A remote security operation and maintenance method and system suitable for unattended operation

By establishing independent service channels and operation and maintenance channels between the acquisition terminal and the secure access gateway, detecting abnormal terminals and implementing fine-grained access control strategies, the problems of unreachable equipment networks and operation and maintenance security risks in the existing technology are solved, and the operation and maintenance security protection level of the acquisition terminal is improved.

CN119583374BActive Publication Date: 2025-05-06信联科技(南京)有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510127571.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2025-05-06
Estimated Expiration
2045-02-05

AI Technical Summary

Technical Problem

The existing unattended remote security operation and maintenance methods have problems with unreachable equipment networks, and there are security risks during operation and maintenance, such as important data leakage and malicious operation risks.

Method used

A remote security operation and maintenance method suitable for unattended use is designed. By establishing independent service channels and operation and maintenance channels between the acquisition terminal and the secure access gateway, the secure access gateway detects abnormal terminals and sends operation and maintenance operations through the operation and maintenance channel, performs fine-grained access control policies, and realizes operation and maintenance updates.

Benefits of technology

The operation and maintenance security protection level of the acquisition terminal under unattended operation and maintenance has been improved, and the active analysis and timely operation and maintenance of abnormal behavior has been achieved, reducing the risk of network attacks due to open public network ports.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583374B_ABST
    Figure CN119583374B_ABST
Patent Text Reader

Abstract

The present invention relates to a remote safe operation and maintenance method suitable for unattended operation. Based on a business channel and an operation and maintenance channel independently constructed from each other, in the process of a collection terminal collecting business data and uploading it to a business system through a business channel, a safe access gateway detects abnormal terminals, obtains operation and maintenance operations generated by the operation and maintenance terminal through the operation and maintenance channel, executes fine-grained access control strategy design, and finally sends the data to the abnormal terminal through the operation and maintenance channel, executes operation and maintenance operations to perform operation and maintenance updates; and designs a corresponding system, specifically refines the modular design of the collection terminal and the safe access gateway, and efficiently realizes the designed remote safe operation and maintenance method; the present invention proposes an active construction mechanism of a remote operation and maintenance channel of a collection terminal, provides a safe operation and maintenance capability for a collection terminal without a public network IP address, and performs safe operation and maintenance on the operation and maintenance channel actively established by the collection terminal by the operation and maintenance terminal, while reducing the risk of the collection terminal being attacked by a network due to an open public network port.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a remote safety operation and maintenance method and system suitable for unattended operation, belonging to the technical field of remote operation and maintenance. Background Art

[0002] With the continuous development of science and technology and the in-depth application of automation technology, unattended operation as an efficient remote management method is gradually being favored by many companies. In addition, a large number of acquisition terminals often work on the front line for a long time, with wide distribution and diverse numbers and types. How to efficiently and timely operate and manage such distributed equipment has become an important industry topic. The current mainstream remote operation and maintenance method is to actively access the acquisition terminal based on the SSH protocol through terminal simulation software such as xshell or putty.

[0003] Since the working mode of the collection terminal is to collect data and actively upload it, private addresses are generally used for communication. Therefore, a large number of collection terminals cannot be actively accessed, and there is a problem of unreachable equipment network. In addition, while the operation and maintenance tools facilitate the operation of operation and maintenance personnel, they will inevitably bring security risks caused by improper operation and maintenance operations or malicious attacks, and there are risks such as important data leakage and malicious operations.

[0004] The existing unattended remote security operation and maintenance construction process involves two entities: terminals and operation and maintenance terminals. The channel construction process is as follows: Figure 1 As shown in the figure, after receiving the operation and maintenance task, the operation and maintenance personnel log in to the operation and maintenance terminal, actively connect to the collection terminal based on network communication and use ssh, telnet or other communication protocols, and use digital certificates or user name and password and other security authentication mechanisms to achieve identity authentication. After successful authentication, the operation and maintenance work can be carried out. Existing operation and maintenance technologies and remote access methods have improved the unattended collection terminal capabilities and the security protection capabilities during the operation and maintenance process to a certain extent, but there are the following shortcomings:

[0005] (1) Currently, most O&M models are post-operation and maintenance, that is, after the terminal runs abnormally or even causes business stagnation, the business management personnel will perform O&M, but they do not have the ability to proactively analyze abnormal behavior during the operation of the terminal business, and cannot achieve proactive and timely O&M after abnormalities are discovered;

