Security authentication method, baseboard management controller, storage medium, and program product

By using biometric recognition technology to generate dynamic authentication information for double security authentication, the problem of baseboard management controller access security relying on preset passwords is solved, achieving higher security and convenience.

CN120408579BActive Publication Date: 2025-10-21INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510897264.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2025-10-21
Estimated Expiration
2045-06-30

AI Technical Summary

Technical Problem

Existing baseboard management controller (BMC) access security relies on pre-set usernames and passwords, which poses a high risk of password leakage and complex password management, threatening server security.

Method used

Using biometric identification technology, dynamic authentication information for temporary accounts is generated by combining biometric parameters, dynamic parameters of the baseboard management controller, and device identification parameters. This dual-security authentication allows users to log in to the temporary account and improve access security.

Benefits of technology

It effectively prevents password leakage and forged login, simplifies the management process, improves the security and convenience of baseboard management controller access, and reduces the risk of illegal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408579B_ABST
    Figure CN120408579B_ABST
Patent Text Reader

Abstract

The application provides a security authentication method, a substrate management controller, a storage medium and a program product. The method comprises: in response to a temporary account creation instruction triggered via a target management account, creating a temporary account and generating target dynamic authentication information for security authentication of the temporary account; the target dynamic authentication information is generated based on a biometric parameter, a dynamic parameter of the substrate management controller and a device identification parameter, the target management account is a management account logged in through first security authentication based on target biometric information, and the biometric parameter is determined based on the target biometric information; in response to receiving to-be-authenticated dynamic authentication information, performing second security authentication on the to-be-authenticated dynamic authentication information based on the target dynamic authentication information to obtain a second authentication result; and in the case that the second authentication result represents that the second security authentication is passed, logging in a target temporary account corresponding to the to-be-authenticated dynamic authentication information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of information security and computer technology, and more particularly to a security authentication method, a baseboard management controller, a storage medium, and a program product. Background Art

[0002] The baseboard management controller (BMC) is a key component in server management, responsible for remotely monitoring and managing the server's hardware status. As server management demands increase, the security of the BMC has become a pressing issue.

[0003] The access security control of the related baseboard management controller mainly relies on pre-set usernames and passwords, which has problems such as high risk of password leakage and complex password management. Summary of the Invention

[0004] In view of the above problems, the present invention provides a security authentication method, a baseboard management controller, a storage medium and a program product.

[0005] According to one aspect of the present invention, a security authentication method is provided, comprising: in response to a temporary account creation instruction triggered via a target management account, creating a temporary account, and generating target dynamic authentication information for securely authenticating the temporary account; the target dynamic authentication information is generated based on biometric parameters, and dynamic parameters and device identification parameters of a baseboard management controller, wherein the target management account is a management account logged in through a first security authentication based on the target biometric information, the target management account has a first control authority over the baseboard management controller, and the biometric parameters are determined based on the target biometric information; in response to receiving dynamic authentication information to be authenticated, performing a second security authentication on the dynamic authentication information to be authenticated based on the target dynamic authentication information to obtain a second authentication result; when the second authentication result indicates that the second security authentication is passed, logging in to the target temporary account corresponding to the dynamic authentication information to be authenticated, the target temporary account has a second control authority over the baseboard management controller.

[0006] Another aspect of the present invention provides a baseboard management controller, comprising: an input-output module, the input-output module being used to input biometric information to be authenticated from a biometric data acquisition device and / or dynamic authentication information to be authenticated from a user terminal, and being used to output target dynamic authentication information to the user terminal; one or more processors; and a memory being used to store one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.

[0007] Another aspect of the present invention further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the computer program or instructions are executed by a processor.

[0008] Another aspect of the present invention further provides a computer program product, comprising a computer program or instructions, which implement the steps of the above method when executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The above contents and other objects, features and advantages of the present invention will become more apparent through the following description of the embodiments of the present invention with reference to the accompanying drawings.

[0010] Figure 1 An application scenario diagram of a security authentication method, a baseboard management controller, a storage medium, and a program product according to an embodiment of the present invention is shown.

[0011] Figure 2 A flow chart of a security authentication method according to an embodiment of the present invention is shown.

[0012] Figure 3A A schematic diagram of generating target dynamic authentication information according to an embodiment of the present invention is shown.

[0013] Figure 3B A schematic diagram of performing a second security authentication on dynamic authentication information to be authenticated according to an embodiment of the present invention is shown.

[0014] Figure 4 A schematic diagram of the first security authentication and the second security authentication according to an embodiment of the present invention is shown.

[0015] Figure 5 FIG. 4 shows a block diagram of a baseboard management controller according to an embodiment of the present invention. DETAILED DESCRIPTION

[0016] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present invention. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of embodiments of the present invention. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concept of the present invention.

[0017] The terms used herein are only for describing specific embodiments and are not intended to limit the present invention. The terms "comprise", "include", etc. used herein indicate the presence of the features, steps, operations and / or components, but do not exclude the presence or addition of one or more other features, steps, operations or components.

[0018] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0019] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0020] The accompanying drawings show some block diagrams and / or flow charts. It should be understood that some blocks in the block diagrams and / or flow charts, or combinations thereof, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when these instructions are executed by the processor, they can create a device for implementing the functions / operations described in the block diagrams and / or flow charts.

[0021] Therefore, the techniques of the present invention can be implemented in hardware and / or software (including firmware, microcode, etc.). Furthermore, the techniques of the present invention can take the form of a computer program product on a computer-readable medium having stored thereon instructions, which can be used by or in conjunction with an instruction execution system. In the context of the present invention, a computer-readable medium can be any medium that can contain, store, convey, propagate, or transmit instructions. For example, a computer-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, device, or propagation medium. Specific examples of computer-readable media include: magnetic storage devices, such as magnetic tape or hard disk drives (HDDs); optical storage devices, such as compact disks (CD-ROMs); memory, such as random access memory (RAM) or flash memory; and / or wired or wireless communication links.

