Access control method and device based on log process exception handling

By generating a key and creating a temporary account to handle log process exceptions, the permission issues and information security risks during log process exception handling in the existing technology are solved, and safe and effective exception handling is achieved.

CN119918074APending Publication Date: 2025-05-02SINOPEC SHARED SERVICES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411984541.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

In the prior art, when logging process is abnormal, professionals need to log in to the system for maintenance, but if an account with lower permissions is provided, it cannot be effectively processed. If an account with higher permissions is provided, there is an information security risk.

Method used

By detecting log process exceptions, a pre-stored random seed, at least two sets of password groups and a set of decode groups are used to generate a temporary account for logging in to the system for exception handling.

Benefits of technology

It realizes that while ensuring information security, temporary accounts are provided to handle log process exceptions, avoiding the problem of being unable to be processed when there is low permissions, and reducing the risk of leaking accounts with high permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119918074A_ABST
    Figure CN119918074A_ABST
Patent Text Reader

Abstract

The invention provides an access control method and device based on log process exception handling, and relates to the technical field of information security. The method comprises the following steps: if detecting that a log process is abnormal, generating a key by utilizing at least two password groups and a decoding group according to a pre-stored random seed; wherein the lengths of any two password groups are not equal, and elements in the password groups are integers; and generating a temporary account according to the key, so that a user of the temporary account logs in a related system through the temporary account to perform log process exception processing. The device executes the method. According to the method and the device provided by the embodiment of the invention, the secret key is generated in a mode of combining the password group and the decoding group, so that the temporary account has relatively high security, and the log process exception handling personnel can be safely and effectively controlled to log in a related system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security, and in particular to an access control method and device based on log process exception handling. Background Art

[0002] With the development of enterprise informatization, there are a lot of system operation and maintenance work, among which a lot of system operation and maintenance work needs to be analyzed according to the log process. Usually when the log process is abnormal, professional personnel are required to perform maintenance and processing. Before professional personnel perform maintenance and processing, they need to log in to the relevant system first. However, if a low-authority account is provided to the staff, a lot of data cannot be operated or even viewed. If a high-authority account is provided, once the account is leaked, it will bring serious risks to the enterprise information security. Summary of the invention

[0003] In view of the problems in the prior art, an embodiment of the present invention provides an access control method and device based on log process exception handling, which can at least partially solve the problems in the prior art.

[0004] On the one hand, the present invention proposes an access control method based on log process exception handling, comprising:

[0005] If an abnormality is detected in the log process, a key is generated based on a pre-stored random seed and using at least two cipher groups and one decryption group;

[0006] Among them, the lengths of any two password groups are different, and the elements in the password group are integers;

[0007] A temporary account is generated according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

[0008] The method of generating a key based on a pre-stored random seed and using at least two cipher groups and one decoding group includes:

[0009] Generate a random number according to the random seed, and generate an integer random array according to the random number; the number of elements in the integer random array is equal to the random number, and each element is a random integer;

[0010] Traversing each element in the integer random array in turn, and extracting the integer value corresponding to each password group according to the corresponding position of each element value in each password group;

[0011] An intermediate value is calculated based on the integer value corresponding to each cipher group, a decoding value is extracted from a corresponding position in the decoding group based on the intermediate value, and the key is obtained based on the decoding value composition corresponding to each element in each traversal.

[0012] The step of calculating the intermediate value according to the integer value corresponding to each password group includes:

[0013] The integer values ​​corresponding to each password group are multiplied respectively to obtain the intermediate value.

[0014] The step of obtaining the key according to the decoded numerical values ​​corresponding to each element in each traversal includes:

[0015] The decoded values ​​corresponding to each element are combined in sequence according to the traversal order to obtain the key.

[0016] The access control method based on log process exception handling also includes:

[0017] If it is determined that the target element value exceeds the length of the target cipher group, a modulo calculation is performed on the target element value and the length of the target cipher group, and the modulo calculation result is used as the corresponding position of the target element value in the target cipher group to extract the integer value corresponding to the target cipher group.

[0018] The access control method based on log process exception handling also includes:

[0019] If it is determined that the target intermediate value exceeds the length of the set of decoding groups, the target intermediate value is converted using the length of the set of decoding groups as a base number, and the converted target intermediate value is determined as the decoding value.