[0006] (2) Some terminals are originally designed to actively access business systems, so they do not have external IP addresses and cannot be actively accessed by external terminals, resulting in the problem of remote access network unreachability;

[0007] (3) Excessive permissions during the operation and maintenance process. Since operation and maintenance generally use system administrator accounts to log in, there are security risks such as illegal access and incorrect modification of important configuration files. Summary of the invention

[0008] The technical problem to be solved by the present invention is to provide a remote safe operation and maintenance method suitable for unattended operation, so as to improve the operation and maintenance safety protection level of the acquisition terminal under unattended operation.

[0009] In order to solve the above technical problems, the present invention adopts the following technical solutions: the present invention designs a remote security operation and maintenance method suitable for unattended operation, based on the business channel and operation and maintenance channel between each acquisition terminal and the security access gateway, the business channel between the security access gateway and the business system, and the operation and maintenance channel between the security access gateway and the operation and maintenance terminal, each acquisition terminal collects business data respectively, and uploads it to the business system through the business channel via the security access gateway, and performs the following steps to realize remote operation and maintenance;

[0010] Step A. The secure access gateway analyzes each business data passing through it, determines whether the collection terminal corresponding to the business data is an abnormal terminal, and associates the abnormal terminal with the abnormal situation, and sends it to the operation and maintenance terminal through the operation and maintenance channel, and then proceeds to step B; otherwise, the business data is further forwarded to the business system;

[0011] Step B. The operation and maintenance terminal generates corresponding operation and maintenance operations under the target protocol for the received abnormal situation, and forwards it to the corresponding abnormal terminal through the operation and maintenance channel via the secure access gateway, and the abnormal terminal executes the operation and maintenance operation to perform operation and maintenance update.

[0012] As a preferred technical solution of the present invention: in the step A, the secure access gateway executes the following steps A1 to A2 for each service data passing through it;

[0013] Step A1. The secure access gateway parses the business data passed through it to obtain the parsed data, and extracts the preset operating status of the business data corresponding to the acquisition terminal, and proceeds to step A2;

[0014] Step A2. The secure access gateway determines whether there are any abnormal conditions in the parsed data that do not meet the preset business collection requirements, and determines whether there are any abnormal conditions in the preset operating states of the collection terminal that do not meet the preset terminal state range. If so, the collection terminal corresponding to the abnormal condition is defined as an abnormal terminal, and the abnormal terminal is associated with the abnormal condition, and is sent to the operation and maintenance terminal through the operation and maintenance channel; otherwise, the business data is further forwarded to the business system.

[0015] As a preferred technical solution of the present invention: the step B includes the following steps B1 to B4;

[0016] Step B1. The operation and maintenance terminal generates the corresponding operation and maintenance operation under the target protocol for the received abnormal situation, and forwards it to the secure access gateway through the operation and maintenance channel, and then proceeds to step B2;

[0017] Step B2. The secure access gateway adds the operation and maintenance object and operation and maintenance time to the operation and maintenance operation received from the operation and maintenance terminal according to the associated abnormal terminal and abnormal situation, constitutes the operation and maintenance data under the target protocol, and forwards it to the corresponding abnormal terminal through the corresponding operation and maintenance channel, and then proceeds to step B3;

[0018] Step B3. The abnormal terminal receives operation and maintenance data from the secure access gateway, parses and obtains the operation and maintenance operations, as well as each other's operation and maintenance subject information and operation and maintenance operation model, and the operation and maintenance subject information and operation and maintenance operation model constitute the access control policy, and then proceeds to step B4;

[0019] Step B4. The abnormal terminal performs operation and maintenance operations on the file system therein according to the access control policy to perform operation and maintenance updates.

[0020] As a preferred technical solution of the present invention: the target protocol in step B is ssh protocol or telnet protocol, and the operation and maintenance subject information in step B3 includes authenticated user, operation and maintenance object, operation and maintenance time, operation and maintenance personnel, and operation and maintenance equipment.

