Authentication method and file storage device
By storing the user's historical authentication information in the file storage device, the authentication interruption problem is solved when the domain controller is abnormal, and the authentication process continuity and security are realized when the domain controller is abnormal.
Patent Information
- Application Number
- CN202311861698.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
In the event of an abnormal domain controller, the prior art cannot effectively perform user authentication, resulting in the host being unable to access shared files in the file storage device.
When the domain controller is abnormal, the file storage device uses the stored user information to authenticate, and authenticates the user instead of the domain controller to ensure the continuity of the authentication process.
By storing the user's historical authentication information, the file storage device can continue to authenticate when the domain controller is abnormal, reducing the chance that the user cannot access the shared files and ensuring the continuity and security of the authentication process.
Smart Images

Figure CN120234790A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the storage field, and particularly to an authentication method and a file storage device. Background Art
[0002] Network Attached Storage (NAS) is a file storage device for data storage and sharing. Compared with traditional local hard disks, NAS can be connected to multiple hosts through a network to achieve file sharing and access. Different users can access the same file on different devices, improving work efficiency and the convenience of data sharing.
[0003] Before sharing a file, it is necessary to authenticate and authorize the accessing user first. For example, in the NTLM (NT LAN Manager) authentication process, the host first sends user information to the file storage device. After the file storage device establishes a connection with the domain controller (DC), it sends the user information to the domain controller for authentication. After the domain controller returns an authentication pass to the file storage device, the file storage device can provide the user with the permission to access the file.
[0004] However, the foregoing authentication method depends on the domain controller. When an abnormality occurs on the domain controller side (for example, a network abnormality on the domain controller side, or an update of the security policy on the domain controller side, etc.), it may cause the host to be unable to authenticate on the domain controller side, and further cause the host to be unable to access the shared files in the file storage device. Summary of the Invention
[0005] The present application provides an authentication method and a file storage device for providing an authentication service for users when an abnormality occurs on the domain controller side, and reducing the probability that users are affected from accessing the shared files in the file storage device due to being unable to authenticate on the domain controller side.
[0006] In a first aspect, the present application provides an authentication method, which is applied to a file storage device. This authentication method can be executed by the file storage device or by components of the file storage device (such as components like a processor, a chip, or a chip system, etc.). In the following, the file storage device is taken as an example. The file storage device receives a first authentication request from a host, and the first authentication request includes first information of a first user, where the first user is a user who has applied for domain authentication through the host. Then, the file storage device attempts to establish a connection with the domain controller. In the case where the file storage device determines that the domain controller corresponding to the file storage device is abnormal, the file storage device authenticates the first user based on the first information of the first user and second information of the first user stored in the file storage device, and obtains an authentication result of the first user. Among them, the second information is the information obtained when the first user successfully passes the domain controller authentication, or it can be understood that the second information is the information of the first user who has successfully passed the domain controller authentication before the domain controller is abnormal. Then, the file storage device sends a first authentication response to the host, and the first authentication response includes the authentication result of the first user.
[0007] In the prior art, when the domain controller is working properly, the file storage device only forwards the authentication request of a certain user from the host to the domain controller, and the domain controller authenticates the user based on the information about the user stored in the domain controller. When the domain controller is abnormal, the domain controller cannot authenticate the user. In the present application, the file storage device stores the second information of the first user, that is, before the domain controller is abnormal, the file storage device stores the information of the first user who has successfully passed the domain controller authentication. When the domain controller is abnormal, the file storage device can use the stored second information of the first user to authenticate the first information of the first user obtained from the first authentication request, that is, the file storage device can use the information of the user who has successfully passed the historical authentication to replace the domain controller to authenticate the user applying for authentication. Therefore, when the domain controller is abnormal, the file storage device will not interrupt the authentication process, which is beneficial to ensuring the continuity of the user's authentication process, and further reducing the probability that the user is affected from accessing the shared files in the file storage device due to the inability to authenticate on the domain controller side.
[0008] In a possible implementation manner, before the domain controller is abnormal, the method further includes: in the case where the first user is successfully authenticated by the domain controller, the file storage device stores the second information of the first user.
[0009] In this embodiment, since the file storage device can store the information of the first user who has been successfully authenticated by the domain controller before the domain controller fails, when the domain controller fails, the file storage device can authenticate the first user using the second information of the first user that has been stored. This helps to avoid interrupting the authentication process due to the failure of the domain controller, ensures the continuity of the user authentication process, and reduces the probability that the user cannot authenticate on the domain controller side and thus affects accessing the shared files in the file storage device.
[0010] In a possible implementation, the file storage device authenticates the first user based on the first information of the first user and the second information of the first user stored in the file storage device to obtain an authentication result, including:
[0011] If the first information of the first user is the same as the second information of the first user, the file storage device determines that the first user is successfully authenticated; or, if the first information of the first user is different from the second information of the first user, the file storage device determines that the first user is not authenticated.
[0012] In a possible implementation, the first information of the first user includes the account of the first user, and the second information of the first user includes the account of the first user. Specifically, the file storage device determines the authentication result of the first user by comparing the account of the first user obtained from the first authentication request with the account of the first user stored in the file storage device. If the account of the first user obtained from the first authentication request is the same as the account of the first user stored in the file storage device, the file storage device determines that the authentication result of the first user is that the first user is successfully authenticated. If the account of the first user obtained from the first authentication request is different from the account of the first user stored in the file storage device, the file storage device determines that the authentication result of the first user is that the first user is not authenticated.
[0013] In this embodiment, the file storage device can use the account of the first user that has been stored to authenticate the first user instead of the domain controller, which helps to ensure the continuity of the user authentication process. In addition, since the file storage device only compares the account of the first user and does not need to compare the information of the host, this embodiment is applicable to scenarios where it is not required to bind the user account to the host (i.e., the host where the account is logged in). For example, before the domain controller fails, the account of the first user successfully logs in to host 1; after the domain controller fails, the account of the first user can try to log in through host 1 again or try to log in on other hosts. This helps to improve the flexibility of user authentication.
[0014] In a possible implementation, the first information of the first user further includes the address of the host that logs in to the account of the first user, and the second information of the first user further includes the address of the host that logs in to the account of the first user when authenticating through the domain controller. Specifically, the file storage device determines the authentication result of the first user by comparing the account and host address of the first user obtained from the first authentication request with the account and host address of the first user stored in the file storage device. If the account of the first user obtained from the first authentication request is the same as the account of the first user stored in the file storage device, and the host address obtained from the first authentication request is the same as the host address stored in the file storage device, the file storage device determines that the authentication result of the first user is that the first user is authenticated successfully. If the account of the first user obtained from the first authentication request is different from the account of the first user stored in the file storage device, or the host address obtained from the first authentication request is different from the host address stored in the file storage device, the file storage device determines that the authentication result of the first user is that the first user is authenticated failed.
[0015] In this implementation, the file storage device can use the already stored account and host address of the first user to authenticate the first user instead of the domain controller, which is beneficial to ensuring the continuity of the user authentication process. In addition, since the file storage device compares the address and host address of the first user, this implementation is applicable to scenarios where the user account needs to be bound to the host (i.e., the host that logs in to the account). That is, the account of the first user can only be logged in on the specified host. For example, before the domain controller fails, the account of the first user successfully logs in on host 1; after the domain controller fails, the account of the first user can only be authenticated successfully if it tries to log in through host 1 again. After the domain controller fails, if the account of the first user tries to log in through other hosts, even if the account of the first user is the same, it cannot be authenticated successfully. This is beneficial to improving the security of user authentication through the file storage device.
[0016] In a possible implementation, the second information of the first user further includes an index of the access permission of the first user, and the index of the access permission of the first user is used to determine the access permission of the first user on the file storage device. If the file storage device determines that the authentication result of the first user is successful, the file storage device determines the index of the access permission of the first user based on the account of the first user.
