Function authorization method, electronic equipment, program product and storage medium

By generating a license information file based on hardware characteristics in the BMC management controller, and using anti-crack signature algorithm and hardware selection circuit to verify the public key, the problem that traditional signature algorithms are easily cracked is solved, and the security and flexibility of BMC license management are realized.

CN120296771AActive Publication Date: 2025-07-11SHANDONG YINGXIN COMP TECH CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510765111.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-07-11
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

The existing BMC License management technology uses traditional signature algorithms and its security is threatened by new computing technologies, resulting in the functional module being easily unlocked illegally.

Method used

The license information file is generated based on the client hardware feature information. The server uses the anti-crack signature algorithm to generate signature information, and reads the public key from the OTP area of the management controller for verification through the hardware selection circuit to ensure the security and flexibility of the public key.

Benefits of technology

Effectively resist new computing attacks, avoid illegal unlocking of functional modules, and reduce the cost of equipment recall caused by private key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296771A_ABST
    Figure CN120296771A_ABST
Patent Text Reader

Abstract

The invention discloses a function authorization method, electronic equipment, a program product and a storage medium, which are applied to the technical field of security management and applied to a management controller of a client, and the method comprises the following steps: generating a license information file based on hardware feature information of the client; receiving a feedback file of the server; selecting a circuit state of the circuit through hardware, and reading a public key specified by the circuit state from an OTP (One Time Programmable) area of the management controller; verifying the signature information based on the public key, the license information file and a Hash algorithm, and when the verification is passed, importing a feedback file into the to-be-unlocked function module to unlock the function module; the public and private key pair is generated in advance through an anti-cracking signature algorithm; a plurality of public keys are stored in the OTP region. By applying the scheme of the invention, the attack of novel calculation can be effectively resisted, and the function module of the management controller is prevented from being illegally unlocked. And the equipment recall cost caused by leakage of the private key is also reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of security management, and in particular, to a function authorization method, an electronic device, a program product, and a storage medium. Background Art

[0002] As an out-of-band management firmware, the BMC (Board Management Controller) of a server is an important part of the server management system. For some special function modules of the BMC, the BMC manufacturer can perform authorization control through the License management of the BMC. That is, for some function modules of the BMC, after obtaining the authorization from the manufacturer through purchase or other means, the client can obtain the permission to use the function module.

[0003] License management needs to use asymmetric encryption technology to generate digital signatures. That is, the BMC manufacturer uses the private key and encryption technology to generate digital signatures. When the client performs License management, after validating the effectiveness through the corresponding public key, the corresponding function module is unlocked. However, the digital signature algorithms used in the current License technology are usually traditional signature algorithms such as RSA (asymmetric encryption algorithm) and ECDSA (Elliptic Curve Digital Signature Algorithm). With the rapid development of new computing technologies with faster computing speeds, the security of traditional signature algorithms such as RSA and ECDSA is gradually threatened. Once the algorithm is cracked, the existing digital signatures can be easily cracked, making the License protection ineffective, and the client can obtain authorization without the BMC manufacturer.

[0004] In summary, how to ensure the security of the License management of the BMC to avoid the illegal unlocking of the function modules of the BMC is a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention

[0005] This application provides a function authorization method, an electronic device, a program product, and a storage medium to ensure the security of the License management of the BMC and avoid the illegal unlocking of the function modules of the BMC.

[0006] To solve the above technical problems, the present invention provides the following technical solutions: This application provides a function authorization method, which is applied to the management controller of the client and includes: Generating a license information file for applying for functions to the server based on the hardware feature information of the client itself; Receive the feedback file from the server; wherein, the feedback file carries the license information file, the signature information obtained by the server digitally signing the license information file with a private key, and the hash algorithm used by the server for digital signature; Read, from the one-time programmable area of the management controller itself, the public key specified by the circuit state through the circuit state of the hardware selection circuit; wherein, the hardware selection circuit is a hardware selection circuit for public key selection; Verify the signature information based on the public key, the license information file, and the hash algorithm. When the verification passes, import the feedback file into the function module to be unlocked to unlock the function module; Wherein, the private key and the public key are a pair of public and private keys pre-generated by an anti-cracking signature algorithm; multiple public keys are stored in the one-time programmable area.

[0007] This application also provides a function authorization method, which is applied to the server and includes: Receive the license information file sent by the client; wherein, the license information file is a license information file generated by the management controller of the client based on the hardware feature information of the client itself for function application to the server; The signature information obtained by digitally signing the license information file with a private key; Generate a feedback file carrying the license information file, the signature information, and the hash algorithm used for digital signature; Send the feedback file to the client, so that the management controller of the client reads, through the circuit state of the hardware selection circuit, the public key specified by the circuit state from the one-time programmable area of the management controller itself, and verifies the signature information based on the public key, the license information file, and the hash algorithm. When the verification passes, import the feedback file into the function module to be unlocked to unlock the function module; Wherein, the hardware selection circuit is a hardware selection circuit for public key selection; the private key and the public key are a pair of public and private keys pre-generated by an anti-cracking signature algorithm; multiple public keys are stored in the one-time programmable area.

[0008] This application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the function authorization method as described above.

[0009] This application also provides an electronic device, including: A memory for storing a computer program; A processor, which is used to implement the steps of the function authorization method as described above when executing the computer program.

