Password maintenance method, device, and electronic device

By storing user operation permission data on the password maintenance platform and encrypting and processing it, and synchronizing server password modification information in real time, the problem of inefficient password modification notification in multi-user shared servers is solved, and efficient and secure password maintenance is achieved.

CN115225253BActive Publication Date: 2025-08-29CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210734839.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-16
Publication Date
2025-08-29
Estimated Expiration
2042-06-16

AI Technical Summary

Technical Problem

In the prior art, after the login password of multiple users share the same server is modified, the notification efficiency is low and the real-time performance is poor, which easily leads to other users being unable to log in normally.

Method used

The password maintenance platform stores user operation permission data, obtains the encryption key to encrypt the modified operation password, determines the user with operation permission, and synchronizes the password modification information in real time.

Benefits of technology

Real-time synchronization of passwords shared by multiple people has been achieved, which improves notification efficiency, avoids omissions, and improves password security and timeliness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115225253B_ABST
    Figure CN115225253B_ABST
Patent Text Reader

Abstract

The present application discloses a password maintenance method, which belongs to the field of communication technology and can improve the real-time synchronization of password maintenance information. The method includes: based on the data entry operation performed on the password maintenance platform, storing user operation permission data on the password maintenance platform; based on the password modification operation performed by the first user on the target server after logging into the password maintenance platform, obtaining an encryption key and a modified operation password; encrypting the modified operation password based on the encryption key to obtain a ciphertext operation password; based on the user operation permission data, determining a second user who has operation permission on the target server; based on the ciphertext operation password, synchronizing the password modification information of the target server to the second user. This method is based on pre-collected user information that shares the operation password of the same server, and synchronizes the operation password modification information of the server to the relevant users in real time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a password maintenance method, device, electronic device, and computer-readable storage medium. Background Art

[0002] In scenarios where multiple users share a server login password, if one user changes the server login password, it is necessary to promptly notify other users to avoid being unable to log in to the server due to not knowing the changed password. To ensure password security, manual notification is often used to inform other users who share the same server login password of the changed password.

[0003] It can be seen that the password notification method in the prior art is inefficient and has low real-time performance. Summary of the Invention

[0004] The embodiments of the present application provide a password maintenance method and device, which facilitates the real-time synchronization of password maintenance information shared by multiple people and improves the efficiency of password maintenance.

[0005] In a first aspect, an embodiment of the present application provides a password maintenance method, comprising:

[0006] Based on the data entry operation performed on the password maintenance platform, a database table is stored in the password maintenance platform, wherein the database table includes: user operation authority data;

[0007] Based on a password modification operation performed by the first user on the target server after logging into the password maintenance platform, obtaining an encryption key and an operation password modified by the password modification operation;

[0008] Encrypting the modified operation password based on the encryption key to obtain a ciphertext operation password;

[0009] Determining a second user who has operation authority on the target server based on the user operation authority data;

[0010] Based on the ciphertext operation password, the password modification information of the target server is synchronized to the second user.

[0011] In a second aspect, an embodiment of the present application provides a password maintenance device, comprising:

[0012] A data acquisition module is configured to store a database table in the password maintenance platform based on a data entry operation performed on the password maintenance platform, wherein the database table includes: user operation authority data;

[0013] A password modification module, configured to obtain an encryption key and an operation password modified by the password modification operation based on a password modification operation performed by the first user on the target server after logging into the password maintenance platform;

[0014] A password encryption processing module, configured to encrypt the modified operation password based on the encryption key to obtain a ciphertext operation password;

[0015] A second user determining module, configured to determine a second user having operation authority on the target server based on the user operation authority data;

[0016] A password modification information synchronization module is used to synchronize the password modification information of the target server to the second user based on the ciphertext operation password.

[0017] In a third aspect, an embodiment of the present application further discloses an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the password maintenance method described in the embodiment of the present application when executing the computer program.

[0018] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps of the password maintenance method disclosed in the embodiment of the present application are performed.

[0019] The password maintenance method disclosed in the embodiment of the present application stores a database table on the password maintenance platform based on data entry operations performed on the password maintenance platform, wherein the database table includes: user operation permission data; based on a password modification operation performed by a first user on a target server after logging into the password maintenance platform, obtaining an encryption key and an operation password modified by the password modification operation; encrypting the modified operation password based on the encryption key to obtain a ciphertext operation password; based on the user operation permission data, determining a second user who has operation permission on the target server; based on the ciphertext operation password, synchronizing the password modification information of the target server to the second user, thereby facilitating real-time synchronization of maintenance information of passwords shared by multiple people.

[0020] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0022] Figure 1 This is one of the flow charts of the password maintenance method in the embodiment of the present application;

[0023] Figure 2 This is one of the flow charts of step 120 in the password maintenance method in the embodiment of the present application;

[0024] Figure 3 This is the second flow chart of step 120 in the password maintenance method in the embodiment of the present application;

[0025] Figure 4 This is the second flowchart of the password maintenance method in the embodiment of the present application;

[0026] Figure 5 This is one of the schematic diagrams of the password maintenance device in the embodiment of the present application;

[0027] Figure 6 This is the second structural diagram of the password maintenance device in the embodiment of the present application;

[0028] Figure 7 A block diagram schematically shows an electronic device for executing the method according to the present application; and

[0029] Figure 8 The figure schematically shows a storage unit for storing or carrying a program code for implementing the method according to the present application. DETAILED DESCRIPTION

[0030] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0031] The password maintenance method disclosed in the embodiments of this application is applicable to scenarios where the operation password of a server is shared with multiple people, wherein the operation password includes but is not limited to: a login password and a configuration password.

