Unlocking locked firmware setting utility using multi-factor authentication supported by baseboard management controller

By leveraging multi-factor authentication supported by BMC and utilizing verification codes and user login credentials to unlock firmware settings utilities, the problem of difficult password resets in existing technologies is solved, thereby improving the security and reliability of computer servers.

CN120883205APending Publication Date: 2025-10-31LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380095655.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-04-26
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In existing technologies, unlocking the firmware settings utility of a computer server requires a password, and in edge and IaaS environments, resetting the password is difficult and may result in all settings being cleared, resulting in low security.

Method used

The firmware setup utility unlocks by using multi-factor authentication supported by the Baseboard Management Controller (BMC) and CAPTCHA and user login credentials, avoiding the need to enter a password.

Benefits of technology

This feature enables the firmware setup utility to be unlocked without requiring the user password, improving the security and reliability of edge and IaaS environments and preventing unauthorized tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120883205A_ABST
    Figure CN120883205A_ABST
Patent Text Reader

Abstract

The invention discloses a firmware setting practical program method which can unlock a computer server without a firmware setting practical program user password. The method includes directing the server to an interface of the firmware setup utility and receiving a user request to unlock the firmware setup utility without a password. The method further includes receiving, via a web interface to a baseboard management controller (BMC) of the server, a login credential for accessing the BMC configuration, where the login credential is authenticated by the BMC. The firmware setup utility, in response to the request, causes the BMC to send a verification code to a registered target address stored by the BMC. A user input including a verification code is received through a web interface of the BMC, and in response to determining that the verification code received through the web interface of the BMC matches the verification code in the message, the firmware setting utility is unlocked.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] background

[0002] This disclosure relates to a system and method for unlocking a locked firmware settings utility.

[0003] Background of existing technology

[0004] The Basic Input / Output System (BIOS) is a firmware program stored in erasable programmable read-only memory (EPROM) that is automatically executed by the Central Processing Unit (CPU) upon computer startup. The BIOS code enables the CPU to perform "boot services" during the computer's boot process, such as hardware initialization, and to provide "runtime services" for the operating system. For example, the BIOS code includes instructions for the Power-On Self-Test (POST), which initializes and tests the system hardware components. The BIOS also loads a boot loader from data memory, allowing the boot loader to subsequently initialize the operating system software.

[0005] The Unified Extensible Firmware Interface (UEFI) is an open-source specification for a software interface between the operating system and platform firmware. UEFI is compatible with the BIOS and in some computers can replace many of the BIOS's functions while providing additional features. As UEFI takes on more functions, the BIOS may become a lightweight BIOS. For example, UEFI can support additional hardware such as large storage devices, provide faster boot times, support 32-bit and 64-bit modes, and provide enhanced security features such as Secure Boot.

[0006] While Windows, Linux, or Mac passwords only prevent unauthorized login to the operating system, firmware systems (BIOS / UEFI) offer the ability to set lower-level passwords. For example, requiring a firmware setup utility password can prevent unauthorized individuals from booting the computer, booting from removable devices, and / or changing BIOS / UEFI settings and system configurations. After system configuration tampering is detected, the firmware setup utility password may also be required to unlock the firmware setup utility and enable system booting. Unfortunately, resetting a forgotten firmware setup utility password typically requires physical access to a reset function located inside the computer case, such as an electrical jumper. Furthermore, resetting the firmware setup utility password in this way will erase all firmware settings. These security issues and challenges are likely to be exacerbated in both edge environments and Infrastructure as a Service (IaaS) environments, where control over users who may have access to computing devices may be weaker and the possibility of unauthorized tampering is higher. Summary of the Invention

[0007] Some implementations provide a method for unlocking a firmware setup utility on a computer server without entering a firmware setup utility user password. The method includes: directing the computer server to a user login interface of the firmware setup utility, and receiving a user request to unlock the firmware setup utility without entering a firmware setup utility user password via the user login interface. The method also includes: receiving user login credentials for accessing BMC configuration. Furthermore, the method includes: in response to receiving a user request, the firmware setup utility instructing the BMC to send a message containing a verification code to a registration target address stored by the BMC via the computer server's network interface controller. Additionally, the method includes: receiving user input containing a verification code, and unlocking the firmware setup utility in response to determining that the verification code received via the user input matches a verification code contained in a message sent to the registration target address.

[0008] Some embodiments provide a computer program product including a non-volatile computer-readable medium and non-transitory program instructions implemented on the non-volatile computer-readable medium, the program instructions being configured to be executable by a processor of a baseboard management controller to cause the processor to perform various operations. The operations include: receiving a verification code and instructions from a firmware setup utility running on a computer server, the instructions being used to cause the baseboard management controller to send a message containing the verification code to a registration target address stored by the baseboard management controller. The operations also include: sending the message containing the verification code to the registration target address via a network interface controller of the computer server; authenticating user credentials for logging into the baseboard management controller entered by a user through a web interface of the baseboard management controller; receiving user input including a verification code via the web interface; and providing the verification code received via the web interface to the firmware setup utility.

