Single Sign-On Verification and Coordinated Management Method and Device Based on PAM Framework

Through the single sign-on method based on the PAM framework, the trust chain is built and the target login interface is called, which solves the problem that the existing technology cannot provide compatibility verification for multi-type single sign-on, and implements a general and extensible single sign-on framework.

CN114428948BActive Publication Date: 2025-06-13HILLSTONE NETWORKS CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210046441.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-12
Publication Date
2025-06-13
Estimated Expiration
2042-01-12

AI Technical Summary

Technical Problem

The prior art is difficult to provide compatibility verification solutions for multiple types of single sign-ons and cannot meet the integrated management needs of different customers.

Method used

The single sign-on method based on the PAM framework is adopted. By determining the target single sign-on type of the administrator user, a trust chain between the integrated management platform, users, and network security devices is built, the target log-on interface is called from the log-on interface provided by the PAM framework, and the resource allocation is uniformly configured using the SSO type library. The SPI based on the PAM framework completes the management and verification functions.

Benefits of technology

It implements a single sign-on framework with strong versatility, high feasibility and configurable for multiple types of single sign-ons, solves the problem that the existing technology cannot provide compatibility verification, and supports expansion and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114428948B_ABST
    Figure CN114428948B_ABST
Patent Text Reader

Abstract

The present application discloses a single sign-on verification and overall management method and device based on the PAM framework. Among them, the method includes: first determining the single sign-on type of the administrator user, and then calling the single sign-on interface corresponding to the target single sign-on type from the set of login interfaces provided by the PAM framework. The single sign-on process can be broken down into: 1. Establishing a trust relationship between the administrator user and the integrated management platform; 2. Establishing a trust relationship between the integrated management platform and the network security device; 3. Establishing a trust relationship between the administrator user and the network security device. This process is uniformly implemented using the PAM framework, and solutions such as the CAS server, certificate, independent password, TOKEN, etc. can be selected. Resource unified allocation is carried out based on the SSO type library, docking platform library, and user library, and the processing and verification functions are completed based on the service provider interface SPI of the PAM framework, solving the technical problem that it is difficult for the prior art to provide compatibility verification for multi-type single sign-on SSO solutions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of management of network security devices. Specifically, it relates to a method and device for single sign-on verification and overall management based on the PAM framework. Background Art

[0002] Currently, the product lines of mainstream network security manufacturers cover various types of network security devices, including border firewalls, Web application firewalls, cloud computing virtual firewalls, network audit systems (bastion hosts), and so on. Although individual network security products have graphical management interfaces, many organizations or enterprises hope to integrate and manage multiple network security products through their own unified integrated management systems. Due to the different environments and node trust levels of different customers, in order to meet the integrated management needs of different customers, network security devices need to support single sign-on access to multiple integrated management systems, but the existing technology cannot provide a compatible solution for different customers.

[0003] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention

[0004] Embodiments of this application provide a single sign-on method and device for docking a network security device with an integrated management platform to solve the problem that the existing technology is difficult to provide a maintainable and extensible compatibility verification solution for multiple types of single sign-on at the same time.

[0005] According to an embodiment of this application, a single sign-on overall solution is provided. This solution verifies and processes multiple types of single sign-on methods based on the pluggable authentication module PAM framework, so as to achieve the purpose that after a user logs in to the integrated management platform, they can directly manage network security devices without secondary authentication. It includes: first determining the target single sign-on type of the administrator user; selecting a credential according to different node trust levels to construct a trust chain among the integrated management platform, the user, and the network security device; calling the target login interface corresponding to the target single sign-on type (i.e., the API of the PAM framework) from the set of login interfaces provided by the PAM framework; after the target login interface is called, using the SSO type library, the docking platform library, and the user library for unified resource allocation; completing the management and verification functions based on the SPI (Service Provider Interface) of the PAM framework to obtain the target verification result; where the service provider interface SPI corresponds one-to-one with the application programming interface API.

[0006] Optionally, when the target single sign-on type is the certificate type, rely on the certificate of the network security device as the credential for single sign-on; the corresponding SPI of the network security device calls the resources of the network security device certificate library and the user library for verification.

[0007] Optionally, when the target single sign-on type is an independent password, rely on the pre-set independent password of the management platform and the network security device as the credential for single sign-on; the network security device calls the password library resource and the user library resource through the corresponding SPI to complete the authentication.

