Authentication Method, Device, Equipment and Medium Based on Distributed System

By introducing an authentication mechanism based on authentication files and authorization files in the distributed system, and combining encryption algorithms to process accounts and passwords, data tampering and message leakage problems caused by users' arbitrary connections and operating nodes in the distributed system are solved, and higher security and permission management are achieved.

CN114117374BActive Publication Date: 2025-06-24ONE CONNECT SMART TECH CO LTD SHENZHEN
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111437871.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-30
Publication Date
2025-06-24
Estimated Expiration
2041-11-30

AI Technical Summary

Technical Problem

In the prior art, there are loopholes in the distributed system's access rights and operation rights of users. Users can connect at will and add and delete nodes, resulting in data being attacked and tampered with, and there are security risks of message leakage.

Method used

It provides an authentication method based on a distributed system. By receiving authentication files sent by the server, generating authorization files according to the verification rules of the distributed system, creating an authentication list for the server, and processing accounts and passwords based on the encryption algorithm, adding them to the permission list to ensure that only authenticated users can establish communication with the server.

Benefits of technology

It effectively prevents the data of the authenticated node from being tampered with and messages leaking on the server, ensures the security of user access rights and operation rights, and prevents unauthorized nodes from adding or deleting operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117374B_ABST
    Figure CN114117374B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of artificial intelligence technology, and provides an authentication method, device, equipment and medium based on a distributed system. The method includes: generating an authorization file corresponding to an authentication file according to a verification rule; creating an authentication list according to the authorization file and the authentication file; reading a first account number and a first password, performing encryption calculation on the first account number and the first password based on an encryption algorithm, obtaining first authentication information and adding it to the permission list of an authentication node; when it is monitored that a user of a client initiates a request to access the authentication node, reading a second account number and a second password to perform encryption calculation to obtain second authentication information, and determining whether the first authentication information is the same as the second authentication information. If so, establish communication between the authentication node and the server according to the permission list and the authentication list. The present invention also relates to the field of blockchain technology, and the above first authentication information and second authentication information can also be stored in a node of a blockchain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular, to an authentication method, device, equipment and medium based on a distributed system. Background Art

[0002] The operation of KAFKA depends on a distributed system (ZooKeeper). The distributed system provides functions such as configuration maintenance, distributed synchronization, and message transmission for the Broker server in KAFKA. Currently, there are some vulnerabilities in the access rights and operation rights of users in the distributed system. As long as the user inputs the IP and port information of the distributed system, they can connect to the distributed system and add or delete nodes of the distributed system, which easily leads to the data of the nodes being attacked and tampered with. They can also obtain the messages of producers and consumers from the server of KAFKA, which easily causes potential security risks of message leakage. Summary of the Invention

[0003] In view of the above, the present invention provides an authentication method, device, equipment and medium based on a distributed system, and its purpose is to solve the technical problems of data tampering of authenticated nodes and message leakage of the server in the prior art.

[0004] To achieve the above object, the present invention provides an authentication method based on a distributed system, and the method includes:

[0005] Receiving an authentication file sent by a server, and generating an authorization file corresponding to the authentication file according to the verification rules of the distributed system;

[0006] Creating an authentication list of the server on an authentication node in the distributed system according to the authorization file and the authentication file;

[0007] Reading a first account number and a first password of a whitelist file of the server, performing encryption calculation on the first account number and the first password based on a preset encryption algorithm, obtaining first authentication information and adding it to a permission list of the authentication node;

[0008] When it is monitored that a user of a client initiates a request to access the authentication node, reading a second account number and a second password of the user and performing encryption calculation to obtain second authentication information, and determining whether the first authentication information is the same as the second authentication information. If so, establishing communication between the authentication node and the server according to the permission list and the authentication list.

[0009] Preferably, before receiving the authentication file sent by the server, the method includes:

[0010] Create the authentication file in the authentication directory on the server side, read multiple authentication packages in the dynamic link sharing directory of the server side, where the authentication packages include the IP identification and port information of the server side;

[0011] Copy the multiple authentication packages to the authentication file and send them to the distributed system.

[0012] Preferably, generating an authorization file corresponding to the authentication file according to the verification rules of the distributed system includes:

[0013] Read the IP identification and port information of the server side from the authentication file, and generate a corresponding authorization file according to the verification rules of the distributed system for the IP identification and port information of the server side.

