Network asset processing method, system and device and electronic equipment
By deploying springboard machines in a virtual private cloud network and combining reverse access and Single Tunnel technology, the interoperability between VPC networks and classic networks is solved, and the problem that bastion machines cannot manage multiple network assets at the same time is improved, the security of network asset operation and maintenance and user login restrictions are enhanced, and the security of bastion machines is enhanced.
Patent Information
- Application Number
- CN202410027159.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-08
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, the network assets under a single network can only be operated and maintained through the bastion machine, and the IDC computer room network assets and the virtual private cloud network assets on the cloud cannot be managed at the same time. The user login portal is not restricted, which has a problem of low security.
By deploying a springboard machine as a single login portal in a virtual private cloud network, combining reverse access and Single Tunnel technology, the interoperability between the VPC network and the classic network is achieved, and identity authentication and permission verification are performed on the springboard machine, restricting user login areas, and ensuring the security of operation and maintenance requests.
The cloud VPC network has achieved the operation and maintenance of classic network assets through the classic network, which has improved the security of network assets, solved the pain point that users cannot operate and maintain classic network assets through the classic network in the cloud VPC network, and enhanced the security isolation of the basin and the restrictions on user login.
Smart Images

Figure CN120276802A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and in particular, to a method, system, device, and electronic device for processing network assets. Background Art
[0002] With the rapid development of cloud computing and the continuous popularization of information technology, more and more users have migrated traditional Internet Data Center (IDC) services to the cloud environment. However, most users, out of security considerations, only migrate non-core data to the cloud environment. Therefore, there is a situation where network assets in the IDC computer room and network assets in the cloud coexist.
[0003] Currently, in related technologies, network asset management is mainly carried out through a bastion host. By using the bastion host to quickly operate and maintain network assets, problems such as a large number of network assets, difficult management, unclear operation and maintenance responsibility permissions, and difficult traceability of operation and maintenance events can be solved. However, through the bastion host, only assets under one network can be operated and maintained, and multiple network assets cannot be operated and maintained simultaneously.
[0004] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of this application provide a method, system, device, and electronic device for processing network assets, so as to at least solve the technical problem that in related technologies, when using a bastion host to operate and maintain network assets under a single network, the user login entry is not restricted, resulting in relatively low security for network asset operation and maintenance.
[0006] According to one aspect of the embodiments of this application, a method for processing network assets is provided, including: receiving a login request of a target object through a jump server of a virtual private cloud network, where the login request at least includes identification information of the target object; performing identity authentication on the target object according to connection parameter information and the identification information of the target object to obtain an identity authentication result, where the connection parameter information is used for login verification; if the identity authentication result indicates that the target object passes the identity authentication, then responding to the login request and receiving an operation and maintenance request of the target object, where the operation and maintenance request at least includes asset information of a target network asset and operation information of a target operation and maintenance operation, the target network asset is a network asset of a target network, and the target network is a network that is not logically isolated; forwarding the operation and maintenance request to a bastion host of the target network, where the bastion host is used to perform a target operation and maintenance operation on the target network asset according to the asset information and the operation information.
[0007] Further, a proxy client is deployed on the jump server, and the target objects at least include a first object. Receiving a login request of the target object through the jump server of the virtual private cloud network includes: receiving the login request of the first object through the proxy client deployed on the jump server based on a first network channel, where the first network channel represents a channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
[0008] Further, connection parameter information is configured in the proxy client. Authenticating the target object based on the connection parameter information and the identification information of the target object to obtain an authentication result includes: determining, through the proxy client, whether there is target connection parameter information identical to the identification information of the target object in the connection parameter information to obtain a determination result; if the determination result indicates the existence of the target connection parameter information, then taking the target object as authenticated as the authentication result; if the determination result indicates the non-existence of the target connection parameter information, then taking the target object as unauthenticated as the authentication result.
[0009] Further, a proxy server is deployed on the bastion host, and the proxy server is used to communicate with the proxy client. Forwarding an operation and maintenance request to the bastion host of the target network includes: forwarding the operation and maintenance request to the proxy server deployed on the bastion host through the proxy client deployed on the jump server based on a second network channel, where the second network channel represents a channel from the virtual private cloud network to the target network.
[0010] Further, before receiving the login request of the target object through the jump server of the virtual private cloud network, the method further includes: responding to a first network channel request sent by the bastion host and establishing a first network channel based on reverse access technology; sending a second network channel request to the bastion host to enable the bastion host to respond to the second network channel request and establish a second network channel based on single-channel connection technology.
[0011] According to one aspect of the embodiments of the present application, a method for processing network assets is provided, including: receiving, through the bastion host of the target network, an operation and maintenance request of a target object sent by a jump server of the virtual private cloud network, where the operation and maintenance request at least includes asset information of the target network asset and operation information of the target operation and maintenance operation; performing permission verification on the operation and maintenance request based on the asset information and the operation information to obtain a verification result; if the verification result indicates that the target object has the operation permission to perform the target operation and maintenance operation on the target network asset, then performing the target operation and maintenance operation on the target network asset.
[0012] Furthermore, a proxy server is deployed on the bastion host. Among them, the bastion host of the target network receives the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network, including: the proxy server deployed on the bastion host receives the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network based on the second network channel, where the second network channel represents the channel from the virtual private cloud network to the target network.
[0013] Furthermore, operation and maintenance permissions for permission management are configured in the proxy server. Among them, the operation and maintenance request is subjected to permission verification based on the asset information and the operation information to obtain a verification result, including: the proxy server deployed on the bastion host determines whether the asset information and the operation information meet the operation and maintenance permissions; if the asset information and the operation information meet the operation and maintenance permissions, then the operation permission for the target object to perform the target operation and maintenance operation on the target network asset is used as the verification result; if the asset information and the operation information do not meet the operation and maintenance permissions, then the operation permission for the target object not to perform the target operation and maintenance operation on the target network asset is used as the verification result.
[0014] Furthermore, a proxy client is deployed on the jump server, and the target object includes at least a first object. Among them, before the bastion host of the target network receives the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network, the method further includes: the proxy server receives the login request of the first object and forwards the login request of the first object to the proxy client based on the first network channel, where the first network channel represents the channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
[0015] Furthermore, before the bastion host of the target network receives the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network, the method further includes: sending a first network channel request to the jump server so that the jump server responds to the first network channel request and establishes the first network channel based on the reverse access technology; responding to the second network channel request sent by the jump server and establishing the second network channel based on the single-channel connection technology.
[0016] According to one aspect of the embodiments of the present application, a processing system for network assets is provided, including: a jump server of a virtual private cloud network, wherein a proxy client is deployed on the jump server, and connection parameter information for login verification is configured in the proxy client. The jump server is used to receive a login request of a target object through the proxy client, authenticate the target object according to the connection parameter information and the identification information of the target object. If the target object passes the authentication, the login request is responded to, and the operation and maintenance request of the target object is received, and the operation and maintenance request is forwarded to the bastion host of the target network; the bastion host of the target network, wherein a proxy server is deployed on the bastion host, and operation and maintenance permissions for permission management are configured in the proxy server. The bastion host is used to receive the operation and maintenance request through the proxy server, and determine whether the asset information of the target network asset and the operation information of the target operation and maintenance operation included in the operation and maintenance request meet the operation and maintenance permissions. If the asset information and the operation information meet the operation and maintenance permissions, the target operation and maintenance operation is performed on the target network asset.
