Power grid dispatching cloud platform access authentication method, device and equipment based on bastion host, storage medium and program product
By combining a bastion host with an OTP server and employing a dual authentication mechanism of password and authentication token, the problem of insufficient authentication factors in accessing the power grid dispatch cloud platform is solved, thereby improving security and the efficiency of operational information management.
Patent Information
- Application Number
- CN202511176322.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-21
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-08-21
AI Technical Summary
The lack of authentication factors and unknown login security in existing technologies for accessing the power grid dispatch cloud platform via bastion hosts pose significant security risks to remote access.
A dual authentication mechanism based on passwords and detection tokens generated by an OTP server is adopted. The bastion host verifies the username, password, and detection token and records the operation information to ensure the legality and compliance of the access.
It improves the authenticity of entity authentication and the security of network communication, reduces the security risks of remote access to the power grid dispatch cloud platform, and enables efficient storage and utilization of operational information.
Smart Images

Figure CN121037044A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, in particular to a power grid dispatching cloud platform access authentication method and device based on a bastion host, a computer device, a computer readable storage medium and a computer program product. BACKGROUND
[0002] With the expansion of the power grid scale and the digital transformation trend of power enterprises, the demand for the power grid dispatching cloud platform to be accessed anytime and anywhere continues to increase. Through a bastion host and the like, an information channel can be established between a personal client and the power grid dispatching cloud platform on a public network, so that cloud platform operation and management personnel can conveniently access the power grid dispatching cloud platform through this way.
[0003] However, the current method of accessing important data platforms such as the power grid dispatching cloud platform through a bastion host has defects such as insufficient authentication factors and unknown login end security, resulting in a high security risk in the current technology when remotely accessing the power grid dispatching cloud platform. SUMMARY
[0004] Therefore, it is necessary to provide a power grid dispatching cloud platform access authentication method and device based on a bastion host, a computer device, a computer readable storage medium and a computer program product in view of the above technical problems.
[0005] In a first aspect, the present application provides a power grid dispatching cloud platform access authentication method based on a bastion host, comprising:
[0006] In response to an access request of a current user to the power grid dispatching cloud platform, the access request is sent to a configured OTP server, so that the OTP server generates a password password and a detection token according to the access request and a hash algorithm, and returns the password password and the detection token to an operation and maintenance terminal;
[0007] The username of the current user, the password password and the detection token are packaged and sent to a bastion host, the bastion host verifies the detection token according to the username, and in the case that the detection token verification is passed, the bastion host sends the password password to the OTP server, and the OTP server verifies the password password;
[0008] In the case that the password password verification is passed, the bastion host is logged in, and the power grid dispatching cloud platform is accessed through the bastion host;
[0009] In the case that the access request is passed, the operation information of this time of power grid dispatching cloud platform access is recorded, the target information entry in the information library is matched according to the username, and the operation information is input to the target information entry.
[0010] In one of the embodiments, the method further comprises, before the responding to the access request of the current user to the power grid dispatching cloud platform:
[0011] obtaining user information of the user, and sending the user information to the to-be-configured server, so that the to-be-configured server binds the user information and the imported seed key to obtain the configured OTP server.
[0012] In one of the embodiments, the OTP server generates a password and a detection token according to the access request and a hash algorithm, comprising:
[0013] The OTP server generates a time factor according to a receiving time of the access request, identifies user information of the current user according to the access request, and matches a target seed key corresponding to the user information of the current user; and calculates the password and the detection token through an SM3 algorithm according to the time factor and the target seed key.
[0014] In one of the embodiments, the power grid dispatching cloud platform comprises a cloud platform deployment server, a cloud platform database, and a cloud platform log server, and the accessing to the to-be-accessed platform in the power grid dispatching cloud platform through the bastion host comprises:
[0015] In response to a platform selection instruction of the current user, determining the to-be-accessed platform in the platform deployment server, the cloud platform database, and the cloud platform log server; and single-sign-on to the to-be-accessed platform through an SSH protocol on the bastion host to access the to-be-accessed platform.
