Server security control device and server

By introducing a key storage module into the server and connecting it to the BMC/CPLD control peripheral interface for key verification, the problem of data leakage caused by unmanaged server peripheral interfaces is solved, and the prevention of unauthorized devices and the improvement of data security are achieved.

CN120805205APending Publication Date: 2025-10-17SHENZHEN YIWANKE DATA EQUIP TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510821034.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

The existing server's peripheral interfaces are not securely managed, allowing unauthorized devices to directly access the server, leading to data leaks and security risks.

Method used

A key storage module is introduced to control the connection between the peripheral interfaces of the BMC and PCH and the peripheral interfaces of the motherboard through the BMC and CPLD. Key verification is performed, and the device is allowed to connect only when the key verification is successful; otherwise, the connection is blocked.

Benefits of technology

Effectively prevents unauthorized devices from accessing the server through the peripheral interfaces of BMC and PCH, avoiding data leakage and improving server data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120805205A_ABST
    Figure CN120805205A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of servers, and discloses a server security control device and a server, and the server security control device comprises a secret key storage module which is used for storing a secret key of the server; the mainboard comprises a BMC, a CPLD, a PCH and a secret key interface, the CPLD is connected with the BMC and the PCH, the secret key interface is connected with the BMC and the CPLD, and the secret key interface is used for being connected with the secret key storage module in an inserted mode; the BMC is used for reading the secret key when it is determined that the secret key storage module is in place and verifying the secret key; the CPLD is used for controlling the peripheral interfaces of the BMC and the PCH to be communicated with the peripheral interface of the mainboard after determining that the secret key storage module is in place and receiving a verification pass signal sent by the BMC; and after determining that the secret key storage module is not in place or determining that the secret key storage module is in place and receiving a verification failure signal sent by the BMC, controlling the peripheral interfaces of the BMC and the PCH not to be communicated with the peripheral interface of the mainboard. In this way, data of the server can be prevented from being leaked through the peripheral interface of the server.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The embodiment of the present application relates to the technical field of server, in particular to a server security control device and a server. BACKGROUND

[0002] The server plays a vital role in the modern computing environment, which provides large-capacity data storage space for storing various types of data, including website content, application data, user information, etc., if the data is leaked or maliciously used, it will cause huge loss, therefore, it is crucial to protect the security of server data.

[0003] The peripheral interface of the existing server is open, and the connection of the peripheral interface and the external device is not limited and managed. When the unauthorized external device is connected to the peripheral interface of the server, the data of the server may be illegally read, copied or transmitted, resulting in the leakage of the data of the server. SUMMARY

[0004] In view of the above problems, the embodiment of the present application provides a server security control device and a server, which can avoid the leakage of the data of the server through the peripheral interface of the server.

[0005] According to an aspect of the embodiment of the present application, a server security control device is provided, which comprises: a secret key storage module for storing a secret key of a server; a mainboard comprising a BMC, a CPLD, a PCH and a secret key interface, the CPLD being connected with the BMC and the PCH respectively, the secret key interface being connected with the BMC and the CPLD respectively, and the secret key interface being used for inserting the secret key storage module; wherein the BMC is used for reading the secret key when it is determined that the secret key storage module is in place, and verifying the secret key, and if the secret key verification is passed, a verification passed signal is sent to the CPLD, and if the secret key verification is not passed, a verification not passed signal is sent to the CPLD; the CPLD is used for: when it is determined that the secret key storage module is in place and the verification passed signal sent by the BMC is received, controlling the peripheral interface of the BMC and the PCH to be in communication with the peripheral interface of the mainboard, so that the external device connected with the peripheral interface of the mainboard can be in communication with the peripheral interface of the BMC and the PCH; and when it is determined that the secret key storage module is not in place, or when it is determined that the secret key storage module is in place and the verification not passed signal sent by the BMC is received, controlling the peripheral interface of the BMC and the PCH to be not in communication with the peripheral interface of the mainboard, so that the external device is not in communication with the peripheral interface of the BMC and the PCH.

[0006] In an alternative manner, the peripheral interface of the BMC is a first VGA interface, the peripheral interface of the PCH is a first USB interface, the peripheral interface of the motherboard comprises a second VGA interface and a second USB interface, and the external device comprises a VGA device and a USB device; the motherboard further comprises a CPU connected with the PCH; the BMC is connected with the PCH, and the BMC is further configured to, after the secret key verification passes, decrypt the video data sent by the PCH, and send a loading instruction to the PCH, so that the PCH sends the loading instruction to an operating system running in the CPU, to enable the operating system to load a driver program of the first USB interface according to the loading instruction; wherein the video data is sent by the CPU to the PCH; and when it is determined that the secret key storage module is not in place or the secret key verification does not pass, encrypt the video data sent by the PCH, and send an uninstalling instruction to the PCH, so that the PCH sends the uninstalling instruction to the operating system, to enable the operating system to uninstall the driver program of the first USB interface according to the uninstalling instruction; the CPLD is further configured to, after it is determined that the secret key storage module is in place and the verification pass signal sent by the BMC is received, control the first VGA interface to be connected with the second VGA interface, so that the VGA device connected with the second VGA interface can obtain the decrypted video data, and control the first USB interface to be connected with the second USB interface, so that the USB device connected with the second USB interface can access the server; and after it is determined that the secret key storage module is not in place or the verification fail signal sent by the BMC is received, control the first VGA interface not to be connected with the second VGA interface, and control the first USB interface not to be connected with the second USB interface.

[0007] In an alternative manner, the motherboard further comprises a selection controller and an enablement controller, the selection controller is connected with the first VGA interface, the CPLD and the second VGA interface respectively, and the enablement controller is connected with the first USB interface, the CPLD and the second USB interface respectively; the CPLD is further configured to, after it is determined that the secret key storage module is in place and the verification pass signal sent by the BMC is received, control the selection controller to connect the first VGA interface with the second VGA interface, and enable the enablement controller to connect the first USB interface with the second USB interface; and after it is determined that the secret key storage module is not in place or the verification fail signal sent by the BMC is received, control the selection controller not to connect the first VGA interface with the second VGA interface, and disable the enablement controller to make the first USB interface not to be connected with the second USB interface.

[0008] In an optional mode, the CPLD comprises a VGA selection pin and a USB selection pin; the selection controller comprises a first pin, a second pin, a third pin and a fourth pin, the first pin is connected with the VGA selection pin, the second pin is connected with the first VGA interface, the third pin is connected with the second VGA interface, and the fourth pin is suspended; the enable controller comprises a fifth pin, a sixth pin and a seventh pin, the fifth pin is connected with the USB selection pin, the sixth pin is connected with the first USB interface, and the seventh pin is connected with the second USB interface; the CPLD is further configured to: after determining that the key storage module is in place and receiving the check pass signal sent by the BMC, control the VGA selection pin to output high level to the first pin, so as to make the selection controller connect the second pin with the third pin, and then connect the first VGA interface with the second VGA interface; and control the USB selection pin to output low level to the fifth pin, so as to make the enable controller connect the sixth pin with the seventh pin, and then connect the first USB interface with the second USB interface; and after determining that the key storage module is not in place or receiving the check fail signal sent by the BMC, control the VGA selection pin to output low level to the first pin, so as to make the selection controller connect the second pin with the fourth pin, and then make the first VGA interface not connected with the second VGA interface; and control the USB selection pin to output high level to the fifth pin, so as to disable the enable controller, so that the first USB interface is not connected with the second USB interface.

[0009] In an optional mode, the BMC further comprises a first detection pin, the CPLD further comprises a second detection pin, and the key storage module comprises a in-place pin, the in-place pin is used to be connected with the key interface when the key storage module is plugged into the key interface, and the key interface is connected with the first detection pin and the second detection pin respectively; when the key storage module is not plugged into the key interface, the first detection pin and the second detection pin are high level, so as to make the BMC and the CPLD determine that the key storage module is not in place; when the key storage module is plugged into the key interface, the in-place pin is low level, so that the first detection pin and the second detection pin are both low level, so as to make the BMC and the CPLD determine that the key storage module is in place.