[0008] Optionally, when the target single sign-on type is the token (TOKEN) type, its token type can be divided into three categories. It can rely on the TOKEN issued by the management platform to the user as the credential for single sign-on, or rely on the TOKEN issued by the security device to the user as the credential for single sign-on, or rely on the TOKEN issued by the security device to the management platform as the credential for single sign-on. Finally, the network security device calls the token library resource and the user library resource through the corresponding SPI to complete the authentication.

[0009] Optionally, the target single sign-on type can at least include: certificate type, independent password type, three types of token types, and the CAS type based on the traditional central authentication server. The above types can be flexibly selected according to the different trust levels and application scenarios of the nodes. At the same time, based on the basic architecture of this solution, new single sign-on types can be quickly formulated, new credentials can be used, or new trust chain nodes can be added.

[0010] According to one aspect of the embodiments of the present application, a single sign-on device is provided, which is characterized by including: an access module: after the user logs in to the integrated management platform, accesses the network security device based on any of the above single sign-on types, and the access module senses the user request action and conducts data interaction with the background program; a verification processing module, configured to call the login interface corresponding to the target single sign-on type from the set of login interfaces (APIs) provided by the PAM framework, and verify and process the login request information of the administrator user based on the SPI to obtain the target verification result; a resource allocation module: configured to assist the above verification process in resource allocation and resource storage.

[0011] According to one aspect of the embodiments of the present application, a non-volatile storage medium is provided. The content stored in the medium includes a program for implementing the above functions, a user library required for single sign-on, a docking platform library, and a sub-resource library of a certain single sign-on type. The sub-resource library of the single sign-on type can include the following content: a certificate library for the certificate SSO type, a password library for the independent password SSO type, a token library for the token SSO type, and a CAS library for the traditional CAS single sign-on type.

[0012] According to one aspect of the embodiments of the present application, a dedicated processor unit for a device is provided. The processor unit is used to run program instructions. When the program runs, it executes any of the above single sign-on verification and overall management methods.

[0013] In the embodiments of the present application, by calling the login interface corresponding to the single sign-on (SSO) type provided by the PAM framework, compatibility verification is performed on multi-type single sign-on (SSO) solutions, achieving the purpose of different processing for different single sign-on (SSO), thereby realizing a single sign-on framework with strong generality, high feasibility, and configurability for multiple access types, and further solving the technical problem that the prior art cannot provide compatibility verification for multi-type single sign-on (SSO) solutions. In addition, this solution also supports extension and maintenance. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0015] Figure 1 is a hardware structure block diagram of a network security device for implementing single sign-on docking according to an embodiment of the present application;

[0016] Figure 2 is the overall flowchart of the embodiments of the present application;

[0017] Figure 3 is a schematic diagram of the general PAM framework based on the embodiments of the present application;

[0018] Figure 4 is the single sign-on (SSO) service flowchart of the embodiments of the present application;

[0019] Figure 5 is a schematic diagram of establishing a trust relationship for single sign-on in the embodiments of the present application;

[0020] Figure 6 is a timing diagram of single sign-on for certificate types in the embodiments of the present application;

[0021] Figure 7 is a timing diagram of single sign-on for independent password types in the embodiments of the present application;

[0022] Figure 8 is a timing diagram of single sign-on for the first type of TOKEN in the embodiments of the present application;

[0023] Figure 9 is a timing diagram of single sign-on for the second type of TOKEN in the embodiments of the present application;

[0024] Figure 10 is a timing diagram of single sign-on for the third type of TOKEN in the embodiments of the present application;

[0025] Figure 11 is a structural diagram of a JWT-form TOKEN in the embodiments of the present application;

[0026] Figure 12 It is the timing diagram of the CAS - type SSO single - sign - on in the embodiment of the present application;

[0027] Figure 13 It is the business - process flowchart for handling multiple types of SSO logins in the embodiment of the present application;

[0028] Figure 14 It is the storage structure diagram in the embodiment of the present application;

[0029] Figure 15 It is the functional structure diagram of unified verification and management in the embodiment of the present application;

[0030] Figure 16 It is the module structure diagram of the single - sign - on device in the embodiment of the present application. Specific implementation manners

[0031] In order to enable those skilled in the art of this technology to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above - mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non - exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0033] According to the embodiments of the present application, an embodiment of a login method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer - executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.

[0034] The single - sign - on method provided in the present application can be used for single - sign - on docking of network security devices (which are also computer devices based on the Linux kernel). Figure 1A hardware block diagram of a network security device for implementing the single sign-on solution is shown. As Figure 1 shown, the computer device 10 may include one or more processors (shown as 102a, 102b, ……, 102n in the figure). The processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a network interface 106 for communication functions. In addition, it may further include (not shown in the figure): a display, an input / output interface (I / O interface), and a power supply. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer device 10 may further include more or fewer components than those Figure 1 shown, or have a different configuration from that Figure 1 shown.