[0014] Preferably, before reading the first account number and the first password of the whitelist file of the server side, the method further includes:

[0015] Obtain the first account number and the first password for the user to log in to the server side from the login interface of the server side, and add the first account number and the first password to the whitelist file.

[0016] Preferably, performing encryption calculation on the first account number and the first password based on a preset encryption algorithm to obtain first authentication information and adding it to the permission list of the authentication node includes:

[0017] Input the sequence numbers of the first account number and the first password into the encryption algorithm to perform encryption calculation to obtain two sets of first encryption results, splice the two sets of first encryption results to obtain the first authentication information, and when adding the first authentication information to the permission list, set the corresponding permissions for the first authentication information according to the permission rules of the distributed system.

[0018] Preferably, the encryption algorithm includes:

[0019] Q L = V1 << 4 + K0 × V1 + A × (V1 >> 5) + K1;

[0020] Q R = V0 << 4 + K2 × V0 + A × (V0 >> 5) + K3;

[0021] where Q L is the encryption result of the left group of the first password, Q R is the encryption result of the right group of the first password, V0 is the first group of plaintext of the first password, V1 is the second group of plaintext of the first password, A is a constant, and K0 - K3 are the first to fourth groups of secret keys of the first password respectively.

[0022] Preferably, the step of determining whether the first authentication information is the same as the second authentication information, and if so, establishing communication between the authentication node and the server according to the permission list and the authentication list includes:

[0023] Reading the lengths and quantities of each byte array in the first authentication information and the second authentication information;

[0024] When it is determined that the lengths and quantities of each byte array are the same, establishing communication between the authentication node and the server according to the permission list and the authentication list.

[0025] To achieve the above object, the present invention also provides an authentication device for a distributed system, the device includes:

[0026] A receiving module: configured to receive an authentication file sent by a server, and generate an authorization file corresponding to the authentication file according to the verification rules of the distributed system;

[0027] An authentication module: configured to create an authentication list of the server at an authentication node in the distributed system according to the authorization file and the authentication file;

[0028] A calculation module: configured to read a first account number and a first password of a whitelist file of the server, perform an encryption calculation on the first account number and the first password based on a preset encryption algorithm, obtain first authentication information and add it to the permission list of the authentication node;

[0029] A judgment module: configured to, when detecting a request from a user of a client to access the authentication node, read a second account number and a second password of the user and perform an encryption calculation to obtain second authentication information, and judge whether the first authentication information is the same as the second authentication information, and if so, establish communication between the authentication node and the server according to the permission list and the authentication list.

[0030] To achieve the above object, the present invention also provides an electronic device, the electronic device includes:

[0031] At least one processor; and,

[0032] A memory communicatively connected to the at least one processor; wherein,

[0033] The memory stores a program executable by the at least one processor, and the program is executed by the at least one processor so that the at least one processor can execute the authentication method based on a distributed system according to any one of claims 1 to 7.

[0034] To achieve the above object, the present invention also provides a computer-readable medium storing an authentication program for a distributed system. When the authentication program for the distributed system is executed by a processor, the steps of the authentication method based on the distributed system as described in any one of claims 1 to 7 are implemented.

[0035] The present invention generates an authorization file corresponding to an authentication file according to the verification rules of the distributed system; creates an authentication list of the server at the authentication node in the distributed system according to the authorization file and the authentication file; performs an encryption calculation on the first account number and the first password based on a preset encryption algorithm to obtain a first authentication information and adds it to the permission list of the authentication node; when it is monitored that a user of the client initiates a request to access the authentication node, reads the second account number and the second password of the user to perform the encryption calculation to obtain a second authentication information, and determines whether the first authentication information is the same as the second authentication information. If so, establishes communication between the authentication node and the server according to the permission list and the authentication list. The present invention sets the access permission and operation permission of the user according to the authentication list and the permission list. The user with the access permission and the operation permission can access the server and the distributed system, and perform operations such as adding and deleting the authentication node, preventing the data of the authentication node from being tampered with, and avoiding the security risk of message leakage of the server. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 It is a flowchart schematic diagram of a preferred embodiment of the authentication method based on the distributed system of the present invention;

[0037] Figure 2 It is a module schematic diagram of a preferred embodiment of the authentication device of the distributed system of the present invention;

[0038] Figure 3 It is a schematic diagram of a preferred embodiment of the electronic device of the present invention;

[0039] The realization, functional features and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] In order to make the object, technical solution and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0041] Embodiments of the present invention can acquire and process relevant data based on artificial intelligence technology. Among them, Artificial Intelligence (AI) is a theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results.

