Function management method, system, device and medium

By introducing an encrypted authorization mechanism for logic devices and controllers into the server management system, the problems of low security and insufficient flexibility in traditional server management systems are solved, enabling dynamic function configuration and efficient management processes.

CN120429038BActive Publication Date: 2025-10-28INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510948939.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-10-28
Estimated Expiration
2045-07-10

AI Technical Summary

Technical Problem

Traditional server management systems rely on software licensing, which suffers from low security, insufficient flexibility, and high management complexity, especially in user management and permission synchronization.

Method used

An encryption authorization mechanism based on logic devices and controllers is adopted. The controller obtains and sends encrypted license information to the logic device for security verification, parses the license level and dynamically enables the function, and uses hardware-level decryption to ensure security and flexibility.

Benefits of technology

It improves the security and flexibility of server function management, reduces management complexity, achieves security verification at the hardware level, prevents unauthorized access and tampering, and simplifies enterprise-level server management processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120429038B_ABST
    Figure CN120429038B_ABST
Patent Text Reader

Abstract

This application discloses a function management method, system, device, and medium, relating to the field of server technology. Based on the collaborative work of a controller and logic devices, the controller is responsible for reading and submitting corresponding encrypted license information, which is then sent to the logic devices. The logic devices are responsible for verifying the authenticity of the encrypted license information, ensuring security through hardware-level decryption. Under the premise of ensuring security, the corresponding license level is parsed, and the corresponding service functions are dynamically enabled based on the license level. This combination of software and hardware significantly improves the security of license verification while increasing the reliability and stability of the server system, making it suitable for various complex application scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of server technology, and in particular to a function management method, system, device and medium. Background Technology

[0002] With the rapid development of information technology, the demands for security and functional flexibility in server equipment are increasing. Traditional server management systems typically rely on circuit board management controllers for remote monitoring and management. However, this management method usually relies on software licensing to manage the controller's functional permissions, which raises security concerns.

[0003] Therefore, there is an urgent need for a functional management method to improve security and solve the above-mentioned technical problems. Summary of the Invention

[0004] This application provides a function management method, device, medium, and product to at least solve the problems in the related art.

[0005] This application provides a function management method applied in a controller, including:

[0006] In response to the detection of controller firmware loading, the encrypted license information pre-stored within the controller is obtained;

[0007] Send encrypted license information to the logic device for security verification;

[0008] The receiving logic device responds to the detection of an unlock function code that has passed security verification.

[0009] Configure server functions based on the unlock function code.

[0010] This application also provides a functional management system, including:

[0011] The data acquisition module is used to acquire the encrypted license information pre-stored in the controller in response to the detection of controller firmware loading;

[0012] The data communication module is used to send encrypted license information to the logic device for security verification;

[0013] The data communication module is also used to receive the unlock function code from the logic device in response to the detection of a successful security verification.

[0014] The function management module is used to manage server resources based on the unlock function code.

[0015] This application also provides an electronic device, including: a memory for storing a computer program; and a processor for implementing the steps of any of the above-described functional management methods when executing the computer program.

[0016] This application also provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of any of the above-described functional management methods.

[0017] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the above-described functional management methods.

[0018] The functional management method disclosed in this application is based on the collaborative work of a controller and logic devices. The controller is responsible for reading and submitting the corresponding encrypted license information, which is then sent to the logic devices. The logic devices are responsible for verifying the authenticity of the encrypted license information, ensuring security through hardware-level decryption. Under the premise of ensuring security, the corresponding license level is parsed, and the corresponding service functions are dynamically enabled according to the license level. By combining software and hardware, the security of license verification is significantly improved, while increasing the reliability and stability of the server system, making it suitable for various complex application scenarios. Attached Figure Description

[0019] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A flowchart of a function management method provided in an embodiment of this application;

[0021] Figure 2 A timing diagram for functional management provided in an embodiment of this application;

[0022] Figure 3 A flowchart illustrating another function management method provided in this application embodiment;