[0017] In the prior art, the index of the access right of the first user is stored in the domain controller. Only after the first user who applies for authentication through the host is successfully authenticated in the domain controller, will the domain controller return the index of the access right of the first user to the file storage device. Subsequently, when the file storage device can receive the file access request of the first user, it can determine whether the first user has the access right to a certain file based on the index of the access right of the first user. In this embodiment, however, the file storage device stores the index of the access right of the first user before the domain controller fails. After the file storage device successfully authenticates the first user on behalf of the domain controller, the file storage device does not need to obtain the index of the access right of the first user from the domain controller, but searches for the index of the access right of the first user stored by itself based on the second information of the first user, and then determines the access right of the first user. Therefore, it is beneficial to ensure the continuity of the service of the user accessing the shared file.
[0018] In a possible implementation manner, before the file storage device receives a first request from the host, the method further includes: the file storage device receives a first negotiation request from the host, and the first negotiation request includes the authentication method supported by the host; when it is determined that the domain controller corresponding to the file storage device is abnormal, the file storage device sends a first negotiation response to the host, and the first negotiation response includes the first authentication information determined by the file storage device based on the first negotiation request, and the first authentication information is used for the host to encrypt the account password of the first user.
[0019] In the prior art, if the domain controller connected to the storage device does not fail, the file storage device forwards the first negotiation request to the domain controller. After the domain controller determines the first authentication information based on the first negotiation request, the first authentication information is then forwarded to the host through the file storage device. In this embodiment, however, the file storage device generates the first authentication information on behalf of the domain controller and returns the first authentication information to the host. This is beneficial to avoid the host not receiving the first authentication information and interrupting the authentication process, and is beneficial to ensuring the continuity of the authentication process.
[0020] In a possible implementation manner, the method further includes: when it is determined that the domain controller corresponding to the file storage device is abnormal, the file storage device enables the function of authenticating users by the proxy domain controller, and starts a first timer, and the duration of the first timer is the duration for which the file storage device authenticates users by the proxy domain controller; when the first timer times out, the file storage device disables the function of authenticating users by the proxy domain controller.
[0021] In this embodiment, the file storage device controls the duration of the function of authenticating users by the proxy domain controller by configuring the first timer, which is beneficial to timely disabling the function of authenticating users by the proxy domain controller and improving the security of network authentication.
[0022] In a possible implementation, the method further includes: when it is determined that the domain controller corresponding to the file storage device resumes normal operation, the file storage device stops the first timer, and closes the function of the proxy domain controller for authenticating users.
[0023] In this implementation, when the file storage device detects that the domain controller corresponding to the file storage device resumes normal operation, closing the function of the proxy domain controller for authenticating users is beneficial to ensuring the reliability of network authentication.
[0024] In a possible implementation, when the file storage device closes the function of the proxy domain controller for authenticating users, the file storage device forwards the received authentication request to the domain controller for processing. Specifically, the file storage device receives a second authentication request from the host, the second authentication request includes information of a second user, and the second user is a user who applies for domain authentication through the host; the file storage device sends the second authentication request to the domain controller; the file storage device receives a second authentication response from the domain controller, the second authentication response includes the authentication result of the second user and the information of the second user, and the information of the second user includes an index of the access permission of the second user.
[0025] In this implementation, after the file storage device closes the function of the proxy domain controller for authenticating users, if the file storage device receives a second authentication request from the second user again, the file storage device forwards the authentication request to the domain controller for processing. If the second user is authenticated successfully, the file storage device stores the account of the second user and the index of the access permission of the second user obtained from the domain controller, so that when the domain controller fails again, the file storage device can authenticate the second user using the information of the second user.
[0026] In a possible implementation, before the file storage device authenticates the first user based on the first information of the first user and the second information of the first user stored by the file storage device, the method further includes: the file storage device receives first configuration information, and the first configuration information is used to instruct the file storage device to enable the function of the proxy domain controller for authenticating users when the domain controller corresponding to the file storage device is abnormal.
[0027] In this implementation, the condition for triggering the enabling of the function of the proxy domain controller for authenticating users is configured in a pre-configured manner, that is, the function of the proxy domain controller for authenticating users is triggered when the domain controller corresponding to the file storage device is abnormal. This is beneficial to immediately and automatically enabling the function of the proxy domain controller for authenticating users when the file storage device detects that the domain controller is abnormal, and further beneficial to ensuring the continuity of user authentication and avoiding authentication delay caused by domain controller abnormality.
[0028] In a possible implementation, before the file storage device authenticates the first user based on the first information of the first user and the second information of the first user stored in the file storage device, the method further includes: when it is determined that the domain controller corresponding to the file storage device is abnormal, the file storage device sends an alarm message and a prompt message, the alarm message is used to indicate that the domain controller corresponding to the file storage device is abnormal, and the prompt message is used to prompt the user whether to enable the function of authenticating the user by the proxy domain controller; and, the file storage device receives a first indication message, and the first indication message is used to indicate that the file storage device enables the function of authenticating the user by the proxy domain controller.
[0029] In this implementation, when the file storage device detects that the domain controller is abnormal, the file storage device can send an alarm message and a prompt message to indicate the abnormality of the domain controller and prompt to enable the function of authenticating the user by the proxy domain controller. After receiving the first indication message, the file storage device enables the function of authenticating the user by the proxy domain controller. Since the file storage device enables the function of authenticating the user by the proxy domain controller after being confirmed by the user or the operation and maintenance personnel, it can avoid the file storage device authenticating the user by the proxy domain controller in an insecure network environment, which is beneficial to improving the security of the file storage device authenticating the user by the proxy domain controller.
[0030] In a second aspect, the present application provides an implementation of a file storage device. The file storage device can be a server for managing a storage array, or a functional module or chip in a server for managing a storage array. The file storage device can include a processing module and a transceiver module. When the file storage device is a server for managing a storage array, the processing module can be a processor, and the transceiver module can be a transceiver; the file storage device can further include a storage module, and the storage module can be a memory; the storage module is used to store instructions, and the processing module executes the instructions stored in the storage module to enable the file storage device to execute the method in the first aspect or any implementation manner of the first aspect. When the file storage device is a functional module or chip in a server for managing a storage array, the processing module can be a processor, and the transceiver module can be an input / output interface, a pin, a circuit, etc.; the processing module executes the instructions stored in the storage module to enable the file storage device to execute the method in the first aspect or any implementation manner of the first aspect. The storage module can be a storage module inside the chip (for example, a register, a cache, etc.), or a storage module outside the chip in the file storage device (for example, a read-only memory, a random access memory, etc.).
[0031] In a third aspect, the present application provides a file storage device, which includes a processor and a memory. The processor is coupled to the memory, and the memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the file storage device is caused to execute the methods described in any of the implementation manners in the foregoing various aspects.
[0032] In a fourth aspect, the present application provides an implementation manner of a computer program product containing instructions. When it runs on a computer, the computer is caused to execute the methods described in any of the implementation manners in the foregoing various aspects.
[0033] In a fifth aspect, the present application provides an implementation manner of a computer-readable storage medium, including instructions. When the instructions run on a computer, the computer is caused to execute the methods described in any of the implementation manners in the foregoing various aspects. Description of the Drawings
[0034] Figure 1 FIG. is an example diagram of an application scenario of the authentication method provided by the present application;
[0035] Figure 2 FIG. is a flowchart of the authentication method provided by the present application;
[0036] Figure 3 FIG. is another flowchart of the authentication method provided by the present application;
[0037] Figure 4 FIG. is another flowchart of the authentication method provided by the present application;
[0038] Figure 5 FIG. is a schematic diagram of the file storage device provided by the present application;
[0039] Figure 6 FIG. is another schematic diagram of the file storage device provided by the present application. Detailed Embodiments
[0040] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments.
[0041] In the description, claims and the above drawings of this application, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0042] It should be understood that the term "and / or" herein is merely a relationship describing associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B may be single or multiple. In addition, the character " / " herein generally represents an "or" relationship between the associated objects before and after. In addition, the expression "at least one of the following" or its similar expression herein is used to represent any combination of the items listed; for example, at least one of A, B, and (or) C may represent the following situations: A exists alone, B exists alone, C exists alone, A and B exist simultaneously, B and C exist simultaneously, A and C exist simultaneously, and A, B, and C exist simultaneously. Here, A, B, and C may be single or multiple.