[0010] The present application also provides a computer-readable storage medium, in which a computer program is stored. Wherein, when the computer program is executed by a processor, the steps of the function authorization method as described above are implemented.

[0011] In the solution of the present application, the server generates a public-private key pair through a special anti-cracking signature algorithm, so that the digital signature generated by such a private key can effectively resist the attacks of new types of computing and is difficult to be cracked. Therefore, it can effectively prevent the function modules of the management controller from being illegally unlocked. Specifically, the management controller of the client needs to generate a license information file for applying for functions to the server based on the hardware feature information of the client itself. After the server obtains the license information file, it can digitally sign the license information file through the private key to obtain the signature information, and needs to feedback a file carrying the license information file, the signature information and the hash algorithm used for digital signature to the client. It can be understood that, under normal circumstances, the client can verify the signature information based on the public key, the license information file and the hash algorithm, and after the verification passes, it can import the feedback file into the function module to be unlocked to unlock the function module. On the contrary, if the verification fails, the process will end and the function module cannot be unlocked. In addition, it should be noted that the public key is stored in the one-time programmable area of the management controller itself, and the public key cannot be modified after the management controller leaves the factory, so it is also beneficial to ensure the security of the public key. Further, in the process of function authorization, the client needs to read the public key specified by the circuit state from its own one-time programmable area through the circuit state of the hardware selection circuit, and there are multiple public keys stored in the one-time programmable area. Such a design can flexibly and effectively implement the change of the public-private key pair used. For example, when the currently used private key is leaked, the manufacturer can discard the leaked private key and enable a new private key, and notify the user to adjust the circuit state of the hardware selection circuit accordingly, so that the client can change the public key used. This process does not require the client to be returned to the factory, effectively reducing the equipment recall cost caused by the leakage of the private key.

[0012] In summary, the solution of the present application can effectively ensure the security of the public-private key pair, resist the attacks of new types of computing, and is therefore beneficial to preventing the function modules of the management controller from being illegally unlocked. In addition, it effectively reduces the equipment recall cost caused by the leakage of the private key. Description of the Drawings

[0013] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0014] Figure 1 The flowchart of the function authorization method provided by a specific embodiment of the present invention when applied to the client. Figure 2 The schematic diagram of the public key stored in the OTP area of the management controller in a specific embodiment of the present invention. Figure 3 The flowchart of the function authorization method provided by a specific embodiment of the present invention when applied to the server. Figure 4 The schematic diagram of the structure of an electronic device according to the present invention. Figure 5 The schematic diagram of the structure of a computer-readable storage medium according to the present invention. Specific embodiments

[0015] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.

[0016] It should be noted that in the description of the present application, the terms "including", "comprising" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0017] To enable those skilled in the art of the present technology to better understand the solution of the present application, the following will further elaborate on the present application in conjunction with the drawings and specific embodiments.

[0018] Please refer to Figure 1 , Figure 1 The flowchart of the function authorization method provided by a specific embodiment of the present invention. This function authorization method can be applied to the management controller of the client and includes the following steps: Step S101: Generate a license information file for applying for functions to the server based on the hardware feature information of the client itself.

[0019] Specifically, the management controller of the client can generally be a BMC (Baseboard Management Controller). The management controller can generate a license information file for applying for functions to the server based on the hardware feature information of the client itself, that is, generate a License information file.

[0020] When generating the license information file based on the hardware feature information of the client itself, the specific hardware features included can be set and adjusted according to actual needs. For example, it can include the model of the BMC, the model of the server managed by the BMC (that is, the client model), and hardware information such as CPU parameters, memory parameters, and hard disk parameters in the server managed by the BMC.

[0021] Furthermore, in a specific embodiment of the present invention, the hardware feature information needs to include the Product ID (Product ID) of the client, that is, the unique product number of the client, so that the manufacturer can determine which specific factory device is currently applying for the functions of its management controller, thereby ensuring security. For example, the manufacturer can check whether the Product ID is a product of its own factory. In addition, it can be understood that the format of the license information file and its specific content can be set and adjusted by the manufacturer according to actual needs, so that after the client is sold, when performing function authorization, a license information file required by the manufacturer can be generated and sent to the server. For example, in actual applications, in addition to the hardware feature information of the client itself, the license information file usually can also carry relevant information about the function module to be unlocked, such as the name and version number of the function module.

[0022] Step S102: Receive the feedback file from the server; wherein, the feedback file carries the license information file, the signature information obtained by the server digitally signing the license information file with a private key, and the hash algorithm used by the server for digital signature.

[0023] The server can be a device such as a server set by the manufacturer for implementing authorization management, as long as it can meet the functional requirements of the server in the present application solution. After receiving the license information file sent by the client, the server needs to generate a feedback file for the license information file and then send the feedback file to the client. The generation process of the feedback file needs to be implemented by the server based on the private key.

[0024] Specifically, for example, a dedicated anti-cracking signature key generation platform can be used to pre-generate multiple groups of public-private key pairs through an anti-cracking signature algorithm. Of course, during a normal function authorization process, only one group of public-private key pairs needs to be used. The anti-cracking signature algorithm is a signature algorithm that can effectively resist new types of computational attacks. The specific algorithm can be selected according to needs, but the selected anti-cracking signature algorithm and its parameters should meet security requirements. For example, the LMS (Leighton-Micali Signature) algorithm can be specifically selected. The LMS algorithm is a hash-based anti-cracking signature algorithm that uses a cryptographic hash function to generate and verify signatures. Even for new types of computations, it is very difficult to crack the cryptographic hash function. Therefore, the LMS algorithm is an anti-cracking signature algorithm that can provide strong security and effectively resist attacks from new types of computations.