[0020] The access control method based on log process exception handling also includes:

[0021] Use server IP, program name and process number as keys to divide the log process;

[0022] If it is determined that the comparison result between the current log process data and the corresponding historical log process data is greater than a preset difference, it is determined that an abnormality occurs in the log process.

[0023] On the one hand, the present invention provides an access control device based on log process exception handling, comprising:

[0024] A first generating unit is used to generate a key according to a pre-stored random seed and using at least two cipher groups and one decoding group if an abnormality is detected in the log process;

[0025] Among them, the lengths of any two password groups are different, and the elements in the password group are integers;

[0026] The second generating unit is used to generate a temporary account according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

[0027] In another aspect, an embodiment of the present invention provides an electronic device, including: a processor, a memory, and a bus, wherein:

[0028] The processor and the memory communicate with each other via the bus;

[0029] The memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the following method:

[0030] If an abnormality is detected in the log process, a key is generated based on a pre-stored random seed and using at least two cipher groups and one decryption group;

[0031] Among them, the lengths of any two password groups are different, and the elements in the password group are integers;

[0032] A temporary account is generated according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

[0033] An embodiment of the present invention provides a non-transitory computer-readable storage medium, including:

[0034] The non-transitory computer-readable storage medium stores computer instructions, which cause the computer to execute the following method:

[0035] If an abnormality is detected in the log process, a key is generated based on a pre-stored random seed and using at least two cipher groups and one decryption group;

[0036] Among them, the lengths of any two password groups are different, and the elements in the password group are integers;

[0037] A temporary account is generated according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

[0038] The access control method and device based on log process exception handling provided by the embodiment of the present invention, if an abnormality is detected in the log process, a key is generated according to a pre-stored random seed and using at least two password groups and one decoding group; wherein the lengths of any two password groups are not equal to each other, and the elements in the password group are all integers; a temporary account is generated according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception handling, and the key is generated by combining the password group and the decoding group, so that the temporary account has a higher security, thereby realizing safe and effective control of the log process exception handling personnel logging into the relevant system. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0040] Figure 1 The present invention is a flowchart of an access control method based on log process exception handling provided by an embodiment of the present invention.

[0041] Figure 2 It is a schematic diagram illustrating the key generation process provided by an embodiment of the present invention.

[0042] Figure 3 It is a structural diagram of an access control device based on log process exception handling provided by an embodiment of the present invention.

[0043] Figure 4 A schematic diagram of the physical structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0044] In order to make the purpose, technical scheme and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below in conjunction with the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention. It should be noted that, in the absence of conflict, the embodiments in this application and the features in the embodiments can be combined with each other arbitrarily.

[0045] Figure 1 FIG. 1 is a flow chart of an access control method based on log process exception handling provided by an embodiment of the present invention. Figure 1 As shown, the access control method based on log process exception handling provided by the embodiment of the present invention includes:

[0046] Step S1: If an abnormality is detected in the log process, a key is generated based on a pre-stored random seed and using at least two cipher groups and one decoding group;

[0047] The lengths of any two password groups are different, and the elements in the password groups are all integers.

[0048] Step S2: Generate a temporary account according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

[0049] In the above step S1, if the device detects that the log process is abnormal, it generates a key based on a pre-stored random seed and using at least two cipher groups and one decoding group;

[0050] The lengths of any two cipher groups are not equal, and the elements in the cipher groups are integers. The device may be a computer device that executes the method, wherein the method generates a key based on a pre-stored random seed and using at least two cipher groups and one decoding group, including:

[0051] Generate a random number according to the random seed, and generate an integer random array according to the random number; the number of elements in the integer random array is equal to the random number, and each element is a random integer;

[0052] Traversing each element in the integer random array in turn, and extracting the integer value corresponding to each password group according to the corresponding position of each element value in each password group;

[0053] An intermediate value is calculated based on the integer value corresponding to each cipher group, a decoding value is extracted from a corresponding position in the decoding group based on the intermediate value, and the key is obtained based on the decoding value composition corresponding to each element in each traversal.

