Embedded server integrated system authentication method and device, equipment and storage medium
By integrating the embedded server internally into the switch, local authentication services and policy execution management functions are provided, and the problem of dependence on external RADIUS/TACACS+ servers in the prior art is solved, and the effect of improving the scalability and efficiency of the switch authentication service is achieved.
Patent Information
- Application Number
- CN202510421510.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing switches rely on external RADIUS/TACACS+ servers in 802.1x/MAC authentication and AAA functions, resulting in high hardware costs, complex management, and may lead to authentication paralysis in high concurrency or high latency scenarios.
By integrating an embedded server in the switch, local authentication services and policy execution management functions are provided, and unified authentication and fine-grained authorization functions are combined to realize authentication interaction and authorization audit within the switch.
It improves the scalability and efficiency of switch authentication services, reduces dependence on external RADIUS/TACACS+ servers, avoids single point of failure and high latency problems, and simplifies management processes.
Smart Images

Figure CN119945800A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of switch technology, and in particular to an authentication method, device, equipment and storage medium for an embedded server integrated system. Background Art
[0002] Sonic switches only serve as authentication clients or authentication intermediate devices, relying on external RADIUS / TACACS+ servers to complete 802.1x / MAC authentication and AAA functions. Additional servers need to be deployed and interaction policies configured, increasing hardware costs and management complexity. In addition, when the external server goes down, the entire network authentication will be paralyzed. In high-concurrency scenarios, the communication delay between the external server and the switch affects the authentication efficiency. Although existing network devices (such as some enterprise-level switches) support local user databases, their functions are limited and cannot replace the complex policy management capabilities of professional RADIUS / TACACS+ servers. Policy updates require the coordinated operation of multiple devices, making it difficult to achieve dynamic policy distribution. Summary of the invention
[0003] The main purpose of this application is to provide an embedded server integrated system authentication method, device, equipment and storage medium, aiming to solve the technical problem of how to improve the efficiency of switch authentication services.
[0004] To achieve the above objectives, the present application proposes an embedded server integrated system authentication method, the method comprising: Select the authentication interaction scenario; According to the authentication interaction scenario, the authentication result is obtained by interactive authentication between the first preset module and the second preset module, wherein the first preset module has a local authentication service function and a policy execution management function, and the second preset module has a unified authentication and fine-grained authorization function; In different authentication interaction scenarios, authorization and auditing are performed according to the authentication results to complete the switch authentication service.
[0005] In one embodiment, the step of obtaining an authentication result by interactive authentication through the first preset module and the second preset module according to the authentication interaction scenario includes: When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, performing remote authentication dial-up user service interaction authentication through the first preset module and the second preset module to obtain an authentication result; When the authentication interaction scenario is an administrator login scenario, the terminal access controller access control system upgraded version interactive authentication is performed through the first preset module and the second preset module to obtain an authentication result.
[0006] In one embodiment, when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, the step of performing remote authentication dial-up user service interaction authentication through the first preset module and the second preset module to obtain an authentication result includes: When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, performing remote authentication dial-up user service interaction authentication based on the first preset module and the second preset module, triggering an extensible authentication protocol handshake; Encapsulate and forward the extensible authentication protocol message to the first preset container for account and password management; Querying user credentials or certificate library information in a second preset container; Interactive authentication is performed according to the extensible authentication protocol message and the user credential or certificate library to obtain an authentication result.
[0007] In one embodiment, when the authentication interaction scenario is an administrator login scenario, the step of performing interactive authentication of the terminal access controller access control system upgraded version through the first preset module and the second preset module to obtain the authentication result includes: When the authentication interaction scenario is an administrator login scenario, detecting whether the administrator logs in through a secure shell protocol; After detecting that the administrator logs in through the secure shell protocol, performing an interactive authentication of the upgraded version of the terminal access controller access control system based on the first preset module and the second preset module, triggering an authentication request; When detecting that the first preset container receives the authentication request, obtaining initial configurations of the first preset container and the third preset container; Authenticate the username / password according to the initial configuration to obtain an authentication result.
[0008] In one embodiment, the steps of performing authorization and auditing according to the authentication results in different authentication interaction scenarios to complete the switch authentication service include: When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, returning an authorization response and issuing a dynamic virtual LAN policy; The dynamic virtual LAN policy is applied and the session is recorded in the audit log to complete the switch authentication service.
[0009] In one embodiment, when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, the step of returning an authorization response and issuing a dynamic virtual LAN policy includes: When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, returning an authorization response and a dynamic virtual LAN attribute, wherein the dynamic virtual LAN attribute is used for resource isolation; Obtaining a dynamic virtual LAN policy according to the dynamic virtual LAN attribute; The dynamic virtual LAN policy is issued.
[0010] In one embodiment, the step of performing authorization and auditing according to the authentication results in different authentication interaction scenarios to complete the switch authentication service further includes: When the authentication interaction scenario is an administrator login scenario and the authentication result is authentication passed, loading a rights configuration file from a policy library and returning an authorization response; Generate a command whitelist according to the authorization response by controlling the command line interface engine, and execute user instructions according to the command whitelist; Encrypted storage operation execution records to complete switch authentication services.
