An EPICS-based human-computer interaction permission management method and system
By deploying CA gateway and MySQL database in the EPICS IOC and Phoebus human-computer interaction interface, the problem of user switching affecting the operation of host programs and the inability to switch freely is solved, and user finesse permission management and cross-host permission switching are realized.
Patent Information
- Application Number
- CN202211471403.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-23
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2042-11-23
AI Technical Summary
In the prior art, user switching behavior will affect the programs running on the current host, and users cannot switch freely within the human-computer interactive interface, which cannot meet the user's finest permission management and the permission switching needs of the same user between different hosts.
By running EPICS IOC in the IOC server that controls the subnet, and deploying a human-computer interaction interface developed based on Phoebus on the user subnet, using a dual network card server as a gateway server, deploying a CA gateway and MySQL database. The system independently stores user account information, and uses permission management to assist the permission configuration files of the IOC and CA gateway, so as to realize user finesse permission management and free switching.
It realizes programs that do not affect the current host running, and realizes free switching of users within the human-computer interactive interface, meeting the user's fineness permission management and the permission switching needs of the same user between different hosts.
Smart Images

Figure CN115859233B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of human-computer interaction permission management and the application of a control system developed based on the EPICS environment, and particularly relates to a human-computer interaction permission management method and system. Background Art
[0002] Large scientific installations such as laser accelerators have the characteristics of having a large number of devices, complex subsystems, a large number of staff and experimental personnel, etc. Due to the complexity of the system, during the commissioning and use of the installation, it is necessary to control the operations of personnel accordingly to prevent system failures and equipment damage caused by incorrect operations. The operator's permissions should be managed by dividing different operation levels, and the management methods are divided into horizontal permission division and vertical permission division. The former refers to the division according to different equipment areas of the accelerator installation, and the latter refers to the division of the operation levels of different personnel groups in the same area.
[0003] The Experimental Physics and Industrial Control System (EPICS) is a commonly used control system architecture for large scientific installations at present. Data is published in the form of Process Variables (PVs), and its basic access mechanism is a channel access mechanism called Channel Access (CA) established on top of the TCP / IP protocol. Phoebus is a human-computer interaction interface development tool for EPICS. In this architecture, under the requirement of managing only the most front-end human-computer interaction layer without affecting the operation of the Input Output Controller (IOC), the isolation of network segments and the control of access permissions for the host where the human-computer interaction interface is located can be achieved by deploying a CA gateway across network segments, so that general users of the control system cannot directly modify the underlying programs and variables.
[0004] The CA gateway's permission management is based on three criteria: the source host of the access request, the current user of the source host, and the current running time. The first is verified by capturing the source host name of the request, the second is verified by capturing the current account of the source host's operating system, and the third is judged in real time through the operations written in the permission configuration file. However, to implement the functions of user authentication and permission management, the development goal of the permission management system should be to achieve user-level permission management and be able to implement user login, logout, and real-time permission changes within a human-machine interaction interface developed based on Phoebus. The CA gateway's method of capturing the current user from the host operating system causes the need to switch accounts through the host operating system user switch, which will affect the programs running on the current host, and cannot achieve the goal of free user switching within the human-machine interaction interface, nor is it applicable to the application scenario where the same user switches between different hosts, and cannot meet the corresponding design requirements. Summary of the Invention
[0005] The object of the present invention is to provide a human-machine interaction permission management method and system to solve the problem that user switching affects the programs running on the current host and users within the human-machine interaction interface cannot be freely switched.