[0054] The intermediate value is calculated according to the integer value corresponding to each password group, including:

[0055] The integer values ​​corresponding to each password group are multiplied respectively to obtain the intermediate value.

[0056] The key is obtained according to the decoded value composition corresponding to each element in each traversal, including:

[0057] The decoded values ​​corresponding to each element are combined in sequence according to the traversal order to obtain the key.

[0058] The access control method based on log process exception handling also includes:

[0059] If it is determined that the target element value exceeds the length of the target cipher group, a modulo calculation is performed on the target element value and the length of the target cipher group, and the modulo calculation result is used as the corresponding position of the target element value in the target cipher group to extract the integer value corresponding to the target cipher group.

[0060] The access control method based on log process exception handling also includes:

[0061] If it is determined that the target intermediate value exceeds the length of the set of decoding groups, the target intermediate value is converted using the length of the set of decoding groups as a base number, and the converted target intermediate value is determined as the decoding value.

[0062] The instructions are as follows:

[0063] In Python, you can use the randint function in the random library with a codebook to generate a key. For a codebook, three groups of data are prepared in advance. The first group is the codegroup A, the second group is the codegroup B, and the third group is the decoding group P. The codegroups A and B should be two arrays of unequal lengths, which can include integers. The decoding group P is a collection of any length and unlimited content. The three groups of data that make up the codebook can be manually maintained and updated regularly by three different people. Among them:

[0064] Cipher group A = [3, 6, 9, 54, 12, 44];

[0065] Cipher group B = [21, 23, 22, 11, 5, 2, 27, 4, 7, 18];

[0066] Decoding group A = [9, 8, 7, 6, 5, 4, 3, 2, 1, 0].

[0067] After adding the random seed in the database to random, use the randint function to generate a random number. The value of this random number should not be too large or too small, and can be between 5 and 50 (the range of random numbers can be limited by parameters without affecting the simultaneous use with the random seed). For example, if the random seed is 373, one or two digits can be randomly selected as the random number, such as selecting the random number 7.

[0068] Then, based on the obtained random number 7, generate an integer random array R with the same number of elements as the generated random number, R = [7, 3, 54, 22, 47, 17, 21].

[0069] Then, in cipher groups A and B, respectively, the numbers corresponding to the values ​​of each element in the generated integer random array are taken out. If this value exceeds the length of cipher group A or B, then the calculation is restarted from the first bit of cipher group A or B. For example, if the length of group A is 6 and the length of group B is 10, when taking the 7th digit, since the length of A is less than 7, the traversal is repeated from the first digit of A, and the 1st digit of group A should be taken. If the length of B is greater than 7, then group B directly takes 7 digits. For example, if R[1]=7, then A[7]=A[1]=3, B[7]=27, and then the two digits are multiplied in pairs, and then the corresponding cipher value in the decoding group is obtained according to the value of this digit, that is, P[3×27]=P

[81] . 81 exceeds the length of R. The length of R is used as the base, and 81 is converted to decimal, that is, the 8th element of the decoding group is 2, and the 1st element of the decoding group is 9, so P

[81] =29 is obtained, which is used as the first part of the key.

[0070] If the integer values ​​corresponding to each cipher suite are multiplied together and the resulting intermediate value is 6, then P[6]=4 is used as the first part of the key.

[0071] If the value of this number exceeds the length of the decoding group, the length of the decoding group is used as a new base to obtain it. For example, if there are only 10 numbers 0-9 in the decoding group, and the order is in descending order, it is in decimal. If the decoding group is a random character set of 15 characters composed of letters, numbers, and special characters, it is in fifteenth base. For the sake of ease of understanding, the array arranged in descending order from 0 to 9 is used as the decoding group as an example. One of the values ​​obtained from the two groups of numbers A and B is 81. Then, according to the order of the decoding group, the eighth number 2 and the first number 9 are obtained, which constitute the first part of the key "29". If the decoding group contains 26 English letters arranged in sequence, the key is in hexadecimal. 81 is converted to hexadecimal as 33, and the corresponding order of the 26 English letters is the third letter "C" and the third letter "C", which constitutes the first part of the key as "CC".