[0011] In addition, to achieve the above purpose, the present application also proposes an embedded server integrated system authentication device, the device comprising: A scenario determination module is used to select an authentication interaction scenario; An interactive authentication module, configured to obtain an authentication result by interactively authenticating with a second preset module through a first preset module according to the authentication interaction scenario, wherein the first preset module has a local authentication service function and a policy execution management function, and the second preset module has a unified authentication and fine-grained authorization function; The authorization and auditing module is used to perform authorization and auditing according to the authentication results in different authentication interaction scenarios to complete the switch authentication service.
[0012] In addition, to achieve the above-mentioned purpose, the present application also proposes an embedded server integrated system authentication device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, and the computer program is configured to implement the steps of the embedded server integrated system authentication method as described above.
[0013] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the embedded server integrated system authentication method described above are implemented.
[0014] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the steps of the embedded server integrated system authentication method described above are implemented.
[0015] One or more technical solutions proposed in this application have at least the following technical effects: This application uses an embedded server to process authentication services for different scenarios inside the switch, solving the switch's dependence on external RADIUS / TACACS+ servers and the technical problems of single point failure, high latency, and management fragmentation in traditional solutions. Compared with the existing technology, it improves the scalability and efficiency of the switch's authentication services. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0018] Figure 1 A flowchart of the first embodiment of the authentication method for an embedded server integrated system provided in this application; Figure 2 A flowchart of the second embodiment of the authentication method for the embedded server integrated system of the present application is provided; Figure 3 A schematic diagram of a container for introducing the authentication method of an embedded server integrated system provided in Embodiment 2 of the present application; Figure 4 A flowchart of the third embodiment of the authentication method for the embedded server integrated system of the present application is provided; Figure 5 A flowchart of the fourth embodiment of the authentication method for the embedded server integrated system of the present application is provided; Figure 6 A brief flowchart of the embedded server integrated system authentication method provided in the embodiment of the present application; Figure 7 This is a schematic diagram of the module structure of the embedded server integrated system authentication device according to an embodiment of the present application; Figure 8 This is a schematic diagram of the device structure of the hardware operating environment involved in the embedded server integrated system authentication method in the embodiment of the present application.
[0019] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0020] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0021] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0022] The main solution of the embodiment of the present application is: selecting an authentication interaction scenario; according to the authentication interaction scenario, obtaining an authentication result through interactive authentication between a first preset module and a second preset module, wherein the first preset module has a local authentication service function and a policy execution management function, and the second preset module has a unified authentication and fine-grained authorization function; in different authentication interaction scenarios, authorization and auditing are performed according to the authentication result to complete the switch authentication service.
[0023] In this embodiment, for the convenience of description, the following description is made by taking the internal executor of the authentication system of the embedded server integrated system as the execution subject.
[0024] The existing switches rely heavily on external RADIUS / TACACS+ servers, and traditional authentication solutions have technical problems such as single point failure, high latency, and fragmented management.
[0025] The present application provides a solution that uses an embedded server to process authentication services for different scenarios inside a switch, thereby improving the scalability and efficiency of the switch authentication service.
[0026] It can be seen from the above embodiments that the present application processes authentication services for different scenarios inside the switch through an embedded server, thereby solving the switch's dependence on an external RADIUS / TACACS+ server and the technical problems of single point failure, high latency, and management fragmentation in traditional solutions, thereby improving the scalability and efficiency of the switch's authentication services.
[0027] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of realizing the above functions, etc. The following takes the internal executor of the embedded server integrated system authentication system as an example to illustrate this embodiment and the following embodiments.
[0028] Based on this, the embodiment of the present application provides an embedded server integrated system authentication method, referring to Figure 1 , Figure 1This is a flowchart of the first embodiment of the embedded server integrated system authentication method of the present application.
[0029] In this embodiment, the embedded server integrated system authentication method includes steps S10 to S30: Step S10, selecting an authentication interaction scenario.
[0030] It should be noted that the authentication interaction scenario refers to the scenario where the Sonic switch only acts as an authentication client or authentication intermediate device to complete 802.1x / MAC authentication and AAA functions, that is, the scenario where RADIUS / TACACS+ is used to complete the AAA function. The authentication interaction scenario includes the 802.1x authentication scenario (RADIUS interaction scenario) and the administrator login scenario (MAC authentication scenario or TACACS+ interaction scenario). AAA stands for authentication, authorization, and accounting, and is an important function used to manage and control users in the field of network security.
[0031] In addition, it should be noted that 802.1X authentication is a network access control technology based on the IEEE 802.1X standard. It is mainly used to authenticate devices or users connected to the network to ensure that only authorized devices or users can access network resources. The authentication process in the 802.1x authentication scenario is often implemented with the help of RADIUS interaction. RADIUS provides background authentication, authorization and billing function support for 802.1x authentication.
