Network equipment background access control method, program product, equipment and medium

The network device backend access control method secures remote access by using Web UI interfaces for secure command processing, ensuring only authorized operations are executed, thus preventing unauthorized access and maintaining security and secrecy.

CN120321056AActive Publication Date: 2025-07-15BEIJING THREATBOOK TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510820438.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-07-15
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

In the prior art, the backend access interface of the network device is exposed to the user, resulting in the inability to effectively ensure the security of backend access. Especially when the manufacturer engineer cannot provide timely remote guidance, the user may execute operation commands at will, affecting the security of the device.

Method used

By obtaining the background access control instructions of the first user on the Web UI interface of the network device, the instructions are processed using the pre-configured message encapsulation structure, encryption algorithm and encoding method, the background access control instructions are generated, and the operation command is executed after a security check is performed to ensure that only the legal instructions are executed.

Benefits of technology

It effectively prevents the exposure of the real backend access interface of network devices, ensures that the right to choose backend operation commands belongs to the second user, and improves the security of backend access of network devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321056A_ABST
    Figure CN120321056A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network equipment background access control method, a program product, equipment and a medium, and relates to the technical field of network security. The network equipment background access control method is applied to target network equipment, and the target network equipment is provided with a network user interface Web UI. The method comprises the following steps: acquiring a background access control instruction input by a first user through the Web UI interface; wherein the background access control instruction is obtained according to a background operation command selected by a second user; and performing security check on the background access control instruction, and executing the background operation command under the condition that the background access control instruction passes the security check to obtain a command execution result. According to the embodiment of the invention, the technical effect of effectively ensuring the background access security of the network equipment can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology. Specifically, it relates to a method, program product, device, and medium for accessing and controlling the background of a network device. Background Art

[0002] To prevent users from randomly accessing the background system of a network device, ensure the normal operation of the network device, and avoid the leakage of technical secrets of the background system, most manufacturers will hide the true background access interface of the network device. When an emergency failure occurs in the network device and the manufacturer's engineers cannot arrive at the scene in time to handle it, the manufacturer's engineers often need to remotely guide the user to enter the background system to execute corresponding operation commands for fault troubleshooting. This will expose the true background access interface of the network device to the user, and the operation commands executed by the user cannot be restricted, making it difficult to effectively ensure the security of accessing the background of the network device. Summary of the Invention

[0003] The purpose of the embodiments of this application is to provide a method, program product, device, and medium for accessing and controlling the background of a network device, so as to achieve the technical effect of effectively ensuring the security of accessing the background of the network device.

[0004] In a first aspect, the embodiments of this application provide a method for accessing and controlling the background of a network device, which is applied to a target network device. The target network device is provided with a Web UI interface for network users. The method includes: Obtain a background access control instruction input by a first user through the Web UI interface; wherein, the background access control instruction is obtained according to a background operation command selected by a second user; Perform a security check on the background access control instruction, and execute the background operation command to obtain a command execution result when the background access control instruction passes the security check.

[0005] In the above implementation process, by setting the target network device to open the Web UI interface to the first user, after the first user obtains the background access control instruction obtained from the background operation command selected by the second user, the first user can directly input the background access control instruction to the target network device through the Web UI interface. The target network device obtains the background access control instruction input by the first user through the Web UI interface, performs a security check on the background access control instruction, and when the background access control instruction passes the security check, executes the background operation command to obtain the command execution result. This can not only enable the first user to directly execute specific background operation commands on the target network device through the Web UI interface without exposing the real background access interface of the target network device to the first user, but also ensure that the option to select the background operation command is reserved for the second user, effectively restricting the background operation commands executed by the first user on the target network device, thereby effectively ensuring the security of the background access of the network device.

[0006] Further, the background access control instruction is obtained by performing the following processing on the background operation command: Encapsulate the background operation command according to a pre-configured message encapsulation structure to generate a first target message; Encrypt the first target message using a pre-configured encryption algorithm to obtain an encrypted message; Encode the encrypted message using a pre-configured encoding method to obtain the background access control instruction.

[0007] In the above implementation process, by adopting a processing method of sequentially encapsulating, encrypting, and encoding the background operation command selected by the second user according to a pre-configured message encapsulation structure, encryption algorithm, and encoding method to obtain the background access control instruction, it can effectively avoid exposing the real background access interface of the target network device and further ensure the security of the background access of the network device.

[0008] Further, the encapsulating the background operation command according to a pre-configured message encapsulation structure to generate a first target message includes: Run the message encapsulation program, obtain the input information input by the second user on the user interface of the message encapsulation program, and fill the input information in the message encapsulation structure to generate the first target message; wherein, the message content of the first target message includes the background operation command, and one or more of the standard message start marker in the message encapsulation structure, the device identification information of the target network device, the task identification information of the current background access control task, and the message generation time of the first target message.

[0009] In the above implementation process, by adopting a running message encapsulation program, obtaining the input information entered by the second user on the user interface of the message encapsulation program, and filling the input information in the message encapsulation structure to encapsulate the background operation command to generate the first target message, the message encapsulation efficiency can be improved.

