Permission Transition Method, Apparatus, System, Device, Storage Medium, and Program Product
By selecting the auxiliary server in the LAN to generate verification information to upgrade the target device permissions, the problem of low BMC security is solved, advanced function management is realized, the risk of username or password leakage is reduced, the authentication process is simplified, and maintenance costs are reduced.
Patent Information
- Application Number
- CN202510528111.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-04-25
AI Technical Summary
现有BMC的安全性较低,易受用户名或密码泄漏影响,导致服务器稳定性和安全性问题,且现有认证方式复杂、成本高,维护难度大。
By selecting the target number of auxiliary servers in the LAN and generating and broadcasting verification information, the target device upgrades permissions after verification is passed, realizing advanced functional management of the server, reducing the default permissions, and avoiding the impact of security due to username or password leakage.
Improves server security, reduces the risk of username or password leakage, simplifies the authentication process, and reduces maintenance costs and complexity.
Smart Images

Figure CN120068049B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of server management, and particularly to a permission transition method, device, system, equipment, storage medium, and program product. Background Art
[0002] The Baseboard Management Controller (BMC) is the core unit for managing a server. It is responsible for functions such as server management, monitoring, regulation, and diagnosis throughout the server's entire life cycle. The BMC has important functions such as controlling the server to power on and off, setting BIOS (Basic Input Output System) options, and triggering NMI (Non-Maskable Interrupt) interrupts. Therefore, the security of the BMC is directly related to the normal operation of the server and the stability and security of the customer's business system. Once the security of the BMC cannot be guaranteed, at the very least, the stability of the server will be affected and the customer's business will be interrupted. At the worst, customer data will be leaked, causing serious economic losses.
[0003] Currently, the verification method of the BMC mostly adopts the form of username + password authentication, and combines permission refinement and user level division, which can improve the security of the server to a certain extent. However, with the frequent turnover of current maintenance personnel and the complex and changeable server usage environment, it is particularly easy to cause the leakage of usernames or passwords, thus posing certain security risks to the application of the server. Summary of the Invention
[0004] This application provides a permission transition method, device, system, equipment, storage medium, and program product to at least solve the problem of low security of servers in related technologies.
[0005] This application provides a permission transition method, which is applied to a main server. The method includes: in response to a permission transition start instruction sent by a target device, select a target number of auxiliary servers from the local area network according to a preset number of verification levels, where the target number is the same as the number of verification levels; generate first verification information for each auxiliary server based on a preset method, and broadcast each first verification information to the local area network so that each auxiliary server can obtain second verification information corresponding to the first verification information, thereby enabling the target device to obtain the second verification information through each auxiliary server; determine whether all the second verification information sent by the target device matches the corresponding first verification information; if all the second verification information matches the corresponding first verification information, then determine that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from a first permission to a second permission, and the second permission is higher than the first permission.
[0006] The present application also provides a permission transition method, which is applied to an auxiliary server. The method includes: obtaining second verification information corresponding to first verification information broadcast by a primary server in a local area network, where the first verification information is generated by the primary server based on a preset verification level number when responding to a permission transition start instruction sent by a target device, selecting a target number of auxiliary servers from the local area network, and generating the first verification information for each auxiliary server based on a preset method. The target number is the same as the verification level number; in response to a query instruction sent by the target device, sending the second verification information to the target device.
[0007] The present application provides a permission transition system, which includes a target device, a primary server, and a plurality of auxiliary servers. Among them, the primary server and the plurality of auxiliary servers are in the same local area network, and the target device is communicatively connected to the primary server and the plurality of auxiliary servers. Among them, the target device sends a permission transition start instruction to the primary server; the primary server, in response to the permission transition start instruction sent by the target device, selects a target number of auxiliary servers from the local area network according to a preset verification level number, generates first verification information for each auxiliary server based on a preset method, and broadcasts each first verification information to the local area network. The target number is the same as the verification level number; each auxiliary server obtains second verification information corresponding to the first verification information broadcast by the primary server in the local area network; the target device sends a query instruction to each auxiliary server; the auxiliary server, in response to the query instruction sent by the target device, sends the second verification information to the target device; the primary server determines whether all the second verification information sent by the target device matches the corresponding first verification information. If all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful. The successful permission transition is used to represent that the current permission of the target device is upgraded from a first permission to a second permission, and the second permission is higher than the first permission.
[0008] The present application also provides a permission transition device, which is applied to the primary server. The device includes: a first selection module, configured to select a target number of auxiliary servers from the local area network according to a preset verification level number in response to a permission transition start instruction sent by the target device, where the target number is the same as the verification level number; a generation module, configured to generate first verification information for each auxiliary server based on a preset method, and broadcast each first verification information to the local area network, so that each auxiliary server obtains second verification information corresponding to the first verification information, so that the target device can obtain the second verification information through each auxiliary server; a first determination module, configured to determine whether all the second verification information sent by the target device matches the corresponding first verification information; a first determination module, configured to determine that the permission transition is successful if all the second verification information matches the corresponding first verification information. The successful permission transition is used to represent that the current permission of the target device is upgraded from a first permission to a second permission, and the second permission is higher than the first permission.
[0009] The present application also provides a permission transition device, which is applied to an auxiliary server. The device includes: a first acquisition module, configured to acquire second verification information corresponding to first verification information broadcast by a primary server in a local area network. The first verification information is generated by the primary server for each of a target number of auxiliary servers selected from the local area network based on a preset manner according to a preset number of verification levels when the primary server responds to a permission transition start instruction sent by a target device. The target number is the same as the number of verification levels; a sending module, configured to send the second verification information to the target device in response to a query instruction sent by the target device.
[0010] The present application also provides a computer device, including: a memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the steps of any one of the above permission transition methods.
[0011] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any one of the above permission transition methods are implemented.
[0012] The present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of any one of the above permission transition methods are implemented.
[0013] Through the privilege transition method of this application, in response to the privilege transition start instruction sent by the target device, according to the preset number of verification levels, a target number of auxiliary servers are selected from the local area network, and first verification information is generated for each auxiliary server based on a preset method. And by means of broadcasting in the local area network, each first verification information is broadcast to the corresponding auxiliary server, so that the target device can obtain the second verification information corresponding to the first verification information through the auxiliary server. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the corresponding main server itself, it is determined that the privilege transition is successful, and this successful privilege transition is used to represent upgrading the current privilege of the target device from the first privilege to the second privilege. That is to say, this solution uses each auxiliary server to verify the identity of the target device, and only when the verification is passed, the current privilege of the target device is upgraded from the first privilege to the second privilege. Since the second privilege is higher than the first privilege, the management of some important functions of the server can be realized in this way. And before the privilege transition, the privilege corresponding to the target device is the first privilege. Even if the user name or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0015] Figure 1 Schematic diagram of a privilege transition system provided by an embodiment of the present application;
[0016] Figure 2 Schematic diagram of a server management software interface provided by an embodiment of the present application;
[0017] Figure 3 Schematic flow diagram of a privilege transition method provided by an embodiment of the present application;
[0018] Figure 4 Schematic flow diagram of another privilege transition method provided by an embodiment of the present application;
[0019] Figure 5 Schematic flow diagram of yet another privilege transition method provided by an embodiment of the present application;
[0020] Figure 6Schematic flowchart of yet another permission transition method provided by an embodiment of the present application;
[0021] Figure 7 Schematic flowchart of a permission transition method with a primary server as the execution entity provided by an embodiment of the present application;
[0022] Figure 8 Schematic flowchart of a permission transition method with a secondary server as the execution entity provided by an embodiment of the present application;
[0023] Figure 9 Schematic flowchart of another permission transition method with a primary server as the execution entity provided by an embodiment of the present application;
[0024] Figure 10 Schematic flowchart of a permission transition method with a secondary server as the execution entity provided by an embodiment of the present application;
[0025] Figure 11 Schematic structural diagram of a permission transition device provided by an embodiment of the present application;
[0026] Figure 12 Schematic structural diagram of another permission transition device provided by an embodiment of the present application;
[0027] Figure 13 Schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0028] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0029] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements includes not only those elements but also other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0030] First, the noun terms involved in one or more embodiments of the present application are explained.
[0031] Web: The World Wide Web, also known as the Web, is a network service built on the Internet. It is based on the Hypertext Transfer Protocol (HTTP) and presents various information resources to users in the form of web pages through Hypertext Markup Language (HTML).
[0032] Redfish: An interface specification based on the RESTful architecture, used to manage data center infrastructure such as servers, storage, and networks. It communicates through standard HTTP / HTTPS protocols and transfers data in JSON format.
[0033] SNMP: Simple Network Management Protocol, a standard protocol for managing and monitoring network devices (such as routers, switches, servers, etc.). It collects the status information of devices by running agent programs on the network devices and sends this information to the management station.
[0034] Syslog: A standard protocol for recording system log information. It allows devices to send system log messages to a remote log server for centralized storage and management.
[0035] IPMI: Intelligent Platform Management Interface, an open standard hardware management interface specification for managing and monitoring computer systems such as servers. It is independent of the server's operating system and enables remote management and monitoring of server hardware through the Baseboard Management Controller (BMC).
[0036] LDAP: Lightweight Directory Access Protocol, a protocol for accessing and maintaining distributed directory information. It is based on the client / server model, and directory information is stored in a tree structure, similar to the directory structure of a file system, facilitating quick query and retrieval.
[0037] AD: Active Directory, a service in the Microsoft Windows Server operating system. It stores information about objects such as users, computers, groups, printers, etc. in the network and provides management and access control functions for these objects. AD communicates based on the LDAP protocol and also includes some Microsoft-specific extended functions.
[0038] MD5: Message - Digest Algorithm 5. It takes data of any length as input and, through a series of complex mathematical operations, generates a 128 - bit (16 - byte) hash value, usually represented as 32 - bit hexadecimal digits. Regardless of the length of the original data, the MD5 algorithm will "compress" it into a hash value of a fixed length, and it is unique, that is, the probability of different data generating the same hash value is extremely low.
[0039] SHA1: Secure Hash Algorithm 1. It also converts the input data into a hash value of a fixed length. The hash value generated by SHA1 is 160 bits (20 bytes) long, usually represented as 40 - bit hexadecimal digits. Similar to MD5, SHA1 also processes data based on a series of mathematical operations to ensure that the hash values of different data have high uniqueness and difference.
[0040] SHA256: Secure Hash Algorithm 256, belonging to the SHA - 2 hash algorithm family. It generates a 256 - bit (32 - byte) hash value after processing the input data, represented as 64 - bit hexadecimal digits. The SHA256 algorithm has higher security and collision resistance. Compared with MD5 and SHA1, it can better resist various password attacks.