[0010] In an alternative mode, the BMC further comprises a first communication pin and a second communication pin, the CPLD further comprises a third communication pin, the key storage module further comprises a fourth communication pin, the first communication pin is connected with the key interface through a first communication bus, the key interface is connected with the fourth communication pin through a second communication bus, and the second communication pin is connected with the third communication pin through a third communication bus; after determining that the key storage module is in place, the BMC reads the key through the first communication bus and the second communication bus; after the key verification passes, the BMC further sends a verification pass signal to the CPLD through the third communication bus; and after the key verification fails, the BMC further sends a verification fail signal to the CPLD through the third communication bus.

[0011] In an alternative mode, when the cover of the server is opened, the BMC is further configured to: after determining that the key storage module is not in place, the key verification fails, or the power-off notification sent by the CPLD is received, control the server to be powered off; and the CPLD is further configured to: after determining that the key storage module is in place and the verification pass signal sent by the BMC is received, enable the power control module of the BMC to respond to the power-on and power-off operation of the server; and after determining that the key storage module is in place and the verification fail signal sent by the BMC is received, disable the power control module to not respond to the power-on and power-off operation of the server.

[0012] In an alternative mode, the mainboard further comprises a CPU, the CPU is connected with the PCH, and the BMC is connected with the PCH; the BMC is further configured to: after determining that the key storage module is not in place or the key verification fails or the power-off notification sent by the CPLD is received, send a power-off instruction to the PCH, and the PCH is configured to: after receiving the power-off instruction, send the power-off instruction to an operating system running in the CPU, so that the operating system powers off the server according to the power-off instruction; the CPLD further comprises a power selection pin, the PCH comprises a button pin, the button pin is configured to be connected with a power button, the power control module comprises an eighth pin and a ninth pin, the eighth pin is connected with the power selection pin, and the ninth pin is connected with the button pin; the CPLD is further configured to: after determining that the key storage module is in place and the verification pass signal sent by the BMC is received, control the power selection pin to input a low level to the eighth pin, so as to enable the power control module, so that the power control module responds to a level signal input by the ninth pin when the ninth pin is configured to input by the BMC, and the level signal is generated by the button pin when the power button is pressed; and after determining that the key storage module is in place and the verification fail signal sent by the BMC is received, control the power selection pin to input a high level to the eighth pin, so as to disable the power control module, so that the power control module does not respond to the level signal input by the ninth pin when the ninth pin is configured to output by the BMC.

[0013] In an alternative mode, the BMC further comprises a third detection pin, and the CPLD further comprises a fourth detection pin; when the cover is in place, the cover button is not popped up, the third detection pin and the fourth detection pin are both connected with the cover button, so that the third detection pin and the fourth detection pin are both high level, and then the BMC and the CPLD determine that the cover is in place; when the cover is opened, the cover button is popped up, the third detection pin and the fourth detection pin are both disconnected with the cover button, so that the third detection pin and the fourth detection pin are both low level, and then the BMC and the CPLD determine that the cover is opened.

[0014] According to another aspect of the embodiments of the present application, a server is provided, comprising the server security control device provided by any of the above embodiments.

[0015] In the server security control device provided by the embodiments of the present application, the key interface is connected with the BMC and the CPLD respectively, the BMC and the CPLD can determine whether the key storage module is plugged on the key interface, and the BMC can read the key and verify the key when the key storage module is plugged on the key interface, and obtain the key verification result. The CPLD is connected with the BMC and the PCH respectively, the BMC can send the key detection result to the CPLD, so that the CPLD can control the peripheral interface of the BMC and the PCH to be in communication with the peripheral interface of the mainboard after determining that the key storage module is in place and receiving the result that the key verification is passed, so that the external device can be in communication with the peripheral interface, and then perform data transmission with the BMC and the PCH; and the CPLD can also control the peripheral interface of the BMC and the PCH to not be in communication with the peripheral interface of the mainboard after determining that the key storage module is not in place or receiving the result that the key verification is not passed, so that the external device cannot be in communication with the peripheral interface, and the data transmission between the external device and the BMC and the PCH is prevented. By verifying the key storage module, the communication between the peripheral interface of the BMC and the PCH and the external device can be controlled, and the unauthorized external device is prevented from accessing the server through the peripheral interface of the BMC and the PCH, so that the data leakage of the server is effectively avoided, and the security risk of the server data is eliminated.

[0016] The above description is only a summary of the technical solutions of the present application, in order to more clearly understand the technical means of the present application, the specific embodiments of the present application can be implemented according to the content of the description, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS

[0017] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments with reference made to the accompanying drawings. The drawings are for purposes of illustration only and are not intended to be limiting in

[0018] Figure 1 A structure diagram of a server security control device provided by an embodiment of the present application;

[0019] Figure 2 A structure diagram of a server security control device provided by an embodiment of the present application;

[0020] Figure 3 A structure diagram of a server security control device provided by an embodiment of the present application;

[0021] Figure 4 A structure diagram of a server security control device provided by an embodiment of the present application;

[0022] Figure 5 An internal circuit diagram of a secret key storage module provided by an embodiment of the present application;

[0023] Figure 6 A structure diagram of a server security control device provided by an embodiment of the present application;

[0024] Figure 7 A structure diagram of a server security control device provided by an embodiment of the present application.

[0025] The reference signs in the detailed description of the embodiments are as follows:

[0026] 1, server; 10, server security control device; 20, 30, external device; 40, VGA device; 50, USB device;

[0027] 100, secret key storage module; 110, in-place pin; 120, fourth communication pin; 200, mainboard; 201, 202, 211, 231, external device interface; 203, second VGA interface; 204, second USB interface; 210, BMC; 212, first VGA interface; 213, first detection pin; 214, first communication pin; 215, second communication pin; 216, first communication bus; 217, third communication bus; 218, power control module; 2181, eighth pin; 2182, ninth pin; 219, third detection pin;

[0028] 220, CPLD; 221, VGA selection pin; 222, USB selection pin; 223, second detection pin; 224, third communication pin; 225, power supply selection pin; 226, fourth detection pin; 227, cover button;

[0029] 230, PCH; 232, first USB interface; 233, button pin; 240, secret key interface; 241, second communication bus; 250, CPU; 251, operating system; 260, selection controller; 261, first pin; 262, second pin; 263, third pin; 264, fourth pin;

[0030] 270, enable controller; 271, fifth pin; 272, sixth pin; 273, seventh pin. DETAILED DESCRIPTION

[0031] The embodiments of the technical solutions of the present application will be described in detail below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present application, and therefore only serve as examples, and cannot limit the protection scope of the present application.

[0032] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit the present application; the terms "include" and "have" and any variations thereof in the specification and claims of the present application and the above description of drawings are intended to cover non-exclusive inclusion.

[0033] In the description of the embodiments of the present application, the technical terms "first", "second", etc. are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number, specific order or primary and secondary relationship of the indicated technical features. In the description of the embodiments of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly and specifically limited.

[0034] Reference herein to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present application. The appearance of the phrase in various places in the specification does not necessarily all refer to the same embodiment, nor is it necessarily independent or alternative embodiments to other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0035] In the description of the embodiments of the present application, the term "and / or" is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of existence of A, existence of A and B, and existence of B. In addition, the character " / " in this paper generally represents that the front and rear associated objects are a "or" relationship.

[0036] In the description of the embodiments of the present application, the term "a plurality of" refers to two or more (including two), and similarly, "a plurality of groups" refers to two or more groups (including two groups), and "a plurality of pieces" refers to two or more pieces (including two pieces).

[0037] In the description of the embodiments of the present application, the technical terms "center", "longitudinal", "transverse", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", "counterclockwise", "axial", "radial", "circumferential" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the embodiments of the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the embodiments of the present application.

[0038] In the description of the embodiments of the present application, unless otherwise explicitly specified and limited, the technical terms "mounting", "connecting", "connecting", "fixing" and the like should be understood in a broad sense, for example, it can be fixedly connected, or it can be detachably connected, or it can be integrated; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium; it can be the internal communication of two elements or the interaction relationship between two elements. For those skilled in the art, the specific meanings of the above terms in the embodiments of the present application can be understood according to the specific circumstances.