[0006] A human-machine interaction permission management method includes:
[0007] Run EPICS IOC in the IOC server of the control subnet, deploy a human-machine interaction interface developed based on Phoebus in the human-machine interaction host of the user subnet, use a dual-network card server that spans the network segments of the control subnet and the user subnet as the gateway server, deploy the CA gateway and the MySQL database, and store the user name, password, and the permission group to which the user belongs in the MySQL database with the user name as the primary key;
[0008] Develop a supporting login window in the human-machine interaction interface and set up a permission management auxiliary IOC; the login window links to the MySQL database; the permission management auxiliary IOC is used to read the current logged-in user and the permission group to which the user belongs on each host;
[0009] According to the user name input in the login window, publish the permission group to which the logged-in user of the current host belongs and the user name of the logged-in user to the permission management auxiliary IOC, and determine the process variable of the permission group corresponding to the current host and the process variable of the user corresponding to the current host;
[0010] In the permission configuration file of the CA gateway, configure the open permissions of each host according to the process variable of the permission group and the process variable of the user; the open permissions include non-accessible permissions, read-only permissions, and writable permissions.
[0011] Optionally, before publishing the user's affiliated permission group and the username of the logged-in user of the current host to the permission management auxiliary IOC according to the username entered in the login window and determining the process variables of the permission group record corresponding to the current host and the process variables of the user record corresponding to the current host, it further includes:
[0012] Verify the username and password entered in the login window using the MySQL database.
[0013] Optionally, after configuring the open permissions of each host according to the process variables of the permission group record and the process variables of the user record in the permission configuration file of the CA gateway, it further includes:
[0014] Classify the open permissions into different levels, so that the low-level read-only permission reads the numerical values of the process variables in the EPICS IOC that are open to the logged-in user and the user's affiliated permission group with the low-level read-only permission, and the high-level read-only permission reads the configuration information of the process variables in the EPICS IOC that are open to the logged-in user and the user's affiliated permission group with the high-level read-only permission.
[0015] A human-computer interaction permission management system, comprising:
[0016] A deployment module, used to run EPICS IOC in the IOC server of the control subnet, deploy a human-computer interaction interface developed based on Phoebus in the human-computer interaction host of the user subnet, use a dual-network card server that spans the network segments of the control subnet and the user subnet as a gateway server, deploy a CA gateway and a MySQL database, and store the username, password, and the user's affiliated permission group in the MySQL database with the username as the primary key;
[0017] A permission management auxiliary IOC setting and login window linking module, used to develop a supporting login window in the human-computer interaction interface and set up a permission management auxiliary IOC; the login window links to the MySQL database; the permission management auxiliary IOC is used to read the current logged-in user and the user's affiliated permission group of each host;
[0018] A process variable recording module, used to publish the user's affiliated permission group and the username of the logged-in user of the current host to the permission management auxiliary IOC according to the username entered in the login window, and determine the process variables of the permission group record corresponding to the current host and the process variables of the user record corresponding to the current host;
[0019] An open permission configuration module is used to configure the open permissions of each host according to the process variable records of the permission group and the process variable records of the user in the permission configuration file of the CA gateway; the open permissions include non-accessible permissions, read-only permissions, and writable permissions.
[0020] Optionally, it further includes:
[0021] A verification unit is used to verify the username and password input in the login window by using the MySQL database.
[0022] Optionally, it further includes:
[0023] A permission level division module is used to divide the open permissions into permission levels, so that the low-level read-only permission reads the numerical values of the process variables in the EPICS IOC that are open to the logged-in user and the permission group to which the user belongs, and the high-level read-only permission reads the configuration information of the process variables in the EPICS IOC that are open to the logged-in user and the permission group to which the user belongs.
[0024] An electronic device includes a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the above-mentioned human-computer interaction permission management method.
[0025] A computer read-only storage medium stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned human-computer interaction permission management method.
[0026] To achieve the above object, the present invention provides the following solutions:
[0027] According to the specific embodiments provided by the present invention, the present invention discloses the following technical effects: The present invention provides a human-computer interaction permission management method and system, which stores the user's account information independently in the MySQL database. By configuring the open permissions for each host, the criterion for permission granting is no longer the logged-in user of the host operating system, and the user switching behavior no longer requires switching the user of the operating system. Therefore, the user switching behavior will not affect other programs running on the current host, realizing the free switching of users within the human-computer interaction interface. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the following described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0029] Figure 1 Flowchart of the human-computer interaction permission management method provided by the present invention;
[0030] Figure 2 Schematic diagram of the hardware of the human-computer interaction permission management system provided by the present invention;
[0031] Figure 3 Structural diagram of the human-computer interaction permission management system provided by the present invention. Specific embodiments
[0032] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0033] The purpose of the present invention is to provide a human-computer interaction permission management method and system, where the user switching behavior will not affect other programs running on the current host, and the free switching of users inside the human-computer interaction interface is realized.
