A password management method, device, electronic device and readable storage medium

By storing and automatically updating the password of the cloud server in the target database, the inefficiency and low security problems caused by users managing multiple cloud server passwords by themselves are solved, and efficient and secure cloud server management is achieved.

CN115733666BActive Publication Date: 2025-08-01INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211341540.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2025-08-01
Estimated Expiration
2042-10-28

AI Technical Summary

Technical Problem

In the prior art, users need to manage the passwords of multiple cloud servers by themselves, resulting in low login efficiency and low security. Once the password of the cloud server is cracked, the security cannot be guaranteed.

Method used

By storing the cloud server passwords applied by each user in the target database, and automatically modifying the passwords based on preset update conditions, providing a unified platform to manage the passwords of multiple cloud servers, and using specified components to automatically obtain and update passwords.

Benefits of technology

It improves the password security of cloud servers, reduces the probability of password being cracked, avoids the security risk of password leakage, and improves login efficiency and information security management level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115733666B_ABST
    Figure CN115733666B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a password management method, device, electronic device, and readable storage medium. In this method, when a login request sent by a target user is received, a specified component is called to obtain, based on the target server identifier carried in the login request, the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database as the target password; log in to the target cloud server using the target password for the target user to use the target cloud server; for any cloud server, when a preset update condition is met, modify the password of the cloud server, and update the password of the cloud server in the server password data based on the modified password. In this way, by uniformly managing the passwords of multiple cloud servers, the probability of the password being cracked can be reduced, and the security risk caused by password leakage can be avoided, ensuring the password security of the cloud server and improving the information security management level of the cloud server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer technology, and particularly relates to a password management method, device, electronic device and readable storage medium. Background Art

[0002] With the progress of technology and the development of the times, mankind has entered a brand-new era: the cloud computing era. With the expansion of business, cloud service users will purchase or use a large number of virtual resources from cloud service providers. For cloud service users, each virtual resource is a cloud server.

[0003] In the prior art, when a user uses a cloud server, the user needs to store the passwords of each cloud server by himself / herself. Since the user may apply for multiple cloud servers, the user needs to store multiple passwords corresponding to multiple cloud servers. In this way, by the user himself / herself managing the passwords of multiple cloud servers, when the user logs in to the target cloud server, the user needs to manually determine the target password corresponding to the target cloud server from multiple passwords. And because the cloud server uses a single fixed password for a long time, once the password of the cloud server is cracked, the security of the cloud server cannot be guaranteed, resulting in potential security hazards for the cloud server. Therefore, there are problems of low login efficiency and low security in the prior art. Summary of the Invention

[0004] The present invention provides a password management method, device, electronic device and readable storage medium to solve the problems of low login efficiency and low security.

[0005] To solve the above technical problems, the present invention is implemented as follows:

[0006] In a first aspect, the present invention provides a password management method, which is applied to a password management terminal, and the method includes:

[0007] When receiving a login request sent by a target user, call a specified component to obtain, based on the target server identifier carried in the login request, the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database as the target password; the server password data includes the passwords of the cloud servers applied for by each user;

[0008] Log in to the target cloud server based on the target password for the target user to use the target cloud server;

[0009] For any one of the cloud servers, when a preset update condition is satisfied, modify the password of the cloud server, and update the password of the cloud server in the server password data based on the modified password.

[0010] Optionally, the method further includes:

[0011] Obtaining server information of the cloud servers applied for by each user; the server information includes a server address, a username, a password, and a system type;

[0012] For the server information of any one of the cloud servers, based on the server address, the username, and the system type, generating a key name corresponding to the cloud server, and, based on the password, generating a key value corresponding to the key name;

[0013] Invoking the specified component to store the key name and the key value in the form of a key-value pair in the target database to obtain the server password data.

[0014] Optionally, the target server identifier includes a target server address and a target username. The step of the specified component determining, based on the target server identifier carried in the login request, the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database as the target password includes:

[0015] Obtaining the target system type of the target cloud server;

[0016] Generating a first key name based on the target server address, the target username, and the target system type;

[0017] Invoking the specified component to determine a first key value corresponding to the first key name from among at least two key-value pairs corresponding to the cloud servers stored in the target database to obtain the target password.

[0018] Optionally, the password is updated by the following method:

[0019] When a preset period is reached, obtaining a target update password generated by the specified component for the cloud server, and modifying the password of the cloud server to the target update password;

[0020] After the modification is completed, based on the target update password, invoking the specified component to update the password of the cloud server in the server password data.

[0021] Optionally, the step of obtaining a target update password generated by the specified component for the cloud server and modifying the password of the cloud server to the target update password includes:

[0022] Obtaining a target password rule of the cloud server according to the preset period, and generating an update password request based on the obtained target password rule;

[0023] Invoke the specified component to generate a random number based on the password update request as the target updated password.

[0024] Send a password change instruction carrying the target updated password to the cloud server so that the cloud server completes password change based on the target updated password.

[0025] Optionally, updating the password of the cloud server in the server password data by the specified component based on the target updated password includes:

[0026] Generate a second key value according to the target updated password and generate a password replacement request based on the second key value.

