User login monitoring method and device, equipment and medium

By introducing a two-factor verification mechanism in the server management system, including login information verification and face verification, security risks and user experience problems in the existing technology are solved, and the security and user experience of the system are improved.

CN120074922APending Publication Date: 2025-05-30SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510222893.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art poses security risks in server management systems, especially after the account is stolen, non-compliant personnel can log in to the system for management, and adding SMS verification may lead to poor user experience.

Method used

By performing two-factor verification when the user logs in, including login information verification and face verification, it is ensured that only users who pass the two-layer verification can obtain access to the server management chip.

Benefits of technology

Improve the security of the system, reduce security risks, improve user experience, and avoid inconvenience caused by multiple verification operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074922A_ABST
    Figure CN120074922A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of identity verification, in particular to a user login monitoring method, device and equipment and a medium, and the method comprises the steps: sending login information of a website of a server management chip of a user login server to the server, so that the server verifies the login information; after the information that the server login information passes verification is received, the user first image collected by the camera device is further obtained so as to be conveniently sent to the server for face verification, a second-layer verification mechanism is added, non-inductive second-layer verification can be achieved through face verification, and the user experience is improved. According to the method and the device, the access authority to the server management chip can be obtained only after the user passes two layers of verification, namely login information verification and face verification, so that the safety of the system is improved, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication, and particularly to a method, device, equipment and medium for monitoring user login. Background Art

[0002] Nowadays, the BMC (Baseboard Management Controller) management system on the server plays a crucial role in daily maintenance. Maintenance personnel can log in to the management system through the account password to perform management. However, if the account is stolen, unauthorized personnel can log in to the system for management, posing a significant security risk.

[0003] In the related art, on the basis of the existing account and password, SMS verification is added to avoid the occurrence of security risks. However, this method may cause excessive operations for users and poor user experience.

[0004] It can be seen that how to provide a convenient and secure method for user account login is a problem that needs to be solved by those skilled in the art. Summary of the Invention

[0005] The purpose of the embodiments of the present invention is to provide a method, device, equipment and medium for monitoring user login. Only after the user passes the login information verification and face verification can the user obtain the access right to the server management chip, improving the security of the system and the user experience.

[0006] In a first aspect, a method for monitoring user login is provided, which is applied to a management system. The management system includes: a maintenance host and a server. The monitoring method is executed by the maintenance host and includes:

[0007] Sending the user's login information to the server for the server to verify the login information; the login information is the login information of the website for logging in to the server management chip of the server;

[0008] After receiving the information that the login information verification by the server is passed, obtaining the first image of the user collected by the camera device and sending the first image of the user to the server for the server to perform face verification on the first image;

[0009] When the face verification by the server is passed, logging in to the management page of the server management chip.

[0010] The present invention can be further configured in a preferred example as: further including:

[0011] When a user registers an account on the server management chip, send the personal identification information of the user to the server, so that the server can determine whether the user is a compliant user according to the personal identification information;

[0012] After determining that the user is a compliant user, obtain the second image of the user collected by the imaging device, and send the second image of the user to the server, so that the server can store the second image and generate a password for the user;

[0013] Display the password of the user to complete the registration of the user.

[0014] In a preferred example, the present invention can be further configured as: before sending the personal identification information of the user to the server, further including:

[0015] Send the third image of the user collected by the imaging device to the server, so that the server can generate a reminder message after determining that it is a first registration according to the third image;

[0016] In response to the reminder message, display a prompt content on the registration interface, and the prompt content is used to prompt the user to provide personal identification information.

[0017] In a preferred example, the present invention can be further configured as: after logging in to the management page of the server management chip, further including:

[0018] Real-time obtain the video stream of the user, and the video stream represents the video stream of the user's operation;

[0019] Identify the operation of the user according to the video stream, and determine whether the operation of the user is a malicious operation;

[0020] If it is a malicious operation, store the video stream in the maintenance host and send an alarm message to the server, so that the server can disconnect the communication connection with the maintenance host.

[0021] In a preferred example, the present invention can be further configured as: identifying the operation of the user according to the video stream and determining whether the operation of the user is a malicious operation, including:

[0022] Extract the operation behavior characteristics of the user according to the video stream;

[0023] Match the operation behavior characteristics with the standard operation mode;

[0024] If the operation behavior characteristics match the standard operation mode, determine that the operation of the user is a non-malicious operation;

[0025] If the operation behavior feature does not match the standard operation mode, determine the operation behavior feature of the user, and determine the user's operation behavior, operation sequence, and operation content;

[0026] Match the operation behavior, operation sequence, and operation content with the preset malicious operation rule library corresponding to the user;

[0027] Determine the risk type corresponding to the successfully matched malicious operation and the historical behavior record of the user;

[0028] If the risk type is low risk and the historical behavior record is good, determine that the user's operation is a non-malicious operation;

[0029] Otherwise, determine that the user's operation is a malicious operation.