[0039] In the existing general server, the commonly used peripheral interface is usually a USB (Universal Serial Bus) peripheral interface, a VGA (Video Graphics Array) peripheral interface, and the like. At present, the peripheral interface of the server is basically not managed in a secure manner, which makes the external device connected to the peripheral interface able to directly access the server, resulting in a certain security risk of the data stored in the server. For example, if the server does not limit the management of the USB interface, when an untrusted USB device accesses the system through the USB interface, the data in the server can be directly copied to the USB device through the USB interface, resulting in leakage of the data of the server. Moreover, when the USB device is implanted with malicious software and the USB device is inserted into the server, the malicious software can automatically run, thereby directly attacking the server, resulting in a huge data security risk of the server. The VGA interface can be directly connected to a display, and if the server does not manage the security of the VGA interface, unauthorized personnel can access the server through the VGA interface, causing the data stored in the server to be visualized through the display, thereby resulting in leakage of the data of the server.

[0040] To solve the above problems, the present application provides a server security control device, which comprises a BMC (Baseboard Management Controller) and a PCH (Platform Controller Hub). The BMC is a special chip for server management, which is usually integrated on the server motherboard. The PCH (Platform Controller Hub) is called "South Bridge chip", which usually serves as a bridge between the CPU and the external device, ensuring efficient transmission of data between the CPU and the external device. The peripheral interface of the server motherboard is a physical interface for connecting various external devices (such as USB devices, hard drives, displays, etc.), and these peripheral interfaces are directly connected to various chips (such as BMC and PCH) and buses on the motherboard for data transmission and device control. In order to connect with the external device, the BMC and the PCH can be provided with peripheral interfaces corresponding to the peripheral interfaces of the motherboard, and the peripheral interfaces of the BMC and the PCH are in communication with the peripheral interfaces of the motherboard, so that the BMC and the PCH can respectively control and manage the external device through their own peripheral interfaces and the peripheral interfaces of the motherboard, and perform data transmission with the external device.

[0041] Based on this, in order to control the peripheral interfaces of the BMC and the PCH, the server security control device introduces a key storage module, which stores the key of the server. By checking the key in the key storage module when it is determined that the key storage module is plugged into the mainboard, the peripheral interfaces of the BMC and the PCH can be controlled to be connected with the peripheral interfaces of the mainboard when the key check is passed, so that the peripheral interfaces of the BMC and the PCH can be connected with the external device connected with the mainboard; by determining that the key storage module is not plugged into the mainboard, or by determining that the key storage module is plugged into the mainboard but the key check is not passed, the peripheral interfaces of the BMC and the PCH can be controlled to be not connected with the peripheral interfaces of the mainboard, so that the peripheral interfaces of the BMC and the PCH are not connected with the external device connected with the mainboard. By introducing the key security check mechanism, the connection between the peripheral interfaces of the BMC and the PCH and the external device can be controlled, and unauthorized external devices are prevented from accessing the server through the peripheral interfaces of the BMC and the PCH, effectively avoiding the leakage of server data and eliminating the security risks of server data.

[0042] Referring to Figure 1 , Figure 1 The structure of the server security control device provided by the embodiment of the application is shown in the figure, which includes a key storage module 100 and a mainboard 200. The key storage module 100 is used to store the key of the server. The mainboard 200 includes a BMC 210, a CPLD 220, a PCH 230 and a key interface 240, the CPLD 220 is connected with the BMC 210 and the PCH 230 respectively, the key interface 240 is connected with the BMC 210 and the CPLD 220 respectively, and the key interface 240 is used to plug in the key storage module 100.

[0043] The key storage module 100 uses a non-volatile storage chip to store the key of the server. The key of the server is a binary file generated by a key generation algorithm based on the model, part number, serial number, factory time range and other parameters of the server. In some embodiments, the key of the server can be encrypted again and then burned into the key storage module 100 to increase the security of the key.

[0044] One key storage module 100 can only store the key of one server and be used together with the server, that is, the key storage modules 100 of different servers cannot be shared. One key storage module 100 can also store the keys of multiple servers in the same batch to be used together with the multiple servers in the same batch, thereby reducing the production cost of the key storage module 100. In this case, different batches of servers cannot share the same key storage module.

[0045] The key interface 240 can adopt a MIC interface (Microphone Interface Connector). The MIC interface is less common, which can increase the difficulty of hardware adaptation for key cracking, and thus can increase the security of the key. The key interface 240 can be arranged on the backplane of the server, so that the key storage module 100 can be plugged on the key interface 240 without opening the cover of the server.

[0046] When the user plugs the external device (20, 30) on the peripheral interface (211, 231) of the server and wants to access the server through the peripheral interface, the key storage module 100 needs to be plugged on the key interface 240, so that the server can perform legal verification on the key in the key storage module 100 to determine whether the user can access the server.

[0047] Please continue to refer to Figure 1 , the BMC 210 is used to read the key when it is determined that the key storage module 100 is in place, and to verify the key. If the key verification is passed, a verification pass signal is sent to the CPLD 220, and if the key verification is not passed, a verification fail signal is sent to the CPLD 220. The CPLD 220 is used to control the communication between the peripheral interfaces (211, 231) of the BMC 210 and the PCH 230 and the peripheral interfaces (201, 202) of the mainboard 200 when it is determined that the key storage module 100 is in place and the verification pass signal sent by the BMC 210 is received, so that the external device (20, 30) connected to the peripheral interfaces (201, 202) of the mainboard 200 can communicate with the peripheral interfaces (201, 202) of the BMC 210 and the PCH 230. The CPLD 220 is used to control the communication between the peripheral interfaces (211, 231) of the BMC 210 and the PCH 230 and the peripheral interfaces (201, 202) of the mainboard when it is determined that the key storage module 100 is not in place, or when it is determined that the key storage module 100 is in place and the verification fail signal sent by the BMC 210 is received, so that the external device (20, 30) cannot communicate with the peripheral interfaces (211, 231) of the BMC 210 and the PCH 230.

[0048] When the peripheral interface 211 of the BMC 210 communicates with the peripheral interface 201 of the mainboard, the external device 20 can communicate with the peripheral interface 211, and then communicate with the BMC 210, so that the external device 20 can perform data transmission with the BMC 210. When the peripheral interface 231 of the PCH 230 communicates with the peripheral interface 202 of the mainboard, the external device 30 can communicate with the peripheral interface 231, and then communicate with the PCH 230, so that the external device 30 can perform data transmission with the PCH 230.

[0049] The key storage module 100 is in place refers to that the key storage module 100 is plugged on the key interface 240, and the key storage module 100 is not in place refers to that the key storage module 100 is not plugged on the key interface 240, the key storage module 100 is not plugged in place or the key storage module 100 is damaged. The application is described by taking that the key storage module 100 is not in place as an example.

[0050] When the key storage module 100 is normally plugged on the key interface 240, the BMC 210 and the CPLD 220 can detect the key storage module 100, that is, it can be determined that the key storage module 100 is in place; when the key storage module 100 is not plugged on the key interface 240, the BMC 210 and the CPLD 220 cannot detect the key storage module 100, and it can be determined that the key storage module 100 is not in place. Wherein, after the BMC 210 determines that the key storage module 100 is in place, the key of the server stored in the key storage module 100 can be read through the key interface 240.

[0051] The BMC 210 of each server pre-stores the model, the part number, the serial number, the factory time range and other parameters of the server. Specifically, after the key of the server is read, the BMC 210 first decrypts the key. Then the model, the part number, the serial number, the factory time range and other parameters of the server are parsed through the key generation algorithm. Then, the model, the part number, the serial number, the factory time range of the server stored in the BMC 210 are compared and verified one by one with the parsed model, the part number, the serial number, the factory time range of the server.

[0052] When the model, the part number, the serial number, the factory time range are all matched, the key verification is passed, which indicates that the key in the key storage module 100 is legal, and the external device (20, 30) can access the server, and then the BMC 210 generates a verification pass signal. Then, the BMC 210 sends the verification pass signal to the CPLD 220.

[0053] When one of the model, the part number, the serial number, the factory time range is not matched, the key verification is not passed, which indicates that the key in the key storage module 100 is not legal, and the external device (20, 30) cannot access the server, and then the BMC 210 generates a verification fail signal. Then, the BMC 210 sends the verification fail signal to the CPLD 220.

[0054] In the embodiments of the present application, when the external device (20, 30) is plugged into the peripheral interface (211, 231) of the server, if the secret key storage module 100 is in place and the secret key verification is passed, the external device (20, 30) is an authorized device; if the secret key storage module 100 is not in place, or the secret key storage module 100 is in place and the secret key verification is not passed, the external device (20, 30) is an unauthorized device.