[0034] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.
[0035] Embodiment 1
[0036] Figure 1 Flowchart of the human-computer interaction permission management method provided by the present invention, as Figure 1 shown, a human-computer interaction permission management method includes:
[0037] Step 101: Run EPICS IOC in the IOC server of the control subnet, deploy a human-computer interaction interface developed based on Phoebus in the human-computer interaction host of the user subnet, use a dual-network card server that spans the network segment of the control subnet and the network segment of the user subnet as the gateway server, deploy a CA gateway and a MySQL database, and store the user name, password, and the permission group to which the user belongs in the MySQL database with the user name as the primary key.
[0038] In practical applications, the control subnet is network segment a, and the user subnet is network segment b.
[0039] Step 102: Develop a supporting login window in the human-computer interaction interface, and set up a permission management auxiliary IOC; the login window links to the MySQL database; the permission management auxiliary IOC is used to read the currently logged-in user and the permission group to which the user belongs on each host.
[0040] In practical applications, on the front-end operation host side, a supporting login window is developed in the Phoebus human-machine interface developed in a supporting manner, and a permission management auxiliary input / output controller (Input Output Controller, IOC) is set up.
[0041] Step 103: According to the user name input in the login window, publish the user's affiliated permission group and the user name of the logged-in user of the current host to the permission management auxiliary IOC, and determine the process variable of the permission group record corresponding to the current host and the process variable of the user record corresponding to the current host.
[0042] Before the said Step 103, it also includes: verifying the user name and password input in the login window by using the MySQL database.
[0043] In practical applications, the login window of the human-machine interface is connected to the MySQL database storing user information. When logging in, according to the input user name, the corresponding password and the user's affiliated permission group are queried. If the password is correct, the permission group to which the logged-in user of the current host belongs is published to the process variable (ProcessVariable, PV) of the permission group record corresponding to the current host in the auxiliary IOC, and the user name of the logged-in user of the current host is published to the user record PV corresponding to the current host in the auxiliary IOC.
[0044] Step 104: In the permission configuration file of the CA gateway, configure the open permissions of each host according to the process variable of the permission group record and the process variable of the user record; the open permissions include non-accessible permissions, read-only permissions, and writable permissions.
[0045] After the said Step 104, it also includes: performing a permission level division on the open permissions, so that the lower-level read-only permission reads the numerical value of the process variable of the EPICS IOC that is open to the logged-in user and the user's affiliated permission group with the lower-level read-only permission, and the higher-level read-only permission reads the configuration information of the process variable of the EPICS IOC that is open to the logged-in user and the user's affiliated permission group with the higher-level read-only permission.
[0046] In practical applications, the permission management of the Channel Access (CA) gateway has an operation function, that is, it makes real-time judgments through the operations written in the permission configuration file. Among them, the configurable parts in the configuration file include host grouping (i.e., the front-end computers that connect to the gateway and read data from the gateway), and PV grouping (i.e., differentiating PVs of different functions and different devices into groups). Thus, the open permissions of each PV group to different host groups can be configured, including no permission, read-only, and read-write, and are divided into permission level 0 and permission level 1. For example, the read-only permission of level 0 can read the value of the PV, while the read-only permission of permission level 1 can read the configuration information of the PV.
[0047] The present invention uses the PV recorded by each host user permission group as the operation input quantity in the permission configuration of the gateway, controls the permissions of the current host through the differentiation of the PV recorded by the permission group, and there is a corresponding relationship between the permission group and the user name. In this way, without changing the users of the human-computer interaction host system, user-level permission authentication and management can be realized.
