Server login authentication method and server cluster
By using the authentication and authentication server and the authentication cache server in the server cluster, and combining the device login certificate and biometric authentication information of the handheld device terminal for two-factor verification, the security risks caused by dynamic token leakage in multiple server scenarios are solved, the security of login authentication is improved and the user login process is simplified.
Patent Information
- Application Number
- CN202510157724.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-06-13
AI Technical Summary
In multi-server scenarios, the existing technology uses the same dynamic token for login authentication, which poses a security risk. If the token is leaked, it will affect all servers.
By introducing authentication and authentication servers and authentication cache servers into the server cluster, the device login certificate and biometric authentication information of the handheld device terminal are used for two-factor verification, replacing the traditional username and password login method.
Improve the security of multi-server login authentication, avoid the security impact of dynamic token leakage on all servers, simplify the user login process, and reduce the user's need to enter information.
Smart Images

Figure CN120150985A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of login authentication, and in particular, to a server login authentication method and a server cluster. Background Art
[0002] Server login generally refers to the act of an administrator or user connecting to a remote server through a network for management and operation.
[0003] In related technologies, to achieve secure login, the method of using a username and password for authentication is generally adopted, and then the authentication and authorization are managed through an authentication module (Password Authentication Module, PAM). When performing login authentication, this method will cause the server to generate a dynamic token for secure authentication. Although secure login can be achieved in this way, in a multi-server scenario, this method will cause all servers to use the same dynamic token. If the dynamic token is leaked, it will have a security impact on all servers, posing a relatively large security risk. Summary of the Invention
[0004] The problem solved by the present invention is how to improve the security of multi-server login authentication.
[0005] To solve the above problems, the present invention provides a server login authentication method and a server cluster.
[0006] In a first aspect, the present invention provides a server login authentication method, which is applied to a server cluster. The server cluster includes an authentication and authorization server, an authentication cache server, and a server group that are sequentially connected. The server login authentication method includes:
[0007] The authentication and authorization server verifies the device login certificate of the handheld device terminal associated with the login request information according to the user's login request information, and obtains the biometric authentication information of the handheld device terminal according to the verification result;
[0008] The authentication and authorization server performs identity verification based on the biometric authentication information, determines the authorized login information of the user after the identity verification is passed, and sends the authorized login information to the authentication cache server;
[0009] The authentication cache server approves the user to log in to the target server in the server group based on the authorized login information.
[0010] Optionally, before the authentication and authorization server obtains the user's login request information, it further includes:
[0011] The target server establishes a two-way authentication connection with the handheld device terminal and generates the device login certificate.
[0012] Optionally, before the authentication and authorization server obtains the login request information of the user, it further includes:
[0013] The handheld device terminal is matched with the user's user device;
[0014] The user device generates the login request information based on the login requirement, where the login request information refers to a connection request between the user device and the target server.
[0015] Optionally, after approving the user to log in to the target server in the server group, it further includes:
[0016] The authentication and authorization server monitors the connection status between the handheld device terminal and the target server;
[0017] When the connection status is offline, the authentication and authorization server rejects the connection request of the user device to the target server.
[0018] Optionally, after approving the user to log in to the target server in the server group, it further includes:
[0019] The authentication cache server stores the authorized login information and updates the authorized login information in the authentication cache server according to the update requirement.
[0020] Optionally, after approving the user to log in to the target server in the server group, it further includes:
[0021] According to the requirement of revoking the user, the authentication cache server deletes the device login certificate corresponding to the target server.
[0022] Optionally, the server login authentication method further includes:
[0023] The authentication and authorization server obtains the network status. When the network status is without network, the pam_unix login authentication technology is adopted.
[0024] Optionally, the server login authentication method further includes:
[0025] The authentication and authorization server obtains the network status. When the network status is without network, the One Time Password login authentication technology is adopted.
[0026] Optionally, obtaining the biometric authentication information of the handheld device terminal according to the verification result includes:
[0027] When the verification result is successful, obtain the biometric authentication information of the handheld device terminal;
[0028] When the verification result is a failure, the authentication and authorization server rejects the user's login.
[0029] In a second aspect, the present invention provides a server cluster, which includes an authentication and authorization server, an authentication cache server, and a server group connected in sequence. The server cluster applies the server login authentication method as described in the first aspect.
