Security authentication method, baseboard management controller, storage medium and program product

Through the combination of biometric recognition and dynamic authentication information, the generation of temporary accounts solves the problem of low access security of substrate management controllers, and achieves a high security and convenient login experience.

CN120408579AActive Publication Date: 2025-08-01INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510897264.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2025-08-01
Estimated Expiration
2045-06-30

AI Technical Summary

Technical Problem

The existing substrate management controller (BMC) access security relies on pre-set usernames and passwords, and there are problems such as high risk of password leakage, complex management and easy to crack, affecting the security and management efficiency of the server.

Method used

Biometric recognition technology is adopted to generate dynamic authentication information for temporary accounts through biometric parameters and dynamic parameters of substrate management controller, and dual authentication is performed in combination with device identification parameters. Log in to temporary accounts to improve security and convenience.

Benefits of technology

It effectively prevents password leakage and brute-force cracking, simplifies management processes, improves the security and convenience of access to the substrate management controller, and reduces the risk of illegal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408579A_ABST
    Figure CN120408579A_ABST
Patent Text Reader

Abstract

The invention provides a security authentication method, a baseboard management controller, a storage medium and a program product, and the method comprises the steps: creating a temporary account in response to a temporary account creation instruction triggered by a target management account, and generating target dynamic authentication information for security authentication of the temporary account; the target dynamic authentication information is generated based on biological characteristic parameters, dynamic parameters of the substrate management controller and equipment identification parameters, the target management account is a management account logged in through first security authentication based on the target biological characteristic information, and the biological characteristic parameters are determined based on the target biological characteristic information; in response to the received to-be-authenticated dynamic authentication information, performing second security authentication on the to-be-authenticated dynamic authentication information based on the target dynamic authentication information to obtain a second authentication result; and logging in a target temporary account corresponding to the to-be-authenticated dynamic authentication information under the condition that the second authentication result represents that the second security authentication is passed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of information security and computer technology, and more particularly, to a security authentication method, a baseboard management controller, a storage medium, and a program product. Background Art

[0002] A baseboard management controller (BMC) is an important component in server management, responsible for remotely monitoring and managing the hardware status of a server. With the increasing demand for server management, the security of the baseboard management controller has become an urgent problem to be solved.

[0003] The related security control for accessing the baseboard management controller mainly relies on pre-set user names and passwords, which has problems such as a high risk of password leakage and complex password management. Summary of the Invention

[0004] In view of the above problems, the present invention provides a security authentication method, a baseboard management controller, a storage medium, and a program product.

[0005] According to one aspect of the present invention, there is provided a security authentication method, including: in response to a temporary account creation instruction triggered via a target management account, creating a temporary account and generating target dynamic authentication information for securely authenticating the temporary account; the target dynamic authentication information is generated based on biometric parameters, as well as dynamic parameters and device identification parameters of the baseboard management controller, wherein the target management account is a management account that logs in through a first security authentication based on target biometric information, the target management account has a first control right for the baseboard management controller, and the biometric parameters are determined based on the target biometric information; in response to receiving the to-be-authenticated dynamic authentication information, performing a second security authentication on the to-be-authenticated dynamic authentication information based on the target dynamic authentication information to obtain a second authentication result; in the case where the second authentication result indicates that the second security authentication is passed, logging in to the target temporary account corresponding to the to-be-authenticated dynamic authentication information, and the target temporary account has a second control right for the baseboard management controller.

[0006] Another aspect of the present invention provides a baseboard management controller, including: an input / output module, which is used to input the to-be-authenticated biometric information from a biometric data acquisition device and / or the to-be-authenticated dynamic authentication information from a user terminal, and is used to output the target dynamic authentication information to the user terminal; one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.

[0007] Another aspect of the present invention also provides a computer-readable storage medium, on which a computer program or instruction is stored, and when the computer program or instruction is executed by a processor, the steps of the above method are implemented.

[0008] Another aspect of the present invention also provides a computer program product, including a computer program or instruction, and when the computer program or instruction is executed by a processor, the steps of the above method are implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Through the following description of the embodiments of the present invention with reference to the accompanying drawings, the above content and other objects, features and advantages of the present invention will become clearer.

[0010] Figure 1 The application scenario diagram of the security authentication method, the baseboard management controller, the storage medium and the program product according to the embodiment of the present invention is shown.

[0011] Figure 2 The flowchart of the security authentication method according to the embodiment of the present invention is shown.

[0012] Figure 3A The schematic diagram of generating target dynamic authentication information according to the embodiment of the present invention is shown.

[0013] Figure 3B The schematic diagram of performing a second security authentication on the dynamic authentication information to be authenticated according to the embodiment of the present invention is shown.

[0014] Figure 4 The schematic diagram of the first security authentication and the second security authentication according to the embodiment of the present invention is shown.

[0015] Figure 5 The block diagram of the baseboard management controller according to the embodiment of the present invention is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present invention. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present invention.

[0017] The terms used herein are only for describing specific embodiments and are not intended to limit the present invention. The terms "including", "comprising" and the like used herein indicate the presence of the described features, steps, operations and / or components, but do not exclude the presence or addition of one or more other features, steps, operations or components.

[0018] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those of ordinary skill in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.

[0019] In cases where expressions similar to "at least one of A, B, and C, etc." are used, generally, it should be interpreted according to the meaning commonly understood by those of ordinary skill in the art (for example, "a system having at least one of A, B, and C" should include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).

[0020] Some block diagrams and / or flowcharts are shown in the accompanying drawings. It should be understood that some blocks or combinations of blocks in the block diagrams and / or flowcharts can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when executed by the processor, these instructions can create a device for implementing the functions / operations illustrated in these block diagrams and / or flowcharts.