[0041] LLDP: Link Layer Discovery Protocol. Network devices can announce their own status to other devices by sending LLDPDU (Link Layer Discovery Protocol Data Unit) in the local network. It is a protocol that enables devices in the network to discover each other, announce their status, and exchange information.
[0042] As the core management unit of the server, BMC is responsible for functions such as server management, monitoring, regulation, and diagnosis throughout the entire life cycle of the server. BMC also has important functions such as controlling the server to power on and off, setting BIOS options, and triggering NMI interrupts. Therefore, the security of BMC is directly related to the normal operation of the server, the stability, and security of the customer's business system. Once the security of BMC cannot be guaranteed, at best, the stability of the server will be affected and the customer's business will be interrupted, and at worst, the customer's data will be leaked, causing serious economic losses.
[0043] Currently, the common remote management methods for BMC include Web, Redfish, SNMP, Syslog, and IPMI, etc. The common authentication methods include username + password, two-factor authentication, LDAP / AD authentication, and MD5 / SHA1 / SHA256 encryption authentication defined in the IPMI protocol, etc.
[0044] At the authentication management level of BMC, the existing technical solutions are mainly based on the username + password method. Among them, the password is encrypted and stored in BMC, or the user authentication information is stored in an independently built LDAP / AD server, and BMC interacts with the LDAP / AD server through the corresponding protocol to implement the user authentication process. In order to further prevent security problems caused by the leakage of the username or password, the commonly used solution is to divide the corresponding users according to their permissions. Different users have different permissions, and the permissions of a single user can be set. Or, introduce the mechanism of two-factor authentication, that is, when authenticating through username + password, combine the verification information, hardware token or software token for double authentication to ensure the security of BMC authentication.
[0045] When using the IPMI command to access BMC, BMC encrypts the password according to the algorithm negotiated with the IPMItool tool and transmits the encrypted password to IPMItool for authentication, ensuring that the user's password is transmitted in ciphertext during the transmission process to avoid the problem of password leakage caused by packet hijacking.
[0046] In summary, the currently adopted username + password authentication method, combined with the design of refined permissions and user level division, can improve the security of the server to a certain extent. However, with the frequent turnover of current maintenance personnel and the complex and changeable server usage environment, it is particularly easy to cause the leakage of the username or password, thus posing a certain security risk to the server application. Specifically, it includes but is not limited to the following aspects:
[0047] 1. When using the IPMItool tool to access BMC, the actually input username and password are in plain text. When the security of the operating environment cannot be guaranteed, it is extremely easy to cause password leakage and pose a security risk.
[0048] 2. Through refined permissions and permission level division, it can be ensured that low-level users cannot operate high-priority operations such as power on / off, log in to KVM (Kernel-based Virtual Machine), set BIOS options, and trigger NMI interrupts. However, when the personnel of high-level users are replaced or the operating environment does not have security, the leakage of high-level users is also likely to pose a security risk to the server.
[0049] 3. For methods such as using verification information in LDAP / AD or two-factor authentication, hardware tokens, and software tokens, corresponding hardware devices or software systems need to be additionally built, which increases the maintenance cost to a certain extent.
[0050] 4. When the set user password is a weak password, it is relatively easy to be brute-forced, resulting in security risks.
[0051] 5. When required by IPMItool and the password is encrypted and transmitted from the BMC to IPMItool according to the agreed algorithm, the encryption algorithm for storing the password in ciphertext in the BMC is reversible and has low security.
[0052] 6. During the deployment process of the server, for unused interaction interfaces, users do not care about or reset the user names + passwords of such interfaces. According to the factory settings, default users are used. When such users are exploited, it will cause irreversible damage to the BMC and the server, affecting the stability and security of the server operation. Especially when one BMC can be accessed, the security of all servers in the local area network may be attacked, resulting in a reduction in security.
[0053] 7. Different BMC interaction interfaces (IPMI, Redfish, SNMP, etc.) have independent user names + passwords and separate authentication processes, lacking unity and increasing the maintenance difficulty.
[0054] In view of this, the present application uniformly reduces the user permissions of each interaction interface of all current BMCs, that is, by default, operations that seriously affect the server business functions such as power on / off, triggering NMI interrupts, and restoring factory settings are not supported. Based on the permission transition method proposed in the present application, the current permissions of users are upgraded to achieve the purpose of being able to operate high-level settings. Specifically, the permission transition method of the present application includes: in response to a permission transition start instruction sent by a target device, according to the preset number of verification levels, select a target number of auxiliary servers from the local area network, where the target number is the same as the number of verification levels; generate first verification information for each auxiliary server based on a preset method, and broadcast each first verification information to the local area network so that each auxiliary server can obtain second verification information corresponding to the first verification information, so that the target device can obtain the second verification information through each auxiliary server; determine whether all the second verification information sent by the target device matches the corresponding first verification information; if all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful, and the successful permission transition is used to represent that the current permission of the target device is upgraded from the first permission to the second permission, and the second permission is higher than the first permission.
[0055] Through the privilege transition method of the present application, in response to the privilege transition start instruction sent by the target device, according to the preset number of verification levels, a target number of auxiliary servers are selected from the local area network, and first verification information is generated for each auxiliary server based on a preset method, and each first verification information is broadcast to the corresponding auxiliary server by means of broadcasting in the local area network, so that the target device can obtain the second verification information corresponding to the first verification information through the auxiliary server. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the main server itself, it is determined that the privilege transition is successful, and the successful privilege transition is used to represent that the current privilege of the target device is upgraded from the first privilege to the second privilege. That is to say, this solution uses each auxiliary server to verify the identity of the target device, and only when the verification is passed, the current privilege of the target device is upgraded from the first privilege to the second privilege. Since the second privilege is higher than the first privilege, the management of some important functions of the server can be realized. Before the privilege transition, the privilege corresponding to the target device is the first privilege. Even if the user name or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0056] Combined with the specific application environment architecture or specific hardware architecture on which the execution of the privilege transition method depends, the specific application environment architecture or specific hardware architecture is described herein.
[0057] The present application provides a privilege transition system. As Figure 1 shown, the system includes a target device and a local area network deploying a switch and multiple servers. Among them, multiple servers deployed in the local area network can be connected to the switch through a network ( Figure 1 the solid line between the server and the switch in the figure), so that each server can obtain a corresponding IP (Internet Protocol Address) address. The target device and multiple servers in the local area network can be connected through a network, so that the target device and multiple servers in the local area network can communicate. Server management software can run on the target device, and users can manage multiple servers in the local area network through the server management software.
[0058] For example, as Figure 2As shown, when the user logs in to the server management software, multiple servers in the local area network can be displayed on the server management software interface. At this time, the user can log in to any server through the user name + password method and any authentication channel (for example, Web, Redfish, SNMP, Syslog, IPMI). For Figure 2 the server where the mouse is located, the user can log in to the server through the user name + password method. At this time, since the permissions corresponding to the user name + password are the first permissions (ordinary operation permissions), if the user needs to perform advanced operations on the server, the permission transition method provided by this application needs to be used to perform permission transition on the server, that is, upgrade the permissions corresponding to the user from the first permissions to the second permissions. Therefore, the server that needs to perform permission transition can be called the primary server. During the process of performing permission transition on the primary server, other servers in the local area network perform auxiliary verification, so the servers that perform auxiliary verification can be called secondary servers.
[0059] Table 1
[0060]
[0061] It should be noted that for the permission transition method of this application, when multiple servers in the local area network leave the factory, by default, all users of the BMC (including Web users, Redfish users, SNMP users, Syslog users, IPMI users, etc.) do not have the permission to perform advanced operations (the permission to perform advanced operations is the permission that affects the normal operation of the BMC and the server operating system services, for example, the BMC's factory reset, the server's power-on and power-off operations, NMI interrupts, etc. In the following text, the permission to perform advanced operations is also called the second permission). After the server deployment is completed, the permission transition method provided by this application is used to achieve permission transition to achieve the purpose of operating high-level permissions.
[0062] Based on this, the BMC in this application mainly provides the following several operation interfaces for the customer or the operation and maintenance background, and users with ordinary permissions (in the following text, ordinary permissions are also called first permissions) can call these interfaces.
[0063] 1. Parameter setting interface. This parameter setting interface is used to set relevant parameter information. Specifically, the parameter information includes enable status, verification level, preset transition success ratio, multi-channel enable, transition time, permission time, and so on. It should be noted that only users with the second-level permission can set and modify this parameter information. Of course, for the parameter information shown in Table 1, it can also be imported into the server's memory in the form of a parameter configuration file. By default, after the user sets the corresponding parameter information through the parameter setting interface, it will not take effect immediately, but only after restarting the server or restarting the BMC. The specific parameter information is shown in Table 1 as follows.
[0064] 2. Permission transition trigger interface. This permission transition trigger interface is used to trigger the permission transition of the currently logged-in user of the target device.
[0065] 3. Permission transition result query interface. This permission transition result query interface is used to return the result after the current user's permission transition. Specifically, it includes the user permission transition status (success, in progress, failed), and the transition response information (if the status is failed, it returns the reason for failure; if it is in progress, it returns the hostname of the next hop and the specified channel information). The information returned by this permission transition result query interface is shown in Table 2 as follows.
[0066] 4. Permission transition verification information input interface. This permission transition verification information input interface is used to input the verification query obtained from the secondary server to the primary server.
[0067] 5. Permission transition verification information query interface. This permission transition verification information query interface is used to query the verification information from the secondary server.
[0068] Table 2
[0069]
[0070] It should be understood that for the above-mentioned parameter setting interface, permission transition trigger interface, permission transition result query interface, permission transition verification information input interface, and permission transition verification information query interface, after the user logs in to any server in the way of username + password through the target device, the above-mentioned interfaces can be displayed to the user in the form of buttons on the server management software; of course, they can also be displayed to the user in the form of commands. Details are not elaborated here one by one, and the attached drawings are not listed one by one either.
[0071] After the permission transition method of this application is implemented in the server management software, for multiple servers in the local area network, by default, the verification level is 3, the transition ratio is 33%, the multi-channel enabling function is disabled, the transition time is 5 minutes, and the permission time is 1 hour. For the sake of easy explanation, the server whose permission transition is to be authenticated currently is called the primary server, and the server that realizes the permission transition of the Nth auxiliary primary server is called the secondary server N, where N starts from 0 to the verification level parameter - 1.
[0072] In practical applications, multiple servers in the local area network can broadcast their basic information to the BMC in other servers in the local area network through LLDP. Specifically, in the custom data field of LLDP, the SN (serial number, Serial Number, abbreviated as SN) of its own BMC, the valid time of the broadcast message (the corresponding basic information becomes invalid after this time, so it is necessary to continuously refresh its own basic information within the valid time of the broadcast message), the supported channel situation, and the IP address list of the target devices that have successfully transitioned currently are included. The basic information of the server broadcast is specifically shown in Table 3.
