Security reinforcement method and device for secure shell protocol remote login

Through the encryption comparison and live authentication of the fortress machine and pre-configured information, the security risks of remote login of the existing secure shell protocol are solved, and multiple dimensions of security verification are realized, which improves the security and reliability of the login process.

CN120415809APending Publication Date: 2025-08-01CHINA CITIC BANK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510538033.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The existing security shell protocol remote login method relies on username and password authentication or public key authentication, and poses security risks such as brute-force cracking and credential theft, and cannot effectively deal with complex and changeable network security threats.

Method used

The bastion machine obtains the information to be authenticated for remote login requests for the secure shell protocol, uses pre-configured information for encryption and comparison, and combines live authentication and historical login log verification to achieve multiple dimensions of security verification to ensure data transmission security and login permissions.

Benefits of technology

It improves the security of remote login of the security shell protocol, avoids the risk of cipher text leakage caused by single-ended accidents and attackers forgery of live authentication, and enhances the security and reliability of the login process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415809A_ABST
    Figure CN120415809A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and provides a security reinforcement method and device for secure shell protocol remote login. The method comprises the following steps: determining to-be-authenticated information corresponding to a secure shell protocol remote login request; the to-be-authenticated information comprises a first ciphertext obtained by encrypting first content input by a user according to the first key; acquiring pre-configuration information from a corresponding domain controller by using the bastion host, so as to judge the validity of the to-be-authenticated information by comparing the first ciphertext with a second ciphertext in the pre-configuration information; the second ciphertext is obtained by encrypting a second content having a corresponding relationship with the first content according to a second key; the fortress machine does not store the pre-configuration information, and deletes the obtained pre-configuration information after the validity judgment of the to-be-authenticated information is completed; and if the to-be-authenticated information is valid, performing living body authentication on the user to realize safe remote login. Through the embodiment of the invention, the security of remote login of the secure shell protocol can be enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of network security technology, and in particular, to a method and device for securing remote login of the Secure Shell (SSH) protocol. Background Art

[0002] With the popularization of cloud computing and remote work, the Secure Shell (SSH) protocol, as a widely used remote login protocol, has attracted increasing attention to its security. Traditional SSH protocol logins rely solely on username and password authentication methods or key authentication methods, presenting security risks such as brute force cracking and credential theft. To address this issue, existing methods reduce potential security risks by taking measures such as restricting access IPs and using public key authentication. However, these existing methods are still insufficient to cope with complex and ever-changing network security threats. Therefore, there is an urgent need for a method for securing remote login of the SSH protocol that can implement multi-dimensional verification of SSH protocol remote login to enhance the security of SSH protocol remote login. Summary of the Invention

[0003] In view of the fact that currently, when remotely logging in to the SSH protocol, measures such as restricting access IPs and using public key authentication are taken to reduce potential security risks, but these existing methods are still insufficient to cope with complex and ever-changing network security threats, this solution is proposed to overcome the above problems or at least partially solve the above problems.

[0004] On the one hand, the purpose of some embodiments of this specification is to provide a method for securing remote login of the SSH protocol, the method comprising:

[0005] Obtain an SSH protocol remote login request;

[0006] Determine the authentication information corresponding to the SSH protocol remote login request; the authentication information includes a first ciphertext obtained by encrypting a first content input by a user according to a preset first key;

[0007] Use a bastion host to obtain preconfigured information from the domain controller corresponding to the SSH protocol remote login request, so as to determine the validity of the authentication information by comparing the first ciphertext and a second ciphertext in the preconfigured information; the preconfigured information includes a second ciphertext obtained by encrypting a second content having a corresponding relationship with the first content according to a preset second key; and the bastion host itself does not store the preconfigured information and deletes the obtained preconfigured information after completing the validity judgment of the authentication information;

[0008] If the authentication information is valid, perform a liveness authentication on the user so that the bastion host determines whether to grant the user terminal the permission to log in;

[0009] If the information to be authenticated is invalid, terminate the current session.

[0010] Further, use the bastion host to obtain pre-configured information from the domain controller corresponding to the Secure Shell (SSH) protocol remote login request, and determine the validity of the information to be authenticated by comparing the first ciphertext and the second ciphertext in the pre-configured information, including:

[0011] Use the bastion host to find the corresponding pre-configured information by searching for a second user identifier that matches the first user identifier in the pre-configured information collection in the domain controller corresponding to the SSH protocol remote login request according to the first user identifier corresponding to the first content, so that the bastion host determines the validity of the information to be authenticated by comparing the first ciphertext and the second ciphertext in the pre-configured information.