[0027] Invoke the specified component to replace the key value corresponding to the target cloud server in the server password data with the second key value based on the password replacement request.

[0028] Optionally, the method further includes:

[0029] In the case that the initial password rule in the target cloud server does not meet the preset requirements, invoke the target plugin in the password management terminal to modify the initial password rule to a target password rule that meets the preset requirements.

[0030] Wherein, the target plugin is a plugin that meets the target plugin format requirements defined by the password management terminal.

[0031] In a second aspect, the present invention provides a password management device, and the device includes:

[0032] A first acquisition module, configured to, when receiving a login request sent by a target user, invoke a specified component to obtain the password of the target cloud server indicated by the target server identifier from the server password data stored in a target database as a target password; the server password data includes passwords of cloud servers applied by each user.

[0033] A first login module, configured to log in to the target cloud server based on the target password for the target user to use the target cloud server.

[0034] A first update module, configured to, for any of the cloud servers, modify the password of the cloud server when meeting a preset update condition and update the password of the cloud server in the server password data based on the modified password.

[0035] In a third aspect, the present invention provides an electronic device, comprising: a processor, a memory, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the above-mentioned password management method is implemented.

[0036] In a fourth aspect, the present invention provides a readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, enabling the electronic device to execute the above-mentioned password management method

[0037] In an embodiment of the present invention, in response to a login request sent by a target user, a specified component is called to obtain, based on the target server identifier carried in the login request, the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database as the target password; the server password data includes the passwords of cloud servers applied for by each user, and the passwords of each cloud server stored in the target database are periodically updated; the target cloud server is logged in based on the target password for the target user to use the target cloud server. In this way, by uniformly storing the passwords of each cloud server in the target database, a unified platform is provided for unified management of the passwords of multiple cloud servers. Modifying and updating the passwords of cloud servers based on preset update conditions can reduce the probability of the passwords being cracked and improve the password security of the cloud servers. At the same time, to a certain extent, the security risks brought by password leakage can be avoided, further ensuring the password security of the cloud servers, and thereby improving the information security management level of the cloud servers. And through the login request sent by the user, the target password corresponding to the target cloud server can be automatically obtained to log in to the target cloud server for the user to use. Compared with the method of manually determining the target password, the login efficiency can be improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0039] Figure 1 is a flowchart of the steps of a password management method provided by an embodiment of the present invention;

[0040] Figure 2 is a schematic diagram of a specific example of data interaction between a password management terminal and a specified component provided by an embodiment of the present invention;

[0041] Figure 3 is a flowchart of the steps of another password management method provided by an embodiment of the present invention;

[0042] Figure 4 It is a schematic diagram of a specific example provided by an embodiment of the present invention;

[0043] Figure 5 It is a structural diagram of a test device for a transcoding card provided by an embodiment of the present invention;

[0044] Figure 6 It is a structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners

[0045] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0046] Figure 1 It is a step flowchart of a password management method provided by an embodiment of the present invention, and this method is applied to a password management terminal.

[0047] In the embodiments of the present invention, the password management terminal is used to manage at least two cloud servers. The cloud server can be a cloud server resource to be managed applied by a user. A virtual cloud server resource is a cloud server, and the cloud server includes cloud resources such as instances, images, and disks. Each cloud server corresponds to a set of user names and passwords respectively used to log in to the cloud server.

[0048] Optionally, the login of the password management terminal can be set with multi-factor authentication. The multi-factor authentication can include two layers of security elements. One layer of security element can be the user name and password corresponding to the password management terminal, and the other layer of security element can include a small storage device with a password verification function, such as a Ukey, and / or a short message verification code, etc. The embodiments of the present invention do not limit this. In this way, by setting multi-factor authentication, an additional layer of security protection is added beyond the user name and password, which can further provide better security protection for the password management terminal, thereby improving the security level of password management.

[0049] Such as Figure 1 shown, this method may include:

[0050] Step 101, when receiving a login request sent by a target user, call a specified component to obtain, based on the target server identifier carried in the login request, the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database as the target password; the server password data includes the passwords of the cloud servers applied by each user.

[0051] In an embodiment of the present invention, the login request is a request sent by a target user to obtain the target password of a target cloud server. The target server identifier corresponding to the target cloud server is carried in the login request, and the target server identifier is used to indicate the target cloud server corresponding thereto. The passwords of the cloud servers applied for by each user are stored in the target database. When the password management terminal receives the login request, in response to the login request, the specified component is called through the interface to determine the password of the target cloud server from the passwords of the cloud servers applied for by each user stored in the target database. The passwords of the cloud servers stored in the target database can be updated periodically. Therefore, the target password is the password currently saved in the target database determined based on the target server identifier.

[0052] Among them, the specified component may be a key management component with key management functions, such as a Key Management System (KMS), a Hardware Security Module (HSM), or other key management components that can provide functions such as password generation, storage, and distribution for the login account of the cloud server. The target database may be an area with storage functions in the specified component or a specified database with storage functions.

