Terminal user storage method and device, electronic equipment and medium

By partitioning and storing user names based on the concurrency of end users, the problem of excessive username comparisons in network security devices is solved, reducing the load on the device and avoiding abnormal hosting.

CN119996026APending Publication Date: 2025-05-13上海安博通科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510235478.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In network security devices, after the same username is authenticated by a large number of IPs, it will lead to a huge number of username comparisons when concurrently offline, resulting in abnormal hosting of network security devices.

Method used

By obtaining the number of concurrency online by the end user, partitioning the network security device according to different concurrency thresholds, and storing the username to reduce the number of comparisons. Specific strategies include: when the number of concurrency is less than the first preset threshold, no partition storage is stored; when the number of concurrency is greater than the first preset threshold, it is divided into area storage of the first preset number; when the number of concurrency is greater than the third preset threshold, it is divided into area storage of the second preset number.

Benefits of technology

By storing user names by partitions, the number of username comparisons when concurrently offline is significantly reduced, and the phenomenon of abnormal hosting of network security devices is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996026A_ABST
    Figure CN119996026A_ABST
Patent Text Reader

Abstract

The invention relates to a terminal user storage method and device, electronic equipment and a medium, and belongs to the technical field of computer application, and the method comprises the following steps: obtaining an online concurrency number of a terminal user; when the concurrency number is smaller than a first preset threshold value, storing a user name corresponding to the terminal user on the network security equipment; when the concurrency number is larger than a first preset threshold value and smaller than a second preset threshold value, dividing the network security equipment into a first preset number of areas, and storing user names corresponding to the terminal users into the first preset number of areas; and when the concurrency number is greater than a third preset threshold value, dividing the network security device into a second preset number of areas, and storing the user name corresponding to the terminal user into the second preset number of areas. According to the invention, the network security equipment is partitioned according to the concurrency number of the user, and the comparison frequency of the user name of the authenticated user is reduced, so that the phenomenon of abnormal hosting of the network security equipment is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer application technology, and in particular to a method, device, electronic equipment and medium for terminal user storage. Background Art

[0002] Online users are very important in the current Internet industry. They can intuitively reflect the user usage and the authentication method used by the user to go online. On network security devices, users usually authenticate and go online in multiple authentication methods, and then perform traffic auditing and control.

[0003] The user can finally go online in an authenticated manner, which contains information such as IP, username, mac, etc. The unique identifier of the authenticated user is the IP address. The same IP can only be authenticated online by one username, but the same username can be authenticated online by different IPs. When the same username is authenticated online by a large number of IPs, there will be a problem of concurrent offline. When choosing to log out all online users, the username will be compared. If there are N identical usernames, then the number of comparisons is N! For example, if N=10, then the number of comparisons is 10. 9 8 … 2 1=3628800 times. The number of devices for authenticated users ranges from 10,000 to 200,000, ranging from low-end hardware to high-end hardware specifications. If all 10,000 authenticated users have the same username, the number of comparisons will be very large when they go offline, resulting in abnormal hosting of network security devices. Summary of the invention

[0004] In view of this, it is necessary to provide a method, device, electronic device and medium for terminal user storage to solve the problem of abnormal hosting of network security equipment.

[0005] In order to solve the above problem, the present invention provides a method for terminal user storage, comprising: Get the number of concurrent online terminal users; When the concurrent number is less than a first preset threshold, storing the user name corresponding to the terminal user on the network security device; When the number of concurrent connections is greater than a first preset threshold and less than a second preset threshold, the network security device is divided into a first preset number of areas, and the user name corresponding to the terminal user is stored in the first preset number of areas; When the concurrent number is greater than a third preset threshold, the network security device is divided into a second preset number of areas, and the user names corresponding to the terminal users are stored in the second preset number of areas.

[0006] In a possible implementation manner, the terminal users include: local users, Ldap domain users, and third-party synchronization users.

[0007] In a possible implementation, when the number of concurrent connections is greater than a first preset threshold and less than a second preset threshold, dividing the network security device into a first preset number of areas, and storing the user name corresponding to the terminal user in the first preset number of areas, includes: When the concurrency number is greater than a first preset threshold and less than a second preset threshold, the network security device is divided into a first preset number of areas, and the user names corresponding to the terminal users are evenly distributed and stored in the first preset number of areas.

[0008] In a possible implementation, the second preset number is equal to the number of concurrent connections divided by the first preset threshold value plus 1.

[0009] In a possible implementation, the network security device includes: one or more of a security router, a line cipher machine, and a firewall.

[0010] In a possible implementation manner, the method further includes: logging out a user with the same name.

[0011] In a possible implementation, the deregistering a user with the same name includes: The user with the same name in each partition of the network security device is queried in turn to log out.

