Password modification method and device, storage medium and electronic device

By determining the target server and the super account of the account to be modified in the basin machine, generating the target password and running the password task script, the problem of large password management load by basin machine is solved, centralized management and cluster-level password tasks are realized, and management load is reduced and security is improved.

CN119966633APending Publication Date: 2025-05-09CHINA CONSTRUCTION BANK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510064787.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

In the prior art, the independent management of the operation and maintenance account leads to the interruption of the connection between accounts, resulting in a huge pressure on password modification tasks, and the tasks that fail to modify due to various reasons have increased, resulting in excessive password management load.

Method used

By determining the target server and the super account of the account to be modified, a target password is generated and a password task script is generated based on this, using the super account to log in and run the script to batch modify the account password, realizing centralized management and cluster-level password tasks.

Benefits of technology

Through centralized management and cluster-level password tasks, it can effectively reduce the password management load, improve the success rate of password modification, reduce operation and maintenance costs, and improve the security of account passwords.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966633A_ABST
    Figure CN119966633A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a password modification method and device, a storage medium and an electronic device, and the method comprises the steps: determining a target server of a to-be-modified account password indicated by a received password task, and determining a first account of the to-be-modified password of the target server, the first account is an account included in other accounts, except the first super account, of the target server, and the first super account is a management account of the target server; generating a target password for each first account; generating a password task script based on the target password; and when the number of the target server is one, logging in a first super account of the target server, and after the first super account is successfully logged in, running the password task script to modify the password of the first account into the target password. According to the method and the device, the problem of large password management load in the prior art is solved, and the effect of reducing the password management load is further achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of communications, and in particular, to a password modification method, device, storage medium and electronic device. Background Art

[0002] In the related art, bastion host password management is based on independent management of each operation and maintenance account at the smallest granularity. However, with the rapid expansion of the operation and maintenance scale, the method of independent account management severs the natural connection between the operation and maintenance accounts. In addition, there are tasks that cannot be successfully modified in one go due to various reasons, or tasks that fail to be modified due to abnormal changes in account passwords during the operation and maintenance process. There are also additional accumulated password tasks that need to be executed, so the password modification task is extremely stressful.

[0003] It can be seen from this that the related technology has the problem of heavy password management load.

[0004] With respect to the above-mentioned problems existing in the related technologies, no effective solution has been proposed yet. Summary of the invention

[0005] The embodiments of the present invention provide a password modification method, device, storage medium and electronic device to at least solve the problem of heavy password management load in the related art.

[0006] According to one embodiment of the present invention, a password modification method is provided, comprising: determining a target server of an account password to be modified indicated by a received password task, and determining a first account of the target server whose password is to be modified, wherein the first account is an account included in other accounts of the target server except a first super account, and the first super account is a management account of the target server; generating a target password for each of the first accounts; generating a password task script based on the target password; when the number of the target servers is one, logging in to the first super account of the target server, and after successfully logging in to the first super account, running the password task script to modify the password of the first account to the target password.

[0007] In an exemplary embodiment, generating a target password for each of the first accounts includes: determining the password complexity corresponding to each of the first accounts indicated by the password task; and generating the target password for each of the first accounts according to the password complexity.

[0008] In an exemplary embodiment, generating the target password for each first account according to the password complexity includes: when the password complexity corresponding to the first account is a random password, generating the target password for the first account in a random manner; when the password complexity corresponding to the first account is a formulated password, generating the target password according to a formulation rule of the formulated password.

[0009] In an exemplary embodiment, the method further includes: when there are multiple target servers and the multiple target servers belong to the same cluster, determining the master node included in the target cluster where the target server is located; when there is only one master node, logging in to the second super account of the master node, and when the login to the second super account is successful, running the password task script to modify the password of the first account to the target password; when there are multiple master nodes, logging in to the third super account of the first master node included in the master nodes, and when the login to the third super account is successful, running the password task script to modify the password of the first account to the target password.

[0010] In an exemplary embodiment, after logging in to a third super account of a first master node included in the master nodes, the method further includes: in case that logging in to the third super account fails, performing a target operation; wherein the target operation includes: logging in to a fourth super account of a second master node included in the master nodes, and in case that logging in to the fourth super account succeeds, running the password task script to modify the password of the first account to the target password, wherein the second master node is another master node included in the master nodes except the first master node; controlling the second master node to log in to a fifth super account, and performing a password collection operation on the fifth super account, wherein the fifth super account is a super account for which login failed; and performing the target operation in case that logging in to the fourth super account fails.