[0023] Figure 4 Another functional management timing diagram provided for embodiments of this application;

[0024] Figure 5 A functional management system architecture diagram provided for embodiments of this application;

[0025] Figure 6 This is a schematic diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0026] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0027] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0028] As stated in the background technology disclosure, with the rapid development of information technology, the demand for security and functional flexibility of hardware devices is increasing. Server management systems typically rely on baseboard management controllers for remote monitoring and management. However, the hierarchical authorization of service functions still mainly relies on software licensing methods, such as using serial numbers, encryption keys, or cloud verification to enable specific functions after verifying permissions. But these methods have the following shortcomings: low security, as traditional software licensing is easily cracked or tampered with, for example, by using pirated keys or software cracking; insufficient flexibility, as most server function authorizations are currently statically set and cannot be dynamically adjusted according to enterprise needs; and high management complexity, as enterprises often need to reapply for licenses or perform manual operations after purchasing servers, leading to increased management costs.

[0029] For example, some existing solutions use local user authentication, defining user group permissions on the user management page of the substrate management controller. Different users can be added based on different user group permissions. However, in this technical solution, password strength depends on the user, making it vulnerable to packet sniffing or dictionary attacks. Password storage is also risky; passwords are usually stored in encrypted or hashed form on the local storage medium of the substrate management controller, but if the password strength is insufficient or the storage method is inappropriate, there is a risk of leakage. Management complexity is high, user management is decentralized, and each substrate management controller needs to manage local user accounts separately, leading to a significant increase in management complexity when there are many devices. Furthermore, there are difficulties in permission synchronization and complex user lifecycle management. Operations such as user creation, modification, deletion, and permission modification need to be manually performed on each substrate management controller, which is inefficient and prone to errors.

[0030] Another existing solution involves domain user authentication, managing users of the baseboard management controller through Active Directory (AD), LDAP (Lightweight Directory Access Protocol), or RADIUS (Remote Authentication Dial-In User Service). Appropriate management permissions are set in AD, LDAP, or RADIUS, and different users are created based on these permissions. However, this authentication method has a single point of failure risk. Since the baseboard management controller's domain user authentication relies on an external authentication service, if this service is unavailable (e.g., due to network outages or server failures), the baseboard management controller will be unable to complete user authentication, leading to management system paralysis. The authentication process requires communication with an external server, and network latency can increase authentication response time, impacting user experience. Furthermore, there is the issue of configuration complexity, requiring integration of the baseboard management controller with the domain authentication system, including binding domain controller addresses, ports, certificates, and user information, which demands a high level of technical expertise from administrators. Certificate management is particularly complex; if encrypted communication is used, the generation, deployment, and updating of certificates need to be managed, increasing the operational burden. Furthermore, there are security risks. If domain account credentials are compromised, attackers can use these credentials to access all baseboard management controller devices that integrate domain authentication, resulting in a wide-ranging impact.

[0031] Therefore, this application proposes an encrypted authorization mechanism based on logic devices and controllers, which enables dynamic adjustment of server functions while ensuring authorization security, thereby improving flexibility.

[0032] Embodiments of this application provide a function management method that, after the server starts up, utilizes controllers and logic devices to dynamically configure and manage server functions, such as... Figure 1 As shown, it includes:

[0033] S1. In response to the detection of controller firmware loading, the controller obtains the encrypted license information pre-stored within the controller.

[0034] Specifically, in the embodiments of this application, the controller is preferably set as a baseboard management controller. In some implementation scenarios, it can also be set as a controller with similar functions to the baseboard management controller, and this application does not limit it in this regard. This application determines whether the server is started by detecting whether the controller firmware is loaded. That is, after detecting that the controller firmware is loaded, the controller determines that the current server is started. At this time, the controller is triggered to obtain the encrypted license information pre-written in the controller. The encrypted license information is usually written in non-ritual memory.

[0035] S2. The controller sends encrypted license information to the logic device for security verification.