[0072] like Figure 2 As shown, by analogy, all the keys can be obtained, namely 2991262698689922651921.

[0073] In order to further ensure the security of the key, the random seed can be dynamically maintained as follows:

[0074] When using the key to log in, a key is generated on-site according to the time and refresh times for comparison and verification. After the verification is successful, the corresponding random seed will be directly destroyed, that is, the random seed value of this data in the database is set to empty.

[0075] If no one uses it, the random seed will be refreshed at a fixed natural time, such as every 20 minutes from 0:00:00 to 23:59:59 every day. The refresh time should be manually modifiable, and the old random seed should be destroyed after the refresh even if no one uses it. If someone uses it, it will be refreshed immediately, and it should be refreshed again after the next natural refresh time. The main purpose of this strategy is to prevent the system from being exposed to external malicious attacks. When it is invaded, even if the database is invaded, the key generation mechanism needs to be cracked to log in to the administrator account. Otherwise, if the key generation mechanism is not clear, even if the random seed information in the database is obtained, the key content cannot be known.

[0076] A field can be added to the database to indicate whether this key is enabled. The default state is disabled and it is enabled when the administrator applies to the system. Only when the state is enabled and the verification result is correct can this key be used to log in. If it is not used within 5 minutes after being enabled, the random seed of the key will be refreshed directly and the random seed that is enabled but not verified will be destroyed.

[0077] In the above step S2, the device generates a temporary account according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to handle the log process exception. The temporary account can be a temporary administrator account with the highest authority. The temporary account can be generated by sequentially adjusting the values ​​in the key, etc., without specific limitation.

[0078] Obtain a temporary key and send it to the user. This key can be entered in the human-machine interface to generate a new temporary account. After logging in, the temporary account can fill in basic information such as the operator, work number, contact information, etc. before continuing to operate, in order to facilitate log recording.

[0079] There are three possible conditions for the end of the temporary account life cycle, which are described as follows:

[0080] The first one is that the user completes the work requirements and is automatically logged out when logging out. If there are any mistakes in the work, they need to apply for the key again from the administrator.

[0081] The second is that the administrator actively ends the life cycle of this account. The administrator can use the administrator account to directly log out of this account. At this time, all operations of the account will be suspended and displayed to the administrator. At this time, the administrator will choose whether to close the ongoing work process or continue it.

[0082] The third is login timeout, which is a protection measure for accounts to prevent users and administrators from forgetting to log out, and to prevent the work from being too cumbersome and causing login timeout before the user completes the work. The timeout period should be set and modified by the administrator. After the timeout causes the login to become invalid, all the user's unfinished automated operations will continue to be executed in the background. And when using the key to log in, you should log in on the key login interface. This interface does not require the account password to be entered, only the key is required, and you can log in directly after entering it. A single key can only be used once, and it will become invalid after use, and the key will be refreshed, which further increases the security of the system. Another advantage of this method is that it allows multiple users to log in to the administrator account at the same time to complete their work.

[0083] The access control method based on log process exception handling also includes:

[0084] Use server IP, program name and process number as keys to divide the log process;

[0085] If it is determined that the comparison result between the current log process data and the corresponding historical log process data is greater than the preset difference, then it is determined that the log process is abnormal. The historical log process data can be selected as the log process data within the last three months. There are many types of log process data. You can perform a numerical comparison on the log process data of numerical type. For example, compare the current log process data value with the average value of the log process data within the last three months. If the comparison result is greater than the preset difference, it means that the current log process data does not match the historical log process data, and it can be determined that the log process is abnormal. The preset difference can be set independently according to the actual situation.

[0086] The access control method based on log process exception handling provided by the embodiment of the present invention, if an abnormality is detected in the log process, generates a key according to a pre-stored random seed and using at least two password groups and one decoding group; wherein the lengths of any two password groups are not equal to each other, and the elements in the password group are all integers; generates a temporary account according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception handling, and generates a key by combining the password group and the decoding group, so that the temporary account has a higher security, thereby realizing safe and effective control of the log process exception handling personnel logging into the relevant system.