[0032] In addition, it should be noted that MAC authentication is a method of identity authentication based on the device's physical address (Media Access Control Address, MAC address), which is often used as a means in administrator login scenarios to enhance the security and accuracy of login. In the administrator login scenario, the TACACS+ protocol is used to authenticate, authorize and audit the administrator's login to the network device. Through this protocol, information is exchanged between the administrator, network device and TACACS+ server to ensure that only authorized administrators can access the network device and effectively manage and supervise their operations.
[0033] In addition, it should be noted that RADIUS (Remote Authentication Dial-In User Service) is a network authentication, authorization and accounting protocol that is widely used in various network environments. The remote authentication dial-in user service interaction scenario is also the 802.1x authentication scenario of RADIUS and AAA authentication interaction. TACACS+ (Terminal Access Controller Access - Control System Plus) is a network security protocol used to centrally manage user access rights to network devices.
[0034] Step S20, according to the authentication interaction scenario, the first preset module interacts with the second preset module to obtain an authentication result, wherein the first preset module has a local authentication service function and a policy execution management function, and the second preset module has a unified authentication and fine-grained authorization function.
[0035] It should be noted that the first preset module is the RADIUS / TACACS+ server module, which has a local authentication service function, can replace the external server, and directly process 802.1x, MAC authentication requests and administrator AAA operations in the switch. It also has a policy execution management function, and can act as the policy execution center of the system, dynamically parse the authentication results and issue port policies (such as VLAN allocation, ACL rules). At the same time, the hardware configuration of the RADIUS / TACACS+ server module includes NPU acceleration, which uses the network processing unit (NPU) of the switching chip to implement protocol encryption and decryption (such as MD5 of RADIUS and AES of TACACS+), and improves performance by 3-5 times. It also includes memory pool optimization, which can pre-allocate DMA buffers and reduce message processing delays (<1ms).
[0036] The RADIUS / TACACS+ server module enables the switch to function as both an authentication client and server, reducing the number of devices and link overhead. The built-in server supports active / standby synchronization and distributed clustering, avoiding single points of failure, improving system availability, and processing authentication requests locally to increase response speed (especially for high-density IoT scenarios).
[0037] In addition, it should be noted that the second preset module is an AAA authentication module, which has a unified authentication function, can link the RADIUS / TACACS+ authentication results with the local user database (such as Linux PAM), supports hybrid authentication mode, and also has a fine-grained authorization function, which can limit the CLI command set based on the permission tag returned by TACACS+ (such as role:admin).
[0038] Authentication is part of the AAA function and is used to verify whether the user's identity is legitimate. By checking the identity information provided by the user, such as user name, password, digital certificate, etc., and comparing it with the user information stored in the system, it is determined whether the user has the right to access network resources. In different authentication scenarios, the RADIUS / TACACS+ server module and the AAA authentication module work together. The RADIUS / TACACS+ server module authenticates the received authentication request and determines whether the authentication is successful and returns an authorization response. The AAA authentication module can integrate the authentication results for subsequent AAA function authorization and billing processes. At the same time, the switch has a unified operation and maintenance interface for integrated switch configuration and authentication service management to simplify the operation and maintenance process.
[0039] Step S30: performing authorization and auditing according to the authentication results in different authentication interaction scenarios to complete the switch authentication service.
[0040] Authorization and audit (billing) are part of AAA functions. Authorization is to determine which resources a user can access and what operation permissions he has after he passes the authentication. For example, an authorized user can access specific files, execute certain commands, or use specific network services. Billing is to record and count the user's use of network resources, including network connection duration, data traffic, type of service used, etc., so as to charge according to a certain billing strategy, or to analyze and manage the use of network resources.
[0041] Switch authentication service is an important mechanism to ensure network security and access control. Common authentication methods include 802.1X authentication, MAC address authentication, port security authentication, etc. The method introduced in this embodiment and other embodiments is used for the two authentication scenarios of 802.1X authentication and MAC address authentication.
[0042] This embodiment provides an embedded server integrated system authentication method, which processes authentication services for different scenarios inside the switch through the embedded server, thereby solving the switch's dependence on external RADIUS / TACACS+ servers and the technical problems of single point failure, high latency, and management fragmentation in traditional solutions, thereby improving the scalability and efficiency of the switch's authentication service.
[0043] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can be referred to the above introduction, and will not be repeated in the following. Figure 2 , step S20 includes steps S21-S22: Step S21, when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, remote authentication dial-up user service interaction authentication is performed through the first preset module and the second preset module to obtain an authentication result.
[0044] It should be noted that the remote authentication dial-up user service interaction scenario is also an 802.1x authentication scenario of RADIUS and AAA authentication interaction.
[0045] In a feasible implementation, step S21 may include steps S211 to S214: Step S211, when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, remote authentication dial-up user service interaction authentication is performed based on the first preset module and the second preset module to trigger an extensible authentication protocol handshake.
