SNMP interface system of server BMC and implementation method thereof

By designing a modular OID tree structure and a BMC/SNMP interface system that supports multiple versions of SNMP, the problems of insufficient functional coverage, security, and ease of use in existing technologies are solved, achieving efficient and secure server management and reducing the complexity of data center operation and maintenance and fault response time.

CN121008970APending Publication Date: 2025-11-25SOUTHEAST UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511003940.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-21
Publication Date
2025-11-25

AI Technical Summary

Technical Problem

The existing BMC/SNMP interface is inadequate in terms of functional coverage, security, ease of use, and performance, which limits its application in complex data center environments.

Method used

An SNMP interface system for a server BMC was designed, including an interface definition layer, a command processing layer, a data interaction layer, a security control layer, and an application integration layer. It supports multiple SNMP versions, adopts a modular OID tree structure to enhance security, realizes data mapping and interaction through MIB files, and integrates with other management tools of the BMC. It also adopts an event-driven mechanism and an efficient data structure to optimize command processing.

Benefits of technology

A comprehensive, secure, reliable, efficient, and easy-to-use BMC/SNMP interface system has been implemented, which enhances remote monitoring and management capabilities, reduces operational complexity and hardware failure response time, and improves management efficiency and system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121008970A_ABST
    Figure CN121008970A_ABST
Patent Text Reader

Abstract

The invention discloses an SNMP (Simple Network Management Protocol) interface system of a server BMC (Baseboard Management Controller) and an implementation method thereof, and the method comprises the following steps: firstly, defining OIDs (Open Identifier) of a plurality of modules such as server overview information, network information, time information, port management information and the like, and determining a complete OID according to the modules and specific node numbers; and then, for node information of each module, creating an operation constraint and setting the operation constraint to carry out detailed elaboration. A server overview information module is taken as an example, a system module containing system power-on time, server basic information, a server environment, BMC basic information, host utilization rate and other information is defined, node information is subjected to tabular description, and constraint conditions of setting operation are clarified. The method covers interface definitions in multiple aspects of network configuration, time synchronization, port management, sensor monitoring, user management, power management, power consumption statistics, alarm configuration and the like, and aims to realize comprehensive, fine and safe remote monitoring and configuration of BMC management through an SNMP protocol.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of server management technology, and in particular to an SNMP interface system for a server BMC and its implementation method. Background Technology

[0002] In large data centers, efficient server management is crucial for ensuring business continuity and stability. Server Management Console (BMC), as a key management component, provides remote monitoring and management capabilities for server hardware status. SNMP, a widely used network management protocol, enables centralized management and monitoring of network devices. However, existing BMC / SNMP interfaces still have shortcomings in terms of functional coverage, security, ease of use, and performance, limiting their application in complex data center environments.

[0003] The technical comparison is as follows:

[0004] Comparison with the technology of patent CN 103607314 A "A system for monitoring and managing servers using the SNMP protocol"

[0005] Patent CN 103607314 A monitors sensor data from a server via a BMC. When the monitored value exceeds a threshold, the BMC sends an alarm to the host via SNMP. The SNMP service program running on the host periodically polls and reads sensor values ​​to achieve basic hardware monitoring. Its management information base uses a statically defined sensor OID tree structure. In contrast, this patent constructs a modular OID tree on the BMC to cover 10 types of BMC management functions, including power supply, temperature, fan, and logs. It also integrates with multiple SNMP versions and IPMI / Redfish protocol integration to achieve a high-performance, secure, and compatible remote management interface. The two patents differ fundamentally in their technical approaches.

[0006] Patent CN 103607314 A uses a fixed MIB node definition and a ported NET-SNMP agent to complete basic monitoring and alarm functions for sensor status. This patent, however, uses an event-driven architecture combined with MIB semantic mapping and secure encryption control mechanisms to achieve comprehensive monitoring of all BMC management functions. The two patents differ fundamentally in their methodological implementation.

[0007] Technical Comparison with Patent CN 104104543 A "A Server Management System and Method Based on SNMP and IPMI Protocols"

[0008] Patent CN 104104543 A centrally manages multiple server nodes through a central BMC. It first uses the IPMI protocol to collect sensor information from each node and converts it into SNMP messages, which are then forwarded to the network management station by an SNMP Trap forwarding module, achieving centralized monitoring of multiple servers. In contrast, this patent directly builds a modular SNMP interface system within the BMC of a single server, covering multiple management functions such as power and environment, and natively integrates IPMI / Redfish protocols to provide a unified remote management service. The two patents differ fundamentally in their technical approaches.

[0009] Patent CN 104104543 A employs a dual-protocol bridging mechanism of IPMI and SNMP, along with an IPMI-SNMP message pool mechanism, to manage the device. Specifically, it uses the message pool to map and convert between IPMI commands and SNMP requests to obtain and set the status of each BMC. In contrast, this patent utilizes an event-driven mechanism with multi-version support for SNMP, along with MIB semantic mapping and encrypted security controls to achieve efficient management and real-time alarms for various BMC functions. The two patents differ fundamentally in their methodological implementation. Summary of the Invention

[0010] To address the aforementioned difficulties and problems in existing methods, this invention innovatively proposes an SNMP interface system for a server BMC and its implementation method. This method provides a comprehensive, secure, reliable, efficient, and easy-to-use server BMC / SNMP interface system, overcoming the shortcomings of existing technologies.

