Firmware parameter operation control method, server and electronic equipment

By determining the user role and permission configuration information through the authorization server and selecting the target user's operation permissions, the problem of unauthorized operation in the system boot firmware configuration is solved, and security and rationality are improved.

CN120704765APending Publication Date: 2025-09-26LENOVO (BEIJING) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510885408.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

When adjusting the setting options of the system boot firmware in an electronic device, unauthorized operations are prone to occur, posing a security risk.

Method used

The user role and permission configuration information are determined by the authorization server, and based on this information, parameters that the target user has operation permissions for are selected from the candidate configuration parameters, and the configuration operation of the system boot firmware is controlled using encrypted authorization indication information.

Benefits of technology

This reduces users' unauthorized access to the system boot firmware, improves the security and rationality of configuration operations, and prevents security risks caused by improper configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120704765A_ABST
    Figure CN120704765A_ABST
Patent Text Reader

Abstract

The invention discloses a firmware parameter operation control method, a server and electronic equipment, in the method, an authorization server obtains a firmware operation request sent by a client, and the firmware operation request is used for requesting an operation system to guide at least one candidate configuration parameter of firmware; determining a target user role corresponding to a target user initiating the firmware operation request; based on permission configuration information associated with a target user role, determining a target configuration parameter with an operation permission of the target user from the at least one candidate configuration parameter; if at least one target configuration parameter is determined, authorization indication information is returned to the client, and the authorization indication information is used for indicating that the target user has the target configuration parameter with the operation authority. The client sends the authorization indication information to a configuration control component in the electronic equipment where the client is located; based on the authorization indication information, the configuration control component executes an operation on a target configuration parameter in the system boot firmware.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a firmware parameter operation control method, a server, and an electronic device. Background Art

[0002] While using an electronic device, you may need to adjust the settings of the system boot firmware, such as the Unified Extensible Firmware Interface (UEFI). However, currently, adjusting the settings of the system boot firmware in electronic devices can easily lead to unauthorized operations and even security risks. Summary of the Invention

[0003] On the one hand, the present application provides a firmware parameter operation control method, which is applied to an authorization server, including:

[0004] Obtaining a firmware operation request sent by a client, wherein the firmware operation request is used to request at least one candidate configuration parameter of an operating system boot firmware, wherein the operating system boot firmware is deployed in the electronic device where the client is located;

[0005] Determine a target user role corresponding to a target user who initiates the firmware operation request;

[0006] Obtaining permission configuration information associated with the target user role;

[0007] Based on the permission configuration information associated with the target user role, determining a target configuration parameter for which the target user has operation permission from the at least one candidate configuration parameter;

[0008] If at least one of the target configuration parameters is determined, authorization indication information is returned to the client, where the authorization indication information is used to indicate the target configuration parameters that the target user has the operation authority for.

[0009] In a possible implementation, the firmware parameter operation control method further includes: obtaining a security level corresponding to the candidate configuration parameter;

[0010] The permission configuration information associated with the target user role includes: at least one target security level corresponding to the configuration parameters of the target user role having the operation permission;

[0011] The determining, based on the permission configuration information associated with the target user role, a target configuration parameter for which the target user has operation permission from the at least one candidate configuration parameter includes:

[0012] Based on at least one target security level corresponding to the target user role and the security levels corresponding to the candidate configuration parameters, a target configuration parameter for which the target user has operation authority is determined from the at least one candidate configuration parameter.

[0013] In yet another possible implementation, the firmware operation request indicates an operation type of operating the candidate configuration parameter;

[0014] The permission configuration information associated with the target user role further includes: at least one target operation type corresponding to the target security level, the target operation type being an operation type for which the target user role has permission to operate the configuration parameters of the target security level;

[0015] The determining, based on at least one target security level corresponding to the target user role and the security levels corresponding to the candidate configuration parameters, a target configuration parameter for which the target user has operation authority from the at least one candidate configuration parameter includes:

[0016] Determining, from the at least one candidate configuration parameter, a target configuration parameter for which the target user has operation permission, based on at least one target security level corresponding to the target user role, at least one target operation type corresponding to each target security level, and the security level and operation type corresponding to each candidate configuration parameter;

[0017] The security level corresponding to the target configuration parameter belongs to the at least one target security level, and the operation type corresponding to the target configuration parameter belongs to at least one target operation type corresponding to the security level of the target configuration parameter in the permission configuration information associated with the target user role.

[0018] In another possible implementation, the at least one target security level corresponding to the configuration parameter for which the target user role has operation authority includes: at least one client type allowed to be used by the target user role and at least one target security level corresponding to the configuration parameter for which the client type has operation authority;

[0019] The permission configuration information associated with the target user role also includes: a maximum number of operations associated with the target security level corresponding to the client type, the maximum number of operations being the maximum number of configuration parameters of the target security level that the target user role is allowed to operate for the client type;

[0020] The firmware parameter operation control method further includes: determining a target client type corresponding to the client;

[0021] The determining, based on at least one target security level corresponding to the target user role and the security levels corresponding to the candidate configuration parameters, a target configuration parameter for which the target user has operation authority from the at least one candidate configuration parameter includes:

[0022] Determining, from the permission configuration information associated with the target user role, at least one target security level corresponding to the target client type and a maximum number of operations associated with each target security level corresponding to the target client type;

[0023] For each target security level corresponding to the target client type, based on the maximum number of operations associated with the target security level and the security level corresponding to each candidate configuration parameter, determine the target configuration parameters belonging to the target security level from the at least one candidate configuration parameter, and the number of the target configuration parameters does not exceed the maximum number of operations associated with the target security level.

[0024] In yet another possible implementation, if at least one target configuration parameter is determined, returning authorization indication information to the client includes:

[0025] If at least one target configuration parameter is determined, an authorization string is generated;

[0026] Encrypting the authorization string using the private key of the authorization server to obtain authorization verification information;

[0027] An authorization indication message is sent to the client, wherein the authorization indication message also indicates the authorization verification information, wherein the electronic device confirms that the at least one target configuration parameter is a configuration parameter that the target user has operation authority when decrypting the authorization string from the authorization verification information based on the public key of the authorization server.

[0028] In another aspect, the present application further provides a firmware parameter operation control method, applied to an electronic device, comprising:

[0029] Sending a firmware operation request to an authorization server through a client, wherein the firmware operation request is used to request operation of at least one candidate configuration parameter of a system boot firmware in the electronic device;

[0030] If authorization indication information returned by the authorization server is obtained, sending the authorization indication information to the configuration control component in the electronic device through the client, where the authorization indication information is used to indicate at least one target configuration parameter that the target user who initiated the firmware operation request has operation authority for, and the target configuration parameter belongs to the at least one candidate configuration parameter;

[0031] Based on the authorization indication information, the configuration control component performs an operation on the target configuration parameter in the system boot firmware.

[0032] In a possible implementation, the authorization indication information further includes: authorization verification information, where the authorization verification information is obtained by encrypting an authorization character string generated by the authorization server using a private key of the authorization server;

[0033] The configuration control component performs an operation on the target configuration parameter in the system boot firmware based on the authorization indication information, including:

[0034] Based on the authorization indication information, the configuration control component decrypts the authorization verification information using the public key corresponding to the authorization server;

[0035] If the authorization character string is decrypted from the authorization verification information, the configuration control component performs an operation on the target configuration parameter in the system boot firmware based on the authorization indication information.

[0036] In yet another possible implementation, the method further includes:

[0037] In response to the authorization indication information, obtaining, through the client, a timing condition for adjusting the system boot firmware;

[0038] transmitting the adjustment timing condition to the configuration control component via the client;

[0039] The configuration control component performs an operation on the target configuration parameter in the system boot firmware based on the authorization indication information, including:

[0040] When the adjustment timing condition is satisfied at the current moment, the configuration control component performs an operation on the target configuration parameter in the system boot firmware.

