A method, system, and storage medium for enhancing the security of a bastion host
By distributing the bastion machine permissions and using challenge code verification, the problems of insufficient security and poor ease of use of the bastion machine system are solved, and secure SSH remote login and efficient maintenance operations are achieved.
Patent Information
- Application Number
- CN202510386498.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-03-31
AI Technical Summary
In the prior art, the security of the remote login basin system is insufficient and the ease of use of disabling remote login is poor, resulting in problems with the security and maintenance efficiency of the basin system.
By distributing the bastion machine permissions, the administrator account can only perform partial permission operations through the bastion machine console when logging in for the first time, and obtain more permissions after the second login. Combining challenge code and answer code verification, a secure SSH remote login is achieved.
It improves the safety of the fortress system, prevents the backend from being broken due to personnel resignation or machine breach, and improves the ease of use and safety of daily maintenance.
Smart Images

Figure CN119892523B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and specifically, to a method, a system, and a storage medium for enhancing the security of a bastion host. Background Art
[0002] After an enterprise deploys a bastion host system, it usually entrusts various assets under it to the bastion host. However, if the bastion host is breached, the corresponding entrusted various assets will face serious security problems.
[0003] In the prior art, the following two methods are usually adopted to enhance the security after deploying a bastion host:
[0004] 1. Use public and private keys to log in when remotely logging in to the bastion host, and regularly replace the public and private keys;
[0005] Although this method can prevent leakage to the greatest extent, there are still problems of leakage caused by the administrator's operation and maintenance machine being breached or personnel leaving the company, and the security is insufficient.
[0006] 2. Directly disable the remote SSH login of the bastion host and strictly prohibit any user from logging in to the bastion host through SSH;
[0007] Directly disabling SSH login can indeed achieve once and for all, but for daily maintenance or when the bastion host has an abnormality, it is necessary to go to the computer room for processing, which involves a series of additional applications and increases the daily maintenance work process.
[0008] Therefore, a method for enhancing the security of a bastion host is needed to solve the technical problems of insufficient security in remotely logging in to the bastion host system and poor usability in disabling remote login to the bastion host in the prior art. Summary of the Invention
[0009] The purpose of the present invention is to provide a method, a system, and a storage medium for enhancing the security of a bastion host. The method disperses the permissions of the bastion host, enables a special administrator account to perform SSH login, and restricts it to perform relevant operations only through the bastion host console. When logging in to the administrator account for the first time, only partial permissions can be obtained, and when logging in to the administrator account for the second time, it is possible to enter the background and obtain more permissions, realizing secure remote login to the bastion host through SSH, and solving the technical problems of insufficient security in remotely logging in to the bastion host system and poor usability in disabling remote login to the bastion host in the prior art.
[0010] The present invention is achieved by the following technical solutions:
[0011] In a first aspect, a method for enhancing the security of a bastion host is disclosed, including the following steps:
[0012] Step S1: Receive a request from the maintenance personnel to log in to the bastion host through the target user with unique SSH login permissions and the corresponding public-private key SSH.
[0013] Step S2: Conduct the first security verification. When the first security verification passes, allow the target user to directly log in to the bastion host console, enabling the maintenance personnel to perform the first-level maintenance by selecting and using the preset first-level maintenance commands in the bastion host console. When the first security verification fails, disconnect the SSH connection.
[0014] Step S3: Receive a request from the maintenance personnel to log in to the bastion host background.
[0015] Step S4: Conduct the second security verification. When the second security verification passes, redirect the maintenance commands entered by the maintenance personnel to the bastion host terminal to achieve the second-level maintenance. When the second security verification fails, disconnect the SSH connection.
[0016] To better implement the present invention, further, the method for configuring the target user includes:
[0017] Disable the sftp server, root login, and password login; only open the target user to obtain root privileges; set the target user to directly enter the bastion host console after logging in.
[0018] To better implement the present invention, further, the method for configuring the target user includes:
[0019] Modify the configuration file to disable root login, password login, and only open the target user to obtain root privileges.
[0020] To better implement the present invention, further, the method for logging in to the bastion host through SSH using the target user and the corresponding public-private key and directly entering the bastion host console includes:
[0021] When the bastion host recognizes that the maintenance personnel log in to the target user through SSH using the public-private key, start the bastion host console service.