[0011] In an exemplary embodiment, determining the first account of the target server whose password is to be modified includes: determining all second accounts of the target server; and determining an account whose account type is a password modification type included in the second accounts as the first account.

[0012] In an exemplary embodiment, after determining all the second accounts of the target server, the method further includes: determining that the account type included in the second accounts is a third account of a type of temporarily canceling and modifying the password; determining a deadline for canceling and modifying the password of the third account; before the deadline is reached, modifying the password of the third account to a preset password; and when the deadline is reached, modifying the account type of the third account to a type of modifying the password.

[0013] In an exemplary embodiment, the method further includes: obtaining an operation and maintenance account list generated by the first super account, wherein the operation and maintenance account list includes accounts whose passwords are to be modified; obtaining a special account list of the target server whose account type is a type for canceling password modification; and determining whether there are risky accounts on the target server based on the operation and maintenance account list and the special account list.

[0014] According to another embodiment of the present invention, a password modification device is provided, comprising: a determination module, used to determine a target server of an account password to be modified indicated by a received password task, and to determine a first account of the target server whose password is to be modified, wherein the first account is an account included in other accounts of the target server except a first super account, and the first super account is a management account of the target server; a first generation module, used to generate a target password for each of the first accounts; a second generation module, used to generate a password task script based on the target password; and a modification module, used to log in to the first super account of the target server when the number of the target servers is one, and after successfully logging in to the first super account, run the password task script to modify the password of the first account to the target password.

[0015] According to yet another embodiment of the present invention, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps of any one of the above method embodiments when run.

[0016] According to yet another embodiment of the present invention, there is provided an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0017] According to yet another embodiment of the present invention, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps of the method described in each embodiment of the present application are implemented.

[0018] Through the present invention, after receiving the password task instruction, the target server of the account password to be modified and the first account other than the super account for managing the account whose password is to be modified in the target server can be determined, and a target password can be generated for each first account. Based on the target password, a corresponding password task script can be generated. When the number of target servers is one, the first super account can be logged in. After successfully logging in to the first super account, the password task script can be run to modify the password of the first account to the target password through the first super account. Since the passwords of other accounts except the first super account can be modified in batches by logging in to the first super account in the target server, the problem of large password management load existing in the related art can be solved, and the effect of reducing the password management load can be achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 is a hardware structure block diagram of a mobile terminal according to a password modification method of an embodiment of the present invention;

[0020] Figure 2 is a flow chart of a method for modifying a password according to an embodiment of the present invention;

[0021] Figure 3 is a schematic diagram of the working principle of centralized management tasks according to an embodiment of the present invention;

[0022] Figure 4 is a schematic diagram of implementing temporary cancellation of collection according to an embodiment of the present invention;

[0023] Figure 5 4 is a structural block diagram of a password modification device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0024] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings and in combination with the embodiments.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0026] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 FIG. 1 is a hardware structure diagram of a mobile terminal of a password modification method according to an embodiment of the present invention. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is for illustration only and does not limit the structure of the mobile terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.

[0027] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the password modification method in the embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the mobile terminal via a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0028] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0029] In this embodiment, a method for modifying a password is provided. Figure 2 is a flow chart of a method for modifying a password according to an embodiment of the present invention, such as Figure 2 As shown, the process includes the following steps:

[0030] Step S202, determining a target server of the account password to be modified indicated by the received password task, and determining a first account of the target server whose password is to be modified, wherein the first account is an account included in other accounts of the target server except the first super account, and the first super account is a management account of the target server;

[0031] Step S204, generating a target password for each of the first accounts;

[0032] Step S206, generating a password task script based on the target password;

[0033] Step S208, when the number of the target server is one, log in to the first super account of the target server, and after successfully logging in to the first super account, run the password task script to modify the password of the first account to the target password.

[0034] In the above embodiment, the target server may be an operation and maintenance server, and the password task may be understood as a management unit for periodically or irregularly modifying the passwords of accounts in the operation and maintenance server, and an operation and maintenance server includes a super account (i.e., the first super account) and multiple operation and maintenance accounts (i.e., the first account). Therefore, when receiving a password task instruction, the operation and maintenance account whose password is to be modified included in the target server of the account whose password is to be modified may be determined. Among them, the target server may be one or more. The super account may be understood as the highest authority account in the operation and maintenance server, which may directly modify the passwords of all operation and maintenance accounts of the server, and the old password is not required during the modification process.

