Account management method and system of network device, authentication platform and medium
By combining the 4A platform with the TacaCS+ protocol, centralized management and unified authentication of network device accounts are achieved, solving the problems of decentralized network device account management and control failure after upgrades, thus improving management efficiency and security.
Patent Information
- Application Number
- CN202410226736.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-28
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-02-28
AI Technical Summary
In existing technologies, network device account management is decentralized, posing a risk of account password leakage. Furthermore, after upgrading the OpenSSH version, the 4A platform's control becomes ineffective, making unified management and authorization impossible.
By introducing the TacaCS+ protocol through the 4A platform, centralized management and unified authentication of network device accounts are achieved. The authentication platform stores login information, and the terminal obtains the login information of the network device through the authentication platform, avoiding direct transmission of account passwords. Access control is managed in conjunction with the authorization service module.
It enables centralized and unified management of network device accounts, reduces the risk of account leakage, improves management efficiency, avoids the need to maintain each device individually, and ensures that network devices can still be managed normally after upgrading the OpenSSH version.
Smart Images

Figure CN118827123B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of communication, and particularly relates to a network device account management method and system, an authentication platform and a medium. BACKGROUND
[0002] The network device account is stored in the network device. At present, the administrator manages the network device account by logging in each network device through the 4A platform to perform account management operations such as adding, deleting, querying, and adding or deleting permissions, and binds the network device account as a resource from the account to the 4A platform master account. The account management system fails to centrally manage the network device account in the 4A platform, and the network device account is actually still distributed in respective network devices, which is inconvenient for unified management of the account. SUMMARY
[0003] The application embodiment provides a network device account management method and system, an authentication platform and a medium, which can uniformly manage the account logged in the network device.
[0004] In a first aspect, the application embodiment provides a network device account management method applied to an authentication platform, and the method comprises the following steps.
[0005] Receiving a login request sent by a terminal, wherein the login request comprises first login information for logging in the authentication platform;
[0006] Obtaining second login information corresponding to the first login information from login information of a plurality of network devices stored in the authentication platform, wherein the second login information is used for logging in a first network device;
[0007] Logging in the first network device by using the second login information.
[0008] In a second aspect, the application embodiment provides a network device account management system, and the system comprises the following modules.
[0009] A receiving module, configured to receive a login request sent by a terminal, wherein the login request comprises first login information for logging in the authentication platform;
[0010] A processing module, configured to obtain second login information corresponding to the first login information from login information of a plurality of network devices stored in the authentication platform, wherein the second login information is used for logging in a first network device; and log in the first network device by using the second login information.
[0011] In a third aspect, the application embodiment provides an authentication platform, comprising a processor and a memory storing computer program instructions.
[0012] The processor implements the account management method of the network device according to the first aspect when executing the computer program instructions.
[0013] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, and the computer readable storage medium stores computer program instructions, and the computer program instructions are executed by a processor to implement the account management method of the network device according to the first aspect.
[0014] The account management method, system, authentication platform and medium of the network device provided in the embodiments of the present application store login information of a plurality of network devices on the authentication platform, and when a terminal logs in the network device through the authentication platform, the authentication platform can obtain second login information according to the first login information, and logs in the first network device by using the second login information. In this process, the login information of the network device is stored on the authentication platform, so that the authentication platform can uniformly manage the login information of the plurality of devices, and since the terminal transmits the first login information for logging in the authentication platform when requesting to log in the first network device, the second login information for logging in the first network device can be prevented from being stolen in the transmission process. BRIEF DESCRIPTION OF DRAWINGS
[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. Those skilled in the art can also obtain other drawings according to these drawings without creating any creative labor.
[0016] Figure 1 is a random access process schematic diagram of a terminal provided by the present application;
[0017] Figure 2 is an account authentication and authorization process schematic diagram provided by the embodiments of the present application;
[0018] Figure 3 is a process schematic diagram of a user logging in a network device through a terminal provided by the embodiments of the present application;
[0019] Figure 4 is a process schematic diagram of a user applying for authorization to an authentication platform through a terminal provided by the embodiments of the present application;
[0020] Figure 5 is a structure schematic diagram of an account management system of a network device provided by the embodiments of the present application;
[0021] Figure 6 is a structure schematic diagram of a terminal provided by the embodiments of the present application. DETAILED DESCRIPTION
[0022] The features and exemplary embodiments of the various aspects of the present application will be described in detail below with reference to the drawings. For the purpose of clarity, the description is divided into the following sections: technical field, background, summary, detailed description, and conclusions. It will be appreciated that the specific embodiments described herein are merely intended to illustrate the application, and not to limit the application. The application can be implemented without some of the specific details, which are set forth below. The description of the embodiments is merely intended to provide a better understanding of the application through the showing of examples of the application.