[0042] Artificial intelligence basic technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, and mechatronics. Artificial intelligence software technologies mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0043] The present invention provides an authentication method based on a distributed system. This method is applied to an electronic device. In one embodiment, the electronic device is an execution server that adopts a distributed system. One or more clients and a server can establish connections with the execution server. Refer to Figure 1 As shown, it is a schematic flowchart of the method of the embodiment of the authentication method based on a distributed system of the present invention. The authentication method based on a distributed system includes:

[0044] Step S10: Receive an authentication file sent by the server, and generate an authorization file corresponding to the authentication file according to the verification rules of the distributed system;

[0045] In this embodiment, whenever the server is started, an authentication node belonging to itself is created in the distributed system according to the ID of the server. At the same time, the server also sends an authentication file to the execution server of the distributed system. Data such as the version number and creation time of the authentication node are stored in the database of the distributed system, which is convenient for data maintenance after the iteration update of the authentication node. The authentication node is used to connect the communication between the distributed system and the server.

[0046] The server includes, but is not limited to, the server (Broker side) in KAFKA. Here, the server refers to a single server or a cluster composed of multiple servers. KAFKA assigns a globally unique number to each server as the server ID. The producer side and consumer side in KAFKA are both clients of the Broker server. The distributed system can be a ZooKeeper distributed system, or it can also be distributed systems such as Google Spanner and OceanBase. The verification rule of the distributed system can be the Addauth verification rule of the distributed system, which is a way to verify user access to the distributed system. The authorization file is used to register the user information in the client (producer side and consumer side) to the authentication node to generate authenticated users. Only authenticated users can access the connection channel between the distributed system and the server through this authentication node.

[0047] In one embodiment, before receiving the authentication file sent by the server, the method includes:

[0048] Create the authentication file in the authentication directory in the server, read multiple authentication packages in the dynamic link shared directory of the server. The authentication packages include the IP identification and port information of the server.

[0049] Copy the multiple authentication packages to the authentication file and send it to the distributed system.

[0050] Create an authentication file in the authentication directory in the server (for example, the authentication directory is kafka / server / config, and the authentication file format is a jaas file). The authentication package refers to multiple file packages such as each port information, the IP identification of the server, the IP identification of the client, and the authorized user (for example, the authentication package uses the JAR file format). The IP identification of the client refers to the IP identification of the producer side and consumer side in KAFKA. The authorized user refers to the user to be authenticated who has the permission to access the connection channel between the distributed system and the server, including the account to be authenticated and the password to be authenticated of the user to be authenticated. In this example, it is necessary to pre-set which users can have the permission to access the connection channel between the distributed system and the server, and also the information about which systems or ports can be accessed.

[0051] In one embodiment, generating the authorization file corresponding to the authentication file according to the verification rule of the distributed system includes:

[0052] Read the IP identification and port information of the server from the authentication file, and generate the corresponding authorization file according to the verification rule of the distributed system with the IP identification and port information of the server.

[0053] When the distributed system receives the server authentication file, it reads the IP identification and port information of the server from the file (for example, the IP identification is 192.168.2.15 and the port information is 9088). The verification rules of the distributed system register and authenticate the IP identification of the server in the authentication directory of the distributed system, and create a socket connection between the port information of the server and the port information of the distributed system, modify parameters such as the environment variables and startup scripts of the distributed system, and generate an authorization file corresponding to the server.

[0054] Step S20: Create an authentication list of the server at the authentication node in the distributed system according to the authorization file and the authentication file;

[0055] In this embodiment, the to-be-authenticated account and to-be-authenticated password of the authorized user (authentication package) in the authentication file are read. According to the port of the verification rules, the authorization file, the to-be-authenticated account and the to-be-authenticated password are registered in the authentication directory of the authentication node (for example, the authentication directory is set / module / list) to obtain the authentication list of the server. This authentication list is used to register the to-be-authenticated users in the authentication file as authenticated users, and it registers information about which systems or ports the authenticated users can access. The authenticated users can access the connection channel between the distributed system and the server through this authentication node, and cannot read or write messages from the server, nor do they have any operation permissions on the authentication node. In the present invention, the access permissions and operation permissions of the authenticated users are set separately. The operation permissions include creating child nodes for this authentication node, setting the data of this authentication node, and adding or deleting this authentication node.