[0021] As a preferred technical solution of the present invention: in the step B4, the abnormal terminal performs the following steps B4-1 to B4-2 for each sub-operation in the operation and maintenance operation in sequence according to the access control policy;

[0022] Step B4-1 abnormal terminal based on the access control policy, determine whether the sub-operation complies with the access control policy, is the abnormal terminal for which the file system performs the sub-operation; otherwise the abnormal terminal terminates the execution of the sub-operation, and proceeds to step B4-2;

[0023] Step B4-2. The abnormal terminal determines whether the risk level of the sub-operation exceeds the preset risk level threshold. If so, the abnormal terminal sends a control command to disconnect the operation terminal from the secure access gateway through the operation channel. The secure access gateway receives the control command and disconnects the operation channel between it and the operation terminal.

[0024] As a preferred technical solution of the present invention: the operation and maintenance channels between each acquisition terminal and the secure access gateway are formed through the heartbeat channel between the corresponding acquisition terminal and the secure access gateway.

[0025] Corresponding to the above, the technical problem that the present invention also needs to solve is to provide a system suitable for unmanned remote security operation and maintenance methods, execute the designed operation and maintenance methods, and improve the operation and maintenance safety protection level of the acquisition terminal under unmanned conditions.

[0026] In order to solve the above technical problems, the present invention adopts the following technical solutions: the present invention designs a system suitable for an unattended remote security operation and maintenance method, wherein the security access gateway comprises an access module, a business analysis module, and a security operation and maintenance module, wherein one end of the access module is used to connect to a business channel connected to a collection terminal, and the other end of the access module is used to connect to a business channel connected to a business system;

[0027] The service analysis module includes a protocol analysis unit, a status monitoring unit, and an abnormal alarm unit, wherein the protocol analysis unit is used to extract service data from the access module, perform the service data analysis in step A1 to obtain the analysis data, and perform the judgment on the analysis data in step A2; the status monitoring unit is used to extract the preset operation states of the acquisition terminal corresponding to the service data in step A1, and perform the judgment on the preset operation states of the acquisition terminal in step A2; the abnormal alarm unit is used to receive abnormal conditions from the protocol analysis unit and the status monitoring unit, perform the association of the abnormal terminal with the abnormal condition in step A2, and send it to the security operation and maintenance module, and send it to the operation and maintenance terminal through the operation and maintenance channel between the security access gateway and the operation and maintenance terminal;

[0028] The security operation and maintenance module includes an operation and maintenance forwarding unit and an operation and maintenance agent unit. One end of the operation and maintenance agent unit is connected to the operation and maintenance channel between the security access gateway and the operation and maintenance terminal, and is used to execute the operation and maintenance operation received from the operation and maintenance terminal in step B2, and forward it to the operation and maintenance forwarding unit; the operation and maintenance forwarding unit receives the associated abnormal terminal and abnormal situation sent by the abnormal alarm unit, and according to the abnormal situation, executes step B2 for the received operation and maintenance operation, constitutes the operation and maintenance data under the target protocol, and forwards it to the corresponding abnormal terminal through the corresponding operation and maintenance channel.

[0029] As a preferred technical solution of the present invention: the acquisition terminal includes a remote security operation and maintenance module, a file system, and a business module, wherein the business module is used to collect business data and upload it to a secure access gateway through a business channel;

[0030] The remote security operation and maintenance module includes an operation and maintenance protocol parsing unit, an operation and maintenance operation unit, and an access control unit. As a collection terminal for abnormal terminals, the operation and maintenance protocol parsing unit executes step B3 to receive operation and maintenance data, parses the operation and maintenance operations therein, and constructs an access control policy, and sends the operation and maintenance operations to the operation and maintenance operation unit, and sends the access control policy to the access control unit; the operation and maintenance operation unit executes step B4 to perform operation and maintenance operations on the file system, and the access control unit performs step B4 to review the operation and maintenance operations of the operation and maintenance operation unit according to the access control policy to allow or block the operations.

[0031] As a preferred technical solution of the present invention: the remote security operation and maintenance module in the collection terminal also includes a heartbeat module, and the security operation and maintenance module in the security access gateway also includes a heartbeat module. The heartbeat module in the collection terminal and the heartbeat module in the security access gateway construct an operation and maintenance channel between the collection terminal and the security access gateway. The operation and maintenance forwarding unit in the security access gateway executes step B2 to obtain the operation and maintenance data under the target protocol and sends it to the heartbeat module in the security access gateway. The heartbeat module sends the data to the heartbeat module in the collection terminal through the connected operation and maintenance channel. The heartbeat module in the collection terminal receives the operation and maintenance data and forwards it to the operation and maintenance protocol parsing unit in the collection terminal. The operation and maintenance protocol parsing unit receives the operation and maintenance data.