[0048] Boolean operations can be written in the configuration file, and only the values of the specified PVs in the IOC are read and numerical operations and Boolean operations are performed, so that when the PV is in different numerical ranges, the open permissions of a certain PV group to each host group are different.
[0049] The permissions are divided into three levels: inaccessible, read-only, and writable. Among them, the read-only and writable permissions are further divided into high and low levels. The high permission allows the host to access all domains of the target PV, and the low permission only allows the host to access the value of the target PV.
[0050] During the CA gateway configuration process, PVs representing the permission groups to which the currently logged-in users of each host belong are introduced, and the user name, password, and the permission groups to which they belong are stored in the MySQL database. The user inputs the user name and password on the login interface developed in the front-end human-computer interaction interface of a certain host. The login interface performs identity verification according to the information stored in the MySQL. After successful verification, the user name of the currently logged-in host and the permission group to which the currently logged-in user of the host belongs are published to the PV. The CA gateway can read the PV representing the permission group to which the currently logged-in user of the host belongs, perform operations based on the value of this PV, and judge the permissions granted to this host by each PV group at this time.
[0051] The present invention can realize user login and logout, user information verification, and permission management in a human-computer interaction platform developed by Phoebus, provide storage and query of login records, realize user identity verification and read-write authorization in the front-end human-computer interaction interface layer of the EPICS control system, and can also realize permission differentiation of user groups and provide customized different permission management for different hosts.
[0052] Assign different permission management schemes to different hosts. That is, the same user can read and write variable 1 on host A, but on host B, it can be set to only read variable 1 and not write, to prevent staff from making incorrect operations on the hosts and devices of other personnel groups.
[0053] Example 2
[0054] As Figure 2 shown, the hardware of the permission management system in this embodiment includes: human-computer interaction hosts PC1, PC2, PC3, PC4, dual-network card gateway server G, IOC operation servers S1, S2, S3, S4. Among them, the network environment of PC1-4 is the user subnet local area network, the network environment of S1-4 is the control subnet local area network, and the two network cards of G straddle the user subnet and the control subnet.
[0055] PC1-4 deploy the Phoebus platform and the developed human-computer interaction interface; S1-4 deploy the EPICS environment to provide IOC operation support; G deploys the CA gateway and the MySQL database accessible by the user subnet. The CA gateway configures the EPICS PV groups and the permission authentication of each PV group on each human-computer interaction host for each user group. The user name, password, and affiliated permission group of the account are configured in the database.
[0056] The implementation of the permission control in this embodiment includes the following configuration contents:
[0057] Perform coding configuration on the CA gateway deployed on the dual-network card gateway server, and define the EPICS PV groups and the permission authentication of each PV group on each human-computer interaction host for each user group.
[0058] Specify the CA communication source as the gateway server in the human-computer interaction platform.
[0059] Configure the user name, password, and affiliated permission group of the account in the MySQL deployed in the human-computer interaction network segment.
[0060] Develop a login / logout window in the human-computer interaction interface and connect to the database for reading.
[0061] Run the IOC in the control subnet, and the human-computer interaction interface in the user subnet realizes user authentication and permission management.
[0062] In this embodiment, the PV groups are divided into laser, optical path transmission, shooting range, beam line, and operating status display, and the user permission groups are divided into User Group 1, User Group 2, User Group 3, and Management Group. Among them, PC1-3 belong to User Group 1 to 3 respectively, and PC4 belongs to the Management Group. In terms of permission design, it is divided into non-accessible, read-only, and writable. Among them, the writable permission includes the read-only permission. All members of the user groups have the read-only permission for all PV groups. Unlogged visitors all have the read-only permission for the operating status display. User Group 1 has the writable permission for laser and optical path transmission. User Group 2 has the writable permission for optical path transmission and shooting range. User Group 3 has the writable permission for the beam line. The Management Group has the writable permission for laser, optical path transmission, shooting range, and beam line. Members of User Group 1, 2, and 3 can only have the aforementioned writable permission after logging in on the PC of their own group. After logging in on other PCs, they only have the read-only permission for all PV groups. The permissions of the Management Group are not restricted by the logged-in PC, as shown in Table 1.