[0055] When the CPLD 220 determines that the secret key storage module 100 is in place and receives the verification passed signal sent by the BMC 210, the CPLD 220 can determine that the secret key stored in the secret key storage module 100 is legal. Then, the CPLD 220 controls the peripheral interface 211 of the BMC 210 to be in communication with the peripheral interface 201 of the mainboard 200, so that the peripheral interface 211 is in communication with the external device 20, thereby enabling the external device 20 to perform data transmission with the BMC 210; and the CPLD 220 also controls the peripheral interface 231 of the PCH 230 to be in communication with the peripheral interface 202 of the mainboard 200, so that the peripheral interface 231 is in communication with the external device 30, thereby enabling the external device 30 to perform data transmission with the PCH 230.

[0056] When the CPLD 220 determines that the secret key storage module 100 is not in place, or when the CPLD 220 determines that the secret key storage module 100 is in place and receives the verification not passed signal sent by the BMC 210, the CPLD 220 determines that the secret key in the secret key storage module 100 is not legal. In these two cases, the CPLD 220 controls the peripheral interface 211 of the BMC 210 to not be in communication with the peripheral interface 201 of the mainboard 200, so that the peripheral interface 211 is not in communication with the external device 20, thereby preventing the external device 20 from performing data transmission with the BMC 210, and avoiding leakage of data of the server through the peripheral interface 211; and the CPLD 220 also controls the peripheral interface 231 of the PCH 230 to not be in communication with the peripheral interface 202 of the mainboard 200, so that the peripheral interface 231 is not in communication with the external device 30, thereby preventing the external device 30 from performing data transmission with the PCH 230, and avoiding leakage of data of the server through the peripheral interface 231.

[0057] In some embodiments, when the BMC 210 and the CPLD 220 determine that the secret key storage module is not in place, or the BMC 210 and the CPLD 220 determine that the secret key storage module is in place but the secret key verification is not passed, the BMC 210 can also generate an alarm information and report the alarm information to the management center of the server and record in the audit diary.

[0058] In the server security control device 10 provided by the embodiments of the present application, the key interface 240 is connected with the BMC 210 and the CPLD 220 respectively, so that the BMC 210 and the CPLD 220 can determine whether the key storage module 100 is connected to the key interface 240, and the BMC 210 can read the key and check the key when the key storage module 100 is connected to the key interface 240, and obtain a key check result. The CPLD 220 is connected with the BMC 210 and the PCH 230 respectively, so that the BMC 210 can send the key check result to the CPLD 220, and the CPLD 220 can control the peripheral interfaces (211, 231) of the BMC 210 and the PCH 230 to be in communication with the peripheral interfaces (201, 202) of the mainboard 200 after determining that the key storage module 100 is in place and receiving the result that the key check is passed, so that the external device (20, 30) can be in communication with the peripheral interfaces (211, 231), and then perform data transmission with the BMC 210 and the PCH 230; and the CPLD 220 can also control the peripheral interfaces (211, 231) of the BMC 210 and the PCH 230 to not be in communication with the peripheral interfaces (201, 202) of the mainboard 200 after determining that the key storage module 100 is not in place or receiving the result that the key check is not passed, so that the external device (20, 30) cannot be in communication with the peripheral interfaces (211, 231), and the data transmission between the external device (20, 30) and the BMC 210 and the PCH 230 is prevented. By checking the key storage module 100, the communication between the peripheral interfaces (211, 231) of the BMC 210 and the PCH 230 and the external device (20, 30) can be controlled, and the unauthorized external device (20, 30) is prevented from accessing the server through the peripheral interfaces (20, 30) of the BMC 210 and the PCH 230, so that the data leakage of the server is effectively avoided, and the security risk of the server data is eliminated.

[0059] To improve the data security of the server, the present application further provides an embodiment, which is described as follows Figure 2 , Figure 2 The structure of the server security control device provided by the embodiments of the present application is shown in the figure, the peripheral interface of the BMC 210 is a first VGA interface 212, the peripheral interface of the PCH 230 is a first USB interface 232, the peripheral interfaces of the mainboard 200 include a second VGA interface 203 and a second USB interface 204, and the external device includes a VGA device 40 and a USB device 50. The mainboard 200 further includes a CPU 250, the CPU 250 is connected with the PCH 230, and the PCH 230 is connected with the BMC 210.

[0060] When the first VGA interface 212 is in communication with the second VGA interface 203, the VGA device 40 can be in communication with the first VGA interface 212, and then in communication with the BMC 210, and data transmission is performed between the VGA device 40 and the BMC 210; when the first USB interface 232 is in communication with the second USB interface 204, the USB device 50 can be in communication with the first USB interface 232, and then in communication with the PCH 230, and data transmission is performed between the USB device 50 and the PCH 230. The VGA device 40 can be a display, a projector, a video capture card, etc., and the USB device 50 can be a storage device, a communication device, a network device, etc.

[0061] The BMC 210 can be connected to the PCH 230 through a PCIE (Peripheral Component Interconnect Express) bus and an LPC bus, respectively, and the PCH 230 can be connected to the CPU 250 through a DMI (Direct Media Interface) bus.

[0062] Please continue to refer to Figure 2 The BMC 210 is configured to, after the secret key is verified, decrypt the video data sent by the PCH 230, and send a loading instruction to the PCH 230, and the PCH 230 sends the loading instruction to an operating system 251 running in the CPU 250, so that the operating system 251 loads a driver of the first USB interface 232 according to the loading instruction. The video data is sent by the CPU 250 to the PCH 230. The BMC 210 is further configured to, when it is determined that the secret key storage module 100 is not in place or the secret key verification fails, encrypt the video data sent by the PCH 230, and send an uninstalling instruction to the PCH 230, and the PCH 230 sends the uninstalling instruction to the operating system, so that the operating system 251 uninstalls the driver of the first USB interface 232 according to the uninstalling instruction.

[0063] During the running of the server, the CPU 250 sends video data to the PCH 230 through the DMI bus, and the PCH 230 sends the video data to the BMC 210 through the PCIE bus. After receiving the video data, the BMC 210 encrypts the video data,

[0064] After the key check passes, the BMC 210 sends a check pass signal to the CPLD 220 while also decrypting the video data to enable the VGA device 40 to normally display the video data. At the same time, the BMC 210 also sends a load instruction to the PCH 230 through the LPC bus, and the PCH 230 sends the load instruction to the operating system 251 through the DMI bus. After the operating system 251 receives the load instruction, the operating system 251 loads the driver of the first USB interface 232 into the kernel to support access to the USB device 50.

[0065] When the key check fails or it is determined that the key storage module 100 is not in place, the BMC 210 cancels the decryption operation of the video data, so that the display can obtain the video data but cannot display the video data, thereby ensuring the security of the video data. At the same time, the BMC 210 also sends an unload instruction to the PCH 230 through the LPC bus, and the PCH 230 sends the unload instruction to the operating system 251 through the DMI bus. After the operating system 251 receives the unload instruction, the operating system 251 unloads the driver of the first USB interface 232 from the kernel, thereby prohibiting the USB device 50 from accessing the operating system 251.

[0066] Please continue to refer to Figure 2 , the CPLD 220 is configured to, after determining that the key storage module 100 is in place and receiving the check pass signal sent by the BMC 210, control the first VGA interface 212 to be connected to the second VGA interface 203, so that the VGA device 40 connected to the second VGA interface 203 can obtain the decrypted video data, and control the first USB interface 232 to be connected to the second USB interface 204, so that the USB device 50 connected to the second USB interface 204 can access the server. The CPLD 220 is also configured to, after determining that the key storage module 100 is not in place or receiving the check fail signal sent by the BMC 210, control the first VGA interface 212 not to be connected to the second VGA interface 203, and control the first USB interface 232 not to be connected to the second USB interface 204.

[0067] After determining that the key storage module 100 is in place and receiving the pass signal sent by the BMC 210, in order to enable the VGA device 40 to communicate with the BMC 210, the CPLD 220 controls the first VGA interface 212 to communicate with the second VGA interface 203, so that the first VGA interface 212 communicates with the VGA device 40, so that the VGA device 40 can obtain the decrypted video data through the first VGA interface 212. In order to enable the USB device 50 to communicate with the PCH 230, the CPLD 220 also controls the first USB interface 232 to communicate with the second USB interface 204, so that the first USB interface 232 communicates with the USB device 50, so that the USB device 50 can communicate with the PCH 230, and then can access the server to obtain the data of the server.