[0032] The present invention discloses a remote security operation and maintenance method and system suitable for unattended operation, which has the following technical effects compared with the prior art by using the above technical solution:

[0033] The remote secure operation and maintenance method designed by the present invention is suitable for unattended operation. It is based on a business channel and an operation and maintenance channel that are independently constructed. For the process in which a collection terminal collects business data and uploads it to a business system through a secure access gateway via a business channel, the secure access gateway detects abnormal terminals, obtains the operation and maintenance operations generated by the operation and maintenance terminals through the operation and maintenance channel, executes fine-grained access control strategy design, and finally sends the data to the abnormal terminals through the operation and maintenance channel to execute the operation and maintenance operations for operation and maintenance updates; and designs a corresponding system to specifically refine the modular design of the collection terminal and the secure access gateway, so as to efficiently implement the designed remote secure operation and maintenance method; the present invention proposes an active construction mechanism for the remote operation and maintenance channel of the collection terminal, which provides the collection terminal without a public network IP address with the capability of secure operation and maintenance, and the operation and maintenance terminal performs secure operation and maintenance on the operation and maintenance channel actively established by the collection terminal, while reducing the risk of the collection terminal being attacked by a network due to the open public network port. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 This is a schematic diagram of the existing unattended remote security operation and maintenance construction channel;

[0035] Figure 2It is a schematic diagram of the architecture of a system designed by the present invention for an unattended remote security operation and maintenance method;

[0036] Figure 3 It is a schematic diagram of the architecture of the acquisition terminal in the design system of the present invention;

[0037] Figure 4 It is a schematic diagram of the architecture of the secure access gateway in the design system of the present invention;

[0038] Figure 5 It is a flow chart of a method for remote safety operation and maintenance suitable for unattended operation designed by the present invention;

[0039] Figure 6 It is a schematic diagram of fine-grained remote operation and maintenance security access designed by the present invention for use in an unattended remote security operation and maintenance method. DETAILED DESCRIPTION

[0040] The specific implementation modes of the present invention will be further described in detail below in conjunction with the accompanying drawings.

[0041] The present invention is designed to be suitable for unattended remote security operation and maintenance method and system. In practical application, such as Figure 2 As shown, the system includes a business system, an operation and maintenance terminal, a secure access gateway, and various collection terminals. Each collection terminal establishes a business channel and an operation and maintenance channel with the secure access gateway, a business channel is established between the secure access gateway and the business system, and an operation and maintenance channel is established between the secure access gateway and the operation and maintenance terminal.

[0042] The structures of each acquisition terminal are the same as each other, such as Figure 3 As shown, each collection terminal includes a file system, a business module, and a remote security operation and maintenance module, wherein the business module is used to collect business data and connect to the business channel to upload it to the secure access gateway; the remote security operation and maintenance module includes a heartbeat unit, an operation and maintenance protocol parsing unit, an operation and maintenance operation unit, and an access control unit. One end of the heartbeat unit is connected to the input end of the operation and maintenance protocol parsing unit, the output end of the operation and maintenance protocol parsing unit is connected to the input end of the operation and maintenance operation unit, the output end of the operation and maintenance protocol parsing unit and the output end of the operation and maintenance operation unit are respectively connected to the input end of the access control unit, and the output end of the access control unit is respectively connected to the file system and the business module.

[0043] like Figure 4As shown, the secure access gateway includes an access module, a business analysis module, and a secure operation and maintenance module, wherein one end of the access module is used to connect to the business channel connected to the collection terminal, and the other end of the access module is used to connect to the business channel connected to the business system; the business analysis module includes a protocol analysis unit, a status monitoring unit, and an abnormal alarm unit, wherein the protocol analysis unit is connected to the access module, the protocol analysis unit is connected to the status monitoring unit, the protocol analysis unit and the status monitoring unit are respectively connected to the abnormal alarm unit, and the abnormal alarm unit is connected to the operation and maintenance terminal via the operation and maintenance channel between the secure access gateway and the operation and maintenance terminal; the secure operation and maintenance module includes a heartbeat unit, an operation and maintenance forwarding unit, and an operation and maintenance agent unit, one end of the operation and maintenance agent unit is connected to the operation and maintenance channel between the secure access gateway and the operation and maintenance terminal, the other end of the operation and maintenance agent unit is connected to one end of the operation and maintenance forwarding unit, the other end of the operation and maintenance forwarding unit is connected to one end of the heartbeat unit, and the abnormal alarm unit is simultaneously connected to the operation and maintenance forwarding unit.