[0073] Table 3
[0074]
[0075] To enable those skilled in the art of this technology to better understand the solution of this application, the following further detailed description of this application will be given in combination with the accompanying drawings and specific implementation manners. In addition, it should be noted that before using the permission transition method of this application, the corresponding parameter information can be set for each server in the local area network through the parameter setting interface mentioned above or through the parameter configuration file. In the permission transition method of this application, it is defaulted that all various parameter information is correctly set.
[0076] According to an embodiment of the present invention, an embodiment of a permission transition method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0077] In this embodiment, a permission transition method is provided, which can be used in the primary server. Figure 3 It is a flowchart of the permission transition method according to an embodiment of the present invention, as Figure 3 shown, and this process includes the following steps:
[0078] Step S301, in response to a permission transition start instruction sent by a target device, select a target number of secondary servers from the local area network according to the preset verification level number, and the target number is the same as the verification level number.
[0079] A Local Area Network (LAN) is a group of computers interconnected within a certain area.
[0080] The privilege transition start instruction is used to represent the process of starting the privilege transition. That is, the user can log in to the main server through the server management software and send a privilege transition start instruction to the main server through the privilege transition trigger interface mentioned above. In the actual application process, for Web users, they can send a privilege transition start instruction by clicking on the interface corresponding to the privilege transition trigger interface displayed on the server management software; for Redfish users, SNMP users, Syslog users, and IPMI users, they can send a privilege transition start instruction to the main server through the privilege transition trigger interface using the corresponding commands.
[0081] For the main server, after receiving the privilege transition start instruction sent by the target device, it can start the privilege transition process. That is, the main server selects the target number of auxiliary servers from the local area network according to the verification level mentioned above to assist the privilege transition of the target device. In the actual application process, the main server can randomly select the target number of auxiliary servers from multiple servers other than the main server in the local area network. Of course, for the main server, it can also specify the target number of auxiliary servers according to the running status of multiple servers other than the main server in the local area network to assist the privilege transition of the target device.
[0082] For example, when the above-mentioned verification level is 3 by default, the main server selects 3 servers from multiple servers other than the main server in the local area network as auxiliary servers.
[0083] After the main server selects the target number of auxiliary servers from the local area network according to the preset verification level number, the main server can also display the first identification information (such as the SN code) and the first channel information of the auxiliary servers on the interface of the server management software, which is convenient for users to know from which auxiliary servers to obtain the second verification information through which authentication channels.
[0084] Step S302: Generate the first verification information for each auxiliary server based on a preset method, and broadcast each first verification information to the local area network so that each auxiliary server can obtain the second verification information corresponding to the first verification information, so that the target device can obtain the second verification information through each auxiliary server.
[0085] The first verification information includes, but is not limited to, numbers, letters, Chinese characters, graphics, or any combination of numbers, letters, and Chinese characters in the form of graphics. That is, in this application, the actual form of the first verification information is not restricted, and it can be any form of verification information used for identity verification.
[0086] The preset method is a method for generating the first verification information that is preset in advance. For example, based on key pairs, random numbers, hash algorithms, time synchronization, or certificates, etc., the first verification information can be generated for each secondary server.
[0087] There are various implementation methods for broadcasting each first verification information to the local area network. For example, each first verification information can be broadcast to the local area network through UDP (User Datagram Protocol); it can also be broadcast to the local area network through the ARP (Address Resolution Protocol); it can also be broadcast to the local area network through the aforementioned LLDP protocol, and it can also be broadcast to the local area network through IGMP (Internet Group Management Protocol) multicast. This application does not restrict the actual form of broadcasting each first verification information to the local area network. In the actual application process, each first verification information can be broadcast to the local area network through any appropriate method.
[0088] In the actual application process, the first verification information and the second verification information can be the same or different. For example, after the secondary server obtains the first verification information, if the first verification information is encrypted, the secondary server can decrypt the first verification information to obtain the second verification information; if the first verification information is not encrypted, in order to further improve security, the secondary server can encrypt the first verification information to obtain the second verification information. Of course, after obtaining the first verification information, the secondary server can generate the second verification information again based on the preset method.
[0089] It should be noted that for the primary server, secondary server, and target device, their encryption algorithms or decryption algorithms are all built into the primary server, secondary server, or target device in advance according to actual needs. The encryption algorithm or decryption algorithm can be any suitable algorithm, and this application does not limit this.
[0090] Step S303, determine whether all the second verification information sent by the target device matches the corresponding first verification information.
[0091] Whether all the second verification information sent by the target device matches the corresponding first verification information can be whether the second verification information obtained by the target device from the first secondary server matches the first verification information given by the primary server to the first secondary server, and whether the second verification information obtained by the target device from the second secondary server matches the first verification information given by the primary server to the second secondary server, and so on.
[0092] When the first verification information is encrypted, after the secondary server obtains the first verification information, it decrypts the first verification information to obtain the second verification information. In this way, it is determined whether all the second verification information sent by the target device is the same as the corresponding first verification information; when the first verification information is not encrypted, the secondary server encrypts the first verification information to obtain the second verification information. After the target device obtains the second verification information, it can decrypt the second verification information to obtain the decrypted second verification information. In this way, it is determined whether all the second verification information sent by the target device is the same as the corresponding first verification information; after the secondary server obtains the first verification information, it can generate the second verification information again based on a preset method. In this way, it is determined whether all the second verification information sent by the target device matches the corresponding first verification information.
[0093] The user can send the second verification information obtained from each secondary server to the primary server through the permission transition verification information input interface of the primary server.
[0094] Step S304, if all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful. The successful permission transition is used to represent that the current permission of the target device is upgraded from the first permission to the second permission, and the second permission is higher than the first permission.
[0095] During the process of performing a permission transition on the target device, the user can also query the progress of this permission transition in a timely manner through the permission transition query interface. After the current permission of the target device is upgraded from the first permission to the second permission, relevant information indicating the successful permission transition can be returned in the interface of the server management software so that the user can know in a timely manner that this permission transition has been successful, which is convenient for the user to perform advanced operations on the server in a timely manner within the permission validity period.
[0096] It should be noted that the permission transition in this application can upgrade the user's current permission, that is, upgrade the user's current permission from the first permission to the second permission, so that the user can perform advanced operations on the primary server. For example, setting the power on / off of the server, triggering an NMI interrupt, and setting BIOS options, etc.
[0097] The privilege transition method provided in this embodiment responds to a privilege transition start instruction sent by a target device. According to a preset number of verification levels, a target number of auxiliary servers are selected from a local area network, and first verification information is generated for each auxiliary server based on a preset method. Then, by broadcasting in the local area network, each first verification information is broadcast to the corresponding auxiliary server, so that the target device can obtain second verification information corresponding to the first verification information through the auxiliary servers. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored in the main server itself, it is determined that the privilege transition is successful, and the successful privilege transition is used to represent upgrading the current privilege of the target device from a first privilege to a second privilege. That is to say, this solution uses each auxiliary server to verify the identity of the target device, and only when the verification is passed, the current privilege of the target device is upgraded from the first privilege to the second privilege. Since the second privilege is higher than the first privilege, this can achieve the management of some important functions of the server. And before the privilege transition, the privilege corresponding to the target device is the first privilege. Even if the user's username or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0098] In this embodiment, a privilege transition method is provided, which can be used in a main server. Figure 4 It is a flowchart of the privilege transition method according to an embodiment of the present invention, as Figure 4 shown, and this process includes the following steps:
[0099] Step S401, in response to a privilege transition start instruction sent by a target device, according to a preset number of verification levels, select a target number of auxiliary servers from a local area network, where the target number is the same as the number of verification levels.
[0100] Specifically, the above step S401 includes:
[0101] Step S4011, randomly select a server from the local area network as the auxiliary server of the first level according to a preset number of verification levels.
[0102] Step S4012, update the number of verification levels, so that the auxiliary server of the first level selects the auxiliary servers of the remaining levels from the remaining servers in the local area network according to the updated number of verification levels.
[0103] For the primary server, after receiving the permission transition start instruction sent by the target device, it can randomly select a target number of secondary servers from multiple servers in the local area network other than the primary server according to the preset verification level. Of course, the primary server can also randomly select a server from the local area network as the secondary server of the first level according to the preset number of verification levels. In this way, the server of the first level can also select a server from the remaining servers in the local area network as the server of the second level according to the updated verification level number, and so on until the verification level number is 0.
[0104] Regarding the update of the verification level number, after the primary server selects the secondary server of the first level, it can update the verification level number in a timely manner and send the updated verification level number to the secondary server of the first level. After the secondary server of the first level randomly selects the secondary server of the second level, it can continue to update the updated verification level number, and so on. Details will not be elaborated one by one later. For example, when the verification level number is 3, after the primary server selects the secondary server of the first level, it updates the verification level number to 2 and sends 2 to the secondary server of the first level. After the secondary server of the first level randomly selects the secondary server of the second level, it continues to update the verification level number to 1, and so on. Details will not be elaborated one by one later.
[0105] Of course, the primary server can also not update the verification level number but directly send the verification level number to the secondary server of the first level. Then the secondary server of the first level updates the verification level number. After the secondary server of the first level randomly selects the secondary server of the second level, it directly sends the updated verification level number to the secondary server of the second level, and so on. Details will not be elaborated one by one later. For example, when the verification level number is 3, the primary server directly sends 3 to the server of the first level. The secondary server of the first level updates 3 to 2 and sends it to the secondary server of the second level.
[0106] Step S402: Generate first verification information for each secondary server based on a preset method, and broadcast each first verification information to the local area network so that each secondary server can obtain second verification information corresponding to the first verification information, thereby enabling the target device to obtain the second verification information through each secondary server. For details, please refer to Figure 3 Step S302 of the embodiment shown, which will not be elaborated here.
[0107] Step S403: Determine whether all the second verification information sent by the target device matches the corresponding first verification information. For details, please refer to Figure 3 Step S303 of the embodiment shown, which will not be elaborated here.
[0108] Step S404: If all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful. The successful permission transition is used to indicate that the current permission of the target device is upgraded from the first permission to the second permission, and the second permission is higher than the first permission. For details, please refer to Figure 3 Step S304 of the embodiment shown, which will not be elaborated here.