[0053] Optionally, the data interaction between the password management terminal and the specified component is implemented through the unified interface of the password management terminal. That is, the password management terminal provides a unified interface for calling the specified component, and multiple interface protocols are integrated in the unified interface, such as: SDF interface protocol, SKF interface protocol, PKCS#11 interface protocol, KMIP interface protocol, etc. The password management terminal can dock with the specified component that follows different interface protocols through the unified interface. In response to the login request, the password management terminal sends a request message to the unified interface, and the request message is used to request to obtain the target password. When the unified interface receives the request message, it selects an interface protocol adapted to the specified component according to the interface protocol followed by the specified component to communicate with the specified component. When a key management component is accessed by the password management terminal, the key management component is determined as the specified component, and the interface protocol adapted to it is selected for communication; when at least two key management components are accessed by the password management terminal, a suitable key management component can be selected as the specified component according to the current state of the key management component, and the interface protocol adapted to the specified component is selected for communication. It can be understood that in addition to the password management terminal described in the embodiment of the present invention, the unified interface can also be used by other systems that have data interaction with the password management terminal, such as a database (DB), or software that needs to log in to the password management terminal for automated testing. Exemplarily, Figure 2 A schematic diagram showing a specific example of data interaction between the password management terminal and the specified component is shown, such asFigure 2 As shown, the specified components include a KMS component that follows the KMIP interface protocol, an HSM_1 component that follows the SDF interface protocol, and an HSM_2 component that follows the PKCS#11 interface protocol. Other systems that have data interactions with the password management terminal may include a database (DB) that follows other interface protocols. The password management terminal (not shown in the figure) can perform data interactions with the specified components through a unified interface based on the various protocols provided in the unified docking layer. For example, it can dock with the HSM_1 component that follows the SDF interface protocol based on the SDF interface protocol through the unified interface to achieve data interaction between the password management terminal and the HSM_1 component, or dock with the database that follows other interface protocols based on other interface protocols through the unified interface to achieve data interaction between the password management terminal and the database, etc.

[0054] In this way, the password management terminal only needs to dock with key management components with different interface protocols through the unified interface, which reduces the adaptation cost of introducing key management components with different interface protocols, and simplifies the development efficiency and the docking difficulty of key management components. At the same time, when the user obtains the target password, there is no need to pay attention to the interface protocol required for docking with the key management component, which is convenient for the user to use.

[0055] Step 102: Log in to the target cloud server based on the target password for the target user to use the target cloud server.

[0056] In the embodiment of the present invention, after obtaining the target password of the target cloud server, the password management terminal can be used to remotely log in to the target cloud server based on the target password for the target user to use the target cloud server. Among them, it can remotely log in to the target cloud server through protocols such as the Secure Shell (SSH) protocol.

[0057] Step 103: For any of the cloud servers, when the preset update condition is met, modify the password of the cloud server, and update the password of the cloud server in the server password data based on the modified password.

[0058] In an embodiment of the present invention, the password management terminal has the function of automatically updating the password of the cloud server. Exemplarily, the password update function of one or more cloud servers can be enabled on the password management terminal. At the same time, the period of automatic password update can be set according to user needs to obtain a preset period, and the password corresponding to the cloud server is periodically updated according to the preset period. The preset update condition can be to enable the function of automatically updating the password of the cloud server on the password management terminal. The preset update condition is used to indicate that the cloud server needs to update its password. When the cloud server needs to update its password, the password of the cloud server is modified, and the password corresponding to the cloud server stored in the target database is updated, that is, the password corresponding to the cloud server in the server password data is updated. In this way, the security of the password can be improved, and the probability of the password being cracked can be reduced. At the same time, even if the password of the cloud server is cracked, since the password of the cloud server is modified and updated, to a certain extent, the loss caused by the cracked password can also be avoided, and the security of the cloud server is improved.

[0059] It should be noted that the execution order of step 103, step 101, and step 102 is not unique. For example, step 103 can be executed synchronously with step 101 and step 102, or step 103 can be executed first and then step 101, or step 103 can be executed first and then step 102.

[0060] In summary, in an embodiment of the present invention, by responding to a login request sent by a target user, a specified component is called to obtain, from the server password data stored in the target database, the password of the target cloud server indicated by the target server identifier carried in the login request as the target password; the server password data includes the passwords of the cloud servers applied for by each user, and the passwords of the cloud servers stored in the target database are periodically updated; the target cloud server is logged in based on the target password for the target user to use the target cloud server. In this way, by uniformly storing the passwords of the cloud servers in the target database, a unified platform is provided for unified management of the passwords of multiple cloud servers. Modifying and updating the passwords of the cloud servers based on the preset update conditions can reduce the probability of the passwords being cracked and improve the password security of the cloud servers. At the same time, to a certain extent, the security risks brought by password leakage can be avoided, further ensuring the password security of the cloud servers, and then improving the information security management level of the cloud servers. And through the login request sent by the user, the target password corresponding to the target cloud server can be automatically obtained to log in to the target cloud server for the user to use. Compared with the method of manually determining the target password, the login efficiency can be improved.