[0046] It should be noted that Extensible Authentication Protocol over LAN (EAPOL) is a protocol used to transmit EAP messages in a local area network environment and is mainly used in the 802.1X authentication system.
[0047] In the 802.1x authentication scenario, after a device is connected to a switch port, the switch port detects the connection and initializes it, setting the port to an unauthorized state. The device then actively sends an EAPoL - Start message to trigger authentication.
[0048] Step S212: encapsulate and forward the extensible authentication protocol message to the first preset container to perform account and password management.
[0049] It should be noted that the first preset container is the radius-service container. The method of the present application is applied to a switch of a containerized deployment architecture, with service isolation between containers, which includes three containers with different functions, namely, the radius-service container, the tacacs-service container, and the policy-db container.
[0050] like Figure 3 The figure shows a schematic diagram of container introduction: radius-service container, whose function is to process 802.1x / MAC authentication requests, and whose security policy is to run as a non-root user and disable privileged mode; tacacs-service container, whose function is to manage AAA operations (login / authorization / audit), and whose security policy is to filter high-risk system calls by Seccomp; policy-db container, whose function is to store authentication policies and session logs, and whose security policy is data volume encryption (LUKS).
[0051] For these containers, communication isolation between containers is also designed, including network isolation and process isolation. For network isolation, each container is assigned an independent virtual network namespace, and communication with the host is only allowed through Socket. Direct interconnection between containers is prohibited, and data must be transferred through the policy database (policy-db). For process isolation, container resource usage is limited (for example, the CPU upper limit of the radius-service container is 20%), configuration files are enabled, and the file system access scope of the container process is limited. At the same time, security enhancement designs are also carried out, including key management and vulnerability protection. For key management, RADIUS shared keys and TACACS+ encryption keys are stored in the chip and dynamically injected when the container starts. The key rotation cycle is 30 days, and automatic updates are supported. For vulnerability protection, the container image is updated with the database every day, vulnerabilities are detected, and reconstruction is automatically triggered (for example, forced update when a high-risk OpenSSL vulnerability is detected). The container also has high availability and elastic expansion, horizontal expansion, support Kubernetes orchestration, and dynamic expansion of container instances (for example, when concurrent authentication requests surge, radius-service containers are automatically added).
[0052] After receiving the EAP message from the client, the switch encapsulates it into an Access-Request message according to the RADIUS protocol, adds its own identification and other information, and then sends it to the radius-service container running the RADIUS server software to manage the account and password, determine whether the account and password are correct, and authorize permissions, etc. The authentication message bypasses the kernel through the DPDK and passes through the container, reducing the number of CPU interrupts, that is, zero-copy transmission.
[0053] Step S213, querying the user credentials or certificate library information in the second preset container.
[0054] It should be noted that the second preset container is the policy-db container. User credentials or certificate library information is information used to verify the identity of a user or device in network security and access control scenarios.
[0055] The RADIUS / TACACS+ server module queries the user credentials or certificate library information in the policy-db container. In 802.1X authentication, the switch compares the identity information received from the client with the user credentials or certificate library information in the policy-db container to determine whether the user is a legitimate user.
[0056] Step S214: performing interactive authentication according to the extensible authentication protocol message and the user credential or certificate library to obtain an authentication result.
[0057] By comparing the received EAP message information with the user credentials or certificate library information in the policy-db container, it is determined whether the user is a legitimate user. Only users who have passed the authentication can access network resources. The authentication results include authentication passed and authentication failed.
[0058] RADIUS and AAA authentication interaction is performed through the RADIUS / TACACS+ server module and the AAA authentication module, thereby improving the efficiency of the switch authentication service.
[0059] Step S22, when the authentication interaction scenario is an administrator login scenario, the terminal access controller access control system upgraded version interactive authentication is performed through the first preset module and the second preset module to obtain an authentication result.
[0060] It should be noted that the administrator login scenario is also the scenario of interaction between TACACS+ and AAA authentication, which can also be called MAC authentication scenario or TACACS+ authentication scenario. The terminal access controller access control system upgraded version interactive authentication is the interaction between TACACS+ and AAA authentication.
[0061] In a feasible implementation, step S22 may include steps S221 to S224: Step S221, when the authentication interaction scenario is an administrator login scenario, detect whether the administrator logs in through the secure shell protocol.
[0062] It should be noted that Secure Shell (SSH) is a network protocol used to securely log in to a server or other network devices remotely in an insecure network environment, execute commands, and transfer files.
[0063] The administrator uses the SSH client on the local terminal to enter the switch's IP address, user name, password and other information to initiate an SSH connection request with the switch. After receiving the SSH connection request, the switch recognizes that this is a login request that requires identity authentication and needs to detect whether the administrator has successfully logged in.
[0064] The reuse rate of TACACS+ TCP long connection pool is >90%, reducing handshake overhead.
[0065] Step S222: after detecting that the administrator has logged in through the secure shell protocol, performing an interactive authentication of the upgraded version of the terminal access controller access control system based on the first preset module and the second preset module, triggering an authentication request.
