Instruction execution method and device, electronic equipment and storage medium
By judging user permissions in the server management system and performing target verification operations, the security problems caused by misoperation in server management are solved, and higher security and anti-error operation effects are achieved.
Patent Information
- Application Number
- CN202510127799.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-27
- Publication Date
- 2025-05-06
AI Technical Summary
In server management, due to user negligence or misoperation, it may cause illegal contact with important operations such as shutdown and restart, resulting in low security of server management.
By responding to the operation instructions sent by the user, it is determined whether the user has operation permissions for the operation instructions. If so, execute the target verification operation to perform secondary verification to determine whether the operation instructions are executed.
Effectively prevent misoperation and improve the security of server management.
Smart Images

Figure CN119938142A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of server management, and in particular to an instruction execution method, device, electronic device and storage medium. Background Art
[0002] In the field of server management, the server can be operated and managed through the server management software platform. The operation and maintenance management can include permission management, operation log recording, hardware monitoring, etc.
[0003] During operation and maintenance management, users may accidentally perform important operations such as shutdown and restart due to negligence or misoperation, causing errors such as shutting down the server and changing key configurations, resulting in low security of server management. Summary of the invention
[0004] The embodiments of the present application provide an instruction execution method, an apparatus, an electronic device, and a storage medium to at least solve the problem of low security of server management in the related art.
[0005] The present application provides an instruction execution method, comprising:
[0006] In response to the operation instruction sent by the user terminal, determine the user identifier corresponding to the user terminal and the target identifier corresponding to the operation instruction;
[0007] According to the user ID and the target ID, determine whether the user terminal has the operation authority of the operation instruction;
[0008] If so, determine the target verification operation based on the target identifier;
[0009] Execute the target verification operation and obtain the verification result, which is used to indicate whether to execute the operation instruction.
[0010] In a possible implementation, determining a target verification operation according to a target identifier includes:
[0011] Acquire instruction management data, the instruction management data including multiple instruction identifiers and current state information corresponding to each instruction identifier, the current state information including first state information or second state information;
[0012] Determine the current status information of the target identification according to the instruction management data;
[0013] Determine the target verification operation based on the current status information of the target identification.
[0014] In a possible implementation, when the current state information of the target identifier is the first state information, the first state information includes a tag type and tag information, determining the target verification operation according to the current state information of the target identifier includes:
[0015] According to the mark type, the current operation state of the operation instruction corresponding to the target mark is determined, and the current operation state is an operable state or an inoperable state;
[0016] When the current operation state is an operable state, generating first prompt information, the first prompt information including confirmation control information and marking information, the confirmation control information is used to generate a confirmation control on the user side, so that the user determines whether to execute the operation instruction;
[0017] When the current operation state is an inoperable state, generating second prompt information, the second prompt information including marking information;
[0018] The target verification operation includes: sending a first prompt message or a second prompt message to the user terminal.
[0019] In a possible implementation, performing a target verification operation to obtain a verification result includes:
[0020] Sending a first prompt message to the user terminal, receiving a response message sent by the user terminal, wherein the response message includes a confirmation instruction or a cancellation instruction, if the response message includes a confirmation instruction, determining that the verification result is an execution instruction, and if the response message includes a cancellation instruction, determining that the verification result is a non-execution instruction, wherein the confirmation instruction and the cancellation instruction are generated by the user terminal according to the user's operation on the confirmation control; or,
[0021] A second prompt message is sent to the user terminal, and according to the second prompt message, a verification result is determined as not executing the operation instruction.
[0022] In a possible implementation, when the current state information of the target identifier is the second state information, the second state information includes the user identifier, the user verification code, the approval user identifier and the approval verification code, and according to the current state information of the target identifier, determining the target verification operation includes:
[0023] Generate first request information according to the target identifier and the user identifier, where the first request information is used to request the user to enter a first verification code;
[0024] Generate second request information according to the target identifier and the approval user identifier, the second request information is used to request the approval user corresponding to the approval user identifier to enter a second verification code;
[0025] The target verification operation includes: sending first request information to the client, or sending first request information and second request information to the client.
[0026] In a possible implementation, performing a target verification operation to obtain a verification result includes:
[0027] Sending first request information to the user terminal;
[0028] Receiving a first response message sent by the user terminal, where the first response message includes a first verification code;
[0029] Determine whether the first verification code is the same as the user verification code;
[0030] If yes, send a second request message to the user terminal, receive a second response message sent by the user terminal, the second response message includes a second verification code, when the second verification code is the same as the approval verification code, determine the verification result is to execute the operation instruction, when the second verification code is different from the approval verification code, determine the verification result is not to execute the operation instruction;
[0031] If not, the verification result is determined to be not executing the operation instruction.
