Network security bastion host operation and maintenance method and system based on mobile vehicle network environment
By introducing automated identity verification and equipment authentication in the mobile vehicle network environment, as well as real-time monitoring and recording of operation and maintenance processes, the problem of time-consuming and incomplete monitoring of operation and maintenance processes in the existing technology is solved, and the efficiency, safety and compliance of operation and maintenance processes are achieved.
Patent Information
- Application Number
- CN202510254288.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-05-30
AI Technical Summary
The existing backend of the bastion machine management platform has problems such as time-consuming identity verification, incomplete monitoring of operation and maintenance processes, and inability to track and record operation and maintenance personnel's operation behavior in real time, resulting in difficult protection of compliance and security.
A network security bastion machine operation and maintenance method and system based on the mobile vehicle network environment is proposed. Equipment information is stored through the code scanning gun of the operation and maintenance terminal to realize automated identity verification and equipment authentication; the backend of the management platform is used to monitor and record key information in the operation and maintenance process in real time to ensure compliance and traceability of operation and maintenance activities.
Through automated identity verification and equipment authentication, the efficiency and security of the operation and maintenance process are significantly improved; through real-time monitoring and recording of the operation and maintenance process, the compliance and traceability of operation and maintenance activities are ensured, and the flexibility and efficiency of mobile vehicle application scenarios are adapted to the flexibility and efficiency of mobile vehicle application scenarios.
Smart Images

Figure CN120075080A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of intelligent transportation systems, and particularly relates to a network security bastion host operation and maintenance method and system based on a mobile vehicle network environment. Background Art
[0002] With the rapid development of intelligent transportation systems, the networking process of transportation tools has been accelerating continuously, and network security has become a key factor in ensuring the stable operation of the system and the security of passenger information. However, the network security challenges faced in this field are becoming increasingly complex, and traditional fixed network security solutions are difficult to meet the requirements of rapid switching, instant deployment, and efficient operation and maintenance among transportation tools.
[0003] At present, although there are bastion host management platform backends in the market as part of network operation and maintenance, they still have significant technical problems in mobile vehicle application scenarios. Most of the existing bastion host management platform backends adopt a separate deployment method, relying on manual verification of the identities of operation and maintenance personnel and operation and maintenance devices. This process is not only time-consuming and laborious but also prone to human errors. More importantly, these bastion host management platform backends lack the ability to comprehensively monitor the operation and maintenance process, unable to track and record the operation behaviors of operation and maintenance personnel in real time, thus making it difficult to ensure the compliance and security of operation and maintenance activities.
[0004] In addition, when the existing bastion host management platform backends are dealing with network threats, they often lack an instant response mechanism and are unable to quickly identify and block potential security risks. In scenarios highly dependent on network security such as mobile vehicles, this may lead to serious consequences, including system paralysis, data leakage, etc. At the same time, there is a lack of a unified management process, and personal devices appear in the intranet operation and maintenance environment. Summary of the Invention
[0005] In view of the above deficiencies of the prior art, the present application provides a network security bastion host operation and maintenance method and system based on a mobile vehicle network environment.
[0006] In the first aspect, the present application proposes a network security bastion host operation and maintenance method based on a mobile vehicle network environment, including the following steps: Information warehousing step: Use a three-proof notebook to build an operation and maintenance terminal. The operation and maintenance terminal enters device information through a barcode scanner to ensure that each device corresponds to a unique device ID. After warehousing, the information entered into the operation and maintenance terminal forms a ledger; Operation and maintenance preparation step: Deploy the operation and maintenance services of the network security bastion host through the account books of the operation and maintenance terminal. Among them, in the initial boot state of the network security bastion host, the operation and maintenance terminal can only enter the user login web page. When the service deployment management platform backend has not issued a requisition form status, the operation and maintenance terminal has no user information and requisition form information, and the operation and maintenance terminal cannot log in. If the operation and maintenance terminal is not registered with the service deployment management platform backend, the service deployment management platform backend cannot construct the current device requisition form; Requisition form creation steps: Submit an operation and maintenance requisition form through the WeChat mini-program or the operation and maintenance management system. The requisition form includes operation and maintenance personnel information, operation and maintenance type, vehicle number, and information of the device under operation and maintenance; Requisition form approval steps: Associate the requisition form with the specified operation and maintenance terminal through a barcode scanner or manual entry, and synchronize the operation and maintenance personnel information; Connection construction steps: The portable operation and maintenance terminal establishes a connection with the management platform backend through DHCP or a fixed IP address; the management platform backend scans the connected devices, automatically performs service device authentication. After successful authentication and construction of the connection, the management platform backend automatically issues the requisition form and user information involved to the portable operation and maintenance terminal; Operation and maintenance steps: The operation and maintenance personnel perform identity verification through face recognition and account password. After logging in to the operation and maintenance terminal, enter the operation and maintenance device service to perform manual or automatic operation and maintenance operations; during the operation and maintenance process, the system automatically records the operation and maintenance logs and videos, and automatically executes the preset work orders; after the operation and maintenance is completed, package and send the operation and maintenance data to the management platform backend through SFTP, and clear all information on the operation and maintenance terminal; the administrator retrieves the relevant information of the requisition form and the upload status of the configuration file through a barcode scanner, and the system automatically checks whether the files are complete and closes the requisition form; Operation and maintenance device stability analysis steps: The management platform backend collects and analyzes the operation and maintenance information. The operation and maintenance information includes the operation and maintenance patch file library, configuration backup library, operation and maintenance tools, operation and maintenance logs, and operation and maintenance videos; evaluate the stability of the terminal and the service through the analysis results of the operation and maintenance information, and alarm the unstable devices.