[0043] First, the application scenarios and system architectures applicable to the authentication method provided in this application will be introduced below:
[0044] The authentication method provided in this application is mainly applied to the scenario where a file storage device provides a file sharing service to a host.
[0045] Such as Figure 1 shown, this scenario mainly involves a file storage device, a host, and a domain controller.
[0046] Among them, the file storage device mainly refers to the server that provides a file sharing service to the host. The file storage device may be a network storage management server separated from a storage device (for example, a physical storage array such as a disk array), or a network storage device integrated with a storage device, which is not limited in this application. Exemplarily, the file storage device may be a network attached storage (NAS) device, or other devices or servers capable of providing a file sharing service.
[0047] In addition, the host refers to a client that accesses data in a file storage device by running an application. The host running the aforementioned application is called an "application server". The host can be a physical machine, a virtual machine, or an operating system. For example, the two hosts applying for the shared file service can be two independent physical machines, two virtual hosts running on the same physical machine, or two virtual hosts running on different physical machines. This application does not impose any restrictions. It should be understood that the aforementioned physical machines include, but are not limited to, desktop computers, servers, laptop computers, and mobile devices, etc. The aforementioned host connects to the file storage device through a network switch and applies to the file storage device to access the data in the file storage device.
[0048] In addition, the domain controller refers to a device responsible for authenticating hosts and users connected to the network in the "domain" mode. For example, the domain controller contains information about the hosts in the domain managed by the domain controller (such as the addresses of the hosts, etc.) and information about the users allowed to log in to the domain (such as user accounts and account passwords, etc.). When a host connects to the domain managed by the domain controller, the domain controller first needs to identify whether the host belongs to this domain, and then identify whether the user account that the user attempts to log in with exists and whether the account password is correct. If all the above information is correct, the domain controller allows the user to log in from this host; if any of the above information is incorrect, the domain controller rejects the user from logging in from this host.
[0049] In the scenario where the file storage device provides a file sharing service, it is necessary to first authenticate the host and the user through the domain controller before the file storage device can provide the user with access rights to the shared files. For example, the host first sends the user information to the file storage device. After the file storage device establishes a connection with the domain controller, it sends the user information to the domain controller for authentication. After the domain controller returns an authentication pass to the file storage device, the file storage device can provide the user with the permission to access the file. However, the aforementioned authentication method depends on the domain controller. When an exception occurs on the domain controller side (such as a network exception on the domain controller side, or an update of the security policy on the domain controller side, etc.), it may cause the host to be unable to authenticate on the domain controller side, and further cause the host to be unable to access the shared files in the file storage device.
[0050] In response to this, this application provides an authentication method and a file storage device for providing an authentication service to users when an exception occurs on the domain controller side, and reducing the probability that users are affected from accessing the shared files in the file storage device due to being unable to authenticate on the domain controller side.
[0051] The following combines Figure 2 to introduce the main process of the authentication method provided by this application. As Figure 2 shown, the file storage device mainly performs the following steps:
[0052] Step 201, the file storage device receives a first authentication request from the host.
[0053] The first authentication request is used to apply for authenticating a first user.
[0054] The first authentication request includes first information of the first user, and the first user is a user who applies for domain authentication through the host. Optionally, the first information of the first user includes the user account of the first user (hereinafter simply referred to as the account of the first user). In some examples, the user account is also referred to as the user name. In other examples, the user account is a combination of the domain control name and the user name. The present application does not limit the implementation form of the user account.
[0055] Optionally, in addition to including the account of the first user, the first information of the first user further includes the address of the host, that is, the address of the host on which the account of the first user is currently logged in, that is, the address of the host that currently sends the first authentication request. Exemplarily, the address of the host may be the internet protocol address (IP) address of the host. In the NTLM authentication process, the host that sends the first authentication request acts as the client, and the file storage device that receives the first authentication request acts as the server. Therefore, the IP address of the host is also referred to as the IP address of the client.
[0056] After the file storage device receives the first authentication request, the file storage device attempts to establish a connection between the file storage device and the corresponding domain controller. When the domain controller corresponding to the file storage device is abnormal, the file storage device will not be able to successfully establish a connection with the domain controller. At this time, the file storage device will execute step 202.
[0057] It should be understood that there is a domain controller corresponding to the file storage device in the present application. The abnormality of the domain controller corresponding to the file storage device may be a network abnormality between the file storage device and the domain controller, or a physical port abnormality of the domain controller, or a software configuration abnormality or change of the domain controller (for example, the domain controller updates the security policy). The present application does not limit the reason for the abnormality of the domain controller.
[0058] Step 202, when the domain controller corresponding to the file storage device is abnormal, the file storage device authenticates the first user based on the first information of the first user and the second information of the first user stored in the file storage device, and obtains the authentication result of the first user.
[0059] The first information of the first user is obtained by the file storage device from the first authentication request received from the host. For the introduction of the first information of the first user, please refer to step 201 above, which will not be elaborated here.
[0060] Among them, the second information of the first user is the information stored by the file storage device before step 201. Specifically, the second information of the first user is the information of the first user who was successfully authenticated by the domain controller before the domain controller malfunctioned. For example, before the domain controller malfunctioned, the file storage device received an authentication request from the first user. The file storage device established a connection with the domain controller and forwarded the authentication request of the first user to the domain controller so that the domain controller could authenticate the first user. If the domain controller successfully authenticated the first user, the domain controller would return the second information of the first user to the file storage device. Then, the file storage device stored the second information of the first user so that the file storage device could authenticate the first user based on the second information of the first user when the domain controller malfunctioned.
[0061] It should be understood that before the domain controller malfunctioned, there might be at least one user who was successfully authenticated by the domain controller through the file storage device, and the file storage device stored the information of at least one user. For the convenience of introduction, the information of at least one user stored by the file storage device before the domain controller malfunctioned will be referred to as the information of historical users hereinafter. Optionally, the information of historical users includes the second information of the first user.
[0062] Among them, the information of historical users includes the accounts of historical users. Optionally, the information of historical users further includes the address of the host that logged in to the account of the historical user when the authentication by the domain controller was successful.
[0063] Exemplarily, taking the information of historical users including the accounts of historical users and the addresses of the hosts that logged in to the accounts of historical users when the authentication by the domain controller was successful as an example, the information of historical users can be as shown in Table 1 below:
[0064] Table 1
[0065] Address of the host Account of the historical user Address of Host 1 Account of User 1 Address of Host 2 Account of User 2 … …
[0066] Taking the first row of Table 1 as an example, it means that before the domain controller malfunctioned, the account of User 1 applied to the file storage device for authentication through Host 1, that is, the account of User 1 applied to log in through Host 1. The file storage device forwarded the information of User 1 (including the account of User 1) to the domain controller for NTLM authentication. After the domain controller returned successful authentication to the file storage device, the file storage device stored the address of Host 1 corresponding to the account of User 1. The other rows of Table 1 are similar and will not be elaborated here.
[0067] Specifically, after the file storage device receives the first authentication request, if the file storage device does not store the second information of the first user, the authentication of the first user fails; if the file storage device stores the second information of the first user, the file storage device determines the authentication result of the first user by comparing the first information of the first user obtained from the first authentication request with the second information of the first user stored in the file storage device. In one example, if the first information of the first user is consistent with the second information of the first user, the file storage device determines that the authentication of the first user is successful. In another example, if the first information of the first user is inconsistent with the second information of the first user, the file storage device determines that the authentication of the first user fails.
[0068] In a possible implementation manner, the second information of the first user includes the account number of the first user. Specifically, the file storage device determines the authentication result of the first user by comparing the account number of the first user obtained from the first authentication request with the account number of the first user stored in the file storage device. If the account number of the first user obtained from the first authentication request is the same as the account number of the first user stored in the file storage device, the file storage device determines that the authentication result of the first user is that the authentication of the first user is successful. If the account number of the first user obtained from the first authentication request is different from the account number of the first user stored in the file storage device, the file storage device determines that the authentication result of the first user is that the authentication of the first user fails.
