Permission transition method, device, system, equipment, storage medium and program product
By introducing permission transition methods in BMC, using secondary servers in the LAN for authentication and permission upgrades, the server security issues caused by username or password leakage are solved, and advanced functional management and security guarantees are achieved.
Patent Information
- Application Number
- CN202510528111.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-25
AI Technical Summary
Currently, BMC authentication methods mostly use username + password authentication, which leads to greater security risks of username or password leakage in the case of frequent maintenance personnel flow and complex server usage environment, resulting in lower server security.
A privilege transition method is proposed. Through the permission transition start instruction sent by the target device, a target number of auxiliary servers is selected from the local area network according to the preset number of verification levels, a first verification information is generated and broadcast. The target device obtains the second verification information through the auxiliary server and matches it with the main server to determine that the permission transition is successful.
It realizes effective verification and upgrade of the permissions of the target device, ensuring advanced functional management of the server. Even if the user name or password is leaked, it will not affect the security of the server, and solves the problem of low server security.
Smart Images

Figure CN120068049A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of server management, and particularly to a method, device, system, equipment, storage medium and program product for permission transition. Background Art
[0002] The Baseboard Management Controller (BMC) is the core unit for managing a server. It is responsible for functions such as server management, monitoring, regulation, and diagnosis throughout the server's entire life cycle. The BMC has important functions such as controlling the server to power on and off, setting BIOS (Basic Input Output System) options, and triggering NMI (Non-Maskable Interrupt) interrupts. Therefore, the security of the BMC is directly related to the normal operation of the server and the stability and security of the customer's business system. Once the security of the BMC cannot be guaranteed, at best, the stability of the server is affected and the customer's business is interrupted, and at worst, customer data is leaked, causing serious economic losses.
[0003] Currently, the verification method of the BMC mostly adopts the form of username + password authentication, and combined with permission refinement and user level division, which can improve the security of the server to a certain extent. However, with the frequent turnover of current maintenance personnel and the complex and changeable server usage environment, it is particularly easy to cause the leakage of usernames or passwords, thus posing a certain security risk to the application of the server. Summary of the Invention
[0004] This application provides a method, device, system, equipment, storage medium and program product for permission transition, so as to at least solve the problem of low security of the server in related technologies.
[0005] This application provides a method for permission transition. This method is applied in the main server and includes: in response to a permission transition start instruction sent by a target device, according to the preset number of verification levels, select a target number of auxiliary servers from the local area network, where the target number is the same as the number of verification levels; generate first verification information for each auxiliary server based on a preset method, and broadcast each first verification information to the local area network, so that each auxiliary server obtains second verification information corresponding to the first verification information, thereby enabling the target device to obtain the second verification information through each auxiliary server; determine whether all the second verification information sent by the target device matches the corresponding first verification information; if all the second verification information matches the corresponding first verification information, then determine that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from a first permission to a second permission, and the second permission is higher than the first permission.
[0006] The present application also provides a permission transition method, which is applied to an auxiliary server. The method includes: obtaining second verification information corresponding to first verification information broadcast by a primary server in a local area network, where the first verification information is generated by the primary server based on a preset verification level number and a preset method for each of a target number of auxiliary servers selected from the local area network in response to a permission transition start instruction sent by a target device, and the target number is the same as the verification level number; and sending the second verification information to the target device in response to a query instruction sent by the target device.
[0007] The present application provides a permission transition system, which includes a target device, a primary server, and multiple auxiliary servers. The primary server and the multiple auxiliary servers are in the same local area network, and the target device is communicatively connected to the primary server and the multiple auxiliary servers. The target device sends a permission transition start instruction to the primary server; the primary server, in response to the permission transition start instruction sent by the target device, selects a target number of auxiliary servers from the local area network according to a preset verification level number, generates first verification information for each of the auxiliary servers based on a preset method, and broadcasts each first verification information to the local area network, where the target number is the same as the verification level number; each auxiliary server obtains second verification information corresponding to the first verification information broadcast by the primary server in the local area network; the target device sends a query instruction to each auxiliary server; the auxiliary server, in response to the query instruction sent by the target device, sends the second verification information to the target device; the primary server determines whether all the second verification information sent by the target device matches the corresponding first verification information. If all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful, and the successful permission transition is used to represent upgrading the current permission of the target device from a first permission to a second permission, where the second permission is higher than the first permission.
[0008] The present application also provides a permission transition device, which is applied to the primary server. The device includes: a first selection module, configured to select a target number of auxiliary servers from the local area network according to a preset verification level number in response to a permission transition start instruction sent by the target device, where the target number is the same as the verification level number; a generation module, configured to generate first verification information for each of the auxiliary servers based on a preset method, and broadcast each first verification information to the local area network, so that each auxiliary server obtains second verification information corresponding to the first verification information, and thus the target device obtains the second verification information through each auxiliary server; a first determination module, configured to determine whether all the second verification information sent by the target device matches the corresponding first verification information; and a first determination module, configured to determine that the permission transition is successful if all the second verification information matches the corresponding first verification information, and the successful permission transition is used to represent upgrading the current permission of the target device from a first permission to a second permission, where the second permission is higher than the first permission.
[0009] The present application also provides a permission transition device, which is applied to an auxiliary server. The device includes: a first acquisition module, configured to acquire second verification information corresponding to first verification information broadcast by a primary server in a local area network. The first verification information is generated by the primary server when responding to a permission transition start instruction sent by a target device. According to a preset number of verification levels, a target number of auxiliary servers are selected from the local area network, and for each auxiliary server based on a preset method. The target number is the same as the number of verification levels; a sending module, configured to send the second verification information to the target device in response to a query instruction sent by the target device.
[0010] The present application also provides a computer device, including: a memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the steps of any of the above permission transition methods.
[0011] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above permission transition methods are implemented.
[0012] The present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of any of the above permission transition methods are implemented.
[0013] Through the privilege transition method of this application, respond to the privilege transition start instruction sent by the target device. According to the preset number of verification levels, select the target number of auxiliary servers from the local area network, generate the first verification information for each auxiliary server based on a preset method, and broadcast each first verification information to the corresponding auxiliary server through the method of broadcasting in the local area network. In this way, the target device can obtain the second verification information corresponding to the first verification information through the auxiliary server. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the main server itself, it is determined that the privilege transition is successful. This successful privilege transition is used to represent upgrading the current privilege of the target device from the first privilege to the second privilege. That is to say, this solution uses each auxiliary server to verify the identity of the target device. Only when the verification is passed, the current privilege of the target device is upgraded from the first privilege to the second privilege. Since the second privilege is higher than the first privilege, this can achieve the management of some important functions of the server. And before the privilege transition, the privilege corresponding to the target device is the first privilege. Even if the user's username or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0015] Figure 1 Schematic diagram of a privilege transition system provided by an embodiment of the present application; Figure 2 Schematic diagram of a server management software interface provided by an embodiment of the present application; Figure 3 Schematic diagram of a process of a privilege transition method provided by an embodiment of the present application; Figure 4 Schematic diagram of a process of another privilege transition method provided by an embodiment of the present application; Figure 5 Schematic diagram of a process of yet another privilege transition method provided by an embodiment of the present application; Figure 6 Schematic diagram of a process of still another privilege transition method provided by an embodiment of the present application; Figure 7A flowchart of a privilege transition method with the primary server as the execution entity provided by an embodiment of the present application; Figure 8 A flowchart of a privilege transition method with the secondary server as the execution entity provided by an embodiment of the present application; Figure 9 A flowchart of another privilege transition method with the primary server as the execution entity provided by an embodiment of the present application; Figure 10 A flowchart of a privilege transition method with the secondary server as the execution entity provided by an embodiment of the present application; Figure 11 A structural diagram of a privilege transition device provided by an embodiment of the present application; Figure 12 A structural diagram of another privilege transition device provided by an embodiment of the present application; Figure 13 A structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0016] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0017] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0018] First, the noun terms involved in one or more embodiments of the present application are explained.
[0019] Web: The World Wide Web, also known as the Web, is a network service built on the Internet. It is based on the Hypertext Transfer Protocol (HTTP) and presents various information resources in the form of web pages through Hypertext Markup Language (HTML) to users.
[0020] Redfish: An interface specification based on the RESTful architecture, used to manage data center infrastructure such as servers, storage, and networks. It communicates through the standard HTTP / HTTPS protocol and transfers data in JSON format.
[0021] SNMP: Simple Network Management Protocol, a standard protocol for managing and monitoring network devices (such as routers, switches, servers, etc.). It collects the status information of devices by running agent programs on network devices and sends this information to the management station.
[0022] Syslog: A standard protocol for recording system log information, which allows devices to send system log messages to a remote log server for centralized storage and management.
[0023] IPMI: Intelligent Platform Management Interface, an open standard hardware management interface specification for managing and monitoring computer systems such as servers. It is independent of the server's operating system and realizes remote management and monitoring of server hardware through the Baseboard Management Controller (BMC).
[0024] LDAP: Lightweight Directory Access Protocol, a protocol for accessing and maintaining distributed directory information. It is based on the client / server model, and directory information is stored in a tree structure, similar to the directory structure of a file system, facilitating quick query and retrieval.
[0025] AD: Active Directory, a service in the Microsoft Windows Server operating system that stores information about users, computers, groups, printers, etc. in the network and provides management and access control functions for these objects. AD communicates based on the LDAP protocol and also includes some Microsoft-specific extended functions.
[0026] MD5: Message - Digest Algorithm 5, which takes data of any length as input and generates a 128-bit (16-byte) hash value through a series of complex mathematical operations, usually represented by 32-bit hexadecimal digits. Regardless of the length of the original data, the MD5 algorithm will "compress" it into a fixed-length hash value, and it is unique, that is, the probability of different data generating the same hash value is extremely low.
[0027] SHA1: Secure Hash Algorithm 1, which also converts input data into a hash value of a fixed length. The hash value generated by SHA1 is 160 bits (20 bytes) long and is usually represented by 40 hexadecimal digits. Similar to MD5, SHA1 also processes data based on a series of mathematical operations to ensure that the hash values of different data have high uniqueness and difference.
[0028] SHA256: Secure Hash Algorithm 256, belonging to the SHA-2 hash algorithm family. It generates a 256-bit (32-byte) hash value after processing the input data, represented by 64 hexadecimal digits. The SHA256 algorithm has higher security and collision resistance. Compared with MD5 and SHA1, it can better resist various password attacks.
[0029] LLDP: Link Layer Discovery Protocol. Network devices can announce their own status to other devices by sending LLDPDU (Link Layer Discovery Protocol Data Unit) in the local network. It is a protocol that enables devices in the network to discover each other, announce their status, and exchange information.