[0041] In another aspect, the present application further provides a server, comprising: a communication module and a processor;

[0042] The communication module is configured to obtain a firmware operation request sent by a client, wherein the firmware operation request is used to request at least one candidate configuration parameter of an operating system boot firmware, and the operating system boot firmware is deployed in the electronic device where the client is located;

[0043] The processor is configured to determine a target user role corresponding to a target user initiating the firmware operation request; obtain permission configuration information associated with the target user role; determine, based on the permission configuration information associated with the target user role, a target configuration parameter for which the target user has permission to operate from the at least one candidate configuration parameter; if at least one target configuration parameter is determined, return authorization indication information to the client via the communication module, wherein the authorization indication information is used to indicate the target configuration parameter for which the target user has permission to operate.

[0044] In yet another aspect, the present application further provides an electronic device, comprising: a communication module, a processor, a system boot firmware, and a configuration control component;

[0045] A client is running in the processor;

[0046] The communication module is configured to send a firmware operation request to an authorization server through a client, wherein the firmware operation request is used to request operation of at least one candidate configuration parameter of the system boot firmware;

[0047] the processor being configured to, upon obtaining authorization indication information returned by the authorization server, send the authorization indication information to the configuration control component through the client, wherein the authorization indication information is used to indicate at least one target configuration parameter with operation permission, the target configuration parameter being one of the at least one candidate configuration parameter;

[0048] The configuration control component is used to perform operations on the target configuration parameters in the system boot firmware based on the authorization indication information. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale.

[0050] Figure 1 A flowchart of the firmware parameter operation control method provided by this application on the authorization server side;

[0051] Figure 2 A schematic diagram of another flow chart of the firmware parameter operation control method provided by this application on the authorization server side;

[0052] Figure 3 Another flow chart of the firmware parameter operation control method provided by this application on the authorization server side

[0053] Figure 4Provides an example diagram of various indicators used to configure user permission configuration information and the categories that each indicator can be divided into for this application;

[0054] Figure 5 A flowchart of the firmware parameter operation control method provided by this application on the electronic device side;

[0055] Figure 6 A schematic diagram of the process interaction of the firmware parameter operation control method provided by this application;

[0056] Figure 7 A schematic diagram of an interaction flow between a client and a configuration control component in an electronic device in the firmware parameter operation control method of this application;

[0057] Figure 8 A schematic diagram of the composition architecture of the authorization server provided for this application;

[0058] Figure 9 A schematic diagram of the composition architecture of the electronic device provided in this application. DETAILED DESCRIPTION

[0059] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application. The terms used in the implementation methods of the present application are only used to explain the specific embodiments of the present application and are not intended to limit the present application. It is known to those skilled in the art that with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0060] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.

[0061] The application scenarios to which the firmware parameter operation control method of the present application is applicable include an authorization server and an electronic device, in which the system boot firmware and the client are deployed. The electronic device may also include a configuration control component, which is used to control the configuration parameters of the operating system boot firmware. The configuration control component can be the system boot firmware itself, or it can be a control component such as a baseboard management controller (BMC) outside the system boot firmware, without specific limitation.

[0062] The system boot firmware is used to boot the electronic device. It can be responsible for the electronic device's power-on self-test, hardware initialization, and loading the operating system loader. For example, the system boot firmware can be the Unified Extensible Firmware Interface (UEFI) or the Basic Input / Output System (BIOS), or other firmware that replaces the BIOS or UEFI for subsequent upgrades, without limitation.

[0063] The client in the electronic device may be a client that can establish a communication connection with the authorization server, such as a browser client or an application client, etc., without specific limitation.

[0064] In this application, the client can interact with the authorization server to determine the configuration parameters in the system boot firmware that the user of the client has the right to operate through the authorization server, so as to reasonably regulate the scope of authority of different users of the client to configure the system boot firmware, reduce unauthorized access or configuration of the system boot firmware, etc.

[0065] The firmware parameter operation control method of this application is introduced from the authorization server side and the electronic device side respectively below.

[0066] First, let’s explain it from the authorization server side. Figure 1 , shows a flow chart of a firmware parameter operation control method provided by the present application. The method of this embodiment can be applied to an authorization server. This embodiment may include:

[0067] S101: Obtain a firmware operation request sent by a client.

[0068] The firmware operation request is used to request at least one candidate configuration parameter of the operating system boot firmware. For example, the firmware operation request may include at least the name of the candidate configuration parameter required for the system boot firmware to operate.

[0069] The configuration parameters of the system boot firmware may also be referred to as configuration options or setting options. They may be options that can be configured or newly added in the system boot firmware. For example, configuration parameters may be options in the system boot firmware for controlling the hardware startup sequence, configuration items for implementing peripheral control, options for hardware monitoring, and options for power control, etc., without limitation. For ease of distinction, this application refers to the configuration parameters requested for operation in the firmware operation request as candidate configuration parameters.

[0070] It is understood that in actual applications, the firmware operation request may also indicate specific operation information for operating the candidate configuration parameter, wherein the specific operation information may include at least one of the operation type for operating the candidate configuration parameter and the target parameter value required to be configured for the candidate configuration parameter.

[0071] For example, the firmware operation request may further include at least the operation type of the candidate configuration parameter. The operation type may include, but is not limited to, a read operation, a write operation, a delete operation, or an additional operation of the candidate configuration parameter. Different candidate configuration parameters may correspond to different operation types.

[0072] The write operation on the candidate configuration parameter may be to modify or set the parameter value of the candidate configuration parameter. The parameter value of the candidate configuration parameter may be a specific value of the candidate configuration parameter or a status value of the candidate configuration parameter, such as changing the usage status of the candidate configuration parameter from an unused state to an enabled state.

[0073] The operation of adding the candidate configuration parameters may be adding function items corresponding to the candidate configuration parameters to the system boot firmware.

[0074] It is understood that if the operation type for manipulating a candidate configuration parameter is a read operation or a delete operation, and the parameter value of the candidate configuration parameter does not need to be changed, then the firmware operation request naturally does not need to include the parameter value of the candidate configuration parameter. However, if the operation type for manipulating a candidate configuration parameter is a write operation or an add operation, then the firmware operation request may also include the target parameter value to which the candidate configuration parameter needs to be adjusted or set.

[0075] As mentioned above, the system boot firmware is deployed in the electronic device where the client is located.

[0076] S102: Determine a target user role corresponding to a target user who initiates a firmware operation request.

[0077] The target user is the user who initiates the firmware operation request through the client.

[0078] There are many possible implementations for determining the target user who initiated the firmware operation request, which are not specifically limited. For example, the firmware operation request can carry a user identifier that can uniquely identify the target user, such as the user name, account number, or other identity identifier of the target user who initiated the firmware operation request. On this basis, the target user corresponding to the user identifier can be determined based on the user identifier carried in the firmware operation request. For another example, when a client establishes a communication connection with an authorization server, the connection request or login request initiated by the client can also carry the user identifier of the target user. Therefore, when the authorization server receives the firmware operation request sent by the client, it can be determined that the user who initiated the firmware operation request on the client side is the target user.

[0079] It is understandable that in scenarios such as when the electronic device is a specific device within an enterprise or a server, there may be multiple users using the electronic device. Therefore, there may be multiple possible target users for initiating firmware operation requests through the client. The identities of different target users may vary, and thus their operating permissions for the system boot firmware may also vary. Based on this, corresponding user roles can be configured for different users in the authorization server. For example, user roles can be divided into: super administrator, general administrator, first-level user, second-level user, and general user.

[0080] Among them, the user role corresponding to the user can also be dynamically adjusted according to the actual scenario needs, the user's position or identity changes, etc.

[0081] Based on this, the authorization server can query the user role configured for the target user, such as determining the user role corresponding to the target user based on the correspondence between different users and user roles. For ease of distinction, the user role corresponding to the target user is referred to as the target user role.

[0082] In particular, before determining the target user's target user role, the authorization server may also verify the legitimacy of the target user's login information, such as verifying whether the target user's username and password are authorized and legal. If so, the login information is determined to be legal. If the login information is illegal, the authorization server does not need to perform step S102 and subsequent operations and may directly return an authorization rejection indication to the client. This authorization rejection indication is used to indicate that the target user does not have permission to operate the configuration parameters of the operating system boot firmware.

[0083] S103: Obtain permission configuration information associated with the target user role.

[0084] The permission configuration information associated with the target user role is used to represent the scope of the target user role's operation permissions on the configuration parameters of the system boot firmware.