[0032] Example 1

[0033] like Figure 1 As shown, a password maintenance method disclosed in an embodiment of the present application includes: steps 110 to 150.

[0034] Step 110: Based on the data entry operation performed on the password maintenance platform, a database table is stored in the password maintenance platform, wherein the database table includes: user operation authority data.

[0035] In some embodiments of the present application, the data entry operation includes: importing an Excel table data template and executing a data writing tool.

[0036] The user operation authority data includes: the association relationship between the user and the province, and the user's operation authority for each server deployed in each province, and the users include: a first user and a second user.

[0037] The password maintenance platform collects the association between the user and the province based on the data entered in the data entry operation, as well as the user's operating permissions for each server deployed in each province, and stores the collected association between the user and the province, as well as the user's operating permissions for each server deployed in each province as user operating permission data in the local database.

[0038] In some embodiments of the present application, the password maintenance platform may also generate user data based on the data entered during the data entry operation and store the generated user data in a database table. The user data may include: user identification (such as the user's registered account on the password maintenance platform), information receiving method, and other information.

[0039] In some embodiments of the present application, the password maintenance platform may also generate server data based on the data entered during the data entry operation, and store the generated server data in a database table. The server data may include information such as a server identifier (such as an IP address), a deployment province, an encryption operation password, and an expiration date of the operation password.

[0040] In some embodiments of the present application, a data entry operation can be performed on the password maintenance platform through a data writing tool or by importing an Excel table data template. The password maintenance platform obtains the data entered by the data entry operation based on the data writing tool, or based on the data entry operation performed by importing an Excel table data template, and updates the user operation permission data stored by the password maintenance platform based on the obtained entry data. In some embodiments of the present application, the data input by the data entry operation includes any one or more of the following: user data (such as the user's identification on the password maintenance platform, the preset information receiving method, etc.), province data (such as the province name, etc.), server data (such as the server's IP address, the server's operation password, the operation password expiration date, etc.), the user's association data with the province (such as the user's associated province list), the user's operation permission data for the server (such as the list of servers for which the user has operation permission), and the deployment relationship data between the server and the province (such as the server's deployment province).

[0041] In some embodiments of the present application, based on the data entry operation performed on the password maintenance platform, a database table is stored in the password maintenance platform, wherein the database table includes: user operation permission data, further including: obtaining information about the province associated with the user, the server on which the user has operation permission, and the province where the corresponding server is deployed; based on the obtained information about the province, the server, and the province where the corresponding server is deployed, the user operation permission data stored in the password maintenance platform is updated. For example, the association relationship between the first user u1 and provinces s1 and s2 is stored, as well as the servers deployed in province s1, the servers on which the first user u1 has operation permission, and the servers deployed in province s2, the servers on which the first user u1 has operation permission.

[0042] In some embodiments of the present application, a user can enter the province associated with the user, the information of the server that the user has the permission to operate, and the province where the corresponding server is located. For example, after the user logs in to the password maintenance platform, the user enters the province associated with the user on the data entry page of the password maintenance platform, and enters the information of the server deployed in each province that the user has the permission to operate. In this way, the data entry page of the password maintenance platform can obtain the province associated with the user, the information of the server that the user has the permission to operate, and the province where the corresponding server is located.

[0043] In other embodiments of the present application, the user may also enter the province associated with the user and other users, information about the server with operation authority, and the province where the corresponding server is located. For example, after the user logs in to the password maintenance platform, the user may import a user data file in a preset format through the data entry portal of the password maintenance platform, so that the password maintenance platform can parse the user data file and obtain the province associated with each user recorded in the user data file, information about the server with operation authority for each user, and the province where the corresponding server is located.

[0044] Step 120: Based on the password modification operation performed by the first user on the target server after logging into the password maintenance platform, an encryption key and an operation password modified by the password modification operation are obtained.

[0045] In an embodiment of the present application, users who wish to maintain server passwords through the password maintenance platform must pre-register an account on the password maintenance platform and establish an association between the user's registered account and the user's user rights data. For example, in the data entered during a data entry operation, the user's registered account on the password maintenance platform is represented by the user account, i.e., the first user is represented by the first user account, and the second user is represented by the second user account. Thus, after logging into the password maintenance platform using the pre-registered account, the user can perform password modification operations on the servers for which the user has rights.

[0046] In some embodiments of the present application, the user first needs to log in to the password maintenance platform. After the user logs in, the password maintenance platform displays a list of servers deployed in a province associated with the user for which the user has operation permissions, or displays a list of servers deployed in all provinces associated with the user for which the user has operation permissions. The user then selects a server from the displayed servers, i.e., the target server, and then performs a password change operation on the target server.

[0047] In some embodiments of the present application, the password maintenance platform can set a corresponding password modification operation entry for each displayed server. After the user triggers the password modification operation entry, the password editing interface is further displayed to facilitate the user to edit the modified operation password in the password editing interface.