[0022] In the technical solution of the present invention, the user information involved (including but not limited to user personal information, user biometric information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0023] In scenarios where user information is used for automated decision-making, the methods, devices, and systems provided by embodiments of the present invention provide users with corresponding operational portals for them to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process is entered. The expression "automated decision-making" herein refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, hobbies, or economic, health, and credit status through computer programs, and making decisions. The expression "expert decision-making" herein refers to the activity of making decisions by individuals who specialize in a particular field, have specialized experience, knowledge, and skills, and have reached a certain level of professionalism.

[0024] The baseboard management controller (BMC) is a key component in server management, responsible for remotely monitoring and managing the server's hardware status. Therefore, BMC access security is crucial to server security. With increasing server management demands, BMC access security has become a pressing issue.

[0025] The access security control of the related baseboard management controller mainly relies on pre-set usernames and passwords, which has problems such as high risk of password leakage and complex password management.

[0026] In a related embodiment, when logging into a baseboard management controller (BMC), a user can enter a pre-set username and password on the BMC login page. The BMC then sends this information to an authentication module on a server. The authentication module then searches a database for the corresponding username and password for a comparison. If the information matches, the user is deemed authorized, allowed to access the BMC, and provided with appropriate operational functions based on their permissions.

[0027] However, the above-mentioned solution of accessing the baseboard management controller based on a preset username and password has the following problems: First, the username and password are easily cracked or leaked. For example, an attacker can use brute force cracking software to repeatedly try different username and password combinations until they successfully log in; or obtain the username and password of the authorized user through network sniffing, phishing emails, etc. Second, the authorized user may forget the login password, resulting in the inability to log in to the baseboard management controller, affecting the management and maintenance of the server. Moreover, once the password is leaked, the attacker can directly log in to the baseboard management controller and perform malicious operations on the server, seriously threatening the security of the server. In addition, password management is not convenient enough. To reduce the risk of password leakage, authorized users need to change their passwords regularly, which increases the complexity of password management.

[0028] In view of this, an embodiment of the present invention provides a security authentication method, a baseboard management controller, a storage medium and a program product, the method comprising: in response to a temporary account creation instruction triggered by a target management account, creating a temporary account, and generating target dynamic authentication information for securely authenticating the temporary account; the target dynamic authentication information is generated based on biometric parameters, and dynamic parameters and device identification parameters of the baseboard management controller, wherein the target management account is a management account that is logged in through a first security authentication based on the target biometric information, the target management account has a first control authority over the baseboard management controller, and the biometric parameters are determined based on the target biometric information; in response to receiving the dynamic authentication information to be authenticated, performing a second security authentication on the dynamic authentication information to be authenticated based on the target dynamic authentication information to obtain a second authentication result; when the second authentication result indicates that the second security authentication is passed, logging in to the target temporary account corresponding to the dynamic authentication information to be authenticated, the target temporary account has a second control authority over the baseboard management controller.

[0029] Figure 1 An application scenario diagram of a security authentication method, a baseboard management controller, a storage medium, and a program product according to an embodiment of the present invention is shown.

[0030] like Figure 1 As shown, the application scenario 100 according to this embodiment may include a server 101, a baseboard management controller 102, a biometric data collection device 103, and a terminal device 104. The baseboard management controller 102 is connected to the server 101, the biometric data collection device 103, and the terminal device 104 respectively.

[0031] Server 101 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using terminal devices 104. The background management server may analyze and process received user requests and other data, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal device.

[0032] The baseboard management controller 102 is an embedded management system on the server 101 motherboard, independent of the host operating system. It features an independent processor, memory, and network interface, and supports the IPMI (Intelligent Platform Management Interface) protocol. The baseboard management controller and the intelligent platform management interface are the server's core functional subsystems, responsible for core functions such as hardware status management, operating system management, health status management, and power consumption management.

[0033] The terminal device 104 may be any electronic device with a display screen and web browsing support, including but not limited to a smartphone, tablet computer, laptop computer, and desktop computer. The terminal device 104 may be connected to the baseboard management controller 102 via a network, for example. The network may include various connection types, such as wired or wireless communication links or fiber optic cables. A user may interact with the baseboard management controller 102 via the terminal device 104 to receive or send messages, etc.

[0034] In one embodiment, a BMC client may be installed on the terminal device 104. The BMC client can provide a graphical user interface (GUI) for users to log in to and access the baseboard management controller 102. For example, a user can log in to the baseboard management controller 102 through the baseboard management controller login interface provided by the BMC client. For example, a user can remotely control the server 101 through the baseboard management controller management interface provided by the BMC client, such as viewing server status and performing maintenance operations.

[0035] The biometric data acquisition device 103 can be various devices that support the collection and transmission of biometric data. The biometric data can include, but is not limited to, fingerprint data, facial data, voiceprint data, iris data, palmprint data, etc. The biometric data acquisition device 103 can include, but is not limited to, fingerprint sensors, 3D structured light cameras, microphones, iris scanners, palmprint scanners, etc.

[0036] The baseboard management controller 102 can receive biometric data collected by the biometric data collection device 103 to implement biometric identification based on the biometric data. Biometric identification technology can use the inherent and unique biological characteristics of the human body for identity authentication, and has the advantages of uniqueness, convenience, security, non-contact, efficiency, and strong adaptability.

