A security authentication method, device, network access service device and storage medium

Through the network access service device, the corresponding security authentication processor is used to perform security authentication based on the target tenant resources requested by the client, which solves the problem that the big data storage system cannot set up different security authentication mechanisms for different tenants, and realizes a personalized security authentication solution.

CN116346498BActive Publication Date: 2025-07-08JINAN INSPUR DATA TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310501138.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-28
Publication Date
2025-07-08
Estimated Expiration
2043-04-28

AI Technical Summary

Technical Problem

The big data storage system cannot set up different security authentication mechanisms for different tenants, and it is difficult to meet the diverse needs of users.

Method used

The network access service device uses the corresponding target security authentication processor to perform security authentication processing based on the target tenant resources requested by the client, and records the mapping relationship between the tenant resources and the security authentication processor, supporting multiple security authentication mechanisms.

Benefits of technology

It has realized the setting of a personalized security authentication mechanism for different tenants to meet the diverse needs of users, while maintaining compatibility with the original security authentication mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346498B_ABST
    Figure CN116346498B_ABST
Patent Text Reader

Abstract

The present invention provides a security authentication method, device, network access service device, and storage medium, which relate to the field of big data storage systems. The method is applied to the network access service device and includes: when receiving the access request information sent by the client, determining the target tenant resource requested by the client to access according to the access request information, and determining the target security authentication processor corresponding to the target tenant resource; using the target security authentication processor to perform security authentication processing on the client; when it is determined that the client passes the security authentication, allowing the client to access the target tenant resource; when the network access service device receives the access request information sent by the client, it can perform security authentication processing on the client by using the corresponding target security authentication processor according to the target tenant resource requested by the client to access, so as to ensure that different security authentication processors can be configured for tenant resources, and further meet different security authentication requirements of users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of big data storage systems, and particularly to a security authentication method, apparatus, network access service device, and computer-readable storage medium. Background Art

[0002] A big data storage system usually sets up a corresponding network access service device to provide system access services for users. The system usually also sets up a security authentication mechanism. When a user accesses the big data storage system through the network access service, the security authentication mechanism needs to perform security authentication. To improve the utilization rate of system resources, the big data storage system can also set up a multi-tenant mechanism to provide system services to multiple tenants to achieve the effect of multi-tenant sharing of big data storage system resources. However, in the related art, the network access service device usually can only dock with a single security authentication mechanism, resulting in the big data storage system being unable to set different security authentication mechanisms for different tenants and being difficult to meet different user requirements. Summary of the Invention

[0003] The object of the present invention is to provide a security authentication method, apparatus, network access service device, and computer-readable storage medium, wherein the network access service device can perform security authentication processing on the client according to the target tenant resources requested by the client using the corresponding target security authentication processor, so as to ensure that different security authentication processors can be configured for tenant resources.

[0004] To solve the above technical problems, the present invention provides a security authentication method, including:

[0005] When receiving the access request information sent by the client, determining the target tenant resources requested by the client according to the access request information, and determining the target security authentication processor corresponding to the target tenant resources;

[0006] Performing security authentication processing on the client using the target security authentication processor;

[0007] When it is determined that the client passes the security authentication, allowing the client to access the target tenant resources.

[0008] Optionally, the determining the target tenant resources requested by the client according to the access request information, and determining the target security authentication processor corresponding to the target tenant resources includes:

[0009] Sending the access request information to a preset multi-tenant security authentication module, so that the multi-tenant security authentication module determines the target tenant resources requested by the client according to the access request information, and determines the target security authentication processor corresponding to the target tenant resources.

[0010] Optionally, before sending the access request information to a preset multi-tenant security authentication module, it further includes:

[0011] Obtain its own security authentication processor configuration, and determine whether the security authentication processor configuration corresponds to the multi-tenant mode;

[0012] If so, execute the step of sending the access request information to the preset multi-tenant security authentication module;

[0013] If not, perform security authentication processing on the client using the security authentication processor configured by itself.

[0014] Optionally, the determining the target tenant resource that the client requests to access according to the access request information, and determining the target security authentication processor corresponding to the target tenant resource includes:

[0015] Determine the target server network address that the client requests to access according to the access request information;

[0016] Use a first preset mapping table to determine the target tenant resource corresponding to the target server network address, and determine the target security authentication processor corresponding to the target tenant resource according to a second preset mapping table; the first preset mapping table is used to record the mapping relationship between the server network address and the tenant resource; the second preset mapping table is used to record the mapping relationship between each tenant resource and the security authentication processor.