[0061] Optionally, an Internet Protocol (IP) address whitelist may be set in the specified component. The whitelist may include the IP addresses of one or more password management terminals, and the whitelist is used to indicate that the password management terminals corresponding to the IP addresses in the list are allowed to call the specified component. In this way, by setting the IP address whitelist, the information security of the information obtained through the specified component can be ensured, and the security of cloud server password management is further improved.

[0062] Figure 3 FIG. 4 is a flowchart of steps of another password management method provided by an embodiment of the present invention. This method may be applied to a password management terminal, such as Figure 3 shown, and the method may include:

[0063] Step 201, obtain the server information of the cloud servers applied for by each user; the server information includes a server address, a username, a password, and a system type.

[0064] In an embodiment of the present invention, the cloud servers applied for by each user may be imported into the password management terminal, and the server information of the cloud servers applied for by each user is obtained. The server information includes the server address, username, password, and system type of the cloud server. The server address corresponding to the cloud server may be obtained by obtaining the default system address data stored in the cloud server. The system type corresponding to the cloud server may obtain the system type identifier corresponding to the cloud server by accessing a specified file in the cloud server. The system type identifier represents the system type corresponding to the cloud server, and the system type may include ubuntu, centos, redhat, sles, etc. The username and password corresponding to the cloud server may be the username and password corresponding to the system administrator account. Among them, the username may be root, administrator, admin, superadmin, etc., and the embodiment of the present invention does not limit this.

[0065] The server address corresponds to the username and password one by one, that is, one server address corresponds to a unique username and a unique password, and the username corresponds to the password one by one. A set of username and password is used to log in to the cloud server represented by the corresponding server address. Among them, since the username and password of the root user cannot be deleted or tampered with, the username and password may be the username and password of the root user. Logging in to the cloud server based on the username and password of the root user can obtain all permissions of the cloud server system bottom layer and system files, including password modification permissions.

[0066] Step 202, for the server information of any one of the cloud servers, generate a key name corresponding to the cloud server based on the server address, the username, and the system type, and generate a key value corresponding to the key name based on the password.

[0067] In an embodiment of the present invention, for any cloud server, the server address, username, and system type corresponding to the cloud server are concatenated to generate a key name corresponding to the cloud server, and the password corresponding to the cloud server is generated as a key value corresponding to the key name. That is to say, a cloud server corresponds to a unique key name and a unique key value, and the number of imported cloud servers, the number of key names, and the number of key values in the password management terminal are equal.

[0068] Optionally, the correspondence between the server address and the system type corresponding to the cloud server can be stored in the database of the password management terminal.

[0069] Step 203: Call the specified component to store the key name and the key value in the form of a key-value pair into the target database to obtain the server password data.

[0070] In an embodiment of the present invention, a password storage request is generated based on the key name and key value of the cloud server, and the specified component is called through the interface to store the key name and key value in the form of a key-value pair into the target database based on the password storage request to obtain the server password data. The server password data stored in the target database includes key-value pairs corresponding to the cloud servers applied for by each user.

[0071] Step 204: When receiving a login request sent by the target user, call the specified component to obtain the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database based on the target server identifier carried in the login request as the target password; the server password data includes the passwords of the cloud servers applied for by each user.

[0072] Specifically, the implementation manner of this step can refer to the foregoing related description and will not be elaborated here.

[0073] Step 205: Log in to the target cloud server based on the target password for the target user to use the target cloud server.

[0074] Specifically, the implementation manner of this step can refer to the foregoing related description and will not be elaborated here.

[0075] Step 206: For any of the cloud servers, when the preset update condition is met, modify the password of the cloud server and update the password of the cloud server in the server password data based on the modified password.

[0076] Specifically, the implementation manner of this step can refer to the foregoing related description and will not be elaborated here.

[0077] In an embodiment of the present invention, by storing the server information of the cloud server in the form of key-value pairs in the target database, the corresponding key value can be quickly queried according to the key name. At the same time, since the key-value pairs are small in size, the memory resources of the target database can be saved, thereby improving the query speed of the cloud server password and the data storage capacity of the target database.

[0078] Optionally, the target server identifier includes a target server address and a target username.

[0079] In an embodiment of the present invention, the target server identifier includes the target server address and the target username corresponding to the target cloud server. The methods for obtaining the target server address and the target username are similar to the methods for obtaining the server address and the username in step 201, and will not be elaborated here.

[0080] Step 101 may include the following steps:

[0081] Step 1011: Obtain the target system type of the target cloud server.

[0082] In an embodiment of the present invention, the target system type corresponding to the target cloud server can be obtained based on the target server address. Exemplarily, the system type corresponding to the target server address can be determined according to the correspondence between the server address and the system type stored in the database of the password management terminal as the target system type, which is the target system type corresponding to the target cloud server.

[0083] Step 1012: Generate a first key name based on the target server address, the target username, and the target system type.

[0084] In an embodiment of the present invention, the target server address, the target username, and the target system type are concatenated to generate a first key name, which is the first key name corresponding to the target cloud server.

[0085] Step 1013: Invoke the specified component to determine a first key value corresponding to the first key name from at least two key-value pairs corresponding to the cloud servers stored in the target database to obtain the target password.