[0109] The permission transition method provided in this embodiment responds to the permission transition start instruction sent by the target device. According to the preset number of verification levels, a server is randomly selected from the local area network as the secondary server of the first level, and the number of verification levels is updated, so that the secondary server of the first level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the updated number of verification levels, and generates the first verification information for each secondary server based on a preset method, and broadcasts each first verification information to the corresponding secondary server in the local area network by means of broadcasting. In this way, the target device can obtain the second verification information corresponding to the first verification information through the secondary server. After the target device obtains the second verification information, it can send each second verification information to the primary server, that is, the primary server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the primary server itself, it is determined that the permission transition is successful. The successful permission transition is used to indicate that the current permission of the target device is upgraded from the first permission to the second permission. That is to say, this solution uses each secondary server to verify the identity of the target device, and only when the verification is passed, the current permission of the target device is upgraded from the first permission to the second permission. Since the second permission is higher than the first permission, the management of some important functions of the server can be realized. Before the permission transition, the permission corresponding to the target device is the first permission. Even if the username or password of the user is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0110] In some optional embodiments, broadcasting each first verification information to the local area network includes: encrypting each first verification information to generate target verification information corresponding to each first verification information; in response to the channel configuration operation for each secondary server, obtaining the first channel information of each secondary server; obtaining the first identification information of each secondary server and the second identification information of the target device; for each secondary server, encapsulating the first identification information, the first channel information, the target verification information and the second identification information into a frame to obtain a plurality of first target frames; and broadcasting the plurality of first target frames to the local area network.
[0111] The first verification information can be a verification code. The first identification information of each auxiliary server and the second identification information of the target device can both be SN codes, but are not limited to SN codes, and can also be MAC (Media Access Control Address), IP address, UUID (Universally Unique Identifier), server name, etc. The first channel information of each auxiliary server can be Web, Redfish, SNMP, Syslog, or IPMI, etc.
[0112] In the actual application process, the primary server can randomly set the first channel information for each auxiliary server. Of course, the primary server can also obtain the first channel information of each auxiliary server through the built-in information.
[0113] In the above implementation, the primary server encrypts each first verification information, which can avoid the leakage of the first verification information during the broadcast process, and responds to the channel configuration operations of each auxiliary server, obtains the first channel information of each auxiliary server, and obtains the first identification information of each auxiliary server and the second identification information of the target device. In this way, the primary server can encapsulate the first verification information, the first channel information, the first identification information, and the second identification information corresponding to each auxiliary server into a frame and broadcast it in the local area network. Since it is a broadcast, multiple auxiliary servers in the local area network can receive all the first target frames. Therefore, after receiving the first target frame, the auxiliary server can compare its own identification information with the first identification information carried by the first target frame to determine whether the first target frame is sent to itself, so that the auxiliary server can quickly and accurately receive the first target frame sent by the primary server to itself, improving the response ability of the entire privilege transition process. Subsequently, during the process of the target device obtaining the first verification information, the auxiliary server can also use the first channel information carried by the first target frame and the second identification information of the target device to authenticate the target device, further improving the security of the server. It can receive the first verification information generated by the primary server for itself in a timely and accurate manner.
[0114] In some alternative embodiments, broadcasting each first verification information to the local area network further includes: encrypting the first verification information to generate target verification information corresponding to the first verification information; in response to a channel configuration operation for the secondary server at the first level, determining the first channel information of the secondary server at the first level; obtaining the first identification information of the secondary server at the first level and the second identification information of the target device; encapsulating the first identification information, the first channel information, the target verification information, and the second identification information of the server at the first level into a frame to obtain a first target frame; and broadcasting the first target frame to the secondary server at the first level, so that after receiving the first target frame, the secondary server at the first level can select secondary servers at the remaining levels from the remaining servers in the local area network according to the updated verification level number.
[0115] For the foregoing implementation, the primary server may randomly select a server from the local area network as the secondary server at the first level according to a preset verification level number. After selecting the secondary server at the first level, the primary server may encrypt the first verification information to prevent the first verification information from being leaked during the broadcast process; the primary server may encapsulate the target verification information, the obtained first channel information, the first identification information of the secondary server at the first level, and the second identification information of the target device, and broadcast the obtained first target frame in the local area network, so that the secondary server at the first level can obtain the first target frame. In this way, after receiving the first target frame, the secondary server at the first level can not only authenticate the target device by using the first channel information and the second identification information of the target device carried in the first target frame, but also select secondary servers at the remaining levels from the remaining service weapons in the local area network according to the updated verification level number.
[0116] In the actual application process, the primary server may also directly send the first target frame to the secondary server at the first level. Additionally, continuing with the previous embodiment, the primary server may also encapsulate the updated verification level number or the unupdated verification level number in the first target frame and send the updated verification level number or the unupdated verification level number to the secondary server at the first level in sequence.
[0117] In some alternative embodiments, before selecting a target number of secondary servers from the local area network according to a preset verification level number, the privilege transition method further includes: obtaining the current transition success ratio, where the current transition success ratio is the ratio of the number of servers in the local area network where the target device has successfully transitioned to the total number of servers in the local area network; if the current transition success ratio is greater than or equal to a preset transition success ratio, upgrading the current privilege of the target device from the first privilege to the second privilege; if the current transition success ratio is less than the preset transition success ratio, then selecting a target number of secondary servers from the local area network according to the preset verification level number.
[0118] The current transition success ratio is the ratio of the number of servers in which the target device has successfully completed the permission transition among all servers in the local area network to the total number of all servers in the local area network. It should be noted that for the target device to have successfully completed the permission transition among all servers, it is also necessary to ensure that it is within the permission time at this moment. Specifically, refer to the description of the transition success ratio in Table 1.
[0119] In the above implementation method, when the current transition success ratio is greater than or equal to the preset transition success ratio, the user permission can be directly transitioned. This ensures that the user background monitoring system does not need to frequently implement authentication transitions after being connected. Additionally, at this time, it can also be confirmed that the target device is reliable and trustworthy. When the current transition success ratio is less than the preset transition success ratio, the permission transition process is started, which can verify the identity of the target device and improve the security of the server.
[0120] In some alternative implementation methods, the permission transition method further includes: before selecting the target number of auxiliary servers from the local area network according to the preset verification level number, triggering the start of the transition time limit timer based on the permission transition start instruction; if the timing time of the transition time limit timer reaches the preset first time and all the second verification information sent by the target device has not been received, it is determined that the permission transition fails, and the permission transition failure is used to indicate that the current permission of the target device is maintained as the first permission; if the timing time of the transition time limit timer reaches the preset first time and all the second verification information does not fully match the corresponding first verification information, it is determined that the permission transition fails.
[0121] In the above implementation method, after receiving the permission transition start instruction sent by the target device, the start of the transition time limit timer is immediately triggered, and the transition time is timed by the transition time limit timer. This ensures that even if the username or password is leaked within the transition time, the impact on the security of the server can be minimized.
[0122] In some alternative implementation methods, if all the second verification information fully matches the corresponding first verification information, it is determined that the permission transition is successful, including: if the timing time of the transition time limit timer has not reached the preset first time and all the second verification information fully matches the corresponding first verification information, it is determined that the permission transition is successful. That is to say, within the transition time limit, the target device obtains all the second verification information from all the auxiliary servers, sends all the second verification information to the main and auxiliary servers, and all the second verification information fully matches the corresponding first verification information, indicating that the identity verification of the target device is passed. Therefore, the target device is safe and reliable, and at this time, it can be determined that the permission transition of the target device is successful.
[0123] In some alternative embodiments, the permission transition method further includes: after upgrading the current permission of the target device from a first permission to a second permission, triggering the start of a permission time limit timer based on the upgrade operation of upgrading the current permission of the target device from the first permission to the second permission; if the timing time of the permission time limit timer reaches a preset second time, or in response to an exit instruction sent by the target device, restoring the current permission of the target device from the second permission to the first permission.
[0124] In the above implementation, after the primary server upgrades the current permission of the target device from the first permission to the second permission, it can immediately start a permission time limit timer. If the timing time of the permission time limit timer reaches the preset second time (i.e., the permission time shown in Table 1), the current permission of the target device is immediately restored or downgraded from the second permission to the first permission, making the security of the server relatively high. Of course, if the timing time of the permission time limit timer does not reach the permission time, and an exit instruction sent by the target device is received, the current permission of the target device is immediately restored from the second permission to the first permission, thus avoiding the impact on the security of the server caused by the leakage of the user's username or password.
[0125] In this embodiment, a permission transition method is provided, which can be used in the secondary server. Figure 5 It is a flowchart of the permission transition method according to an embodiment of the present invention, as Figure 5 shown, and the process includes the following steps:
[0126] Step S501, obtain second verification information corresponding to the first verification information broadcast by the primary server in the local area network. The first verification information is generated by the primary server for each of the target number of secondary servers in the local area network based on a preset method when responding to a permission transition start instruction sent by the target device according to a preset number of verification levels. The target number is the same as the number of verification levels. For details, please refer to Figure 3 the embodiments shown, and will not be elaborated here.
[0127] Step S502, in response to a query instruction sent by the target device, send the second verification information to the target device.
[0128] The query instruction is an instruction for querying the second verification information from the secondary server.
[0129] For the primary server, after randomly selecting a secondary server, it can display the relevant information of the secondary server, such as the first identification information and the first channel information of the server, on the interface of the server management software. Then, the user can know from which secondary servers to obtain the second verification information. After that, the user can query the second verification information through the permission transition verification information query interface on the secondary server. For the secondary server, after receiving the query instruction sent through the permission transition verification information query interface, it can send the second verification information to the target device.
[0130] In the permission transition method of this embodiment, the primary server responds to the permission transition start instruction sent by the target device, selects a target number of secondary servers from the local area network according to the preset number of verification levels, generates the first verification information for each secondary server based on a preset method, and broadcasts each first verification information to the corresponding secondary server through broadcasting in the local area network. The secondary server can obtain the second verification information corresponding to the first verification information through the first verification information broadcast by the primary server in the local area network. After receiving the query instruction sent by the target device, it can send the second verification information to the target device. In this way, the target device can obtain the second verification information from the secondary server in a timely manner. After the target device obtains the second verification information, it can send each second verification information to the primary server, that is, the primary server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the primary server itself correspondingly, it is determined that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission. That is to say, this solution uses each secondary server to verify the identity of the target device. Only when the verification is passed, the current permission of the target device is upgraded from the first permission to the second permission. Since the second permission is higher than the first permission, this can realize the management of some important functions of the server. And before the permission transition, the permission corresponding to the target device is the first permission. Even if the user name or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0131] In this embodiment, a permission transition method is provided, which can be used in a secondary server. Figure 6 It is a flowchart of the permission transition method according to an embodiment of the present invention. As Figure 6 shown, the process includes the following steps:
[0132] Step S601: Obtain a second verification message corresponding to a first verification message broadcast by the primary server in the local area network. The first verification message is generated by the primary server based on a preset number of verification levels when the primary server responds to a permission transition start instruction sent by the target device. The primary server selects a target number of secondary servers from the local area network and generates, for each secondary server, the first verification message based on a preset method. The target number is the same as the number of verification levels.