[0017] Optionally, before receiving the access request information sent by the client, it further includes:

[0018] Obtain the tenant configuration information corresponding to the tenant resource;

[0019] Record the mapping relationship between the tenant resource and the server network address recorded in the tenant configuration information into the first preset mapping table;

[0020] Create a corresponding security authentication processor for the tenant resource according to the security authentication configuration information included in the tenant configuration information, and record the mapping relationship between the tenant resource and its corresponding security authentication processor into the second preset mapping table.

[0021] Optionally, before creating a corresponding security authentication processor for the tenant resource according to the security authentication configuration information included in the tenant configuration information, it further includes:

[0022] Determine whether the security authentication configuration information is included in the tenant configuration information;

[0023] If so, enter the step of creating a corresponding security authentication processor for the tenant resource according to the security authentication configuration information included in the tenant configuration information;

[0024] If not, create a default security authentication processor for the tenant resource, and record the mapping relationship between the tenant resource and the default security authentication processor in the second preset mapping table.

[0025] Optionally, the determining the target server network address that the client requests to access according to the access request information includes:

[0026] Determine the target server network address that the client requests to access according to the domain name information included in the access request information.

[0027] The present invention also provides a security authentication device, including:

[0028] A processor confirmation module, configured to, when receiving access request information sent by a client, determine a target tenant resource that the client requests to access according to the access request information, and determine a target security authentication processor corresponding to the target tenant resource;

[0029] A processing module, configured to perform security authentication processing on the client by using the target security authentication processor;

[0030] An access service module, configured to allow the client to access the target tenant resource when it is determined that the client passes the security authentication.

[0031] The present invention also provides an electronic device, including:

[0032] A memory, configured to store a computer program;

[0033] A processor, configured to implement the security authentication method as described above when executing the computer program.

[0034] The present invention also provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are loaded and executed by a processor, the security authentication method as described above is implemented.

[0035] The present invention provides a security authentication method, which is applied to a network access service device, and the method includes: when receiving access request information sent by a client, determining a target tenant resource that the client requests to access according to the access request information, and determining a target security authentication processor corresponding to the target tenant resource; performing security authentication processing on the client by using the target security authentication processor; when it is determined that the client passes the security authentication, allowing the client to access the target tenant resource.

[0036] It can be seen that when the network access service device in the present invention receives the access request information sent by the client, it can first determine the target security authentication processor corresponding to the target tenant resource requested by the client according to the access request information; subsequently, the present invention can use the target security authentication processor to perform security authentication processing on the client, and when it is determined that the client passes the security authentication, the client is allowed to access the target tenant resource. In other words, the present invention can set corresponding security authentication processors for the tenant resources of each tenant, and can record the mapping relationship between the tenant resources and the security authentication processors, so that when receiving the access request information of the client, it can automatically determine the target security authentication processor corresponding to the target tenant resource requested by the client according to the information, so as to ensure that the network access service can correspond to multiple security authentication mechanisms, and further ensure that the big data storage system can set different security authentication mechanisms for different tenants to meet the different needs of users. The present invention also provides a security authentication device, a network access service device and a computer-readable storage medium, which have the above beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0038] Figure 1 It is a flowchart of a security authentication method provided by an embodiment of the present invention;

[0039] Figure 2 It is a schematic diagram of the security authentication structure of a distributed big data storage WebHDFS provided by an embodiment of the present invention;

[0040] Figure 3 It is a flowchart of another security authentication method provided by an embodiment of the present invention;

[0041] Figure 4 It is a block diagram of the structure of a security authentication device provided by an embodiment of the present invention;