[0012] On the other hand, the present invention also provides a terminal user storage device, comprising: The concurrent number acquisition module is used to obtain the concurrent number of terminal users online; A first storage module, configured to store the user name corresponding to the terminal user on a network security device when the concurrent number is less than a first preset threshold; A second storage module is used to divide the network security device into a first preset number of areas when the concurrent number is greater than the first preset threshold and less than the second preset threshold, and store the user name corresponding to the terminal user in the first preset number of areas; The third storage module is used to divide the network security device into a second preset number of areas when the concurrency number is greater than a third preset threshold, and store the user name corresponding to the terminal user in the second preset number of areas.

[0013] On the other hand, the present invention also provides an electronic device, including a memory and a processor, wherein: The memory is used to store programs; The processor is coupled to the memory and is used to execute the program stored in the memory to implement the steps in the terminal user storage method described in any one of the above implementations.

[0014] On the other hand, the present invention also provides a computer-readable storage medium for storing computer-readable programs or instructions, which, when executed by a processor, can implement the steps in a terminal user storage method described in any of the above implementations.

[0015] The beneficial effects of the present invention are as follows: a terminal user storage method provided by the present invention first obtains the concurrent number of terminal users online, and then selects a partitioning strategy according to the concurrent number; when the concurrent number is less than a first preset threshold, the user name corresponding to the terminal user is stored on the network security device, that is, when the concurrent number is small, the network security device is not partitioned, and the user name of the user is directly stored on the network security device; when the concurrent number is greater than the first preset threshold and less than the second preset threshold, the network security device is divided into a first preset number of areas, and the user name corresponding to the terminal user is stored in the first preset number of areas, that is, when the concurrent number is greater than the third preset threshold, the network security device is divided into a second preset number of areas, and the user name corresponding to the terminal user is stored in the second preset number of areas; the present invention partitions the network security device according to the concurrent number of users, reduces the number of comparisons of the authenticated user's user name, and thus solves the problem of abnormal hosting of the network security device. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 A method flow chart of an embodiment of a method for terminal user storage provided by the present invention; Figure 2 A method flow chart of a specific embodiment of a method for terminal user storage provided by the present invention; Figure 3 A user logout flow chart of an embodiment of a method for storing terminal users provided by the present invention; Figure 4 A schematic flow chart of an embodiment of a terminal user storage device provided by the present invention; Figure 5 A schematic structural diagram of an embodiment of an electronic device provided by the present invention. DETAILED DESCRIPTION

[0017] The preferred embodiments of the present invention are described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not used to limit the scope of the present invention.

[0018] Before presenting the embodiments, the following terms are explained.

[0019] LDAP domain users refer to user accounts created and managed in the LDAP (Lightweight Directory Access Protocol) server.

[0020] LDAP is an open standard protocol for accessing and maintaining distributed directory information services. In LDAP, domain users refer to user accounts that belong to a specific domain (or organizational unit). These user accounts are stored in the LDAP directory and can be queried, authenticated, and managed through the LDAP protocol.

[0021] The present invention provides a method, device, electronic device and medium for terminal user storage, which are described below respectively.

[0022] Figure 1 A flow chart of an embodiment of the method for storing terminal users provided by the present invention is as follows: Figure 1 As shown, the method for terminal user storage includes: S101. Obtain the number of concurrent online terminal users; S102, when the number of concurrent connections is less than a first preset threshold, storing the user name corresponding to the terminal user on a network security device; S103, when the number of concurrent connections is greater than a first preset threshold and less than a second preset threshold, dividing the network security device into a first preset number of regions, and storing the user name corresponding to the terminal user in the first preset number of regions; S104: When the number of concurrent connections is greater than a third preset threshold, the network security device is divided into a second preset number of areas, and the user names corresponding to the terminal users are stored in the second preset number of areas.

[0023] Compared with the prior art, the present embodiment provides a method for storing terminal users, firstly obtaining the number of concurrent terminal users online, and then selecting a partition strategy according to the number of concurrent terminal users, when the number of concurrent terminal users is less than a first preset threshold, the user name corresponding to the terminal user is stored on the network security device, that is, when the number of concurrent terminal users is small, the network security device is not partitioned, and the user name of the user is directly stored on the network security device, when the number of concurrent terminal users is greater than the first preset threshold and less than the second preset threshold, the network security device is divided into a first preset number of areas, and the user name corresponding to the terminal user is stored in the first preset number of areas, that is, when the number of concurrent terminal users is greater than the third preset threshold, the network security device is divided into a second preset number of areas, and the user name corresponding to the terminal user is stored in the second preset number of areas. The present invention partitions the network security device according to the number of concurrent terminal users, reduces the number of comparisons of the user names of authenticated users, and thus solves the problem of abnormal hosting of network security devices.