[0023] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one from another entity or action, without necessarily requiring or implying any actual such relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without further limitation, an element preceded by "comprises... a" does not, without more constraints, foreclose the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0024] With the rapid growth of information-based business, the number of network devices of operators is increasing, and the existing network devices access the 4A platform (the 4A platform is a security management platform integrating account, authentication, authorization, and audit) through the proxy gateway of the SSH protocol (Secure Shell: Secure Shell protocol), and the slave account (the slave account is the account in the network device) of the network device resource is bound through the 4A master account, so as to realize the single sign-on authentication of the network device through the account password on the device and the OpenSSH protocol of the network device, and the centralized authorization and audit of the network device have been basically realized.
[0025] However, the access mode of the network device managed by the OpenSSH protocol still has multiple accounts and multiple corresponding passwords for different network devices, which is equivalent to that the account password is still stored independently in the respective network device and the 4A platform, the account password management of the network device is scattered, there is still a risk of account password leakage, and the centralized management of the account password of the network device has not been realized in a true sense.
[0026] The access mode of the network device managed by the OpenSSH protocol provides the account password filling function, the authentication and authorization of the account is actually completed by each network device respectively, the authentication and authorization is relatively scattered, and the unified authentication by the 4A platform has not been realized.
[0027] At the same time, the network device upgrades the OpenSSH version due to security vulnerabilities, which will cause the OpenSSH protocol encryption algorithm to be strengthened, the security to be improved, the 4A platform to be invalid for network device management and control, and the network device to be invalid for account management and single sign-on through the 4A platform. Therefore, the 4A management through the SSH protocol has great significance for the safe operation of the entire information system. Once someone misoperates or maliciously operates the network device, the normal operation of the entire system will be affected, and therefore the network device must be protected. Since the systems of network devices are different, remote login and misoperation are still easy to be exploited, and therefore secure identity authentication and complete log recording are essential.
[0028] Although the current 4A platform and password authentication combined identity security authentication and log recording can achieve certain effects, due to the limitations of the technology itself and the actual application range, the following deficiencies still exist:
[0029] 1) The network device account is not centrally managed, the device itself has many account passwords, the network device account is independently stored in the network device, and each network device account needs to be managed and maintained separately, which is difficult to operate and maintain, and there is a risk of account password information leakage.
[0030] 2) The existing management method binds the 4A account and the device itself through the 4A account, and the device itself is authenticated by the 4A authorization. The network device account authentication does not realize real centralized and unified authentication and unified permission management, and there is a risk of account overreach.
[0031] 3) The existing method does not centrally authorize the network device account, and the network device account permission is scattered, and needs to be authorized separately on each network device.
[0032] 4) After the network device upgrades the OpenSSH version, the OpenSSH protocol encryption algorithm is strengthened, the 4A platform management of the network device will be invalid, and the 4A platform cannot normally manage the network device account, single sign-on and log recording, and the network device often logs in by bypassing the 4A platform.
[0033] In order to solve the problems in the prior art, the embodiments of the present application provide a network device account management method, system, authentication platform and medium. First, the network device account management method provided by the embodiments of the present application is introduced.
[0034] Figure 1 The flowchart of the network device account management method provided by one embodiment of the present application is shown. As shown in FIG. 1, the network device account management method provided by one embodiment of the present application includes the following steps. Figure 1As shown, the account management method of the network device provided in the embodiment of the present application is applied to an authentication platform and includes the following steps 101-103, wherein:
[0035] Step 101, receiving a login request sent by a terminal, wherein the login request includes first login information for logging in to the authentication platform.
[0036] The authentication platform can be a 4A platform, which can also be referred to as a 4A authentication center. The first login information includes a username and a password for logging in to the authentication platform. When a user registers on the authentication platform, the authentication platform generates a platform account for the user and an identifier of a network device that can be operated by the user, and these information can be stored in a corresponding relationship, wherein the corresponding relationship includes a plurality of login information and a platform account and an identifier of a network device corresponding to each login information, and the identifier of the network device can be an access address of the network device.
[0037] Step 102, obtaining second login information corresponding to the first login information from a plurality of login information of network devices stored in the authentication platform, wherein the second login information is used for logging in to a first network device.
[0038] In the embodiment, the authentication platform stores a plurality of login information of network devices, so as to facilitate the authentication platform to uniformly manage the login accounts of the network devices.
[0039] After the user logs in to the authentication platform through the first login information, it can be determined which network device the user wants to log in to, and for the convenience of description, the network device that the user wants to log in to is determined as a first network device. The authentication platform queries the login information of the first network device from the stored plurality of login information of network devices, and the login information is referred to as second login information. The second login information can include a username and a password for logging in to the first network device.
[0040] Step 103, logging in to the first network device by using the second login information.
[0041] In the embodiment, the authentication platform stores a plurality of login information of network devices, and when the terminal logs in to the network device through the authentication platform, the authentication platform can query the second login information according to the first login information and log in to the first network device by using the second login information. In this process, the login information of the network device is stored in the authentication platform, which can facilitate the authentication platform to uniformly manage the login information of a plurality of devices, and since the terminal transmits the first login information for logging in to the authentication platform when requesting the authentication platform to log in to the first network device, the second login information for logging in to the first network device can be prevented from being stolen in the transmission process.