[0021] Therefore, the technology of the present invention can be implemented in the form of hardware and / or software (including firmware, microcode, etc.). Additionally, the technology of the present invention can take the form of a computer program product on a computer-readable medium storing instructions, which can be used by or in conjunction with an instruction execution system. In the context of the present invention, a computer-readable medium can be any medium that can contain, store, transmit, propagate, or transport instructions. For example, a computer-readable medium can include, but not be limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, components, or propagation media. Specific examples of computer-readable media include: magnetic storage devices, such as magnetic tapes or hard disk drives (HDDs); optical storage devices, such as compact discs (CD-ROMs); memories, such as random access memories (RAMs) or flash memories; and / or wired / wireless communication links.

[0022] In the technical solution of the present invention, the user information involved (including but not limited to user personal information, user biometric information, user image information, user device information, such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) are all information and data that have been authorized by the user or fully authorized by all parties, and the processing of the relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, etc., all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or reject.

[0023] In the scenario of making automated decisions using user information, the methods, devices, and systems provided by the embodiments of the present invention all provide corresponding operation entrances for users to choose to agree or reject the automated decision results; if the user chooses to reject, the expert decision-making process will be entered. The expression "automated decision" here refers to the activity of automatically analyzing and evaluating an individual's behavior habits, hobbies, or economic, health, credit status, etc. through a computer program and making a decision. The expression "expert decision" here refers to the activity of making a decision by a person who specializes in a certain field, has specialized experience, knowledge, and skills, and has reached a certain professional level.

[0024] The baseboard management controller (BMC) is an important component in server management and is responsible for remotely monitoring and managing the hardware status of the server. Therefore, the access security of the baseboard management controller is crucial for the security of the server. With the increasing demand for server management, the access security of the baseboard management controller has become an urgent problem to be solved.

[0025] The related access security control of the baseboard management controller mainly relies on pre-set usernames and passwords, and there are problems such as high risk of password leakage and complex password management.

[0026] In a related embodiment, when a user logs in to the baseboard management controller, the user can enter the pre-set username and password on the baseboard management controller login page, and the baseboard management controller sends the received information to the authentication module of the server. The authentication module queries the corresponding username and password records in the database for comparison. If the information is consistent, it is determined that the user is an authorized user, and the user is allowed to access the baseboard management controller and corresponding operation functions are provided according to the user's permissions.

[0027] However, the above solution for accessing the baseboard management controller based on pre-set usernames and passwords has the following problems: First, the username and password are easily cracked or leaked. For example, an attacker can use brute-force cracking software to continuously try different combinations of usernames and passwords until successful login; or obtain the username and password of an authorized user through means such as network sniffing and phishing emails. Second, the authorized user may forget the login password, resulting in inability to log in to the baseboard management controller, affecting the management and maintenance of the server. Moreover, once the password is leaked, the attacker can directly log in to the baseboard management controller and perform malicious operations on the server, seriously threatening the security of the server. In addition, password management is not convenient. To reduce the risk of password leakage, the authorized user needs to change the password regularly, which increases the complexity of password management.

[0028] In view of this, embodiments of the present invention provide a security authentication method, a baseboard management controller, a storage medium, and a program product. The method includes: in response to a temporary account creation instruction triggered via a target management account, creating a temporary account and generating target dynamic authentication information for securely authenticating the temporary account; the target dynamic authentication information is generated based on biometric parameters, as well as dynamic parameters and device identification parameters of the baseboard management controller, wherein the target management account is a management account that logs in through a first security authentication based on target biometric information, the target management account has a first control authority over the baseboard management controller, and the biometric parameters are determined based on the target biometric information; in response to receiving the dynamic authentication information to be authenticated, performing a second security authentication on the dynamic authentication information to be authenticated based on the target dynamic authentication information to obtain a second authentication result; and in the case where the second authentication result indicates that the second security authentication is passed, logging in to the target temporary account corresponding to the dynamic authentication information to be authenticated, and the target temporary account has a second control authority over the baseboard management controller.

[0029] Figure 1 FIG. shows an application scenario diagram of a security authentication method, a baseboard management controller, a storage medium, and a program product according to an embodiment of the present invention.

[0030] As Figure 1 shown, the application scenario 100 according to this embodiment may include a server 101, a baseboard management controller 102, a biometric data acquisition device 103, and a terminal device 104. The baseboard management controller 102 is connected to the server 101, the biometric data acquisition device 103, and the terminal device 104 respectively.

[0031] The server 101 may be a server that provides various services. For example, it is a background management server (only an example) that supports the websites browsed by users using the terminal device 104. The background management server may analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.

[0032] The baseboard management controller 102 is an embedded management system independent of the host operating system on the motherboard of the server 101, with an independent processor, memory, and network interface, and supports the IPMI (Intelligent Platform Management Interface) protocol. The baseboard management controller and the intelligent platform management interface are basic core functional subsystems of the server, responsible for core functions such as hardware status management, operating system management, health status management, and power consumption management of the server.

[0033] The terminal device 104 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablets, laptop computers, desktop computers, and the like. The terminal device 104 can be connected to the baseboard management controller 102 via a network, for example. The network can include various connection types, such as wired, wireless communication links, or fiber optic cables, and the like. The user can interact with the baseboard management controller 102 through the terminal device 104 to receive or send messages and the like.

[0034] In one embodiment, a BMC client can be installed on the terminal device 104. The BMC client can provide a graphical user interface (Graphics User Interface, GUI) for the user to log in and access the baseboard management controller 102. For example, the user can log in to the baseboard management controller 102 through the baseboard management controller login interface provided by the BMC client. For example, the user can remotely control the server 101 through the baseboard management controller management interface provided by the BMC client, such as viewing the server status, performing maintenance operations, and the like.

[0035] The biometric data collection device 103 can be various devices that support the collection and transmission of biometric data. Biometric data can include, for example, but not limited to fingerprint data, facial data, voiceprint data, iris data, palmprint data, and the like. The biometric data collection device 103 can include, for example, but not limited to fingerprint sensors, 3D structured light cameras, microphones, iris scanners, palmprint scanners, and the like.