[0024] It should be noted that the terminal and user storage method provided by the present invention is applied to network security equipment, and the network security equipment includes: one or more of a security router, a line cipher machine and a firewall.

[0025] In some embodiments of the present invention, the terminal users include: local users, Ldap domain users and third-party synchronization users.

[0026] In a specific embodiment of the present invention, Figure 2 As shown, for example, partitions are set on the network security device according to the number of concurrent users. Specifically, a step threshold (a, b, c) and the number of partitions (1, 2, 3...N) are set for the number of concurrent users. For example, (the first step threshold a=200, the second step threshold b=400, the third step threshold c=600); When the number of concurrent users online is less than 200 in the first tier, the device is not partitioned (the number of partitions is 1); When the number of concurrent users online is greater than the first level 200 and less than the second level 400, active partitioning is performed (the number of partitions is 2, and the users are evenly distributed to the two zones); When the number of concurrent users online is greater than the second level 400 and less than the third level 600, active partitioning is performed (the number of partitions is 3, and the users are evenly distributed to 3 zones); When the number of concurrent users online is greater than the third-tier threshold of 600, active partitioning is performed (the number of partitions is N, and the maximum number of users in each partition is the first-tier threshold of 200, so N = concurrent number / first-tier threshold rounded up and added to 1).

[0027] In some embodiments of the present invention, when the number of concurrent connections is greater than a first preset threshold and less than a second preset threshold, dividing the network security device into a first preset number of areas, and storing the user name corresponding to the terminal user in the first preset number of areas, includes: When the concurrency number is greater than a first preset threshold and less than a second preset threshold, the network security device is divided into a first preset number of areas, and the user names corresponding to the terminal users are evenly distributed and stored in the first preset number of areas.

[0028] In some embodiments of the present invention, the second preset number is equal to the number of concurrencies divided by the first preset threshold value plus 1.

[0029] In some embodiments of the present invention, in some embodiments of the present invention, it also includes: logging out the user with the same name.

[0030] In some embodiments of the present invention, the deregistering a user with the same name includes: The user with the same name in each partition of the network security device is queried in turn to log out.

[0031] In a specific embodiment of the present invention, Figure 3 As shown, after partitioned storage, if a user with the same name is logged out, a search and comparison is performed in each zone first. After one zone is logged out, the next zone is searched and compared. In this way, the user with the same name can be quickly logged out.

[0032] The embodiment of the present invention can partition and store users with the same name, and then quickly log off the user to be logged off during logoff and offline comparison, thereby saving performance for network security devices.

[0033] In order to better implement a terminal user storage method in an embodiment of the present invention, based on a terminal user storage method, correspondingly, as Figure 4 As shown, an embodiment of the present invention further provides a terminal user storage device, a terminal user storage device 400, including: The concurrent number acquisition module 401 is used to obtain the concurrent number of terminal users online; A first storage module 402, configured to store the user name corresponding to the terminal user on the network security device when the concurrent number is less than a first preset threshold; The second storage module 403 is used to divide the network security device into a first preset number of areas when the number of concurrent connections is greater than the first preset threshold and less than the second preset threshold, and store the user name corresponding to the terminal user in the first preset number of areas; The third storage module 404 is used to divide the network security device into a second preset number of areas when the concurrency number is greater than a third preset threshold, and store the user name corresponding to the terminal user in the second preset number of areas.

[0034] The terminal user storage device 400 provided in the above embodiment can implement the technical solution described in the above terminal user storage method embodiment. The specific implementation principles of the above modules or units can refer to the corresponding contents in the above terminal user storage method embodiment, which will not be repeated here.

[0035] like Figure 5 As shown, the present invention also provides an electronic device 500. The electronic device 500 includes a processor 501, a memory 502 and a display 503. Figure 5 Only some components of the electronic device 500 are shown, but it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead.

[0036] In some embodiments, the processor 501 may be a central processing unit (CPU), a microprocessor or other data processing chip, used to run program codes or process data stored in the memory 302, such as a terminal user storage method in the present invention.

[0037] In some embodiments, the processor 501 may be a single server or a server group. The server group may be centralized or distributed. In some embodiments, the processor 501 may be local or remote. In some embodiments, the processor 501 may be implemented in a cloud platform. In some embodiments, the cloud platform may include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an internal cloud, a multi-cloud, etc., or any combination thereof.

[0038] In some embodiments, the memory 502 may be an internal storage unit of the electronic device 500, such as a hard disk or memory of the electronic device 500. In other embodiments, the memory 502 may also be an external storage device of the electronic device 500, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 500.

[0039] Furthermore, the memory 502 may include both an internal storage unit of the electronic device 500 and an external storage device. The memory 502 is used to store application software installed in the electronic device 500 and various data.