[0010] Further, the encryption algorithm includes an asymmetric encryption algorithm, and the encoding method includes a base64 encoding method.

[0011] In the above implementation process, by encrypting the first target message with an asymmetric encryption algorithm to obtain an encrypted message, on the one hand, the structure of the first target message can be hidden to prevent the background operation command from being leaked, and on the other hand, it can ensure successful decryption when holding the correct key later to prevent the background operation command from being forged, and by encoding the encrypted message with a base64 encoding method to obtain a background access control instruction, the background access control instruction can be made printable, which is convenient for subsequent display on the Web UI of the target network device.

[0012] Further, the background access control instruction is obtained by successively encapsulating, encrypting, and encoding the background operation command; The security check on the background access control instruction includes: Decoding the background access control instruction to obtain a message to be decrypted; Decrypting the message to be decrypted to obtain a second target message; Verifying whether the message content of the second target message is correct; Determining whether the background access control instruction passes the security check according to the verification result.

[0013] In the above implementation process, on the premise that the background access control instruction is obtained by successively encapsulating, encrypting, and encoding the background operation command, by adopting the processing method of successively decoding, decrypting, and verifying the content of the background access control instruction to perform a security check on the background access control instruction, the security of the background access control instruction can be quickly and accurately checked, further ensuring the security of the background access of the network device.

[0014] Further, the message content of the second target message includes the background operation command, as well as the message start marker of the second target message, the device identification information of the network device to be accessed, the task identification information of the current background access control task, and the message generation time of the second target message; The verification of whether the message content of the second target message is correct includes: Comparing whether the message start marker is consistent with a pre-configured standard message start marker; Compare whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device; Compare whether the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task; Statistically calculate the interval duration from the message generation time to the current time, and determine whether the interval duration reaches the interval duration threshold; Determining whether the background access control instruction passes the security check according to the verification result includes: If the message start marker is consistent with the standard message start marker, the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, the task identification information of the current background access control task is inconsistent with the task identification information of the historical background access control task, and the interval duration does not reach the interval duration threshold, then determine that the background access control instruction passes the security check; Otherwise, determine that the background access control instruction fails the security check.

[0015] In the above implementation process, when the message content of the second target message obtained by the target network device includes a background operation command, as well as the message start marker of the second target message, the device identification information of the network device to be accessed, the task identification information of the current background access control task, and the message generation time of the second target message, compare whether the message start marker is consistent with the pre-configured standard message start marker, compare whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, compare whether the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task, and determine whether the interval duration from the message generation time to the current time reaches the interval duration threshold. If the message start marker is consistent with the standard message start marker, the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, the task identification information of the current background access control task is inconsistent with the task identification information of the historical background access control task, and the interval duration does not reach the interval duration threshold, then determine that the background access control instruction passes the security check, otherwise determine that the background access control instruction fails the security check, which can comprehensively check the message content of the second target message and ensure that the background access control instruction is comprehensively and accurately subject to a security check.

[0016] Further, the method further includes: Return the command execution result; and / or, Store the command execution result and return the download link of the command execution result.

[0017] In the above implementation process, after the target network device obtains the command execution result, it returns the command execution result, and / or stores the command execution result and returns the download link of the command execution result, so as to flexibly select one or more ways to provide the command execution result to the first user, which is convenient for the first user to quickly obtain the command execution result.

[0018] In a second aspect, an embodiment of the present application provides a network device background access control device, which is applied to a target network device, and the target network device is provided with a network user interface Web UI interface; the device includes: An instruction receiving module, configured to obtain a background access control instruction input by a first user through the Web UI interface; wherein, the background access control instruction is obtained according to a background operation command selected by a second user; An access control module, configured to perform a security check on the background access control instruction, and execute the background operation command to obtain a command execution result when the background access control instruction passes the security check.

[0019] In a third aspect, an embodiment of the present application provides a computer program product, which includes instructions that, when executed by a computer, cause the computer to implement the method described above.

[0020] In a fourth aspect, an embodiment of the present application provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method described above is implemented.

[0021] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method described above. Description of the Drawings

[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0023] Figure 1 It is a schematic flowchart of a network device background access control method provided by the first embodiment of the present application; Figure 2 It is a schematic flowchart of a network device background access control method exemplified in the first embodiment of the present application; Figure 3 Schematic structural diagram of a network device background access control device provided in the second embodiment of the present application; Figure 4 Schematic structural diagram of an electronic device provided in the third embodiment of the present application. Specific embodiments

[0024] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0025] It should be noted that: in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions, and cannot be understood as indicating or implying relative importance. At the same time, the step numbers in the text are only for the convenience of explaining the embodiments of the present application, and do not serve as a function of limiting the execution order of the steps.

[0026] In order to prevent users from randomly accessing the background system of the network device, ensure the normal operation of the network device, and avoid the leakage of the technical secrets of the background system, most manufacturers will hide the real background access interface of the network device. When an emergency fault occurs in the network device and the manufacturer's engineers cannot arrive at the scene in time to handle it, the manufacturer's engineers often need to remotely guide the user to enter the background system to execute corresponding operation commands for fault troubleshooting. This will expose the real background access interface of the network device to the user, and the operation commands executed by the user cannot be restricted, making it difficult to effectively ensure the security of the network device background access.