[0036] The baseboard management controller 102 can receive the biometric data collected by the biometric data collection device 103 to implement biometric identification based on the biometric data. Biometric identification technology can use the inherent and unique biometric characteristics of the human body for identity authentication, and has the advantages of uniqueness, convenience, security, non-contact, high efficiency, and strong adaptability.

[0037] [[ID=1,2]]

[0038] ​According to an embodiment of the present invention, the biometric data acquisition device 103 may include: a biometric sensor for acquiring biometric data; a data processing unit for processing the biometric data into initial biometric information and encrypting the initial biometric information to obtain biometric information to be authenticated; and a data transmission unit for sending the biometric information to be authenticated to the baseboard management controller. As an example, the biometric sensor may be selected as a fingerprint sensor, and the acquired biometric data is a fingerprint image.

[0039] In the acquisition stage of biometric data, a liveness detection combination technology can be adopted to prevent spoofing attacks. For example, a fingerprint sensor can be built with a capacitance detection circuit that can sense the dielectric characteristics of a finger to ensure that the acquisition object is real human tissue. The acquired original biometric data is immediately preprocessed in the secure area at the sensor end, extracting the feature vector (i.e., the above-mentioned initial biometric information) and discarding the original image (i.e., the above-mentioned biometric data), reducing the risk of privacy data exposure from the source.

[0040] In the transmission stage of biometric data, an end-to-end encryption protection mechanism can be adopted. For example, during the process of biometric data being transmitted from the biometric data acquisition device 103 to the baseboard management controller 102, it is processed entirely within the hardware secure area. The data transmission adopts a segmented encryption strategy. For example, the AES-128 algorithm can be used for encryption from the biometric sensor to the interface controller, and the AES-256 algorithm can be used for encryption from the interface controller to the BMC security coprocessor. Further, the data packet structure of the biometric information to be authenticated may include a dynamically changing header check code to prevent the data packet from being tampered with or replayed.

[0041] In the embodiment of the present invention, before collecting biometric data, the consent or authorization of the user for collecting biometric data can be obtained. For example, before collecting biometric data, a request to obtain the user's biometric data can be sent to the user. When the user consents or authorizes to obtain the user's biometric data, the biometric data of the user is collected based on the biometric data acquisition device 103.

[0042] Automated processing operations such as feature extraction, encryption, and transmission can be performed on the collected biometric data. A corresponding operation entry can be provided for the user to choose to consent or reject the automated processing operation. For example, before performing the foregoing automated processing operation, an instruction for the user to consent or reject the automated processing operation input through the corresponding operation entry can be obtained. When the user consents to perform the automated processing operation, automated processing operations such as feature extraction, encryption, and transmission are performed on the collected biometric data.

[0043] It should be noted that the security authentication method provided by the embodiments of the present invention can generally be executed by the baseboard management controller 102. It should be understood that Figure 1 the numbers of the server, the baseboard management controller, the terminal device, and the biometric data acquisition device in

[0044] Figure 2 are merely illustrative. According to the implementation requirements, there can be any number of servers, baseboard management controllers, terminal devices, and biometric data acquisition devices.

[0045] As Figure 2 shown, the method 200 includes operation S210 to operation S230.

[0046] In operation S210, in response to a temporary account creation instruction triggered via a target management account, a temporary account is created, and target dynamic authentication information for securely authenticating the temporary account is generated; the target dynamic authentication information is generated based on biometric parameters, as well as dynamic parameters and device identification parameters of the baseboard management controller, where the target management account is a management account that logs in through the first security authentication based on target biometric information, the target management account has a first control authority for the baseboard management controller, and the biometric parameters are determined based on the target biometric information.

[0047] In operation S220, in response to receiving the dynamic authentication information to be authenticated, the second security authentication is performed on the dynamic authentication information to be authenticated based on the target dynamic authentication information, and a second authentication result is obtained.

[0048] In operation S230, in the case where the second authentication result indicates that the second security authentication is passed, the target temporary account corresponding to the dynamic authentication information to be authenticated is logged in, and the target temporary account has a second control authority for the baseboard management controller.

[0049] The management account can be understood as an authorized user who can log in to and access the baseboard management controller, and can also be called an administrator account. The first security authentication can be biometric authentication, and the management account can log in through biometric authentication. Since biometrics has uniqueness and non-replicability, it makes it difficult for attackers to log in to the baseboard management controller by forging biometrics, thereby effectively improving the security of accessing the baseboard management controller. Moreover, biometric identification does not require the user to remember a password, solves the problem that the user cannot log in to the baseboard management controller due to forgetting the password, and can quickly complete the security authentication, facilitating the management and maintenance of the server.

[0050] Exemplarily, the target management account can be a management account authenticated by biometrics based on target biometric information, and the target management account has a first control right (such as administrator right) for the baseboard management controller. For example, the target management account can trigger a temporary account creation instruction through the baseboard management controller management interface to create a temporary account and generate target dynamic authentication information for securely authenticating the temporary account.

[0051] The temporary account has a second control right for the baseboard management controller (such as guest right, test right, etc.) and can be used for specific short-term tasks or services. For example, the temporary account usually has limited permissions and usage periods and can be deleted or disabled after the task is completed. By setting up a temporary account, flexible access permissions can be provided, the security of the baseboard management controller can be enhanced, and various temporary tasks (such as testing, maintenance, and automation tasks) can be supported. The use of the temporary account improves the security of the baseboard management controller and also simplifies the management process.

[0052] In one embodiment, the temporary account can be used for testers to test the server. For example, in a scenario where the server needs to be tested, the target management account can create one or more temporary accounts for testers to use. The temporary account can provide the necessary access permissions while restricting the modification permissions for critical content. The target dynamic authentication information can be understood as a dynamic password for logging in to the temporary account, and the baseboard management controller can send the target dynamic authentication information to the terminal device so that the tester can log in to the temporary account.