[0012] Further, there is an association relationship between the first key and the second key. The bastion host determines the validity of the information to be authenticated by comparing the first ciphertext and the second ciphertext in the pre-configured information, and further includes:

[0013] Based on the association relationship, use the bastion host to determine the corresponding third key;

[0014] According to the third key, use a preset comparison algorithm to determine whether the first ciphertext and the second ciphertext match;

[0015] If they match, the information to be authenticated is valid;

[0016] If they do not match, the information to be authenticated is invalid.

[0017] Further, it further includes:

[0018] Use the bastion host to obtain the domain information in the SSH protocol remote login request;

[0019] Determine whether the domain information matches the current domain controller corresponding to the user terminal;

[0020] If they match, obtain the domain controller corresponding to the SSH protocol remote login request according to the domain controller corresponding to the current user terminal;

[0021] If they do not match, forward the domain information to the domain controller associated with the current domain controller for matching to obtain the domain controller corresponding to the SSH protocol remote login request.

[0022] Further, if the information to be authenticated is valid, perform a liveness authentication on the user, so that the bastion host determines whether to grant the login permission to the user terminal, including:

[0023] If the information to be authenticated is valid, obtain the user's real-time facial image and perform liveness authentication on the real-time facial image;

[0024] If the liveness authentication passes, the bastion host issues an allowed login permission to the user;

[0025] If the liveness authentication fails and the number of failed attempts reaches a preset value, lock the current session and obtain user feedback, so that the domain controller determines whether to unlock the current session based on the user feedback.

[0026] Furthermore, it further includes:

[0027] Obtain the historical login logs;

[0028] Record the corresponding current login log according to the Secure Shell protocol remote login request;

[0029] Use the historical login logs to verify the current login log.

[0030] On the other hand, some embodiments of this specification also provide a security reinforcement device for Secure Shell protocol remote login, and the device includes:

[0031] A receiving module, configured to obtain a Secure Shell protocol remote login request;

[0032] A determination module, configured to determine the information to be authenticated corresponding to the Secure Shell protocol remote login request; the information to be authenticated includes a first ciphertext obtained by encrypting a first content input by the user according to a preset first key;

[0033] A judgment module, configured to use the bastion host to obtain pre-configured information from the domain controller corresponding to the Secure Shell protocol remote login request, and judge the validity of the information to be authenticated by comparing the first ciphertext and a second ciphertext in the pre-configured information; wherein, the second ciphertext is obtained by encrypting a second content having a corresponding relationship with the first content according to a preset second key; and

[0034] The bastion host itself does not store the pre-configured information, and deletes the obtained pre-configured information after completing the validity judgment of the information to be authenticated;

[0035] An authentication module, configured to perform liveness authentication on the user if the information to be authenticated is valid, so that the bastion host judges whether to issue an allowed login permission to the user terminal;

[0036] A termination module, configured to terminate the current session if the information to be authenticated is invalid.

[0037] On the other hand, some embodiments of this specification also provide a computer device, including a memory, a processor, and a computer program stored on the memory. When the computer program is run by the processor, it executes the instructions of the above method.

[0038] On the other hand, some embodiments of this specification also provide a computer storage medium, on which a computer program is stored. When the computer program is run by the processor of a computer device, it executes the instructions of the above method.

[0039] On the other hand, some embodiments of this specification also provide a computer program product, which includes a computer program. When the computer program is run by the processor of a computer device, it executes the instructions of the above method.

[0040] One or more technical solutions provided by some embodiments of this specification have at least the following technical effects:

[0041] As can be seen from the technical solutions provided by the embodiments of this specification above, the embodiments of this specification first obtain a Secure Shell (SSH) protocol remote login request to determine the corresponding information to be authenticated. The information to be authenticated includes a first ciphertext obtained by encrypting a first content input by a user according to a preset first key, so that the first content input by the user is transmitted to the bastion host from the user terminal in an encrypted manner. Then, the bastion host obtains pre-configured information for verifying the validity of the information to be authenticated from the domain controller corresponding to the SSH protocol remote login request. The pre-configured information includes a second ciphertext obtained by encrypting a second content having a corresponding relationship with the first content according to a preset second key, so that the pre-configured information obtained by the bastion host is also obtained in an encrypted transmission manner, ensuring the security of data transmission. And the corresponding relationship between the first content and the second content ensures that the appropriate pre-configured information can be quickly and accurately called to determine the validity of the information to be authenticated.

