Login control method and device based on operation and maintenance, bastion host, system, storage medium and program product
By using a bastion host system to authenticate and approve requests for operation and maintenance terminals, and automatically complete the login to the target server, the problem of easily cracked passwords in traditional bastion host systems is solved, thereby improving the security and efficiency of the operation and maintenance process.
Patent Information
- Application Number
- CN202411752099.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2044-11-29
AI Technical Summary
Traditional bastion host systems rely on password management server access permissions, which poses a risk that passwords can be easily cracked, resulting in insufficient system security and cumbersome operation and maintenance processes.
By using a bastion host system as an intermediary, the system automatically completes the login to the target server by verifying the identity of the operation and maintenance terminal and approving the request, thereby achieving centralized management and verification and preventing unauthorized access.
It improves the security and efficiency of the operation and maintenance process, simplifies the operation and maintenance process, and enhances the security and traceability of login.
Smart Images

Figure CN119520146B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computers, and in particular to a login control method, device, bastion host, system, storage medium, and program product based on operation and maintenance. Background Technology
[0002] With the advancement of technology, systems face increasing security threats, especially in server access and management. Ensuring system security and reliability has become a key focus for the industry.
[0003] Traditional bastion host systems primarily maintain security by managing server passwords and user login permissions. This relies on the server's own login failure policies to prevent unauthorized access. However, once an attacker obtains the server password through cracking methods, they can still directly access the server and launch attacks.
[0004] Therefore, there is an urgent need for a more secure bastion host operation and maintenance system solution. Summary of the Invention
[0005] This application provides a login control method, device, bastion host, system, storage medium, and program product based on operation and maintenance, which can enhance the security and traceability of operation and maintenance, and improve the efficiency and compliance of operation and maintenance management.
[0006] In a first aspect, embodiments of this application provide a login control method based on operation and maintenance, the method being applied to a bastion host, the method comprising:
[0007] In response to a first login request sent by the operation and maintenance terminal, the operation and maintenance terminal is verified; wherein, the first login request represents logging into the bastion host.
[0008] After confirming successful verification of the maintenance terminal, a second login request is sent to the target server, wherein the second login request includes the account information of the target server corresponding to the maintenance terminal.
[0009] In response to the first login response information sent by the target server, the first login response information is sent to the operation and maintenance terminal; wherein, the first login response information indicates that the operation and maintenance terminal has successfully logged into the target server.
[0010] Secondly, embodiments of this application provide a login control device based on operation and maintenance, wherein the method is applied to a bastion host, and the method includes:
[0011] The verification module is used to verify the operation and maintenance terminal in response to the first login request sent by the operation and maintenance terminal; wherein, the first login request represents logging into the bastion host;
[0012] The login module is used to send a second login request to the target server after confirming that the verification of the operation and maintenance terminal is successful. The second login request includes the account information of the target server corresponding to the operation and maintenance terminal.
[0013] The sending module is used to send the first login response information to the operation and maintenance terminal in response to the first login response information sent by the target server; wherein the first login response information indicates that the operation and maintenance terminal has successfully logged into the target server.
[0014] Thirdly, embodiments of this application provide a bastion host, including: a memory and a processor;
[0015] The memory stores computer-executed instructions;
[0016] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.
[0017] Fourthly, embodiments of this application provide a login control system based on operation and maintenance, including: an operation and maintenance terminal, a target server, and a bastion host as described in the third aspect above.
[0018] Fifthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.
[0019] In a sixth aspect, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.
