Terminal Cross-Domain Management Method, Device, Equipment, and Product

By establishing trust relationships and encryption channels between domain nodes, cross-domain management is realized, and the problems of high hardware pressure and high management complexity under centralized management and control are solved, and the simplification of terminal cross-domain login and data security are achieved.

CN119520175BActive Publication Date: 2025-07-11KYLIN CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510097782.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-07-11
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

When the existing centralized terminal management and control methods face the problems of large number of terminals and extensive geographical distribution, the hardware performance and cost pressure are high, the management complexity is high, and the administrator's tasks are heavy.

Method used

By establishing trust relationships and encryption channels between domain nodes, the terminal can be managed across domains, using the domain nodes where the user is located for information verification, establishing cascade relationships and node trees, and using symmetric key encryption channels to make cross-node service calls to ensure data isolation and security.

Benefits of technology

It simplifies the cross-domain login process of terminals, improves data privacy and usage efficiency, realizes rich and secure cross-domain management, and expands the scope of application.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520175B_ABST
    Figure CN119520175B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, apparatus, device, and product for cross-domain management of terminals, including: establishing a trust relationship between domain nodes according to the user's need to log in to a cross-domain terminal; when the user logs in to a cross-domain terminal, the domain node where the logged-in terminal is located uses the trust relationship established between the domain nodes to verify the user information through the domain node where the user is located; if the user information verification is passed, the user is allowed to log in to the cross-domain terminal. The present invention discloses a method, apparatus, device, and product for cross-domain management of terminals. By removing the centralized control method, it realizes the cross-domain management of distributed terminals, can ensure data isolation between domain nodes, improve data privacy, simplify the cross-domain login process of terminals, improve the usage efficiency, and has the characteristics of high data security for cross-domain management of terminals, rich functions that can be realized, and a wide range of applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of domestic information and communication technology (ICT) systems, and in particular, relates to a method, device, equipment, and product for cross-domain management of terminals. Background Art

[0002] With the large-scale promotion of domestic ICT systems, the management scenario of domestic large-scale ICT terminals has become increasingly important. Under the existing technical conditions, in the traditional centralized management method, the domain control end will face great pressure. As the number of managed terminals continues to increase and the geographical distribution range continues to expand, the hardware performance and cost of centralized management have become problems that cannot be ignored. At the same time, the existing centralized terminal management method will also bring problems such as too high management complexity and too heavy tasks for administrators. Summary of the Invention

[0003] In view of this, the present invention aims to overcome the defects in the prior art and proposes a method, device, equipment, and product for cross-domain management of terminals.

[0004] To achieve the above object, the technical solution of the present invention is realized as follows:

[0005] In a first aspect, the present invention discloses a method for cross-domain management of terminals, including:

[0006] According to the user's requirement for logging in to a cross-domain terminal, establish a trust relationship between domain nodes, where the domain nodes include: a domain control end and a number of terminals managed by the domain control end;

[0007] When a user logs in to a cross-domain terminal, the domain node where the logged-in terminal is located uses the trust relationship established between the domain nodes to verify the user information through the domain node where the user is located;

[0008] If the user information verification is passed, the user is allowed to log in to the cross-domain terminal.

[0009] In another embodiment of the present invention, establishing a trust relationship between domain nodes according to the user's requirement for logging in to a cross-domain terminal includes: according to the user's requirement for logging in to a cross-domain terminal, establish an encrypted channel between the domain node where the user is located and the domain node where the cross-domain terminal to be logged in is located, and the encrypted channel is used to implement cross-node service calls between the two domain nodes.

[0010] In another embodiment of the present invention, establishing a trust relationship between domain nodes according to the user's requirement for logging in to a cross-domain terminal includes: establish a cascading relationship between all domain nodes, and generate a node tree. According to the user's requirement for logging in to a cross-domain terminal, use the topology data included in the node tree to establish a trust relationship between domain nodes, where the topology data includes: the node id, node name, node domain name, node communication address, and superior node id of each domain node.

[0011] In another embodiment of the present invention, the encrypted channel uses a symmetric key to implement cross-node service calls between two domain nodes.

[0012] In another embodiment of the present invention, according to the needs of a user to log in to a cross-domain terminal, a trust relationship between domain nodes is established, including: using an audit node to audit whether a trust relationship can be established.

[0013] In another embodiment of the present invention, each domain node on the node tree stores topology data.

[0014] In another embodiment of the present invention, the topology data is updated according to the changes in the node tree.