[0007] In some embodiments, the connection construction steps further include: log in through the requisition form and user information involved issued by the management platform backend to the operation and maintenance terminal. After logging in to the operation and maintenance device service, the web page only includes the operation and maintenance device in the requisition form, the device connection method, and the operation and maintenance operations required for the operation and maintenance device.
[0008] In some embodiments, the operation and maintenance steps further include an environment preparation step: Create corresponding directories through the portable operation and maintenance terminal for environment initialization. The directories include a first-level directory, a second-level directory, and a third-level directory. The first-level directory includes a requisition form directory. The second-level directory includes directories for each device in the requisition form directory. The third-level directory includes an operation and maintenance patch file library, a configuration backup library, an operation and maintenance tool directory, an operation and maintenance log directory, and an operation and maintenance video directory.
[0009] In some embodiments, the operation and maintenance steps further include a user group management step: Manage through user groups to create an operation and maintenance user group. Among them, the operation and maintenance user group cannot operate on the operation and maintenance directory, cannot create, modify, or migrate, and tools not in the operation and maintenance tool directory cannot be executed.
[0010] In some embodiments, the operation and maintenance steps further include an operation and maintenance directory mapping step: When logging in to the operation and maintenance user group to enter the device operation and maintenance process, the service maps the operation and maintenance configuration backup library, operation and maintenance tools, and operation and maintenance patch file library. Among them, the operation and maintenance configuration backup library, operation and maintenance tool directory, and operation and maintenance patch file library directories between different device operation and maintenance processes are permission-separated, and only the directory information of the current device is visible.
[0011] In some embodiments, the operation and maintenance steps further include the technical details of automatic work order execution: (1) Build a server execution command group, which internally contains operation commands and operation command steps; (2) Build an abnormal automatic exit flag service group, which internally constructs: a file operation group, an information collection group, a service operation group, and a user operation group; (3) Automatically improve the service, implement an automatic exit mechanism for the execution command group, and the service automatically identifies abnormal situations that occur in the operation commands; (4) Build an ssh client with python to achieve connection to a remote server; (5) If an automatic execution script, python automatically executes a preset command and automatically determines whether the execution reaches the preset purpose; (6) Both automatic operation and maintenance and manual operation and maintenance will record all executed commands and execution results.
[0012] In some embodiments, the operation and maintenance steps further include the operation steps of automatic work order analysis: (1) Collect all operation commands; (2) Automatically analyze the operation processes with a large number of relevant executed commands. Whether it is the entire process or a part of the previous group of processes, an automatic operation template is automatically extracted and formed; (3) Identify the variable parameters in the commands, and generate a script manually after identification; (4)Construct operation and maintenance processes for different scenarios through the combination of multiple groups of automated script templates and partial command self-input.
[0013] In some embodiments, the operation and maintenance data is packaged and sent to the back end of the management platform through SFTP, including: packaging by device directory, generating file md5 values, adding the files and their corresponding md5 values to the info.txt file, and finally packaging the compressed packages of each directory and the info.txt together as the final compressed package. The name of the final compressed package is the application form id + the current timestamp. The info.txt file contains the md5 values of all files and is used to verify the integrity of the files.