[0025] After pre-generating multiple groups of public-private key pairs through the anti-cracking signature algorithm, for these private keys, the manufacturer needs to store them securely. For example, in a specific implementation, the private key is the private key stored in a cryptographic machine. That is to say, for each private key generated by the anti-cracking signature algorithm, it is stored in the cryptographic machine. A cryptographic machine is a device that can securely store private keys, and unauthorized personnel cannot obtain the private keys from it, which can effectively prevent illegal personnel from stealing private keys from the manufacturer. For each public key generated by the anti-cracking signature algorithm, it needs to be stored in the OTP (One Time Programmable) area of the management controller before the management controller leaves the factory. For example, in one case, the public key can be directly transferred from the anti-cracking signature key generation platform to the BMC production system for secure storage, and this process does not involve manual operation, thus ensuring the security of the public key.

[0026] Taking a group of public-private key pairs consisting of private key A and public key A as an example, after the server receives the license information file sent by the client, according to the principle of digital signature, the server needs to perform a hash calculation on the license information file to obtain a hash calculation result. Then the server retrieves private key A from the cryptographic machine, and then encrypts the hash calculation result with private key A. The result obtained is the signature information obtained after the server digitally signs the license information file with private key A. Subsequently, the client needs to use public key A for verification.

[0027] After the server obtains the signature information, it is necessary to generate a feedback file by using the signature information, together with the license information file and the hash algorithm used for digital signature. It can be understood that the specific format of the feedback file can be preset in advance, but it should include the license information file, the signature information obtained after the server digitally signs the license information file with the private key, and the hash algorithm used by the server for digital signature, so that the client can verify based on this and then unlock the function.

[0028] Step S103: Read the public key specified by the circuit state from the one-time programmable area of the management controller itself through the circuit state of the hardware selection circuit. The hardware selection circuit is a hardware selection circuit used for public key selection.

[0029] Multiple public keys are stored in the one-time programmable area of the management controller itself. Which public key should be specifically used currently depends on the circuit state of the hardware selection circuit. Of course, the manufacturer should inform the customer how to set the circuit state of the hardware selection circuit currently, so that after the management controller of the client detects the circuit state of its own hardware selection circuit, it can read the correct public key required currently from the one-time programmable area of the management controller itself.

[0030] The specific structure of the hardware selection circuit can be set according to actual needs. As long as it can change the circuit state under user operation and can be detected by the management controller, the purpose of public key selection can be achieved. That is to say, the hardware selection circuit, as a hardware selection circuit for public key selection, is equivalent to providing an external communication interface for the control of the management controller, so that users can replace the public key by operating the hardware selection circuit.

[0031] For example, in a specific embodiment of the present invention, the hardware selection circuit is a DIP switch type hardware selection circuit, so as to conveniently adjust the circuit state of the hardware selection circuit through the DIP switch of the hardware selection circuit.

[0032] In this embodiment, the hardware selection circuit is a DIP switch type hardware selection circuit, which has a simple structure and high reliability. The required hardware selection circuit can be realized through DIP switches and related resistors. For example, in a certain scenario, there are 4 public keys stored in the one-time programmable area of the management controller itself. Then, the DIP switch type hardware selection circuit needs to provide 4 DIP switches for users to operate, so that the hardware selection circuit has a total of 4 circuit states. For example, in a certain scenario, the user toggles DIP switch 1 among the 4 DIP switches to ON, and DIP switches 2, 3, and 4 are toggled to OFF. Then, pin 1 of the management controller is at a high level (controlled by DIP switch 1), and pins 2 to 4 are at low levels (controlled by DIP switches 2, 3, and 4 in sequence). The management controller can determine the current circuit state of the hardware selection circuit, and then read the public key specified by this circuit state from the OTP area. This public key is the public key corresponding to DIP switch 1, that is, the state of DIP switch 1 is equivalent to the control bit of this public key, determining whether to use this public key currently.

[0033] In addition, it should be noted that in some scenarios, if the public key to be used needs to be switched, the management controller needs to be restarted. This is because in some scenarios, the management controller will detect the circuit state of the hardware selection circuit only during the startup phase, and will no longer update the circuit state of the hardware selection circuit after startup is completed.

[0034] In a specific embodiment of the present invention, the DIP switches of the hardware selection circuit are hardware interlocked DIP switches, so that at most one DIP switch is in a triggered state at the same time.

[0035] Among them, there are multiple DIP switches in the hardware selection circuit. When any one DIP switch is in a triggered state, the remaining DIP switches are all in a non-triggered state.

[0036] This embodiment takes into account that in some cases, the customer may accidentally operate the DIP switches of the hardware selection circuit. Therefore, the DIP switches of the hardware selection circuit are set as hardware interlocked DIP switches, so that at most one DIP switch is in a triggered state at the same time, which can effectively reduce the probability of accidental operation.