[0027] To this end, the embodiments of the present application provide a network device background access control method. By setting the target network device to open the Web UI interface to the first user, the first user can directly input the background access control instruction to the target network device through the Web UI interface after obtaining the background access control instruction obtained according to the background operation command selected by the second user. The target network device obtains the background access control instruction input by the first user through the Web UI interface, performs a security check on the background access control instruction, and when the background access control instruction passes the security check, executes the background operation command to obtain the command execution result. This can not only enable the first user to directly execute specific background operation commands on the target network device through the Web UI interface without exposing the real background access interface of the target network device to the first user, but also ensure that the option of the background operation command is reserved for the second user, effectively restricting the background operation commands executed by the first user on the target network device, thereby effectively ensuring the security of the network device background access.

[0028] The method provided in the embodiments of the present application can be executed by relevant terminal devices, and hereinafter, the network device is taken as the execution subject for illustration.

[0029] Please refer toFigure 1 , Figure 1 It is a schematic flowchart of a method for controlling background access to a network device provided by the first embodiment of this application. The first embodiment of this application provides a method for controlling background access to a network device, which is applied to a target network device. The target network device is provided with a Web UI interface for network users; the method includes steps S101 to S102: S101. Obtain a background access control instruction input by a first user through the Web UI interface; wherein, the background access control instruction is obtained according to a background operation command selected by a second user; S102. Perform a security check on the background access control instruction, and execute the background operation command to obtain a command execution result when the background access control instruction passes the security check.

[0030] Exemplarily, Web UI interfaces are set for each network device deploying the system developed by the manufacturer in advance. The Web UI (Website User Interface) interface allows users to interact with the background system of the network device. The user, that is, the first user, can select any network device to be accessed as the target network device according to actual application requirements. The target network device is provided with a Web UI interface, which is convenient for the first user to directly input the background access control instruction to the target network device through the Web UI interface after obtaining the background access control instruction. Among them, the background access control instruction is obtained according to the management user, such as the manufacturer's engineer, that is, the second user's selected background operation command, which is convenient for the second user to entrust the first user to execute a specific background operation command on the target network device according to the first user's background access requirements for the target network device.

[0031] In practical applications, the second user can select background operation commands that allow the first user to execute according to the first user's background access requirements for the target network device, such as CPU viewing commands, service running status viewing commands, configuration modification commands, and process viewing commands, perform corresponding processing according to the selected background operation commands to obtain background access control instructions, and send the background access control instructions to the first user, so that the first user can directly obtain the background access control instructions.

[0032] It can be understood that by enabling the first user to directly obtain the background access control instruction, it is possible to prevent the first user from changing the background operation command selected by the second user, effectively restricting the background operation command executed by the first user on the target network device.

[0033] After the first user inputs the background access control instruction to the target network device through the Web UI interface, the target network device obtains the background access control instruction input by the first user through its own Web UI interface.

[0034] The target network device performs a security check on the background access control instruction to determine whether the background access control instruction passes the security check.

[0035] When the target network device determines that the background access control instruction passes the security check, it indicates that the background access control instruction is a legal and secure instruction, determines the background operation command in the background access control instruction, executes the background operation command, and obtains a command execution result.

[0036] When the target network device determines that the background access control instruction fails the security check, it indicates that the background access control instruction is illegal and insecure. At this time, the background operation command will not be executed, and an error prompt message can be directly returned.

[0037] In the embodiment of the present application, by setting the target network device to open the Web UI interface to the first user, the first user can directly input the background access control instruction to the target network device through the Web UI interface after obtaining the background access control instruction obtained according to the background operation command selected by the second user. The target network device obtains the background access control instruction input by the first user through the Web UI interface, performs a security check on the background access control instruction, and when the background access control instruction passes the security check, executes the background operation command to obtain a command execution result. This can not only enable the first user to directly execute specific background operation commands on the target network device through the Web UI interface without exposing the real background access interface of the target network device to the first user, but also ensure that the option to select the background operation command is reserved for the second user, effectively restricting the background operation commands executed by the first user on the target network device, thereby effectively ensuring the security of the background access of the network device.

[0038] In an alternative embodiment, the background access control instruction is obtained by performing the following processing on the background operation command: encapsulating the background operation command according to a pre-configured message encapsulation structure to generate a first target message; encrypting the first target message using a pre-configured encryption algorithm to obtain an encrypted message; and encoding the encrypted message using a pre-configured encoding method to obtain the background access control instruction.