[0069] Exemplarily, if the account number of the first user in the first authentication request is "abcd", and the account number of the first user stored in the file storage device is "abcd", the file storage device determines that the authentication of the first user is successful. If the account number of the first user in the first authentication request is "abcd", however, the account number "abcd" is not stored in the file storage device, the file storage device determines that the authentication of the first user fails.
[0070] In this implementation manner, the file storage device can use the account number of the first user that has been stored to authenticate the first user instead of the domain controller, which is beneficial to ensuring the continuity of the user authentication process. In addition, since the file storage device only compares the account number of the first user and does not need to compare the information of the host, this implementation manner is applicable to scenarios where the account is not required to be bound to the host (i.e., the host where the account logs in). For example, before the domain controller is abnormal, the account "abcd" successfully logs in on host 1; after the domain controller is abnormal, the account "abcd" can try to log in again through host 1 or try to log in on other hosts. This is beneficial to improving the flexibility of user authentication.
[0071] In another possible implementation, the second information of the first user includes, in addition to the account of the first user, the address of the host, that is, the address of the host that logs in to the account of the first user. Specifically, the file storage device determines the authentication result of the first user by comparing the account and host address of the first user obtained from the first authentication request with the account and host address of the first user stored in the file storage device. If the account of the first user obtained from the first authentication request is the same as the account of the first user stored in the file storage device, and the host address obtained from the first authentication request is the same as the host address stored in the file storage device, the file storage device determines that the authentication result of the first user is that the first user authentication is successful. If the account of the first user obtained from the first authentication request is different from the account of the first user stored in the file storage device, or the host address obtained from the first authentication request is different from the host address stored in the file storage device, the file storage device determines that the authentication result of the first user is that the first user authentication fails.
[0072] Exemplarily, if the account of the first user in the first authentication request is "abcd", the host address attempting to log in to the account "abcd" is "IP1", and the account of the first user stored in the file storage device is "abcd", and the host address corresponding to the account "abcd" is "IP1", the file storage device determines that the first user authentication is successful. If the account of the first user in the first authentication request is "abcd", however, the account of the first user stored in the file storage device is "abcd", and the host address corresponding to the account "abcd" is not "IP1", the file storage device determines that the first user authentication fails.
[0073] In this implementation, the file storage device can use the stored account and host address of the first user to authenticate the first user instead of the domain controller, which helps to ensure the continuity of the user authentication process. In addition, since the file storage device compares the address and host address of the first user, this implementation is applicable to scenarios where the user account needs to be bound to the host (i.e., the host that logs in to the account), that is, the account of the first user can only be logged in on the specified host. For example, before the domain controller fails, the account "abcd" successfully logs in on host 1; after the domain controller fails, the account "abcd" can only be successfully authenticated if it attempts to log in again through host 1. After the domain controller fails, if the account "abcd" attempts to log in through other hosts, even if the user account and password are the same, the authentication will not be successful. This helps to improve the security of user authentication through the file storage device.
[0074] Step 203, the file storage device sends a first authentication response to the host.
[0075] Among them, the first authentication response includes the authentication result of the first user, and the authentication result of the first user is used to indicate that the authentication of the first user is successful or the authentication of the first user fails.
[0076] In this embodiment, the file storage device stores the second information of the first user, that is, the information of the first user who has been successfully authenticated by the domain controller before the domain controller fails. When the domain controller fails, the file storage device can use the stored second information of the first user to authenticate the first information of the first user obtained from the first authentication request, that is, the file storage device can use the information of the user who has been successfully authenticated historically to authenticate the user applying for authentication instead of the domain controller. Therefore, when the domain controller fails, the file storage device will not interrupt the authentication process, which is beneficial to ensuring the continuity of the user's authentication process, and further reducing the probability that the user cannot access the shared files in the file storage device due to the inability to authenticate on the domain controller side.
[0077] Next, in combination with Figure 3 the authentication method provided by this application will be further introduced. As Figure 3 shown, the file storage device and the host mainly perform the following steps:
[0078] Step 301, the host sends a first negotiation request to the file storage device; correspondingly, the file storage device receives the first negotiation request from the host.
[0079] Among them, the first negotiation request is used to negotiate the authentication information used in the authentication process. Since the host is not aware of whether the domain controller fails, the host sends the first negotiation request to negotiate the authentication information used when authenticating on the domain controller. This first negotiation request is similar to the authentication request in the first stage of the NTLM network authentication (also known as NTLM authentication in the domain environment) process.
[0080] Among them, the first negotiation request includes the authentication methods supported by the host. The authentication methods supported by the host can also be understood as the authentication algorithms supported by the host. Exemplarily, the authentication algorithms supported by the host include the data encryption standard (DES) algorithm, the HMAC-MD5 algorithm, or other algorithms, which are not limited in this application.
[0081] After receiving the first negotiation request, the file storage device attempts to establish a connection with the domain controller. If the file storage device detects a domain controller failure, or the file storage device fails to establish a connection with the domain controller, the file storage device executes step 302.
[0082] Step 302, the file storage device enables the function of authenticating users by acting as a proxy domain controller.
[0083] It should be noted that the file storage device can enable the foregoing function based on pre-configuration or based on the user's instruction. The following are examples for introduction respectively:
[0084] In a possible implementation manner, the file storage device receives first configuration information before step 301. The first configuration information is used to instruct the file storage device to enable the function of authenticating users by the proxy domain controller when the domain controller corresponding to the file storage device is abnormal. After receiving the first configuration information, if the file storage device receives a negotiation request (for example, the first negotiation request), and the file storage device determines that the domain controller is abnormal, the file storage device enables the function of authenticating users by the proxy domain controller.
[0085] In another possible implementation manner, when it is determined that the domain controller corresponding to the file storage device is abnormal, the file storage device sends an alarm message and a prompt message. For example, the file storage device displays the alarm message and the prompt message to the user through an output device such as a display device; or the file storage device sends the alarm message and the prompt message to the host, and the host displays the alarm message and the prompt message to the user through an output device such as a display device. Among them, the alarm message is used to indicate that the domain controller corresponding to the file storage device is abnormal, and the prompt message is used to prompt the user whether to enable the function of authenticating users by the proxy domain controller. If the file storage device receives the first indication information fed back by the user, and the first indication information is used to instruct the file storage device to enable the function of authenticating users by the proxy domain controller, the file storage device enables the function of authenticating users by the proxy domain controller.
[0086] Exemplarily, enabling the function of authenticating users by the proxy domain controller includes at least one of the following:
[0087] The file storage device processes the first negotiation request (for example, step 304) from the host on behalf of the domain controller;
[0088] The file storage device returns the processing result of the first negotiation request (i.e., the first negotiation response) to the host on behalf of the domain controller (for example, step 305);
[0089] The file storage device processes the first authentication request (for example, step 307) from the host on behalf of the domain controller;
[0090] The file storage device returns the processing result of the first authentication request (i.e., the first authentication response) to the host on behalf of the domain controller (for example, step 309);
[0091] The file storage device queries the index of the access permission of the first user on behalf of the domain controller (for example, step 312).
[0092] Step 303, the file storage device starts the first timer.
[0093] For example, while the file storage device enables the function of the proxy domain controller to authenticate users, the file storage device starts the first timer. Among them, the duration of the first timer is the duration for which the file storage device's proxy domain controller authenticates users. When the first timer times out, the file storage device will disable the function of the proxy domain controller to authenticate users. For details, please refer to step 310 later.
[0094] Optionally, the duration of the first timer is a pre-configured duration. In one example, the duration of the first timer is related to the duration of the abnormal recovery of the domain controller. In another example, the duration of the first timer is related to the duration used by the file storage device for the first user authentication. For example, the duration of the first timer is greater than or equal to the duration used by the file storage device for the first user authentication. This application does not limit the duration of the first timer. By configuring the first timer, the file storage device is beneficial to timely disable the function of the proxy domain controller to authenticate users and improve the security of network authentication.
