Authority management method and system

By verifying permissions for executing commands in the basin machine and sending machine identification in the basin machine, combining IAM and Kubernetes RBAC management permissions, and using PBCLA for command auditing, the security risks and efficiency problems of basin machine permission management are solved, and system security and production efficiency are improved.

CN120342680APending Publication Date: 2025-07-18SHANGHAI SIGEYUAN INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510461397.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The lack of strict control of existing bastion machine authority management, resulting in security risks and unavailability of production environments, and the existing solutions are complex and time-consuming, affecting production efficiency.

Method used

By verifying permissions of executing commands in the fortress machine, the verified commands are sent to the corresponding operating machine based on the operator identification, combining the IAM role and Kubernetes RBAC management permissions, PBCLA is used for command auditing to ensure the secure transmission and audit of commands.

Benefits of technology

Reduces the risk of deletion or disabling of key components caused by users' unfamiliarity with commands or operational errors, improves system security and production efficiency, simplifies multi-operation machine management, and enhances system flexibility and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342680A_ABST
    Figure CN120342680A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of bastion hosts, and provides an authority management method and system, and the method comprises the steps: carrying out the authority verification of a to-be-executed command in a bastion host, and obtaining the to-be-executed command passing the authority verification; wherein the command to be executed comprises a manipulator identifier; and sending the to-be-executed command passing the permission verification to the corresponding manipulator based on the manipulator identifier. It is ensured that only the to-be-executed command passing permission verification can be executed in the operation machine, the risk of misoperation and malicious operation is reduced, and the safety of the whole system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the technical field of bastion servers, and in particular, relates to a permission management method and system. Background Art

[0002] Currently, all employees in the company have the permission to log in to the bastion host and can execute any command in the AWS or Kubernetes cluster. This lack of strict permission control will lead to security risks. If employees delete or disable key components in the AWS or Kubernetes cluster because they are not familiar with the specific behavior of certain commands, the production environment may become unavailable, resulting in immeasurable losses. In addition, employees have deployed a large number of scripts or programs on the bastion host, which directly connect to the bastion host to execute commands. It is dangerous and time-consuming to change permissions directly on the bastion host. For example, some scripts that have not been manually run for a long time may be forgotten, and the permissions that can be executed by an employee may be ignored. This may cause the automation program designed by the relevant employee to be unable to execute the script due to insufficient permissions, which may lead to version mismatch or database backup failure. There is currently no good solution to the bastion host permission problem. Summary of the invention

[0003] The embodiments of the present application provide a permission management method and system, which can solve the technical problem of lack of strict bastion host permission control in the prior art.

[0004] In a first aspect, an embodiment of the present application provides a rights management method, including:

[0005] In a possible implementation manner of the first aspect,

[0006] In a second aspect, an embodiment of the present application provides a rights management system, including:

[0007] In a third aspect, an embodiment of the present application provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the permission management method described in any one of the first aspects above when executing the computer program.

[0008] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the permission management method described in any one of the above-mentioned first aspects is implemented.

[0009] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a computer device, enables the computer device to execute the permission management method described in any one of the above-mentioned first aspects.

[0010] In an embodiment of the present application, the to-be-executed command in the bastion host is subjected to permission verification to obtain the to-be-executed command that passes the permission verification; wherein, the to-be-executed command includes an operator identifier; based on the operator identifier, the to-be-executed command that passes the permission verification is sent to the corresponding operator. By implementing strict command permission verification, it is ensured that only the to-be-executed commands that pass the permission verification are allowed to be sent to the operator for execution, thereby reducing the risk of key components being erroneously deleted or disabled due to users' unfamiliarity with commands or operational mistakes, and improving the overall system security.

[0011] It can be understood that the beneficial effects of the second to fifth aspects can refer to the relevant descriptions in the first aspect above, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0013] Figure 1 is a schematic flowchart of a permission management method provided by an embodiment of the present application;

[0014] Figure 2 is a schematic structural diagram of a permission management system provided by an embodiment of the present application;

[0015] Figure 3 is a schematic structural diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0017] It should be understood that when used in the specification and appended claims of the present application, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0018] It should also be understood that the term "and / or" as used in the specification of this application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes such combinations.