[0035] It should be noted that the above one or more processors 102 and / or other data processing circuits are generally referred to as "data processing circuits" in this article. The data processing circuit may be embodied in software, hardware, firmware, or any combination thereof, in whole or in part.

[0036] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the single sign-on solution in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned login solution. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the computer device 10 through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0037] The network interface 106 is used to receive or send data via one or more networks. The specific examples of the above network mainly refer to the target network managed by the network security device and the Internet network provided by the ISP. The network interface 106 is connected to a network adapter (Network Interface Controller, NIC), and it can communicate with other network devices through a data link.

[0038] The network security device shown in the figure mainly consists of two major parts, the control plane and the data plane. The former occupies most of the CPU and is used to implement the basic service functions (service traffic processing) of the network security device (firewall). The latter occupies a small part of the CPU and is used to implement ordinary login, single sign-on, function configuration, etc. for administrator users. The main service of this application acts on the control plane. Usually, users can access the control plane via network interface 106 based on protocols such as HTTPS. After successful login verification, they can view relevant data of the security device or configure relevant functions.

[0039] It should be noted that in some alternative embodiments, the above Figure 1 shown network security device may include hardware components (including circuits), software components (including computer code stored on a computer-readable medium), or a combination of both hardware and software components. It should be pointed out that Figure 1 is only an example of a specific concrete instance and is intended to illustrate the types of components that may exist in the above network security device.

[0040] Under the above operating environment, the embodiments of this application provide a Figure 2 shown single sign-on solution. This solution verifies and processes various types of single sign-on methods based on the Pluggable Authentication Modules (PAM) framework, so as to achieve the purpose that after the user logs in to the integrated management platform, they can directly manage the network security device without secondary authentication:

[0041] Figure 2 is a flowchart of a single sign-on solution according to an embodiment of this application. As Figure 2 shown, the method includes the following steps:

[0042] Step S202, determine the target single sign-on type of the administrator user, select a credential according to the trust level of different nodes, and construct a trust chain among the integrated management platform, the user, and the network security device, that is, determine what method to use as a credential to construct a trust chain among the integrated management platform, the user, and the network security device.

[0043] Step S204, call the target login interface corresponding to the target single sign-on type from the set of login interfaces provided by the PAM framework, that is, call a certain API of the PAM framework.

[0044] Step S206, after the target login interface is called, use the SSO type library, the docking platform library, and the user library to perform unified resource allocation. Based on the SPI (Service Provider Interface) of the PAM framework, complete the management and verification functions to obtain the target verification result. Among them, the service provider interface SPI corresponds one-to-one with the application programming interface API;

[0045] The above steps achieve the purpose of performing different processes for different single sign-on (SSO), and provide a login solution with strong generality, high feasibility, configurability, extensibility, and easy maintenance for various types of SSO access.

[0046] Figure 3 It is a schematic diagram of the PAM framework. The Pluggable Authentication Modules is an authentication mechanism proposed by Sun. It separates the services provided by the system from the authentication methods of these services by providing some dynamic link libraries and a set of unified APIs, enabling system administrators to flexibly configure different authentication methods for different services according to needs without changing the application program, and also facilitating the addition of new authentication means to the system.

[0047] Such as Figure 3 shown, the application program in the PAM framework realizes the functions related to verification by calling the API; the specific processing of the corresponding functions is completed by calling the SPI corresponding to the API. These function modules include the verification service module, the account management module, the session management module, and the password management module. The SPI corresponds one-to-one with the API, and the SPI determines the implementation result of the API call. In the embodiments of the present application, the PAM framework no longer performs password authentication only based on the local or external user account library. The present invention uses it for the administrator to perform SSO login of network security devices on the integrated platform. Usually, before calling the API, use pam_set_item() to set the single sign-on type. In the SPI, use pam_get_item() to obtain the single sign-on type and dispatch it to the corresponding processing logic.

[0048] In some embodiments of the present application, Figure 4 is the flowchart of the single sign-on (SSO) service. Such as Figure 4As shown in the figure, the main process includes: ① The administrator user logs in to the integrated management platform through password authentication. ② The user sends a single sign-on (SSO) login request to the network security device by clicking the management button on the integrated management platform. ③ The network security device verifies the login request and returns the verification result to the integrated management platform. ④ The network security device returns the verification result. ⑤ When the verification result indicates that the administrator user can access, the integrated management platform redirects the administrator user to the network security device management page. ⑥ The user performs management operations. In the above SSO process, the administrator user does not need to enter the device management password again, avoiding secondary authentication.

