Access Method, Device, Equipment and Storage Medium of Operating System

By proxying the operating system's SSH service to the server, the problem of low access efficiency during direct connection access network failure is solved, and automated operating system access is realized and access efficiency is improved.

CN115988073BActive Publication Date: 2025-06-03北京自如信息科技有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211639990.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-20
Publication Date
2025-06-03
Estimated Expiration
2042-12-20

AI Technical Summary

Technical Problem

In large data centers, when the network of direct access fails, the existing indirect access cannot be automated, resulting in inefficient access of the operating system.

Method used

By proxying the operating system's SSH service to the server, the user terminal sends SSH access commands to the server, and the server responds to the SSH access commands through the proxy's SSH service to the operating system, thereby helping the user terminal to achieve access to the operating system.

Benefits of technology

It provides a new operating system access method, which can automatically achieve access to the operating system through SSH access in the event of a network failure of direct connection access, and improves the efficiency of user terminal access to the operating system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115988073B_ABST
    Figure CN115988073B_ABST
Patent Text Reader

Abstract

This application relates to a method, device, equipment, and storage medium for accessing an operating system, specifically in the field of Internet technology. The method is applied to an operating system access platform, which includes a server and a user terminal, and the server includes an operating system. The method includes: proxying the Secure Shell (SSH) service of the operating system to the server; the user terminal sending an SSH access command to the server; and the server responding to the SSH access command through the proxied SSH service of the operating system to assist the user terminal in accessing the operating system. Based on this technical solution, a new way of accessing an operating system is provided. When there is a network failure in direct connection access, the user terminal can still access the operating system automatically through the SSH access method, improving the efficiency of the user terminal accessing the operating system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet technologies, and particularly relates to a method, apparatus, device and storage medium for accessing an operating system. Background Art

[0002] Inside a large data center, operating systems (Linux or Windows) are installed inside servers. To manage the operating systems, it is necessary to provide engineers' corresponding user terminals with access methods to the operating systems.

[0003] Generally, the access methods to the operating systems include direct access and indirect access. Direct access refers to an access method in which an engineer's corresponding user terminal directly performs Secure Shell (SSH) access to the operating system; indirect access refers to an access method in which an engineer's corresponding user terminal first accesses the server through the web and then accesses the operating system through the server.

[0004] When there is a network failure in direct access, generally, the access to the operating system is achieved through indirect access. The step of accessing the server through the web in indirect access is relatively complex and cannot be automated. Summary of the Invention

[0005] The present application provides a method, apparatus, device and medium for accessing an operating system, and the technical solution is as follows.

[0006] On the one hand, a method for accessing an operating system is provided. The method is applied to an operating system access platform, and the operating system access platform includes: a server and a user terminal, and the server includes an operating system. The method includes:

[0007] Proxy the SSH service of the operating system to the server;

[0008] The user terminal sends an SSH access command to the server;

[0009] The server responds to the SSH access command through the proxied SSH service of the operating system to help the user terminal achieve access to the operating system.

[0010] On the other hand, an apparatus for accessing an operating system is provided. The apparatus includes:

[0011] A server, configured to proxy the SSH service of the operating system in the server;

[0012] A user terminal, configured to send an SSH access command to the server;

[0013] The server is used to respond to the SSH access command through the SSH service of the proxy operating system, and help the user terminal to access the operating system.

[0014] In another aspect, a computer device is provided. The computer device includes a processor and a memory. At least one instruction, at least one program, a code set or an instruction set is stored in the memory. The at least one instruction, at least one program, the code set or the instruction set is loaded and executed by the processor to implement the above-mentioned access method of the operating system.

[0015] In another aspect, a computer-readable storage medium is provided. At least one instruction, at least one program, a code set or an instruction set is stored in the computer-readable storage medium. The at least one instruction, at least one program, the code set or the instruction set is loaded and executed by a processor to implement the above-mentioned access method of the operating system.

[0016] In yet another aspect, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above-mentioned access method of the operating system.

[0017] The technical solution provided by this application may include the following beneficial effects:

[0018] The server proxies the SSH service of the operating system. The user terminal can send an SSH access command to the server. Since the server proxies the SSH service of the operating system, the server can respond to and process the SSH access command, and help the user terminal to access the operating system. A new access method for the operating system is provided. When there is a network failure in direct access, the user terminal can still access the operating system automatically through the SSH access method, improving the efficiency of the user terminal to access the operating system. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.