[0037] Still taking the case where the DIP switch type hardware selection circuit described above provides 4 DIP switches for users to operate as an example. For example, in one case, if a hardware interlocked DIP switch is not used and the user toggles both DIP switch 1 and DIP switch 2 among the 4 DIP switches to ON, errors may occur in the subsequent process of determining the circuit state of the hardware selection circuit. However, if a hardware interlocked DIP switch is used, the user can at most toggle 1 DIP switch among the 4 DIP switches to ON, effectively reducing the probability of misoperation. In this example, the DIP switch is in the triggered state when toggled to ON. Correspondingly, the DIP switch is in the non-triggered state when toggled to OFF. Another example is that in one case, the user needs to toggle DIP switch 1 among the 4 DIP switches to ON and DIP switches 2, 3, and 4 to OFF. Subsequently, for example, if the user's arm accidentally touches DIP switch 3 and toggles DIP switch 3 to ON, at this time, due to the hardware interlock structure, DIP switch 1 that was toggled to ON before will be switched to OFF, making it easier for the user to discover this situation. Then, the user can re-toggle DIP switch 1 back to ON, causing DIP switch 3 to switch back to OFF.

[0038] In a specific embodiment of the present invention, step S103 may specifically include: When the circuit state of the hardware selection circuit is the i-th state, read the public key pre-stored in the i-th storage block from the i-th storage block in the one-time programmable area of the management controller itself. Among them, there are multiple storage blocks in the one-time programmable area of the management controller itself, and i is a positive integer.

[0039] This embodiment takes into account that multiple public keys need to be stored in the OTP area of the management controller. For the convenience of management and distinction, they can be stored in different storage blocks in the OTP area respectively. Refer to Figure 2 , which is a schematic diagram of the public keys stored in the OTP area of the management controller in a specific embodiment. In the example of Figure 2 , the OTP area of the management controller stores 4 different public keys through 4 different storage blocks, which are respectively denoted as public key A, public key B, public key C, and public key D.

[0040] In this embodiment, when the circuit state of the hardware selection circuit is the i-th state, the public key pre-stored in the i-th storage block can be read from the i-th storage block in the OTP area of the management controller. It can be seen that this embodiment effectively realizes the correspondence between different public keys and different circuit states of the hardware selection circuit, and the correspondence is simple, convenient, easy to implement, and not prone to errors.

[0041] In a specific embodiment of the present invention, reading the public key specified by the circuit state from the one-time programmable area of the management controller itself through the circuit state of the hardware selection circuit includes: Detect the level states of each specified pin in sequence according to the set order; When the level state of the i-th pin is detected to be the set state, determine that the circuit state of the hardware selection circuit is the i-th state; When the circuit state of the hardware selection circuit is the i-th state, read the public key pre-stored in the i-th storage block from the one-time programmable area of the management controller itself.

[0042] This implementation mode takes into account that, under normal circumstances, for the level states of each specified pin, only the level state of 1 pin will be the set state. For example, the set state is the high level state. In some special cases, due to reasons such as circuit interference, it may occur that the level states of multiple pins are all the set state. In order to effectively cope with such a situation, in this implementation mode, the level states of each specified pin will be detected in sequence according to the set order. Once the level state of a certain pin is detected to be the set state, it is not necessary to detect the subsequent pins. Based on the current pin, the circuit state of the hardware selection circuit can be directly determined. That is, when the current pin is the i-th pin, the circuit state of the hardware selection circuit can be directly determined to be the i-th state without continuing to detect the remaining pins. After determining that the circuit state of the hardware selection circuit is the i-th state, the public key pre-stored in the i-th storage block can be read from the one-time programmable area of the management controller itself.

[0043] Step S104: Verify the signature information based on the public key, the license information file, and the hash algorithm. When the verification passes, import the feedback file into the function module to be unlocked to unlock the function module.

[0044] After reading the public key specified by the circuit state from the OTP area of the management controller through the circuit state of the hardware selection circuit, the signature information in the feedback file can be verified based on this public key, combined with the license information file and the hash algorithm in the feedback file.

[0045] Under normal circumstances, the public key read from the OTP area of the management controller is the current correct public key and can be successfully verified. The verification process is the general digital signature verification process. Specifically, the signature information can be decrypted with the public key, and the obtained hash value is called the first hash value, for example. And, through the hash algorithm provided in the feedback file, the license information file is hashed, and the obtained hash value is called the second hash value, for example. If the first hash value and the second hash value are the same, it can be determined that the verification passes; otherwise, it can be determined that the verification fails.

[0046] When the verification passes, the management controller of the client can determine that it has obtained the authorization from the manufacturer, and then import the feedback file into the function module to be unlocked, thereby unlocking the function module. Correspondingly, if the verification fails, the management controller will end the process, which makes the function module to be unlocked unable to be unlocked. In addition, in some cases, when the verification fails, operations such as logging and reporting signature failure can also be performed.

[0047] In a specific embodiment of the present invention, reading the public key pre-stored in the i-th storage block from the one-time programmable area of the management controller itself may specifically include: Obtaining the activation flag bit of the i-th storage block in the one-time programmable area of the management controller itself; When the activation flag bit is the first value indicating the unactivated state, changing the activation flag bit to the second value indicating the activated state, and reading the public key pre-stored in the i-th storage block; When the activation flag bit is the second value indicating the activated state, reading the public key pre-stored in the i-th storage block; Wherein, only when the activation flag bit of the i-th storage block is the second value, is it allowed to read the public key in the i-th storage block.

[0048] This embodiment takes into account that when reading the public key specified by the circuit state from the OTP area of the management controller itself according to the circuit state of the hardware selection circuit, the selection of the public key can be specifically implemented through the activation flag bit.