[0022] The bastion host console displays the challenge code login interface and generates the first challenge code on the console service login interface.
[0023] The response code generation module receives the first challenge code entered by the maintenance personnel and generates the first response code.
[0024] The bastion host console receives the first response code entered by the maintenance personnel and starts the console service management interface after the first response code verification passes.
[0025] To better implement the present invention, further, after starting the bastion host console service, limit the concurrent number of the bastion host console at the same time, so that all maintenance personnel can only establish a fixed number of SSH connections with the bastion host at the same time.
[0026] To better implement the present invention, further, the method for the bastion host console to generate the first challenge code includes:
[0027] Randomly generate an original string, then use the sm2 algorithm for encryption and store the public key of the sm2 algorithm, and use the encrypted original string as the first challenge code.
[0028] To better implement the present invention, further, the response code generation module is independent of the bastion host, and the method for the response code generation module to generate the first response code includes:
[0029] Use the sm2 algorithm to decrypt the first challenge code, obtain the original string and combine it with a preset salt value, calculate the hash value of the combined string through the sm3 hashing algorithm, and intercept a specified part of the hash value as the first response code.
[0030] To better implement the present invention, further, the method for using the target user to trigger a secondary login on the bastion host console includes:
[0031] When the bastion host console recognizes the specified command input by the maintenance personnel, jump to the secondary login interface;
[0032] The bastion host console displays a challenge code login interface on the secondary login interface and generates a second challenge code;
[0033] The response code generation module receives the second challenge code input by the maintenance personnel and generates a second response code;
[0034] The bastion host console receives the second response code input by the maintenance personnel and, after the second response code is verified and passed, redirects the input to the bastion host terminal.
[0035] In a second aspect, the present application discloses a system for enhancing the security of a bastion host, including:
[0036] A first login module, which is used to receive a request from a maintenance personnel to log in to the bastion host through a target user with a unique SSH login privilege and the corresponding public and private key SSH;
[0037] A first verification module, which is used to perform a first security verification. When the first security verification passes, the target user is directly logged in to the bastion host console, so that the maintenance personnel can implement the first-level maintenance by selecting to use the preset first-level maintenance commands in the bastion host console. When the first security verification fails, the SSH connection is disconnected;
[0038] A second login module, which is used to receive requests from maintenance personnel to log in to the bastion host background.
[0039] A second verification module, which is used to perform a second security verification. When the second security verification is passed, the maintenance command input by the maintenance personnel is redirected to the bastion host terminal to implement the second-level maintenance. When the second security verification fails, the SSH connection is disconnected.
[0040] In a third aspect, the present application discloses a computer-readable storage medium, on which a computer program is stored. The program is characterized in that when executed by a processor, it implements the method for improving the security of the bastion host according to any one of the first aspects.
[0041] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0042] Using the bastion host console to manage the bastion host terminal can effectively restrict personnel from remotely logging in to the bastion host terminal and improve the security of the bastion host system.
[0043] Separate permissions to prevent the result that the bastion host background is breached due to personnel leaving or a single person's machine being breached. Brief Description of the Drawings
[0044] The present invention will be further described below in conjunction with the following drawings and embodiments. All creative concepts of the present invention should be regarded as the disclosed content and the protection scope of the present invention.
[0045] Figure 1 It is a schematic flowchart of Embodiment 1 of the method for improving the security of the bastion host in the present application.
[0046] Figure 2 It is a schematic flowchart of implementing the first-level maintenance and the second-level maintenance of the method for improving the security of the bastion host in Embodiment 1 of the present application.
[0047] Figure 3 It is a schematic diagram of implementing the first-level maintenance and the second-level maintenance of Embodiment 2 of the method for improving the security of the bastion host in the present application.
[0048] Figure 4 It is a schematic diagram of the system embodiment for improving the security of the bastion host in the present application. Detailed Embodiments
[0049] Embodiment 1
[0050] A method for improving the security of a bastion host includes the following steps:
[0051] Step S1: Receive requests from maintenance personnel to log in to the bastion host through a target user with a unique SSH login permission and the corresponding public and private key SSH.