[0085] In this application, there are no restrictions on the specific information format of the permission configuration information or the specific method for limiting the scope of operation permissions. For example, the permission configuration information may include one or more of the names, parameter categories, and quantities of configuration parameters in the system boot firmware that the target user role has operation permissions for. Of course, the specific content of the permission configuration information can also be other, and there is no restriction on this.

[0086] In this application, the permission configuration information corresponding to different user roles may be different. On this basis, by configuring or adjusting the user role, the user can have different permission configuration information, thereby flexibly and dynamically controlling the operation permissions of different users for the configuration parameters in the system boot firmware.

[0087] S104: Based on the permission configuration information associated with the target user role, determine a target configuration parameter for which the target user has the permission to operate from at least one candidate configuration parameter.

[0088] In this application, the configuration parameters among the candidate configuration parameters that the target user role has operation permissions for are referred to as target configuration parameters.

[0089] It is understandable that the specific manner of specifying the operating authority scope of the target user role in the authority configuration information is different, and the specific implementation of determining the target configuration parameters will also be different.

[0090] For example, if the permission configuration information includes configuration parameters (such as the names of the configuration parameters) that the target user role has permission to operate, then it is only necessary to check whether each candidate configuration parameter belongs to the configuration parameters configured in the permission configuration information associated with the target user role. Accordingly, the target configuration parameter configured in the permission configuration information associated with the target user role can be determined from at least one candidate configuration parameter.

[0091] For example, if the permission configuration information includes the parameter categories of the configuration parameters that the target user role has operation permissions, it is necessary to determine the parameter category of each candidate configuration parameter, and from at least one candidate configuration parameter, determine the target configuration parameter whose corresponding parameter category belongs to the parameter category included in the permission configuration information associated with the target user role.

[0092] It is understandable that if, based on the permission configuration information associated with the target user role, it is determined that the target user role does not have the operation permission for the at least one candidate configuration parameter, then the determined target configuration parameter is empty.

[0093] S105: If at least one target configuration parameter is determined, authorization indication information is returned to the client.

[0094] The authorization indication information is used to indicate the target configuration parameters that the target user has the operation authority for.

[0095] It is understandable that since the authorization indication information indicates the target configuration parameters that the target user has operation authority for, after the electronic device obtains the authorization indication information through the client, the electronic device side will only allow the target user to operate the target configuration parameters that he has operation authority for.

[0096] In particular, if there is no target configuration parameter for which the target user has operation permission in at least one candidate configuration parameter, the authorization server may also return an authorization rejection indication to the client. The function of the authorization rejection indication is the same as described above.

[0097] From the above content, it can be seen that after the authorization server obtains the firmware operation request sent by the client of the electronic device, it will determine the target user role corresponding to the target user who initiated the firmware operation request, and based on the permission configuration information associated with the target user role, it will determine the target configuration parameter that the target user has the permission to operate from at least one candidate configuration parameter of the system boot firmware requested by the firmware operation request. On this basis, the authorization server can notify the client of each target configuration parameter that the target user has the permission to operate by sending authorization indication information to the client, so that the electronic device can confirm the target configuration parameters that the target user has the permission to operate, thereby reducing the possibility of the target user operating the configuration parameters that he does not have the permission to operate, and reducing the situation where the user performs unauthorized operations on the configuration parameters of the system boot firmware.

[0098] In this application, the specific information used to limit the scope of the operation authority in the authority configuration information associated with the target user role can have various possibilities. The following describes the possible situations of the authority configuration information.

[0099] In the first possible scenario, the permission configuration information associated with a user role includes at least one security level corresponding to the configuration parameters for which the user role has permission to operate. In this case, each user role only has permission to operate the configuration parameters of the corresponding security level configured in the associated permission configuration information.

[0100] The configuration parameters that different user roles have operation permissions to may correspond to different security levels. For example, a super administrator may have the permission to operate any configuration parameter related to the system boot firmware of an electronic device, while ordinary users can only operate configuration parameters that do not affect the security of the electronic device. Therefore, the permission configuration information associated with the super administrator may include: each security level corresponding to all configuration parameters in the system boot firmware; while the permission configuration information associated with ordinary users only includes: the lowest security level corresponding to configuration parameters that are not related to the security of the electronic device. Among them, the configuration parameters that affect the security of the electronic device can be configuration parameters related to the power-on security of the electronic device, configuration parameters related to the operation of the electronic device or the operation of the operating system, etc., without specific restrictions.

[0101] For this possible situation of permission configuration information, the following is combined with Figure 2 The firmware parameter operation control method of this application is introduced. Figure 2 , shows another flow chart of the firmware parameter operation control method provided by the present application. This embodiment is applied to an authorization server. The method of this embodiment may include:

[0102] S201: Obtain a firmware operation request sent by a client.

[0103] The firmware operation request is used to request at least one candidate configuration parameter of an operating system boot firmware, which is deployed in an electronic device where a client is located.

[0104] S202: For each candidate configuration parameter, obtain a security level corresponding to the candidate configuration parameter.

[0105] In the embodiment of the present application, the authorization server maintains security levels corresponding to different configuration parameters, or various configuration parameters included in different security levels.

[0106] The higher the security level of the configuration parameter, the greater the impact of the configuration parameter in the system boot firmware on the security of the electronic device. Therefore, the greater the impact of modifying, adjusting or accessing the configuration parameter on the electronic device.

[0107] For example, the security levels corresponding to the configuration parameters in the system boot firmware can be divided into: level 1 security level, level 2 security level, and level 3 security level. Among them, the configuration parameters corresponding to level 3 security level have the greatest impact on the security of the electronic device.

[0108] For example, configuration parameters in the system boot firmware can be divided into two categories based on whether they affect the security of the electronic device: security-related configuration parameters and non-security-related configuration parameters. Accordingly, the security level of the configuration parameters can be divided into two categories: security-related level and no security risk level.

[0109] Of course, there are other possibilities for dividing security levels, and there are no restrictions on this.

[0110] Based on the above, the authorization server can query the security level of each candidate configuration parameter.

[0111] S203: Determine a target user role corresponding to the target user who initiates the firmware operation request.

[0112] For step S203, reference may be made to the relevant introduction of the previous embodiment, which will not be repeated here.

[0113] S204: Obtain permission configuration information associated with the target user role.

[0114] In this embodiment, the permission configuration information associated with the target user role includes: at least one target security level corresponding to the configuration parameters of the target user role's operation permissions.

[0115] It should be noted that the order of step S202, step S203 and step S204 is not limited to Figure 2 As shown, in actual application, step S202 only needs to be executed before the subsequent step S205. Therefore, the order of step S202 and steps S203 and S204 can be interchanged or executed simultaneously.

[0116] S205 : Based on at least one target security level corresponding to the target user role and the security levels corresponding to the candidate configuration parameters, determine a target configuration parameter for which the target user has operation authority from the at least one candidate configuration parameter.

[0117] It can be understood that if the security level corresponding to the candidate configuration parameter belongs to at least one target security level corresponding to the target user role, then the candidate configuration parameter is determined to be a target configuration parameter for which the target user has operation permission. Conversely, if the security level corresponding to the candidate configuration parameter does not belong to at least one target security level corresponding to the target user role, then the candidate configuration parameter is determined not to be a target configuration parameter. Therefore, it can be seen that the target configuration parameter is a candidate configuration parameter whose security level belongs to at least one target security level corresponding to the target user role.

[0118] S206: If at least one target configuration parameter is determined, authorization indication information is returned to the client.

[0119] The authorization indication information is used to indicate target configuration parameters that the target user has the operation authority for.

[0120] It is understood that, given that the target user may have different specific operational requirements for different candidate configuration parameters, the firmware operation request further indicates the operation type to be performed on each candidate configuration parameter. Based on this, if the candidate configuration parameter falls within at least one target security level configured in the target user's permission configuration information, the target user may be confirmed to have permission to perform each operation type on the candidate configuration parameter.

[0121] In the second possible situation, considering that for the same configuration parameter, different types of operations performed on the configuration parameter will have different degrees of impact on the security of the electronic device and the system boot firmware, the permission configuration information associated with the target user role of this application includes not only at least one target security level corresponding to the configuration parameter for which the target user role has operation authority, but also at least one target operation type corresponding to each target security level.