[0133] The above step S601 further includes:
[0134] Step S6011: Receive a first target frame broadcast by the primary server in the local area network. The first target frame carries first identification information of the secondary server and target verification information, and the target verification information is the encrypted first verification information.
[0135] After receiving the first target frame broadcast by the primary server in the local area network, the secondary server parses the first target frame to obtain the first identification information of the secondary server and the target verification information carried in the first target frame.
[0136] For the primary server, to prevent the first verification information from being leaked during the broadcast process, the first verification information is encrypted to generate the corresponding target verification information. At the same time, for the convenience of transmission and to reduce the number of broadcasts in the local area network, avoid network congestion and errors, the primary server can encapsulate, including but not limited to, the target verification information, the first identification information of the secondary server, etc. into a frame to obtain the first target frame. Therefore, for the secondary server, the secondary server can receive the first target frame. The secondary server parses the first target frame to obtain the first identification information and the target verification information carried in the first target frame.
[0137] Step S6012: If the first identification information is the same as the third identification information corresponding to the secondary server, decrypt the target verification information in the first target frame to obtain the second verification information.
[0138] As can be seen from step S6011, the first identification information is the identification information of the secondary server, but the first identification information is parsed from the first target frame. The third identification information is also the identification information of the secondary server, which is the identification information carried by the secondary server itself and has not undergone network transmission. That is to say, although both the first identification information and the third identification information are the identification information of the secondary server, their sources are different.
[0139] For the master server, it broadcasts the first target frames of multiple slave servers in the local area network. For a slave server, it can obtain all the first target frames broadcast by the master server. To facilitate the slave server to identify which first target frame is broadcast by the master server for itself, the master server carries the first identification information of the corresponding slave server in the first target frame. After the slave server parses the first identification information in the first target frame, it can compare the first identification information with the third identification information carried by itself. If they are the same, it indicates that the first target frame is broadcast by the master server for itself, so it saves the first target frame. And decrypts the target verification information carried in the first target frame to obtain the second verification information.
[0140] Step S6013, if the first identification information is different from the third identification information, then enter the step of receiving the first target frame broadcast by the master server in the local area network.
[0141] After the slave server parses the first identification information in the first target frame, it can compare the first identification information with the third identification information carried by itself. If they are different, it indicates that the first target frame is sent by the master server for another slave server, so it can perform packet loss processing on the first target frame and continue to receive other first target frames broadcast by the master server in the local area network until the slave server obtains the first target frame broadcast by the master server for itself.
[0142] Step S602, in response to the query instruction sent by the target device, send the second verification information to the target device. For details, please refer to Figure 5 Step S502 shown, which will not be elaborated here.
[0143] In the permission transition method of this embodiment, after the secondary server receives the first target frame broadcast by the primary server in the local area network, it parses the first target frame to obtain the first identification information of the secondary server and the target verification information carried in the first target frame. If the first identification information is the same as the third identification information corresponding to the secondary server, it decrypts the target verification information in the first target frame to obtain the second verification information. After receiving the query instruction sent by the target device, it can send the second verification information to the target device. In this way, the target device can obtain the second verification information from the secondary server in a timely manner. After the target device obtains the second verification information, it can send each second verification information to the primary server, that is, the primary server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the primary server itself, it is determined that the permission transition is successful. This successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission. That is to say, this solution uses each secondary server to verify the identity of the target device. Only when the verification is passed, the current permission of the target device is upgraded from the first permission to the second permission. Since the second permission is higher than the first permission, it is possible to manage some important functions of the server. And before the permission transition, the permission corresponding to the target device is the first permission. Even if the user's username or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0144] In some optional embodiments, after receiving the first target frame broadcast by the primary server in the local area network, the method further includes: determining whether the updated verification level number is 0; when the updated verification level number is not 0, according to the updated verification level number, selecting a server from the remaining servers in the local area network as the secondary server of the next level; updating the verification level number again so that the secondary server of the next level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the verification level number updated again.
[0145] As described above, the first target frame may carry the updated verification level number, or may not carry the updated verification level number. When the first target frame carries the updated verification level number, the secondary server can obtain the updated verification level number by parsing the first target frame. When the first target frame does not carry the updated verification level number, the primary server can broadcast the updated verification level number separately in the local area network.
[0146] When the updated number of verification levels is not 0, according to the updated number of verification levels, select a server from the remaining servers in the local area network as the secondary server of the next level. For example, as the secondary server of the second level. This step-by-step approach helps ensure the accuracy and integrity of verification. The secondary server of each level can perform further verification based on the results of the previous level, thereby improving the accuracy of verification.
[0147] In some alternative embodiments, the permission transition method further includes: after selecting a server from the remaining servers in the local area network as the secondary server of the next level according to the updated number of verification levels, randomly generate the third verification information for the secondary server of the next level based on a preset method, and encrypt the third verification information; in response to the channel configuration operation for the secondary server of the next level, obtain the first channel information of the secondary server of the next level; obtain the first identification information of the secondary server of the next level and the second identification information of the target device; encapsulate the first identification information, the first channel information, the encrypted third verification information, and the second identification information of the secondary server of the next level into a frame to obtain the second target frame, and broadcast the second target frame to the secondary server of the next level and the primary server.
[0148] After broadcasting the second target frame to the secondary server of the next level, the secondary server of the next level can continue to select the secondary servers of the remaining levels from the remaining servers in the local area network based on the obtained updated number of verification levels. At the same time, broadcasting the second target frame to the primary server is to pre-store the third verification information in the second target frame on the primary server in advance, so that it is convenient for the primary server to match with the pre-stored third verification information after the target device sends the decrypted third verification information to the primary server.
[0149] In the above implementation manner, the secondary server of the previous level randomly generates the third verification information for the secondary server of the next level, and encapsulates the third verification information, the first channel information of the secondary server of the next level, the encrypted third verification information, and the second identification information of the target device into a frame to obtain the second target frame, and broadcasts it to the secondary server of the next level, which can enhance the security in the process of authenticating the identity of the target device.
[0150] In some alternative embodiments, the first target frame also carries the second identification information of the target device and the first channel information of the secondary server. In response to the query instruction sent by the target device, sending the second verification information to the target device includes: using the data information carried in the query instruction to obtain the fourth identification information of the target device and the second channel information of the secondary server; if the second identification information of the target device is the same as the fourth identification information, and the first channel information is the same as the second channel information, then send the second verification information to the target device.
[0151] Regarding the second identification information and the fourth identification information, both are identification information of the target device and are used to uniquely identify the target device. However, the sources of the second identification information and the fourth identification information are different. For the second identification information, it is carried in the first target frame, that is to say, it is informed by the primary server to the secondary server. The fourth identification information is obtained from the query instruction sent by the target device.
[0152] Regarding the first channel information and the second channel information, both are channel information of the secondary server, but the sources of the first channel information and the second channel information are different. The first channel information is the channel information of the secondary server that the primary server responds to the target device channel configuration operation or the primary server sets. And the second channel information is obtained by the target device after the primary server displays the channel information of the secondary server on the interface of the server management software. After the target device obtains it, along with the query instruction, it sends the second channel information of the secondary server to the secondary server.
[0153] For example, assume that at this time, there are a primary server, a first-level secondary server, a second-level secondary server, and a third-level secondary server. The primary server broadcasts the first verification information to the first-level secondary server, the first-level secondary server broadcasts the second verification information to the second-level secondary server, and the second-level secondary server broadcasts the third verification information to the third-level secondary server. If the target device wants to obtain the first verification information, the second verification information, and the third verification information from the first-level secondary server, the second-level secondary server, and the third-level secondary server respectively, it needs to send query instructions to the first-level secondary server, the second-level secondary server, and the third-level secondary server respectively to obtain all the first verification information, the second verification information, and the third verification information.
[0154] If the second identification information and the fourth identification information of the target device are the same, and the first channel information and the second channel information of the secondary server are the same, it indicates that the authentication of the target device is passed, and then the second verification information is sent to the target device. In this way, through a strict verification process, the identity of the target device can be accurately verified, avoiding permission escalation for a forged target device or a template device under malicious attack.
[0155] In some optional embodiments, when the target device is in the process of obtaining relevant verification information of the auxiliary server, the auxiliary server of the last level needs to input the verification information to the server of the second-to-last level through the authority transition verification information input interface of the server of the second-to-last level after obtaining the corresponding verification information. The server of the second-to-last level verifies the verification information, and if the second identification information and the fourth identification information of the target device are the same, and the first channel information and the second channel information of the auxiliary server are the same, the second verification information is sent to the target device.
[0156] For example, it is assumed that at this time, there are a main server, a first-level auxiliary server, a second-level auxiliary server, and a third-level auxiliary server. The main server broadcasts the first verification information to the first-level auxiliary server, the first-level auxiliary server broadcasts the second verification information to the second-level auxiliary server, and the second-level auxiliary server broadcasts the third verification information to the third-level auxiliary server. If the target device wants to obtain the first verification information, the second verification information, and the third verification information from the first-level auxiliary server, the second-level auxiliary server, and the third-level auxiliary server, respectively. The target device needs to obtain the third verification information from the third-level auxiliary server, and then input the third verification information to the second-level auxiliary server, and the second-level auxiliary server will send the second verification information to the target device, and the same is true for the auxiliary servers of the previous level. Finally, after the target device sends all the first verification information, the second verification information, and the third verification information to the main server, the main server determines that the authority transition is successful. Or, after the target device sends the first verification information to the main server, the main server determines that the authority transition is successful.
[0157] In some optional implementations, the permission transition method further includes: determining whether the target device has queried the second verification information; if the target device has queried the second verification information, deleting the second verification information from the local storage. When the auxiliary server has been queried for the second verification information normally, the second verification information is deleted from the local cache of the auxiliary server, so that the uniqueness of the query can be guaranteed.
[0158] In this embodiment, a permission transition system is provided. The permission transition system includes a target device, a main server, and multiple auxiliary servers. Among them, the main server and the multiple auxiliary servers are in the same local area network. The target device is communicatively connected to the main server and the multiple auxiliary servers. Among them, the target device sends a permission transition start instruction to the main server; the main server responds to the permission transition start instruction sent by the target device, selects a target number of auxiliary servers from the local area network according to the preset number of verification levels, generates first verification information for each auxiliary server based on a preset method, and broadcasts each first verification information to the local area network. The target number is the same as the number of verification levels; each auxiliary server obtains second verification information corresponding to the first verification information broadcast by the main server in the local area network; the target device sends a query instruction to each auxiliary server; the auxiliary server responds to the query instruction sent by the target device and sends the second verification information to the target device; the main server determines whether all the second verification information sent by the target device matches the corresponding first verification information. If all the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission, and the second permission is higher than the first permission.