[0030] In a second aspect, a monitoring method for user login is provided, which is applied to a management system. The management system includes: a maintenance host and a server. The monitoring method is executed by the server and includes:

[0031] Verify the login information of the server management chip sent by the maintenance host and send the verification result to the maintenance host;

[0032] Obtain the first image sent by the maintenance host. The first image is an image of the user collected by a camera device;

[0033] Perform face verification based on the first image, and after the verification passes, return the management page to the maintenance host.

[0034] In a preferred example of the present invention, it can be further configured to: further include:

[0035] When the user registers an account for the server management chip, obtain the second image of the user sent by the maintenance host;

[0036] Perform color conversion, sampling, block processing, and discrete cosine transform on the second image in sequence to obtain a processed image;

[0037] Store the processed image in the server.

[0038] In a third aspect, a monitoring device for user login is provided, including:

[0039] A sending module, configured to send the login information of the user to the server for the server to verify the login information; the login information is the login information of the website of the server management chip for logging in to the server;

[0040] A first acquisition module, configured to, after receiving the information that the login information of the server is verified successfully, acquire a first image of the user collected by a camera device, and send the first image of the user to the server, so that the server performs face verification on the first image;

[0041] A login module, configured to log in to the management page of the server management chip after the face verification of the server is passed.

[0042] In a fourth aspect, a monitoring device for user login is provided, including:

[0043] A first verification module, configured to verify the login information of the server management chip sent by a maintenance host, and send the verification result to the maintenance host;

[0044] A second acquisition module, configured to acquire a first image sent by the maintenance host, where the first image is an image of a user collected by a camera device;

[0045] A second verification module, configured to perform face verification according to the first image, and after the verification is passed, return the management page to the maintenance host.

[0046] In a fifth aspect, an electronic device is provided. The electronic device includes a memory and a processor. A computer program is stored in the memory, and when the processor runs the computer program, it executes the method according to any one of the first aspect or any one of the second aspect.

[0047] In a sixth aspect, a computer-readable storage medium is provided. At least one program code is stored in the computer-readable storage medium, and the program code is loaded and executed by a processor to implement the method according to any one of the first aspect or any one of the second aspect.

[0048] In a seventh aspect, a computer program product is provided, including a computer program or instruction. When the computer program or instruction is executed by a processor, it implements the method according to any one of the first aspect or any one of the second aspect.

[0049] In summary, the method provided by the present invention includes the following beneficial technical effects:

[0050] By adopting the above technical solution, the login information of the website of the server management chip for user login is sent to the server to facilitate the verification of the login information by the server; after receiving the information that the server login information verification is passed, the first user image collected by the camera device is further obtained to facilitate sending it to the server for face verification, adding a second-layer verification mechanism, and through face verification, a non-intrusive second-layer verification can be achieved, ensuring that only after the user passes two-layer verification (login information verification and face verification) can the access permission to the server management chip be obtained, improving the security of the system and enhancing the user experience.

[0051] In addition, the present invention also provides a device, a device and a medium, all of which have the above beneficial technical effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the embodiments of the present invention, the drawings required to be used in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.

[0053] Figure 1 It is a schematic diagram of the application scenario of a monitoring method for user login provided by an embodiment of the present invention;

[0054] Figure 2 It is a schematic diagram of the overall structure of image acquisition provided by an embodiment of the present invention;

[0055] Figure 3 It is a schematic diagram of the process flow of a monitoring method for user login provided by an embodiment of the present invention;

[0056] Figure 4 It is a schematic diagram of the process flow of user registration provided by an embodiment of the present invention;

[0057] Figure 5 It is a schematic diagram of the process flow of another monitoring method for user login provided by an embodiment of the present invention;

[0058] Figure 6 It is a schematic diagram of the process flow of image processing provided by an embodiment of the present invention;

[0059] Figure 7 It is a schematic diagram of the structure of a monitoring device for user login provided by an embodiment of the present invention;

[0060] Figure 8 It is a schematic diagram of the structure of another monitoring device for user login provided by an embodiment of the present invention;

[0061] Figure 9A schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners

[0062] This specific embodiment is only an interpretation of the present invention and does not limit the present invention. After reading this specification, those skilled in the art can make modifications to this embodiment without creative contributions as needed, but as long as they are within the scope of the present invention, they are protected by the patent law.

[0063] It should be noted that in the alternative embodiments of the present invention, for relevant data such as object information, when the embodiments of the present invention are applied to specific products or technologies, object permission or consent needs to be obtained, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions. That is to say, if the embodiments of the present invention involve data related to an object, it needs to be obtained under the authorization and consent of the object, the authorization and consent of relevant departments, and compliance with the relevant laws, regulations, and standards of the country and region. In the embodiments, if personal information is involved, the acquisition of all personal information needs to obtain the consent of the individual. If sensitive information is involved, the separate consent of the information subject needs to be obtained, and the embodiments also need to be implemented under the authorization and consent of the object.

[0064] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0065] In addition, the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after unless otherwise specified.