[0122] The target operation type corresponding to the target security level is the operation type for which the target user role has permission to operate the configuration parameters of the target security level. For example, if the target security level is level 2, and the target operation types corresponding to level 2 include read and write operations, the target user role has permission to read and write configuration parameters of level 2, but does not have permission to delete configuration parameters of level 2.

[0123] In this possible case, the types of operations allowed by the same user role for configuration parameters of different security levels for which the user role has operation permissions may not be exactly the same.

[0124] For example, if the user role is a super administrator, the super administrator can perform any type of operation on configuration parameters of any security level. Therefore, the super administrator's permission configuration information defines that the super administrator has permission to perform any type of operation on configuration parameters of all security levels in the system boot firmware. If the user role is a level one user, although the user role can access configuration parameters of any security level, it only has read permission for configuration parameters of the highest security level, and does not have permission to perform operations such as write operations and delete operations. For configuration parameters of the first and second security levels other than the highest security level, the level one user has permission to perform any type of operation. Therefore, the permission configuration information of the level one user can be configured with various security levels that may correspond to any configuration parameter in the system boot firmware, but the operation type corresponding to the highest security level only includes read operations; while the operation types corresponding to the first and second security levels can include multiple operation types such as read operations, write operations, add operations, and delete operations.

[0125] On this basis, based on at least one target security level corresponding to the target user role, at least one target operation type corresponding to each target security level, and the security level and operation type corresponding to each candidate configuration parameter, the target configuration parameter that the target user has operation authority for can be determined from the at least one candidate configuration parameter.

[0126] It can be understood that if the security level of the candidate configuration parameter belongs to at least one target security level corresponding to the target user role, and the operation type corresponding to the candidate configuration parameter belongs to at least one target operation type corresponding to the security level of the candidate configuration parameter in the permission configuration information associated with the target user role, then it means that the candidate configuration parameter belongs to the target configuration parameter that the target user has operation permission.

[0127] For example, assuming that the permission configuration information associated with the target user role includes: a level 1 security level and a level 2 security level, and the operation type corresponding to the level 1 security level includes a read operation. If the security level of the candidate configuration parameter is level 1 security level, and the firmware operation request is used to request a read operation on the candidate configuration parameter, then the target user has permission to operate the candidate configuration parameter. If the security level of the candidate configuration parameter is level 1 security level, and the firmware operation request is used to request a write operation on the candidate configuration parameter, then since the target user does not have permission to write the candidate configuration parameter, the candidate configuration parameter is not a target configuration parameter for which the target user has permission to operate.

[0128] From this, it can be seen that the security level corresponding to the target configuration parameter belongs to at least one target security level corresponding to the target user role, and the operation type corresponding to the target configuration parameter belongs to at least one target operation type corresponding to the security level of the target configuration parameter in the permission configuration information associated with the target user role.

[0129] In the third possible scenario, in order to ensure the security of the system boot firmware, it is necessary to limit the maximum number of operations that users can perform on configuration parameters of certain security levels. Based on this, the permission configuration information associated with the target user role includes not only at least one target security level corresponding to the configuration parameters that the target user role has operation permissions for, but also the maximum number of operations associated with each target security level. Among them, the maximum number of operations associated with the target security level is the maximum number of configuration parameters of the target security level that the target user role is allowed to operate.

[0130] For example, the permission configuration information of the target user role may include: first-level security level: 3; second-level security level: 2, which means that the target user of this target user role is allowed to operate on a maximum of 3 configuration parameters belonging to the first-level security level at a time; and the target user of the target user role is only allowed to operate on a maximum of 2 configuration parameters belonging to the second-level security level at a time.

[0131] In this possible scenario, based on at least one target security level corresponding to the target user role and the maximum number of operations corresponding to each target security level, and in combination with the security levels corresponding to each candidate configuration parameter, a target configuration parameter for which the target user has operation permission can be determined from the at least one candidate configuration parameter. For each target security level, the number of target configuration parameters belonging to that target security level does not exceed the maximum number of operations corresponding to that target security level.

[0132] For example, for each target security level corresponding to the target user, if the number of candidate configuration parameters belonging to the target security level does not exceed the maximum number of operations corresponding to the target security level, then all candidate configuration parameters belonging to the target security level can be determined as target configuration parameters; if the number of candidate configuration parameters belonging to the target security level exceeds the maximum number of operations, the candidate configuration parameters with the highest number of operations can be randomly selected or the candidate configuration parameters with the highest number of operations that are closest to the target security level can be selected as target configuration parameters.

[0133] In the fourth possible scenario, considering that electronic devices can initiate firmware operation requests to the authorization server through different types of clients, and that different types of clients may differ in the types of configuration parameters that are suitable for requesting configuration, the permission configuration information associated with the target user role in this application may include: at least one client type allowed by the target user role, and at least one target security level corresponding to the configuration parameters that each client type has operation permission for. This possible scenario is equivalent to a special case of the first possible scenario.

[0134] Among them, the client type can be divided into application clients and web clients (or browser clients) that can establish a connection with the authorization server.

[0135] In this possible scenario, the target security level corresponding to the configuration parameters for which the target user role has permission to operate is related to the client type corresponding to the client initiating the firmware operation request. Based on this, in this possible scenario, before determining the target configuration parameters, it is also necessary to determine the target client type corresponding to the client initiating the firmware operation request. Accordingly, at least one target security level corresponding to the target client type can be first determined from the permission configuration information associated with the target user role. Then, based on the at least one target security level corresponding to the target client type and the security level corresponding to each candidate configuration parameter, the target configuration parameter for which the target user has permission to operate can be determined from the at least one candidate configuration parameter.

[0136] For example, assuming that the target user role is only allowed to initiate firmware operation requests through an application client, the permission configuration information corresponding to the target user role may include: at least one security level corresponding to the application client. Assuming that the security level corresponding to the application client includes a level 1 security level, then if the client initiating the firmware operation request is a web client, the target user does not have operation permissions for at least one candidate configuration parameter in the firmware operation request. If the client initiating the firmware operation request is an application client, the candidate configuration parameter corresponding to the level 1 security level may be determined as the target configuration parameter that the target user has operation permissions for.

[0137] It is understandable that the above-mentioned situations of permission configuration information can be combined with each other.

[0138] For example, the permission configuration information associated with the target user role may include: at least one client type that the target user role is allowed to use, at least one target security level corresponding to the configuration parameters that each client type has permission to operate, and the maximum number of operations associated with the target security level corresponding to each client type. In this case, the maximum number of operations associated with the target security level corresponding to a client type is the maximum number of configuration parameters of the target security level that the target user role is allowed to operate for that client type.

[0139] Accordingly, after determining the target client type corresponding to the client, at least one target security level corresponding to the target client type and the maximum number of operations associated with each target security level corresponding to the target client type can be determined from the permission configuration information associated with the target user role. For each target security level corresponding to the target client type, based on the maximum number of operations associated with the target security level and the security level corresponding to each candidate configuration parameter, target configuration parameters belonging to the target security level can be determined from the at least one candidate configuration parameter, with the number of target configuration parameters not exceeding the maximum number of operations associated with the target security level.

[0140] For another example, the permission configuration information associated with the target user role may include: at least one target security level corresponding to the configuration parameters for which the target user role has permission to operate, at least one target operation type corresponding to each target security level, and the maximum number of operations corresponding to each target security level. The process for determining the target configuration parameters in this case is similar to the second possible scenario, except that for each target security level, the number of target configuration parameters determined cannot exceed the maximum number of operations corresponding to that target security level.

[0141] The following describes the firmware parameter operation control method of this application by taking the combination of the above-mentioned several situations as an example of the permission configuration information associated with the target user role. Figure 3 , shows another flow chart of the firmware parameter operation control method provided by the present application. The method of this embodiment is applied to the authorization server. The method of this embodiment may include:

[0142] S301: Obtain a firmware operation request sent by a client.

[0143] The firmware operation request is used to request the operating system to boot at least one candidate configuration parameter of the firmware, and the firmware operation request indicates an operation type for operating the candidate configuration parameter.

[0144] The system boot firmware is deployed in the electronic device where the client is located.

[0145] S302: Determine the target client type corresponding to the client.