[0042] In addition, the bastion host does not store pre-configured information itself, and deletes the obtained pre-configured information after completing the validity judgment of the authentication information to realize the interaction process between the terminal and the remote server for remote login via the Secure Shell protocol in a decoupled manner in the domain control mode, thus avoiding the problem of ciphertext leakage that may be caused by the bastion host storing valid password information. Moreover, the entire secure login process is realized in a multi-terminal mode including the user terminal, the bastion host, the domain controller, and the remote server, which can avoid the security risk problems caused by single-terminal accidents to a certain extent. After verifying the information to be authenticated, a liveness authentication is performed on the user, which not only avoids the opportunity for attackers to forge liveness authentication but also fully ensures the security and effectiveness of login permission granting, and can realize remote login verification of the Secure Shell protocol in multiple dimensions to enhance the security of remote login via the Secure Shell protocol.

[0043] The above description is only an overview of the technical solutions of some embodiments of this specification. In order to be able to more clearly understand the technical means of some embodiments of this specification, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of some embodiments of this specification more obvious and understandable, the following specifically presents the specific implementation manners of some embodiments of this specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate some embodiments of this specification or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. In the drawings:

[0045] Figure 1 It shows a schematic diagram of the implementation system of a security reinforcement method for remote login via the Secure Shell protocol in some embodiments of this specification;

[0046] Figure 2 It shows a flowchart of a security reinforcement method for remote login via the Secure Shell protocol in some embodiments of this specification;

[0047] Figure 3 It is a schematic diagram of the steps for the bastion host to judge the validity of the information to be authenticated through pre-configured information in some embodiments of this specification;

[0048] Figure 4 It is a schematic diagram of the steps for determining the domain controller in some embodiments of this specification;

[0049] Figure 5 It is a schematic diagram of the steps for judging whether to grant the permission to log in to the user terminal in some embodiments of this specification;

[0050] Figure 6 Schematic diagram of steps for live authentication of real-time facial images in some embodiments of this specification;

[0051] Figure 7 Schematic diagram of steps for verifying the current login log using historical login logs in some embodiments of this specification;

[0052] Figure 8 Schematic diagram of the structure of a security enhancement device for remote login of the Secure Shell protocol in some embodiments of this specification;

[0053] Figure 9 Schematic diagram of the computer device provided in some embodiments of this specification.

[0054]

Description of the reference numerals

[0055] 101, Terminal;

[0056] 102, Bastion host;

[0057] 103, Domain controller;

[0058] 801, Receiving module;

[0059] 802, Determining module;

[0060] 803, Judging module;

[0061] 804, Authentication module;

[0062] 805, Termination module;

[0063] 902, Computer device;

[0064] 904, Processor;

[0065] 906, Memory;

[0066] 908, Driving mechanism;

[0067] 910, Input / output interface;

[0068] 912, Input device;

[0069] 914, Output device;

[0070] 916, Presentation device;

[0071] 918, Graphical user interface;

[0072] 920, Network interface;

[0073] 922, Communication link;

[0074] 924. Communication bus. Detailed implementation manners

[0075] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in some embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Based on some embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this specification.

[0076] It should be noted that the terms "first", "second", etc. in the specification, claims and above-mentioned drawings of this article are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this article described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any of their deformations are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or equipment.

[0077] It should be noted that the acquisition, storage, use, processing, etc. of data in the technical solution of this application all comply with the relevant regulations of relevant laws and regulations.

[0078] It should be noted that in the embodiments of this specification, some industry-existing solutions such as certain software, components, models, etc. may be mentioned. They should be regarded as exemplary, and their purpose is only to illustrate the feasibility in the implementation of the technical solution of this application, but it does not mean that the applicant has already or necessarily used this solution.

[0079] Such as Figure 1The following is a schematic diagram of an implementation system for a security enhancement method for Secure Shell (SSH) protocol remote login according to an embodiment of the present invention, which may include: a terminal 101, a bastion host 102, and a domain controller 103. The terminal 101, the bastion host 102, and the domain controller 103 communicate with each other through a network. The network may include a Local Area Network (LAN), a Wide Area Network (WAN), the Internet, or a combination thereof, and is connected to a website, user equipment (such as a computing device), and a backend system. A staff member may send an SSH protocol remote login request to the bastion host 102 through the terminal 101. After receiving the SSH protocol remote login request, the bastion host 102 responds to the SSH protocol remote login request, determines the information to be authenticated corresponding to the SSH protocol remote login request, and obtains pre-configured information from the domain controller 103 to process the information to be authenticated and the pre-configured information, obtains a processing result, and sends the processing result to the terminal 101 so that the user can achieve secure remote login according to the processing result.