[0020] Figure 1 It is a schematic structural diagram of an access platform for an operating system shown according to an exemplary embodiment.

[0021] Figure 2 is a flowchart of a method for accessing an operating system according to an exemplary embodiment.

[0022] Figure 3 is a schematic structural diagram of an access platform for an operating system according to an exemplary embodiment.

[0023] Figure 4 is a flowchart of a method for accessing an operating system according to an exemplary embodiment.

[0024] Figure 5 is a flowchart of a method for accessing an operating system according to an exemplary embodiment.

[0025] Figure 6 is a block diagram of the structure of an access device for an operating system according to an exemplary embodiment.

[0026] Figure 7 is a schematic diagram of a computer device provided according to an exemplary embodiment. Detailed implementation manners

[0027] Next, the technical solutions of the present application will be clearly and completely described in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0028] It should be understood that the "indication" mentioned in the embodiments of the present application can be a direct indication, an indirect indication, or a representation of an associated relationship. For example, A indicates B, which can mean that A directly indicates B. For example, B can be obtained through A; it can also mean that A indirectly indicates B. For example, A indicates C, and B can be obtained through C; it can also mean that there is an associated relationship between A and B.

[0029] In the description of the embodiments of the present application, the term "corresponding" can represent a direct or indirect corresponding relationship between two parties, can also represent an associated relationship between the two parties, or can be a relationship such as indication and being indicated, configuration and being configured, etc.

[0030] In the embodiments of the present application, "predefined" can be implemented by pre-saving corresponding codes, tables, or other means that can be used to indicate relevant information in a device (for example, including a terminal device and a network device). The present application does not limit its specific implementation manner.

[0031] Figure 1It is a schematic structural diagram of an access platform for an operating system shown according to an exemplary embodiment. The platform includes a user terminal 110 and a server 120, and an operating system is installed inside the server 120.

[0032] Among them, the user terminal 110 can be a device used by a user (such as an engineer). For example, the user terminal 110 can be devices such as a smart phone, a tablet computer, a desktop computer, a smart wearable device, etc.

[0033] Among them, an operating system is installed in the server 120.

[0034] In the related art, the access methods to the operating system include direct access and indirect access. The user terminal 110 can directly access the operating system through SSH through a direct connection with the operating system; or, through an indirect connection between the server and the operating system, first access the server 120 through web, and then indirectly access the operating system in the server 120.

[0035] Optionally, the above-mentioned server 110 can be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, and can also be a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery network (Content Delivery Network, CDN), and big data and artificial intelligence platforms, etc.

[0036] In the embodiments of the present application, a new access method different from the existing direct access and indirect access to the operating system is provided in the access platform of the operating system. Next, the technical solutions provided by the present application will be further described.

[0037] Figure 2 It is a method flow chart of an access method for an operating system shown according to an exemplary embodiment. This method is applied to the access platform of the operating system. As Figure 2 shown, the access method for this operating system can include the following steps:

[0038] Step 210: Proxy the SSH service of the operating system to the server.

[0039] Among them, the SSH service refers to a service that guarantees the direct access method through the SSH protocol. The SSH service of the operating system can enable the user terminal to directly access the operating system through SSH.

[0040] In the embodiments of the present application, the server proxies the SSH service of the operating system. It can be understood that the server's proxying of the SSH service of the operating system does not affect the normal operation of the SSH service of the operating system itself.

[0041] Step 220: The user terminal sends an SSH access command to the server.

[0042] In the embodiments of the present application, after the server proxies the SSH service of the operating system, the user terminal can send an SSH access command to the server. Correspondingly, the server receives the SSH access command sent by the user terminal.

[0043] In a possible implementation, when there is a network failure in direct access, the user terminal sends an SSH access command to the server.

[0044] Step 230: The server responds to the SSH access command through the proxy SSH service of the operating system to help the user terminal access the operating system.

[0045] In the embodiments of the present application, after receiving the SSH access command, since the server proxies the SSH service of the operating system, the server can respond to and process the SSH access command to help the user terminal access the operating system.

[0046] Exemplarily, with reference to Figure 3 , the server 120 proxies the SSH service of the operating system. Therefore, the user terminal 110 can perform SSH access to the server 120 and then access the operating system.

[0047] It can be understood that the server can execute the above steps through a remote management card. The remote management card is generally used to maintain the hardware of the server (such as: Central Processing Unit (CPU), memory, hard disk). In addition, the remote management card can simultaneously access the operating system installed in the server.