[0066] In the related art, based on the existing account and password, SMS verification is added to avoid the occurrence of security risks. However, this method may cause excessive operations for users and the user experience is poor.

[0067] The face recognition function has been widely applied in many fields, such as mobile phones, security monitoring, financial services, etc. Based on this, the embodiments of the present invention provide a monitoring solution for user login. By maintaining the physical camera on the host, the images collected through the physical camera on the host are stored through the network, avoiding the occupation of hardware resources on the server and increasing the security of the server system at the same time.

[0068] To better understand the solution provided by the embodiments of the present invention, the following describes the solution in combination with a specific application scenario.

[0069] In one embodiment, please refer to Figure 1 , Figure 1 which is a schematic diagram of an application scenario of a monitoring method for user login provided by the embodiments of the present invention. The monitoring method for user login can be applied to a management system.

[0070] In some embodiments, the management system includes a maintenance host and a server. Among them, the maintenance host includes, but is not limited to, mobile terminals such as laptops, PADs (tablet computers), and fixed terminals such as digital TVs, desktop computers, etc. The server management chip of the server, i.e., BMC, and the maintenance host can be directly or indirectly connected through wired or wireless communication methods, which can be achieved through an EMAV network card for communication connection. The embodiments of the present invention do not limit this here.

[0071] The maintenance host sends the login information of the website of the server management chip for the user to log in to the server; the server verifies the login information; after the maintenance host receives the information that the login information verification of the server is passed, the maintenance host obtains the first image of the user collected by the imaging device set on it and sends the first image of the user to the server; the server performs face verification on the first image; when the face verification of the server is passed, the maintenance host logs in to the management page of the server management chip.

[0072] Furthermore, the server is also deployed with a JPEG image compression engine and a ROM storage module.

[0073] Specifically, after entering the IP address of the server management chip, when entering the login interface, the physical camera on the maintenance host side starts to work and starts to collect images in real time to determine whether it is a previously collected portrait to determine whether it is pre-registered. If not, the personal information of the maintenance personnel needs to be entered before starting the collection work of the camera. After completing the overall portrait collection work, the collected images will be transmitted through the network to the jpeg module of the server management chip to compress the collected images, and then put into the ROM chip of the server for storage for subsequent portrait comparison; the user registration is completed. Among them, the overall system architectureFigure 2 shown.

[0074] It is understandable that the above is only an example and this embodiment is not limited here.

[0075] The embodiment of the present invention provides a method for monitoring user login, such as Figure 3 As shown, the method provided in the embodiment of the present invention can be executed by an electronic device, the electronic device is a maintenance host, and the method includes:

[0076] S101, sending the user's login information to the server so that the server can verify the login information; the login information is the login information of the website of the server management chip for logging into the server;

[0077] Among them, the server management chip refers to a chip installed on the server for monitoring and managing the server, such as BMC (Baseboard Management Controller); the server management chip management interface can be accessed through the server management chip's website; login information refers to the identity authentication data provided by the user in order to log in to the server management chip interface, including but not limited to the user name and password.

[0078] When the user needs to remotely manage the server hardware or view the server status, the user enters the URL of the server management chip and the corresponding login information through the browser or client software of the maintenance host. The login information will be sent to the server, and the verification mechanism on the server will verify this information to determine whether the user has the right to access the management interface of the server management chip, thereby ensuring the safe management and remote control of the server hardware.

[0079] S102, after receiving information from the server indicating that the login information has been verified, obtaining a first image of the user captured by the camera device, and sending the first image of the user to the server, so that the server can perform face verification of the first image;

[0080] The camera device is arranged on the maintenance host side, and may be a camera device integrated with the maintenance host, or may be a camera device of a separate device, for capturing the image of the user, which image at least includes the facial image of the user.

[0081] Specifically, when the user initiates a login request to the server through login information and the server has verified the correctness of the login information, the maintenance host will trigger the camera device to capture the user's first image and obtain the first image of the user captured by the camera device. The first image is sent back to the server, and the server compares it with the pre-stored user facial feature data to confirm the user's true identity.

[0082] S103. After the face verification of the server is passed, log in to the management page of the server management chip.

[0083] Among them, when the user logs in to the management page of the server management chip in the present invention, an additional security verification mechanism of face verification is added. The identity of the user can be more accurately confirmed through the face of the logged-in user, thereby effectively preventing unauthorized access and potential security risks. Moreover, compared with the conventional method of re-verifying by combining the verification code of the mobile phone, the method provided by the embodiment of the present invention does not require additional operations by the user, enabling the user to log in more conveniently and improving the user's login experience.

[0084] It can be seen that in the embodiment of the present invention, by adopting the above technical solution, the login information of the website of the server management chip for the user to log in to the server is sent to the server for the server to verify the login information; after receiving the information that the server login information verification is passed, the first image of the user collected by the camera device is further obtained for sending to the server for face verification, adding a second-layer verification mechanism, and through face verification, a non-sensing second-layer verification can be realized, ensuring that only after the user passes two-layer verification (login information verification and face verification) can the access permission to the server management chip be obtained, improving the security of the system and the user experience.