[0095] Optionally, while the file storage device enables the function of the proxy domain controller to authenticate users, the file storage device also generates first identification information, which is used to indicate that the file storage device enables the function of the proxy domain controller to authenticate users. The first identification information generated by the file storage device can be displayed to the user through the user interaction interface provided by the display device of the file storage device to prompt the user that the function of the proxy domain controller to authenticate users has been enabled, thereby improving the user experience of the user authenticating through the file storage device.
[0096] It should be understood that in this embodiment, step 303 is an optional step. When the file storage device does not execute step 303, the file storage device can disable the function of the proxy domain controller to authenticate users through other means.
[0097] Step 304, the file storage device determines the first authentication information based on the first negotiation request.
[0098] Among them, the first authentication information includes the authentication algorithm determined by the file storage device from the authentication algorithms supported by the host, and the random number determined by the file storage device. This first authentication information is used by the host to encrypt the account password of the first user to be sent.
[0099] Among them, the first negotiation request provides at least one authentication algorithm supported by the host. The file storage device selects one algorithm from the foregoing at least one authentication algorithm supported by the host for authenticating the user logging in through the host. It should be understood that the algorithm selected by the file storage device is also an algorithm supported by the file storage device. For example, if the first negotiation request indicates that the host supports Algorithm 1, Algorithm 2, and Algorithm 3, and the file storage device supports Algorithm 3, the file storage device can determine Algorithm 3 as the algorithm for subsequently authenticating the user logging in through the host.
[0100] It should be understood that in the traditional technology, if the domain controller connected to the storage device does not fail, the file storage device forwards the negotiation request from the host to the domain controller. After the domain controller determines the authentication information used by the host based on the negotiation request, it is then forwarded to the host through the file storage device. Thus, in this application, the file storage device executes steps 304 and 305, that is, the file storage device generates the first authentication information instead of the domain controller and returns the first authentication information to the host. This helps to avoid the authentication process being interrupted due to the host not receiving the first authentication information.
[0101] Step 305, the file storage device sends a first negotiation response to the host; correspondingly, the host receives the first negotiation response from the file storage device.
[0102] Among them, the first negotiation response includes the first authentication information determined by the file storage device based on the first negotiation request.
[0103] Step 306, the host encrypts the account password of the first user based on the first authentication information to obtain a first ciphertext.
[0104] Among them, the first ciphertext refers to the ciphertext obtained by encrypting the account password of the first user.
[0105] Optionally, the host encrypts the account password of the first user based on the first authentication information and the random number generated by the host to obtain a first ciphertext. Exemplarily, if the first authentication information obtained by the host from the first negotiation response includes Algorithm 3 and random number 1, and the host generates random number 2, then the host encrypts the account password of the first user based on Algorithm 3, random number 1, and random number 2 to generate ciphertext 1.
[0106] In this embodiment, since the host is not aware of whether the domain controller fails and the file storage device has replaced the domain controller to return the first authentication information to the host, the host generates the first ciphertext for identity verification according to the process in the traditional technology and sends the first ciphertext through the subsequent first authentication request. This embodiment does not require modifying the behavior of the host, reducing the difficulty of implementing the solution.
[0107] Step 307: The host sends a first authentication request to the file storage device; accordingly, the file storage device receives the first authentication request from the host.
[0108] The first authentication request includes the first information of the first user who applies for authentication through the host. The first information of the first user includes the account of the first user. Optionally, the first information of the first user includes the address of the host. For an explanation of the first information of the first user, please refer to the above text. Figure 2 The relevant introduction in step 201 of the corresponding embodiment will not be repeated here.
[0109] In addition, the first authentication request also includes a first ciphertext. Optionally, the first authentication request also includes a random number generated by the host.
[0110] Exemplarily, if the first authentication information obtained by the host from the first negotiation response includes algorithm 3 and random number 1, and the host generates random number 2, then the host encrypts the account password of the first user based on algorithm 3, random number 1 and random number 2 to generate ciphertext 1, and the first authentication request includes random number 2, ciphertext 1, the user account of the first user and the address of the host. After the file storage device receives the first authentication request, the file storage device can obtain the user account of the first user and the address of the host from the first authentication request. Since the process of the file storage device authenticating the first user does not use other information (for example, random number 2 and ciphertext 1, etc.) except the account of the first user and the address of the host, the file storage device can ignore other information in the first authentication request (for example, random number 2 and ciphertext 1, etc.).
[0111] It should be understood that even if the file storage device does not use the random number and the first ciphertext generated by the host, the host sends the random number and the first ciphertext generated by the host to the file storage device in order to complete the authentication of the host and the first user without modifying the behavior of the host, thereby reducing the difficulty of implementing the solution.
[0112] Step 308: The file storage device authenticates the first user based on the first information of the first user in the first authentication request and the second information of the first user stored in the file storage device to obtain an authentication result of the first user.
[0113] In a possible implementation, the second information of the first user includes an account number of the first user. Specifically, the file storage device determines the authentication result of the first user by comparing the account number of the first user obtained from the first authentication request with the account number of the first user stored in the file storage device.
[0114] In another possible implementation, the second information of the first user includes not only the account of the first user but also the address of the host, that is, the address of the host that logs in to the account of the first user. Specifically, the file storage device determines the authentication result of the first user by comparing the account and host address of the first user obtained from the first authentication request with the account and host address of the first user stored in the file storage device.
[0115] For the detailed introduction and examples of the above two implementations, please refer to step 202 in the previous text, which will not be elaborated here.
[0116] Step 309, the file storage device sends a first authentication response to the host; correspondingly, the host receives the first authentication response from the file storage device.
[0117] Among them, the first authentication response includes the authentication result of the first user.
[0118] Step 310, the file storage device closes the function of the proxy domain controller for user authentication.
[0119] In one example, when the first timer times out, the file storage device closes the function of the proxy domain controller for user authentication.
[0120] In another example, when the file storage device determines that the corresponding domain controller returns to normal, the first timer is stopped, and the function of the proxy domain controller for user authentication is closed.
[0121] In another example, after the file storage device completes the authentication of the first user, the file storage device closes the proxy function.
[0122] In this step, the file storage device can close the function of the proxy domain controller for user authentication at a certain time, which is beneficial to improving the security of network authentication.
[0123] Optionally, when the first timer times out or when the first timer stops, the file storage device deletes the first identification information. This is beneficial to saving the storage resources of the file storage device.
[0124] It should be understood that steps 311 to 314 are optional steps. If the file storage device successfully authenticates the first user, the file storage device will also execute steps 311 to 314.
[0125] Step 311, the host sends a file access request to the file storage device; correspondingly, the file storage device receives the file access request from the host.
[0126] Exemplarily, the file access request can be a read operation instruction or a write operation instruction, which is not limited in this application.
[0127] Step 312, the file storage device determines an index of the access permission of the first user based on the first information of the first user.
[0128] In this embodiment, the second information of the first user stored in the file storage device further includes an index of the access permission of the first user. Optionally, the information of the index of the access permission includes security identifiers (SID), and the SID is used to uniquely identify a user. Optionally, the information of the index of the access permission further includes group identifiers (GID), and the GID is used to indicate the user group where the user is located.
[0129] It should be understood that the index of the access permission of the first user is the information returned by the domain controller to the file storage device for uniquely identifying the first user when the first user successfully authenticates on the domain controller before the domain controller fails.
[0130] It should be understood that before the domain controller fails, there may be at least one user who successfully authenticates on the domain controller through the file storage device, and the file storage device stores the information of at least one user (i.e., the information of historical users). Optionally, the information of historical users includes an index of the access permission of historical users.
[0131] Exemplarily, when the information of historical users includes an index of the access permission, the information of historical users can be as shown in Table 2 below:
[0132] Table 2
[0133] Address of the host Account of the historical user Index of the access rights of the historical user Address of Host 1 Account of User 1 SID1, GID1 Address of Host 2 Account of User 2 SID2, GID2 … … …
[0134] Taking the first row of Table 2 as an example, it means that before the domain controller fails, the account of User 1 applies for authentication to the file storage device through Host 1, that is, the account of User 1 applies for login on Host 1. The file storage device forwards the information of User 1 (including the account of User 1) to the domain controller for NTLM authentication. After the domain controller returns successful authentication to the file storage device, the file storage device obtains the index of the access permission of User 1 (i.e., SID1 and GID1) from the domain controller, and then the file storage device stores the address of Host 1, the account of User 1, and the index of the access permission of User 1 (i.e., SID1 and GID1) in a corresponding manner. The other rows of Table 2 are similar and will not be elaborated here.
