Instruction permission obtaining method and device of network equipment, equipment and medium

By obtaining user permission levels in network devices and performing permission checks, combined with the authorization decision processing of the authentication server, the problem of network equipment security risks is solved, and higher security and reliability are achieved.

CN119995990APending Publication Date: 2025-05-13INSPUR NETWORK TECH (SHANDONG) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510145891.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Existing network devices lack effective permission management mechanisms, resulting in security risks such as unauthorized access, malicious attacks, and data breaches.

Method used

By obtaining the permission level of the specified user, perform permission checks to run the instructions, and sending the instructions to the authentication server for authorization decision processing, ensuring that only verified and authorized instructions will be executed.

Benefits of technology

Effectively prevent unauthorized access, reduce the risks of malicious attacks and data leakage, enhance the security protection capabilities of network devices, and ensure that users can only access and operate resources within their permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995990A_ABST
    Figure CN119995990A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an instruction permission obtaining method and device of network equipment, equipment and a medium, and the method comprises the steps: obtaining an operation instruction input by a specified user in terminal equipment, and the operation instruction is used for accessing the corresponding network equipment; determining the authority level of the specified user; on the basis of the permission level of the specified user, performing permission check on the execution requirement of the operation instruction; if the authority level of the specified user meets the execution requirement of the operation instruction, sending the operation instruction to an authentication server, so that the authentication server performs authorization decision processing on the operation instruction; and if the received authorization decision of the authentication server for the operation instruction is passing, executing the operation instruction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method, device, equipment and medium for obtaining instruction permissions of a network device. Background Art

[0002] With the rapid development of the Internet and data center industries, the number and scale of network devices are growing, and the security and reliability of network devices have become critical issues. As the core of information transmission and processing, the security of network devices is directly related to the stability and data security of the entire network system.

[0003] In actual applications, due to the lack of an effective permission management mechanism, many network devices face security risks such as unauthorized access, malicious attacks, and data leakage. Summary of the invention

[0004] One or more embodiments of the present specification provide a method, apparatus, device and medium for obtaining instruction permissions of a network device, which are used to solve the technical problems raised by the background technology.

[0005] One or more embodiments of this specification adopt the following technical solutions:

[0006] One or more embodiments of this specification provide a method for obtaining instruction permissions of a network device, the method comprising:

[0007] Obtaining an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device;

[0008] Determining the authority level of the designated user;

[0009] Based on the authority level of the designated user, performing an authority check on the execution requirement of the run instruction;

[0010] If the authority level of the designated user meets the execution requirements of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction;

[0011] If the authorization decision received from the authentication server regarding the running instruction is passed, the running instruction is executed.

[0012] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0013] Improved security: By implementing permission checks and authorization decision processes, this method can effectively prevent unauthorized access, reduce the risk of malicious attacks and data leakage, and thus enhance the security protection capabilities of network devices.

[0014] Strengthen access control: By determining the user's permission level, this method can ensure that users can only access and operate network device resources within their permission range, prevent unauthorized operations, and reduce potential security risks.

[0015] Dynamic permission management: This method supports dynamic adjustment of instruction execution permissions based on the user's actual permission level, adapting to different security requirements and work scenarios, and improving the flexibility and adaptability of permission management.

[0016] Enhanced reliability: Through the authorization decision processing of the authentication server, this method can ensure that only verified and authorized instructions are executed, reducing system failures caused by misoperation or malicious instructions.

[0017] Furthermore, before performing a permission check on the execution requirement of the run instruction based on the permission level of the designated user, the method further includes:

[0018] Based on the preset format of the operation instruction, performing a legality check on the operation instruction;

[0019] If the running instruction passes the legality check, the permission check based on the permission level of the designated user is performed on the execution requirement of the running instruction.

[0020] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0021] Enhanced instruction security: By performing a validity check on the running instructions before the permission check, illegal or malformed instructions can be prevented from being executed, thereby reducing system errors or security vulnerabilities caused by instruction errors.