[0032] In a possible implementation, the method further includes:
[0033] In response to a permission modification instruction sent by the user terminal, user permission data is obtained, and the user permission data is updated according to the permission modification instruction, the permission modification instruction is used to modify the user's operation permission for each operation instruction, and the user permission data includes multiple user identifiers and multiple operation instruction identifiers corresponding to each user identifier; or,
[0034] In response to a state modification instruction sent by the user terminal, the instruction management data is acquired, and the instruction management data is updated according to the state modification instruction, where the state modification instruction is used to modify the current state information corresponding to the instruction identifier.
[0035] The present application also provides an instruction execution device, comprising:
[0036] A first determination module, configured to determine a user identifier corresponding to the user terminal and a target identifier corresponding to the operation instruction in response to the operation instruction sent by the user terminal;
[0037] A judgment module, used to judge whether the user terminal has the operation authority of the operation instruction according to the user identification and the target identification;
[0038] If yes, a second determination module is used to determine a target verification operation according to the target identifier;
[0039] The execution module is used to execute the target verification operation and obtain the verification result, and the verification result is used to indicate whether to execute the operation instruction.
[0040] In a possible implementation manner, the second determining module is specifically configured to:
[0041] Acquire instruction management data, the instruction management data including multiple instruction identifiers and current state information corresponding to each instruction identifier, the current state information including first state information or second state information;
[0042] Determine the current status information of the target identification according to the instruction management data;
[0043] Determine the target verification operation based on the current status information of the target identification.
[0044] In a possible implementation manner, when the current state information of the target identifier is the first state information, the first state information includes the tag type and the tag information, and the second determination module is specifically configured to:
[0045] According to the mark type, the current operation state of the operation instruction corresponding to the target mark is determined, and the current operation state is an operable state or an inoperable state;
[0046] When the current operation state is an operable state, generating first prompt information, the first prompt information including confirmation control information and marking information, the confirmation control information is used to generate a confirmation control on the user side, so that the user determines whether to execute the operation instruction;
[0047] When the current operation state is an inoperable state, generating second prompt information, the second prompt information including marking information;
[0048] The target verification operation includes: sending a first prompt message or a second prompt message to the user terminal.
[0049] In a possible implementation, the execution module is specifically used to:
[0050] Sending a first prompt message to the user terminal, receiving a response message sent by the user terminal, wherein the response message includes a confirmation instruction or a cancellation instruction, if the response message includes a confirmation instruction, determining that the verification result is an execution instruction, and if the response message includes a cancellation instruction, determining that the verification result is a non-execution instruction, wherein the confirmation instruction and the cancellation instruction are generated by the user terminal according to the user's operation on the confirmation control; or,
[0051] A second prompt message is sent to the user terminal, and according to the second prompt message, a verification result is determined as not executing the operation instruction.
[0052] In a possible implementation, when the current state information of the target identifier is the second state information, the second state information includes the user identifier, the user verification code, the approval user identifier and the approval verification code, the second determination module is specifically used to:
[0053] Generate first request information according to the target identifier and the user identifier, where the first request information is used to request the user to enter a first verification code;
[0054] Generate second request information according to the target identifier and the approval user identifier, the second request information is used to request the approval user corresponding to the approval user identifier to enter a second verification code;
[0055] The target verification operation includes: sending first request information to the client, or sending first request information and second request information to the client.
[0056] In a possible implementation, the execution module is specifically used to:
[0057] Sending first request information to the user terminal;
[0058] Receiving a first response message sent by the user terminal, where the first response message includes a first verification code;
[0059] Determine whether the first verification code is the same as the user verification code;
[0060] If yes, send a second request message to the user terminal, receive a second response message sent by the user terminal, the second response message includes a second verification code, when the second verification code is the same as the approval verification code, determine the verification result is to execute the operation instruction, when the second verification code is different from the approval verification code, determine the verification result is not to execute the operation instruction;
[0061] If not, the verification result is determined to be not executing the operation instruction.
[0062] In a possible implementation, the device further includes an updating module, and the updating module is used to:
[0063] In response to a permission modification instruction sent by the user terminal, user permission data is obtained, and the user permission data is updated according to the permission modification instruction, the permission modification instruction is used to modify the user's operation permission for each operation instruction, and the user permission data includes multiple user identifiers and multiple operation instruction identifiers corresponding to each user identifier; or,
[0064] In response to a state modification instruction sent by the user terminal, the instruction management data is acquired, and the instruction management data is updated according to the state modification instruction, where the state modification instruction is used to modify the current state information corresponding to the instruction identifier.
[0065] The present application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the steps of any one of the above instruction execution methods when executing the computer program.