[0044] A heartbeat channel is established between the other end of the heartbeat unit in each collection terminal and the other end of the heartbeat unit in the security access gateway, that is, as an operation and maintenance channel. In actual applications, the remote security operation and maintenance module in the collection terminal establishes an operation and maintenance channel with the security access gateway by actively initiating a TCP connection. The heartbeat units distributed in the collection terminal and the security access gateway send heartbeat data to each other at regular intervals to maintain the online status of the operation and maintenance channel. At the same time, the operation and maintenance channel realizes remote operation and maintenance between the collection terminal and the security access gateway.

[0045] The above designed system is applied in practice. The business data is collected from the business modules in each collection terminal respectively, and uploaded to the business system through the access module in the security access gateway through the corresponding business channel. Figure 5 As shown, perform the following steps A to B to achieve remote operation and maintenance.

[0046] Step A. The secure access gateway analyzes each business data passing through it, determines whether the collection terminal corresponding to the business data is an abnormal terminal, and associates the abnormal terminal with the abnormal situation, and sends it to the operation and maintenance terminal through the operation and maintenance channel, and enters step B; otherwise, the business data is further forwarded to the business system.

[0047] In actual application, in the above step A, the secure access gateway executes the following steps A1 to A2 for each service data passing through it.

[0048] Step A1. The protocol parsing unit in the secure access gateway extracts the service data from the access module, parses the service data to obtain parsed data, and extracts the preset operating states of the acquisition terminal corresponding to the service data by the status monitoring unit, and then proceeds to step A2.

[0049] Step A2. The protocol parsing unit in the secure access gateway determines whether there are abnormal conditions in the parsed data that do not meet the preset business collection requirements, and the status monitoring unit determines whether there are abnormal conditions in the preset operating states of the collection terminal that do not meet the preset terminal state range. The abnormal alarm unit receives the abnormal conditions from the protocol parsing unit and the status monitoring unit, defines the collection terminal corresponding to the abnormal condition as an abnormal terminal, associates the abnormal terminal with the abnormal condition, places it in the list to be operated and maintained, and specifies the port opening of the operation and maintenance channel of the abnormal terminal. Then, the associated abnormal terminal and the abnormal condition are sent to the security operation and maintenance module in the secure access gateway, and sent to the operation and maintenance terminal via the operation and maintenance channel; otherwise, the access module in the secure access gateway directly forwards the business data to the business system through the business channel.

[0050] In actual applications, an abnormal alarm unit can also be designed to send the associated abnormal terminal and abnormal situation to the administrator, and the administrator can control the operation and maintenance terminal work.

[0051] The judgment in the above step A2 is about judging whether there is an abnormal situation in the parsed data that does not meet the preset business collection requirements. In actual applications, such as judging whether the parsed data exceeds the preset business definition extraction range threshold. If it exceeds, it means that there is an abnormality in the collection object or collection method of the current collection terminal; about judging whether there is an abnormal situation in the preset operating states of the collection terminal that does not meet the preset terminal state range. In actual applications, such as judging whether the real-time information of the CPU and memory of the collection terminal is overloaded. If an overload occurs, it means that there is an abnormality in the internal process of the collection terminal.

[0052] Next, Figure 6 As shown, the operation and maintenance terminal is further designed for fine-grained remote operation and maintenance of abnormal terminals, and the following step B is performed.

[0053] Step B. The operation and maintenance terminal uses tools such as putty and xshell to generate corresponding operation and maintenance operations under the target protocol for the received abnormal situation, and forwards it to the corresponding abnormal terminal through the operation and maintenance channel via the secure access gateway. The abnormal terminal executes the operation and maintenance operation to perform operation and maintenance updates.