[0015] In a second aspect, the present invention discloses a terminal cross-domain management device, which includes:

[0016] A trust relationship establishment module, configured to establish a trust relationship between domain nodes according to the needs of a user to log in to a cross-domain terminal, where the domain nodes include: a domain control end and a number of terminals managed by the domain control end;

[0017] A verification module, configured to, when a user logs in to a cross-domain terminal, the domain node where the logged-in terminal is located uses the trust relationship established between the domain nodes to verify the user information through the domain node where the user is located;

[0018] A login module, configured to, if the user information verification is passed, allow the user to log in to the cross-domain terminal.

[0019] In a third aspect, the present invention discloses an electronic device, including: one or more processors; a storage device for storing one or more programs, where, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above method.

[0020] In a fourth aspect, the present invention discloses a computer program product, including a computer program, which implements the above method when executed by a processor.

[0021] Compared with the prior art, the present invention has the following advantages:

[0022] The present invention discloses a terminal cross - domain management method, device, equipment and product, including: establishing a trust relationship between domain nodes according to the user's need to log in to a cross - domain terminal; when the user logs in to a cross - domain terminal, the domain node where the logged - in terminal is located uses the trust relationship established between domain nodes to verify the user information through the domain node where the user is located; if the user information verification is passed, the user is allowed to log in to the cross - domain terminal. The present invention discloses a terminal cross - domain management method, device, equipment and product, which realizes the cross - domain management of distributed terminals by removing the centralized control method, can ensure data isolation between domain nodes, improve data privacy; simplifies the terminal cross - domain login process and improves the usage efficiency; has the characteristics of high data security for terminal cross - domain management, rich functions that can be realized and wide application scope. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The accompanying drawings, which form a part of this invention, are used to provide a further understanding of the invention. The schematic embodiments and descriptions thereof of the invention are used to explain the invention and do not constitute an improper limitation of the invention.

[0024] In the drawings:

[0025] Figure 1 is a schematic diagram of the application scenario of a terminal cross - domain management method according to an embodiment of the present invention;

[0026] Figure 2 is a schematic diagram of a terminal cross - domain management method according to an embodiment of the present invention;

[0027] Figure 3 is a schematic diagram of the node tree of a terminal cross - domain management method according to an embodiment of the present invention;

[0028] Figure 4 is a schematic diagram of a terminal cross - domain management device according to an embodiment of the present invention;

[0029] Figure 5 is a schematic diagram of an electronic device for terminal cross - domain management according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0030] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0031] In the description of the present invention, it should be further noted that the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first", "second", etc. may explicitly or implicitly include one or more of such features. In the description of the present invention, unless otherwise stated, the meaning of "a plurality" is two or more.

[0032] The present invention discloses a method, apparatus, device, and product for cross-domain management of terminals. The application scenario is as follows Figure 1 As shown, under the existing technical conditions, in the traditional centralized management and control method, the domain control end will have a great deal of pressure. With the continuous increase in the number of managed terminals and the continuous expansion of the geographical distribution range, the hardware performance and cost of centralized management and control have become issues that cannot be ignored. At the same time, the existing centralized terminal management and control method will also bring problems such as overly high management complexity and excessive workload for administrators. The present invention discloses a method, apparatus, device, and product for cross-domain management of terminals. By removing the centralized management and control method, cross-domain management of terminals is achieved, which can ensure data isolation between domain nodes, improve data privacy; simplify the cross-domain login process of terminals, and improve the usage efficiency; and has the characteristics of high data security for cross-domain management of terminals, rich functions that can be realized, and a wide application range.

[0033] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0034] In an embodiment disclosed by the present invention, as Figure 2 shown, a method for cross-domain management of terminals includes:

[0035] Step S201, according to the user's need to log in to a cross-domain terminal, establish a trust relationship between domain nodes, where the domain nodes include: a domain control end and a number of terminals managed by the domain control end;

[0036] In this embodiment, the domain control end and a number of terminals managed by the domain control end form a set of domain control solutions, which is represented as a domain node;

[0037] Exemplarily, the domain control end and the terminals are domestic information technology innovation products.

[0038] In this embodiment, first establish a cascading relationship between all domain nodes, and generate a node tree. According to the user's need to log in to a cross-domain terminal, use the topological data included in the node tree to establish a trust relationship between domain nodes, where the topological data includes: the node id, node name, node domain name, node communication address, and superior node id of each domain node.