[0009] Some embodiments provide a computer program product including a non-volatile computer-readable medium and non-transitory program instructions implemented in the non-volatile computer-readable medium, the program instructions being configured to be executable by a processor to cause the processor to perform various operations. The operations include: loading a firmware setting utility having a user login interface, and receiving a user request to unlock the firmware setting utility via the user login interface of the firmware setting utility without entering a user password for the firmware setting utility. The operations also include: providing a first verification code to a baseboard management controller of a computer server, and instructing the baseboard management controller to send a message containing the first verification code to a registration destination stored by the baseboard management controller, wherein the message is sent to the registration destination via a network interface controller of the computer server. Further, the operations include: receiving a second verification code entered by a user from the baseboard management controller, and unlocking the firmware setting utility in response to determining that the second verification code received from the baseboard management controller matches the first verification code provided to the baseboard management controller. Attached Figure Description

[0010] Figure 1 This is a diagram of a system including a computer server according to some implementation methods.

[0011] Figure 2 This is a diagram of a computer server according to some implementation methods.

[0012] Figure 3 This is a diagram of a Baseboard Management Controller (BMC) according to some implementation methods.

[0013] Figure 4 This is a flowchart of server operation according to some implementation methods.

[0014] Figure 5 This is a flowchart of the operation of a baseboard management controller according to some implementation methods.

[0015] Figure 6 This is a flowchart of the operation of a firmware setup utility according to some implementation methods. Detailed Implementation

[0016] Some implementations provide a method for unlocking a firmware setup utility on a computer server without requiring a firmware setup utility user password. The method includes: directing the computer server to a user login interface of the firmware setup utility, and receiving a user request to unlock the firmware setup utility via the user login interface without requiring a firmware setup utility user password. The method also includes: receiving user login credentials for accessing BMC configuration. Furthermore, the method includes: in response to receiving a user request, the firmware setup utility instructing the BMC to send a message containing a verification code to a registration target address stored by the BMC via the computer server's network interface controller. Additionally, the method includes: receiving user input containing a verification code, and unlocking the firmware setup utility in response to determining that the verification code received via the user input matches a verification code contained in a message sent to the registration target address.

[0017] In some implementations, the computer server can have its system configuration established and password-protected by a firmware setup utility at a point in time when hosting and system configuration are trusted. For example, hosting and system configuration can be trusted when the computer server is in its initial installation facility. For instance, a system integrator installing a new computing system can have complete control over the system's setup and configuration until the system is delivered to a customer. System configuration data can be stored in a tamper-proof manner in the computer server's persistent firmware store so that any tampering with the computer server's system configuration can be automatically detected during firmware code execution, for example, during the Basic Input / Output System (BIOS) Power-On Self-Test (POST) process or at some stage of the Unified Extensible Firmware Interface (UEFI) process.

[0018] During the startup of a computer server after system configuration has been established, firmware code such as BIOS and / or UEFI (“BIOS / UEFI”) codes may enable the computer server’s central processing unit (“CPU” or “processor”) to verify that the firmware settings in the system configuration have not been tampered with and to verify that the actual physical (hardware) state of the system matches the expected system configuration. If there is evidence that the firmware settings in the system configuration have been tampered with, or if the current physical state of the system does not match the expected system configuration, the computer system may be prevented from booting the operating system until the system configuration is re-authenticated as trustworthy. For example, firmware may record the system’s physical topology, including unique identifiers for pluggable options, and identify any changes in physical topology that may occur between firmware cycles.

[0019] In some implementations, tampering with the system configuration can be detected by the following steps: calculating a checksum of the system configuration using a checksum function in each boot process; storing the current checksum; and then detecting any changes to the checksum from one boot process to the next. Optionally, the checksum function can be a cryptographic hash function. If the checksum from the current boot process matches the checksum from the most recent previous boot process, the data integrity of the system configuration is verified (i.e., the system configuration has not changed since the last checksum calculation). Furthermore, the checksum can be updated and stored whenever an authorized change occurs to the system configuration.

[0020] Re-authenticating trust may require a system administrator (personnel or "user") to enter a firmware setup utility password into the firmware (BIOS / UEFI) interface. For the entered firmware setup utility password to be accepted, it must match the firmware setup utility password stored thereto to protect the system configuration. Since the system configuration is stored in a protected system configuration area within the firmware storage, the firmware setup utility password must also be entered to make legitimate changes to the system configuration. However, if the firmware setup utility password is forgotten, it must be reset before re-authenticating or changing the existing system configuration can be performed.

[0021] In some implementations, a multi-factor authentication process supported by BMC can be used to reset or authenticate the firmware setup utility password that protects the system configuration. For example, the first authentication factor may include entering a combination of user identifier (“User ID” or “Username”) and password, and the second authentication factor may include entering a challenge response sent to a registered target address such as an email address or mobile phone number. However, no aspect of the multi-factor authentication process can rely on the operating system or software applications, because detecting tampering or a mismatch in system configuration (i.e., the actual hardware does not match the intended hardware) will cause the firmware setup utility to be locked before the operating system and any applications are loaded, preventing boot processing. Furthermore, the operating system and any applications may be prevented from loading until the firmware setup utility is unlocked. Therefore, once the firmware setup utility is locked due to tampering or mismatch, the system firmware cannot use any services of the operating system or applications to reset or authenticate the firmware setup utility password.

