Operation and maintenance method, device and equipment of Internet of Things platform, medium and product
By creating mirror instance accounts and configuring operation and maintenance permissions in the Internet of Things platform, the operation and maintenance management process of user accounts is simulated, and the problem of low security in operation and maintenance management in the existing technology is solved, achieving higher security and stability.
Patent Information
- Application Number
- CN202510337711.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-07-08
AI Technical Summary
The operation and maintenance management of IoT platforms in the prior art is low because they need to log in for each account, resulting in frequent transmission and login operations on account confidential information, which poses security risks.
By obtaining user privacy authorization information, create a mirror instance account corresponding to the user account, configure corresponding operation and maintenance permissions, and perform operation and maintenance operations within the operation and maintenance permissions, simulate the operation and maintenance management process of the user account and avoid frequent logins.
It improves the security of IoT operation and maintenance management, ensures the security of user account information, and avoids multiple frequent account login operations.
Smart Images

Figure CN120277710A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet of Things technology, and in particular, to an operation and maintenance method, device, equipment, medium and product for an Internet of Things platform. Background Art
[0002] In the actual operation scenario of an Internet of Things platform, a user may have multiple accounts, and different accounts are used for different business modules or service scenarios. When a user reports a problem with an account, the operation and maintenance platform needs to check each of the user's multiple accounts one by one to ensure accurate problem location.
[0003] In the prior art, the method for checking each account of a user is as follows: obtain the account password information of different user accounts, and log in to the corresponding accounts one by one for problem checking.
[0004] Since the problem checking method in the prior art requires logging in to each account, there is a technical problem of low security in Internet of Things operation and maintenance management in the prior art. Summary of the Invention
[0005] Embodiments of this application provide an operation and maintenance method, device, equipment, medium and product for an Internet of Things platform, so as to achieve the technical effect of improving the security of Internet of Things operation and maintenance management.
[0006] In a first aspect, an embodiment of this application provides an operation and maintenance method for an Internet of Things platform, including:
[0007] In response to a user's operation and maintenance request, obtain the user's privacy authorization information; the operation and maintenance request includes at least operation and maintenance requirements;
[0008] Based on the user's privacy authorization information, create a mirror instance account corresponding to the user account; the mirror instance account has the same operation permissions and operation environment as the user account;
[0009] According to the operation and maintenance requirements, configure first operation and maintenance permissions for the mirror instance account;
[0010] Perform operation and maintenance operations on the mirror instance account within the first operation and maintenance permissions.
[0011] In a possible implementation manner, in response to a user's operation and maintenance request, obtaining the user's privacy authorization information includes:
[0012] In response to a user's operation and maintenance request, send a privacy authorization request to the user;
[0013] In response to the user's operation on the privacy configuration switch, obtain the user's privacy authorization information.
[0014] In a possible implementation, the privacy authorization information at least includes the user's account list and account configuration information. The account list includes the user's sub - user accounts, and the operation permissions corresponding to the sub - user accounts; the account configuration information is the information required to create a mirror instance account.
[0015] Based on the user's privacy authorization information, creating a mirror instance account corresponding to the user's account includes:
[0016] Based on the account configuration information and the operation permissions corresponding to the sub - user accounts, creating a mirror instance account corresponding to each sub - user account.
[0017] In a possible implementation, after creating a mirror instance account corresponding to each sub - user account based on the account configuration information and the operation permissions corresponding to the sub - user accounts, the method further includes:
[0018] When the number of created mirror instance accounts exceeds a preset number threshold, sending an alarm message to the operation and maintenance personnel.
[0019] In a possible implementation, after sending an alarm message to the operation and maintenance personnel, the method further includes:
[0020] In response to the operation and maintenance personnel's request to increase the number of account creations, determining whether the number of account creations can be increased according to the account creation number limit included in the user's privacy authorization information;
[0021] If so, sending the allowed increased number of account creations to the operation and maintenance personnel;
[0022] If not, sending a prohibition message to the operation and maintenance personnel to prohibit the operation and maintenance personnel from creating mirror instance accounts.
[0023] In a possible implementation, configuring first operation and maintenance permissions for the mirror instance account according to the operation and maintenance requirements includes:
[0024] Based on a preset operation and maintenance permission rule library, determining the first operation and maintenance permissions corresponding to the operation and maintenance requirements;
[0025] Configuring the first operation and maintenance permissions to the mirror instance account.
[0026] In a possible implementation, based on a preset operation and maintenance permission rule library, determining the first operation and maintenance permissions corresponding to the operation and maintenance requirements includes:
[0027] According to the operation and maintenance problems included in the operation and maintenance requirements, determining the security level, sensitivity level, and core degree corresponding to the operation and maintenance problems from the operation and maintenance permission rule library;
[0028] According to the security level, sensitivity level, and core degree, determining the first operation and maintenance permissions.
[0029] In a possible implementation, after configuring the first operation and maintenance permission for the mirror instance account according to the operation and maintenance requirements, the method further includes:
[0030] Receiving a permission extension request, where the permission extension request includes a target operation and maintenance operation;
[0031] When it is determined that the target operation and maintenance operation conforms to the preset permission adjustment policy, updating the first operation and maintenance permission of the mirror instance account to a second operation and maintenance permission, where the second operation and maintenance permission is an extended operation and maintenance permission of the first operation and maintenance permission;
[0032] When it is determined that the target operation and maintenance operation does not conform to the permission adjustment policy, generating a permission extension response, where the permission extension response at least includes a message for refusing to extend the permission and risk notification information.