[0146] S303: For each candidate configuration parameter, obtain a security level corresponding to the candidate configuration parameter.

[0147] S304: Determine a target user role corresponding to the target user who initiates the firmware operation request.

[0148] S305: Obtain permission configuration information associated with the target user role.

[0149] In this embodiment, the permission configuration information associated with the target user role may include: at least one client type allowed to be used by the target user role, at least one target security level corresponding to the configuration parameters of the operation permissions of each client type, at least one target operation type allowed by the target security level corresponding to each client type, and the maximum number of operations associated with the target security level corresponding to each client type.

[0150] The maximum number of operations associated with the target security level is the maximum number of configuration parameters of the target security level that the target user role is allowed to operate for a certain client type.

[0151] In this embodiment, the user's operation rights for configuration parameters are limited from multiple dimensions. For ease of understanding, please refer to Figure 4 , which shows the various indicators referenced for configuring user permission configuration information in this application and the categories that each indicator can be divided into.

[0152] Depend on Figure 4 It can be seen that the indicators involved in the process of user operation permission management include: user role, option security level (that is, the security level of configuration parameters), client type, operation type and operation quantity.

[0153] User roles can be categorized as super administrators, first-level users, and regular users. Option security levels can be categorized as security-related options (i.e., security-related configuration parameters) and general options (i.e., configuration parameters not related to security). Client types can be categorized as application clients and web clients. Operation types can be categorized as read, add, delete, and modify. The number of operations can be categorized as greater than or equal to three.

[0154] exist Figure 4On this basis, the present application can configure the super administrator user role to allow any client type to perform any number of operations and any operation type on any configuration parameter. Accordingly, the super administrator's permission configuration information may include the following: all client types, each client type corresponds to security-related options and general options, the maximum number of operations corresponding to security-related options and general options is greater than 3, and the operation types corresponding to security-related options and general options can be any operation type.

[0155] Similarly, a user with a first-level user role can be configured to allow any operation on any number of common options through any type of client. Furthermore, any client can read, add, and modify fewer than three security options, but cannot delete any security options. The permission configuration information for this first-level user role can include: application clients and web clients, and the corresponding security levels for these two clients include security-related options and common options. The maximum number of operations for security-related options is three, and the corresponding operation types include read, add, and modify. The maximum number of operations for common options can be greater than three, and the corresponding operation types include read, add, modify, and delete.

[0156] For users with the role of "ordinary user," read and add operations can be configured to be performed on up to three common options through any client, but read operations can only be performed on up to three security options through the application client. Accordingly, the permission configuration information associated with ordinary users can include: application clients and web clients. The maximum number of operations for common options on the application and web clients is three, and the corresponding operation types for common options include read and add operations. The maximum number of operations for security-related options on the application client is also three, and the corresponding operation types for security-related options include only read operations.

[0157] It should be noted that the order of steps S302 and S303 is not limited to Figure 3 As shown, in actual application, the order of these two steps can be interchanged or performed in parallel. In addition, steps S302 and S303 can also be performed after step S304 or S305, or, while performing step S304 or S305, steps S302 and S303 can be performed synchronously, without specific limitation.

[0158] S306: Determine, from the permission configuration information associated with the target user role, at least one target security level corresponding to the target client type and a maximum number of operations and at least one operation type associated with each target security level corresponding to the target client type.

[0159] S307, for each target security level corresponding to the target client type, based on the maximum number of operations and at least one operation type associated with the target security level, and in combination with the security level and operation type corresponding to each candidate configuration parameter, determine from the at least one candidate configuration parameter a target configuration parameter that belongs to the target security level and does not exceed the maximum number of operations.

[0160] For each target security level corresponding to the target client type, the target configuration parameter is a candidate configuration parameter belonging to the target security level and the operation type belongs to the operation type associated with the target security level.

[0161] Combine Figure 4 For example, assuming the target user role is a common user and the target client type is a web client, then based on the common user's permission configuration information, when the common user initiates a firmware operation request using the web client, they are only allowed to operate on common options, and can read and add up to three configuration parameters belonging to common options. Therefore, if the security level of a candidate configuration parameter belongs to the security-related option, the target user does not have the operation permission to operate on the candidate configuration parameter. If there is at least one candidate configuration parameter with a security level belonging to the common option, up to three target configuration parameters can be selected from the at least one candidate configuration parameter with a security level belonging to the common option, and the operation type corresponding to the selected target configuration parameter belongs to the read operation or the add operation.

[0162] S308: If at least one target configuration parameter is determined, return authorization indication information to the client.

[0163] The authorization indication information is used to indicate the target configuration parameters that the target user has the operation authority for.

[0164] It is understood that in any of the above embodiments of the present application, if the firmware operation request includes the operation type corresponding to the candidate configuration parameter, then the authorization indication information may also indicate the operation type corresponding to the target configuration parameter in addition to indicating the target configuration parameter for which the operation permission is granted. For example, the authorization indication information may include: each target configuration parameter for which the target user has operation permission and the operation type corresponding to each target configuration parameter.

[0165] Furthermore, if the firmware operation request indicates a target parameter value corresponding to the target configuration parameter, the target parameter value corresponding to the target configuration parameter is the target parameter value to be configured for the target configuration parameter. For example, the target parameter value to be configured for the target configuration parameter may be the target parameter value to which the target configuration parameter is to be modified, or the target parameter value to be set when the target configuration parameter is added. Based on this, the authorization indication information may include: each target configuration parameter for which the target user has operation authority, as well as the operation type and target parameter value corresponding to each target configuration parameter.

[0166] The following describes the firmware parameter operation control method of the present application from the electronic device side. Figure 5 , shows a schematic diagram of an implementation flow of the firmware parameter operation control method provided by the present application on the electronic device side. The method of this embodiment may include:

[0167] S501: Send a firmware operation request to an authorization server through a client.

[0168] For example, the client obtains a firmware operation request input by a target user and sends the firmware operation request to the authorization server; or the client sends a firmware operation request to the authorization server based on a firmware operation application of the target user.

[0169] In one optional embodiment, after the client receives the firmware operation request or application input by the target user, the client may further verify whether the format of the firmware operation request or application is qualified. If the format of the firmware operation request or application is qualified, the client will send the firmware operation request to the authorization server. The qualified format of the firmware operation request or application may include, but is not limited to, indicating that the firmware operation request or application contains candidate configuration parameters for the requested operation and that the format of the candidate configuration parameters complies with parameter format requirements, etc.

[0170] The firmware operation request is used to request operation of at least one candidate configuration parameter of the system boot firmware in the electronic device. For example, the firmware operation request may include the at least one candidate configuration parameter requested to be operated.

[0171] Furthermore, the firmware operation request may also include the operation type corresponding to each candidate configuration parameter. Of course, when the operation type of the candidate configuration parameter is a write operation or an add operation, the firmware operation request may also include the target parameter value of the candidate configuration parameter.

[0172] Among them, regarding the firmware operation request, please refer to the previous introduction on the authorization server side, which will not be repeated here.

[0173] S502: If authorization indication information returned by the authorization server is obtained, the authorization indication information is sent to the configuration control component in the electronic device through the client.

[0174] As described above, the authorization indication information is used to indicate at least one target configuration parameter that the target user initiating the firmware operation request has operation authority for. The target configuration parameter belongs to at least one candidate configuration parameter indicated in the firmware operation request.

[0175] Among them, the specific implementation of the authorization server confirming the at least one target configuration parameter and generating the authorization indication information can be found in the relevant introduction of the authorization server side, which will not be repeated here.

[0176] As mentioned above, the configuration control component may be a system boot firmware or a control component such as a BMC, without any specific limitation.

[0177] S503: Based on the authorization indication information, the configuration control component performs an operation on the target configuration parameter in the system boot firmware.

[0178] The configuration control component may determine each target configuration parameter allowed to be operated in the system boot firmware based on the authorization indication information and perform operations such as reading, writing, deleting or adding each target configuration parameter.

[0179] In one possible scenario, the authorization indication information includes, in addition to at least one target configuration parameter for which operation permission is granted, the operation type corresponding to each target configuration parameter. Based on this, the target configuration parameter in the system boot firmware can be operated based on the operation type corresponding to each target configuration parameter. For example, if the operation type corresponding to the target configuration parameter is a read operation, the specific parameter value and other information of the target configuration parameter can be read from the system boot firmware and output. For example, if the operation type corresponding to the target configuration parameter is a delete operation, the target configuration parameter and its specific parameter value in the system boot firmware can be deleted.