[0022] In some implementations, the multi-factor authentication process may include a first authentication factor and a second authentication factor. The first authentication factor may be the correct entry of BMC account credentials for successful login to the BMC. The second authentication factor may be the entry of a code that matches a nonce code sent from the firmware setup utility via the BMC to the registration target address.

[0023] The BMC configuration can store a registration target address, which the BMC can use to send messages. This message can be an email message and may include a verification code obtained from the firmware setup utility. Furthermore, the registration target address can belong to an individual or user, such as a data center administrator.

[0024] The recipient of the message can log in to the BMC web interface using their BMC login credentials (e.g., username and password) and then enter the verification code from the received message into the BMC web interface (“Entered Verification Code”). The BMC can then pass the Entered Verification Code to the Firmware Setup Utility. The Firmware Setup Utility then compares the Entered Verification Code received via the BMC with a previously provided verification code to the BMC. If the Entered Verification Code matches the previously provided verification code, the Firmware Setup Utility will be unlocked to enable access to and changes to system configuration and / or provide any other access, as if the Firmware Setup Utility password had been successfully entered into the Firmware Setup Utility's user interface.

[0025] The registration target address can be a locked value that is part of the BMC configuration, so it cannot be modified using only BMC login credentials (this would reduce security to single-factor authentication only). Instead, any change to the registration target address requires successful entry of BMC credentials and a successful entry of the firmware setup utility user password or successful completion of currently exposed multi-factor authentication.

[0026] When a user, such as a data center administrator, forgets their current firmware setup utility password, they cannot directly unlock the firmware setup utility by entering the password into its user interface. However, the user can interact with the firmware setup utility's user interface to initiate an access recovery process. This firmware-enforced access recovery process requires multi-factor authentication as an alternative to directly entering the current firmware setup utility password, used to reset a new password and / or unlock the firmware setup utility. When the access recovery process is initiated, the firmware setup utility instructs the BMC to send a message to the registered target address, which is stored in the BMC configuration and locked using the firmware setup utility password. This message includes a verification code provided to the BMC by the firmware setup utility. For example, the verification code can be generated by a random number generator in response to receiving a user's request to unlock the firmware setup utility; this random number generator is part of the firmware setup utility's code. The message may also include a prompt instructing the recipient to log in to the BMC web interface using their BMC account credentials (e.g., username and BMC password). The username and BMC password are the BMC account credentials used to gain access to the BMC and serve as the primary authentication factor. However, BMC account credentials are independent of the firmware settings utility password required to reset or access and modify the system configuration of the firmware storage.

[0027] The BMC web interface can be displayed in a web browser using the Internet Protocol (IP) address configured in the BMC interface. After successfully logging into the BMC web interface, the user can enter the verification code they received in the message. The BMC receives the entered code and sends it to the firmware setup utility. The firmware setup utility compares the entered code received from the BMC with the verification code, which was previously generated by the firmware setup utility and provided to the BMC for sending to the registration destination. If the codes match, this serves as a second authentication factor, and the locked firmware setup utility is unlocked. After the firmware setup utility is unlocked, the user can view or update their firmware setup utility password and / or confirm or change system configurations, including firmware settings and hardware configurations.

[0028] In some implementations, the firmware setup utility is a setup utility for the Basic Input / Output System and / or the Unified Extensible Firmware Interface. In one alternative, unlocking the firmware setup utility may include unlocking a locked system configuration on a computer server.

[0029] In some implementations, the operation may further include: allowing a user to create a new firmware setup utility user password, verifying system configuration, and / or modifying system configuration in response to unlocking the firmware setup utility. Optionally, the firmware including the firmware setup utility and system configuration may be stored on an erasable programmable read-only memory (EPROM) of a computer server.

[0030] In some implementations, user login credentials for accessing the Baseboard Management Controller (BMC) configuration are entered into and received by the BMC via its web interface. Subsequently, user input containing a verification code is entered into and received by the BMC via the web interface. The BMC can then pass this user input containing the verification code to a firmware setup utility. The firmware setup utility can then determine whether the verification code received via the BMC web interface matches the verification code contained in a message sent to the registration target address.

[0031] In some implementations, user login credentials for accessing the baseboard management controller configuration can be entered and received in the firmware setup utility's interface. These login credentials can then be verified using the BMC. Similarly, user input containing a verification code can be directly received in the firmware setup utility.

[0032] In some implementations, the operation may also include automatically determining, during the boot process of the computer server, whether any unauthorized changes have occurred to the system configuration and / or physical state of the computer server since its last boot. In one example, the computer server may automatically boot to the user login interface of a firmware setup utility in response to determining that unauthorized changes have occurred to the system configuration and / or physical state of the computer server since its last boot.