[0042] In the above, the authentication platform includes an account service module, an authentication service module and an authentication gateway module.
[0043] obtain, from login information of a plurality of network devices stored in the authentication platform, second login information corresponding to the first login information, including:
[0044] The account service module obtains, from the pre-obtained correspondence, a first platform account corresponding to the first login information and a first identifier of the first network device;
[0045] The account service module sends the first platform account, the first identifier and the encrypted data message to the first network device, and the first network device sends a start message to the authentication gateway module, wherein the data message includes first information, the first information includes at least one of a first username and a first password for logging in to the first network device, and the start message includes the first platform account, the first identifier and the data message.
[0046] After receiving the start message, the authentication gateway module determines a decryption key according to the first platform account and the first identifier, and decrypts the data message according to the decryption key to obtain the first information.
[0047] In the above, when a user registers on the authentication platform, a correspondence will be generated, which includes login information, and a platform account and an identifier of a network device corresponding to the login information. In order to avoid leaking the login information for logging in to the first network device, the data message needs to be encrypted and sent to the first network device. The first network device sends a start message to the authentication gateway module to request decryption of the data message.
[0048] It should be noted that whether the first username is carried in the start message can be determined by the first network device. If the first username is not carried, the first network device carries the first username in a subsequent continue message.
[0049] Specifically, the decryption process includes:
[0050] The authentication gateway module sends a key query request to the authentication service module, and the key query request includes the first platform account and the first identifier.
[0051] The authentication service module queries the corresponding decryption key according to the first platform account and the first identifier, and sends the decryption key to the authentication gateway module.
[0052] The authentication gateway module decrypts the data message using the decryption key to obtain the first information.
[0053] In the above, the decryption key is stored in the authentication service module, and the authentication gateway module needs to query the authentication service module when decryption of the data message is needed, so that decryption and key query are separated, and modular implementation is facilitated.
[0054] The authentication gateway module sends a key query request to the authentication service module, and the key query request includes the first identifier.
[0055] The authentication gateway module sends a first request to the authentication service module, and the first request includes the first identifier.
[0056] The authentication service module performs black list query on the first identifier, and sends the query result to the authentication gateway module.
[0057] If the query result indicates that the first identifier is not located in the black list, the authentication gateway module sends a key query request to the authentication service module.
[0058] If the first identifier is located in the black list, the subsequent process is ended; if the first identifier is not located in the black list, the authentication gateway module sends a key query request to the authentication service module.
[0059] In the above, after the decryption key is determined according to the first platform account and the first identifier, and the data message is decrypted according to the decryption key to obtain the first information, the method further includes:
[0060] If the first information does not include the first username or the first password, the authentication gateway module sends a login information acquisition request to the first network device, and the first network device sends the login information acquisition request to the account service module, and the login information acquisition request includes the first platform account and the first identifier.
[0061] After receiving the login information acquisition request, the account service module determines the second login information according to the first platform account and the first identifier, and sends the second login information to the first network device, and the second login information includes the first username and the first password.
[0062] In this embodiment, if the first information does not include the first username or the first password, the authentication gateway module sends a login information acquisition request to the first network device to request to acquire the first username and the first password.
[0063] It should be noted that if the first information includes the first username and the first password, the first network device allows login using the first username and the first password after receiving the first information.
[0064] The first network device sends the first username and the first password to the authentication gateway module after obtaining the first username and the first password, and the authentication gateway module implements login to the first network device according to the first username and the first password, specifically, the login to the first network device by using the second login information includes:
[0065] The authentication gateway module receives a continue message sent by the first network device, and the continue message includes the first username and the first password;
[0066] The authentication gateway module sends the first username and the first password to the authentication service module;
[0067] The authentication service module performs consistency check on the first username and the first password, checks whether the first username and the first password match, generates a transaction pass according to the permission corresponding to the first username in the case of authentication passing, and sends the transaction pass to the authentication gateway module;
[0068] The authentication gateway module sends a reply message to the first network device, and the first network device sends the reply message to the account service module, and the reply message carries the transaction pass;
[0069] The account service module sends a login success message to the terminal after receiving the reply message sent by the first network device.
[0070] In the above manner, the user successfully logs in to the first network device through the terminal, and the user does not need to input the first username and the first password for logging in to the first network device in the whole process, so that information leakage can be avoided.
[0071] In another embodiment of the present application, the authentication platform further includes an authorization service module;
[0072] After the login to the first network device by using the second login information, the method further includes:
[0073] The authentication gateway module receives a privilege level request sent by the first network device, and the privilege level request is used to request to promote the permission level, and the privilege level request includes the first platform account, and the privilege level request is generated based on the authorization request sent by the terminal;
[0074] The authentication gateway module sends a permission level query request to the authorization service module, and the permission level query request includes the first platform account;
[0075] The authorization service module obtains a permission level query result according to the first platform account, and sends the permission level query result to the authentication gateway module;
[0076] The authentication gateway module sends the permission level query result to the first network device, and the first network device responds to the control command sent by the terminal according to the permission level query result.