[0020] This application provides a login control method, device, bastion host, system, storage medium, and program product based on operations and maintenance (O&M). The method uses a bastion host system as an intermediary. First, it responds to a first login request sent by an O&M terminal, which aims to log in to the bastion host. At this stage, the account management service verifies the identity and approval request of the O&M terminal. After successful verification, the O&M terminal sends a second login request to the account management service to log in to the target server. The account management service and the bastion host service then complete the encryption / unlocking and login of the O&M terminal account. Finally, the bastion host provides real-time feedback of this login result to the O&M terminal, allowing O&M personnel to immediately understand the login status. Through the intermediary role of the bastion host, centralized management and verification of O&M login requests are achieved, effectively preventing unauthorized access and significantly improving the security of the O&M process. O&M personnel do not need to remember or manage account passwords for multiple servers; they only need to perform a single login operation through the bastion host to automatically complete the connection to the target server, simplifying the O&M process and improving work efficiency. Attached Figure Description
[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0022] Figure 1 A schematic diagram illustrating a scenario of operation and maintenance-based login control provided in an embodiment of this application;
[0023] Figure 2 A flowchart illustrating a login control method based on operation and maintenance provided in this application embodiment. Figure 1 ;
[0024] Figure 3 A flowchart illustrating a login control method based on operation and maintenance provided in this application embodiment. Figure 2 ;
[0025] Figure 4 A schematic diagram of the structure of a login control device based on operation and maintenance provided in this application embodiment. Figure 1 ;
[0026] Figure 5 A schematic diagram of the structure of a login control device based on operation and maintenance provided in this application embodiment. Figure 2 ;
[0027] Figure 6 This is a schematic diagram of a bastion host provided in an embodiment of this application.
[0028] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0029] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0030] Figure 1 This application provides a schematic diagram of a scenario for login control based on operation and maintenance, as shown in the embodiments of this application. Figure 1 As shown, the maintenance terminal 101 is connected to the bastion host 102, and the bastion host 102 is connected to multiple target servers 103 and 104. The maintenance terminal 101 serves as the terminal for maintenance operations; from here, maintenance personnel can execute a series of maintenance tasks after security verification. The bastion host 102 acts as an maintenance intermediary, protecting internal network resources and providing additional security measures such as multi-factor authentication and command filtering. The target server 103 receives maintenance instructions forwarded from the bastion host and completes corresponding configuration changes, status queries, etc.
[0031] Traditional bastion host systems primarily rely on passwords to manage server access permissions. However, password management itself has several problems, such as the complexity requirements for passwords, the cumbersome nature of regularly changing passwords, and the tendency for users to use weak passwords. These issues make passwords easy to crack, leading to greater vulnerability to attacks. While servers typically have login failure policies (such as locking accounts after a certain number of consecutive failed login attempts), these policies have significant limitations. Attackers can bypass these safeguards through distributed attacks or by retrying after the lockout period.
[0032] Therefore, the login control method, device, bastion host, system, storage medium and program product based on operation and maintenance provided in this application can solve the above problems.
[0033] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0034] Figure 2 A flowchart illustrating a login control method based on operation and maintenance provided in this application embodiment. Figure 1 ,like Figure 2 As shown, the method includes:
[0035] S201. In response to the first login request sent by the operation and maintenance terminal, verify the operation and maintenance terminal; wherein, the first login request represents logging into the bastion host.
[0036] For example, an operations and maintenance (O&M) terminal refers to the device or software interface used by O&M personnel to perform O&M operations, such as a computer, mobile phone, or a specific O&M management software client. O&M personnel connect to servers or other IT resources through the O&M terminal to perform daily maintenance, monitoring, and management. In the deployment architecture of a bastion host, account management service and bastion host service are two core components. The account management service is the core component of the bastion host system used to store and manage all O&M personnel account information; it is responsible for maintaining account creation, modification, deletion, and permission allocation; the account management service authenticates the O&M terminal. This typically includes steps such as verifying the existence of the account and the correctness of the password. The bastion host service filters and controls access requests from the O&M terminal based on the permission information provided by the account server. Only authorized access requests are allowed to pass; the bastion host service also has command filtering capabilities, which can prevent the O&M terminal from executing certain potentially dangerous or unauthorized commands. Simultaneously, it records all commands and operations executed through the bastion host for subsequent auditing and monitoring.