[0135] When the file storage device receives a file access request from the host, since the file storage device has successfully authenticated the first user, the file storage device can find the index of the access permission of the first user in the second information of the first user stored in the file storage device based on the first information of the first user.
[0136] Step 313: The file storage device determines the access right of the first user based on the index of the access right of the first user.
[0137] In this embodiment, the file storage device stores the correspondence between the index of the access right of the first user and the access right information of the first user. After determining the index of the access right of the first user, the file storage device can determine the access right of the first user based on the index of the access right of the first user.
[0138] It should be understood that in the traditional technology, the index of the access right of the first user is stored in the domain controller. Only after the first user applying for authentication through the host is successfully authenticated in the domain controller, the domain controller will return the index of the access right of the first user to the file storage device. Then, when the file storage device can receive the file access request of the first user, it can determine whether the first user has the access right to a certain file based on the index of the access right of the first user. In this embodiment, the file storage device stores the index of the access right of the first user before the domain controller fails. After the file storage device successfully authenticates the first user instead of the domain controller, the file storage device does not need to obtain the index of the access right of the first user from the domain controller, but searches for the index of the access right of the first user stored by itself based on the second information of the first user, and then determines the access right of the first user. Therefore, it is beneficial to ensure the continuity of the service for users to access shared files.
[0139] Step 314: The file storage device sends a file access response to the host; correspondingly, the host receives the file access response from the file storage device.
[0140] Among them, the file access response includes the processing result of a read operation instruction or a write operation instruction. Taking the read operation instruction as an example, the file storage device sends the shared file requested to be read by the read operation instruction to the host.
[0141] In this embodiment, the file storage device stores the second information of the first user, that is, the account, host address, and index of the access permission of the first user who has been successfully authenticated by the domain controller before the domain controller fails. When the domain controller fails, the file storage device can use the stored second information of the first user to authenticate the first information of the first user obtained from the first authentication request, that is, the file storage device can use the information of the user who has been successfully authenticated historically to authenticate the user applying for authentication instead of the domain controller. Therefore, it is beneficial to ensure the continuity of the user authentication process, and further reduce the probability that the user is affected from accessing the shared files in the file storage device due to the inability to authenticate on the domain controller side. In addition, the file storage device can also find the index of the access permission of the first user from the stored second information of the first user based on the first information of the first user, and then determine the access permission of the first user. Therefore, it is beneficial to ensure the continuity of the service for the user to access the shared files.
[0142] The following combines Figure 4 to introduce the authentication process of the user on the domain controller. As Figure 4 shown, after the domain controller is restored, or before the domain controller fails, the user performs authentication through the Figure 4 process shown, and the file storage device can store the information of the successfully authenticated user (that is, the information of the historical user), so that the file storage device can use the information of the historical user (including the second information of the first user, etc.) to adopt the Figure 2 or Figure 3 way provided by the corresponding embodiment to authenticate the first user. In this embodiment, the authentication of the second user is taken as an example for introduction. It should be understood that the second user in this embodiment and the first user in the foregoing embodiment may be the same user or different users, which is not limited herein. In this embodiment, the host, file storage device, and domain controller mainly perform the following steps:
[0143] Step 401, the host sends a second negotiation request to the file storage device; correspondingly, the file storage device receives the second negotiation request from the host.
[0144] Among them, the second negotiation request includes the authentication method supported by the host. The authentication method supported by the host can also be understood as the authentication algorithm supported by the host. This second negotiation request is similar to the first negotiation request in step 301 above. For the specific introduction of the first negotiation request, please refer to the introduction of the first negotiation request in step 301 above, and it will not be elaborated here.
[0145] After the file storage device receives the second negotiation request, the file storage device attempts to establish a connection with the domain controller. If the file storage device successfully establishes a connection with the domain controller, the file storage device executes step 402.
[0146] Step 402: The file storage device sends a second negotiation request to the domain controller; correspondingly, the domain controller receives the second negotiation request from the file storage device.
[0147] Since the file storage device can establish a connection with the domain controller, that is, the domain controller corresponding to the file storage device is working properly, the file storage device forwards the second negotiation request to the domain controller for processing.
[0148] Step 403: The domain controller determines second authentication information based on the second negotiation request.
[0149] The second authentication information includes the authentication algorithm determined by the domain controller from the authentication algorithms supported by the host, and the random number determined by the file storage device.
[0150] The second negotiation request provides at least one authentication algorithm supported by the host. The domain controller selects one algorithm from the aforementioned at least one authentication algorithm supported by the host for authenticating the user logging in through the host. It should be understood that the algorithm selected by the domain controller is also an algorithm supported by the domain controller. For example, if the second negotiation request indicates that the host supports algorithm 1, algorithm 2, and algorithm 3, and the domain controller supports algorithm 2, then the domain controller can determine algorithm 2 as the algorithm for subsequent authentication of the user logging in through the host.
[0151] Step 404: The domain controller sends a second negotiation response to the file storage device; correspondingly, the file storage device receives the second negotiation response from the domain controller.
[0152] The second negotiation response includes the second authentication information determined by the domain controller based on the second negotiation request.
[0153] Step 405: The file storage device sends the second negotiation response to the host; correspondingly, the host receives the second negotiation response from the file storage device.
[0154] Step 406: The host encrypts the account password of the second user based on the second authentication information to obtain a second ciphertext.
[0155] The second ciphertext refers to the ciphertext obtained by encrypting the account password of the second user.
[0156] Optionally, the host encrypts the account password of the second user based on the second authentication information and the random number generated by the host to obtain a second ciphertext. Exemplarily, if the second authentication information obtained by the host from the second negotiation response includes algorithm 2 and random number 3, and the host generates random number 4, then the host encrypts the account password of the second user based on algorithm 2, random number 3, and random number 4 to generate ciphertext 3. In this example, ciphertext 3 is the second ciphertext.
[0157] Step 407: The host sends a second authentication request to the file storage device; correspondingly, the file storage device receives the second authentication request from the host.
[0158] Among them, the second authentication request includes information of a second user applying for authentication through the host. The information of the second user includes the user account of the second user and the account password of the second user. Among them, the account password of the second user is carried in the second authentication request in the form of a second ciphertext.
[0159] In addition, the information of the second user also includes the address of the host, that is, the address of the host sending the second authentication request.
[0160] In addition, the second authentication request also includes a random number generated by the host.
[0161] Exemplarily, if the second authentication information obtained by the host from the second negotiation response includes algorithm 2 and random number 3, and the host generates random number 4, then the host encrypts the account password of the second user based on algorithm 2, random number 3 and random number 4 to generate ciphertext 3. Then the second authentication request includes random number 4, ciphertext 3, the user account of the second user and the address of the host. In this example, ciphertext 3 is the second ciphertext.
[0162] Step 408: The file storage device sends the second authentication request to the domain controller; correspondingly, the domain controller receives the second authentication request from the file storage device.
[0163] Step 409: The domain controller authenticates the second user based on the second ciphertext in the second authentication request and a third ciphertext generated by the domain controller, and obtains the authentication result of the second user.
[0164] Among them, the third ciphertext is determined by the domain controller based on the second authentication information, the account password of the second user and the random number generated by the host. Specifically, the database of the domain controller stores the user account and account password of the second user, and the domain controller can find the account password of the second user based on the user account of the second user in the second authentication request. Then, the domain controller determines the third ciphertext based on the second authentication information, the found account password of the second user and the random number generated by the host in the second authentication request. For example, the second authentication information determined by the domain controller includes algorithm 2 and random number 3, and random number 4 is carried in the second authentication request. Then the domain controller encrypts the account password of the second user based on algorithm 2, random number 3 and random number 4 to generate ciphertext 4. In this example, ciphertext 4 is the third ciphertext.