[0063] Table 1 PC1 Login Authentication and Permission Granting Situation Table
[0064]
[0065] The PV corresponding to the permission group of PC1 is recorded as PC1:UsrGroup, and the PV corresponding to the user of PC1 is recorded as PC1:Usr. The value of PC1:UsrGroup is 0 when not logged in, and is 1, 2, 3, 4 respectively when User Group 1 to 3 and the Management Group log in. In the configuration of the CA gateway, authentication operation configuration is carried out, and the value of PC1:UsrGroup is the authentication standard for the CA gateway to grant access permissions to PC1. That is to say, when PC1:UsrGroup = 0, the PC1 human-machine interface has no right to access the laser, optical path transmission, shooting range, and beam line PVs, and can read the operating status display PV. When PC1:UsrGroup = 1, the PC1 human-machine interface can write to the laser and optical path transmission PVs, and can read the shooting range, beam line, and operating status display PVs. When PC1:UsrGroup = 2, 3, it can read the aforementioned groups of PVs. When PC1:UsrGroup = 4, it can write to the laser, optical path transmission, shooting range, and beam line PVs, and can read the operating status display PV.
[0066] By recording the change of the value of PC1:Usr, it is possible to record who logged in to which human-machine interaction host at what time, which serves as a record of permission change logs and a trace for controlling operations.
[0067] The permission configuration method adopted in this embodiment is as described above, which gives priority to ensuring the operation permissions of the permission group members on the PC of their own group, and at the same time protects the human-machine interface of their own group from being operated by others.
[0068] Embodiment 3
[0069] To implement the method corresponding to the first embodiment above to achieve the corresponding functions and technical effects, the following provides a human-computer interaction permission management system.
[0070] Figure 3 The structure diagram of the human-computer interaction permission management system provided by the present invention is as Figure 3 shown. A human-computer interaction permission management system includes:
[0071] A deployment module 301, configured to run EPICS IOC in the IOC server of the control subnet, deploy a human-computer interaction interface developed based on Phoebus in the human-computer interaction host of the user subnet, use a dual-network card server spanning the network segments of the control subnet and the network segments of the user subnet as a gateway server, deploy a CA gateway and a MySQL database, and store the user name, password, and the permission group to which the user belongs in the MySQL database with the user name as the primary key.
[0072] A permission management auxiliary IOC setting and login window link module 302, configured to develop a supporting login window in the human-computer interaction interface and set a permission management auxiliary IOC; the login window links to the MySQL database; the permission management auxiliary IOC is used to read the currently logged-in user and the permission group to which the user belongs on each host.
[0073] A process variable recording module 303, configured to publish the permission group to which the logged-in user of the current host belongs and the user name of the logged-in user to the permission management auxiliary IOC according to the user name input in the login window, and determine the process variable of the permission group corresponding to the current host and the process variable of the user corresponding to the current host.
[0074] An open permission configuration module 304, configured to configure the open permissions of each host in the permission configuration file of the CA gateway according to the process variable of the permission group and the process variable of the user; the open permissions include non-accessible permissions, read-only permissions, and writable permissions.
[0075] The present invention further includes: a verification unit, configured to verify the user name and password input in the login window by using the MySQL database.
[0076] The present invention further includes: a permission level division module, configured to divide the open permissions into permission levels, so that the low-level read-only permission reads the numerical value of the process variable in the EPICS IOC that is open to the logged-in user and the permission group to which the user belongs for the low-level read-only permission, and the high-level read-only permission reads the configuration information of the process variable in the EPICS IOC that is open to the logged-in user and the permission group to which the user belongs for the high-level read-only permission.
[0077] In the present specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0078] In this article, specific examples are used to elaborate on the principles and implementation manners of the present invention. The descriptions of the above embodiments are only used to help understand the method of the present invention and its core idea. At the same time, for those of ordinary skill in the art, based on the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation on the present invention.