[0085] A possible implementation manner of the embodiment of the present invention is that before the user logs in for the first time, registration is required. The specific registration process may include:

[0086] When the user registers an account for the server management chip, the personal identification information of the user is sent to the server so that the server can determine whether the user is a compliant user according to the personal identification information; after determining that the user is a compliant user, the second image of the user collected by the camera device is obtained and sent to the server so that the server stores the second image and generates a password for the user; the password of the user is displayed to complete the registration of the user.

[0087] Among them, the personal identification information refers to the information that can uniquely identify the user's identity, such as the ID number, mobile phone number, email address, or work number, which is used by the server to verify the compliance of the user. Among them, the server stores an information set for maintaining users, and only the users within this information set for maintaining users are compliant users who are allowed to create and use accounts.

[0088] In an embodiment of the present invention, the user first needs to fill in personal identification information on the registration page. After the server receives the personal identification information, it will verify to determine whether the user is a compliant user. If it is determined that the user is a compliant user, the server will trigger an image acquisition request to the maintenance host. The maintenance host acquires the facial image of the user collected by the camera device (i.e., the second image) and sends it to the server. The server stores it and associates it with the user's account information (account and password, where the account can be identification information or information set by the user himself).

[0089] After collecting and storing the user's facial image, the server generates a password for the user and displays it to the user through the registration page to complete the registration process.

[0090] It can be seen that in an embodiment of the present invention, when the user registers an account for the server management chip, the compliance of the user is ensured by verifying the user's personal identification information. Furthermore, the security of the account is ensured by collecting the user's facial image. And the password is not set by the user himself, but generated by the server, which can avoid the user using his regular password to a certain extent and further ensure the security of the account.

[0091] In a possible implementation manner of the embodiment of the present invention, some users may have the situation of registering multiple times. To reduce unnecessary operations, in the embodiment of the present invention, before sending the user's personal identification information to the server, it further includes:

[0092] Sending the third image of the user collected by the camera device to the server, so that after the server determines that it is the first registration according to the third image, it generates a reminder message; in response to the reminder message, prompt content is displayed on the registration interface, and the prompt content is used to prompt the user to provide personal identification information.

[0093] Among them, the third image is the image collected when the user attempts to register, and is used for the initial verification of the user's identity to determine whether the user has already registered an account.

[0094] Specifically, when the user attempts to perform a registration operation, the camera device will collect the facial image of the user (i.e., the third image) and send it to the server through the maintenance host. After the server receives the third image, it will compare it with the registered image data to determine whether the user is registering for the first time.

[0095] If the server determines that the user is registering for the first time, it will generate a reminder message and display prompt content on the registration interface to guide the user to provide personal identification information (such as ID number, mobile phone number, etc.), so as to complete the registration process.

[0096] It can be seen that in the embodiments of the present invention, when a user attempts to perform a registration operation, the user's image is collected and sent to the server for comparison to determine whether the user is registering for the first time. If it is determined that the user is registering for the first time, the user is guided to provide personal identification information by displaying prompt content, which can effectively prevent the occurrence of duplicate registration behaviors.

[0097] The embodiments of the present invention provide a specific registration process. Specifically, refer to Figure 4 , including:

[0098] The user inputs the IP website provided by the server management chip through the maintenance host. After the web page is loaded, the server management chip (such as BMC) will call a program to connect to the maintenance host through the internal network. The maintenance host uses a polling method to scan the camera device interface to determine whether there is a camera device. If there is, when the maintenance personnel input an account (personal identification information), the maintenance host will remind the camera on the maintenance host side to start the recognition work. If it is the first recognition, the maintenance host will remind the user to provide personal identification information such as the work number to determine whether the person in front of the camera is an internal maintenance personnel of the company, that is, a compliant person. If the person is not an internal personnel of the company, the portrait collection process will be automatically cancelled and the person has no right to log in to the system. If the person is an internal personnel of the company, after the personal information is submitted, the application layer of the maintenance host will use the ioctl function to send a command to start collection to the physical camera interface to enable the camera on the maintenance host side to start the image collection function and then start the portrait collection process. After the collection is completed, the maintenance host will generate a unique password for the maintenance personnel through a random number to further improve security. The relevant flowchart of the above process is as follows.

[0099] Among them, the server can call the image information stored in the ROM in the application layer and compare it with the currently used personnel for collection. If it has not been collected, it will be identified as a non-user, and the user will be reminded to provide personal information, and then it will be determined whether to grant the permission to use the server management system according to the provided information.

[0100] In a possible implementation manner of the embodiments of the present invention, even if the user is a maintenance personnel, there may be malicious behaviors after the user logs in successfully. Therefore, in the embodiments of the present invention, after logging in to the management page of the server management chip, it further includes:

[0101] Real-time obtain the video stream of the user, where the video stream represents the video stream of the user's operations; identify the user's operations according to the video stream, and determine whether the user's operations are malicious operations; if they are malicious operations, store the video stream in the maintenance host and send an alarm message to the server so that the server can disconnect the communication connection with the maintenance host.