[0017] According to another aspect of the embodiments of the present application, a processing device for network assets is further provided, including: a first receiving unit, configured to receive a login request of a target object through a jump server of a virtual private cloud network, wherein the login request at least includes the identification information of the target object; a first processing unit, configured to authenticate the target object according to the connection parameter information and the identification information of the target object to obtain an authentication result, wherein the connection parameter information is used for login verification; a second receiving unit, configured to, if the authentication result indicates that the target object passes the authentication, respond to the login request and receive the operation and maintenance request of the target object, wherein the operation and maintenance request at least includes the asset information of the target network asset and the operation information of the target operation and maintenance operation, the target network asset is a network asset of the target network, and the target network is a network that is not logically isolated; a second processing unit, configured to forward the operation and maintenance request to the bastion host of the target network, wherein the bastion host is configured to perform the target operation and maintenance operation on the target network asset according to the asset information and the operation information.
[0018] Further, a proxy client is deployed on the jump server, and the target object at least includes a first object. The first receiving unit includes: a first receiving subunit, configured to receive the login request of the first object through the proxy client deployed on the jump server based on a first network channel, wherein the first network channel represents a channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
[0019] Further, connection parameter information is configured in the proxy client. Among them, the first processing unit includes: a first judgment subunit, configured to judge whether there is target connection parameter information identical to the identification information of the target object in the connection parameter information through the proxy client, and obtain a judgment result; a first determination subunit, configured to, if the judgment result indicates the existence of the target connection parameter information, use the successful authentication of the target object as the authentication result; a second determination subunit, configured to, if the judgment result indicates the non-existence of the target connection parameter information, use the failed authentication of the target object as the authentication result.
[0020] Further, a proxy server is deployed on the bastion host. The proxy server is used for communicating with the proxy client. Among them, the second processing unit includes: a first forwarding subunit, configured to forward the operation and maintenance request sent by the proxy client deployed on the jump server to the proxy server deployed on the bastion host based on the second network channel through the jump server, where the second network channel represents the channel from the virtual private cloud network to the target network.
[0021] Further, the processing device for network assets further includes: a first construction unit, configured to, before receiving the login request of the target object through the jump server of the virtual private cloud network, respond to the first network channel request sent by the bastion host and establish a first network channel based on the reverse access technology; a second construction unit, configured to send a second network channel request to the bastion host, so that the bastion host responds to the second network channel request and establishes a second network channel based on the single-channel connection technology.
[0022] According to another aspect of the embodiments of the present application, there is also provided a processing device for network assets, including: a third receiving unit, configured to receive the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network, where the operation and maintenance request at least includes the asset information of the target network asset and the operation information of the target operation and maintenance operation; a third processing unit, configured to perform permission verification on the operation and maintenance request according to the asset information and the operation information to obtain a verification result; a fourth processing unit, configured to, if the verification result indicates that the target object has the operation permission to perform the target operation and maintenance operation on the target network asset, perform the target operation and maintenance operation on the target network asset.
[0023] Further, a proxy server is deployed on the bastion host. Among them, the third receiving unit includes: a second receiving subunit, configured to receive the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network based on the second network channel through the proxy server deployed on the bastion host, where the second network channel represents the channel from the virtual private cloud network to the target network.
[0024] Further, the proxy server is configured with operation and maintenance permissions for permission management. Among them, the third processing unit includes: a second judgment subunit, configured to judge whether the asset information and operation information meet the operation and maintenance permissions through the proxy server deployed on the bastion host; a third determination subunit, configured to, if the asset information and operation information meet the operation and maintenance permissions, use the operation permission of the target object to perform the target operation and maintenance operation on the target network asset as the verification result; a fourth determination subunit, configured to, if the asset information and operation information do not meet the operation and maintenance permissions, use the lack of operation permission of the target object to perform the target operation and maintenance operation on the target network asset as the verification result.
[0025] Further, a proxy client is deployed on the jump server. The target object includes at least a first object. The processing device for network assets further includes: a fourth receiving unit, configured to, before receiving the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network, receive the login request of the first object through the proxy server and forward the login request of the first object to the proxy client based on the first network channel, where the first network channel represents the channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
[0026] Further, the processing device for network assets further includes: a third construction unit, configured to, before receiving the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network, send a first network channel request to the jump server, so that the jump server responds to the first network channel request and establishes the first network channel based on the reverse access technology; a fourth construction unit, configured to respond to the second network channel request sent by the jump server and establish the second network channel based on the single-channel connection technology.
[0027] In the embodiments of the present application, a jump server in a virtual private cloud network is adopted to receive a login request of a target object, where the login request at least includes identification information of the target object; the target object is authenticated based on connection parameter information and the identification information of the target object to obtain an authentication result, where the connection parameter information is used for login verification; if the authentication result indicates that the target object passes the authentication, the login request is responded to, and an operation and maintenance request of the target object is received, where the operation and maintenance request at least includes asset information of a target network asset and operation information of a target operation and maintenance operation, the target network asset is a network asset of a target network, and the target network is a network that is not logically isolated; the operation and maintenance request is forwarded to a bastion host of the target network, where the bastion host is used to perform a target operation and maintenance operation on the target network asset according to the asset information and the operation information. By deploying a jump server as a single login entry point, all remote connections to the bastion host need to access through the jump server, restricting user logins to the cloud VPC environment, achieving a restriction on the user login area, providing better security isolation for the bastion host, improving the security factor of the bastion host, protecting the security of internal servers, improving the security of network asset operation and maintenance, and solving the pain point that in the current cloud computing environment, users cannot operate and maintain classic network assets through the bastion host of the classic network (i.e., the target network) in the cloud VPC network, achieving the purpose of restricting user logins to the cloud VPC environment, thereby realizing the operation and maintenance of classic network assets through the bastion host of the classic network in the cloud VPC network and improving the security of network asset operation and maintenance, and further solving the technical problem that in the related art, when operating and maintaining network assets in a single network through a bastion host, the user login entry is not restricted, resulting in low security of network asset operation and maintenance. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0029] Figure 1 is a flowchart of a method for processing network assets according to Embodiment 1 of the present application;
[0030] Figure 2 is a schematic diagram of an optional processing flow of network assets according to Embodiment 1 of the present application;
[0031] Figure 3 is a flowchart of a method for processing network assets according to Embodiment 2 of the present application;
[0032] Figure 4 is a schematic diagram of a system for processing network assets according to Embodiment 3 of the present application;
[0033] Figure 5 It is a schematic diagram of a network asset processing device provided in Embodiment 4 of the present application;
[0034] Figure 6 It is a schematic diagram of a network asset processing device provided in Embodiment 5 of the present application. Detailed implementation manners
[0035] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0036] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data used in appropriate cases can be interchanged so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0037] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties. And the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards in the relevant regions, and corresponding operation entrances are provided for the user to select authorization or rejection.
[0038] First, some nouns or terms that appear during the description of the embodiments of the present application are applicable to the following explanations:
[0039] Fortress machine: It is a control platform that provides operation and maintenance and security auditing for users. It can centrally manage operation and maintenance permissions, control operation behaviors throughout the process, restore operation and maintenance scenarios in real time, ensure that the identities of operation and maintenance behaviors can be authenticated, permissions can be controlled, and operations can be audited, and solve problems such as many assets, difficult management, unclear operation and maintenance responsibilities and authorities, and difficult traceability of operation and maintenance events.
[0040] Jump Server in front of the bastion host: The jump server in front of the bastion host refers to a jump server, also known as the proxy server of the bastion host, which is generally a Windows graphical jump server. It acts as an intermediate node for security isolation and access control, and is used to manage and control access to remote servers.