[0049] In some alternative embodiments of the present application, when there is no Central Authentication Service (CAS) server in the environment where the integrated management platform and the network security device are located, the process of implementing single sign-on (SSO) for the administrator user is essentially a process of establishing a mutual trust relationship among the administrator user, the integrated management platform, and the network security device.

[0050] Figure 5 It is a flowchart of the overall timing of this type of solution (non-CAS solution), as Figure 5 shown, the main process includes: establishing a trust relationship between the administrator user and the integrated management platform; establishing a trust relationship between the integrated management platform and the network security device; establishing a trust relationship between the administrator user and the network security device. These SSO types can include certificate type, independent password type, and token type, and their classification basis is the credential relied on to establish the trust relationship.

[0051] Optionally, if the target single sign-on type is the certificate type, the specific processing procedures of steps S202, S204, and S206 are as follows:

[0052] In step S202, the management platform installs the certificate of the network security device, and the network security device secretly stores its certificate private key in the certificate library.

[0053] In step S204, after the administrator user logs in to the management platform, the management platform encrypts the administrator user information using the certificate public key.

[0054] In step S206, the network security device invokes the network security device certificate library resources and user library resources corresponding to the SPI, decrypts the user information based on the certificate private key to obtain the decryption result, and verifies the user information based on the decryption result.

[0055] In some embodiments of the present application, Figure 6 It is a timing diagram of single sign-on of the certificate type, as Figure 6As shown in the figure, the main process of the timing diagram is as follows: ① The integrated management platform installs the certificate of the network security device. Among them, the public key of the certificate is stored by the integrated management platform, and the private key of the certificate is stored by the network security device. ② The administrator user logs in to the integrated management platform using password authentication. The administrator user clicks the network security device management button on the integrated management platform. ③ The integrated management platform encrypts the user information of the administrator user based on the public key of the certificate and sends the encrypted information to the network security device. Among them, the user information includes at least: the name of the administrator user, management authority, access authority, login IP, etc. ④ The network security device decrypts the information based on the private key of the certificate, obtains the decryption result, and verifies the decryption result with the information stored in the user library. ⑤ If the verification is correct, return an "ok" message to the integrated management platform; based on the "ok" message, the integrated management platform redirects the administrator user to the network security device management interface.

[0056] If the target single sign-on type is the certificate type, the APIs, SPIs, functions, and implementations of the PAM framework are as shown in the following table:

[0057]

[0058]

[0059] Optionally, if the target single sign-on type is the independent password type, the specific processing procedures of step S202, step S204, and step S206 are as follows:

[0060] In step S202, an independent password for the management platform and the network security device is preset.

[0061] In step S204, after the administrator user logs in to the management platform, the management platform uses the salted MD5 digest algorithm to perform a digest operation on the independent password and the user information.

[0062] In step S206, the network security device calls the password library and user information library resources corresponding to the SPI to verify the password to determine the legitimacy of the integrated management platform's identity, and verify the user information to determine the legitimacy of the user's identity.

[0063] Figure 7 It is the timing diagram of the independent password single sign-on type, as Figure 7As shown in the figure, the main processes of the timing diagram are as follows: ① Set an independent password in the network security device in advance, where the independent password is exclusive to the integrated management platform. ② The administrator user logs in to the integrated management platform using password authentication. When the administrator user clicks the network security device management button on the integrated management platform. ③ The integrated management platform sends the user information of the administrator user and the independent password encrypted with MD5 and salt to the network security device; the network security device verifies the user information and the independent password. ⑤ After the verification is successful, it returns an "ok" message to the integrated management platform. ⑥ Based on the "ok" message, the integrated management platform redirects the administrator user to the network security device management interface.

[0064] If the single sign-on type is the independent password type, the functions and implementations of the corresponding APIs and SPIs of the PAM framework are as shown in the following table:

[0065]

[0066] Optionally, this system provides three types of token SSO at the same time, which are detailed as follows:

[0067] If the single sign-on type is the first type of token login (i.e., based on the TOKEN issued by the management platform to the user), the specific processing processes of steps S202, S204, and S206 are as follows:

[0068] In step S202, the management platform and the network security device synchronize the administrator user information in advance.