[0066] The present application also provides a computer-readable storage medium, in which a computer program is stored, wherein when the computer program is executed by a processor, the steps of any of the above-mentioned instruction execution methods are implemented.
[0067] The present application also provides a computer program product, including a computer program, which implements the steps of any of the above instruction execution methods when executed by a processor.
[0068] Through this application, after determining that the user terminal has the operating authority for the operation instruction, the target verification operation is performed for secondary verification. Therefore, the technical problem of low security of server management can be solved, the occurrence of misoperation can be effectively prevented, and the security of server management can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0070] Figure 1 A schematic diagram of an application scenario provided for an embodiment of the present application;
[0071] Figure 2 A flowchart of an instruction execution method provided in an embodiment of the present application;
[0072] Figure 3 A flowchart of another instruction execution method provided in an embodiment of the present application;
[0073] Figure 4 A schematic diagram of an interface provided in an embodiment of the present application;
[0074] Figure 5 A flowchart of another instruction execution method provided in an embodiment of the present application;
[0075] Figure 6 A schematic diagram of the structure of an instruction execution device provided in an embodiment of the present application;
[0076] Figure 7 A schematic diagram of the structure of the electronic device provided in this application. DETAILED DESCRIPTION
[0077] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0078] It should be noted that, in the description of this application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence.
[0079] The nouns are explained below.
[0080] Desktop Bus (D-Bus) is an inter-process communication and remote procedure call mechanism developed for Linux systems. It uses a unified communication protocol to replace the existing solutions for various processes. D-Bus allows system-level processes to communicate with ordinary user processes.
[0081] In the field of server management, the server can be operated and managed through the server management software platform. The operation and maintenance management can include permission management, operation log recording, hardware monitoring, etc.
[0082] During operation and maintenance management, users may accidentally perform important operations such as shutdown and restart due to negligence or misoperation, causing errors such as shutting down the server and changing key configurations, resulting in low security of server management.
[0083] In order to solve the above technical problems, the embodiment of the present application provides an instruction execution method, which, in response to an operation instruction sent by a user terminal, determines whether the user terminal has the operation authority of the operation instruction, and if so, determines the target verification operation according to the target identifier corresponding to the operation instruction, performs the target verification operation, and obtains the verification result, which is used to indicate whether to execute the operation instruction. In this way, after determining that the user terminal has the operation authority of the operation instruction, the target verification operation can be performed to perform secondary verification, effectively preventing the occurrence of misoperation and improving the security of server management.
[0084] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0085] In conjunction with the specific application environment architecture or the specific hardware architecture on which the execution of the instruction execution method depends, the specific application environment architecture or the specific hardware architecture is described herein.
[0086] Next, combine Figure 1, taking a baseboard management controller (BMC) system as an example, a server management software platform is explained, and the server management software platform may include a BMC system.
[0087] See also Figure 1 , Figure 1 A schematic diagram of an application scenario provided for an embodiment of the present application. Figure 1 It can include a BMC system, which can include a user management module, a Redfish module, a webpage module, and a control module.
[0088] The user management module can be used to manage user-related matters, such as creating new users, deleting useless accounts, and setting permissions for different users. Through detailed permission settings, only authorized users can perform specific operations, thus ensuring the security of the server system.
[0089] The Redfish module can be used to implement the Redfish protocol and provide hardware configuration, status, and health information to the management end through a standard HTTP / HTTPS interface. This allows users to remotely manage hardware resources using a common network request method, making it easier for different management tools to interact with the server. Redfish can be a standard RESTful-based interface specifically designed for managing modern data center hardware devices.
[0090] The webpage module can be used to provide a visual web interface, which facilitates users to interact with the server through a browser. The webpage module can be used to handle the front-end page display and back-end logic. By interacting with other modules, it can intuitively present information such as server status and operation results to users. Users can manage the server through simple webpage operations without using command line tools, which greatly improves the convenience of management.
[0091] The control module can monitor and control the server hardware, such as remote power on and off, obtaining sensor data such as temperature, voltage, fan speed, etc. The control module can include an intelligent platform management interface, a network management protocol interface, etc.
[0092] The above modules can communicate via Dbus. This allows each module to run as an independent process and be decoupled from each other, which means that each module can be independently developed, tested and maintained.
[0093] Figure 2 A flowchart of a method for executing an instruction provided in an embodiment of the present application. The execution subject of the embodiment of the present application may be a baseboard management controller. Figure 2 As shown, the method is as follows:
[0094] S201: In response to an operation instruction sent by a user terminal, determine a user identifier corresponding to the user terminal and a target identifier corresponding to the operation instruction.
[0095] The user terminal may be a web page terminal generated based on the web page module. The user may log in to the web page terminal to perform relevant operations on the server.