[0077] After completing the login on the first network device through the authentication gateway module, the user can input a corresponding command in the terminal to control the user's permission on the device, including administrator and ordinary user, the permission levels are different, and the operations that can be performed are also different, the general permission level range is 1-15, the super administrator has the highest permission level 15, and the user performs each command line, and the permission control is performed, and only after the authorization is passed, the command can be executed, otherwise it cannot be executed.
[0078] In the above embodiment, the authentication gateway module receives the privilege level request sent by the first network device, the authorization service module obtains the permission level query result, and the authentication gateway module sends the permission level query result to the first network device, and the first network device responds to the control command sent by the terminal according to the permission level query result.
[0079] In the above embodiment, after the authentication gateway module sends the permission level query result to the first network device, the method further comprises:
[0080] The authentication gateway module receives the command authorization request message sent by the first network device, the command authorization request message is generated based on the control command sent by the terminal, the control command is input by the user to the terminal, and the command authorization request message includes the control command and the privilege parameter;
[0081] The authentication gateway module sends a query command authorization message to the authorization service module, and the query command authorization message includes the control command and the privilege parameter;
[0082] The authorization service module determines an authorization strategy according to the control command and the privilege parameter, and sends the authorization strategy to the authentication gateway module;
[0083] The authentication gateway module determines a first permission level corresponding to the control command according to the authorization strategy, and if the first permission level is the same as a second permission level in the permission level query result, sends an authorization result response message to the first network device, so that the first network device responds to the control command according to the authorization result response message.
[0084] In this embodiment, the user's permission can be adjusted by the above-mentioned manner to improve the user's permission, so that the first network device can execute the control command input by the user.
[0085] The account management method of the network device provided in the application is illustrated as follows.
[0086] As Figure 2 The account authentication authorization process schematic diagram provided by the embodiment of the application is shown in the figure.
[0087] Terminal Access Controller Access Control System (Tacacs+) protocol is a security protocol with enhanced functions based on TACACS protocol. The protocol is similar in function to RADIUS protocol, and adopts client / server mode to realize communication between NAS and Tacacs+ server.
[0088] The embodiment of the application is a network device account centralized management and authentication method based on 4A platform and Tacacs+ protocol. The Tacacs+ service component (also referred to as Tacacs+ authentication gateway or authentication gateway module) is introduced through the 4A platform, the existing scattered network device account is replaced by 4A account, and the account is no longer stored in each network device, thereby realizing centralized management of the account and facilitating the whole life cycle maintenance of the account.
[0089] The application adopts 4A account management module to centrally manage network device accounts through 4A platform, centrally authorizes network device accounts through 4A platform TACACS authorization module, and centrally authenticates and takes over network device accounts through 4A platform TACACS authentication module, so that network device login is completed through 4A platform (Tacacs+) authentication hub, to solve the problems of not centralized management of network device accounts, not centralized unified authentication, unified authorization, account unauthorized access, and invalid 4A platform control of network devices.
[0090] As Figure 3 The process schematic diagram for logging into the network device provided by the embodiment of the application is shown in the figure. The 4A platform integrates Tacacs+ authentication gateway to realize unified account management, centralized authentication and centralized authorization of network devices, uses ASCII authentication type, and contains START message (start message), REPLAY message (reply message) and CONTINUE message (continue message) in the authentication process. The username information can be selected to be carried in the START message, and if not, it is embodied in the CONTINUE message. The authentication process schematic diagram is as follows:
[0091] step1: the user logs into the 4A platform,Figure 3 The 4A authentication center in the network device can be understood as an account service module, the 4A authentication service can be understood as an authentication service module, and the Tacacs+ authentication gateway can be understood as an authentication gateway module.
[0092] Step 2: The 4A authentication center requests to log in the network device.
[0093] Step 3: The network device sends a START message to the Tacacs+ authentication gateway.
[0094] Step 4: The Tacacs+ authentication gateway requests a message decryption key from the 4A authentication service.
[0095] Step 5: The 4A authentication service returns the key for decryption to the Tacacs+ authentication gateway.
[0096] Step 6: The Tacacs+ authentication gateway decrypts the START message.
[0097] Step 7: After decrypting the message, the Tacacs+ authentication gateway determines whether the START message contains a username and a password.
[0098] Step 8: If the START message does not contain a username or a password, the network device requests the username or the password from the 4A authentication center.
[0099] Step 9: The 4A authentication center queries the password corresponding to the account and returns the password to the user device.
[0100] Step 10: After obtaining the account and the password returned by the 4A authentication center, the network device initiates an authentication process using a CONTINUE message, performs consistency checking, and receives the consistency checking result fed back by the user management device, wherein the message contains a username and a password used for TACACS service authentication.
[0101] Step 11: The Tacacs+ authentication gateway requests consistency checking from the 4A authentication service.