[0039] Exemplarily, in order to restrict the data supported by the Web UI interface, prevent other users from accessing the background of the target network device through the WebUI interface at will, and more effectively avoid exposing the true background access interface of the target network device, a message encapsulation structure, an encryption algorithm, and an encoding method can be pre-configured on the terminal device used to obtain the background access control instruction according to the background operation command selected by the second user. After the terminal device obtains the background operation command selected by the second user, it encapsulates, encrypts, and encodes the background operation command in sequence according to the pre-configured message encapsulation structure, encryption algorithm, and encoding method to obtain the background access control instruction. Specifically, according to the pre-configured message encapsulation structure, the background operation command is encapsulated to generate a first target message, the first target message is encrypted using the pre-configured encryption algorithm to obtain an encrypted message, and the encrypted message is encoded using the pre-configured encoding method to obtain the background access control instruction, so as to provide the background access control instruction to the first user.

[0040] In practical applications, a message encapsulation structure, an encryption algorithm, and an encoding method can be pre-configured on the terminal device held by the second user, that is, the second user terminal. The second user selects the background operation command that allows the first user to execute according to the background access requirement of the first user for the target network device, and inputs the selected background operation command into the second user terminal. After the second user terminal obtains the background operation command selected by the second user, it encapsulates, encrypts, and encodes the background operation command in sequence according to the pre-configured message encapsulation structure, encryption algorithm, and encoding method to obtain the background access control instruction. It is also possible to pre-configure a message encapsulation structure, an encryption algorithm, and an encoding method on the terminal device held by a third party, that is, the third party terminal, such as a server. The second user selects the background operation command that allows the first user to execute according to the background access requirement of the first user for the target network device, and inputs the selected background operation command into the third party terminal. After the third party terminal obtains the background operation command selected by the second user, it encapsulates, encrypts, and encodes the background operation command in sequence according to the pre-configured message encapsulation structure, encryption algorithm, and encoding method to obtain the background access control instruction.

[0041] By adopting the processing method of encapsulating, encrypting, and encoding the background operation command selected by the second user in sequence according to the pre-configured message encapsulation structure, encryption algorithm, and encoding method, the embodiment of the present application can effectively avoid exposing the true background access interface of the target network device, and further ensure the security of the background access of the network device.

[0042] In an alternative embodiment, encapsulating the background operation command according to a pre-configured message encapsulation structure to generate a first target message includes: running a message encapsulation program, obtaining input information entered by a second user on the user interface of the message encapsulation program, and filling the input information in the message encapsulation structure to generate a first target message; wherein, the message content of the first target message includes a background operation command, and one or more of a standard message start marker in the message encapsulation structure, device identification information of the target network device, task identification information of the current background access control task, and the message generation time of the first target message.

[0043] As an example, in the scenario of selecting a second user terminal to execute a background access control instruction obtained according to a background operation command selected by the second user, in order to improve the message encapsulation efficiency, a message encapsulation program can be developed in advance and deployed on the second user terminal.

[0044] The second user terminal triggers the running of the message encapsulation program, presents the user interface of the message encapsulation program to the second user, so that the second user can select a background operation command for the first user's background access requirement for the target network device, and directly enter the corresponding input information on the user interface of the message encapsulation program. For example, the input information includes a background operation command and a target network device, etc.

[0045] After the second user terminal obtains the input information entered by the second user on the user interface of the message encapsulation program, it fills the input information in the message encapsulation structure to generate a first target message. Among them, the message content of the first target message includes a background operation command, and one or more of a standard message start marker in the message encapsulation structure, device identification information of the target network device, task identification information of the current background access control task, and the message generation time of the first target message. Subsequently, a pre-configured encryption algorithm is continued to encrypt the first target message to obtain an encrypted message, and a pre-configured encoding method is used to encode the encrypted message to obtain a background access control instruction to provide the background access control instruction to the first user.

[0046] For example, assuming the message encapsulation structure is as follows, the message content of the first target message includes a background operation command, and a standard message start marker in the message encapsulation structure, device identification information of the target network device, task identification information of the current background access control task, and the message generation time of the first target message: "Magic4byte / / Standard message start marker, is a fixed value, used to mark the start of the message Length 4byte / / Is an integer, used to indicate the effective length of the entire message Devid8byte / / Device identification information of the network device Time 8 bytes / / Message generation time of the entire message Taskid 4 bytes / / Task identification information for the background access control task, which is incrementing Number 4 bytes / / The number N of background operation commands Oplen1 4 bytes / / The length of background operation command 1 Op1 / / The content of background operation command 1, not a fixed value Oplen2 4 bytes / / The length of background operation command 2 Op2 / / The content of background operation command 2, not a fixed value ...... Oplen1N 4 bytes / / The length of background operation command N OpN / / The content of background operation command N, not a fixed value”.

[0047] In practical applications, in the scenario of selecting a third-party terminal to execute the operation of obtaining a background access control instruction according to the background operation command selected by the second user, a pre-developed message encapsulation program can be deployed on the third-party terminal.

[0048] The third-party terminal triggers the running of the message encapsulation program, presents the user interface of the message encapsulation program to the third party, so that the third party can directly input the corresponding input information on the user interface of the message encapsulation program according to the background operation command selected by the second user for the background access requirements of the first user for the target network device. For example, the input information includes background operation commands and target network devices, etc.