[0056] For example, authenticated user A only has the access permission to access the connection channel between the distributed system and the server. When authenticated user A accesses the authentication node of the distributed system, according to the corresponding access permission of authenticated user A in the authentication list, authenticated user A can only access the connection channel between the distributed system and the server, cannot access other connection channels of the distributed system, nor can it read or write messages from the server, and even less can it have any operation permissions on the authentication node. This solves the problem in the prior art that when a user inputs the IP and port information of the distributed system, it can connect to the distributed system, resulting in the leakage of messages on the server.

[0057] Step S30: Read the first account and the first password of the whitelist file of the server, perform an encryption calculation on the first account and the first password based on a preset encryption algorithm, obtain the first authentication information, and add it to the permission list of the authentication node;

[0058] In this embodiment, the serial numbers of the first account and the first password of the user in the whitelist file are read from the server, and the serial numbers are input into an encryption algorithm to perform encryption calculation to obtain the first authentication information. The encryption algorithm includes but is not limited to the DES algorithm. In this embodiment, the first account and the first password in the whitelist file are the same as the account to be authenticated and the password to be authenticated in the authentication file. However, in other embodiments, the first account and the first password in the whitelist file may not be the same as the account to be authenticated and the password to be authenticated in the authentication file. According to the permission rules of the distributed system, the first authentication information is added to the permission list. The permission rules may be the ACL permission rules of the distributed system. The operation permissions of the user are set through the SetAal command in the ACL permission rules. The operation permissions are divided into multiple levels (for example, from low to high, they are divided into levels 1-5. Level 1 is for reading, level 2 is for writing, level 3 is for creating sub-nodes, level 4 is for setting node data, and level 5 is for setting to add or delete authentication nodes). According to the operation permission level of the user, the operation permissions of the user on the nodes are uniformly managed, solving the problem in the prior art that users can easily add or delete authentication nodes of the distributed system at will, which easily leads to the data of the authentication nodes being attacked and tampered with.

[0059] In one embodiment, before reading the first account and the first password of the whitelist file of the server, the method further includes:

[0060] Obtain the first account and the first password of the user logging in to the server from the login interface of the server, and add the first account and the first password to the whitelist file.

[0061] The user may refer to a registered user at the producer side or the consumer side. According to the registration information provided by the user, the server generates a random first account and first password for the user. The registration information includes the user's name, gender, age, education level, work unit, position, and the first invitation code. The first invitation code is encrypted and generated based on the initial account and the initial password in the whitelist file. The corresponding operation permissions for the authentication nodes have been set, and are provided by the administrator of the distributed system or the server through offline or online means. When the first invitation code provided by the user during registration is correct, obtain the first account and the first password of the user logging in to the server from the login interface of the server, replace the first account and the first password with the initial account and the initial password in the whitelist file, and store them in the whitelist file.

[0062] In one embodiment, performing the encryption calculation on the first account and the first password based on a preset encryption algorithm to obtain the first authentication information and adding it to the permission list of the authentication node includes:

[0063] Input the sequence numbers of the first account and the first password into an encryption algorithm to perform encryption calculations to obtain two sets of first encryption results. Concatenate the two sets of first encryption results to obtain the first authentication information. When adding the first authentication information to the permission list, set the corresponding permissions for the first authentication information according to the permission rules of the distributed system.

[0064] Input the sequence numbers of the first account and the first password into a 32-bit binary plaintext. Shuffle the order of the sequence numbers according to the permutation table of the encryption algorithm to obtain two permuted left and right plaintexts (for example, the left V0 is the first set of plaintext of the first password, and the right V1 is the second set of plaintext of the first password). Form an encryption framework with a 64-bit key divided into four sets of keys. Perform cyclic encryption on the two sets of plaintext a preset number of times (for example, the preset number of times is 10 times) to obtain two sets of first encryption results for the left and right outputs. Concatenate the two sets of first encryption results for the left and right outputs to obtain the first authentication information, which includes multiple byte arrays. Add the multiple byte arrays to the permission list and set the corresponding permissions for the first authentication information according to the ACL permission rules of the distributed system. For example, setting the operation permission for the first authentication information A allows reading messages from servers A and B, and setting the operation permission for the first authentication information B allows writing messages to server A and also allows creating child nodes for the authentication nodes of the distributed system.