[0180] Furthermore, the authorization indication information may also include: a target parameter value of a target configuration parameter. For any target configuration parameter, if the authorization indication indicates the operation type and target parameter value of the target configuration parameter, the configuration control component may perform an operation on the target configuration parameter in the system boot firmware based on the operation type and target parameter value of the target configuration parameter. For example, if the operation type corresponding to the target configuration parameter is a write operation, the parameter value of the target configuration parameter in the system boot firmware may be adjusted to the corresponding target parameter value. For another example, if the operation type corresponding to the target configuration parameter is an add operation, the target configuration parameter may be added to the system boot firmware, and the parameter value of the target configuration parameter may be configured to the corresponding target parameter value. The target parameter value of the target configuration parameter may be empty. For example, if the operation type corresponding to the target configuration parameter is a read operation or a delete operation, the target parameter value of the target configuration parameter may be empty.

[0181] In another possible implementation, the client may also send a firmware operation request to the configuration control component at the same time as sending the authorization indication information. Based on the firmware operation request, the configuration control component may determine the operation type corresponding to each target configuration parameter indicated in the authorization indication information, and may also determine the target parameter value corresponding to each target configuration parameter. The target parameter value may be empty.

[0182] It is understandable that if the configuration control component is a system boot firmware, then the system boot firmware can directly operate its corresponding target configuration parameters based on the authorization indication information.

[0183] If the configuration control component is a control component such as a BMC other than the system boot firmware, then the configuration control component can instruct the system boot firmware to operate the at least one target configuration parameter, such as sending an operation command to the system boot firmware, where the operation command indicates the at least one target configuration parameter. Of course, the operation command can also include the operation type and target parameter value of the target configuration parameter.

[0184] From the above content, it can be seen that after the client of the electronic device obtains the firmware operation request, the client can send the firmware operation request to the authorization server. If the client receives the authorization indication information returned by the authorization server, it can send the authorization indication information to the configuration control component in the electronic device, so that the configuration control component can only operate the target configuration parameters in the system boot firmware that the target user has the operation authority based on the authorization indication information, thereby reducing the possibility of users operating the configuration parameters in the system boot firmware that they do not have the operation authority, and reducing the situation where users perform unauthorized operations on the configuration parameters of the system boot firmware.

[0185] It is understandable that in order to enable the electronic device to detect whether the authorization indication information is legal authorization indication information issued by the authorization server. In the present application, the authorization server may also generate authorization verification information indicating that the authorization indication information comes from the authorization server before feeding back the authorization indication information to the client. On this basis, the authorization verification information returned by the authorization server to the client also indicates the authorization verification information. Accordingly, the electronic device will confirm that the at least one target configuration parameter indicated in the authorization indication information is a configuration parameter that the target user has operation authority only when the authorization string is decrypted from the authorization verification information based on the public key of the authorization server.

[0186] The following is an explanation from the perspective of the interaction between the authorization server and the electronic device. Figure 6 Another flow chart of the firmware parameter operation control method provided by the present application is shown. The method of this embodiment is applied to an authorization server. The method of this embodiment may include:

[0187] S601: A client in an electronic device sends a firmware operation request to an authorization server.

[0188] The firmware operation request is used to request operation of at least one candidate configuration parameter of the system boot firmware in the electronic device. The firmware operation request also includes the operation type corresponding to each candidate configuration parameter. Of course, the firmware operation request may also include: the target parameter value corresponding to the candidate configuration parameter.

[0189] S602: The authorization server determines a target user role corresponding to the target user who initiates the firmware operation request.

[0190] For example, in one optional embodiment, the firmware operation request may also include a user identifier of the target user initiating the firmware operation request. Accordingly, the authorization server may determine the target user role corresponding to the target user initiating the firmware operation request based on the user identifier. For example, the target user role corresponding to the target user's user identifier may be determined based on the correspondence between user identifiers and user roles of different users.

[0191] S603: The authorization server obtains permission configuration information associated with the target user role.

[0192] S604: The authorization server determines, based on the permission configuration information associated with the target user role, a target configuration parameter for which the target user has the permission to operate from at least one candidate configuration parameter.

[0193] For the above steps S602 to S604, reference can be made to the related introduction of the previous embodiment on the authorization server side, which will not be repeated here.

[0194] S605: If at least one target configuration parameter is determined, the authorization server generates an authorization string.

[0195] S606: The authorization server encrypts the authorization string using its private key to obtain authorization verification information.

[0196] S607: The authorization server sends authorization instruction information to the client of the electronic device.

[0197] In this embodiment, the authorization indication information not only indicates at least one target configuration parameter for which the target user has permission to operate, but also indicates the authorization verification information. Of course, the authorization indication information may also indicate the operation type and target parameter value corresponding to each target configuration parameter. The target parameter value corresponding to a target configuration parameter may be empty. For example, if the operation type corresponding to the target configuration parameter is a read operation, the target parameter value of the target configuration parameter is empty.

[0198] In addition, to enable administrators and other users to obtain information from the authorization server regarding operations on configuration parameters of the system boot firmware in electronic devices, the authorization server may also generate a processing log corresponding to the firmware operation request and send the processing log to the target device. The processing log may include information such as the target user corresponding to the firmware operation request, at least one authorized target configuration parameter corresponding to the firmware operation request, the operation type of each target configuration parameter, and the target parameter value.

[0199] S608: The client of the electronic device sends the authorization instruction information to the configuration control component in the electronic device.

[0200] S609: Based on the authorization indication information, the configuration control component uses the public key corresponding to the authorization server to decrypt the authorization verification information.

[0201] The configuration control component may be pre-configured with a public key corresponding to the authorization server.

[0202] S610: If the authorization character string is decrypted from the authorization verification information, the configuration control component performs operations on target configuration parameters in the system boot firmware based on the authorization indication information.

[0203] It can be understood that if the configuration control component can successfully decrypt the authorization string from the authorization verification information using the public key of the authorization server, it means that the authorization indication information is a legal authorization indication information issued by the authorization server. In this case, the configuration control component can operate on the target configuration parameters in the system boot firmware based on the target configuration parameters indicated in the authorization indication information.

[0204] Of course, if the configuration control component cannot decrypt the authorization string from the authorization verification information using the public key of the authorization server, then the configuration control component can confirm that the authorization indication information is illegal, and thus will not respond to the authorization indication information, and naturally will not operate the target configuration parameters in the system boot firmware.

[0205] It is understandable that after initiating a firmware operation request, the target user may not necessarily wish to immediately operate the corresponding configuration parameters in the system boot firmware. For example, the target user may wish to operate the configuration parameters in the system boot firmware when the electronic device is powered off, or during a period when the electronic device has a low workload. Based on this, in response to the authorization indication information returned by the authorization server, the client can obtain the adjustment timing conditions for the system boot firmware. The client then transmits the adjustment timing conditions to the configuration control component.

[0206] The adjustment timing condition may be a target time for the operating system to boot the firmware, or an operating state condition of the electronic device. For example, the adjustment timing condition may be a time corresponding to one hour after the current time, or when the electronic device receives a shutdown instruction.

[0207] The client transmitting the adjustment timing condition to the configuration control component may be by the client proactively sending the adjustment timing condition information to the transmission configuration control component simultaneously with or after sending the authorization indication information to the configuration control component. For example, if the client is a web client, if the web client exits, the configuration control component will be unable to interact with the web client. In this case, the web client can proactively send the adjustment timing condition corresponding to the system boot firmware to the configuration control component.

[0208] The client may transmit the adjustment timing condition to the configuration control component by, after receiving a configuration timing query request from the configuration control component, responding to the configuration timing query request and transmitting the adjustment timing condition to the configuration control component. The configuration timing query request may be sent by the configuration control component after receiving the authorization indication information.

[0209] The configuration time query request is used to request the timing for operating the target configuration parameters in the system boot firmware. For example, if the client is an application client, the configuration control component can establish a connection with the application client and send the configuration timing query request to the client at any time.