[0033] Some implementations provide a computer program product including a non-volatile computer-readable medium and non-transitory program instructions implemented in the non-volatile computer-readable medium, the program instructions being configured to be executable by a processor of a BMC to cause the processor to perform various operations. The operations include: receiving a verification code and instructions from a firmware setup utility running on a computer server, for instructing the BMC to send a message containing the verification code to a registration target address stored by the BMC. The operations also include: sending the message containing the verification code to the registration target address via a network interface controller of the computer server; authenticating user credentials entered by a user through a BMC web interface for logging into the BMC; receiving user input including a verification code via the web interface; and providing the verification code received via the web interface to the firmware setup utility.

[0034] Some implementations provide a computer program product comprising a non-volatile computer-readable medium and non-transitory program instructions implemented in the non-volatile computer-readable medium, the program instructions being configured to be executable by a processor to cause the processor to perform various operations. For example, the processor may be a central processing unit (CPU) of a computer server, and the program instructions may be program instructions for a firmware setup utility of BIOS / UEFI firmware. After loading a firmware setup utility with a user login interface, the operation may include receiving a user request to unlock the firmware setup utility via the user login interface of the firmware setup utility without requiring the user to enter a firmware setup utility user password. The operation also includes providing a first verification code to the BMC of the computer server and instructing the BMC to send a message containing the first verification code to a registration destination stored by the BMC, wherein the message is sent to the registration destination via a network interface controller of the computer server. Further, the operation includes receiving a second verification code entered by the user from the BMC, and unlocking the firmware setup utility in response to determining that the second verification code received from the BMC matches the first verification code provided to the BMC.

[0035] In some implementations, unlocking the firmware setup utility may include unlocking a locked system configuration of the computer server. Some implementations may also include, in response to unlocking the firmware setup utility, allowing the user to create a new firmware setup utility user password, verify the system configuration, and / or modify the system configuration.

[0036] The aforementioned computer program product may further include program instructions for implementing or initiating one or more operations of the methods described herein, and the aforementioned methods may also include any operation of the computer program product. Furthermore, implementations may include a computer server configured to perform the operations and / or methods of the computer program product described herein.

[0037] Figure 1 This is a diagram of a system 10 including a computer server 20 according to some embodiments. The computer server 20 communicates with a computer 60 and a mobile communication device 67 via one or more networks 12. The computer 60 and the mobile communication device 67, such as a smartphone, can be accessed by a data center administrator or similar authorized personnel, who may be referred to herein as "users". For example, the data center administrator may have login credentials for both device 60 and device 67. In addition, the data center administrator ("user") may have login credentials for the BMC web interface, firmware setup utility interface, and email application. Optionally, the email application may reside on the computer 60 or other devices.

[0038] Computer server 20 includes a central processing unit (CPU) 22, memory 24, a network interface controller (NIC) 26, firmware 30 including a basic input / output system (BIOS) and / or a unified extensible firmware interface (UEFI), and a baseboard management controller (BMC) 50. Both CPU 22 and BMC 50 are capable of accessing network 12 via NIC 26 (or a separate NIC), but BMC 50 receives standby power even when computer server 20 is "shut down" and CPU 22 is not running. Therefore, as long as computer server 20 is connected to power and network 12, BMC 50 can support remote connections to computer 60 operated by a data center administrator.

[0039] Firmware (BIOS / UEFI) 30 may include EPROM and / or other data storage for storing firmware setup utility 32 and system configuration 40. During the boot process of computer server 20, CPU 22 loads and runs firmware (BIOS / UEFI) code before loading the operating system and any applications. Therefore, CPU 22 runs firmware setup utility 32, which can provide access control logic including lock / unlock criteria 34 and multi-factor authentication logic 36. Lock / unlock criteria 34 may include logic to determine whether system configuration 40 has been tampered with (i.e., unauthorized changes to system configuration 40 or the physical hardware configuration of computer server 20). For example, system configuration 40 may include firmware settings 42 and hardware configuration 44 of the system hardware. If a checksum and / or hash value is calculated and stored after each authorized change in firmware settings 42, the firmware can cause the CPU to calculate a new checksum and / or hash value during boot. If the new checksum and / or hash value calculated during boot matches the stored checksum and / or hash value, it is determined that no unauthorized changes exist in firmware settings 42. Tampering or alteration. However, if the new checksum and / or hash value calculated during boot does not match the stored checksum and / or hash value, it is determined that there is indeed unauthorized tampering or alteration in the firmware settings 42, and therefore the lock / unlock standard 34 can put the firmware setup utility 32 into "lock" mode, and boot processing cannot continue to the stage of loading the operating system. The firmware setup utility password (displayed at 37; optionally, displayed as "BIOS / UEFI password") can be used to unlock the firmware setup utility. However, if the firmware setup utility password 37 is forgotten, it may be necessary to reset the password before continuing.