[0036] Specifically, in this application, the aforementioned logic device is preferably configured as a CPLD (Complex Programmable Logic Device). Of course, in some embodiments, it can also be configured as a PLD (Programmable Logic Device) or an FPGA (Field Programmable Gate Array), etc. This application does not limit the specific type of logic device, which can be set by those skilled in the art according to the actual situation. This application pre-programs security verification and decryption implementation files for encrypted license information into the logic device.

[0037] In this application, communication between the controller and the logic device can be achieved through various interfaces, including but not limited to SPI (Serial Peripheral Interface, a synchronous serial communication interface), I²C (Inter-Integrated Circuit, a serial communication protocol) and GPIO (General-Purpose Input / Output).

[0038] The aforementioned security verification is performed within the logic device, specifically including:

[0039] The encrypted license information is parsed to obtain the license signature. Understandably, server manufacturers generate license files based on customer requirements and digitally sign them using their private key. When the controller needs to activate the license file, it sends it to the logic device, which verifies the validity of the license signature using a pre-stored public key. If a valid license signature is detected, the security verification is confirmed, meaning the license file has not been modified. If an invalid license signature is detected, the security verification is confirmed to have failed, meaning the license file may have been modified and lacks security; in this case, the use of the license file is rejected.

[0040] Specifically, the encryption algorithms for generating public and private keys mentioned above preferentially use RSA or ECC algorithms. Of course, in some special implementation scenarios, those skilled in the art can also set them according to the actual situation, and this application does not limit this. The RSA (Rivest-Shamir-Adleman algorithm), which is an asymmetric encryption algorithm based on the large integer factorization problem, is widely used in various scenarios and provides high security. Compared with RSA, the ECC (Elliptic curve cryptography) algorithm provides the same or even higher level of security, but uses a shorter key length, which means that it can perform encryption operations faster and consume less resources.

[0041] This application utilizes logic devices to decrypt licenses, adding security measures at the hardware layer. Since the signature verification process is completed internally within the logic device, rather than relying on easily compromised software, the attack surface is significantly reduced, greatly improving the security of the license verification process and preventing unauthorized access and tampering. Even if an attacker gains control of the controller, they cannot forge a valid license document without physical access to reprogram the logic device or crack its internally stored public key.

[0042] S3. The controller receives the unlock function code from the logic device in response to the detection of the security verification pass and configures the server functions according to the unlock function code.

[0043] Furthermore, after confirming that the security verification has passed, the logic device needs to perform the following steps, including: parsing the license file level in the encrypted license information; determining the unlock function code based on the license level and a pre-stored mapping table (which stores the correspondence between license file levels and function codes); and sending the unlock function code to the controller. If the controller detects that the security verification has failed, it receives an abnormal alarm from the logic device; based on the abnormal alarm, it interrupts the controller firmware loading; that is, the controller firmware cannot be successfully burned.

[0044] Specifically, the aforementioned license file levels define the functional levels that users can obtain. In a specific implementation scenario, this can be set to three levels: Level 1 corresponds to a personal license, with corresponding functions of querying and configuring itself; Level 2 corresponds to a small business license, with corresponding functions of general configuration, power control, remote media, remote KVM, querying, and configuring itself; Level 3 corresponds to an enterprise license, with corresponding functions of user configuration, general configuration, power control, remote media, remote KVM, security configuration, debugging and diagnostics, querying, and configuring itself. It is understood that the license file level settings are not limited to the specific scenarios mentioned above and can be customized according to different permission requirements; this application does not impose any limitations on this. Consistent with the aforementioned disclosure, the above levels and corresponding functions are predefined in a mapping table and stored in a readable storage medium for the logic device to read and parse. Through the above steps, the available functions can be dynamically activated in the logic device according to the license level, enabling dynamic adjustment of server functions and further improving the flexibility of server function configuration.