[0068] After determining that the key storage module 100 is not in place or receiving the fail signal sent by the BMC 210, the CPLD 220 controls the first VGA interface 212 not to communicate with the second VGA interface 203, so that the first VGA interface 212 does not communicate with the VGA device 40, and the VGA device 40 can be prevented from obtaining the data of the server through the first VGA interface 212. At the same time, the CPLD 220 also controls the first USB interface 232 not to communicate with the second USB interface 204, so that the first USB interface 232 does not communicate with the USB device 50, and the USB device 50 can be prevented from accessing the server, that is, the USB device 50 is prevented from obtaining the data of the server.

[0069] The video data sent by the CPU 250 through the PCH 230 is decrypted by the BMC 210 after the key check passes, and the operation system 251 is controlled to load the driver of the first USB interface 232, the video data is encrypted after the key storage module 100 is not in place or the key check fails, and the operation system 251 is controlled to unload the driver of the first USB interface 232, when the key storage module 100 is not in place or the key check fails, the unauthorized VGA device 40 cannot read the data even if it obtains the data of the server through the first VGA interface 212, and the unauthorized USB device 50 cannot access the operation system 251 even if it connects the PCH 230 through the first USB interface 232, which effectively improves the security of the data of the server. After it is determined that the key storage module 100 is in place and the check pass signal sent by the BMC 210 is received, the CPLD 220 controls the first VGA interface 212 to connect the VGA device 40 and controls the first USB interface 232 to connect the USB device 50, and after it is determined that the key storage module 100 is not in place or the check fail signal sent by the BMC 210 is received, the CPLD 220 controls the first VGA interface 212 not to connect the VGA device 40 and controls the first USB interface 232 not to connect the USB device 50, which can prevent the unauthorized VGA device 40 and the USB device 50 from transmitting data with the server, greatly improving the security of the data of the server.

[0070] In order to control the data transmission of the peripheral interfaces of the BMC 210 and the PCH 230, the application further provides an embodiment, which refers to Figure 3 , Figure 3 The structure schematic diagram of the server security control device provided by the embodiment of the application is shown, as shown in the figure, the mainboard 200 further includes a selection controller 260 and an enable controller 270, the selection controller 260 is connected with the first VGA interface 212, the CPLD 220 and the second VGA interface 203 respectively, and the enable controller 270 is connected with the first USB interface 232, the CPLD 220 and the second USB interface 204 respectively. The CPLD 220 is used for controlling the selection controller 260 to connect the first VGA interface 212 and the second VGA interface 203 and enabling the enable controller 270 to connect the first USB interface 232 and the second USB interface 204 after it is determined that the key storage module 100 is in place and the check pass signal sent by the BMC 210 is received. The CPLD 220 is further used for controlling the selection controller 260 not to connect the first VGA interface 212 and the second VGA interface 203 and disabling the enable controller 270 to make the first USB interface 232 and the second USB interface 204 not to be connected after it is determined that the key storage module 100 is not in place or the check fail signal sent by the BMC 210 is received.

[0071] The selection controller 260 can be a MUX controller. The MUX controller is a device or chip used to manage and control multiplexers (MUXs), which select one of multiple input signals by a control signal and output it to a single output channel. For example, the CPLD 220 can control the MUX controller to switch the input pin by controlling the control signal input to the MUX controller, so as to control the connection between the first VGA interface 212 and the second VGA interface 203.

[0072] The enable controller can be a HUB controller. The HUB controller is a device that expands the number of USB interfaces, allows multiple USB devices to be connected to one USB interface, and is responsible for managing and coordinating the connection and communication of these USB devices. The HUB controller is low-level enabled and high-level disabled, so the CPLD 220 can control the HUB controller by controlling the control signal input to the HUB controller, so as to control the connection between the first USB interface 232 and the second USB interface 204.

[0073] After determining that the secret key storage module 100 is in place and receiving the pass signal sent by the BMC 210, the CPLD 220 changes the control signal input to the selection controller 260, and then the selection controller 260 switches the input pin to the pin connected to the second VGA interface 203, so that the first VGA interface 212 and the second VGA interface 203 are connected, so that the selection controller 260 connects the first VGA interface 212 and the second VGA interface 203, so that the VGA device 40 is connected to the first VGA interface 212, and the VGA device 40 can transmit data with the BMC 210. At the same time, the CPLD 220 also changes the control signal input to the enable controller 270 to enable the enable controller 270 to work normally, and connects the first USB interface 232 and the second USB interface 204, so that the USB device 50 is connected to the first USB interface 232, and the USB device 50 can transmit data with the PCH 230.

[0074] After determining that the secret key storage module 100 is not in place or receiving the check failure signal sent by the BMC 210, the CPLD 220 changes the control signal input to the selection controller 260, and the selection controller 260 switches the input pin to the pin not connected to the second VGA interface 203, so that the first VGA interface 212 is not connected to the second VGA interface 203, so that the VGA device 40 is not connected to the first VGA interface 212, preventing the VGA device 40 from obtaining data of the server through the first VGA interface 212. At the same time, the CPLD 220 also changes the control signal input to the enable controller 270 to disable the enable controller 270, so that the enable controller 270 cannot work normally, resulting in that the first USB interface 232 is not connected to the second USB interface 204, so that the USB device 50 cannot perform data transmission with the PCH 230.

[0075] By controlling the selection controller 260 to realize the on-off between the first VGA interface 212 and the VGA device 40, and by controlling the enable controller 270 to realize the on-off between the first USB interface 232 and the USB device 50, the CPLD 220 can quickly prevent data transmission between the VGA device 40 and the BMC 210 and quickly prevent data transmission between the USB device 50 and the PCH 230 when the unauthorized VGA device 40 and the USB device 50 obtain data of the server, thereby guaranteeing the data security of the server.

[0076] In order to control the on-off between the first VGA interface 212 and the second VGA interface 203 and the on-off between the first USB interface 232 and the second USB interface 204, the application further provides an embodiment, please refer to Figure 4 , Figure 4 The structure schematic diagram of the server security control device provided by the embodiment of the application is shown, as shown in the figure, the CPLD 220 includes a VGA selection pin 221 and a USB selection pin 222. The selection controller 260 includes a first pin 261, a second pin 262, a third pin 263 and a fourth pin 264, the first pin 261 is connected with the VGA selection pin 221, the second pin 262 is connected with the first VGA interface 212, the third pin 263 is connected with the second VGA interface 203, and the fourth pin 264 is suspended. The enable controller 270 includes a fifth pin 271, a sixth pin 272 and a seventh pin 273, the fifth pin 271 is connected with the USB selection pin 222, the sixth pin 272 is connected with the first USB interface 232, and the seventh pin 273 is connected with the second USB interface 204.

[0077] CPLD 220 is configured to control the VGA selection pin 221 to output a high level to the first pin 261 to make the selection controller 260 connect the second pin 262 with the third pin 263, and thus connect the first VGA interface 212 with the second VGA interface 203, after determining that the key storage module 100 is present and receiving the pass signal sent by the BMC 210. The CPLD 220 is also configured to control the USB selection pin 222 to output a low level to the fifth pin 271 to make the enable controller 270 connect the sixth pin 272 with the seventh pin 273, and thus connect the first USB interface 232 with the second USB interface 204.

[0078] The CPLD 220 is also configured to control the VGA selection pin 221 to output a low level to the first pin 261 to make the selection controller 260 connect the second pin 262 with the fourth pin 264, and thus disconnect the first VGA interface 212 from the second VGA interface 203, after determining that the key storage module 100 is not present or receiving the fail signal sent by the BMC 210. The CPLD 220 is also configured to control the USB selection pin 222 to output a high level to the fifth pin 271 to disable the enable controller 270, so that the first USB interface 232 is disconnected from the second USB interface 204.

[0079] Specifically, after determining that the key storage module 100 is present and receiving the pass signal sent by the BMC 210, the CPLD 220 pulls up the VGA selection pin 221 to output a high level to the first pin 261. The selection controller 260 detects the high level and switches the input pin to the third pin 263, so that the second pin 262 is connected with the third pin 263. Meanwhile, the CPLD 220 also pulls down the USB selection pin 222 to output a low level to the fifth pin 271 to enable the enable controller 270. The enabled enable controller 270 can work normally to connect the sixth pin 272 with the seventh pin 273.