[0030] As the core management unit of the server, BMC is responsible for server management, monitoring, regulation, diagnosis, etc. throughout the entire life cycle of the server. BMC also has important functions such as controlling the server to power on and off, setting BIOS options, and triggering NMI interrupts. Therefore, the security of BMC is directly related to the normal operation of the server, the stability and security of the customer's business system. Once the security of BMC cannot be guaranteed, at least the stability of the server will be affected and the customer's business will be interrupted. At worst, customer data will be leaked, causing serious economic losses.
[0031] Currently, the commonly used remote management methods for BMC include Web, Redfish, SNMP, Syslog, and IPMI, etc. Common authentication methods include username + password, two-factor authentication, LDAP / AD authentication, and MD5 / SHA1 / SHA256 encryption authentication defined in the IPMI protocol, etc.
[0032] At the authentication management level of the BMC, the existing technical solutions mainly rely on the username + password method. Among them, the password is encrypted and stored in the BMC, or the user authentication information is stored in an independently set up LDAP / AD server. The BMC interacts with the LDAP / AD server through the corresponding protocol to implement the user authentication process. To further prevent security issues caused by the leakage of usernames or passwords, the commonly used solution is to divide the corresponding users according to their permissions. Different users have different permissions, and the permissions of individual users can be set. Or, a two-factor authentication mechanism is introduced, that is, when authenticating through the username + password, a dual authentication is carried out by combining verification information, hardware tokens or software tokens to ensure the security of BMC authentication.
[0033] When accessing the BMC using IPMI commands, the BMC encrypts the password according to the algorithm negotiated with the IPMItool and transmits the encrypted password to the IPMItool for authentication, ensuring that the user's password is transmitted in ciphertext during the transmission process and avoiding the problem of password leakage caused by packet hijacking.
[0034] In summary, the currently adopted username + password authentication method, combined with the design of refined permissions and user level division, can improve the security of the server to a certain extent. However, with the frequent turnover of current maintenance personnel and the complex and changeable server usage environment, it is particularly easy to cause the leakage of usernames or passwords, thus posing certain security risks to the application of the server. Specifically, it includes but is not limited to the following aspects: 1. When using the IPMItool to access the BMC, the actually entered username and password are in plain text. When the security of the operating environment cannot be guaranteed, it is extremely easy to cause password leakage and pose a security risk.
[0035] 2. Through refined permissions and permission level division, it can be ensured that low-level users cannot operate high-priority operations such as power on / off, logging in to KVM (Kernel-based Virtual Machine), setting BIOS options, and triggering NMI interrupts. However, when the personnel of high-level users change or the operating environment is not secure, the leakage of high-level users is also likely to pose a security risk to the server.
[0036] 3. Through methods such as LDAP / AD or the verification information, hardware tokens, and software tokens in two-factor authentication, it is necessary to build corresponding hardware devices or software systems additionally, which increases the maintenance cost to a certain extent.
[0037] 4. When the set user password is a weak password, it is relatively easy to be brute-forced, posing a security risk.
[0038] 5. When IPMItool requests that the BMC encrypt and transmit the password to IPMItool according to the agreed algorithm, it results in the reversibility of the encryption algorithm for storing the password in ciphertext in the BMC, with relatively low security.
[0039] 6. During the deployment of the server, for unused interaction interfaces, users do not care about or reset the user names + passwords of such interfaces. According to the factory settings, default users are used. When such users are exploited, it will cause irreversible damage to the BMC and the server, affecting the stability and security of the server operation. Especially when one BMC can be accessed, the security of all servers within the local area network may be attacked, reducing security.
[0040] 7. Different BMC interaction interfaces (such as IPMI, Redfish, SNMP, etc.) have independent user names + passwords and separate authentication processes, lacking unity and increasing the maintenance difficulty.
[0041] In view of this, this application uniformly reduces the user permissions of each interaction interface of all current BMCs, that is, by default, operations that seriously affect the server business functions, such as power on / off, triggering NMI interrupts, and restoring factory settings, are not supported. Based on the permission transition method proposed in this application, the current permissions of users are upgraded to achieve the purpose of being able to operate high-level settings. Specifically, the permission transition method of this application includes: in response to a permission transition start instruction sent by a target device, according to the preset number of verification levels, select a target number of auxiliary servers from the local area network, where the target number is the same as the number of verification levels; generate first verification information for each auxiliary server based on a preset method, and broadcast each first verification information to the local area network so that each auxiliary server can obtain second verification information corresponding to the first verification information, thereby enabling the target device to obtain the second verification information through each auxiliary server; determine whether all the second verification information sent by the target device matches the corresponding first verification information; if all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful, and the successful permission transition is used to indicate that the current permission of the target device is upgraded from a first permission to a second permission, where the second permission is higher than the first permission.
[0042] Through the privilege transition method of this application, respond to the privilege transition start instruction sent by the target device. According to the preset number of verification levels, select the target number of auxiliary servers from the local area network, and generate the first verification information for each auxiliary server based on the preset method. And by means of broadcasting in the local area network, broadcast each first verification information to the corresponding auxiliary server, so that the target device can obtain the second verification information corresponding to the first verification information through the auxiliary server. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the main server itself, it is determined that the privilege transition is successful, and this successful privilege transition is used to represent upgrading the current privilege of the target device from the first privilege to the second privilege. That is to say, this solution uses each auxiliary server to verify the identity of the target device. Only when the verification is passed, the current privilege of the target device is upgraded from the first privilege to the second privilege. Since the second privilege is higher than the first privilege, this can realize the management of some important functions of the server. And before the privilege transition, the privilege corresponding to the target device is the first privilege. Even if the user's username or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0043] Combined with the specific application environment architecture or specific hardware architecture on which the execution of the privilege transition method depends, the specific application environment architecture or specific hardware architecture is described here.
[0044] This application provides a privilege transition system. As Figure 1 shown, the system includes a target device and a local area network deploying switches and multiple servers. Among them, multiple servers deployed in the local area network can be connected to the switch through the network ( Figure 1 the solid line between the server and the switch in the figure), so that each server can obtain the corresponding IP (Internet Protocol Address) address. The target device can be connected to multiple servers in the local area network through the network, so that the target device and multiple servers in the local area network can communicate. Server management software can run on the target device, and users can manage multiple servers in the local area network through the server management software.
[0045] For example, as Figure 2As shown, when the user logs in to the server management software, multiple servers in the local area network can be displayed on the server management software interface. At this time, the user can log in to any server by using the username + password method and any authentication channel (for example, Web, Redfish, SNMP, Syslog, IPMI). For Figure 2 the server where the mouse is located in Figure 2 , the user can log in to the server by using the username + password method. At this time, since the permissions corresponding to the username + password are the first permissions (ordinary operation permissions), if the user needs to perform advanced operations on the server, the permission transition method provided by this application needs to be used to perform permission transition on the server, that is, to upgrade the permissions corresponding to the user from the first permissions to the second permissions. Therefore, the server that needs to perform permission transition can be called the primary server. During the process of performing permission transition on the primary server, other servers in the local area network perform auxiliary verification, so the servers for auxiliary verification can be called secondary servers.
[0046] Table 1
[0047] It should be noted that for the permission transition method of this application, when multiple servers in the local area network leave the factory, by default, all users of the BMC (including Web users, Redfish users, SNMP users, Syslog users, IPMI users, etc.) do not have the permission to perform advanced operations (the permission for advanced operations is the permission that affects the normal operation of the BMC and the server operating system services, for example, the factory reset of the BMC, the power-on and power-off operations of the server, NMI interrupt, etc., and the permission for advanced operations is also called the second permission in the following text). After the server deployment is completed, the permission transition method provided by this application is used to achieve permission transition to achieve the purpose of operating high-level permissions.
[0048] Based on this, the BMC in this application mainly provides the following several operation interfaces for the customer or the operation and maintenance background, and users with ordinary permissions (ordinary permissions are also called the first permissions in the following text) can call these interfaces.
[0049] 1. Parameter setting interface. This parameter setting interface is used to set relevant parameter information. Specifically, the parameter information includes enable status, verification level, preset transition success ratio, multi-channel enable, transition time, and permission time, etc. It should be noted that only users with the second permission can set and modify these parameter information. Of course, as shown in Table 1, the parameter information can also be imported into the memory of the server in the form of a parameter configuration file. By default, after the user sets the corresponding parameter information through the parameter setting interface, it will not take effect immediately, but only after restarting the server or restarting the BMC. The specific parameter information is shown in Table 1.
[0050] 2. Permission transition trigger interface. This permission transition trigger interface is used to trigger the permission transition of the user currently logged in to the target device.
[0051] 3. Permission transition result query interface. This permission transition result query interface is used to return the result after the permission transition of the current user. Specifically, it includes the user permission transition status (success, in progress, failure), and the transition response information (if the status is failure, it returns the reason for failure; if it is in progress, it returns the hostname of the next hop and the specified channel information). The information returned by this permission transition result query interface is shown in Table 2 as follows.
[0052] 4. Permission transition verification information input interface. This permission transition verification information input interface is used to input the verification query obtained from the secondary server to the primary server.
[0053] 5. Permission transition verification information query interface. This permission transition verification information query interface is used to query the verification information from the secondary server.
[0054] Table 2
[0055] It should be understood that for the above-mentioned parameter setting interface, permission transition trigger interface, permission transition result query interface, permission transition verification information input interface, and permission transition verification information query interface, after the user logs in to any server in the form of username + password through the target device, the above-mentioned interfaces can be displayed to the user in the form of buttons on the server management software; of course, they can also be displayed to the user in the form of commands. This will not be elaborated one by one here, and the accompanying drawings will not be listed one by one either.
[0056] After the permission transition method of this application is implemented in the server management software, for multiple servers in the local area network, by default, the verification level is 3, the transition ratio is 33%, the multi-channel enabling function is disabled, the transition time is 5 minutes, and the permission time is 1 hour. For the sake of easy explanation, the server currently to be authenticated for permission transition is called the primary server, and the Nth secondary server that realizes the permission transition is called secondary server N, where N starts from 0 to the verification level parameter - 1.
[0057] In practical applications, multiple servers in a local area network can broadcast their basic information to the BMCs in other servers in the same local area network through LLDP. Specifically, in the custom data field of LLDP, the SN (serial number) of its own BMC, the valid time of the broadcast message (the corresponding basic information becomes invalid after this time, so it is necessary to continuously refresh its own basic information within the valid time of the broadcast message), the supported channel conditions, and the IP address list of the target device that has successfully transitioned currently are included. The basic information broadcast by the server is specifically shown in Table 3 below.
