User limiting method for centralized authorization control cluster service
By binding hardware fingerprints with unique service IDs and using a TCP long connection mechanism, the problem of authorization failure caused by node replication in distributed systems is solved, achieving high-security, low-cost, and real-time authorization control, and simplifying the operation and maintenance process.
Patent Information
- Application Number
- CN202511078647.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-01
- Publication Date
- 2025-10-31
AI Technical Summary
In distributed systems, node replication can lead to authorization failures. Traditional authorization methods are insecure, inefficient in operation and maintenance, and difficult to prevent the abuse of node cloning.
By binding hardware fingerprints to unique service IDs for life and using a dynamic authentication mechanism with long TCP connections, centralized authorization control is achieved. Hardware fingerprint information is bound and stored with unique service IDs, a unique long TCP connection is established, and dynamic access control and real-time policy execution are implemented.
It eliminates node impersonation, simplifies authorization operations, enables policies to take effect in seconds, reduces operational complexity and hardware costs, and provides highly secure, real-time authorization control.
Smart Images

Figure CN120880745A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of centralized security management and control technology for cluster services, and relates to a method for centralized authorization control of user restrictions in cluster services. Background Technology
[0002] In distributed system architectures, business service clusters are typically deployed on cloud servers. Traditional authorization methods, such as static policy pre-configuration or decentralized authentication based on account passwords, suffer from weaknesses in security, inefficient operation and maintenance, and policy lag. For example, host information (such as IP and MAC addresses) is easily copied, allowing attackers to impersonate legitimate nodes and gain privileges, leading to double-authorization vulnerabilities. Existing technologies improve identity credibility by using digital certificate authentication, but the digital certificates used are also easily exported and copied, failing to prevent node cloning and abuse.
[0003] Furthermore, the authorization process is cumbersome due to the complexity of authorizing multiple servers, requiring remote configuration of authorization policies for each machine. This can easily lead to the duplication of all information from the copied host, resulting in double use and negating the purpose of authorization. Therefore, to avoid the problem of reusing authorization information after copying host information, and to simplify the authorization process, it is necessary to research and improve the authorization control methods. Summary of the Invention
[0004] The purpose of this invention is to provide a user restriction method for centralized authorization control of cluster services. By permanently binding hardware fingerprints with unique service IDs and using a dynamic authentication mechanism with long TCP connections, this method solves the authorization failure problem caused by node replication in distributed systems and simplifies the authorization operation process.
[0005] The technical solution adopted in this invention provides a user restriction method for centralized authorization control cluster services. The key point is that the above user restriction method is applied to the centralized authorization service between business service clusters and cloud hosts, specifically including:
[0006] S1. Identity Registration and Establishment of TCP Long Connections: When a business service node starts up, it initiates an independent TCP long connection request to the authorization service as a client. The business service node submits hardware fingerprint information to the authorization service through the aforementioned independent TCP connection. After verifying the legality of the hardware fingerprint, the authorization service assigns a unique service ID and binds the aforementioned hardware fingerprint information with the unique service ID to the permission policy library. The aforementioned independent TCP long connection corresponds one-to-one with the business service node, and the same hardware fingerprint information is only allowed to be registered once.
[0007] S2, Dynamic Access Control Steps: The business service node forwards the user's identity and resource access request to the authorization service through the TCP long connection established in step S1. The authorization service queries the permission policy library to match permissions. If the match is successful, an authorization instruction is generated and sent to the business service node in real time through the same TCP long connection. If the match fails, the authorization is rejected and the process is terminated.
[0008] S3. Authorization Execution and Resource Access: After receiving the authorization instruction, the business service node performs certificate verification and decryption operations to extract the authorization plaintext information; and performs resource access operations based on the authorization plaintext information.
[0009] Specifically, the hardware fingerprint information in step S1 includes the CPU serial number, motherboard UUID, and network card MAC address.
[0010] More specifically, in step S1, the hardware fingerprint information and the unique service ID are one-to-one and cannot be changed during the service lifecycle; all subsequent communications of the service node must carry the unique service ID, and the authorized service verifies the node's legitimacy through this ID.
[0011] Furthermore, the specific process of establishing a TCP long connection in step S1 is as follows: the business service node needs to submit hardware fingerprint information through the initial transmission; the unique service ID returned by the authorization service serves as the authentication identifier for all subsequent communications, and requests without a valid ID will be rejected.
[0012] Furthermore, the aforementioned user restriction method also includes a management platform linked to the authorization service. The management platform is connected to the authorization service through an independent link. The management platform is used to configure the hardware fingerprint binding rules of the permission policy library, terminal capacity and service period policies, and monitor the status of all TCP long connections and illegal registration alarms.