[0022] Improve system stability: Legality checks help ensure that all executed network device commands comply with predetermined format standards, which helps maintain the stable operation of network devices and reduce system crashes or failures caused by command format errors.

[0023] Furthermore, if the execution instruction fails the legality check, the method further includes:

[0024] A notification message that fails the validity check is sent to the designated user.

[0025] Furthermore, sending the operation instruction to the authentication server includes:

[0026] The running instruction is encapsulated in an authorization request message, and the authorization request message is sent to the authentication server.

[0027] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0028] Enhanced security: By encapsulating the running instructions in the authorization request message and sending it to the authentication server, an additional security layer can be provided to prevent the running instructions from being intercepted or tampered with during transmission, thereby protecting the security of the instruction content.

[0029] Further, encapsulating the running instruction in an authorization request message, and sending the authorization request message to the authentication server, includes:

[0030] The operation instruction is encapsulated in a TACACS+ authorization request message, and the authorization request message is sent to a TACACS+ authentication server.

[0031] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0032] Standardized secure communication: The authorization request message using TACACS+ (Terminal Access Controller AccessControl System Plus) protocol ensures the security and standardization of communication. TACACS+ is a network access control protocol that provides encrypted user authentication, authorization, and accounting (AAA) services.

[0033] Enhanced security: The TACACS+ protocol provides an encrypted communication method, which means that when the run command is encapsulated in the authorization request message, its content cannot be easily intercepted or understood by a man-in-the-middle attacker.

[0034] Furthermore, the authentication server performs authorization decision processing on the running instruction, including:

[0035] The authentication server determines the authorization decision for the running instruction by comparing whether the pre-written command set includes the running instruction.

[0036] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0037] Simplify the authorization process: By comparing running instructions with pre-written command sets, the authentication server can quickly make authorization decisions, simplifying the authorization process and reducing decision complexity.

[0038] Improved efficiency: Predefined command sets allow the authentication server to quickly match and verify run instructions, thereby improving the efficiency of authorization decisions and reducing processing time.

[0039] Furthermore, the method further comprises:

[0040] If the command set includes the running instruction, the authorization decision for the running instruction is passed;

[0041] If the command set does not include the running instruction, the authorization decision for the running instruction is rejected.

[0042] One or more embodiments of this specification provide a device for obtaining instruction authority of a network device, including:

[0043] An instruction acquisition unit, which acquires an operation instruction input by a designated user on a terminal device, wherein the operation instruction is used to access a corresponding network device;

[0044] An authority level determination unit, which determines the authority level of the designated user;

[0045] an authority checking unit, which performs an authority check on the execution requirement of the operation instruction based on the authority level of the designated user;

[0046] an instruction sending unit, which sends the operation instruction to the authentication server if the authority level of the designated user meets the execution requirement of the operation instruction, so that the authentication server performs authorization decision processing on the operation instruction;

[0047] The instruction execution unit executes the operation instruction if receiving the authorization decision of the authentication server for the operation instruction is passed.

[0048] One or more embodiments of this specification provide a network device instruction authority acquisition device, including:

[0049] at least one processor; and,

[0050] a memory communicatively connected to the at least one processor; wherein,

[0051] The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:

[0052] Obtaining an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device;

[0053] Determining the authority level of the designated user;

[0054] Based on the authority level of the designated user, performing an authority check on the execution requirement of the run instruction;

[0055] If the authority level of the designated user meets the execution requirements of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction;

[0056] If the authorization decision received from the authentication server regarding the running instruction is passed, the running instruction is executed.

[0057] One or more embodiments of this specification provide a non-volatile computer storage medium storing computer executable instructions, which can achieve the following when executed by a computer:

[0058] Obtaining an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device;

[0059] Determining the authority level of the designated user;

[0060] Based on the authority level of the designated user, performing an authority check on the execution requirement of the run instruction;

[0061] If the authority level of the designated user meets the execution requirements of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction;

[0062] If the authorization decision received from the authentication server regarding the running instruction is passed, the running instruction is executed.