[0045] Of course, in some implementation scenarios, instruction sequences corresponding to specific functions for each license level can be directly embedded in the logic design of the logic device. Thus, when the logic device receives and parses the encrypted license information to obtain the corresponding license level, it automatically executes the corresponding instruction sequence to enable the corresponding function, and then sends the function code corresponding to the enabled function to the controller for subsequent resource allocation.

[0046] The logic device uses a pre-configured public key to verify the data signature of the encrypted license information, ensuring that the license file has not been tampered with. It then extracts the license level from the encrypted license information. Next, it determines the decryption function code by querying a mapping table, activates the corresponding function, and finally sends the function code to the controller. At this point, the controller dynamically allocates the resources required for each server function based on the received decrypted unlocking function code, thereby configuring the unlocked server functions.

[0047] like Figure 2 As shown in the timing diagram, this application is based on the collaborative work of the controller and logic devices. The controller is responsible for reading and submitting the corresponding encrypted license information, which is then sent to the logic devices. The logic devices are responsible for verifying the authenticity of the encrypted license information and ensuring security by decrypting at the hardware level. Under the premise of ensuring security, the corresponding license level is parsed and the corresponding service functions are dynamically enabled according to the license level.

[0048] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0049] Embodiments of this application also provide a function management method, which, after the server starts up, utilizes controllers and logic devices to achieve dynamic configuration management of server functions, such as... Figure 3 As shown, it includes:

[0050] X1. Upon receiving a server authorization change request, the controller parses the license information to be updated contained in the server authorization change request.

[0051] Specifically, the customer submits a server license change request, and the controller responds to the server license change request by parsing the license information to be changed contained therein so that it can be sent to the cloud license server later.

[0052] X2. The controller generates a license update instruction based on the license information to be updated and sends it to the cloud authorization server to verify the legality of the license information to be updated.

[0053] In this setup, the cloud-based authorization server and the controller typically communicate via an encrypted channel, such as HTTPS, to send the generated license update command to the cloud-based authorization server. Alternatively, a two-way TLS (Transport Layer Security) protocol can be used, where the controller possesses a certificate from the cloud-based authorization server to verify its identity before communication. If the controller's identity is invalid, a malicious modification warning is issued, alerting the user that the current controller is abnormal. Of course, in other implementation scenarios, other communication methods can also be used to achieve communication between the cloud-based authorization server and the controller.

[0054] In some implementation scenarios, the cloud-based licensing server disclosed in this application is also seamlessly integrated with a central management system. The central management system provides an interface for administrators to view, manage, and update the license files stored on the entire cloud-based licensing server. Specifically, when a new server comes online, the controller sends a license activation request to the cloud-based licensing server. This request includes the server identifier. The cloud-based server responds to the license activation request by sending the corresponding license file back to the controller and writing it. The central management system periodically generates management reports displaying the license status of all servers recorded on the cloud-based server, including validity periods and enabled functions, and provides detailed log records to help administrators track any suspicious activities or errors. Through the integration of the cloud-based licensing server with the central management system, enterprises can centrally manage license information for multiple servers, greatly simplifying management processes and improving management efficiency.

[0055] Specifically, the license update instruction includes the license information to be updated and the target server identifier; after receiving the license update instruction sent by the controller, the cloud authorization server performs a validity verification, specifically including:

[0056] The license information to be updated is parsed to obtain the license signature and license file in the updated license information; the validity of the license signature is verified according to the pre-stored public key; wherein, the method of verifying the validity of the license signature in the cloud server is the same as that of verifying the validity of the license signature in the logic device, and will not be described in detail here.

[0057] In response to the detection of a valid license signature, the validity period of the license document is queried; in response to the detection that the license document is within the validity period, the uniqueness of the license document is verified; if the license document is not within the validity period, it is determined that the license document is not valid; in response to the detection that the license document is unique, the license information to be updated is determined to be valid.