[0013] Compared with the prior art, the present invention has the following advantages:
[0014] This invention is based on the lifelong binding of hardware fingerprints and unique service IDs, and completely eliminates node impersonation through a dynamic ID authentication mechanism using TCP long connections. This invention relies on a separate architecture of centralized authorization service unified decision-making and management platform for independent control, so as to achieve policy effect in seconds and real-time circuit breaking of illegal connections. While ensuring security, it significantly reduces the complexity of operation and maintenance and hardware investment costs, and provides a copy-proof, high real-time and low-cost authorization control paradigm for distributed systems.
[0015] The digital certificate used in this invention differs from traditional digital certificates. The digital certificate of this invention is permanently bound to the hardware fingerprint and is non-exportable, thereby solving the problem of authorization invalidation caused by the easy copying of traditional digital certificates. Attached Figure Description
[0016] Figure 1 This is a centralized authorization framework diagram of the present invention. Detailed Implementation
[0017] Various exemplary embodiments of the present invention will now be described in detail. This detailed description should not be considered as a limitation of the present invention, but rather as a more detailed description of certain aspects, features, and embodiments of the present invention.
[0018] Various modifications and variations can be made to the specific embodiments described in this specification without departing from the scope or spirit of the invention, as will be apparent to those skilled in the art. Other embodiments derived from this specification will also be readily apparent to those skilled in the art. This specification and embodiments are merely exemplary.
[0019] The terms “include,” “including,” “have,” “contain,” etc., used in this article are all open-ended terms, meaning that they include but are not limited to.
[0020] Example
[0021] This embodiment discloses a user restriction method for centralized authorization control cluster services, applied to centralized authorization services between business service clusters and cloud hosts, specifically including:
[0022] S1. Identity registration and establishment of TCP long connections:
[0023] When the business service node starts, it initiates an independent TCP long connection request to the authorization service as a client;
[0024] The business service node submits hardware fingerprint information to the authorization service through this independent TCP connection. The hardware fingerprint information includes information such as CPU serial number, motherboard UUID and network card MAC address. After verifying the legality of the hardware fingerprint, the authorization service assigns a unique service ID and binds the hardware fingerprint information with the unique service ID to the permission policy library.
[0025] Each independent TCP long connection corresponds one-to-one with a business service node, and the same hardware fingerprint information can only be registered once;
[0026] The hardware fingerprint information and the unique service ID are one-to-one and cannot be changed during the service lifecycle; all subsequent communications of the service node must carry the unique service ID, and the authorized service uses this ID to verify the node's legitimacy.
[0027] The specific process for establishing a TCP long connection is as follows: the business service node needs to submit hardware fingerprint information through the initial transmission; the unique service ID returned by the authorization service serves as the authentication identifier for all subsequent communications, and requests without a valid ID will be rejected.
[0028] S2. Dynamic access control steps:
[0029] The business service node forwards the user's identity and resource access request to the authorization service through the TCP long connection established in step S1. The authorization service queries the permission policy library to match permissions. If the match is successful, it generates an authorization instruction and sends it to the business service node in real time through the same TCP long connection. If the match fails, it rejects the authorization and terminates the process.
[0030] S3. Authorization Execution and Resource Access: After receiving the authorization instruction, the business service node performs certificate verification and decryption operations to extract the authorization plaintext information; and performs resource access operations based on the authorization plaintext information.
[0031] This embodiment includes a management platform that is linked to the authorization service. The management platform is connected to the authorization service through an independent link. The management platform is used to configure the hardware fingerprint binding rules of the permission policy library, the terminal capacity and service period policies, and to monitor the status of all TCP long connections and illegal registration alarms.
[0032] Application Examples
[0033] This embodiment will provide an application scenario, such as a factory independently deploying a single intercom system on a host computer. Using existing technologies, factory technicians may copy host computer information to deploy multiple intercom systems; they may also copy capacity limits and modify expiration dates within the same system, leading to uncontrolled use of the intercom system.
[0034] The user restriction method for the centralized authorization control cluster service of the present invention specifically includes:
[0035] S1. Identity registration and establishment of TCP long connections:
[0036] The business service node establishes a TCP connection with the authorization service as a client. Because the TCP connection is the only channel in communication, if other business service nodes want to communicate with the authorization service, they need to re-establish the TCP connection and cannot use the existing TCP connection for communication.
[0037] The business service node submits hardware fingerprint information to the authorization service through this independent TCP connection. The hardware fingerprint information includes the CPU serial number, motherboard UUID, and network card MAC address.
[0038] After the authorization service verifies the legality of the hardware fingerprint, it assigns a unique service ID and binds the hardware fingerprint information with the unique service ID to the permission policy library. If the same fingerprint is detected to be registered repeatedly, such as when a technician tries to clone the host, the management platform will immediately trigger an alarm and refuse the connection.