[0052] Step S2: Conduct the first security verification. When the first security verification passes, directly log the target user in to the bastion host console, enabling the maintenance personnel to achieve the first-level maintenance by selecting and using the preset first-level maintenance commands in the bastion host console. When the first security verification fails, disconnect the SSH connection;
[0053] Step S3: Receive the request from the maintenance personnel to log in to the bastion host background;
[0054] Step S4: Conduct the second security verification. When the second security verification passes, redirect the maintenance command entered by the maintenance personnel to the bastion host terminal to achieve the second-level maintenance. When the second security verification fails, disconnect the SSH connection.
[0055] In this embodiment, the bastion host system is a comprehensive operation and maintenance management platform integrating system operation and maintenance and security auditing; the bastion host console is a service installed on the bastion host for hosting the bastion host terminal; the bastion host terminal is the bash of the bastion host system; the personnel logging in to the target user are the maintenance personnel of the bastion host system, rather than the personnel using the bastion host system for asset operation and maintenance; the first-level maintenance includes low-privilege operations such as shutting down, restarting, restoring factory settings, resetting the bastion host web administrator password, and checking the operation status of other services of the bastion host. The target user selects the first-level maintenance commands through simple methods such as using the arrow keys and the Enter key to execute the above low-privilege operations; the second-level maintenance is a series of high-privilege operations that cannot use the preset commands and require entering commands using the command line interface after entering the bastion host background.
[0056] See Figure 2 , in an alternative implementation manner of this embodiment, after creating the target user and the corresponding public and private keys and configuring the permissions of the target user and other users, the method for implementing the first-level maintenance and the second-level maintenance includes the following steps:
[0057] Step S101: Receive the request from the maintenance personnel to log in to the target user via public-private key SSH;
[0058] Step S102: Display a one-time login interface to the maintenance personnel;
[0059] Step S103: Verify the one-time login information of the maintenance personnel. Specifically, receive the one-time login information from the maintenance personnel. When the one-time login information verification passes, display the bastion host console service management interface to the maintenance personnel. When the one-time login information verification fails, disconnect the SSH connection;
[0060] Step S104: Implement the first-level maintenance according to the first-level maintenance command selected by the maintenance personnel in the bastion host console service management interface;
[0061] Step S105: Receive the secondary login request from the maintenance personnel;
[0062] Step S106: Display the secondary login interface to the maintenance personnel;
[0063] Step S107: Verify the secondary login information of the maintenance personnel and perform secondary-level maintenance. Specifically, receive the secondary login information from the maintenance personnel. When the secondary login information is verified successfully, redirect the input to the bastion host terminal. When the secondary login information is verified failed, disconnect the SSH connection.
[0064] Adopting this embodiment, through the idea of decentralized permissions, a dual security maintenance mechanism based on permission stratification and operation isolation is constructed. The target user, as a special administrator account, can perform SSH login and is restricted to perform relevant operations only through the bastion host console. Through the primary maintenance with low-privilege operations, the risk of direct exposure of high-risk instructions is eliminated. Only when it is necessary to log in to the bastion host background, that is, when secondary-level maintenance is required, permissions will be granted through secondary login. The commands input by the user are relayed to the bastion host terminal through the bastion host console, avoiding direct exposure of the bastion host terminal interface and enabling timely permission revocation. This is different from the existing technology where the bastion host background password or public-private key cannot be modified in a timely manner.
[0065] In addition, the following settings can also be made: The user who approves the secondary-level maintenance permissions does not have the permission to apply to enter the bastion host background, which can prevent the bastion host background from being breached due to personnel leaving the company or a single person's machine being compromised.
[0066] Embodiment 2
[0067] This embodiment further optimizes on the basis of the above Embodiment 1. In this embodiment, the method for configuring the target user includes:
[0068] Disable the sftp server, root login, and password login; only open the target user to obtain root permissions; set the target user to directly enter the bastion host console after logging in.
[0069] Further, the method for configuring the target user includes:
[0070] Modify the configuration file to disable root login, password login, and only open the target user to obtain root permissions.
[0071] Specifically, by modifying the / etc / passwd file, it is possible to set the target user to directly enter the bastion host console after logging in; by modifying the SSH configuration file / etc / ssh / sshd_config, root login and password login can be disabled; by modifying / etc / sudoers, other users can be disabled from obtaining root privileges, and only the previously created target user can obtain root privileges.