[0080] After determining that the key storage module 100 is not present or receiving the fail signal sent by the BMC 210, the CPLD 220 pulls down the VGA selection pin 221 to output a low level to the first pin 261. The selection controller 260 detects the low level and switches the input pin to the fourth pin 264, so that the first VGA interface 212 is disconnected from the second VGA interface 203. Meanwhile, the CPLD 220 also pulls up the USB selection pin 222 to output a high level to the fifth pin 271 to disable the enable controller 270. The disabled enable controller 270 cannot work, resulting in that the sixth pin 272 is disconnected from the seventh pin 273.

[0081] By connecting the VGA selection pin 221 with the first pin 261 and connecting the USB selection pin 222 with the fifth pin 271, the CPLD 220 can control the selection controller 260 to connect the first VGA interface 212 with the second VGA interface 203 through the VGA selection pin 221 and enable the enable controller 270 to connect the first USB interface 232 with the second USB interface 204 through the USB selection pin 222 when the authorized VGA device 40 and USB device 50 acquire the data of the server, and also make the CPLD 220 control the selection controller 260 not to connect the first VGA interface 212 with the second VGA interface 203 through the VGA selection pin 221 and disable the enable controller 270 to not connect the first USB interface 232 with the second USB interface 204 through the USB selection pin 222 when the unauthorized VGA device 40 and USB device 50 acquire the data of the server, so that the CPLD 220 realizes the on-off control between the first VGA interface 212 and the second VGA interface 203 and the on-off control between the first USB interface 232 and the second USB interface 204.

[0082] In order to detect whether the key storage module 100 is in place, the application further proposes an embodiment, please continue to refer to Figure 4 As shown in the figure, the BMC 210 further includes a first detection pin 213, the CPLD 220 further includes a second detection pin 223, and the key storage module 100 includes a in place pin 110, which is used to be connected with the key interface 240 when the key storage module 100 is plugged into the key interface 240, and the key interface 240 is connected with the first detection pin 213 and the second detection pin 223 respectively. When the key storage module 100 is not plugged into the key interface 240, the first detection pin 213 and the second detection pin 223 are high level, so that the BMC 210 and the CPLD 220 determine that the key storage module 100 is not in place. When the key storage module 100 is plugged into the key interface 240, the in place pin 110 is low level, so that the first detection pin 213 and the second detection pin 223 are both low level, so that the BMC 210 and the CPLD 220 determine that the key storage module 100 is in place.

[0083] As shown in the figure, when the key storage module 100 is not plugged into the key interface 240, the pin in the key interface 240 connected to the in-place pin 110 is left hanging, and the pin is at a high level, so that the first detection pin 213 and the second detection pin 223 connected to the pin are at a high level. When the BMC 210 detects that the first detection pin 213 is at a high level, and the CPLD 220 detects that the second detection pin 223 is at a high level, the BMC 210 and the CPLD 220 can determine that the key storage module 100 is not plugged into the key interface 240, that is, the key storage module 100 is not in place.

[0084] Please continue to refer to Figure 4 , and in combination with Figure 5 , Figure 5 The internal circuit schematic diagram of the key storage module 100 is shown in the figure. As shown in the figure, when the key storage module 100 is plugged into the key interface 240, the power interface A of the key storage module 100 is connected to the power supply, at this time, the circuit connection point B is at a low level, so that the pin 3 of the element 101 is at a low level, and the in-place pin 110 connected to the pin 3 is also pulled to a low level. In this case, the pin in the key interface 240 connected to the in-place pin 110 is at a low level, so that the first detection pin 213 and the second detection pin 223 are at a low level. When the BMC 210 detects that the first detection pin 213 is at a low level, and the CPLD 220 detects that the second detection pin 223 is at a low level, the BMC 210 and the CPLD 220 can determine that the key storage module 100 is plugged into the key interface 240, that is, the key storage module 100 is in place.

[0085] In the above manner, the BMC 210 and the CPLD 220 can automatically detect whether the key storage module 100 is in place, so that the BMC 210 can quickly read the server key in the key storage module 100 when the key storage module 100 is in place, and the response speed of the BMC 210 and the CPLD 220 is improved.

[0086] In order to realize the communication between the BMC 210 and the key storage module 100, and the communication between the BMC 210 and the CPLD 220, the present application further proposes an embodiment, please continue to refer to Figure 4As shown in the figure, the BMC 210 further includes a first communication pin 214 and a second communication pin 215, the CPLD 220 further includes a third communication pin 224, and the key storage module 100 further includes a fourth communication pin 120. The first communication pin 214 is connected with the key interface 240 through a first communication bus 216, the key interface 240 is connected with the fourth communication pin 120 through a second communication bus 241, and the second communication pin 215 is connected with the third communication pin 224 through a third communication bus 217. After determining that the key storage module 100 is in place, the BMC 210 reads the key through the first communication bus 216 and the second communication bus 241. After the key verification passes, the BMC further sends a pass signal to the CPLD 220 through the third communication bus 217. After the key verification fails, the BMC 210 further sends a fail signal to the CPLD 220 through the third communication bus 217.

[0087] The first communication bus 216, the second communication bus 241 and the third communication bus 217 can all be I2C buses.

[0088] After determining that the key storage module 100 is in place, the BMC 210 enters an interrupt processing task, reads the key in the key storage module 100 into the file system of the BMC 210 through the first communication bus 216 and the second communication bus 241, and decrypts the key.

[0089] In the above manner, the BMC 210 can read the key of the key storage module 100 and verify the key. Moreover, the BMC 210 can send the key verification result to the CPLD 220, so that the CPLD 220 controls the on-off of the first VGA interface 212 and the VGA device 40 and controls the on-off of the first USB interface 232 and the USB device 50 according to the key verification result, thereby realizing the control of the data transmission of the server.

[0090] In some cases, if the server does not have a boot restriction for illegal opening of the cover, unauthorized personnel can directly access the memory, storage device or other components of the server, thereby causing data leakage. Therefore, in order to avoid data leakage of the server in the case of illegal opening of the cover and ensure the data security of the server, the present application further proposes an implementation manner, please refer to Figure 6 , Figure 6A structure diagram of the server security control apparatus provided by the embodiments of the present application is shown in the figure. When the server cover is opened, the BMC 210 is further configured to control the server to power off after determining that the secret key storage module 100 is not in place, the secret key check fails or a power-off notification sent by the CPLD 220 is received. The CPLD 220 is configured to enable the power control module 218 of the BMC 210 to respond to the power-on and power-off operation of the server after determining that the secret key storage module 100 is in place and receiving the check pass signal sent by the BMC 210. The CPLD 220 is further configured to disable the power control module 218 to not respond to the power-on and power-off operation of the server after determining that the secret key storage module 100 is in place and receiving the check fail signal sent by the BMC 210.

[0091] The power control module 218 is a module for managing the power button of the server. The CPLD 220 can control the power button of the server by controlling the power control module 218, so as to control whether the server responds to the power-on and power-off operation.

[0092] When the server cover is not opened, the BMC 210 can send a cover not opened signal to the CPLD 220. After receiving the cover not opened signal, the CPLD 220 enables the power control module 218 to work normally. In this way, the power control module 218 can respond to the power-on and power-off operation of the server, and normally power on and power off the server.

[0093] When the server cover is opened, it is necessary to determine whether the secret key storage module 100 is in place. When the secret key storage module 100 is in place, it is further necessary to check the secret key stored in the secret key storage module 100. When the secret key check passes, it can be indicated that the cover is opened by authorized personnel, and the data of the server can be accessed. When the secret key storage module 100 is not in place or the secret key check fails, it indicates that the cover may be opened by unauthorized personnel. At this time, the server needs to be powered off, and the server cannot respond to the power-on and power-off operation of the unauthorized personnel, so as to ensure that the server cannot be accessed.

[0094] Specifically, when the cover of the server is opened, after determining that the secret key storage module 100 is in place and receiving the check pass signal sent by the BMC 210, the CPLD 220 enables the power control module 218 of the BMC 210 to enable the power control module 218 to work normally. In this way, the power control module 218 can respond to the power-on and power-off operations of the server by the authorized personnel, and the authorized personnel can open the server and access the data of the server. After determining that the secret key storage module 100 is in place and receiving the check fail signal sent by the BMC 210, the CPLD 220 disables the power control module 218, so that the power control module 218 cannot work. In this way, the power control module 218 cannot respond to the power-on and power-off operations of the server by the unauthorized personnel, and the unauthorized personnel cannot open the server and access the data of the server.