[0016] In one of the embodiments, the method further comprises:
[0017] In a case where the password or the OTP detection token fails to be verified, rejecting the access request and updating a cumulative number of verification failures of an account of the current user within a preset time window; and in a case where the cumulative number of verification failures exceeds a number threshold, canceling an account login permission of the account within the preset time window.
[0018] In one of the embodiments, the method further comprises, before the packing and sending the username of the current user, the password, and the detection token to the bastion host:
[0019] obtaining a username of the current user, and receiving the password and the detection token returned by the OTP server.
[0020] In a second aspect, the application further provides a power grid dispatching cloud platform access authentication device based on a bastion host, comprising:
[0021] The request receiving module is configured to, in response to an access request of a current user for the power grid dispatching cloud platform, send the access request to a configured OTP server, so that the OTP server generates a password and a detection token according to the access request and a hash algorithm, and returns the password and the detection token to an operation and maintenance terminal;
[0022] The information verifying module is configured to package and send a username of the current user, the password, and the detection token to a bastion host, verify the detection token by the bastion host according to the username, send the password to the OTP server by the bastion host in the case that the detection token is verified, and verify the password by the OTP server.
[0023] The login access module is configured to log in the bastion host in the case that the password is verified, and access a to-be-accessed platform in the power grid dispatching cloud platform through the bastion host.
[0024] The operation recording module is configured to, in the case that the access request is passed, record operation information of this time of access to the power grid dispatching cloud platform, match a target information entry in an information library according to the username, and input the operation information to the target information entry.
[0025] In a third aspect, the present application further provides a computer device, comprising a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0026] In response to an access request of a current user for the power grid dispatching cloud platform, the access request is sent to a configured OTP server, so that the OTP server generates a password and a detection token according to the access request and a hash algorithm, and returns the password and the detection token to an operation and maintenance terminal; the username of the current user, the password, and the detection token are packaged and sent to a bastion host, the detection token is verified by the bastion host according to the username, the password is sent to the OTP server by the bastion host in the case that the detection token is verified, and the password is verified by the OTP server; in the case that the password is verified, the bastion host is logged in, and a to-be-accessed platform in the power grid dispatching cloud platform is accessed through the bastion host; in the case that the access request is passed, operation information of this time of access to the power grid dispatching cloud platform is recorded, a target information entry in an information library is matched according to the username, and the operation information is input to the target information entry.
[0027] In a fourth aspect, the present application also provides a computer readable storage medium, having stored thereon a computer program, which, when executed by a processor, implements the following steps:
[0028] In response to an access request of a current user to the power grid dispatching cloud platform, the access request is sent to a configured OTP server for the OTP server to generate a password and a detection token according to the access request and a hash algorithm, and return the password and the detection token to an operation and maintenance terminal; the username of the current user, the password and the detection token are packaged and sent to a bastion host, the detection token is verified by the bastion host according to the username, in the case that the detection token is verified, the password is sent to the OTP server by the bastion host, and the password is verified by the OTP server; in the case that the password is verified, the bastion host is logged in, and the to-be-accessed platform in the power grid dispatching cloud platform is accessed through the bastion host; in the case that the access request is passed, operation information of this time of access to the power grid dispatching cloud platform is recorded, a target information entry in an information library is matched according to the username, and the operation information is input to the target information entry.
[0029] In a fifth aspect, the present application also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the following steps:
[0030] In response to an access request of a current user to the power grid dispatching cloud platform, the access request is sent to a configured OTP server for the OTP server to generate a password and a detection token according to the access request and a hash algorithm, and return the password and the detection token to an operation and maintenance terminal; the username of the current user, the password and the detection token are packaged and sent to a bastion host, the detection token is verified by the bastion host according to the username, in the case that the detection token is verified, the password is sent to the OTP server by the bastion host, and the password is verified by the OTP server; in the case that the password is verified, the bastion host is logged in, and the to-be-accessed platform in the power grid dispatching cloud platform is accessed through the bastion host; in the case that the access request is passed, operation information of this time of access to the power grid dispatching cloud platform is recorded, a target information entry in an information library is matched according to the username, and the operation information is input to the target information entry.