[0165] Then, the domain controller compares the second ciphertext obtained from the second authentication request with the third ciphertext generated by the domain controller. If the second ciphertext is the same as the third ciphertext, the domain controller determines that the second user authentication is successful; if the second ciphertext is different from the third ciphertext, the domain controller determines that the second user authentication fails.
[0166] Step 410, the domain controller sends a second authentication response to the file storage device; correspondingly, the file storage device receives the second authentication response from the domain controller.
[0167] Among them, the second authentication response includes the authentication result of the second user. The authentication result of the second user may be authentication success or authentication failure.
[0168] In one example, if the authentication result of the second user is authentication success, the second authentication response further includes an index of the access rights of the second user. Optionally, the information of the index of the access rights includes security identifiers (SID). Optionally, the information of the index of the access rights further includes group identifiers (GID).
[0169] In another example, if the authentication result of the second user is authentication failure, the second authentication response does not include an index of the access rights of the second user.
[0170] Step 411, the file storage device sends the second authentication response to the host; correspondingly, the host receives the second authentication response from the file storage device.
[0171] Among them, the second authentication response includes the authentication result of the second user. The authentication result of the second user may be authentication success or authentication failure.
[0172] It should be understood that steps 412 to 415 are optional steps. If the domain controller determines that the second user authentication is successful, that is, the second authentication response indicates that the second user authentication is successful, the file storage device will further execute steps 412 to 415. If the domain controller determines that the second user authentication fails, that is, the second authentication response indicates that the second user authentication fails, the file storage device does not execute steps 412 to 415.
[0173] Step 412, the file storage device persistently stores the information of the second user.
[0174] Among them, the information of the second user at least includes the account of the second user and the index of the access rights of the second user. Optionally, the information of the second user further includes the address of the host.
[0175] Specifically, if the second authentication response received by the file storage device indicates that the second user authentication is successful, and the second authentication response includes the index of the access rights of the second user, the file storage device stores the index of the access rights of the second user in the second authentication response corresponding to the information of the second user in the file storage device. For example, the file storage device stores the index of the access rights of the second user, the account number of the second user, and the address of the host in the file storage device. For specific examples, please refer to Table 2 above, which will not be elaborated here.
[0176] It should be noted that the file storage device stores the information of the second user in a non-volatile memory (NVM). Exemplarily, the non-volatile memory can be a read-only memory (ROM), such as a programmable read-only memory (PROM), an electrically alterable read-only memory (EAROM), an erasable programmable read-only memory (EPROM), or an electrically erasable programmable read-only memory (EEPROM). In addition, the non-volatile memory can also be a flash memory or other devices.
[0177] Step 413, the host sends a file access request to the file storage device; correspondingly, the file storage device receives the file access request from the host.
[0178] Exemplarily, the file access request can be a read operation instruction or a write operation instruction, which is not limited in this application.
[0179] Step 414, the file storage device determines the access rights of the second user based on the index of the access rights of the second user.
[0180] Step 415, the file storage device sends a file access response to the host; correspondingly, the host receives the file access response from the file storage device.
[0181] In this embodiment, the file storage device can store the information of the user who has been successfully authenticated in the domain controller in the non-volatile memory. This is beneficial for the file storage device to authenticate the user applying for authentication using the stored user information when the domain controller is abnormal. Therefore, it is beneficial to ensure the continuity of the user authentication process.
[0182] Corresponding to the scheme given in the above method embodiment, the embodiment of the present application also provides a corresponding file storage device, which includes a module or unit for executing each part of the above embodiment. The module or unit can be software, hardware, or a combination of software and hardware. The following is only a brief description of the file storage device. For the implementation details of the scheme, reference can be made to the description of the above method embodiment, which will not be repeated below.
[0183] like Figure 5 FIG. 5 is a schematic diagram of the structure of a file storage device 50 provided in an embodiment of the present application. Figure 2 , Figure 3 or Figure 4 The file storage device in the corresponding method embodiment can be based on the Figure 5 The structure of the file storage device 50 is shown. Figure 5 As shown, the file storage device 50 may include a processor 501. In addition, the file storage device 50 may also include a memory 503 and a communication interface 502. The processor 501 is coupled to the memory 503, and the processor 501 is coupled to the communication interface 502.
[0184] The aforementioned communication interface 502 is connected to other devices through a communication link. For example, the communication interface 502 may include an interface between the file storage device 50 and the host, and the file storage device 50 establishes a connection with at least two hosts in the host group through the communication interface 502. For another example, the communication interface 502 may include an interface between the file storage device 50 and a switch, and the file storage device 50 is connected to the switch through the communication interface 502, and the switch establishes a connection with at least two hosts in the host group. For example, the communication interface 502 may be an interface between the file storage device 50 and a network switch, which is not limited in this application.
[0185] Among them, the aforementioned processor 501 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The aforementioned PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 501 may refer to a single processor or may include multiple processors, and specific details are not limited herein.
[0186] In addition, the aforementioned memory 503 is mainly used to store software programs and data. The memory 503 may exist independently and be connected to the processor 501. Optionally, the memory 503 may be integrated with the processor 501, for example, integrated within one or more chips. Among them, the memory 503 can store the program code for implementing the technical solution of this embodiment of the present application and is controlled by the processor 501 for execution. Various computer program codes being executed can also be regarded as the driver programs of the processor 501. The memory 503 may include volatile memory, such as random-access memory (RAM); the memory may also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); the memory 503 may also include a combination of the above types of memory. The memory 503 may refer to a single memory or may include multiple memories. Exemplarily, the memory 503 is used to store the second information of the first user in the non-volatile storage medium of the memory 503. Among them, the second information of the first user includes the account number of the first user. Optionally, the second information of the first user further includes the address of the host that logs in to the account of the first user during authentication by the domain controller. Optionally, the second information of the first user further includes an index of the access rights of the first user, and the index of the access rights of the first user is used to determine the access rights of the first user on the file storage device. Exemplarily, the index of the access rights of the first user includes SID and GID.
[0187] In addition, the processor 501 invokes a program in the memory 503 to enable the file storage device 50 to implement the following functions:
[0188] In one design, the file storage device 50 is used to execute the method of the file storage device in the foregoing Figure 2 or Figure 3 corresponding embodiment. Among them, the communication interface 502 is used to receive a first authentication request from the host. The first authentication request includes first information of a first user, and the first user is a user who applies for domain authentication through the host; the processor 501 is used to, when the domain controller corresponding to the file storage device is abnormal, authenticate the first user based on the first information of the first user and second information of the first user stored in the file storage device, and obtain an authentication result of the first user. The second information is the information obtained when the first user successfully passes the domain controller authentication; in addition, the communication interface 502 is further used to send a first authentication response to the host, and the first authentication response includes the authentication result of the first user.
[0189] In a possible implementation manner, when the first user is successfully authenticated by the domain controller, the memory 503 is used to store the second information of the first user.
[0190] In a possible implementation manner, the processor 501 is specifically used to determine that the first user is successfully authenticated when it is determined that the first information of the first user is consistent with the second information of the first user.
[0191] Optionally, the first information of the first user includes the account number of the first user, and the second information of the first user includes the account number of the first user.
[0192] Optionally, the first information of the first user further includes the address of the host that logs in to the account of the first user, and the second information of the first user further includes the address of the host that logs in to the account of the first user when authenticating through the domain controller.
[0193] Optionally, the second information of the first user further includes an index of the access permission of the first user, and the index of the access permission of the first user is used to determine the access permission of the first user on the file storage device.
[0194] In a possible implementation manner, the processor 501 is used to determine the index of the access permission of the first user based on the account number of the first user.
[0195] In a possible implementation, the communication interface 502 is used to receive a first negotiation request from the host, and the first negotiation request includes the authentication methods supported by the host; the processor 501 is used to determine a first negotiation response based on the first negotiation request in the case where the domain controller corresponding to the file storage device is abnormal; the communication interface 502 is used to send the first negotiation response to the host, and the first negotiation response includes first authentication information determined by the file storage device based on the first negotiation request, and the first authentication information is used for the host to encrypt the account password of the first user.