[0095] After the CPLD 220 controls the power control module 218 not to respond to the power-on and power-off operations of the server, the CPLD 220 also starts a preset time, which can be 5 minutes, 10 minutes, etc. After the timing reaches, the CPLD 220 sends a power-off notification to the BMC 210, so that the BMC 210 starts the power-off operation after receiving the power-off notification to power off the server. Therefore, when the cover of the server is opened, after determining that the secret key storage module 100 is not in place, the secret key check fails, or the power-off notification sent by the CPLD 220 is received, the BMC 210 controls the server to power off, so that the server cannot be accessed, avoiding the risk of data leakage.

[0096] When the cover of the server is opened, by judging whether the secret key storage module 100 is in place and whether the secret key is legal, when the cover is opened by the unauthorized personnel, the CPLD 220 can timely disable the power control module 218, so that the server cannot be opened by the unauthorized personnel, and the BMC 210 can timely power off the server, so that the unauthorized personnel cannot access the server, and also cannot access the memory and storage device of the server, ensuring the security of the data of the server.

[0097] In order to realize the power-on and power-off control of the server, the present application further proposes an implementation mode on the basis of the embodiment Figure 4 of the embodiment, please refer to Figure 7 , Figure 7 The structure schematic diagram of the server security control device provided by the embodiment of the present application is shown, as shown in the figure, the BMC 210 is further used to send a power-off instruction to the PCH 230 after determining that the secret key storage module 100 is not in place or the secret key check fails or receiving the power-off notification sent by the CPLD 220, and the PCH 230 is used to send the power-off instruction to the operating system 251 running in the CPU 250 after receiving the power-off instruction, so that the operating system 251 powers off the server according to the power-off instruction.

[0098] Specifically, the BMC 210 can receive the power-off notification sent by the CPLD 220 through the third communication bus 217. After receiving the power-off instruction, the PCH 230 can send the power-off instruction to the operating system 251 through the DMI bus to trigger the NMI (Non Maskable Interrupt) of the operating system 251, so that the operating system 251 powers off the server. In this way, the BMC 210 can power off the server in time when the server cover is opened by an unauthorized person, avoiding the data of the server being leaked.

[0099] Please continue to refer to Figure 7 , the CPLD 220 further includes a power selection pin 225, the PCH 230 includes a button pin 233 for connecting a power button, the power control module 218 includes an eighth pin 2181 and a ninth pin 2182, the eighth pin 2181 is connected with the power selection pin 225, and the ninth pin 2182 is connected with the button pin 233. The CPLD 220 is further configured to, after determining that the key storage module 100 is in place and receiving the pass signal sent by the BMC 210, control the power selection pin 225 to input a low level to the eighth pin 2181, so as to enable the power control module 218, so that the power control module 218 responds to a level signal input by the ninth pin 2182 when the ninth pin 2182 is configured to input by the BMC 210, the level signal being generated by the button pin 233 when the power button is pressed. The CPLD 220 is further configured to, after determining that the key storage module 100 is in place and receiving the fail signal sent by the BMC 210, control the power selection pin 225 to input a high level to the eighth pin 2181, so as to disable the power control module 218, so that the power control module 218 does not respond to the level signal input by the ninth pin 2182 when the ninth pin 2182 is configured to output by the BMC 210.

[0100] Wherein, the power control module 218 is enabled at low level and disabled at high level.

[0101] When the server's cover is not opened, or when the server's cover is not opened, it is determined that the secret key storage module 100 is in place and the check pass signal sent by the BMC 210 is received, the CPLD 220 pulls down the power selection pin 225, so that the power selection pin 225 inputs a low level to the eighth pin 2181, enabling the power control module 218, so that the power control module 218 can work normally, that is, it can control the power-on and power-off of the server. When the BMC 210 detects that the eighth pin 2181 is at a low level, the BMC 210 will also configure the ninth pin 2182 as an input. In this way, when the power button is pressed and the button pin 233 generates a level signal and inputs the level signal to the ninth pin 2182, the ninth pin 2182 can only input the level signal, so that the power control module 218 can control the power-on and power-off of the server according to the level signal, so that the power control module 218 can respond to the power-on and power-off operation of the server in response to the power button.

[0102] When the server's cover is opened, it is determined that the secret key storage module 100 is in place, and the check fail signal sent by the BMC 210 is received, the CPLD 220 does not pull down the power selection pin 225, so that the power selection pin 225 inputs a high level to the eighth pin 2181, disables the power control module 218, so that the power control module 218 cannot work, that is, it cannot control the power-on and power-off of the server. When the BMC 210 detects that the eighth pin 2181 is at a high level, the BMC 210 will also configure the ninth pin 2182 as an output, so that the ninth pin 2182 always outputs a high level. In this way, even if the power button is pressed and the button pin 233 generates a level signal, it cannot always be input to the ninth pin 2182, and the power control module 218 cannot receive the level signal, so that the power control module 218 cannot respond to the power-on and power-off operation of the server in response to the power button.

[0103] By connecting the eighth pin 2181 of the BMC 210 and the power control module 218 with the power selection pin 225 of the CPLD 220, when the cover is opened by an unauthorized person, the CPLD 220 can disable the power control module 218, and the BMC 210 can configure the ninth pin 2182 connected with the button pin 233 as an output, so that the power control module 218 cannot always respond to the power-on and power-off operation of the server in response to the power button, effectively preventing unauthorized access to the server.

[0104] In order to detect whether the cover of the server is opened, the present application further proposes an embodiment, please continue to refer to Figure 7 As shown in the figure, the BMC 210 further includes a third detection pin 219, and the CPLD 220 further includes a fourth detection pin 226.

[0105] When the cover is in place, the cover button 227 is not popped up, the third detection pin 219 and the fourth detection pin 226 are both connected with the cover button 227, so that the third detection pin 219 and the fourth detection pin 226 are both high level, and then the BMC 210 and the CPLD 220 determine that the cover is in place.

[0106] When the cover is opened, the cover button 227 is popped up, the third detection pin 219 and the fourth detection pin 226 are both disconnected with the cover button 227, so that the third detection pin 219 and the fourth detection pin 226 are both low level, and then the BMC 210 and the CPLD 220 determine that the cover is opened.

[0107] Wherein, the cover in place means that the cover of the server is not opened. The cover of the server is integrated with the cover button 227. When the cover is in place, the cover button 227 will not be popped up. When the cover is opened, the cover button 227 will be popped up.

[0108] When the cover button 227 is not popped up, the cover button 227 is connected with the third detection pin 219 and the fourth detection pin 226 at the same time, so that the third detection pin 219 and the fourth detection pin 226 are both high level. When the BMC 210 and the CPLD 220 detect the high level, it can be determined that the cover is in place.

[0109] When the cover button 227 is popped up, the cover button 227 is disconnected with the third detection pin 219 and the fourth detection pin 226 at the same time, so that the third detection pin 219 and the fourth detection pin 226 are low level. When the BMC 210 and the CPLD 220 detect the low level, it can be determined that the cover is opened.

[0110] In some embodiments, when the BMC 210 determines that the cover is opened, the BMC 210 can generate an open cover alarm information, and report the open cover alarm information to the management center of the server and record in the audit diary.

[0111] In the above manner, the BMC 210 and the CPLD 220 can automatically detect whether the cover of the server is opened, so that the BMC 210 and the CPLD 220 can quickly determine whether the secret key storage module 100 is plugged on the secret key interface 240 when the cover is opened, and the response speed of the BMC 210 and the CPLD 220 is improved.

[0112] According to another aspect of the embodiments of the present application, a server is provided, which comprises the server security control device provided in any of the above embodiments.

[0113] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than limit them. Although the present application has been described in detail with reference to the foregoing embodiments, it should be understood by those skilled in the art that the technical solutions recorded in the foregoing embodiments can be modified, or some or all of the technical features can be replaced by equivalent replacements. These modifications or replacements do not change the essence of the corresponding technical solutions, which should be covered in the scope of the claims and the specification of the present application. In particular, the technical features mentioned in each embodiment can be combined in any manner as long as there is no structural conflict. The present application is not limited to the specific embodiments disclosed herein, but includes all technical solutions falling within the scope of the claims.