[0033] In a possible implementation, after performing an operation and maintenance operation on the mirror instance account within the first operation and maintenance permission, the method further includes:
[0034] After monitoring the operation and maintenance operation information for the mirror instance account, synchronizing the operation and maintenance operation information to each system associated with the user account.
[0035] In a possible implementation, before creating a mirror instance account corresponding to the user account based on the user privacy authorization information, the method further includes:
[0036] Obtaining the operation and maintenance operation order number input by the operation and maintenance personnel.
[0037] In a second aspect, an operation and maintenance device for an Internet of Things platform provided by an embodiment of the present application includes:
[0038] An obtaining module, configured to obtain user privacy authorization information in response to a user's operation and maintenance request; the operation and maintenance request at least includes operation and maintenance requirements;
[0039] A first processing module, configured to create a mirror instance account corresponding to the user account based on the user privacy authorization information; the mirror instance account has the same operation permissions and operation environment as the user account;
[0040] A second processing module, configured to configure a first operation and maintenance permission for the mirror instance account according to the operation and maintenance requirements;
[0041] A third processing module, configured to perform an operation and maintenance operation on the mirror instance account within the first operation and maintenance permission.
[0042] In a possible implementation, the obtaining module is further configured to:
[0043] In response to the user's operation and maintenance request, send a privacy authorization request to the user;
[0044] In response to a user's operation on the privacy configuration switch, obtain the user's privacy authorization information.
[0045] In a possible implementation, the privacy authorization information at least includes the user's account list and account configuration information. The account list includes the user's sub - user accounts, and the operation permissions corresponding to the sub - user accounts; the account configuration information is the information required to create a mirror instance account;
[0046] The first processing module is further configured to:
[0047] Based on the account configuration information and the operation permissions corresponding to the sub - user accounts, create mirror instance accounts corresponding to each sub - user account.
[0048] In a possible implementation, the first processing module is further configured to:
[0049] When the number of created mirror instance accounts exceeds a preset number threshold, send an alarm message to the operation and maintenance personnel.
[0050] In a possible implementation, the first processing module is further configured to:
[0051] In response to a request from the operation and maintenance personnel to increase the number of account creations, determine whether the number of account creations can be increased according to the account creation number limit included in the user privacy authorization information;
[0052] If so, send the allowed increased number of account creations to the operation and maintenance personnel;
[0053] If not, send a prohibition message to the operation and maintenance personnel to prohibit the operation and maintenance personnel from creating mirror instance accounts.
[0054] In a possible implementation, the second processing module is further configured to:
[0055] Based on a preset operation and maintenance permission rule library, determine the first operation and maintenance permission corresponding to the operation and maintenance requirements;
[0056] Configure the first operation and maintenance permission to the mirror instance account.
[0057] In a possible implementation, the second processing module is further configured to:
[0058] According to the operation and maintenance problems included in the operation and maintenance requirements, determine the security level, sensitivity level, and core degree corresponding to the operation and maintenance problems from the operation and maintenance permission rule library;
[0059] According to the security level, sensitivity level, and core degree, determine the first operation and maintenance permission.
[0060] In a possible implementation, the second processing module is further configured to:
[0061] Receive a permission extension request, where the permission extension request includes a target operation and maintenance operation;
[0062] When it is determined that the target operation and maintenance operation conforms to the preset permission adjustment policy, update the first operation and maintenance permission of the mirror instance account to the second operation and maintenance permission, where the second operation and maintenance permission is an extended operation and maintenance permission of the first operation and maintenance permission;
[0063] When it is determined that the target operation and maintenance operation does not conform to the permission adjustment policy, generate a permission extension response, where the permission extension response includes at least a message for refusing to extend the permission and risk notification information.
[0064] In a possible implementation manner, the third processing module is further configured to:
[0065] After monitoring the operation and maintenance operation information for the mirror instance account, synchronize the operation and maintenance operation information to each system associated with the user account.
[0066] In a possible implementation manner, the first processing module is further configured to:
[0067] Obtain the operation and maintenance operation order number input by the operation and maintenance personnel.
[0068] In a third aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor;
[0069] The memory stores computer-executable instructions;
[0070] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and various possible implementation manners in the first aspect.
[0071] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, where computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the above first aspect and various possible implementation manners in the first aspect.
[0072] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the above first aspect and various possible implementation manners in the first aspect.
[0073] The operation and maintenance method, apparatus, device, medium and product of the Internet of Things platform provided by the embodiments of the present application. The method responds to the operation and maintenance request of the user, obtains the user privacy authorization information, creates an image instance account corresponding to the user account based on the user privacy authorization information, configures the first operation and maintenance permissions for the image instance account according to the operation and maintenance requirements, and performs the operation and maintenance operations on the image instance account within the first operation and maintenance permissions. Compared with the existing method of obtaining user account information and logging in to each account for operation and maintenance management, the present application uses the user privacy authorization information to create an image instance account, and performs the operation and maintenance operations in the form of image simulation without logging in to the user account, which not only ensures the security of the user account information, but also avoids frequent account logins, thus achieving the technical effect of improving the security of the Internet of Things operation and maintenance management. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0075] Figure 1 Flow diagram of the operation and maintenance method of the Internet of Things platform provided by the present application Figure 1 ;
[0076] Figure 2 Flow diagram of the operation and maintenance method of the Internet of Things platform provided by the present application Figure 2 ;
[0077] Figure 3 Flow diagram of the operation and maintenance method of the Internet of Things platform provided by the present application Figure 3 ;
[0078] Figure 4 Flow diagram of the operation and maintenance method of the Internet of Things platform provided by the present application Figure 4 ;
[0079] Figure 5 Structural diagram of the operation and maintenance device of the Internet of Things platform provided by the present application;
[0080] Figure 6 Structural diagram of the electronic device provided by the present application.