[0058] Table 3
[0059] To enable those skilled in the art of this technical field to better understand the solution of this application, the following further elaborates on this application in conjunction with the accompanying drawings and specific implementation manners. Additionally, it should be noted that before using the permission transition method of this application, the corresponding parameter information can be set for each server in the local area network through the parameter setting interface mentioned above or through the parameter configuration file. In the permission transition method of this application, it is assumed that all parameter information is correctly set by default.
[0060] According to an embodiment of the present invention, an embodiment of a permission transition method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0061] In this embodiment, a permission transition method is provided, which can be used in a primary server. Figure 3 It is a flowchart of the permission transition method according to an embodiment of the present invention, as Figure 3 shown, and this process includes the following steps: Step S301, in response to a permission transition start instruction sent by a target device, select a target number of secondary servers from the local area network according to a preset verification level number, and the target number is the same as the verification level number.
[0062] A local area network (LAN) is a computer group interconnected by multiple computers in a certain area.
[0063] The permission transition start instruction is used to represent the process of starting a permission transition. That is, the user can log in to the main server through the server management software and send a permission transition start instruction to the main server through the permission transition trigger interface mentioned above. In the actual application process, for Web users, they can send a permission transition start instruction by clicking on the interface corresponding to the permission transition trigger interface displayed on the server management software; for Redfish users, SNMP users, Syslog users, and IPMI users, they can send a permission transition start instruction to the main server through the permission transition trigger interface using the corresponding commands.
[0064] For the main server, after receiving the permission transition start instruction sent by the target device, it can start the permission transition process. That is, the main server selects the target number of secondary servers from the local area network according to the verification level mentioned above to assist the permission transition of the target device. In the actual application process, the main server can randomly select the target number of secondary servers from multiple servers other than the main server in the local area network. Of course, for the main server, it can also specify the target number of secondary servers according to the running status of multiple servers other than the main server in the local area network to assist the permission transition of the target device.
[0065] For example, if the above-mentioned verification level is 3 by default, the main server selects 3 servers from multiple servers other than the main server in the local area network as secondary servers.
[0066] After the main server selects the target number of secondary servers from the local area network according to the preset verification level number, the main server can also display the first identification information (such as the SN code) and the first channel information of the secondary servers on the interface of the server management software, so that it is convenient for the user to know from which secondary servers to obtain the second verification information through which authentication channels.
[0067] Step S302, generate the first verification information for each secondary server based on a preset method, and broadcast each first verification information to the local area network so that each secondary server can obtain the second verification information corresponding to the first verification information, so that the target device can obtain the second verification information through each secondary server.
[0068] The first verification information includes but is not limited to numbers, letters, Chinese characters, graphics, or any combination of numbers, letters, Chinese characters, and graphics. That is, in this application, the actual form of the first verification information is not restricted, and it can be any form of verification information used for identity verification.
[0069] The preset method is a method for generating the first verification information that is preset in advance. For example, based on methods such as key pairs, random numbers, hash algorithms, time synchronization, or certificates, the first verification information can be generated for each secondary server.
[0070] There are various implementation methods for broadcasting each first verification information to the local area network. For example, each first verification information can be broadcast to the local area network through UDP (User Datagram Protocol); it can also be broadcast to the local area network through the ARP (Address Resolution Protocol) protocol; it can also be broadcast to the local area network through the above-mentioned LLDP protocol, and it can also be broadcast to the local area network through IGMP (Internet Group Management Protocol) multicast. This application does not limit the actual form of broadcasting each first verification information to the local area network. In the actual application process, each first verification information can be broadcast to the local area network through any appropriate method.
[0071] In the actual application process, the first verification information and the second verification information can be the same or different. For example, after the secondary server obtains the first verification information, if the first verification information is encrypted, the secondary server can decrypt the first verification information to obtain the second verification information; if the first verification information is not encrypted, in order to further improve security, the secondary server can encrypt the first verification information to obtain the second verification information. Of course, after obtaining the first verification information, the secondary server can generate the second verification information again based on the preset method.
[0072] It should be noted that for the primary server, secondary server, and target device, their encryption algorithms or decryption algorithms are all built in the primary server, secondary server, or target device in advance according to actual needs. The encryption algorithm or decryption algorithm can be any appropriate algorithm, and this application does not limit it.
[0073] Step S303, determine whether all the second verification information sent by the target device matches the corresponding first verification information.
[0074] Whether all the second verification information sent by the target device matches the corresponding first verification information can be whether the second verification information obtained by the target device from the first secondary server matches the first verification information given by the primary server to the first secondary server, and whether the second verification information obtained by the target device from the second secondary server matches the first verification information given by the primary server to the second secondary server, and so on.
[0075] When the first verification information is encrypted, after obtaining the first verification information, the secondary server decrypts the first verification information to obtain the second verification information. In this way, it is determined whether all the second verification information sent by the target device is the same as the corresponding first verification information. When the first verification information is not encrypted, the secondary server encrypts the first verification information to obtain the second verification information. After obtaining the second verification information, the target device can decrypt the second verification information to obtain the decrypted second verification information. In this way, it is determined whether all the second verification information sent by the target device is the same as the corresponding first verification information. After obtaining the first verification information, the secondary server can generate the second verification information again based on a preset method. In this way, it is determined whether all the second verification information sent by the target device matches the corresponding first verification information.
[0076] The user can send the second verification information obtained from each secondary server to the primary server through the permission transition verification information input interface of the primary server.
[0077] Step S304, if all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission, and the second permission is higher than the first permission.
[0078] During the process of performing a permission transition on the target device, the user can also query the progress of this permission transition in a timely manner through the permission transition query interface. After upgrading the current permission of the target device from the first permission to the second permission, relevant information indicating the successful permission transition can be returned in the interface of the server management software, so that the user can know in a timely manner that this permission transition has been successful, which is convenient for the user to perform advanced operations on the server in a timely manner within the permission validity period.
[0079] It should be noted that the permission transition in this application can upgrade the user's current permission, that is, upgrade the user's current permission from the first permission to the second permission, so that the user can perform advanced operations on the primary server. For example, setting the power on / off of the server, triggering an NMI interrupt, and setting BIOS options, etc.
[0080] The privilege transition method provided in this embodiment responds to the privilege transition start instruction sent by the target device. According to the preset number of verification levels, a target number of auxiliary servers are selected from the local area network, and the first verification information is generated for each auxiliary server based on a preset method. And by means of broadcasting in the local area network, each first verification information is broadcast to the corresponding auxiliary server, so that the target device can obtain the second verification information corresponding to the first verification information through the auxiliary server. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the main server itself, it is determined that the privilege transition is successful. This successful privilege transition is used to represent the upgrade of the current privilege of the target device from the first privilege to the second privilege. That is to say, this solution uses each auxiliary server to verify the identity of the target device, and only when the verification is passed, the current privilege of the target device is upgraded from the first privilege to the second privilege. Since the second privilege is higher than the first privilege, the management of some important functions of the server can be realized. And before the privilege transition, the privilege corresponding to the target device is the first privilege. Even if the user name or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0081] In this embodiment, a privilege transition method is provided, which can be used in the main server. Figure 4 It is a flowchart of the privilege transition method according to an embodiment of the present invention, as Figure 4 shown, and this process includes the following steps: Step S401, in response to the privilege transition start instruction sent by the target device, according to the preset number of verification levels, select a target number of auxiliary servers from the local area network, and the target number is the same as the number of verification levels.
[0082] Specifically, the above step S401 includes: Step S4011, according to the preset number of verification levels, randomly select a server from the local area network as the auxiliary server of the first level.
[0083] Step S4012, update the number of verification levels, so that the auxiliary server of the first level selects the auxiliary servers of the remaining levels from the remaining servers in the local area network according to the updated number of verification levels.
[0084] For the primary server, after receiving the permission transition start instruction sent by the target device, it can randomly select a target number of secondary servers from multiple servers in the local area network other than the primary server according to the preset verification level. Of course, the primary server can also randomly select a server from the local area network as the secondary server of the first level according to the preset number of verification levels. In this way, the server of the first level can also select a server from the remaining servers in the local area network as the server of the second level according to the updated verification level number, and so on until the verification level number is 0.
[0085] Regarding the update of the verification level number, after the primary server selects the secondary server of the first level, it can update the verification level number in a timely manner and send the updated verification level number to the secondary server of the first level. After the secondary server of the first level randomly selects the secondary server of the second level, it can continue to update the updated verification level number, and so on. Details will not be elaborated one by one later. For example, when the verification level number is 3, after the primary server selects the secondary server of the first level, it updates the verification level number to 2 and sends 2 to the secondary server of the first level. After the secondary server of the first level randomly selects the secondary server of the second level, it continues to update the verification level number to 1, and so on. Details will not be elaborated one by one later.
[0086] Of course, the primary server can also not update the verification level number but directly send the verification level number to the secondary server of the first level. Then the secondary server of the first level updates the verification level number. After the secondary server of the first level randomly selects the secondary server of the second level, it directly sends the updated verification level number to the secondary server of the second level, and so on. Details will not be elaborated one by one later. For example, when the verification level number is 3, the primary server directly sends 3 to the server of the first level. The secondary server of the first level updates 3 to 2 and sends it to the secondary server of the second level.
[0087] Step S402: Generate first verification information for each secondary server based on a preset method, and broadcast each first verification information to the local area network so that each secondary server can obtain second verification information corresponding to the first verification information, thereby enabling the target device to obtain the second verification information through each secondary server. For details, please refer to Figure 3 Step S302 of the illustrated embodiment, which will not be elaborated here.
[0088] Step S403: Determine whether all the second verification information sent by the target device matches the corresponding first verification information. For details, please refer to Figure 3 Step S303 of the illustrated embodiment, which will not be elaborated here.
[0089] Step S404: If all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful. The successful permission transition is used to indicate that the current permission of the target device is upgraded from the first permission to the second permission, and the second permission is higher than the first permission. For details, please refer to Figure 3 Step S304 of the embodiment shown, which will not be elaborated here.
