Configuration issuing method, device and equipment based on Kerberos authentication

By building a configuration dictionary and an automated configuration module, the problems of long processing time and low accuracy when accessing the data warehouse from different platforms were solved, and fast and accurate configuration distribution was achieved.

CN120658456APending Publication Date: 2025-09-16CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510802904.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

In the context of the Internet of Vehicles, with the diversification of vehicle data access to data warehouses, different configuration requirements are placed on different platforms, resulting in problems such as long configuration time and low accuracy.

Method used

A configuration dictionary is built, which includes various types of configuration data. The dictionary is queried based on the target platform, and the corresponding configuration module is called to automatically distribute the configuration data, thereby realizing automated configuration management.

Benefits of technology

It achieves automated configuration management, reduces configuration time, improves accuracy, and supports multi-platform adaptation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658456A_ABST
    Figure CN120658456A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a configuration issuing method, device and equipment based on Kerberos certification, and the method comprises the steps: constructing a configuration dictionary which comprises various types of configuration data required by a plurality of docking platforms to access a target data warehouse; querying the configuration dictionary based on the target docking platform, and determining various types of configuration data required by the target docking platform for accessing the target data bin; and calling a corresponding configuration module based on the type of the configuration data, and issuing the corresponding configuration data to the target docking platform by the configuration module, so that the target docking platform accesses the target data bin. Therefore, the problems of long time consumption, low accuracy and the like when different types of platforms are accessed to the number bins for configuration in the related technology are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a configuration delivery method, apparatus, and device based on Kerberos authentication. Background Art

[0002] In the context of vehicle networks and data warehouses with Kerberos (network authentication protocol, identity authentication mechanism) security authentication enabled, as more and more vehicle data is connected, the requirements for data processing and timeliness are becoming increasingly diverse. This has led to the emergence of many systems that connect to big data clusters, such as offline scheduling platforms, real-time scheduling platforms, alarm platforms, Jupter, Kyuubi, DataOS, and other docking platforms. Each platform has a different architectural design and different requirements for platform administrator accounts, Kerberos keytab files, offline real-time tasks, configuration files, etc.

[0003] As a data warehouse operation and maintenance personnel, the connection between different platforms requires different parameter configurations, different administrator accounts, and different account permissions. As the number of systems increases, the number of connection configurations increases. In the scenario where the data warehouse big data environment needs to be delivered quickly, the operation and maintenance personnel need to manually configure and issue each connection, which is extremely time-consuming and has a very low accuracy rate. Once a problem occurs, it is necessary to repeatedly check and configure with the platform development. Summary of the Invention

[0004] This application provides a configuration delivery method, device, and equipment based on Kerberos authentication to solve the problems in related technologies such as long time consumption and low accuracy when configuring different types of platforms to access data warehouses.

[0005] The first embodiment of the present application provides a configuration delivery method based on Kerberos authentication, comprising the following steps: constructing a configuration dictionary, wherein the configuration dictionary includes multiple types of configuration data required for multiple docking platforms to access a target data warehouse; querying the configuration dictionary based on the target docking platform to determine the multiple types of configuration data required for the target docking platform to access the target data warehouse; calling a corresponding configuration module based on the type of configuration data, and the configuration module delivering the corresponding configuration data to the target docking platform to enable the target docking platform to access the target data warehouse.

[0006] Optionally, in one embodiment of the present application, the multiple types of configuration data include Kerberos principal data, dependency configuration data, and user configuration data.

[0007] Optionally, in one embodiment of the present application, the corresponding configuration module is called based on the type of configuration data, including: if the type of the configuration data is Kerberos principal data, the first configuration module is called, and the first configuration module processes the principal data of the target docking platform; if the type of the configuration data is dependent configuration data, the second configuration module is called, and the second configuration module processes the dependent configuration data of the target docking platform; if the type of the configuration data is user configuration data, the third configuration module is called, and the third configuration module processes the user configuration data of the target docking platform.

[0008] Optionally, in one embodiment of the present application, the first configuration module is used to: identify the Kerberos subject data of the target docking platform or the user of the target docking platform; identify the Kerberos key distribution center of the target data warehouse; send the subject data to the key distribution center of the target data warehouse, wherein the key distribution center generates a key file based on the subject data, key version number, encryption type and encryption key; and send the key file to the target directory of the target machine of the target docking platform, wherein the target machine and target directory of the target docking platform are determined based on the configuration dictionary.