[0030] The beneficial effects of the server login authentication method and the server cluster of the present invention are as follows:
[0031] Based on the user's login request information, the authentication and authorization server verifies the device login certificate of the handheld device terminal associated with the login request information, which can preliminarily verify the user's identity to initially ensure the security of the login. Moreover, the device login certificate is the only authentication between the user's handheld device terminal and the server cluster. The authentication and authorization server allows the user's handheld device terminal to log in to the corresponding server. Then, the biometric authentication information of the handheld device terminal is obtained, and based on the biometric authentication information, the authentication and authorization server conducts a secondary identity verification of the user to further ensure the security of the login. After successful verification, the authorized login information of the user is generated. If the verification fails, the authorized login information of the user is not generated. Finally, the authentication cache server approves the user to log in to the target server in the server group based on the authorized login information to complete the login. By sequentially verifying the device login certificate of the user's handheld device terminal and the biometric authentication information of the user, the present invention replaces the login method using a username and password in the related art, enabling multiple servers not to generate dynamic tokens, avoiding the problem of the security impact on all servers caused by the leakage of dynamic tokens, improving the security of server login. If the device login certificate of the user's handheld device terminal is leaked, the user still needs the biometric authentication information to log in during login, further improving the security. In addition, the present invention is simpler. The user does not need to input a username, password, and dynamic token, and only needs to submit a login application and conduct biometric authentication, saving the user's time. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 It is a schematic flowchart of the server login authentication method provided by an embodiment of the present invention;
[0033] Figure 2 It is a schematic structural diagram of the server cluster provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0034] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of specific embodiments of the present invention in conjunction with the accompanying drawings. Although certain embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments described herein. Instead, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.
[0035] It should be understood that the various steps recorded in the method embodiments of the present invention can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.
[0036] As used herein, the term "including" and its variants are open-ended, that is, "including but not limited to"; the term "based on" is "at least partially based on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules, or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules, or units.
[0037] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless clearly stated otherwise in the context, it should be understood as "one or more".
[0038] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0039] In view of the problems existing in the above related technologies, this embodiment provides a server login authentication method and a server cluster.
[0040] As Figure 1 shown, a server login authentication method provided by an embodiment of the present invention is applied to a server cluster, and the server cluster includes an authentication and authorization server, an authentication cache server, and a server group connected in sequence.
[0041] Specifically, as Figure 2As shown in the figure, the server cluster includes an authentication and authorization server, an authentication cache server, and a server group that are sequentially connected. The server group includes multiple servers. The authentication and authorization server is used for authentication and authorization, and the authentication cache server is used for storing information.
[0042] The server login authentication method includes:
[0043] The authentication and authorization server verifies the device login certificate of the handheld device terminal associated with the login request information according to the user's login request information, and obtains the biometric authentication information of the handheld device terminal according to the verification result.
[0044] Specifically, the login request information includes the login request server domain name, IP address, and login username. The authentication and authorization server verifies whether there is a handheld device terminal associated with the login username, IP, and the main server of the login request server domain name. If so, it verifies whether the device login certificate of the handheld device terminal is correct, that is, determines whether the handheld device terminal has the permission to log in to the target server. If correct, it obtains the biometric authentication information of the handheld device terminal, such as fingerprint, facial features, and voiceprint, etc., for biometric authentication. Among them, the handheld device terminal can include handheld device terminals such as mobile phones, smart watches, and tablet computers.
[0045] The authentication and authorization server performs identity verification based on the biometric authentication information, determines the authorized login information of the user after the identity verification passes, and sends the authorized login information to the authentication cache server.
[0046] Specifically, after the biometric authentication information is also successfully authenticated, the authentication and authorization server queries and determines the authorized login information of the user. The authorized login information refers to the authentication and authorization information of the user, including user groups and Sudoers permissions, etc., and returns the authorized login information to the device that the user needs to connect to, such as a computer, etc. At the same time, the authentication and authorization server provides the user's directory and additional information, such as the validity period of the certificate or specific access restrictions, etc.
[0047] The authentication cache server approves the user to log in to the target server in the server group based on the authorized login information.
[0048] Specifically, the authentication cache server approves the user to log in to the target server in the server group based on the authorized login information, establishes a session between the user and the target server to complete the login. Exemplarily, if any one of the steps fails in authentication, the corresponding error information is returned to the user to explain the reason for the login failure and the login is refused.
[0049] Exemplarily, the present invention can be applied to scenarios such as unified user identity management in large data centers or large distributed infrastructures.