[0081] Through the above accompanying drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and the written description are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0082] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0083] In the prior art, when an Internet of Things user initiates an operation and maintenance request, the method for performing operation and maintenance management on multiple accounts of the Internet of Things user is as follows: sending an account password authorization request to the Internet of Things user, obtaining the account password information of multiple accounts associated with the Internet of Things user, logging in to each account of the user in sequence, and performing operation and maintenance management in each account, so as to troubleshoot and handle the operation and maintenance problems feedback by the Internet of Things user.
[0084] However, in actual Internet of Things operation and maintenance management, each time the user's account is logged in, the transmission of account password information and the login operation are required. There is a risk of interruption or leakage of account password information in case of network anomalies. Therefore, there is a technical problem of low security in Internet of Things operation and maintenance management in the prior art.
[0085] In view of the above technical problems, the present application proposes the following technical concept: aiming at the technical problem of low security in operation and maintenance management caused by the account password login method in the prior art. The present application proposes a method for improving the security of Internet of Things operation and maintenance management, specifically: when the user initiates an operation and maintenance request, obtaining the user privacy authorization information corresponding to the user, creating a mirror instance account corresponding to the user account according to the user privacy authorization information, and the operation permissions and operation environment of the created mirror instance account are the same as those of the user account; according to the operation and maintenance requirements in the operation and maintenance request, configuring corresponding operation and maintenance permissions for the mirror instance account, and performing operation and maintenance operations on the mirror instance account within the operation and maintenance permissions. Compared with the prior art, the present application uses the method of creating a mirror instance to simulate the operation and maintenance management process of the user account, and through the consistent operation environment and operation permissions, performs virtualized operation and maintenance management on the user account, so as to manage and operate the operation and maintenance requirements of the user account in the mirror instance account, and can perform operation and maintenance management on multiple accounts of the user without obtaining the account password information of the user account, thereby achieving the technical effect of improving the security of Internet of Things operation and maintenance management.
[0086] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0087] Figure 1Flow diagram of the operation and maintenance method for the Internet of Things platform provided by this application Figure 1 , such as Figure 1 shown, this method includes:
[0088] S101. In response to the user's operation and maintenance request, obtain the user's privacy authorization information.
[0089] In this step, the operation and maintenance request at least includes the operation and maintenance requirements; the user's privacy authorization information at least includes the user's account information.
[0090] The implementation ways to obtain the user's privacy authorization information can be any one of the web page, application, SMS, and email.
[0091] Exemplarily, the way to obtain the user's privacy authorization information using the web page can be:
[0092] S1011. In response to the user's operation and maintenance request, pop up an authorization prompt box and an authorization prompt button on the interface where the user submits the operation and maintenance request.
[0093] In this step, the authorization prompt box can contain: information prompting the user to perform privacy authorization, and risk notification information.
[0094] S1012. When the user clicks the authorization prompt button and the information indicated by the authorization prompt button is unified authorization, obtain the user's privacy authorization information in the operation and maintenance management platform.
[0095] S102. Based on the user's privacy authorization information, create a mirror instance account corresponding to the user's account.
[0096] In this step, the mirror instance account has the same operation permissions and operation environment as the user's account.
[0097] Optionally, before creating a mirror instance account corresponding to the user's account based on the user's privacy authorization information, the operation and maintenance order number input by the operation and maintenance personnel can also be obtained.
[0098] Among them, the operation and maintenance order number is used to be associated with the operation and maintenance operation process of the mirror instance account after obtaining the user's privacy authorization information to ensure the traceability of the operation.
[0099] Exemplarily, after obtaining the operation and maintenance order number, record the operations of the operation and maintenance personnel in the mirror instance account in the form of logs, and store the operation and maintenance order number in the logs; if it is necessary to trace the operation process, the operation and maintenance operation logs corresponding to a specific time, a specific user, and the user's specific account can be found through the operation and maintenance order number query method.
[0100] It should be noted that the operation and maintenance order number can be obtained by: obtaining the operation and maintenance order number entered by the operation and maintenance personnel, or generating a unique corresponding operation and maintenance order number for a user non-user account.
[0101] S103: According to the operation and maintenance requirements, configure the first operation and maintenance authority for the image instance account.
[0102] In this step, the operation and maintenance requirements at least include operation and maintenance problems, where the types of operation and maintenance problems can be: equipment management problems, data anomaly problems, account security problems, service subscription and billing problems, equipment failure repairs, configuration change requests, security vulnerability feedback, and energy consumption anomaly feedback.
[0103] Among them, operation and maintenance requirements refer to the physical network usage requirements that users feedback to the physical network operation and maintenance management platform through various means, including various troubleshooting requirements and equipment management requirements.