[0048] It can be understood that in the existing access methods of the operating system, direct access is better than indirect access. This is because in direct access, SSH access is through a command-line interaction method, while in indirect access, web access requires manual operation of the web page. Therefore, compared with direct access, indirect access cannot be simulated by a machine and cannot achieve automated operation. And in the access method of the operating system provided in the above steps, it is also SSH access and can be automated.

[0049] In summary, for the access method of the operating system provided in this embodiment, the server proxies the SSH service of the operating system. The user terminal can send an SSH access command to the server. Since the server proxies the SSH service of the operating system, the server can respond to and process the SSH access command to help the user terminal access the operating system, providing a new way to access the operating system. When there is a network failure in direct connection access, the user terminal can still access the operating system automatically through the SSH access method, improving the efficiency of the user terminal to access the operating system.

[0050] In the illustrative embodiment, the proxy of the SSH service is implemented through a Transmission Control Protocol (TCP) long connection between the server and the operating system.

[0051] Specifically, the above step 210 can be alternatively implemented as:

[0052] Mount the SSH service of the operating system on the TCP long connection between the server and the operating system to implement the proxy of the SSH service of the operating system by the server.

[0053] In the embodiment of the present application, there is a TCP long connection between the server and the operating system. For example, based on this TCP long connection, indirect access to the operating system can be achieved. Therefore, the SSH service of the operating system can be mounted on this TCP long connection to implement the proxy of the SSH service.

[0054] In a possible implementation, in the case of a network failure of the operating system, the SSH service of the operating system is mounted on the TCP long connection between the server and the operating system.

[0055] That is to say, after detecting the network failure of the operating system, the SSH service can be mounted on the TCP long connection. Based on this implementation, in the scenario where direct connection access fails, the access method can be automatically switched. The server proxies the SSH service of the operating system, and then through the server that has proxied the SSH service, access to the operating system is achieved. Since the proxy of the SSH service of the operating system by the server is only executed after detecting the network failure of the operating system, the security of the access can be guaranteed.

[0056] In another possible implementation, at the time point of deploying the server, the SSH service of the operating system is mounted on the TCP long connection between the server and the operating system.

[0057] That is to say, when deploying the server, the SSH service can be mounted on the TCP long connection. Based on this implementation, the success of the mounting can be guaranteed.

[0058] In summary, the access method for the operating system provided in this embodiment provides two different mounting schemes for the SSH service to implement the proxy of the SSH service of the server to the operating system, which can be applied to different scenarios.

[0059] In the illustrative embodiment, it is necessary to enable the SSH service of the server in advance.

[0060] Figure 4 It is a flowchart of a method for accessing an operating system shown according to an exemplary embodiment. This method is applied to an access platform for an operating system. As Figure 4 shown, the access method for this operating system may include the following steps:

[0061] Step 410: Proxy the SSH service of the operating system to the server.

[0062] For the specific implementation of this step, reference may be made to the above embodiments and will not be elaborated here.

[0063] Step 420: The user terminal sends an SSH service activation instruction to the server.

[0064] Correspondingly, the server receives the SSH service activation instruction sent by the user terminal.

[0065] In a possible implementation, the generation method of the SSH service activation instruction includes: the user terminal displays an out-of-band management page of the server, and the out-of-band management page includes an SSH service activation control; the user terminal generates an SSH service activation instruction in response to a trigger operation on the SSH service activation control.

[0066] That is to say, the user can perform out-of-band management on the server through the user terminal. At this time, the user terminal displays an out-of-band management page of the server, and the out-of-band management page includes an SSH service activation control. When the user terminal receives a trigger operation of the user on the SSH service activation control, the user terminal correspondingly generates an SSH service activation instruction.

[0067] Step 430: The server activates the SSH service of the server in response to the SSH service activation instruction.

[0068] The server activates the SSH service based on the SSH service activation instruction to provide the SSH service externally.

[0069] It can be understood that this application does not limit the execution order of the above steps 410, 420 to 430. It is also possible to execute steps 420 to 430 first and then execute step 410.

[0070] Step 440: The user terminal sends an SSH access command to the server.

[0071] For the specific implementation of this step, reference may be made to the above embodiments and will not be elaborated herein.

[0072] Step 450: The server responds to the SSH access command through the SSH service of the proxy operating system to help the user terminal access the operating system.

[0073] For the specific implementation of this step, reference may be made to the above embodiments and will not be elaborated herein.