[0040] In some embodiments, the display 503 may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, an OLED (Organic Light-Emitting Diode) touch device, etc. The display 503 is used to display information on the electronic device 500 and to display a visual user interface. The components 501-503 of the electronic device 500 communicate with each other via a system bus.

[0041] In one embodiment, when the processor 501 executes a program stored by a terminal user in the memory 502, the following steps may be implemented: Get the number of concurrent online terminal users; When the concurrent number is less than a first preset threshold, storing the user name corresponding to the terminal user on the network security device; When the number of concurrent connections is greater than a first preset threshold and less than a second preset threshold, the network security device is divided into a first preset number of areas, and the user name corresponding to the terminal user is stored in the first preset number of areas; When the concurrent number is greater than a third preset threshold, the network security device is divided into a second preset number of areas, and the user names corresponding to the terminal users are stored in the second preset number of areas.

[0042] It should be understood that: when the processor 501 executes a program stored by a terminal user in the memory 502, in addition to the above functions, other functions can also be implemented. For details, please refer to the description of the corresponding method embodiment above.

[0043] Furthermore, the embodiment of the present invention does not specifically limit the type of the electronic device 500 mentioned, and the electronic device 500 may be a portable electronic device such as a mobile phone, a tablet computer, a personal digital assistant (PDA), a wearable device, a laptop computer, etc. Exemplary embodiments of portable electronic devices include but are not limited to portable electronic devices equipped with IOS, Android, Microsoft or other operating systems. The above-mentioned portable electronic devices may also be other portable electronic devices, such as a laptop computer with a touch-sensitive surface (e.g., a touch panel). It should also be understood that in some other embodiments of the present invention, the electronic device 500 may not be a portable electronic device, but a desktop computer with a touch-sensitive surface (e.g., a touch panel).

[0044] Those skilled in the art will appreciate that all or part of the processes of the above-mentioned embodiments can be implemented by instructing related hardware through a computer program, and the program can be stored in a computer-readable storage medium, wherein the computer-readable storage medium is a disk, an optical disk, a read-only storage memory, or a random access memory, etc.

[0045] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by any technician familiar with the technical field within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.

Claims

1. A method for terminal user storage, applied to network security equipment, characterized in that: include: Get the number of concurrent online terminal users; When the concurrent number is less than a first preset threshold, storing the user name corresponding to the terminal user on the network security device; When the number of concurrent connections is greater than a first preset threshold and less than a second preset threshold, the network security device is divided into a first preset number of areas, and the user name corresponding to the terminal user is stored in the first preset number of areas; When the concurrent number is greater than a third preset threshold, the network security device is divided into a second preset number of areas, and the user names corresponding to the terminal users are stored in the second preset number of areas.

2. The method for terminal user storage according to claim 1, characterized in that: The terminal users include: local users, Ldap domain users and third-party synchronization users.

3. The method for terminal user storage according to claim 1, characterized in that: When the number of concurrent connections is greater than a first preset threshold and less than a second preset threshold, the network security device is divided into a first preset number of areas, and the user name corresponding to the terminal user is stored in the first preset number of areas, including: When the concurrency number is greater than a first preset threshold and less than a second preset threshold, the network security device is divided into a first preset number of areas, and the user names corresponding to the terminal users are evenly distributed and stored in the first preset number of areas.

4. The method for terminal user storage according to claim 1, characterized in that: The second preset number is equal to the concurrent number divided by the first preset threshold value plus 1.

5. The method for terminal user storage according to claim 1, characterized in that: The network security equipment includes: one or more of a security router, a line cipher machine and a firewall.

6. The method for terminal user storage according to claim 1, characterized in that: Also includes: Log out the user with the same name.

7. The method for terminal user storage according to claim 6, characterized in that: The deregistration of the user with the same name includes: The user with the same name in each partition of the network security device is queried in turn to log out.

8. A device for end-user storage, characterized in that: include: The concurrent number acquisition module is used to obtain the concurrent number of terminal users online; A first storage module, configured to store the user name corresponding to the terminal user on a network security device when the concurrent number is less than a first preset threshold; A second storage module is used to divide the network security device into a first preset number of areas when the concurrent number is greater than the first preset threshold and less than the second preset threshold, and store the user name corresponding to the terminal user in the first preset number of areas; The third storage module is used to divide the network security device into a second preset number of areas when the concurrency number is greater than a third preset threshold, and store the user name corresponding to the terminal user in the second preset number of areas.

9. An electronic device, characterized in that: comprising a memory and a processor, wherein: The memory is used to store programs; The processor is coupled to the memory and is used to execute the program stored in the memory to implement the steps in the terminal user storage method described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: Used to store computer-readable programs or instructions, which, when executed by a processor, can implement the steps in the terminal user storage method described in any one of claims 1 to 7.