[0210] When the client responds to the configuration time query request, transmitting the adjustment timing condition to the configuration control component may be directly sending specific information of the adjustment timing condition to the configuration control component, or may be sending only information on whether the adjustment timing condition is currently met to the configuration control component, without specific limitation.

[0211] On this basis, the configuration control component can perform operations on target configuration parameters in the system boot firmware: if the adjustment timing condition is met at the current moment, the configuration control component performs operations on the target configuration parameters in the system boot firmware. For example, if the adjustment event condition is the electronic device shutting down, the configuration control component will perform operations on the corresponding target configuration parameters in the system boot firmware before the electronic device meets the shutdown condition and shuts down. Only after the operations on the target configuration parameters in the system boot firmware are completed will the electronic device shut down normally.

[0212] In particular, if the configuration control component is a BMC or other control component other than the system boot firmware, then when the configuration control component determines that the current moment meets the adjustment timing condition, it sends the authorization indication information to the system boot firmware, or sends at least one target configuration parameter indicated in the authorization indication information and the operation type and target parameter value of the target configuration parameter to the system boot firmware, so that the system boot firmware operates the target configuration parameter in the system boot firmware based on the operation type and target parameter value of the target configuration parameter.

[0213] For ease of understanding, the following description is made by taking the client as the application client and the configuration control component as the system boot firmware itself, and for ease of intuitive understanding, the description is made by taking the system boot firmware as UEFI as an example. Figure 7 A schematic diagram of an interaction process between a client and a configuration control component in an electronic device in the firmware parameter operation control method of the present application is shown. In this embodiment, taking the configuration control component and the system boot firmware both being UEFI as an example, the method of this embodiment may include:

[0214] S701 : In response to a firmware operation request initiated by a target user, send a firmware operation request to an authorization server.

[0215] The firmware operation request is used to request operation of at least one candidate configuration parameter of UEFI in the electronic device, and the firmware operation request indicates the operation type and target parameter value of each candidate configuration parameter, wherein the target parameter value of the candidate configuration parameter can be empty.

[0216] In an optional manner, the client may further detect whether the request format of the firmware operation request is qualified. If the request format of the firmware operation request is unqualified, the firmware operation request may be discarded; if the request format of the firmware operation request is qualified, the firmware operation request may be sent to the authorization server. The qualified request format of the firmware operation request may include, for example, that the candidate configuration parameters indicated in the firmware operation request are not empty, and that the operation types corresponding to the candidate configuration parameters are not empty, etc., without limitation.

[0217] In this embodiment, the client sends a firmware operation request to the authorization server in response to the firmware operation request initiated by the target user as an example. The other situations mentioned above are also applicable to this embodiment and will not be described in detail here.

[0218] S702: If the client obtains authorization indication information returned by the authorization server, the client sends the authorization indication information to UEFI.

[0219] The authorization indication information is used to indicate at least one target configuration parameter with operation permission, the operation type and target parameter value corresponding to each target configuration parameter. The target configuration parameter belongs to at least one candidate configuration parameter indicated in the firmware operation request.

[0220] In this application, the authorization indication information also includes authorization verification information, which is obtained by encrypting the authorization string generated by the authorization server using the authorization server's private key. In this case, the authorization indication information can be considered as two parts: one part is the operation command, and the other part is the authorization verification information (relative to the token used for verification). The operation command includes at least one target configuration parameter, the operation type corresponding to each target configuration parameter, and the target parameter value.

[0221] S703: In response to the authorization indication information, the client obtains the adjustment timing condition of the UEFI.

[0222] The adjustment timing condition may be an adjustment timing condition that is prompted to be set by the user after the client obtains the authorization indication information.

[0223] The adjustment timing condition may also be set by the target user when initiating the firmware operation request or thereafter; however, the client obtains the adjustment timing condition configured by the user after obtaining the authorization indication information.

[0224] The order of step S703 and step S702 can be interchanged, or they can be executed simultaneously, without any specific limitation.

[0225] S704: Based on the authorization indication information, UEFI decrypts the authorization verification information using the public key corresponding to the authorization server.

[0226] The public key corresponding to the authorization server may be pre-configured in UEFI.

[0227] S705: If the UEFI decrypts the authorization string from the authorization verification information, the UEFI caches the target configuration parameters indicated in the authorization indication information and the operation type and target parameter value corresponding to each target configuration parameter.

[0228] It is understandable that if the UEFI cannot decrypt the authorization verification information using the public key of the authorization server, the UEFI may discard the authorization indication information and will not perform related operations on its own configuration parameters.

[0229] S706: UEFI obtains adjustment timing conditions for operating each target configuration parameter from the client.

[0230] S707: If it is determined that the current moment meets the adjustment timing condition, the UEFI performs operations on each target configuration parameter in the UEFI based on each cached target configuration parameter and the operation type and target parameter value corresponding to each target configuration parameter.

[0231] For example, UEFI obtains each target configuration parameter cached by itself and the operation type and target parameter value corresponding to each target configuration parameter, and for each target configuration parameter, based on the operation type and target parameter value corresponding to the target configuration parameter, performs operations such as reading, writing, deleting, or adding the target configuration parameter in UEFI.

[0232] It is understandable that if the adjustment timing condition is not met at the current moment, UEFI will still maintain the cache of each target configuration parameter and the operation type and target parameter value corresponding to each target configuration parameter, and continue monitoring until the adjustment timing condition is met.

[0233] It is understandable that the above description is based on the example that both the system boot firmware and the configuration control component are UEFI. For the case where both the system boot firmware and the configuration control component are BIOS, it is only necessary to change Figure 7 In this embodiment, UEFI can be replaced with BIOS. If the configuration control component is a BMC or other control components other than the system boot firmware, the present embodiment is also applicable. It is only necessary to replace the operation of performing each target configuration parameter in UEFI in step S706 with instructing the system boot firmware to perform the operation on each target parameter.

[0234] On the other hand, the present application also provides a server, such as Figure 8 A schematic diagram of the structure of a server provided by the present application is shown. The server comprises at least: a communication module 801 and a processor 802;

[0235] The communication module 801 is configured to obtain a firmware operation request sent by a client, wherein the firmware operation request is used to request at least one candidate configuration parameter of an operating system boot firmware deployed in the electronic device where the client is located;

[0236] Processor 802 is used to determine a target user role corresponding to the target user who initiates the firmware operation request; obtain permission configuration information associated with the target user role; based on the permission configuration information associated with the target user role, determine a target configuration parameter for which the target user has operation permission from the at least one candidate configuration parameter; if at least one target configuration parameter is determined, return authorization indication information to the client through the communication module, wherein the authorization indication information is used to indicate the target configuration parameter for which the target user has operation permission.

[0237] Among them, the relevant operations performed by the processor in the server can be found in the previous introduction to the authorization server side, which will not be repeated here.

[0238] It is understandable that the server may further include a memory 803 for storing programs required for the processor to perform operations.

[0239] Of course, the server may also include components such as an input device and a display device, without specific limitation.

[0240] On the other hand, the present application also provides an electronic device. Figure 9 , shows a schematic diagram of the structure of an electronic device provided by the present application, which may include: a communication module 901, a processor 902, a system boot firmware 903, and a configuration control component 904. The configuration control component and the system boot firmware may be the same firmware or different firmware.

[0241] A client is running in the processor 902 .

[0242] The communication module 901 is configured to send a firmware operation request to an authorization server via a client, wherein the firmware operation request is configured to request operation of at least one candidate configuration parameter of the system boot firmware 903 in the electronic device;

[0243] The processor 902 is configured to, upon obtaining authorization indication information returned by the authorization server, send the authorization indication information to a configuration control component in the electronic device through the client, where the authorization indication information indicates at least one target configuration parameter with operation permission, where the target configuration parameter is one of the at least one candidate configuration parameter;

[0244] The configuration control component 904 is configured to perform operations on the target configuration parameters in the system boot firmware based on the authorization indication information.

[0245] The related operations performed by the processor and the configuration control component can refer to the introduction of the related operations performed by the client and the configuration control component on the electronic device side, which will not be repeated here.

[0246] Of course, the electronic device may also include: part or all of the components such as an input device, an output device, and a memory, without specific limitation.