[0053] The target dynamic authentication information is generated based on biometric parameters, as well as the dynamic parameters and device identification parameters of the baseboard management controller. Among them, the dynamic parameters of the baseboard management controller can include, for example, a timestamp, a random number, or a GUID (Globally Unique Identifier). The device identification parameter of the baseboard management controller can include the unique identifier of the baseboard management controller hardware, which is generated by PUF (Physical Unclonable Functions) technology. By utilizing the inherent properties of silicon-based semiconductors to randomly extract unclonable physical features, it can be used as the unique identity identifier of the chip. The biometric parameters are determined based on the target biometric information corresponding to the target management account. In other words, the target dynamic authentication information can be bound to specific target biometric information through biometric parameters, thereby improving the complexity and security of the target dynamic authentication information.

[0054] In response to receiving the dynamic authentication information to be authenticated, the second security authentication can be performed on the dynamic authentication information to be authenticated based on the target dynamic authentication information, and a second authentication result can be obtained. Among them, the dynamic authentication information to be authenticated can be understood as the dynamic password to be authenticated. In the case where the second authentication result indicates that the second security authentication is passed, the target temporary account corresponding to the dynamic authentication information to be authenticated can be logged in. In one embodiment, a new target dynamic authentication information can be generated each time the temporary account is logged in to further increase the difficulty for an attacker to predict or guess the dynamic password.

[0055] It can be understood that by directly logging in to the management account by using biometric information and avoiding the risk of directly logging in to the baseboard management controller after the anti-counterfeiting code (similar to the traditional password) is stolen, the security and convenience of accessing the baseboard management controller can be effectively improved, and at least partially overcome the problems existing in the related baseboard management controller access solutions, such as low security, password leakage, brute force cracking, and difficult password management. By setting up a temporary account, flexible access permissions can be provided, enhancing the security of the baseboard management controller. Moreover, the target dynamic authentication information used to log in to the temporary account is generated based on biometric parameters, dynamic parameters, and device identification parameters, and the target dynamic authentication information is bound to a specific target biometric information through biometric parameters, thereby improving the complexity and security of the target dynamic authentication information, increasing the cracking difficulty of the target dynamic authentication information, and ensuring the security of each access to the temporary account. Based on this, the security authentication method provided by the embodiments of the present invention can significantly improve the security of accessing the baseboard management controller and reduce the risk of illegal access.

[0056] According to an embodiment of the present invention, a security authentication method for a target management account includes: in response to receiving biometric information to be authenticated, performing a first security authentication on the biometric information to be authenticated based on a preset biometric information library to obtain a first authentication result; and in the case where the first authentication result indicates that the first security authentication is passed, logging in to the target management account corresponding to the biometric information to be authenticated.

[0057] In one embodiment, the biometric information to be authenticated can be sent by a biometric data acquisition device to the baseboard management controller. As an example, a biometric data acquisition device (such as a fingerprint recognition module or a face recognition camera) can be integrated into the baseboard management controller system of the server. Exemplarily, when a user needs to log in to the baseboard management controller, biometric data can be collected on the biometric data acquisition device, such as placing a finger on the fingerprint recognizer or facing the face recognition camera. The biometric data acquisition device can process the collected original biometric data (such as a fingerprint image or a face image) to obtain the biometric information to be authenticated and send the biometric information to be authenticated to the baseboard management controller.

[0058] The baseboard management controller receives the biometric information to be authenticated and can perform a first security authentication on the biometric information to be authenticated based on a preset biometric information database, obtaining a first authentication result. Exemplarily, the preset biometric information database can be stored in the baseboard management controller. When the first authentication result indicates that the first security authentication is passed, the user can log in to the target management account corresponding to the biometric information to be authenticated.

[0059] According to an embodiment of the present invention, the preset biometric information database includes at least one management account biometric template; performing a first security authentication on the biometric information to be authenticated based on the preset biometric information database to obtain a first authentication result includes: matching the biometric information to be authenticated with at least one management account biometric template to obtain a first authentication result; wherein, when the biometric information to be authenticated matches at least one management account biometric template successfully, it is determined that the first authentication result indicates that the first security authentication is passed, and the biometric information to be authenticated is used as the target biometric information, and the target management account is determined according to the management account biometric template that matches the target biometric information successfully.

[0060] A biometric template can be understood as a data structure used to store and compare biometric data in a biometric recognition system. A biometric template can be generated by collecting and processing a user's biometric features (such as fingerprints, faces, irises, etc.) for subsequent identity recognition and verification. The core role of a biometric template is to convert complex biometric data into a standardized and comparable form. These templates usually contain key feature points or feature vectors extracted from biometric features for fast and efficient matching operations.

[0061] A management account biometric template can be understood as the biometric template of an authorized user, and a management account corresponds to the management account biometric template. The preset biometric information database includes at least one management account biometric template. In one embodiment, the stored management account biometric template can be protected by using physical unclonable function (PUF) technology, so that the original biometric information cannot be extracted even if the chip is physically obtained.

[0062] In one embodiment, the biometric information to be authenticated can be, for example, a fingerprint feature vector. The biometric information to be authenticated can be matched with at least one management account biometric template (for example, based on vector similarity calculation) to obtain a first authentication result. When the biometric information to be authenticated matches at least one management account biometric template successfully, it is determined that the first authentication result indicates that the first security authentication is passed. The biometric information to be authenticated can be used as the target biometric information, and the target management account is determined according to the management account biometric template that matches the target biometric information successfully.