[0069] In step S204, after the administrator user logs in to the management platform, the management platform saves the user information as a TOKEN in the JWT format and issues it to the user.

[0070] In step S206, the user accesses the security device with the TOKEN. The network security device's corresponding SPI calls the token library resources and user library resources. After verifying the user information correctly, it sends the signed TOKEN back to the integrated management platform. After the platform verifies the signature, it returns the final authentication result.

[0071] Figure 8 is the timing diagram of the first type of token single sign-on. As Figure 8 shown, the main processes of this timing diagram include: ① The integrated management platform synchronizes the administrator user information shared by the network security device. ② The administrator user logs in to the integrated management platform based on password authentication. ③ The integrated management platform saves the administrator user information in a TOKEN in the JSON WEB TOKEN (JWT) format. And issues the JWT-format TOKEN to the administrator user. Among them, the structure of the JWT-format token is shown in Figure 11, ④The administrator user accesses the network security device with the TOKEN. ⑤The network security device extracts the information in the TOKEN and verifies the user information. ⑤After the network security device verifies that the target information is correct, it sends the signature part of the TOKEN to the integrated management platform; the integrated management platform performs signature verification and returns the verification result to the network security device. ⑤The network security device confirms that the token is valid and returns an "ok" message to the integrated management platform; based on the "ok", the integrated management platform redirects the administrator user to the network security device management interface.

[0072] If the single sign-on type is the second type of token login (TOKEN issued to the user by the security device), the specific processing procedures for steps S202, S204, and S206 are as follows:

[0073] In step S202, for the user to log in to the network security device based on the proxy login program and input the account and password from the integrated platform, the network security device issues a TOKEN with a certain validity period for the user.

[0074] In step S204, after the administrator obtains the TOKEN, if SSO is required, the platform directly redirects the user to the network security device.

[0075] In step S206, the user can access the security device by virtue of the TOKEN. The network security device invokes the token library resources and user library resources corresponding to the SPI, verifies that the user TOKEN is valid, and permits the access.

[0076] Figure 9 It is the sequence diagram of the second type of token single sign-on, as Figure 9 shown. The main processes of this sequence diagram include: ①The administrator user logs in to the integrated management platform based on password authentication. ②The administrator user clicks the management button to access the network security device. ③Since the administrator user cannot directly single sign on to the network security device at this time, the network security device returns the information to the integrated management platform: TOKEN is missing. ④The integrated management platform jumps to the proxy login program. ⑤The administrator user inputs the username and password for logging in to the network security device in the proxy login program of the integrated management platform. ⑥The integrated management platform encrypts the username and password based on salted MD5 and sends the encryption result to the network security device. ⑦The network security device verifies the encrypted username and password. If the verification result indicates that it is correct, the network security device generates an administrator user single sign-on TOKEN and issues the TOKEN to the user. ⑧The administrator user can then access the network security device according to the TOKEN next time without re-authentication.

[0077] If the single sign-on type is the third type of token login (TOKEN issued by the security device to the management platform), the specific processing procedures for steps S202, S204, and S206 are as follows:

[0078] In step S202, corresponding configuration items (regarding the relevant requirements and information of the docking platform and TOKEN) can be newly added to the network security device in advance.

[0079] In step S204, after the administrator logs in to the integrated management platform, if SSO is required, the platform requests a TOKEN from the network security device, and the network security device issues a TOKEN to the platform.

[0080] In step S206, if the user needs to access the network security device, the platform sends its own TOKEN to the network security device. If the verification passes, the user is redirected to the device management interface.

[0081] Figure 10 is the sequence diagram of the third type of token single sign-on. As Figure 10 shown, the main processes of this sequence diagram include: ① The administrator user logs in to the network security device through the account password in advance. ② The administrator user newly creates a configuration item for the integrated management platform on the network security device in advance. Among them, the configuration item includes the basic information of the integrated management platform regarding single sign-on, such as the unified resource locator URL of the single sign-on request, the range of source IPs, the administrator user information, the TOKEN validity period, whether TOKEN renewal is allowed, etc. ③ The administrator user logs in to the integrated management platform through password authentication. ④ The administrator user clicks the button to request SSO access to the network security device. ⑤ The platform requests a TOKEN from the network security device; ⑥ The network security device determines whether to issue a TOKEN with a certain validity period to the integrated management platform based on the content in the configuration item. ⑦ If permission is granted to issue, the network security device issues a TOKEN to the integrated management platform. ⑧ When the user performs single sign-on, if the platform holds the TOKEN, the platform requests the security device to verify the TOKEN and carries the user information. ⑨ The platform verifies the TOKEN and confirms the user information. ⑩ If the TOKEN is legal and the user information is correct, the device returns an ok message to the platform. The platform redirects the administrator user to the network security device management interface.