[0065] In one embodiment, the encryption algorithm includes:

[0066] Q L = V1 << 4 + K0 × V1 + A × (V1 >> 5) + K1;

[0067] Q R = V0 << 4 + K2 × V0 + A × (V0 >> 5) + K3;

[0068] Where Q L is the encryption result of the left group of the first password, and Q R is the encryption result of the right group of the first password, V0 is the first set of plaintext of the first password, V1 is the second set of plaintext of the first password, A is a constant, and K0 - K3 are the first to fourth sets of keys of the first password respectively.

[0069] Perform the above encryption algorithm on the first account to obtain the output results of the left and right groups of the first account.

[0070] Step S40: When it is monitored that a user of the client initiates a request to access the authentication node, read the second account number and second password of the user and perform an encryption calculation to obtain second authentication information, and determine whether the first authentication information is the same as the second authentication information. If so, establish communication between the authentication node and the server according to the permission list and the authentication list.

[0071] In this embodiment, according to a preset encryption algorithm, the sequence numbers of the user's second account number and second password are input into the encryption algorithm to perform an encryption calculation to obtain two sets of second encryption results, and the two sets of second encryption results are concatenated to obtain second authentication information. When the second authentication information is the same as the first authentication information in the permission list, a connection channel between the authentication node and the server is established according to the operation permissions of the user in the permission list and the access permissions in the authentication list, that is, the connection channel between the client and the server is opened. The user of the client reads messages, writes information, or performs corresponding permission operations on the authentication node through this connection channel, solving the problem in the prior art that any user can connect to the distributed system by inputting the IP and port information of the distributed system and arbitrarily add or delete the authentication node of the distributed system.

[0072] In one embodiment, the determining whether the first authentication information is the same as the second authentication information, and if so, establishing communication between the authentication node and the server according to the permission list and the authentication list includes:

[0073] Read the length and quantity of each byte array in the first authentication information and the second authentication information;

[0074] When it is determined that the length and quantity of each byte array are the same, establish communication between the authentication node and the server according to the permission list and the authentication list.

[0075] The user's second account number and second password are randomly generated by the server according to a second invitation code. The second invitation code is encrypted and generated according to the first account number and first password in the whitelist file. Corresponding operation permissions have been set before each second invitation code is issued. When the length and quantity of each byte array of the first authentication information and the second authentication information are different, it means that the second invitation code provided by the user is incorrect and the user is not in the whitelist file and has no operation permissions. A preset prompt message (Hello, the account number and password you entered are incorrect. Please re-enter or contact the administrator) is fed back to the user. The user checks whether their second account number and second password are correct or contacts the administrator according to this prompt message, thus solving the problem in the prior art that any user or client can connect to the distributed system without authentication, read messages, write messages, or add or delete nodes from the server.

[0076] Refer to Figure 2 As shown, it is a schematic diagram of the functional modules of the authentication device 100 of the distributed system of the present invention.

[0077] The authentication device 100 of the distributed system described in the present invention can be installed in an electronic device. According to the functions to be realized, the authentication device 100 of the distributed system may include a receiving module 110, an authentication module 120, a calculation module 130, and a judgment module 140. The modules described in the present invention may also be referred to as units, which refer to a series of computer program segments that can be executed by the processor of the electronic device and can complete fixed functions, and are stored in the memory of the electronic device.

[0078] In this embodiment, the functions of each module / unit are as follows:

[0079] The receiving module 110 is used to receive the authentication file sent by the server and generate an authorization file corresponding to the authentication file according to the verification rules of the distributed system.

[0080] The authentication module 120 is used to create an authentication list of the server at the authentication node in the distributed system according to the authorization file and the authentication file.

[0081] The calculation module 130: is used to read the first account number and the first password of the whitelist file of the server, perform encryption calculation on the first account number and the first password based on a preset encryption algorithm, obtain the first authentication information and add it to the permission list of the authentication node.

[0082] The judgment module 140 is used to, when detecting that a user of the client initiates a request to access the authentication node, read the second account number and the second password of the user and perform encryption calculation to obtain the second authentication information, and judge whether the first authentication information is the same as the second authentication information. If so, establish communication between the authentication node and the server according to the permission list and the authentication list.

[0083] In one embodiment, before receiving the authentication file sent by the server, the method includes:

[0084] Create the authentication file in the authentication directory in the server, read multiple authentication packets in the dynamic link shared directory of the server, and the authentication packets include the IP identification and port information of the server;

[0085] Copy the multiple authentication packets to the authentication file and send them to the distributed system.

[0086] In one embodiment, generating the authorization file corresponding to the authentication file according to the verification rules of the distributed system includes:

[0087] Read the IP identification and port information of the server from the authentication file, and generate a corresponding authorization file according to the verification rules of the distributed system for the IP identification and port information of the server.