[0072] By adopting the above implementation method, by modifying the configuration file, it is possible to more conveniently separate the permissions of the bastion host; disabling the sftp server can limit the file transfer ability through the SSH protocol, reducing the attack surface of the bastion host system, centralizing the control of permissions, and further improving security; by disabling root login, the attack surface of the system can be reduced, and attackers cannot directly initiate brute-force cracking or vulnerability exploitation against the default privileged account (root); by disabling password login, it is possible to enforce the use of SSH key authentication, avoiding risks such as weak passwords, credential stuffing attacks, or man-in-the-middle eavesdropping.
[0073] In this embodiment, the method of using the target user and the corresponding public and private keys to log in to the bastion host through SSH and directly enter the bastion host console includes:
[0074] When the bastion host recognizes that the maintenance personnel log in to the target user through SSH using the public and private keys, the bastion host console service is started;
[0075] The bastion host console displays a challenge code login interface on the console service login interface and generates a first challenge code;
[0076] The response code generation module receives the first challenge code input by the maintenance personnel and generates a first response code;
[0077] The bastion host console receives the first response code input by the maintenance personnel and starts the console service management interface after the first response code is verified and passed.
[0078] By adopting this implementation method, it is possible to improve usability while ensuring security.
[0079] Further, after starting the bastion host console service, the concurrent number of the bastion host console at the same time is restricted, so that all maintenance personnel can only establish a fixed number of SSH connections with the bastion host at the same time.
[0080] By adopting this implementation method, the probability of the bastion host console being brute-force cracked can be minimized.
[0081] Further, the method for the bastion host console to generate the first challenge code includes:
[0082] Randomly generate an original string, then use the SM2 algorithm to encrypt it and store the public key of the SM2 algorithm. Use the encrypted original string as the first challenge code.
[0083] Furthermore, the response code generation module is independent of the bastion host. The method for the response code generation module to generate the first response code includes:
[0084] Use the SM2 algorithm to decrypt the first challenge code, obtain the original string and combine it with a preset salt value. Calculate the hash value of the combined result through the SM3 hashing algorithm, and intercept a specified part of the hash value as the first response code.
[0085] Adopting this embodiment makes the response code generation module completely independent of the bastion host system and has an independent user permission system. The permissions of maintenance personnel for daily maintenance of the bastion host system and the root permission to enter the bastion host background can be separated, and the permissions can be eliminated in a timely manner;
[0086] By using the national cryptography algorithms SM2 and SM3 to design the challenge code-response code system, the probability of brute-forcing the bastion host background by others is further reduced;
[0087] For the convenience of personnel input, the first response code can be set to about 10 digits, and the first 10 digits of the hash value are intercepted correspondingly as the first response code.
[0088] Furthermore, the method for the target user to trigger secondary login on the bastion host console includes:
[0089] When the bastion host console recognizes a specified command input by the maintenance personnel, it jumps to the secondary login interface;
[0090] The bastion host console displays the challenge code login interface on the secondary login interface and generates a second challenge code;
[0091] The response code generation module receives the second challenge code input by the maintenance personnel and generates a second response code;
[0092] The bastion host console receives the second response code input by the maintenance personnel and, after the second response code is verified and passed, redirects the input to the bastion host terminal.
[0093] Specifically, the specified command input by the maintenance personnel can be in the form of an easter egg command, which is invisible when input in the menu of the service management interface of the bastion host console. By inputting the easter egg command, as long as a certain segment of the input matches the easter egg, it will be triggered, and then the bastion host console will directly jump to the secondary login interface; the generation logic of the second response code is the same as that of the first response code, but the keys and salt values are different.
[0094] Optionally, when the challenge code is displayed on the console service login interface, in addition to displaying the challenge code in string form, a QR code is also shown as a picture.
[0095] Since the challenge code may be relatively long as a whole, the response code generation system and the bastion host background service may need to transfer data. When it is not possible to directly copy the challenge code, one can choose to take a photo and use the QR code.
[0096] Optionally, limit the input time and the number of input attempts for the challenge code.