[0042] Figure 5 It is a block diagram of the structure of a network access service device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0044] A big data storage system is usually provided with a corresponding network access service device for providing system access services to users. For example, for the HDFS platform (Hadoop Distributed File System), a corresponding network access service device, WebHDFS, is usually provided. In addition, the system is usually also provided with a security authentication mechanism. When a user accesses the big data storage system through the network access service, the security authentication mechanism is required to perform security authentication. To improve the utilization rate of system resources, the big data storage system can also be provided with a multi-tenant mechanism, which can provide system services to multiple tenants to achieve the effect of multi-tenant sharing of big data storage system resources. However, in the related art, the network access service device usually only supports a single security authentication mechanism. In other words, the network access service device can only call a fixed security authentication mechanism to perform security authentication on the client. This results in the big data storage system being unable to set different security authentication mechanisms for different tenants and being difficult to meet the different needs of users. In view of this, the present invention can provide a security authentication method, in which the network access service device can perform security authentication processing on the client according to the target tenant resources requested by the client to access by using the corresponding target security authentication processor, so as to ensure that different security authentication processors can be configured for tenant resources. It should be noted that the execution entity of this method, the network access service device, specifically refers to an electronic device deployed with the network access service, such as an electronic device deployed with WebHDFS. The embodiments of the present invention do not limit the type of the electronic device on which the above network service device can be deployed. For example, it can be a personal computer, a server, etc., which can be set according to actual application requirements. Please refer to Figure 1 , Figure 1 which is a flowchart of a security authentication method provided by an embodiment of the present invention. The method may include:

[0045] S101. When receiving the access request information sent by the client, determine the target tenant resources requested by the client to access according to the access request information, and determine the target security authentication processor corresponding to the target tenant resources.

[0046] Tenant resources refer to the system resources leased by a tenant in a big data storage system, such as the file storage space leased by the tenant. To ensure that a tenant can use different security authentication mechanisms, an embodiment of the present invention enables a network access service to interface with at least two security authentication processors; in addition, during the process of configuring tenant resources, the network access service device can also record the mapping relationship between each tenant resource and the security authentication processor. Furthermore, when the network access service receives the access request information sent by the client, it will not, as in the related art, call a fixed security authentication processor, but will determine the target tenant resource that the client requests to access according to the access request information, and query the target security authentication processor corresponding to the target tenant resource according to the record, and then only need to call the target security authentication processor to perform security authentication processing on the client, so as to ensure that different security authentication processors can be set for each tenant resource and meet the different security authentication requirements of the tenant.

[0047] It should be noted that the embodiment of the present invention does not limit the security authentication processors that can be configured for each tenant resource. For example, it may include a Kerberos security authentication processor, a Simple security authentication processor, an Ldap security authentication processor, etc., which can be set according to actual application requirements.

[0048] Furthermore, it should be noted that the embodiment of the present invention does not limit how to determine the target tenant resource that the client requests to access according to the access request information. For example, the client can carry relevant information of the tenant in the access request information, and then determine the target tenant resource that the client requests to access based on this information; or, one or more server nodes can be configured for the tenant resource, so that the client can access the tenant resource through these server nodes, and then only need to record the mapping relationship between the tenant resource and the server node, and the tenant resource that the client specifically requests to access can be determined according to this mapping relationship and the target server network address (server IP address) requested by the client in the access request information. From the above description, it can be seen that the embodiment of the present invention specifically involves two mapping relationships. One is the mapping relationship between the server network address and the tenant resource, and the other is the mapping relationship between the tenant resource and the security authentication processor. The network access service only needs to pre-store the above two mapping relationships, and then can quickly find the target security authentication processor corresponding to the client when receiving the access request information sent by the client. Further, to improve the storage standardization of the mapping relationship, the network access service can specifically use a mapping table to store the above mapping relationship.

[0049] Based on this, determining the target tenant resource that the client requests to access according to the access request information and determining the target security authentication processor corresponding to the target tenant resource may include:

[0050] Step 11: Determine the target server network address that the client requests to access according to the access request information;

[0051] Step 12: Determine the target tenant resources corresponding to the target server network address by using the first preset mapping table, and determine the target security authentication processor corresponding to the target tenant resources according to the second preset mapping table; the first preset mapping table is used to record the mapping relationship between the server network address and the tenant resources; the second preset mapping table is used to record the mapping relationship between each tenant resource and the security authentication processor.

[0052] Furthermore, it should be noted that the embodiments of the present invention do not limit how to determine the target server network address accessed by the client according to the access request information. For example, the client can add a specific server network address to the access request information, and the network access service can directly extract the target server network address from the access request information; for another example, the client can access the big data storage system through a specific domain name, and the network access service can convert the specific domain name through a DNS server (Domain Name System) to obtain the corresponding target server network address. To improve the access convenience, the client can access the target tenant resources by accessing a specific domain name, and the network access service can determine the target server network address requested by the client according to the domain name information carried by the client in the access request information.

[0053] Based on this, determining the target server network address requested by the client according to the access request information may include:

[0054] Step 21: Determine the target server network address requested by the client according to the domain name information included in the access request information.