[0048] In other embodiments of the present application, after a user selects a target server, the password maintenance platform may further display information about the target server by redirecting the user to a detailed interface displaying the target server. The displayed target server information includes the target server's operation password. Furthermore, the interface may include a corresponding password modification entry. After the user triggers the password modification entry, a password edit box may be displayed, allowing the user to modify the operation password within the password edit box.

[0049] In other embodiments of the present application, the password maintenance platform may also use other interactive processes to interact with the user, so that the user can perform a password modification operation on the target server on the password maintenance platform.

[0050] After the user completes the password change and submits it, the password maintenance platform can obtain the user's modified operation password through the password editing interface.

[0051] In some embodiments of the present application, in order to protect the security of the operation password, the operation password of the server can be stored in an encrypted storage manner. For example, the modified operation password is encrypted with an encryption key to obtain a ciphertext operation password, and the ciphertext operation password is stored. In some embodiments of the present application, the encryption key can be automatically generated by the password maintenance platform according to preset rules, or it can be set by the user. For example, the encryption key includes: an encryption key obtained by randomly combining the deployment province information of the target server and a preset number. In this way, the encryption keys of the operation passwords of the servers in each province are different, which helps to improve the security of the operation passwords.

[0052] When the encryption key is automatically generated by the password maintenance platform, in some embodiments of the present application, the password maintenance platform can obtain the encryption key when obtaining the user's modified operation password, or it can obtain the encryption key when the user starts to modify the operation password. This application does not limit this.

[0053] When the encryption key is the encryption key set by the user, the password maintenance platform can obtain the encryption key set by the user when obtaining the operation password modified by the user.

[0054] Step 130: encrypt the modified operation password based on the encryption key to obtain a ciphertext operation password.

[0055] After obtaining the encryption key and the modified operation password, the password maintenance platform encrypts the modified operation password using the obtained encryption key to obtain the ciphertext operation password. In some embodiments of the present application, encrypting the modified operation password based on the encryption key to obtain the ciphertext operation password includes: performing MD5 (Message-Digest Algorithm 5) encryption on the modified operation password based on the encryption key to obtain the ciphertext operation password.

[0056] Step 140: Determine a second user who has operation authority for the target server based on the user operation authority data.

[0057] Next, the password maintenance platform uses the target server as a query value to search pre-stored user operation authority data to obtain all second users who have operation authority on the target server, wherein the second user is a registered user of the password maintenance platform different from the first user.

[0058] In some embodiments of the present application, the user operation permission data can be stored in the form of a correspondence between (user ID, province number, server number). In this way, by traversing the server number in the above correspondence, the corresponding user ID can be obtained, that is, the user who has the operation permission for the specified server is determined. In other embodiments of the present application, the user operation permission data can also be stored in other forms, and the embodiments of the present application do not limit the storage method of the user operation permission data. Accordingly, in the embodiments of the present application, the specific implementation method of determining the second user who has the operation permission for the target server based on the user operation permission data is also not limited.

[0059] Step 150: Synchronize the password modification information of the target server to the second user based on the ciphertext operation password.

[0060] Afterwards, the password maintenance platform synchronizes the password modification information of the target server to all the second users found, so that other users who have operation authority on the target server can be informed of the password modification status of the target server in a timely manner.

[0061] In some embodiments of the present application, synchronizing the password modification information of the target server to the second user based on the ciphertext operation password may include at least one or two of the following methods.

[0062] First, the database table also includes: server data, based on the encrypted operation password, updating the operation password of the target server in the server data, so that the second user can learn the encrypted operation password of the target server by logging into the password maintenance platform.

[0063] For example, the password maintenance platform updates the encrypted operation password of the target server in the currently stored server data to the encrypted operation password generated by encrypting the operation password modified by the first user. In this way, when a second user logs into the password maintenance platform and queries for servers for which the second user has operation permissions, the password maintenance platform will display the encrypted operation password modified and stored by the first user when displaying information about the target server to the second user.

[0064] In some embodiments of the present application, when the encryption key used to generate the ciphertext operation password is a key generated by the password maintenance platform according to preset rules, the password maintenance platform can only update and store the ciphertext operation password; when the encryption key used to generate the ciphertext operation password is a key customized by the first user, the password maintenance platform also needs to store the encryption key used to generate the ciphertext operation password in the password maintenance platform, so that the password maintenance platform can decrypt the ciphertext operation password according to the encryption key of the ciphertext operation password.

[0065] In some embodiments of the present application, the password maintenance platform also stores a target server's operation password modification log. The operation password modification log may include information such as the password modification time, the modifying user, and the modified ciphertext operation password. After the second user logs in to the password maintenance platform, they can query the operation password modification log for the server (e.g., the target server) for which they have operation authority, facilitating server password maintenance.

[0066] The second method is to send a notification message to the second user indicating that the operation password of the target server has been modified.

[0067] In some embodiments of the present application, the database table also includes: user data, and the notification information sent to the second user to indicate that the operation password of the target server has been modified includes: obtaining the information receiving method preset by each second user according to the user data; sending the notification information to the corresponding second user through the information receiving method to indicate that the operation password of the target server has been modified, wherein the notification information includes one or more of the following information: the ciphertext operation password, the IP address and / or province of the target server, the password modification time, and the password modification user.