[0049] After the third-party terminal obtains the input information input by the third party on the user interface of the message encapsulation program, it fills the input information in the message encapsulation structure to generate a first target message. Among them, the message content of the first target message includes background operation commands, and one or more of the standard message start marker in the message encapsulation structure, the device identification information of the target network device, the task identification information of this background access control task, and the message generation time of the first target message. Subsequently, the first target message is encrypted using a pre-configured encryption algorithm to obtain an encrypted message, and the encrypted message is encoded using a pre-configured encoding method to obtain a background access control instruction, so as to provide a background access control instruction to the first user.

[0050] By adopting the method of running a message encapsulation program, obtaining the input information input by the second user on the user interface of the message encapsulation program, and filling the input information in the message encapsulation structure to encapsulate the background operation command to generate a first target message, the embodiment of the present application can improve the message encapsulation efficiency.

[0051] In an alternative embodiment, the encryption algorithm includes an asymmetric encryption algorithm, and the encoding method includes the base64 encoding method.

[0052] Exemplarily, according to actual application requirements, an asymmetric encryption algorithm and the base64 encoding method can be selected and pre-configured on the terminal device for obtaining the background access control instruction according to the background operation command selected by the second user.

[0053] The asymmetric encryption algorithm requires two keys for encryption and decryption, providing higher security. The base64 encoding method is one of the most common encoding methods for transmitting 8-bit byte codes on the network. It is a method for representing binary data based on 64 printable characters. Through Base64 encoding, the background access control instruction can be subsequently presented on a web page.

[0054] In practical applications, the encryption algorithm can also be a symmetric encryption algorithm, and the encoding method can also be a URL encoding method or other encoding methods.

[0055] In the embodiment of the present application, by encrypting the first target message with an asymmetric encryption algorithm to obtain an encrypted message, on the one hand, the structure of the first target message can be hidden to prevent the background operation command from being leaked, and on the other hand, successful decryption can be ensured when the correct key is held later to prevent the background operation command from being forged. In addition, by encoding the encrypted message with the base64 encoding method to obtain the background access control instruction, the background access control instruction can be made printable, facilitating subsequent display on the Web UI of the target network device.

[0056] In an alternative embodiment, the background access control instruction is obtained by encapsulating, encrypting, and encoding the background operation command in sequence. The security check for the background access control instruction includes: decoding the background access control instruction to obtain the message to be decrypted; decrypting the message to be decrypted to obtain the second target message; verifying whether the message content of the second target message is correct; and determining whether the background access control instruction passes the security check according to the verification result.

[0057] Exemplarily, after the target network device obtains the background access control instruction input by the first user, it performs a security check on the background access control instruction. Since the background access control instruction is obtained by encapsulating, encrypting, and encoding the background operation command in sequence, the security check process can decode, decrypt, and verify the content of the background access control instruction in sequence. Specifically: decode the background access control instruction to obtain the message to be decrypted, decrypt the message to be decrypted to obtain the second target message, and verify whether the message content of the second target message is correct. If the verification result is that all the message content of the second target message is correct, it is considered that the background access control instruction is a legal and secure instruction, and it is determined that the background access control instruction passes the security check. If the verification result is that at least part of the message content of the second target message is incorrect, it is considered that the background access control instruction is illegal and insecure. At this time, it is determined that the background access control instruction fails the security check.

[0058] In practical applications, if an error occurs during the decoding process of the background access control instruction, it is directly determined that the background access control instruction fails the security check. If an error occurs during the decryption process of the message to be decrypted, it is directly determined that the background access control instruction fails the security check.

[0059] In the embodiment of the present application, on the premise that the background access control instruction is obtained by encapsulating, encrypting, and encoding the background operation command in sequence, a processing method of decoding, decrypting, and verifying the content of the background access control instruction in sequence is adopted to perform a security check on the background access control instruction, which can quickly and accurately check the security of the background access control instruction, and further ensure the security of the background access of the network device.

[0060] In an alternative embodiment, the message content of the second target message includes a background operation command, as well as a message start marker of the second target message, device identification information of the network device to be accessed, task identification information of the current background access control task, and the message generation time of the second target message; verifying whether the message content of the second target message is correct includes: comparing whether the message start marker is consistent with a pre-configured standard message start marker; comparing whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device; comparing whether the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task; calculating the elapsed time from the message generation time to the current time, and determining whether the elapsed time reaches an elapsed time threshold; determining whether the background access control instruction passes the security check according to the verification result includes: if the message start marker is consistent with the standard message start marker, the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, the task identification information of the current background access control task is inconsistent with the task identification information of the historical background access control task, and the elapsed time does not reach the elapsed time threshold, then it is determined that the background access control instruction passes the security check; otherwise, it is determined that the background access control instruction fails the security check.