[0039] When two domain nodes establish a connection relationship, it is called establishing a cascading relationship. The cascading initiator is called the lower-level node, that is: the child node; the cascading approval party is called the upper-level node, that is: the parent node; after the cascading is completed, the upper-level node has the access right and control right to the lower-level node.

[0040] In this embodiment, use an audit node to audit whether a trust relationship can be established. Exemplarily, the audit node can be a third-party audit node, and the third-party audit node has the characteristics of being controllable, traceable, and highly secure for trust authorization.

[0041] In this embodiment, for two domain nodes that have established a trust relationship through verification, the trusted domain node has the access right and control right to the trusted domain node.

[0042] Step S202, when a user logs in to a cross-domain terminal, the domain node where the logged-in terminal is located uses the trust relationship established between the domain nodes to verify the user information through the domain node where the user is located.

[0043] Step S203, if the user information verification is passed, the user is allowed to log in to the cross-domain terminal.

[0044] A terminal cross-domain management method disclosed in this embodiment realizes cross-domain management of terminals by removing the centralized control method, can ensure data isolation between domain nodes, improve data privacy, simplify the cross-domain login process of terminals, and improve the usage efficiency.

[0045] Based on the previous embodiment, in another embodiment of the present invention, as Figure 2 shown, Step S201, according to the requirement of the user to log in to a cross-domain terminal, establish a trust relationship between domain nodes, including: according to the requirement of the user to log in to a cross-domain terminal, establish an encrypted channel between the domain node where the user is located and the domain node where the cross-domain terminal to be logged in is located, and the encrypted channel is used to realize cross-node service invocation between the two domain nodes.

[0046] In this embodiment, the cross-node service invocation process is as follows:

[0047] Cross-node service invocation involves parameters serviceName, method, uri, header, body. The requesting domain node sends the above information to the target domain node through the encrypted channel. After the target domain node parses it, according to the serviceName routing configuration, it uses other parameters to call the interface of the corresponding service. After obtaining the returned data result, it encrypts and returns it to the requesting domain node. The requesting domain node decrypts it to obtain the business interface return data result, and finally realizes cross-node service invocation;

[0048] Exemplarily, the process of domain node A cross-node invoking the service of domain node B to obtain the number of managed terminals of domain node B is as follows:

[0049] 1. Each domain node itself has a business service busiService, listening on port 8080, providing a query interface countTerminal for obtaining the number of managed terminals of the domain node itself, and the interface is a method of HTTP protocol GET.

[0050] 2. Domain Node A assembles an encrypted message: serviceName = busiService, port = 8080, method = GET, uri = / countTerminal, hearder = default, body = none;

[0051] 3. When Domain Node A initiates a cross - node service call, it selects Domain Node B in the node tree as the target, obtains the communication address of Domain Node B, and sends the assembled encrypted message to Domain Node B through an encrypted channel;

[0052] 4. After receiving the encrypted message, Domain Node B parses the request. Through the locally configured routing table, it parses that the service address of busiService is monit - web.kmp.local; initiates a local interface call, and the complete path of the interface is:

[0053] http: / / monit - web.kcm.local:8080 / countTerminal;

[0054] The local interface returns the result, and Domain Node B returns the result to Domain Node A through the encrypted channel;

[0055] 5. Domain Node A receives the result, parses and displays it, and the cross - node service call is completed.

[0056] In this embodiment, the cross - node service call supports calling all business interfaces of all business services on domain nodes, and has the characteristics of strong generality and wide application scope.

[0057] In this embodiment, the encrypted channel uses a symmetric key to implement cross - node service calls between two domain nodes.

[0058] Exemplarily, the establishment process of the encrypted channel is as follows:

[0059] The trust relationship includes a superior domain node and an inferior domain node. After the trust relationship is audited and approved, the superior domain node generates an asymmetric key pair, including a private key P1 and a public key P2. The public key P2 is delivered to the inferior domain node offline. The inferior domain node generates an asymmetric key pair for the inferior domain node, including a private key C1 and a public key C2. The inferior domain node uses the public key P2 of the superior domain node to encrypt the symmetric key negotiation factor information S1 and the public key C2 generated by the inferior domain node and then sends them to the superior domain node. The superior domain node uses the private key P1 to decrypt and obtain the symmetric key negotiation factor information S1 and the public key C2. The superior domain node generates a symmetric key negotiation factor S2, further combines the symmetric key negotiation factor S1 and the symmetric key negotiation factor S2 together to generate a symmetric key. The superior domain node uses the public key C2 to encrypt the symmetric key negotiation factor S2 and sends it to the inferior domain node. The inferior domain node uses the private key C1 to decrypt and obtain the symmetric key negotiation factor S2, further combines the symmetric key negotiation factor S1 and the symmetric key negotiation factor S2 together to generate a symmetric key. At this time, both the superior domain node and the inferior domain node obtain the symmetric key generated by combining the symmetric key negotiation factor S1 and the symmetric key negotiation factor S2. Subsequently, the two domain nodes use this symmetric key for encryption and decryption during communication.