[0102] In the embodiment of the present invention, on the basis of the face recognition system, a real-time acquisition step is added. After the user logs in to the server management system, the camera device will be reminded to enter the background for real-time video recording. If it is found that the maintenance personnel perform malicious operations on the server management system, such as maliciously damaging the maintenance host or unauthorized operations on the management interface, a warning signal will be sent to the physical camera and the server management chip. The camera will immediately save the real-time acquired video in the hard disk of the maintenance host, and then both will perform a shutdown operation, avoiding the occurrence of system crashes.

[0103] Among them, malicious operations include but are not limited to: when the server management chip BMC is collecting data / logs, the user at the maintenance host end cuts off the power supply to the BMC; when the user maliciously cuts off the power supply during the system upgrade of the remote host through the BMC; maliciously deleting the storage information of the server through the BMC; reducing the fan speed through the BMC when the temperature is relatively high; resetting the BMC configuration.

[0104] It can be understood that when the user operates the BMC management interface to set parameters, the camera will capture the pictures of the user's specific operations such as clicking the mouse to select parameter options and inputting values on the keyboard. During normal operations, the user usually operates according to a certain process and permissions, and the frequency and order of mouse clicks and keyboard inputs have certain rules. If malicious operations occur, for example, the user quickly clicks on sensitive setting options frequently within a short period of time, or inputs some character combinations that are clearly inconsistent with normal logic, the system will identify it as an abnormal behavior. Another example is that when the user attempts to modify the key configuration parameters of the BMC, such as network settings and security policies, without the corresponding permissions, after the maintenance host identifies this unauthorized operation behavior through image analysis, it will be determined as a malicious operation.

[0105] Furthermore, for the acquisition angle of the camera device, it can be fixed, capable of simultaneously acquiring the user's face image and the display interface, or variable, capable of determining the shooting angle according to the actual working conditions. Of course, two camera devices can also be used, one for acquiring the face image and the other for acquiring the user's operations. The embodiments of the present invention do not limit this anymore.

[0106] It can be seen that in the embodiment of the present invention, the user's behavior is monitored through the operation video stream, so as to be able to detect malicious behaviors in a timely manner and make responses.

[0107] A possible implementation manner of the embodiment of the present invention is to identify the user's operation according to the video stream and determine whether the user's operation is a malicious operation, including: extracting the operation behavior characteristics of the user according to the video stream; matching the operation behavior characteristics with the standard operation mode; if the operation behavior characteristics match the standard operation mode, determining that the user's operation is a non-malicious operation; if the operation behavior characteristics do not match the standard operation mode, determining the operation behavior characteristics of the user, determining the user's operation behavior, operation sequence, and operation content; matching according to the operation behavior, operation sequence, and operation content with the preset malicious operation rule library corresponding to the user; determining the risk type corresponding to the successfully matched malicious operation, and the user's historical behavior record; if the risk type is low risk and the historical behavior record is good, determining that the user's operation is a non-malicious operation; otherwise, determining that the user's operation is a malicious operation.

[0108] Among them, the standard operation mode is the operation mode of the regular standard process after logging in with the permissions matched by the user; comparing the extracted operation behavior characteristics with the predefined standard operation mode to preliminarily determine the operation characteristics of the user; if they do not match, there may be a malicious situation, and combining the user's operation behavior, operation sequence, and operation content with the malicious operation rule library for matching. The malicious operation rule library contains various malicious operation modes and behavior characteristics, which can further determine whether the user has performed a malicious operation.

[0109] Different risk levels, that is, risk types, are set for different malicious operations; querying the user's historical behavior record database to obtain the operation behavior data of the user in the past period of time; comprehensively analyzing the risk type and the historical behavior record; if the risk type is low risk and the user's historical behavior record is good, determining that the user's operation is a non-malicious operation. Otherwise, determining that the user's operation is a malicious operation.

[0110] It can be seen that in the embodiment of the present invention, by real-time analyzing the operation behavior characteristics of the user in the video stream, combining multi-dimensional information such as the standard operation mode, the malicious operation rule library, and the historical behavior record, accurately judging whether the user's operation is a malicious operation. By comprehensively evaluating the risk type and the historical behavior record, the system can make a more intelligent judgment, reducing the situation of false positives and false negatives.

[0111] Furthermore, the embodiment of the present invention provides a monitoring method for user login, as Figure 5 shown. The method provided in the embodiment of the present invention can be executed by an electronic device, and the electronic device is a server. The method includes:

[0112] S201. Verifying the login information of the server management chip sent by the maintenance host and sending the verification result to the maintenance host;

[0113] S202. Obtain the first image sent by the maintenance host, where the first image is an image of the user captured by the imaging device;

[0114] S203. Perform face verification based on the first image, and after the verification passes, return the management page to the maintenance host.

