Multi-user management system based on communication management machine

By establishing a mapping relationship table between users, permission groups and processes in the communication management machine of the railway power supply monitoring system, the access rights management of different users is realized, and the security risks caused by the communication management machine being completely open to all users is solved, and the stability and security of the system are improved.

CN119995961APending Publication Date: 2025-05-13NANJING SAC RAIL TRAFFIC ENG CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510091024.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the railway power supply monitoring system, the communication management machine is completely open to all remotely accessed users, resulting in a security risk of network attacks. In severe cases, the communication management machine system will crash and cannot work properly.

Method used

Establish a mapping relationship table between users, permission groups and processes in the database. User-state processes query the user information table based on the process name to be started to determine the user running the process and the permission groups to which the process belongs, so that different users have different access rights.

Benefits of technology

It effectively solves the permission level problem caused by the remote access communication management machine in the railway power supply monitoring system, greatly enhances the security risk prevention capabilities of the integrated system in the institute, and improves the stability and security of the management machine.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995961A_ABST
    Figure CN119995961A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-user management system based on a communication management machine in the field of railway traction power supply systems. The multi-user management system comprises a user information management module which divides management machine users into root users, system users and common users; the user switching module is responsible for switching a running user of the process from a root user to a system user or a common user; the permission group setting module is used for adding the process into a corresponding permission group according to a current running user of the process; the user and the permission group are in a one-to-many relationship, and one process can join a plurality of permission groups; the root directory setting module is used for resetting the root directory after the user logs in when the user logs in the shell terminal, so that the root directory is different from the root directory during initialization starting; according to the invention, not only can the authority level problem caused by remote access to the communication management machine in the railway power supply monitoring system be effectively solved, but also the security risk prevention capability of the comprehensive automation system in the substation is greatly enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the field of railway traction power supply systems and is particularly applicable to a multi-user management system of a communication management machine in a railway power supply monitoring system. Background Art

[0002] In recent years, the automation and information construction of domestic railway power monitoring systems has shown a rapid and steady development trend. With the deep integration of informatization and automation, the railway power supply monitoring system has also developed rapidly in the direction of distribution and intelligence. More and more TCP / IP-based communication protocols and interfaces have been adopted, realizing the communication and control of the dispatching system and the substation integrated system, and realizing the interconnection and resource sharing of various subsystems. Since the communication management machine in the substation has to face data access from multiple external subsystems at the same time, such as the railway dispatching monitoring system, the power monitoring system of the local power supply bureau and the provincial power monitoring system, etc., the access rights level of each subsystem to the communication management machine in the substation is not fully considered, resulting in the communication management machine in the substation being completely open to all remote access users. There is a security risk of network attacks under this method, which may cause the communication management machine system to crash and fail to work normally in serious cases, and the communication of the entire railway power supply monitoring network will be interrupted. Summary of the invention

[0003] In view of the above technical problems, the purpose of the present invention is to provide a multi-user management system based on a communication management machine, which establishes a mapping relationship table between users, permission groups and processes in the database. The user state process queries the user information table according to the name of the process to be started to determine the user running the process and the permission group to which it belongs, so that different users have different access rights. It can not only effectively solve the permission level problem caused by remote access to the communication management machine in the railway power supply monitoring system, but also greatly enhance the security risk prevention capability of the integrated system.

[0004] To achieve the above objectives, the present invention is implemented through the following technical solutions: a multi-user management system based on a communication management machine, including a user information management module, a user switching module, a permission group setting module and a root directory setting module, and the four sub-function modules are provided in the form of a supporting interface for the process management module to call; The user information management module divides the management machine users into root users, system users and common users; The user switching module is responsible for switching the running user of the process from the root user to the system user or the ordinary user; The permission group setting module: adds the process to the corresponding permission group according to the current running user of the process; the relationship between users and permission groups is one-to-many, and one process can be added to multiple permission groups; The root directory setting module resets the root directory after the user logs in to the shell terminal to make it different from the root directory at the initial startup. After the user logs in to the shell terminal, the user cannot access other data of the management machine and can only perform operations with corresponding permissions under the configured running root directory.