Claims

1. A server security control device, characterized in that: The device comprises: The key storage module is used to store the server's key; A mainboard, comprising a BMC, a CPLD, a PCH and a key interface, wherein the CPLD is connected to the BMC and the PCH respectively, the key interface is connected to the BMC and the CPLD respectively, and the key interface is used to plug in the key storage module; wherein, The BMC is configured to read the key when determining that the key storage module is in place, and verify the key, and send a verification pass signal to the CPLD if the key verification passes, and send a verification failure signal to the CPLD if the key verification fails; The CPLD is used to: After determining that the key storage module is in place and receiving the verification pass signal sent by the BMC, controlling the peripheral interface of the BMC and the PCH to communicate with the peripheral interface of the mainboard, so that the external device connected to the peripheral interface of the mainboard can communicate with the peripheral interface of the BMC and the PCH; and After determining that the key storage module is not in place, or after determining that the key storage module is in place and receiving the verification failure signal sent by the BMC, controlling the peripheral interface of the BMC and the PCH to be disconnected from the peripheral interface of the mainboard, so that the external device is disconnected from the peripheral interface of the BMC and the PCH.

2. The device according to claim 1, characterized in that The peripheral interface of the BMC is a first VGA interface, the peripheral interface of the PCH is a first USB interface, the peripheral interface of the motherboard includes a second VGA interface and a second USB interface, and the external device includes a VGA device and a USB device; The mainboard further includes a CPU, and the CPU is connected to the PCH; The BMC is connected to the PCH and is further configured to: After the secret key verification passes, decrypting the video data sent by the PCH and sending a loading instruction to the PCH, wherein the PCH sends the loading instruction to the operating system running in the CPU, so that the operating system loads the driver of the first USB interface according to the loading instruction; wherein the video data is sent by the CPU to the PCH; and When it is determined that the key storage module is not in place or the key verification fails, encrypting the video data sent by the PCH and sending an uninstall instruction to the PCH, so that the PCH sends the uninstall instruction to the operating system, so that the operating system uninstalls the driver of the first USB interface according to the uninstall instruction; The CPLD is also used for: After determining that the key storage module is in place and receiving the verification pass signal sent by the BMC, controlling the first VGA interface to connect to the second VGA interface so that the VGA device connected to the second VGA interface can obtain decrypted video data, and controlling the first USB interface to connect to the second USB interface so that the USB device connected to the second USB interface can access the server; and After determining that the key storage module is not in place or receiving the verification failure signal sent by the BMC, the first VGA interface is controlled to be disconnected from the second VGA interface, and the first USB interface is controlled to be disconnected from the second USB interface.

3. The device according to claim 2, characterized in that The mainboard further includes a selection controller and an enable controller, wherein the selection controller is connected to the first VGA interface, the CPLD, and the second VGA interface respectively, and the enable controller is connected to the first USB interface, the CPLD, and the second USB interface respectively; The CPLD is also used for: After determining that the key storage module is in place and receiving the verification pass signal sent by the BMC, controlling the selection controller to connect the first VGA interface and the second VGA interface, and enabling the enabling controller to connect the first USB interface and the second USB interface; as well as After determining that the key storage module is not in place or receiving the verification failure signal sent by the BMC, controlling the selection controller to disconnect the first VGA interface and the second VGA interface, and disabling the enable controller to disconnect the first USB interface and the second USB interface.

4. The device according to claim 3, characterized in that The CPLD includes a VGA selection pin and a USB selection pin; The selection controller includes a first pin, a second pin, a third pin and a fourth pin, the first pin is connected to the VGA selection pin, the second pin is connected to the first VGA interface, the third pin is connected to the second VGA interface, and the fourth pin is left floating; The enabling controller includes a fifth pin, a sixth pin, and a seventh pin, the fifth pin is connected to the USB selection pin, the sixth pin is connected to the first USB interface, and the seventh pin is connected to the second USB interface; The CPLD is also used for: After confirming that the key storage module is in place and receiving the verification pass signal sent by the BMC, controlling the VGA selection pin to output a high level to the first pin, so that the selection controller connects the second pin to the third pin, thereby connecting the first VGA interface to the second VGA interface; and controlling the USB selection pin to output a low level to the fifth pin, so that the enable controller connects the sixth pin to the seventh pin, thereby connecting the first USB interface to the second USB interface; and After determining that the key storage module is not in place or receiving the verification failure signal sent by the BMC, Controlling the VGA selection pin to output a low level to the first pin, so that the selection controller connects the second pin to the fourth pin, thereby disconnecting the first VGA interface from the second VGA interface; as well as The USB selection pin is controlled to output a high level to the fifth pin to disable the enable controller, so that the first USB interface is disconnected from the second USB interface.

5. The device according to claim 1, characterized in that The BMC further includes a first detection pin, the CPLD further includes a second detection pin, the key storage module includes an in-position pin, the in-position pin is used to connect to the key interface when the key storage module is plugged into the key interface, and the key interface is connected to the first detection pin and the second detection pin respectively; When the key storage module is not plugged into the key interface, the first detection pin and the second detection pin are at a high level, so that the BMC and the CPLD determine that the key storage module is not in place; When the key storage module is plugged into the key interface, the in-position pin is at a low level, so that both the first detection pin and the second detection pin are at a low level, so that the BMC and the CPLD determine that the key storage module is in place.

6. The device according to claim 5, characterized in that The BMC further includes a first communication pin and a second communication pin, the CPLD further includes a third communication pin, and the key storage module further includes a fourth communication pin, the first communication pin is connected to the key interface via a first communication bus, the key interface is connected to the fourth communication pin via a second communication bus, and the second communication pin is connected to the third communication pin via a third communication bus; After determining that the key storage module is in place, the BMC reads the key through the first communication bus and the second communication bus; After the key verification passes, the BMC further sends the verification pass signal to the CPLD via the third communication bus; After the key verification fails, the BMC further sends a verification failure signal to the CPLD via the third communication bus.

7. The device according to claim 1, characterized in that When the cover of the server is opened, The BMC is also used to: After determining that the key storage module is not in place, the key verification fails, or a power-off notification sent by the CPLD is received, controlling the server to power off; and The CPLD is also used for: After determining that the key storage module is in place and receiving the verification pass signal sent by the BMC, enabling the power control module of the BMC to respond to power on and off operations of the server; and After determining that the key storage module is in place and receiving the verification failure signal sent by the BMC, the power control module is disabled to not respond to power on and off operations of the server.

8. The device according to claim 7, characterized in that The mainboard further includes a CPU, the CPU is connected to the PCH, and the BMC is connected to the PCH; The BMC is further configured to, upon determining that the key storage module is not in place or the key verification fails or receiving a power-off notification sent by the CPLD, send a power-off instruction to the PCH. The PCH is configured to, upon receiving the power-off instruction, send the power-off instruction to the operating system running in the CPU, so that the operating system powers off the server according to the power-off instruction. The CPLD further includes a power selection pin, the PCH includes a button pin, the button pin is used to connect to a power button, the power control module includes an eighth pin and a ninth pin, the eighth pin is connected to the power selection pin, and the ninth pin is connected to the button pin; The CPLD is also used for: After determining that the key storage module is in place and receiving the verification pass signal sent by the BMC, controlling the power selection pin to input a low level to the eighth pin to enable the power control module, so that the power control module responds to the level signal input by the ninth pin when the ninth pin is configured as an input by the BMC, the level signal being generated by the button pin when the power button is pressed; as well as After determining that the key storage module is in place and receiving the verification failure signal sent by the BMC, controlling the power selection pin to input a high level to the eighth pin to disable the power control module, so that the power control module does not respond to the level signal input by the ninth pin when the ninth pin is configured as an output by the BMC.

9. The device according to claim 7, characterized in that The BMC further includes a third detection pin, and the CPLD further includes a fourth detection pin; When the cover is in place and the cover button does not pop up, the third detection pin and the fourth detection pin are both connected to the cover button, so that the third detection pin and the fourth detection pin are both high, thereby enabling the BMC and the CPLD to determine that the cover is in place; When the cover is opened, the cover button pops up, and the third detection pin and the fourth detection pin are disconnected from the cover button, so that the third detection pin and the fourth detection pin are both low level, thereby enabling the BMC and the CPLD to determine that the cover is opened.

10. A server, characterized in that: The server includes the server security control device according to any one of claims 1 to 9.