[0035] In the above embodiment, the credential management module included in the password management platform can synchronously create corresponding credentials according to the password task instruction, that is, the core of credential management can be the generation of new passwords, where the credentials are account-level, each account corresponds to a credential, and the account and the credential are in a one-to-one correspondence. When the account password needs to be modified, the credential management module can generate a target password for each first account to be modified. The modification process can be seen in Figure 3 , Figure 3 Schematic diagram of the working principle of centralized management tasks according to an embodiment of the present invention. Figure 3As shown, taking a Linux server as an example, the super account can be root, the first account can be application account A1, application monitoring account A2, operating system monitoring account A3, middleware account A4 and tool account A5. When the passwords of application account A1, application monitoring account A2, operating system monitoring account A3, middleware account A4 and tool account A5 in the first account need to be modified, the credential module will generate a target password for each account, and pass the target password as a parameter to the task module (and the above-mentioned password task), and the task module can generate a password task script according to the target password. Among them, the target password of each account can be determined by a random password generated by the credential module.

[0036] In the above embodiment, when the number of target servers to be modified is one, all non-super accounts of the target server can be subjected to server-level centralized management tasks, that is, the first super account of the target server can be directly logged in, and the first account other than the super account can be modified by the method of "super account batch modification", that is, after successfully logging in to the first super account, the process of root batch modification of the first account password to the target password can be executed on the target server through the collection template (i.e. the above password task script), and the account password can be updated to the target password if the modification is successful, and the old password is maintained if the modification fails. Among them, running the password task script can be understood as remotely logging in to the target server through the access server of the password collection management platform through ssh (secure shell, secure shell protocol) and other protocols, and then executing the script content on the target server to complete the process of password modification task. After logging in to the super account in the target server, the super account and non-super account password modification commands, such as passwd applaud, can be executed to realize the password modification of the applaud account. In the case of a modification failure, the password task script can return a failure reminder and interrupt the exit. In the platform's front-end - password task management view, the corresponding password task will have a "failed" task status and will give a reminder of the reason for the failure. In addition, a failure record can be generated in the password modification history record, which can be queried in the platform system. When a task fails, a prompt message will be generated synchronously and pushed to the administrator of the password collection management platform, so that it can be discovered and tracked in time. For situations where automatic modification fails, a default re-run mechanism can also be set to resolve failures caused by occasional reasons such as network fluctuations. Whether the target password cannot be generated or the modification operation fails, it will be included in the password task execution failure, and the administrator of the password collection management platform can discover it in time. If manual triggering still fails, take appropriate emergency measures depending on the situation: In non-emergency situations, the password collection administrator can check whether there are any problems with the password collection configuration. If there are any problems, they can make corrections and try again. If there are no problems, they can report the problems to the responsible party of the operation and maintenance account, and both parties will work together to solve the problem. In emergency situations, the password administrator can directly cancel the collection of passwords temporarily, that is, clear the passwords, and restore the operation and maintenance personnel to manually enter the password to log in, so that the operation and maintenance personnel can log in to the machine normally after resetting the password in an emergency, and then collect the password again.

[0037] In the above embodiment, the security of the password modification operation mainly depends on network security, which is usually limited to the unit's intranet, that is, a network access relationship is opened separately for the password collection management platform; in addition, the accuracy of the password task script will also affect the security of the password modification operation. In order to ensure that no script bugs occur, the password task scripts of the password collection management platform are fully tested and verified before being allowed to be used, and can also be continuously iterated and updated according to the upgrading of the operation and maintenance machines.

[0038] Through the present invention, after receiving the password task instruction, the target server of the account password to be modified and the first account other than the super account for managing the account whose password is to be modified in the target server can be determined, and a target password can be generated for each first account. Based on the target password, a corresponding password task script can be generated. When the number of target servers is one, the first super account can be logged in. After successfully logging in to the first super account, the password task script can be run to modify the password of the first account to the target password through the first super account. Since the passwords of other accounts except the first super account can be modified in batches by logging in to the first super account in the target server, the problem of large password management load existing in the related art can be solved, and the effect of reducing the password management load can be achieved.

[0039] Optionally, the execution subject of the above steps can be a bastion host, or any device with the same function, but is not limited thereto.

[0040] In an exemplary embodiment, generating a target password for each of the first accounts includes: determining the password complexity corresponding to each of the first accounts indicated by the password task; and generating the target password for each of the first accounts according to the password complexity.

[0041] In the above embodiment, according to the needs in different scenarios, the credential management module can set the generation rule of the target password by the password complexity, that is, the value of the target password can be controlled by the password complexity. After receiving the password complexity corresponding to each first account indicated by the password task, the credential management module can generate a target password for each first account according to different password complexities. In addition, the password complexity can also be manually configured according to needs. Setting different password complexities and combining flexible password task management can greatly improve the flexibility of password management, and can improve operation and maintenance efficiency, password collection coverage, and the convenience and security of operation and maintenance.