[0061] Exemplarily, after obtaining the second target message, when the message content of the second target message includes a background operation command, as well as the message start marker of the second target message, the device identification information of the network device to be accessed, the task identification information of the current background access control task, and the message generation time of the second target message, the target network device can verify whether each message content of the second target message is correct, specifically: compare whether the message start marker is consistent with the pre-configured standard message start marker, that is, the standard message start marker in the message encapsulation structure; compare whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device; compare whether the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task; count the interval duration from the message generation time to the current time, and determine whether the interval duration reaches the pre-set interval duration threshold to obtain the verification result. If the message start marker is consistent with the standard message start marker, the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, the task identification information of the current background access control task is inconsistent with the task identification information of the historical background access control task, and the interval duration does not reach the interval duration threshold, then the verification result is that all message contents of the second target message are correct, and it is considered that the background access control instruction is a legal and secure instruction, and it is determined that the background access control instruction passes the security check. If the message start marker is inconsistent with the standard message start marker, the device identification information of the network device to be accessed is inconsistent with the device identification information of the target network device, the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task, or the interval duration reaches the interval duration threshold, then the verification result is that at least some message contents of the second target message are incorrect, and it is considered that the background access control instruction is illegal and insecure. At this time, it is determined that the background access control instruction fails the security check, and an error prompt message can be returned.

[0062] It can be understood that by comparing whether the start tag of the message is consistent with the pre-configured standard message start tag, it can be verified whether the second target message is a message encapsulating a background operation command, ensuring the effectiveness and availability of the second target message; by comparing whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, it can be verified whether the network device targeted by the second target message is the network device that the first user wants to access, ensuring accurate access to the network device that the first user wants to access; by comparing whether the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task, it can be verified whether the current background access control task has been executed, avoiding repeated execution of the previously executed background access control task; by counting the interval duration from the message generation time to the current time and determining whether the interval duration reaches the pre-set interval duration threshold, it can be verified whether the first user has timed out in inputting the background access control instruction, taking the background access control instruction timed out by the first user as an invalid instruction, strictly ensuring the security of the background access to the network device.

[0063] In practical applications, the task identification information can be represented by a numerical value, and the numerical value is positively correlated with the execution order. That is to say, the larger the numerical value, the later the execution order of the task. For example, for the historical background access control tasks of task 1 and task 2, the target network device previously executed task 1 first and then task 2.

[0064] If the task identification information is selected to be represented by a numerical value, considering that the target network device will not execute illegal or invalid tasks. For example, for the historical background access control tasks of task 1, task 2, and task 4, the verification method of the task identification information of the current background access control task in the second target message by the target network device can be: determine whether the task identification information (numerical value) of the current background access control task is greater than the task identification information (numerical value) of the historical background access control task. If so, it can be considered that the task identification information of the current background access control task is inconsistent with the task identification information of the historical background access control task; otherwise, it is considered that the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task.

[0065] In practical applications, when the target network device determines that the background access control instruction passes the security check, it determines the background operation command in the background access control instruction and executes the background operation commands in sequence. For example, it executes background operation command 1, background operation command 2,..., and background operation command N in sequence, obtains the command execution result, and stores the task identification information of the current background access control task, making the task identification information of the current background access control task become the task identification information of the historical background access control task.

[0066] In practical applications, when the message content of the second target message includes a background operation command, and one or more of the message start marker of the second target message, the device identification information of the network device to be accessed, the task identification information of the current background access control task, and the message generation time of the second target message, the target network device can verify whether each message content of the second target message is correct in the corresponding manner during the above content verification process. For example, assuming that the message content of the second target message includes a background operation command, and the message start marker of the second target message and the device identification information of the network device to be accessed, the target network device verifies the content of the second target message by comparing whether the message start marker is consistent with the pre-configured standard message start marker and whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device.

[0067] In the embodiment of the present application, when the message content of the second target message obtained by the target network device includes a background operation command, and the message start marker of the second target message, the device identification information of the network device to be accessed, the task identification information of the current background access control task, and the message generation time of the second target message, the target network device compares whether the message start marker is consistent with the pre-configured standard message start marker, whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, whether the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task, and determines whether the interval duration from the message generation time to the current time reaches the interval duration threshold. If the message start marker is consistent with the standard message start marker, the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, the task identification information of the current background access control task is inconsistent with the task identification information of the historical background access control task, and the interval duration does not reach the interval duration threshold, it is determined that the background access control instruction passes the security check; otherwise, it is determined that the background access control instruction fails the security check. It can comprehensively check the message content of the second target message and ensure that the security check of the background access control instruction is comprehensive and accurate.

[0068] In an alternative embodiment, the method further includes step S103: S103. Return the command execution result; and / or, store the command execution result and return the download link of the command execution result.

[0069] Exemplarily, after obtaining the command execution result, the target network device may provide the command execution result to the first user in any of the following ways: return the command execution result so that the first user can quickly view the command execution result; store the command execution result and return the download link of the command execution result so that the first user can download the command execution result for viewing; return the command execution result, store the command execution result, and return the command execution result so that the first user can quickly view the command execution result and choose whether to download the command execution result for archiving.

[0070] In practical applications, if the execution duration of the background operation command reaches the execution duration threshold, the query entry of the command execution result may also be returned, so that the first user can query the execution progress of the background operation command and obtain the command execution result.