[0037] The maintenance terminal sends an initial login request to the bastion host by entering its username and password. Upon receiving the login request, the account management service within the bastion host verifies the entered username and password. This verification process may include checking account existence, password correctness, and account validity. If verification succeeds, the maintenance terminal is allowed access to the bastion host system; if verification fails, the login request is rejected, and an error message may be displayed. If the maintenance terminal successfully logs into the bastion host, it initiates an approval request to the account management service based on the maintenance task requirements. This request includes the target server number, scope of use, duration of use, and purpose of use. Upon receiving the approval request, the account management service forwards it to the designated approver. The approver carefully reviews the content of the approval request according to approval rules and business needs. If the approval is successful, the approver replies with "Approval Approved" to the maintenance terminal through the account management service. After receiving the "Approval Approved" message, the maintenance terminal can continue with subsequent operations. If the review fails, the approving personnel will reply with a "Review Failed" message to the operations and maintenance terminal via the account management service, possibly including the reason for the rejection. Upon receiving the "Review Failed" message, the operations and maintenance terminal needs to rectify the issues based on the reason for rejection or resubmit the approval request. To ensure the security and compliance of operations and maintenance operations, the login request and approval request of the operations and maintenance terminal are usually combined to form a complete verification process. Only when both requests are approved can the operations and maintenance terminal be considered verified and can proceed to the next step.
[0038] S202. After confirming that the verification of the operation and maintenance terminal is successful, a second login request is sent to the target server, wherein the second login request includes the account information of the target server corresponding to the operation and maintenance terminal.
[0039] For example, after the maintenance terminal is authenticated by the bastion host, it sends a second login request to the bastion host to log in to the target server. Upon receiving this second login request, the bastion host's account management service forwards the request to the bastion host service according to its configuration or policy. This is because the bastion host service is responsible for the actual login authentication and session management. The bastion host service typically stores the username and password information used by maintenance personnel to log in to the target server. This information is pre-configured. Upon receiving the login request from the account management service, the bastion host service retrieves the corresponding login credentials from the stored username and password information based on the identity information in the request. After retrieving the login credentials, the bastion host service automatically fills them into the target server's login interface, thus completing the login process. In this way, the maintenance terminal does not need to manually enter the username and password.
[0040] S203. In response to the first login response information sent by the target server, the first login response information is sent to the operation and maintenance terminal; wherein, the first login response information indicates that the operation and maintenance terminal has successfully logged into the target server.
[0041] For example, the first login response message is a message generated by the target server to confirm that the operations and maintenance terminal has successfully logged into the target server. The first login response message includes confirmation of successful login, session ID, access permissions, and other additional information. The first login response message corresponds to the login request and signifies the successful completion of the login process. Once the target server generates the first login response message, this information needs to be passed back to the operations and maintenance terminal that initiated the login request. The login process is conducted through a bastion host system (account management service, bastion host service), which is responsible for forwarding the first login response message from the target server to the operations and maintenance terminal. After receiving this response message, the operations and maintenance terminal typically displays a login success message, allowing operations and maintenance personnel to begin subsequent operations.
[0042] This application provides a login control method based on operations and maintenance (O&M). This method uses a bastion host system as an intermediary. First, it responds to a first login request sent by an O&M terminal, which aims to log in to the bastion host. At this stage, the account management service verifies the O&M terminal's identity and approval request. After successful verification, the O&M terminal sends a second login request to the account management service to log in to the target server. The account management service and the bastion host service then complete the encryption / unlocking and login of the O&M terminal's account. Finally, the bastion host provides real-time feedback of this login result to the O&M terminal, allowing O&M personnel to immediately understand the login status. Through the intermediary role of the bastion host, centralized management and verification of O&M login requests are achieved, effectively preventing unauthorized access and significantly improving the security of the O&M process. O&M personnel do not need to remember or manage account passwords for multiple servers; they only need to perform a single login operation through the bastion host to automatically complete the connection to the target server, simplifying the O&M process and improving work efficiency.
[0043] Figure 3 A flowchart illustrating a login control method based on operation and maintenance provided in this application embodiment. Figure 2 ,like Figure 3 As shown, in this embodiment... Figure 2 Based on the embodiments, a login control method based on operation and maintenance is described in detail, which includes:
[0044] S301. In response to the first login request sent by the operation and maintenance terminal, establish a connection with the operation and maintenance terminal and send a second login response information to the operation and maintenance terminal; wherein, the second login response information indicates that the operation and maintenance terminal has successfully logged into the bastion host; receive the approval request sent by the operation and maintenance terminal and verify the approval request in order to verify the operation and maintenance terminal.