[0055] For ease of understanding, please refer to Figure 2 , Figure 2 FIG. 18 is a schematic diagram of a distributed big data storage WebHDFS security authentication structure provided by an embodiment of the present invention. Among them, the client is located in the user layer, and it accesses different tenant resources by accessing different domain names (domain name - 1, domain name - 2, domain name - 3); WebHDFS (working in a cluster form, including three nodes WebHDFS - 1, WebHDFS - 2, WebHDFS - 3) can determine the server IP (i.e., namespace) accessed by the client according to the domain name when receiving access requests from each domain name, and determine the tenant resources and security authentication processor corresponding to the server IP according to the mapping relationship, and then call the security authentication processor to perform security authentication processing on the client. After determining that the client passes the authentication, the client is allowed to access the storage pool through the above server IP.

[0056] S102. Perform security authentication processing on the client by using the target security authentication processor.

[0057] S103. When it is determined that the client passes the security authentication, the client is allowed to access the target tenant resources.

[0058] It should be noted that the embodiments of the present invention do not limit how the security authentication processor performs security authentication processing on the client. For details, reference can be made to the related technologies of the security authentication processor. For example, reference can be made to the related technologies of the Kerberos authentication processor, the Simple authentication processor, and the Ldap authentication processor.

[0059] Based on the above embodiments, when the present invention receives the access request information sent by the client, first, the target security authentication processor corresponding to the target tenant resources requested by the client can be determined according to the access request information. Subsequently, the present invention can use the target security authentication processor to perform security authentication processing on the client, and when it is determined that the client passes the security authentication, the client is allowed to access the target tenant resources. In other words, the present invention can set corresponding security authentication processors for the tenant resources of each tenant, and can record the mapping relationship between the tenant resources and the security authentication processors, so that when the access request information of the client is received, the target security authentication processor corresponding to the target tenant resources requested by the client can be automatically determined according to the information, so as to ensure that the network access service can correspond to multiple security authentication mechanisms, and further ensure that the big data storage system can set different security authentication mechanisms for different tenants to meet the different needs of users.

[0060] Based on the above embodiments, considering that directly modifying the network access service itself is likely to cause it to be incompatible with the original security authentication mechanism, and thus is likely to cause compatibility problems, the embodiments of the present invention can also construct an independent multi-tenant security authentication module. This module is used to query and call the security authentication processors corresponding to the tenant resources of each tenant, and the network access service device can use this module in accordance with the original security authentication processor usage process, so as to ensure that the network access service can achieve the docking effect of different security authentication processors for multiple tenants while being compatible with the original security authentication mechanism. Based on this, determining the target tenant resources requested by the client according to the access request information and determining the target security authentication processor corresponding to the target tenant resources may include:

[0061] S201. Send the access request information to a preset multi-tenant security authentication module, so that the multi-tenant security authentication module determines the target tenant resources requested by the client according to the access request information and determines the target security authentication processor corresponding to the target tenant resources.

[0062] As described above, the embodiment of the present invention particularly provides an independent multi-tenant security authentication module for querying and invoking the security authentication processors corresponding to the resources of each tenant. Moreover, the process of the network access service device using this multi-tenant security authentication module is similar to its process of using the original security authentication processors. Therefore, the network access service device only needs to forward the access request information sent by the client to the multi-tenant security authentication module, and the multi-tenant security authentication module can complete the querying and invocation of the relevant security authentication processors.

[0063] Furthermore, since the embodiment of the present invention can set the multi-tenant security authentication module close to the interaction process between the network access service device and the original security authentication processors, the configuration process of the network access service device for the network access service device is also similar to its configuration process for the original security authentication processors. Specifically, the network access service device usually configures the corresponding security authentication processor by configuring the security authentication processor configuration information. Therefore, the embodiment of the present invention can add a type of security authentication processor configuration information associated with the multi-tenant mode to correspond to the multi-tenant security authentication module. Furthermore, when the network access service device determines that its security authentication processor configuration corresponds to the multi-tenant mode, it can automatically invoke the multi-tenant security authentication module to implement the multi-tenant function; and when it is necessary to adjust the network access service device to work in the compatibility mode, it only needs to adjust its security authentication processor configuration information to correspond to the original security authentication processor.