[0088] In one embodiment, before reading the first account number and the first password of the whitelist file of the server, the method further includes:

[0089] Obtain the first account number and the first password for the user to log in to the server from the login interface of the server, and add the first account number and the first password to the whitelist file.

[0090] In one embodiment, performing an encryption calculation on the first account number and the first password based on a preset encryption algorithm to obtain first authentication information and adding it to the permission list of the authentication node, includes:

[0091] Input the sequence numbers of the first account number and the first password into the encryption algorithm to perform an encryption calculation to obtain two groups of first encryption results, splice the two groups of first encryption results to obtain the first authentication information, and when adding the first authentication information to the permission list, set the corresponding permissions for the first authentication information according to the permission rules of the distributed system.

[0092] In one embodiment, the encryption algorithm includes:

[0093] Q L = V1 << 4 + K0 × V1 + A × (V1 >> 5) + K1;

[0094] Q R = V0 << 4 + K2 × V0 + A × (V0 >> 5) + K3;

[0095] Wherein, Q L is the encryption result of the left group of the first password, Q R is the encryption result of the right group of the first password, V0 is the first group of plaintext of the first password, V1 is the second group of plaintext of the first password, A is a constant, and K0 - K3 are the first to fourth groups of secret keys of the first password respectively.

[0096] In one embodiment, judging whether the first authentication information is the same as the second authentication information, if so, establishing communication between the authentication node and the server according to the permission list and the authentication list, includes:

[0097] Read the length and quantity of each byte array in the first authentication information and the second authentication information;

[0098] When it is determined that the lengths and quantities of each byte array are the same, communication is established between the authentication node and the server according to the permission list and the authentication list.

[0099] Referring to Figure 3 As shown, it is a schematic diagram of a preferred embodiment of the electronic device 1 of the present invention.

[0100] The electronic device 1 includes, but is not limited to: a memory 11, a processor 12, a display 13, and a network interface 14. The electronic device 1 connects to a network through the network interface 14 to obtain raw data. Among them, the network can be a wireless or wired network such as an enterprise internal network (Intranet), the Internet, Global System of Mobile communication (GSM), Wideband Code Division Multiple Access (WCDMA), 4G network, 5G network, Bluetooth, Wi-Fi, a call network, etc.

[0101] Among them, the memory 11 includes at least one type of readable medium, and the readable medium includes flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 11 may be an internal storage unit of the electronic device 1, such as the hard disk or memory of the electronic device 1. In other embodiments, the memory 11 may also be an external storage device of the electronic device 1, such as a plug-in hard disk equipped with the electronic device 1, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Of course, the memory 11 may also include both the internal storage unit and the external storage device of the electronic device 1. In this embodiment, the memory 11 is generally used to store the operating system installed on the electronic device 1 and various application software, such as the program code of the authentication program 10 of the distributed system. In addition, the memory 11 may also be used to temporarily store various data that have been output or will be output.

[0102] In some embodiments, the processor 12 may be a Central Processing Unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 12 is generally used to control the overall operation of the electronic device 1, such as performing control and processing related to data interaction or communication. In this embodiment, the processor 12 is used to run the program code stored in the memory 11 or process data, such as running the program code of the authentication program 10 of the distributed system.

[0103] The display 13 may be referred to as a display screen or a display unit. In some embodiments, the display 13 may be an LED display, a liquid crystal display, a touch liquid crystal display, and an Organic Light-Emitting Diode (OLED) touch device, etc. The display 13 is used to display the information processed in the electronic device 1 and to display a visual working interface, such as displaying the results of data statistics.

[0104] The network interface 14 may optionally include a standard wired interface, a wireless interface (such as a WI-FI interface). The network interface 14 is generally used to establish a communication connection between the electronic device 1 and other electronic devices.

[0105] Figure 3 Only the electronic device 1 with components 11-14 and the authentication program 10 of the distributed system is shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively.

[0106] Optionally, the electronic device 1 may further include a user interface. The user interface may include a display, an input unit such as a keyboard. Optionally, the user interface may further include a standard wired interface, a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch liquid crystal display, and an Organic Light-Emitting Diode (OLED) touch device, etc. Among them, the display may also be appropriately referred to as a display screen or a display unit, which is used to display the information processed in the electronic device 1 and to display a visual user interface.