[0060] In this embodiment, the establishment of the encryption channel effectively improves the security of cross-domain access of the terminal. An independent symmetric key is used for the connection between each domain node, which maximally guarantees the security of the overall network environment.

[0061] In another embodiment of the present invention, as Figure 3 shown, each domain node on the domain node tree stores topology data, and the topology data is updated according to the change situation of the domain node tree.

[0062] In this embodiment, as Figure 3 shown, the topology data of the domain node tree will automatically spread to each domain node of the node tree to ensure that each domain node has the same full amount of topology data.

[0063] Exemplarily, as Figure 3 shown, when a new domain node is added to the node tree:

[0064] The domain node E is connected to the domain node B. The domain node E is a newly added domain node of the node tree. At this time, it is necessary to notify the other domain nodes A, C, and D of the node tree to ensure that the topology data of all domain nodes on the node tree is consistent;

[0065] After the connection between the domain node E and the domain node B is approved, the domain node B will automatically notify the superior domain node A and the inferior domain node D that a new domain node E has joined the node tree;

[0066] After the domain node A receives the notification, it will automatically notify the superior domain node (none) and the subordinate domain node C that a new domain node E has joined the node tree, and so on, to add a new domain node to the node tree;

[0067] Exemplarily, as Figure 3 shown, when deleting a domain node from the node tree:

[0068] As Figure 3 shown, the domain node E cancels the connection to the domain node B. The domain node E is the domain node to be deleted from the node tree. At this time, it is necessary to notify the other domain nodes A, C, and D of the node tree to ensure that the topological data of all domain nodes on the node tree is consistent.

[0069] After the approval for the domain node E to cancel the connection to the domain node B is passed, the domain node B will automatically notify the superior domain node A and the subordinate domain node D that the domain node E is deleted from the node tree;

[0070] After the level domain node A node receives the notification, it will automatically notify the superior domain node (none) and the subordinate level domain node C that the domain node E is deleted from the node tree, and so on, to delete the domain node from the node tree;

[0071] In this embodiment, since all domain nodes on the node tree store the topological data of each domain node, it is possible to visually select a target domain node based on the trust requirements between the node tree and the domain nodes, and establish a trust relationship between any two domain nodes.

[0072] In this embodiment, a new domain node can join the node tree after the approval is passed. Each domain node holds the full topological data that is automatically synchronized, solving the problems in the prior art that domain nodes cannot perceive the overall topological data and cannot view their own topological positions.

[0073] As Figure 1 and Figure 2 shown, in step S202, when the user logs in to a cross-domain terminal, the domain node where the logged-in terminal is located uses the trust relationship established between the domain nodes to verify the user information through the domain node where the user is located. The example is as follows:

[0074] The domain node B trusts the domain node A. The cross-domain authentication process is as follows:

[0075] 1. The domain name of the domain node A is A.local, and the domain name of the B node is B.local;

[0076] 2. userB is a user of the domain node B, and the complete user information is userB@B.local; the terminal terminalA is joined to the domain node A and is under the control of the domain node A; at this time, userB travels to the area where the domain node A is located and needs to log in to use the terminal termianlA. This scenario involves cross-domain authentication of the terminal;

[0077] 3. When at terminal A, enter the username userB@B.local and password to initiate a login authentication. The authentication service of domain node A resolves userB@B.local and discovers that it is a user of domain node B. At this time, domain node A initiates a cross-node service call, forwards the authentication to domain node B, with the request parameters being serviceName=authService, port=8000, method=POST, uri= / auth, hearder=default, and body={user:userB,password:xxx}.

[0078] 4. Domain node B receives the request, parses the parameters, and according to the local routing table, queries that the address of authService is kim.local, and executes a local interface call:

[0079] The complete path of the interface is http: / / kim.local:8000 / auth;

[0080] The body is {user:userB,password:xxx};

[0081] 5. Domain node B returns the authentication result to domain node A through an encrypted channel;

[0082] 6. Domain node A receives the authentication result. If the authentication is successful, user userB successfully logs in to terminal A, and the cross-domain authentication process is completed.