[0014] In a second aspect, the present application proposes a network security bastion host operation and maintenance system based on a mobile vehicle network environment, including an information storage module, an operation and maintenance preparation module, an application form creation module, an application form approval module, a connection construction module, an operation and maintenance module, and an operation and maintenance equipment stability analysis module; The information storage module is used to execute the information storage step: Use a three-proof notebook to build an operation and maintenance terminal. The operation and maintenance terminal enters device information through a barcode scanner to ensure that each device corresponds to a unique device ID. After storage, the information entered into the operation and maintenance terminal forms a ledger; The operation and maintenance preparation module is used to execute the operation and maintenance preparation step: Deploy the operation and maintenance service of the network security bastion host through the ledger of the operation and maintenance terminal. Among them, in the initial boot state of the network security bastion host, the operation and maintenance terminal can only enter the user login web page. When the service deployment management platform back end has not issued an application form status, the operation and maintenance terminal has no user information and application form information, and the operation and maintenance terminal cannot log in. If the operation and maintenance terminal is not registered with the service deployment management platform back end, the service deployment management platform back end cannot build an application form for the current device; The application form creation module is used to execute the application form creation step: Submit an operation and maintenance application form through a WeChat mini-program or an operation and maintenance management system. The application form includes operation and maintenance personnel information, operation and maintenance type, vehicle number, and information of the device to be maintained; The application form approval module is used to execute the application form approval step: Associate the application form with the specified operation and maintenance terminal through a barcode scanner or manual entry, and synchronize the operation and maintenance personnel information; The connection construction module is used to execute the connection construction step: The portable operation and maintenance terminal establishes a connection with the management platform back end through DHCP or a fixed IP address; the management platform back end scans the connected devices, automatically performs service device authentication, and after successful authentication and construction of the link, the management platform back end automatically issues the application form and user information involved to the portable operation and maintenance terminal; The operation and maintenance module is used to perform operation and maintenance steps: The operation and maintenance personnel use face recognition and account password for identity verification. After logging into the operation and maintenance terminal, they enter the operation and maintenance equipment service and perform manual or automatic operation and maintenance operations. During the operation and maintenance process, the system automatically records the operation and maintenance logs and videos, and automatically executes the preset work orders. After the operation and maintenance is completed, the operation and maintenance data is packaged and sent to the back end of the management platform via SFTP, and all information on the operation and maintenance terminal is cleared. The administrator uses a barcode scanner to retrieve the relevant information of the application form and the upload status of the configuration file. The system automatically checks whether the files are complete and closes the application form. The operation and maintenance equipment stability analysis module is used to perform the operation and maintenance equipment stability analysis steps: The backend of the management platform collects and analyzes operation and maintenance information, including an operation and maintenance patch file library, a configuration backup library, operation and maintenance tools, operation and maintenance logs, and operation and maintenance videos; the stability of terminals and services is evaluated through the analysis results of the operation and maintenance information, and alarms are issued for unstable devices.
[0015] In a third aspect, the present application proposes an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.
[0016] In a fourth aspect, the present application proposes a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0017] Beneficial effects of the present invention: Automatic identity verification and device authentication: By integrating advanced identity recognition technology, this solution can automatically verify the identity of operation and maintenance personnel and the legitimacy of operation and maintenance equipment. In addition, there is a strong binding relationship between the platform and the bastion host, which can only establish a connection with the platform through DHCP or a fixed IP address. When initialized, the operation and maintenance terminal can only enter the user login web page, and the operation and maintenance terminal has no operation and maintenance authority without an application form, and cannot perform operation and maintenance operations when connected to the network, which significantly improves the efficiency and security of the operation and maintenance process.
[0018] Comprehensive monitoring of the operation and maintenance process: By leveraging the powerful data processing and analysis capabilities of the data platform, this solution can monitor the operational behavior of operation and maintenance personnel in real time, record and analyze key information in the operation and maintenance process, and ensure the compliance and traceability of operation and maintenance activities.
[0019] Flexible adaptation to mobile vehicle application scenarios: This solution fully considers the particularities of the mobile vehicle network environment, such as fast switching, instant access and other requirements. By optimizing the collaborative work between the bastion host and the data platform, it achieves flexibility and efficiency in the operation and maintenance process. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 This is the overall flowchart of the present invention.
[0021] Figure 2 This is the operation and maintenance flowchart of the present invention.
[0022] Figure 3 This is the system principle block diagram of the present invention. Detailed implementation manners
[0023] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein; on the contrary, these embodiments are provided so that the present invention can be more thoroughly understood and the scope of the present invention can be fully communicated to those skilled in the art.
[0024] This solution uses spring Boot to build the backend of the management platform, uses a three-proof book to build a mobile operation and maintenance bastion host, uses the Linux system to build a service deployment platform for the bastion host service, and uses a Python service internally.