[0097] For example, the input window for the challenge code (including the first challenge code and the second challenge code) is only 5 minutes, and each incorrect input will directly generate a new challenge code. If there are 3 incorrect inputs, the SSH connection will be directly disconnected.
[0098] In a specific implementation manner, by modifying the configuration file, it is possible to disable root login, password login, only allow target users to obtain root privileges, and directly enter the bastion host console after the target user logs in, and after disabling the sftp server, see Figure 3 The method for implementing the first-level maintenance and the second-level maintenance includes the following steps:
[0099] Step S201: The bastion host console receives a request from the maintenance personnel to log in to the target user via public-private key SSH.
[0100] Step S202: The bastion host console displays the challenge code login interface on the console service login interface and generates the first challenge code.
[0101] Step S203: The response code generation module receives the first challenge code input by the maintenance personnel and generates the first response code.
[0102] Step S204: Verify the first response code. Specifically, the bastion host console receives the first response code from the maintenance personnel. When the first response code is verified to be passed, the bastion host console service management interface is displayed to the maintenance personnel. When the first response code is verified to be failed, the SSH connection is disconnected.
[0103] Step S205: Perform the first-level maintenance. Specifically, the bastion host console implements the first-level maintenance according to the first-level maintenance command selected by the maintenance personnel in the bastion host console service management interface.
[0104] Step S206: The bastion host console receives the easter egg command from the maintenance personnel.
[0105] Step S207: The bastion host console displays the challenge code login interface to the maintenance personnel and generates the second challenge code.
[0106] Step S208: The response code generation module receives the second challenge code input by the maintenance personnel and generates a second response code;
[0107] Step S209: Verify the second response code and perform the second-level maintenance. Specifically, the bastion host console receives the second response code from the maintenance personnel. When the second response code is verified successfully, the input is redirected to the bastion host terminal. When the second response code is verified failed, the SSH connection is disconnected.
[0108] Embodiment 3:
[0109] See Figure 4 , a system for enhancing the security of a bastion host, including a bastion host console, which is used to create a target user and the corresponding public and private keys and configure the permissions of the target user and other users, so that only the target user and the public and private keys can be used to log in to the bastion host through SSH and directly enter the bastion host console. By selecting and using the preset first-level maintenance commands in the bastion host console, the first-level maintenance is realized;
[0110] After the target user triggers a secondary login in the bastion host console and logs in successfully, the maintenance command is input in the bastion host console, and the maintenance command is redirected to the bastion host terminal to realize the second-level maintenance.
[0111] Embodiment 4
[0112] A computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method for enhancing the security of a bastion host according to any one of Embodiments 1 to 2.
[0113] The above are only the preferred embodiments of the present invention, and do not impose any form of limitation on the present invention. Any simple modification or equivalent change made to the above embodiments based on the technical essence of the present invention falls within the protection scope of the present invention.
Claims
1. A method for enhancing the security of a bastion host, characterized in that, Including the following steps: Step S1: Receive a request from a maintenance personnel to log in to the bastion host through a target user with a unique SSH login privilege and the corresponding public-private key pair. Here, the maintenance personnel are the maintenance personnel of the bastion host system, and the bastion host system is a comprehensive operation and maintenance management platform integrating system operation and maintenance and security auditing; Step S2: Conduct the first security verification. When the first security verification passes, allow the target user to directly log in to the bastion host console, so that the maintenance personnel can implement the first-level maintenance by selecting and using the preset first-level maintenance commands in the bastion host console. When the first security verification fails, disconnect the SSH connection. Here, the bastion host console is a service installed on the bastion host for hosting the bastion host terminal, and the first-level maintenance commands are the preset low-privilege maintenance operations of the bastion host system; Step S3: Receive a request from the maintenance personnel to log in to the bastion host background. Here, the request to log in to the bastion host background is an easter egg command that is invisible when input in the bastion host console; Step S4: Conduct the second security verification. When the second security verification passes, redirect the maintenance commands input by the maintenance personnel to the bastion host terminal to implement the second-level maintenance. When the second security verification fails, disconnect the SSH connection. Here, the maintenance commands corresponding to the second-level maintenance are the high-privilege maintenance operations of the bastion host system for entering the bastion host background and inputting commands using the command-line interface. The user who approves the second-level maintenance privilege does not have the privilege to apply to enter the bastion host background, and the bastion host terminal is the bash of the bastion host system.