[0196] In a possible implementation, when it is determined that the domain controller corresponding to the file storage device is abnormal, the processor 501 is further used to enable the function of authenticating users by the proxy domain controller, and start a first timer, and the duration of the first timer is the duration for which the file storage device authenticates users by the proxy domain controller; and when the first timer times out, the processor 501 is further used to disable the function of authenticating users by the proxy domain controller.
[0197] In a possible implementation, when it is determined that the domain controller corresponding to the file storage device returns to normal, the processor 501 is further used to stop the first timer and disable the function of authenticating users by the proxy domain controller.
[0198] In a possible implementation, the communication interface 502 is further used to receive a second authentication request from the host, and the second authentication request includes information of a second user, and the second user is a user who applies for domain authentication through the host; and the communication interface 502 is further used to send the second authentication request to the domain controller; and the communication interface 502 is further used to receive a second authentication response from the domain controller, and the second authentication response includes the authentication result of the second user and the information of the second user, and the information of the second user includes an index of the access permission of the second user.
[0199] In a possible implementation, the communication interface 502 is further used to receive first configuration information, and the first configuration information is used to instruct the file storage device to enable the function of authenticating users by the proxy domain controller when the domain controller corresponding to the file storage device is abnormal.
[0200] In a possible implementation, when it is determined that the domain controller corresponding to the file storage device is abnormal, the communication interface 502 is further used to send an alarm message and a prompt message, the alarm message is used to indicate that the domain controller corresponding to the file storage device is abnormal, and the prompt message is used to prompt the user whether to enable the function of authenticating users by the proxy domain controller; the communication interface 502 is further used to receive first indication information, and the first indication information is used to instruct the file storage device to enable the function of authenticating users by the proxy domain controller.
[0201] It should be noted that for the specific implementation manners and beneficial effects of this embodiment, reference may be made to the method of the file storage device in the foregoing embodiment, which will not be elaborated herein.
[0202] As Figure 6 shown, the present application also provides a file storage device 60. The file storage device 60 may be a network storage management server separated from a storage device (for example, a physical storage array such as a disk array), or may be a network storage device integrated with a storage device. The file storage device 60 may also be other devices or modules for implementing the method in the method embodiments of the present application.
[0203] The file storage device 60 may include a processing module 601 (or referred to as a processing unit). Optionally, the file storage device 60 may further include an interface module 602 (or referred to as a transceiver unit or transceiver module) and a storage module 603 (or referred to as a storage unit). The interface module 602 is used to communicate with other devices. For example, the interface module 602 may be a transceiver module or an input / output module.
[0204] In a possible design, one or more of the modules in Figure 6 may be implemented by one or more processors, or by one or more processors and a memory; or by one or more processors and a transceiver; or by one or more processors, a memory and a transceiver. The embodiments of the present application do not make any limitations in this regard. The processor, memory, and transceiver may be provided separately or integrated together.
[0205] The file storage device 60 has the functions of the file storage device described in the embodiments of the present application. For example, the file storage device 60 includes modules or units or means corresponding to the steps involved in the file storage device described in the embodiments of the present application. The functions or units or means may be implemented by software, or by hardware, or by hardware executing corresponding software, or by a combination of software and hardware. For specific details, please refer to the corresponding descriptions in the foregoing Figure 2 、 Figure 3 or Figure 4 corresponding method embodiments, which will not be elaborated herein.
[0206] In addition, the present application provides a computer program product, which includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are fully or partially generated. For example, the methods related to the file storage device as described in the foregoing Figure 2 、 Figure 3 or Figure 4 are implemented. For another example, the methods related to the file storage device as described in the foregoing Figure 2 orFigure 4 Methods related to a file storage device therein. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired manner (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., digital versatile disc (DVD)), or a semiconductor medium (e.g., solid state disk (SSD)), etc.
[0207] In addition, the present application also provides a computer-readable storage medium storing a computer program, which is executed by a processor to implement the methods related to the file storage device as described above Figure 2 , Figure 3 or Figure 4 as described therein.
[0208] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0209] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
Claims
1. A authentication method, applied to a file storage device, characterized in that including: Receiving a first authentication request from a host, the first authentication request including first information of a first user, where the first user is a user applying for domain authentication through the host; When a domain controller corresponding to the file storage device is abnormal, authenticating the first user based on the first information of the first user and second information of the first user stored in the file storage device to obtain an authentication result of the first user, where the second information is information obtained when the first user is successfully authenticated by the domain controller; Sending a first authentication response to the host, the first authentication response including the authentication result of the first user.
2. The method according to claim 1, characterized in that, Before the domain controller is abnormal, the method further includes: When the first user is successfully authenticated by the domain controller, storing the second information of the first user.
3. The method according to claim 1 or 2, characterized in that, The authenticating the first user based on the first information of the first user and second information of the first user stored in the file storage device to obtain an authentication result includes: If the first information of the first user is consistent with the second information of the first user, determining that the first user is successfully authenticated.
4. The method according to any one of claims 1 to 3, characterized in that The first information of the first user includes the account of the first user, and the second information of the first user includes the account of the first user.
5. The method according to claim 4, characterized in that, The first information of the first user further includes the address of the host logging in to the account of the first user, and the second information of the first user further includes the address of the host logging in to the account of the first user when authenticating through the domain controller.
6. The method according to claim 4 or 5, characterized in that The second information of the first user further includes an index of the access permission of the first user, and the index of the access permission of the first user is used to determine the access permission of the first user in the file storage device; The method further includes: Determining an index of the access permission of the first user based on the account of the first user.
7. The method according to any one of claims 4 to 6, characterized in that, Before receiving the first request from the host, the method further includes: Receiving a first negotiation request from the host, the first negotiation request including an authentication method supported by the host; When it is determined that the domain controller corresponding to the file storage device is abnormal, sending a first negotiation response to the host, the first negotiation response including first authentication information determined by the file storage device based on the first negotiation request, and the first authentication information is used for the host to encrypt the account password of the first user.
8. The method according to any one of claims 1 to 7, characterized in that The method further includes: When it is determined that the domain controller corresponding to the file storage device is abnormal, enabling the function of proxying the domain controller to authenticate users, and starting a first timer, where the duration of the first timer is the duration for which the file storage device proxies the domain controller to authenticate users; When the first timer times out, disabling the function of proxying the domain controller to authenticate users.
9. The method according to claim 8, wherein The method further includes: When it is determined that the domain controller corresponding to the file storage device returns to normal, stopping the first timer and disabling the function of proxying the domain controller to authenticate users.
10. The method according to claim 9, characterized in that, The method further includes: Receive a second authentication request from the host, where the second authentication request includes information of a second user, and the second user is a user who applies for domain authentication through the host; Send the second authentication request to the domain controller; Receive a second authentication response from the domain controller, where the second authentication response includes an authentication result of the second user and information of the second user, and the information of the second user includes an index of access permissions of the second user; Store the information of the second user.
11. The method according to any one of claims 1 to 10, characterized in that, Before authenticating the first user based on the first information of the first user and the second information of the first user stored in the file storage device, the method further includes: Receive first configuration information, where the first configuration information is used to instruct the file storage device to enable the function of proxying the domain controller to authenticate users when the domain controller corresponding to the file storage device is abnormal.
12. The method according to any one of claims 1 to 10, characterized in that, Before authenticating the first user based on the first information of the first user and the second information of the first user stored in the file storage device, the method further includes: When it is determined that the domain controller corresponding to the file storage device is abnormal, send an alarm message and a prompt message, where the alarm message is used to indicate that the domain controller corresponding to the file storage device is abnormal, and the prompt message is used to prompt the user whether to enable the function of proxying the domain controller to authenticate users; Receive first indication information, where the first indication information is used to instruct the file storage device to enable the function of proxying the domain controller to authenticate users.
13. A file storage device, characterized in that, Include a processor, where the processor is configured to execute the method according to any one of claims 1 to 12.
14. A file storage device, characterized in that, The file storage device includes a module for executing the method according to any one of claims 1 to 12.
15. A computer-readable storage medium, characterized in that, Store instructions, when the instructions run on a computer, cause the computer to execute the method according to any one of claims 1 to 12.