[0159] The main server of the permission transition system responds to the permission transition start instruction sent by the target device, selects a target number of auxiliary servers from the local area network according to the preset number of verification levels, generates first verification information for each auxiliary server based on a preset method, and broadcasts each first verification information to the corresponding auxiliary server by broadcasting in the local area network. In this way, the target device can obtain the second verification information corresponding to the first verification information through the auxiliary server. After the target device obtains the second verification information, it can send each second verification information to the main server, that is, the main server receives the second verification information sent by the target device. When all the second verification information matches the first verification information stored by the main server itself, it is determined that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission. That is to say, this solution uses each auxiliary server to verify the identity of the target device. Only when the verification is passed, the current permission of the target device is upgraded from the first permission to the second permission. Since the second permission is higher than the first permission, this can realize the management of some important functions of the server. And before the permission transition, the permission corresponding to the target device is the first permission. Even if the user's username or password is leaked, it will not affect the security of the server. Therefore, this solution can solve the problem of low security of the server.
[0160] For ease of understanding, as Figure 7 and Figure 8As shown in the figure, an embodiment of the present application further provides a schematic flowchart of a permission transition method. Among them, on the main server side, the execution process of the main server includes Figure 7 the steps S701 to S720 shown in the figure. On the auxiliary server side, the execution process of the auxiliary server includes Figure 8 the steps S801 to S806 shown in the figure. Among them,
[0161] On the main server side:
[0162] Step S701, configure parameter information in multiple servers in the local area network.
[0163] Step S702, for multiple servers in the local area network, each server broadcasts its own basic information in the local area network.
[0164] Step S703, for each server, receive the basic information broadcast by other servers, update the cache, and execute steps S712 to S715.
[0165] Step S704, in response to the permission transition start instruction sent by the target device, and execute steps S716 to S720.
[0166] Step S705, determine the current transition success ratio according to the basic information of each server in the cache.
[0167] Step S706, determine whether the current transition success ratio is greater than or equal to the preset transition success ratio. If the current transition success ratio is greater than or equal to the preset transition success ratio, execute step S711 to determine that the permission transition is successful; if the current transition success ratio is less than the preset transition success ratio, execute steps S707 to S711.
[0168] Step S707, select a target number of auxiliary servers from the local area network according to the preset number of verification levels.
[0169] Step S708, generate first verification information for each auxiliary server, obtain the first channel information and first identification information of each auxiliary server, and obtain the second identification information of the target device. Package the first verification information, first channel information, first identification information of each server and the second identification information of the target device into a frame to obtain the first target frame and broadcast it to each auxiliary server.
[0170] Step S709, at this time, the main server waits for the second verification information obtained by the target device from each auxiliary server. That is, receive the second verification information sent by the target device.
[0171] Step S710, determine whether all the second verification information matches the corresponding first verification information. That is, the master server determines whether all the second verification information obtained from each slave server sent by the target device matches the first verification information stored in its own cache. If all match, it is determined that the permission transition is successful, and step S711 is executed. If not all match, step S718 is executed.
[0172] Step S711, determine that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission.
[0173] Step S712, for each server in the local area network, after receiving the basic information of other servers, start a basic information timer to time the basic information of each server.
[0174] Step S713, during the timing of the basic information timer, determine whether the basic information is received again. If the basic information is received again, step S703 is executed; if the basic information is not received again, steps S714 and S715 are executed.
[0175] Step S714, determine whether it times out, that is, determine whether the basic information timer reaches the valid time of the broadcast message. If the basic information timer corresponding to this basic information times out, delete the basic information cached in the cache, that is, execute step S715. If the basic information timer corresponding to this basic information does not time out, go to step S713.
[0176] Step S715, delete the basic information cached in the cache.
[0177] Step S716, in response to the permission transition start instruction sent by the target device, trigger the start of the transition time limit timer.
[0178] Step S717, determine whether it times out, that is, whether the timing time of the transition time limit timer reaches the transition time. If the timing time of the transition time limit timer reaches the transition time, execute step S718; if the timing time of the transition time limit timer does not reach the transition time, execute steps S719 and S720.
[0179] Step S718, determine that the permission transition fails.
[0180] Step S719, determine whether the permission transition is successful. If the permission transition is successful, delete the transition timer; if the permission transition fails, execute steps S717 and S718.
[0181] Step S720, delete the transition time limit timer.
[0182] On the secondary server side:
[0183] Step S801: For multiple servers in the local area network, each server broadcasts its basic information in the local area network.
[0184] Step S802: Determine whether the first target frame is received; if the first target frame is received, execute steps S803 to S806; if the first target frame is not received, go to step S802.
[0185] Step S803: Decode the first target frame to obtain the second verification information.
[0186] Step S804: Determine whether a query instruction is received; if the query instruction is received, execute steps S805 and S806; if the query instruction is not received, go to step S804.
[0187] Step S805: Determine whether the authentication passes, that is, whether the second identification information of the target device in the first target frame is the same as the fourth identification information carried in the query instruction of the target device, and whether the first channel information of the secondary server in the first target frame is the same as the second channel information carried in the query instruction; if they are the same, determine that the authentication passes and execute step S806; if they are not the same, determine that the authentication fails and go to step S804.
[0188] Step S806: Determine whether the target device has queried the second verification information on the secondary server. If it is determined that the target device has queried the second verification information on the secondary server, delete the first target frame in the cache.
[0189] For ease of understanding, as Figure 9 and Figure 10 shown, the embodiments of the present application also provide a flowchart of a main privilege transition method. Among them, on the primary server side, the execution process of the primary server includes Figure 9 the steps S901 to S920 shown.
[0190] On the secondary server side, the execution process of the secondary server includes Figure 10Steps S1001 to S1010 as shown. It should be noted that the main difference between this embodiment and the previous one lies in the different selection methods of the secondary servers. In this embodiment, the primary server randomly selects 1 secondary server according to the verification level number, and then randomly generates the verification information of the secondary server, obtains the first channel information and the first identification information of the secondary server, and sends them to the secondary server through LLDP. Then, the verification level number is decreased by 1. Then, the secondary server randomly selects a server in its cache as the lower-level secondary server and automatically generates the verification information of the lower-level secondary server, etc. (not repeated here), until the verification level number is reduced to 0. Each secondary server sends the verification information randomly generated by itself to the primary server.
[0191] On the primary server side:
[0192] Step S901, configure parameter information among multiple servers in the local area network.
[0193] Step S902, for multiple servers in the local area network, each server broadcasts its own basic information in the local area network.
[0194] Step S903, for each server, receive the basic information broadcast by other servers, update the cache, and execute steps S912 to S915.
[0195] Step S904, in response to the permission transition start instruction sent by the target device, and execute steps S716 to S720.
[0196] Step S905, determine the current transition success ratio according to the basic information of each server in the cache.
[0197] Step S906, determine whether the current transition success ratio is greater than or equal to the preset transition success ratio. If the current transition success ratio is greater than or equal to the preset transition success ratio, execute step S911 and determine that the permission transition is successful; if the current transition success ratio is less than the preset transition success ratio, execute steps S907 to S911.
[0198] Step S907, according to the preset verification level number, select 1 server from the local area network as the secondary server of the first level, so that the secondary server of the first level selects the secondary servers of the remaining levels from the remaining servers according to the updated verification level number.
[0199] Step S908: Generate the first verification information for the secondary servers at the first level, obtain the first channel information and the first identification information of the secondary servers at the first level, and obtain the second identification information of the target device. Package the first verification information, the first channel information, the first identification information of the secondary servers at the first level, and the second identification information of the target device into a frame to obtain a second target frame, and broadcast it to the secondary servers at the first level. The steps for the secondary servers at other levels are similar and will not be elaborated here one by one. Meanwhile, the primary server also needs to receive the target frames sent by each secondary server in the local area network to the secondary servers at the lower level, so as to obtain the verification information sent by each secondary server to the secondary servers at the lower level.
[0200] Step S909: At this time, the primary server waits for the verification information obtained by the target device from each secondary server, that is, receives the verification information obtained by the target device from each secondary server.
[0201] Step S910: Determine whether all the verification information sent by the target device matches the verification information stored in the primary server. If all match, it is determined that the permission transition is successful, and Step S911 is executed. If not all match, then Step S918 is executed.
[0202] Step S911: Determine that the permission transition is successful. The successful permission transition is used to represent upgrading the current permission of the target device from the first permission to the second permission.
[0203] Step S912: For each server in the local area network, after receiving the basic information of other servers, start a basic information timer to time the basic information of each server.
[0204] Step S913: During the timing of the basic information timer, determine whether the basic information is received again. If the basic information is received again, then Step S903 is executed; if the basic information is not received again, then Step S914 and Step S915 are executed.
[0205] Step S914: Determine whether it times out, that is, determine whether the basic information timer reaches the valid time of the broadcast message. If the basic information timer corresponding to this basic information times out, delete the basic information cached in the cache, that is, execute Step S915. If the basic information timer corresponding to this basic information does not time out, then go to Step S913.
[0206] Step S915: Delete the basic information cached in the cache.
[0207] Step S916: In response to the permission transition start instruction sent by the target device, trigger the start of the transition time limit timer.
[0208] Step S917, determine whether it times out, that is, whether the timing time of the transition aging timer reaches the transition time. If the timing time of the transition aging timer reaches the transition time, execute Step S918; if the timing time of the transition aging timer does not reach the transition time, execute Step S919 and Step S920.
[0209] Step S918, determine that the permission transition fails.
[0210] Step S919, determine whether the permission transition is successful. If the permission transition is successful, delete the transition timer; if the permission transition fails, execute Step S917 and Step S918.
[0211] Step S920, delete the transition aging timer.
[0212] On the secondary server side:
[0213] Step S1001, for multiple servers in the local area network, each server broadcasts its own basic information in the local area network.
[0214] Step S1002, determine whether the first target frame is received; if the first target frame is received, execute Step S1003, Step S1008, and Step S1010; if the first target frame is not received, go to Step S1002.
[0215] Step S1003, decode the first target frame to obtain the second verification information.
[0216] Step S1004, determine whether the updated verification level is 0. If the updated verification level is not 0, execute Step S1005 to Step S1007; if the updated verification level is 0, execute Step S1008 to Step S1010.
[0217] Step S1005, according to the updated verification level number, select a server from the remaining servers in the local area network as the secondary server of the next level.
[0218] Step S1006, encapsulate the first identification information, the first channel information, the encrypted third verification information, and the second identification information of the secondary server of the next level into a frame to obtain the second target frame.
[0219] Step S1007, broadcast the second target frame to the secondary server of the next level and the primary server.
[0220] Step S1008, determine whether a query instruction is received; if a query instruction is received, execute Step S1009 and Step S1010; if a query instruction is not received, go to Step S1008.