[0041] Virtual Private Cloud: The full English name is Virtual Private Cloud, abbreviated as VPC. It is a single-tenant network form belonging to a specific private network. Networks between VPCs are not connected. Users can control their own private networks within the VPC. For example, they can select the IP address range, configure the routing table and gateway, etc. They can also use various cloud resources in the VPC, such as Elastic Compute Service (ECS for short), Relational Database Service (RDS for short), and Server Load Balancer (SLB for short), etc.
[0042] Classic network: Different from the VPC network, the classic network is an earlier network architecture. All resources are connected to the same physical network and are connected through the Internet, and can only be interconnected within the entire region.
[0043] Reverse access: For normal service requests, generally users access the ECS within the VPC, and the ECS then calls the relevant services. Reverse access can achieve two-way Network Address Translation (NAT) mapping through the virtual private cloud gateway XGW, realizing the connection from the classic network to the VPC network.
[0044] Single Tunnel: It is a type of Application Load Balancer (ALB) service that can achieve network connection between VPCs and between VPC and the classic network. The service object of the Single Tunnel access cloud service instance is a VPC, and users in other VPCs or the classic network cannot access this cloud service instance. The SingleTunnel cloud service instance provides access services to the VPC by applying for a Single Tunnel VIP on the ALB and mounting the backend server under this VIP.
[0045] Embodiment 1
[0046] With the rapid development of cloud computing and the increasing popularity of information technology, more and more users are migrating traditional Internet Data Center (IDC) services to the cloud environment. However, for security reasons, most users will only migrate non-core data to the cloud environment, resulting in the coexistence of IDC room network assets and cloud network assets.
[0047] At present, the relevant technologies mainly use bastion hosts to manage network assets. The rapid operation and maintenance of network assets by bastion hosts can solve the problems of many network assets, difficult management, unclear operation and maintenance responsibilities and authorities, and difficult tracing of operation and maintenance events. However, the bastion host can only operate and maintain assets under one network, that is, the bastion host of the classic network operates and maintains classic network assets, and the bastion host of the virtual private cloud (VPC) network on the cloud operates and maintains VPC network assets. It is impossible to operate and maintain multiple network assets at the same time, which determines that users cannot operate and maintain classic network assets through the bastion host of the classic network in the VPC network on the cloud. In addition, the bastion host of the classic network does not restrict the user login entrance. Users can initiate requests in any area of the IDC computer room, which has certain security risks and the security of network asset operation and maintenance is low.
[0048] In the above technical background, the present application provides Figure 1 The processing method of network assets shown. Figure 1 This is a flow chart of a method for processing network assets provided in accordance with Embodiment 1 of the present application. The method includes:
[0049] Step S101: receiving a login request of a target object through a jump server of a virtual private cloud network, wherein the login request at least includes identification information of the target object.
[0050] Optionally, in this solution, a jump server is deployed in the virtual private cloud VPC network as a single login entry point, and the jump server of the VPC network is used as a front-end machine for the bastion machine of the classic network (i.e., the target network). All remote connections to the bastion machine must be accessed through the jump server, and user login is restricted to the VPC environment on the cloud, thereby implementing restrictions on the user login area and providing better security isolation for the bastion machine.
[0051] Therefore, the login request of the target object is received through the jump server of the VPC network. The target object can be a VPC user on the cloud or a user on the classic network side. The identification information can be a user name and password, etc. For example, a VPC user on the cloud sends a login request through the public network SLB or elastic public network EIP (i.e. Elastic IP) to request to log in to the bastion machine front-end (i.e. jump server). In this case, the login request of the VPC user on the cloud is received through the jump server of the VPC network.
[0052] Step S102: Authenticate the target object based on the connection parameter information and the identification information of the target object to obtain an authentication result. The connection parameter information is used for login verification.
[0053] Step S103: If the authentication result indicates that the target object passes the authentication, then respond to the login request and receive the operation and maintenance request of the target object. The operation and maintenance request at least includes the asset information of the target network asset and the operation information of the target operation and maintenance operation. The target network asset is the network asset of the target network, and the target network is a network without logical isolation.
[0054] The connection parameter information can be pre-configured user login information, etc., and at least includes the username and password for logging in to the jump server. Therefore, the target object can be authenticated based on the connection parameter information and the identification information of the target object. For example, the jump server can match the pre-configured user login information with the received identification information such as the username and password to implement the authentication of the target object and obtain the authentication result. For example, the authentication is successful or the authentication fails.
[0055] If the authentication result indicates that the target object passes the authentication, for example, the authentication is successful, then the jump server responds to the login request, that is, the target object logs in to the jump server, and then the jump server can receive the operation and maintenance request of the target object. The target network asset is the network asset of the classic network. For example, the server group in the computer room. The asset information can be the asset identifier, etc. For example, the server group PC-1. The target operation and maintenance operation can be operations such as authentication, authorization, account management, and auditing. The operation information can be specific description information. For example, authorize the user account X.
[0056] Step S104: Forward the operation and maintenance request to the bastion host of the target network. The bastion host is used to perform the target operation and maintenance operation on the target network asset based on the asset information and the operation information.
[0057] The jump server can forward the operation and maintenance request to the bastion host of the classic network, so that the bastion host can perform the target operation and maintenance operation on the target network asset based on the asset information and the operation information, realizing that the user accesses the bastion host of the classic network through the jump server in the cloud VPC network area.
[0058] In this solution, by deploying a jump server as a single login entry point, all remote connections to the bastion host need to access through the jump server. The user login is restricted to the cloud VPC environment, realizing the restriction of the user login area, providing better security isolation for the bastion host, improving the security factor of the bastion host, protecting the security of the internal server, enhancing the security of network asset operation and maintenance, and solving the pain point that in the current cloud computing environment, users cannot operate and maintain classic network assets through the bastion host in the classic network (i.e., the target network) in the cloud VPC network.
[0059] In an alternative embodiment, the schematic diagram shown in Figure 2 can be adopted to implement the processing of network assets. As shown in Figure 2 , a bastion host pre-processor (i.e., jump server) is deployed in the cloud VPC, and a bastion host is deployed in the classic network, including service terminals, management asset services, and imported asset services. Bastion host A operates and maintains the assets of classic network A, i.e., the server groups PC-1, PC-2, PC-3, …, PC-N in computer room IDC-A. Bastion host B operates and maintains the assets of classic network B, i.e., the server groups PC-1, PC-2, PC-3, …, PC-N in computer room IDC-B.
[0060] Optionally, cloud VPC users can operate and maintain the assets on the classic network side. For example, cloud VPC users log in to the bastion host pre-processor (i.e., jump server) based on the public network domain name through the public network SLB or public network EIP, and then the jump server is used to operate and maintain the assets of the bastion host computer room IDC-A (or IDC-B).
[0061] Optionally, since the cloud VPC network and the classic network are not connected by default, in this solution, the Single Tunnel technology is used to connect the VPC network to the classic network, so as to realize the operation and maintenance of the assets under the classic network through the jump server in the VPC network. For example, after the VPC network is connected to the classic network, the assets of computer room IDC-A can be operated and maintained through the management asset service of bastion host A.
[0062] Optionally, users on the classic network side also need to operate and maintain the assets on the classic network side. Since the user is restricted to operate and maintain the assets through the jump server, and the classic network is not connected to the VPC network, in this solution, the reverse access technology is used to connect the classic network to the VPC network. For example, by means of the service terminal built in the bastion host service, a reverse access channel from the classic network to the VPC network can be established. After the classic network is connected to the VPC network, users on the classic network side can log in to the jump server through the service terminal built in bastion host A to operate and maintain the assets of computer room IDC-A.