[0037] In one embodiment, the baseboard management controller 102 can be externally integrated with a fingerprint sensor and / or a 3D structured light camera, making biometric authentication a native capability of the baseboard management controller 102. This hardware-level integration not only improves authentication security but also enables the transmission of biometric data via a dedicated secure bus (eSPI), avoiding potential security risks at the operating system level. eSPI (Enhanced Serial Peripheral Interface) is an enhanced SPI bus. While its physical layer is highly similar to SPI, its protocol layer is a unique Intel communication protocol.

[0038] According to one embodiment of the present invention, the biometric data collection device 103 may include: a biometric sensor for collecting biometric data; a data processing unit for processing the biometric data into initial biometric information and encrypting the initial biometric information to obtain biometric information to be authenticated; and a data transmission unit for transmitting the biometric information to be authenticated to the baseboard management controller. As an example, the biometric sensor may be a fingerprint sensor, and the collected biometric data may be a fingerprint image.

[0039] During the biometric data collection phase, liveness detection combined with other technologies can be used to prevent forgery attacks. For example, fingerprint sensors can include built-in capacitance detection circuits that sense the dielectric properties of the finger, ensuring that the captured data is authentic human tissue. The collected raw biometric data is immediately preprocessed within a secure area on the sensor side to extract feature vectors (the initial biometric information mentioned above) and discard the original image (the biometric data mentioned above), mitigating the risk of privacy exposure at the source.

[0040] During the transmission phase of biometric data, an end-to-end encryption protection mechanism can be employed. For example, during the transmission of biometric data from the biometric data acquisition device 103 to the baseboard management controller 102, the entire process is processed within the hardware security zone. Data transmission adopts a segmented encryption strategy. For example, the biometric sensor to the interface controller can be encrypted using the AES-128 algorithm, and the interface controller to the BMC security coprocessor can be encrypted using the AES-256 algorithm. Furthermore, the data packet structure of the biometric information to be authenticated can include a dynamically changing header checksum to prevent the data packet from being tampered with or replayed.

[0041] In an embodiment of the present invention, before collecting biometric data, the user's consent or authorization for collecting the biometric data may be obtained. For example, before collecting the biometric data, a request to obtain the user's biometric data may be issued to the user. If the user agrees or authorizes the collection of the user's biometric data, the user's biometric data is collected based on the biometric data collection device 103.

[0042] Automated processing operations such as feature extraction, encryption, and transmission can be performed on the collected biometric data. A corresponding operation portal can be provided for the user to choose to agree or reject the automated processing operation. For example, before executing the aforementioned automated processing operation, an instruction to agree or reject the automated processing operation can be obtained from the user through the corresponding operation portal. If the user agrees to the automated processing operation, the automated processing operations such as feature extraction, encryption, and transmission can be performed on the collected biometric data.

[0043] It should be noted that the security authentication method provided in the embodiment of the present invention can generally be executed by the baseboard management controller 102. It should be understood that Figure 1 The number of servers, baseboard management controllers, terminal devices, and biometric data collection devices is merely illustrative. Any number of servers, baseboard management controllers, terminal devices, and biometric data collection devices may be provided as needed.

[0044] Figure 2 A flow chart of a security authentication method according to an embodiment of the present invention is shown.

[0045] like Figure 2 As shown, the method 200 includes operations S210 to S230.

[0046] In operation S210, in response to a temporary account creation instruction triggered by a target management account, a temporary account is created, and target dynamic authentication information for securely authenticating the temporary account is generated; the target dynamic authentication information is generated based on biometric parameters, as well as dynamic parameters and device identification parameters of the baseboard management controller, wherein the target management account is a management account that is logged in through a first security authentication based on the target biometric information, the target management account has a first control authority over the baseboard management controller, and the biometric parameters are determined based on the target biometric information.

[0047] In operation S220, in response to receiving the dynamic authentication information to be authenticated, a second security authentication is performed on the dynamic authentication information to be authenticated based on the target dynamic authentication information to obtain a second authentication result.

[0048] In operation S230 , if the second authentication result indicates that the second security authentication is passed, a target temporary account corresponding to the dynamic authentication information to be authenticated is logged in, and the target temporary account has a second control authority for the baseboard management controller.

[0049] An administrative account can be understood as an authorized user who can log in to and access the baseboard management controller (BMC), also known as an administrator account. The primary security authentication method can be biometric authentication, which can be used to log in to the administrative account. Because biometrics are unique and cannot be replicated, it is difficult for attackers to forge biometrics to log in to the BMC, effectively improving the security of BMC access. Furthermore, biometric recognition eliminates the need for users to remember passwords, resolving the issue of being unable to log in to the BMC due to forgotten passwords. It also allows for quick completion of security authentication, facilitating server management and maintenance.

[0050] For example, the target management account can be a management account that has passed biometric authentication based on target biometric information, and the target management account has first control permissions (such as administrator permissions) for the baseboard management controller. For example, the target management account can trigger a temporary account creation instruction through the baseboard management controller management interface to create a temporary account and generate target dynamic authentication information for secure authentication of the temporary account.

[0051] Temporary accounts have secondary control permissions for the baseboard management controller (such as guest permissions, test permissions, etc.) and can be used for specific short-term tasks or services. For example, temporary accounts typically have limited permissions and a limited usage period and can be deleted or disabled after the task is completed. By setting up temporary accounts, flexible access permissions can be provided, the security of the baseboard management controller can be enhanced, and a variety of temporary tasks (such as testing, maintenance, and automation tasks) can be supported. The use of temporary accounts improves the security of the baseboard management controller and simplifies the management process.

[0052] In one embodiment, temporary accounts can be used by testers to test servers. For example, in a scenario where server testing is required, the target management account can create one or more temporary accounts for testers to use. These temporary accounts can provide necessary access permissions while limiting modification rights to critical content. The target dynamic authentication information can be understood as a dynamic password used to log in to the temporary account. The baseboard management controller can send the target dynamic authentication information to the terminal device, allowing testers to log in to the temporary account.