[0080] In an embodiment of this specification, the domain controller 103 may be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms.

[0081] In an optional embodiment, the terminal 101 may include, but is not limited to, types of electronic devices such as self-service terminal devices, desktop computers, tablet computers, laptop computers, and smart wearable devices. Optionally, the operating system running on the electronic device may include, but is not limited to, Android, IOS, Linux, Windows, etc. Of course, the terminal 101 is not limited to the above-mentioned electronic devices with a certain entity, and it may also be software running on the above-mentioned electronic devices.

[0082] In addition, it should be noted that Figure 1 The following shows only an application environment provided by the present disclosure. In actual applications, there may also be multiple terminals 101, which are not limited in this specification.

[0083] Figure 2It is a flowchart of a security reinforcement method for remote login of the Secure Shell (SSH) protocol provided by an embodiment of the present invention. This specification provides the method operation steps as described in the embodiment or flowchart, but based on routine or non-creative labor, it may include more or fewer operation steps. The step order listed in the embodiment is only one of the execution orders of numerous steps and does not represent the only execution order. When the actual system or device product executes, it can be executed in the order of the method shown in the embodiment or the accompanying drawings, or executed in parallel. Specifically, as Figure 2 shown, applied to the server side as described above, the method may include:

[0084] S201: Obtain a remote login request for the Secure Shell protocol;

[0085] S202: Determine the information to be authenticated corresponding to the remote login request for the Secure Shell protocol;

[0086] The information to be authenticated includes a first ciphertext obtained by encrypting a first content input by a user according to a preset first key;

[0087] S203: Use a bastion host to obtain pre-configured information from the domain controller corresponding to the remote login request for the Secure Shell protocol, so as to judge the validity of the information to be authenticated by comparing the first ciphertext and a second ciphertext in the pre-configured information; wherein, the second ciphertext is obtained by encrypting a second content having a corresponding relationship with the first content according to a preset second key; and

[0088] The bastion host itself does not store pre-configured information and deletes the obtained pre-configured information after completing the validity judgment of the information to be authenticated;

[0089] S204: If the information to be authenticated is valid, perform a liveness authentication on the user, so that the bastion host judges whether to grant the permission to log in to the user terminal;

[0090] S205: If the information to be authenticated is invalid, terminate the current session.

[0091] As can be seen from the technical solutions provided in the embodiments of this specification above, the embodiments of this specification first obtain a Secure Shell (SSH) protocol remote login request to determine corresponding information to be authenticated. The information to be authenticated includes a first ciphertext obtained by encrypting a first content input by a user according to a preset first key, so that the first content input by the user is transmitted from the user terminal to the bastion host in an encrypted manner. Then, the bastion host obtains preconfigured information for verifying the validity of the information to be authenticated from the domain controller corresponding to the SSH protocol remote login request. The preconfigured information includes a second ciphertext obtained by encrypting a second content having a corresponding relationship with the first content according to a preset second key, so that the preconfigured information obtained by the bastion host is also obtained in an encrypted transmission manner, ensuring the security of data transmission. And the corresponding relationship between the first content and the second content ensures that appropriate preconfigured information can be quickly and accurately called to determine the validity of the information to be authenticated.

[0092] Moreover, the bastion host does not store the preconfigured information itself, and deletes the obtained preconfigured information after completing the validity judgment of the information to be authenticated, so as to implement the interaction process between the terminal and the remote server of the SSH protocol remote login in a decoupled manner in the domain control mode, thereby avoiding the problem of ciphertext leakage that may be caused by the bastion host storing valid password information. And the entire secure login process is implemented in a multi-terminal mode of the user terminal, the bastion host, the domain controller, and the remote server, which can avoid the security risk problems caused by single-terminal accidents to a certain extent. And after verifying the information to be authenticated, live authentication of the user is performed again, which not only avoids the opportunity for an attacker to forge live authentication, but also fully ensures the security and effectiveness of the login permission issuance, and can implement multi-dimensional SSH protocol remote login verification to enhance the security of SSH protocol remote login.