[0066] After the administrator successfully logs in to the switch, since the switch is configured with TACACS+ authentication, it will redirect the login request to the TACACS+ authentication process, which triggers a TACACS+ authentication request.
[0067] Step S223: when it is detected that the first preset container receives the authentication request, the initial configurations of the first preset container and the third preset container are obtained.
[0068] It should be noted that the third preset container is the tacacs-service container. The initial configuration is a user name / password created by the user for login authentication.
[0069] After receiving the authentication request, the radius-service container needs to obtain the configuration on the radius-service / tacacs-service container. The initial configuration is the username / password. Similar to wifi login, you need to create a wifi account and password first, and the user logs in using this account and password.
[0070] Step S224, authenticating the username / password according to the initial configuration to obtain an authentication result.
[0071] Verify that the username / password entered for this login is correct according to the initial configuration. If it is correct, the authentication is successful; if it is incorrect, the authentication fails.
[0072] Through the RADIUS / TACACS+ server module and the AAA authentication module, TACACS+ and AAA authentication interact with each other, thus improving the efficiency of the switch authentication service.
[0073] This embodiment provides an embedded server integrated system authentication method. When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, the remote authentication dial-up user service interaction authentication is performed by the first preset module and the second preset module to obtain an authentication result; when the authentication interaction scenario is an administrator login scenario, the terminal access controller access control system upgraded version interaction authentication is performed by the first preset module and the second preset module to obtain an authentication result, thereby improving the efficiency of the switch authentication service.
[0074] Based on the first embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can be referred to the above introduction, and will not be repeated in the following. Figure 4 , step S30 includes steps S31-S32: Step S31, when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, an authorization response is returned and a dynamic virtual LAN policy is issued.
[0075] It should be noted that the dynamic virtual LAN policy, namely the VLAN (Virtual Local Area Network) policy, refers to a series of rules and measures formulated in a virtual LAN environment to achieve the goals of reasonable allocation of network resources, improving network security, and optimizing network performance.
[0076] In a feasible implementation manner, step S31 includes steps S311 to S313: Step S311, when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, returning an authorization response and dynamic virtual LAN attributes, wherein the dynamic virtual LAN attributes are used for resource isolation.
[0077] It should be noted that the dynamic virtual LAN attribute is the VLAN attribute. The role of the VLAN attribute is to isolate resources, which is equivalent to dividing different areas for different users.
[0078] If authentication succeeds, an Access-Accept packet is returned with dynamic VLAN attributes (such as Tunnel-Private-Group-ID=200).
[0079] Step S312, obtaining a dynamic virtual LAN policy according to the dynamic virtual LAN attribute.
[0080] VLAN policies are obtained based on VLAN attributes. Management and access policies can be formulated based on VLAN ID ranges or special IDs. Access rights can be restricted or opened based on whether the member is a user or a server. High security and VPN access policies can be adopted for core and edge area VLANs according to network locations. Bandwidth can be allocated and priorities can be set for voice, video surveillance and other VLANs based on business needs. Different levels of security protection measures can be implemented for high security and general security area VLANs according to security requirements.
[0081] Step S313: issuing the dynamic virtual LAN policy.
[0082] After obtaining the VLAN policy, it is sent down, and the port management module of the switch receives and applies the VLAN policy.
[0083] By obtaining corresponding policies through local authentication, the efficiency of switch authentication services can be improved.
[0084] Step S32, applying the dynamic virtual LAN policy and recording the session to the audit log to complete the switch authentication service.
[0085] When applying VLAN policies and recording sessions to audit logs, you can first plan the VLAN policies, including VLAN division and access control; then create VLANs on the switch, assign ports, and configure inter-VLAN access control and authentication services, such as enabling 802.1X authentication and configuring the authentication server and port authentication mode; then enable the logging function and configure session logging to send the logs to the specified server; finally, perform user authentication tests and audit log checks to verify the validity of the configuration.
[0086] This embodiment provides an embedded server integrated system authentication method. When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, an authorization response is returned and a dynamic virtual LAN policy is issued; the dynamic virtual LAN policy is applied and the session is recorded in an audit log to complete the switch authentication service, thereby improving the efficiency of the switch authentication service.
[0087] Based on the first embodiment of the present application, in the fourth embodiment of the present application, the same or similar contents as those in the first embodiment can be referred to the above description, and will not be described in detail later. Figure 5 , step S30 also includes steps A01 to A03: Step A01, when the authentication interaction scenario is an administrator login scenario and the authentication result is authentication passed, load a rights configuration file from a policy library and return an authorization response.
[0088] It should be noted that the policy library is a collection or database for storing and managing various policies.
[0089] In addition, it should be noted that a permission profile is a file used to define and manage the permissions of users or roles in a system, application, or network. It usually contains a series of rules and settings that clearly define the access rights of different users or roles to various resources (such as files, folders, database tables, functional modules, etc.), such as read, write, modify, delete, execute, and other operation permissions. Through the permission profile, user permissions can be flexibly configured and managed to ensure the security of the system and the confidentiality of data, while meeting the differentiated requirements for user access rights in different business scenarios.