[0063] For example, a proxy service terminal can be deployed on the bastion host of the classic network, such as OpenSSH (an open-source encrypted communication software), FreeRDP (a graphical remote control software), etc. This proxy service terminal can be used to create and manage remote connections. Then, configure the access permissions of the proxy service terminal (i.e., the Single Tunnel whitelist) to restrict connections only to specified users or IP addresses. Deploy a proxy client on the jump server in the VPC network, such as PuTTY (a remote login tool), Remmina (a remote desktop client), etc. This proxy client can be used to connect to the bastion host of the classic network and access the target server through the proxy of the bastion host (for example, the server group PC-1 in the IDC-A computer room). Then, configure the connection parameters of the proxy client, including the IP address, port number of the bastion host, and the username and password for logging in to the bastion host. After receiving the running instruction, run the proxy client to establish a connection through the proxy service terminal of the bastion host. During the connection process, the proxy client will transfer all data through the bastion host to achieve access to the target server.
[0064] It should be noted that based on the advantages of cloud computing technology, this solution can achieve network connection between the VPC network and the classic network by combining technologies such as reverse access and Single Tunnel. Thus, users can access the bastion host of the classic network through the jump server in the cloud VPC network area and maintain the classic network assets through the bastion host of the classic network, optimizing the way the bastion host manages classic network assets and restricting users' access requests to the cloud VPC environment. In addition, by deploying a jump server as a single login entry point under the cloud VPC network, all remote connections to the bastion host need to pass through it. The jump server can configure access policies to restrict only authorized users to log in using authorized keys or usernames / passwords and can limit the target servers to be accessed, enabling more centralized management of user authentication and authorization, recording users' operation logs, etc., improving the security coefficient of the bastion host, providing better security isolation for the bastion host, and thus protecting the security of internal servers and improving the security of network asset operation and maintenance.
[0065] How to achieve communication between the VPC network and the classic network is crucial. Therefore, in the method for processing network assets provided in Embodiment 1 of this application, a proxy client is deployed on the jump server, and the target object includes at least a first object. Among them, receiving the login request of the target object through the jump server in the virtual private cloud network includes: receiving the login request of the first object through the proxy client deployed on the jump server based on the first network channel, where the first network channel represents the channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
[0066] Optionally, since the VPC network on the cloud is not connected to the classic network, and the classic network is not connected to the VPC network either. Therefore, before receiving the login request of the target object through the jump server in the virtual private cloud network, deploy a jump server on the VPC network and deploy a proxy client on the jump server, such as PuTTY (a remote login tool), Remmina (a remote desktop client), etc. This proxy client can be used to connect to the bastion host in the classic network; and configure the connection parameter information of the proxy client, and the connection parameter information includes at least the IP address, port number, login username and password of the bastion host, etc.
[0067] The first object is the user on the classic network side, and the first network channel can be a reverse access channel established based on reverse access technology, that is, the channel from the classic network to the VPC network. For example, when the user on the classic network side needs to operate and maintain the assets under the classic network side, the user on the classic network side sends a login request through the proxy server of the bastion host and the reverse access channel. The jump server can receive the login request through the proxy client based on the reverse access channel, and then authenticate the user on the classic network side according to the connection parameter information (such as username and password) and the username and password of the user on the classic network side. And when the user on the classic network side passes the identity authentication, log in to the proxy client of the jump server.
[0068] Optionally, the target object can also be a second object, that is, a VPC user on the cloud. For example, when a VPC user on the cloud needs to operate and maintain the assets under the classic network side, the VPC user on the cloud sends a login request based on the public network domain name through the public network SLB or public network EIP. The jump server can receive the login request sent by the VPC user on the cloud through the public network SLB or public network EIP through the proxy client, and then authenticate the VPC user on the cloud according to the connection parameter information (such as username and password) and the username and password of the VPC user on the cloud. And when the VPC user on the cloud passes the identity authentication, log in to the proxy client of the jump server.
[0069] It should be noted that through the above deployment and information configuration, the system setup and configuration are realized, providing an accurate data basis for subsequent identity authentication.
[0070] In order to limit user logins to the cloud VPC environment, in the method for processing network assets provided in Embodiment 1 of this application, connection parameter information is configured in the proxy client. Among them, identity authentication is performed on the target object based on the connection parameter information and the identity information of the target object, and the identity authentication result includes: judging whether there is target connection parameter information in the connection parameter information that is the same as the identity information of the target object through the proxy client to obtain a judgment result; if the judgment result indicates the existence of target connection parameter information, then taking the target object as authenticated as the identity authentication result; if the judgment result indicates the non-existence of target connection parameter information, then taking the target object as unauthenticated as the identity authentication result.
[0071] The jump server can perform identity authentication on the target object through the connection parameter information configured in the proxy client. For example, judging whether there is a username and password in the connection parameter information that is the same as the received username and password (i.e., target connection parameter information). If the judgment result indicates the existence of a username and password that is the same as the received username and password, it can be determined that the target object is authenticated, that is, the authentication is successful; if the judgment result indicates the non-existence of a username and password that is the same as the received username and password, it can be determined that the target object is unauthenticated, that is, the authentication fails.
[0072] It should be noted that through the above identity authentication, user logins are limited to the cloud VPC environment, realizing the restriction of the user login area, providing better security isolation for the bastion host, and improving the security factor of the bastion host.
[0073] In order to limit user logins to the cloud VPC environment, in the method for processing network assets provided in Embodiment 1 of this application, a proxy server is deployed on the bastion host, and the proxy server is used to communicate with the proxy client. Among them, forwarding the operation and maintenance request to the bastion host of the target network includes: forwarding the operation and maintenance request to the proxy server deployed on the bastion host through the proxy client deployed on the jump server based on the second network channel, where the second network channel represents the channel from the virtual private cloud network to the target network.
[0074] Optionally, before receiving the login request of the target object through the jump server of the virtual private cloud network, a proxy server such as OpenSSH (an open-source encryption communication software) and FreeRDP (a graphical remote control software) is deployed on the bastion host of the classic network. This proxy server can be used to create and manage remote connections; and configure the operation and maintenance permissions of the proxy server, where the operation and maintenance permissions can be permissions that restrict only specified users or IP addresses to connect.
[0075] The second network channel can be a SingleTunnel channel established based on the single-channel connection technology (i.e., the Single Tunnel technology), that is, the channel from the VPC network to the classic network. Through the proxy client, the jump server can forward the operation and maintenance request to the proxy server deployed on the bastion host based on the SingleTunnel channel.
[0076] Since the proxy server on the bastion host is configured with operation and maintenance permissions, after the target object logs in to the proxy client of the jump server in the VPC network, the proxy client can forward the operation and maintenance request to the proxy server on the bastion host, so as to verify whether the target object has the operation permission to perform target operation and maintenance on the target network assets.
[0077] It should be noted that forwarding the operation and maintenance request to the proxy server through the proxy client protects the security of the internal server and improves the security of network asset operation and maintenance.
[0078] In order to realize the connection between the VPC network and the classic network and the connection between the classic network and the VPC network, in the method for processing network assets provided in the first embodiment of this application, before receiving the login request of the target object through the jump server of the virtual private cloud network, respond to the first network channel request sent by the bastion host and establish the first network channel based on the reverse access technology; send a second network channel request to the bastion host, so that the bastion host responds to the second network channel request and establishes the second network channel based on the single-channel connection technology.
[0079] Since by default, the VPC network and the classic network are not connected, and the classic network and the VPC network are also not connected, which restricts users from accessing the bastion host in the classic network through the jump server in the VPC network and performing operation and maintenance on classic network assets through the bastion host in the classic network. Therefore, in this solution, the connection between the VPC network and the classic network is realized through the Single Tunnel technology, and the connection between the classic network and the VPC network is realized through the reverse access technology.