[0093] It can be understood that in some embodiments, the user operates on a terminal in the domain control mode, for example, through an SSH protocol remote login tool, and hopes to establish a connection with the remote server. The bastion host can be understood as an intermediate jump unit for the user terminal to achieve remote login, and all operation behaviors of the user need to be recorded by the bastion host to facilitate the smooth progress of operations such as operation and maintenance and auditing. Specifically, the first content input by the user may include a user identifier symbolizing the user identity and information such as a password / passphrase corresponding to the user identifier. In some embodiments, after the user inputs the first content, the corresponding information to be authenticated is quickly generated and sent to the bastion host, and the bastion host and the terminal do not save any information such as user identifiers, passwords / passphrases, and information to be authenticated, thereby reducing the possibility of the user terminal leaking sensitive information.

[0094] After obtaining the information to be authenticated, the bastion host needs to verify it to determine its validity. In some embodiments, the bastion host is used to obtain preconfigured information from the domain controller corresponding to the Secure Shell (SSH) protocol remote login request, and the validity of the information to be authenticated is determined by comparing the first ciphertext and the second ciphertext in the preconfigured information, including:

[0095] Using the bastion host, according to the first user identifier corresponding to the first content, the preconfigured information collection in the domain controller corresponding to the SSH protocol remote login request is searched to obtain the corresponding preconfigured information by finding the second user identifier that matches the first user identifier, so that the bastion host can determine the validity of the information to be authenticated by comparing the first ciphertext and the second ciphertext in the preconfigured information.

[0096] It can be understood that in some embodiments, since the domain controller stores a preconfigured information collection composed of multiple preconfigured information for implementing the SSH protocol remote login of multiple users, after obtaining the information to be authenticated, it is first necessary to find the preconfigured information that matches the information to be authenticated from the preconfigured information collection. Specifically, in some embodiments, the bastion host needs to find the second user identifier that matches the first user identifier from the preconfigured information collection in the domain controller corresponding to the SSH protocol remote login request according to the first user identifier corresponding to the first content, and based on the key-value correspondence relationship preset between the second user identifier and the preconfigured information, quickly and accurately obtain the corresponding preconfigured information, so that the bastion host can determine the validity of the information to be authenticated through the preconfigured information.

[0097] Further, in some embodiments, the preconfigured information includes a second ciphertext obtained by encrypting the second content corresponding to the first content according to a preset second key to ensure the security of the preconfigured information, and the first content and the second content have a corresponding relationship. For example, the second content may be the same as the first content, or the first content is a part of the second content, or the second content is a part of the first content. This is not limited herein to facilitate quickly and accurately determining the validity of the information to be authenticated according to the preconfigured information later.

[0098] Specifically, in some embodiments, there is an association relationship between the first key and the second key. Refer to the appendix Figure 3 In some embodiments, the bastion host determines the validity of the information to be authenticated by comparing the first ciphertext and the second ciphertext in the preconfigured information. Further, it may include:

[0099] S301: Based on the association relationship, use the bastion host to determine the corresponding third key;

[0100] S302: Determine whether the first ciphertext matches the second ciphertext according to the third key by using a preset comparison algorithm;

[0101] S303: If they match, the information to be authenticated is valid;

[0102] S304: If they do not match, the information to be authenticated is invalid.

[0103] It can be understood that in some embodiments, there is an association relationship between the first key and the second key. This association relationship can be that the first key and the second key are the same key, for example, both are the same public key, or the first key and the second key are different keys, which is not limited herein. Based on this association relationship, the corresponding third key can be determined. For example, when the first key and the second key are the same key, the third key is the private key corresponding to the first key and the second key at this time. The third key decrypts the first ciphertext and the second ciphertext, and uses a preset comparison algorithm to compare the decryption results of the two to determine whether the first ciphertext matches the second ciphertext. When the first key and the second key are not the same key, the third key includes the private key corresponding to the first key and the private key corresponding to the second key. According to the third key, the first ciphertext and the second ciphertext can be decrypted respectively, and the decryption results obtained from the two are compared to determine whether the first ciphertext matches the second ciphertext.

[0104] Further, in some embodiments, when the first key and the second key are not the same key, if the third key includes the private key corresponding to the first key and the private key corresponding to the second key, then it is necessary to decrypt both the first ciphertext and the second ciphertext, which may increase the risk of leaking the decrypted plaintext. Therefore, in order to reduce the risk of information leakage, the third key can also include the private key of the first ciphertext and the second key, or the private key of the second ciphertext and the first ciphertext. Taking the third key including the private key of the first ciphertext and the second key as an example, the first ciphertext can be decrypted first by using the private key of the first ciphertext, and then the decryption result can be encrypted by using the second key. A preset comparison algorithm is used to determine whether the encrypted result matches the second ciphertext, so as to quickly and safely determine the validity of the information to be authenticated. In some embodiments, the preset comparison algorithm can be a homomorphic comparison algorithm, which is not limited herein.