[0221] Step S1009, determine whether the authentication passes, that is, whether the second identification information of the target device in the first target frame is the same as the fourth identification information carried in the query instruction of the target device, and whether the first channel information of the secondary server in the first target frame is the same as the second channel information carried in the query instruction; if they are the same, determine that the authentication passes and execute Step 1010, if they are not the same, determine that the authentication fails and go to Step S1008.
[0222] Step S1010, determine whether the target device has queried the second verification information on the secondary server. If it is determined that the second verification information on the secondary server has been queried, delete the first target frame in the cache.
[0223] The privilege transition method of the present application reduces the operation privileges of the user name and password, and the default user privileges do not have the privileges that affect the operation, stability and security of the server, so as to solve the potential security hazards that may be brought by the leakage of the user name or password.
[0224] The privilege transition method of the present application can solve the additional costs brought by building LDAP / AD or hardware tokens in two-factor authentication, that is, the built server cluster itself can complete the high-security user authentication logic without building additional hardware and software systems, reducing the maintenance cost.
[0225] The privilege transition method of the present application can solve the potential security hazards that may be brought after the brute force cracking of weak passwords. Even if the weak password is brute force cracked, the impact on the security of the server is relatively small.
[0226] The privilege transition method of the present application can solve the hidden danger that the current user only sets the user name + password for the used interaction interface, while other interaction interfaces use the default user information of the server factory, and relevant personnel log in to the BMC through the default user information of other channels to cause damage.
[0227] The privilege transition method of the present application can solve the problem that the security authentication processes of different interfaces of the BMC lack unified processing logic, the authentication processes and logical security performances of each interface are different, and the security upgrades of each module are not unified, resulting in great maintenance difficulty.
[0228] The privilege transition method of the present application includes timing restrictions both in the privilege transition stage and after the privilege is obtained, ensuring that the impact on the server is minimized when the user name is leaked or the user privilege transition is successful within the timing time.
[0229] The privilege transition method of this application uses the commonly used LLDP in current embedded products as the way for different servers in the local area network to interact, and borrows the user-defined field in LLDP to customize different formats of information, without the need to additionally integrate a network protocol stack, and uses the characteristics of limited local area network propagation and communication of this protocol to achieve the security of network information dissemination.
[0230] Based on the characteristic of the dynamic timed broadcast information of LLDP, the privilege transition method of this application can implement the dynamic management function of server replacement in the local area network, without manual intervention, reducing the labor cost.
[0231] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method.
[0232] The embodiment of this application also provides a privilege transition device, as Figure 11 shown. This device is applied to the main server, and this device includes:
[0233] A first selection module 1101, configured to, in response to a privilege transition start instruction sent by a target device, select a target number of secondary servers from the local area network according to a preset number of verification levels, where the target number is the same as the number of verification levels.
[0234] A generation module 1102, configured to generate first verification information for each secondary server based on a preset method, and broadcast each first verification information to the local area network, so that each secondary server obtains second verification information corresponding to the first verification information, so that the target device obtains the second verification information through each secondary server.
[0235] A first determination module 1103, configured to determine whether all the second verification information sent by the target device matches the corresponding first verification information.
[0236] A first determination module 1104, configured to, if all the second verification information matches the corresponding first verification information, determine that the privilege transition is successful. The successful privilege transition is used to represent upgrading the current privilege of the target device from a first privilege to a second privilege, and the second privilege is higher than the first privilege.
[0237] In some optional implementation manners, the first selection module includes a first selection sub-module and an update sub-module. Among them, the first selection sub-module is configured to randomly select a server from the local area network as the secondary server of the first level according to the preset number of verification levels; the update sub-module is configured to update the number of verification levels, so that the secondary server of the first level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the updated number of verification levels.
[0238] In some alternative embodiments, the generating module includes a first generating sub-module, a first determining sub-module, a first obtaining sub-module, a first encapsulating sub-module, and a first broadcasting sub-module. Among them, the first generating sub-module is configured to encrypt each first verification information to generate target verification information corresponding to each first verification information; the first determining sub-module is configured to, in response to a channel configuration operation for each secondary server, obtain the first channel information of each secondary server; the first obtaining sub-module is configured to obtain the first identification information of each secondary server and the second identification information of the target device; the first encapsulating sub-module is configured to, for each secondary server, encapsulate the first identification information, the first channel information, the target verification information, and the second identification information into a frame to obtain a plurality of first target frames; the first broadcasting sub-module is configured to broadcast the plurality of first target frames to the local area network.
[0239] In some alternative embodiments, the generating module further includes a second generating sub-module, a second determining sub-module, a second obtaining sub-module, a second encapsulating sub-module, and a second broadcasting sub-module. Among them, the second generating sub-module is configured to encrypt the first verification information to generate target verification information corresponding to the first verification information; the second determining sub-module is configured to, in response to a channel configuration operation for the secondary servers at the first level, obtain the first channel information of the secondary servers at the first level; the second obtaining sub-module is configured to obtain the first identification information of the secondary servers at the first level and the second identification information of the target device; the second encapsulating sub-module is configured to encapsulate the first identification information, the first channel information, the target verification information, and the second identification information of the servers at the first level into a frame to obtain a first target frame; the second broadcasting sub-module is configured to broadcast the first target frame to the secondary servers at the first level, so that after receiving the first target frame, the secondary servers at the first level select the secondary servers at the remaining levels from the remaining servers in the local area network according to the updated verification level number.
[0240] In some alternative embodiments, the apparatus further includes a second obtaining module and an upgrading module. Among them, the second obtaining module is configured to obtain the current transition success ratio before selecting a target number of secondary servers from the local area network according to a preset verification level number. The current transition success ratio is the ratio of the number of servers that the target device has successfully transitioned to in the local area network to the total number of servers in the local area network; the upgrading module is configured to upgrade the current permission of the target device from the first permission to the second permission if the current transition success ratio is greater than or equal to a preset transition success ratio; the first selection module is configured to, if the current transition success ratio is less than the preset transition success ratio, then select a target number of secondary servers from the local area network according to the preset verification level number.
[0241] In some alternative embodiments, the device further includes a first trigger module, a second determination module, and a third determination module. Among them, the first trigger module is used to trigger the start of a transition time limit timer based on a privilege transition start instruction before selecting a target number of secondary servers from the local area network according to a preset number of verification levels; the second determination module is used to determine that the privilege transition fails if all the second verification information sent by the target device has not been received when the timing time of the transition time limit timer reaches a preset first time. The failure of the privilege transition is used to indicate that the current privilege of the target device is maintained as the first privilege; the third determination module is used to determine that the privilege transition fails if all the second verification information does not match the corresponding first verification information when the timing time of the transition time limit timer reaches the preset first time.
[0242] In some alternative embodiments, the first determination module includes a first determination sub-module, which is used to determine that the privilege transition is successful if all the second verification information matches the corresponding first verification information when the timing time of the transition time limit timer has not reached the preset first time.
[0243] In some alternative embodiments, the device further includes a second trigger module and a recovery module. Among them, the second trigger module is used to trigger the start of a privilege time limit timer based on the upgrade operation of upgrading the current privilege of the target device from the first privilege to the second privilege after the current privilege of the target device is upgraded from the first privilege to the second privilege; the recovery module is used to restore the current privilege of the target device from the second privilege to the first privilege if the timing time of the privilege time limit timer reaches a preset second time, or in response to an exit instruction sent by the target device.
[0244] An embodiment of the present application also provides a privilege transition device, as Figure 12 shown. This device is applied to a secondary server, and the device includes:
[0245] A first acquisition module 1201, which is used to acquire second verification information corresponding to the first verification information broadcast by the primary server in the local area network. The first verification information is generated by the primary server for each secondary server based on a preset method when the primary server responds to a privilege transition start instruction sent by the target device, selects a target number of secondary servers from the local area network according to a preset number of verification levels, and the target number is the same as the number of verification levels.
[0246] A sending module 1202, which is used to send the second verification information to the target device in response to a query instruction sent by the target device.
[0247] In some alternative embodiments, the first acquisition module includes a receiving sub-module, a decryption sub-module, and a loop sub-module. The receiving sub-module is configured to receive a first target frame broadcast by the primary server in the local area network. The first target frame carries first identification information of the secondary server and target verification information, and the target verification information is the encrypted first verification information. The decryption sub-module is configured to decrypt the target verification information in the first target frame to obtain second verification information if the first identification information is the same as the third identification information corresponding to the secondary server. The loop sub-module is configured to enter the step of receiving the first target frame broadcast by the primary server in the local area network if the first identification information is different from the third identification information.
[0248] In some alternative embodiments, the device further includes a second determination module, a second selection module, and an update module. The second determination module is configured to determine whether the updated verification level number is 0 after receiving the first target frame broadcast by the primary server in the local area network. The second selection module is configured to select a server from the remaining servers in the local area network as the secondary server of the next level according to the updated verification level number if the updated verification level number is not 0. The update module is configured to update the verification level number again so that the secondary server of the next level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the verification level number updated again.
[0249] In some alternative embodiments, the device further includes an encryption module, a third determination module, a second acquisition module, a packaging module, and a broadcast module. The encryption module is configured to randomly generate third verification information for the secondary server of the next level based on a preset method and encrypt the third verification information after selecting a server from the remaining servers in the local area network as the secondary server of the next level according to the updated verification level number. The third determination module is configured to obtain the first channel information of the secondary server of the next level in response to a channel configuration operation for the secondary server of the next level. The second acquisition module is configured to obtain the first identification information of the secondary server of the next level and the second identification information of the target device. The packaging module is configured to package the first identification information, the first channel information, the encrypted third verification information, and the second identification information of the secondary server of the next level into a frame to obtain a second target frame. The broadcast module is configured to broadcast the second target frame to the secondary server of the next level and the primary server.
[0250] In some alternative embodiments, the first target frame further carries second identification information of the target device and first channel information of the secondary server. The sending module includes a third acquisition sub-module and a sending sub-module. Among them, the third acquisition sub-module is configured to use the data information carried in the query instruction to acquire fourth identification information of the target device and second channel information of the secondary server; the sending sub-module is configured to send the second verification information to the target device if the second identification information of the target device is the same as the fourth identification information, and the first channel information is the same as the second channel information.
[0251] In some alternative embodiments, the device further includes a fourth determination module and a deletion module. Among them, the fourth determination module is configured to determine whether the target device has queried the second verification information; the deletion module is configured to delete the second verification information from the local storage if the target device has queried the second verification information.
[0252] For the description of the features in the corresponding embodiments of the permission transition device, reference can be made to the relevant descriptions in the corresponding embodiments of the permission transition method, which will not be elaborated here one by one.