[0064] Based on this, before sending the access request information to the preset multi-tenant security authentication module, it further includes:

[0065] Step 31: Obtain its own security authentication processor configuration, and determine whether the security authentication processor configuration corresponds to the multi-tenant mode; if so, proceed to Step 32; if not, proceed to Step 33;

[0066] Step 32: Execute the step of sending the access request information to the preset multi-tenant security authentication module;

[0067] Step 33: Perform security authentication processing on the client using the security authentication processor configured by itself.

[0068] Based on the above embodiments, the configuration process of the network access service will be introduced in detail below. In a possible situation, before receiving the access request information sent by the client, it may further include:

[0069] S301. Obtain the tenant configuration information corresponding to the tenant resources;

[0070] S302. Record the mapping relationship between the tenant resources recorded in the tenant configuration information and the server network address in the first preset mapping table;

[0071] S303. Create a corresponding security authentication processor for the tenant resources according to the security authentication configuration information included in the tenant configuration information, and record the mapping relationship between the tenant resources and their corresponding security authentication processors in a second preset mapping table.

[0072] As described above, embodiments of the present invention can realize the mutual association among the server network address, tenant resources, and security authentication processors through the mapping relationship. Therefore, during the configuration process, the network access service device needs to record the mapping relationship between the tenant resources in the tenant configuration information and the server network address in a first preset mapping table, and after completing the configuration of the relevant security authentication processors according to the security authentication configuration information in the tenant configuration information, record the mapping relationship between the tenant resources and the security authentication processors in a second preset mapping table for subsequent query.

[0073] Furthermore, it can be understood that some tenant configuration information may not carry security authentication configuration information. In this case, embodiments of the present invention may not configure a security authentication processor for this part of the tenants, or may also configure a default security authentication processor for this part of the tenants. To improve the security of the big data storage system, embodiments of the present invention may configure a default security authentication processor for the tenant resources in the tenant configuration information that do not carry security authentication configuration information.

[0074] Based on this, before creating a corresponding security authentication processor for the tenant resources according to the security authentication configuration information included in the tenant configuration information, it further includes:

[0075] Step 41: Determine whether the tenant configuration information includes security authentication configuration information; if yes, go to Step 42; if no, go to Step 43;

[0076] Step 42: Enter the step of creating a corresponding security authentication processor for the tenant resources according to the security authentication configuration information included in the tenant configuration information;

[0077] Step 43: Create a default security authentication processor for the tenant resources, and record the mapping relationship between the tenant resources and the default security authentication processor in a second preset mapping table.

[0078] It should be noted that embodiments of the present invention do not limit the specific default security authentication processor, and it can be set according to the optional security authentication processors. For example, when the optional security authentication processors include a Kerberos authentication processor and a Simple authentication processor, considering that the Simple authentication processor requires less configuration information, the Simple authentication processor can be set as the default security authentication processor.

[0079] The above security authentication method is introduced based on specific examples. Specifically, when the WebHDFS service starts, different security authentication processors can be started according to the security authentication processor configuration of WebHDFS. In a multi-tenant scenario, WebHDFS can start the multi-tenant WebHDFS security authentication module according to the pre-configured "multi-tenant", and load the mapping relationship between the server IP and tenant resources, and the WebHDFS security authentication configuration information of the tenant from the configuration file. If the WebHDFS security authentication method of the tenant is configured as the Kerberos method, the processor parameters such as the Principal and Keytab corresponding to the tenant are further obtained to create a Kerberos security authentication processor for the tenant; if the tenant is not configured as the Kerberos method, a Simple security authentication processor is created for the tenant. In addition, a default Simple security authentication processor is also started for the security authentication of tenants with default configured security authentication methods. Finally, the mapping relationship between the tenant and the security authentication processor is cached in the multi-tenant WebHDFS security authentication module. There are mainly several corresponding relationships in the multi-tenant security authentication module: the mapping relationship between the server IP and tenant resources (hereinafter simply referred to as "tenant mapping"), and the mapping relationship between tenant resources and security authentication processors (hereinafter simply referred to as "processor mapping"). The above two mapping relationships are used when the client accesses.

[0080] After the above configuration is completed, WebHDFS can provide different security authentication services for each tenant. Specifically, the security authentication process is as Figure 3 shown Figure 3 is a flowchart of another security authentication method provided by an embodiment of the present invention. When the client accesses, the client first establishes a network connection with WebHDFS. WebHDFS can obtain the server IP requested by the client, find the tenant resources accessed by the user from the tenant mapping relationship according to the requested server IP, and further find the corresponding security authentication processor from the processor mapping according to the tenant resources to be accessed, and perform security authentication processing of the client request in the corresponding security authentication processor.