[0071] In the embodiment of the present application, by having the target network device return the command execution result and / or store the command execution result and return the download link of the command execution result after obtaining the command execution result, one or more ways of providing the command execution result to the first user can be flexibly selected, which is convenient for the first user to quickly obtain the command execution result.

[0072] To more clearly illustrate a network device background access control method provided in the first embodiment of the present application, it is assumed that the second user selects the background operation command, and the second user terminal sequentially encapsulates, encrypts, and encodes the background operation command according to the pre-configured message encapsulation structure, encryption algorithm, and encoding method to obtain the background access control instruction, provides the background access control instruction to the first user, and then the first user inputs the background access control instruction to the target network device. The process schematic diagram of applying the network device background access control method is as Figure 2 shown.

[0073] Please refer to Figure 3 , Figure 3 which is the structural schematic diagram of a network device background access control device provided in the second embodiment of the present application. The second embodiment of the present application provides a network device background access control device, which is applied to the target network device, and the target network device is provided with a network user interface Web UI interface; the device includes: an instruction receiving module 201, configured to obtain the background access control instruction input by the first user through the Web UI interface; wherein, the background access control instruction is obtained according to the background operation command selected by the second user; an access control module 202, configured to perform a security check on the background access control instruction, and execute the background operation command to obtain the command execution result when the background access control instruction passes the security check.

[0074] In an alternative embodiment, the background access control instruction is obtained by processing the background operation command as follows: encapsulating the background operation command according to a pre-configured message encapsulation structure to generate a first target message; encrypting the first target message using a pre-configured encryption algorithm to obtain an encrypted message; and encoding the encrypted message using a pre-configured encoding method to obtain the background access control instruction.

[0075] In an alternative embodiment, the encapsulating the background operation command according to a pre-configured message encapsulation structure to generate a first target message includes: running a message encapsulation program, obtaining input information entered by a second user on the user interface of the message encapsulation program, and filling the input information in the message encapsulation structure to generate a first target message; wherein the message content of the first target message includes the background operation command, and one or more of a standard message start marker in the message encapsulation structure, device identification information of a target network device, task identification information of the current background access control task, and the message generation time of the first target message.

[0076] In an alternative embodiment, the encryption algorithm includes an asymmetric encryption algorithm, and the encoding method includes a base64 encoding method.

[0077] In an alternative embodiment, the background access control instruction is obtained by sequentially encapsulating, encrypting, and encoding the background operation command; the security check on the background access control instruction includes: decoding the background access control instruction to obtain a message to be decrypted; decrypting the message to be decrypted to obtain a second target message; verifying whether the message content of the second target message is correct; and determining whether the background access control instruction passes the security check according to the verification result.

[0078] In an alternative embodiment, the message content of the second target message includes a background operation command, as well as a message start marker of the second target message, device identification information of the network device to be accessed, task identification information of the current background access control task, and the message generation time of the second target message; verifying whether the message content of the second target message is correct includes: comparing whether the message start marker is consistent with a pre-configured standard message start marker; comparing whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device; comparing whether the task identification information of the current background access control task is consistent with the task identification information of the historical background access control task; counting the interval duration from the message generation time to the current time, and determining whether the interval duration reaches an interval duration threshold; determining whether the background access control instruction passes the security check according to the verification result includes: if the message start marker is consistent with the standard message start marker, the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, the task identification information of the current background access control task is inconsistent with the task identification information of the historical background access control task, and the interval duration does not reach the interval duration threshold, then it is determined that the background access control instruction passes the security check; otherwise, it is determined that the background access control instruction fails the security check.

[0079] In an alternative embodiment, the apparatus further includes: A result processing module, configured to: return a command execution result; and / or, store the command execution result and return a download link of the command execution result.

[0080] The implementation processes of the functions and roles of each module in the above apparatus are specifically described in detail in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.

[0081] A third embodiment of the present application provides a computer program product, which includes instructions that, when executed by a computer, cause the computer to implement the method described in the first embodiment of the present application and achieve the same beneficial effects.

[0082] The method described in the first embodiment of the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in various embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model), or other programmable devices.

[0083] Computer programs or instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer programs or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center integrating one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.

[0084] Please refer to Figure 4 , Figure 4 FIG. [FIG. NUMBER] is a schematic structural diagram of an electronic device provided in the fourth embodiment of the present application. The fourth embodiment of the present application provides an electronic device 30, including a processor 301, a memory 302, and a computer program stored in the memory 302 and configured to be executed by the processor 301; when the processor 301 executes the computer program, the method described in the first embodiment of the present application is implemented, and the same beneficial effects can be achieved.

[0085] Among them, when the processor 301 reads the computer program from the memory 302 through the bus 303 and executes the computer program, the method including any embodiment of the method described in the first embodiment of the present application can be implemented.

[0086] The processor 301 can process digital signals and can include various computing architectures. For example, a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, the processor 301 can be a microprocessor.

[0087] The memory 302 can be used to store instructions executed by the processor 301 or data related to the execution of the instructions. These instructions and / or data can include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 301 of the present disclosure embodiment can be used to execute the instructions in the memory 302 to implement the method described in the first embodiment of the present application. The memory 302 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memories well known to those skilled in the art.