[0019] As used in the specification of this application and the appended claims, the term "if" can be interpreted as "when" or "once" or "in response to determining" or "in response to detecting" depending on the context. Similarly, the phrases "if determined" or "if [the described condition or event] is detected" can be interpreted as meaning "once determined" or "in response to determining" or "once [the described condition or event] is detected" or "in response to detecting [the described condition or event]" depending on the context.

[0020] In addition, in the description of the specification of this application and the appended claims, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0021] Reference to "one embodiment" or "some embodiments" or the like described in the specification of this application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized.

[0022] Currently within the company, all employees have the permission to log in to the bastion machine and can execute any commands within the aws or kubernetes clusters. This lack of strict permission control poses security risks. If an employee deletes or disables critical components in the aws or kubernetes clusters due to unfamiliarity with the specific behaviors of certain commands, it may render the production environment unavailable, resulting in immeasurable losses. In addition, employees have deployed a large number of scripts or programs on the bastion machine and directly connect to the bastion machine to execute commands. Making permission changes directly on the bastion machine is dangerous and time-consuming. For example, some scripts that have not been manually run for a long time may be forgotten, and the permissions that a certain employee can execute may be overlooked and attached. This may cause the automated programs designed by the relevant employees to be unable to execute this script due to insufficient permissions, leading to problems such as version mismatches or database backup failures. Regarding the permission management of the bastion machine, most of the existing solutions to solve the bastion machine permission problems focus on large-scale transformation of the existing bastion machine system. However, the above solutions often do not meet the current requirements. These solutions not only increase the complexity of the existing bastion machine system but also require a large amount of time and resources for adaptation and implementation. In addition, redesigning the bastion machine may interfere with the existing work processes, making it difficult for employees to quickly adapt to the new operation mode, thereby affecting production efficiency. In summary, there is currently no good solution to the bastion machine permission problem.

[0023] To facilitate the understanding of the solution, the relevant technical features in this application are explained here first.

[0024] A bastion machine, also known as a jump server or a bastion host, is a dedicated server used to enhance network security. It provides a highly secure access mechanism through centralized access control, authentication, authorization management, and operation auditing, preventing unauthorized access and malicious operations. Among them, the bastion machine realizes centralized control of user access permissions through a permission management system, supports role-based access control (RBAC), and ensures that users can only access the minimum permission resources required for their work. At the same time, the bastion machine also records users' command operations through a packet-based command line audit system (PBCLA) to prevent log tampering and enhance the reliability and independence of auditing.

[0025] The permission management system is one of the core functional modules of the bastion machine, used to verify user identities, allocate permissions according to users' roles and responsibilities, define and execute access control policies, etc.

[0026] The Packet-based Command Audit System (PBCLA) is a command-line audit tool implemented through network packet capture and analysis techniques. It captures and parses the data packets in network transmissions, records the commands executed by users on remote systems, thereby providing an audit mechanism independent of the operating system.

[0027] An Operation Machine refers to a machine or system dedicated to performing specific operation tasks. In the AWS cloud platform, an operation machine usually refers to a virtual machine or container instance deployed in the cloud environment for managing and operating AWS resources. In a Kubernetes cluster, an operation machine usually refers to a node in the cluster, and these nodes run containerized applications and services.

[0028] Figure 1 The schematic flowchart of the permission management method provided by an embodiment of the present application is shown.

[0029] S101, perform permission verification on the to-be-executed command in the bastion host to obtain the to-be-executed command that passes the permission verification; wherein, the to-be-executed command includes an operation machine identifier.

[0030] Among them, the to-be-executed command refers to an instruction input by a user through the bastion host interface or API and not yet executed on the target operation machine. The composition of the to-be-executed command includes but is not limited to: command text (the specific operation instruction input by the user) and operation machine identifier (the unique identifier of the operation machine, which can be an IP address, hostname, UUID, or custom label). Optionally, it can also include user identification (user information initiating the to-be-executed command, including attributes such as username, user ID, and affiliated department, etc.).