[0083] The present invention also discloses a terminal cross-domain management device, as Figure 4 shown, including:

[0084] A trust relationship establishment module 401, configured to establish a trust relationship between domain nodes according to the needs of a user to log in to a cross-domain terminal, where the domain nodes include: a domain control end and a plurality of terminals managed by the domain control end;

[0085] A verification module 402, configured to when a user logs in to a cross-domain terminal, the domain node where the logged-in terminal is located uses the trust relationship established between the domain nodes to verify user information through the domain node where the user is located;

[0086] A login module 403, configured to if the user information verification is passed, the user is allowed to log in to the cross-domain terminal.

[0087] The present invention also discloses an electronic device, as Figure 5 shown, which discloses an embodiment, a block diagram of an electronic device applicable to the above terminal cross-domain management.

[0088] In this embodiment, the electronic device 50 includes a processor 501, which can perform various appropriate actions and processes according to the programs stored in the ROM 502 or loaded into the RAM 503 from the storage section 508. The processor 501 can include, for example, a general microprocessor, an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor, etc. The processor 501 can also include on-board memory for caching purposes. The processor 501 can include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiments of the present invention.

[0089] In the RAM 503, various programs and data required for the operation of the electronic device 50 are stored. The processor 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. The processor 501 performs various operations of the method flow according to the embodiments of the present invention by executing the programs in the ROM 502 and / or the RAM 503. It should be noted that the programs can also be stored in one or more memories other than the ROM 502 and the RAM 503, and the processor 501 can also perform various operations of the method flow according to the embodiments of the present invention by executing the programs stored in one or more memories.

[0090] According to an embodiment of the present invention, the electronic device 50 may further include an I / O interface 505, and the I / O interface 505 is also connected to the bus 504. The electronic device 50 may further include one or more of the following components connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, etc.; an output section 507 including a cathode ray tube, a liquid crystal display, a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, a modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 5010 is also connected to the I / O interface 505 as needed. A removable medium 5011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 5010 as needed, so that the computer program read from it can be installed into the storage section 508 as needed.

[0091] The present invention also provides a computer-readable storage medium.

[0092] The computer-readable storage medium may be included in the electronic device / device system described in the above embodiments; or it may exist separately without being assembled into the electronic device / device. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present invention is implemented.

[0093] According to an embodiment of the present invention, the computer-readable storage medium may be a non-volatile computer-readable storage medium. For example, it may include but is not limited to: portable computer disks, hard disks, random access memory RAM, read-only memory ROM, erasable programmable read-only memory EPROM or flash memory, portable compact disk read-only memory CD-ROM, optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0094] An embodiment of the present invention also includes a computer program product.

[0095] This computer program product includes a computer program, and this computer program contains program code for executing the method provided by the embodiment of the present invention. When the computer program product runs on an electronic device, this program code is used to enable the electronic device to implement the method provided by the embodiment of the present invention.

[0096] In one embodiment, this computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, this computer program may also be transmitted and distributed in the form of a signal on a network medium. The program code contained in this computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0097] According to an embodiment of the present invention, the program code for executing the computer program provided by the embodiment of the present invention can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedures and / or object-oriented programming languages. Programming languages include but are not limited to, such as Java, C++, python, C language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network or a wide area network, or can be connected to an external computing device.

[0098] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in an order different from that noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as combinations of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions. Those skilled in the art can understand that the features described in various embodiments and / or claims of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features described in various embodiments and / or claims of the present invention can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present invention.

[0099] The embodiments of the present invention have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present invention. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present invention is defined by the appended claims and their equivalents, and without departing from the scope of the present invention, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present invention.