[0096] The operation instruction may be an operation instruction generated based on operation information input by the user at the user terminal, or may be an operation instruction generated by the user selecting an operation control at the user terminal.
[0097] Operation instructions can be used to control the server to perform specific operations.
[0098] The user identification may be a user identification corresponding to the user who logs into the client.
[0099] The target identifier may be an identifier corresponding to the operation instruction.
[0100] An operation instruction sent by a user terminal can be received, the operation instruction can be parsed, a target identifier corresponding to the operation instruction can be determined, and a user identifier corresponding to the user terminal can be determined based on the user terminal.
[0101] S202: judging whether the user terminal has the operation authority for the operation instruction according to the user identifier and the target identifier.
[0102] The operation permission can be used to indicate that the user of the client has the permission to execute the operation instruction.
[0103] User authority data can be obtained, and based on the user authority data, multiple operation instruction identifiers corresponding to the user identifier can be determined, and it can be judged whether the target identifier exists among the multiple operation instruction identifiers. If so, it is determined that the user terminal has the operation authority for the operation instruction; if not, it is determined that the user terminal does not have the operation authority for the operation instruction.
[0104] The user authority data may include multiple user identifiers and multiple operation instruction identifiers corresponding to each user identifier.
[0105] S203: If yes, determine the target verification operation according to the target identifier.
[0106] The target verification operation may be a verification operation corresponding to the operation instruction.
[0107] Different verification operations may correspond to different operation modes.
[0108] The verification operation may include a first verification operation and a second verification operation, and so on.
[0109] The first verification operation may include sending a prompt message to the user terminal so that the user can perform a second verification.
[0110] The second verification operation may include sending a request message to the user terminal so that the user performs a second verification.
[0111] Optionally, if so, a mapping relationship may be obtained, and the target verification operation may be determined according to the target identifier and the mapping relationship. The mapping relationship may include multiple instruction identifiers and a verification operation corresponding to each instruction identifier.
[0112] Optionally, instruction management data is obtained, the instruction management data including multiple instruction identifiers and current status information corresponding to each instruction identifier, the current status information including first status information or second status information; based on the instruction management data, the current status information of the target identifier is determined; based on the current status information of the target identifier, a target verification operation is determined.
[0113] It should be noted that the target verification operation can be determined according to any feasible implementation method, and the embodiments of the present application are not limited to this.
[0114] S204: Execute the target verification operation to obtain the verification result.
[0115] The verification result is used to indicate whether to execute the operation instruction.
[0116] A target verification operation can be executed to obtain execution information, and a verification result can be determined based on the execution information.
[0117] The execution information may be information obtained by interacting with the user terminal during the execution of the target verification operation.
[0118] Optionally, the method further comprises:
[0119] Responding to the permission modification instruction sent by the user terminal, obtaining user permission data, and updating the user permission data according to the permission modification instruction; or,
[0120] In response to the state modification instruction sent by the user terminal, the instruction management data is acquired, and the instruction management data is updated according to the state modification instruction.
[0121] The permission modification instruction is used to modify the user's operation permission for each operation instruction, and the user permission data includes multiple user identifiers and multiple operation instruction identifiers corresponding to each user identifier.
[0122] User authority data can be stored in the database of the user management module.
[0123] The state modification instruction is used to modify the current state information corresponding to the instruction identifier.
[0124] The user can modify the state of an operation by clicking the state configuration control corresponding to an operation on the user-side interface, and confirm the modification operation, and the user-side generates a state modification instruction.
[0125] The status configuration control may include whether to activate the marking function, input the marking reason, whether to prohibit the operation, etc. It may also include whether to activate the approval function, input the approval user ID, etc.
[0126] The instruction execution method provided in this embodiment determines the user identification corresponding to the user terminal and the target identification corresponding to the operation instruction by responding to the operation instruction sent by the user terminal; judges whether the user terminal has the operation authority of the operation instruction according to the user identification and the target identification; if so, determines the target verification operation according to the target identification; performs the target verification operation to obtain the verification result, and the verification result is used to indicate whether to execute the operation instruction. In this way, after judging that the user terminal has the operation authority of the operation instruction, the target verification operation can be performed to perform secondary verification, effectively preventing the occurrence of misoperation and improving the security of server management.
[0127] Next, combine Figure 3 , the process (S203) of determining the target verification operation according to the target identification is explained.
[0128] Figure 3 A flowchart of another instruction execution method provided by an embodiment of the present application. Based on the above embodiment, see Figure 3 , the method is described in detail. The method comprises:
[0129] S301: Acquire instruction management data.
[0130] The instruction management data includes a plurality of instruction identifiers and current status information corresponding to each instruction identifier.
[0131] The instruction management data can be obtained in the database of the user management module.