[0058] Specifically, verifying the uniqueness of the license file includes checking for the existence of a historical server identifier that matches the license file. That is, the cloud-based authorization server queries its built-in database to see if a historical server identifier matching the license file exists. It's understandable that when a license file is activated for the first time, initial binding is usually required. During initial binding, the controller sends the license file and the corresponding bound server identifier to the cloud-based authorization server. Therefore, the uniqueness of the license file can be determined by checking if a corresponding server identifier exists in the cloud-based authorization server.

[0059] If no historical server identifier is detected, the license information to be updated is deemed legitimate, indicating that the license file is being activated for the first time. If a historical server identifier is detected, the system verifies whether the historical server identifier matches the target server identifier. If the historical server identifier matches the target server identifier, the license information to be updated is deemed legitimate, meaning that although the license file is not being activated for the first time, it is unique as it is bound to the same device. If the historical server identifier does not match the target server identifier, the license information to be updated is deemed illegitimate, meaning that the target server to which the license file is currently bound is different from the historical servers it was previously bound to, and therefore it is not unique. If the cloud authorization server determines that the license file is illegitimate, it directly generates an exception alarm to notify the server management user of the license anomaly on the target server. Based on the above verification license file authentication mechanism, unauthorized users are prevented from abusing server resources, and exceptions caused by compromised license files are prevented, further improving server stability.

[0060] X3. The controller receives the updated license information from the cloud authorization server after confirming that the license information to be updated is valid, and sends it to the logic device for security verification.

[0061] That is, after verifying the legitimacy of the license information to be updated, the controller sends the license information to the logic device, which then performs security verification on the license information and determines the matching unlock function code to be changed. The process of security verification and determining the unlock function code to be changed within the logic device is the same as described above, and will not be repeated here.

[0062] X4. The controller receives the unlock function code to be changed in response to the detection of the security verification passed feedback from the logic device and reconfigures the server functions according to the unlock function code to be changed.

[0063] like Figure 4 As shown in the sequence diagram, this application responds to server authorization changes through the controller, interacts with the cloud authorization server to verify the legality of the license file to be updated, and then completes the startup of server functions and resource configuration based on the license information to be updated. This application achieves the goal of not restarting the server during the license file update and function adjustment process, thereby improving server availability.

[0064] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0065] Based on the methods disclosed in the above embodiments, this application also provides a functional management system, such as... Figure 5 As shown, it specifically includes:

[0066] The data acquisition module 510 is used to acquire the encrypted license information pre-stored in the controller in response to the detection of controller firmware loading;

[0067] Data communication module 520 is used to send encrypted license information to the logic device for security verification;

[0068] The data communication module 520 is also used to receive an unlock function code from the logic device in response to the detection of a security verification pass.

[0069] Function management module 530 is used to manage server resources based on the unlock function code.

[0070] In some implementation scenarios, the data acquisition module 510 is also used to respond to a received server authorization change request by parsing the license information to be updated contained in the server authorization change request;

[0071] The data communication module 520 is also used to generate a license update instruction to the cloud authorization server based on the license information to be updated in order to verify the legality of the license information to be updated. The license update instruction includes the license information to be updated and the target server identifier.

[0072] The data communication module 520 is also used to receive the updated license information from the cloud authorization server after it has determined that the updated license information is legal, and send it to the logic device for security verification.

[0073] The data communication module 520 is also used to receive a change unlock function code from the logic device in response to the detection of a security verification pass.

[0074] The function management module 530 is also used to reconfigure server functions based on the unlock function code to be changed.

[0075] Embodiments of this application also provide an electronic device, including: one or more processors; and a memory associated with the one or more processors, the memory being used to store program instructions, which, when read and executed by the one or more processors, perform the following operations:

[0076] In response to the detection of controller firmware loading, the encrypted license information pre-stored within the controller is obtained;

[0077] Send encrypted license information to the logic device for security verification;

[0078] The receiving logic device responds to the detection of an unlock function code that has passed security verification.

[0079] Configure server functions based on the unlock function code.