[0063] At least one of the above technical solutions adopted in the embodiments of this specification can achieve the following beneficial effects:

[0064] Improved security: By implementing permission checks and authorization decision processes, this method can effectively prevent unauthorized access, reduce the risk of malicious attacks and data leakage, and thus enhance the security protection capabilities of network devices.

[0065] Strengthen access control: By determining the user's permission level, this method can ensure that users can only access and operate network device resources within their permission range, prevent unauthorized operations, and reduce potential security risks.

[0066] Dynamic permission management: This method supports dynamic adjustment of instruction execution permissions based on the user's actual permission level, adapting to different security requirements and work scenarios, and improving the flexibility and adaptability of permission management.

[0067] Enhanced reliability: Through the authorization decision processing of the authentication server, this method can ensure that only verified and authorized instructions are executed, reducing system failures caused by misoperation or malicious instructions. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art description. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative labor. In the drawings:

[0069] Figure 1 A flowchart of a method for obtaining instruction permissions of a network device provided in one or more embodiments of this specification;

[0070] Figure 2 A flowchart of a network device dynamically obtaining instruction permissions provided by one or more embodiments of this specification;

[0071] Figure 3 A schematic diagram of the structure of a device for obtaining instruction authority of a network device provided in one or more embodiments of this specification;

[0072] Figure 4 A schematic diagram of the structure of a command authority acquisition device for a network device provided in one or more embodiments of the present specification. DETAILED DESCRIPTION

[0073] The embodiments of this specification provide a method, apparatus, device and medium for obtaining instruction permissions of a network device.

[0074] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments of this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.

[0075] Figure 1 A flowchart of a method for obtaining instruction permissions of a network device provided in one or more embodiments of this specification is provided, and the process can be executed by a switch. Certain input parameters or intermediate results in the process allow manual intervention and adjustment to help improve accuracy.

[0076] The method steps of the embodiment of this specification are as follows:

[0077] S101, obtaining an operation instruction input by a designated user on a terminal device, wherein the operation instruction is used to access a corresponding network device.

[0078] In the embodiments of this specification, regarding the above S101, the following specific implementation scheme can be adopted:

[0079] User authentication: Configure 802.1X authentication on the switch, requiring all terminal devices connected to the switch to pass user authentication. Supports multiple authentication methods, such as user name and password, digital certificate, RADIUS server authentication, etc.

[0080] Terminal device configuration: Install or configure network connection software on terminal devices (such as PCs, laptops, mobile devices, etc.). Ensure that the terminal device can connect to the switch and supports SSH, Telnet, or other remote access protocols.

[0081] Switch configuration: Configure VLAN (Virtual Local Area Network) and port security functions on the switch to control user access. Enable SSH or Telnet service and configure corresponding security settings, such as key exchange, encryption, etc.

[0082] Command capture: Enable the command line interface (CLI) log function on the switch to record the operation commands entered by the user through the terminal device. You can use the switch's built-in command "show command" or "show log" to view these logs.

[0083] Command analysis: Develop or use existing log analysis tools to analyze switch logs and extract the operating commands entered by users. Ensure that the analysis tools can identify and distinguish different user inputs.

[0084] S102: Determine the authority level of the designated user.

[0085] In the embodiments of this specification, regarding the above S102, the following specific implementation scheme can be adopted:

[0086] User database establishment: Establish a user database on the switch or use an existing user authentication system (such as a RADIUS server) to store user information. User information should include user name, password (encrypted storage), permission level, etc.

[0087] User Authentication: Configure the switch to support multiple authentication methods such as local database, TACACS+, Radius, etc. Users are required to authenticate when they try to access the switch.

[0088] Permission level definition: Define different permission levels, for example:

[0089] Read permission: Allows users to view network status and configuration information.