[0090] The permission transition method provided in this embodiment responds to the permission transition start instruction sent by the target device. According to the preset number of verification levels, a server is randomly selected from the local area network as the auxiliary server of the first level, and the number of verification levels is updated, so that the auxiliary server of the first level selects the auxiliary servers of the remaining levels from the remaining servers in the local area network according to the updated number of verification levels, and generates the first verification information for each auxiliary server based on the preset method, and broadcasts each first verification information to the corresponding auxiliary server in the local area network by means of broadcasting. In this way, the target device can obtain the second verification information corresponding to the first verification information through the auxiliary server. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the main server itself, it is determined that the permission transition is successful. The successful permission transition is used to indicate that the current permission of the target device is upgraded from the first permission to the second permission. That is to say, this solution uses each auxiliary server to verify the identity of the target device, and only when the verification is passed, the current permission of the target device is upgraded from the first permission to the second permission. Since the second permission is higher than the first permission, the management of some important functions of the server can be realized. Before the permission transition, the permission corresponding to the target device is the first permission. Even if the username or password of the user is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0091] In some optional embodiments, broadcasting each first verification information to the local area network includes: encrypting each first verification information to generate target verification information corresponding to each first verification information; in response to the channel configuration operation for each auxiliary server, obtaining the first channel information of each auxiliary server; obtaining the first identification information of each auxiliary server and the second identification information of the target device; for each auxiliary server, encapsulating the first identification information, the first channel information, the target verification information and the second identification information into a frame to obtain a plurality of first target frames; and broadcasting the plurality of first target frames to the local area network.
[0092] The first verification information can be a verification code. The first identification information of each secondary server and the second identification information of the target device can both be SN codes, but are not limited to SN codes, and can also be MAC (Media Access Control Address), IP address, UUID (Universally Unique Identifier), server name, etc. The first channel information of each secondary server can be Web, Redfish, SNMP, Syslog, or IPMI, etc.
[0093] In the actual application process, the primary server can randomly set the first channel information for each secondary server. Of course, the primary server can also obtain the first channel information of each secondary server through the built-in information.
[0094] In the above implementation method, the primary server encrypts each first verification information, which can avoid the leakage of the first verification information during the broadcast process, and responds to the channel configuration operations of each secondary server, obtains the first channel information of each secondary server, and obtains the first identification information of each secondary server and the second identification information of the target device. In this way, the primary server can encapsulate the first verification information, the first channel information, the first identification information, and the second identification information corresponding to each secondary server into a frame and broadcast it in the local area network. Since it is a broadcast, multiple secondary servers in the local area network can receive all the first target frames. Therefore, after receiving the first target frame, the secondary server can compare its own identification information with the first identification information carried by the first target frame to determine whether the first target frame is sent to itself, so that the secondary server can quickly and accurately receive the first target frame sent by the primary server to itself, improving the response ability of the entire privilege transition process. Subsequently, during the process of the target device obtaining the first verification information, the secondary server can also use the first channel information carried by the first target frame and the second identification information of the target device to authenticate the target device, further improving the security of the server. It can receive the first verification information generated by the primary server for itself in a timely and accurate manner.
[0095] In some alternative embodiments, broadcasting each first verification information to the local area network further includes: encrypting the first verification information to generate target verification information corresponding to the first verification information; in response to a channel configuration operation for a secondary server at the first level, determining first channel information of the secondary server at the first level; obtaining first identification information of the secondary server at the first level and second identification information of the target device; encapsulating the first identification information, the first channel information, the target verification information, and the second identification information of the server at the first level into a frame to obtain a first target frame; and broadcasting the first target frame to the secondary server at the first level, so that after receiving the first target frame, the secondary server at the first level can select secondary servers of the remaining levels from the remaining servers in the local area network according to the updated verification level number.
[0096] For the foregoing implementation, the primary server may randomly select a server from the local area network as the secondary server at the first level according to a preset verification level number. After selecting the secondary server at the first level, the primary server may encrypt the first verification information to prevent the first verification information from being leaked during the broadcast process; the primary server may encapsulate the target verification information, the obtained first channel information, the first identification information of the secondary server at the first level, and the second identification information of the target device, and broadcast the obtained first target frame in the local area network, so that the secondary server at the first level can obtain the first target frame. After receiving the first target frame, the secondary server at the first level can not only use the first channel information and the second identification information of the target device carried in the first target frame to authenticate the target device, but also select secondary servers of the remaining levels from the remaining service weapons in the local area network according to the updated verification level number.
[0097] In actual application, the primary server may also directly send the first target frame to the secondary server at the first level. Additionally, following the previous embodiment, the primary server may also encapsulate the updated verification level number or the unupdated verification level number in the first target frame and send the updated verification level number or the unupdated verification level number to the secondary server at the first level in sequence.
[0098] In some alternative embodiments, before selecting a target number of secondary servers from the local area network according to a preset verification level number, the permission transition method further includes: obtaining a current transition success ratio, where the current transition success ratio is the ratio of the number of servers to which the target device has successfully transitioned in the local area network to the total number of servers in the local area network; if the current transition success ratio is greater than or equal to a preset transition success ratio, upgrading the current permission of the target device from a first permission to a second permission; if the current transition success ratio is less than the preset transition success ratio, then selecting a target number of secondary servers from the local area network according to the preset verification level number.
[0099] The current transition success ratio is the ratio of the number of servers in which the target device has successfully completed the permission transition among all servers in the local area network to the total number of all servers in the local area network. It should be noted that for the target device among all servers, not only the permission transition is successful, but also it is necessary to ensure that it is within the permission time. Specifically, refer to the description of the transition success ratio in Table 1.
[0100] In the above implementation, when the current transition success ratio is greater than or equal to the preset transition success ratio, the user permission can be directly transitioned, which ensures that the user background monitoring system does not need to frequently implement authentication transitions after access. Additionally, at this time, it can also be confirmed that the target device is reliable and trustworthy. When the current transition success ratio is less than the preset transition success ratio, the permission transition process is started, which can verify the identity of the target device and improve the security of the server.
[0101] In some alternative embodiments, the permission transition method further includes: before selecting a target number of secondary servers from the local area network according to the preset verification level number, triggering the start of the transition time limit timer based on the permission transition start instruction; if the timing time of the transition time limit timer reaches the preset first time and all the second verification information sent by the target device has not been received, it is determined that the permission transition fails, and the permission transition failure is used to indicate that the current permission of the target device is maintained as the first permission; if the timing time of the transition time limit timer reaches the preset first time and all the second verification information does not completely match the corresponding first verification information, it is determined that the permission transition fails.
[0102] In the above implementation, after receiving the permission transition start instruction sent by the target device, the start of the transition time limit timer is immediately triggered, and the transition time is timed by the transition time limit timer, which ensures that even if the username or password is leaked within the transition time, the impact on the security of the server can be minimized.
[0103] In some alternative embodiments, if all the second verification information completely matches the corresponding first verification information, it is determined that the permission transition is successful, including: if the timing time of the transition time limit timer has not reached the preset first time and all the second verification information completely matches the corresponding first verification information, it is determined that the permission transition is successful. That is to say, within the transition time limit, the target device obtains all the second verification information from all the secondary servers, sends all the second verification information to the primary and secondary servers, and all the second verification information completely matches the corresponding first verification information, which indicates that the identity verification of the target device is passed. Therefore, the target device is secure and reliable, so it can be determined that the permission transition of the target device is successful at this time.
[0104] In some alternative embodiments, the permission transition method further includes: after upgrading the current permission of the target device from a first permission to a second permission, triggering the start of a permission expiration timer based on the upgrade operation of upgrading the current permission of the target device from the first permission to the second permission; if the timing time of the permission expiration timer reaches a preset second time, or in response to an exit instruction sent by the target device, restoring the current permission of the target device from the second permission to the first permission.
[0105] In the above implementation, after the main server upgrades the current permission of the target device from the first permission to the second permission, it can immediately start a permission expiration timer. If the timing time of the permission expiration timer reaches the preset second time (i.e., the permission time shown in Table 1), the current permission of the target device is immediately restored to or downgraded to the first permission, making the security of the server relatively high. Of course, if the timing time of the permission expiration timer does not reach the permission time and an exit instruction sent by the target device is received, the current permission of the target device is immediately restored from the second permission to the first permission, thus avoiding the impact on the security of the server caused by the leakage of the user's username or password.
[0106] In this embodiment, a permission transition method is provided, which can be used in an auxiliary server. Figure 5 It is a flowchart of the permission transition method according to an embodiment of the present invention. As Figure 5 shown, the process includes the following steps: Step S501, obtain second verification information corresponding to first verification information broadcast by the main server in the local area network. The first verification information is generated by the main server for each auxiliary server in a preset manner when responding to a permission transition start instruction sent by the target device, according to a preset verification level number, and selecting a target number of auxiliary servers from the local area network. The target number is the same as the verification level number. For details, please refer to Figure 3 the embodiments shown, and details will not be described herein again.
[0107] Step S502, in response to a query instruction sent by the target device, send the second verification information to the target device.
[0108] The query instruction is an instruction for querying the second verification information from the auxiliary server.
[0109] For the primary server, after randomly selecting a secondary server, it can display the relevant information of the secondary server, such as the first identification information and the first channel information of the server, on the interface of the server management software. Then, the user can know from which secondary servers to obtain the second verification information. After that, the user can query the second verification information through the permission transition verification information query interface on the secondary server. For the secondary server, after receiving the query instruction sent through the permission transition verification information query interface, it can send the second verification information to the target device.
[0110] In the permission transition method of this embodiment, the primary server responds to the permission transition start instruction sent by the target device, selects a target number of secondary servers from the local area network according to the preset number of verification levels, generates the first verification information for each secondary server based on a preset method, and broadcasts each first verification information to the corresponding secondary server through broadcasting in the local area network. The secondary server can obtain the second verification information corresponding to the first verification information through the first verification information broadcast by the primary server in the local area network. After receiving the query instruction sent by the target device, it can send the second verification information to the target device. In this way, the target device can obtain the second verification information from the secondary server in a timely manner. After the target device obtains the second verification information, it can send each second verification information to the primary server, that is, the primary server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the primary server itself, it is determined that the permission transition is successful. This successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission. That is to say, this solution uses each secondary server to verify the identity of the target device. Only when the verification is passed, the current permission of the target device is upgraded from the first permission to the second permission. Since the second permission is higher than the first permission, this can achieve the management of some important functions of the server. And before the permission transition, the permission corresponding to the target device is the first permission. Even if the user's username or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0111] In this embodiment, a permission transition method is provided, which can be used in a secondary server. Figure 6 It is a flowchart of the permission transition method according to an embodiment of the present invention, as Figure 6 shown, and this process includes the following steps: Step S601: Obtain a second verification information corresponding to a first verification information broadcast by the master server in the local area network. The first verification information is generated by the master server based on a preset number of verification levels when responding to a permission transition start instruction sent by the target device. The master server selects a target number of slave servers from the local area network according to the preset number of verification levels, and generates, for each slave server, based on a preset method. The target number is the same as the number of verification levels.
[0112] The above step S601 further includes: Step S6011: Receive a first target frame broadcast by the master server in the local area network. The first target frame carries a first identification information of the slave server and a target verification information, and the target verification information is the encrypted first verification information.