[0025] In a first aspect, the present application proposes a network security bastion host operation and maintenance method based on a mobile vehicle network environment, as Figure 1-2 shown, including the following steps: Information warehousing step: S100: Use a three-proof book to build an operation and maintenance terminal. The operation and maintenance terminal inputs device information through a barcode scanner to ensure that each device corresponds to a unique device ID. After warehousing, the information input into the operation and maintenance terminal forms a ledger; Among them, the specific process of information warehousing includes: Barcode scanner warehousing: The portable operation and maintenance terminal is warehoused through a barcode scanner to ensure that each device has a unique device ID (the product serial number can be borrowed).
[0026] Input association: The operation and maintenance terminal information can be input into the system by manual input or barcode scanning association to form an operation and maintenance terminal ledger.
[0027] Record personnel information: Operation and maintenance personnel who submit an application for the first time need to record face information. Existing operation and maintenance personnel can directly call the previously input information, and the system automatically creates a default user name (full spelling of the operation and maintenance personnel's name) and password (the last six digits of the operation and maintenance personnel's ID card number).
[0028] Operation and maintenance preparation step: S200: Deploy the operation and maintenance service of the network security bastion host through the account books of the operation and maintenance terminal. Among them, when the network security bastion host is in the initial boot state, the operation and maintenance terminal can only enter the user login web page. When the service deployment management platform backend has not issued the requisition form status, the operation and maintenance terminal has no user information and requisition form information, and the operation and maintenance terminal cannot log in. If the operation and maintenance terminal is not registered with the service deployment management platform backend, the service deployment management platform backend cannot construct the current device requisition form; Requisition form creation steps: S300: Submit the operation and maintenance requisition form through the WeChat mini-program or the operation and maintenance management system. The requisition form includes operation and maintenance personnel information, operation and maintenance type, vehicle number, and information of the device to be operated and maintained; Among them, after submitting through the WeChat mini-program, all relevant data is saved in the cloud. Considering that the operation and maintenance environment may be an intranet environment, the mini-program encrypts the relevant data. Provide the encrypted QR code for data interaction with the intranet platform. After the platform scans the code, it loads the created requisition form.
[0029] Requisition form approval steps: S400: Associate the requisition form with the specified operation and maintenance terminal through a barcode scanner or manual entry, and synchronize the operation and maintenance personnel information; Connection construction steps: S500: The portable operation and maintenance terminal establishes a connection with the management platform backend through DHCP or a fixed IP address; the management platform backend scans the connected devices, automatically performs service device authentication. After successful authentication and connection construction, the management platform backend automatically issues the requisition form and user information related to the portable operation and maintenance terminal; In some embodiments, the connection construction steps further include: log in through the requisition form and user information issued by the management platform backend to the operation and maintenance terminal. After logging in to the operation and maintenance device service, the web page only includes the operation and maintenance device in the requisition form, the device connection method, and the operation and maintenance operations required for the operation and maintenance device.
[0030] Specifically: Information issuance: The platform scans the connected devices, automatically performs service device authentication. After successful authentication and connection construction, the platform automatically issues the requisition form and user information related to this terminal (including user login information and biometric information).
[0031] The user logs in to the operation and maintenance terminal by the issued user, and at the same time, the biometric information needs to be verified. After logging in, enter the operation and maintenance device service, and only the operation and maintenance device in the requisition form, the device connection method, and the operation and maintenance operations required for the operation and maintenance device can be seen on the page.
[0032] Operation and maintenance steps: S600: After the operation and maintenance personnel complete identity verification through face recognition and account password, and log in to the operation and maintenance terminal, they enter the operation and maintenance device service to perform manual or automatic operation and maintenance operations. During the operation and maintenance process, the system automatically records operation and maintenance logs and videos, and automatically executes preset work orders. After the operation and maintenance is completed, the operation and maintenance data is packaged and sent to the back-end of the management platform through SFTP, and all information on the operation and maintenance terminal is cleared. The administrator retrieves the relevant information of the requisition form and the upload status of the configuration file through a barcode scanner, and the system automatically checks whether the files are complete and closes the requisition form. In some embodiments, the operation and maintenance steps further include an environment preparation step: Create corresponding directories through a portable operation and maintenance terminal for environment initialization. The directories include a first-level directory, a second-level directory, and a third-level directory. The first-level directory includes a requisition form directory. The second-level directory includes directories for each device in the requisition form directory. The third-level directory includes an operation and maintenance patch file library, a configuration backup library, an operation and maintenance tool directory, an operation and maintenance log directory, and an operation and maintenance video directory.