[0031] The power grid dispatching cloud platform access authentication method, device, computer equipment, computer readable storage medium and computer program product based on a bastion host, by receiving the password order generated by the OTP server and detecting the token, the username, password order and detection token of the current user are packaged and sent to the bastion host, the detection token is verified according to the username by the bastion host, and the password order is sent to the OTP server in the case that the detection token verification is passed. The password order is verified by the OTP server; in the case that the password order is verified, the bastion host is logged in, and the power grid dispatching cloud platform is accessed through the bastion host; at the same time, the operation information of the power grid dispatching cloud platform access is recorded, and the operation information is recorded into the corresponding target information entry in the information base. The authentication mechanism of the password order + detection token can accurately verify whether the user's access behavior is legal and compliant, and can make up for the defects of insufficient authentication factors and unknown login end security in the traditional technology; after the user logs in the bastion host through the double verification, the user is connected to the power grid dispatching cloud platform through the bastion host again. Through this way, all operations will be strictly controlled and audited by the bastion host, thereby improving the authenticity of entity identity verification and the security of network communication, and reducing the security risk existing in remote access to the power grid dispatching cloud platform. In addition, the application can record the operation information of the power grid dispatching cloud platform access in the case that the access request is passed, match the target information entry in the information base according to the username, and record the operation information into the target information entry, so as to divide the username of each user as a division identifier, and record the operation information table of the user each time in the information base in a regular and orderly manner. It is beneficial to efficient storage and subsequent use of operation information. BRIEF DESCRIPTION OF DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the present application or the related art. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other related drawings according to these drawings without any creative effort.
[0033] Figure 1 An application environment diagram of the power grid dispatching cloud platform access authentication method based on a bastion host in an embodiment;
[0034] Figure 2 A flowchart of the power grid dispatching cloud platform access authentication method based on a bastion host in an embodiment;
[0035] Figure 3 A flowchart of the power grid dispatching cloud platform access authentication method based on a bastion host in an embodiment;
[0036] Figure 4A structural block diagram of a power grid dispatch cloud platform access authentication device in an embodiment is shown in the figure;
[0037] Figure 5 An internal structure diagram of a computer device in an embodiment is shown in the figure. DETAILED DESCRIPTION
[0038] For the purpose, technical solutions and advantages of the present application to be clearer, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application.
[0039] The power grid dispatch cloud platform access authentication method based on the bastion host provided by the embodiments of the present application can be applied in an application environment as shown in the figure. Figure 1 The operation and maintenance terminal can communicate with the bastion host through the network, the bastion host is in communication connection with the power grid dispatch platform, and the OTP server is in communication connection with the bastion host and the operation and maintenance terminal.
[0040] Specifically, the power grid dispatch cloud platform access authentication method based on the bastion host provided by the embodiments of the present application can be executed by the operation and maintenance terminal.
[0041] Illustratively, the operation and maintenance terminal sends an access request to the configured OTP server in response to the access request of the current user to the power grid dispatch cloud platform, so that the OTP server generates a password password and a detection token according to the access request and a hash algorithm, and returns the password password and the detection token to the operation and maintenance terminal; the operation and maintenance terminal packs and sends the username, the password password and the detection token of the current user to the bastion host, and the bastion host verifies the detection token according to the username, and in the case that the detection token verification is passed, the bastion host sends the password password to the OTP server, and the OTP server verifies the password password; the operation and maintenance terminal logs in the bastion host in the case that the password password verification is passed, and accesses the to-be-accessed platform in the power grid dispatch cloud platform through the bastion host; the operation and maintenance terminal records the operation information of the power grid dispatch cloud platform access this time, matches the target information entry in the information library according to the username, and inputs the operation information to the target information entry.