[0053] The target dynamic authentication information is generated based on biometric parameters, as well as the baseboard management controller's dynamic parameters and device identification parameters. The baseboard management controller's dynamic parameters may include, for example, a timestamp, a random number, or a GUID (Globally Unique Identifier). The baseboard management controller's device identification parameter may include a unique identifier for the baseboard management controller hardware, generated using PUF (Physical Unclonable Functions) technology. This identifier utilizes the inherent properties of silicon-based semiconductors to randomly extract unclonable physical features, which can serve as a unique chip identifier. The biometric parameters are determined based on the target biometric information corresponding to the target management account. In other words, the target dynamic authentication information can be bound to specific target biometric information through the biometric parameters, thereby increasing the complexity and security of the target dynamic authentication information.

[0054] In response to receiving the dynamic authentication information to be authenticated, a second security authentication can be performed on the dynamic authentication information to be authenticated based on the target dynamic authentication information, resulting in a second authentication result. The dynamic authentication information to be authenticated can be understood as the dynamic password to be authenticated. If the second authentication result indicates that the second security authentication has passed, the user can log in to the target temporary account corresponding to the dynamic authentication information to be authenticated. In one embodiment, each login to the temporary account can generate a new target dynamic authentication information to further increase the difficulty for attackers to predict or guess the dynamic password.

[0055] It is understandable that by using biometric information to directly log in to the management account, while avoiding the risk of directly logging into the baseboard management controller after the anti-counterfeiting code (similar to a traditional password) is stolen, the security and convenience of access to the baseboard management controller can be effectively improved, and at least partially overcome the problems of low security, password leakage, brute force cracking, and difficult password management in related baseboard management controller access solutions. By setting up a temporary account, flexible access rights can be provided, enhancing the security of the baseboard management controller. In addition, the target dynamic authentication information used to log in to the temporary account is generated based on biometric parameters, dynamic parameters, and device identification parameters. The target dynamic authentication information is bound to specific target biometric information through the biometric parameters, thereby increasing the complexity and security of the target dynamic authentication information, increasing the difficulty of cracking the target dynamic authentication information, and ensuring the security of each access to the temporary account. Based on this, the security authentication method provided by the embodiment of the present invention can significantly improve the security of access to the baseboard management controller and reduce the risk of illegal access.

[0056] According to an embodiment of the present invention, a security authentication method for a target management account includes: in response to receiving biometric information to be authenticated, performing a first security authentication on the biometric information to be authenticated based on a preset biometric information database to obtain a first authentication result; when the first authentication result indicates that the first security authentication has passed, logging into the target management account corresponding to the biometric information to be authenticated.

[0057] In one embodiment, the biometric information to be authenticated may be sent by a biometric data acquisition device to the baseboard management controller. For example, a biometric data acquisition device (such as a fingerprint recognition module or a facial recognition camera) may be integrated into the baseboard management controller system of the server. For example, when a user needs to log in to the baseboard management controller, they may perform biometric acquisition on the biometric data acquisition device, such as by placing a finger on a fingerprint reader or facing a facial recognition camera. The biometric data acquisition device may process the collected raw biometric data (such as a fingerprint image or facial image) to obtain the biometric information to be authenticated, and then transmit this biometric information to the baseboard management controller.

[0058] The baseboard management controller receives the biometric information to be authenticated and may perform a first security authentication on the biometric information to be authenticated based on a preset biometric information database, thereby obtaining a first authentication result. For example, the preset biometric information database may be stored in the baseboard management controller. If the first authentication result indicates that the first security authentication has passed, the user may log in to the target management account corresponding to the biometric information to be authenticated.

[0059] According to an embodiment of the present invention, a preset biometric information database includes at least one management account biometric template; performing a first security authentication on the biometric information to be authenticated based on the preset biometric information database, and obtaining a first authentication result includes: matching the biometric information to be authenticated with at least one management account biometric template to obtain a first authentication result; wherein, when the biometric information to be authenticated successfully matches the at least one management account biometric template, determining that the first authentication result indicates that the first security authentication has passed, and using the biometric information to be authenticated as the target biometric information, and determining the target management account based on the management account biometric template that successfully matches the target biometric information.

[0060] A biometric template can be understood as a data structure used to store and compare biometric data in biometric recognition systems. Biometric templates are generated by collecting and processing a user's biometric features (such as fingerprints, facial features, and irises) for subsequent identification and verification. The core function of a biometric template is to convert complex biometric data into a standardized, comparable form. These templates typically contain key feature points or feature vectors extracted from the biometrics, enabling fast and efficient matching operations.

[0061] A management account biometric template can be understood as a biometric template for an authorized user. A management account biometric template corresponds to a management account. The preset biometric information database includes at least one management account biometric template. In one embodiment, physically unclonable function (PUF) technology can be used to protect the stored management account biometric template, preventing the extraction of the original biometric information even if the chip is physically accessed.

[0062] In one embodiment, the biometric information to be authenticated may be, for example, a fingerprint feature vector. The biometric information to be authenticated may be matched with at least one management account biometric template (e.g., based on vector similarity calculation) to obtain a first authentication result. If the biometric information to be authenticated successfully matches the at least one management account biometric template, the first authentication result is determined to indicate that the first security authentication has passed. The biometric information to be authenticated may be used as the target biometric information, and the target management account may be determined based on the management account biometric template that successfully matches the target biometric information.