[0033] Among them, the operation and maintenance patch file library is used for operation and maintenance device patches downloaded by the platform; the configuration backup library is used for the operation and maintenance configuration directory and the device configuration backup save directory during the operation and maintenance process; the operation and maintenance tools are used for operation and maintenance tools downloaded by the platform; the operation and maintenance logs are used for service logs generated during the operation and maintenance process; the operation and maintenance videos are used for operation and maintenance videos generated during the operation and maintenance process; In some embodiments, the operation and maintenance steps further include a user group management step: Manage through user groups to create an operation and maintenance user group. Among them, the operation and maintenance user group cannot operate on the operation and maintenance directory, cannot create, modify, or migrate, and tools not in the operation and maintenance tool directory cannot be executed.
[0034] In some embodiments, the operation and maintenance steps further include an operation and maintenance directory mapping step: When logging in to the operation and maintenance user group and entering the device operation and maintenance process, the service maps the operation and maintenance configuration backup library, operation and maintenance tools, and operation and maintenance patch file library. Among them, the operation and maintenance configuration backup library, operation and maintenance tool directory, and operation and maintenance patch file library directories between different device operation and maintenance processes are permission-separated, and only the directory information of the current device is visible.
[0035] The terminal device for which the operation and maintenance can issue requisition forms for manual or automatic operation and maintenance information. After connecting to the terminal, manual operation and maintenance can be selected, or the operation and maintenance process script sent down can be automatically run. Further, during the operation and maintenance process, the system automatically records operation and maintenance logs and videos.
[0036] In some embodiments, the operation and maintenance steps further include the technical details of automatic work order execution: (1) Build a server execution command group, which internally contains operation commands and operation command steps; (2)Construct an abnormal automatic exit flag service group, with internal components: file operation group, information collection group, service operation group, and user operation group; (3)Automatically improve the service, implement an automatic exit mechanism for command group errors, and automatically identify abnormal situations in operation commands; (4)Build an SSH client using Python to connect to a remote server; (5)If an automatic execution script is used, Python automatically executes preset commands and automatically determines whether the execution reaches the preset goal; (6)Both automatic operation and maintenance and manual operation and maintenance will record all executed commands and execution results.
[0037] In some embodiments, the operation and maintenance steps further include an automatic analysis operation step for work orders: (1)Collect all operation commands; (2)Automatically analyze the operation processes with a large number of related executed commands. Whether it is the entire process or a part of the previous group of processes, an automated operation template is automatically extracted and formed; (3)Identify variable parameters in the commands, and generate a script manually after identification; (4)Construct operation and maintenance processes for different scenarios through the combination of multiple groups of automated script templates and the manual input of partial commands.
[0038] It also includes an intelligent learning process: after the user's manual operation, the system can record the user's operation and maintenance operations. In intelligent learning, the operation and maintenance process can be automatically displayed in parts through recording, variable parameters can be automatically identified, used for the user to set different operation parameters, and an automatic operation and maintenance process can be constructed.
[0039] In some embodiments, sending the operation and maintenance data to the back end of the management platform through SFTP includes: packing by device directory, generating the md5 value of the file, adding the file and its corresponding md5 value to the info.txt file, and finally packing the compressed packages of each directory and the info.txt together into a final compressed package. The name of the final compressed package is the application form ID + the current timestamp. The info.txt file contains the md5 values of all files, which is used to verify the integrity of the files.
[0040] Steps for analyzing the stability of operation and maintenance devices: S700: The back end of the management platform collects and analyzes operation and maintenance information, and the operation and maintenance information includes an operation and maintenance patch file library, a configuration backup library, operation and maintenance tools, operation and maintenance logs, and operation and maintenance videos; evaluate the stability of the terminal and the service through the analysis results of the operation and maintenance information, and alarm unstable devices.
[0041] Among them, after the operation and maintenance process ends, the application form is stored in the library of operation and maintenance devices, operation and maintenance personnel, operation and maintenance time, etc.
[0042] Unpack the operation and maintenance report file, and verify the correctness of the unpacked data. Perform device-specific data parsing on the operation and maintenance patch file library, configuration backup library, operation and maintenance tools, operation and maintenance logs, and operation and maintenance videos.
[0043] 1) Operation and maintenance patch file library: After parsing, perform md5 parsing and supplement the patch package to the platform patch management library.
[0044] 2) Configuration backup library: After parsing, report it to the configuration backup library for rapid deployment of user operation and maintenance devices.
[0045] 3) Operation and maintenance tools: After parsing, perform md5 parsing and supplement the operation and maintenance tools to the platform operation and maintenance tool library.
[0046] 4) Operation and maintenance logs: Back up the log data.