[0082] In the case where the target single sign-on type is determined to be token login, including the first type of token login, the second type of token login, and the third type of token login, the PAM framework API and SPI functions of the network security device and their implementations are as shown in the following table:

[0083]

[0084]

[0085] In some alternative embodiments of the present application, the TOKEN in the first type of token, the second type of token, and the third type of token can all adopt the form of JSON Web Token (JWT). Specifically, Figure 11 is the structural diagram of the basic form of JWT. As Figure 11 shown, in addition to containing the identifier of JWT, the header of JWT also indicates the signature algorithm (the default is SHA256); the payload part of JWT usually contains some important information. For example, if JWT is a TOKEN issued by a network security device to an administrator user, the payload contains information such as the username, user type, and user permissions. At the same time, the payload can also contain the validity period of JWT. The signature part of JWT is signed by the issuer of the TOKEN. When the signature algorithm is a digest algorithm such as SHA256 or MD5, the issuer adds salt during encryption, which is also called secret. The secret is secretly stored by the issuer, so that JWT can only be verified by the issuer and the information in the header and payload cannot be tampered with. In some embodiments of the present application, the private content contained in the TOKEN and the encryption algorithm adopted by the signature part of the TOKEN can be different in different single sign-on types.

[0086] In some embodiments of the present application, the traditional CAS login scheme is also compatible. When the environment where the integrated management platform and the network security device are located has a CAS server, the verification of single sign-on SSO can be completed based on the CAS server.

[0087] Figure 12 is the timing flowchart of the CAS SSO scheme. The CAS scheme is a mature scheme. In the figure, TGC represents TicketGranted Cookie (TGC). The user sets this cookie locally in the browser, and the server (integrated management platform or network security device) can match the corresponding service ticket according to this cookie, so as to go to the CAS server to verify the legitimacy of the user's login status. In the above figure, the integrated management platform and the network security device share a CAS server. Both service tickets are issued by the CAS server, and all verification work is completed by the CAS server. The security device and the integrated management platform both act as CAS clients to provide services.

[0088] In some embodiments of the present application, the network security device can complete the verification of single sign-on SSO based on the CAS server. The API, SPI implementation, and functions corresponding to the CAS single sign-on type are shown in the following table:

[0089]

[0090] In the embodiments of the present invention application, the administrator single sign-on types may include: certificate type, independent password type, three token types, and CAS type. The administrator user can select different types of SSO according to requirements, and support the addition and extension of login types.

[0091] Figure 13 It is a business processing flowchart of multiple types of login schemes, such as Figure 13 shown. This process mainly includes: judging whether to log in through the front end. If so, further judge the request type of the login through the background; if the request type is a single sign-on request, further judge the single sign-on type; if it is a TOKEN single sign-on type and a TOKEN is carried, verify the TOKEN and the user information in the TOKEN; if it is a TOKEN single sign-on type and no TOKEN is carried, judge whether to issue a TOKEN according to the TOKEN request object; if it is a certificate / independent password login type, verify the certificate / independent password and user information; if it is a CAS login type, judge whether there is a ticket. If there is, verify the ticket, otherwise generate a service and redirect to CAS.

[0092] Figure 14 It is a structure diagram of the overall framework storage, such as Figure 14 shown. This structure diagram mainly includes the following three parts:

[0093] (1) SSO type library. During the implementation process in C / C++ language, corresponding macros are defined in the SSO type library. In the later stage, the SSO type can be expanded by adding macro definitions. Certificates, independent passwords, TOKENs, and CAS are the first-level classifications of SSO types. On this basis, they can be further divided into multiple subtypes according to the requirements of different platforms. Among them, the SSO single sign-on of the certificate type corresponds to the certificate library. The certificate library stores the certificates for the firewall to handle different services, which can be either the firewall's own certificate or the certificate provided by the docking platform (which can be used for further mutual verification). Similarly, the independent password SSO type corresponds to the password library; the TOKEN SSO type corresponds to the TOKEN library, and each item in the TOKEN library should contain information such as the generation time, validity period, TOKEN content, and secret of the TOKEN; the CAS SSO type corresponds to the CAS library, and each item in the CAS library table contains the service provided by the security device to the user and the ticket verification URL of the CAS server.