[0086] In an embodiment of the present invention, a password acquisition request is generated based on the first key name. The specified component is invoked through the interface to determine the first key value from at least two key-value pairs stored in the target database based on the password acquisition request, and the first key value is used as the target password. Exemplarily, the first key name can be matched with the key names in the key-value pairs stored in the target database, and the key value in the first key-value pair whose key name matches the first key name is used as the first key value. That is to say, the key value corresponding to the key name that matches the first key name is the first key value corresponding to the first key name, and this first key value is the target password corresponding to the target cloud server.

[0087] In a possible implementation, the system type corresponding to the cloud server is determined in the database of the password management end according to the server address of the cloud server carried in the login request sent by the user, and the user name, server address carried in the login request, and the system type corresponding to the server address are concatenated to generate a key name. A specified component is called to obtain the key value corresponding to the cloud server based on the key name as the login password of the cloud server, and the cloud server is remotely logged in based on the login password.

[0088] In the embodiment of the present invention, by generating the first key name corresponding to the target cloud server, when obtaining the target password corresponding to the target cloud server, the corresponding first key value can be automatically determined according to the first key name, so that the target password corresponding to the target cloud server can be determined, improving the efficiency of obtaining the password.

[0089] Optionally, step 103 may include the following steps:

[0090] Step 301, when the preset period is reached, obtain the target update password generated by the specified component for the cloud server, and modify the password of the cloud server to the target update password.

[0091] In the embodiment of the present invention, for any cloud server, when the password update function of the cloud server has been enabled at the password management end and the preset period is reached, the target update password generated by the specified component based on the update password request generated by the password management end can be obtained. The update password request is used to request the specified component to generate a new target update password for the cloud server. After obtaining the target update password generated by the specified component, based on the target update password, the current password of the cloud server is changed to the target update password.

[0092] Correspondingly, step 103 may further include the following steps:

[0093] Step 302, when the modification is completed, based on the target update password, call the specified component to update the password of the cloud server in the server password data.

[0094] In the embodiment of the present invention, when the current password of the cloud server has been changed to the target update password, it indicates that the password modification of the cloud server is completed. Then, based on the target update password, call the specified component to change the password of the cloud server in the server password data stored in the target database to the target update password.

[0095] In the embodiments of the present invention, by modifying the password of the cloud server, the information security management level of the cloud server can be improved, and the potential risks of information security can be reduced. At the same time, the password stored in the target database is changed to the modified password. Since users do not need to store the password, to a certain extent, the risk of password leakage is also reduced. While improving the security of the password, the security of the data of the cloud server is also ensured.

[0096] Optionally, step 301 may include the following steps:

[0097] Step 3011: Obtain the target password rule of the cloud server according to the preset period, and generate an update password request based on the obtained target password rule.

[0098] In the embodiments of the present invention, the target password rule may include information such as password length limit information and password complexity limit information, and can be obtained based on a specified system configuration file in the cloud server. Exemplarily, by scanning the specified system configuration file in the cloud server, information such as password length limit and password complexity limit can be obtained. The specified system configuration file is used to store the password rules of the cloud server and can be determined according to the system type of the cloud server. For example, the specified system configuration files corresponding to the centos system are / etc / passwd file, / etc / login.defs, etc. Among them, the password length limit information is used to limit the length requirement that the password of the cloud server follows, and the password complexity limit information is used to limit the complexity requirement that the password of the cloud server follows.

[0099] In the embodiments of the present invention, an update password request can be generated based on the target password rule. The update password request is used to request a specified component to generate a new random number as the target update password of the cloud server.

[0100] Step 3012: Call the specified component to generate a random number based on the update password request as the target update password.

[0101] In the embodiments of the present invention, a specified component is called through an interface to generate a random number based on the update password request. The random number should comply with all the rules specified by the target password rule, and the random number is used as the target update password corresponding to the cloud server.

[0102] Step 3013: Send a password change instruction carrying the target update password to the cloud server, so that the cloud server completes the password change based on the target update password.

[0103] In an embodiment of the present invention, a target update password generated by a specified component is obtained, and a password change instruction is generated based on the target update password. The password change instruction may include an instruction for changing the password of the root user of the cloud server. The password change instruction is sent to the cloud server. When the cloud server receives the password change instruction, it changes the password of the current root user of the cloud server to the target update password.

[0104] In an embodiment of the present invention, a target update password that meets the target password rule is generated by a specified component, and the cloud server completes the password change, ensuring the randomness of the target update password, improving the security level of the password to a certain extent, and at the same time ensuring the consistency between the actual password of the cloud server and the target update password.

[0105] Optionally, when obtaining the target password rule, user list information can be obtained in a specified system configuration file. The user list information includes all created users currently in the cloud server, and information about each user necessary for logging in to the cloud server system, such as username, password, user identity identifier, etc. It can be understood that the password change instruction may include changing the password of any created user in the user list based on the target update password, so that the cloud server completes the password change of any created user in the user list based on the target update password. In this way, according to user requirements, the password of any user in the cloud server can be automatically updated, further improving the system security level of the cloud server.