[0090] The tacacs-service container verifies the user name / password, loads the permission profile from the policy library (such as allowing the show command and prohibiting reboot), and returns an authorization response (ACCEPT + cmd-permit: show, ping).
[0091] Step A02, generating a command whitelist according to the authorization response by controlling the command line interface engine, and executing user instructions according to the command whitelist.
[0092] It should be noted that the command line interface engine, also known as the CLI (Command-Line Interface) engine, refers to the core processing mechanism or component of the command line interface. It is mainly responsible for parsing the commands entered by the user in the command line, converting them into operations that the system can understand and execute, coordinating related system resources to execute these operations, and then feeding back the execution results to the user.
[0093] In addition, it should be noted that the command whitelist is an access control mechanism that specifies a list of commands that are allowed to be executed in a specific environment. In a computer system, network device or application, the command whitelist explicitly allows specific commands or operations to be executed through pre-set rules, while other commands not in the whitelist are prohibited or restricted from execution. This mechanism helps to enhance the security and stability of the system and prevent unauthorized or potentially dangerous commands from being executed, thereby reducing the risk of the system being attacked maliciously, misoperated or violated. For example, in an enterprise network, an administrator can set up a command whitelist to only allow employees to execute specific work-related commands in the command line interface, such as viewing network status, querying files, etc., while prohibiting the execution of commands that may damage the system or leak sensitive information. The permission profile and the command whitelist correspond to each other and are both used to specify what CLI commands a user can use.
[0094] Step A03, encrypt and store the operation execution record to complete the switch authentication service.
[0095] All operation records of the switch executing user instructions will be strictly encrypted. The encryption algorithm can adopt a variety of methods to effectively resist various forms of password cracking attacks. Whether it is user login, data access, permission modification, or any other system operation, the detailed records of these operations, including the time of operation, the identity information of the operator, the specific content of the operation, and the relevant parameters, will be captured completely and accurately. The encrypted operation records will be stored in the policy-db container. The policy-db container has powerful storage and management capabilities and a complete backup and recovery mechanism to prevent data loss. When audit work is required, whether it is internal compliance inspection, external regulatory requirements, or investigation and tracing when a security incident occurs, auditors can retrieve the corresponding encrypted operation records from the policy-db container through specific authorization and secure access methods. By decrypting and analyzing these records, the entire operation process can be clearly restored, and it can be accurately judged whether the operation complies with regulations and whether there are potential security risks or violations.
[0096] This embodiment provides an embedded server integrated system authentication method. When the authentication interaction scenario is an administrator login scenario and the authentication result is authentication passed, a permission configuration file is loaded from a policy library and an authorization response is returned; a command whitelist is generated according to the authorization response by controlling a command line interface engine, and user instructions are executed according to the command whitelist; and operation execution records are encrypted and stored to complete a switch authentication service, thereby improving the efficiency of the switch authentication service.
[0097] For example, to help understand the implementation process of the embedded server integrated system authentication method obtained by combining the above-mentioned embodiments 1, 2, 3, and 4, please refer to Figure 6 , Figure 6 A brief flow chart of an embedded server integrated system authentication method is provided, specifically: Terminal / administrator (account, password); encapsulate / parse / forward the protocol through ssh / eapol and return the authentication result; then issue the permission and policy configuration; encapsulate / parse / forward the message in the radius-service container / tacacs-service container through radius / tacacs request message, and reply the message; then parse the account / password / mac, etc., configure the permission and policy information in the policy-db container, and return the result / vlan attribute / permission.
[0098] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the embedded server integrated system authentication method of the present application. More simple transformations based on this technical concept are all within the protection scope of the present application.
[0099] This application also provides an embedded server integrated system authentication device, please refer to Figure 7 , the device comprises: A scenario determination module 10, used to select an authentication interaction scenario; An interactive authentication module 20, configured to obtain an authentication result by interactive authentication through a first preset module and a second preset module according to the authentication interaction scenario, wherein the first preset module has a local authentication service function and a policy execution management function, and the second preset module has a unified authentication and fine-grained authorization function; The authorization and auditing module 30 is used to perform authorization and auditing according to the authentication results in different authentication interaction scenarios to complete the switch authentication service.
[0100] In one embodiment, the interactive authentication module 20 is also used to, when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, perform remote authentication dial-up user service interactive authentication through the first preset module and the second preset module to obtain an authentication result; when the authentication interaction scenario is an administrator login scenario, perform terminal access controller access control system upgraded version interactive authentication through the first preset module and the second preset module to obtain an authentication result.
[0101] In one embodiment, the interactive authentication module 20 is also used to, when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, perform remote authentication dial-up user service interactive authentication based on the first preset module and the second preset module, triggering an extensible authentication protocol handshake; encapsulating and forwarding extensible authentication protocol messages to a first preset container for account and password management; querying user credentials or certificate library information in a second preset container; and performing interactive authentication based on the extensible authentication protocol message and the user credentials or certificate library to obtain an authentication result.