[0011] The purpose of this invention is to propose an SNMP interface system for a server BMC, comprising an interface definition layer, a command processing layer, a data interaction layer, a security control layer, and an application integration layer;

[0012] The interface definition layer is used to define SNMP interfaces covering multiple functional modules. Each module contains multiple OID nodes and has a pre-defined modular OID tree structure.

[0013] The command processing layer is used to support command processing for multiple SNMP versions;

[0014] The data interaction layer is used to implement data mapping and interaction through MIB files;

[0015] A security control layer is used to enhance the security of SNMP v3.

[0016] Application integration layer, used for integration with other management tools of BMC.

[0017] The purpose of this invention is to propose an implementation method for an SNMP interface system based on a server BMC, characterized by the following specific steps:

[0018] In step 1), the interface definition layer is the foundation of the entire SNMP interface system. It is responsible for defining all manageable OID nodes. These OID nodes are organized according to functional modules, covering all aspects of server management. Each OID node has a clear semantic and data type definition, ensuring that the management software can accurately understand and operate these nodes. To further enhance system availability and configuration security, the interface definition layer also clarifies the operational constraints and typical applications of nodes in each functional module. For example, settings in the network configuration module can only be modified in static address mode; the fan control module only supports settings to predefined mode values; sensor nodes are read-only and cannot be modified; the power control module only accepts fixed command string inputs. These constraints ensure that the SNMP interface, while covering multiple functions, has robust operational boundaries and secure execution logic. Through these detailed module definitions, the SNMP interface can not only support remote data acquisition but also be applied to configuration management and alarm response in real-world scenarios, thereby improving the server BMC's practical application capabilities in remote monitoring and automated operation and maintenance.

[0019] In step 2), the command processing layer is responsible for receiving and processing command requests from the SNMP management software. It supports three protocol versions: SNMPv1, v2c, and v3, to adapt to different network environments and security requirements. For each version, the system provides corresponding command processing logic. When a command is received, the system first parses the command type and target OID, and then looks up the corresponding management information node based on the OID. For GET operations, the current value of the node is returned directly. For SET operations, in addition to updating the node value, strict permission verification and data validity checks are performed to ensure that only users with the corresponding permissions can modify key settings, and that the modified data conforms to the predefined format and range.

[0020] In step 3), the data interaction layer uses the MIB file to realize data mapping and interaction between the BMC and the SNMP management software. The MIB file is a standard text file that uses the SMI language to define the structure, syntax and semantics of OID nodes. The MIB file defines the detailed information of all OID nodes, including node name, OID value, data type, access permissions and descriptive text. The data types include strings, integers and enumerations, and the access permissions include read-only and read-write. When the SNMP management software sends a request, the system will convert the request into an operation on the internal data of the BMC according to the definition in the MIB file, and then convert the operation result into a response format that conforms to the MIB definition and return it to the management software.

[0021] In step 4), the security control layer is designed for SNMP v3 to enhance the security of remote management;

[0022] In step 5), the application integration layer is responsible for seamlessly integrating the SNMP interface with other BMC management tools to provide administrators with a unified management experience. Integration with the BMC web interface allows administrators to directly view and configure SNMP interface parameters and view SNMP Trap alarm information through the web interface; integration with the IPMI interface allows the IPMI management tool to access and manipulate data in the SNMP interface; and integration with the Redfish interface enables higher-level management functions for the server.

[0023] Step 6) involves the following steps to cover the entire lifecycle from system initialization to log auditing:

[0024] Interface initialization:

[0025] During BMC startup, the system loads a predefined MIB file and initializes the SNMP service. The initialization process includes setting default SNMP parameters. At the same time, the system checks the integrity and correctness of the MIB file to ensure that all OID nodes are correctly defined and there are no conflicts. In addition, the system will perform initial configuration of SNMP v3 users based on configuration files or user input, including creating default users, setting default passwords and encryption algorithms.

[0026] Command parsing and execution:

[0027] When the SNMP management software sends a command request, the system first receives the command data packet and parses it. The parsing process includes extracting the command type, version number, community name or username, target OID, and optional parameters. Based on the command type and target OID, the system searches for the corresponding OID node in the Management Information Base (MIB). For GET operations, it directly reads the node's current value and encapsulates it into a response data packet, returning it to the management software. For SET operations, it includes reading and modifying the node value. For example, when the SNMP management terminal sends a setting command to perform a remote shutdown, the command parsing locates the "powerStatus" node in the server overview module. The system first performs permission verification and data validity checks, confirming that the requesting user has the right to perform the shutdown operation and that the set value is a valid shutdown command such as "ForceOff". After successful verification, the command processing layer calls the BMC underlying interface to perform the shutdown operation and updates the value of "powerStatus" to "Off" (indicating shutdown) for subsequent queries. The entire process returns a success status code in the SNMP response, thus confirming that the remote shutdown has been executed.