[0049] Specifically, still taking Figure 2 as an example, the OTP area of the management controller stores 4 different public keys in 4 different storage blocks, which are respectively denoted as public key A, public key B, public key C, and public key D, and each of these 4 different storage blocks has its own activation flag bit. The role of the activation flag bit is to indicate whether the public key in the corresponding storage block needs to be used. The activation flag bit cannot be directly modified by the user, but the value of the activation flag bit can be changed by adjusting the values in the relevant registers through the underlying code, that is, the value of the activation flag bit can be changed according to the description of the embodiment of the present application according to certain rules.

[0050] At the time of factory shipment, the activation flag bits of each storage block are all the first value to indicate that the public keys of each storage block are in the unactivated state. For example Figure 2 in the specific example, the activation flag bits of each storage block are all the first value, and the first value is specifically 0x00.

[0051] For example, in one of the above scenarios, the user toggles the DIP switch 1 among the 4 DIP switches to ON, and toggles the remaining 3 DIP switches to OFF, making the pin 1 of the management controller at high level and the pins 2 to 4 at low level. Then the management controller can determine that the current circuit state of the hardware selection circuit is the first state, that is, it determines that the activation flag bit of the first memory block should be read from the OTP area at present. For example, if the activation flag bit of the first memory block read is the first value 0x00, then at this time, the activation flag bit needs to be changed to the second value indicating the activated state, and then the public key pre-stored in the first memory block is read, that is, read Figure 2 the public key A in. The specific value of the second value indicating the activated state can be set as needed. For example, in one scenario, the second value is specifically 0x01.

[0052] In practical applications, changing the activation flag bit of a certain memory block from the first value to the second value indicating the activated state usually occurs when the public key corresponding to the activation flag bit is used for the first time. In the above example, after changing the activation flag bit of the first memory block to the second value 0x01 indicating the activated state, the public key A pre-stored in the first memory block can be read.

[0053] Another example is that the management controller can determine that the current circuit state of the hardware selection circuit is the first state, that is, it determines that the activation flag bit of the first memory block should be read from the OTP area at present. And for example, the activation flag bit of the first memory block is already the second value 0x01 indicating the activated state, then at this time, there is no need to change the value of the activation flag bit, and the public key A pre-stored in the first memory block can be directly read. The activation flag bit is already the second value indicating the activated state, which usually occurs when the public key corresponding to the activation flag bit is not used for the first time.

[0054] In addition, it can be understood that for any memory block, only when the activation flag bit of the memory block is the second value, the public key in the memory block is allowed to be read at this time, otherwise, through code setting, the subsequent process cannot be carried out.

[0055] In a specific embodiment of the present invention, when the activation flag bit is the first value indicating the unactivated state, after changing the activation flag bit to the second value indicating the activated state, it may further include: Taking the public key used for the previous function authorization as the invalid public key; Changing the activation flag bit of the memory block storing the invalid public key to the third value indicating the invalid state.

[0056] After changing the activation flag bit corresponding to a certain public key from the first value indicating the unactivated state to the second value indicating the activated state, it means that the currently used public key is this one. For example, in the above example, the activation flag bit of the first storage block is changed from the first value 0x00 to the second value 0x01 to use public key A during this function authorization.

[0057] Furthermore, this implementation mode takes into account that when such a situation occurs, it means that the management controller either conducts function authorization for the first time, that is, uses the public key for the first time, or the previously used public key has become invalid. It can be understood that if it is the first time to use the public key, there is no public key used during the previous function authorization, so it can be ignored. If there is a public key used during the previous function authorization, then at this time, the public key used during the previous function authorization needs to be used as the invalid public key, and then the activation flag bit of the storage block storing the invalid public key is changed to the third value indicating the invalid state to indicate that the invalid public key has become invalid and cannot be used anymore.

[0058] Still taking Figure 2 as an example, for example, the management controller conducts function authorization for the first time, and the user, according to the manufacturer's requirements, makes the circuit state of the hardware selection circuit be the first state by operating the DIP switch, so that the management controller reads public key A from the first storage block in its own OTP area to complete this function authorization based on public key A. Subsequently, for example, the manufacturer discovers that both private key A and private key B are leaked and need to be discarded, then the corresponding public key A and public key B should also be abandoned. For example, when the manufacturer selects private key C and public key C as the public-private key pair for implementing function authorization at this time, when the management controller needs to conduct function authorization subsequently, the user needs to make the circuit state of the hardware selection circuit be the third state by operating the DIP switch, so that during the verification process of function authorization, the management controller can read public key C in the third storage block to complete the verification. And it can be seen that if public key C needs to be selected, the management controller needs to change the activation flag bit of the third storage block from the first value 0x00 to the second value 0x01 to use public key C during this function authorization. In this example, there is a public key used during the previous function authorization, that is, public key A, then public key A needs to be used as the invalid public key, and the activation flag bit of the first storage block storing public key A is changed to the third value indicating the invalid state. For example, in one case, the third value is specifically 0xFF.

[0059] It can be seen that in this implementation mode, when there is a replacement of the used public key, since the old public-private key pair will no longer be used, in this implementation mode, the activation flag bit of the storage block storing the invalid public key will be changed to the third value indicating the invalid state to further ensure security and is conducive to avoiding illegal unlocking of the function module.