[0047] 5) Operation and maintenance videos: Back up the data and parse the operation and maintenance videos.
[0048] Collection of operation and maintenance information: Collect and analyze the number of operation and maintenance terminals in the application form, the number of operation and maintenance times of the maintained terminals within a fixed time, the operation and maintenance time of each terminal, and the status information of the maintained terminals. The purpose of operation and maintenance is to analyze the usage status of the terminals, evaluate the stability of the terminals and services, and perform visual display.
[0049] Analysis of the stability of operation and maintenance equipment: 1. Operation and maintenance metrics: Through the application form mechanism, the operation and maintenance times, operation and maintenance time, etc. of the terminals can be extracted and analyzed. The automatic operation and maintenance plug-in can extract the components of the operation and maintenance terminals involved for analysis.
[0050] 2. Through data analysis, the stability of the terminals and the stability of the device components can provide information reference for operation and maintenance personnel.
[0051] 3. Alarms can be issued for devices that have been operated and maintained multiple times and whose operation and maintenance equipment is unstable, informing the instability of the terminal system.
[0052] In a second aspect, the present application proposes a network security bastion host operation and maintenance system based on a mobile vehicle network environment, as Figure 3 shown, including an information storage module, an operation and maintenance preparation module, an application form creation module, an application form approval module, a connection construction module, an operation and maintenance module, and an operation and maintenance equipment stability analysis module; The information storage module is used to execute the information storage step: Use a three-proof notebook to build an operation and maintenance terminal. The operation and maintenance terminal enters the device information through a barcode scanner to ensure that each device corresponds to a unique device ID. After storage, the information of the operation and maintenance terminal is entered to form a ledger; The operation and maintenance preparation module is used to execute the operation and maintenance preparation step: Deploy the operation and maintenance services of the network security bastion host through the ledger of the operation and maintenance terminal. Among them, in the initial boot state of the network security bastion host, the operation and maintenance terminal can only enter the user login web page. When the service deployment management platform backend has not issued the requisition form status, the operation and maintenance terminal has no user information and requisition form information, and the operation and maintenance terminal cannot log in. If the operation and maintenance terminal is not registered with the service deployment management platform backend, the service deployment management platform backend cannot construct the current device requisition form; The requisition form creation module is used to execute the requisition form creation steps: Submit the operation and maintenance requisition form through the WeChat mini-program or the operation and maintenance management system. The requisition form includes operation and maintenance personnel information, operation and maintenance type, vehicle number, and information of the device under operation and maintenance; The requisition form approval module is used to execute the requisition form approval steps: Associate the requisition form with the specified operation and maintenance terminal through a barcode scanner or manual entry, and synchronize the operation and maintenance personnel information; The connection construction module is used to execute the connection construction steps: The portable operation and maintenance terminal establishes a connection with the management platform backend through DHCP or a fixed IP address; the management platform backend scans the connected devices, automatically performs service device authentication, and after successful authentication and construction of the link, the management platform backend automatically issues the requisition form and user information involved to the portable operation and maintenance terminal; The operation and maintenance module is used to execute the operation and maintenance steps: The operation and maintenance personnel perform identity verification through face recognition and account password. After logging in to the operation and maintenance terminal, they enter the operation and maintenance device service and perform manual or automatic operation and maintenance operations; during the operation and maintenance process, the system automatically records the operation and maintenance logs and videos, and automatically executes the preset work orders; after the operation and maintenance is completed, the operation and maintenance data is packaged and sent to the management platform backend through SFTP, and all information on the operation and maintenance terminal is cleared; the administrator retrieves the relevant information of the requisition form and the upload status of the configuration file through a barcode scanner, and the system automatically checks whether the files are complete and closes the requisition form; The operation and maintenance device stability analysis module is used to execute the operation and maintenance device stability analysis steps: The management platform backend collects and analyzes the operation and maintenance information. The operation and maintenance information includes the operation and maintenance patch file library, configuration backup library, operation and maintenance tools, operation and maintenance logs, and operation and maintenance videos; evaluate the stability of the terminal and the service through the analysis results of the operation and maintenance information, and alarm the unstable devices.
[0053] In a third aspect, the present application proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above method are implemented.
[0054] Fourth aspect, the present application provides a computer-readable storage medium storing a computer program, which when executed by a processor implements the steps of the above-mentioned method.
[0055] Those skilled in the art can clearly understand that for the convenience and conciseness of description, only the above-mentioned division of each functional unit and module is used as an example. In actual applications, the above-mentioned functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiments can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working processes of the units and modules in the above-mentioned system can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0056] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0057] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present disclosure.