[0028] Data updates and notifications:

[0029] To ensure the SNMP management software can promptly detect changes in server status, the system proactively updates relevant data in the SNMP interface and sends notifications to subscribed management software when key server metrics change. When the server's temperature sensor detects that the CPU temperature exceeds a preset threshold, the system immediately updates the value of the corresponding OID node and sends a notification to the management software via SNMP Trap or Inform messages. Upon receiving the notification, the management software takes timely action, such as sending alarm messages to the administrator and automatically performing cooling operations. The system employs an event-driven mechanism to capture server status changes. Various sensors and monitoring modules within the BMC periodically report data to the system. When data exceeds normal ranges or specific events occur, event notifications are generated. Upon receiving these event notifications, the system quickly processes and updates the SNMP interface data, ensuring the management software can obtain the latest server status information promptly. Furthermore, the system immediately notifies relevant modules to update after critical configurations are modified via SNMP. For example, when modifying network configuration via SNMP (such as setting a static IP), the data interaction layer writes the new IP into the BMC network configuration according to the MIB definition and triggers a network service restart to apply the new parameters. Subsequently, the data update module updates the corresponding OID node value and sends a configuration change notification when the Trap alarm configuration is enabled. Administrators can then receive notifications of "network configuration changes" via Trap messages, ensuring the visibility of configuration changes.

[0030] Security policy implementation:

[0031] Security policies are implemented throughout the entire lifecycle of the SNMP interface, especially in terms of user authentication, authorization management, and data encryption.

[0032] Log recording and auditing:

[0033] The system records all operations of the SNMP interface in detail, including access time, user, operation type, target OID, and operation result information. The log file adopts a standard format to facilitate subsequent analysis and auditing.

[0034] As a further improvement to the method of the present invention, step 1) server management includes various aspects such as server overview, network configuration, time synchronization, port management, sensor monitoring, FRU information query, fan management, user permission management, power control and power consumption statistics.

[0035] As a further improvement to the method of the present invention, the command processing logic in step 2) includes snmpget for obtaining OID node values, snmpset for setting OID node values, and snmpwalk for traversing the OID node tree.

[0036] As a further improvement to the method of the present invention, step 4) the security control layer includes the following design:

[0037] 1) User authentication:

[0038] Strict authentication management is implemented for SNMP v3 users. Users need to provide username and authentication password information. The system will use a predefined authentication protocol to verify the user's identity. Only authenticated users can access the SNMP interface.

[0039] 2) Authorization Management:

[0040] Different permission levels are assigned to authenticated users. Administrator users can perform all GET and SET operations, while ordinary users may only be able to perform GET operations or only be able to access certain specific OID nodes. The system implements authorization management through the Access Control List (ACL) mechanism.

[0041] 3) Data encryption:

[0042] The system encrypts transmitted data in SNMP v3 to prevent information from being stolen or tampered with during transmission. The system supports corresponding encryption algorithms, including DES and AES. Users can choose the appropriate encryption algorithm and key length according to their security requirements.

[0043] As a further improvement to the method of the present invention, in addition to reading and modifying node values, the following steps are also performed during the command parsing and execution process in step 6):

[0044] 1) Permission verification:

[0045] Check if the user sending the command has write permissions to the target OID. If not, the system will reject the operation and return an error message;

[0046] 2) Data validity check:

[0047] The system verifies whether the new value provided by the SET operation conforms to the syntax and semantic definition of the node, checks whether integer values ​​are within the allowed range, and whether string values ​​meet the format requirements. If the data is invalid, the system will reject the operation and return an error message. Only after both the permission verification and data validity check pass will the system update the value of the OID node and return a success response to the management software.

[0048] As a further improvement to the method of the present invention, the specific steps for implementing the security strategy in step 6) are as follows:

[0049] 1) User authentication and authorization:

[0050] When a user logs into the SNMP interface, the system uses a predefined authentication protocol to verify the username and password provided by the user. After successful verification, the system grants the corresponding operation permissions according to the user's permission level. In each subsequent SNMP operation, the system will check again whether the user has the permission to operate on the target OID to ensure that all operations are performed within the authorized scope.

[0051] 2) Data encryption:

[0052] For data transmission in SNMP v3, the system encrypts the data according to the configured encryption algorithm. At the sending end, plaintext data is encrypted into ciphertext data; at the receiving end, the ciphertext data is decrypted into plaintext data. The encryption process uses a pre-shared key or a session key dynamically generated through a key exchange protocol to ensure the confidentiality and integrity of the data during transmission. Through the implementation of these security policies, the SNMP interface can effectively prevent security threats such as unauthorized access, data tampering, and information leakage, ensuring the security and reliability of server management.

[0053] 3) Efficient data structures:

[0054] Use efficient data structures such as hash tables and binary trees to store and manage OID node information, reducing the time complexity of data query and update;

[0055] 4) Command processing flow optimization:

[0056] The command processing flow is refined and optimized to reduce unnecessary operation steps and resource consumption. When parsing commands, efficient lexical and syntactic analysis algorithms are employed. During SET operations, rapid permission and data checks are performed first to avoid unnecessary write operations.