[0104] Optionally, a possible implementation method of configuring the first operation and maintenance permission for the image instance account is:
[0105] S1031. Determine a first operation and maintenance authority corresponding to an operation and maintenance requirement based on a preset operation and maintenance authority rule library.
[0106] In this step, the first operation and maintenance permission refers to a set of basic permissions assigned to the image instance account based on operation and maintenance requirements; illustratively, for low-sensitivity issues, the first operation and maintenance permission is to read some non-critical business data and view system logs; for high-sensitivity issues involving core business data, the first operation and maintenance permission is strictly limited to reading specific key data fields and executing specific diagnostic commands.
[0107] Optionally, a possible implementation manner of determining the first operation and maintenance authority corresponding to the operation and maintenance requirement is:
[0108] a1. Based on the operation and maintenance issues included in the operation and maintenance requirements, determine the security level, sensitivity level and core degree corresponding to the operation and maintenance issues from the operation and maintenance authority rule library.
[0109] In this step, the operation and maintenance permission rule base includes various types of operation and maintenance issues; the security level, sensitivity level, and core level corresponding to each operation and maintenance issue; and the permission restrictions corresponding to the security level, sensitivity level, and core level.
[0110] Among them, the security level indicates the degree of security threat that an operation and maintenance operation may pose to the system or user data, with a focus on whether the operation will trigger security vulnerabilities, data leakage, or system damage; the sensitivity level indicates the sensitivity of the data or resources involved in the operation and maintenance operation, measuring the privacy, compliance, or business losses that may be caused by data leakage or misoperation; the core degree indicates the importance of the resources or services involved in the operation and maintenance operation to the business, measuring the impact that operation errors may have on business continuity, revenue, or reputation.
[0111] Exemplarily, the security level can be used to limit the validity period of the operation and maintenance permissions and whether the operation and maintenance permissions trigger an approval process; the sensitivity level can be used to limit the data access scope corresponding to the operation and maintenance permissions, the read and write restrictions on the data, and the data transmission method; the core degree can be used to limit the access personnel of the operation and maintenance permissions, the specific access time period of the operation and maintenance permissions, the access devices of the operation and maintenance permissions, and the data backup method corresponding to the operation and maintenance permissions.
[0112] a2. Determine the first operation and maintenance permission according to the security level, sensitivity level, and core degree.
[0113] Exemplarily, when the operation and maintenance problem included in the operation and maintenance requirement is: an account security problem, the security level corresponding to the operation and maintenance problem determined from the operation and maintenance permission rule library is high, indicating that the operation and maintenance problem involves user privacy and system security; the sensitivity level is high, indicating that the operation and maintenance problem involves account operations and device permission control; the core degree is medium, indicating that the account involved in the operation and maintenance problem is an ordinary account, and the device associated with this account is a non-core device. The operation and maintenance permissions corresponding to the security level are: temporary permissions are required, operations need to be approved, and audit logs need to be compulsorily recorded; the operation and maintenance permissions corresponding to the sensitivity level are: only allowing reading of account operation logs and prohibiting modification of account data; the operation and maintenance permissions corresponding to the core degree are: restricting the permission scope to the devices associated with the user account; combining the operation and maintenance permissions corresponding to the security level, sensitivity level, and core degree to obtain the first operation and maintenance permission.
[0114] S1032. Configure the first operation and maintenance permission to the mirror instance account.
[0115] In this step, the method of configuring the first operation and maintenance permission to the mirror instance account can be: writing the first operation and maintenance permission into the configuration file of the mirror instance account.
[0116] Optionally, the method of configuring the first operation and maintenance permission to the mirror instance account can also be dynamic permission configuration. A possible implementation method of dynamic permission configuration is:
[0117] b1. Generate a permission template in a preset format based on the first operation and maintenance permission.
[0118] b2. Bind the permission template to the mirror instance account by means of file call or interface call.
[0119] S104. Perform operation and maintenance operations on the mirror instance account within the first operation and maintenance permission.
[0120] In this step, performing operation and maintenance operations within the first operation and maintenance permission means that within the scope of permission restrictions, operating on the data and devices within the scope of operation permission to troubleshoot and handle operation and maintenance problems.
[0121] Exemplarily, the result after configuring the first operation and maintenance permission to the mirror instance account is: only allowing log queries and prohibiting writing and exporting; operations require approval; the validity period of the permission is 30 minutes. Then the operation and maintenance operations on the mirror instance account can be: querying log information within the restricted time.
[0122] Optionally, after performing the operation and maintenance operations, reverse synchronization can also be performed based on the information generated by the operation and maintenance operations. A possible implementation method of reverse synchronization is: after detecting the operation and maintenance operation information for the mirror instance account, synchronizing the operation and maintenance operation information to each system associated with the user account.
[0123] Exemplarily, the implementation method of synchronizing the operation and maintenance operation information to each system associated with the user account can be:
[0124] c1. Collect the operation and maintenance operation information generated during the operation and maintenance process.
[0125] Among them, the operation and maintenance operation information is a multi-dimensional information, including: operation behavior, permission change, configuration change, and system identification information; among them, the system identification refers to the device identification corresponding to the device operated by the mirror instance account and the tenant identification corresponding to the tenant to which the device belongs.
[0126] c2. Based on the preset synchronization rules and the multi-system mapping relationship, sort out and integrally analyze the operation and maintenance operation information to obtain the operation and maintenance operation information after standardized processing.