[0090] Configuration permissions: Allow users to modify network configuration.

[0091] Administrative privileges: Allows the user to perform advanced management tasks, such as rebooting the switch.

[0092] Permission mapping: Assign corresponding permission levels to each user in the user database.

[0093] Ensure that each user has access only to the features that match their permission level.

[0094] Switch configuration:

[0095] Configure access control lists (ACLs) in the switch's command line interface (CLI). Set different CLI command access permissions based on user privilege levels.

[0096] CLI Access Control: Use the CLI access control feature of the switch to restrict the commands that users can execute. Authentication, Authorization, and Accounting (AAA) services can be configured through the command aaa.

[0097] S103: Performing an authority check on the execution requirement of the run instruction based on the authority level of the designated user.

[0098] In an embodiment of the present specification, before performing a permission check on the execution requirement of the running instruction based on the permission level of the designated user, a legality check can be performed on the running instruction based on a preset format of the running instruction; if the running instruction passes the legality check, the permission check on the execution requirement of the running instruction based on the permission level of the designated user is performed; if the running instruction fails the legality check, a notification of failure to pass the legality check is sent to the designated user.

[0099] In the examples of this specification, the above content can be implemented by the following specific implementation scheme:

[0100] Define the run command format: Clearly define the format of all valid run commands, including command keywords, parameter order, parameter type, etc. Create a run command format document or configuration file for system reference.

[0101] Validity check mechanism: Develop or integrate a validity check module that can parse the running instructions and verify whether they conform to the predefined format. This module can include regular expression matching, pattern recognition algorithms, etc.

[0102] Implement legality check: After the user submits the running instruction, the legality check module is called immediately. If the instruction does not conform to the predefined format, an error message is returned to the user and subsequent processing is stopped.

[0103] Permission check mechanism: Create a permission check list or rule set based on the user permission level definition. The permission check module will determine whether the user has the right to execute the instruction based on the user's permissions and the content of the running instruction.

[0104] Execution requires permission check: If the running instruction passes the legality check, call the permission check module to check whether the user has the permission to perform the operation corresponding to the instruction. If the user does not have sufficient permissions, return permission error information to the user and stop the instruction execution.

[0105] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0106] Enhanced instruction security: By performing a validity check on the running instructions before the permission check, illegal or malformed instructions can be prevented from being executed, thereby reducing system errors or security vulnerabilities caused by instruction errors.

[0107] Improve system stability: Legality checks help ensure that all executed network device commands comply with predetermined format standards, which helps maintain the stable operation of network devices and reduce system crashes or failures caused by command format errors.

[0108] S104: If the authority level of the designated user meets the execution requirement of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction.

[0109] In the embodiment of the present specification, when the running instruction is sent to the authentication server, the running instruction can be encapsulated in an authorization request message, and the authorization request message is sent to the authentication server.

[0110] In the examples of this specification, the above content can be implemented by the following specific implementation scheme:

[0111] Define the authorization request message format: Design a standardized authorization request message format, including the following fields:

[0112] Instruction content: Contains the command that the user wants to execute.

[0113] User ID: A unique identifier for a user, such as a username or user ID.

[0114] User permission level: The user's permission level, used for subsequent permission checks.

[0115] Timestamp: The time when the request was sent.

[0116] Request ID: A unique identifier for the request, used to track the request.

[0117] Security information: such as encrypted signatures to ensure message integrity and non-tampering.

[0118] Develop a message encapsulation tool: Develop or integrate a tool to encapsulate the run command into an authorization request message. The tool will parse the run command, extract the necessary information, and construct the message according to the defined format.

[0119] Implement the authentication server interface: Determine the authentication server's communication protocol (such as HTTP, HTTPS, TCP, etc.) and interface. Develop or integrate a client to send authorization request messages to the authentication server.

[0120] Secure transmission: Use secure communication protocols (such as TLS / SSL) to encrypt transmitted messages to ensure the security of data during transmission.