[0074] In summary, for the method for accessing an operating system provided in this embodiment, the SSH service of the server is enabled in advance so that the server provides the SSH service externally, and thus can receive the SSH access command, and responds to the SSH access command through the SSH service of the proxy operating system to help the user terminal access the operating system.

[0075] In the exemplary embodiment, the security of the SSH access command is verified first and then the SSH access command is responded to.

[0076] Figure 5 is a flowchart of a method for accessing an operating system shown according to an exemplary embodiment. This method is applied to an operating system access platform. As Figure 5 shown, the method for accessing the operating system may include the following steps:

[0077] Step 510: Proxy the SSH service of the operating system to the server.

[0078] For the specific implementation of this step, reference may be made to the above embodiments and will not be elaborated herein.

[0079] Step 520: The user terminal sends an SSH access command to the server.

[0080] For the specific implementation of this step, reference may be made to the above embodiments and will not be elaborated herein.

[0081] Step 530: The server verifies the security of the SSH access command through the configuration of an Access Control List (ACL).

[0082] That is, after the SSH service of the server is enabled, the SSH service of the operating system will be exposed, and there may be access by unknown users. To ensure the security of the access, the security of the SSH access command is verified by configuring the ACL.

[0083] In a possible implementation, when the source address of the SSH access command belongs to the ACL, the server confirms that the SSH access command is secure; when the source address of the SSH access command does not belong to the ACL, the server confirms that the SSH access command is not secure.

[0084] Step 540: When it is confirmed that the SSH access command is secure, the server responds to the SSH access command through the SSH service of the proxy operating system to help the user terminal access the operating system.

[0085] In summary, the access method for the operating system provided in this embodiment configures the ACL for the server to restrict the source address of the SSH access command, and then responds to the SSH access command only when the security check of the SSH access command passes, thus ensuring the security of the operating system.

[0086] It should be noted that the above method embodiments can be implemented separately or in combination, and the present application does not limit this.

[0087] Figure 6 It is a structural block diagram of an access device for an operating system shown according to an exemplary embodiment. The device includes:

[0088] A server 601 for proxying the Secure Shell protocol (SSH) service of the operating system in the server 601;

[0089] A user terminal 602 for sending an SSH access command to the server 601;

[0090] The server 601 for responding to the SSH access command through the proxy SSH service of the operating system to help the user terminal 602 access the operating system.

[0091] In a possible implementation, the server 601 is used to mount the SSH service of the operating system on the Transmission Control Protocol (TCP) long connection between the server 601 and the operating system to implement the proxy of the SSH service of the operating system by the server 601.

[0092] In a possible implementation, the server 601 is used to mount the SSH service of the operating system on the TCP long connection between the server 601 and the operating system in the case of a network failure of the operating system; or, at the time point of deploying the server 601, mount the SSH service of the operating system on the TCP long connection between the server 601 and the operating system.

[0093] In a possible implementation, the user terminal 602 is configured to send an SSH service activation instruction to the server 601 before sending an SSH access command from the user terminal 602 to the server 601.

[0094] The server 601 is configured to activate the SSH service of the server 601 in response to the SSH service activation instruction.

[0095] In a possible implementation, the user terminal 602 is configured to display an out-of-band management page of the server 601, where the out-of-band management page includes an SSH service activation control.

[0096] The user terminal 602 is configured to generate the SSH service activation instruction in response to a trigger operation on the SSH service activation control.

[0097] In a possible implementation, the server 601 is configured to verify the security of the SSH access command through the configuration of an access control list (ACL); when it is confirmed that the SSH access command is secure, the server 601 responds to the SSH access command through the SSH service of the proxy operating system to help the user terminal 602 access the operating system.

[0098] In a possible implementation, the server 601 is configured to confirm that the SSH access command is secure when the source address of the SSH access command belongs to the ACL; and to confirm that the SSH access command is not secure when the source address of the SSH access command does not belong to the ACL.

[0099] It should be noted that: the access device for the operating system provided in the above embodiments is only illustrated by the division of the above functional modules. In practical applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device provided in the above embodiments and the method embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be elaborated here.

[0100] Please refer to Figure 7 , which is a schematic diagram of a computer device provided according to an exemplary embodiment of the present application. The computer device includes a memory and a processor. The memory is used to store a computer program. When the computer program is executed by the processor, the above-described method for accessing an operating system is implemented.