[0063] According to an embodiment of the present invention, a temporary account creation instruction indicates temporary account configuration parameters and a target management account that triggers the temporary account creation instruction; in response to the temporary account creation instruction triggered by the target management account, a temporary account is created, and target dynamic authentication information for securely authenticating the temporary account is generated, including: in response to the temporary account creation instruction, a temporary account is created according to the temporary account configuration parameters, and target biometric information corresponding to the target management account that triggers the temporary account creation instruction is determined; dynamic parameters are determined according to the current timestamp and hardware random number of the baseboard management controller; device identification parameters are determined according to the device identifier of the baseboard management controller; a hash value of the target biometric information is calculated as a biometric parameter; and the target dynamic authentication plaintext containing dynamic parameters, device identification parameters and biometric parameters is encrypting to generate target dynamic authentication information.

[0064] Temporary account configuration parameters may include, but are not limited to, the number of temporary accounts, permissions, validity period, and validity period of the target dynamic password, etc. For example, the target management account may set temporary account configuration parameters through the baseboard management controller management interface and trigger a temporary account creation instruction.

[0065] The temporary account creation instruction indicates the temporary account configuration parameters and the target management account that triggers the temporary account creation instruction. In response to the temporary account creation instruction, a temporary account can be created according to the temporary account configuration parameters, and the target biometric information corresponding to the target management account that triggers the temporary account creation instruction can be determined.

[0066] For example, a dynamic password generation algorithm based on a multi-hybrid security design can ensure highly unpredictable dynamic password output. For example, dynamic parameters can be determined based on the current timestamp and hardware random number, using the baseboard management controller's secure clock and hardware random number generator (HRNG), providing time correlation and randomness to the dynamic password. Device identification parameters can be determined based on the baseboard management controller's unique identifier, generated using PUF technology and unique even for chips from the same batch. A hash value of the target biometric information can be calculated as the biometric parameter, converting the user's biometrics into a fixed-length cryptographic digest. The dynamic parameters, device identification parameters, and biometric parameters can be combined using a modified HKDF (HMAC-based Extract-and-Expand Key Derivation Function) algorithm to generate a cryptographic derivation key (i.e., the target dynamic authentication information). This generated target dynamic authentication information can be sent to the user via a secure channel (such as dedicated SNMPTRAP V3 encrypted communication).

[0067] Based on the aforementioned dynamic password generation algorithm, dynamic password generation not only considers dynamic parameters and device identification parameters but also incorporates biometric hash values ​​as biometric parameters, effectively binding each dynamic password to a specific user's biometrics. This design achieves true "one person, one password"; even at the same time, dynamic passwords obtained by different users are completely different. The security of dynamic passwords can be further enhanced through encryption algorithms and encrypted transmission. This dynamic password generation algorithm effectively increases the complexity and security of the target dynamic authentication information, making it more difficult to crack. This significantly improves the security of baseboard management controller access and reduces the risk of unauthorized access.

[0068] According to an embodiment of the present invention, a second security authentication is performed on the dynamic authentication information to be authenticated based on the target dynamic authentication information, and the second authentication result is obtained, which includes: decrypting the dynamic authentication information to be authenticated, determining the dynamic parameters to be authenticated, the device identification parameters to be authenticated and the biometric parameters to be authenticated; performing timeliness verification on the dynamic authentication information to be authenticated based on the dynamic parameters to be authenticated, and obtaining a first intermediate authentication result; when the first intermediate authentication result indicates that the dynamic authentication information to be authenticated meets the timeliness, performing usage status verification on the dynamic authentication information to be authenticated based on the security authentication log, and obtaining a second intermediate authentication result, and the security authentication log is stored in the baseboard management controller; the second intermediate authentication result indicates that the dynamic authentication information to be authenticated is consistent with at least one authenticated dynamic authentication recorded in the security authentication log When all the information are inconsistent, the biometric parameters to be authenticated are respectively verified for consistency with at least one biometric parameter to obtain a third intermediate authentication result; when the third intermediate authentication result indicates that the biometric parameters to be authenticated are consistent with the target biometric parameters, the device identification parameters to be authenticated are verified for consistency with the target device identification parameters corresponding to the target biometric parameters to obtain a second authentication result; when the second authentication result indicates that the device identification parameters to be authenticated are consistent with the target device identification parameters, it is determined that the second authentication result indicates that the second security authentication is passed, and the temporary account corresponding to the target biometric parameters and / or target device parameters is determined as the target temporary account, and the dynamic authentication information to be authenticated is recorded as authenticated dynamic authentication information in the security authentication log.

[0069] As an embodiment, after receiving the dynamic authentication information to be authenticated, the baseboard management controller may decrypt the dynamic authentication information to be authenticated, and determine the dynamic parameter to be authenticated, the device identification parameter to be authenticated, and the biometric parameter to be authenticated.

[0070] For example, the timeliness verification of the dynamic authentication information to be authenticated can be performed based on the dynamic parameters to be authenticated to obtain the first intermediate authentication result. The timeliness verification can be, for example, checking whether the timestamp of the dynamic password is within the current validity window.

[0071] For example, if the first intermediate authentication result indicates that the dynamic authentication information to be authenticated meets the timeliness requirement, the usage status of the dynamic authentication information to be authenticated can be verified based on the security authentication log to obtain a second intermediate authentication result. The security authentication log is stored in the baseboard management controller, and the security authentication log records the dynamic passwords that have passed the second security authentication. The usage status verification can, for example, verify whether a dynamic password that is consistent with the dynamic password to be authenticated (i.e., the dynamic authentication information to be authenticated) is recorded in the security authentication log. If a dynamic password that is consistent with the dynamic password to be authenticated exists in the security authentication log, it means that the dynamic password to be authenticated has been used; if a dynamic password that is consistent with the dynamic password to be authenticated does not exist in the security authentication log, it means that the dynamic password to be authenticated has not been used.