[0045] In one example, the approval request includes one or more of the following information: scope of use, duration of use, and purpose of use; verification of the approval request includes: verifying the information in the approval request based on pre-stored information; wherein the pre-stored information includes one or more of the following information: permissible scope of use, permissible duration of use, and permissible purpose of use. The approval request also includes information about the target server accessed by the operation and maintenance terminal.
[0046] For example, the operations and maintenance (O&M) terminal sends a first login request to the account management service in the bastion host. This first login request is a request to log in to the bastion host, including the O&M terminal's identity information for verification. After accepting the login request, the account management service establishes a communication connection with the O&M terminal. This connection can be a TCP / IP-based network connection for subsequent information transmission. After successfully verifying the O&M terminal's login request, the account management service generates a second login response message, which is a confirmation message indicating that the O&M terminal has successfully logged into the bastion host. If the account management service fails to verify the login, it will also send a login failure message to the O&M terminal.
[0047] After successfully logging into the bastion host, the operations and maintenance (O&M) endpoint sends an approval request to the account management service. The approval request may contain one or more of the following information: scope of use, duration of use, and purpose of use. Scope of use specifies the specific resources or systems the O&M endpoint needs to access or operate; duration of use specifies the duration for which the O&M endpoint needs access; purpose of use explains the purpose or reason for the O&M endpoint to access or operate the resources. Upon receiving the approval request from the O&M endpoint, the account management service verifies the information in the request. The account server verifies the legality and validity of the information in the approval request based on previously stored "pre-stored information." The pre-stored information includes the permitted scope of use, permitted duration of use, and permitted purpose of use. The permitted scope of use is a list of specific resources or systems that the O&M endpoint can access or operate; the permitted duration of use is the maximum duration for which the O&M endpoint can obtain access; and the permitted purpose of use is the legitimate purpose or reason for the O&M endpoint to access or operate the resources. If the information in the approval request matches the pre-stored information and meets other verification requirements, the account server considers the verification successful and grants the O&M endpoint the corresponding access permissions. If the information in the approval request does not match the pre-stored information, or does not meet other verification requirements, the account management service will consider the verification failed and reject the access request from the operations and maintenance terminal. Passing the approval means that the operations and maintenance terminal has passed the bastion host's authentication and obtained access to the target server.
[0048] S302. After confirming that the verification of the operation and maintenance terminal is successful, a second login request is sent to the target server, wherein the second login request includes the account information of the target server corresponding to the operation and maintenance terminal.
[0049] In one example, before sending the second login request to the target server, the process includes: sending an account unlock request to the target server; wherein the account unlock request includes account information of the target server corresponding to the operation and maintenance terminal, and the account unlock request is used to unlock the account of the operation and maintenance terminal based on the account information in the account unlock request; and receiving account unlock success information sent by the target server. The account information includes the account and password of the target server corresponding to the operation and maintenance terminal login.
[0050] For example, after the account management service verifies the operation and maintenance terminal, the terminal first sends a second login request to the account management service. This request contains the account information corresponding to the target server. Upon receiving this request, the account management service first sends an account unlocking request to the target server to unlock the target server account corresponding to the operation and maintenance terminal. If the target server successfully unlocks the account, it sends an account unlocking success message to the account management service. This message indicates that the account is now available and can receive subsequent login requests. After receiving the account unlocking success message, the account management service retrieves the account information from the previously stored username and password and uses it to log in to the target server. Once the login is successful, the target server sends a login success message to the account management service. Subsequently, the account management service sends the login success message back to the operation and maintenance terminal, thus completing the feedback of the entire login process.
[0051] S303. Send an account lockout request to the target server; wherein, the account lockout request indicates the maintenance terminal to be locked; the account lockout request is used to lock the account of the maintenance terminal indicated by the account lockout request; receive the account lockout success information sent by the target server.