[0068] In some implementations of this application, when a user performs a data entry operation, the password maintenance platform can collect user data based on the data entered in the data entry operation and store the user data. In an embodiment of this application, the user data can be stored in a database table in the form of an independent data table, or can be stored in a database table as part of the user operation permission data. This application does not limit the storage format of the user data. In this way, the password maintenance platform can obtain the user data of a specified second user by retrieving the user data, for example, obtaining the information reception method preset by the second user.

[0069] In some embodiments of the present application, the information receiving method may be sending an email to a designated email address, sending a text message to a designated phone number, etc., which is not limited in the embodiments of the present application.

[0070] Furthermore, the password maintenance platform generates notification information based on one or more pieces of information, such as the ciphertext operation password, the IP address and / or province of the target server, the password modification time, and the password modification user, and sends the notification message to the second user who has operation authority on the target server via the information receiving method. For example, the password maintenance platform generates notification information based on the ciphertext operation password, the IP address and province of the target server, the password modification time, and the password modification user, and sends the notification message to the second user via the email address preset by the second user, so as to promptly inform the second user of the password maintenance status of the target server.

[0071] In some embodiments of the present application, after sending a notification message to the second user indicating that the operation password of the target server has been modified, the password maintenance platform further determines the sending status of the notification message. If the notification message fails to be sent, the platform repeats the message a preset number of times (e.g., three times) so that the second user can promptly learn of the password maintenance status of the target server.

[0072] In some embodiments of the present application, Figure 2 As shown, in the aforementioned step 120, based on the password modification operation performed by the first user on the target server after logging into the password maintenance platform, the encryption key and the operation password modified by the password modification operation are obtained, further including: sub-steps 1201 to 1203.

[0073] Sub-step 1201: After a first user successfully logs into the password maintenance platform, information of each server associated with the first user is obtained.

[0074] The servers associated with the first user are selected from servers for which the first user has operation authority.

[0075] Sub-step 1202: Display the information of each server to the first user.

[0076] Among them, the servers associated with the first user can be servers deployed in various provinces for which the first user has operation authority, or can be servers deployed in designated provinces for which the first user has operation authority.

[0077] In some embodiments of the present application, after the first user successfully logs into the password maintenance platform, information of each server associated with the first user is obtained, including: based on the first user successfully logging into the password maintenance platform, obtaining the province associated with the first user according to the user operation authority data stored in the password maintenance platform; among the servers deployed in the province associated with the first user, obtaining information of the servers on which the first user has operation authority according to the user operation authority data.

[0078] For example, after the first user successfully logs into the password maintenance platform, the password maintenance platform first searches the pre-stored user operation permission data for the province associated with the first user, and then further obtains the servers in each province for which the first user has operation permissions, and displays the obtained information of these servers to the first user in the form of a list.

[0079] In some embodiments of the present application, after the first user successfully logs into the password maintenance platform, information of each server associated with the first user is obtained, including: based on the first user successfully logging into the password maintenance platform, according to the user operation permission data stored in the password maintenance platform, obtaining the provinces associated with the first user; displaying the list of provinces associated with the first user to the first user; based on the first user's selection operation for the provinces in the list, according to the user operation permission data, obtaining information of the servers for which the first user has operation permissions in the servers deployed in the provinces targeted by the selection operation.

[0080] For example, after the first user logs in to the password maintenance platform, the password maintenance platform first searches the pre-stored user operation permission data for the province associated with the first user and displays a list of the retrieved provinces to the first user. The user can select a displayed province to further view the servers deployed in the province for which the first user has operation permissions. After the first user selects a province in the province list, the password maintenance platform further searches for servers deployed in the province for which the first user has operation permissions, thereby obtaining servers deployed in the specified province for which the first user has operation permissions, and displays the information of the obtained servers to the first user in the form of a list.

[0081] Sub-step 1203: acquiring an encryption key and an operation password modified by the password modification operation based on the password modification operation performed by the first user on the displayed target server.

[0082] Next, the first user may select a server, ie, a target server, from the displayed server list and perform a password modification operation on the target server.

[0083] In some embodiments of the present application, the server information displayed to the first user includes: a ciphertext operation password of the server. After the step of displaying the information of each server to the first user, the step further includes: decrypting and displaying the ciphertext operation password based on a display-plaintext switching operation for the ciphertext operation password.

[0084] In some embodiments of the present application, based on the display plaintext switching operation for the ciphertext operation password, the ciphertext operation password is decrypted and displayed, including: based on the display plaintext switching operation for the ciphertext operation password, obtaining a first encryption key stored in association with the ciphertext operation password in the password maintenance platform, and decrypting the ciphertext operation password using a decryption key corresponding to the first encryption key to obtain a plaintext password corresponding to the ciphertext operation password.

[0085] For example, for a ciphertext operation password encrypted with a user-defined encryption key, the password maintenance platform needs to store the ciphertext operation password and the encryption key in association. This way, when decrypting the ciphertext operation password, the password maintenance platform can obtain the corresponding decryption key using the encryption key stored in association with the ciphertext operation password, and then use the decryption key to decrypt the ciphertext operation password.

[0086] In some embodiments of the present application, based on the display plaintext switching operation for the ciphertext operation password, the ciphertext operation password is decrypted and displayed, including: based on the display plaintext switching operation for the ciphertext operation password, obtaining a second encryption key corresponding to the province where the server is located, and decrypting the ciphertext operation password using the decryption key corresponding to the second encryption key to obtain the plaintext password corresponding to the ciphertext operation password.