[0072] For example, if the second intermediate authentication result indicates that the dynamic authentication information to be authenticated is inconsistent with at least one authenticated dynamic authentication information recorded in the security authentication log, that is, if it is determined that the dynamic authentication information to be authenticated has not been used, the biometric parameter to be authenticated can be verified for consistency with at least one biometric parameter to obtain a third intermediate authentication result. For example, if the third intermediate authentication result indicates that the biometric parameter to be authenticated is consistent with the target biometric parameter, the device identification parameter to be authenticated can be verified for consistency with the target device identification parameter corresponding to the target biometric parameter to obtain a second authentication result. For example, if the second authentication result indicates that the device identification parameter to be authenticated is consistent with the target device identification parameter, it can be determined that the second verification result indicates that the second security authentication has passed.

[0073] If the second security authentication passes, the temporary account corresponding to the target biometric parameters and / or target device parameters can be determined as the target temporary account, and the dynamic authentication information to be authenticated can be recorded in the security authentication log as authenticated dynamic authentication information.

[0074] It can be understood that the dynamic authentication information to be authenticated, in addition to meeting the timeliness and non-use requirements, also needs to match the biometric parameters and device identification parameters used when generating the target dynamic authentication information in order to pass the second security authentication, thereby effectively preventing password redirection attacks and significantly improving the security of access to the baseboard management controller.

[0075] Figure 3A A schematic diagram of generating target dynamic authentication information according to an embodiment of the present invention is shown. Figure 3B A schematic diagram of performing a second security authentication on dynamic authentication information to be authenticated according to an embodiment of the present invention is shown.

[0076] like Figure 3AAs shown, in operation S301 , in response to a temporary account creation instruction, a temporary account may be created and target biometric information corresponding to the temporary account creation instruction may be determined.

[0077] In operation S302, a dynamic parameter may be determined based on a current timestamp of the baseboard management controller and a hardware random number. A device identification parameter may be determined based on a device identifier of the baseboard management controller. A hash value of the target biometric information may be calculated as a biometric parameter.

[0078] In operation S303 , the target dynamic authentication plaintext including the dynamic parameters, the device identification parameters, and the biometric parameters may be encrypted to generate target dynamic authentication information.

[0079] In operation S304, the generated target dynamic authentication information may be sent to the terminal device through encrypted communication.

[0080] like Figure 3B As shown, in operation S305, in response to receiving the dynamic authentication information to be authenticated, the dynamic authentication information to be authenticated may be decrypted to determine the dynamic parameters to be authenticated, the device identification parameters to be authenticated, and the biometric parameters to be authenticated.

[0081] In operation S306, the timeliness of the dynamic authentication information to be authenticated may be verified based on the dynamic parameters to be authenticated to obtain a first intermediate authentication result.

[0082] In operation S307, when the first intermediate authentication result indicates that the dynamic authentication information to be authenticated meets the timeliness, the usage status of the dynamic authentication information to be authenticated may be verified based on the security authentication log to obtain a second intermediate authentication result.

[0083] In operation S308, when the second intermediate authentication result indicates that the dynamic authentication information to be authenticated is inconsistent with at least one authenticated dynamic authentication information recorded in the security authentication log, the biometric parameter to be authenticated can be respectively verified for consistency with at least one biometric parameter to obtain a third intermediate authentication result.

[0084] In operation S309, when the third intermediate authentication result indicates that the biometric parameter to be authenticated is consistent with the target biometric parameter, the device identification parameter to be authenticated and the target device identification parameter corresponding to the target biometric parameter may be verified for consistency to obtain a second authentication result.

[0085] In operation S310, when the second authentication result indicates that the identification parameters of the device to be authenticated are consistent with the identification parameters of the target device, it can be determined that the second verification result indicates that the second security authentication is passed, and the temporary account corresponding to the target biometric parameters and / or target device parameters is determined as the target temporary account, and the dynamic authentication information to be authenticated is recorded as authenticated dynamic authentication information in the security authentication log.

[0086] Figure 4 A schematic diagram of the first security authentication and the second security authentication according to an embodiment of the present invention is shown.

[0087] like Figure 4 As shown, an authorized user can pass the first security authentication based on the target biometric information and log in to the target management account. The target management account has the first control permission for the baseboard management controller. For example, the target management account can set temporary account configuration parameters based on the baseboard management controller management interface and trigger the temporary account creation instruction.

[0088] In response to a temporary account creation instruction, the baseboard management controller can create a temporary account, generate target dynamic authentication information for securely authenticating the temporary account, and send the target dynamic authentication information to the terminal device. The target dynamic authentication information is generated based on biometric parameters, dynamic parameters of the baseboard management controller, and device identification parameters. The biometric parameters are determined based on the target biometric information. Thus, the target dynamic authentication information can be bound to the target biometric information using the biometric parameters, thereby increasing the complexity and security of the target dynamic authentication information.

[0089] like Figure 4 As shown, the temporary user can pass the second security authentication based on the target dynamic authentication information and log in to the target temporary account, which has the second control authority for the baseboard control manager. For example, the target temporary account can test the server based on the baseboard management controller.

[0090] According to an embodiment of the present invention, the security authentication method also includes: sending a first security authentication request in response to a risk operation execution instruction; in response to receiving biometric information to be re-authenticated, performing a first security authentication on the biometric information to be re-authenticated based on a preset biometric information database to obtain a third authentication result; and executing a risk operation when the third authentication result indicates that the first security authentication has passed.

[0091] Risky operations can be understood as those that have a significant impact on system security and stability. These operations typically involve changes to server hardware, firmware, operating systems, or critical configurations, and can have a direct impact on the normal operation of the system and data security. Examples include firmware updates, system configuration changes, and access to sensitive data.

[0092] In response to the risk operation execution instruction, biometric verification can be performed again to further confirm the operator's identity and ensure the continuity and legitimacy of the operator's identity. This mechanism can effectively prevent identity fraud and unauthorized operations, and ensure the security and reliability of the system.