[0054] In practical application, the above step B is designed to specifically perform the following steps B1 to B4.

[0055] Step B1. The operation and maintenance terminal generates corresponding operation and maintenance operations under the target protocol such as ssh protocol or telnet protocol for the received abnormal situation, and forwards it to the operation and maintenance agent unit in the secure access gateway through the operation and maintenance channel, and then enters step B2.

[0056] Step B2. The operation and maintenance agent unit in the secure access gateway receives the operation and maintenance operations from the operation and maintenance terminal and forwards them to the operation and maintenance forwarding unit. The operation and maintenance forwarding unit adds the operation and maintenance objects and operation and maintenance time for the operation and maintenance operations based on the associated abnormal terminal and abnormal situation sent from the abnormal alarm unit, constitutes the operation and maintenance data under the target protocol, implements a fine-grained remote operation and maintenance security access control mechanism, and forwards the heartbeat unit in the secure access gateway. Then, based on the list of operations to be performed, the operation and maintenance data is forwarded to the corresponding abnormal terminal through the operation and maintenance channel constructed based on the heartbeat unit between the secure access gateway and the corresponding abnormal terminal, and then enters step B3.

[0057] Step B3. The heartbeat unit in the abnormal terminal receives the operation and maintenance data sent from the secure access gateway and forwards it to the operation and maintenance protocol parsing unit, which parses the operation and maintenance data to obtain the operation and maintenance operations, operation and maintenance subject information, and operation and maintenance operation models, and forms an access control policy based on the operation and maintenance subject information and operation and maintenance operation models, sends the operation and maintenance operations to the operation and maintenance operation unit, sends the access control policy to the access control unit, and then enters step B4. Among them, the operation and maintenance subject information includes the authenticated user, operation and maintenance object, operation and maintenance time, operation and maintenance personnel, and operation and maintenance equipment.

[0058] Step B4. The abnormal terminal performs operation and maintenance operations on the file system therein according to the access control policy to perform operation and maintenance updates.

[0059] In actual application of the above step B4, the specific abnormal terminal executes the following steps B4-1 to B4-2 for each sub-operation in the operation and maintenance operation in sequence according to the access control policy to prevent unauthorized behavior.

[0060] Step B4-1. The access control unit in the abnormal terminal determines whether the sub-operation performed by the operation and maintenance unit in the abnormal terminal complies with the access control policy based on the access control policy. If so, the operation and maintenance unit executes the sub-operation for the file system therein; otherwise, the access control unit terminates the sub-operation of the operation and maintenance unit and enters step B4-2.

[0061] Step B4-2. The access control unit further determines whether the risk level of the sub-operation exceeds the preset risk level threshold. If so, the access control unit sends a control command to disconnect the operation and maintenance terminal to the secure access gateway through the operation and maintenance channel. The secure access gateway receives the control command and disconnects the operation and maintenance channel between it and the operation and maintenance terminal.

[0062] The remote security operation and maintenance mechanism designed by the present invention is based on the security access technology. The security access gateway is used to analyze the business characteristics of the collection terminal in real time, and the active alarm of abnormal behavior of the collection terminal is realized. For suspicious terminals, that is, abnormal terminals, the operation and maintenance terminal uses the security access gateway as a springboard to perform remote operation and maintenance, and reuses the operation and maintenance channel between the collection terminal and the security access gateway to actively initiate secure interaction of operation and maintenance data. At the same time, during the remote operation and maintenance process, the security protection of the core data inside the collection terminal is realized by setting and executing fine-grained access control strategies.

[0063] The above technical scheme is designed to be suitable for an unattended remote secure operation and maintenance method, which is based on a business channel and an operation and maintenance channel that are independently constructed. For the process in which the collection terminal collects business data and uploads it to the business system through the business channel via a secure access gateway, the secure access gateway detects abnormal terminals, obtains the operation and maintenance operations generated by the operation and maintenance terminal through the operation and maintenance channel, executes fine-grained access control strategy design, and finally sends it to the abnormal terminal through the operation and maintenance channel to execute the operation and maintenance operations for operation and maintenance updates; and designs a corresponding system to specifically refine the modular design of the collection terminal and the secure access gateway, and efficiently implements the designed remote secure operation and maintenance method; the present invention proposes an active construction mechanism for the remote operation and maintenance channel of the collection terminal, which provides the collection terminal without a public IP address with the capability of secure operation and maintenance, and the operation and maintenance terminal performs secure operation and maintenance on the operation and maintenance channel actively established by the collection terminal, while reducing the risk of the collection terminal being attacked by a network due to the open public network port.