[0106] Optionally, step 302 may include the following steps:

[0107] Step 3021: Generate a second key value according to the target update password, and generate a password replacement request based on the second key value.

[0108] In an embodiment of the present invention, when the cloud server completes the password change based on the target update password, it is necessary to change and replace the password corresponding to the cloud server stored in the target database. Therefore, a second key value is generated according to the target update password, and a password replacement request is generated based on the second key value. The password replacement request is used to request the specified component to replace the password corresponding to the cloud server stored in the server password data with the second key value, that is, the target update password.

[0109] The password replacement request may further include a key name generated based on the server address, username, and system type of the cloud server. The key name is used to determine the cloud server for which password replacement is required in the server password data.

[0110] Step 3022: Call the specified component to replace the key value corresponding to the cloud server in the server password data with the second key value.

[0111] In an embodiment of the present invention, by invoking a specified component through an interface to perform password replacement based on a password replacement request, the password of the cloud server in the server password data stored in the target database can be replaced. Specifically, based on the key name corresponding to the cloud server carried in the password replacement request, a key-value pair corresponding to the cloud server can be determined in the server password data. The key value in the key-value pair in the server password data is replaced with a second key value to implement password replacement of the password stored in the target database.

[0112] In an embodiment of the present invention, by replacing the password corresponding to the cloud server in the server password data with a second key value, the password of the cloud server stored in the target database can be replaced, so that the password stored in the target database is synchronized with the actual password of the cloud server, ensuring the timeliness and accuracy of the password stored in the target database.

[0113] Optionally, an embodiment of the present invention further includes the following steps:

[0114] Step 401: When the initial password rule in the cloud server does not meet the preset requirements, call the target plug-in in the password management terminal to modify the initial password rule to a target password rule that meets the preset requirements;

[0115] Among them, the target plug-in is a plug-in that meets the target plug-in format requirements defined by the password management terminal. The target plug-in format requirements can be defined through the plug-in loading framework of the password management terminal. Exemplarily, the target plug-in format requirements include: having a detect() detection function interface, an execute() execution function interface, a rollback() rollback function interface, a callback() callback function interface, etc. When the target plug-in follows the above target plug-in format requirements, that is, includes interfaces such as a detect() detection function, an execute() execution function, a rollback() rollback function, and a callback() callback function, it can be called to achieve seamless access of the target plug-in.

[0116] In an embodiment of the present invention, the password management terminal may include one or more target plug-ins. The target plug-in may be a plug-in for checking and adjusting password rules, and can load the plug-in into the password management terminal by automatically scanning all preset plug-in scripts in the system directory of the password management terminal. The system directory may be the system temporary directory of the password management terminal, and it can be loaded into the password management terminal only after being evaluated by the administrator and manually reviewed.

[0117] Exemplarily, the initial password rules in the specified system configuration file of the cloud server can be detected according to preset rules. When the initial password rules in the cloud server do not meet the preset requirements, the target plugin is called to adjust the initial password rules, and the initial password rules are modified to target password rules that meet the preset requirements. Among them, the preset rules can be the execution frequency and method of calling the functions of the target plugin. For example, the plugin for detecting and adjusting password rules can be executed only when the cloud server imports the password management terminal. The preset requirements are preset password rules that meet security requirements.

[0118] It can be understood that the target plugin can also be a plugin for strengthening configuration to improve system security, such as: a plugin for enabling or setting the firewall function, a plugin for downloading system patches, a plugin for detecting disk capacity, etc. The embodiments of the present invention do not limit this. The target plugin can also be a third-party plugin that meets the format requirements of the target plugin defined by the password management terminal, such as scripts like Python scripts and shell scripts. Exemplarily, the third-party provided plugins such as Python scripts and shell scripts can be executed through the execute() function. Correspondingly, the target plugin can be executed periodically according to the execution frequency indicated by the preset rules. For example, the target plugin for detecting the disk capacity of the cloud server can be executed once every other week.

[0119] In the embodiments of the present invention, using the target plugin to modify the password rules to target password rules that meet the preset requirements can ensure the complexity requirements and length requirements of the target password rules, thereby making the password of the cloud server have better security.

[0120] Optionally, the password management terminal can also generate system logs.

[0121] Exemplarily, Figure 4 A schematic diagram showing a specific example is as Figure 4As shown, the cloud server can be represented by any server resource in the figure. The unified interface layer can provide a unified interface for calling a specified component or database. The unified interface layer is used to provide an interface for docking the target plug-in. The target plug-in can be represented by one or more security feature plug-ins in the figure. SYSLOG in the figure can represent the system log generated by the password management terminal. The user logs in to the password management terminal through multi-factor authentication, such as Ukey + account password. Multiple cloud servers are managed in the password management terminal. The password management terminal loads server resources for the connected cloud servers to obtain server resources 1 - n. In response to the login request sent by the user, the password management terminal calls a specified component, such as specified components like KMS and HSM, through the unified interface to obtain the target password of the target cloud server to log in to the target cloud server, or calls the database through the unified interface to organize, store, and manage data. The required target plug-in is selected from the security feature plug-ins 1 - n through the interface provided by the unified interface layer for calling to execute the functions corresponding to the security feature plug-ins. It can be understood that the password management terminal can also generate a system log to record the events occurring in the password management terminal and store the system log in a specified area.