[0031] S102, based on the operation machine identifier, send the to-be-executed command that passes the permission verification to the corresponding operation machine.

[0032] In the embodiment of the present application, the to-be-executed command that passes the permission verification is packaged into a network packet, and the network packet is transmitted to the operation machine corresponding to the operation machine identifier. Specifically, the bastion host sends the packaged command to one or more operation machines through the network. This can be achieved through SSH, API calls, or other remote execution protocols.

[0033] In an optional embodiment, the to-be-executed command that passes the verification and its associated metadata (such as timestamp, command ID, etc.) can be converted into the standard JSON format. After converting the to-be-executed command into the standard JSON format, the command content can be encrypted, an HMAC-SHA256 signature can be added, etc., to ensure that the command is not tampered with during transmission. Then, the to-be-executed command converted into the standard JSON format and the signature, etc., are encapsulated into a network packet, and the network packet is transmitted to the operator corresponding to the operator identifier, that is, the network packet is transmitted to the network reachable address of the operator. After receiving the network packet, the operator parses the network packet and executes the to-be-executed command.

[0034] Optionally, before sending the to-be-executed command that passes the permission verification to the corresponding operator, security protocol adaptation is also required. For Linux operators, the SSHv2 protocol is preferably used; for Windows operators, the WinRM or SMB protocol is used; for containerized environments, the Kubernetes API or Docker Socket is used.

[0035] Optionally, it is supported to send to-be-executed commands to multiple operators simultaneously, which is applicable to batch operation scenarios. Among them, in the one-to-many relationship between the bastion host and the operator, the management and coordination of the command sending and result collection for multiple operators are usually achieved by assigning a unique operator identifier to each operator. These operator identifiers can be IP addresses, hostnames, or other unique identification information, used to distinguish different operators and ensure that commands can be correctly sent to the target operator. The specific operation process is as follows: On the bastion host, when the user enters a command, the command is associated with the identifier of the target operator; the bastion host packs the command and attaches the operator identifier of the target operator, and sends it to the corresponding operator through the network; after receiving the command from the bastion host, the operator identifies that the command is prepared for itself according to the operator identifier. Then, the operator will execute the command and start performing the corresponding operations; after the operator executes the command, it will pack the result and return it to the bastion host. The returned data packet will also contain the identifier of the operator, so that the bastion host knows which operator the result is returned by; after receiving the result from the operator, the bastion host will associate the result with the original command according to the operator identifier and display it to the user. At the same time, the bastion host will also record these operations and results for subsequent auditing and analysis. In this way, the bastion host can effectively manage and coordinate the command sending and result collection for multiple operators, ensuring that each command can be correctly executed and the expected result can be returned. This mechanism not only improves the security of operations but also enhances the flexibility and scalability of the system.

[0036] Optionally, when the selected operator corresponding to the operator identifier is unreachable, it is automatically switched to the backup operator.

[0037] Optionally, after receiving the command from the bastion host, the operator first decrypts it (if necessary) and then verifies the legitimacy of the command. If the command is legitimate, the operator executes the command locally.

[0038] Optionally, if the permission verification of the command to be executed fails, insufficient permission is displayed. The failure of permission verification may include the following scenarios: the user role does not allow the execution of the command to be executed, the selected operation machine is not in the user authorization list, the command to be executed contains high-risk operations, etc.

[0039] In an embodiment of the present application, permissions are verified for commands to be executed in the bastion host to obtain commands to be executed that have passed the permission verification; wherein, the commands to be executed include an operating machine identifier; based on the operating machine identifier, the commands to be executed that have passed the permission verification are sent to the corresponding operating machine. By implementing strict command permission verification, it is ensured that only commands to be executed that have passed the permission verification are allowed to be sent to the operating machine for execution, thereby reducing the risk of key components being mistakenly deleted or disabled due to user unfamiliarity with commands or operating errors, and improving the security of the overall system. In addition, by sending commands to be executed to the corresponding operating machine based on the operating machine identifier, the bastion host can isolate operations on different operating machines to prevent confusion and errors in command execution; ensure that each command is correctly sent to the predetermined operating machine for execution; and the bastion host centrally manages the command execution of all operating machines, simplifying the management and monitoring of multiple operating machines.