[0064] The embodiments of the present invention are described in detail above with reference to the accompanying drawings, but the present invention is not limited to the above embodiments, and various changes can be made within the knowledge scope of ordinary technicians in this field without departing from the purpose of the present invention.

Claims

1. A remote security operation and maintenance method suitable for unattended operation, characterized in that: Based on the business channel and operation and maintenance channel between each collection terminal and the security access gateway, as well as the business channel between the security access gateway and the business system, and the operation and maintenance channel between the security access gateway and the operation and maintenance terminal, each collection terminal collects business data respectively, and uploads it to the business system through the business channel via the security access gateway, and performs the following steps to realize remote operation and maintenance; Step A. The secure access gateway analyzes each business data passing through it, determines whether the collection terminal corresponding to the business data is an abnormal terminal, and associates the abnormal terminal with the abnormal situation, and sends it to the operation and maintenance terminal through the operation and maintenance channel, and then proceeds to step B; otherwise, the business data is further forwarded to the business system; Step B. The operation and maintenance terminal generates corresponding operation and maintenance operations under the target protocol for the received abnormal situation, and forwards it to the corresponding abnormal terminal through the operation and maintenance channel via the secure access gateway, and the abnormal terminal executes the operation and maintenance operation to perform operation and maintenance update.

2. A remote security operation and maintenance method suitable for unattended operation according to claim 1, characterized in that: In the step A, the secure access gateway executes the following steps A1 to A2 for each service data passing through it; Step A1. The secure access gateway parses the business data passed through it to obtain the parsed data, and extracts the preset operating status of the business data corresponding to the acquisition terminal, and proceeds to step A2; Step A2. The secure access gateway determines whether there are any abnormal conditions in the parsed data that do not meet the preset business collection requirements, and determines whether there are any abnormal conditions in the preset operating states of the collection terminal that do not meet the preset terminal state range. If so, the collection terminal corresponding to the abnormal condition is defined as an abnormal terminal, and the abnormal terminal is associated with the abnormal condition, and is sent to the operation and maintenance terminal through the operation and maintenance channel; otherwise, the business data is further forwarded to the business system.

3. A remote security operation and maintenance method suitable for unattended operation according to claim 2, characterized in that: The step B includes the following steps B1 to B4; Step B1. The operation and maintenance terminal generates the corresponding operation and maintenance operation under the target protocol for the received abnormal situation, and forwards it to the secure access gateway through the operation and maintenance channel, and then proceeds to step B2; Step B2. The secure access gateway adds the operation and maintenance object and operation and maintenance time to the operation and maintenance operation received from the operation and maintenance terminal according to the associated abnormal terminal and abnormal situation, constitutes the operation and maintenance data under the target protocol, and forwards it to the corresponding abnormal terminal through the corresponding operation and maintenance channel, and then proceeds to step B3; Step B3. The abnormal terminal receives operation and maintenance data from the secure access gateway, parses and obtains the operation and maintenance operations, as well as each other's operation and maintenance subject information and operation and maintenance operation model, and the operation and maintenance subject information and operation and maintenance operation model constitute the access control policy, and then proceeds to step B4; Step B4. The abnormal terminal performs operation and maintenance operations on the file system therein according to the access control policy to perform operation and maintenance updates.

4. A remote security operation and maintenance method suitable for unattended operation according to claim 3, characterized in that: The target protocol in step B is ssh protocol or telnet protocol, and the operation and maintenance subject information in step B3 includes the authenticated user, operation and maintenance object, operation and maintenance time, operation and maintenance personnel, and operation and maintenance equipment.

5. A remote security operation and maintenance method suitable for unattended operation according to claim 3, characterized in that: In step B4, the abnormal terminal executes the following steps B4-1 to B4-2 for each sub-operation in the operation and maintenance operation in sequence according to the access control policy; Step B4-1 abnormal terminal based on the access control policy, determine whether the sub-operation complies with the access control policy, is the abnormal terminal for which the file system performs the sub-operation; otherwise the abnormal terminal terminates the execution of the sub-operation, and proceeds to step B4-2; Step B4-2. The abnormal terminal determines whether the risk level of the sub-operation exceeds the preset risk level threshold. If so, the abnormal terminal sends a control command to disconnect the operation terminal from the secure access gateway through the operation channel. The secure access gateway receives the control command and disconnects the operation channel between it and the operation terminal.