[0058] In the embodiments provided by the present disclosure, it should be understood that the disclosed device / computer device and method can be implemented in other ways. For example, the device / computer device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division, and there can be other division methods in actual implementation. Multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0059] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0060] In addition, each functional unit in various embodiments of the present disclosure may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0061] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present disclosure, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above various method embodiments can be implemented. The computer program may include computer program code, and the computer program code may be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0062] The above is only the preferred implementation manner of the present invention. It should be pointed out that for those skilled in the art, without departing from the premise of this technical solution, several modified and improved technical solutions should also be regarded as falling within the scope protected by this claim book.
Claims
1. A network security bastion host operation and maintenance method based on a mobile vehicle network environment, characterized by: The following steps are involved: Steps for entering information into the database: Use a three-proof notebook to build an operation and maintenance terminal, which uses a barcode scanner to store device information, ensuring that each device corresponds to a unique device ID. After storage, the information entered into the operation and maintenance terminal forms a ledger; Operation and maintenance preparation steps: The operation and maintenance service of the network security bastion host is deployed through the account of the operation and maintenance terminal. In the initial startup state of the network security bastion host, the operation and maintenance terminal can only enter the user login web page. When the service deployment management platform backend has not issued the application form status, the operation and maintenance terminal has no user information and application form information, and the operation and maintenance terminal cannot log in. If the operation and maintenance terminal is not registered with the service deployment management platform backend, the service deployment management platform backend cannot build the current device application form; Steps to create a request form: Submit an operation and maintenance application form through the WeChat applet or the operation and maintenance management system. The application form contains the operation and maintenance personnel information, operation and maintenance type, vehicle number, and the information of the equipment being operated and maintained; Application form approval steps: Use a barcode scanner or manual entry to associate the application form with the designated operation and maintenance terminal, and synchronize the operation and maintenance personnel information; Connection building steps: The portable operation and maintenance terminal establishes a connection with the management platform backend through DHCP or a fixed IP address; the management platform backend scans the connected device and automatically authenticates the service device. After the authentication is successful and the link is established, the management platform backend automatically sends the application form and user information involved to the portable operation and maintenance terminal; Operation and maintenance steps: The operation and maintenance personnel use face recognition and account password for identity verification. After logging into the operation and maintenance terminal, they enter the operation and maintenance equipment service and perform manual or automatic operation and maintenance operations. During the operation and maintenance process, the system automatically records the operation and maintenance logs and videos, and automatically executes the preset work orders. After the operation and maintenance is completed, the operation and maintenance data is packaged and sent to the back end of the management platform via SFTP, and all information on the operation and maintenance terminal is cleared. The administrator uses a barcode scanner to retrieve the relevant information of the application form and the upload status of the configuration file. The system automatically checks whether the files are complete and closes the application form. Operation and maintenance equipment stability analysis steps: The backend of the management platform collects and analyzes operation and maintenance information, including an operation and maintenance patch file library, a configuration backup library, operation and maintenance tools, operation and maintenance logs, and operation and maintenance videos; the stability of terminals and services is evaluated through the analysis results of the operation and maintenance information, and alarms are issued for unstable devices.
2. The method according to claim 1, characterized in that: The connection building step also includes: logging in through the application form and user information involved in the operation and maintenance terminal issued by the back end of the management platform. After logging in to the operation and maintenance equipment service, the web page only includes the operation and maintenance equipment in the application form, the equipment connection method and the operation and maintenance operations required for the operation and maintenance equipment.
3. The method according to claim 2, characterized in that: The operation and maintenance steps also include the environment preparation steps: Create corresponding directories through the portable operation and maintenance terminal to initialize the environment. The directories include primary, secondary and tertiary directories. The primary directory includes an application form directory, the secondary directory includes the directory of each device in the application form directory, and the tertiary directory includes an operation and maintenance patch file library, a configuration backup library, an operation and maintenance tool directory, an operation and maintenance log directory and an operation and maintenance video directory.
4. The method according to claim 3, characterized in that: The operation and maintenance steps also include user group management steps: Management is performed through user groups. Operation and maintenance user groups are created. The operation and maintenance user groups cannot operate the operation and maintenance catalog, and cannot create, modify, or migrate. Tools that are not in the operation and maintenance tool catalog cannot be executed.
5. The method according to claim 4, characterized in that: The operation and maintenance steps also include an operation and maintenance directory mapping step: When the logged-in operation and maintenance user group enters the device operation and maintenance process, the service maps the operation and maintenance configuration backup library, operation and maintenance tools, and operation and maintenance patch file library to directories. The operation and maintenance configuration backup library, operation and maintenance tool directory, and operation and maintenance patch file library directory between different device operation and maintenance processes are separated by permissions, and only the directory information of the current device is visible.