[0122] Figure 5 It is a structural diagram of a password management device provided by an embodiment of the present invention. The device 50 may include:

[0123] The first acquisition module 501 is configured to, when receiving a login request sent by a target user, call a specified component to obtain, based on the target server identifier carried in the login request, the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database as the target password; the server password data includes the passwords of the cloud servers applied for by each user.

[0124] The first login module 502 is configured to log in to the target cloud server based on the target password for the target user to use the target cloud server.

[0125] The first update module 503 is configured to, for any of the cloud servers, when the preset update condition is met, modify the password of the cloud server and update the password of the cloud server in the server password data based on the modified password.

[0126] Optionally, the device 50 further includes:

[0127] The second acquisition module is configured to acquire the server information of the cloud servers applied for by each user; the server information includes the server address, username, password, and system type.

[0128] A first generation module, for the server information of any of the cloud servers, based on the server address, the user name, and the system type, generate a key name corresponding to the cloud server, and, based on the password, generate a key value corresponding to the key name.

[0129] A first call module, for calling the specified component to store the key name and the key value in the form of a key-value pair in the target database, to obtain the server password data.

[0130] Optionally, the target server identifier includes a target server address and a target user name, and the first acquisition module 501 includes:

[0131] A first acquisition sub-module, for acquiring the target system type of the target cloud server.

[0132] A first generation sub-module, for generating a first key name based on the target server address, the target user name, and the target system type.

[0133] A first call sub-module, for calling the specified component to determine a first key value corresponding to the first key name from at least two key-value pairs stored in the target database for the cloud server, to obtain the target password.

[0134] Optionally, the first update module 503 includes:

[0135] A second acquisition module, for, when a preset period is reached, acquiring a target update password generated by the specified component for the cloud server, and modifying the password of the cloud server to the target update password.

[0136] A second call module, for, when the modification is completed, based on the target update password, calling the specified component to update the password of the cloud server in the server password data.

[0137] Optionally, the second acquisition module includes:

[0138] A second generation sub-module, for acquiring a target password rule of the cloud server according to the preset period, and generating an update password request based on the acquired target password rule.

[0139] A second call sub-module, for calling the specified component to generate a random number based on the update password request, as the target update password.

[0140] A first sending module, for sending a password change instruction carrying the target update password to the cloud server, so that the cloud server completes password change based on the target update password.

[0141] Optionally, the second calling module includes:

[0142] A third generation sub-module, configured to generate a second key value according to the target update password, and generate a password replacement request based on the second key value;

[0143] A third calling sub-module, configured to call the specified component to replace the key value corresponding to the cloud server in the server password data with the second key value based on the password replacement request.

[0144] Optionally, the apparatus 5 further includes:

[0145] A third calling module, configured to call a target plug-in in the password management terminal to modify the initial password rule to a target password rule that meets the preset requirements when the initial password rule in the cloud server does not meet the preset requirements; wherein, the target plug-in is a plug-in that meets the target plug-in format requirements defined by the password management terminal.

[0146] In summary, the password management apparatus provided by the embodiments of the present invention, by responding to a login request sent by a target user, calls a specified component to obtain, from the server password data stored in a target database, the password of a target cloud server indicated by the target server identifier carried in the login request as a target password; the server password data includes the passwords of cloud servers applied by each user, and the passwords of each cloud server stored in the target database are periodically updated; logs in to the target cloud server based on the target password for the target user to use the target cloud server. In this way, by uniformly storing the passwords of each cloud server in the target database, a unified platform is provided for unified management of the passwords of multiple cloud servers. Modifying and updating the passwords of cloud servers based on preset update conditions can reduce the probability of passwords being cracked and improve the password security of cloud servers. At the same time, to a certain extent, the security risks brought by password leakage can be avoided, further ensuring the password security of cloud servers, and thus improving the information security management level of cloud servers. And through the login request sent by the user, the target password corresponding to the target cloud server can be automatically obtained to log in to the target cloud server for the user to use. Compared with the method of manually determining the target password, the login efficiency can be improved while ensuring the accuracy of the target password.

[0147] The present invention also provides an electronic device, see Figure 6 , including: a processor 601, a memory 602, and a computer program 6021 stored on the memory and executable on the processor, and when the processor executes the program, it implements the password management method of the foregoing embodiments.

[0148] The present invention also provides a readable storage medium. When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device can execute the password management method of the foregoing embodiments.

[0149] For the device embodiments, since they are substantially similar to the method embodiments, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiments.

[0150] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. The structure required to construct such systems will be apparent from the above description. In addition, the present invention is not directed to any particular programming language. It should be understood that the content of the present invention described herein can be implemented using various programming languages, and the description of the specific language above is to disclose the best mode of the present invention.