[0042] In an exemplary embodiment, generating the target password for each first account according to the password complexity includes: when the password complexity corresponding to the first account is a random password, generating the target password for the first account in a random manner; when the password complexity corresponding to the first account is a formulated password, generating the target password according to a formulation rule of the formulated password.

[0043] In the above embodiment, the password complexity may include a random password, i.e., a password with a random value that meets the password security management requirements in the normal mode; the password complexity may also include a formulated password, i.e., a password that can be set according to the requirements in the special mode, and its password composition, length, etc. can be customized, and can also be set as a specified value password. For example: the password required for a certain type of machine can only be 8 bits in length, and only uppercase letters and numbers are allowed, then the customized special password rule can be UUUUNNNN%, where U can represent random uppercase letters (AZ), N can represent random numbers (0-9), and the last % can represent random generation, i.e., "UUUUNNNN%" can represent a random password with a length of 8 bits of 4 uppercase letters and 4 numbers. The random password in the normal mode is usually set to a password with a length of 10 bits, including uppercase (U), lowercase (L), numbers (N) and special symbols (D), i.e., it can be UULLLNNNDD%.

[0044] In the above embodiment, the designated value password can be understood as the generation rule of the password in extreme cases. Usually, the designated value password is provided by the operator, and its security and uniqueness are reviewed by the administrator of the password management platform to ensure that the password complexity meets the basic requirements in terms of length and composition. To avoid the possibility of password reuse, the password management platform can combine common weak passwords and used designated value passwords into a common password library. New designated value passwords need to be stored in the library for comparison before use, and can only be used if they are confirmed to be not in the library.

[0045] In the above embodiment, the credential management module can also set a single or multiple password complexities for the operation and maintenance account, wherein a single password complexity can be understood as generating a target password according to the same rules for each password modification, and multiple password complexities can be understood as a round-robin mode, that is, automatically switching to the next password complexity after each password modification, and can also support custom sorting. Example: Configure the specified value passwords of the two password complexities of password-comp1 and password-comp2, which can be recorded as password1 and password2 respectively. When the sorting is the default, the target password of the account becomes password1 after the first successful password modification, the target password after the second successful password modification is password2, and the target password after the third successful password modification is password1... and so on.

[0046] In the above embodiment, in actual operation and maintenance work, due to special reasons such as server manufacturer reasons or system operation characteristics, there are usually special operation and maintenance accounts whose plain text passwords need to be mastered by a very small number of operation and maintenance administrators, and the same-name operation and maintenance accounts between batches of servers must maintain the same target password. The operation and maintenance party must manage the passwords of such accounts by themselves, and not only must they manually change the passwords regularly, but they must also inform other operation and maintenance personnel who need to use the account but do not need to know the plain text password of the plain text password, which forces them to expand the scope of people who know the target password, posing a password security risk. However, by setting different password complexities, the passwords of such special accounts can be collected. For example, when modifying the passwords of special accounts on a server, the historical passwords used in the past 10 times are not allowed to be used. In this case, all special accounts on the server can be set to passwords with specified values ​​of password complexity, including password-comp1, password-comp2...passwd-comp11, which can be recorded as password1, password2...password11, and sorted in ascending order of the suffix numbers. Then, after the first password modification, the target password of the account becomes password1, and after the second password modification, the target password of the account becomes password2..., and so on. The set password task cycle, the specified password value, and the sorting are all provided by the operation and maintenance party. The initial password modification is performed on the date specified by the operation and maintenance party. In this way, the operation and maintenance party can accurately grasp the plain text password change rules of the special accounts on the server, and they are always consistent. It not only meets the specific operation and maintenance needs of special accounts, but also collects account passwords that were originally not supported. It also saves the operation and maintenance party from the burden of regularly resetting passwords. It breaks the existing technical limitations and requires the operation and maintenance to master the plain text passwords to collect special account passwords, ensures the minimum knowledge scope of the plain text passwords, and improves the security of account passwords.

[0047] In an exemplary embodiment, the method further includes: when there are multiple target servers and the multiple target servers belong to the same cluster, determining the master node included in the target cluster where the target server is located; when there is only one master node, logging in to the second super account of the master node, and when the login to the second super account is successful, running the password task script to modify the password of the first account to the target password; when there are multiple master nodes, logging in to the third super account of the first master node included in the master nodes, and when the login to the third super account is successful, running the password task script to modify the password of the first account to the target password.