[0102] Step 12: When the consistency checking result is in compliance, according to the authentication type, the username, and the authentication data, the transaction pass of the 4A platform is sent to the Tacacs+ authentication gateway.
[0103] Step 13: The Tacacs+ authentication gateway sends a REPLAY message to respond to the CONTINUE request.
[0104] Step 14: The network device sends a REPLAY message to respond to the 4A authentication center.
[0105] Step 15: After the 4A authentication center successfully authenticates, it returns a user TACACS authentication login success result, and sends transaction request information and user login success information to the Tacacs+ authentication gateway.
[0106] After the 4A linkage Tacacs+ authentication gateway completes the authentication login success, the user inputs a corresponding command to control the user's authority on the device, including administrators and ordinary users. The authority levels are different, and the operations that can be performed are also different. Generally, the authority level range is 1-15, and the super administrator has the highest authority level 15. When the user executes each command line, the authority control is performed. Only after the authorization passes can the command be executed, otherwise it cannot be executed.
[0107] When a special user needs to be temporarily promoted, a promotion request will be initiated, and the interface returns whether the promotion is successful. If successful, the user is given the defined highest authority to release the authority;
[0108] Figure 4 As shown in FIG. 1, the 4A platform Tacacs+ authorization process is shown in FIG. 1, as shown in FIG. 1: Figure 4
[0109] Step 1: After the user is successfully authenticated by the 4A authentication center, the user has single sign-on to the network device. The user inputs a promotion command to initiate an authorization application;
[0110] Step 2: The network device requests a privilege level through a command authorization message to the Tacacs+ authentication gateway;
[0111] Step 3: After the Tacacs+ authentication gateway receives the command authorization message from the network device side, it requests a permission level from the 4A authorization service;
[0112] Step 4: The 4A authorization service (i.e., the authorization service module) returns the permission level corresponding to the request of the Tacacs+ authentication gateway;
[0113] Step 5: After the Tacacs+ authentication gateway receives the permission level return value from the 4A authorization service, it replies to the network device privilege level request;
[0114] Step 6: The user inputs a device control command to request control operation of the network device;
[0115] Step 7: After the network device receives the user control command, it sends a command authorization request message to the Tacacs+ authentication gateway;
[0116] Step 8-Step 11: The Tacacs+ authentication gateway queries the command authorization from the 4A authorization service, and performs consistency audit on the returned authorization information. After the audit is consistent, it replies to the network device request;
[0117] Step 12: The Tacacs+ authentication gateway replies to the network device command authorization request, and sends a command authorization result response message to the network device.
[0118] Step 13: The network device receives the authorization return result, executes the user input control command, returns the command execution result to the user, and the command authorization is successful.
[0119] The present application realizes the centralized management and authentication of network device accounts based on the 4A platform and the Tacacs+ protocol, realizes the use of 4A accounts for network device accounts, realizes unified account management, unified authorization and centralized authentication; the network device no longer stores and maintains device accounts and passwords locally, realizes the centralized management, authentication and authorization of network device accounts, and the main advantages are as follows:
[0120] 1) The network device accounts are centrally and uniformly managed, the network device accounts and passwords are no longer stored independently in the network device, and each network device account does not need to be managed separately, which improves the account maintenance efficiency and reduces the risk of account leakage.
[0121] 2) The network device realizes the centralized and unified authentication of accounts in a true sense, and eliminates the risk of unauthorized access of local authentication of the network device.
[0122] 3) The network device accounts are centrally and uniformly authorized, and the permissions of the network device accounts are no longer scattered, and there is no need to authorize each network device on each network device, which improves the authorization efficiency.
[0123] 4) The device management mode is optimized, after the network device upgrades the OpenSSH version, the 4A platform no longer fails to manage and control the network device, and the 4A platform can normally manage and single sign-on the network device.
[0124] Figure 5 The structure diagram of the account management system of the network device provided by the embodiment of the present application is shown.
[0125] As shown in Figure 5 , the account management system of the network device, the device 300 comprises:
[0126] The receiving module 301 is configured to receive a login request sent by a terminal, wherein the login request comprises first login information for logging in to the authentication platform;
[0127] The processing module 302 is configured to obtain second login information corresponding to the first login information from login information of a plurality of network devices stored in the authentication platform, wherein the second login information is used for logging in to a first network device; and log in to the first network device by using the second login information.
[0128] In an embodiment of the present application, the processing module 302 comprises an account service module, an authentication service module and an authentication gateway module.
[0129] The account service module is configured to obtain, from a pre-acquired correspondence relationship, a first platform account corresponding to the first login information and a first identifier of a first network device, wherein the correspondence relationship comprises a plurality of login information, and a platform account and an identifier of a network device corresponding to each login information.
[0130] The account service module is configured to obtain, from a pre-acquired correspondence relationship, a first platform account corresponding to the first login information and a first identifier of a first network device, wherein the correspondence relationship comprises a plurality of login information, and a platform account and an identifier of a network device corresponding to each login information.