[0121] Sending an authorization request: When the user submits a run command, the encapsulation tool converts the command into an authorization request message. The client sends the encapsulated message to the authentication server.

[0122] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0123] Enhanced security: By encapsulating the running instructions in the authorization request message and sending it to the authentication server, an additional security layer can be provided to prevent the running instructions from being intercepted or tampered with during transmission, thereby protecting the security of the instruction content.

[0124] Furthermore, when encapsulating the running instruction in an authorization request message and sending the authorization request message to the authentication server, the running instruction may be encapsulated in a TACACS+ authorization request message and the authorization request message may be sent to the TACACS+ authentication server.

[0125] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0126] Standardized secure communication: The authorization request message using TACACS+ (Terminal Access Controller AccessControl System Plus) protocol ensures the security and standardization of communication. TACACS+ is a network access control protocol that provides encrypted user authentication, authorization, and accounting (AAA) services.

[0127] Enhanced security: The TACACS+ protocol provides an encrypted communication method, which means that when the run command is encapsulated in the authorization request message, its content cannot be easily intercepted or understood by a man-in-the-middle attacker.

[0128] Furthermore, when the authentication server performs authorization decision processing on the running instruction, the authentication server determines the authorization decision for the running instruction by comparing whether the pre-written command set contains the running instruction. If the command set contains the running instruction, the authorization decision for the running instruction is passed; if the command set does not contain the running instruction, the authorization decision for the running instruction is not passed.

[0129] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0130] Simplify the authorization process: By comparing running instructions with pre-written command sets, the authentication server can quickly make authorization decisions, simplifying the authorization process and reducing decision complexity.

[0131] Improved efficiency: Predefined command sets allow the authentication server to quickly match and verify run instructions, thereby improving the efficiency of authorization decisions and reducing processing time.

[0132] S105: If the authorization decision received from the authentication server regarding the running instruction is approved, execute the running instruction.

[0133] It should be noted that the embodiments of this specification have the following beneficial effects through the above contents:

[0134] Improved security: By implementing permission checks and authorization decision processes, this method can effectively prevent unauthorized access, reduce the risk of malicious attacks and data leakage, and thus enhance the security protection capabilities of network devices.

[0135] Strengthen access control: By determining the user's permission level, this method can ensure that users can only access and operate network device resources within their permission range, prevent unauthorized operations, and reduce potential security risks.

[0136] Dynamic permission management: This method supports dynamic adjustment of instruction execution permissions based on the user's actual permission level, adapting to different security requirements and work scenarios, and improving the flexibility and adaptability of permission management.

[0137] Enhanced reliability: Through the authorization decision processing of the authentication server, this method can ensure that only verified and authorized instructions are executed, reducing system failures caused by misoperation or malicious instructions.

[0138] It should be noted that in recent years, with the rapid development of the Internet and data center industries, the number and scale of network devices have become increasingly large. In order to improve the security and reliability of network devices, it is necessary to perform necessary permission management on users accessing network devices. Currently, there are two common methods:

[0139] The first is to perform identity authentication when users access the network. Only users who pass the authentication can access the network. Common methods include AAA authentication, RADIUS authentication, and TACACS authentication. Users who fail the authentication will not be able to access the network, and users who pass the authentication can only perform authorized operations within their authority.

[0140] The second is to clearly classify the permissions of users who access network devices, such as dividing them into ordinary users, administrator users, super users, etc., or dividing users into more detailed levels, strictly controlling the permissions that can be executed by users at each level, and uniformly defining and planning the instructions that users at each level are allowed to execute.

[0141] Based on the existing implementation scheme, there are still some risks in user authority management. For a user with the highest authority, the operation and maintenance personnel still have some operations that they do not want the user to perform, such as the user mistakenly inputs the reboot command, causing the network device to be abnormally restarted; the user mistakenly deletes the key configuration, causing other users to be unable to access the network normally; the user can modify the device configuration at will, causing network abnormalities and other serious problems. The purpose of the present invention is to solve these problems. When all users access network devices, each legal instruction that the user wants to execute needs to be sent to the authentication server for judgment and decision-making to identify whether the command can be executed, so as to ensure the stability and reliability of the network equipment.