[0102] In one embodiment, the interactive authentication module 20 is also used to detect whether the administrator logs in through the secure shell protocol when the authentication interaction scenario is an administrator login scenario; after detecting that the administrator logs in through the secure shell protocol, perform interactive authentication of the upgraded version of the terminal access controller access control system based on the first preset module and the second preset module to trigger an authentication request; when detecting that the first preset container receives the authentication request, obtain the initial configuration of the first preset container and the third preset container; authenticate the username / password according to the initial configuration to obtain an authentication result.
[0103] In one embodiment, the authorization audit module 30 is also used to return an authorization response and issue a dynamic virtual LAN policy when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed; apply the dynamic virtual LAN policy and record the session to the audit log to complete the switch authentication service.
[0104] In one embodiment, the authorization audit module 30 is also used to return an authorization response and dynamic virtual LAN attributes when the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, wherein the dynamic virtual LAN attributes are used for resource isolation; obtain a dynamic virtual LAN policy based on the dynamic virtual LAN attributes; and issue the dynamic virtual LAN policy.
[0105] In one embodiment, the authorization audit module 30 is also used to load the permission configuration file from the policy library and return an authorization response when the authentication interaction scenario is an administrator login scenario and the authentication result is authentication passed; generate a command whitelist according to the authorization response by controlling the command line interface engine, and execute user instructions according to the command whitelist; encrypt and store operation execution records to complete the switch authentication service.
[0106] The embedded server integrated system authentication device provided by the present application adopts the embedded server integrated system authentication method in the above embodiment, which can solve the technical problem of how to improve the scalability and efficiency of the switch authentication service. Compared with the prior art, the beneficial effects of the embedded server integrated system authentication device provided by the present application are the same as the beneficial effects of the embedded server integrated system authentication method provided by the above embodiment, and other technical features in the embedded server integrated system authentication device are the same as the features disclosed in the above embodiment method, which will not be repeated here.
[0107] The present application provides an embedded server integrated system authentication device, which includes: at least one processor; and a memory that is communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the embedded server integrated system authentication method in the above-mentioned embodiment one.
[0108] Reference below Figure 8 , which shows a schematic diagram of the structure of an embedded server integrated system authentication device suitable for implementing the embodiment of the present application. The embedded server integrated system authentication device in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The embedded server integrated system authentication device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0109] like Figure 8As shown, the embedded server integrated system authentication device may include a processing device 1001 (such as a central processing unit, a graphics processor, etc.), which can perform various appropriate actions and processes according to the program stored in the ROM (Read Only Memory) 1002 or the program loaded from the storage device 1003 to the RAM (Random Access Memory) 1004. Various programs and data required for the operation of the automatic flashing overtaking lights and automatic horn devices in the smart driving are also stored in RAM1004. The processing device 1001, ROM1002 and RAM1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices 1008 including, for example, an LCD (Liquid Crystal Display), a speaker, a vibrator, etc.; storage devices 1003 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 1009. The communication device 1009 can allow the embedded server integrated system certification device to communicate wirelessly or wired with other devices to exchange data. Although the figure shows an embedded server integrated system certification device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems may be implemented or have alternatively.
[0110] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0111] The embedded server integrated system authentication device provided by the present application adopts the embedded server integrated system authentication method in the above embodiment, which can solve the technical problem of how to improve the scalability and efficiency of the switch authentication service. Compared with the prior art, the beneficial effects of the embedded server integrated system authentication device provided by the present application are the same as the beneficial effects of the embedded server integrated system authentication method provided by the above embodiment, and the other technical features in the embedded server integrated system authentication device are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.
[0112] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0113] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0114] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, and the computer-readable program instructions are used to execute the embedded server integrated system authentication method in the above-mentioned embodiment.
[0115] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, RAM (Random Access Memory), ROM (Read Only Memory), EPROM (Erasable Programmable Read Only Memory or flash memory, erasable programmable read-only memory), optical fiber, CD-ROM (CD-Read Only Memory, portable compact disk read-only memory), optical storage device, magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0116] The computer-readable storage medium may be included in the embedded server integrated system authentication device; or may exist independently without being assembled into the embedded server integrated system authentication device.
[0117] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the embedded server integrated system authentication device, the embedded server integrated system authentication device: selects an authentication interaction scenario; according to the authentication interaction scenario, performs interactive authentication through a first preset module and a second preset module to obtain an authentication result, wherein the first preset module has a local authentication service function and a policy execution management function, and the second preset module has a unified authentication and fine-grained authorization function; in different authentication interaction scenarios, authorization and auditing are performed according to the authentication result to complete the switch authentication service.
[0118] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a LAN (Local Area Network) or a WAN (Wide Area Network), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0119] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0120] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.