[0151] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that the embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures, and technologies have not been shown in detail so as not to obscure the understanding of this specification.

[0152] Similarly, it should be understood that, in order to streamline the present invention and assist in understanding one or more of the various inventive aspects, in the foregoing description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspects lie in less than all the features of the single foregoing disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into the detailed description, with each claim standing on its own as a separate embodiment of the present invention.

[0153] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and set in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be adopted to combine all the features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all the processes or units of any method or device thus disclosed. Unless otherwise explicitly stated, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) can be replaced by an alternative feature that provides the same, equivalent, or similar purpose.

[0154] Each component embodiment of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the sorting device according to the present invention. The present invention can also be implemented as a device or apparatus program for executing some or all of the methods described herein. Such a program for implementing the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0155] It should be noted that all actions of obtaining signals, information, or data in this application are carried out on the premise of complying with the corresponding data protection regulations and policies of the country where the location is located and obtaining the authorization given by the owner of the corresponding device.

[0156] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a properly programmed computer. In the unit claims listing several devices, several of these devices can be embodied by the same hardware item. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.

[0157] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0158] The foregoing are only preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

[0159] The foregoing is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present invention, and all such changes or replacements should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A password management method, applied to a password management terminal, characterized in that The method includes: In the case of receiving a login request sent by a target user, calling a specified component to obtain, based on the target server identifier carried in the login request, the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database as the target password; the server password data includes the passwords of the cloud servers applied for by each user; Logging in to the target cloud server based on the target password for the target user to use the target cloud server; For any of the cloud servers, when a preset update condition is met, modifying the password of the cloud server and updating the password of the cloud server in the server password data based on the modified password; The modifying the password of the cloud server when a preset update condition is met includes: When a preset period is reached, obtaining the target update password generated by the specified component for the cloud server and modifying the password of the cloud server to the target update password; The updating the password of the cloud server included in the server password data based on the modified password includes: When the modification is completed, calling the specified component to update the password of the cloud server in the server password data based on the target update password.

2. The method according to claim 1, wherein The method further includes: Obtaining the server information of the cloud servers applied for by each user; the server information includes the server address, username, password, and system type; For the server information of any of the cloud servers, generating a key name corresponding to the cloud server based on the server address, the username, and the system type, and generating a key value corresponding to the key name based on the password; Calling the specified component to store the key name and the key value in the form of a key-value pair in the target database to obtain the server password data.

3. The method according to claim 2, characterized in that The target server identifier includes the target server address and the target username. The calling the specified component to determine, based on the target server identifier carried in the login request, the password of the target cloud server indicated by the target server identifier from the server password data stored in the target database as the target password includes: Obtaining the target system type of the target cloud server; Generating a first key name based on the target server address, the target username, and the target system type; Calling the specified component to determine a first key value corresponding to the first key name from at least two key-value pairs corresponding to the cloud servers stored in the target database to obtain the target password.

4. The method according to claim 1, wherein The obtaining the target update password generated by the specified component for the cloud server and modifying the password of the cloud server to the target update password includes: Obtaining the target password rule of the cloud server according to the preset period and generating an update password request based on the obtained target password rule; Calling the specified component to generate a random number based on the update password request as the target update password; Send a password change instruction carrying the target updated password to the cloud server, so that the cloud server completes the password change based on the target updated password.

5. The method according to claim 1, characterized in that, Based on the target updated password, calling the specified component to update the password of the cloud server in the server password data includes: Generate a second key value according to the target updated password, and generate a password replacement request based on the second key value; Call the specified component to replace the key value corresponding to the cloud server in the server password data with the second key value based on the password replacement request.

6. The method according to claim 4, characterized in that The method further includes: When the initial password rule in the cloud server does not meet the preset requirements, call the target plug-in in the password management terminal to modify the initial password rule to a target password rule that meets the preset requirements; Wherein, the target plug-in is a plug-in that meets the target plug-in format requirements defined by the password management terminal.

7. A password management device, characterized in that, The device includes: A first acquisition module, configured to, when receiving a login request sent by a target user, call a specified component to acquire, from the server password data stored in a target database, the password of a target cloud server indicated by the target server identifier carried in the login request as a target password; the server password data includes the passwords of cloud servers applied for by each user; A first login module, configured to log in to the target cloud server based on the target password for the target user to use the target cloud server; A first update module, configured to, for any one of the cloud servers, when a preset update condition is met, modify the password of the cloud server, and update the password of the cloud server in the server password data based on the modified password; The first update module includes: A second acquisition module, configured to, when a preset period is reached, acquire the target updated password generated by the specified component for the cloud server, and modify the password of the cloud server to the target updated password; A second call module, configured to, when the modification is completed, call the specified component to update the password of the cloud server in the server password data based on the target updated password.

8. An electronic device, characterized in that, Includes: A processor, a memory, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the password management method described in any one of claims 1-6 is implemented.

9. A readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is enabled to execute the password management method described in any one of claims 1-6.

Citation Information

Patent Citations

  • Password automatic unified management system and method

    CN111859369A

  • Information processor, control method for information processor, and control program for information processor

    JP2015141691A