[0115] Furthermore, in a possible implementation manner of the embodiment of the present invention, since the volume of the image is generally large, in order to reduce the space occupied by the image, refer to Figure 6 , the method further includes:

[0116] When the user registers an account for the server management chip, obtain the second image of the user sent by the maintenance host; perform color conversion, sampling, block processing, and discrete cosine transform on the second image in sequence to obtain the processed image; store the processed image in the server.

[0117] Among them, when the image acquisition is completed and the server management system interface is returned, the captured image and the corresponding personal information are transmitted to the management chip end through the local area network composed of the emac of the server management chip and the network port of the maintenance host for further processing actions. Generally, the space occupied by the captured image is relatively large, mostly occupying an area of about 10MB. Therefore, after being sent to the server management chip end of the server, the integrated jpeg image compression engine is used to compress the captured image using a compression algorithm to minimize the occupied space while ensuring the image quality to the greatest extent. After the image is transmitted to JPEG, first, color space conversion is performed, converting from the RGB color space to the YCbCr (Y represents luminance, and Cb and Cr represent the luminance of red and blue respectively) color space. This conversion utilizes the characteristic that the human eye is sensitive to luminance, and further prepares for retaining important visual information in the subsequent compression process.

[0118] After the conversion, the sampling process will be entered. By sampling the Cb and Cr two color channels, the resolution of the image is reduced. At the same time, the full resolution of the Y luminance is retained to ensure the clarity of the image edges and textures. Since the human eye is significantly more sensitive to Y than to the Cb and Cr two color channels, there is no obvious decline in the image quality felt by the naked eye. Exemplarily, during chrominance sampling, for example, sampling can be performed, where the full resolution of the luminance is retained, and the resolution of the chrominance is reduced to half of the original in both the horizontal and vertical directions. By reducing the amount of data of the chrominance information, the size of the image is reduced, thereby reducing the transmission and storage costs of the image. Since the y is fully retained, the details of the image edges and textures are clearly visible.

[0119] After the sampling is completed, image block division will be performed. This operation will divide the image into multiple pixel blocks (such as for discrete cosine transform. Through DCT transform, high-frequency information and low-frequency information of the image will be separated first. Among them, high-frequency coefficients are used to represent the details and edges of the image block, while low-frequency coefficients are used to represent the average brightness and smooth changes of the image block. The human eye is more sensitive to low-frequency coefficients. Therefore, after DCT transform, the low-frequency coefficients of the image will be preferentially retained, while the high-frequency coefficients will be reduced, so as to ensure the image quality. Through the above encoding process, the final compressed JPEG face image file is generated.

[0120] Furthermore, the ROM chip of the server management chip can be divided into 2 regions in the storage part. One region is used to store portrait pictures, and the other region is used to store personal information. After the JPEG image file is generated, it will be put into the JPEG image storage area of the ROM, and personal information will also be put into the corresponding area of the ROM.

[0121] It can be seen that in the embodiment of the present invention, by processing the image, the space occupation can be reduced while ensuring the clarity.

[0122] Furthermore, in a possible implementation manner of the embodiment of the present invention, verifying the login information of the server management chip sent by the maintenance host includes:

[0123] Verifying the account of the login information of the server management chip sent by the maintenance host. After the verification passes, obtaining the user's historical login behavior and maintenance host information; verifying the login information sent by the maintenance host; determining whether the user's login behavior is a normal behavior according to the historical login behavior and the current login behavior; so as to determine whether the user has an abnormal behavior different from the historical behavior; if it is a normal behavior, determining whether the current operation environment is a safe environment according to the user's permissions and maintenance host information; if it is a safe environment, determining that the verification passes, otherwise, determining that the verification fails.

[0124] Among them, the historical login behavior includes but is not limited to the hot time, frequency, location, and device of login; the maintenance host information includes but is not limited to the IP address, device type, operating system, and network security. The higher the user's permissions, the greater the privacy of the data that can be accessed, and thus more secure and high-performance devices are required to access it. Based on this, matching the standard maintenance host information corresponding to the user's permissions with the current maintenance host information to determine whether the basic requirements are met. If so, determining that the verification passes, otherwise, determining that the verification fails, so as to ensure that the user can perform operations and access resources in a safe environment.

[0125] It can be seen that in the embodiments of the present invention, the current verification situation is determined from multiple dimensions of the login information of the server management chip sent by the maintenance host, the current login behavior, and the current operating environment, so as to make a more reasonable access control decision.

[0126] Based on any of the above embodiments, the technical solution provided by the present invention can effectively improve the security of the server management system. In terms of inputting personnel information, steps of judging the job number information (personal identification information) and generating exclusive accounts and passwords are added, avoiding the risk of the entire server crashing due to non-company employees maliciously using the server management system.

[0127] In addition, a ROM storage module is added to the technical solution provided by the present invention. Due to its small capacity and characteristics such as read-only and non-writable and non-erasable, the number of people who can use the server management system is limited, thereby further reducing the risk of the server system crashing due to malicious operations. This solution minimizes the space occupied by collecting images. By using the JPEG compression engine to compress the resolution while ensuring the image quality, the collected images are reduced from 10M to 600KB.