[0105] In some embodiments, the bastion host does not store pre-configured information itself, and in order to ensure data security, after the validity of the information to be authenticated is determined, the bastion host will immediately delete the pre-configured information that has been obtained.

[0106] Refer to the appendix Figure 4 , in some embodiments, there may be multiple domain controllers in the current domain control mode, and determining the domain controller may further include:

[0107] S401: Obtain the domain information in the Secure Shell protocol remote login request by using the bastion host;

[0108] S402: Determine whether the domain information matches the current domain controller corresponding to the user terminal;

[0109] S403: If it matches, obtain the domain controller corresponding to the Secure Shell protocol remote login request according to the domain controller corresponding to the current user terminal;

[0110] S404: If it does not match, forward the domain information to the domain controller associated with the current domain controller for matching to obtain the domain controller corresponding to the Secure Shell protocol remote login request.

[0111] It can be understood that in some embodiments, first, it is determined whether the domain information in the Secure Shell protocol remote login request matches the current domain controller corresponding to the user terminal. If it matches or there is no restrictive requirement for the domain information, the domain controller corresponding to the current user terminal is used as the domain controller corresponding to the Secure Shell protocol remote login request. If it does not match, the domain information needs to be forwarded to the domain controller associated with the current domain controller for matching to obtain the domain controller corresponding to the Secure Shell protocol remote login request, so that the Secure Shell protocol remote login request can run across domain controllers, meet the needs of the current user terminal to access shared resources on other associated domain controllers, and this solution can greatly improve the security performance of access and avoid possible risk problems caused by running across domain controllers.

[0112] Refer to the appendix Figure 5 , in some embodiments, if the information to be authenticated is valid, perform liveness authentication on the user so that the bastion host determines whether to grant the login permission to the user terminal, which may include:

[0113] S501: If the information to be authenticated is valid, obtain the real-time facial image of the user and perform liveness authentication on the real-time facial image;

[0114] S502: If the liveness authentication passes, the bastion host grants the login permission to the user;

[0115] S503: If the liveness authentication fails and the number of failed attempts reaches the preset value, lock the current session and obtain the user feedback so that the domain controller determines whether to unlock the current session according to the user feedback.

[0116] It can be understood that in some embodiments, if the information to be authenticated is valid, refer to the appendix Figure 6 , in some embodiments, obtaining the real-time facial image of the user and performing liveness authentication on the real-time facial image includes:

[0117] S601: Use the screen of the user terminal to emit dynamically changing detection light to irradiate the user's face and obtain a real-time face image;

[0118] S602: Determine whether the user passes the liveness authentication according to the real-time face image, and after the liveness authentication passes, use a preset face database for authentication and identification.

[0119] Specifically, in some embodiments, the emission of the dynamically changing detection light can be achieved by dynamically switching the display lights of different brightness and colors on the entire screen or a part of the screen, so that no new hardware device needs to be introduced to ensure the acquisition of an effective real-time face image. Then, first, determine whether the user passes the liveness authentication according to the real-time face image, and after the liveness authentication passes, use a preset face database for authentication and identification. After the liveness authentication passes, the bastion host issues the permission to log in to the user. If the liveness authentication fails or the authentication and identification fails, both indicate that the liveness authentication fails. And if the number of failed times reaches the preset value, lock the current session and obtain the user feedback, so that the domain controller determines whether to unlock the current session according to the user feedback, thereby ensuring the security of remote login through the dual authentication method.

[0120] Refer to the appendix Figure 7 , in some embodiments, it may further include:

[0121] S701: Obtain the historical login logs;

[0122] S702: Record the corresponding current login logs according to the Secure Shell protocol remote login request;

[0123] S703: Use the historical login logs to verify the current login logs.

[0124] It can be understood that in some embodiments, the bastion host can comprehensively and accurately record the current login logs, including time, location, authentication status, etc., and it is convenient to obtain comprehensive and accurate historical login logs, so as to realize the verification of the current login logs by using the historical login logs, which is convenient for subsequent risk investigation and review work.

[0125] It should be noted that although the operations of the method of the present invention are described in a specific order in the above embodiments and the accompanying drawings, this does not require or imply that these operations must be performed in this specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.