[0052] For example, after an operations and maintenance (O&M) terminal successfully logs into the target server via the account management service, the target server sends a login success notification to the bastion host server. This notification signals that the O&M terminal's target server account has been successfully used on the target server and is currently active. The account management service then proactively sends an account lock request to the target server. This request is an instruction that requires the target server to lock the specified account. The account management service constructs a request packet containing the lock instruction and necessary information, and then sends it to the target server over the network. This request packet typically includes the identifier of the locked account (such as username), the type of lock operation (such as immediate lock, delayed lock, etc.), and possibly other relevant parameters. A key part of the account lock request is indicating the account of the O&M terminal that needs to be locked. This indication is usually achieved by specifying one or more specific account identifiers (such as username, user ID, etc.) in the request packet. In this way, the target server can accurately identify which accounts need to be locked. When the target server receives the account lock request, it performs a lock operation on the specified account according to the instructions in the request. This operation includes setting the account status to locked in the target server's user database. The purpose of this is to ensure that even if someone obtains the account's login credentials, they cannot log in to the account while it is locked. After completing the account locking operation, the target server sends a notification to the account management service indicating successful account locking. This notification is a confirmation signal that the target server has successfully locked the specified account. Upon receiving this notification, the account management service can confirm that the account has been securely locked.
[0053] S304. In response to the maintenance request sent by the maintenance terminal, if the maintenance request is determined to be a legitimate request, the maintenance request is sent to the target server; wherein, the maintenance request includes maintenance tasks, which are executed by the target server; the maintenance result information sent by the target server is received and the maintenance result information is sent to the maintenance terminal.
[0054] For example, the maintenance terminal sends a maintenance request to the target server. This request typically contains information about the task or operation the maintenance terminal needs to perform. The bastion host, acting as an intermediary, performs protocol-level auditing and logging of the maintenance request sent by the maintenance terminal. The bastion host records the entire maintenance request session, including screenshots, keyboard input, and mouse operations, documenting all operations performed by the maintenance terminal. The bastion host also generates detailed log files, recording detailed information about the maintenance terminal's operations, including but not limited to: operation time, user, operation content (such as executed commands, accessed files, etc.), and operation result. Furthermore, the bastion host checks the source of the maintenance request, its format, the validity of any parameters carried in the request, and whether the request complies with the system's security policies. Only when the request meets all legality conditions will the bastion host consider the maintenance request legitimate and continue processing it. Once the legitimacy of the maintenance request is determined, the bastion host sends it to the target server. The target server is the server specified in the maintenance request that needs to perform a specific task or operation. The maintenance request contains specific information about the maintenance task, which will be used by the target server to perform the corresponding operation. The maintenance task is included in the maintenance request and sent to the target server. The target server then performs the corresponding operations based on this task information. This is the core of the maintenance process and the ultimate purpose of the maintenance request. After the target server completes the maintenance task, it sends maintenance result information to the system. This information includes the task execution result, possible logs, error messages, etc. After receiving this information, the system can analyze the execution status of the maintenance task. The final step is to feed back the maintenance result information to the maintenance terminal. In this way, maintenance personnel can understand the task execution status in a timely manner and make further decisions or actions based on the result information.
[0055] S305. Regularly update the passwords of the stored operation and maintenance terminals.
[0056] For example, a bastion host will establish a password policy, including requirements for password length, complexity, and update frequency. The bastion host uses encryption technologies such as symmetric and asymmetric encryption to protect these passwords, ensuring their security during storage and transmission. The bastion host will record password update operation logs. These logs include information such as the time of the update operation, the executor, and the updated password. Administrators can use the bastion host's auditing capabilities to view these logs. This helps ensure the compliance and traceability of password update operations.