[0113] After receiving the first target frame broadcast by the master server in the local area network, the slave server parses the first target frame to obtain the first identification information of the slave server and the target verification information carried in the first target frame.
[0114] For the master server, in order to avoid the leakage of the first verification information during the broadcast process, the first verification information is encrypted to generate a target verification information corresponding to the first verification information. At the same time, for the convenience of transmission, and to reduce the number of broadcasts in the local area network, avoid network congestion and errors, the master server can encapsulate, including but not limited to, the target verification information, the first identification information of the slave server, etc. into a frame to obtain the first target frame. Therefore, for the slave server, the slave server can receive the first target frame. The slave server parses the first target frame to obtain the first identification information and the target verification information carried in the first target frame.
[0115] Step S6012: If the first identification information is the same as a third identification information corresponding to the slave server, decrypt the target verification information in the first target frame to obtain the second verification information.
[0116] As can be seen from step S6011, the first identification information is the identification information of the slave server, but the first identification information is parsed from the first target frame. The third identification information is also the identification information of the slave server, which is the identification information carried by the slave server itself and has not been transmitted through the network. That is to say, although both the first identification information and the third identification information are the identification information of the slave server, their sources are different.
[0117] For the master server, it broadcasts the first target frames of multiple slave servers in the local area network. For a slave server, it can obtain all the first target frames broadcast by the master server. To facilitate the slave server to identify which first target frame is broadcast by the master server for itself, the master server carries the first identification information of the corresponding slave server in the first target frame. After the slave server parses the first identification information in the first target frame, it can compare the first identification information with the third identification information carried by itself. If they are the same, it indicates that the first target frame is broadcast by the master server for itself, so it saves the first target frame. And decrypts the target verification information carried in the first target frame to obtain the second verification information.
[0118] Step S6013, if the first identification information is different from the third identification information, then enter the step of receiving the first target frame broadcast by the master server in the local area network.
[0119] After the slave server parses the first identification information in the first target frame, it can compare the first identification information with the third identification information carried by itself. If they are different, it indicates that the first target frame is sent by the master server for other slave servers, so it can perform a packet loss process on the first target frame and continue to receive other first target frames broadcast by the master server in the local area network until the slave server obtains the first target frame broadcast by the master server for itself.
[0120] Step S602, in response to the query instruction sent by the target device, send the second verification information to the target device. For details, please refer to Figure 5 Step S502 shown, which will not be elaborated here.
[0121] In the permission transition method of this embodiment, after the secondary server receives the first target frame broadcast by the primary server in the local area network, it parses the first target frame to obtain the first identification information of the secondary server and the target verification information carried in the first target frame. If the first identification information is the same as the third identification information corresponding to the secondary server, it decrypts the target verification information in the first target frame to obtain the second verification information. After receiving the query instruction sent by the target device, it can send the second verification information to the target device. In this way, the target device can obtain the second verification information from the secondary server in a timely manner. After the target device obtains the second verification information, it can send each second verification information to the primary server, that is, the primary server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the primary server itself, it is determined that the permission transition is successful. The successful permission transition is used to represent that the current permission of the target device is upgraded from the first permission to the second permission. That is to say, this solution uses each secondary server to verify the identity of the target device. Only when the verification is passed, the current permission of the target device is upgraded from the first permission to the second permission. Since the second permission is higher than the first permission, it can manage some important functions of the server. Before the permission transition, the permission corresponding to the target device is the first permission. Even if the username or password of the user is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0122] In some alternative embodiments, after receiving the first target frame broadcast by the primary server in the local area network, the method further includes: determining whether the updated verification level number is 0; when the updated verification level number is not 0, selecting a server from the remaining servers in the local area network as the secondary server of the next level according to the updated verification level number; updating the verification level number again so that the secondary server of the next level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the verification level number updated again.
[0123] As described above, the updated verification level number may be carried in the first target frame, or may not be carried in the first target frame. When the updated verification level number is carried in the first target frame, the secondary server can obtain the updated verification level number by parsing the first target frame. When the updated verification level number is not carried in the first target frame, the primary server can broadcast the updated verification level number separately in the local area network.
[0124] When the updated verification level number is not 0, according to the updated verification level number, select a server from the remaining servers in the local area network as the secondary server of the next level. For example, as the secondary server of the second level. This step-by-step approach helps ensure the accuracy and integrity of the verification. The secondary server at each level can perform further verification based on the results of the previous level, thereby improving the accuracy of the verification.
[0125] In some optional embodiments, the permission transition method further includes: after selecting a server from the remaining servers in the local area network as the secondary server of the next level according to the updated verification level number, randomly generate the third verification information for the secondary server of the next level based on a preset method, and encrypt the third verification information; in response to the channel configuration operation for the secondary server of the next level, obtain the first channel information of the secondary server of the next level; obtain the first identification information of the secondary server of the next level and the second identification information of the target device; encapsulate the first identification information, the first channel information, the encrypted third verification information, and the second identification information of the secondary server of the next level into a frame to obtain the second target frame, and broadcast the second target frame to the secondary server of the next level and the primary server.
[0126] After broadcasting the second target frame to the secondary server of the next level, the secondary server of the next level can continue to select the secondary servers of the remaining levels from the remaining servers in the local area network based on the obtained updated verification level. At the same time, broadcasting the second target frame to the primary server is to pre-store the third verification information in the second target frame on the primary server in advance, so that it is convenient for the primary server to match with the pre-stored third verification information after the target device sends the decrypted third verification information to the primary server.
[0127] In the above implementation, the secondary server of the previous level randomly generates the third verification information for the secondary server of the next level, and encapsulates the third verification information, the first channel information of the secondary server of the next level, the encrypted third verification information, and the second identification information of the target device into a frame to obtain the second target frame, and broadcasts it to the secondary server of the next level, which can enhance the security in the process of authenticating the identity of the target device.
[0128] In some optional embodiments, the first target frame also carries the second identification information of the target device and the first channel information of the secondary server. Responding to the query instruction sent by the target device and sending the second verification information to the target device includes: using the data information carried in the query instruction to obtain the fourth identification information of the target device and the second channel information of the secondary server; if the second identification information of the target device is the same as the fourth identification information, and the first channel information is the same as the second channel information, then send the second verification information to the target device.
[0129] Regarding the second identification information and the fourth identification information, both are identification information of the target device and are used to uniquely identify the target device. However, the sources of the second identification information and the fourth identification information are different. For the second identification information, it is carried in the first target frame, that is to say, it is informed by the primary server to the secondary server. The fourth identification information is obtained from the query instruction sent by the target device.
[0130] Regarding the first channel information and the second channel information, both are channel information of the secondary server, but the sources of the first channel information and the second channel information are different. The first channel information is the channel information of the secondary server that the primary server responds to the target device channel configuration operation or the primary server sets. And the second channel information is obtained by the target device after the primary server displays the channel information of the secondary server on the interface of the server management software. After the target device obtains it, along with the query instruction, it sends the second channel information of the secondary server to the secondary server.
[0131] For example, assume that at this time, there are a primary server, a first-level secondary server, a second-level secondary server, and a third-level secondary server. The primary server broadcasts the first verification information to the first-level secondary server, the first-level secondary server broadcasts the second verification information to the second-level secondary server, and the second-level secondary server broadcasts the third verification information to the third-level secondary server. If the target device wants to obtain the first verification information, the second verification information, and the third verification information from the first-level secondary server, the second-level secondary server, and the third-level secondary server respectively, it needs to send query instructions to the first-level secondary server, the second-level secondary server, and the third-level secondary server respectively to obtain all the first verification information, the second verification information, and the third verification information.
[0132] If the second identification information and the fourth identification information of the target device are the same, and the first channel information and the second channel information of the secondary server are the same, it indicates that the authentication of the target device is passed, and then the second verification information is sent to the target device. In this way, through a strict verification process, the identity of the target device can be accurately verified, avoiding permission escalation for a forged target device or a template device under malicious attack.
[0133] In some optional embodiments, when the target device is in the process of obtaining relevant verification information of the auxiliary server, the auxiliary server of the last level needs to input the verification information to the server of the second-to-last level through the authority transition verification information input interface of the server of the second-to-last level after obtaining the corresponding verification information. The server of the second-to-last level verifies the verification information, and if the second identification information and the fourth identification information of the target device are the same, and the first channel information and the second channel information of the auxiliary server are the same, the second verification information is sent to the target device.
[0134] For example, it is assumed that at this time, there are a main server, a first-level auxiliary server, a second-level auxiliary server, and a third-level auxiliary server. The main server broadcasts the first verification information to the first-level auxiliary server, the first-level auxiliary server broadcasts the second verification information to the second-level auxiliary server, and the second-level auxiliary server broadcasts the third verification information to the third-level auxiliary server. If the target device wants to obtain the first verification information, the second verification information, and the third verification information from the first-level auxiliary server, the second-level auxiliary server, and the third-level auxiliary server, respectively. The target device needs to obtain the third verification information from the third-level auxiliary server, and then input the third verification information to the second-level auxiliary server, and the second-level auxiliary server will send the second verification information to the target device, and the same is true for the auxiliary servers of the previous level. Finally, after the target device sends all the first verification information, the second verification information, and the third verification information to the main server, the main server determines that the authority transition is successful. Or, after the target device sends the first verification information to the main server, the main server determines that the authority transition is successful.
[0135] In some optional implementations, the permission transition method further includes: determining whether the target device has queried the second verification information; if the target device has queried the second verification information, deleting the second verification information from the local storage. When the auxiliary server has been queried for the second verification information normally, the second verification information is deleted from the local cache of the auxiliary server, so that the uniqueness of the query can be guaranteed.
[0136] In this embodiment, a permission transition system is provided. The permission transition system includes a target device, a main server, and multiple auxiliary servers. Among them, the main server and the multiple auxiliary servers are in the same local area network. The target device is communicatively connected to the main server and the multiple auxiliary servers. Among them, the target device sends a permission transition start instruction to the main server; the main server responds to the permission transition start instruction sent by the target device, selects a target number of auxiliary servers from the local area network according to the preset number of verification levels, generates first verification information for each auxiliary server based on a preset method, and broadcasts each first verification information to the local area network. The target number is the same as the number of verification levels; each auxiliary server obtains second verification information corresponding to the first verification information broadcast by the main server in the local area network; the target device sends a query instruction to each auxiliary server; the auxiliary server responds to the query instruction sent by the target device and sends the second verification information to the target device; the main server determines whether all the second verification information sent by the target device matches the corresponding first verification information. If all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission, and the second permission is higher than the first permission.