[0126] Corresponding to the above security reinforcement method for remote login of the Secure Shell protocol, some embodiments of this specification also provide a security reinforcement device for remote login of the Secure Shell protocol. Refer to Figure 8 As shown, in some embodiments, the device may include:

[0127] A receiving module 801, configured to obtain a Secure Shell protocol remote login request;

[0128] A determining module 802, configured to determine authentication information corresponding to the Secure Shell protocol remote login request; the authentication information includes a first ciphertext obtained by encrypting a first content input by a user according to a preset first key;

[0129] A judging module 803, configured to obtain pre-configured information from a domain controller corresponding to the Secure Shell protocol remote login request by using a bastion host, and judge the validity of the authentication information by comparing the first ciphertext and a second ciphertext in the pre-configured information; wherein, the second ciphertext is obtained by encrypting a second content having a corresponding relationship with the first content according to a preset second key; and

[0130] The bastion host itself does not store pre-configured information, and deletes the obtained pre-configured information after completing the validity judgment of the authentication information;

[0131] An authentication module 804, configured to perform liveness authentication on the user if the authentication information is valid, so that the bastion host judges whether to grant a login permission to the user terminal;

[0132] A termination module 805, configured to terminate the current session if the authentication information is invalid.

[0133] For the convenience of description, when describing the above device, various units are described separately according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in one or more software and / or hardware.

[0134] It should be noted that in the embodiments of this specification, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved are all information and data that have been authorized and consented by the user and fully authorized by all parties.

[0135] It should be noted that the computer program product described in this specification is a software product mainly implementing the method described in this specification through a computer program.

[0136] The embodiments of this specification also provide a computer device. As Figure 9As shown, in some embodiments of this specification, the computer device 902 may include one or more processors 904, such as one or more central processing units (CPUs) or graphics processing units (GPUs), and each processing unit may implement one or more hardware threads. The computer device 902 may also include any memory 906, which is used to store any kind of information such as code, settings, data, etc. In a specific embodiment, a computer program stored on the memory 906 and executable on the processor 904, when run by the processor 904, may execute the instructions of the method described in any of the above embodiments. Non-limitingly, for example, the memory 906 may include any one or more combinations of the following: any type of RAM, any type of ROM, flash memory devices, hard disks, optical discs, etc. More generally, any memory may use any technology to store information. Further, any memory may provide volatile or non-volatile retention of information. Further, any memory may represent a fixed or removable component of the computer device 902. In one case, when the processor 904 executes the associated instructions stored in any memory or combination of memories, the computer device 902 may perform any operation of the associated instructions. The computer device 902 also includes one or more drive mechanisms 908 for interacting with any memory, such as a hard disk drive mechanism, an optical disc drive mechanism, etc.

[0137] The computer device 902 may also include an input / output interface 910 (I / O), which is used to receive various inputs (via the input device 912) and to provide various outputs (via the output device 914). A specific output mechanism may include a presentation device 916 and an associated graphical user interface 918 (GUI). In other embodiments, the input / output interface 910 (I / O), the input device 912, and the output device 914 may not be included, and it may only be a computer device in a network. The computer device 902 may also include one or more network interfaces 920, which are used to exchange data with other devices via one or more communication links 922. One or more communication buses 924 couple the components described above together.

[0138] The communication link 922 may be implemented in any way, for example, through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication link 922 may include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc. governed by any protocol or combination of protocols.

[0139] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), computer-readable storage media, and computer program products according to some embodiments of the present specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processors to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processors generate a device for implementing the functions specified in one or more flows Figure 1 or more flows and / or blocks Figure 1 or a device for implementing the functions specified in one or more blocks.

[0140] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processors to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in one or more flows Figure 1 or more flows and / or blocks Figure 1 or a device for implementing the functions specified in one or more blocks.

[0141] These computer program instructions can also be loaded onto a computer or other programmable data processors, such that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in one or more flows Figure 1 or more flows and / or blocks Figure 1 or a device for implementing the functions specified in one or more blocks.

[0142] In a typical configuration, a computer device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.

[0143] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0144] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information accessible by a computer device. As defined in this specification, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0145] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, the embodiments of this specification can take the form of an all-hardware embodiment, an all-software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0146] The embodiments of this specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The embodiments of this specification can also be practiced in a distributed computing environment where tasks are performed by remote processors connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0147] It should also be understood that in the embodiments of this specification, the term "and / or" is merely a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.

[0148] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and for related parts, reference can be made to the description of the method embodiments.

[0149] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the embodiments of this specification. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0150] The above description is only for the embodiments of this application and is not intended to limit this application. For those skilled in the art, various changes and modifications can be made to this application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall be included within the scope of the claims of this application.