[0127] In this step, the method of sorting out and integrally analyzing is specifically: performing multi-system mapping on the operation and maintenance operation information to ensure that the permission changes, configuration changes, operation behaviors involved in the operation and maintenance operation information correspond to multiple systems associated with the user account, and at the same time ensuring the consistency between multiple systems associated with the user account and the mirror instance user based on the preset synchronization rules.
[0128] c3. Push the processed operation and maintenance operation information to each system associated with the user account.
[0129] In this step, each system determines the corresponding operation and maintenance operations within each system through information parsing, and synchronizes the operation and maintenance operations to the system internal to achieve reverse synchronization with the mirror instance account.
[0130] c4. During the reverse synchronization process, if information transmission fails or the system response is abnormal, record the current exception and generate an exception log; initiate reverse synchronization again according to the preset retry policy until the synchronization and update of multiple systems corresponding to the user account are completed.
[0131] In this step, the preset retry amount can be: persist the operation and maintenance operation information to be transmitted into the local queue and resynchronize the information when the network resumes.
[0132] The operation and maintenance method of the Internet of Things platform provided by the embodiments of the present application responds to the user's operation and maintenance request, obtains the user privacy authorization information, creates a mirror instance account corresponding to the user account based on the user privacy authorization information, configures the first operation and maintenance permissions for the mirror instance account according to the operation and maintenance requirements, and performs the operation and maintenance operations on the mirror instance account within the first operation and maintenance permissions. Compared with the method of obtaining user account information and logging in to each account for operation and maintenance management in the prior art, the present application uses the user privacy authorization information to create a mirror instance account, and performs operation and maintenance operations in the form of mirror simulation without logging in to the user account, which not only ensures the security of user account information but also avoids frequent account logins, thus achieving the technical effect of improving the security of Internet of Things operation and maintenance management.
[0133] Figure 2 It is a flowchart of the operation and maintenance method of the Internet of Things platform provided by the present application Figure 2 , on the basis of the above Figure 1 shown embodiment, this embodiment further explains the acquisition of user privacy authorization information and the creation of mirror instance accounts in steps S101 and S102. As Figure 2 shown, the method includes:
[0134] S201. Respond to the user's operation and maintenance request and send a privacy authorization request to the user.
[0135] In this step, the method of sending a privacy authorization request to the user can be: send a privacy authorization request to the user by email and add an authorization button in the email; send a short-link-containing SMS, and the user jumps to the authorization page after clicking; embed the authorization page on the web page to clarify the request scope.
[0136] S202. Respond to the user's operation on the privacy configuration switch and obtain the user privacy authorization information.
[0137] In this step, the privacy authorization information at least includes the user's account list and account configuration information. The account list includes the user's sub-user accounts and the operation permissions corresponding to the sub-user accounts; the account configuration information is the information required to create a mirror instance account.
[0138] S203. Create a mirror instance account corresponding to each sub - user account based on the account configuration information and the operation permissions corresponding to the sub - user account.
[0139] In this step, the account configuration information may include: a preset quantity threshold for restricting the number of created mirror instance accounts; a default validity period for restricting the effective duration of the mirror instance accounts.
[0140] Optionally, a possible implementation of creating a mirror instance account is as follows:
[0141] S2031. Generate a minimized mirror instance account permission policy based on the operation permissions corresponding to the sub - user account.
[0142] Exemplarily, the mirror instance account permission policy generated based on the operation permissions of the sub - user account is: only allowing reading the logs of a specified device, only allowing restarting a specified device, and only allowing updating non - security - related configurations.
[0143] S2032. Create an independent mirror instance account for each sub - user account and bind the corresponding permission policy.
[0144] S2033. Store the account information corresponding to the created mirror instance account.
[0145] Exemplarily, the account information corresponding to the mirror instance account includes: a mirror instance account identifier, a sub - user account associated with the mirror instance account, a permission list corresponding to the mirror instance account, a creation time of the mirror instance account, an expiration time of the mirror instance account, and a device identifier associated with the mirror instance account.
[0146] After the creation of the mirror instance account is completed, verify whether the mirror instance account is effective. When the mirror instance account is not effective, prompt the operation and maintenance personnel to recreate the mirror instance account.
[0147] S204. When the number of created mirror instance accounts exceeds the preset quantity threshold, send an alarm message to the operation and maintenance personnel.
[0148] In this step, the channels for sending the alarm message to the operation and maintenance personnel can be: text message, email, and device - side push; the preset quantity threshold is the number of created mirror instance accounts within a default period, and the length of a period can be one day or one week.
[0149] Optionally, the alarm message corresponds to a preset response duration. When no feedback from the operation and maintenance personnel based on the alarm message is received within the preset response duration, the alarm message is escalated and the sending channel of the alarm message is changed.
[0150] Exemplarily, the current preset quantity threshold is 10, and 10 mirror instance accounts have been created; when creating the 11th mirror instance account, it is detected that the number of mirror instance accounts exceeds the preset quantity threshold, an alarm is triggered, and an alarm prompt box pops up on the mirror instance account creation page.
[0151] S205. In response to the request from the operation and maintenance personnel to increase the number of account creations, determine whether the number of account creations can be increased according to the account creation quantity limit included in the user privacy authorization information.