[0137] The main server of the permission transition system responds to the permission transition start instruction sent by the target device, selects a target number of auxiliary servers from the local area network according to the preset number of verification levels, generates first verification information for each auxiliary server based on a preset method, and broadcasts each first verification information to the corresponding auxiliary server by broadcasting in the local area network. In this way, the target device can obtain the second verification information corresponding to the first verification information through the auxiliary server. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the main server itself, it is determined that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission. That is to say, this solution uses each auxiliary server to verify the identity of the target device. Only when the verification is passed, the current permission of the target device is upgraded from the first permission to the second permission. Since the second permission is higher than the first permission, the management of some important functions of the server can be realized. Before the permission transition, the permission corresponding to the target device is the first permission. Even if the user's username or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0138] For the sake of easy understanding, as Figure 7 and Figure 8As shown in the figure, an embodiment of the present application further provides a schematic flowchart of a permission transition method. Among them, on the main server side, the execution process of the main server includes Figure 7 the steps S701 to S720 shown in the figure. On the secondary server side, the execution process of the secondary server includes Figure 8 the steps S801 to S806 shown in the figure. Among them, On the main server side: Step S701, configure parameter information in multiple servers in the local area network.
[0139] Step S702, for multiple servers in the local area network, each server broadcasts its own basic information in the local area network.
[0140] Step S703, for each server, receive the basic information broadcast by other servers, update the cache, and execute steps S712 to S715.
[0141] Step S704, in response to the permission transition start instruction sent by the target device, and execute steps S716 to S720.
[0142] Step S705, determine the current transition success ratio according to the basic information of each server in the cache.
[0143] Step S706, determine whether the current transition success ratio is greater than or equal to the preset transition success ratio. If the current transition success ratio is greater than or equal to the preset transition success ratio, execute step S711 to determine that the permission transition is successful; if the current transition success ratio is less than the preset transition success ratio, execute steps S707 to S711.
[0144] Step S707, select a target number of secondary servers from the local area network according to the preset number of verification levels.
[0145] Step S708, generate first verification information for each secondary server, obtain the first channel information and first identification information of each secondary server, and obtain the second identification information of the target device. Package the first verification information, first channel information, first identification information of each server, and the second identification information of the target device into a frame to obtain a first target frame and broadcast it to each secondary server.
[0146] Step S709, at this time, the main server waits for the second verification information obtained by the target device from each secondary server. That is, receive the second verification information sent by the target device.
[0147] Step S710: Determine whether all the second verification information matches the corresponding first verification information. That is, the master server determines whether all the second verification information obtained from each slave server by the target device matches the first verification information stored in its own cache. If all match, it is determined that the permission transition is successful, and step S711 is executed. If not all match, step S718 is executed.
[0148] Step S711: Determine that the permission transition is successful. The successful permission transition is used to indicate that the current permission of the target device is upgraded from the first permission to the second permission.
[0149] Step S712: For each server in the local area network, after receiving the basic information of other servers, start a basic information timer to time the basic information of each server.
[0150] Step S713: During the timing of the basic information timer, determine whether the basic information is received again. If the basic information is received again, step S703 is executed; if the basic information is not received again, steps S714 and S715 are executed.
[0151] Step S714: Determine whether it times out, that is, determine whether the basic information timer reaches the broadcast message valid time. If the basic information timer corresponding to this basic information times out, delete the basic information cached in the cache, that is, execute step S715. If the basic information timer corresponding to this basic information does not time out, go to step S713.
[0152] Step S715: Delete the basic information cached in the cache.
[0153] Step S716: In response to the permission transition start instruction sent by the target device, trigger the start of the transition time limit timer.
[0154] Step S717: Determine whether it times out, that is, whether the timing time of the transition time limit timer reaches the transition time. If the timing time of the transition time limit timer reaches the transition time, execute step S718; if the timing time of the transition time limit timer does not reach the transition time, execute steps S719 and S720.
[0155] Step S718: Determine that the permission transition fails.
[0156] Step S719: Determine whether the permission transition is successful. If the permission transition is successful, delete the transition timer; if the permission transition fails, execute steps S717 and S718.
[0157] Step S720: Delete the transition time limit timer.
[0158] On the secondary server side: Step S801: For multiple servers in the local area network, each server broadcasts its basic information in the local area network.
[0159] Step S802: Determine whether the first target frame is received; if the first target frame is received, execute Steps S803 to S806; if the first target frame is not received, go to Step S802.
[0160] Step S803: Decode the first target frame to obtain the second verification information.
[0161] Step S804: Determine whether a query instruction is received; if the query instruction is received, execute Steps S805 and S806; if the query instruction is not received, go to Step S804.
[0162] Step S805: Determine whether the authentication passes, that is, whether the second identification information of the target device in the first target frame is the same as the fourth identification information carried in the query instruction of the target device, and whether the first channel information of the secondary server in the first target frame is the same as the second channel information carried in the query instruction; if they are the same, determine that the authentication passes and execute Step S806; if they are not the same, determine that the authentication fails and go to Step S804.
[0163] Step S806: Determine whether the target device has queried the second verification information on the secondary server. If it is determined that the target device has queried the second verification information on the secondary server, delete the first target frame in the cache.
[0164] For ease of understanding, as Figure 9 and Figure 10 shown, the embodiments of the present application also provide a flowchart of a main privilege transition method. Among them, on the primary server side, the execution process of the primary server includes Figure 9 Steps S901 to S920 shown in
[0165] On the secondary server side, the execution process of the secondary server includes Figure 10Steps S1001 to S1010 shown. It should be noted that the main difference between this embodiment and the previous embodiment lies in the different selection methods of the secondary servers. In this embodiment, the primary server randomly selects 1 secondary server according to the verification level number, and then randomly generates the verification information of this secondary server, obtains the first channel information and the first identification information of this secondary server, and sends them to the secondary server through LLDP, and subtracts 1 from the verification level number. Then, this secondary server randomly selects a server in its cache as the lower-level secondary server and automatically generates the verification information of the lower-level secondary server, etc. (not repeated here), until the verification level number is reduced to 0. Each secondary server sends the verification information randomly generated by itself to the primary server.
[0166] On the primary server side: Step S901, configure parameter information among multiple servers in the local area network.
[0167] Step S902, for multiple servers in the local area network, each server broadcasts its own basic information in the local area network.
[0168] Step S903, for each server, receive the basic information broadcast by other servers, update the cache, and execute steps S912 to S915.
[0169] Step S904, in response to the permission transition start instruction sent by the target device, and execute steps S716 to S720.
[0170] Step S905, determine the current transition success ratio according to the basic information of each server in the cache.
[0171] Step S906, determine whether the current transition success ratio is greater than or equal to the preset transition success ratio. If the current transition success ratio is greater than or equal to the preset transition success ratio, execute step S911 and determine that the permission transition is successful; if the current transition success ratio is less than the preset transition success ratio, execute steps S907 to S911.
[0172] Step S907, select 1 server from the local area network as the secondary server of the first level according to the preset verification level number, so that the secondary server of the first level selects the secondary servers of the remaining levels from the remaining servers according to the updated verification level number.
[0173] Step S908: Generate the first verification information for the secondary servers at the first level, obtain the first channel information and the first identification information of the secondary servers at the first level, and obtain the second identification information of the target device. Package the first verification information, the first channel information, the first identification information of the secondary servers at the first level, and the second identification information of the target device into a frame to obtain the second target frame and broadcast it to the secondary servers at the first level. The steps for the secondary servers at other levels are similar and will not be elaborated here one by one. Meanwhile, the primary server also needs to receive the target frames sent by each secondary server in the local area network to the lower-level secondary servers, so as to obtain the verification information sent by each secondary server to the lower-level secondary servers.
[0174] Step S909: At this time, the primary server waits for the verification information obtained by the target device from each secondary server, that is, receives the verification information obtained by the target device from each secondary server.
[0175] Step S910: Determine whether all the verification information sent by the target device matches the verification information stored in the primary server. If all match, determine that the permission transition is successful and execute Step S911. If not all match, then execute Step S918.
[0176] Step S911: Determine that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission.
[0177] Step S912: For each server in the local area network, after receiving the basic information of other servers, start the basic information timer to time the basic information of each server.
[0178] Step S913: During the timing of the basic information timer, determine whether the basic information is received again. If the basic information is received again, then execute Step S903; if the basic information is not received again, then execute Step S914 and Step S915.
[0179] Step S914: Determine whether it times out, that is, determine whether the basic information timer reaches the valid time of the broadcast message. If the basic information timer corresponding to this basic information times out, delete the basic information cached in the cache, that is, execute Step S915. If the basic information timer corresponding to this basic information does not time out, then go to Step S913.
[0180] Step S915: Delete the basic information cached in the cache.
[0181] Step S916: In response to the permission transition start instruction sent by the target device, trigger the start of the transition time limit timer.
[0182] Step S917, determine whether it times out, that is, whether the timing time of the transition aging timer reaches the transition time. If the timing time of the transition aging timer reaches the transition time, execute step S918; if the timing time of the transition aging timer does not reach the transition time, execute step S919 and step S920.
[0183] Step S918, determine that the permission transition fails.
[0184] Step S919, determine whether the permission transition is successful. If the permission transition is successful, delete the transition timer; if the permission transition fails, execute step S917 and step S918.
[0185] Step S920, delete the transition aging timer.
[0186] On the secondary server side: Step S1001, for multiple servers in the local area network, each server broadcasts its own basic information in the local area network.
[0187] Step S1002, determine whether the first target frame is received; if the first target frame is received, execute step S1003, and step S1008 and step S1010; if the first target frame is not received, go to step S1002.
[0188] Step S1003, decode the first target frame to obtain the second verification information.
[0189] Step S1004, determine whether the updated verification level is 0. If the updated verification level is not 0, execute step S1005 to step S1007; if the updated verification level is 0, execute step S1008 to step S1010.
[0190] Step S1005, according to the updated verification level number, select a server from the remaining servers in the local area network as the secondary server of the next level.
[0191] Step S1006, encapsulate the first identification information, the first channel information, the encrypted third verification information and the second identification information of the secondary server of the next level into a frame to obtain the second target frame.
[0192] Step S1007, broadcast the second target frame to the secondary server of the next level and the primary server.
[0193] Step S1008, determine whether a query instruction is received; if a query instruction is received, execute step S1009 and step S1010; if a query instruction is not received, go to step S1008.
[0194] Step S1009, determine whether the authentication passes, that is, whether the second identification information of the target device in the first target frame is the same as the fourth identification information carried in the query instruction of the target device, and whether the first channel information of the secondary server in the first target frame is the same as the second channel information carried in the query instruction; in the case of being the same, determine that the authentication passes and execute step 1010, in the case of being different, determine that the authentication fails and go to step S1008.