[0040] In an optional embodiment, S101 performs permission verification on the to-be-executed command in the bastion host to obtain the to-be-executed command that passes the permission verification, including:

[0041] Step a1, obtaining the command to be executed entered by the user on the bastion host.

[0042] Among them, the instructions entered by the user through the bastion machine interface or API that have not yet been executed on the operating machine are obtained.

[0043] Step a2, obtaining the IAM role of the user.

[0044] Among them, the IAM role can be pre-configured for each user according to the user category.

[0045] In the embodiments of the present application, in the AWS environment, the AWS Security Token Service (AWS STS) is generally used to obtain temporary permissions according to user categories to achieve fine-grained access control and enhanced security. AWS STS allows users to request temporary security credentials, which can be used to access AWS services and resources. Different Identity and Access Management (IAM) roles are configured according to different user categories, such as developers, operation and maintenance personnel, auditors, etc., and corresponding permission policies are assigned to these roles.

[0046] The user logs in to the bastion host through SSH or other remote access methods. On the bastion host, authentication is required, including but not limited to: entering the username and password, using the SSH key, or through multi-factor authentication. Once the user successfully logs in to the bastion host, the user can use the temporary security credentials obtained from AWS STS before to access AWS services and resources.

[0047] Step a3, perform permission verification on the to-be-executed command based on the permission policy of the user's IAM role.

[0048] In the embodiments of the present application, obtain the permission policy corresponding to the to-be-executed command (that is, the AWS services and resources that the user currently wants to access), and verify the permission policy corresponding to the to-be-executed command based on the permission policy of the user's IAM role to ensure that the permission policy of the IAM role matches the command that the user or service needs to execute.

[0049] Among them, if it is found that the permission settings are inappropriate, the permission policy of the IAM role should be adjusted in a timely manner.

[0050] In the embodiments of the present application, the user identity can be verified based on the permission management system, permissions can be assigned according to the user's role and responsibilities, access control policies can be defined and executed, etc.

[0051] The above permission management system is a hybrid system that combines AWS IAM and Kubernetes RBAC, aiming to provide fine-grained access control for different users and services. The following is an introduction to the main components of this system:

[0052] Part 1: AWS IAM Permission Management. AWS IAM allows the creation of roles and policies that define allowed or denied actions. By attaching policies to roles, access to AWS resources by users and services can be controlled. Since IAM does not directly provide a mapping function with Linux user accounts, a Python script mappingIAMUser.py was developed to achieve this function. This script is executed when a user logs in to the bastion host and obtains temporary security tokens through AWS STS so that users can use these tokens to access AWS resources.

[0053] Part 2: Kubernetes RBAC Permission Management. In Kubernetes, RBAC is used to define roles and role bindings to control user access to cluster resources. Different roles can be created for different users and user groups. Additionally, a kubeconfig file is generated for each user or user group, which contains the authentication information required to access the Kubernetes cluster. These files are saved in the home directory of the user on the operation machine so that users can use them to access and manage Kubernetes resources.

[0054] Part 3: Automated Scripts and User Management. Scripts are written to automatically perform necessary configurations when a user is created, such as creating IAM roles, generating kubeconfig files, etc. Administrators can easily manage user permissions through these automated scripts without having to perform each step manually.

[0055] In the embodiments of this application, through the above operations, it is ensured that users can only perform actions clearly allowed by their roles, reducing security risks caused by excessive permissions, and supporting dynamic updates of permission policies to ensure that policy changes take effect immediately and adapt to the rapid adjustment of enterprise security policies.