[0101] Among them, the processor can be a Central Processing Unit (CPU). The processor can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., such as chips, or combinations of the above types of chips.

[0102] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as program instructions / modules corresponding to the methods in the embodiments of the present invention. By running the non-transitory software programs, instructions, and modules stored in the memory, the processor can execute various functional applications and data processing of the processor, that is, implement the methods in the above method embodiments.

[0103] The memory can include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created by the processor, etc. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory can optionally include a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0104] In an exemplary embodiment, a computer-readable storage medium is also provided, which is used to store at least one computer program, and the at least one computer program is loaded and executed by the processor to implement all or part of the steps in the above method. For example, the computer-readable storage medium can be a Read-Only Memory (ROM), a Random Access Memory (RAM), a Compact Disc Read-Only Memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.

[0105] Other embodiments of the present application will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.

[0106] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.

Claims

1. A method for accessing an operating system, characterized in that, the method is applied to an operating system access platform, the operating system access platform includes: a server and a user terminal, and the server includes an operating system and a remote management card, and the remote management card is used to maintain the hardware of the server and access the operating system; the method includes: the user terminal accesses the out-of-band management page of the server through the remote management card, and the out-of-band management page includes an SSH service activation control integrated with the hardware maintenance function; the user terminal generates an SSH service activation instruction in response to a trigger operation on the SSH service activation control, and sends the SSH service activation instruction to the server; the server dynamically updates the access control list ACL to add the source address of the user terminal in response to the SSH service activation instruction, and activates the SSH service of the server; proxy the Secure Shell protocol SSH service of the operating system to the server, wherein the trigger condition for the proxy is: when a network failure of the operating system is detected, or, at the initial deployment time point of the server; the user terminal sends an SSH access command to the server; the server responds to the SSH access command through the SSH service of the operating system proxied by the remote management card, and helps the user terminal to access the operating system.

2. The method according to claim 1, characterized in that, the proxying the SSH service of the operating system to the server includes: mounting the SSH service of the operating system on the Transmission Control Protocol TCP long connection between the server and the operating system to implement the proxy of the SSH service of the operating system by the server.

3. The method according to claim 2, characterized in that, the mounting the SSH service of the operating system on the TCP long connection between the server and the operating system includes: in the case of a network failure of the operating system, mounting the SSH service of the operating system on the TCP long connection between the server and the operating system; or, at the time of deploying the server, mounting the SSH service of the operating system on the TCP long connection between the server and the operating system.

4. The method according to claim 1, characterized in that, the server responds to the SSH access command through the SSH service of the operating system proxied to help the user terminal to access the operating system, including: the server checks the security of the SSH access command through the configuration of the access control list ACL; when it is confirmed that the SSH access command is secure, the server responds to the SSH access command through the SSH service of the operating system proxied to help the user terminal to access the operating system.

5. The method according to claim 4, characterized in that, The server checks the security of the SSH access command through the configuration of the ACL, including: When the source address of the SSH access command belongs to the ACL, the server confirms that the SSH access command has security; When the source address of the SSH access command does not belong to the ACL, the server confirms that the SSH access command does not have security.

6. An access device for an operating system, characterized in that the device includes: a server and a user terminal; The user terminal is used to access the out-of-band management page of the server through a remote management card. The out-of-band management page includes an SSH service activation control integrated with the hardware maintenance function; in response to a trigger operation on the SSH service activation control, generate the SSH service activation instruction and send the SSH service activation instruction to the server; The server is used to, in response to the SSH service activation instruction, dynamically update the access control list ACL to add the source address of the user terminal and activate the SSH service of the server; proxy the secure shell protocol SSH service of the operating system to the server, where the trigger condition for the proxy is: detecting a network failure of the operating system, or, at the initial deployment time point of the server; The user terminal is used to send an SSH access command to the server; The server is used to respond to the SSH access command through the SSH service of the operating system proxied by the remote management card to help the user terminal achieve access to the operating system.

7. A computer device, characterized in that the computer device includes a processor and a memory. The memory stores at least one instruction, at least one program, a code set or an instruction set. The at least one instruction, at least one program, a code set or an instruction set is loaded and executed by the processor to implement the access method of the operating system according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that the computer-readable storage medium stores at least one instruction, at least one program, a code set or an instruction set. The at least one instruction, at least one program, a code set or an instruction set is loaded and executed by a processor to implement the access method of the operating system according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Access method and device for remote host

    CN114090981A