[0042] In the application environment as shown in the figure, Figure 1 The operation and maintenance terminal can be, but is not limited to, various personal computers, notebook computers, smart phones and tablet computers. The OTP server can be implemented by an independent OTP server or an OTP server cluster composed of multiple OTP servers. The bastion host is a special server used to enhance network security, and is usually used to protect internal networks and management permissions. The power grid dispatch cloud platform is composed of a cloud platform deployment server, a cloud platform database and a cloud platform log server.
[0043] In one embodiment, as shown in Figure 2 A bastion-based power grid dispatch cloud platform access authentication method is provided, which can be applied to Figure 1 operation and maintenance terminal, the method can include the following steps:
[0044] Step S201, in response to the access request of the current user to the power grid dispatch cloud platform, the access request is sent to the configured OTP server for the OTP server to generate the password password and the detection token according to the access request and the hash algorithm, and the password password and the detection token are returned to the operation and maintenance terminal.
[0045] Wherein, the detection token is a security measure for identity verification, which can be an OTP detection token, and is usually used to ensure the security of online transactions, logins or access to sensitive information. The OTP detection token generates one-time passwords, which are valid for a short time and change every time you log in, thereby improving the security of the system.
[0046] Wherein, the password password is a kind of identity verification method for protecting the security of user account.
[0047] Specifically, in response to the access request of the current user to the power grid dispatch cloud platform, the operation and maintenance terminal sends the access request to the configured OTP server for the OTP server to generate the password password and the detection token according to the access request and the hash algorithm, and the password password and the detection token are returned to the operation and maintenance terminal.
[0048] Step S202, the username, password password and detection token of the current user are packaged and sent to the bastion, and the bastion verifies the detection token according to the username, and in the case that the detection token verification is passed, the bastion sends the password password to the OTP server, and the OTP server verifies the password password.
[0049] Wherein, the username can refer to the unique name used to identify the user in the system or platform, which is usually used together with the password for user identity verification.
[0050] Wherein, the bastion is an important component in the network, mainly used for safely managing access to other computers or servers in the network, and its role is similar to a "jumping board", through which you can safely access servers located in the firewall or intranet, avoiding direct exposure of sensitive systems.
[0051] Specifically, the operation and maintenance terminal sends the username, password password and detection token of the current user to the bastion, and the bastion verifies the detection token according to the username, and in the case that the detection token verification is passed, the bastion sends the password password to the OTP server, and the OTP server verifies the password password.
[0052] Step S203, in the case of password verification, log in the bastion host, and access the platform to be accessed in the power grid dispatching cloud platform through the bastion host.
[0053] Specifically, the operation and maintenance terminal logs in the bastion host through the HTTPS protocol (HyperText Transfer Protocol Secure) in the case of identifying that the password verification is passed, and accesses the platform to be accessed in the power grid dispatching cloud platform through the bastion host.
[0054] The HTTPS protocol is a secure protocol based on HTTP (HyperText Transfer Protocol), which is used to securely transmit data on the Internet. It combines the SSL / TLS (Secure Sockets Layer / Transport Layer Security) encryption protocol to ensure the confidentiality and integrity of data transmission between the client and the server.
[0055] Step S204, in the case of access request, record the operation information of this time of power grid dispatching cloud platform access, match the target information entry in the information library according to the username, and record the operation information to the target information entry.
[0056] The operation information can be related information generated by the user when performing various operations on the power grid dispatching cloud platform, such as information query, username change, etc.
[0057] The information entry generally refers to a short information unit arranged according to certain rules in a book, literature, database or encyclopedia, etc. It is similar to a title or a section.
[0058] Specifically, the operation and maintenance terminal records the operation information of this time of power grid dispatching cloud platform access in the case of access request, matches the target information entry in the information library according to the username, and records the operation information to the target information entry, so as to record the operation information of each user each time in the information library in a regular and orderly manner, which is beneficial to the efficient storage and utilization of operation information.