[0063] According to an embodiment of the present invention, the temporary account creation instruction indicates the temporary account configuration parameters and the target management account that triggers the temporary account creation instruction; in response to the temporary account creation instruction triggered via the target management account, a temporary account is created, and the target dynamic authentication information for securely authenticating the temporary account is generated, including: in response to the temporary account creation instruction, a temporary account is created according to the temporary account configuration parameters, and the target biometric information corresponding to the target management account that triggers the temporary account creation instruction is determined; according to the current timestamp and the hardware random number of the baseboard management controller, dynamic parameters are determined; according to the device identifier of the baseboard management controller, device identification parameters are determined; the hash value of the target biometric information is calculated as the biometric parameter; and the target dynamic authentication plaintext including the dynamic parameters, the device identification parameters, and the biometric parameter is encrypted to generate the target dynamic authentication information.

[0064] The temporary account configuration parameters may include, for example, but are not limited to, the number of temporary accounts, permissions, validity periods, and the validity period of the target dynamic password, etc. For example, the target management account may set the temporary account configuration parameters through the baseboard management controller management interface and trigger the temporary account creation instruction.

[0065] The temporary account creation instruction indicates the temporary account configuration parameters and the target management account that triggers the temporary account creation instruction. In response to the temporary account creation instruction, a temporary account can be created according to the temporary account configuration parameters, and the target biometric information corresponding to the target management account that triggers the temporary account creation instruction can be determined.

[0066] Exemplarily, a dynamic password generation algorithm based on a multi - hybrid security design can be used to ensure that the output dynamic password has a high degree of unpredictability. For example, based on the secure clock and the hardware random number generator of the baseboard management controller, dynamic parameters can be determined according to the current timestamp and the hardware random number to provide time correlation and randomness factors for the dynamic password. The device identification parameters can be determined based on the unique identifier of the baseboard management controller, which is generated by PUF technology and cannot be repeated even for chips of the same batch. The hash value of the target biometric information can be calculated as the biometric parameter to convert the user biometric into a fixed - length cryptographic digest. The dynamic parameters, the device identification parameters, and the biometric parameter can be mixed through an improved HKDF (HMAC - based Extract - and - Expand Key Derivation Function) algorithm to generate a password - derived key (i.e., the target dynamic authentication information). The generated target dynamic authentication information can be sent to the user through a secure channel (such as a dedicated SNMPTRAP V3 encrypted communication).

[0067] Based on the above dynamic password generation algorithm, the generation of dynamic passwords not only considers dynamic parameters and device identification parameters, but also introduces a biometric hash value as a biometric parameter, so that each dynamic password is bound to the biometric characteristics of a specific user. This design realizes a truly "one password per person". Even at the same time point, the dynamic passwords obtained by different users are completely different. Through encryption algorithms and encrypted transmission, the security of dynamic passwords can be further improved. Therefore, the dynamic password generation algorithm effectively improves the complexity and security of the target dynamic authentication information, increases the difficulty of cracking the target dynamic authentication information, can significantly enhance the security of accessing the baseboard management controller, and reduces the risk of illegal access.

[0068] According to an embodiment of the present invention, a second security authentication is performed on the to-be-authenticated dynamic authentication information based on the target dynamic authentication information, and the obtained second authentication result includes: decrypting the to-be-authenticated dynamic authentication information to determine the to-be-authenticated dynamic parameter, the to-be-authenticated device identification parameter, and the to-be-authenticated biometric parameter; verifying the timeliness of the to-be-authenticated dynamic authentication information based on the to-be-authenticated dynamic parameter to obtain a first intermediate authentication result; when the first intermediate authentication result indicates that the to-be-authenticated dynamic authentication information meets the timeliness, verifying the usage status of the to-be-authenticated dynamic authentication information based on the security authentication log to obtain a second intermediate authentication result, and the security authentication log is stored in the baseboard management controller; when the second intermediate authentication result indicates that the to-be-authenticated dynamic authentication information is inconsistent with at least one authenticated dynamic authentication information recorded in the security authentication log, verifying the consistency between the to-be-authenticated biometric parameter and at least one biometric parameter to obtain a third intermediate authentication result; when the third intermediate authentication result indicates that the to-be-authenticated biometric parameter is consistent with the target biometric parameter, verifying the consistency between the to-be-authenticated device identification parameter and the target device identification parameter corresponding to the target biometric parameter to obtain a second authentication result; when the second authentication result indicates that the to-be-authenticated device identification parameter is consistent with the target device identification parameter, determining that the second authentication result indicates that the second security authentication is passed, determining the temporary account corresponding to the target biometric parameter and / or the target device parameter as the target temporary account, and recording the to-be-authenticated dynamic authentication information as the authenticated dynamic authentication information in the security authentication log.

[0069] As an embodiment, after receiving the to-be-authenticated dynamic authentication information, the baseboard management controller can decrypt the to-be-authenticated dynamic authentication information to determine the to-be-authenticated dynamic parameter, the to-be-authenticated device identification parameter, and the to-be-authenticated biometric parameter.

[0070] For example, the timeliness of the to-be-authenticated dynamic authentication information can be verified based on the to-be-authenticated dynamic parameter to obtain a first intermediate authentication result. The timeliness verification can be, for example, checking whether the timestamp of the dynamic password is within the current valid window.

[0071] For example, when the first intermediate authentication result indicates that the dynamic authentication information to be authenticated meets the timeliness requirement, the usage status of the dynamic authentication information to be authenticated can be verified based on the security authentication log to obtain a second intermediate authentication result. The security authentication log is stored in the baseboard management controller, and the security authentication log records the dynamic passwords that have passed the second security authentication. The usage status verification can be, for example, verifying whether there is a dynamic password in the security authentication log that is consistent with the dynamic password to be authenticated (i.e., the dynamic authentication information to be authenticated). If there is a dynamic password in the security authentication log that is consistent with the dynamic password to be authenticated, it indicates that the dynamic password to be authenticated has been used; if there is no dynamic password in the security authentication log that is consistent with the dynamic password to be authenticated, it indicates that the dynamic password to be authenticated has not been used.