[0057] This application provides a login control method based on operations and maintenance (O&M). By establishing a connection between the bastion host and the O&M terminal after the bastion host responds to a first login request and sends a second login response, effective login control of the O&M terminal is achieved. By receiving and verifying approval requests from the O&M terminal, the security and compliance of O&M operations are ensured. The approval request includes information such as the scope of use, duration of use, and purpose of use. Comparison with pre-stored permitted information further improves the accuracy and security of O&M operations. After successful verification, the bastion host sends a second login request to the target server, performing account unlocking beforehand to ensure the O&M terminal can successfully access the target server. After the O&M operation is completed, the bastion host also sends an account lock request to the target server to ensure the account security of the O&M terminal. Regularly updating the stored passwords for the O&M terminal further enhances system security. This method significantly enhances the security and traceability of O&M operations, improving the efficiency and compliance of O&M management.
[0058] Figure 4 A schematic diagram of the structure of a login control device based on operation and maintenance provided in this application embodiment. Figure 1 ,like Figure 4 As shown, the login control device 40 based on operation and maintenance provided in this embodiment includes:
[0059] The verification module 401 is used to verify the operation and maintenance terminal in response to the first login request sent by the operation and maintenance terminal; wherein, the first login request represents logging into the bastion host.
[0060] The login module 402 is used to send a second login request to the target server after confirming that the verification of the operation and maintenance terminal is successful. The second login request includes the account information of the target server corresponding to the operation and maintenance terminal.
[0061] The sending module 403 is used to send the first login response information to the operation and maintenance terminal in response to the first login response information sent by the target server; wherein, the first login response information indicates that the operation and maintenance terminal has successfully logged into the target server.
[0062] This embodiment provides a login control device based on operation and maintenance, which can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0063] Figure 5 A schematic diagram of the structure of a login control device based on operation and maintenance provided in this application embodiment. Figure 2 ,like Figure 5 As shown, the login control device 50 based on operation and maintenance provided in this embodiment includes:
[0064] The verification module 501 is used to verify the operation and maintenance terminal in response to the first login request sent by the operation and maintenance terminal; wherein, the first login request represents logging into the bastion host;
[0065] The login module 502 is used to send a second login request to the target server after confirming that the verification of the operation and maintenance terminal is successful. The second login request includes the account information of the target server corresponding to the operation and maintenance terminal.
[0066] The sending module 503 is used to send the first login response information to the operation and maintenance terminal in response to the first login response information sent by the target server; wherein, the first login response information indicates that the operation and maintenance terminal has successfully logged into the target server.
[0067] In one example, the verification module 501 is specifically used for:
[0068] In response to the first login request sent by the operation and maintenance terminal, a connection is established with the operation and maintenance terminal, and a second login response message is sent to the operation and maintenance terminal; wherein, the second login response message indicates that the operation and maintenance terminal has successfully logged into the bastion host.
[0069] Receive approval requests sent by the operation and maintenance terminal and verify the approval requests in order to verify the operation and maintenance terminal.
[0070] In one example, the approval request includes one or more of the following information: scope of use, duration of use, purpose of use; the approval request is verified specifically for:
[0071] The information in the approval request is verified based on the pre-stored information, which includes one or more of the following: permitted scope of use, permitted duration of use, and permitted purpose of use.
[0072] The approval request also includes information about the target server accessed by the operation and maintenance terminal.
[0073] In one example, before sending the second login request to the target server, the following is also included:
[0074] Send an account unlock request to the target server; the account unlock request includes the account information of the target server corresponding to the operation and maintenance terminal, and the account unlock request is used to unlock the account of the operation and maintenance terminal based on the account information in the account unlock request; receive the account unlock success information sent by the target server.
[0075] In one example, the apparatus provided in this application embodiment further includes:
[0076] Send an account lockout request to the target server; the account lockout request indicates the maintenance terminal to be locked; the account lockout request is used to lock the account of the maintenance terminal indicated by the account lockout request; receive the account lockout success information sent by the target server.
[0077] In one example, the apparatus provided in this application embodiment further includes:
[0078] In response to an operation and maintenance request sent by the operation and maintenance terminal, if the operation and maintenance request is determined to be a legitimate request, the operation and maintenance request is sent to the target server; wherein, the operation and maintenance request includes an operation and maintenance task, which is executed by the target server; the operation and maintenance result information sent by the target server is received and the operation and maintenance result information is sent to the operation and maintenance terminal.