[0040] According to some implementations, the firmware setup utility 32 may include multi-factor authentication (MFA) logic 36 to support the unlocking of the firmware setup utility 32 and allow the boot process to continue. As the name suggests, multi-factor authentication requires the user to authenticate through more than one form (factor). In some implementations, the first authentication factor may be the user's BMC login credentials, and the second authentication factor may be a verification code. Therefore, the MFA logic 36 may determine that the entered password does not match the firmware setup utility password 37, and then use a random number generator (logic) 38 to generate a verification code provided to the BMC 50.

[0041] BMC 50 may include a BMC network interface 52, a BMC configuration 54, and a firmware (BIOS / UEFI) interface 58. The BMC network interface 52 handles input / output via NIC 26, and the firmware interface 58 handles communication with firmware 30. The BMC configuration 54 may include various settings and logic, but may also store BMC login credentials 55 and a registration target address (email address) 56 locked using the firmware setup utility password 37. Therefore, only users who successfully enter authorized BMC login credentials 55 and firmware setup utility password 37 can change the registration target address (email address) 56.

[0042] Computer 60 can run a web browser application 62 to access the BMC web interface 64. For example, an Internet Protocol (IP) address can be assigned to BMC 50. Users can access the BMC web interface by entering the IP address of BMC 50 into web browser 62, followed by BMC login credentials 55. If the entered BMC login credentials match BMC login credentials 55 stored in BMC configuration 54, then the user is authenticated and can access the data and services of BMC 50.

[0043] Mobile communication device or computer 67 can be configured to receive emails associated with registered email address 56. Therefore, if BMC 50 sends an email to registered email address 56, that email will be sent to mobile communication device 67 via NIC 26 and network 12. Only authorized users can access emails sent to the registered email address.

[0044] Therefore, if the firmware setup utility 32 of firmware (BIOS / UEFI) 30 has determined that the lock / unlock standard 37 has been violated (i.e., unauthorized tampering has occurred), and it has been determined that the user has requested access recovery via firmware (BIOS / UEFI) interface 66 (possibly due to forgetting the firmware setup utility password), then MFA logic 36 can use random number generator 38 to generate a verification code and provide it to firmware interface 58. BMC 50 can then send an email message containing the verification code to registered email address 56, causing the email to be routed to a mobile communication device or computer 67 accessible to the authorized user. The user can view the email message received at email application 68 associated with the registered email address 56 and obtain the verification code. The user can then access the BMC web interface and successfully enter BMC login credentials 55 (first authentication factor) to access BMC 50 data and services, and enter the verification code (second authentication factor) into BMC web interface 64. After receiving the verification code entered by the user, BMC 50 can pass the entered verification code to firmware 30. If MFA logic 36 determines that the verification code received from BMC 50 matches the verification code 38 generated by MFA logic 36, multi-factor authentication is successfully performed, and firmware setup utility 32 can be unlocked to allow changes to system configuration 40. Therefore, before instructing or otherwise causing firmware (BIOS / UEFI) 30 to reboot or continue booting, the user can further interact with firmware interface 66 on computer 60 to confirm or modify system configuration 40 and / or view or replace firmware setup utility password.

[0045] Figure 2 This is a schematic diagram of computer server 100, which can represent Figure 1 The system 10 shows computer server 20. However, server 100 may also represent most of the architecture of computer 60 and / or computing mobile device / computer 67. Nevertheless, computer 60 and / or mobile device / computer 67 typically do not include BMC.

[0046] Server 100 includes a processor unit 104 coupled to a system bus 106. Processor unit 104 may use one or more processors, each having one or more processor cores. An optional graphics adapter 108 may also be coupled to the system bus 106, and this graphics adapter 108 may drive / support an optional display 120. For example, graphics adapter 108 may include a graphics processing unit (GPU). System bus 106 may be coupled to input / output (I / O) bus 114 via bus bridge 112. I / O interface 116 is coupled to I / O bus 114, wherein I / O interface 116 provides connectivity to various optional I / O devices, such as camera 110, keyboard 118 (e.g., touchscreen virtual keyboard), and USB mouse 124 (or other types of pointing devices, such as touchpads) via USB port 126. As shown, computer 100 can communicate with other network devices via network 12 using a network adapter or network interface controller 130.

[0047] Hard disk drive interface 132 is also coupled to system bus 106. Hard disk drive interface 132 interfaces with hard disk drive 134. In a preferred embodiment, hard disk drive 134 may communicate with system memory 136, which is also coupled to system bus 106. System memory may be volatile or non-volatile and may include additional higher-level volatile memory (not shown), including but not limited to buffer memory, registers, and buffers. Data filling system memory 136 may include operating system (OS) 140 and application programs 144. The hardware elements shown in server 100 are not exhaustive but representative.

[0048] Operating system 114 includes a shell 141 for providing users with transparent access to resources such as application 144. Typically, shell 141 is a program that provides an interpreter and an interface between the user and the operating system. More specifically, shell 141 can execute commands entered into a command-line user interface or commands from a file. Therefore, shell 141, also called a command processor, is typically at the highest level of the operating system software hierarchy and acts as a command interpreter. The shell can provide system prompts, interpret commands entered via the keyboard, mouse, or other user input media, and send the interpreted commands to the appropriate lower level of the operating system (e.g., kernel 142) for processing. It should be noted that while shell 141 can be a text-based, line-oriented user interface, the present invention can support other user interface modes, such as graphics, voice, gestures, etc.