Claims

1. A terminal cross-domain management method, characterized in that Including: According to the user's requirement to log in to a cross-domain terminal, establish a trust relationship between domain nodes, where the domain nodes include: a domain control end and a number of terminals managed by the domain control end; Establish an encrypted channel between the domain node where the user is located and the domain node where the cross-domain terminal to be logged in is located, and the encrypted channel is used to implement cross-node service calls between the two domain nodes; When the user logs in to the cross-domain terminal, the domain node where the logged-in terminal is located uses the trust relationship established between the domain nodes to verify the user information through the domain node where the user is located; If the user information verification is passed, the user is allowed to log in to the cross-domain terminal; Establishing the encrypted channel includes: The trust relationship includes a superior domain node and an inferior domain node. The superior domain node generates an asymmetric key pair, including a private key P1 and a public key P2, and delivers the public key P2 to the inferior domain node offline. The inferior domain node generates an asymmetric key pair of the inferior domain node, including a private key C1 and a public key C2. The inferior domain node uses the public key P2 of the superior domain node to encrypt the symmetric key negotiation factor information S1 and the public key C2 generated by the inferior domain node and then sends them to the superior domain node; The superior domain node uses the private key P1 to decrypt to obtain the symmetric key negotiation factor information S1 and the public key C2. The superior domain node generates a symmetric key negotiation factor S2, combines the symmetric key negotiation factor S1 and the symmetric key negotiation factor S2 together to generate a symmetric key; The superior domain node uses the public key C2 to encrypt the symmetric key negotiation factor S2 and sends it to the inferior domain node; The inferior domain node uses the private key C1 to decrypt to obtain the symmetric key negotiation factor S2, combines the symmetric key negotiation factor S1 and the symmetric key negotiation factor S2 together to generate a symmetric key, and the two domain nodes use the symmetric key for encryption and decryption during communication.

2. The method for cross-domain management of a terminal according to claim 1, wherein The establishing of the trust relationship between domain nodes according to the user's requirement to log in to a cross-domain terminal includes: establishing a cascading relationship between all the domain nodes and generating a node tree, and according to the user's requirement to log in to a cross-domain terminal, using the topological data included in the node tree to establish the trust relationship between the domain nodes, where the topological data includes: the node id, node name, node domain name, node communication address and superior node id of each domain node.

3. The method for cross-domain management of a terminal according to claim 2, wherein The encrypted channel realizes cross-node service calls between the two domain nodes through a symmetric key.

4. The terminal cross-domain management method according to claim 1, wherein The establishing of the trust relationship between domain nodes according to the user's requirement to log in to a cross-domain terminal includes: using an audit node to audit whether the trust relationship can be established.

5. The terminal cross-domain management method according to claim 3, wherein Each domain node on the node tree stores the topological data.

6. The method for cross - domain management of a terminal according to claim 5, wherein, The topological data is updated according to the change situation of the node tree.

7. A terminal cross-domain management device, characterized in that: The device includes: A trust relationship establishment module is used to establish a trust relationship between domain nodes according to the needs of a user to log in to a cross-domain terminal. Among them, the domain nodes include: a domain control end and a number of terminals managed by the domain control end; an encrypted channel is established between the domain node where the user is located and the domain node where the cross-domain terminal to be logged in is located, and the encrypted channel is used to implement cross-node service calls between the two domain nodes; establishing the encrypted channel includes: the trust relationship includes a superior domain node and an inferior domain node. The superior domain node generates an asymmetric key pair, including a private key P1 and a public key P2. The public key P2 is delivered to the inferior domain node offline. The inferior domain node generates an asymmetric key pair of the inferior domain node, including a private key C1 and a public key C2. The inferior domain node uses the public key P2 of the superior domain node to encrypt the symmetric key negotiation factor information S1 and the public key C2 generated by the inferior domain node and then sends them to the superior domain node; the superior domain node uses the private key P1 to decrypt to obtain the symmetric key negotiation factor information S1 and the public key C2. The superior domain node generates a symmetric key negotiation factor S2, combines the symmetric key negotiation factor S1 and the symmetric key negotiation factor S2 together to generate a symmetric key; the superior domain node uses the public key C2 to encrypt the symmetric key negotiation factor S2 and sends it to the inferior domain node; the inferior domain node uses the private key C1 to decrypt to obtain the symmetric key negotiation factor S2, combines the symmetric key negotiation factor S1 and the symmetric key negotiation factor S2 together to generate a symmetric key, and the two domain nodes use the symmetric key for encryption and decryption during communication; A verification module is used to, when the user logs in to the cross-domain terminal, the domain node where the logged-in terminal is located uses the trust relationship established between the domain nodes to verify the user information through the domain node where the user is located; A login module is used to, if the user information verification is passed, the user is allowed to log in to the cross-domain terminal.

8. An electronic device, characterized in that, Comprising: One or more processors; A storage device is used to store one or more programs. Among them, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 6.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Decentralized Internet-of-Things cross-domain access authorization method and system

    CN111835528A