[0072] For example, when the second intermediate authentication result indicates that the dynamic authentication information to be authenticated is inconsistent with all of the at least one authenticated dynamic authentication information recorded in the security authentication log, that is, when it is determined that the dynamic authentication information to be authenticated has not been used, the biometric parameter to be authenticated can be respectively verified for consistency with at least one biometric parameter to obtain a third intermediate authentication result. For example, when the third intermediate authentication result indicates that the biometric parameter to be authenticated is consistent with the target biometric parameter, the device identification parameter to be authenticated can be verified for consistency with the target device identification parameter pair corresponding to the target biometric parameter to obtain a second authentication result. For example, when the second authentication result indicates that the device identification parameter to be authenticated is consistent with the target device identification parameter, it can be determined that the second verification result indicates that the second security authentication has passed.

[0073] When the second security authentication passes, the temporary account corresponding to the target biometric parameter and / or target device parameter can be determined as the target temporary account, and the dynamic authentication information to be authenticated can be recorded in the security authentication log as the authenticated dynamic authentication information.

[0074] It can be understood that, when the dynamic authentication information to be authenticated meets the timeliness requirement and has not been used, it also needs to match both the biometric parameter and the device identification parameter used when generating the target dynamic authentication information to pass the second security authentication, thereby effectively preventing password redirection attacks and significantly improving the security of accessing the baseboard management controller.

[0075] Figure 3A Shows a schematic diagram of generating target dynamic authentication information according to an embodiment of the present invention. Figure 3B Shows a schematic diagram of performing a second security authentication on the dynamic authentication information to be authenticated according to an embodiment of the present invention.

[0076] Such as Figure 3AAs shown, in operation S301, in response to a temporary account creation instruction, a temporary account can be created and target biometric information corresponding to the temporary account creation instruction can be determined.

[0077] In operation S302, a dynamic parameter can be determined based on the current timestamp and the hardware random number of the baseboard management controller. A device identification parameter can be determined based on the device identifier of the baseboard management controller. A hash value of the target biometric information can be calculated as the biometric parameter.

[0078] In operation S303, the target dynamic authentication plaintext containing the dynamic parameter, the device identification parameter, and the biometric parameter can be encrypted to generate the target dynamic authentication information.

[0079] In operation S304, the generated target dynamic authentication information can be sent to the terminal device through encrypted communication.

[0080] As Figure 3B shown, in operation S305, in response to receiving the dynamic authentication information to be authenticated, the dynamic authentication information to be authenticated can be decrypted to determine the dynamic parameter to be authenticated, the device identification parameter to be authenticated, and the biometric parameter to be authenticated.

[0081] In operation S306, the timeliness of the dynamic authentication information to be authenticated can be verified based on the dynamic parameter to be authenticated to obtain a first intermediate authentication result.

[0082] In operation S307, when the first intermediate authentication result indicates that the dynamic authentication information to be authenticated meets the timeliness requirement, the usage status of the dynamic authentication information to be authenticated can be verified based on the security authentication log to obtain a second intermediate authentication result.

[0083] In operation S308, when the second intermediate authentication result indicates that the dynamic authentication information to be authenticated is inconsistent with at least one authenticated dynamic authentication information recorded in the security authentication log, the biometric parameter to be authenticated can be respectively verified for consistency with at least one biometric parameter to obtain a third intermediate authentication result.

[0084] In operation S309, when the third intermediate authentication result indicates that the biometric parameter to be authenticated is consistent with the target biometric parameter, the device identification parameter to be authenticated can be verified for consistency with the target device identification parameter pair corresponding to the target biometric parameter to obtain a second authentication result.

[0085] In operation S310, when the second authentication result indicates that the device identification parameter to be authenticated is consistent with the target device identification parameter, it can be determined that the second verification result indicates that the second security authentication is passed, and the temporary account corresponding to the target biometric parameter and / or target device parameter is determined as the target temporary account, and the to-be-authenticated dynamic authentication information is recorded as the authenticated dynamic authentication information in the security authentication log.

[0086] Figure 4 FIG. shows a schematic diagram of the first security authentication and the second security authentication according to an embodiment of the present invention.

[0087] As Figure 4 shown, the authorized user can log in to the target management account through the first security authentication based on the target biometric information, and the target management account has the first control right for the baseboard management controller. For example, the target management account can set the temporary account configuration parameters based on the baseboard management controller management interface and trigger the temporary account creation instruction.

[0088] In response to the temporary account creation instruction, the baseboard management controller can create a temporary account, generate the target dynamic authentication information for securely authenticating the temporary account, and send the target dynamic authentication information to the terminal device. Among them, the target dynamic authentication information is generated based on the biometric parameter, as well as the dynamic parameter and device identification parameter of the baseboard management controller, and the biometric parameter is determined based on the target biometric information. Thus, the target dynamic authentication information can be bound to the target biometric information through the biometric parameter, improving the complexity and security of the target dynamic authentication information.

[0089] As Figure 4 shown, the temporary user can log in to the target temporary account through the second security authentication based on the target dynamic authentication information, and the target temporary account has the second control right for the baseboard control manager. For example, the target temporary account can test the server based on the baseboard management controller.

[0090] According to an embodiment of the present invention, the security authentication method further includes: sending a first security authentication request in response to a risk operation execution instruction; performing a first security authentication on the biometric information to be re-authenticated based on a preset biometric information library in response to receiving the biometric information to be re-authenticated, to obtain a third authentication result; and performing a risk operation when the third authentication result indicates that the first security authentication is passed.

[0091] The risk operation can be understood as an operation that has a significant impact on the security and stability of the system. These operations usually involve changes to the server hardware, firmware, operating system, or key configurations, and may have a direct impact on the normal operation and data security of the system, such as firmware updates, system configuration changes, access to sensitive data, etc.