[0093] According to an embodiment of the present invention, the security authentication method further includes: recording the first authentication result, the second authentication result and / or the third authentication result in a security authentication log; and digitally signing entries in the security authentication log based on the root key of the baseboard management controller.

[0094] The baseboard management controller's root key can be used for encryption and signing operations in the baseboard management controller system. The root key has extremely high security requirements and is generally generated using a complex mathematical algorithm to ensure that it cannot be easily cracked.

[0095] In one embodiment, all authentication attempts (whether successful or not) are recorded in a secure authentication log. Entries in the secure authentication log are signed using the baseboard management controller's root key to prevent subsequent tampering.

[0096] By signing security authentication log entries with the baseboard management controller root key, the integrity and credibility of the logs are ensured. This mechanism not only prevents log tampering but also enhances system security, auditing capabilities, and compliance support, providing system administrators with reliable data support and behavior tracking.

[0097] According to an embodiment of the present invention, the security authentication method also includes: refusing to log in to the temporary account and / or sending the first security authentication request during the first preset period when the second authentication result indicates that the number of security authentication failures is greater than or equal to a preset threshold; refusing to log in to the management account during the second preset period when the first authentication result or the third authentication result indicates that the number of security authentication failures is greater than or equal to the preset threshold.

[0098] In one embodiment, if a temporary account fails authentication for more than a preset threshold, login to the temporary account may be denied for a first preset period of time, or an authorized user may be required to intervene and re-verify their biometrics. In another embodiment, if a management account fails authentication for more than a preset threshold, login to the management account may be denied for a second preset period of time. Those skilled in the art may appropriately set the first and second preset periods based on actual needs or application scenarios, and again, these are not specifically limited.

[0099] In an optional embodiment, the baseboard management controller can obtain data transmission timing characteristics and power consumption curves. If the timing characteristics and power consumption curves indicate an anomaly, a security alert can be triggered, prompting the user to send an SNMP notification to the authorized user's email address on the IDL page and erase sensitive data. This data can include, for example, target biometric information, target dynamic authentication information, biometric information to be authenticated, and dynamic authentication information to be authenticated.

[0100] Figure 5 FIG. 4 shows a block diagram of a baseboard management controller according to an embodiment of the present invention.

[0101] like Figure 5 As shown, the baseboard management controller 102 may include an input / output module 501 , a memory 502 , and one or more processors 503 .

[0102] The input / output module 501 is used to input biometric information to be authenticated from a biometric data collection device and / or dynamic authentication information to be authenticated from a user terminal, and to output the target dynamic authentication information to the user terminal. The memory 502 is used to store one or more computer programs. One or more processors 503 execute one or more computer programs to implement the steps of the security authentication method provided in the embodiments of the present invention. The memory 502 may include, for example, but is not limited to, read-only memory (ROM), random access memory (RAM), non-volatile memory (NVSRAM), erasable programmable read-only memory (EPROM or flash memory), and the like.

[0103] For example, the processor 503, memory 502, and input / output module 501 may be connected to each other via a bus. The memory 502 stores various programs and data required for the operation of the baseboard management controller 102. The processor 503 executes the programs in the memory 502 to perform various operations according to the method flow of the embodiment of the present invention. It should be noted that the programs may also be stored in one or more memories 502 other than ROM and RAM. The processor 503 may also execute the programs stored in the one or more memories 502 to perform various operations according to the method flow of the embodiment of the present invention.

[0104] The processor 503 can perform various appropriate actions and processes according to the program stored in the memory 502. The processor 503 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or related chipsets, and / or a dedicated microprocessor (e.g., an application-specific integrated circuit (ASIC)). The processor 503 may also include onboard memory for caching. The processor 503 may include a single processing unit or multiple processing units for performing different actions of the method flow according to embodiments of the present invention.

[0105] Optionally, the baseboard management controller 102 may also include one or more of the following components connected to the input / output module 501: an input section including a keyboard, mouse, etc.; an output section including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section including a hard disk; and a communication section including a network interface card such as a LAN card or modem. The communication section performs communication processing via a network such as the Internet. A drive is also connected to the input / output module 501 as needed. Removable media such as magnetic disks, optical disks, magneto-optical disks, semiconductor memories, etc. are installed in the drive as needed, so that computer programs read from the media can be installed in the storage section as needed.

[0106] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the security authentication method according to the embodiments of the present invention.

[0107] According to embodiments of the present invention, a computer-readable storage medium may be a non-volatile computer-readable storage medium, such as, but not limited to, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of the present invention, a computer-readable storage medium may include one or more memories other than the memory 502 described above.

[0108] An embodiment of the present invention further includes a computer program product comprising a computer program containing program code for executing the method shown in the flowchart. When the computer program product is executed in a computer system, the program code is used to enable the computer system to implement the security authentication method provided by the embodiment of the present invention.

[0109] The computer program executes the above functions defined in the system / device of the embodiment of the present invention when executed by the processor 503. According to the embodiment of the present invention, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0110] In one embodiment, the computer program may be stored on a tangible storage medium, such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal over a network medium, downloaded and installed via a communication component, and / or installed from a removable medium. The program code contained in the computer program may be transmitted using any suitable network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0111] In such an embodiment, the computer program can be downloaded and installed from a network via the communication portion, and / or installed from a removable medium. When the computer program is executed by the processor, the above-described functions defined in the system of the embodiment of the present invention are performed. According to the embodiment of the present invention, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0112] According to an embodiment of the present invention, the program code for executing the computer program provided by the embodiment of the present invention can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0113] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0114] It will be understood by those skilled in the art that the features described in the various embodiments of the present invention may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in the present invention. In particular, the features described in the various embodiments of the present invention may be combined and / or coupled in various ways without departing from the spirit and teachings of the present invention. All such combinations and / or couplings fall within the scope of the present invention.