[0087] Further, the generating of the key according to the pre-stored random seed and using at least two cipher groups and one decoding group includes:

[0088] A random number is generated according to the random seed, and an integer random array is generated according to the random number; the number of elements of the integer random array is equal to the random number, and each element is a random integer; the above-mentioned embodiment can be referred to for description and will not be repeated here.

[0089] Each element in the integer random array is traversed in turn, and the integer value corresponding to each password group is extracted according to the corresponding position of each element value in each password group; the above embodiment can be referred to for description and will not be repeated here.

[0090] The intermediate value is calculated according to the integer value corresponding to each password group, the decoding value is extracted at the corresponding position in the decoding group according to the intermediate value, and the key is obtained according to the decoding value composition corresponding to each element in each traversal. The above embodiment can be referred to for explanation and will not be repeated here.

[0091] Further, the calculating of the intermediate value according to the integer value corresponding to each password group includes:

[0092] The integer values ​​corresponding to each password group are multiplied to obtain the intermediate value. Please refer to the above embodiment for explanation, which will not be repeated here.

[0093] Furthermore, the key is obtained according to the decoded numerical values ​​corresponding to each element in each traversal, including:

[0094] The decoded values ​​corresponding to each element are combined in sequence according to the traversal order to obtain the key. The above description can be referred to in the above embodiment and will not be repeated here.

[0095] Furthermore, the access control method based on log process exception handling also includes:

[0096] If it is determined that the target element value exceeds the length of the target cipher group, a modulo calculation is performed on the target element value and the length of the target cipher group, and the modulo calculation result is used as the corresponding position of the target element value in the target cipher group to extract the integer value corresponding to the target cipher group. The above embodiment can be referred to for explanation and will not be repeated here.

[0097] Furthermore, the access control method based on log process exception handling also includes:

[0098] If it is determined that the target intermediate value exceeds the length of the set of decoding groups, the target intermediate value is converted using the length of the set of decoding groups as a base number, and the converted target intermediate value is determined as the decoding value. The above embodiment can be referred to for explanation and will not be repeated here.

[0099] Furthermore, the access control method based on log process exception handling also includes:

[0100] The server IP, program name and process number are used as keys to divide the log process; the above-mentioned embodiment can be referred to for description and will not be described in detail.

[0101] If it is determined that the comparison result between the current log process data and the corresponding historical log process data is greater than the preset difference, it is determined that the log process is abnormal.

[0102] Figure 3 is a schematic diagram of the structure of an access control device based on log process exception handling provided by an embodiment of the present invention. Figure 3 As shown, the access control device based on log process exception handling provided by the embodiment of the present invention includes a first generating unit 301 and a second generating unit 302, wherein:

[0103] The first generation unit 301 is used to generate a key based on a pre-stored random seed and using at least two cipher groups and one decoding group if an abnormality is detected in the log process; wherein the lengths of any two cipher groups are different and the elements in the cipher groups are all integers; the second generation unit 302 is used to generate a temporary account based on the key, so that the user of the temporary account can log in to the relevant system through the temporary account to handle the log process abnormality.

[0104] Specifically, the first generating unit 301 in the device is used to generate a key based on a pre-stored random seed and using at least two cipher groups and one decoding group if an abnormality is detected in the log process; wherein the lengths of any two cipher groups are not equal to each other, and the elements in the cipher groups are all integers; the second generating unit 302 is used to generate a temporary account based on the key, so that the user of the temporary account can log in to the relevant system through the temporary account to handle the log process abnormality.

[0105] The access control device based on log process exception handling provided by the embodiment of the present invention, if an abnormality is detected in the log process, generates a key based on a pre-stored random seed and using at least two password groups and one decoding group; wherein the lengths of any two password groups are not equal to each other, and the elements in the password groups are all integers; generates a temporary account based on the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception handling, and generates a key by combining the password group and the decoding group, so that the temporary account has a higher security, thereby realizing safe and effective control of the log process exception handling personnel logging into the relevant system.

[0106] The embodiment of the present invention provides an access control device based on log process exception handling, which can be specifically used to execute the processing flow of the above-mentioned method embodiments. Its functions are not repeated here, and reference can be made to the detailed description of the above-mentioned method embodiments.