2. The method for enhancing the security of the bastion host according to claim 1, wherein, The method for configuring the target user includes: Disable the sftp server, root login, and password login; only open the target user to obtain root privileges; set the target user to directly enter the bastion host console after logging in.
3. The method for enhancing the security of the bastion host according to claim 2, wherein The method for configuring the target user includes: Modify the configuration file to disable root login, password login, and only open the target user to obtain root privileges.
4. The method for enhancing the security of the bastion host according to claim 1, wherein The method for conducting the first security verification includes: When the bastion host recognizes that the maintenance personnel log in to the target user through the public-private key using SSH, start the bastion host console service; The bastion host console displays a challenge code login interface and generates a first challenge code on the console service login interface; the response code generation module receives the first challenge code input by the maintenance personnel and generates a first response code; The bastion host console receives the first response code input by the maintenance personnel and starts the console service management interface after the first response code is verified.
5. The method for enhancing the security of the bastion host according to claim 4, characterized in that: After starting the bastion host console service, limit the concurrent number of the bastion host console at the same time, so that all maintenance personnel can only establish a fixed number of SSH connections with the bastion host at the same time.
6. The method for enhancing the security of the bastion host according to claim 4, wherein The method for the bastion host console to generate the first challenge code includes: Randomly generate a string of original strings, then encrypt them using the sm2 algorithm and store the public key of the sm2 algorithm, and use the encrypted original string as the first challenge code.
7. The method for enhancing the security of the bastion host according to claim 6, wherein, The response code generation module is independent of the bastion host. The method for the response code generation module to generate the first response code includes: Decrypt the first challenge code using the SM2 algorithm to obtain the original string and combine it with the preset salt value. Calculate the hash value of the combined string using the SM3 hashing algorithm, and intercept the specified part of the hash value as the first response code.
8. The method for enhancing the security of the bastion host according to claim 6, wherein The method for triggering secondary login by the target user on the bastion host console includes: When the bastion host console recognizes the specified command entered by the maintenance personnel, it jumps to the secondary login interface; the bastion host console displays the challenge code login interface on the secondary login interface and generates a second challenge code; The response code generation module receives the second challenge code entered by the maintenance personnel and generates a second response code; The bastion host console receives the second response code entered by the maintenance personnel and, after the second response code is verified and passed, redirects the input to the bastion host terminal.
9. A system for enhancing the security of a bastion host, characterized in that, Including: The first login module is used to receive the request from the maintenance personnel to log in to the bastion host through the target user with unique SSH login permissions and the corresponding public and private keys. Here, the maintenance personnel are the maintenance personnel of the bastion host system, and the bastion host system is a comprehensive operation and maintenance management platform integrating system operation and maintenance and security auditing; The first verification module is used to perform the first security verification. When the first security verification is passed, the target user is directly logged in to the bastion host console, enabling the maintenance personnel to implement the first-level maintenance by selecting the preset first-level maintenance commands in the bastion host console. When the first security verification fails, the SSH connection is disconnected. Here, the bastion host console is a service installed on the bastion host for hosting the bastion host terminal, and the first-level maintenance command is a preset low-privilege maintenance operation of the bastion host system; The second login module is used to receive the request from the maintenance personnel to log in to the bastion host background. Here, the request to log in to the bastion host background is an easter egg command that is invisible when entered in the bastion host console; The second verification module is used to perform the second security verification. When the second security verification is passed, the maintenance command entered by the maintenance personnel is redirected to the bastion host terminal to implement the second-level maintenance. When the second security verification fails, the SSH connection is disconnected. Here, the maintenance command corresponding to the second-level maintenance is a high-privilege maintenance operation of the bastion host system for entering the bastion host background and using the command line interface to enter commands. The user who approves the second-level maintenance privilege does not have the privilege to apply to enter the bastion host background, and the bastion host terminal is the bash of the bastion host system.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method for enhancing the security of the bastion host described in any one of claims 1-8.
Citation Information
Patent Citations
Remote control method and device for bastion host resources, storage medium and terminal equipment
CN113079164A