6. The method according to claim 5, characterized in that: The operation and maintenance steps also include technical details for automatic execution of work orders: (1) Build a server execution command group, which contains operation commands and operation command steps; (2) Construct an abnormal automatic exit flag service group, which includes: file operation group, information collection group, service operation group and user operation group; (3) Automatic service improvement, automatic exit mechanism when executing command group errors, and automatic identification of abnormal situations in operation commands; (4) Use Python to build an SSH client to connect to a remote server; (5) If the script is executed automatically, Python automatically executes the preset command and automatically determines whether the execution achieves the preset purpose; (6) Both automatic and manual operations will record all execution commands and results.
7. The method according to claim 6, characterized in that: The operation and maintenance steps also include the work order automatic analysis operation steps: (1) Collect all operation commands; (2) Automatically analyze the operation flow where a large number of related execution commands appear, and automatically extract the entire flow or part of the previous set of flows to form an automated operation template; (3) Identify variable parameters in the command and generate the script manually after identification; (4) Build operation and maintenance processes for different scenarios by combining multiple sets of automated script templates with autonomous input of some commands.
8. The method according to claim 7, characterized in that: The operation and maintenance data is packaged and sent to the management platform backend through SFTP, including: packaging by device directory and generating file md5 values, adding the md5 values corresponding to the files to the info.txt file, and finally packaging the compressed packages of each directory with the info.txt into a final compressed package. The final compressed package name is the application form id + current timestamp. The info.txt file contains the md5 values of all files for verifying the integrity of the files.
9. A network security bastion host operation and maintenance system based on a mobile vehicle network environment, characterized by: It includes information storage module, operation and maintenance preparation module, application form creation module, application form approval module, connection construction module, operation and maintenance module and operation and maintenance equipment stability analysis module; The information storage module is used to perform the information storage steps: Use a three-proof notebook to build an operation and maintenance terminal, which uses a barcode scanner to store device information, ensuring that each device corresponds to a unique device ID. After storage, the information entered into the operation and maintenance terminal forms a ledger; The operation and maintenance preparation module is used to perform the operation and maintenance preparation steps: The operation and maintenance service of the network security bastion host is deployed through the account of the operation and maintenance terminal. In the initial startup state of the network security bastion host, the operation and maintenance terminal can only enter the user login web page. When the service deployment management platform backend has not issued the application form status, the operation and maintenance terminal has no user information and application form information, and the operation and maintenance terminal cannot log in. If the operation and maintenance terminal is not registered with the service deployment management platform backend, the service deployment management platform backend cannot build the current device application form; The application form creation module is used to execute the application form creation steps: Submit an operation and maintenance application form through the WeChat applet or the operation and maintenance management system. The application form contains the operation and maintenance personnel information, operation and maintenance type, vehicle number, and the information of the equipment being operated and maintained; The application form approval module is used to execute the application form approval steps: Use a barcode scanner or manual entry to associate the application form with the designated operation and maintenance terminal, and synchronize the operation and maintenance personnel information; The connection building module is used to perform the connection building steps: The portable operation and maintenance terminal establishes a connection with the management platform backend through DHCP or a fixed IP address; the management platform backend scans the connected device and automatically authenticates the service device. After the authentication is successful and the link is established, the management platform backend automatically sends the application form and user information involved to the portable operation and maintenance terminal; The operation and maintenance module is used to perform operation and maintenance steps: The operation and maintenance personnel use face recognition and account password for identity verification. After logging into the operation and maintenance terminal, they enter the operation and maintenance equipment service and perform manual or automatic operation and maintenance operations. During the operation and maintenance process, the system automatically records the operation and maintenance logs and videos, and automatically executes the preset work orders. After the operation and maintenance is completed, the operation and maintenance data is packaged and sent to the back end of the management platform via SFTP, and all information on the operation and maintenance terminal is cleared. The administrator uses a barcode scanner to retrieve the relevant information of the application form and the upload status of the configuration file. The system automatically checks whether the files are complete and closes the application form. The operation and maintenance equipment stability analysis module is used to perform the operation and maintenance equipment stability analysis steps: The backend of the management platform collects and analyzes operation and maintenance information, including an operation and maintenance patch file library, a configuration backup library, operation and maintenance tools, operation and maintenance logs, and operation and maintenance videos; the stability of terminals and services is evaluated through the analysis results of the operation and maintenance information, and alarms are issued for unstable devices.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.