[0092] In response to a risk operation execution instruction, biometric verification can be performed again to further confirm the identity of the operator, ensuring the continuity and legality of the operator's identity. This mechanism can effectively prevent identity theft and unauthorized operations, enhancing the security and reliability of the system.

[0093] According to an embodiment of the present invention, the security authentication method further includes: recording the first authentication result, the second authentication result, and / or the third authentication result in a security authentication log; digitally signing the entries of the security authentication log based on the root key of the baseboard management controller.

[0094] The root key of the baseboard management controller can be used for encryption and signature operations in the baseboard management controller system. The security requirements for the root key are extremely high, and it is generally generated using complex mathematical algorithms to ensure that it cannot be easily cracked.

[0095] In one embodiment, all verification attempts (whether successful or not) are recorded in the security authentication log, and the entries of the security authentication log are signed using the root key of the baseboard management controller to prevent post - factum tampering.

[0096] By signing the entries of the security authentication log using the root key of the baseboard management controller, the integrity and credibility of the log can be ensured. This mechanism not only prevents the log from being tampered with, but also enhances the security, auditability, and compliance support of the system, providing reliable data support and behavior tracking means for system administrators.

[0097] According to an embodiment of the present invention, the security authentication method further includes: in the case where the second authentication result indicates that the number of security authentication failures is greater than or equal to a preset threshold, rejecting the login to the temporary account and / or sending a first security authentication request during a first preset period; in the case where the first authentication result or the third authentication result indicates that the number of security authentication failures is greater than or equal to a preset threshold, rejecting the login to the management account during a second preset period.

[0098] In one embodiment, in the case where the verification of the temporary account fails more than the preset threshold, the login to the temporary account can be rejected during the first preset period, or an authorized user can be required to intervene and perform biometric verification again. In another embodiment, in the case where the verification of the management account fails more than the preset threshold, the login to the management account can be rejected during the second preset period. Those skilled in the art can reasonably set the first preset period and the second preset period according to actual needs or application scenarios, and no specific limitation is made here again.

[0099] In an optional embodiment, the baseboard management controller may obtain the timing characteristic information and power consumption curve of data transmission. When the timing characteristic information and power consumption curve are characterized as abnormal, a security alarm may be triggered, and it is prompted to send to the authorized user's email through SNMP on the IDL page and erase sensitive data. The aforementioned data may include, for example, target biometric information, target dynamic authentication information, biometric information to be authenticated, dynamic authentication information to be authenticated, and the like.

[0100] Figure 5 FIG. shows a block diagram of a baseboard management controller according to an embodiment of the present invention.

[0101] As Figure 5 shown, the baseboard management controller 102 may include an input / output module 501, a memory 502, and one or more processors 503.

[0102] The input / output module 501 is configured to input the biometric information to be authenticated from the biometric data acquisition device and / or the dynamic authentication information to be authenticated from the user terminal, and to output the target dynamic authentication information to the user terminal. The memory 502 is used to store one or more computer programs. The one or more processors 503 execute the one or more computer programs to implement the steps of the security authentication method provided in the embodiments of the present invention. The memory 502 may include, for example, but not limited to, read-only memory (ROM), random access memory (RAM), non-volatile static random access memory (NVSRAM), erasable programmable read-only memory (EPROM or flash memory), and the like.

[0103] For example, the processor 503, the memory 502, and the input / output module 501 may be connected to each other through a bus. In the memory 502, various programs and data required for the operation of the baseboard management controller 102 are stored. The processor 503 executes various operations of the method flow according to the embodiments of the present invention by executing the programs in the memory 502. It should be noted that the programs may also be stored in one or more memories 502 other than ROM and RAM. The processor 503 may also execute various operations of the method flow according to the embodiments of the present invention by executing the programs stored in the one or more memories 502.

[0104] The processor 503 may perform various appropriate actions and processes according to the programs stored in the memory 502. The processor 503 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), and the like. The processor 503 may further include on-board memory for caching purposes. The processor 503 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiments of the present invention.

[0105] Optionally, the baseboard management controller 102 may further include one or more of the following components connected to the input / output module 501: an input section including a keyboard, a mouse, etc.; an output section including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section including a hard disk, etc.; and a communication section including a network interface card such as a LAN card, a modem, etc. The communication section performs communication processing via a network such as the Internet. A drive is also connected to the input / output module 501 as needed. Removable media, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., are installed on the drive as needed so that a computer program read from it can be installed into the storage section as needed.

[0106] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist alone without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the security authentication method according to the embodiments of the present invention is implemented.

[0107] According to an embodiment of the present invention, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present invention, the computer-readable storage medium may include one or more memories other than the memory 502 described above.

[0108] An embodiment of the present invention further includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to cause the computer system to implement the security authentication method provided by the embodiments of the present invention.

[0109] When the computer program is executed by the processor 503, the above functions defined in the system / apparatus of the embodiments of the present invention are executed. According to an embodiment of the present invention, the above-described systems, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0110] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of signals on a network medium, and downloaded and installed through the communication part, and / or installed from a removable medium. The program code included in the computer program may be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0111] In such an embodiment, the computer program may be downloaded and installed from the network through the communication part, and / or installed from a removable medium. When the computer program is executed by a processor, the above functions defined in the system of the embodiments of the present invention are performed. According to the embodiments of the present invention, the above-described systems, devices, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0112] According to the embodiments of the present invention, the program code for executing the computer program provided by the embodiments of the present invention may be written in any combination of one or more programming languages. Specifically, these computing programs may be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include but are not limited to, such as Java, C++, python, the "C" language, or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0113] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0114] Those skilled in the art can understand that the features described in the various embodiments of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features described in the various embodiments of the present invention can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present invention.

[0115] The embodiments of the present invention have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present invention. Although the embodiments have been described separately above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of the present invention, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present invention.