[0059] In the embodiment, the username, the password and the detection token of the current user are packaged and sent to the bastion host by receiving the password generated by the OTP server and detecting the token, the detection token is verified according to the username by the bastion host, the password is sent to the OTP server in the case that the detection token is verified, the password is verified by the OTP server, the bastion host is logged in in the case that the password is verified, the power grid dispatching cloud platform is accessed through the bastion host, the operation information of the current access to the power grid dispatching cloud platform is recorded, and the operation information is recorded into the corresponding target information entry in the information base. The application can accurately verify whether the access behavior of the user is legal and compliant through the authentication mechanism of the password + detection token, which makes up for the defects of insufficient authentication factors and unknown login end security in the traditional technology; the user logs in the bastion host through the double verification, and then connects to the power grid dispatching cloud platform through the bastion host, so that all operations are strictly controlled and audited through the bastion host, thereby improving the authenticity of entity identity verification and the security of network communication, and reducing the security risk of remote access to the power grid dispatching cloud platform. In addition, the application can record the operation information of the current access to the power grid dispatching cloud platform in the case that the access request is passed, match the target information entry in the information base according to the username, and record the operation information into the target information entry, so as to record the operation information of each user in the information base in a regular and orderly manner, which is beneficial to efficient storage and utilization of operation information.
[0060] In one of the embodiments, before responding to the access request of the current user to the power grid dispatching cloud platform, the method of the application further includes the following steps:
[0061] The user information of the user is obtained, and the user information is sent to the to-be-configured server, so that the to-be-configured server binds the user information and the imported seed key to obtain the configured OTP server.
[0062] The user can be an operation and maintenance personnel and an operation personnel of a power enterprise.
[0063] The user information usually includes a series of data for identifying and describing the user, for example, basic personal information (name, age, etc.), account information (username, account status and level permission, etc.), and identity verification information (ID number, face information and fingerprint information, etc.).
[0064] The seed key usually refers to an initial value used in the fields of encryption, algorithm generation, random number generation, etc., and its main function is to provide initial input for the output of random number or encryption algorithm. The seed key can be originally filled in when the OTP detection token hardware is produced.
[0065] Specifically, the operation and maintenance terminal obtains user information of the user, and sends the user information to the to-be-configured server, so that the to-be-configured server binds the user information and the imported seed key to obtain a configured OTP server, thereby completing the initialization user configuration.
[0066] In one of the embodiments, the OTP server in step S201 generates the password and the detection token according to the access request and the hash algorithm, which can include the following steps:
[0067] The OTP server generates a time factor according to the receiving time of the access request, identifies user information of the current user according to the access request, and matches a target seed key corresponding to the user information of the current user; and calculates the password and the detection token through the SM3 algorithm according to the time factor and the target seed key.
[0068] The SM3 algorithm is a hash algorithm, which belongs to a part of the national secret algorithm, and is mainly used in the fields of data integrity protection, digital signature, message authentication, etc. The SM3 algorithm and the international standard hash algorithm (such as SHA-256) have similar functions, and are both encryption hash functions used to generate hash values of fixed length.
[0069] Specifically, the OTP server generates a time factor according to the receiving time of the cloud platform access request, identifies user information of the current user according to the cloud platform access request, and matches a target seed key corresponding to the user information of the current user; and calculates the password and the OTP detection token through the SM3 algorithm according to the time factor and the target seed key.
[0070] In one of the embodiments, the power grid dispatching cloud platform includes a cloud platform deployment server, a cloud platform database, and a cloud platform log server, and the access to the power grid dispatching cloud platform through the bastion host in step S203 can include the following steps:
[0071] In response to a platform selection instruction of the current user, a to-be-accessed platform is determined in the cloud platform deployment server, the cloud platform database, and the cloud platform log server; and the to-be-accessed platform is accessed by single sign-on to the to-be-accessed platform through the SSH (Secure Shell, Secure Shell) protocol on the bastion host.
[0072] The SSH protocol is a network communication protocol, which aims to securely access remote computers through insecure networks, and provides an encrypted communication channel for managing remote systems, file transfer, and executing commands, etc.
[0073] Among them, the cloud platform deployment server can quickly create and deploy servers through the virtual machine instance provided by the cloud service provider, support automation and elastic scaling. The cloud platform database can choose to host a relational or non-relational database service, simplify the management, expansion and backup of the database. The cloud platform log server can use the log management tool provided by the cloud platform to collect, store, analyze and visualize log data, and improve the ability of system monitoring and troubleshooting.