[0107] Figure 4 A schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention, such as Figure 4As shown, the electronic device includes: a processor (processor) 401, a memory (memory) 402 and a bus 403;

[0108] The processor 401 and the memory 402 communicate with each other via a bus 403;

[0109] The processor 401 is used to call the program instructions in the memory 402 to execute the methods provided by the above method embodiments, for example, including:

[0110] If an abnormality is detected in the log process, a key is generated based on a pre-stored random seed and using at least two cipher groups and one decryption group;

[0111] Among them, the lengths of any two password groups are different, and the elements in the password group are integers;

[0112] A temporary account is generated according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

[0113] This embodiment discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can perform the methods provided by the above method embodiments, for example, including:

[0114] If an abnormality is detected in the log process, a key is generated based on a pre-stored random seed and using at least two cipher groups and one decryption group;

[0115] Among them, the lengths of any two password groups are different, and the elements in the password group are integers;

[0116] A temporary account is generated according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

[0117] This embodiment provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program enables the computer to execute the methods provided by the above method embodiments, for example, including:

[0118] If an abnormality is detected in the log process, a key is generated based on a pre-stored random seed and using at least two cipher groups and one decryption group;

[0119] Among them, the lengths of any two password groups are different, and the elements in the password group are integers;

[0120] A temporary account is generated according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

[0121] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0122] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0123] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0124] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0125] In the description of this specification, the description with reference to the terms "one embodiment", "a specific embodiment", "some embodiments", "for example", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0126] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. An access control method based on log process exception handling, characterized in that: include: If an abnormality is detected in the log process, a key is generated based on a pre-stored random seed and using at least two cipher groups and one decryption group; Among them, the lengths of any two password groups are different, and the elements in the password group are integers; A temporary account is generated according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

2. The access control method based on log process exception handling according to claim 1 is characterized in that: The method of generating a key based on a pre-stored random seed and using at least two cipher groups and one decoding group comprises: Generate a random number according to the random seed, and generate an integer random array according to the random number; the number of elements in the integer random array is equal to the random number, and each element is a random integer; Traversing each element in the integer random array in turn, and extracting the integer value corresponding to each password group according to the corresponding position of each element value in each password group; An intermediate value is calculated based on the integer value corresponding to each cipher group, a decoding value is extracted from a corresponding position in the decoding group based on the intermediate value, and the key is obtained based on the decoding value composition corresponding to each element in each traversal.

3. The access control method based on log process exception handling according to claim 2 is characterized in that: The intermediate value is calculated according to the integer value corresponding to each password group, including: The integer values ​​corresponding to each password group are multiplied respectively to obtain the intermediate value.

4. The access control method based on log process exception handling according to claim 2 is characterized in that: The key is obtained according to the decoded value composition corresponding to each element in each traversal, including: The decoded values ​​corresponding to each element are combined in sequence according to the traversal order to obtain the key.

5. The access control method based on log process exception handling according to claim 2 is characterized in that: The access control method based on log process exception handling also includes: If it is determined that the target element value exceeds the length of the target cipher group, a modulo calculation is performed on the target element value and the length of the target cipher group, and the modulo calculation result is used as the corresponding position of the target element value in the target cipher group to extract the integer value corresponding to the target cipher group.

6. The access control method based on log process exception handling according to claim 2 is characterized in that: The access control method based on log process exception handling also includes: If it is determined that the target intermediate value exceeds the length of the set of decoding groups, the target intermediate value is converted using the length of the set of decoding groups as a base number, and the converted target intermediate value is determined as the decoding value.

7. The access control method based on log process exception handling according to claim 1 is characterized in that: The access control method based on log process exception handling also includes: Use server IP, program name and process number as keys to divide the log process; If it is determined that the comparison result between the current log process data and the corresponding historical log process data is greater than a preset difference, it is determined that an abnormality occurs in the log process.

8. An access control device based on log process exception handling, characterized in that: include: A first generating unit is used to generate a key according to a pre-stored random seed and using at least two cipher groups and one decoding group if an abnormality is detected in the log process; Among them, the lengths of any two password groups are different, and the elements in the password group are integers; The second generating unit is used to generate a temporary account according to the key, so that the user of the temporary account can log in to the relevant system through the temporary account to perform log process exception processing.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.