[0247] A computer program product is also provided in an embodiment of the present application, including computer-readable instructions. When the computer-readable instructions are executed on an electronic device, the electronic device implements any firmware parameter operation control method provided in the embodiment of the present application.

[0248] A computer-readable storage medium is also provided in an embodiment of the present application. The storage medium carries one or more computer programs. When the one or more computer programs are executed by an electronic device, the electronic device can implement any firmware parameter operation control method provided in the embodiment of the present application.

[0249] It should also be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided in this application, the connection relationship between the modules indicates that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines.

[0250] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus necessary general hardware, and of course can also be implemented by special hardware including application-specific integrated circuits, special CPUs, special memories, special components, etc. In general, all functions performed by computer programs can be easily implemented with corresponding hardware, and the specific hardware structures used to implement the same function can also be diverse, such as analog circuits, digital circuits or special circuits, etc. However, for the present application, software program implementation is a better implementation method in most cases. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a readable storage medium, such as a computer's floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk or optical disk, etc., and includes a number of instructions to enable a computer device (which can be a personal computer, training equipment, or network equipment, etc.) to execute the methods described in each embodiment of the present application.

[0251] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments may be implemented in the form of a computer program product.

[0252] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, a computer, a training device or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website, a computer, a training device or a data center. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a training device, a data center, etc. that includes one or more available media integrations. The available medium can be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

Claims

1. A firmware parameter operation control method, applied to an authorization server, comprising: Obtaining a firmware operation request sent by a client, wherein the firmware operation request is used to request at least one candidate configuration parameter of an operating system boot firmware, wherein the operating system boot firmware is deployed in the electronic device where the client is located; Determine a target user role corresponding to a target user who initiates the firmware operation request; Obtaining permission configuration information associated with the target user role; Based on the permission configuration information associated with the target user role, determining a target configuration parameter for which the target user has operation permission from the at least one candidate configuration parameter; If at least one of the target configuration parameters is determined, authorization indication information is returned to the client, where the authorization indication information is used to indicate the target configuration parameters that the target user has the operation authority for.

2. The firmware parameter operation control method according to claim 1, further comprising: Obtaining a security level corresponding to the candidate configuration parameter; The permission configuration information associated with the target user role includes: at least one target security level corresponding to the configuration parameters of the target user role having the operation permission; The determining, based on the permission configuration information associated with the target user role, a target configuration parameter for which the target user has operation permission from the at least one candidate configuration parameter includes: Based on at least one target security level corresponding to the target user role and the security levels corresponding to the candidate configuration parameters, a target configuration parameter for which the target user has operation authority is determined from the at least one candidate configuration parameter.

3. The firmware parameter operation control method according to claim 2, wherein the firmware operation request indicates an operation type of operating the candidate configuration parameter; The permission configuration information associated with the target user role also includes: At least one target operation type corresponding to the target security level, the target operation type being an operation type for which the target user role has operation authority over the configuration parameters of the target security level; The determining, based on at least one target security level corresponding to the target user role and the security levels corresponding to the candidate configuration parameters, a target configuration parameter for which the target user has operation authority from the at least one candidate configuration parameter includes: Determining, from the at least one candidate configuration parameter, a target configuration parameter for which the target user has operation permission, based on at least one target security level corresponding to the target user role, at least one target operation type corresponding to each target security level, and the security level and operation type corresponding to each candidate configuration parameter; The security level corresponding to the target configuration parameter belongs to the at least one target security level, and the operation type corresponding to the target configuration parameter belongs to at least one target operation type corresponding to the security level of the target configuration parameter in the permission configuration information associated with the target user role.

4. The firmware parameter operation control method according to claim 2, wherein the at least one target security level corresponding to the configuration parameter for which the target user role has operation authority comprises: At least one client type allowed by the target user role and at least one target security level corresponding to the configuration parameters for which the client type has operation permissions; The permission configuration information associated with the target user role also includes: a maximum number of operations associated with the target security level corresponding to the client type, the maximum number of operations being the maximum number of configuration parameters of the target security level that the target user role is allowed to operate for the client type; The firmware parameter operation control method further includes: determining a target client type corresponding to the client; The determining, based on at least one target security level corresponding to the target user role and the security levels corresponding to the candidate configuration parameters, a target configuration parameter for which the target user has operation authority from the at least one candidate configuration parameter includes: Determining, from the permission configuration information associated with the target user role, at least one target security level corresponding to the target client type and a maximum number of operations associated with each target security level corresponding to the target client type; For each target security level corresponding to the target client type, based on the maximum number of operations associated with the target security level and the security level corresponding to each candidate configuration parameter, determine the target configuration parameters belonging to the target security level from the at least one candidate configuration parameter, and the number of the target configuration parameters does not exceed the maximum number of operations associated with the target security level.

5. The firmware parameter operation control method according to claim 1, wherein if at least one target configuration parameter is determined, returning authorization indication information to the client comprises: If at least one target configuration parameter is determined, an authorization string is generated; Encrypting the authorization string using the private key of the authorization server to obtain authorization verification information; An authorization indication message is sent to the client, wherein the authorization indication message also indicates the authorization verification information, wherein the electronic device confirms that the at least one target configuration parameter is a configuration parameter that the target user has operation authority when decrypting the authorization string from the authorization verification information based on the public key of the authorization server.

6. A firmware parameter operation control method, applied to an electronic device, comprising: Sending a firmware operation request to an authorization server through a client, wherein the firmware operation request is used to request operation of at least one candidate configuration parameter of a system boot firmware in the electronic device; If authorization indication information returned by the authorization server is obtained, sending the authorization indication information to the configuration control component in the electronic device through the client, where the authorization indication information is used to indicate at least one target configuration parameter that the target user who initiated the firmware operation request has operation authority for, and the target configuration parameter belongs to the at least one candidate configuration parameter; Based on the authorization indication information, the configuration control component performs an operation on the target configuration parameter in the system boot firmware.

7. The firmware parameter operation control method according to claim 6, wherein the authorization indication information further comprises: Authorization verification information, where the authorization verification information is obtained by encrypting the authorization string generated by the authorization server using the private key of the authorization server; The configuration control component performs an operation on the target configuration parameter in the system boot firmware based on the authorization indication information, including: Based on the authorization indication information, the configuration control component decrypts the authorization verification information using the public key corresponding to the authorization server; If the authorization character string is decrypted from the authorization verification information, the configuration control component performs an operation on the target configuration parameter in the system boot firmware based on the authorization indication information.

8. The firmware parameter operation control method according to claim 6 or 7, further comprising: In response to the authorization indication information, obtaining, through the client, a timing condition for adjusting the system boot firmware; transmitting the adjustment timing condition to the configuration control component via the client; The configuration control component performs an operation on the target configuration parameter in the system boot firmware based on the authorization indication information, including: When the adjustment timing condition is satisfied at the current moment, the configuration control component performs an operation on the target configuration parameter in the system boot firmware.

9. A server comprising: Communication modules and processors; The communication module is configured to obtain a firmware operation request sent by a client, wherein the firmware operation request is used to request at least one candidate configuration parameter of an operating system boot firmware, and the operating system boot firmware is deployed in the electronic device where the client is located; The processor is configured to determine a target user role corresponding to a target user initiating the firmware operation request; Obtaining permission configuration information associated with the target user role; Based on the permission configuration information associated with the target user role, determine the target configuration parameter that the target user has the operation permission for from the at least one candidate configuration parameter; if at least one of the target configuration parameters is determined, return authorization indication information to the client through the communication module, and the authorization indication information is used to indicate the target configuration parameter that the target user has the operation permission for.

10. An electronic device comprising: Communication module, processor, system boot firmware and configuration control components; A client is running in the processor; The communication module is configured to send a firmware operation request to an authorization server through a client, wherein the firmware operation request is used to request operation of at least one candidate configuration parameter of the system boot firmware; the processor being configured to, upon obtaining authorization indication information returned by the authorization server, send the authorization indication information to the configuration control component through the client, wherein the authorization indication information is used to indicate at least one target configuration parameter with operation permission, the target configuration parameter being one of the at least one candidate configuration parameter; The configuration control component is used to perform operations on the target configuration parameters in the system boot firmware based on the authorization indication information.