[0074] Specifically, the operation and maintenance terminal determines the to-be-accessed platform in the platform deployment server, the cloud platform database, and the cloud platform log server in response to the platform selection instruction of the current user; and logs in to the to-be-accessed platform through the SSH protocol single point on the bastion host to access the to-be-accessed platform.
[0075] In one of the embodiments, the method of the present application further comprises the following steps:
[0076] In the case of password or OTP detection token verification failure, the access request is rejected and the cumulative number of verification failures of the current user's account within the preset time window is updated; in the case that the cumulative number of verification failures exceeds the number threshold, the account login permission of the account within the preset time window is cancelled.
[0077] Among them, the account login permission refers to the operation and access permission that the user has when using the account. These permissions are usually set and assigned by the account manager or system administrator to ensure that the user can only perform the operations required, and to protect the security of the account and the system.
[0078] Specifically, in the case of password or OTP detection token verification failure, the operation and maintenance terminal rejects the access request and updates the cumulative number of verification failures of the current user's account within the preset time window; in the case that the cumulative number of verification failures exceeds the number threshold, the account login permission of the account within the preset time window is cancelled, so that the user's abnormal login situation can be effectively identified, and the security of user identity verification is improved.
[0079] In one of the embodiments, before the username, password and detection token of the current user are packaged and sent to the bastion host, the method of the present application further comprises the following steps:
[0080] Obtain the username of the current user, and receive the password and detection token returned by the OTP server.
[0081] Specifically, the operation and maintenance terminal obtains the username input by the current user through a preset username input window, and receives the password and detection token returned by the OTP server.
[0082] In one embodiment, as Figure 3As shown, a specific embodiment of a power grid scheduling cloud platform access authentication method based on a bastion host is provided, and specifically includes the following steps:
[0083] In step S301, user information of a user is obtained, and the user information is sent to a to-be-configured server, so that the to-be-configured server binds the user information and a seed key after import to obtain a configured OTP server.
[0084] In step S302, in response to an access request of a current user to the power grid scheduling cloud platform, the access request is sent to the configured OTP server, so that the OTP server generates a time factor according to a receiving time of the access request, identifies user information of the current user according to the access request, and matches a target seed key according to the user information of the current user; and a password and an OTP detection token are calculated by an SM3 algorithm according to the time factor and the target seed key.
[0085] In step S303, a username of the current user is obtained, and the password and the OTP detection token returned by the OTP server are received, and the username, the password and the OTP detection token are packaged and sent to the bastion host, the bastion host verifies the detection token according to the username, and in a case where the detection token is verified, the bastion host sends the password to the OTP server, and the OTP server verifies the password.
[0086] In step S304, the bastion host is logged in in a case where the password is verified, and in response to a platform selection instruction of the current user, a to-be-accessed platform is determined in a platform deployment server, a cloud platform database and a cloud platform log server; and the to-be-accessed platform is accessed by single sign-on to the to-be-accessed platform through an SSH protocol on the bastion host.
[0087] In step S305, in a case where the access request is passed, operation information of this time of access to the power grid scheduling cloud platform is recorded; and target information entries in an information library are matched according to the username, and the operation information is input to the target information entries.
[0088] The beneficial effects brought by the above embodiment are as follows:
[0089] 1) By using the national secret algorithm and the authentication mechanism of the password and the detection token, the user is double-verified, which can accurately verify whether the access behavior of the user is legal and compliant, and makes up for the defects of insufficient authentication factors and unknown login end security in traditional technologies.
[0090] 2) Users first access the bastion host through security authentication, and then connect to the power grid dispatch cloud platform through the bastion host. In this way, all operations are strictly controlled and audited by the bastion host, thereby improving the authenticity of entity authentication and the security of network communication, and reducing the security risks when remotely accessing the power grid dispatch cloud platform.