[0050] In this embodiment, the authentication and authorization server verifies the device login certificate of the handheld device terminal associated with the user's login request information according to the login request information, so as to preliminarily verify the user's identity and initially ensure the security of the login. Moreover, the device login certificate is the only authentication between the user's handheld device terminal and the server cluster, which can prove that the authentication and authorization server allows the user's handheld device terminal to log in to the corresponding server. Then, the biometric authentication information of the handheld device terminal is obtained, and based on the biometric authentication information, the authentication and authorization server generates the authorized login information of the user to conduct a secondary identity verification of the user, further ensuring the security of the login. Finally, the authentication and authorization server determines the authorized login information of the user based on the biometric authentication information, and the authentication cache server approves the user to log in to the target server in the server group based on the authorized login information, completing the login. By separately verifying the device login certificate of the user's handheld device terminal and the biometric authentication information of the user, the present invention replaces the login method using the username and password in the related art, avoids the problem of the security impact on all servers caused by the leakage of the dynamic token, improves the security of the server login, and is more simple. The user does not need to input the username, password, and dynamic token, and only needs to submit a login application and conduct biometric authentication, saving the user's time.
[0051] Optionally, before the authentication and authorization server obtains the user's login request information, it further includes:
[0052] The target server establishes a two-way authentication connection with the handheld device terminal and generates the device login certificate.
[0053] Specifically, the Mutual Authentication HTTPS method can be used to establish a two-way authentication connection between the handheld device terminal and the target server. Mutual Authentication refers to the two-way certificate verification method between the client and the server side. The client verifies that the server is the authorized server for access, and the server verifies that the client is the authorized client connection. HTTPS refers to HTTP with TLS encryption. By using the Mutual Authentication HTTPS method to establish a two-way authentication connection between the handheld device terminal and the target server, the handheld device terminal has a client certificate signed by the authentication server, that is, the device login certificate, which is used as the "token" for the user to log in, thus facilitating the login verification.
[0054] Optionally, before the authentication and authorization server obtains the user's login request information, it further includes:
[0055] The handheld device terminal is matched with the user's user device;
[0056] The user equipment generates the login request information based on the login requirement, where the login request information refers to the connection request of the user equipment to the target server.
[0057] Specifically, the user can use the device login certificate of the handheld device terminal as the "key" for the user equipment to connect to the target server. That is, through the handheld device terminal, the user equipment, such as a computer, can log in to the target server. That is, when the user equipment makes a connection request to the target server, authentication and login can be performed through the user's handheld device terminal, which can eliminate the steps of using a username and password, thereby avoiding security issues. The user equipment generates login request information based on the login requirement through the PAM authentication server of the user equipment, and sends the login request server domain name, IP address, and login username to the authentication and authorization server.
[0058] Optionally, after approving the user to log in to the target server in the server group, it further includes:
[0059] The authentication and authorization server monitors the connection status between the handheld device terminal and the target server;
[0060] When the connection status is offline, the authentication and authorization server rejects the connection request of the user equipment to the target server.
[0061] Specifically, after approving the login, the connection status between the handheld device terminal and the target server is monitored in real time. If the handheld device terminal is offline, the connection request of the user equipment to the target server is rejected, the connection is disconnected, and the reason for the login failure is sent to the user to ensure security and avoid information leakage.
[0062] Optionally, after approving the user to log in to the target server in the server group, it further includes:
[0063] The authentication cache server stores the authorized login information and updates the authorized login information in the authentication cache server according to the update requirement.
[0064] Specifically, if it is necessary to change or update the user's authorized login information, only the corresponding configuration needs to be changed and adjusted in the authentication cache server, without other operations.
[0065] Optionally, after approving the user to log in to the target server in the server group, it further includes:
[0066] According to the requirement of revoking the user, the authentication cache server deletes the device login certificate corresponding to the target server.
[0067] Specifically, if it is necessary to revoke a user's permissions, it is only necessary to delete the device login certificate of the user's handheld device terminal, and all the authorized permissions of the user can be revoked without any other operations.
[0068] Optionally, the server login authentication method further includes:
[0069] The authentication and authorization server obtains the network status. When the network status is no network, the pam_unix login authentication technology is adopted.
[0070] Specifically, when the user device is in a non-networked state without network, the traditional PAM login authentication technology based on username and password, that is, the pam_unix login authentication technology, can be adopted to ensure that the user can log in under any circumstances.