Claims
1. A human-computer interaction permission management method, characterized in that, including: Run EPICS IOC in the IOC server of the control subnet, deploy a human-machine interaction interface developed based on Phoebus in the human-machine interaction host of the user subnet, use a dual-network card server that spans the network segments of the control subnet and the user subnet as the gateway server, deploy a CA gateway and a MySQL database, and store the username, password, and the permission group to which the user belongs in the MySQL database with the username as the primary key; Develop a supporting login window in the human-machine interaction interface and set up a permission management auxiliary IOC; The login window is linked to the MySQL database; the permission management auxiliary IOC is used to read the currently logged-in user and the permission group to which the user belongs on each host; According to the username entered in the login window, publish the permission group to which the logged-in user of the current host belongs and the username of the logged-in user to the permission management auxiliary IOC, and determine the process variables of the permission group corresponding to the current host and the process variables of the user corresponding to the current host; In the permission configuration file of the CA gateway, configure the open permissions of each host according to the process variables of the permission group record and the process variables of the user record; the open permissions include non-accessible permissions, read-only permissions, and writable permissions.
2. The human-computer interaction permission management method according to claim 1, characterized in that, Before the step of publishing the permission group to which the logged-in user of the current host belongs and the username of the logged-in user to the permission management auxiliary IOC according to the username entered in the login window, and determining the process variables of the permission group corresponding to the current host and the process variables of the user corresponding to the current host, it further includes: Verify the username and password entered in the login window using the MySQL database.
3. The human-computer interaction permission management method according to claim 1, characterized in that, After the step of configuring the open permissions of each host according to the process variables of the permission group record and the process variables of the user record in the permission configuration file of the CA gateway, it further includes: Perform a permission level division on the open permissions, so that the low-level read-only permission reads the numerical values of the process variables in the EPICS IOC that are open to the logged-in user and the permission group to which the user belongs with the low-level read-only permission, and the high-level read-only permission reads the configuration information of the process variables in the EPICS IOC that are open to the logged-in user and the permission group to which the user belongs with the high-level read-only permission.
4. A human-computer interaction permission management system, characterized in that, including: A deployment module for running EPICS IOC in the IOC server of the control subnet, deploying a human-machine interaction interface developed based on Phoebus in the human-machine interaction host of the user subnet, using a dual-network card server that spans the network segments of the control subnet and the user subnet as the gateway server, deploying a CA gateway and a MySQL database, and storing the username, password, and the permission group to which the user belongs in the MySQL database with the username as the primary key; A permission management auxiliary IOC setting and login window linking module for developing a supporting login window in the human-machine interaction interface and setting up a permission management auxiliary IOC; The login window is linked to the MySQL database; the permission management auxiliary IOC is used to read the current logged-in user and the permission group to which the user belongs on each host; The process variable recording module is used to publish the permission group to which the logged-in user on the current host belongs and the user name of the logged-in user to the permission management auxiliary IOC according to the user name input in the login window, and determine the process variable of the permission group corresponding to the current host and the process variable of the user corresponding to the current host; The open permission configuration module is used to configure the open permissions of each host in the permission configuration file of the CA gateway according to the process variable of the permission group and the process variable of the user; the open permissions include non-accessible permissions, read-only permissions, and writable permissions.
5. The human-computer interaction permission management system according to claim 4, characterized in that, It further includes: The verification unit is used to verify the user name and password input in the login window by using the MySQL database.
6. The human-computer interaction permission management system according to claim 4, characterized in that, It further includes: The permission level division module is used to divide the open permissions into permission levels, so that the low-level read-only permission reads the value of the process variable of the EPICS IOC that opens the low-level read-only permission to the logged-in user and the permission group to which the user belongs, and the high-level read-only permission reads the configuration information of the process variable of the EPICS IOC that opens the high-level read-only permission to the logged-in user and the permission group to which the user belongs.
Citation Information
Patent Citations
Control method for user access of Linux host
CN110677404A
System and method for detection of malicious interactions in a computer network
US20190379694A1