[0080] Before receiving the login request of the target object through the jump server of the virtual private cloud network, the bastion host in the classic network requests to establish a network channel (i.e., the first network channel request) from the jump server in the VPC network. The jump server responds to the first network channel request sent by the bastion host and establishes the first network channel from the classic network to the VPC network (i.e., the reverse access channel) based on the reverse access technology.
[0081] The jump server in the VPC network requests to establish a network channel from the VPC network to the classic network from the bastion host in the classic network, that is, sends a second network channel request to the bastion host, so that the bastion host responds to the second network channel request and establishes the second network channel from the VPC network to the classic network (i.e., the Single Tunnel channel) based on the single-channel connection technology.
[0082] It should be noted that through the construction of the above network channels, the connection between the VPC network and the classic network and the connection from the classic network to the VPC network are realized, enabling users to access the bastion host of the classic network through the jump server in the VPC network area and operating and maintaining the classic network assets through the bastion host of the classic network, thus solving the pain point that in the current cloud computing environment, users cannot operate and maintain the classic network assets through the bastion host of the classic network (i.e., the target network) in the cloud VPC network.
[0083] In the embodiment of the present application, the jump server of the virtual private cloud network is adopted to receive the login request of the target object, where the login request at least includes the identification information of the target object; the target object is authenticated according to the connection parameter information and the identification information of the target object to obtain an identity authentication result, where the connection parameter information is used for login verification; if the identity authentication result indicates that the target object passes the identity authentication, the login request is responded to, and the operation and maintenance request of the target object is received, where the operation and maintenance request at least includes the asset information of the target network asset and the operation information of the target operation and maintenance operation, the target network asset is the network asset of the target network, and the target network is a network without logical isolation; the operation and maintenance request is forwarded to the bastion host of the target network, where the bastion host is used to perform the target operation and maintenance operation on the target network asset according to the asset information and the operation information. By deploying the jump server as a single login entry point, all remote connections to the bastion host need to be accessed through the jump server, restricting the user login to the cloud VPC environment, realizing the restriction of the user login area, providing better security isolation for the bastion host, improving the security coefficient of the bastion host, protecting the security of the internal server, improving the security of the operation and maintenance of network assets, and solving the pain point that in the current cloud computing environment, users cannot operate and maintain the classic network assets through the bastion host of the classic network (i.e., the target network) in the cloud VPC network, achieving the purpose of restricting the user login to the cloud VPC environment, thus realizing the operation and maintenance of the classic network assets through the bastion host of the classic network in the cloud VPC network and improving the security of the operation and maintenance of network assets, and further solving the technical problem that in the related art, when operating and maintaining network assets in a single network through the bastion host, the user login entry is not restricted, resulting in relatively low security of the operation and maintenance of network assets.
[0084] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0085] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present application.
[0086] Embodiment 2
[0087] According to an embodiment of the present application, there is provided a method for processing network assets as shown in Figure 3 shown. Figure 3 FIG. is a flowchart of a method for processing network assets according to Embodiment 2 of the present application. The method includes:
[0088] Step S301, receiving an operation and maintenance request of a target object sent by a jump server of a virtual private cloud network through a bastion host of a target network, where the operation and maintenance request at least includes asset information of a target network asset and operation information of a target operation and maintenance operation.
[0089] Step S302, performing permission verification on the operation and maintenance request according to the asset information and the operation information to obtain a verification result.
[0090] Step S303, if the verification result indicates that the target object has the operation permission to perform the target operation and maintenance operation on the target network asset, then perform the target operation and maintenance operation on the target network asset.
[0091] The bastion host of the classic network (i.e., the target network) is configured with operation and maintenance permissions. According to the operation and maintenance permissions, asset information, and operation information, permission verification of the operation and maintenance request can be implemented to obtain a verification result. For example, after the target object logs in to the jump server of the VPC network, the jump server of the VPC network can forward the operation and maintenance request to the bastion host of the classic network. Therefore, the bastion host of the classic network receives the operation and maintenance request sent by the jump server of the VPC network, and then the bastion host verifies whether the target object has the operation permission to perform the target operation and maintenance operation on the target network asset. If the verification result indicates that the target object has the operation permission to perform the target operation and maintenance operation on the target network asset, then perform the target operation and maintenance operation on the target network asset. For example, the target service (such as the management asset service) of the bastion host audits the server group PC-1.
[0092] If the verification result indicates that the target object does not have the operation permission to perform the target operation and maintenance operation on the target network asset, then reject the operation and maintenance request.
[0093] So far, it has been realized that the user accesses the bastion host in the classic network through the jump server in the VPC network area on the cloud, and maintains the classic network assets through the bastion host in the classic network.
[0094] In this solution, by deploying a jump server as a single login entry point, all remote connections to the bastion host need to be accessed through the jump server, restricting the user login to the VPC environment on the cloud, realizing the restriction of the user login area, providing better security isolation for the bastion host, improving the security factor of the bastion host, protecting the security of the internal server, improving the security of network asset operation and maintenance, and solving the pain point that in the current cloud computing environment, users cannot maintain classic network assets through the bastion host in the classic network (i.e., the target network) in the VPC network on the cloud.
[0095] How to realize the communication between the VPC network and the classic network is crucial. Therefore, in the method for processing network assets provided in the second embodiment of this application, a proxy server is deployed on the bastion host. Among them, the bastion host in the target network receives the operation and maintenance request of the target object sent by the jump server in the virtual private cloud network, including: receiving the operation and maintenance request of the target object sent by the jump server in the virtual private cloud network based on the second network channel through the proxy server deployed on the bastion host, where the second network channel represents the channel from the virtual private cloud network to the target network.
[0096] Deploy a proxy server on the bastion host in the classic network, such as OpenSSH (an open-source encrypted communication software), FreeRDP (a graphical remote control software), etc. This proxy server can be used to create and manage remote connections; and configure the operation and maintenance permissions of the proxy server, where the operation and maintenance permissions can be permissions that restrict only specified users or IP addresses to connect.
[0097] The second network channel can be a SingleTunnel channel established based on the single-channel connection technology (i.e., the Single Tunnel technology), that is, the channel from the VPC network to the classic network. The bastion host can receive the operation and maintenance request of the target object sent by the jump server based on the SingleTunnel channel through the proxy server.
[0098] Since the operation and maintenance permissions are configured on the proxy server of the bastion host, after the proxy client of the target object logs in to the jump server in the VPC network, the proxy client can forward the operation and maintenance request to the proxy server of the bastion host, and the bastion host can receive the operation and maintenance request of the target object sent by the proxy client based on the Single Tunnel channel through the proxy server, so as to be able to verify whether the target object has the operation permission to perform the target operation and maintenance operation on the target network asset.
[0099] In order to accurately determine whether a target object has the operation permission to perform target operation and maintenance on a target network asset, in the method for processing network assets provided in the second embodiment of the present application, an operation and maintenance permission for permission management is configured in the proxy server. Among them, the permission verification of the operation and maintenance request is performed according to the asset information and the operation information, and the verification result is obtained, including: judging whether the asset information and the operation information meet the operation and maintenance permission through the proxy server deployed on the bastion host; if the asset information and the operation information meet the operation and maintenance permission, then taking that the target object has the operation permission to perform target operation and maintenance on the target network asset as the verification result; if the asset information and the operation information do not meet the operation and maintenance permission, then taking that the target object does not have the operation permission to perform target operation and maintenance on the target network asset as the verification result.