[0087] For example, for the ciphertext operation password obtained by encrypting the encryption key generated by the password maintenance platform according to the preset rules, when decrypting the ciphertext operation password, the password maintenance platform can generate a decryption key according to the rules corresponding to the preset rules, and then use the decryption key to decrypt the ciphertext operation password.

[0088] In some embodiments of the present application, the server information also includes: the expiration date of the operation password, such as Figure 3 As shown, after the first user successfully logs into the password maintenance platform and obtains information of each server associated with the first user, the process further includes: sub-step 1204 and sub-step 1205.

[0089] Sub-step 1204: determining whether each server associated with the first user meets a preset password maintenance condition based on the expiration date.

[0090] In some embodiments of the present application, password maintenance conditions for operation passwords can be pre-set. For example, a condition can be set that the remaining expiration time of the operation password is less than or equal to 7 days, which satisfies the password maintenance platform's maintenance prompt. During the operation of the password maintenance platform, after the user logs in to the password maintenance platform, the current system time of the password maintenance platform and the expiration date of the operation password of each server are compared to determine the remaining valid days of the operation password of each server. When the remaining valid days of a certain operation password are less than or equal to 7 days, the corresponding server is considered to meet the preset password maintenance conditions.

[0091] In response to the preset password maintenance condition being met, jump to sub-step 1205 ; otherwise, jump to sub-step 1202 .

[0092] If it is determined that none of the servers for which the first user has operation authority meets the preset password maintenance conditions, the obtained server list is directly displayed. If it is determined that there is a server for which the first user has operation authority that meets the preset password maintenance conditions, the process proceeds to the step of sending a first password maintenance reminder to the first user.

[0093] Sub-step 1205: Displaying first password maintenance reminder information to the first user, where the first password maintenance reminder information is used to indicate that the operation password of the corresponding server needs to be maintained in a timely manner.

[0094] In some embodiments of the present application, when it is determined that among the servers for which the first user has operation authority, there is a server that meets the preset password maintenance conditions, the first user can be notified that the operation password of the corresponding server needs to be maintained in a timely manner by displaying a password maintenance prompt message on the current interface of the password maintenance platform. For example, the first password maintenance prompt message may include: the IP address of the server that meets the preset password maintenance conditions, the province where it is deployed, the expiration date of the operation password, and other information. In this way, the first user can maintain the operation password of the server in a timely manner.

[0095] In some embodiments of the present application, the database table further includes: server data and user data, wherein the server data includes: the expiration date of the operation password of each server, such as Figure 4As shown, the data entry operation performed on the password maintenance platform, after the password maintenance platform stores the database table, further includes: steps 160 to 190.

[0096] Step 160 : According to the preset maintenance monitoring condition, based on the stored expiration date of the operation password of each server, obtain the server to be maintained whose expiration date of the operation password meets the preset password maintenance condition.

[0097] In some embodiments of the present application, for example, the maintenance monitoring condition can be set to 8 o'clock every morning, or to 9 o'clock every Monday morning, etc. During the operation of the password maintenance platform, the password maintenance platform traverses the expiration date of the operation password of each server stored in the server data according to the preset maintenance monitoring condition, and determines whether the expiration date of the operation password of the server meets the preset password maintenance condition (such as whether the password expiration date is less than or equal to 7 days from the current date), so as to obtain each server to be maintained whose expiration date of the operation password meets the preset password maintenance condition.

[0098] Step 170 : Based on the user operation authority data, target users who have operation authority for each of the servers to be maintained are determined respectively.

[0099] For a specific implementation method of respectively determining the target user having the operation authority for each server to be maintained based on the user operation authority data, refer to the aforementioned implementation method of determining the second user having the operation authority for the target server, which will not be repeated here.

[0100] Step 180: Based on the user data, obtain the information receiving mode preset by each target user.

[0101] For a specific implementation method of obtaining the information receiving mode preset by each target user based on the user data, please refer to the above description and will not be repeated here.

[0102] Step 190: Send a second password maintenance reminder message to the target user through the information receiving method, where the second password maintenance reminder message is used to indicate that the operation password of the corresponding server to be maintained needs to be maintained in time.

[0103] For example, the second password maintenance prompt information may include: the IP address of the server to be maintained, the province where it is deployed, the expiration date of the operation password, etc. In this way, the target user can maintain the operation password of the server in a timely manner.

[0104] For a specific implementation of sending the second password maintenance reminder information to the target user through the information receiving method, refer to the implementation of sending notification information to the second user through the information receiving method mentioned above, which will not be repeated here.

[0105] The password maintenance method disclosed in the embodiment of the present application stores a database table on the password maintenance platform based on data entry operations performed on the password maintenance platform, wherein the database table includes: user operation permission data; based on a password modification operation performed by a first user on a target server after logging into the password maintenance platform, obtaining an encryption key and an operation password modified by the password modification operation; encrypting the modified operation password based on the encryption key to obtain a ciphertext operation password; based on the user operation permission data, determining a second user who has operation permission on the target server; based on the ciphertext operation password, synchronizing the password modification information of the target server to the second user, thereby facilitating real-time synchronization of maintenance information of passwords shared by multiple people.