[0039] After a TCP connection is established, the business server will inform the authorization server of its identity information. This identity is unique, and if any other business service uses this identity information to register, it will be considered illegal.
[0040] In this embodiment, the authorized service generates a unique service ID that is bound for life, such as FACTORY_AS01, which is stored together with the hardware fingerprint in the permission policy library. All subsequent communications must carry this ID. If the cloned host cannot communicate because it does not have a valid ID, the request will be directly rejected.
[0041] S2. Dynamic access control steps:
[0042] After establishing a TCP connection and registering their identities, the business service can maintain legitimate data communication with the authorization service. The authorization service can send authorization information to the business service in real time according to the needs of the business service, thereby achieving dynamic access control.
[0043] In this embodiment, when a worker with employee number W0231 calls the quality inspection channel through a terminal, the business service node forwards the user's identity (i.e., employee number W0231) and resource request (i.e., access to the quality inspection channel) to the authorized service in real time through the original TCP long connection.
[0044] The authorization service queries the policy library and dynamically matches the following rules:
[0045] User role: W0231 belongs to "Assembly Line Worker" and is only allowed to call workers in the same group and the quality inspection channel;
[0046] Resource status: The current capacity of the quality inspection channel is not exceeded;
[0047] If a match is successful, an encrypted authorization command is generated and returned via the same long connection.
[0048] S3, Authorized Execution and Resource Access:
[0049] After receiving the authorization information from the authorization service, the business service performs certificate verification and decrypts the information to obtain the plaintext authorization information, such as terminal capacity and authorization expiration information. The business service can then determine whether to allow new terminals to log in and whether to remove existing terminals from the business service functions based on the existing terminal capacity and service period.
[0050] In this embodiment, after receiving the instruction, the service node extracts the plaintext policy (e.g., terminal capacity = 200, validity period = 2026-08-01) through certificate verification and decryption.
[0051] Implement resource access control:
[0052] Over-limit blocking: When the 201st terminal attempts to connect, the earliest idle terminal (such as a terminal that has not made a call for 5 consecutive minutes) will be automatically kicked out;
[0053] Expiration circuit breaker: An alarm is sent 7 days before the service expires, and all terminals are forced offline after the expiration date.
[0054] The embodiments described above are merely preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Various modifications and improvements made by those skilled in the art to the technical solutions of the present invention without departing from the spirit of the present invention should fall within the protection scope defined by the claims of the present invention.
Claims
1. A method for restricting users in a centralized authorization control cluster service, characterized in that, The user restriction method is applied to the centralized authorization service of business service clusters and cloud hosts, specifically including: S1. Identity Registration and Establishment of TCP Long Connection: When a business service node starts up, it initiates an independent TCP long connection request to the authorization service as a client; the business service node submits hardware fingerprint information to the authorization service through the independent TCP connection; after verifying the legality of the hardware fingerprint, the authorization service assigns a unique service ID and binds the hardware fingerprint information with the unique service ID to the permission policy library; the independent TCP long connection corresponds one-to-one with the business service node, and the same hardware fingerprint information is only allowed to be registered once; S2, Dynamic Access Control Steps: The business service node forwards the user's identity and resource access request to the authorization service through the TCP long connection established in step S1. The authorization service queries the permission policy library to match permissions. If the match is successful, an authorization instruction is generated and sent to the business service node in real time through the same TCP long connection. If the match fails, the authorization is rejected and the process is terminated. S3. Authorization Execution and Resource Access: After receiving the authorization instruction, the business service node performs certificate verification and decryption operations to extract the authorization plaintext information; and performs resource access operations based on the authorization plaintext information.
2. The user restriction method for centralized authorization control cluster services according to claim 1, characterized in that, The hardware fingerprint information in step S1 includes the CPU serial number, motherboard UUID, and network card MAC address.
3. The user restriction method for centralized authorization control cluster services according to claim 1, characterized in that, In step S1, the hardware fingerprint information and the unique service ID are one-to-one and cannot be changed during the service lifecycle. All subsequent communications of the service node must carry the unique service ID, and the authorized service verifies the node's legitimacy through this ID.
4. The user restriction method for centralized authorization control cluster services according to claim 1, characterized in that, The specific process for establishing a TCP long connection in step S1 is as follows: the business service node needs to submit hardware fingerprint information through the initial transmission; the unique service ID returned by the authorization service serves as the authentication identifier for all subsequent communications, and requests without a valid ID will be rejected.
5. The user restriction method for centralized authorization control cluster services according to claim 1, characterized in that, The user restriction method also includes a management platform that is linked to the authorization service. The management platform is connected to the authorization service through an independent link. The management platform is used to configure the hardware fingerprint binding rules of the permission policy library, the terminal capacity and service period policies, and to monitor the status of all TCP long connections and illegal registration alarms.