6. A remote security operation and maintenance method suitable for unattended operation according to claim 1, characterized in that: The operation and maintenance channels between each acquisition terminal and the secure access gateway are formed through a heartbeat channel between the corresponding acquisition terminal and the secure access gateway.

7. A system for implementing the unattended remote security operation and maintenance method according to claim 3, characterized in that: The secure access gateway includes an access module, a service analysis module, and a secure operation and maintenance module, wherein one end of the access module is used to connect to a service channel connected to a collection terminal, and the other end of the access module is used to connect to a service channel connected to a service system; The service analysis module includes a protocol analysis unit, a status monitoring unit, and an abnormal alarm unit, wherein the protocol analysis unit is used to extract service data from the access module, perform the service data analysis in step A1 to obtain the analysis data, and perform the judgment on the analysis data in step A2; the status monitoring unit is used to extract the preset operation states of the acquisition terminal corresponding to the service data in step A1, and perform the judgment on the preset operation states of the acquisition terminal in step A2; the abnormal alarm unit is used to receive abnormal conditions from the protocol analysis unit and the status monitoring unit, perform the association of the abnormal terminal with the abnormal condition in step A2, and send it to the security operation and maintenance module, and send it to the operation and maintenance terminal through the operation and maintenance channel between the security access gateway and the operation and maintenance terminal; The security operation and maintenance module includes an operation and maintenance forwarding unit and an operation and maintenance agent unit. One end of the operation and maintenance agent unit is connected to the operation and maintenance channel between the security access gateway and the operation and maintenance terminal, and is used to execute the operation and maintenance operation received from the operation and maintenance terminal in step B2, and forward it to the operation and maintenance forwarding unit; the operation and maintenance forwarding unit receives the associated abnormal terminal and abnormal situation sent by the abnormal alarm unit, and according to the abnormal situation, executes step B2 for the received operation and maintenance operation, constitutes the operation and maintenance data under the target protocol, and forwards it to the corresponding abnormal terminal through the corresponding operation and maintenance channel.

8. The system according to claim 7, characterized in that: The acquisition terminal includes a remote security operation and maintenance module, a file system, and a business module, wherein the business module is used to collect business data and upload it to a secure access gateway through a business channel; The remote security operation and maintenance module includes an operation and maintenance protocol parsing unit, an operation and maintenance operation unit, and an access control unit. As a collection terminal for abnormal terminals, the operation and maintenance protocol parsing unit executes step B3 to receive operation and maintenance data, parses the operation and maintenance operations therein, and constructs an access control policy, and sends the operation and maintenance operations to the operation and maintenance operation unit, and sends the access control policy to the access control unit; the operation and maintenance operation unit executes step B4 to perform operation and maintenance operations on the file system, and the access control unit performs step B4 to review the operation and maintenance operations of the operation and maintenance operation unit according to the access control policy to allow or block the operations.

9. The system according to claim 8, characterized in that: The remote security operation and maintenance module in the collection terminal also includes a heartbeat module, and the security operation and maintenance module in the secure access gateway also includes a heartbeat module. The heartbeat module in the collection terminal and the heartbeat module in the secure access gateway construct an operation and maintenance channel between the collection terminal and the secure access gateway. The operation and maintenance forwarding unit in the secure access gateway executes step B2 to obtain the operation and maintenance data under the target protocol and sends it to the heartbeat module in the secure access gateway. The heartbeat module sends the data to the heartbeat module in the collection terminal through the connected operation and maintenance channel. The heartbeat module in the collection terminal receives the operation and maintenance data and forwards it to the operation and maintenance protocol parsing unit in the collection terminal, and the operation and maintenance protocol parsing unit receives the operation and maintenance data.

Citation Information

Patent Citations

  • Cloud-platform-based remote operation and maintenance system

    CN108681288A

  • Multi-source data fusion-based intelligent terminal and method for power internet of things

    CN114745404A