[0106] The password maintenance method disclosed in the embodiment of the present application is to design a password maintenance platform, and pre-collect the user's operation authority data for the server's operation password and the user's information receiving method, and store them in the password maintenance platform. In this way, when a user modifies the operation password of the server that has been collected, the password maintenance platform can promptly inform other users who have corresponding operation authority for the server (i.e., share the operation password of the server) of the modification information of the operation password of the server by sending notification information and / or updating the operation password stored in the password maintenance platform. This not only realizes the real-time synchronization of the operation password maintenance information, but also greatly improves the efficiency compared to the notification method in the prior art. In addition, it can effectively avoid the occurrence of missed notifications.

[0107] Furthermore, by storing the operation password in an encrypted storage manner, or carrying the encrypted password in the notification message, the security of the operation password when multiple people synchronize their passwords is effectively improved.

[0108] On the other hand, this method maintains the expiration date of the operation password. When the operation password of the server is about to reach the expiration date, a password maintenance reminder is sent to the relevant user in a timely manner, which also improves the timeliness of password maintenance.

[0109] Example 2

[0110] The embodiment of the present application discloses a password maintenance device, such as Figure 5 As shown, the device includes:

[0111] The data collection module 510 is configured to store a database table in the password maintenance platform based on data entry operations performed on the password maintenance platform, wherein the database table includes: user operation authority data;

[0112] A password modification module 520 is configured to obtain an encryption key and an operation password modified by the password modification operation based on a password modification operation performed by the first user on the target server after logging into the password maintenance platform;

[0113] The password encryption processing module 530 is used to encrypt the modified operation password based on the encryption key to obtain a ciphertext operation password;

[0114] A second user determining module 540 is configured to determine a second user who has operation authority on the target server based on the user operation authority data;

[0115] The password change information synchronization module 550 is configured to synchronize the password change information of the target server to the second user based on the ciphertext operation password.

[0116] In some embodiments of the present application, the database table also includes: server data, such as Figure 6 As shown, the password modification information synchronization module 550 further includes:

[0117] The first password modification information synchronization submodule 5501 is configured to update the operation password of the target server in the server data based on the ciphertext operation password, so that the second user can obtain the ciphertext operation password of the target server by logging into the password maintenance platform; and / or

[0118] The second password modification information synchronization submodule 5502 is used to send a notification message to the second user indicating that the operation password of the target server has been modified.

[0119] In some embodiments of the present application, the database table further includes: user data, and the sending of notification information to the second user indicating that the operation password of the target server has been modified includes:

[0120] acquiring, according to the user data, an information receiving mode preset by each second user;

[0121] Through the information receiving method, a notification message is sent to the corresponding second user to indicate that the operation password of the target server has been modified, wherein the notification message includes one or more of the following information: the encrypted operation password, the IP address and / or province of the target server, the password modification time, and the password modification user.

[0122] In some embodiments of the present application, Figure 6 As shown, the password modification module 520 further includes:

[0123] The associated server information acquisition submodule 5201 is configured to acquire information about each server associated with the first user after the first user successfully logs into the password maintenance platform, wherein the servers associated with the first user are selected from servers for which the first user has operation authority;

[0124] The server information display submodule 5202 is used to display the information of each server to the first user;

[0125] The password modification submodule 5203 is configured to obtain an encryption key and an operation password modified by the password modification operation based on the password modification operation performed by the first user on the displayed target server.

[0126] In some embodiments of the present application, the server information displayed to the first user includes: the ciphertext operation password of the server, and after displaying the information of each server to the first user, the method further includes:

[0127] Based on a display-plaintext switching operation for the ciphertext operation password, obtaining a first encryption key stored in association with the ciphertext operation password in the password maintenance platform, and decrypting the ciphertext operation password using a decryption key corresponding to the first encryption key to obtain a plaintext password corresponding to the ciphertext operation password; or

[0128] Based on the display plaintext switching operation for the ciphertext operation password, a second encryption key corresponding to the province where the server is located is obtained, and the ciphertext operation password is decrypted using the decryption key corresponding to the second encryption key to obtain the plaintext password corresponding to the ciphertext operation password.

[0129] In some embodiments of the present application, the server information also includes: the expiration date of the operation password, such as Figure 6 As shown, the password modification module 520 further includes:

[0130] A password maintenance processing submodule 5204 is configured to determine, based on the expiration date, whether each server associated with the first user meets a preset password maintenance condition;

[0131] The password maintenance processing submodule 5204 is used to display first password maintenance prompt information to the first user in response to meeting a preset password maintenance condition, where the first password maintenance prompt information is used to indicate that the operation password of the corresponding server needs to be maintained in a timely manner.

[0132] In some embodiments of the present application, the encryption key includes: an encryption key obtained by randomly combining the deployment province information of the target server and a preset number.

[0133] In some embodiments of the present application, the database table further includes: server data and user data, wherein the server data includes: the expiration date of the operation password of each server, such as Figure 6 As shown, the device also includes:

[0134] The password maintenance processing module 560 is configured to obtain servers to be maintained whose expiration dates of the operation passwords of the servers satisfy the preset maintenance monitoring conditions based on the stored expiration dates of the operation passwords of the servers according to the preset maintenance monitoring conditions;

[0135] The password maintenance processing module 560 is also used to determine the target users who have operation permissions for each of the servers to be maintained based on the user operation permission data; obtain the information receiving method preset by each of the target users based on the user data; and send a second password maintenance reminder message to the target user through the information receiving method, where the second password maintenance reminder message is used to indicate that the operation password of the corresponding server to be maintained needs to be maintained in a timely manner.