[0056] In the prior art, in the command auditing section, if the bastion host system lacks a perfect auditing mechanism, administrators or malicious users may tamper with the command history through various means to evade responsibility or hide improper operations. For example, users may delete or modify the records of sensitive operations by editing the.bash_history file, or avoid key commands being recorded by temporarily turning off the history recording function (such as setting HISTFILE to be empty). In addition, some high-privilege users may also use their privileges to modify or clear the log files, thus covering up improper operations, posing a major challenge to auditing. Such tampering behavior will not only lead to the breakage of the audit chain, making it difficult to trace and investigate problems and determine responsibilities subsequently, but also may bring serious security risks to the bastion host system. Once the command history cannot be completely retained, malicious operations (such as deleting important files, modifying the configuration of the bastion host system, or installing malicious software) may not be discovered in time, thus affecting the normal operation of the bastion host system and the security of data. In addition, such behavior may also lead to compliance issues and increase the operational risks of enterprises. To solve this problem, the present application can obtain the network packet through the command auditing system.

[0057] In the embodiment of the present application, tools (such as PBCLA) can be used to capture the network packets sent by users from the bastion host to the operation machine. Key information such as command content, user information, and timestamp can be extracted from the network packets. Then, the key information can be stored in a secure storage system (such as AWS S3) to ensure the integrity and immutability of the data. Among them, PBCLA is independent of the operating system of the bastion host, avoiding the risk of log tampering in traditional auditing methods.

[0058] Optionally, the communication system between PBCLA, the bastion host, and the operation machine is mainly written in Python, aiming to provide secure and auditable command execution and recording functions. PBCLA consists of three core parts:

[0059] The first part: the network packet capture background service is responsible for capturing the data packets transmitted over the network and storing the content of the data packets in the AWS S3 service.

[0060] The second part: the communication between the bastion host and the operation machine is responsible for packing, sending, receiving, and executing commands between the bastion host and the operation machine.

[0061] The third part: the command auditing client with a UI provides a graphical user interface (UI) to facilitate administrators to view and manage historical commands.

[0062] In an embodiment of the present application, a program named packet_capture.py can be deployed on the bastion host. This program filters data packets through the IP address of the operator machine, captures the packets sent to the operator machine, and periodically sends them to S3 for storage. A server.py program is deployed on the operator machine, which is responsible for receiving instructions from the bastion host, executing these instructions, and returning the execution results to the bastion host.

[0063] Optionally, before deploying these programs, it is necessary to share an encryption key between the bastion host and the operator machine to ensure that both parties can successfully decrypt the data packet content.

[0064] In an embodiment of the present application, through the above design, fine-grained auditing of the commands to be executed in the bastion host can be achieved, while ensuring the secure transmission and execution of the commands, improving the security and traceability of the overall system.

[0065] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0066] Corresponding to the permission management method described in the above embodiments, Figure 2 The structural block diagram of the permission management system provided by the embodiment of the present application is shown. For the convenience of description, only the parts related to the embodiment of the present application are shown.

[0067] Referring to Figure 2 , the permission management system includes:

[0068] A permission management module that performs permission verification on the commands to be executed in the bastion host to obtain the commands to be executed that pass the permission verification; wherein, the commands to be executed include an operator machine identifier;

[0069] A sending module for sending the commands to be executed that pass the permission verification to the corresponding operator machine based on the operator machine identifier.

[0070] In a possible implementation manner, the permission management module is used to:

[0071] Obtain the commands to be executed input by the user on the bastion host;

[0072] Obtain the IAM role of the user;

[0073] Perform permission verification on the commands to be executed based on the permission policy of the IAM role of the user.

[0074] In a possible implementation manner, the permission management system further includes:

[0075] A display module, configured to display insufficient permissions if the verification of the permissions of the to-be-executed command fails.

[0076] In a possible implementation, the permission management system further includes:

[0077] A configuration module, configured to configure an IAM role for each user according to the user category.

[0078] In a possible implementation, a sending module, configured to:

[0079] Package the to-be-executed command that passes the permission verification into a network packet;

[0080] Transmit the network packet to the operator corresponding to the operator identifier.

[0081] In a possible implementation, the permission management system further includes:

[0082] An acquisition module, configured to acquire the network packet through a command auditing system.

[0083] It should be noted that for the information interaction, execution process, etc. between the above modules, since they are based on the same concept as the method embodiments of the present application, their specific functions and the technical effects brought about can be specifically referred to in the method embodiment part, and will not be elaborated here.

