is within the validity period, perform data encryption processing on the data to be sent according to the public key after the verification passes, and perform data decryption processing on the encrypted data according to the private key.

Citation Information

Patent Citations

  • Data processing method, device and system, electronic equipment and storage medium

    CN113381984A

  • PMU power system communication method based on national cryptographic algorithm

    CN115484033A

  • Key management method, management controller and server

    CN117675184A

  • Intelligent chip special for security of Internet of Things

    CN118174880A

  • System upgrading method, controller and computing device

    CN118295688A