[0009] Optionally, in one embodiment of the present application, the second configuration module is used to: identify a target configuration file in the dependent configuration data; and send the target configuration file to a target directory of a target machine of a target docking platform.

[0010] Optionally, in one embodiment of the present application, the third configuration module is used to: identify user configuration data; create a user on a target machine of a target docking platform based on the user configuration data, and set corresponding permissions for the user based on the user configuration data.

[0011] The second aspect of the present application provides a configuration delivery device based on Kerberos authentication, including: a construction module for constructing a configuration dictionary, wherein the configuration dictionary includes multiple types of configuration data required for multiple docking platforms to access a target data warehouse; a query module for querying the configuration dictionary based on the target docking platform to determine the multiple types of configuration data required for the target docking platform to access the target data warehouse; a delivery module for calling a corresponding configuration module based on the type of configuration data, and the configuration module delivers the corresponding configuration data to the target docking platform to enable the target docking platform to access the target data warehouse.

[0012] Optionally, in one embodiment of the present application, the multiple types of configuration data include Kerberos principal data, dependency configuration data, and user configuration data.

[0013] Optionally, in one embodiment of the present application, the sending module is further used to: if the type of the configuration data is Kerberos principal data, call the first configuration module, and the first configuration module processes the principal data of the target docking platform; if the type of the configuration data is dependent configuration data, call the second configuration module, and the second configuration module processes the dependent configuration data of the target docking platform; if the type of the configuration data is user configuration data, call the third configuration module, and the third configuration module processes the user configuration data of the target docking platform.

[0014] Optionally, in one embodiment of the present application, the first configuration module is used to: identify the Kerberos subject data of the target docking platform or the user of the target docking platform; identify the Kerberos key distribution center of the target data warehouse; send the subject data to the key distribution center of the target data warehouse, wherein the key distribution center generates a key file based on the subject data, key version number, encryption type and encryption key; and send the key file to the target directory of the target machine of the target docking platform, wherein the target machine and target directory of the target docking platform are determined based on the configuration dictionary.

[0015] Optionally, in one embodiment of the present application, the second configuration module is used to: identify a target configuration file in the dependent configuration data; and send the target configuration file to a target directory of a target machine of a target docking platform.

[0016] Optionally, in one embodiment of the present application, the third configuration module is used to: identify user configuration data; create a user on a target machine of a target docking platform based on the user configuration data, and set corresponding permissions for the user based on the user configuration data.

[0017] The third aspect of the present application provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and runnable on the processor. The processor executes the program to perform the configuration delivery method based on Kerberos authentication as described in the above embodiment.

[0018] The fourth aspect of the present application provides a computer-readable storage medium having a computer program or instruction stored thereon, and the computer program or instruction is executed by a processor to execute the configuration delivery method based on Kerberos authentication as described in the above embodiment.

[0019] The fifth aspect of the present application provides a computer program product, including a computer program or instructions. When the computer program or instructions are executed, they can implement the configuration delivery method based on Kerberos authentication as described in the above embodiment.

[0020] Therefore, this application has at least the following beneficial effects:

[0021] The embodiment of the present application can construct a configuration dictionary including various types of configuration data required for multiple docking platforms to access the data warehouse, and query the configuration dictionary based on the target docking platform to determine the various types of configuration data required for the target docking platform to access the target data warehouse, and then call the corresponding configuration module according to the type of configuration data, and send the corresponding configuration data to the target docking platform through the configuration module to enable the target platform to access, thereby realizing automated management of the configuration, achieving one-click configuration, avoiding manual configuration by operation and maintenance personnel, reducing configuration time, and based on the dictionary structured data, it can improve the accuracy of the configuration, support multi-platform adaptation, and manage the differentiated configuration requirements of different platforms through a unified dictionary. As a result, the technical problems in the related technology such as long time consumption and low accuracy when configuring different types of platforms to access the data warehouse are solved.

[0022] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0024] Figure 1 A flowchart of a configuration delivery method based on Kerberos authentication provided in accordance with an embodiment of the present application;

[0025] Figure 2 A complete flow chart of a configuration delivery method based on Kerberos authentication according to an embodiment of the present application;

[0026] Figure 3 This is a timing diagram of module 1 provided according to an embodiment of the present application;

[0027] Figure 4 This is a timing diagram of module 2 provided according to an embodiment of the present application;

[0028] Figure 5 This is a timing diagram of module three provided according to an embodiment of the present application;

[0029] Figure 6 This is an example diagram of a configuration delivery device based on Kerberos authentication according to an embodiment of the present application;