[0152] Optionally, a possible implementation manner for determining whether the number of account creations can be increased is as follows:
[0153] S2051. In response to the request from the operation and maintenance personnel to increase the number of account creations, obtain the number of accounts to be newly added.
[0154] S2052. Based on the user privacy authorization information, obtain the account creation quantity limit, and determine whether the number of accounts after the addition exceeds the account creation quantity limit.
[0155] S2053. If it exceeds the account creation quantity limit, determine that the number of account creations cannot be increased; if it does not exceed the account creation quantity limit, determine that the number of account creations can be increased.
[0156] S206. If so, send the allowed increased number of account creations to the operation and maintenance personnel.
[0157] In this step, when the increased number of accounts in the quantity increase request is within the allowed range, the allowed increased number of accounts is pushed to you.
[0158] S207. If not, send a prohibition message to the operation and maintenance personnel to prohibit the operation and maintenance personnel from creating mirror instance accounts.
[0159] In this step, when the increased number of accounts in the quantity increase request is not within the allowed range, the allowed range and the prohibition message are pushed to the operation and maintenance personnel.
[0160] In this embodiment, the creation quantity of mirror instance accounts is restricted by means of the account quantity limit; this avoids frequent access to user data caused by multiple creations of mirror instance accounts within the same period and reduces the risk of data leakage.
[0161] Figure 3 It is the flowchart of the operation and maintenance method for the Internet of Things platform provided by this application Figure 3 , on the basis of the above Figure 1 shown embodiment, the permission configuration in step S103 is further elaborated in detail. The method includes:
[0162] S301. Receive a permission extension request, which includes a target operation and maintenance operation.
[0163] In this step, the permission extension request includes: a target operation and maintenance operation, an extension reason, and associated information. Among them, the target operation and maintenance operation refers to the specific permission to be extended, the extension reason refers to the background and necessity of the operation and maintenance operation, and the associated information refers to the image instance account identifier, device identifier, and operation time.
[0164] Exemplarily, the target operation and maintenance operation in the permission extension request is: modifying the device configuration; the extension reason is: fixing the configuration error of the device; the associated information is: the identifier of the device, the identifier of the image instance account, and the operation time.
[0165] S302. When it is determined that the target operation and maintenance operation conforms to the preset permission adjustment policy, update the first operation and maintenance permission of the image instance account to the second operation and maintenance permission, where the second operation and maintenance permission is the extended operation and maintenance permission of the first operation and maintenance permission.
[0166] In this step, the preset permission adjustment policy includes: permitted operations, prohibited operations, and conditions for extending permissions. Among them, permitted operations refer to clarifying which operations can extend permissions, such as: restarting the device and modifying non-security configurations; prohibited operations refer to clarifying which operations are prohibited from extending permissions, such as: deleting logs and modifying security configurations; extension conditions refer to allowing extensions only when specific conditions are met, such as: permission extension requests submitted during working hours, and permission extension requests approved by the superior system.
[0167] Exemplarily, the permission extension request is: adding permission M1 for image instance account X1 to fix the device configuration error; based on the judgment of the preset permission adjustment policy, it is obtained that: the permission M1 corresponding to the target operation and maintenance operation is among the permitted operations, the operation time is within working hours, and the permission extension request has been approved by the superior system, then it is determined that the permission extension is successful, and the first operation and maintenance permission is updated to obtain the second operation and maintenance permission.
[0168] It should be noted that the extended second operation and maintenance permission has a time limit. When the time limit is exceeded, the second operation and maintenance permission is reset to the first operation and maintenance permission.
[0169] S303. When it is determined that the target operation and maintenance operation does not conform to the permission adjustment policy, generate a permission extension response.
[0170] In this step, the permission extension response includes at least a message refusing to extend permissions and risk notification information.
[0171] Exemplarily, for the mirrored instance account X2, permission M2 is added to reset the user password; based on the preset permission adjustment policy, it is determined that the permission M2 corresponding to the target operation and maintenance operation is among the prohibited operations, then it is determined that the extension fails, and a risk notification message and the conclusion of the extension failure are pushed to the operation and maintenance personnel.
[0172] In this embodiment, when the operation and maintenance personnel perform in-depth operation and maintenance operations through the operation and maintenance permission management method, the permission extension request of the operation and maintenance personnel is responded to, and the permission extension response is carried out according to the preset permission adjustment policy, so as to realize dynamic permission adjustment.
[0173] Figure 4 Flow schematic of the operation and maintenance method for the Internet of Things platform provided by this application Figure 4 , such as Figure 4 shown, the method includes:
[0174] A1. Receive an operation and maintenance request.
[0175] Specifically: In response to the operation and maintenance request of the user, obtain the user work order corresponding to the operation and maintenance request.
[0176] A2. Determine whether to obtain user privacy authorization information.
[0177] Specifically: The user sends a privacy authorization request, and in response to the user's operation on the privacy configuration switch, obtain the user privacy authorization information.
[0178] A3. Determine whether to obtain an operation and maintenance order number.
[0179] Specifically: Determine whether to obtain the operation and maintenance operation order number input by the operation and maintenance personnel.
[0180] A4. Create a mirrored instance account based on the user privacy authorization information.
[0181] Specifically: Based on the account configuration information in the user privacy authorization information and the operation permissions corresponding to the sub-user accounts, create a mirrored instance account corresponding to each sub-user account
[0182] A5. Determine whether the creation quantity of the mirrored instance accounts reaches the upper limit.