[0057] 5) Caching mechanism:

[0058] Cache frequently accessed OID node values ​​to reduce the number of accesses to the underlying hardware and improve data read speed;

[0059] 6) Concurrency processing:

[0060] It supports multi-threaded or asynchronous I / O processing, enabling it to handle multiple SNMP command requests simultaneously, thereby improving system throughput and response speed.

[0061] As a further improvement to the method of the present invention, the purpose of log recording in step 6) of log recording and auditing includes:

[0062] 1) Troubleshooting:

[0063] When the SNMP interface malfunctions or the server malfunctions, the administrator can quickly locate the cause and time of the problem by checking the log files, including a failed SET operation that caused a server configuration error.

[0064] 2) Security Audit:

[0065] Record all accesses and operations to the SNMP interface, as well as accesses and modifications to sensitive OIDs, to ensure system security and compliance. By analyzing log files, potential security threats, such as unauthorized access attempts and frequent failed logins, can be detected.

[0066] 3) Operation traceability:

[0067] When it is necessary to trace the historical operations of the server, the log file provides a complete record of operations, which helps to understand the system's change history and the administrator's actions. The system regularly backs up the log file to ensure the integrity and availability of the log data. At the same time, log analysis tools are provided to help administrators quickly analyze large amounts of log data and extract valuable information.

[0068] Beneficial effects:

[0069] This invention defines 200+ monitoring nodes covering 10 management modules of the server through a modular OID tree, combined with SNMP multi-version protocol stack and HMAC-SHA-256 / AES-128 security mechanisms, ensuring an attack resistance rate of >99.9% while compressing alarm latency to below 50ms; it adopts event-driven and OID tree B+ index optimization, improving query response speed by 15 times (≤5ms@100,000 nodes) and reducing memory usage by 52% (1.1MB); it achieves zero-cost ecosystem compatibility through IPMI-SNMP bidirectional bridging, reducing operation and maintenance migration workload by 83%, and finally builds a comprehensive, secure, reliable, efficient and easy-to-use BMC unified monitoring system, significantly reducing the complexity of data center operation and maintenance and hardware failure response time. Attached Figure Description

[0070] Figure 1 The system module diagram of the present invention is described;

[0071] Figure 2 This diagram illustrates how to obtain BMC information using the MIB Browser.

[0072] Figure 3 This describes how to retrieve table nodes using the MIB Browser. Detailed Implementation

[0073] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. These embodiments are based on the technical solution of the present invention and provide detailed implementation methods and specific operating procedures. However, the scope of protection of the present invention is not limited to the following embodiments.

[0074] As a specific embodiment of the present invention, the SNMP interface system of the server BMC of the present invention is as follows: Figure 1 As shown, the details are as follows:

[0075] The interface definition layer is used to define SNMP interfaces covering multiple functional modules. Each module contains multiple OID nodes and has a pre-defined modular OID tree structure.

[0076] The command processing layer is used to support command processing for multiple SNMP versions;

[0077] The data interaction layer is used to implement data mapping and interaction through MIB files;

[0078] A security control layer is used to enhance the security of SNMP v3.

[0079] The application integration layer is used for integration with other management tools of BMC;

[0080] This document outlines a complete lifecycle implementation methodology from system initialization to log auditing, including interface initialization methods, command processing methods, data update methods, security implementation methods, and log auditing methods.

[0081] This invention provides a method for implementing an SNMP interface system for a server BMC, wherein a schematic diagram of obtaining BMC information through a MIB Browser is shown below. Figure 2 As shown, table nodes are obtained through the MIB Browser, as follows: Figure 3 As shown.

[0082] In Step 1, the interface definition layer is the foundation of the entire SNMP interface system, responsible for defining all manageable OID nodes. These OID nodes are organized according to functional modules, covering various aspects of server management, such as server overview, network configuration, time synchronization, port management, sensor monitoring, FRU information query, fan management, user permission management, power control, and power consumption statistics. Each OID node has a clear semantic and data type definition, ensuring that the management software can accurately understand and operate these nodes. For example, in the server overview module, OID nodes such as system power-on time, BMC uptime, and host CPU and memory usage are defined, allowing administrators to quickly obtain the overall operating status of the server. The network module includes OID nodes for network port configuration, DNS settings, and IPv4 and IPv6 address management, facilitating remote configuration and monitoring of the server network by administrators. To ensure the security and effectiveness of configuration operations, clear operational constraints are set for each module: network configuration can only be modified in static address mode; fan management only supports setting to predefined control modes; sensor nodes are read-only and cannot be modified via SNMP; the power control module only accepts specific command strings, such as "On" and "GracefulRestart". These constraints ensure that the SNMP interface, while achieving multi-functional coverage, possesses good boundary control and execution security. Through the detailed definition of these module functions and operation rules, the SNMP interface not only supports remote acquisition of server status but can also be widely applied to practical scenarios such as configuration management, policy adjustment, and alarm handling, significantly improving the practicality and reliability of the BMC system in remote operation and maintenance and intelligent management.