[0128] Next, a monitoring device for user login provided by the embodiments of the present invention will be introduced. The device described below can be correspondingly referred to the method described above. The device of this embodiment is set in an electronic device. Refer to Figure 7 , Figure 7 which is the structural block diagram of the device of one embodiment of the present invention, including:

[0129] A sending module 310, configured to send the user's login information to the server for the server to verify the login information; the login information is the login information of the website of the server management chip for logging in to the server;

[0130] A first obtaining module 320, configured to obtain the first image of the user collected by the imaging device after receiving the information that the login information verification of the server passes, and send the first image of the user to the server for the server to perform face verification on the first image;

[0131] A login module 330, configured to log in to the management page of the server management chip when the face verification of the server passes.

[0132] In a feasible manner, it further includes:

[0133] A registration module, configured to send the user's personal identification information to the server when the user registers an account for the server management chip, so that the server determines whether the user is a compliant user according to the personal identification information;

[0134] After determining that the user is a compliant user, obtain the second image of the user collected by the camera device, and send the second image of the user to the server, so that the server stores the second image and generates a password for the user;

[0135] Display the password of the user to complete the registration of the user.

[0136] In an implementable manner, the registration module is further configured to send the third image of the user collected by the camera device to the server, so that the server generates a reminder message after determining that it is the first registration according to the third image;

[0137] In response to the reminder message, display prompt content on the registration interface, and the prompt content is used to prompt the user to provide personal identification information.

[0138] In an implementable manner, it further includes:

[0139] The behavior monitoring module is configured to: obtain the video stream of the user in real time, and the video stream represents the video stream of the user's operations;

[0140] Identify the user's operations according to the video stream, and determine whether the user's operations are malicious operations;

[0141] If it is a malicious operation, store the video stream in the maintenance host and send an alarm message to the server, so that the server disconnects the communication connection with the maintenance host.

[0142] In an implementable manner, the behavior monitoring module is configured to: obtain the video stream of the user in real time, and the video stream represents the video stream of the user's operations;

[0143] Extract the operation behavior characteristics of the user according to the video stream;

[0144] Match the operation behavior characteristics with the standard operation mode;

[0145] If the operation behavior characteristics match the standard operation mode, determine that the user's operations are non-malicious operations;

[0146] If the operation behavior characteristics do not match the standard operation mode, determine the operation behavior characteristics of the user, determine the user's operation behavior, operation sequence, and operation content;

[0147] Match the operation behavior, operation sequence, and operation content with the preset malicious operation rule library corresponding to the user;

[0148] Determine the risk type corresponding to the successfully matched malicious operation, as well as the user's historical behavior records;

[0149] If the risk type is low risk and the historical behavior records are good, determine that the user's operations are non-malicious operations;

[0150] Otherwise, determine that the user's operation is a malicious operation.

[0151] Next, a monitoring device for user login provided by an embodiment of the present invention will be introduced. The device described below can be correspondingly referred to the method described above. The device of this embodiment is set in an electronic device. Refer to Figure 8 , Figure 8 is a structural block diagram of the device of one embodiment of the present invention, including:

[0152] The first verification module 410 is configured to verify the login information of the server management chip sent by the maintenance host and send the verification result to the maintenance host;

[0153] The second acquisition module 420 is configured to acquire the first image sent by the maintenance host, where the first image is an image of the user collected by the imaging device;

[0154] The second verification module 430 is configured to perform face verification according to the first image, and after the verification is passed, return the management page to the maintenance host.

[0155] In a feasible manner, it further includes:

[0156] The image processing module is configured to acquire the second image of the user sent by the maintenance host when the user registers an account for the server management chip; perform color conversion, sampling, block processing, and discrete cosine transform on the second image in sequence to obtain the processed image;

[0157] The image storage module is configured to store the processed image in the server.

[0158] Figure 9 is a structural diagram of an electronic device provided by an embodiment of the present invention, including: a memory 60 for storing a computer program;

[0159] A processor 61, configured to implement the steps of the monitoring method for user login in the above embodiment when executing the computer program.

[0160] When the electronic device is a maintenance host, the processor 61 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. The processor 61 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 61 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as the central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 61 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 61 may further include an artificial intelligence (AI) processor, and the AI processor is used to process computational operations related to machine learning.

[0161] When the electronic device is a server, the processor 61 further includes at least: a server management chip, such as BMC.

[0162] The memory 60 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 60 may further include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 60 is at least used to store the following computer program 601. After the computer program is loaded and executed by the processor 61, it can implement the relevant steps of the user login monitoring method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 60 may further include an operating system 602 and data 603, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 602 may include Windows, Unix, Linux, etc.

[0163] In some embodiments, the electronic device may further include a display screen 62, an input / output interface 63, a communication interface 64, a power supply 65, and a communication bus 66.