[0183] A6. When reaching the upper limit, send an alarm message.
[0184] A7. When not reaching the upper limit, allocate the operation and maintenance permissions corresponding to the mirrored instance accounts.
[0185] A8. Perform operation and maintenance operations in the mirrored instance accounts based on the operation and maintenance permissions.
[0186] A9. Record the operation and maintenance operation information and synchronize it to each system associated with the sub-user account.
[0187] A10. After the operation and maintenance operation is completed, the operation and maintenance permissions are recycled, and relevant logs are recorded based on the user work order and the operation and maintenance order number.
[0188] Figure 5 It is a schematic structural diagram of the operation and maintenance device of the Internet of Things platform provided by this application. As Figure 5 shown, the operation and maintenance device of the Internet of Things platform provided in this embodiment includes:
[0189] An acquisition module 501, configured to obtain user privacy authorization information in response to a user's operation and maintenance request; the operation and maintenance request includes at least operation and maintenance requirements.
[0190] A first processing module 502, configured to create a mirror instance account corresponding to the user account based on the user privacy authorization information; the mirror instance account has the same operation permissions and operation environment as the user account.
[0191] A second processing module 503, configured to configure first operation and maintenance permissions for the mirror instance account according to the operation and maintenance requirements.
[0192] A third processing module 504, configured to perform operation and maintenance operations on the mirror instance account within the first operation and maintenance permissions.
[0193] In a possible implementation manner, the acquisition module 501 is further configured to:
[0194] Send a privacy authorization request to the user in response to the user's operation and maintenance request.
[0195] Obtain user privacy authorization information in response to the user's operation on the privacy configuration switch.
[0196] In a possible implementation manner, the privacy authorization information includes at least the user's account list and account configuration information. The account list includes the user's sub-user accounts and the corresponding operation permissions for the sub-user accounts; the account configuration information is the information required to create the mirror instance account.
[0197] The first processing module 502 is further configured to:
[0198] Create mirror instance accounts corresponding to each sub-user account based on the account configuration information and the operation permissions corresponding to the sub-user accounts.
[0199] In a possible implementation manner, the first processing module 502 is further configured to:
[0200] When the number of created mirror instance accounts exceeds a preset number threshold, send an alarm message to the operation and maintenance personnel.
[0201] In a possible implementation manner, the first processing module 502 is further configured to:
[0202] In response to a request from an operation and maintenance personnel to increase the number of account creations, determine whether the number of account creations can be increased based on the account creation number limit included in the user privacy authorization information.
[0203] If so, send the allowed increased number of account creations to the operation and maintenance personnel.
[0204] If not, send a prohibition message to the operation and maintenance personnel to prohibit the operation and maintenance personnel from creating mirror instance accounts.
[0205] In a possible implementation, the second processing module 503 is further configured to:
[0206] Based on a preset operation and maintenance permission rule library, determine the first operation and maintenance permission corresponding to the operation and maintenance requirements;
[0207] Configure the first operation and maintenance permission to the mirror instance account.
[0208] In a possible implementation, the second processing module 503 is further configured to:
[0209] According to the operation and maintenance problems included in the operation and maintenance requirements, determine the security level, sensitivity level, and core degree corresponding to the operation and maintenance problems from the operation and maintenance permission rule library.
[0210] Determine the first operation and maintenance permission according to the security level, sensitivity level, and core degree.
[0211] In a possible implementation, the second processing module 503 is further configured to:
[0212] Receive a permission extension request, where the permission extension request includes a target operation and maintenance operation.
[0213] In the case where it is determined that the target operation and maintenance operation conforms to the preset permission adjustment policy, update the first operation and maintenance permission of the mirror instance account to the second operation and maintenance permission, where the second operation and maintenance permission is an extended operation and maintenance permission of the first operation and maintenance permission.
[0214] In the case where it is determined that the target operation and maintenance operation does not conform to the permission adjustment policy, generate a permission extension response, where the permission extension response at least includes a message for refusing to extend the permission and risk notification information.
[0215] In a possible implementation, the third processing module 504 is further configured to:
[0216] After monitoring the operation and maintenance operation information for the mirror instance account, synchronize the operation and maintenance operation information to each system associated with the user account.
[0217] In a possible implementation, the first processing module 502 is further configured to:
[0218] Obtain the operation and maintenance operation order number input by the operation and maintenance personnel.
[0219] The operation and maintenance device of the Internet of Things platform provided in this embodiment can execute the method provided in the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.
[0220] Figure 6 It is a schematic structural diagram of the electronic device provided in this application. As Figure 6 shown, the electronic device provided in this embodiment includes: at least one processor 601 and a memory 602. Optionally, the device further includes a communication component 603. Among them, the processor 601, the memory 602, and the communication component 603 are connected through a bus 604.
[0221] In the specific implementation process, at least one processor 601 executes the computer execution instructions stored in the memory 602, so that at least one processor 601 executes the above-mentioned operation and maintenance method of the Internet of Things platform or the test case generation method.
[0222] For the specific implementation process of the processor 601, reference can be made to the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.
[0223] In the above embodiment, it should be understood that the processor may be a central processing unit (English: Central Processing Unit, abbreviated as: CPU), and may also be other general-purpose processors, digital signal processors (English: Digital Signal Processor, abbreviated as: DSP), application specific integrated circuits (English: Application Specific Integrated Circuit, abbreviated as: ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0224] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0225] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience in representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.