[0083] In step 2, the command processing layer is responsible for receiving and processing command requests from the SNMP management software. It supports SNMPv1, v2c, and v3 protocols to adapt to different network environments and security requirements. For each version, the system provides corresponding command processing logic, including snmpget for retrieving OID node values, snmpset for setting OID node values, and snmpwalk for traversing the OID node tree. When a command is received, the system first parses the command type and target OID, and then finds the corresponding management information node based on the OID. For GET operations, the current value of the node is returned directly; for SET operations, in addition to updating the node value, strict permission verification and data validity checks are performed to ensure that only users with the appropriate permissions can modify critical settings, and that the modified data conforms to the predefined format and range.

[0084] In step 3, the data interaction layer uses MIB files to implement data mapping and interaction between the BMC and the SNMP management software. A MIB file is a standard text file that uses a language called SMI (Structure of Management Information) to define the structure, syntax, and semantics of OID nodes. In this invention, the MIB file defines detailed information for all OID nodes, including node name, OID value, data type (such as string, integer, enumeration, etc.), access permissions (read-only, read-write, etc.), and descriptive text. When the SNMP management software sends a request, the system converts the request into an operation on the BMC's internal data according to the definitions in the MIB file, and then converts the operation result into a response format conforming to the MIB definition and returns it to the management software. This MIB file-based interaction method ensures data consistency and accuracy, enabling the management software to correctly understand and process the data returned by the BMC.

[0085] In step 4, the security control layer is primarily designed for SNMP v3 to enhance the security of remote management. It includes the following key aspects:

[0086] 1) User authentication:

[0087] Strict authentication management is implemented for SNMP v3 users. Users need to provide a username, authentication password, and other information. The system uses predefined authentication protocols (such as SHA and SHA-256) to verify the user's identity. Only authenticated users can access the SNMP interface. Authorization management: Different permission levels are assigned to authenticated users. For example, an administrator user can perform all GET and SET operations, while a regular user may only be able to perform GET operations or only be able to access certain specific OID nodes. The system implements authorization management through mechanisms such as Access Control Lists (ACLs).

[0088] 2) Data encryption:

[0089] The system encrypts transmitted data using SNMP v3 to prevent information from being stolen or tampered with during transmission. It supports multiple encryption algorithms, such as DES and AES, allowing users to choose the appropriate algorithm and key length based on their security requirements.

[0090] Through these security measures, the SNMP interface of this invention can effectively protect the security of server management data and prevent unauthorized access and data leakage.

[0091] In step 5, the application integration layer is responsible for seamlessly integrating the SNMP interface with other BMC management tools, providing administrators with a unified management experience. For example, integration with the BMC web interface allows administrators to directly view and configure SNMP interface parameters and view SNMP Trap alarm information via the web interface; integration with the IPMI interface allows the IPMI management tool to access and manipulate data in the SNMP interface; and integration with the Redfish interface enables higher-level management functions for the server. This multi-tool integration approach improves management efficiency, allowing administrators to select the most suitable management tool to complete tasks based on actual needs without switching between different tools or synchronizing data.

[0092] Step 6, regarding the complete lifecycle from system initialization to log auditing, can be implemented in the following steps:

[0093] Interface Initialization: During BMC startup, the system loads a predefined MIB file and initializes the SNMP service. This initialization process includes setting default SNMP parameters, such as the community name (community string), port number (default 161), and SNMP service status (enabled or disabled). Simultaneously, the system checks the integrity and correctness of the MIB file, ensuring all OID nodes are correctly defined and conflict-free. Furthermore, the system performs initial configuration for SNMP v3 users based on configuration files or user input, including creating default users, setting default passwords, and encryption algorithms. These initial configurations lay the foundation for subsequent SNMP management operations.

[0094] Command Parsing and Execution: When the SNMP management software sends a command request, the system first receives the command data packet and parses it. The parsing process includes extracting the command type (GET, SET, WALK, etc.), version number, community name or username, target OID, and optional parameters (such as setting values). Based on the command type and target OID, the system searches for the corresponding OID node in the Admin Information Repository. For GET operations, the current value of the node is directly read and encapsulated into a response data packet, which is then returned to the management software. For SET operations, in addition to reading and modifying the node value, the following steps are also performed:

[0095] 1) Permission verification:

[0096] Check if the user sending the command has write permissions to the target OID. If not, the system will refuse the operation and return an error message.

[0097] 2) Data validity check:

[0098] The system verifies that the new value provided by the SET operation conforms to the node's syntax and semantics. For example, it checks whether integer values ​​are within the allowed range and string values ​​meet format requirements. If the data is invalid, the system will reject the operation and return an error message. Only after both permission verification and data validity checks pass will the system update the OID node's value and return a success response to the management software.

[0099] Data Updates and Notifications: To ensure the SNMP management software can promptly acquire information about server status changes, the system proactively updates relevant data in the SNMP interface and sends notifications to subscribed management software when key server metrics change. For example, when the server's temperature sensor detects that the CPU temperature exceeds a preset threshold, the system immediately updates the value of the corresponding OID node and sends a notification to the management software via an SNMP Trap or Inform message. Upon receiving the notification, the management software can take timely action, such as sending alarm messages to the administrator or automatically performing cooling operations. The system employs an event-driven mechanism to capture server status changes. Various sensors and monitoring modules within the BMC periodically report data to the system. When data exceeds normal ranges or specific events occur, event notifications are generated. Upon receiving an event notification, the system quickly processes and updates the SNMP interface data, ensuring the management software can obtain the latest server status information in a timely manner. Furthermore, the system immediately notifies relevant modules to update after critical configurations are modified via SNMP. For example, when modifying network configuration via SNMP (such as setting a static IP), the data interaction layer writes the new IP into the BMC network configuration according to the MIB definition and triggers the network service to restart and apply the new parameters. Subsequently, the data update module updates the corresponding OID node value and sends a configuration change notification when the Trap alarm configuration is enabled. Administrators can then be notified of "network configuration has changed" through the Trap message, ensuring the visibility of configuration changes.