[0142] like Figure 2 The flowchart shown is a flow chart of a network device dynamically obtaining instruction permissions. The user logs in to the network device switch through a terminal device and enters an instruction. At this time, the switch receives the user instruction, first checks the legality of the instruction, and then encapsulates the instruction in a TACACS+ authorization request message and sends it to the authentication server. After receiving the request message, the authentication server makes an authority decision and then sends a reply message. After receiving the reply message, the switch parses the message and decides whether to execute or reject the instruction based on the content of the message.

[0143] The specific implementation process is:

[0144] 1. After the user logs in to the switch using a terminal device, enter the corresponding command;

[0145] 2. After receiving the user's command, the switch will first check the basic legality of the command. For illegal commands, a prompt message will be directly given and the execution will fail. For legal commands, the command will be checked for permissions based on the current user's permission level. If the user's permissions are illegal and he is not authorized to use the command, a prompt message will be directly given to inform the user that the execution failed. If the user's permissions are legal, the command will be encapsulated in a TACACS+ authorization request message and sent to the TACACS+ authentication server;

[0146] 3. After receiving the authorization request message, the server will make an authorization decision by comparing the command set on the server to determine whether the instruction can be executed, and encapsulate the authorization result in the authorization reply message and send it back to the switch;

[0147] 4. After receiving the authorization reply message, the switch will parse the message content. If the authorization result is not passed, it will directly give a prompt message to inform the user that the command authorization failed and cannot be executed. If the authorization result is passed, the switch will execute the command normally.

[0148] Through the above-mentioned scheme of dynamically obtaining instruction permissions, the operation and maintenance personnel of the network equipment only need to maintain the command set on the authorization server to realize the dynamic management of user instruction permissions, thereby improving the flexibility and reliability of operation and maintenance.

[0149] It should be noted that through the embodiments of this specification, operation and maintenance personnel can dynamically authorize and make decisions on user instructions for accessing network devices, realizing customizable management. Operation and maintenance personnel only need to maintain the command set on the server, which greatly reduces the operation and maintenance costs, and also improves the security, flexibility and reliability of network devices.

[0150] Figure 3 A structural diagram of an instruction permission acquisition device of a network device provided for one or more embodiments of this specification includes: an instruction acquisition unit 301, a permission level determination unit 302, a permission checking unit 303, an instruction sending unit 304 and an instruction execution unit 305.

[0151] The instruction acquisition unit 301 acquires an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device;

[0152] The authority level determination unit 302 determines the authority level of the designated user;

[0153] The permission checking unit 303 performs a permission check on the execution requirement of the running instruction based on the permission level of the designated user;

[0154] The instruction sending unit 304 sends the operation instruction to the authentication server if the authority level of the designated user meets the execution requirement of the operation instruction, so that the authentication server performs authorization decision processing on the operation instruction;

[0155] The instruction execution unit 305 executes the operation instruction if the authorization decision of the authentication server for the operation instruction is passed.

[0156] Figure 4 A schematic diagram of a structure of a command authority acquisition device for a network device provided for one or more embodiments of this specification includes:

[0157] at least one processor; and,

[0158] a memory communicatively connected to the at least one processor; wherein,

[0159] The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:

[0160] Obtaining an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device;

[0161] Determining the authority level of the designated user;

[0162] Based on the authority level of the designated user, performing an authority check on the execution requirement of the run instruction;

[0163] If the authority level of the designated user meets the execution requirements of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction;

[0164] If the authorization decision received from the authentication server regarding the running instruction is passed, the running instruction is executed.