[0094] (2) Docking platform library. The relationship between the docking platform and the SSO type is 1:1 or n:1, that is, one type of platform uses one form of SSO, while one type of SSO can be used for multiple platforms.

[0095] (3) User library. The user library is used to store administrator user information and is also used for identity recognition. Each item in the user library table contains the username, management permissions, access permissions, and so on.

[0096] In some embodiments of the present application, Figure 15 is a structural diagram for implementing unified authentication and management functions based on the PAM framework. As Figure 15 shown, in the functional structure diagram: the front-end page of the security device management is responsible for interacting with the docking platform, and php is responsible for parsing the interaction request and sending the relevant parameters of the request to the access module; the access module sends the relevant parameters of the message to the PAM module for verification; the PAM module completes the functions of unified authentication and management through password algorithm functions, API libraries, and SPI libraries.

[0097] In the embodiments of the present invention, by calling a set of APIs provided by the PAM module, the purpose of SSO authentication and management is achieved. The above authentication and management both start with pam_start() and end with pam_end(). Among them, pam_start() is used to input parameters such as the application name, username, conversation function, and pam handle. Since the access module in the embodiments of the present application is responsible for interacting with the front end, the conversation function can be empty.

[0098] In the embodiments of the present invention, by calling a set of SPIs provided by the PAM module, the specific implementation of the identity authentication and management functions is completed. For example, calling the API pam_authenticate to implement the SSO authentication function, and using the SPI pam_sm_authenticate() corresponding to the API pam_authenticate to implement the specific authentication process. Before calling the API, use pam_set_item() to set the type of SSO authentication, and obtain the SS O type through pam_get_item() when implementing the SPI, and then perform different processing for different SSOs.

[0099] Figure 16 is a module relationship diagram of a login device according to an embodiment of the present application. As Figure 16 shown, the device includes the following modules:

[0100] Access module 160, which is used for the user to access the network security device based on any of the above single sign-on types after logging in to the integrated management platform. The access module senses the user request action and performs data interaction with the background program.

[0101] The verification processing module 162 is used to call the login interface corresponding to the target single sign-on type from the set of login interfaces (APIs) provided by the PAM framework, and perform verification processing on the login request information of the administrator user based on the SPI to obtain the target verification result. This module corresponds to Figure 15 the described PAM module.

[0102] The resource allocation module 164 is used to assist the above verification process in resource allocation and resource storage, corresponding to Figure 14 the described various resource libraries.

[0103] In this device, the access module 160 is used for the user to access the network security device based on any of the above single sign-on types after logging in to the integrated management platform. The access module senses the user request actions and performs data interaction with the background program; the verification processing module 162 is used to call the login interface corresponding to the target single sign-on type from the set of login interfaces (APIs) provided by the PAM framework, and perform verification processing on the login request information of the administrator user based on the SPI to obtain the target verification result. This module corresponds to Figure 15 the described PAM module; the resource allocation module 164 is used to assist the above verification process in resource allocation and resource storage, corresponding to Figure 14 the described various resource libraries, achieving the purpose of performing different processing on different single sign-on SSOs, thereby realizing a single sign-on framework with strong generality, high feasibility, and configurability for multiple access types, and further solving the technical problem that the prior art cannot provide compatibility verification for multi-type single sign-on SSO solutions. In addition, this solution also supports extension and maintenance.

[0104] According to another aspect of the embodiments of the present application, a non-volatile storage medium is further provided. The content stored in the medium includes a program for implementing the above functions, a user library required for single sign-on, a docking platform library, and a sub-resource library for a certain single sign-on type. The sub-resource library for the single sign-on type may include the following content: a certificate library for the certificate SSO type, a password library for the independent password SSO type, a token library for the token SSO type, and a CAS library for the traditional CAS single sign-on type.

[0105] According to another aspect of the embodiments of the present application, a dedicated processor unit for the device is further provided. The dedicated processor unit executes the relevant program instructions for the single sign-on function. Among them, when the program runs, it executes any of the above single sign-on verification and overall management methods to provide single sign-on access for the management of the network security device.

[0106] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.

[0107] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0108] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.

[0109] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0110] In addition, the functional units in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0111] If the above-mentioned integrated units are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks or optical discs and other various media that can store program codes.