[0100] The bastion host can judge whether the asset information and the operation information meet the operation and maintenance permission through the proxy server. If the asset information and the operation information meet the operation and maintenance permission, then taking that the target object has the operation permission to perform target operation and maintenance on the target network asset as the verification result; if the asset information and the operation information do not meet the operation and maintenance permission, then taking that the target object does not have the operation permission to perform target operation and maintenance on the target network asset as the verification result.
[0101] For example, the target object is user Y, the operation and maintenance permission is to allow user Y to access and perform operation and maintenance on the assets in the IDC-A computer room of the bastion host A, the asset information is the server group PC-1 in the IDC-A computer room, and the operation information is to authorize the user account X. At this time, through the proxy server deployed on the bastion host, it can be judged that the asset information and the operation information meet the operation and maintenance permission, and the verification result that the target object (i.e., user Y) has the operation permission to perform target operation and maintenance (i.e., authorization) on the target network asset (i.e., the server group in the IDC-A computer room) is obtained.
[0102] It should be noted that through the above permission verification, the accurate determination of the operation permission is realized, the security of the internal server is protected, and the security of the operation and maintenance of the network asset is improved.
[0103] In order to be able to limit user login to the cloud VPC environment, in the method for processing network assets provided in the second embodiment of the present application, a proxy client is deployed on the jump server, and the target object includes at least a first object. Among them, before receiving the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network, the proxy server receives the login request of the first object and forwards the login request of the first object to the proxy client based on the first network channel, where the first network channel represents the channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
[0104] The first object is a user on the classic network side. The first network channel can be a reverse access channel established based on reverse access technology, that is, a channel from the classic network to the VPC network. For example, when a user on the classic network side needs to operate and maintain the assets under the classic network side, a login request is sent to the bastion host. Therefore, the bastion host receives the login request of the user on the classic network side through the proxy server and forwards the login request to the proxy client based on the reverse access channel. The jump server can receive the login request based on the reverse access channel through the proxy client, and then authenticate the user on the classic network side according to the connection parameter information (such as username and password) and the username and password of the user on the classic network side. When the user on the classic network side passes the authentication, the user logs in to the proxy client of the jump server.
[0105] In order to realize the connection from the VPC network to the classic network and the connection from the classic network to the VPC network, in the method for processing network assets provided in the second embodiment of this application, before receiving the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network, a first network channel request is sent to the jump server, so that the jump server responds to the first network channel request and establishes a first network channel based on reverse access technology; respond to the second network channel request sent by the jump server and establish a second network channel based on single-channel connection technology.
[0106] Since by default, the VPC network and the classic network are not connected, and the classic network to the VPC network is also not connected, which limits the user to access the bastion host of the classic network through the jump server of the VPC network and operate and maintain the classic network assets through the bastion host of the classic network. Therefore, in this solution, the connection from the VPC network to the classic network is realized through the Single Tunnel technology, and the connection from the classic network to the VPC network is realized through reverse access technology.
[0107] Before receiving the operation and maintenance request of the target object sent by the jump server of the VPC network through the bastion host of the classic network, the bastion host of the classic network requests the jump server of the VPC network to establish a network channel (that is, the first network channel request), so that the jump server responds to the first network channel request sent by the bastion host and establishes the first network channel from the classic network to the VPC network (that is, the reverse access channel) based on reverse access technology.
[0108] The jump server of the VPC network requests the bastion host of the classic network to establish a network channel, that is, sends a second network channel request to the bastion host. Therefore, the bastion host responds to the second network channel request sent by the jump server and establishes the second network channel from the VPC network to the classic network (that is, the Single Tunnel channel) based on single-channel connection technology.
[0109] It should be noted that through the above construction of the network channel, the connection between the VPC network and the classic network and the connection from the classic network to the VPC network are realized, enabling users to access the bastion host of the classic network through the jump server in the VPC network area and maintaining the classic network assets through the bastion host of the classic network, thus solving the pain point that in the current cloud computing environment, users cannot maintain the classic network assets through the bastion host of the classic network (i.e., the target network) in the cloud VPC network.
[0110] In the embodiment of the present application, by deploying a jump server as a single login entry point, all remote connections to the bastion host need to be accessed through the jump server, restricting user logins to the cloud VPC environment, realizing the restriction of the user login area, providing better security isolation for the bastion host, improving the security factor of the bastion host, protecting the security of internal servers, enhancing the security of network asset maintenance, and solving the pain point that in the current cloud computing environment, users cannot maintain the classic network assets through the bastion host of the classic network (i.e., the target network) in the cloud VPC network, achieving the purpose of restricting user logins to the cloud VPC environment, thereby realizing the maintenance of classic network assets through the bastion host of the classic network in the cloud VPC network and enhancing the security of network asset maintenance, and further solving the technical problem in the related art that when maintaining network assets in a single network through a bastion host, the user login entry is not restricted, resulting in relatively low security of network asset maintenance.
[0111] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0112] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present application.
[0113] Embodiment 3
[0114] According to an embodiment of the present application, there is provided a processing system for network assets as shown in Figure 4 Figure 401 of the processing system for network assets provided in Embodiment 3 of the present application. The system includes: Figure 4 A jump server 401 of a virtual private cloud network. A proxy client is deployed on the jump server 401, and connection parameter information for login verification is configured in the proxy client. The jump server 401 is used to receive a login request of a target object through the proxy client, authenticate the target object based on the connection parameter information and the identification information of the target object. If the target object passes the authentication, the jump server 401 responds to the login request, receives an operation and maintenance request of the target object, and forwards the operation and maintenance request to a bastion host 402 of the target network;
[0115] The bastion host 402 of the target network. A proxy server is deployed on the bastion host 402, and operation and maintenance permissions for permission management are configured in the proxy server. The bastion host 402 is used to receive the operation and maintenance request through the proxy server, and determine whether the asset information of the target network asset and the operation information of the target operation and maintenance operation included in the operation and maintenance request meet the operation and maintenance permissions. If the asset information and the operation information meet the operation and maintenance permissions, the bastion host 402 performs the target operation and maintenance operation on the target network asset.
[0116] It should be noted that the preferred implementation schemes involved in the above embodiments of the present application are the same as those provided in Embodiment 1 in terms of the application scenarios and implementation processes, but are not limited to the schemes provided in Embodiment 1.
[0117] Embodiment 4
[0118] According to an embodiment of the present application, there is also provided a processing device for network assets for implementing the above-mentioned processing method for network assets, as shown in
[0119] Figure 501. The device includes: a first receiving unit 501, a first processing unit 502, a second receiving unit 503, and a second processing unit 504. Figure 5 The first receiving unit 501 is used to receive a login request of a target object through a jump server of a virtual private cloud network, where the login request includes at least the identification information of the target object;
[0120] The first processing unit 502 is used to authenticate the target object based on the connection parameter information and the identification information of the target object to obtain an authentication result, where the connection parameter information is used for login verification;
[0121] The second receiving unit 503 is used to receive an operation and maintenance request of the target object forwarded by the first processing unit;
[0122] A second receiving unit 503, configured to, if the identity authentication result indicates that the target object passes the identity authentication, respond to the login request and receive an operation and maintenance request of the target object, where the operation and maintenance request at least includes asset information of a target network asset and operation information of a target operation and maintenance operation, the target network asset is a network asset of a target network, and the target network is a network that is not logically isolated;
[0123] A second processing unit 504, configured to forward the operation and maintenance request to a bastion host of the target network, where the bastion host is configured to perform a target operation and maintenance operation on the target network asset according to the asset information and the operation information.