[0048] In the above embodiment, when there are multiple target servers, the first account under all target servers in the same cluster (i.e., the above target cluster) can also be modified through the cluster-level centralized management mode. Clustered operation and maintenance is a common operation and maintenance method for large-scale information systems. Since the servers in the same cluster can communicate with each other, the account can be modified by determining the master node in the target cluster, that is, other servers can be directly accessed without a password through the master node. Among them, the master node can be determined by the operation and maintenance party, and the password management platform implements password collection management for the cluster, that is, before collecting in a cluster manner, the master node machine information (such as IP information) of the cluster needs to be entered first, and the machine information of the master node can be directly provided by the operation and maintenance party.

[0049] In the above embodiment, the master node can be set to one or more. When there is one master node, the super account in the master node target server (i.e., the second super account) can be logged in. If the login is successful, the execution of the server-level centralized management task can be completed directly with this master node super account, that is, the passwords of all first accounts in the target cluster are modified to the target password through the password task script. When there are multiple master nodes, the super account in the first master node target server (i.e., the third super account) can be logged in. If the login is successful, the passwords of all first accounts in the target cluster can be modified to the target password through the password task script. Example: There is a cluster of 100 servers with 3 master nodes. Then the password task of cluster-level centralized management can be to set the super accounts of the 3 master node servers as a set. When the cluster-level centralized management password task is executed, the first master node super account can be logged in first according to the set order. If the login is successful, the execution of the server-level centralized management task can be completed directly with this master node super account, and then the other server super accounts of the cluster are logged in in sequence to complete the password modification of all accounts including the super account.

[0050] In an exemplary embodiment, after logging in to a third super account of a first master node included in the master nodes, the method further includes: in case that logging in to the third super account fails, performing a target operation; wherein the target operation includes: logging in to a fourth super account of a second master node included in the master nodes, and in case that logging in to the fourth super account succeeds, running the password task script to modify the password of the first account to the target password, wherein the second master node is another master node included in the master nodes except the first master node; controlling the second master node to log in to a fifth super account, and performing a password collection operation on the fifth super account, wherein the fifth super account is a super account for which login failed; and performing the target operation in case that logging in to the fourth super account fails.

[0051] In the above embodiment, if the login to the third super account in the first master node fails, the super account of the second master node (i.e., the fourth super account) can be automatically tried. If the login is successful, the passwords of all the first accounts in the cluster can be modified to the target password through the password task script. The super account of the master node where the last login failed (i.e., the fifth super account) can be immediately logged in without password, and the password of the fifth super account can be collected to restore the validity of the fifth super account. After that, the password collection of all accounts in the entire cluster can be completed. Therefore, as long as not all the master nodes in the target cluster cannot be logged in, the password management of the entire cluster can be guaranteed to operate normally.

[0052] In the above embodiment, when the first master node fails to log in successfully, the password collection template will receive a login failure flag return value, and can start trying to log in to the second master node according to the judgment branch. If it fails, it will try to log in to the third master node again, until the last master node is tried. The detection of failed or successful login can be implemented by the password collection template script, for example: expect statement, etc. If all master nodes cannot log in, the password management platform will give an alarm prompt, for example: "Password collection cannot be completed" or "Password abnormal, please deal with it in time". After reviewing and confirming the alarm prompt, the problem can be fed back to the cluster operation and maintenance party in time. The cluster operation and maintenance party can be responsible for password reset and other related disposal work. When it is confirmed that the master node password is normal and can be logged in normally, the password collection can be re-implemented.

[0053] In an exemplary embodiment, determining the first account of the target server whose password is to be modified includes: determining all second accounts of the target server; and determining an account whose account type is a password modification type included in the second accounts as the first account.

[0054] In the above embodiment, after the server account is managed, the task module can simultaneously create two types of password tasks, namely super account password tasks and centralized management tasks. The super account password task can be understood as a one-time task, and each server's super account corresponds to a super account password task. The centralized management task can be understood as a periodic task, and all the accounts of each server except the super account (i.e., the second account mentioned above) are included in the centralized management task as the first account to be modified. Since the super account password task is a manual trigger mode, and its password should not be modified frequently, the password is rarely modified after it is collected, so the focus of password task management is non-super accounts, that is, periodic tasks.

[0055] In an exemplary embodiment, after determining all the second accounts of the target server, the method further includes: determining that the account type included in the second accounts is a third account of a type of temporarily canceling and modifying the password; determining a deadline for canceling and modifying the password of the third account; before the deadline is reached, modifying the password of the third account to a preset password; and when the deadline is reached, modifying the account type of the third account to a type of modifying the password.