[0112] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A management method for single sign-on verification and coordination based on the PAM framework, characterized in that, the method verifies and processes various types of single sign-on methods based on the Pluggable Authentication Module (PAM) framework. After the user logs in to the integrated management platform, it provides access to network security device management for the user, avoiding secondary authentication, including: Determining the target single sign-on type of the administrator user; Invoking the target login interface corresponding to the target single sign-on type from the set of login interfaces provided by the PAM framework, where the target login interface corresponds to a set of Application Programming Interfaces (APIs) in the PAM framework; After the target login interface is invoked, use the SSO type library, docking platform library, and user library to uniformly allocate resources, and complete the management and verification functions based on the Service Provider Interface (SPI) of the PAM framework to obtain the target verification result; where the Service Provider Interface (SPI) corresponds one-to-one with the Application Programming Interface (API); The method further includes: when the target single sign-on type of the administrator user is the certificate type, use the certificate as a credential to construct a trust chain among the integrated management platform, the user, and the network security device. The process of constructing the trust chain includes: the management platform installs the certificate of the network security device, and the network security device secretly stores its certificate private key in the certificate library; after the administrator user logs in to the management platform, the management platform encrypts the administrator user information using the certificate public key; the SPI corresponding to the network security device calls the resources of the network security device certificate library and the user library, decrypts the information of the administrator user based on the certificate private key to obtain the decryption result, and verifies the information of the administrator user based on the decryption result.

2. The method according to claim 1, characterized in that, it includes: when the target single sign-on type of the administrator user is the independent password type, use the independent password as a credential to construct a trust chain among the integrated management platform, the user, and the network security device. The process of constructing the trust chain includes: Presetting the independent passwords of the management platform and the network security device; After the administrator user logs in to the management platform, the management platform performs a digest operation on the independent password and the administrator user information using the salted MD5 digest algorithm; The SPI corresponding to the network security device calls the resources of the password library and the user information library, verifies the independent password to determine the legitimacy of the integrated management platform identity, and verifies the information of the administrator user to determine the legitimacy of the user identity.

3. The method according to claim 2, characterized in that, it includes: when the target single sign-on type of the administrator user is the token (TOKEN) type, use the token as a credential to construct a trust chain among the integrated management platform, the user, and the network security device; Among them, the token types are divided into three categories, including: TOKEN issued to users based on the management platform, TOKEN issued to users based on the network security device, and TOKEN issued to the management platform based on the network security device. Finally, the SPI corresponding to the network security device calls the token library resources and user library resources to complete the authentication.

4. The method according to claim 3, characterized in that, the target single sign-on type at least includes: the certificate type, the independent password type, the three types of token types, and the CAS type based on the traditional central authentication server. The above types can be flexibly selected according to different trust levels and different application scenarios of nodes, and new single sign-on types can be quickly formulated, new credentials can be used, or new trust chain nodes can be added.

5. A single sign-on coordination device, characterized in that, the device verifies and processes various types of single sign-on methods based on the pluggable authentication module PAM framework, so as to achieve the purpose that after the user logs in to the integrated management platform, the user can directly manage the network security device without secondary authentication, including: An access module, which is used for the user to access the network security device based on any single sign-on type after logging in to the integrated management platform. The access module senses the user request action and conducts data interaction with the background program; A verification processing module, which is used to call the login interface corresponding to the target single sign-on type from the set of login interfaces API provided by the PAM framework, and verify and process the login request information of the administrator user based on the SPI to obtain the target verification result; A resource allocation module, which is used to assist the above verification process in resource allocation and resource storage; The single sign-on coordination device is also used to use the certificate as a credential to construct a trust chain among the integrated management platform, the user, and the network security device when the target single sign-on type of the administrator user is the certificate type. Among them, the process of constructing the trust chain includes: the management platform installs the certificate of the network security device, and the network security device secretly stores its own certificate private key in the certificate library; after the administrator user logs in to the management platform, the management platform encrypts the administrator user information with the certificate public key; the SPI corresponding to the network security device calls the network security device certificate library resources and user library resources, decrypts the administrator user's information based on the certificate private key to obtain the decryption result, and verifies the administrator user's information based on the decryption result.

6. A non-volatile storage medium, characterized in that, the content stored in the medium includes a functional program corresponding to any one of claims 1 to 4, a user library required for single sign-on, a docking platform library, and a sub-resource library of a certain single sign-on type. The sub-resource library of the single sign-on type includes the following content: a certificate library of the certificate SSO type, a password library of the independent password SSO type, a token library of the token SSO type, and a CAS library of the traditional CAS single sign-on type.

7. A dedicated processor unit of a device, characterized in that, The processor unit is used to run a program instruction set, wherein, when the program runs, it executes the method for single sign-on verification and overall management based on the PAM framework according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Single sign-on method and device based on NeoKylin operation system

    CN107070902A