[0124] In the processing device for network assets provided in Embodiment 4 of this application, a first receiving unit 501 receives a login request of a target object through a jump server of a virtual private cloud network, where the login request at least includes identification information of the target object; a first processing unit 502 performs identity authentication on the target object according to connection parameter information and the identification information of the target object to obtain an identity authentication result, where the connection parameter information is used for login verification; a second receiving unit 503, if the identity authentication result indicates that the target object passes the identity authentication, responds to the login request and receives an operation and maintenance request of the target object, where the operation and maintenance request at least includes asset information of a target network asset and operation information of a target operation and maintenance operation, the target network asset is a network asset of a target network, and the target network is a network that is not logically isolated; a second processing unit 504 forwards the operation and maintenance request to a bastion host of the target network, where the bastion host is configured to perform a target operation and maintenance operation on the target network asset according to the asset information and the operation information. In this solution, by deploying a jump server as a single login entry point, all remote connections to the bastion host need to access through the jump server, restricting user logins to the cloud VPC environment, achieving a restriction on the user login area, providing better security isolation for the bastion host, improving the security factor of the bastion host, protecting the security of internal servers, improving the security of network asset operation and maintenance, and solving the pain point that in the current cloud computing environment, users cannot operate and maintain classic network assets through the bastion host of the classic network (i.e., the target network) in the cloud VPC network, achieving the purpose of restricting user logins to the cloud VPC environment, thereby realizing operating and maintaining classic network assets through the bastion host of the classic network in the cloud VPC network and improving the security of network asset operation and maintenance, and further solving the technical problem that in the related art, when operating and maintaining network assets in a single network through a bastion host, there is no restriction on the user login entry point, resulting in low security of network asset operation and maintenance.
[0125] Optionally, in the network asset processing device provided in the fourth embodiment of the present application, the first receiving unit 501 includes: a first receiving subunit, configured to receive a login request of a first object based on a first network channel through a proxy client deployed on a jump server, where the first network channel represents a channel from a target network to a virtual private cloud network, and the first object is a user on the target network side.
[0126] Optionally, in the network asset processing device provided in the fourth embodiment of the present application, the first processing unit 502 includes: a first determination subunit, configured to determine whether there is target connection parameter information identical to the identification information of a target object in the connection parameter information through the proxy client, to obtain a determination result; a first determination subunit, configured to, if the determination result indicates the existence of the target connection parameter information, authenticate the target object as an authentication result; a second determination subunit, configured to, if the determination result indicates the non-existence of the target connection parameter information, authenticate the target object as not passing the authentication as the authentication result.
[0127] Optionally, in the network asset processing device provided in the fourth embodiment of the present application, the second processing unit 504 includes: a first forwarding subunit, configured to forward an operation and maintenance request to a proxy server deployed on a bastion host based on a second network channel through a proxy client deployed on a jump server, where the second network channel represents a channel from a virtual private cloud network to a target network.
[0128] Optionally, in the network asset processing device provided in the fourth embodiment of the present application, the device further includes: a first construction unit, configured to, before receiving a login request of a target object through a jump server of a virtual private cloud network, respond to a first network channel request sent by a bastion host, and establish a first network channel based on a reverse access technology; a second construction unit, configured to send a second network channel request to the bastion host, so that the bastion host responds to the second network channel request, and establish a second network channel based on a single-channel connection technology.
[0129] It should be noted here that the above-mentioned first receiving unit 501, first processing unit 502, second receiving unit 503, and second processing unit 504 correspond to steps S101 to S104 in Embodiment 1. The above units and the corresponding steps have the same implemented examples and application scenarios, but are not limited to the content disclosed in the above-mentioned Embodiment 1.
[0130] It should be noted that the preferred implementation schemes involved in the above embodiments of the present application are the same as the schemes, application scenarios, and implementation processes provided in Embodiment 1, but are not limited to the schemes provided in Embodiment 1.
[0131] Embodiment 5
[0132] According to an embodiment of the present application, there is also provided a processing device for network assets for implementing the above-mentioned processing method of network assets, as Figure 6 shown. The device includes: a third receiving unit 601, a third processing unit 602, and a fourth processing unit 603.
[0133] The third receiving unit 601 is configured to receive, through a bastion host of a target network, an operation and maintenance request of a target object sent by a jump server of a virtual private cloud network, where the operation and maintenance request at least includes asset information of the target network asset and operation information of the target operation and maintenance operation;
[0134] The third processing unit 602 is configured to perform permission verification on the operation and maintenance request according to the asset information and the operation information to obtain a verification result;
[0135] The fourth processing unit 603 is configured to, if the verification result indicates that the target object has the operation permission to perform the target operation and maintenance operation on the target network asset, perform the target operation and maintenance operation on the target network asset.
[0136] In the processing device for network assets provided in Embodiment 5 of the present application, the third receiving unit 601 receives, through a bastion host of a target network, an operation and maintenance request of a target object sent by a jump server of a virtual private cloud network, where the operation and maintenance request at least includes asset information of the target network asset and operation information of the target operation and maintenance operation; the third processing unit 602 performs permission verification on the operation and maintenance request according to the asset information and the operation information to obtain a verification result; the fourth processing unit 603, if the verification result indicates that the target object has the operation permission to perform the target operation and maintenance operation on the target network asset, performs the target operation and maintenance operation on the target network asset. In this solution, by deploying a jump server as a single login entry point, all remote connections to the bastion host need to be accessed through the jump server, restricting user logins to the cloud VPC environment, achieving a restriction on the user login area, providing better security isolation for the bastion host, improving the security factor of the bastion host, protecting the security of internal servers, improving the security of network asset operation and maintenance, and solving the pain point that in the current cloud computing environment, users cannot use the bastion host of the classic network (i.e., the target network) to operate and maintain classic network assets in the cloud VPC network, achieving the purpose of restricting user logins to the cloud VPC environment, thereby realizing the operation and maintenance of classic network assets in the cloud VPC network through the bastion host of the classic network and improving the security of network asset operation and maintenance, and further solving the technical problem that in the related art, when operating and maintaining network assets in a single network through a bastion host, the user login entry is not restricted, resulting in low security of network asset operation and maintenance.
[0137] Optionally, in the network asset processing device provided in Embodiment 5 of the present application, the third receiving unit 601 includes: a second receiving subunit, configured to receive an operation and maintenance request of a target object sent by a jump server of a virtual private cloud network through a proxy server deployed on a bastion host based on a second network channel, where the second network channel represents a channel from the virtual private cloud network to the target network.
[0138] Optionally, in the network asset processing device provided in Embodiment 5 of the present application, the third processing unit 602 includes: a second determination subunit, configured to determine whether asset information and operation information meet the operation and maintenance permissions through a proxy server deployed on a bastion host; a third determination subunit, configured to, if the asset information and operation information meet the operation and maintenance permissions, use that the target object has the operation permission to perform a target operation and maintenance operation on the target network asset as a verification result; a fourth determination subunit, configured to, if the asset information and operation information do not meet the operation and maintenance permissions, use that the target object does not have the operation permission to perform a target operation and maintenance operation on the target network asset as a verification result.
[0139] Optionally, in the network asset processing device provided in Embodiment 5 of the present application, the device further includes: a fourth receiving unit, configured to, before receiving an operation and maintenance request of a target object sent by a jump server of a virtual private cloud network through a bastion host of a target network, receive a login request of a first object through a proxy server and forward the login request of the first object to a proxy client based on a first network channel, where the first network channel represents a channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
[0140] Optionally, in the network asset processing device provided in Embodiment 5 of the present application, the device further includes: a third construction unit, configured to, before receiving an operation and maintenance request of a target object sent by a jump server of a virtual private cloud network through a bastion host of a target network, send a first network channel request to the jump server, so that the jump server responds to the first network channel request and establishes a first network channel based on reverse access technology; a fourth construction unit, configured to respond to a second network channel request sent by the jump server and establish a second network channel based on single-channel connection technology.