[0091] 3) Each user's username is used as a identifier, and the user's operation information is entered into the corresponding information entry in the information database in an orderly manner, which is conducive to the efficient storage and subsequent use of operation information.
[0092] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0093] Based on the same inventive concept, this application also provides a bastion host-based power grid dispatching cloud platform access authentication device for implementing the aforementioned bastion host-based power grid dispatching cloud platform access authentication method. The solution provided by this device is similar to the implementation described in the above method. Therefore, the specific limitations in one or more bastion host-based power grid dispatching cloud platform access authentication device embodiments provided below can be found in the limitations of the bastion host-based power grid dispatching cloud platform access authentication method described above, and will not be repeated here.
[0094] In one exemplary embodiment, such as Figure 4 As shown, a bastion host-based access authentication device for a power grid dispatch cloud platform is provided. This device may include:
[0095] The request receiving module 401 is used to respond to the current user's access request to the power grid dispatch cloud platform, send the access request to the configured OTP server, so that the OTP server can generate a password and a detection token according to the access request and hash algorithm, and return the password and detection token to the operation and maintenance terminal.
[0096] The information verification module 402 is configured to package and send the username, password and detection token of the current user to the bastion host, verify the detection token according to the username by the bastion host, and send the password to the OTP server by the bastion host in the case of passing the detection token verification, and verify the password by the OTP server.
[0097] The login access module 403 is configured to log in the bastion host in the case of passing the password verification, and access the to-be-accessed platform in the power grid dispatching cloud platform through the bastion host.
[0098] The operation record module 404 is configured to record the operation information of the current access to the power grid dispatching cloud platform in the case of passing the access request, match the target information item in the information library according to the username, and record the operation information to the target information item.
[0099] In an embodiment, the apparatus can further include a user binding module configured to obtain user information of the user, and send the user information to the to-be-configured server, so that the to-be-configured server binds the user information and the imported seed key to obtain the configured OTP server.
[0100] In an embodiment, the request receiving module 401 is further configured to generate a time factor according to the receiving time of the access request, identify the user information of the current user according to the access request, and match the corresponding target seed key according to the user information of the current user; and calculate the password and the detection token by the SM3 algorithm according to the time factor and the target seed key.
[0101] In an embodiment, the power grid dispatching cloud platform includes a cloud platform deployment server, a cloud platform database and a cloud platform log server, and the login access module 403 is further configured to determine the to-be-accessed platform in the cloud platform deployment server, the cloud platform database and the cloud platform log server in response to a platform selection instruction of the current user, and access the to-be-accessed platform by single sign-on to the to-be-accessed platform through the SSH protocol on the bastion host.
[0102] In an embodiment, the apparatus can further include a failure statistics module configured to reject the access request and update the cumulative number of verification failures of the account of the current user within a preset time window in the case of password or OTP detection token verification failure, and cancel the account login permission of the account within the preset time window in the case of the cumulative number of verification failures exceeding a number threshold.
[0103] In an embodiment, the apparatus can further include an information receiving module configured to obtain the username of the current user, and receive the password and the detection token returned by the OTP server.
[0104] The various modules in the power grid dispatching cloud platform access authentication apparatus based on the bastion host can be implemented by software, hardware, or a combination thereof. The various modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a memory in a computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to the various modules.
[0105] In an exemplary embodiment, a computer device, which can be a terminal, has an internal structure diagram as shown in Figure 5 The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to perform wired or wireless communication with external terminals. The wireless communication can be achieved through WIFI, mobile cellular network, near field communication (NFC), or other technologies. The computer program is executed by the processor to implement an access authentication method of a power grid dispatching cloud platform. The display unit of the computer device is configured to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball, or touchpad arranged on the shell of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0106] Those skilled in the art can understand that Figure 5 The structure shown in the above
[0107] In an embodiment, a computer device is also provided, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0108] In an embodiment, a computer readable storage medium is provided, having stored thereon a computer program which, when executed by a processor, implements the steps of any of the method embodiments described above.
[0109] In an embodiment, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the steps of any of the method embodiments described above.