[0136] The password maintenance device disclosed in the embodiment of the present application is used to implement the password maintenance method described in the first embodiment of the present application. The specific implementation methods of each module of the device will not be repeated here. Please refer to the specific implementation methods of the corresponding steps in the method embodiment.

[0137] The password maintenance device disclosed in the embodiment of the present application stores a database table on the password maintenance platform based on data entry operations performed on the password maintenance platform, wherein the database table includes: user operation permission data; based on a password modification operation performed by a first user on a target server after logging into the password maintenance platform, an encryption key is obtained, as well as an operation password modified by the password modification operation; the modified operation password is encrypted based on the encryption key to obtain a ciphertext operation password; based on the user operation permission data, a second user who has operation permission on the target server is determined; based on the ciphertext operation password, the password modification information of the target server is synchronized to the second user, which facilitates real-time synchronization of maintenance information of passwords shared by multiple people.

[0138] The password maintenance device disclosed in the embodiment of the present application is designed with a password maintenance platform, and pre-collects the user's operation authority data for the server's operation password and the user's information receiving method, and stores them in the password maintenance platform. In this way, when a user modifies the operation password of the server that has been collected, the password maintenance platform can promptly inform other users who have corresponding operation authority for the server (i.e., share the operation password of the server) of the modification information of the operation password of the server by sending notification information and / or updating the operation password stored in the password maintenance platform. This not only realizes the real-time synchronization of the operation password maintenance information, but also greatly improves the efficiency compared to the notification method in the prior art. In addition, it can effectively avoid the occurrence of missed notifications.

[0139] Furthermore, by storing the operation password in an encrypted storage manner, or carrying the encrypted password in the notification message, the security of the operation password when multiple people synchronize their passwords is effectively improved.

[0140] On the other hand, this device maintains the expiration date of the operation password. When the operation password of the server is about to reach the expiration date, the device promptly sends a password maintenance reminder to the relevant user, which also improves the timeliness of password maintenance.

[0141] Each embodiment in this specification is described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between the various embodiments can be referred to in conjunction with each other. For the device embodiments, since they are generally similar to the method embodiments, their description is relatively simple, and for relevant parts, reference can be made to the description of the method embodiments.

[0142] The above is a detailed introduction to a password maintenance method and device provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

[0143] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0144] The various component embodiments of the present application can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It will be appreciated by those skilled in the art that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the electronic device according to the embodiment of the present application. The application can also be implemented as a device or apparatus program (for example, a computer program and a computer program product) for performing a part or all of the methods described herein. Such a program implementing the present application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0145] For example, Figure 7 An electronic device that can implement the method according to the present application is shown. The electronic device can be a PC, a mobile terminal, a personal digital assistant, a tablet computer, etc. The electronic device conventionally includes a processor 710 and a memory 720, and program code 730 stored on the memory 720 and executable on the processor 710. When the processor 710 executes the program code 730, the method described in the above embodiments is implemented. The memory 720 can be a computer program product or a computer-readable medium. The memory 720 can be an electronic memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read-Only Memory), an EPROM, a hard disk, or a ROM. The memory 720 has a storage space 7201 for program code 730 of a computer program for executing any of the method steps described above. For example, the storage space 7201 for program code 730 can include individual computer programs for implementing various steps in the above method. The program code 730 is computer-readable code. These computer programs can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards, or floppy disks. The computer program includes a computer-readable code, and when the computer-readable code is run on an electronic device, the electronic device is caused to execute the method according to the above embodiment.

[0146] An embodiment of the present application further discloses a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps of the password maintenance method described in the first embodiment of the present application are implemented.

[0147] Such a computer program product may be a computer-readable storage medium having a computer program product. Figure 7The memory 720 in the electronic device shown is similarly arranged as a storage segment, storage space, etc. The program code can be compressed and stored in the computer readable storage medium in an appropriate form. The computer readable storage medium is generally as shown in FIG. Figure 8 The portable or fixed storage unit generally includes computer-readable code 730', which is a code read by a processor and implements the steps of the above-described method when the code is executed by the processor.

[0148] References herein to "one embodiment," "an embodiment," or "one or more embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present application. Furthermore, please note that instances of the phrase "in one embodiment" do not necessarily all refer to the same embodiment.

[0149] In the description provided herein, a large number of specific details are described. However, it is understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.

[0150] In the claims, any reference signs placed between brackets shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present application may be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.

[0151] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A password maintenance method, characterized in that: include: Based on the data entry operation performed on the password maintenance platform, a database table is stored in the password maintenance platform, wherein the database table includes: user operation authority data, which is used to record the user's operation authority on the server; the user operation authority data includes the association between the user and the deployment province, and the user's operation authority on the server in each province; server data, which is used to record the deployment province, IP address and operation password of the server; user data, which is used to record the user's identification and preset information receiving method; based on the password modification operation performed by the first user on the target server after logging into the password maintenance platform, the encryption key is obtained, as well as the operation password after the password modification operation is modified; Encrypting the modified operation password based on the encryption key to obtain a ciphertext operation password; Determining a second user who has operation authority on the target server based on the user operation authority data; Based on the ciphertext operation password, the target server identifier in the server data, and the information receiving method of the second user in the user data, the password modification information of the target server is synchronized to the second user, wherein the password modification information includes at least the ciphertext operation password and the IP address of the target server.