[0132] S302: Determine the current status information of the target identifier according to the instruction management data.
[0133] The current state information includes first state information or second state information.
[0134] The first state information may be used to indicate current state information corresponding to the operation instruction to perform a first verification operation.
[0135] The first state information includes a tag type and tag information.
[0136] The tag type may include a first type and a second type.
[0137] The first type may indicate that the current operation state of the operation instruction is an operable state.
[0138] The second type may indicate that the current operating state of the operating instruction is an inoperable state.
[0139] The second state information may be used to indicate current state information corresponding to the operation instruction, so as to perform a second verification operation.
[0140] The current state information of the target identifier may be determined in the instruction management data according to the target identifier.
[0141] S303: Determine the current operation state of the operation instruction corresponding to the target identifier according to the mark type.
[0142] The current operation status is an operational status or an inoperable status.
[0143] If the current operation state is an operable state, execute S304;
[0144] If the current operation state is an inoperable state, execute S305.
[0145] The current operation state of the operation instruction corresponding to the target identifier may be determined according to the tag type and the first mapping relationship.
[0146] The first mapping relationship includes multiple types and a current operation state corresponding to each type.
[0147] S304: Generate first prompt information.
[0148] After S304, S306 is executed.
[0149] The first prompt information includes confirmation control information and mark information.
[0150] The confirmation control information is used to generate a confirmation control on the user side to allow the user to determine whether to execute the operation instruction.
[0151] Next, combine Figure 4 , explain the confirmation control.
[0152] Figure 4 This is a schematic diagram of an interface provided by an embodiment of the present application. Figure 4 , including the client interface.
[0153] The client interface includes a power control interface, and the power control interface includes an operation of powering on and off the server, and the current state of the operation is first state information to indicate that the operation has been marked.
[0154] In response to the user clicking on the server power-on and power-off execution operation control, a prompt box is displayed, where the prompt box is generated according to the first prompt information.
[0155] The prompt box can be used to display that the current operation has been marked, the marking reason, the start time, and a confirmation control.
[0156] The confirmation control can be used to confirm to the user whether to execute the operation instruction.
[0157] S305: Generate second prompt information.
[0158] After S305, S307 is executed.
[0159] The second prompt information includes marking information.
[0160] The second prompt information is used to generate a prompt box on the user side.
[0161] The prompt box is similar to the Figure 4 The prompt box in is similar.
[0162] S306: Send first prompt information to the user terminal, and receive response information sent by the user terminal.
[0163] If the response information includes a confirmation instruction, the verification result is determined to be an execution operation instruction; if the response information includes a cancellation instruction, the verification result is determined to be a non-execution operation instruction.
[0164] The response message includes a confirmation command or a cancellation command.
[0165] The confirmation instruction and the cancel instruction are generated by the user end according to the user's operation on the confirmation control.
[0166] When the user clicks the confirmation control, a confirmation instruction is generated.
[0167] When the user closes the prompt box, a cancel instruction is generated.
[0168] S307: Send a second prompt message to the user terminal, and determine, based on the second prompt message, that the verification result is not to execute the operation instruction.
[0169] Sending the second prompt message may indicate that the operation has been prohibited.
[0170] Displaying a prompt box to the user can remind the user why and when the operation is prohibited, so that the user can understand the specific reason.
[0171] The instruction execution method provided in the present embodiment obtains instruction management data, the instruction management data includes multiple instruction identifiers, and current state information corresponding to each instruction identifier, the current state information includes first state information or second state information; according to the instruction management data, the current state information of the target identifier is determined; when the current state information of the target identifier is the first state information, the first state information includes a mark type and mark information, according to the mark type, the current operation state of the operation instruction corresponding to the target identifier is judged, and the current operation state is an operable state or an inoperable state; when the current operation state is an operable state, first prompt information is generated, the first prompt information includes confirmation control information and mark information, and the confirmation control information is used to generate a confirmation control on the user end, so as to Allow the user to determine whether to execute the operation instruction; when the current operation state is an inoperable state, generate a second prompt information, the second prompt information includes marking information; wherein the target verification operation includes: sending the first prompt information or the second prompt information to the user terminal, sending the first prompt information to the user terminal, receiving the response information sent by the user terminal, the response information includes a confirmation instruction or a cancel instruction, if the response information includes a confirmation instruction, then determine the verification result to be to execute the operation instruction, if the response information includes a cancel instruction, then determine the verification result to be not to execute the operation instruction, wherein the confirmation instruction and the cancel instruction are generated by the user terminal according to the user's operation on the confirmation control; or, send a second prompt information to the user terminal, and according to the second prompt information, determine the verification result to be not to execute the operation instruction. In this way, after determining that the user terminal has the operation authority for the operation instruction, the target verification operation can be performed to perform secondary verification, effectively prevent the occurrence of misoperation, and improve the security of server management.