[0071] Optionally, the server login authentication method further includes:
[0072] The authentication and authorization server obtains the network status. When the network status is no network, the One Time Password login authentication technology is adopted.
[0073] Specifically, when the user device is in a non-networked state without network, the traditional one-time password authentication technology, that is, the One Time Password authentication technology, can be adopted to ensure that the user can log in under any circumstances.
[0074] Optionally, obtaining the biometric authentication information of the handheld device terminal according to the verification result includes:
[0075] When the verification result is successful, obtain the biometric authentication information of the handheld device terminal;
[0076] When the verification result is failed, the authentication and authorization server rejects the user's login.
[0077] Specifically, when the verification result is successful, obtain the biometric authentication information of the handheld device terminal; when the verification result is failed, the authentication and authorization server rejects the user's login to ensure security.
[0078] A server cluster provided by an embodiment of the present invention, the server cluster includes an authentication and authorization server, an authentication cache server, and a server group connected in sequence, and the server cluster applies the server login authentication method as described above.
[0079] Or rather, the server cluster performs the following operations:
[0080] The authentication and authorization server verifies the device login certificate of the handheld device terminal associated with the user's login request information according to the login request information of the user, and obtains the biometric authentication information of the handheld device terminal according to the verification result;
[0081] Based on the biometric authentication information, the authentication and authorization server determines the authorized login information of the user and sends the authorized login information to the authentication cache server;
[0082] The authentication cache server approves the user to log in to the target server in the server group based on the authorized login information.
[0083] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disc, a read-only memory (ROM), or a random access memory (RAM), etc. In this application, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention. In addition, the functional units in the various embodiments of the present invention can be integrated in one processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0084] Although the present invention is disclosed as above, the protection scope of the present invention is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention, and these changes and modifications will all fall within the protection scope of the present invention.
Claims
1. A server login authentication method, characterized in that: Applied to a server cluster, the server cluster includes an authentication server, an authentication cache server and a server group connected in sequence, and the server login authentication method includes: The authentication server verifies the device login certificate of the handheld device terminal associated with the login request information according to the user's login request information, and obtains the biometric authentication information of the handheld device terminal according to the verification result; The authentication server performs identity authentication based on the biometric authentication information, determines the user's authorized login information after the identity authentication is passed, and sends the authorized login information to the authentication cache server; The authentication cache server approves the user to log in to the target server in the server group based on the authorized login information.
2. The server login authentication method according to claim 1, characterized in that: Before the authentication server obtains the user's login request information, it also includes: The target server establishes a two-way authentication connection with the handheld device terminal and generates the device login certificate.
3. The server login authentication method according to claim 1, characterized in that: Before the authentication server obtains the user's login request information, it also includes: The handheld device terminal is matched with the user equipment of the user; The user device generates the login request information based on the login requirement, wherein the login request information refers to a connection request between the user device and the target server.
4. The server login authentication method according to claim 2, characterized in that: After approving the user to log in to the target server in the server group, the method further includes: The authentication server monitors the connection status between the handheld device terminal and the target server; When the connection state is offline, the authentication server rejects the connection request between the user equipment and the target server.
5. The server login authentication method according to claim 1, characterized in that: After approving the user to log in to the target server in the server group, the method further includes: The authentication cache server stores the authorized login information and updates the authorized login information in the authentication cache server according to an update requirement.
6. The server login authentication method according to claim 1, characterized in that: After approving the user to log in to the target server in the server group, the method further includes: According to the revocation user demand, the authentication cache server deletes the device login certificate corresponding to the target server.
7. The server login authentication method according to claim 1, characterized in that: Also includes: The authentication server obtains the network status, and when the network status is no network, the pam_unix login authentication technology is used.
8. The server login authentication method according to claim 1, characterized in that: Also includes: The authentication server obtains the network status, and when the network status is no network, the One Time Password login authentication technology is used.
9. The server login authentication method according to claim 1, characterized in that: The step of obtaining the biometric authentication information of the handheld device terminal according to the verification result includes: When the verification result is successful, obtaining the biometric authentication information of the handheld device terminal; When the verification result is failure, the authentication server rejects the user's login.
10. A server cluster, characterized in that: The server cluster includes an authentication server, an authentication cache server and a server group connected in sequence, and applies the server login authentication method as described in any one of claims 1 to 9.