[0165] One or more embodiments of this specification provide a non-volatile computer storage medium storing computer executable instructions, which can achieve the following when executed by a computer:

[0166] Obtaining an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device;

[0167] Determining the authority level of the designated user;

[0168] Based on the authority level of the designated user, performing an authority check on the execution requirement of the run instruction;

[0169] If the authority level of the designated user meets the execution requirements of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction;

[0170] If the authorization decision received from the authentication server regarding the running instruction is passed, the running instruction is executed.

[0171] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device, equipment, and non-volatile computer storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0172] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0173] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0174] In the embodiments provided in the present application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0175] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0176] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above units may be implemented in the form of hardware or software.

[0177] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0178] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A method for obtaining instruction permissions of a network device, characterized in that Obtaining an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device; Determining the authority level of the designated user; Based on the authority level of the designated user, performing an authority check on the execution requirement of the run instruction; If the authority level of the designated user meets the execution requirements of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction; If the authorization decision received from the authentication server regarding the running instruction is passed, the running instruction is executed.

2. The method according to claim 1, characterized in that: Before performing the permission check on the execution requirement of the run instruction based on the permission level of the designated user, the method further includes: Based on the preset format of the operation instruction, performing a legality check on the operation instruction; If the running instruction passes the legality check, the permission check based on the permission level of the designated user is performed on the execution requirement of the running instruction.

3. The method according to claim 2, characterized in that If the execution instruction fails the legality check, the method further includes: A notification message that fails the validity check is sent to the designated user.

4. The method according to claim 1, characterized in that The sending the running instruction to the authentication server includes: The running instruction is encapsulated in an authorization request message, and the authorization request message is sent to the authentication server.

5. The method according to claim 4, characterized in that The step of encapsulating the running instruction in an authorization request message and sending the authorization request message to the authentication server includes: The operation instruction is encapsulated in a TACACS+ authorization request message, and the authorization request message is sent to a TACACS+ authentication server.

6. The method according to claim 1, characterized in that The authentication server performs authorization decision processing on the running instruction, including: The authentication server determines the authorization decision for the running instruction by comparing whether the pre-written command set includes the running instruction.

7. The method according to claim 6, characterized in that The method further comprises: If the command set includes the running instruction, the authorization decision for the running instruction is passed; If the command set does not include the running instruction, the authorization decision for the running instruction is rejected.

8. A device for obtaining instruction authority of a network device, characterized in that: include: An instruction acquisition unit, which acquires an operation instruction input by a designated user on a terminal device, wherein the operation instruction is used to access a corresponding network device; An authority level determination unit, which determines the authority level of the designated user; an authority checking unit, which performs an authority check on the execution requirement of the operation instruction based on the authority level of the designated user; an instruction sending unit, which sends the operation instruction to the authentication server if the authority level of the designated user meets the execution requirement of the operation instruction, so that the authentication server performs authorization decision processing on the operation instruction; The instruction execution unit executes the operation instruction if the authorization decision of the authentication server for the operation instruction is passed.

9. A device for obtaining instruction authority of a network device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to: Obtaining an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device; Determining the authority level of the designated user; Based on the authority level of the designated user, performing an authority check on the execution requirement of the run instruction; If the authority level of the designated user meets the execution requirements of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction; If the authorization decision received from the authentication server regarding the running instruction is passed, the running instruction is executed.

10. A non-volatile computer storage medium, characterized in that: Computer executable instructions are stored, and when the computer executable instructions are executed by a computer, the following can be achieved: Obtaining an operation instruction input by a specified user on a terminal device, wherein the operation instruction is used to access a corresponding network device; Determining the authority level of the designated user; Based on the authority level of the designated user, performing an authority check on the execution requirement of the run instruction; If the authority level of the designated user meets the execution requirements of the running instruction, the running instruction is sent to the authentication server so that the authentication server performs authorization decision processing on the running instruction; If the authorization decision received from the authentication server regarding the running instruction is passed, the running instruction is executed.