[0084] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiments and will not be elaborated here.

[0085] The embodiment of the present application further provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor. When the processor executes the computer program, the steps in any of the foregoing method embodiments are implemented.

[0086] An embodiment of the present application also provides a computer-readable storage medium storing a computer program, which when executed by a processor can implement the steps in the above-mentioned method embodiments.

[0087] An embodiment of the present application provides a computer program product, which when running on a computer device enables the computer device to implement the steps in the above-mentioned method embodiments.

[0088] Figure 3 is a schematic structural diagram of a computer device provided by an embodiment of the present application. As Figure 3 shown, the computer device of this embodiment includes: at least one processor 20 ( Figure 3 only one is shown in the figure), a memory 21, and a computer program 22 stored in the memory 21 and executable on the at least one processor 20. When the processor 20 executes the computer program 22, it implements the steps in any of the above-mentioned permission management method embodiments.

[0089] The computer device may include, but is not limited to, a processor 20 and a memory 21. Those skilled in the art can understand that Figure 3 this is only an example of a computer device and does not constitute a limitation on the computer device. It may include more or fewer components than shown in the figure, or combine certain components, or different components. For example, it may also include input / output devices, network access devices, etc.

[0090] The so-called processor 20 may be a central processing unit (CPU), and the processor 20 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0091] In some embodiments, the memory 21 may be an internal storage unit of the computer device, such as the hard disk or memory of the computer device. In some other embodiments, the memory 21 may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the computer device. Further, the memory 21 may also include both the internal storage unit and the external storage device of the computer device. The memory 21 is used to store an operating system, application programs, a BootLoader, data, and other programs, such as the program code of the computer program. The memory 21 may also be used to temporarily store data that has been output or is to be output.

[0092] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of the present application, a computer program may be used to instruct the relevant hardware to complete. The computer program may be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments may be implemented. Among them, the computer program includes computer program code, and the computer program code may be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the device / computer device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium may not be an electrical carrier signal and a telecommunication signal.

[0093] In the above embodiments, the descriptions of the various embodiments have their own emphases. For parts not detailed or recorded in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0094] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0095] In the embodiments provided in this application, it should be understood that the disclosed device / computer device and method can be implemented in other ways. For example, the device / computer device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.

[0096] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0097] The above-described embodiments are only used to illustrate the technical solutions of this application, rather than to limit it; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included in the protection scope of this application.

Claims

1. A permission management method, characterized in that, Including: Perform permission verification on the to-be-executed command in the bastion host to obtain the to-be-executed command that passes the permission verification; wherein, the to-be-executed command includes an operator identifier; Based on the operator identifier, send the to-be-executed command that passes the permission verification to the corresponding operator.

2. The permission management method according to claim 1, characterized in that The performing permission verification on the to-be-executed command in the bastion host includes: Obtain the to-be-executed command input by the user on the bastion host; Obtain the IAM role of the user; Perform permission verification on the to-be-executed command based on the permission policy of the user's IAM role.

3. The permission management method according to claim 1, characterized in that, The method further includes: If the permission verification of the to-be-executed command fails, display insufficient permissions.

4. The permission management method according to claim 2, wherein The method further includes: Configure the IAM role for each user according to the user category.

5. The permission management method according to claim 1, characterized in that The sending the to-be-executed command that passes the permission verification to the corresponding operator based on the operator identifier includes: Pack the to-be-executed command that passes the permission verification into a network packet; Transmit the network packet to the operator corresponding to the operator identifier.

6. The privilege management method according to claim 5, wherein The method further includes: Obtain the network packet through the command auditing system.

7. A permission management system, characterized in that Including: A permission management module that performs permission verification on the to-be-executed command in the bastion host to obtain the to-be-executed command that passes the permission verification; wherein, the to-be-executed command includes an operator identifier; A sending module for sending the to-be-executed command that passes the permission verification to the corresponding operator based on the operator identifier.

8. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the method according to any one of claims 1 to 6.

10. A computer program product, characterized in that, When the computer program product runs on a computer device, it causes the computer device to execute the method according to any one of claims 1 to 6.