[0172] Next, combine Figure 5 , the process (S203) of determining the target verification operation according to the target identification is explained.
[0173] Figure 5 A flowchart of another instruction execution method provided in an embodiment of the present application. Based on the above embodiment, see Figure 5 , the method is described in detail. The method comprises:
[0174] S501: Acquire instruction management data.
[0175] The execution process of S501 can refer to the execution process of S301, which will not be described in detail here.
[0176] S502: Determine the current status information of the target identifier according to the instruction management data.
[0177] The execution process of S502 can refer to the execution process of S302, which will not be described in detail here.
[0178] S503: Generate first request information according to the target identifier and the user identifier.
[0179] The first request information is used to request the user to input a first verification code.
[0180] Preset request information may be obtained, and first request information may be generated according to the user identifier and the preset request information.
[0181] S504: Generate second request information according to the target identifier and the approval user identifier.
[0182] The second request information is used to request the approval user corresponding to the approval user identifier to input a second verification code.
[0183] Preset request information may be obtained, and second request information may be generated according to the approval user identifier and the preset request information.
[0184] S505: Sending first request information to the user terminal.
[0185] The first request information is sent to the user terminal through DBus communication.
[0186] S506: Receive the first response information sent by the user terminal.
[0187] The first response information includes a first verification code.
[0188] Receive the first response information sent by the user through DBus communication.
[0189] S507: Determine whether the first verification code is the same as the user verification code.
[0190] If yes, execute S508;
[0191] If not, execute S509.
[0192] The first verification code and the user verification code may be analyzed and processed to determine whether the first verification code and the user verification code are the same.
[0193] S508: Send a second request message to the user terminal, and receive a second response message sent by the user terminal, wherein the second response message includes a second verification code, and when the second verification code is the same as the approval verification code, determine that the verification result is to execute the operation instruction; when the second verification code is different from the approval verification code, determine that the verification result is not to execute the operation instruction.
[0194] A second request message can be sent to the user terminal, and a second response message sent by the user terminal can be received. The second response message includes a second verification code. The second verification code and the approval verification code are analyzed and processed. When the second verification code is the same as the approval verification code, the verification result is determined to be an execution operation instruction. When the second verification code is different from the approval verification code, the verification result is determined to be a non-execution operation instruction.
[0195] S509: Determine that the verification result is not to execute the operation instruction.
[0196] The instruction execution method provided in the present embodiment obtains instruction management data, the instruction management data includes multiple instruction identifiers, and current state information corresponding to each instruction identifier, the current state information includes first state information or second state information; according to the instruction management data, the current state information of the target identifier is determined; when the current state information of the target identifier is the second state information, the second state information includes a user identifier, a user verification code, an approval user identifier and an approval verification code, a first request information is generated according to the target identifier and the user identifier, the first request information is used to request the user to enter the first verification code; according to the target identifier and the approval user identifier, a second request information is generated, the second request information is used to request the approval user identifier corresponding to the approval user identifier Batch users enter the second verification code; the target verification operation includes: sending a first request message to the client, or sending a first request message and a second request message to the client, sending the first request message to the user end; receiving a first response message sent by the user end, the first response message includes the first verification code; judging whether the first verification code is the same as the user verification code; if so, sending a second request message to the user end, receiving a second response message sent by the user end, the second response message includes the second verification code, when the second verification code is the same as the approval verification code, determining the verification result to be an execution instruction, when the second verification code is different from the approval verification code, determining the verification result to be a non-execution instruction; if not, determining the verification result to be a non-execution instruction. In this way, after judging that the user end has the operation authority for the operation instruction, the target verification operation can be performed to perform a secondary verification, effectively preventing the occurrence of misoperation and improving the security of server management.
[0197] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.
[0198] Figure 6 This is a schematic diagram of the structure of an instruction execution device provided in an embodiment of the present application. Figure 6 The instruction execution device 600 includes a first determination module 601, a judgment module 602, a second determination module 603 and an execution module 604, wherein:
[0199] The first determination module 601 is used to determine the user identifier corresponding to the user terminal and the target identifier corresponding to the operation instruction in response to the operation instruction sent by the user terminal;
[0200] The judgment module 602 is used to judge whether the user terminal has the operation authority of the operation instruction according to the user identification and the target identification;
[0201] If yes, the second determination module 603 is used to determine the target verification operation according to the target identifier;
[0202] The execution module 604 is used to execute the target verification operation and obtain a verification result, and the verification result is used to indicate whether to execute the operation instruction.