[0115] The above describes embodiments of the present invention. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present invention. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be advantageously used in combination. Without departing from the scope of the present invention, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present invention.

Claims

1. A security authentication method, applied to a baseboard management controller, characterized in that: The method comprises: In response to a temporary account creation instruction triggered by a target management account, a temporary account is created, and target dynamic authentication information is generated for secure authentication of the temporary account; the target dynamic authentication information is generated based on biometric parameters, dynamic parameters of the baseboard management controller, and device identification parameters, wherein the target management account is a management account logged in through a first security authentication based on the target biometric information, the target management account has a first control authority for the baseboard management controller, and the biometric parameters are determined based on the target biometric information; In response to receiving the dynamic authentication information to be authenticated, performing a second security authentication on the dynamic authentication information to be authenticated based on the target dynamic authentication information to obtain a second authentication result; If the second authentication result indicates that the second security authentication is passed, logging into a target temporary account corresponding to the dynamic authentication information to be authenticated, the target temporary account having a second control authority for the baseboard management controller; The temporary account creation instruction indicates temporary account configuration parameters and a target management account that triggers the temporary account creation instruction; and the step of creating a temporary account in response to the temporary account creation instruction triggered by the target management account and generating target dynamic authentication information for securely authenticating the temporary account includes: In response to the temporary account creation instruction, create the temporary account according to the temporary account configuration parameters, and determine target biometric information corresponding to the target management account that triggered the temporary account creation instruction; wherein the target biometric information is obtained by processing biometric data collected by a biometric data collection device integrated into the baseboard management controller; Determining the dynamic parameter according to a current timestamp of the baseboard management controller and a hardware random number; Determining the device identification parameter according to the device identifier of the baseboard management controller; the device identifier is generated by randomly extracting non-clonable physical features using inherent properties of silicon-based semiconductors; Calculating a hash value of the target biometric information as the biometric parameter; and The target dynamic authentication plaintext including the dynamic parameter, the device identification parameter and the biometric parameter is encrypted to generate the target dynamic authentication information.

2. The method according to claim 1, characterized in that The security authentication method of the target management account includes: In response to receiving the biometric information to be authenticated, performing a first security authentication on the biometric information to be authenticated based on a preset biometric information database to obtain a first authentication result; In a case where the first authentication result indicates that the first security authentication is passed, the target management account corresponding to the biometric information to be authenticated is logged in.

3. The method according to claim 2, characterized in that The preset biometric information database includes at least one management account biometric template; performing a first security authentication on the biometric information to be authenticated based on the preset biometric information database to obtain a first authentication result includes: Matching the biometric information to be authenticated with the at least one management account biometric template to obtain the first authentication result; Among them, when the biometric information to be authenticated successfully matches the at least one management account biometric template, it is determined that the first authentication result indicates that the first security authentication has passed, and the biometric information to be authenticated is used as the target biometric information, and the target management account is determined based on the management account biometric template that successfully matches the target biometric information.

4. The method according to claim 1, wherein The performing a second security authentication on the dynamic authentication information to be authenticated based on the target dynamic authentication information to obtain a second authentication result includes: Decrypting the dynamic authentication information to be authenticated, and determining the dynamic parameters to be authenticated, the device identification parameters to be authenticated, and the biometric parameters to be authenticated; Performing timeliness verification on the dynamic authentication information to be authenticated based on the dynamic parameter to be authenticated to obtain a first intermediate authentication result; If the first intermediate authentication result indicates that the dynamic authentication information to be authenticated meets the timeliness, verifying the usage status of the dynamic authentication information to be authenticated based on the security authentication log to obtain a second intermediate authentication result, wherein the security authentication log is stored in the baseboard management controller; If the second intermediate authentication result indicates that the dynamic authentication information to be authenticated is inconsistent with at least one authenticated dynamic authentication information recorded in the security authentication log, performing consistency verification on the biometric parameter to be authenticated and at least one of the biometric parameters to obtain a third intermediate authentication result; If the third intermediate authentication result indicates that the biometric parameter to be authenticated is consistent with the target biometric parameter, verifying the consistency of the device identification parameter to be authenticated with the target device identification parameter corresponding to the target biometric parameter to obtain the second authentication result; Among them, when the second authentication result indicates that the identification parameters of the device to be authenticated are consistent with the identification parameters of the target device, it is determined that the second authentication result indicates that the second security authentication is passed, and the temporary account corresponding to the target biometric parameters and / or the target device parameters is determined as the target temporary account, and the dynamic authentication information to be authenticated is recorded as the authenticated dynamic authentication information in the security authentication log.

5. The method according to claim 2, characterized in that The method further comprises: In response to the risk operation execution instruction, sending a first security authentication request; In response to receiving the biometric information to be re-authenticated, performing a first security authentication on the biometric information to be re-authenticated based on a preset biometric information database to obtain a third authentication result; In a case where the third authentication result indicates that the first security authentication is passed, a risk operation is performed.

6. The method according to claim 5, characterized in that The method further comprises: Recording the first authentication result, the second authentication result and / or the third authentication result in a security authentication log; Entries of the security authentication log are digitally signed based on a root key of the baseboard management controller.

7. The method according to claim 5, characterized in that The method further comprises: If the second authentication result indicates that the number of security authentication failures is greater than or equal to a preset threshold, refusing to log into the temporary account and / or send the first security authentication request during the first preset period; If the first authentication result or the third authentication result indicates that the number of security authentication failures is greater than or equal to the preset threshold, logging into the management account is denied during a second preset period.

8. A baseboard management controller, characterized in that: include: one or more processors; A memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Biological characteristic authentication method and system

    CN115834088A

  • Processing method based on baseboard management controller in server

    CN117668783A