Claims

1. A security authentication method, applied to a baseboard management controller, characterized in that The method includes: In response to a temporary account creation instruction triggered via a target management account, creating a temporary account and generating target dynamic authentication information for securely authenticating the temporary account; the target dynamic authentication information is generated based on biometric parameters, as well as dynamic parameters and device identification parameters of the baseboard management controller, wherein the target management account is a management account that logs in through a first security authentication based on target biometric information, the target management account has a first control authority over the baseboard management controller, and the biometric parameters are determined based on the target biometric information; In response to receiving the dynamic authentication information to be authenticated, performing a second security authentication on the dynamic authentication information to be authenticated based on the target dynamic authentication information, and obtaining a second authentication result; In the case where the second authentication result indicates that the second security authentication is passed, logging in to the target temporary account corresponding to the dynamic authentication information to be authenticated, and the target temporary account has a second control authority over the baseboard management controller.

2. The method according to claim 1, characterized in that, The security authentication method of the target management account includes: In response to receiving the biometric information to be authenticated, performing a first security authentication on the biometric information to be authenticated based on a preset biometric information library, and obtaining a first authentication result; In the case where the first authentication result indicates that the first security authentication is passed, logging in to the target management account corresponding to the biometric information to be authenticated.

3. The method according to claim 2, wherein The preset biometric information library includes at least one management account biometric template; the performing a first security authentication on the biometric information to be authenticated based on the preset biometric information library and obtaining a first authentication result includes: Matching the biometric information to be authenticated with the at least one management account biometric template to obtain the first authentication result; Wherein, in the case where the biometric information to be authenticated matches successfully with the at least one management account biometric template, determining that the first authentication result indicates that the first security authentication is passed, using the biometric information to be authenticated as the target biometric information, and determining the target management account according to the management account biometric template that matches successfully with the target biometric information.

4. The method according to claim 1, characterized in that, The temporary account creation instruction indicates temporary account configuration parameters and the target management account that triggers the temporary account creation instruction; the creating a temporary account and generating target dynamic authentication information for securely authenticating the temporary account in response to the temporary account creation instruction triggered via the target management account includes: In response to the temporary account creation instruction, creating the temporary account according to the temporary account configuration parameters, and determining the target biometric information corresponding to the target management account that triggers the temporary account creation instruction; Determining the dynamic parameters according to the current timestamp and the hardware random number of the baseboard management controller; Determining the device identification parameters according to the device identifier of the baseboard management controller; Calculating the hash value of the target biometric information as the biometric parameter; and Encrypt the target dynamic authentication plaintext containing the dynamic parameter, the device identification parameter, and the biometric parameter to generate the target dynamic authentication information.

5. The method according to claim 4, characterized in that, The second security authentication of the to-be-authenticated dynamic authentication information based on the target dynamic authentication information, and the obtained second authentication result includes: Decrypt the to-be-authenticated dynamic authentication information to determine the to-be-authenticated dynamic parameter, the to-be-authenticated device identification parameter, and the to-be-authenticated biometric parameter; Perform timeliness verification on the to-be-authenticated dynamic authentication information based on the to-be-authenticated dynamic parameter to obtain a first intermediate authentication result; When the first intermediate authentication result indicates that the to-be-authenticated dynamic authentication information meets the timeliness, perform usage status verification on the to-be-authenticated dynamic authentication information based on the security authentication log, and obtain a second intermediate authentication result, where the security authentication log is stored in the baseboard management controller; When the second intermediate authentication result indicates that the to-be-authenticated dynamic authentication information is inconsistent with at least one authenticated dynamic authentication information recorded in the security authentication log, perform consistency verification on the to-be-authenticated biometric parameter with at least one of the biometric parameters to obtain a third intermediate authentication result; When the third intermediate authentication result indicates that the to-be-authenticated biometric parameter is consistent with the target biometric parameter, perform consistency verification on the to-be-authenticated device identification parameter with the target device identification parameter corresponding to the target biometric parameter to obtain the second authentication result; Wherein, when the second authentication result indicates that the to-be-authenticated device identification parameter is consistent with the target device identification parameter, it is determined that the second authentication result indicates that the second security authentication is passed, and the temporary account corresponding to the target biometric parameter and / or the target device parameter is determined as the target temporary account, and the to-be-authenticated dynamic authentication information is recorded as the authenticated dynamic authentication information in the security authentication log.

6. The method according to claim 2, wherein The method further includes: Respond to the risk operation execution instruction and send a first security authentication request; Respond to receiving the biometric information to be re-authenticated, and perform a first security authentication on the biometric information to be re-authenticated based on a preset biometric information library to obtain a third authentication result; When the third authentication result indicates that the first security authentication is passed, execute the risk operation.

7. The method according to claim 6, characterized in that, The method further includes: Record the first authentication result, the second authentication result, and / or the third authentication result in the security authentication log; Perform digital signature on the entries of the security authentication log based on the root key of the baseboard management controller.

8. The method according to claim 6, characterized in that, The method further includes: When the second authentication result indicates that the number of security authentication failures is greater than or equal to a preset threshold, reject logging in to the temporary account and / or send a first security authentication request within a first preset period; When the first authentication result or the third authentication result indicates that the number of security authentication failures is greater than or equal to the preset threshold, reject logging in to the management account within a second preset period.

9. A baseboard management controller, characterized in that, Includes: An input / output module, which is configured to input biometric information to be authenticated from a biometric data acquisition device and / or dynamic authentication information to be authenticated from a user terminal, and to output target dynamic authentication information to the user terminal; One or more processors; A memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.

10. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.

11. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Biological characteristic authentication method and system

    CN115834088A

  • Identity authentication method, server and terminal equipment

    CN117527333A

  • Processing method based on baseboard management controller in server

    CN117668783A

  • Configuration recovery method of substrate management controller and substrate management controller

    CN120086834A

  • Systems and methods for randomized mobile payment

    US20120116902A1