[0049] As shown in the figure, the operating system 140 also includes a kernel 142, which includes lower-level functions of the operating system 140, including providing basic services required by other parts of the operating system 140 and applications 144. These basic services may include memory management, processing and task management, disk management, and mouse and keyboard management. Furthermore, the computer 100 may include applications 144 stored in system memory 136.

[0050] In addition, server 100 may include a service processor, such as BMC 50. The BMC is considered an out-of-band controller that can monitor and control the various components of server 100. However, the BMC can communicate with various devices via network interface 26 and network 12, for example, by sending email messages to registered email addresses and receiving input through the BMC web interface.

[0051] Figure 3 This is a diagram of a BMC 50 according to some implementations. The BMC 50 is similar to a small computer or system-on-a-chip (SoC), including a central processing unit (CPU) 70 (the CPU 70 is associated with...). Figure 1 The BMC 50 includes a central processing unit 22 (a separate entity), memory 71 (e.g., random access memory (RAM) on a double data rate (DDR) bus), flash memory (e.g., embedded multimedia card (eMMC) flash or serial peripheral interface (SPI) flash), firmware 72, and a root of trust (RoT) chip 74. The BMC 50 also includes various input / output ports. For example, input / output (I / O) ports may include: I / O ports 75 connecting to hardware components of the server, such as Platform Environment Control Interface (PECI) ports and / or Advanced Platform Management Link (APML) ports; I / O ports 76 connecting to hardware components of the server and / or network interface controllers (NICs), such as peripheral component fast interconnect (PCIe) ports; I / O ports 77 connecting to the NIC, such as Network Controller Sideband Interface (NC-SI) ports; and I / O ports 78 connecting to external user-accessible networks, such as Ethernet ports. The BMC 50 can use one or more of these I / O ports to interact with hardware devices installed on the server to obtain hardware performance data of the hardware devices. Alternatively, the output from BMC 50 to the BMC web interface or Redfish interface can be routed via I / O port 78 to the Network Interface Controller (NIC) 26 (see...). Figure 1 ), and finally routed to network 12, which can be accessed through NIC 26.

[0052] Figure 4This is a flowchart of server operation 150 according to some implementations. In the context of the operations in the flowchart, the firmware setup utility locking function has been previously configured to require a firmware setup utility password during boot processing if an attempt to tamper with the system configuration or the server's physical hardware configuration is detected. Implementations may also require specifying a registration target address, such as an email address, as part of the BMC configuration. When the firmware setup utility is locked by the firmware setup utility password, the registration target address informs the BMC where to send a verification (one-time) code to unlock the firmware setup utility. The registration email address may be stored in the BMC configuration but is protected by the firmware setup utility password, so only a user possessing both BMC login credentials and the firmware setup utility password can change the registration target address. It should be understood that the BMC operates in standby power and is always on, even if the server power state is "off".

[0053] Operation 152 includes booting the computer server to the user login interface of the firmware setup utility. The user may intentionally boot to the system firmware setup utility (“F1”) during computer startup to manually initiate changes to the system configuration, or the computer system may automatically boot to the system firmware setup utility in response to the detection of unauthorized changes to the system configuration or physical hardware configuration. In either case, the system firmware setup utility will prompt the user for authentication input, such as a firmware setup utility password. The F1 key is typically the key that the user can press to interrupt the normal startup of the computer and enter the firmware setup utility.

[0054] Operation 154 includes receiving a user request via the user login interface of the firmware setup utility to unlock the firmware setup utility without having to enter the firmware setup utility user password. For example, if the user has forgotten the firmware setup utility password, such a user request can be entered.

[0055] Operation 156 includes receiving user login credentials for accessing BMC configuration via the BMC web interface of the computer server, wherein the user login credentials are authenticated by the BMC. Successful entry of the user's BMC login credentials can be considered as a primary authentication factor.

[0056] Operation 158 includes the firmware setup utility instructing or otherwise causing the BMC to send a message containing a verification code to the registration target address stored by the BMC via the network interface controller of the computer server in response to a user request.

[0057] Operation 160 includes receiving user input containing a verification code via the BMC web interface. Operation 162 includes unlocking the firmware setup utility (i.e., unlocking the system configuration) in response to determining that the verification code received via the BMC web interface matches a verification code contained in a message sent to the registration target address. Successful input of the verification code can be considered a second authentication factor. After passing the described multi-factor authentication process, the user can use the firmware setup utility to confirm or change the system configuration, physical hardware configuration, and / or firmware setup utility password.