[0131] The authentication gateway module is configured to, after receiving the start message, determine a decryption key according to the first platform account and the first identifier, and decrypt the data message according to the decryption key to obtain the first information.
[0132] In an embodiment of the present application, the authentication gateway module is further configured to send a key query request to the authentication service module, wherein the key query request comprises the first platform account and the first identifier.
[0133] The authentication service module is configured to query a corresponding decryption key according to the first platform account and the first identifier, and send the decryption key to the authentication gateway module.
[0134] The authentication gateway module is further configured to decrypt the data message by using the decryption key to obtain the first information.
[0135] In an embodiment of the present application, the authentication gateway module is further configured to send a first request to the authentication service module, wherein the first request comprises the first identifier.
[0136] The authentication service module is further configured to perform a blacklist query on the first identifier, and send a query result to the authentication gateway module.
[0137] In a case where the query result indicates that the first identifier is not located in the blacklist, the authentication gateway module is further configured to send a key query request to the authentication service module.
[0138] In an embodiment of the present application, if the first information does not include the first username or the first password, the authentication gateway module is further configured to send a login information obtaining request to the first network device, send the login information obtaining request to an account service module by the first network device, and the login information obtaining request includes the first platform account and the first identifier.
[0139] The account service module is further configured to determine the second login information according to the first platform account and the first identifier after receiving the login information obtaining request, and send the second login information to the first network device, and the second login information includes the first username and the first password.
[0140] In an embodiment of the present application, the authentication gateway module is further configured to receive a continue message sent by the first network device, and the continue message includes the first username and the first password.
[0141] The authentication gateway module is further configured to send the first username and the first password to the authentication service module.
[0142] The authentication service module is further configured to perform consistency check on the first username and the first password, and generate a transaction pass according to the permission corresponding to the first username in the case of authentication passing, and send the transaction pass to the authentication gateway module.
[0143] The authentication gateway module is further configured to send a reply message to the first network device, and the first network device sends the reply message to the account service module, and the reply message carries the transaction pass.
[0144] The account service module is further configured to send a login success message to the terminal after receiving the reply message sent by the first network device.
[0145] In an embodiment of the present application, the authentication platform further includes an authorization service module.
[0146] The authentication gateway module is further configured to receive a privilege level request sent by the first network device, the privilege level request is used to request to promote the permission level, the privilege level request includes the first platform account, and the privilege level request is generated based on the authorization request sent by the terminal; send a permission level query request to the authorization service module, and the permission level query request includes the first platform account.
[0147] The authorization service module is further configured to obtain a permission level query result according to the first platform account, and send the permission level query result to the authentication gateway module.
[0148] The authentication gateway module is further configured to send the permission level query result to the first network device, and the first network device responds to the control command sent by the terminal according to the permission level query result.
[0149] In an embodiment of the present application, the authentication gateway module is further configured to receive a command authorization request message sent by the first network device, the command authorization request message is generated based on the control command sent by the terminal, and the command authorization request message includes the control command and an escalation parameter;
[0150] The authentication gateway module is further configured to send a query command authorization message to the authorization service module, and the query command authorization message includes the control command and the escalation parameter;
[0151] The authorization service module is further configured to determine an authorization policy according to the control command and the escalation parameter, and send the authorization policy to the authentication gateway module;
[0152] The authentication gateway module is further configured to determine a first permission level corresponding to the control command according to the authorization policy, and if the first permission level is the same as a second permission level in the permission level query result, send an authorization result response message to the first network device, so that the first network device responds to the control command according to the authorization result response message.
[0153] The account management system 300 of the network device provided by the embodiments of the present application can realize the various processes realized by the account management method of the network device, and achieve the same technical effects. To avoid repetition, details are not repeated here.
[0154] Figure 6 A hardware structure schematic diagram of an authentication center provided by an embodiment of the present application is shown.
[0155] The authentication center can include a processor 401 and a memory 402 storing computer program instructions.
[0156] Specifically, the processor 401 described above can include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or can be configured to implement one or more integrated circuits of the embodiments of the present application.
[0157] The memory 402 can include mass storage for data or instructions. As an example and not by way of limitation, the memory 402 can include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disc (e.g., a compact disc (CD) or a digital versatile disc (DVD)), a solid-state drive (SSD), a USB drive, or a combination of two or more of these. Where appropriate, the memory 402 can include removable or non-removable (or fixed) media. Where appropriate, the memory 402 can be internal or external to the integrated gateway disaster recovery appliance. In particular embodiments, the memory 402 is non-volatile, solid-state memory.
[0158] The memory can include read-only memory (ROM), random-access memory (RAM), magnetic disk storage mediums, optical storage mediums, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software that, when executed (by one or more processors), is operable to
[0159] The processor 401 implements any one of the information auditing methods in the above embodiments by reading and executing the computer program instructions stored in the memory 402.