[0107] The electronic device 1 may further include a Radio Frequency (RF) circuit, sensors, an audio circuit, etc., which will not be elaborated here.

[0108] In the above embodiment, when the processor 12 executes the authentication program 10 of the distributed system stored in the memory 11, the following steps may be implemented:

[0109] Receiving the authentication file sent by the server, and generating an authorization file corresponding to the authentication file according to the verification rules of the distributed system;

[0110] Creating an authentication list of the server at an authentication node in the distributed system according to the authorization file and the authentication file;

[0111] Reading a first account and a first password from the whitelist file of the server, performing encryption calculation on the first account and the first password based on a preset encryption algorithm, obtaining first authentication information and adding the first authentication information to the authority list of the authentication node;

[0112] When it is monitored that the user of the client initiates a request to access the authentication node, the user's second account and second password are read and encryption calculation is performed to obtain second authentication information, and it is determined whether the first authentication information is the same as the second authentication information. If so, communication between the authentication node and the server is established based on the permission list and the authentication list.

[0113] The storage device may be the memory 11 of the electronic device 1 , or may be another storage device that is communicatively connected to the electronic device 1 .

[0114] For a detailed description of the above steps, please refer to the above Figure 2 Functional module diagram of an embodiment of an authentication device 100 for a distributed system and Figure 1 Description of a flowchart of an embodiment of an authentication method based on a distributed system.

[0115] In addition, an embodiment of the present invention further proposes a computer-readable medium, which may be non-volatile or volatile. The computer-readable medium may be any one or any combination of a hard disk, a multimedia card, an SD card, a flash memory card, an SMC, a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a portable compact disk read-only memory (CD-ROM), a USB memory, etc. The computer-readable medium includes a data storage area and a program storage area, the data storage area stores data created according to the use of the blockchain node, and the program storage area stores a distributed system authentication program 10, and the distributed system authentication program 10 is executed by the processor to implement the following operations:

[0116] Receiving the authentication file sent by the server, and generating an authorization file corresponding to the authentication file according to the verification rules of the distributed system;

[0117] Creating an authentication list of the server at an authentication node in the distributed system according to the authorization file and the authentication file;

[0118] Reading a first account and a first password from the whitelist file of the server, performing encryption calculation on the first account and the first password based on a preset encryption algorithm, obtaining first authentication information and adding the first authentication information to the authority list of the authentication node;

[0119] When it is monitored that the user of the client initiates a request to access the authentication node, the user's second account and second password are read and encryption calculation is performed to obtain second authentication information, and it is determined whether the first authentication information is the same as the second authentication information. If so, communication between the authentication node and the server is established based on the permission list and the authentication list.

[0120] The specific implementation of the computer-readable medium of the present invention is substantially the same as the specific implementation of the above-mentioned authentication method based on the distributed system, and will not be described in detail here.

[0121] In another embodiment, the authentication method based on the distributed system provided by the present invention can further ensure the privacy and security of all the above data, and all the above data can also be stored in a blockchain node. For example, the first authentication information and the second authentication information can be stored in the blockchain node.

[0122] It should be noted that the blockchain referred to in the present invention is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm, etc. Blockchain is essentially a decentralized database, a string of data blocks generated by cryptographic methods. Each data block contains a batch of network transaction information, which is used to verify the validity of its information (anti-counterfeiting) and generate the next block. Blockchain can include the blockchain underlying platform, platform product service layer, and application service layer.

[0123] It should be noted that the serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments. And the terms "including", "comprising" or any other variants thereof in this article are intended to cover non-exclusive inclusion, so that a process, device, article or method including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, device, article or method. In the absence of further restrictions, an element defined by the sentence "including a ..." does not exclude the presence of other identical elements in the process, device, article or method including the element.

[0124] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described example methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a medium as described above (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, computer, electronic device, or network device, etc.) to execute the methods described in various embodiments of the present invention.

[0125] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. An authentication method based on a distributed system, which is applied to an execution server that adopts a distributed system, and is characterized in that, The method includes: Receiving an authentication file sent by the server, and generating an authorization file corresponding to the authentication file according to the verification rules of the distributed system; Reading the account to be authenticated and the password to be authenticated of the authorized user in the authentication file, and registering the authorization file, the account to be authenticated, and the password to be authenticated to the authentication directory corresponding to the authentication node in the distributed system to obtain the authentication list of the server; Reading the first account and the first password in the whitelist file of the server, performing encryption calculation on the first account and the first password based on a preset encryption algorithm, and obtaining first authentication information and adding it to the permission list of the authentication node; When it is monitored that a user of the client initiates a request to access the authentication node, reading the second account and the second password of the user and performing encryption calculation to obtain second authentication information, and determining whether the first authentication information is the same as the second authentication information. If so, establishing communication between the authentication node and the server according to the permission list and the authentication list; The user accesses the connection channel between the distributed system and the server through the authentication node, and separately sets the access permission and the operation permission of the user. The operation permission includes creating a sub-node for the authentication node, setting the data of the authentication node, adding or deleting the authentication node.