[0195] Step S1010, determine whether the target device has queried the second verification information on the secondary server. If it is determined that the second verification information on the secondary server has been queried, delete the first target frame in the cache.
[0196] The privilege transition method of this application reduces the operation privileges of the username and password, and the default user privileges do not have the privileges that affect the operation, stability and security of the server, so as to solve the potential security hazards that may be brought by the leakage of the username or password.
[0197] The privilege transition method of this application can solve the additional costs brought by methods such as building LDAP / AD or hardware tokens in two-factor authentication, that is, the built server cluster itself can complete the high-security user authentication logic without building additional hardware and software systems, reducing the maintenance cost.
[0198] The privilege transition method of this application can solve the potential security hazards that may be brought after a brute-force crack of a weak password. Even if the weak password is brute-force cracked, the impact on the security of the server is relatively small.
[0199] The privilege transition method of this application can solve the hidden danger that the current user only sets the username + password for the used interaction interface, while other interaction interfaces use the default user information of the server factory, and relevant personnel log in to the BMC through the default user information of other channels to cause damage.
[0200] The privilege transition method of this application can solve the problem that the security authentication processes of different interfaces of the BMC lack a unified processing logic, the authentication processes and logical security performances of each interface are different, the security upgrades of each module are not unified, and the maintenance difficulty is relatively large.
[0201] The privilege transition method of this application includes timing restrictions both in the privilege transition stage and after the privilege is obtained. Within the timing time, ensure that the leakage of the username or the successful privilege transition of the user has the least impact on the server.
[0202] The permission transition method of the present application uses the commonly used LLDP in current embedded products as the way for different servers in the local area network to interact, and borrows the user-defined field in LLDP to customize different formats of information, without the need to additionally integrate a network protocol stack, and uses the characteristics of limited local area network propagation and communication of this protocol to achieve the security of network information dissemination.
[0203] The permission transition method of the present application, based on the characteristic of dynamic timed broadcast information of LLDP, can implement the dynamic management function of server replacement in the local area network, without manual intervention, reducing the labor cost.
[0204] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0205] The embodiment of the present application also provides a permission transition device, as Figure 11 shown. This device is applied to the main server, and this device includes: The first selection module 1101 is used to, in response to a permission transition start instruction sent by a target device, select a target number of auxiliary servers from the local area network according to a preset verification level number, and the target number is the same as the verification level number.
[0206] The generation module 1102 is used to generate first verification information for each auxiliary server based on a preset method, and broadcast each first verification information to the local area network, so that each auxiliary server obtains second verification information corresponding to the first verification information, so that the target device obtains the second verification information through each auxiliary server.
[0207] The first determination module 1103 is used to determine whether all the second verification information sent by the target device matches the corresponding first verification information.
[0208] The first determination module 1104 is used to, if all the second verification information matches the corresponding first verification information, determine that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission, and the second permission is higher than the first permission.
[0209] In some optional implementation manners, the first selection module includes a first selection sub-module and an update sub-module. Among them, the first selection sub-module is used to randomly select a server from the local area network as the auxiliary server of the first level according to the preset verification level number; the update sub-module is used to update the verification level number, so that the auxiliary server of the first level selects the auxiliary servers of the remaining levels from the remaining servers in the local area network according to the updated verification level number.
[0210] In some alternative embodiments, the generating module includes a first generating sub-module, a first determining sub-module, a first obtaining sub-module, a first encapsulating sub-module, and a first broadcasting sub-module. Among them, the first generating sub-module is configured to encrypt each first verification information to generate target verification information corresponding to each first verification information; the first determining sub-module is configured to obtain the first channel information of each secondary server in response to a channel configuration operation for each secondary server; the first obtaining sub-module is configured to obtain the first identification information of each secondary server and the second identification information of the target device; the first encapsulating sub-module is configured to encapsulate the first identification information, the first channel information, the target verification information, and the second identification information into a frame for each secondary server to obtain a plurality of first target frames; the first broadcasting sub-module is configured to broadcast the plurality of first target frames to the local area network.
[0211] In some alternative embodiments, the generating module further includes a second generating sub-module, a second determining sub-module, a second obtaining sub-module, a second encapsulating sub-module, and a second broadcasting sub-module. Among them, the second generating sub-module is configured to encrypt the first verification information to generate target verification information corresponding to the first verification information; the second determining sub-module is configured to obtain the first channel information of the secondary servers at the first level in response to a channel configuration operation for the secondary servers at the first level; the second obtaining sub-module is configured to obtain the first identification information of the secondary servers at the first level and the second identification information of the target device; the second encapsulating sub-module is configured to encapsulate the first identification information, the first channel information, the target verification information, and the second identification information of the servers at the first level into a frame to obtain a first target frame; the second broadcasting sub-module is configured to broadcast the first target frame to the secondary servers at the first level so that, after receiving the first target frame, the secondary servers at the first level select the secondary servers at the remaining levels from the remaining servers in the local area network according to the updated verification level number.
[0212] In some alternative embodiments, the apparatus further includes a second obtaining module and an upgrading module. Among them, the second obtaining module is configured to obtain the current transition success ratio before selecting a target number of secondary servers from the local area network according to a preset verification level number. The current transition success ratio is the ratio of the number of servers to which the target device has successfully transitioned in the local area network to the total number of servers in the local area network; the upgrading module is configured to upgrade the current permission of the target device from a first permission to a second permission if the current transition success ratio is greater than or equal to a preset transition success ratio; the first selection module is configured to select a target number of secondary servers from the local area network according to the preset verification level number if the current transition success ratio is less than the preset transition success ratio.
[0213] In some alternative embodiments, the device further includes a first trigger module, a second determination module, and a third determination module. Among them, the first trigger module is used to trigger the start of a transition time limit timer based on a privilege transition start instruction before selecting a target number of secondary servers from the local area network according to a preset number of verification levels; the second determination module is used to determine that the privilege transition fails if all the second verification information sent by the target device is not received when the timing time of the transition time limit timer reaches a preset first time. The failure of the privilege transition is used to indicate that the current privilege of the target device is maintained as the first privilege; the third determination module is used to determine that the privilege transition fails if the second verification information is not all the same as the corresponding first verification information when the timing time of the transition time limit timer reaches the preset first time.
[0214] In some alternative embodiments, the first determination module includes a first determination sub-module, which is used to determine that the privilege transition is successful if all the second verification information matches the corresponding first verification information when the timing time of the transition time limit timer does not reach the preset first time.
[0215] In some alternative embodiments, the device further includes a second trigger module and a recovery module. Among them, the second trigger module is used to trigger the start of a privilege time limit timer based on the upgrade operation of upgrading the current privilege of the target device from the first privilege to the second privilege after the current privilege of the target device is upgraded from the first privilege to the second privilege; the recovery module is used to restore the current privilege of the target device from the second privilege to the first privilege if the timing time of the privilege time limit timer reaches a preset second time, or in response to an exit instruction sent by the target device.
[0216] An embodiment of the present application further provides a privilege transition device, as Figure 12 shown. This device is applied to a secondary server, and the device includes: A first acquisition module 1201, which is used to acquire second verification information corresponding to first verification information broadcast by the primary server in the local area network. The first verification information is generated by the primary server for each secondary server based on a preset method when the primary server responds to a privilege transition start instruction sent by the target device, selects a target number of secondary servers from the local area network according to a preset number of verification levels, and the target number is the same as the number of verification levels.
[0217] A sending module 1202, which is used to send the second verification information to the target device in response to a query instruction sent by the target device.
[0218] In some alternative embodiments, the first acquisition module includes a receiving sub-module, a decryption sub-module, and a loop sub-module. Among them, the receiving sub-module is configured to receive a first target frame broadcast by the primary server in the local area network. The first target frame carries the first identification information of the secondary server and target verification information, and the target verification information is the encrypted first verification information. The decryption sub-module is configured to decrypt the target verification information in the first target frame to obtain second verification information if the first identification information is the same as the third identification information corresponding to the secondary server. The loop sub-module is configured to enter the step of receiving the first target frame broadcast by the primary server in the local area network if the first identification information is different from the third identification information.
[0219] In some alternative embodiments, the apparatus further includes a second determination module, a second selection module, and an update module. Among them, the second determination module is configured to determine whether the updated verification level number is 0 after receiving the first target frame broadcast by the primary server in the local area network. The second selection module is configured to select a server from the remaining servers in the local area network as the secondary server of the next level according to the updated verification level number if the updated verification level number is not 0. The update module is configured to update the verification level number again so that the secondary server of the next level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the verification level number updated again.
[0220] In some alternative embodiments, the apparatus further includes an encryption module, a third determination module, a second acquisition module, a packaging module, and a broadcast module. Among them, the encryption module is configured to randomly generate third verification information for the secondary server of the next level based on a preset method and encrypt the third verification information after selecting a server from the remaining servers in the local area network as the secondary server of the next level according to the updated verification level number. The third determination module is configured to obtain the first channel information of the secondary server of the next level in response to a channel configuration operation for the secondary server of the next level. The second acquisition module is configured to obtain the first identification information of the secondary server of the next level and the second identification information of the target device. The packaging module is configured to package the first identification information, the first channel information, the encrypted third verification information, and the second identification information of the secondary server of the next level into a frame to obtain a second target frame. The broadcast module is configured to broadcast the second target frame to the secondary server of the next level and the primary server.
[0221] In some alternative embodiments, the first target frame further carries second identification information of the target device and first channel information of the secondary server. The sending module includes a third acquisition sub-module and a sending sub-module. Among them, the third acquisition sub-module is configured to use the data information carried in the query instruction to acquire fourth identification information of the target device and second channel information of the secondary server; the sending sub-module is configured to send the second verification information to the target device if the second identification information of the target device is the same as the fourth identification information, and the first channel information is the same as the second channel information.
[0222] In some alternative embodiments, the device further includes a fourth determination module and a deletion module. Among them, the fourth determination module is configured to determine whether the target device has queried the second verification information; the deletion module is configured to delete the second verification information from the local storage if the target device has queried the second verification information.
[0223] For the descriptions of the features in the corresponding embodiments of the permission transition device, reference can be made to the relevant descriptions in the corresponding embodiments of the permission transition method, which will not be elaborated here one by one.
[0224] An embodiment of the present application further provides an electronic device, as Figure 13 shown, including a memory 1310 and a processor 1320. A computer program is stored in the memory 1310, and the processor 1320 is configured to run the computer program to execute the steps in any one of the above-mentioned embodiments of the permission transition method.