[0060] In a specific embodiment of the present invention, it may further include: After obtaining the activation flag bit of the i-th storage block in the one-time programmable area of the management controller itself, when the activation flag bit is the third value indicating the invalid state, end the current function authorization process.

[0061] As can be seen from the above description, for any storage block, the activation flag bit of this storage block may be the first value, the second value, or the third value. And this embodiment further considers that if, after obtaining the activation flag bit of the i-th storage block in the one-time programmable area of the management controller itself, it is found that the activation flag bit is the third value indicating the invalid state, it can be immediately determined that the function authorization fails. Therefore, at this time, the public key cannot be successfully obtained to verify the feedback file, and the current function authorization process can be directly ended to further ensure security and is conducive to avoiding the illegal unlocking of the function module.

[0062] In practical applications, such a situation may be caused by the user attempting to unlock illegally or by the user incorrectly setting the circuit state of the hardware selection circuit. Therefore, in some cases, after ending the current function authorization process, relevant prompt information can be output so that the user can check whether the circuit state of the hardware selection circuit is set correctly.

[0063] In a specific embodiment of the present invention, it may further include: When the circuit state of the hardware selection circuit is the i-th state, obtain the index value stored in the i-th storage block in the one-time programmable area of the management controller itself; Judge whether the index value is i; If it is, perform the operation of reading the public key pre-stored in the i-th storage block from the i-th storage block in the one-time programmable area of the management controller itself; If not, end the current function authorization process.

[0064] In this embodiment, each storage block stores the index value of this storage block, which serves as the number of the public key. For example Figure 2 in the embodiment of

[0065] For example, in a certain scenario, the user toggles the DIP switch 2 among the 4 DIP switches to ON, and toggles the remaining 3 DIP switches to OFF, so that the circuit state of the hardware selection circuit is the second state. After the management controller determines the circuit state of the hardware selection circuit, it can obtain the index value stored in the second storage block of its own OTP area. Under normal circumstances, the stored index value 2 can be successfully read from the second storage block. That is, the value of the index value is normally consistent with the state number of the circuit state. Then, subsequent operations can be normally executed, that is, the operation of reading the public key pre-stored in the i-th storage block from the one-time programmable area of the management controller itself described in step S103 is executed. In a small number of cases, due to factors such as circuit errors and signal interference, the determined circuit state i of the hardware selection circuit may be inconsistent with the index value stored in the i-th storage block. At this time, to ensure reliability and avoid illegal unlocking of the function module, the current function authorization process can be directly terminated.

[0066] In a specific scenario, the set pseudocode can be: void activate_key(uint8_t new_index) {if (read_jumper() == new_index) {if (otp_block[new_index].active ==0) {otp_block[current_index].active = 0xFF; otp_block[new_index].active =0x01; current_index = new_index;}}. Among them, read_jumper is the circuit state of the hardware selection circuit, and new_index is the index value stored in the i-th storage block. Therefore, the function of if (read_jumper() == new_index) is to detect whether the circuit state of the hardware selection circuit matches the index value stored in the i-th storage block. The function of if (otp_block[new_index].active == 0) is to check whether the activation flag bit of the i-th storage block indicates the unactivated state. The function of otp_block[current_index].active=0xFF is to invalidate the old key, and the function of otp_block[new_index].active = 0x01 is to activate the new key.

[0067] In a specific embodiment of the present invention, the hardware selection circuit is arranged inside the chassis so that the circuit state of the hardware selection circuit can be adjusted only after the chassis is opened.

[0068] This implementation mode takes into account that the hardware selection circuit requires user operation to determine its circuit state, which in turn affects the public key used. To ensure security and reduce the probability of accidental touch, in this implementation mode, the hardware selection circuit will be set inside the chassis so that only authorized personnel can access it by disassembling the chassis, that is, the circuit state of the hardware selection circuit can be adjusted only after the chassis is opened, which is simple and safe to operate. Further, in a specific implementation mode of the present invention, after detecting that the chassis is opened, an alarm can also be issued and a log can be recorded for auditing, which can further improve security.

[0069] In a specific implementation mode of the present invention, the anti-cracking signature algorithm used includes a variety of different anti-cracking signature algorithms, so that the multiple public keys stored in the one-time programmable area are public keys generated from a variety of different anti-cracking signature algorithms.

[0070] This implementation mode takes into account that multiple public keys need to be stored in the OTP area of the management controller. These public keys can be from the same anti-cracking signature algorithm or from a variety of different anti-cracking signature algorithms, and the latter implementation mode has higher reliability and is conducive to flexibly meeting user needs. For example, in a certain scenario, the public key A in the OTP area is specifically a public key generated based on the LMS algorithm, the public key B is specifically a public key generated based on the XMSS algorithm, and the public key C is specifically a public key generated based on the Crystal-Dilithum algorithm. For example, after a certain management controller is sold to user 1, user 1 believes that the security of the public-private key pair generated by the LMS algorithm is higher, that is, user 1's preference is the LMS algorithm. Then, when authorizing the functions of user 1's management controller, the manufacturer can meet user 1's needs and use the private key in the public-private key pair generated by the LMS algorithm to perform numerical signature on the license information file, so that user 1 can complete the verification based on the corresponding public key. Similarly, for example, after a certain management controller is sold to user 2, user 2 believes that the security of the public-private key pair generated by the XMSS algorithm is higher, that is, user 2's preference is the XMSS algorithm. Then, when authorizing the functions of user 2's management controller, the manufacturer can meet user 2's needs and use the private key in the public-private key pair generated by the XMSS algorithm to perform numerical signature on the license information file, so that user 2 can complete the verification based on the corresponding public key.