[0058] Figure 5 This is a flowchart of operation 170 of the BMC according to some embodiments. Operation 172 includes receiving a verification code and instructions from a firmware setup utility running on a computer server, causing the BMC to send a message containing the verification code to a registration target address stored by the BMC. Operation 174 includes sending the message containing the verification code to the registration target address via the network interface controller of the computer server. Operation 176 includes authenticating user credentials entered by the user through the BMC web interface for logging into the BMC. Operation 178 includes receiving user input including a verification code via the web interface. Operation 180 includes providing the verification code received via the web interface to the firmware setup utility.

[0059] Figure 6 This is a flowchart of operation 190 of a firmware setup utility with a user login interface, wherein the firmware setup utility has been loaded in operation 192. Operation 194 includes receiving a user request via the user login interface of the firmware setup utility to unlock the firmware setup utility without entering a firmware setup utility user password. Operation 196 includes providing a first verification code to the BMC of the computer server. Operation 198 includes instructing or otherwise causing the BMC to send a message containing the first verification code to a registration destination stored by the BMC, wherein the message is sent to the registration destination via the network interface controller of the computer server. Operation 200 includes receiving a second verification code entered by the user from the BMC. Operation 202 includes unlocking the firmware setup utility in response to determining that the second verification code received from the BMC matches the first verification code provided to the BMC.

[0060] Those skilled in the art will understand that implementation methods can take the form of systems, methods, or computer program products. Therefore, implementation methods can take the form of entirely hardware implementations, entirely software implementations (including firmware, resident software, microcode, etc.), or implementations combining software and hardware aspects, which are generally referred to herein as “circuit,” “module,” or “system.” Furthermore, implementation methods can take the form of computer program products embodied in one or more computer-readable media, wherein computer-readable program code is embodied in the computer-readable media.

[0061] Any combination of one or more computer-readable storage media may be used. For example, a computer-readable storage medium may be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing, but is not limited thereto. Computer-readable storage media includes more specific examples (a non-exhaustive list) of the following: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing. In the context of this document, a computer-readable storage medium may be any tangible medium that can contain or store a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. Furthermore, for the avoidance of doubt, any program instructions or code embodied on such a computer-readable storage medium (including forms referred to as volatile memory) are considered “non-transient” as long as they are not transient signals.

[0062] Program code implemented on a computer-readable storage medium can be transmitted using any suitable medium, including but not limited to wireless, wired, fiber optic cable, RF, or any suitable combination of the above media. Computer program code for performing various operations can be written in any combination of one or more programming languages, including: object-oriented programming languages ​​such as Java, Smalltalk, C++, etc.; and traditional procedural programming languages ​​such as the "C" programming language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the remote computer can be connected to an external computer (e.g., via the Internet provided by an Internet service provider).

[0063] Implementation methods can be described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products. It is understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, and / or other programmable data processing apparatus used for manufacturing machines, such that, when executed by the processor of the computer or other programmable data processing apparatus, these instructions are designed to implement means for carrying out the functions / actions specified in the blocks of the flowchart illustrations and / or block diagrams.

[0064] These computer program instructions, which can also be stored on computer-readable storage media, are not transient signals. This allows the program instructions to instruct a computer, other programmable data processing device, or other equipment to operate in a particular manner, and enables the program instructions stored on the computer-readable storage media to produce industrial products.

[0065] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus or other device to cause the computer, other programmable apparatus or other device to perform a series of operational steps to produce a computer-implemented process, such that when the instructions are executed on the computer or other programmable device, they provide for implementing the function / action specified in the boxes of the flowchart and / or block diagram.

[0066] The flowcharts and block diagrams in the accompanying drawings illustrate possible implementations of the structure, function, and operation of the system, method, and computer program product. In this regard, each block in a flowchart or block diagram may represent a code module, code segment, or portion of code, including one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may not occur in the order shown in the figures. For example, two consecutively displayed blocks may actually be executed substantially simultaneously, or sometimes in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware system or a combination of dedicated hardware and computer instructions that performs the specified function or action.

[0067] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of the claims. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “the” used herein are also intended to include the plural forms. It should also be understood that the terms “comprising” and / or “including” as used in this specification indicate the presence of said features, integers, steps, operations, elements, components, and / or groups, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups. The terms “preferred,” “ideally,” “preferred,” “optionally,” “may,” and similar terms are used to indicate that the mentioned items, conditions, or steps are optional (non-essential) features of the embodiment.

[0068] The corresponding structures, materials, actions, and equivalents of all means or steps and functional elements in the following claims are intended to include any structure, material, or action used to perform the function in conjunction with other claimed elements that are explicitly claimed. Embodiments have been presented for purposes of illustration and description, but are not exhaustive and are not intended to limit the form of the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art upon reading this disclosure. The disclosed embodiments have been chosen and described as non-limiting examples to enable others skilled in the art to understand these embodiments, as well as other embodiments involving modifications suitable for a particular implementation.