[0203] In a possible implementation manner, the second determining module 603 is specifically configured to:
[0204] Acquire instruction management data, the instruction management data including multiple instruction identifiers and current state information corresponding to each instruction identifier, the current state information including first state information or second state information;
[0205] Determine the current status information of the target identification according to the instruction management data;
[0206] Determine the target verification operation based on the current status information of the target identification.
[0207] In a possible implementation manner, when the current state information of the target identifier is the first state information, the first state information includes the tag type and the tag information, the second determination module 603 is specifically configured to:
[0208] According to the mark type, the current operation state of the operation instruction corresponding to the target mark is determined, and the current operation state is an operable state or an inoperable state;
[0209] When the current operation state is an operable state, generating first prompt information, the first prompt information including confirmation control information and marking information, the confirmation control information is used to generate a confirmation control on the user side, so that the user determines whether to execute the operation instruction;
[0210] When the current operation state is an inoperable state, generating second prompt information, the second prompt information including marking information;
[0211] The target verification operation includes: sending a first prompt message or a second prompt message to the user terminal.
[0212] In a possible implementation, the execution module 604 is specifically configured to:
[0213] Sending a first prompt message to the user terminal, receiving a response message sent by the user terminal, wherein the response message includes a confirmation instruction or a cancellation instruction, if the response message includes a confirmation instruction, determining that the verification result is an execution instruction, and if the response message includes a cancellation instruction, determining that the verification result is a non-execution instruction, wherein the confirmation instruction and the cancellation instruction are generated by the user terminal according to the user's operation on the confirmation control; or,
[0214] A second prompt message is sent to the user terminal, and according to the second prompt message, a verification result is determined as not executing the operation instruction.
[0215] In a possible implementation, when the current state information of the target identifier is the second state information, the second state information includes the user identifier, the user verification code, the approval user identifier and the approval verification code, the second determination module 603 is specifically used to:
[0216] Generate first request information according to the target identifier and the user identifier, where the first request information is used to request the user to enter a first verification code;
[0217] Generate second request information according to the target identifier and the approval user identifier, the second request information is used to request the approval user corresponding to the approval user identifier to enter a second verification code;
[0218] The target verification operation includes: sending first request information to the client, or sending first request information and second request information to the client.
[0219] In a possible implementation, the execution module 604 is specifically configured to:
[0220] Sending first request information to the user terminal;
[0221] Receiving a first response message sent by the user terminal, where the first response message includes a first verification code;
[0222] Determine whether the first verification code is the same as the user verification code;
[0223] If yes, send a second request message to the user terminal, receive a second response message sent by the user terminal, the second response message includes a second verification code, when the second verification code is the same as the approval verification code, determine the verification result is to execute the operation instruction, when the second verification code is different from the approval verification code, determine the verification result is not to execute the operation instruction;
[0224] If not, the verification result is determined to be not executing the operation instruction.
[0225] In a possible implementation, the device further includes an updating module 605, and the updating module 605 is configured to:
[0226] In response to a permission modification instruction sent by the user terminal, user permission data is obtained, and the user permission data is updated according to the permission modification instruction, the permission modification instruction is used to modify the user's operation permission for each operation instruction, and the user permission data includes multiple user identifiers and multiple operation instruction identifiers corresponding to each user identifier; or,
[0227] In response to a state modification instruction sent by the user terminal, the instruction management data is acquired, and the instruction management data is updated according to the state modification instruction, where the state modification instruction is used to modify the current state information corresponding to the instruction identifier.
[0228] For the description of the features in the embodiment corresponding to the instruction execution device, reference can be made to the relevant description of the embodiment corresponding to the instruction execution method, which will not be repeated here.
[0229] Figure 7 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 7 As shown, the electronic device 700 provided in this embodiment includes: at least one processor 701 and a memory 702. Optionally, the device 700 also includes a communication component 703. The processor 701, the memory 702 and the communication component 703 are connected via a bus 704.
[0230] In a specific implementation process, at least one processor 701 executes the computer execution instructions stored in the memory 702, so that at least one processor 701 executes the above-mentioned instruction execution method embodiment.
[0231] The specific implementation process of the processor 701 can be found in the above method embodiment, and its implementation principle and technical effect are similar, so this embodiment will not be repeated here.
[0232] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the application may be directly implemented as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0233] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0234] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application is not limited to only one bus or one type of bus.
[0235] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above-mentioned instruction execution method embodiments when running.
[0236] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0237] An embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in any one of the above instruction execution method embodiments are implemented.
[0238] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above-mentioned instruction execution method embodiments are implemented.
[0239] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0240] The above is a detailed introduction to an instruction execution method provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the claims of the present application.