[0164] Those skilled in the art can understand that Figure 9 the structure shown in

[0165] It can be understood that if the user login monitoring method in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the current technology, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods in the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), electrically erasable programmable ROMs, registers, hard disks, removable disks, CD-ROMs, magnetic disks, or optical discs that can store program codes.

[0166] Based on this, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the user login monitoring method as described above.

[0167] Based on this, an embodiment of the present invention further provides a computer program product, including a computer program or instruction. When the computer program or instruction is executed by a processor, it implements the method as described above.

[0168] The above has provided a detailed introduction to a user login monitoring method, device, equipment, and medium provided by the embodiments of the present invention. The various embodiments in the specification are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.

[0169] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0170] The above has introduced in detail a method, device, equipment, and medium for monitoring user login provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.

Claims

1. A method for monitoring user login, characterized in that: Applied to a management system, the management system includes: a maintenance host and a server, the monitoring method is executed by the maintenance host, and includes: Sending the user's login information to the server so that the server can verify the login information; the login information is the login information of the website of the server management chip of the server; After receiving the information that the login information of the server has been verified, obtaining the first image of the user captured by the camera device, and sending the first image of the user to the server, so that the server can perform face verification of the first image; When the face verification of the server is passed, log in to the management page of the server management chip.

2. The user login monitoring method according to claim 1, characterized in that: Also includes: When a user registers an account of the server management chip, the user's personal identification information is sent to the server, so that the server can determine whether the user is a compliant user based on the personal identification information; After determining that the user is a compliant user, obtaining a second image of the user captured by the camera device, and sending the second image of the user to the server, so that the server stores the second image and generates a password for the user; The password of the user is displayed to complete the registration of the user.

3. The user login monitoring method according to claim 2, characterized in that: Before sending the user's personal identification information to the server, the method further includes: sending a third image of the user captured by the camera device to the server, so that the server generates a reminder message after determining that it is a first registration according to the third image; In response to the reminder information, prompt content is displayed on the registration interface, and the prompt content is used to prompt the user to provide personal identification information.

4. The user login monitoring method according to claim 1, characterized in that: After logging into the management page of the server management chip, the method further includes: Acquire a video stream of the user in real time, wherein the video stream represents a video stream of the user's operation; Identifying the user's operation according to the video stream, and determining whether the user's operation is a malicious operation; If it is a malicious operation, the video stream is stored in the maintenance host, and an alarm message is sent to the server so that the server disconnects the communication connection with the maintenance host.

5. The method for monitoring user login according to claim 4, characterized in that: Identifying the user's operation according to the video stream and determining whether the user's operation is a malicious operation includes: Extracting the operation behavior characteristics of the user according to the video stream; Matching the operational behavior characteristics with a standard operational mode; If the operation behavior characteristics match the standard operation mode, determining that the user's operation is a non-malicious operation; If the operation behavior characteristics do not match the standard operation mode, determining the operation behavior characteristics of the user, and determining the user's operation behavior, operation sequence, and operation content; According to the operation behavior, operation sequence, and operation content, matching is performed with a preset malicious operation rule library corresponding to the user; Determine the risk type corresponding to the successfully matched malicious operation and the historical behavior record of the user; If the risk type is low risk and the historical behavior record is good, then the user's operation is determined to be non-malicious; Otherwise, it is determined that the user's operation is a malicious operation.

6. A method for monitoring user login, characterized in that: Applied to a management system, the management system includes: a maintenance host and a server, the monitoring method is executed by the server, and includes: Verifying the login information of the server management chip sent by the maintenance host, and sending the verification result to the maintenance host; Acquire a first image sent by the maintenance host, where the first image is an image of the user captured by a camera device; Perform face verification based on the first image, and after the verification is passed, return the management page to the maintenance host.

7. The method for monitoring user login according to claim 6, characterized in that: Also includes: When the user registers an account of the server management chip, obtaining a second image of the user sent by the maintenance host; performing color conversion, sampling, block processing, and discrete cosine transformation on the second image in sequence to obtain a processed image; The processed images are stored in the server.

8. A user login monitoring device, characterized in that: include: A sending module, used to send the user's login information to the server so that the server can verify the login information; The login information is the login information of the website of the server management chip for logging into the server; A first acquisition module is used to acquire a first image of the user captured by a camera device after receiving information from the server indicating that the login information has been verified, and send the first image of the user to the server so that the server can perform face verification of the first image; The login module is used to log in to the management page of the server management chip after the face verification of the server is passed.

9. A user login monitoring device, characterized in that: include: A first verification module, used to verify the login information of the server management chip sent by the maintenance host, and send the verification result to the maintenance host; A second acquisition module, configured to acquire a first image sent by the maintenance host, wherein the first image is an image of the user captured by a camera device; The second verification module is used to perform face verification based on the first image, and return the management page to the maintenance host after the verification is passed.

10. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to execute the computer program to implement the steps of the user login monitoring method as described in any one of claims 1 to 7.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the user login monitoring method as claimed in any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Repeater maintenance system login method and system, and medium

    CN121036993A