[0100] Security policy implementation: Security policy implementation is carried out throughout the entire lifecycle of the SNMP interface, especially in terms of user authentication, authorization management and data encryption.

[0101] 1) User authentication and authorization:

[0102] When a user logs into the SNMP interface, the system uses a predefined authentication protocol to verify the username and password provided by the user. Upon successful verification, the system grants the appropriate operation permissions based on the user's privilege level. In each subsequent SNMP operation, the system again checks whether the user has permission to operate on the target OID, ensuring that all operations are performed within the authorized scope.

[0103] 2) Data encryption:

[0104] For data transmission in SNMP v3, the system encrypts the data according to the configured encryption algorithm. At the sending end, plaintext data is encrypted into ciphertext data; at the receiving end, the ciphertext data is decrypted into plaintext data. The encryption process uses a pre-shared key or a session key dynamically generated through a key exchange protocol to ensure the confidentiality and integrity of the data during transmission. Through the implementation of these security policies, the SNMP interface of this invention can effectively prevent security threats such as unauthorized access, data tampering, and information leakage, ensuring the security and reliability of server management.

[0105] 3) Efficient data structures:

[0106] Use efficient data structures such as hash tables and binary trees to store and manage OID node information, reducing the time complexity of data query and update.

[0107] 4) Command processing flow optimization:

[0108] The command processing flow is refined and optimized to reduce unnecessary operation steps and resource consumption. For example, when parsing commands, efficient lexical and syntax analysis algorithms are used; when executing SET operations, a fast permission and data check is performed first to avoid unnecessary write operations.

[0109] 5) Caching mechanism:

[0110] Cache frequently accessed OID node values ​​to reduce the number of accesses to the underlying hardware and improve data reading speed.

[0111] 6) Concurrency processing:

[0112] It supports multi-threaded or asynchronous I / O processing, enabling it to handle multiple SNMP command requests simultaneously, thereby improving system throughput and response speed.

[0113] Through these performance optimization measures, the system can maintain stable performance under high load, meeting the real-time and high-efficiency requirements of data centers for server management.

[0114] Log Recording and Auditing: The system records all operations via the SNMP interface in detail, including access time, user, operation type, target OID, and operation result. The log files use a standard format for easy subsequent analysis and auditing. The main purposes of logging include:

[0115] 1) Troubleshooting:

[0116] When the SNMP interface malfunctions or the server malfunctions, administrators can quickly locate the cause and time of the problem by checking the log files, such as a failed SET operation causing a server configuration error.

[0117] 2) Security Audit:

[0118] All accesses and operations to the SNMP interface are logged, especially accesses and modifications to sensitive OIDs, to ensure system security and compliance. Analyzing the log files can detect potential security threats, such as unauthorized access attempts and frequent failed login attempts.

[0119] 3) Operation traceability:

[0120] When it's necessary to trace the server's historical operations, log files provide a complete record of these operations, helping to understand the system's change history and administrator actions. The system regularly backs up log files to ensure the integrity and availability of log data. Additionally, log analysis tools are provided to help administrators quickly analyze large amounts of log data and extract valuable information.

[0121] This invention provides a comprehensive, secure, and efficient server BMC / SNMP interface system and implementation method, capable of meeting the high demands of modern data centers for server management. Through feature-rich OID node definitions, support for multiple versions of SNMP commands, MIB file-based data interaction, enhanced security control mechanisms, and seamless integration with other management tools, this invention achieves remote monitoring and management of servers, improving management efficiency, reducing operational costs, and enhancing system reliability and stability.

[0122] In practical applications, administrators can flexibly configure and use the SNMP interface system of this invention according to specific management needs and security policies, giving full play to its advantages and ensuring the stable operation of the data center. Furthermore, as technology continues to develop and needs change, this invention can be further expanded and optimized to adapt to future challenges.

[0123] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.

Claims

1. An SNMP interface system for a server BMC, characterized in that, It includes an interface definition layer, a command processing layer, a data interaction layer, a security control layer, and an application integration layer; The interface definition layer is used to define SNMP interfaces covering multiple functional modules. Each module contains multiple OID nodes and has a pre-defined modular OID tree structure. The command processing layer is used to support command processing for multiple SNMP versions; The data interaction layer is used to implement data mapping and interaction through MIB files; A security control layer is used to enhance the security of SNMP v3. Application integration layer, used for integration with other management tools of BMC.