[0160] In one example, the electronic device can further include a communication interface 403 and a bus 410. As shown, the processor 401, the memory 402, and the communication interface 403 are connected through the bus 410 and complete communication among each other. Figure 6
[0161] The communication interface 403 is mainly used to realize the communication between the modules, devices, units, and / or equipment in the embodiments of the present application.
[0162] Bus 410 includes a hardware, software, or both that couples components of the information auditing method or verification device to each other. As an example without limitation, bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand™ interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or another suitable bus or a combination of two or more of these. Where appropriate, bus 410 can include one or more buses. Although the present application is described and illustrated with a particular bus, it is not intended to be limited to this arrangement.
[0163] In addition, in combination with the account management method of the network device in the above embodiments, the embodiments of the present application can provide a computer storage medium for implementation. The computer storage medium has computer program instructions stored thereon; the computer program instructions are executed by a processor to implement any of the account management methods of the network device in the above embodiments.
[0164] It is to be understood that the present application is not limited to the particular configurations and processes described and illustrated herein. Detailed descriptions of known methods are omitted so as not to obscure the description of the present application. In the above embodiments, several specific steps are described and illustrated as examples. However, the method processes of the present application are not limited to the specific steps described and illustrated, and one skilled in the art can make various changes, modifications and additions, or change the order of the steps, after understanding the spirit of the present application.
[0165] The functional blocks shown in the structural block diagrams described above can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present application are program or code segments used to perform the required tasks. The program or code segments can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine-readable medium" can include any medium capable of storing or transmitting information. Examples of the machine-readable medium include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segments can be downloaded via a computer network such as the Internet, an intranet, etc.
[0166] It is also important to note that the example embodiments described herein can be implemented in a variety of environments and applications. Although the example embodiments are described in the context of a particular implementation, those skilled in the art will appreciate that the example embodiments described herein are not limited for use with the particular implementation described but are to be applied with any other systems, where typically an improved method, system and computer program product is needed. The specific embodiments below are described to first illustrate the general methodology.
[0167] In addition, the network device account management method described in the above embodiments can be implemented by a computer storage medium. The computer storage medium stores computer program instructions. The computer program instructions are executed by a processor to implement any of the network device account management methods described in the above embodiments.
[0168] It is to be understood that the specific configurations and processes described above are merely illustrative and that the application is not limited to the specific configurations and processes described above. For the sake of brevity, the detailed descriptions of known methods are omitted. In the above embodiments, a number of specific steps are described and illustrated as examples. However, the method processes of the present application are not limited to the specific steps described and illustrated, and those skilled in the art can make various changes, modifications and additions, or change the order of the steps, after understanding the spirit of the present application.
[0169] The functional blocks shown in the structural block diagrams described above can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present application are program or code segments used to perform the required tasks. The program or code segments can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segments can be downloaded via a computer network such as the Internet, an intranet, etc.
[0170] It is also important to note that the example embodiments described herein can be implemented in a variety of environments and applications. Although the example embodiments are described in the context of a particular implementation, those skilled in the art will appreciate that the example embodiments described herein are not limited for use with the particular implementation described but are to be applied with any other systems, where typically an improved method, system and computer program product is needed. The specific embodiments below are described to first illustrate the general methodology.
[0171] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0172] The above only is a specific implementation of the present application, and those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described system, module and unit can refer to the corresponding process in the foregoing method embodiments, which will not be described herein. It should be understood that the protection scope of the present application is not limited to this, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed in the present application, and these modifications or replacements shall be covered within the protection scope of the present application.
Claims
1. A method for managing accounts on a network device, applied to an authentication platform, characterized in that, The method comprises: receiving a login request sent by a terminal, the login request comprising first login information for logging into the authentication platform; obtaining second login information corresponding to the first login information from login information of a plurality of network devices stored by the authentication platform, the second login information being used for logging into a first network device; logging into the first network device using the second login information; The authentication platform comprises an account service module, an authentication service module and an authentication gateway module. Obtaining the second login information corresponding to the first login information from the login information of the plurality of network devices stored by the authentication platform comprises: The account service module obtains a first platform account corresponding to the first login information and a first identifier of the first network device from a pre-obtained correspondence relationship, wherein the correspondence relationship comprises a plurality of login information and a platform account and an identifier of a network device corresponding to each login information; The account service module sends the first platform account, the first identifier and an encrypted data packet to the first network device, and the first network device sends a start message to the authentication gateway module, wherein the data packet comprises first information, the first information comprises at least one of a first username and a first password for logging into the first network device, and the start message comprises the first platform account, the first identifier and the data packet; The authentication gateway module determines a decryption key according to the first platform account and the first identifier after receiving the start message, and decrypts the data packet according to the decryption key to obtain the first information.
2. The method of claim 1, wherein, The authentication gateway module determines a decryption key according to the first platform account and the first identifier after receiving the start message, and decrypts the data packet according to the decryption key to obtain the first information, comprising: The authentication gateway module sends a key query request to the authentication service module, wherein the key query request comprises the first platform account and the first identifier; The authentication service module queries a corresponding decryption key according to the first platform account and the first identifier, and sends the decryption key to the authentication gateway module; The authentication gateway module decrypts the data packet using the decryption key to obtain the first information.