[0056] In the above embodiment, for a small number of accounts with special needs, they can be removed from the centralized management task, and an independent task can be created separately to manage the password. Among them, special accounts can be understood as accounts for which the operation and maintenance party has special requirements for the password value during the password collection management process. It can be decided before the password is collected, or it can be temporarily decided to change after the password is collected. When the operation and maintenance party determines that a certain account has special password requirements, the account can be "marked". For example: a switch field can be set in the account credential management, with a value of 1 or 0. The default value 0 can be represented as a normal account, and 1 can be represented as a special account; when the value is 1, the validity period setting can automatically appear (the format is generally the start and end date and time, such as December 1, 2024 0:00-December 31, 2024 23:59, the default default is long-term validity). When the switch field is assigned a value of "1", a validity period limit can be set synchronously. When the time exceeds the validity period, the value of the switch field can automatically change to "0", and the special demand account is restored to a normal account. If the operation and maintenance party's requirements are completed ahead of schedule, you can also manually modify the value of the switch field to "0" to restore the special demand account to a normal account.

[0057] In the above embodiment, the independent management of special accounts can be divided into temporary special management and long-term special management, where temporary special management can be understood as time-limited management, that is, within a certain time limit, this special demand account can be removed from the centralized management task and a separate independent task can be created. Once the time limit is reached, the independent task will be automatically deleted, and the special demand account can be automatically re-included in the original centralized management task for password management. Long-term special management can be understood as management without a time limit, that is, the account independent management task is valid for a long time.

[0058] In the above embodiment, when there is a special account (i.e., the third account mentioned above) that needs to temporarily cancel the password modification, this account can be removed from the centralized management task, and the deadline for canceling the password modification for this special account is determined, and a preset password is created for it with a time limit of the deadline. Once the time limit is over, this special account will be included in the centralized management task again. Taking a Linux server as an example, the super account is root, the account to be temporarily canceled is the application privileged account A1, and the deadline for temporarily canceling the collection is yyyy-mm-dd (i.e., the above deadline). The process of temporarily canceling the collection of the application privileged account A1 can be seen in Figure 4 , Figure 4 is a schematic diagram of temporarily canceling collection according to an embodiment of the present invention, such as Figure 4 As shown, you can temporarily remove the special account A1 from the centralized management task and create an independent one-time task with a temporary time limit set to yyyy-mm-dd. At the same time, configure a specific password generation rule-specified value, and manually perform a password modification to make the modified password the specified password for operation and maintenance (i.e. the preset password mentioned above). After the time limit, account A1 will be automatically included in the centralized management task again, and the corresponding one-time task will be automatically deleted. Adjust the password complexity of the A1 credential to the default random rule, and perform a password modification again to complete the password re-collection. The whole process is convenient and seamless, which not only saves the operation and maintenance costs of applying for password reset and password re-collection by the operation and maintenance party, but also ensures the continuity of the effective password of the operation and maintenance server account, effectively improving the security of operation and maintenance.

[0059] In an exemplary embodiment, the method further includes: obtaining an operation and maintenance account list generated by the first super account, wherein the operation and maintenance account list includes accounts whose passwords are to be modified; obtaining a special account list of the target server whose account type is a type for canceling password modification; and determining whether there are risky accounts on the target server based on the operation and maintenance account list and the special account list.

[0060] In the above embodiment, in order to ensure the security of operation and maintenance, all operation and maintenance accounts should be included in the management of the secure operation and maintenance bastion host, and all managed operation and maintenance accounts should also receive passwords. When executing the password task, the super account can be used to obtain the full list of machine operation and maintenance accounts and generate a report. Only one command needs to be executed and embedded in the password task script to complete the query. For example: For a Linux server, after logging in to the root of the target machine, the "cat / etc / passwd" command can be executed to view all account information of the machine (account name, etc.). In addition, the full list report of the operation and maintenance account and the special case approval and filing account list report can be compared regularly. The managed accounts under the same target server can be placed in a set X for password modification; during the execution of the password task, the full account information can be obtained after logging in to the target server and a temporary list can be generated. The accounts in this temporary list are compared with the managed account set X. If the account in the temporary account list is in set X, it can be considered that the management is completed; if it is not in set X, it is considered that the account should be managed but is not managed. You can also put the list of collected accounts into another set Y and perform similar comparisons to obtain a list of accounts receivable but not collected. This means that you can automatically check whether there are any operation and maintenance accounts that should be managed but are not, and whether there are any operation and maintenance account passwords that should be collected but are not. The generated result report can be used for audit inspections, which can effectively control operation and maintenance risks and further improve operation and maintenance safety.