[0071] It can be seen that since multiple public keys are stored in the OTP area and are public keys generated from a variety of different anti-cracking signature algorithms, the compatibility of the solution of the present application is strong, which is conducive to flexibly meeting the needs of different users, adapting to multi-algorithm scenarios, and eliminating the need to recall the management controller.

[0072] In the solution of this application, the server generates a public-private key pair through a dedicated anti-cracking signature algorithm, so that the digital signature generated by such a private key can effectively resist the attacks of new types of computing and is difficult to be cracked. Therefore, it can effectively prevent the functional modules of the management controller from being illegally unlocked. Specifically, the management controller of the client needs to generate a license information file for applying for functions to the server based on the hardware characteristic information of the client itself. After the server obtains the license information file, it can digitally sign the license information file with the private key to obtain the signature information, and needs to feedback a feedback file carrying the license information file, the signature information, and the hash algorithm used for digital signature to the client. It can be understood that under normal circumstances, the client can verify the signature information based on the public key, the license information file, and the hash algorithm, and after the verification passes, it can import the feedback file into the functional module to be unlocked to unlock the functional module. Conversely, if the verification fails, the process will end and the functional module cannot be unlocked. In addition, it should be noted that the public key is stored in the one-time programmable area of the management controller itself, and the public key cannot be modified after the management controller leaves the factory, so it is also beneficial to ensure the security of the public key. Further, in the process of function authorization, the client needs to read the public key specified by the circuit state from its own one-time programmable area through the circuit state of the hardware selection circuit, and there are multiple public keys stored in the one-time programmable area. Such a design can flexibly and effectively implement the change of the public-private key pair used. For example, when the currently used private key is leaked, the manufacturer can discard the leaked private key and enable a new private key, and notify the user to adjust the circuit state of the hardware selection circuit accordingly, so that the client can change the public key used. This process does not require the client to be returned to the factory, effectively reducing the device recall cost caused by private key leakage.

[0073] In summary, the solution of this application can effectively ensure the security of the public-private key pair, resist the attacks of new types of computing, and is therefore beneficial to preventing the functional modules of the management controller from being illegally unlocked. In addition, it effectively reduces the device recall cost caused by private key leakage.

[0074] For reference, Figure 3 , the present invention also provides a function authorization method, which can be applied to the server and includes the following steps: Step S301: Receive the license information file sent by the client; wherein, the license information file is a license information file generated by the management controller of the client based on the hardware characteristic information of the client itself for applying for functions to the server; Step S302: The signature information obtained after digitally signing the license information file with the private key.

[0075] Step S303: Generate a feedback file carrying the license information file, the signature information, and the hash algorithm used for digital signature.

[0076] Step S304: Send the feedback file to the client, so that the management controller of the client reads the public key specified by the circuit state from its own one-time programmable area through the circuit state of the hardware selection circuit, and verifies the signature information based on the public key, the license information file, and the hash algorithm. When the verification passes, import the feedback file into the function module to be unlocked to unlock the function module.

[0077] Among them, the hardware selection circuit is a hardware selection circuit for public key selection. The private key and the public key are a set of public-private key pairs pre-generated by the server through an anti-cracking signature algorithm; multiple public keys are stored in the one-time programmable area.

[0078] Corresponding to the above method embodiments, the embodiments of the present invention also provide an electronic device, a computer-readable storage medium, and a computer program product, which can be correspondingly referred to above.

[0079] See Figure 4 As shown, the electronic device may include: A memory 401 for storing computer programs; A processor 402 for executing the computer program to implement the steps of the function authorization method in any of the above embodiments.

[0080] The computer program product includes a computer program, and when the computer program is executed by the processor, it implements the steps of the function authorization method in any of the above embodiments.

[0081] Refer to Figure 5 , a computer program 51 is stored on the computer-readable storage medium 50, and when the computer program 51 is executed by the processor, it implements the steps of the function authorization method in any of the above embodiments. The computer-readable storage medium 50 mentioned here includes RAM (Random Access Memory), memory, ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), registers, hard disks, removable disks, or any other form of storage medium well-known in the technical field.

[0082] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0083] The above has introduced in detail a function authorization method, an electronic device, a program product, and a storage medium provided by this application. Specific examples are used herein to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of this application.

Claims

1. A function authorization method, characterized in that, A management controller applied to a client, including: Generating a license information file for applying for functions to a server based on the hardware feature information of the client itself; Receiving the feedback file from the server; wherein, the feedback file carries the license information file, the signature information obtained after the server digitally signs the license information file with a private key, and the hash algorithm used by the server for digital signature; Reading the public key specified by the circuit state from the one-time programmable area of the management controller itself through the circuit state of the hardware selection circuit; wherein, the hardware selection circuit is a hardware selection circuit for public key selection; Verifying the signature information based on the public key, the license information file, and the hash algorithm, and when the verification passes, importing the feedback file into the function module to be unlocked to unlock the function module; Wherein, the private key and the public key are a pair of public and private keys pre-generated by an anti-cracking signature algorithm; multiple public keys are stored in the one-time programmable area.