[0110] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.
[0111] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0112] The technical features of the above embodiments can be combined in any manner. To make the description concise, not all possible combinations of the technical features in the above embodiments are described, but as long as the combinations of the technical features do not exist contradictions, they should be considered as the scope of the present application.
[0113] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.
Claims
1. A method for access authentication in a power grid dispatch cloud platform based on a bastion host, characterized in that, Applied to operation and maintenance terminals, the method includes: In response to the current user's access request to the power grid dispatch cloud platform, the access request is sent to the configured OTP server, so that the OTP server can generate a password and a detection token according to the access request and hash algorithm, and return the password and the detection token to the operation and maintenance terminal. The current user's username, password, and detection token are packaged and sent to the bastion host. The bastion host verifies the detection token based on the username. If the detection token is verified, the bastion host sends the password to the OTP server, which then verifies the password. Log in to the bastion host after the password verification is successful, and access the platform to be accessed in the power grid dispatch cloud platform through the bastion host; If the access request is approved, the operation information of this access to the power grid dispatch cloud platform is recorded, the target information entry in the information database is matched according to the username, and the operation information is entered into the target information entry.
2. The method according to claim 1, characterized in that, The response prior to the current user's access request to the power grid dispatch cloud platform also includes: Obtain the user's information and send it to the server to be configured, so that the server to be configured can bind the user information and the imported seed key to obtain the configured OTP server.
3. The method according to claim 2, characterized in that, The OTP server generates a password and a verification token based on the access request and a hash algorithm, including: The OTP server generates a time factor based on the time the access request is received, identifies the user information of the current user based on the access request, and matches the corresponding target seed key based on the user information of the current user. The password and the detection token are calculated using the SM3 algorithm based on the time factor and the target seed key.
4. The method according to claim 1, characterized in that, The power grid dispatch cloud platform includes a cloud platform deployment server, a cloud platform database, and a cloud platform log server. Accessing the platform to be accessed within the power grid dispatch cloud platform via the bastion host includes: In response to the current user's platform selection instruction, the platform to be accessed is determined from the platform deployment server, the cloud platform database, and the cloud platform log server; The user can access the platform to be accessed via SSH single sign-on on the bastion host.
5. The method according to claim 1, characterized in that, The method further includes: If the password or OTP detection token fails to verify, the access request is rejected and the current user's account is updated with the cumulative number of verification failures within a preset time window. If the cumulative number of verification failures exceeds a threshold, the account's login privileges will be revoked within the preset time window.
6. The method according to any one of claims 1 to 5, characterized in that, Before sending the current user's username, password, and detection token to the bastion host, the process further includes: Obtain the username of the current user, and receive the password and detection token returned by the OTP server.
7. A power grid dispatch cloud platform access authentication device based on a bastion host, characterized in that, The device, applied to maintenance terminals, includes: The request receiving module is used to respond to the current user's access request for the power grid dispatch cloud platform, send the access request to the configured OTP server, so that the OTP server can generate a password and a detection token according to the access request and a hash algorithm, and return the password and the detection token to the operation and maintenance terminal. The information verification module is used to package the current user's username, password, and detection token and send them to the bastion host. The bastion host verifies the detection token based on the username. If the detection token is verified, the bastion host sends the password to the OTP server, and the OTP server verifies the password. The login access module is used to log in to the bastion host when the password verification is successful, and to access the platform to be accessed in the power grid dispatch cloud platform through the bastion host. The operation recording module is used to record the operation information of this access to the power grid dispatch cloud platform when the access request is approved, match the target information entry in the information database according to the username, and enter the operation information into the target information entry.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Automatic user management method and system based on FreeIPA platform
CN120408584A
Apparatus and method for authentication by using one time password
WO2008102930A1
Safety protection system, method and apparatus, device, storage medium and program product
WO2025130131A1
Cited By
Access authentication method and device of power grid dispatching cloud platform, computer equipment, storage medium and program product
CN121037043A
Access authentication method and device of power grid dispatching cloud platform, computer device, storage medium and program product
CN121037043B