3. The method of claim 1, wherein, The authentication gateway module sends a key query request to the authentication service module, comprising: The authentication gateway module sends a first request to the authentication service module, wherein the first request comprises the first identifier; The authentication service module performs blacklist query on the first identifier, and sends the query result to the authentication gateway module; In the case where the query result indicates that the first identifier is not located in the blacklist, the authentication gateway module sends a key query request to the authentication service module.
4. The method according to any one of claims 1-3, characterized in that, After determining the decryption key according to the first platform account and the first identifier, and decrypting the data packet according to the decryption key to obtain the first information, the method further comprises: If the first information does not include the first username or the first password, the authentication gateway module sends a login information acquisition request to the first network device, the first network device sends the login information acquisition request to an account service module, and the login information acquisition request includes the first platform account and the first identifier; After receiving the login information acquisition request, the account service module determines the second login information according to the first platform account and the first identifier, and sends the second login information to the first network device, wherein the second login information includes the first username and the first password.
5. The method of claim 4, wherein, The login of the first network device by using the second login information includes: The authentication gateway module receives a continue message sent by the first network device, and the continue message includes the first username and the first password; The authentication gateway module sends the first username and the first password to the authentication service module; The authentication service module performs consistency check on the first username and the first password, and generates a transaction pass according to the authority corresponding to the first username in the case of authentication passing, and sends the transaction pass to the authentication gateway module; The authentication gateway module sends a reply message to the first network device, and the first network device sends the reply message to the account service module, and the reply message carries the transaction pass; After receiving the reply message sent by the first network device, the account service module sends a login success message to the terminal.
6. The method of claim 1, wherein, The authentication platform further includes an authorization service module; After the login of the first network device by using the second login information, the method further includes: The authentication gateway module receives a privilege level request sent by the first network device, and the privilege level request is used to request to promote the authority level, and the privilege level request includes the first platform account, and the privilege level request is generated based on the authorization request sent by the terminal; The authentication gateway module sends an authority level query request to the authorization service module, and the authority level query request includes the first platform account; The authorization service module obtains an authority level query result according to the first platform account, and sends the authority level query result to the authentication gateway module; The authentication gateway module sends the authority level query result to the first network device, and the first network device responds to the control command sent by the terminal according to the authority level query result.
7. The method of claim 6, wherein, After the authentication gateway module sends the authority level query result to the first network device, the method further includes: The authentication gateway module receives a command authorization request message sent by the first network device, and the command authorization request message is generated based on the control command sent by the terminal, and the command authorization request message includes the control command and the privilege parameter; The authentication gateway module receives a command authorization request message sent by the first network device, and the command authorization request message is generated based on the control command sent by the terminal, and the command authorization request message includes the control command and the privilege parameter; The authentication gateway module sends a query command authorization message to the authorization service module, the query command authorization message including the control command and the privilege parameter; The authorization service module determines an authorization policy according to the control command and the privilege parameter, and sends the authorization policy to the authentication gateway module; The authentication gateway module determines a first permission level corresponding to the control command according to the authorization policy, and if the first permission level is the same as a second permission level in the permission level query result, sends an authorization result response message to the first network device, so that the first network device responds to the control command according to the authorization result response message.
8. An account management system of a network device, applied to an authentication platform, characterized in that, The system comprises: A receiving module configured to receive a login request sent by a terminal, the login request including first login information for logging into the authentication platform; A processing module configured to obtain second login information corresponding to the first login information from login information of a plurality of network devices stored in the authentication platform, the second login information being used for logging into a first network device; and log into the first network device using the second login information. The authentication platform comprises an account service module, an authentication service module, and an authentication gateway module. The processing module comprises: The account service module is configured to obtain a first platform account corresponding to the first login information and a first identifier of the first network device from a pre-obtained correspondence relationship, wherein the correspondence relationship includes a plurality of login information, and a platform account and a network device identifier corresponding to each login information; and further configured to send the first platform account, the first identifier, and an encrypted data message to the first network device, the data message including first information, the first information including at least one of a first username and a first password for logging into the first network device. The authentication gateway module is configured to receive a start message sent by the first network device, the start message including the first platform account, the first identifier, and the data message; and further configured to determine a decryption key according to the first platform account and the first identifier after receiving the start message, and decrypt the data message according to the decryption key to obtain the first information.
9. An authentication platform characterized by, Comprise: A processor and a memory having computer program instructions stored therein; The processor executes the computer program instructions to implement the method of any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium has computer program instructions stored thereon, and the computer program instructions are executed by the processor to implement the method of any one of claims 1-7.
Citation Information
Patent Citations
Single sign-on method, single sign-on terminal and single sign-on system
CN107294916A
Account login verification method, account login verification device, computer equipment, and storage medium
CN108365958A