Claims
1. A method for executing an instruction, characterized in that: include: In response to an operation instruction sent by a user terminal, determining a user identifier corresponding to the user terminal and a target identifier corresponding to the operation instruction; According to the user identifier and the target identifier, determining whether the user terminal has the operation authority for the operation instruction; If so, determining a target verification operation according to the target identifier; The target verification operation is performed to obtain a verification result, wherein the verification result is used to indicate whether to execute the operation instruction.
2. The instruction execution method according to claim 1, characterized in that: Determining a target verification operation according to the target identifier includes: Acquire instruction management data, the instruction management data including a plurality of instruction identifiers and current state information corresponding to each instruction identifier, the current state information including first state information or second state information; Determining current status information of the target identifier according to the instruction management data; A target verification operation is determined according to the current state information of the target identifier.
3. The instruction execution method according to claim 2, characterized in that: When the current state information of the target identifier is the first state information, and the first state information includes a tag type and tag information, determining a target verification operation according to the current state information of the target identifier includes: According to the mark type, determining the current operation state of the operation instruction corresponding to the target identifier, the current operation state being an operable state or an inoperable state; In the case where the current operation state is an operable state, generating first prompt information, the first prompt information including confirmation control information and the mark information, the confirmation control information being used to generate a confirmation control on the user end so that the user determines whether to execute the operation instruction; When the current operation state is an inoperable state, generating second prompt information, wherein the second prompt information includes the mark information; The target verification operation includes: sending the first prompt information or the second prompt information to the user terminal.
4. The instruction execution method according to claim 3, characterized in that: Executing the target verification operation to obtain a verification result includes: sending the first prompt information to the user terminal, receiving response information sent by the user terminal, the response information including a confirmation instruction or a cancellation instruction, if the response information includes the confirmation instruction, determining that the verification result is to execute the operation instruction, and if the response information includes the cancellation instruction, determining that the verification result is not to execute the operation instruction, wherein the confirmation instruction and the cancellation instruction are generated by the user terminal according to the user's operation on the confirmation control; or, The second prompt information is sent to the user terminal, and according to the second prompt information, the verification result is determined to be not executing the operation instruction.
5. The instruction execution method according to claim 2, characterized in that: The current state information of the target identifier is the second state information, and the second state information includes a user identifier, a user verification code, an approval user identifier, and an approval verification code. According to the current state information of the target identifier, a target verification operation is determined, including: Generate first request information according to the target identifier and the user identifier, where the first request information is used to request the user to enter a first verification code; Generate second request information according to the target identifier and the approval user identifier, wherein the second request information is used to request the approval user corresponding to the approval user identifier to enter a second verification code; The target verification operation includes: sending the first request information to the client, or sending the first request information and the second request information to the client.
6. The instruction execution method according to claim 5, characterized in that: Executing the target verification operation to obtain a verification result includes: Sending the first request information to the user terminal; Receiving first response information sent by the user terminal, where the first response information includes the first verification code; Determining whether the first verification code is the same as the user verification code; If yes, send the second request information to the user terminal, receive the second response information sent by the user terminal, the second response information includes the second verification code, when the second verification code is the same as the approval verification code, determine the verification result is to execute the operation instruction, when the second verification code is different from the approval verification code, determine the verification result is not to execute the operation instruction; If not, determine that the verification result is not to execute the operation instruction.
7. The instruction execution method according to any one of claims 1 to 6, characterized in that: The method further comprises: In response to a permission modification instruction sent by the user terminal, user permission data is obtained, and the user permission data is updated according to the permission modification instruction, wherein the permission modification instruction is used to modify the user's operation permission for each operation instruction, and the user permission data includes multiple user identifiers and multiple operation instruction identifiers corresponding to each user identifier; or In response to the state modification instruction sent by the user terminal, instruction management data is acquired, and the instruction management data is updated according to the state modification instruction, wherein the state modification instruction is used to modify the current state information corresponding to the instruction identifier.
8. An instruction execution device, characterized in that: include: A first determination module, configured to determine, in response to an operation instruction sent by a user terminal, a user identifier corresponding to the user terminal and a target identifier corresponding to the operation instruction; A judgment module, used for judging whether the user terminal has the operation authority of the operation instruction according to the user identifier and the target identifier; If yes, a second determination module is used to determine a target verification operation according to the target identifier; The execution module is used to execute the target verification operation and obtain a verification result, wherein the verification result is used to indicate whether to execute the operation instruction.
9. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the instruction execution method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the instruction execution method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Running state information interaction platform system of users and towering machines
CN101644988A
Cloud file processing method and device
CN105812432A
Equipment control method, device and system, storage medium and electronic device
CN112099968A
Method and system for realizing remote one-key tapping in front of furnace based on multiple terminals
CN113885421A
Authority management method and device, equipment and storage medium
CN116204894A