[0061] In the above embodiment, the detected lists of accounts that should be managed but are not, and accounts that should be receivable but are not collected, can be automatically added to the report of accounts that should be managed but are not, and the report of accounts that should be receivable but are not collected, and timestamped. When there is new data in the above two types of reports, a prompt message can be generated synchronously and pushed to the administrator of the password collection management platform so that subsequent rectification can be discovered and completed in time. The administrator can view the special account ledger and related setting information through the report function, and can also view the validity period settings of special accounts based on the historical operation logs retained in the database. In addition, risk accounts can also be automatically checked regularly. When it is checked that the risk account has been rectified (collected), the risk account report can automatically remove the relevant data, and can also be manually updated.

[0062] In the above-mentioned embodiment, the super account of the target server is used to manage the passwords of all accounts of the server, which can make full use of the correlation between accounts, and the effect of summarizing the main points can make the password management work more targeted, more efficient and safer. For non-super accounts, the number of password tasks can be greatly reduced by using server-level or even cluster-level password tasks, especially the number of periodic tasks, which significantly reduces the load of password management. It is also possible to solve the problem of invalid and expired passwords of non-super accounts by only manually performing a password modification once, and reset the problem account to restore the operation and maintenance login to normal. In addition, the use of super accounts for password modification has a higher success rate. As long as the super account password is correct, the password of the modified account can be successfully modified regardless of whether it is right or wrong. This mechanism of changing passwords for high-authority accounts naturally ensures that the password modification success rate is extremely high, and the password collection template used in the modification process is also unified, and there is no need to configure a dedicated collection template for the remaining accounts separately. Each password modification process is a verification of the validity of the super account password, which guarantees the data quality of the offline backup of the super account password. Since there is a password verification script after the password is modified in the password task script, the execution of the password task itself is a verification process of the password validity. The method of using a super account to modify the password of a non-super account, that is, the periodic modification of the non-super account, is to periodically verify the validity of the super account password.

[0063] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present invention.

[0064] In the present embodiment, a password modification device is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made are omitted. As used below, the term "module" can implement a combination of software and / or hardware of a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0065] Figure 5 is a structural block diagram of a password modification device according to an embodiment of the present invention, such as Figure 5 As shown, the device comprises:

[0066] The determination module 52 is used to determine the target server of the account password to be modified indicated by the received password task, and determine the first account of the target server whose password is to be modified, wherein the first account is an account included in other accounts of the target server except the first super account, and the first super account is the management account of the target server;

[0067] A first generating module 54, configured to generate a target password for each of the first accounts;

[0068] A second generating module 56, for generating a password task script based on the target password;

[0069] The modification module 58 is used to log in to the first super account of the target server when the number of the target server is one, and after successfully logging in to the first super account, run the password task script to modify the password of the first account to the target password.

[0070] In an exemplary embodiment, the first generation module 54 can generate a target password for each of the first accounts in the following manner: determine the password complexity corresponding to each of the first accounts indicated by the password task; and generate the target password for each of the first accounts according to the password complexity.

[0071] In an exemplary embodiment, the first generation module 54 can generate the target password for each first account according to the password complexity in the following manner: when the password complexity corresponding to the first account is a random password, the target password is generated for the first account in a random manner; when the password complexity corresponding to the first account is a formulated password, the target password is generated according to the formulated rules of the formulated password.

[0072] In an exemplary embodiment, the protection device can also be used for: when there are multiple target servers and the multiple target servers belong to the same cluster, determining the master node included in the target cluster where the target server is located; when there is only one master node, logging in to the second super account of the master node, and when the login to the second super account is successful, running the password task script to modify the password of the first account to the target password; when there are multiple master nodes, logging in to the third super account of the first master node included in the master nodes, and when the login to the third super account is successful, running the password task script to modify the password of the first account to the target password.

[0073] In an exemplary embodiment, the device can also be used to, after logging in to a third super account of a first master node included in the master nodes: if logging in to the third super account fails, perform a target operation; wherein the target operation includes: logging in to a fourth super account of a second master node included in the master nodes, and if logging in to the fourth super account is successful, run the password task script to modify the password of the first account to the target password, wherein the second master node is another master node included in the master nodes except the first master node; control the second master node to log in to a fifth super account, and perform a password collection operation on the fifth super account, wherein the fifth super account is a super account for which login failed; and perform the target operation if logging in to the fourth super account fails.

[0074] In an exemplary embodiment, the determination module 52 can determine the first account of the target server whose password is to be modified by: determining all second accounts of the target server; and determining the account whose account type is the password modification type included in the second accounts as the first account.