[0005] The root user has the highest level of authority; system users and ordinary users are non-root users. Ordinary users are used for login access. The username, password and user group information of ordinary users are placed in the three files of passwd, shadow and group in the etc directory. When logging in remotely to access the management machine, the Login login process reads the user information for verification and authority configuration; system users are used for process operation, and a mapping relationship table between system users, authority groups and processes is established in the database, namely the user information table. According to the configuration in the user information table, different processes use different system users to run.

[0006] When using the FTP service to remotely access the communication management machine, the process management module queries the user information table to obtain the system user and permission group of the FTP process, and then the current running process starts the FTP child process and switches the current root user to the FTP system user in the child process. The started FTP child process inherits the permissions of the system user.

[0007] When the process of the management machine is called by a system user, the user switching module will switch the root user to the system user. Then the process management module will query the user information table according to the name of the process to be started to determine the user running the process and the permission group to which it belongs. Then, the user state process of the corresponding permission will be started through the system to achieve different access rights for different users.

[0008] When the called X process runs as the X user, the permission group setting module adds the X process to the permission group according to the permission group list found in the user information table, and then calls the exec() function to load the program file of the process.

[0009] The root directory setting module reconfigures the root directory after the user logs in, so that after the user logs in to the shell terminal, the user cannot access the system data of the management machine and can only perform operations with corresponding permissions under the configured root directory. The process user of the Telnet debugging process is an ordinary user, and its user information is stored in the corresponding module configuration table under the database. When the Telnet debugging process user calls the shell terminal process, the user information table will be queried according to the user information, and the shell terminal process with corresponding permissions of the user will be started.

[0010] Compared with the prior art, the present invention has the following beneficial effects: 1. The present invention effectively manages the resource usage of the system by dividing the process permissions. Each process has its own independent permissions and running directory, which prevents a process from excessively occupying resources and improves the stability and security of the management machine.

[0011] 2. The present invention can control the access rights of different users or processes to system resources through a sophisticated permission allocation strategy, thereby reducing potential security risks.

[0012] 3. The present invention realizes isolation between processes by configuring the mapping between users and processes. The user records can be used to more easily track the process running process, which is helpful for troubleshooting and solving faults.

[0013] 4. The present invention realizes the security of multi-user login and access of the communication management machine under the railway integrated system. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 This is a schematic diagram of the structure of a multi-user management system based on a communication management machine in this embodiment.

[0015] Figure 2 This is a schematic diagram of user information relationships in a multi-user management system based on a communication management machine in this embodiment.

[0016] Figure 3 This is a schematic diagram of process startup when users switch in the multi-user management system of this embodiment. DETAILED DESCRIPTION

[0017] The technical solution of the present invention is described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0018] like Figure 1 As shown in FIG. 1 , a schematic diagram of the structure of a multi-user management system based on a communication management machine in this embodiment includes four sub-function modules: user information management, user switching, permission group setting, and root directory setting. The sub-modules are provided in the form of supporting interfaces for the management process to call. The specific implementation method of the user information management module is as follows: Figure 2 As shown in the figure, the user information management module divides the users of the management machine into three categories: root users, system users and ordinary users. The root user has the highest level of root user authority; system users and ordinary users are non-root users. Ordinary users are used for login access. The username, password and user group information of ordinary users are respectively placed in the three files of passwd, shadow and group in the etc directory. When logging in to access the management machine, the Login process reads the user information for verification and permission configuration. It is used to log in to the management machine through the serial port.

[0019] When the process of the management machine is called by the system user, the user switching module will switch the root user to the system user, and then the management module will query the user information table according to the process name to obtain the system user and the permission group to which the process belongs. The process is as follows: Figure 3 As shown in the figure, when the called X process runs as the X user, the X process is added to the permission group according to the permission group list found in the user information table, and finally the exec() function is called to load the program file of the X process, which includes: 1. The process management module queries the user information table through the process name to obtain the user information of process X; 2. The process management module notifies the operating system to run process X; 3. Start the child process, namely the X process; 4. Switch users in the X process, from root user to X user; 5. Add the X process to the permission group; 6. Call the exec() function to load the program file of the X process.