[0080] In some implementation scenarios, when program instructions are read and executed by one or more processors, the following operations are also performed:

[0081] In response to receiving a server authorization change request, parse the license information to be updated contained in the server authorization change request;

[0082] The license update instruction is generated based on the license information to be updated and sent to the cloud authorization server to verify the legality of the license information to be updated. The license update instruction includes the license information to be updated and the target server identifier.

[0083] After receiving the updated license information from the cloud authorization server and confirming its legitimacy, the updated license information is sent to the logic device for security verification.

[0084] The receiving logic device responds to the detection of a security verification pass feedback of the pending unlock function code;

[0085] Reconfigure server functions based on the unlock function code to be changed.

[0086] In some implementation scenarios, when program instructions are read and executed by one or more processors, the following operations are also performed:

[0087] In response to the detection of a security verification failure, receive an abnormal alarm from the logic device;

[0088] Based on the abnormal alarm, the interrupt controller firmware was loaded.

[0089] In some implementation scenarios, when program instructions are read and executed by one or more processors, the following operations are also performed:

[0090] Parse the encrypted license information to obtain the license signature within the encrypted license information;

[0091] Verify the validity of the licensed signature based on the pre-stored public key;

[0092] Upon detecting a valid license signature, the security verification is confirmed to have passed.

[0093] In response to the detection of an invalid license signature, the security verification was confirmed to have failed.

[0094] In some implementation scenarios, when program instructions are read and executed by one or more processors, the following operations are also performed:

[0095] Parse the license file level in the encrypted license information;

[0096] Based on the license level and a pre-stored mapping table, the unlock function code is determined. The mapping table stores the correspondence between license file levels and function codes.

[0097] Send the unlock function code to the controller.

[0098] In some implementation scenarios, when program instructions are read and executed by one or more processors, the following operations are also performed:

[0099] Parse the license information to be updated to obtain the license signature and license document from the license information to be updated;

[0100] Verify the validity of the licensed signature based on the pre-stored public key;

[0101] In response to the detection that the license signature is valid, query the validity period of the license file;

[0102] In response to the detection that the license document is within its validity period, verify the uniqueness of the license document;

[0103] In response to the detection that the license document is unique, the validity of the license information to be updated is determined.

[0104] In some implementation scenarios, when program instructions are read and executed by one or more processors, the following operations are also performed:

[0105] Check if a historical server identifier matches the license document;

[0106] Since no historical server identifier was detected, the license information to be updated is deemed legitimate.

[0107] In response to the detection of a historical server identifier, verify whether the historical server identifier is consistent with the target server identifier;

[0108] In response to the detection that the historical server identifier matches the target server identifier, it is determined that the license information to be updated is legitimate;

[0109] In response to the detection that the historical server identifier is inconsistent with the target server identifier, it is determined that the license information to be updated is not legitimate.

[0110] in, Figure 6 An exemplary architecture of an electronic device is shown, which may include a processor 610, a video display adapter 611, a disk drive 612, an input / output interface 613, a network interface 614, and a memory 620. The processor 610, video display adapter 611, disk drive 612, input / output interface 613, network interface 614, and memory 620 can communicate with each other via a bus 630.

[0111] The processor 610 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solution provided in this application.

[0112] The memory 620 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 620 can store the operating system 621 for controlling the execution of the electronic device 600, and the basic input / output system (BIOS) 622 for controlling the low-level operations of the electronic device 600. Additionally, it can store a web browser 623, a data storage management system 624, and an icon font processing system 625, etc. The aforementioned icon font processing system 625 can be the application program that specifically implements the aforementioned steps in this embodiment. In summary, when implementing the technical solution provided in this application through software or firmware, the relevant program code is stored in the memory 620 and is called and executed by the processor 610.

[0113] Input / output interface 613 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touch screens, microphones, various sensors, etc., and output devices may include displays, speakers, vibrators, indicator lights, etc.

[0114] Network interface 614 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0115] Bus 630 includes a pathway for transmitting information between various components of the device, such as processor 610, video display adapter 611, disk drive 612, input / output interface 613, network interface 614, and memory 620.