[0075] In an exemplary embodiment, the device can also be used to, after determining all the second accounts of the target server: determine that the account type included in the second accounts is a third account of the temporarily canceled password modification type; determine a deadline for canceling the password modification of the third account; before the deadline is reached, modify the password of the third account to a preset password; when the deadline is reached, modify the account type of the third account to a password modification type.

[0076] In an exemplary embodiment, the device can also be used to: obtain an operation and maintenance account list generated by the first super account, wherein the operation and maintenance account list includes accounts whose passwords are to be modified; obtain a special account list of the target server whose account type is a type for canceling password modification; and determine whether there are risky accounts on the target server based on the operation and maintenance account list and the special account list.

[0077] It should be noted that the above modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.

[0078] An embodiment of the present invention further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.

[0079] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0080] An embodiment of the present invention further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0081] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0082] An embodiment of the present invention further provides a computer program product, including a computer program, which implements the steps of the method in each embodiment of the present application when the computer program is executed by a processor.

[0083] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0084] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.

[0085] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for modifying a password, characterized in that: include: Determine a target server of the account password to be modified indicated by the received password task, and determine a first account of the target server whose password is to be modified, wherein the first account is an account included in other accounts of the target server except the first super account, and the first super account is a management account of the target server; generating a target password for each of the first accounts; Generate a password task script based on the target password; When the number of the target server is one, log in to the first super account of the target server, and after successfully logging in to the first super account, run the password task script to modify the password of the first account to the target password.

2. The method according to claim 1, characterized in that Generating a target password for each of the first accounts includes: Determine the password complexity corresponding to each of the first accounts indicated by the password task; The target password is generated for each of the first accounts according to the password complexity.

3. The method according to claim 2, characterized in that Generating the target password for each first account according to the password complexity includes: In a case where the password complexity corresponding to the first account is a random password, generating the target password for the first account in a random manner; When the password complexity corresponding to the first account is a formulated password, the target password is generated according to a formulation rule of the formulated password.

4. The method according to claim 1, characterized in that: The method further comprises: In the case that there are multiple target servers and the multiple target servers belong to the same cluster, determining a master node included in the target cluster where the target server is located; In the case where there is only one master node, log in to a second super account of the master node, and when the login to the second super account is successful, run the password task script to modify the password of the first account to the target password; In the case where there are multiple master nodes, log in to a third super account of a first master node included in the master nodes, and if the login to the third super account is successful, run the password task script to modify the password of the first account to the target password.

5. The method according to claim 4, characterized in that After logging into a third super account of a first master node included in the master nodes, the method further includes: In case of a failure in logging into the third super account, executing the target operation; The target operation includes: logging into a fourth super account of a second master node included in the master nodes, and, if the login to the fourth super account is successful, running the password task script to modify the password of the first account to the target password, wherein the second master node is another master node included in the master nodes except the first master node; Control the second master node to log in to a fifth super account, and perform a password collection operation on the fifth super account, wherein the fifth super account is the super account that fails to log in; In the case where logging into the fourth super account fails, performing the target operation.

6. The method according to claim 1, characterized in that Determining a first account of the target server whose password is to be modified includes: Determine all second accounts of the target server; An account whose account type is a password modification type included in the second account is determined as the first account.

7. The method according to claim 6, characterized in that After determining all second accounts of the target server, the method further includes: Determining that the account type included in the second account is a third account of a type of temporarily canceling the password modification; Determining a deadline for canceling and modifying the password of the third account; Before the deadline, the password of the third account is changed to a preset password; When the deadline is reached, the account type of the third account is changed to a password-modified type.

8. The method according to claim 1, characterized in that The method further comprises: Obtaining an operation and maintenance account list generated by the first super account, wherein the operation and maintenance account list includes an account whose password is to be modified; Obtain a list of special accounts of the target server whose account type is a type that cancels password modification; Determine whether the target server has a risky account based on the operation and maintenance account list and the special account list.

9. A password modification device, characterized in that: include: a determination module, configured to determine a target server of the account password to be modified indicated by the received password task, and determine a first account of the target server whose password is to be modified, wherein the first account is an account included in other accounts of the target server except the first super account, and the first super account is a management account of the target server; A first generating module, used to generate a target password for each of the first accounts; A second generating module, used for generating a password task script based on the target password; The modification module is used to log in to the first super account of the target server when the number of the target server is one, and after successfully logging in to the first super account, run the password task script to modify the password of the first account to the target password.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program is configured to execute the method according to any one of claims 1 to 8 when executed.

11. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 8.

12. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.