[0020] The root directory setting module mainly reconfigures the root directory after the user logs in, so that after the user logs in to the shell terminal, he cannot access the system data of the management machine and can only perform operations with corresponding permissions under the configured root directory.

[0021] System users are used for process operation. A mapping table between system users, permission groups, and processes is established in the database, namely the user information table. The process management module queries the user information table according to the name of the process to be started to determine the user running the process and the permission group to which it belongs. Then, the system starts the user state process with corresponding permissions, so that different users have different access rights. However, the Telnet debugging process is slightly different. The user of this process is an ordinary user, and its user information is stored in the corresponding module configuration table under the database. When the Telnet debugging process user calls the shell terminal process, the user information table will be queried according to the user information, and the shell terminal process with corresponding permissions for the user will be started.

[0022] The setting of the user information table solves the problem that the current communication management machine process has too much permissions, which makes it easy for certain services run by users under the station, such as FTP services, to invade or change the services and configuration files under the running directory of the scheduling master station.

[0023] The user information is shown below: The above embodiments are only for explaining the technical idea of ​​the present invention, and cannot be used to limit the protection scope of the present invention. Any changes made on the basis of the technical solution according to the technical idea proposed by the present invention shall fall within the protection scope of the present invention. The technologies not involved in the present invention can be realized by existing technologies.

Claims

1. A multi-user management system based on a communication management machine, characterized in that: Including user information management module, user switching module, permission group setting module and root directory setting module. The four sub-function modules are provided in the form of supporting interfaces for the process management module to call; The user information management module divides the management machine users into root users, system users and common users; The user switching module is responsible for switching the running user of the process from the root user to the system user or the ordinary user; The permission group setting module: adds the process to the corresponding permission group according to the current running user of the process; the relationship between users and permission groups is one-to-many, and one process can be added to multiple permission groups; The root directory setting module: when a user logs in to the shell terminal, resets the root directory after the user logs in to make it different from the root directory at the time of initialization.

2. A multi-user management system based on a communication management machine according to claim 1, characterized in that: The root user has the highest level of authority as the root user; system users and ordinary users are non-root users. Ordinary users are used for login access. The username, password and user group information of ordinary users are respectively placed in the three files passwd, shadow and group under the etc directory. When logging in to access the management machine, the Login process reads the user information for verification and permission configuration; system users are used for process running, and a mapping relationship table between system users, permission groups and processes is established in the database, namely the user information table.

3. A multi-user management system based on a communication management machine according to claim 2, characterized in that: When the process of the management machine is called by a system user, the user switching module will switch the root user to the system user. Then the process management module will query the user information table according to the name of the process to be started to determine the user running the process and the permission group to which it belongs. Then, the user state process of the corresponding permission will be started through the system to achieve different access rights for different users.

4. A multi-user management system based on a communication management machine according to claim 2 or 3, characterized in that: When an external program or service accesses the management machine, the user switching process includes the following steps: Step 1: The process management module queries the user information table through the process name to obtain the user information of process X; Step 2: The process management module notifies the operating system to run process X; Step 3: Start the child process, namely the X process; Step 4: Switch users in the X process, from root user to X user; Step 5: Add the X process to the permission group; Step 6: Call the exec() function to load the program file of the X process.

5. The multi-user management system based on a communication management machine according to claim 1, characterized in that: The root directory setting module reconfigures the root directory after the user logs in, so that after the user logs in to the shell terminal, the user cannot access the system data of the management machine and can only perform operations with corresponding permissions under the configured root directory.

6. A multi-user management system based on a communication management machine according to claim 5, characterized in that: The process user of the Telnet debugging process is a common user, whose user information is stored in the Telnet account information configuration table of the corresponding module under the database. When the Telnet debugging process user calls the shell terminal process, the user information table is queried according to the user information, and the shell terminal process with the corresponding permissions of the user is started.

Citation Information

Cited By

  • Network account process permission level-to-level management method and device and storage medium

    CN120455100A