[0088] The fifth embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method described in the first embodiment of the present application, and can achieve the same beneficial effects.

[0089] In summary, the embodiments of the present application provide a method, program product, device, and medium for controlling access to the background of a network device. The method for controlling access to the background of the network device is applied to a target network device, and the target network device is provided with a network user interface Web UI interface. The method includes: obtaining a background access control instruction input by a first user through the Web UI interface, where the background access control instruction is obtained according to a background operation command selected by a second user; performing a security check on the background access control instruction, and when the background access control instruction passes the security check, executing the background operation command to obtain a command execution result. By setting the target network device to open the Web UI interface to the first user, the first user can directly input the background access control instruction to the target network device through the Web UI interface after obtaining the background access control instruction obtained according to the background operation command selected by the second user. The target network device obtains the background access control instruction input by the first user through the Web UI interface, performs a security check on the background access control instruction, and when the background access control instruction passes the security check, executes the background operation command to obtain a command execution result. This can not only enable the first user to directly execute specific background operation commands on the target network device through the Web UI interface without exposing the true background access interface of the target network device to the first user, but also ensure that the option to select the background operation command is reserved for the second user, effectively restricting the background operation commands executed by the first user on the target network device, thereby effectively ensuring the security of accessing the background of the network device.

[0090] In several embodiments provided by this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0091] In addition, the functional modules in each embodiment of this application can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0092] If the described functions are implemented in the form of software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0093] The above description is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A method for controlling background access of a network device, characterized in that, Applied to a target network device, the target network device is provided with a network user interface (Web UI) interface; the method includes: Obtaining a background access control instruction input by a first user through the Web UI interface; wherein, the background access control instruction is obtained according to a background operation command selected by a second user; Performing a security check on the background access control instruction, and when the background access control instruction passes the security check, executing the background operation command to obtain a command execution result.

2. The method according to claim 1, wherein The background access control instruction is obtained by performing the following processing on the background operation command: Encapsulating the background operation command according to a pre-configured message encapsulation structure to generate a first target message; Encrypting the first target message using a pre-configured encryption algorithm to obtain an encrypted message; Encoding the encrypted message using a pre-configured encoding method to obtain the background access control instruction.

3. The method according to claim 2, wherein The encapsulating the background operation command according to a pre-configured message encapsulation structure to generate a first target message includes: Running a message encapsulation program, obtaining input information input by the second user on the user interface of the message encapsulation program, and filling the input information in the message encapsulation structure to generate the first target message; wherein, the message content of the first target message includes the background operation command, and one or more of a standard message start marker in the message encapsulation structure, device identification information of the target network device, task identification information of the current background access control task, and the message generation time of the first target message.

4. The method according to claim 2, wherein The encryption algorithm includes an asymmetric encryption algorithm, and the encoding method includes a base64 encoding method.

5. The method according to claim 1, characterized in that, The background access control instruction is obtained by sequentially encapsulating, encrypting, and encoding the background operation command; The performing a security check on the background access control instruction includes: Decoding the background access control instruction to obtain a message to be decrypted; Decrypting the message to be decrypted to obtain a second target message; Verifying whether the message content of the second target message is correct; Determining whether the background access control instruction passes the security check according to the verification result.

6. The method according to claim 5, characterized in that, The message content of the second target message includes the background operation command, and a message start marker of the second target message, device identification information of the network device to be accessed, task identification information of the current background access control task, and the message generation time of the second target message; The verifying whether the message content of the second target message is correct includes: Comparing whether the message start marker is consistent with a pre-configured standard message start marker; Comparing whether the device identification information of the network device to be accessed is consistent with the device identification information of the target network device; Comparing whether the task identification information of the current background access control task is consistent with the task identification information of a historical background access control task; Counting the interval duration from the message generation time to the current time, and determining whether the interval duration reaches an interval duration threshold; Determining whether the background access control instruction passes the security check according to the verification result includes: If the message start tag is consistent with the standard message start tag, the device identification information of the network device to be accessed is consistent with the device identification information of the target network device, the task identification information of the current background access control task is inconsistent with the task identification information of the historical background access control task, and the interval duration does not reach the interval duration threshold, it is determined that the background access control instruction passes the security check; Otherwise, it is determined that the background access control instruction fails the security check.

7. The method according to any one of claims 1 to 6, characterized in that The method further includes: Returning the command execution result; and / or Storing the command execution result and returning the download link of the command execution result.

8. A computer program product, characterized in that, The computer program product includes instructions that, when executed by a computer, cause the computer to implement the method according to any one of claims 1 to 7.

9. An electronic device, characterized in that, Including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program; wherein, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Access control method and mobile terminal which employs access control method

    CN104052726A

  • Method for realizing authority control and related equipment

    CN111488595A

  • Network access control method, system and device and readable storage medium

    CN111901312A

  • Access method and device of background management system and electronic equipment

    CN115052045A

  • Method for accessing application and apparatus, electronic device, and storage medium

    US20220207164A1