Claims

1. A method for accessing a firmware setup utility on a computer server without entering a firmware setup utility user password, the method comprising: The computer server is redirected to the user login interface of the firmware setup utility; The user request to unlock the firmware setting utility is received via the user login interface of the firmware setting utility without having to enter the firmware setting utility user password. Receive user login credentials for accessing the configuration of the baseboard management controller, wherein the user login credentials are authenticated by the baseboard management controller; In response to receiving the user request, the firmware setting utility instructs the baseboard management controller to send a message containing a verification code to the registration target address stored by the baseboard management controller through the network interface controller of the computer server; Receive user input containing the verification code; and In response to determining that the verification code received via the user input matches the verification code contained in a message sent to the registration target address, the firmware settings utility is unlocked.

2. The method according to claim 1, wherein, The firmware settings unlocking utility includes: unlocking the system configuration of the computer server.

3. The method according to claim 1, wherein, The firmware setup utility is a setup utility for the Basic Input / Output System and / or the Unified Extensible Firmware Interface.

4. The method according to claim 1, wherein, The computer server does not load the operating system until the firmware setup utility is unlocked.

5. The method according to claim 1, further comprising: In response to unlocking the firmware settings utility, the user is allowed to create a new firmware settings utility user password, confirm system configuration, and / or modify the system configuration.

6. The method according to claim 5, wherein, The system configuration is stored on the erasable programmable read-only memory of the computer server.

7. The method according to claim 1, further comprising: The firmware setup utility generates the verification code in response to a user request to unlock the firmware setup utility.

8. The method according to claim 1, wherein, The user login credentials used to access the configuration of the baseboard management controller are received by the baseboard management controller through the baseboard management controller web interface, and the user input containing the verification code is received by the baseboard management controller through the baseboard management controller web interface.

9. The method according to claim 8, further comprising: The baseboard management controller passes user input containing the verification code to the firmware setting utility, wherein the firmware setting utility determines that the verification code received through the baseboard management controller's web interface matches the verification code contained in a message sent to the registration target address.

10. The method according to claim 1, wherein, The firmware setup utility receives user login credentials for accessing the baseboard management controller configuration, as well as user input containing the verification code.

11. The method according to claim 1, wherein, The registered target address stored by the baseboard management controller is protected by the user password of the firmware setting utility.

12. The method according to claim 1, further comprising: During the booting of the computer server, it is automatically determined whether any unauthorized changes have occurred to the system configuration and / or physical state of the computer server since its last boot. In response to determining that unauthorized changes have occurred to the system configuration and / or physical state of the computer server since its last boot, the computer server automatically boots to the user login interface of the firmware setup utility.

13. The method according to claim 1, further comprising: Prevent the computer server from booting the operating system until the user has been verified as trustworthy in the system configuration and / or physical state of the computer server after the firmware setup utility has been unlocked.

14. A computer program product comprising a non-volatile computer-readable medium and non-transitory program instructions implemented in the non-volatile computer-readable medium, the program instructions being configured to be executable by a processor of a baseboard management controller to cause the processor to perform operations, the operations including: The system receives a verification code and instructions from a firmware setup utility running on a computer server. The instructions are used to cause the baseboard management controller to send a message containing the verification code to a registration target address stored by the baseboard management controller. The computer server's network interface controller sends a message containing the verification code to the registration target address. Authenticate the user credentials used to log in to the baseboard management controller by the user entering them through the web interface of the baseboard management controller; Receive user input, including the verification code, via a web interface; as well as The verification code received via the web interface is provided to the firmware setup utility.

15. The computer program product according to claim 14, wherein the operation further comprises: The registered target address is protected with a user password using the firmware setup utility.

16. A computer program product comprising a non-volatile computer-readable medium and non-transitory program instructions implemented in the non-volatile computer-readable medium, the program instructions being configured to be executable by a processor to cause the processor to perform operations, the operations including: The user request to unlock the firmware setting utility is received via the user login interface of the firmware setting utility running on the computer server without having to enter the firmware setting utility user password; The first verification code is provided to the baseboard management controller of the computer server; The baseboard management controller is instructed to send a message containing the first verification code to a registration destination stored by the baseboard management controller, wherein the message is sent to the registration destination through the network interface controller of the computer server; Receives a second verification code input by the user from the baseboard management controller; and In response to determining that the second verification code received from the baseboard management controller matches the first verification code provided to the baseboard management controller, the firmware setting utility is unlocked.

17. The computer program product according to claim 16, further comprising: In response to unlocking the firmware settings utility, the user is allowed to create a new firmware settings utility user password, confirm system configuration, and / or modify the system configuration.

18. The computer program product according to claim 16, further comprising: The verification code is generated in response to a user request to unlock the firmware settings utility.

19. The computer program product according to claim 16, further comprising: During the booting of the computer server, it is automatically determined whether any unauthorized changes have occurred to the system configuration and / or physical state of the computer server since its last boot. In response to determining that unauthorized changes have occurred to the system configuration and / or physical state of the computer server since its last boot, the computer server automatically boots to the user login interface of the firmware setup utility.

20. The computer program product according to claim 16, further comprising: In response to unlocking the firmware settings utility, the user is allowed to create a new firmware settings utility user password, confirm system configuration, and / or modify the system configuration.