2. The method according to claim 1, characterized in that The step of synchronizing the password modification information of the target server to the second user based on the ciphertext operation password, the target server identifier in the server data, and the information receiving mode of the second user in the user data includes: Based on the encrypted operation password, updating the operation password of the target server in the server data so that the second user can obtain the encrypted operation password of the target server by logging into the password maintenance platform; and / or, Sending a notification message to the second user indicating that the operation password of the target server has been modified.

3. The method according to claim 2, characterized in that The sending, to the second user, notification information indicating that the operation password of the target server has been modified, includes: acquiring, according to the user data, an information receiving mode preset by each second user; Through the information receiving method, a notification message is sent to the corresponding second user to indicate that the operation password of the target server has been modified, wherein the notification message includes one or more of the following information: the encrypted operation password, the IP address and / or province of the target server, the password modification time, and the password modification user.

4. The method according to claim 1, wherein The obtaining of the encryption key and the operation password modified by the password modification operation based on the password modification operation performed by the first user on the target server after logging into the password maintenance platform includes: After the first user successfully logs into the password maintenance platform, obtaining information of each server associated with the first user, wherein each server associated with the first user is selected from servers for which the first user has operation authority; Displaying information of each server to the first user; Based on the password modification operation performed by the first user on the displayed target server, an encryption key and an operation password modified by the password modification operation are obtained.

5. The method according to claim 4, characterized in that The server information displayed to the first user includes: the ciphertext operation password of the server. After the step of displaying the information of each server to the first user, the step further includes: Based on a display-plaintext switching operation for the ciphertext operation password, obtaining a first encryption key stored in association with the ciphertext operation password in the password maintenance platform, and decrypting the ciphertext operation password using a decryption key corresponding to the first encryption key to obtain a plaintext password corresponding to the ciphertext operation password; or Based on the display plaintext switching operation for the ciphertext operation password, a second encryption key corresponding to the province where the server is located is obtained, and the ciphertext operation password is decrypted using the decryption key corresponding to the second encryption key to obtain the plaintext password corresponding to the ciphertext operation password.

6. The method according to claim 4, wherein: The server information also includes: the expiration date of the operation password. After the first user successfully logs into the password maintenance platform, after obtaining the information of each server associated with the first user, it also includes: Based on the expiration date, determining whether each server associated with the first user meets a preset password maintenance condition; In response to meeting a preset password maintenance condition, first password maintenance prompt information is displayed to the first user, where the first password maintenance prompt information is used to indicate that the operation password of the corresponding server needs to be maintained in a timely manner.

7. The method according to any one of claims 1 to 6, characterized in that The encryption key includes: an encryption key obtained by randomly combining the deployment province information of the target server and a preset number.

8. The method according to any one of claims 1 to 6, characterized in that The database table also includes: server data and user data, the server data includes: the expiration date of the operation password of each server, and the data entry operation performed on the password maintenance platform, after the password maintenance platform stores the database table, further includes: According to the preset maintenance monitoring conditions, based on the expiration dates of the stored operation passwords of the servers, obtaining servers to be maintained whose expiration dates of the operation passwords meet the preset maintenance monitoring conditions; Based on the user operation authority data, respectively determining target users who have operation authority for each of the servers to be maintained; Based on the user data, obtaining the information receiving mode preset by each target user; A second password maintenance reminder message is sent to the target user through the information receiving method, where the second password maintenance reminder message is used to indicate that the operation password of the corresponding server to be maintained needs to be maintained in a timely manner.

9. A password maintenance device, characterized in that: include: A data collection module is configured to store a database table in the password maintenance platform based on data entry operations performed on the password maintenance platform, wherein the database table includes: user operation authority data, which is used to record the user's operation authority for the server; the user operation authority data includes the association between the user and the deployment province, and the user's operation authority for the server in each province; server data, which is used to record the server's deployment province, IP address, and operation password; user data, which is used to record the user's identification and preset information receiving method; A password modification module, configured to obtain an encryption key and an operation password modified by the password modification operation based on a password modification operation performed by the first user on the target server after logging into the password maintenance platform; A password encryption processing module, configured to encrypt the modified operation password based on the encryption key to obtain a ciphertext operation password; A second user determining module, configured to determine a second user having operation authority on the target server based on the user operation authority data; A password change information synchronization module is used to synchronize the password change information of the target server to the second user based on the ciphertext operation password, the target server identifier in the server data, and the second user's information reception method in the user data, wherein the password change information at least includes the ciphertext operation password and the IP address of the target server.

10. An electronic device comprising a memory, a processor, and a program code stored in the memory and executable on the processor, wherein: When the processor executes the program code, the password maintenance method according to any one of claims 1 to 8 is implemented.

11. A computer-readable storage medium having program code stored thereon, characterized in that: When the program code is executed by a processor, the steps of the password maintenance method according to any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Linux password management method, central control computer, and readable storage medium

    CN109472130A

  • Key synchronization method and device, computer equipment and storage medium

    CN113452519A