2. The functional authorization method according to claim 1, wherein The hardware selection circuit is a DIP switch type hardware selection circuit to adjust the circuit state of the hardware selection circuit through the DIP switch of the hardware selection circuit.

3. The functional authorization method according to claim 2, wherein The DIP switch of the hardware selection circuit is a hardware interlocked DIP switch so that at most a single DIP switch is in the triggered state at the same time; Wherein, the DIP switch of the hardware selection circuit includes multiple ones, and when any one DIP switch is in the triggered state, the remaining DIP switches are all in the non-triggered state.

4. The function authorization method according to claim 1, wherein Reading the public key specified by the circuit state from the one-time programmable area of the management controller itself through the circuit state of the hardware selection circuit includes: When the circuit state of the hardware selection circuit is the i-th state, reading the public key pre-stored in the i-th storage block from the i-th storage block of the one-time programmable area of the management controller itself; Wherein, there are multiple storage blocks in the one-time programmable area of the management controller itself, and i is a positive integer.

5. The function authorization method according to claim 4, characterized in that Reading the public key specified by the circuit state from the one-time programmable area of the management controller itself through the circuit state of the hardware selection circuit includes: Sequentially detecting the level states of each specified pin in a set order; When the level state of the i-th pin is detected to be the set state, determining that the circuit state of the hardware selection circuit is the i-th state; When the circuit state of the hardware selection circuit is the i-th state, reading the public key pre-stored in the i-th storage block from the i-th storage block of the one-time programmable area of the management controller itself.

6. The functional authorization method according to claim 4, wherein Reading the public key pre-stored in the i-th storage block from the i-th storage block of the one-time programmable area of the management controller itself includes: Obtaining the activation flag bit of the i-th storage block of the one-time programmable area of the management controller itself; When the activation flag bit is the first value indicating the unactivated state, changing the activation flag bit to the second value indicating the activated state and reading the public key pre-stored in the i-th storage block; When the activation flag bit is the second value indicating the activated state, read the public key pre-stored in the i-th storage block; Among them, only when the activation flag bit of the i-th storage block is the second value, is it allowed to read the public key in the i-th storage block.

7. The function authorization method according to claim 6, wherein When the activation flag bit is the first value indicating the unactivated state, after changing the activation flag bit to the second value indicating the activated state, it further includes: Regarding the public key used during the previous function authorization as the invalid public key; Changing the activation flag bit of the storage block storing the invalid public key to the third value indicating the invalid state.

8. The function authorization method according to claim 6, characterized in that It further includes: After obtaining the activation flag bit of the i-th storage block in the one-time programmable area of the management controller itself, when the activation flag bit is the third value indicating the invalid state, end the current function authorization process.

9. The functional authorization method according to claim 6, wherein It further includes: When the circuit state of the hardware selection circuit is the i-th state, obtain the index value stored in the i-th storage block in the one-time programmable area of the management controller itself; Judge whether the index value is i; If so, perform the operation of reading the public key pre-stored in the i-th storage block from the i-th storage block in the one-time programmable area of the management controller itself; If not, end the current function authorization process.

10. The functional authorization method according to claim 1, characterized in that The hardware selection circuit is set inside the chassis so that the circuit state of the hardware selection circuit can only be adjusted after the chassis is opened; It further includes: after detecting that the chassis is opened, give an alarm and record a log.

11. The function authorization method according to any one of claims 1 to 10, characterized in that, The anti-cracking signature algorithm used includes a variety of different anti-cracking signature algorithms, so that the multiple public keys stored in the one-time programmable area are public keys generated from a variety of different anti-cracking signature algorithms.

12. A function authorization method, characterized in that, Applied to the server side, it includes: Receiving the license information file sent by the client; among them, the license information file is a license information file generated by the management controller of the client based on the hardware feature information of the client itself for applying for functions to the server; The signature information obtained after digitally signing the license information file with the private key; Generating a feedback file carrying the license information file, the signature information, and the hash algorithm used during digital signature; Sending the feedback file to the client, so that the management controller of the client reads the public key specified by the circuit state from the one-time programmable area of the management controller itself through the circuit state of the hardware selection circuit, and based on the public key, the license information file, and the hash algorithm, verify the signature information. When the verification passes, import the feedback file into the function module to be unlocked to unlock the function module; Among them, the hardware selection circuit is a hardware selection circuit for public key selection; the private key and the public key are a set of public and private key pairs pre-generated through an anti-cracking signature algorithm; multiple public keys are stored in the one-time programmable area.

13. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the function authorization method according to any one of claims 1 to 11, or implements the steps of the function authorization method according to claim 12.

14. An electronic device, characterized in that, Including: A memory for storing a computer program; A processor for implementing the steps of the function authorization method according to any one of claims 1 to 11, or implementing the steps of the function authorization method according to claim 12 when executing the computer program.

15. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein when the computer program is executed by a processor, it implements the steps of the function authorization method according to any one of claims 1 to 11, or implements the steps of the function authorization method according to claim 12.

Citation Information

Patent Citations

  • Firmware security detection method of electronic equipment and related equipment

    CN111008379A

  • Authorization control method and device, authorization method and device and computing equipment

    CN112699342A

  • Unofficial component disabling method and device, equipment and storage medium

    CN113010881A

  • Software authorization method and device, license authorization method and device, equipment and storage medium

    CN115374405A

  • Key management method and device, battery management system and storage medium

    CN115834029A