2. The authentication method based on a distributed system according to claim 1, wherein Before receiving the authentication file sent by the server, the method includes: Creating the authentication file in the authentication directory in the server, and reading multiple authentication packets in the dynamic link sharing directory of the server. The authentication packets include the IP identification and port information of the server; Copying the multiple authentication packets to the authentication file and sending them to the distributed system.

3. The authentication method based on a distributed system according to claim 1 or 2, characterized in that The generating an authorization file corresponding to the authentication file according to the verification rules of the distributed system includes: Reading the IP identification and port information of the server from the authentication file, and generating a corresponding authorization file according to the verification rules of the distributed system for the IP identification and port information of the server.

4. The authentication method based on a distributed system according to claim 1, wherein, Before reading the first account and the first password in the whitelist file of the server, the method further includes: Obtaining the first account and the first password of the user logging in to the server from the login interface of the server, and adding the first account and the first password to the whitelist file.

5. The authentication method based on a distributed system according to claim 1, characterized in that The performing encryption calculation on the first account and the first password based on a preset encryption algorithm, obtaining first authentication information and adding it to the permission list of the authentication node includes: Inputting the serial numbers of the first account and the first password into the encryption algorithm to perform encryption calculation to obtain two sets of first encryption results, splicing the two sets of first encryption results to obtain the first authentication information. When adding the first authentication information to the permission list, setting the corresponding permission for the first authentication information according to the permission rules of the distributed system.

6. The authentication method based on a distributed system according to claim 1, wherein, The encryption algorithm includes: = <<4+ +A ( >>5)+ ; = <<4+ +A ( >>5)+ ; Among them, is the encryption result of the left group of the first password, is the encryption result of the right group of the first password, is the first group of plaintext of the first password, is the second group of plaintext of the first password, and A is a constant. are the first to fourth group keys of the first password respectively.

7. The authentication method based on a distributed system according to claim 1, wherein The determining whether the first authentication information is the same as the second authentication information. If so, establishing communication between the authentication node and the server according to the permission list and the authentication list includes: Read the lengths and quantities of each byte array in the first authentication information and the second authentication information; When it is determined that the lengths and quantities of each byte array are the same, establish communication between the authentication node and the server according to the permission list and the authentication list.

8. An authentication device for a distributed system, characterized in that, The device includes: A receiving module: configured to receive an authentication file sent by a server, and generate an authorization file corresponding to the authentication file according to the verification rules of the distributed system; An authentication module: configured to read the account to be authenticated and the password to be authenticated of the authorized user in the authentication file, and register the authorization file, the account to be authenticated, and the password to be authenticated to the authentication directory corresponding to the authentication node in the distributed system, to obtain the authentication list of the server; A calculation module: configured to read the first account and the first password in the whitelist file of the server, perform encryption calculation on the first account and the first password based on a preset encryption algorithm, obtain first authentication information and add it to the permission list of the authentication node; A judgment module: configured to, when detecting a request from a user of a client to access the authentication node, read the second account and the second password of the user and perform encryption calculation to obtain second authentication information, and judge whether the first authentication information is the same as the second authentication information. If so, establish communication between the authentication node and the server according to the permission list and the authentication list; the user accesses the connection channel between the distributed system and the server through the authentication node, and separately sets the access permission and operation permission of the user. The operation permission includes creating a child node for the authentication node, setting the data of the authentication node, and adding or deleting the authentication node.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores a program executable by the at least one processor, and the program is executed by the at least one processor, so that the at least one processor can execute the authentication method based on a distributed system according to any one of claims 1 to 7.

10. A computer-readable medium, characterized in that, The computer-readable medium stores an authentication program for a distributed system. When the authentication program for the distributed system is executed by a processor, the steps of the authentication method based on a distributed system according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Server user authority centralized control system and server use authority centralized control method

    CN104243154A

  • Password-based authentication

    CN106416123A