Claims

1. A security reinforcement method for remote login of Secure Shell protocol, characterized in that, The method includes: Obtaining a Secure Shell (SSH) protocol remote login request; Determining authentication information corresponding to the SSH protocol remote login request; the authentication information includes a first ciphertext obtained by encrypting first content input by a user according to a preset first key; Using a bastion host to obtain pre-configured information from a domain controller corresponding to the SSH protocol remote login request, so as to determine the validity of the authentication information by comparing the first ciphertext and a second ciphertext in the pre-configured information; wherein, the second ciphertext is obtained by encrypting second content having a corresponding relationship with the first content according to a preset second key; and The bastion host itself does not store pre-configured information, and deletes the obtained pre-configured information after completing the validity judgment of the authentication information; If the authentication information is valid, perform liveness authentication on the user, so that the bastion host determines whether to grant a login permission to the user terminal; If the authentication information is invalid, terminate the current session.

2. The method according to claim 1, characterized in that, Using a bastion host to obtain pre-configured information from a domain controller corresponding to the SSH protocol remote login request, so as to determine the validity of the authentication information by comparing the first ciphertext and a second ciphertext in the pre-configured information, includes: Using the bastion host, according to a first user identifier corresponding to the first content, obtaining corresponding pre-configured information by searching for a second user identifier matching the first user identifier from a pre-configured information collection in the domain controller corresponding to the SSH protocol remote login request, so that the bastion host determines the validity of the authentication information by comparing the first ciphertext and the second ciphertext in the pre-configured information.

3. The method according to claim 2, wherein there is an association relationship between the first key and the second key, characterized in that The bastion host determining the validity of the authentication information by comparing the first ciphertext and the second ciphertext in the pre-configured information further includes: Based on the association relationship, using the bastion host to determine a corresponding third key; According to the third key, using a preset comparison algorithm to determine whether the first ciphertext matches the second ciphertext; If they match, the authentication information is valid; If they do not match, the authentication information is invalid.

4. The method according to claim 2, wherein Further includes: Using the bastion host to obtain domain information in the SSH protocol remote login request; Judging whether the domain information matches the current domain controller corresponding to the user terminal; If they match, obtaining the domain controller corresponding to the SSH protocol remote login request according to the domain controller corresponding to the current user terminal; If they do not match, forwarding the domain information to a domain controller associated with the current domain controller for matching to obtain the domain controller corresponding to the SSH protocol remote login request.

5. The method according to claim 1, characterized in that, If the authentication information is valid, performing liveness authentication on the user, so that the bastion host determines whether to grant a login permission to the user terminal, includes: If the authentication information is valid, obtaining a real-time facial image of the user and performing liveness authentication on the real-time facial image; If the liveness authentication passes, the bastion host grants a login permission to the user; If the live authentication fails and the number of failed attempts reaches a preset value, lock the current session and obtain user feedback so that the domain controller can determine whether to unlock the current session based on the user feedback.

6. The method according to claim 1, characterized in that, Further includes: Obtain historical login logs; Record the corresponding current login log according to the Secure Shell protocol remote login request; Verify the current login log using the historical login log.

7. A security reinforcement device for remote login of Secure Shell protocol, characterized in that, The device includes: A receiving module for obtaining a Secure Shell protocol remote login request; A determination module for determining the authentication information corresponding to the Secure Shell protocol remote login request; the authentication information includes a first ciphertext obtained by encrypting a first content input by the user according to a preset first key; A judgment module for using the bastion host to obtain pre-configured information from the domain controller corresponding to the Secure Shell protocol remote login request, and judging the validity of the authentication information by comparing the first ciphertext and the second ciphertext in the pre-configured information; wherein, the second ciphertext is obtained by encrypting a second content corresponding to the first content according to a preset second key; and The bastion host itself does not store pre-configured information and deletes the obtained pre-configured information after completing the validity judgment of the authentication information; An authentication module for performing live authentication on the user if the authentication information is valid, so that the bastion host determines whether to grant the user terminal the permission to log in; A termination module for terminating the current session if the authentication information is invalid.

8. A computer device, comprising a memory, a processor, and a computer program stored on the memory, characterized in that When the computer program is run by the processor, it executes the instructions of the method according to any one of claims 1-6.

9. A computer storage medium having a computer program stored thereon, characterized in that, When the computer program is run by the processor of the computer device, it executes the instructions of the method according to any one of claims 1-6.

10. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is run by the processor, it executes the instructions of the method according to any one of claims 1-6.