[0079] In one example, the apparatus provided in this application embodiment further includes:
[0080] The account information includes the username and password for the target server corresponding to the operations and maintenance terminal login. The stored passwords for the operations and maintenance terminals are updated regularly.
[0081] This embodiment provides a login control device based on operation and maintenance, which can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0082] Figure 6 This is a schematic diagram of a bastion host provided as an embodiment of this application. Figure 6 As shown, the electronic device 60 provided in this embodiment includes at least one processor 601 and a memory 602. Optionally, the device 60 further includes a communication component 603. The processor 601, memory 602, and communication component 603 are connected via a bus 604.
[0083] In a specific implementation, at least one processor 601 executes computer execution instructions stored in memory 602, causing at least one processor 601 to perform the above-described method.
[0084] The specific implementation process of processor 601 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0085] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0086] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0087] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0088] This application also provides a login control system based on operation and maintenance, which includes: an operation and maintenance terminal, a target server, and a bastion host 60.
[0089] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0090] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.
[0091] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0092] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0093] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0094] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0095] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0096] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0097] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0098] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A login control method based on operation and maintenance, characterized in that, The method is applied to a bastion host, and the method includes: In response to a first login request sent by the operation and maintenance terminal, the operation and maintenance terminal is verified; wherein, the first login request indicates login to the bastion host; in response to the first login request sent by the operation and maintenance terminal, a connection is established with the operation and maintenance terminal, and a second login response information is sent to the operation and maintenance terminal; wherein, the second login response information indicates that the operation and maintenance terminal has successfully logged into the bastion host; The system receives and verifies an approval request sent by the maintenance terminal to verify the maintenance terminal. The approval request includes one or more of the following information: scope of use, duration of use, and purpose of use. Verification of the approval request includes: The information in the approval request is verified based on the pre-stored information; wherein the pre-stored information includes one or more of the following: permissible scope of use, permissible duration of use, and permissible purpose of use; The approval request also includes information about the target server accessed by the maintenance terminal; After confirming that the verification of the operation and maintenance terminal is successful, a second login request is sent to the target server, wherein the second login request includes the account information of the target server corresponding to the operation and maintenance terminal; In response to the first login response information sent by the target server, the first login response information is sent to the operation and maintenance terminal; wherein, the first login response information indicates that the operation and maintenance terminal has successfully logged into the target server.
2. The method according to claim 1, characterized in that, Before sending the second login request to the target server, it also includes: Send an account unlock request to the target server; wherein the account unlock request includes account information of the target server corresponding to the operation and maintenance terminal, and the account unlock request is used to unlock the account of the operation and maintenance terminal based on the account information in the account unlock request; Receive a message from the target server indicating that the account has been successfully unlocked.
3. The method according to any one of claims 1-2, characterized in that, The method further includes: Send an account lockout request to the target server; wherein the account lockout request indicates the maintenance terminal to be locked; the account lockout request is used to lock the account of the maintenance terminal indicated by the account lockout request; Receive the account lock success message sent by the target server.
4. The method according to any one of claims 1-2, characterized in that, The method further includes: In response to the maintenance request sent by the maintenance terminal, if the maintenance request is determined to be a legitimate request, the maintenance request is sent to the target server; wherein, the maintenance request includes a maintenance task, and the maintenance task is executed by the target server; The system receives the maintenance result information sent by the target server and sends the maintenance result information to the maintenance terminal.
5. The method according to any one of claims 1-2, characterized in that, The account information includes the account and password of the target server corresponding to the operation and maintenance terminal login; the method further includes: The passwords for the stored operation and maintenance terminals are updated regularly.
6. A bastion host, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-5.
7. A login control system based on operation and maintenance, characterized in that, The term includes: The operation and maintenance terminal, the target server, and the bastion host as described in claim 6.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-5.
Citation Information
Patent Citations
Bastion host
CN111586032A
Method for operation and maintenance of hosting-free host account through bastion host
CN113810415A