[0253] Embodiments of the present application also provide an electronic device, as Figure 13 shown, including a memory 1310 and a processor 1320. A computer program is stored in the memory 1310, and the processor 1320 is configured to run the computer program to execute the steps in any one of the above-described embodiments of the permission transition method.
[0254] Embodiments of the present application also provide a computer-readable storage medium, in which a computer program is stored. Among them, the computer program is configured to execute the steps in any one of the above-described embodiments of the permission transition method when running.
[0255] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical discs that can store computer programs.
[0256] Embodiments of the present application also provide a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any one of the above-described embodiments of the permission transition method.
[0257] Embodiments of the present application also provide another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any one of the above-described embodiments of the permission transition method.
[0258] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0259] The above has introduced in detail a method, device, system, equipment, storage medium, and program product for permission transition provided by this application. Specific examples are used herein to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A privilege transition method, characterized in that, Applied to the main server, the method includes: In response to a permission transition start instruction sent by a target device, according to a preset number of verification levels, select a target number of secondary servers from the local area network, where the target number is the same as the number of verification levels; Generate first verification information for each of the secondary servers based on a preset method, and broadcast each of the first verification information to the local area network, so that each of the secondary servers obtains second verification information corresponding to the first verification information, thereby enabling the target device to obtain the second verification information through each of the secondary servers; Determine whether all of the second verification information sent by the target device matches the corresponding first verification information; If all of the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful. The successful permission transition is used to indicate that the current permission of the target device is upgraded from a first permission to a second permission, and the second permission is higher than the first permission.
2. The method according to claim 1, characterized in that Selecting a target number of secondary servers from the local area network according to a preset number of verification levels includes: Randomly select one server from the local area network as the secondary server of the first level according to the preset number of verification levels; Update the number of verification levels, so that the secondary server of the first level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the updated number of verification levels.
3. The method according to claim 1, wherein Broadcasting each of the first verification information to the local area network includes: Encrypt each of the first verification information to generate target verification information corresponding to each of the first verification information; In response to a channel configuration operation for each of the secondary servers, obtain the first channel information of each of the secondary servers; Obtain the first identification information of each of the secondary servers and the second identification information of the target device; For each of the secondary servers, encapsulate the first identification information, the first channel information, the target verification information, and the second identification information into a frame to obtain a plurality of first target frames; Broadcast the plurality of first target frames to the local area network.
4. The method according to claim 2, wherein Broadcasting each of the first verification information to the local area network further includes: Encrypt the first verification information to generate target verification information corresponding to the first verification information; In response to a channel configuration operation for the secondary server of the first level, obtain the first channel information of the secondary server of the first level; Obtain the first identification information of the secondary server of the first level and the second identification information of the target device; Encapsulate the first identification information, the first channel information, the target verification information, and the second identification information of the server of the first level into a frame to obtain a first target frame; Broadcast the first target frame to the secondary server of the first level, so that after receiving the first target frame, the secondary server of the first level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the updated number of verification levels.
5. The method according to claim 1, wherein Before selecting a target number of secondary servers from the local area network according to a preset number of verification levels, the method further includes: Obtain the current transition success ratio, where the current transition success ratio is the ratio of the number of servers to which the target device has successfully transitioned in the local area network to the total number of servers in the local area network; If the current transition success ratio is greater than or equal to a preset transition success ratio, upgrade the current permission of the target device from the first permission to the second permission; If the current transition success ratio is less than the preset transition success ratio, then select a target number of the secondary servers from the local area network according to the preset number of verification levels; 6. The method according to any one of claims 1 to 5, characterized in that The method further includes: Before selecting the target number of the secondary servers from the local area network according to the preset number of verification levels, trigger the start of a transition time limit timer based on the permission transition start instruction; If the timing time of the transition time limit timer reaches a preset first time and all of the second verification information sent by the target device is not received, it is determined that the permission transition fails, and the failure of the permission transition is used to indicate that the current permission of the target device is maintained as the first permission; If the timing time of the transition time limit timer reaches the preset first time and all of the second verification information and the corresponding first verification information are not the same, it is determined that the permission transition fails.
7. The method according to claim 6, characterized in that, If all of the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful, including: If the timing time of the transition time limit timer does not reach the preset first time and all of the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful.
8. The method according to any one of claims 1 to 5, characterized in that After upgrading the current permission of the target device from the first permission to the second permission, the method further includes: Based on the upgrade operation of upgrading the current permission of the target device from the first permission to the second permission, trigger the start of a permission time limit timer; If the timing time of the permission time limit timer reaches a preset second time, or in response to an exit instruction sent by the target device, restore the current permission of the target device from the second permission to the first permission.
9. A permission transition method, characterized in that, When applied to a secondary server, the method further includes: Obtain second verification information corresponding to first verification information broadcast by the primary server in the local area network. The first verification information is generated by the primary server for each of the secondary servers in a preset manner when the primary server responds to a permission transition start instruction sent by a target device, selects a target number of secondary servers from the local area network according to a preset number of verification levels, and the target number is the same as the number of verification levels; In response to a query instruction sent by the target device, send the second verification information to the target device, so that the target device sends the second verification information to the primary server, and the primary server determines whether all of the second verification information sent by the target device matches the corresponding first verification information; if all of the second verification information matches the corresponding first verification information, it is determined that the permission transition is successful, and the successful permission transition is used to represent upgrading the current permission of the target device from a first permission to a second permission, where the second permission is higher than the first permission.
10. The method according to claim 9, wherein Obtain second verification information corresponding to first verification information broadcast by the primary server in the local area network, including: Receive a first target frame broadcast by the primary server in the local area network, where the first target frame carries first identification information of the secondary server and target verification information, and the target verification information is the encrypted first verification information; If the first identification information is the same as third identification information corresponding to the secondary server, decrypt the target verification information in the first target frame to obtain the second verification information; If the first identification information is different from the third identification information, enter the step of receiving the first target frame broadcast by the primary server in the local area network.
11. The method according to claim 10, wherein After receiving the first target frame broadcast by the primary server in the local area network, the method further includes: Determine whether the updated verification level number is 0; In the case where the updated verification level number is not 0, select one server from the remaining servers in the local area network according to the updated verification level number as the secondary server of the next level; Update the verification level number again, so that the secondary server of the next level selects the secondary servers of the remaining levels from the remaining servers in the local area network according to the verification level number updated again.
12. The method according to claim 11, wherein After selecting one server from the remaining servers in the local area network as the secondary server of the next level according to the updated verification level number, the method further includes: Randomly generate third verification information for the secondary server of the next level based on the preset method, and encrypt the third verification information; In response to a channel configuration operation for the secondary server of the next level, obtain first channel information of the secondary server of the next level; Obtain first identification information of the secondary server of the next level and second identification information of the target device; Encapsulate the first identification information, the first channel information, the encrypted third verification information, and the second identification information of the secondary server of the next level into a frame to obtain a second target frame; Broadcast the second target frame to the secondary server of the next level and the primary server.
13. The method according to claim 10, characterized in that, The first target frame further carries second identification information of the target device and first channel information of the secondary server. In response to a query instruction sent by the target device, sending the second verification information to the target device includes: Using the data information carried by the query instruction, obtain the fourth identification information of the target device and the second channel information of the secondary server; If the second identification information of the target device is the same as the fourth identification information, and the first channel information is the same as the second channel information, then send the second verification information to the target device.
14. The method according to any one of claims 10 to 13, characterized in that, The method further includes: Determine whether the target device has queried the second verification information; If the target device has queried the second verification information, delete the second verification information from local storage.
15. A permission transition system, characterized in that, The privilege transition system includes a target device, a primary server, and multiple secondary servers. Among them, the primary server and the multiple secondary servers are in the same local area network. The target device is communicatively connected to the primary server and the multiple secondary servers. Among them, The target device sends a privilege transition start instruction to the primary server; In response to the privilege transition start instruction sent by the target device, the primary server selects a target number of secondary servers from the local area network according to the preset number of verification levels, generates first verification information for each secondary server based on a preset method, and broadcasts each first verification information to the local area network. The target number is the same as the number of verification levels; Each secondary server obtains second verification information corresponding to the first verification information broadcast by the primary server in the local area network; The target device sends a query instruction to each secondary server; In response to the query instruction sent by the target device, the secondary server sends the second verification information to the target device; The primary server determines whether all the second verification information sent by the target device matches the corresponding first verification information. If all the second verification information matches the corresponding first verification information, it is determined that the privilege transition is successful. The successful privilege transition is used to indicate that the current privilege of the target device is upgraded from the first privilege to the second privilege, and the second privilege is higher than the first privilege.
16. A permission transition device, characterized in that, Applied to the primary server, the device includes: A first selection module, configured to select a target number of secondary servers from the local area network according to the preset number of verification levels in response to a privilege transition start instruction sent by a target device. The target number is the same as the number of verification levels; A generation module, configured to generate first verification information for each secondary server based on a preset method, and broadcast each first verification information to the local area network, so that each secondary server obtains second verification information corresponding to the first verification information, so that the target device obtains the second verification information through each secondary server; A first determination module, configured to determine whether all the second verification information sent by the target device matches the corresponding first verification information; A first determination module, configured to determine that the privilege transition is successful if all of the second verification information matches the corresponding first verification information. The successful privilege transition is used to indicate that the current privilege of the target device is upgraded from a first privilege to a second privilege, and the second privilege is higher than the first privilege.
17. A permission transition device, characterized in that, Applied to an auxiliary server, the apparatus further includes: A first acquisition module, configured to acquire second verification information corresponding to first verification information broadcast by a primary server in a local area network. The first verification information is generated by the primary server for each of the auxiliary servers in a preset manner when the primary server responds to a privilege transition start instruction sent by a target device, according to a preset number of verification levels, by selecting a target number of auxiliary servers from the local area network, where the target number is the same as the number of verification levels. A sending module, configured to send the second verification information to the target device in response to a query instruction sent by the target device, so that the target device sends the second verification information to the primary server, and the primary server determines whether all of the second verification information sent by the target device matches the corresponding first verification information. If all of the second verification information matches the corresponding first verification information, it is determined that the privilege transition is successful. The successful privilege transition is used to indicate that the current privilege of the target device is upgraded from a first privilege to a second privilege, and the second privilege is higher than the first privilege.
18. A computer device, characterized in that, Including: A memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to execute the privilege transition method according to any one of claims 1 to 8 or the privilege transition method according to any one of claims 9 to 14.
19. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, it implements the privilege transition method according to any one of claims 1 to 8 or the privilege transition method according to any one of claims 9 to 14.
20. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the privilege transition method according to any one of claims 1 to 8 or the privilege transition method according to any one of claims 9 to 14.
Citation Information
Patent Citations
Remote identity authentication method and device, equipment and storage medium
CN115150158A
Authority control method, authority control device, electronic equipment and storage medium
CN117134941A