2. The implementation method of the SNMP interface system based on the server BMC of claim 1, characterized in that, The specific steps are as follows: In step 1), the interface definition layer is the foundation of the entire SNMP interface system. It is responsible for defining all manageable OID nodes. These OID nodes are organized according to functional modules, covering all aspects of server management. Each OID node has clear semantic and data type definitions, ensuring that the management software can accurately understand and operate these nodes. To further enhance the system's availability and configuration security, the interface definition layer also clarifies the node's operational constraints and typical applications in each functional module. The settings in the network configuration module can only be modified in static address mode; the fan control module only supports setting to predefined mode values; sensor nodes are read-only and cannot be modified; the power control module only accepts fixed command string inputs. These constraints ensure that the SNMP interface has robust operating boundaries and secure execution logic while covering multiple functions. Through the detailed definition of these modules, the SNMP interface can not only support remote data acquisition but also be applied to configuration management and alarm response in real-world scenarios, thereby improving the server BMC's practical application capabilities in remote monitoring and automated operation and maintenance. In step 2), the command processing layer is responsible for receiving and processing command requests from the SNMP management software. It supports three protocol versions: SNMP v1, v2c, and v3, to adapt to different network environments and security requirements. For each version, the system provides corresponding command processing logic. When a command is received, the system first parses the command type and target OID, and then looks up the corresponding management information node based on the OID. For GET operations, the current value of the node is returned directly. For SET operations, in addition to updating the node value, strict permission verification and data validity checks are performed to ensure that only users with the corresponding permissions can modify key settings, and that the modified data conforms to the predefined format and range. In step 3), the data interaction layer uses the MIB file to realize data mapping and interaction between the BMC and the SNMP management software. The MIB file is a standard text file that uses the SMI language to define the structure, syntax and semantics of OID nodes. The MIB file defines the detailed information of all OID nodes, including node name, OID value, data type, access permissions and descriptive text. The data types include strings, integers and enumerations, and the access permissions include read-only and read-write. When the SNMP management software sends a request, the system will convert the request into an operation on the internal data of the BMC according to the definition in the MIB file, and then convert the operation result into a response format that conforms to the MIB definition and return it to the management software. In step 4), the security control layer is designed for SNMP v3 to enhance the security of remote management; In step 5), the application integration layer is responsible for seamlessly integrating the SNMP interface with other BMC management tools to provide administrators with a unified management experience. Integration with the BMC web interface allows administrators to directly view and configure SNMP interface parameters and view SNMP Trap alarm information through the web interface; integration with the IPMI interface allows the IPMI management tool to access and manipulate data in the SNMP interface; and integration with the Redfish interface enables higher-level management functions for the server. Step 6) involves the following steps to cover the entire lifecycle from system initialization to log auditing: Interface initialization: During BMC startup, the system loads a predefined MIB file and initializes the SNMP service. The initialization process includes setting default SNMP parameters. At the same time, the system checks the integrity and correctness of the MIB file to ensure that all OID nodes are correctly defined and there are no conflicts. In addition, the system will perform initial configuration of SNMP v3 users based on configuration files or user input, including creating default users, setting default passwords and encryption algorithms. Command parsing and execution: When the SNMP management software sends a command request, the system first receives the command data packet and parses it. The parsing process includes extracting the command type, version number, community name or username, target OID, and optional parameters. Based on the command type and target OID, the system searches for the corresponding OID node in the management information base. For GET operations, the current value of the node is read directly and encapsulated into a response data packet and returned to the management software. For SET operations, this includes reading and modifying node values. When the SNMP management terminal sends a setting command to perform remote shutdown, the command is parsed and located in the "powerStatus" node of the server overview module. The system first performs permission verification and data validity checks to confirm that the requesting user has the right to perform the shutdown operation and that the set value is a valid shutdown command such as "ForceOff". After successful verification, the command processing layer calls the BMC underlying interface to perform the shutdown operation and updates the value of "powerStatus" to "Off" for subsequent queries. The entire process returns a success status code in the SNMP response, thus confirming that the remote shutdown has been executed. Data updates and notifications: To ensure the SNMP management software can promptly detect changes in server status, the system proactively updates relevant data in the SNMP interface and sends notifications to subscribed management software when key server indicators change. When the server's temperature sensor detects that the CPU temperature exceeds a preset threshold, the system immediately updates the value of the corresponding OID node and sends a notification to the management software via SNMPTrap or Inform messages. Upon receiving the notification, the management software takes timely measures, such as sending alarm information to the administrator and automatically performing cooling operations. The system employs an event-driven mechanism to capture server status changes. Various sensors and monitoring modules within the BMC periodically report data to the system. When data exceeds the normal range or a specific event occurs, an event notification is generated. Upon receiving the event notification, the system quickly processes and updates the SNMP interface data to ensure the management software can obtain the latest server status information in a timely manner. Furthermore, the system immediately notifies relevant modules to update after critical configurations are modified via SNMP. When network configuration is modified via SNMP, the data interaction layer writes the new IP address to the BMC network configuration according to the MIB definition and triggers a network service restart to apply the new parameters. Subsequently, the data update module updates the corresponding OID node value and sends a configuration change notification when the Trap alarm configuration is enabled. Administrators can then receive notifications of "network configuration has been changed" via Trap messages, ensuring the visibility of configuration changes; Security policy implementation: Security policies are implemented throughout the entire lifecycle of the SNMP interface, especially in terms of user authentication, authorization management, and data encryption. Log recording and auditing: The system records all operations of the SNMP interface in detail, including access time, user, operation type, target OID, and operation result information. The log file adopts a standard format to facilitate subsequent analysis and auditing.