[0141] It should be noted here that the above-mentioned third receiving unit 601, third processing unit 602, and fourth processing unit 603 correspond to steps S301 to S303 in Embodiment 2. The above-mentioned units and the corresponding steps have the same implemented instances and application scenarios, but are not limited to the content disclosed in the above-mentioned Embodiment 2.
[0142] It should be noted that the preferred implementation schemes involved in the above embodiments of the present application are the same as the schemes, application scenarios, and implementation processes provided in Embodiment 2, but are not limited to the schemes provided in Embodiment 2.
[0143] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.
[0144] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0145] In the several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0146] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0147] In addition, the functional units in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0148] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. And the aforementioned storage medium includes: USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks or optical disks and other various media that can store program codes.
[0149] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A method for processing network assets, characterized in that, including: Receiving a login request of a target object through a jump server of a virtual private cloud network, where the login request at least includes identification information of the target object; Authenticating the identity of the target object according to connection parameter information and the identification information of the target object to obtain an identity authentication result, where the connection parameter information is used for login verification; If the identity authentication result indicates that the target object passes the identity authentication, then responding to the login request and receiving an operation and maintenance request of the target object, where the operation and maintenance request at least includes asset information of a target network asset and operation information of a target operation and maintenance operation, the target network asset is a network asset of a target network, and the target network is a network without logical isolation; Forwarding the operation and maintenance request to a bastion host of the target network, where the bastion host is used to perform the target operation and maintenance operation on the target network asset according to the asset information and the operation information.
2. The method according to claim 1, wherein A proxy client is deployed on the jump server, and the target object at least includes a first object. Receiving a login request of a target object through a jump server of a virtual private cloud network includes: Receiving the login request of the first object through the proxy client deployed on the jump server based on a first network channel, where the first network channel represents a channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
3. The method according to claim 2, characterized in that, The connection parameter information is configured in the proxy client. Authenticating the identity of the target object according to connection parameter information and the identification information of the target object to obtain an identity authentication result includes: Judging whether there is target connection parameter information identical to the identification information of the target object in the connection parameter information through the proxy client to obtain a judgment result; If the judgment result indicates that the target connection parameter information exists, then taking that the target object passes the identity authentication as the identity authentication result; If the judgment result indicates that the target connection parameter information does not exist, then taking that the target object fails the identity authentication as the identity authentication result.
4. The method according to claim 2, characterized in that A proxy server is deployed on the bastion host, and the proxy server is used to communicate with the proxy client. Forwarding the operation and maintenance request to a bastion host of the target network includes: Forwarding the operation and maintenance request to the proxy server deployed on the bastion host through the proxy client deployed on the jump server based on a second network channel, where the second network channel represents a channel from the virtual private cloud network to the target network.
5. The method according to claim 4, wherein Before receiving a login request of a target object through a jump server of a virtual private cloud network, the method further includes: Responding to a first network channel request sent by the bastion host and establishing the first network channel based on reverse access technology; Sending a second network channel request to the bastion host so that the bastion host responds to the second network channel request and establishes the second network channel based on single-channel connection technology.
6. A method for processing network assets, characterized in that, including: Receive the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network, where the operation and maintenance request at least includes the asset information of the target network asset and the operation information of the target operation and maintenance operation; Perform permission verification on the operation and maintenance request according to the asset information and the operation information to obtain a verification result; If the verification result indicates that the target object has the operation permission to perform the target operation and maintenance operation on the target network asset, perform the target operation and maintenance operation on the target network asset.
7. The method according to claim 6, characterized in that, A proxy server is deployed on the bastion host, where receiving the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network includes: Receive the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the proxy server deployed on the bastion host based on the second network channel, where the second network channel represents the channel from the virtual private cloud network to the target network.
8. The method according to claim 7, characterized in that The operation and maintenance permissions for permission management are configured in the proxy server, where performing permission verification on the operation and maintenance request according to the asset information and the operation information to obtain a verification result includes: Judge whether the asset information and the operation information meet the operation and maintenance permissions through the proxy server deployed on the bastion host; If the asset information and the operation information meet the operation and maintenance permissions, use the operation permission that the target object has to perform the target operation and maintenance operation on the target network asset as the verification result; If the asset information and the operation information do not meet the operation and maintenance permissions, use the operation permission that the target object does not have to perform the target operation and maintenance operation on the target network asset as the verification result.
9. The method according to claim 7, characterized in that, A proxy client is deployed on the jump server, and the target object at least includes a first object. Before receiving the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network, the method further includes: Receive the login request of the first object through the proxy server and forward the login request of the first object to the proxy client based on the first network channel, where the first network channel represents the channel from the target network to the virtual private cloud network, and the first object is a user on the target network side.
10. The method according to claim 9, characterized in that Before receiving the operation and maintenance request of the target object sent by the jump server of the virtual private cloud network through the bastion host of the target network, the method further includes: Send a first network channel request to the jump server so that the jump server responds to the first network channel request and establishes the first network channel based on reverse access technology; Respond to the second network channel request sent by the jump server and establish the second network channel based on single-channel connection technology.
11. A processing system for network assets, characterized in that, Include: Jump server for virtual private cloud network. An agent client is deployed on the jump server, and connection parameter information for login verification is configured in the agent client. The jump server is used to receive a login request from a target object through the agent client, authenticate the identity of the target object based on the connection parameter information and the identity information of the target object. If the target object passes the identity authentication, the jump server responds to the login request, receives the operation and maintenance request of the target object, and forwards the operation and maintenance request to the bastion host of the target network; The bastion host of the target network. An agent server is deployed on the bastion host, and operation and maintenance permissions for permission management are configured in the agent server. The bastion host is used to receive the operation and maintenance request through the agent server, and determine whether the asset information of the target network asset and the operation information of the target operation and maintenance operation included in the operation and maintenance request meet the operation and maintenance permissions. If the asset information and the operation information meet the operation and maintenance permissions, the bastion host performs the target operation and maintenance operation on the target network asset.
12. A processing device for network assets, characterized in that, Comprising: A first receiving unit, configured to receive a login request from a target object through a jump server of a virtual private cloud network, where the login request at least includes identity information of the target object; A first processing unit, configured to authenticate the identity of the target object based on connection parameter information and the identity information of the target object to obtain an identity authentication result, where the connection parameter information is used for login verification; A second receiving unit, configured to, if the identity authentication result indicates that the target object passes the identity authentication, respond to the login request and receive the operation and maintenance request of the target object, where the operation and maintenance request at least includes asset information of a target network asset and operation information of a target operation and maintenance operation, the target network asset is a network asset of a target network, and the target network is a network that is not logically isolated; A second processing unit, configured to forward the operation and maintenance request to the bastion host of the target network, where the bastion host is used to perform the target operation and maintenance operation on the target network asset based on the asset information and the operation information.
13. A processing device for network assets, characterized in that, Comprising: A third receiving unit, configured to receive an operation and maintenance request of a target object sent by a jump server of a virtual private cloud network through a bastion host of a target network, where the operation and maintenance request at least includes asset information of a target network asset and operation information of a target operation and maintenance operation; A third processing unit, configured to perform permission verification on the operation and maintenance request based on the asset information and the operation information to obtain a verification result; A fourth processing unit, configured to, if the verification result indicates that the target object has the operation permission to perform the target operation and maintenance operation on the target network asset, perform the target operation and maintenance operation on the target network asset.