[0081] The security authentication device, network access service device, and computer-readable storage medium provided by the embodiments of the present invention are introduced below. The security authentication device, network access service device, and computer-readable storage medium described below can be mutually corresponded and referred to with the security authentication method described above.

[0082] Please refer to Figure 4 , Figure 4 which is a structural block diagram of a security authentication device provided by an embodiment of the present invention. The device is applied to a network access service device and can include:

[0083] The processor confirmation module 401 is configured to, when receiving access request information sent by a client, determine a target tenant resource requested by the client to be accessed according to the access request information, and determine a target security authentication processor corresponding to the target tenant resource;

[0084] The processing module 402 is configured to perform security authentication processing on the client by using the target security authentication processor;

[0085] The access service module 403 is configured to allow the client to access the target tenant resource when it is determined that the client has passed the security authentication.

[0086] Optionally, the processor confirmation module 401 may include:

[0087] A sending sub-module, configured to send the access request information to a preset multi-tenant security authentication module, so that the multi-tenant security authentication module determines a target tenant resource requested by the client to be accessed according to the access request information, and determines a target security authentication processor corresponding to the target tenant resource.

[0088] Optionally, the processor confirmation module 401 may further include:

[0089] A judgment sub-module, configured to obtain its own security authentication processor configuration, and judge whether the security authentication processor configuration corresponds to the multi-tenant mode; if so, execute the step of sending the access request information to the preset multi-tenant security authentication module; if not, perform security authentication processing on the client by using the security authentication processor configured by itself.

[0090] Optionally, the processor confirmation module 401 includes:

[0091] A server-side network address determination sub-module, configured to determine a target server-side network address requested by the client to be accessed according to the access request information;

[0092] A query sub-module, configured to determine a target tenant resource corresponding to the target server-side network address by using a first preset mapping table, and determine a target security authentication processor corresponding to the target tenant resource according to a second preset mapping table; the first preset mapping table is used to record the mapping relationship between the server-side network address and the tenant resource; the second preset mapping table is used to record the mapping relationship between each tenant resource and the security authentication processor.

[0093] Optionally, the apparatus may further include:

[0094] A tenant configuration information acquisition module, configured to acquire tenant configuration information corresponding to the tenant resource;

[0095] The first configuration module is used to record the mapping relationship between the tenant resources recorded in the tenant configuration information and the server network address into a first preset mapping table;

[0096] The second configuration module is used to create a corresponding security authentication processor for the tenant resources according to the security authentication configuration information included in the tenant configuration information, and record the mapping relationship between the tenant resources and their corresponding security authentication processors into a second preset mapping table.

[0097] Optionally, the second configuration module may further include:

[0098] The security authentication processor selection sub-module is used to determine whether the tenant configuration information includes security authentication configuration information; if so, it enters the step of creating a corresponding security authentication processor for the tenant resources according to the security authentication configuration information included in the tenant configuration information; if not, it creates a default security authentication processor for the tenant resources, and records the mapping relationship between the tenant resources and the default security authentication processor into a second preset mapping table.

[0099] Optionally, the server network address determination sub-module includes:

[0100] The server network address determination unit is used to determine the target server network address that the client requests to access according to the domain name information included in the access request information.

[0101] Please refer to Figure 5 , Figure 5 For the structural block diagram of a network access service device provided by an embodiment of the present invention, an embodiment of the present invention provides a network access service device 50, including a processor 51 and a memory 52; wherein, the memory 52 is used to store a computer program; the processor 51 is used to execute the security authentication method provided in the foregoing embodiment when executing the computer program.

[0102] For the specific process of the foregoing security authentication method, reference can be made to the corresponding content provided in the foregoing embodiment, and details will not be repeated here.

[0103] Moreover, as a carrier for resource storage, the memory 52 can be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the storage method can be temporary storage or permanent storage.

[0104] In addition, the network access service device 50 further includes a power supply 53, a communication interface 54, an input / output interface 55, and a communication bus 55. Among them, the power supply 53 is used to provide working voltage for each hardware device on the network access service device 50; the communication interface 54 can create a data transmission channel between the network access service device 50 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present invention, and specific limitations are not imposed here; the input / output interface 55 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and specific limitations are not imposed here.