[0225] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. Among them, the computer program is configured to execute the steps in any one of the above-mentioned embodiments of the permission transition method when running.
[0226] In an exemplary embodiment, the above-mentioned computer-readable storage medium may include, but is not limited to: USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical discs and other various media that can store computer programs.
[0227] An embodiment of the present application further provides a computer program product. The above-mentioned computer program product includes a computer program, and the steps in any one of the above-mentioned embodiments of the permission transition method are implemented when the computer program is executed by a processor.
[0228] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and the steps in any one of the above-mentioned embodiments of the permission transition method are implemented when the computer program is executed by a processor.
[0229] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0230] The above has introduced in detail a privilege transition method, device, system, equipment, storage medium, and program product provided by this application. Specific examples are used herein to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A permission transition method, characterized in that: Applied in a main server, the method comprises: In response to the permission transition start instruction sent by the target device, a target number of auxiliary servers are selected from the local area network according to a preset number of verification levels, wherein the target number is the same as the number of verification levels; Generate first verification information for each of the auxiliary servers based on a preset method, broadcast each of the first verification information to the local area network, so that each of the auxiliary servers obtains second verification information corresponding to the first verification information, and thus the target device obtains the second verification information through each of the auxiliary servers; Determining whether each of the second verification information sent by the target device matches the corresponding first verification information; If all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful, and the successful permission transition is used to indicate that the current permission of the target device is upgraded from the first permission to the second permission, and the second permission is higher than the first permission.
2. The method according to claim 1, characterized in that According to the preset number of authentication levels, select the target number of secondary servers from the local area network, including: According to the preset number of verification levels, randomly selecting one of the servers from the local area network as the auxiliary server of the first level; The verification level number is updated so that the auxiliary server of the first level selects the auxiliary servers of the remaining levels from the remaining servers in the local area network according to the updated verification level number.
3. The method according to claim 1, characterized in that Broadcasting each of the first verification information to the local area network includes: Encrypting each of the first verification information to generate target verification information corresponding to each of the first verification information; In response to the channel configuration operation for each of the auxiliary servers, obtaining first channel information of each of the auxiliary servers; Acquire the first identification information of each of the auxiliary servers and the second identification information of the target device; For each of the auxiliary servers, encapsulate the first identification information, the first channel information, the target verification information and the second identification information into a frame to obtain a plurality of first target frames; Broadcasting a plurality of the first target frames to the local area network.
4. The method according to claim 2, characterized in that: Broadcasting each of the first verification information to the local area network further includes: encrypting the first verification information to generate target verification information corresponding to the first verification information; In response to a channel configuration operation for the auxiliary server of the first level, obtaining first channel information of the auxiliary server of the first level; Acquire first identification information of the auxiliary server of the first level and second identification information of the target device; Encapsulate the first identification information of the server at the first level, the first channel information, the target verification information, and the second identification information into a frame to obtain a first target frame; The first target frame is broadcast to the auxiliary servers of the first level, so that after receiving the first target frame, the auxiliary servers of the first level select auxiliary servers of the remaining levels from the remaining servers in the local area network according to the updated verification level number.
5. The method according to claim 1, characterized in that Before selecting a target number of auxiliary servers from the local area network according to a preset number of verification levels, the method further includes: Obtaining a current successful transition ratio, where the current successful transition ratio is a ratio of the number of servers to which the target device has successfully transitioned in the local area network to the total number of servers in the local area network; If the current transition success ratio is greater than or equal to a preset transition success ratio, upgrading the current authority of the target device from the first authority to the second authority; If the current transition success ratio is less than the preset transition success ratio, a target number of auxiliary servers are selected from the local area network according to the preset number of verification levels.
6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Before selecting the target number of auxiliary servers from the local area network according to the preset number of verification levels, triggering the start of a transition validity timer based on the authority transition start instruction; If the timing time of the transition validity timer reaches the preset first time and all the second verification information sent by the target device is not received, it is determined that the permission transition fails, and the permission transition failure is used to indicate that the current permission of the target device is maintained as the first permission; If the timing time of the transition validity timer reaches the preset first time, and the second verification information is not completely identical to the corresponding first verification information, it is determined that the authority transition has failed.
7. The method according to claim 6, characterized in that If all the second verification information matches the corresponding first verification information, then determining that the authority transition is successful includes: If the timing time of the transition validity timer does not reach the preset first time, and each of the second verification information matches the corresponding first verification information, it is determined that the authority transition is successful.
8. The method according to any one of claims 1 to 5, characterized in that After upgrading the current permission of the target device from the first permission to the second permission, the method further includes: Based on the upgrade operation of upgrading the current permission of the target device from the first permission to the second permission, triggering the start of the permission validity timer; If the timing time of the permission validity timer reaches a preset second time, or in response to an exit instruction sent by the target device, the current permission of the target device is restored from the second permission to the first permission.
9. A permission transition method, characterized in that: Applied to the auxiliary server, the method further includes: Acquire second verification information corresponding to first verification information broadcasted by the primary server in the local area network, wherein the first verification information is generated for each of the secondary servers based on a preset method by selecting a target number of secondary servers from the local area network according to a preset number of verification levels when the primary server responds to a permission transition start instruction sent by the target device, and the target number is the same as the number of verification levels; In response to the query instruction sent by the target device, the second verification information is sent to the target device.
10. The method according to claim 9, characterized in that Acquiring second verification information corresponding to first verification information broadcasted by the main server in the local area network includes: receiving a first target frame broadcasted by the primary server in the local area network, wherein the first target frame carries first identification information and target verification information of the secondary server, and the target verification information is the encrypted first verification information; If the first identification information is the same as the third identification information corresponding to the secondary server, decrypting the target verification information in the first target frame to obtain the second verification information; If the first identification information is different from the third identification information, the process proceeds to a step of receiving the first target frame broadcasted by the main server in the local area network.
11. The method according to claim 10, characterized in that After receiving the first target frame broadcasted by the main server in the local area network, the method further includes: Determine whether the updated verification level number is 0; When the updated verification level number is not 0, selecting one of the servers from the remaining servers in the local area network as the auxiliary server of the next level according to the updated verification level number; The verification level number is updated again, so that the auxiliary server of the next level selects the auxiliary servers of the remaining levels from the remaining servers in the local area network according to the verification level number after the update again.
12. The method according to claim 11, characterized in that After selecting one server from the remaining servers in the local area network as the auxiliary server of the next level according to the updated number of verification levels, the method further includes: Based on the preset method, randomly generate third verification information for the secondary server at the next level, and encrypt the third verification information; In response to the channel configuration operation for the auxiliary server at the next level, obtaining first channel information of the auxiliary server at the next level; Acquire the first identification information of the secondary server at the next level and the second identification information of the target device; Encapsulate the first identification information, the first channel information, the encrypted third verification information, and the second identification information of the secondary server at the next level into a frame to obtain a second target frame; The second target frame is broadcast to the secondary server and the primary server at the next level.
13. The method according to claim 10, characterized in that The first target frame also carries the second identification information of the target device and the first channel information of the auxiliary server, and in response to the query instruction sent by the target device, sends the second verification information to the target device, including: Using the data information carried by the query instruction, acquiring the fourth identification information of the target device and the second channel information of the auxiliary server; If the second identification information and the fourth identification information of the target device are the same, and the first channel information and the second channel information are the same, the second verification information is sent to the target device.
14. The method according to any one of claims 10 to 13, characterized in that The method further comprises: determining whether the target device has queried the second verification information; If the target device has queried the second verification information, the second verification information is deleted from the local storage.
15. A permission transition system, characterized in that: The authority transition system includes a target device, a main server and a plurality of auxiliary servers, wherein the main server and the plurality of auxiliary servers are in the same local area network, and the target device is in communication connection with the main server and the plurality of auxiliary servers, wherein: The target device sends a permission transition start instruction to the main server; The primary server, in response to the permission transition start instruction sent by the target device, selects a target number of the secondary servers from the local area network according to a preset number of verification levels, generates first verification information for each of the secondary servers based on a preset method, and broadcasts each of the first verification information to the local area network, wherein the target number is the same as the number of verification levels; Each of the secondary servers obtains second verification information corresponding to the first verification information broadcasted by the primary server in the local area network; The target device sends a query instruction to each of the auxiliary servers; The auxiliary server sends the second verification information to the target device in response to the query instruction sent by the target device; The main server determines whether each second verification information sent by the target device matches the corresponding first verification information. If each second verification information matches the corresponding first verification information, it is determined that the authority transition is successful. The successful authority transition is used to indicate that the current authority of the target device is upgraded from the first authority to the second authority, and the second authority is higher than the first authority.
16. A permission transition device, characterized in that: Applied in a main server, the device comprises: A first selection module is used to select a target number of auxiliary servers from the local area network in response to the permission transition start instruction sent by the target device according to a preset number of verification levels, wherein the target number is the same as the number of verification levels; a generating module, configured to generate first verification information for each of the auxiliary servers based on a preset method, and broadcast each of the first verification information to the local area network, so that each of the auxiliary servers obtains second verification information corresponding to the first verification information, thereby enabling the target device to obtain the second verification information through each of the auxiliary servers; A first determination module, used to determine whether each of the second verification information sent by the target device matches the corresponding first verification information; The first determination module is used to determine that the permission transition is successful if all the second verification information matches the corresponding first verification information. The successful permission transition is used to indicate that the current permission of the target device is upgraded from the first permission to the second permission, and the second permission is higher than the first permission.
17. A permission transition device, characterized in that: Applied in the auxiliary server, the device further includes: A first acquisition module is used to acquire second authentication information corresponding to first authentication information broadcasted by the primary server in the local area network, wherein the first authentication information is generated for each of the secondary servers based on a preset method by selecting a target number of secondary servers from the local area network according to a preset number of authentication levels when the primary server responds to a permission transition start instruction sent by a target device, and the target number is the same as the number of authentication levels; A sending module is used to send the second verification information to the target device in response to the query instruction sent by the target device.
18. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the permission transition method described in any one of claims 1 to 8 or the permission transition method described in any one of claims 9 to 14 by executing the computer instructions.
19. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the permission transition method as described in any one of claims 1 to 8 or the permission transition method as described in any one of claims 9 to 14.
20. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method for permission transition as described in any one of claims 1 to 8 or the method for permission transition as described in any one of claims 9 to 14 is implemented.
Citation Information
Patent Citations
Service authorization management method and device
CN112913209A
Remote identity authentication method and device, equipment and storage medium
CN115150158A
Authority control method, authority control device, electronic equipment and storage medium
CN117134941A
Security authentication method, device, equipment, system, storage medium and program product
CN118505229A