[0116] In addition, the electronic device 600 can also obtain information on specific claim conditions from the virtual resource object claim condition information database for use in condition judgment.

[0117] It should be noted that although the above-described device only shows the processor 610, video display adapter 611, disk drive 612, input / output interface 613, network interface 614, memory 620, bus 630, etc., in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the solution of this application, and does not necessarily include all the components shown in the figures.

[0118] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above-described resource management method embodiments at runtime.

[0119] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0120] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above-described functional management method embodiments.

[0121] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above-described functional management method embodiments.

[0122] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0123] The functional management method provided in this application has been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and its core ideas. It should be noted that those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of this application.

Claims

1. A function management method, characterized in that, When applied in a controller, the method includes: In response to the detection of controller firmware loading, the encrypted license information pre-stored within the controller is obtained; The encrypted license information is sent to the logic device for security verification; The logic device receives an unlock function code in response to the detection that the security verification has passed. Configure server functions according to the unlock function code; After the server starts, the method includes: In response to receiving a server authorization change request, the system parses the license information to be updated contained in the server authorization change request; A license update instruction is generated based on the license information to be updated and sent to the cloud authorization server to verify the legality of the license information to be updated. The license update instruction includes the license information to be updated and the target server identifier. The system receives the updated license information from the cloud authorization server after confirming its legitimacy and sends it to the logic device for security verification. The logic device receives the pending unlock function code in response to the detection that the security verification has passed. Reconfigure the server functions according to the unlock function code to be changed; The cloud-based authorization server is integrated with the central management system to achieve centralized management of at least one license information contained within the cloud-based authorization server. The security verification of the logic device includes: Parse the encrypted license information to obtain the license signature within the encrypted license information; Verify the validity of the license signature using a pre-stored public key; In response to the detection that the license signature is valid, the security verification is confirmed to be passed, and the license file level in the encrypted license information is parsed; according to the license file level and a pre-stored mapping table, the unlock function code is determined, and the mapping table stores the correspondence between the license file level and the function code; Send the unlock function code to the controller; In response to the detection that the license signature is invalid, it is confirmed that the security verification has failed; The cloud-based authorization server verifies the legality of the license information to be updated, including: Parse the license information to be updated to obtain the license signature and license document from the license information to be updated; The validity of the license signature is verified using a pre-stored public key; In response to the detection that the license signature is valid, the validity period of the license file is queried; In response to detecting that the license document is within its validity period, query whether there is a historical server identifier that matches the license document; In response to the absence of the historical server identifier, it is determined that the license information to be updated is legitimate; In response to the detection of the existence of the historical server identifier, verify whether the historical server identifier is consistent with the target server identifier; In response to the detection that the historical server identifier is consistent with the target server identifier, it is determined that the license information to be updated is legitimate; In response to the detection that the historical server identifier is inconsistent with the target server identifier, it is determined that the license information to be updated is not legitimate.

2. The method according to claim 1, characterized in that, After sending the encryption license information to the logic device for security verification, the method further includes: In response to the detection that the security verification has failed, an abnormal alarm is received from the logic device; Based on the aforementioned abnormal alarm, the loading of the controller firmware is interrupted.

3. A function management system for implementing the function management method as described in any one of claims 1 to 2, characterized in that, The system includes: The data acquisition module is used to acquire the encrypted license information pre-stored in the controller in response to the detection of controller firmware loading; The data communication module is used to send the encrypted license information to the logic device for security verification; The data communication module is also used to receive the unlock function code from the logic device in response to the detection of a successful security verification. The function management module is used to manage server resources based on the unlock function code.

4. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for implementing the steps of the function management method as described in any one of claims 1 to 2 when executing the computer program.

5. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, it implements the steps of the function management method as described in any one of claims 1 to 2.

Citation Information

Patent Citations

  • Server security management method and device, equipment and medium

    CN119378004A