[0105] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the security authentication method in any of the above embodiments are implemented.

[0106] Since the embodiments of the computer-readable storage medium part correspond to the embodiments of the security authentication method part, for the description of the embodiments of the storage medium part, please refer to the description of the embodiments of the security authentication method part, and details will not be repeated here.

[0107] The various embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.

[0108] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0109] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0110] The above has introduced in detail a security authentication method, device, network access service device and computer-readable storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can still be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.

Claims

1. A security authentication method, characterized in that, Applied to a network access service device, the method includes: When receiving access request information sent by a client, sending the access request information to a preset multi-tenant security authentication module, so that the multi-tenant security authentication module determines the target tenant resource requested by the client to access according to the access request information, and determines the target security authentication processor corresponding to the target tenant resource; Invoking the target security authentication processor through the multi-tenant security authentication module to perform security authentication processing on the client; When it is determined that the client passes the security authentication, allowing the client to access the target tenant resource; The determining the target tenant resource requested by the client to access according to the access request information, and determining the target security authentication processor corresponding to the target tenant resource includes: Determining the target server network address requested by the client to access according to the domain name information included in the access request information; Using a first preset mapping table to determine the target tenant resource corresponding to the target server network address, and using a second preset mapping table to determine the target security authentication processor corresponding to the target tenant resource; the first preset mapping table is used to record the mapping relationship between the server network address and the tenant resource; the second preset mapping table is used to record the mapping relationship between each tenant resource and the security authentication processor.

2. The security authentication method according to claim 1, characterized in that, Before sending the access request information to the preset multi-tenant security authentication module, it further includes: Obtaining its own security authentication processor configuration, and determining whether the security authentication processor configuration corresponds to the multi-tenant mode; If so, performing the step of sending the access request information to the preset multi-tenant security authentication module; If not, using the security authentication processor configured by itself to perform security authentication processing on the client.

3. The security authentication method according to claim 1, wherein Before receiving the access request information sent by the client, it further includes: Obtaining the tenant configuration information corresponding to the tenant resource; Recording the mapping relationship between the tenant resource and the server network address recorded in the tenant configuration information into the first preset mapping table; Creating a corresponding security authentication processor for the tenant resource according to the security authentication configuration information included in the tenant configuration information, and recording the mapping relationship between the tenant resource and its corresponding security authentication processor into the second preset mapping table.

4. The security authentication method according to claim 3, wherein Before creating a corresponding security authentication processor for the tenant resource according to the security authentication configuration information included in the tenant configuration information, it further includes: Determining whether the security authentication configuration information is included in the tenant configuration information; If so, entering the step of creating a corresponding security authentication processor for the tenant resource according to the security authentication configuration information included in the tenant configuration information; If not, creating a default security authentication processor for the tenant resource, and recording the mapping relationship between the tenant resource and the default security authentication processor into the second preset mapping table.

5. A security authentication device, characterized in that, Applied to a network access service device, the device includes: A processor confirmation module, configured to, when receiving access request information sent by a client, send the access request information to a preset multi-tenant security authentication module, so that the multi-tenant security authentication module determines a target tenant resource requested by the client to be accessed according to the access request information, and determines a target security authentication processor corresponding to the target tenant resource; A processing module, configured to call the target security authentication processor through the multi-tenant security authentication module to perform security authentication processing on the client; An access service module, configured to allow the client to access the target tenant resource when it is determined that the client passes the security authentication; The determining the target tenant resource requested by the client to be accessed according to the access request information, and determining the target security authentication processor corresponding to the target tenant resource includes: A server-side network address determination sub-module, configured to determine a target server-side network address requested by the client to be accessed according to domain name information included in the access request information; A query sub-module, configured to determine the target tenant resource corresponding to the target server-side network address by using a first preset mapping table, and determine a target security authentication processor corresponding to the target tenant resource according to a second preset mapping table; The first preset mapping table is used to record the mapping relationship between the server-side network address and the tenant resource; The second preset mapping table is used to record the mapping relationship between each tenant resource and the security authentication processor.

6. A network access service device, characterized in that, including: A memory, configured to store a computer program; A processor, configured to implement the security authentication method according to any one of claims 1 to 4 when executing the computer program.

7. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are loaded and executed by a processor, the security authentication method according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Security authentication method and system, electronic equipment, distributed storage system and medium

    CN115913793A