[0121] The readable storage medium provided by the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned embedded server integrated system authentication method, and can solve the technical problem of how to improve the scalability and efficiency of the switch authentication service. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as the beneficial effects of the embedded server integrated system authentication method provided by the above-mentioned embodiment, and will not be repeated here.
[0122] The present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned embedded server integrated system authentication method when executed by a processor.
[0123] The computer program product provided by the present application can solve the technical problem of how to improve the scalability and efficiency of the switch authentication service. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as the beneficial effects of the embedded server integrated system authentication method provided by the above embodiment, which will not be repeated here.
[0124] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present application.
Claims
1. An embedded server integrated system authentication method, characterized in that: The method is applied to a switch of a containerized deployment architecture, and the method includes: Select the authentication interaction scenario; According to the authentication interaction scenario, the authentication result is obtained by interactive authentication between the first preset module and the second preset module, wherein the first preset module has a local authentication service function and a policy execution management function, and the second preset module has a unified authentication and fine-grained authorization function; In different authentication interaction scenarios, authorization and auditing are performed according to the authentication results to complete the switch authentication service.
2. The method according to claim 1, characterized in that The step of obtaining an authentication result by interactive authentication between the first preset module and the second preset module according to the authentication interaction scenario includes: When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, performing remote authentication dial-up user service interaction authentication through the first preset module and the second preset module to obtain an authentication result; When the authentication interaction scenario is an administrator login scenario, the terminal access controller access control system upgraded version interactive authentication is performed through the first preset module and the second preset module to obtain an authentication result.
3. The method according to claim 2, characterized in that When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, the step of performing remote authentication dial-up user service interaction authentication by the first preset module and the second preset module to obtain an authentication result includes: When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario, performing remote authentication dial-up user service interaction authentication based on the first preset module and the second preset module, triggering an extensible authentication protocol handshake; Encapsulate and forward the extensible authentication protocol message to the first preset container for account and password management; Querying user credentials or certificate library information in a second preset container; Interactive authentication is performed according to the extensible authentication protocol message and the user credential or certificate library to obtain an authentication result.
4. The method according to claim 2, characterized in that When the authentication interaction scenario is an administrator login scenario, the step of performing interactive authentication of the upgraded version of the terminal access controller access control system through the first preset module and the second preset module to obtain the authentication result includes: When the authentication interaction scenario is an administrator login scenario, detecting whether the administrator logs in through a secure shell protocol; After detecting that the administrator has logged in through the secure shell protocol, performing an interactive authentication of the upgraded version of the terminal access controller access control system based on the first preset module and the second preset module, triggering an authentication request; When detecting that the first preset container receives the authentication request, obtaining initial configurations of the first preset container and the third preset container; Authenticate the username / password according to the initial configuration to obtain an authentication result.
5. The method according to claim 1, characterized in that The steps of performing authorization and auditing according to the authentication results in different authentication interaction scenarios to complete the switch authentication service include: When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, returning an authorization response and issuing a dynamic virtual LAN policy; The dynamic virtual LAN policy is applied and the session is recorded in the audit log to complete the switch authentication service.
6. The method according to claim 5, characterized in that When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, the step of returning an authorization response and issuing a dynamic virtual LAN policy comprises: When the authentication interaction scenario is a remote authentication dial-up user service interaction scenario and the authentication result is authentication passed, returning an authorization response and a dynamic virtual LAN attribute, wherein the dynamic virtual LAN attribute is used for resource isolation; Obtaining a dynamic virtual LAN policy according to the dynamic virtual LAN attribute; The dynamic virtual LAN policy is issued.
7. The method according to claim 1, characterized in that The step of performing authorization and auditing according to the authentication results in different authentication interaction scenarios to complete the switch authentication service also includes: When the authentication interaction scenario is an administrator login scenario and the authentication result is authentication passed, loading a rights configuration file from a policy library and returning an authorization response; Generate a command whitelist according to the authorization response by controlling the command line interface engine, and execute user instructions according to the command whitelist; Encrypted storage operation execution records to complete switch authentication services.
8. An embedded server integrated system authentication device, characterized in that: The device comprises: A scenario determination module is used to select an authentication interaction scenario; An interactive authentication module, used to obtain an authentication result by interactive authentication through a first preset module and a second preset module according to the authentication interaction scenario, wherein the first preset module has a local authentication service function and a policy execution management function, and the second preset module has a unified authentication and fine-grained authorization function; The authorization and auditing module is used to perform authorization and auditing according to the authentication results in different authentication interaction scenarios to complete the switch authentication service.
9. An embedded server integrated system authentication device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the embedded server integrated system authentication method according to any one of claims 1 to 7.
10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the embedded server integrated system authentication method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Method for identification and deployment and management equipment thereof
CN101599834A
Management method and device for service quality
CN101695022A
Method and device for deploying authentication
CN102111289A
Enabling fine granular service chaining in a network-function virtualization architecture
CN108475206A
Distribution and management of services in virtual environments
CN110168504A