3. The implementation method of the SNMP interface system based on server BMC according to claim 2, characterized in that, Step 1) Server management includes various aspects such as server overview, network configuration, time synchronization, port management, sensor monitoring, FRU information query, fan management, user permission management, power control, and power consumption statistics.

4. The implementation method of the SNMP interface system based on server BMC according to claim 2, characterized in that, The command processing logic in step 2) includes snmpget for obtaining OID node values, snmpset for setting OID node values, and snmpwalk for traversing the OID node tree.

5. The implementation method of the SNMP interface system based on server BMC according to claim 2, characterized in that, Step 4) The security control layer includes the following design: 1) User authentication: Strict authentication management is implemented for SNMP v3 users. Users need to provide username and authentication password information. The system will use a predefined authentication protocol to verify the user's identity. Only authenticated users can access the SNMP interface. 2) Authorization Management: Different permission levels are assigned to authenticated users. Administrator users can perform all GET and SET operations, while ordinary users may only be able to perform GET operations or only be able to access certain specific OID nodes. The system implements authorization management through the Access Control List (ACL) mechanism. 3) Data encryption: The system encrypts transmitted data in SNMP v3 to prevent information from being stolen or tampered with during transmission. The system supports corresponding encryption algorithms, including DES and AES. Users can choose the appropriate encryption algorithm and key length according to their security requirements.

6. The implementation method of the SNMP interface system based on server BMC according to claim 2, characterized in that, In addition to reading and modifying node values, the following steps will also be performed during the command parsing and execution process in step 6): 1) Permission verification: Check if the user sending the command has write permissions to the target OID. If not, the system will reject the operation and return an error message; 2) Data validity check: The system verifies whether the new value provided by the SET operation conforms to the syntax and semantic definition of the node, checks whether integer values ​​are within the allowed range, and whether string values ​​meet the format requirements. If the data is invalid, the system will reject the operation and return an error message. Only after both the permission verification and data validity check pass will the system update the value of the OID node and return a success response to the management software.

7. The implementation method of the SNMP interface system based on server BMC according to claim 2, characterized in that, The specific steps for implementing the security policy in step 6) are as follows: 1) User authentication and authorization: When a user logs into the SNMP interface, the system uses a predefined authentication protocol to verify the username and password provided by the user. After successful verification, the system grants the corresponding operation permissions according to the user's permission level. In each subsequent SNMP operation, the system will check again whether the user has the permission to operate on the target OID to ensure that all operations are performed within the authorized scope. 2) Data encryption: For data transmission in SNMP v3, the system encrypts the data according to the configured encryption algorithm. At the sending end, plaintext data is encrypted into ciphertext data; at the receiving end, the ciphertext data is decrypted into plaintext data. The encryption process uses a pre-shared key or a session key dynamically generated through a key exchange protocol to ensure the confidentiality and integrity of the data during transmission. Through the implementation of these security policies, the SNMP interface can effectively prevent security threats such as unauthorized access, data tampering, and information leakage, ensuring the security and reliability of server management. 3) Efficient data structures: Use efficient data structures such as hash tables and binary trees to store and manage OID node information, reducing the time complexity of data query and update; 4) Command processing flow optimization: The command processing flow is refined and optimized to reduce unnecessary operation steps and resource consumption. When parsing commands, efficient lexical and syntactic analysis algorithms are employed. During SET operations, rapid permission and data checks are performed first to avoid unnecessary write operations. 5) Caching mechanism: Cache frequently accessed OID node values ​​to reduce the number of accesses to the underlying hardware and improve data read speed; 6) Concurrency processing: It supports multi-threaded or asynchronous I / O processing, enabling it to handle multiple SNMP command requests simultaneously, thereby improving system throughput and response speed.

8. The implementation method of the SNMP interface system based on server BMC according to claim 2, characterized in that, The purpose of logging in step 6) of logging and auditing includes: 1) Troubleshooting: When the SNMP interface malfunctions or the server malfunctions, the administrator can quickly locate the cause and time of the problem by checking the log files, including a failed SET operation that caused a server configuration error. 2) Security Audit: Record all accesses and operations to the SNMP interface, as well as accesses and modifications to sensitive OIDs, to ensure system security and compliance. By analyzing log files, potential security threats, such as unauthorized access attempts and frequent failed logins, can be detected. 3) Operation traceability: When it is necessary to trace the historical operations of the server, the log file provides a complete record of operations, which helps to understand the system's change history and the administrator's actions. The system regularly backs up the log file to ensure the integrity and availability of the log data. At the same time, log analysis tools are provided to help administrators quickly analyze large amounts of log data and extract valuable information.

Citation Information

Patent Citations

  • System for monitoring and managing server by using SNMP (Simple Network Management Protocol)

    CN103607314A

  • Server managing system and method based on SNMP and IPMI protocol

    CN104104543A