[0226] This application also provides a computer program product, including a computer program, which implements the above-mentioned operation and maintenance method of the Internet of Things platform or the test case generation method when executed by a processor.
[0227] This application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When the processor executes the computer-executable instructions, the above-mentioned operation and maintenance method of the Internet of Things platform or the test case generation method is implemented.
[0228] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk or an optical disc. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0229] An exemplary readable storage medium is coupled to the processor, so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in a device.
[0230] The division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.
[0231] The unit described as a separation component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0232] In addition, in each embodiment of the present invention, each functional unit may be integrated into a processing unit, or each unit may physically exist alone, or two or more units may be integrated into one unit.
[0233] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or part of the technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0234] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes: various media such as ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0235] Finally, it should be noted that: After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily think of other implementation schemes of the present invention. The present invention aims to cover any variations, uses, or adaptations of the present invention. These variations, uses, or adaptations follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not disclosed in the present invention. It is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. An operation and maintenance method for an Internet of Things platform, characterized in that, Including: Upon receiving a user's operation and maintenance request, obtain the user's privacy authorization information; The operation and maintenance request at least includes operation and maintenance requirements; Based on the user's privacy authorization information, create a mirror instance account corresponding to the user account; The mirror instance account has the same operation permissions and operation environment as the user account; According to the operation and maintenance requirements, configure the first operation and maintenance permissions for the mirror instance account; Perform operation and maintenance operations on the mirror instance account within the first operation and maintenance permissions.
2. The method according to claim 1, wherein The step of upon receiving a user's operation and maintenance request, obtaining the user's privacy authorization information includes: Upon receiving a user's operation and maintenance request, send a privacy authorization request to the user; Upon receiving the user's operation on the privacy configuration switch, obtain the user's privacy authorization information.
3. The method according to claim 1, characterized in that, The privacy authorization information at least includes the user's account list and account configuration information. The account list includes the user's sub-user accounts and the corresponding operation permissions for the sub-user accounts; the account configuration information is the information required to create the mirror instance account; The step of based on the user's privacy authorization information, creating a mirror instance account corresponding to the user account includes: Based on the account configuration information and the operation permissions corresponding to the sub-user accounts, create a mirror instance account corresponding to each sub-user account.
4. The method according to claim 3, characterized in that After creating a mirror instance account corresponding to each sub-user account based on the account configuration information and the operation permissions corresponding to the sub-user accounts, the method further includes: When the number of created mirror instance accounts exceeds a preset number threshold, send an alarm message to the operation and maintenance personnel.
5. The method according to claim 4, characterized in that, After sending the alarm message to the operation and maintenance personnel, the method further includes: Upon receiving the request from the operation and maintenance personnel to increase the number of account creations, determine whether the number of account creations can be increased according to the limit on the number of account creations included in the user's privacy authorization information; If so, send the allowed increased number of account creations to the operation and maintenance personnel; If not, send a prohibition message to the operation and maintenance personnel to prohibit the operation and maintenance personnel from creating the mirror instance account.
6. The method according to claim 1, wherein The step of according to the operation and maintenance requirements, configuring the first operation and maintenance permissions for the mirror instance account includes: Based on a preset operation and maintenance permission rule library, determine the first operation and maintenance permissions corresponding to the operation and maintenance requirements; Configure the first operation and maintenance permissions to the mirror instance account.
7. The method according to claim 6, characterized in that, The step of based on a preset operation and maintenance permission rule library, determining the first operation and maintenance permissions corresponding to the operation and maintenance requirements includes: According to the operation and maintenance problems included in the operation and maintenance requirements, determine the corresponding security level, sensitivity level, and core degree from the operation and maintenance permission rule library; According to the security level, sensitivity level, and core degree, determine the first operation and maintenance permissions.
8. The method according to claim 1, characterized in that After configuring the first operation and maintenance permissions for the mirror instance account according to the operation and maintenance requirements, the method further includes: Receive a permission extension request, and the permission extension request includes a target operation and maintenance operation; When it is determined that the target operation and maintenance operation complies with the preset permission adjustment policy, update the first operation and maintenance permission of the mirror instance account to the second operation and maintenance permission, where the second operation and maintenance permission is an extended operation and maintenance permission of the first operation and maintenance permission; When it is determined that the target operation and maintenance operation does not comply with the permission adjustment policy, generate a permission extension response, where the permission extension response at least includes a message for refusing to extend the permission and risk notification information.
9. The method according to claim 1, characterized in that, After performing the operation and maintenance operation on the mirror instance account within the first operation and maintenance permission, the method further includes: After monitoring the operation and maintenance operation information for the mirror instance account, synchronize the operation and maintenance operation information to each system associated with the user account.
10. The method according to claim 1, characterized in that Before creating a mirror instance account corresponding to the user account based on the user privacy authorization information, the method further includes: Obtain the operation and maintenance operation order number input by the operation and maintenance personnel.
11. An electronic device, characterized in that, including: a memory, a processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory, so that the processor executes the method according to any one of claims 1-10.
12. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by the processor, they are used to implement the method according to any one of claims 1-10.
13. A computer program product, characterized in that, including a computer program, which when executed by a processor implements the method according to any one of claims 1-10.