[0030] Figure 7 A schematic diagram of the structure of an electronic device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0031] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0032] The following describes the configuration delivery method, device and equipment based on Kerberos authentication of the embodiment of the present application with reference to the accompanying drawings. In view of the fact that the data warehouse operation and maintenance personnel mentioned in the above background technology need to manually provide different parameter configurations, administrator accounts and account permissions when docking different platforms. As the number of systems increases, the docking configuration becomes more and more complicated. In the scenario of rapid delivery of data warehouse big data environment, manual configuration delivery not only consumes a lot of time, but also has the problem of low accuracy. The present application provides a configuration delivery method based on Kerberos authentication, in which a configuration dictionary including multiple types of configuration data required for multiple docking platforms to access the data warehouse can be constructed, and the configuration dictionary can be queried based on the target docking platform to determine the multiple types of configuration data required for the target docking platform to access the target data warehouse, and then the corresponding configuration module is called according to the type of configuration data, and the corresponding configuration data is delivered to the target docking platform through the configuration module, so that the target platform can be connected, thereby realizing automatic management of the configuration, avoiding manual configuration of operation and maintenance, reducing configuration time, and based on the dictionary structured data, improving the accuracy of configuration delivery, while supporting multi-platform adaptation, and managing the differentiated configuration requirements of different platforms through a unified dictionary. This solves the problems in related technologies such as long time consumption and low accuracy when configuring different types of platforms to access data warehouses.

[0033] Specifically, Figure 1 A flowchart of a configuration delivery method based on Kerberos authentication provided in an embodiment of the present application.

[0034] like Figure 1 As shown, the configuration delivery method based on Kerberos authentication includes the following steps:

[0035] In step S101 , a configuration dictionary is constructed, wherein the configuration dictionary includes various types of configuration data required for multiple docking platforms to access the target data warehouse.

[0036] Among them, various types of configuration data include Kerberos principal data, dependent configuration data, and user configuration data; the configuration dictionary is used to store a structured data set of configuration data required for different docking platforms to access the target data warehouse; the target data warehouse includes a vehicle network data warehouse with Kerberos security authentication enabled; the docking platform is a system that docks with the big data cluster, that is, a system that accesses the target data warehouse, such as an offline scheduling platform, a real-time scheduling platform, an alarm platform, jupter, kyuubi, dataos, etc.

[0037] Specifically, Kerberos principal data is used for the identity identifier Principal of Kerberos authentication, including user name, domain, and other information. It is used to generate the keytab authentication file and can be stored in the keytabs field. Dependent location data is the data warehouse big data component configuration file or jar package that the docking platform depends on, which can be stored in the confs field. User configuration data includes the data warehouse computing node account information required for the docking platform to execute tasks, including account name, password, home directory location, etc., which can be stored in the users field.

[0038] In step S102, a configuration dictionary is queried based on the target docking platform to determine various types of configuration data required for the target docking platform to access the target data warehouse.

[0039] It is understandable that the embodiments of the present application can query the configuration dictionary based on the target docking platform to determine various types of configuration data required for the target docking platform to access the target data warehouse.

[0040] In step S103, the corresponding configuration module is called based on the type of the configuration data, and the configuration module sends the corresponding configuration data to the target docking platform so that the target docking platform can access the target data warehouse.

[0041] It can be understood that the embodiment of the present application can call the corresponding configuration module based on the type of configuration data, and the configuration module can send the corresponding configuration data to the target docking platform so that the target docking platform can access the target data warehouse, thereby realizing automated management of the configuration, avoiding manual configuration of operation and maintenance, reducing configuration time, and based on dictionary structured data, improving the accuracy of configuration delivery, while supporting multi-platform adaptation, and managing the differentiated configuration requirements of different platforms through a unified dictionary.

[0042] In an embodiment of the present application, the corresponding configuration module is called based on the type of configuration data, including: if the type of the configuration data is Kerberos principal data, the first configuration module is called, and the first configuration module processes the principal data of the target docking platform; if the type of the configuration data is dependent configuration data, the second configuration module is called, and the second configuration module processes the dependent configuration data of the target docking platform; if the type of the configuration data is user configuration data, the third configuration module is called, and the third configuration module processes the user configuration data of the target docking platform.

[0043] It can be understood that the configuration modules of the embodiment of the present application mainly include three types, namely the first configuration module, the second configuration module and the third configuration module. Among them, the first configuration module is mainly used to process the main data of the target docking platform, that is, to process the Kerberos authentication related logic, the second configuration module is used to process the dependent configuration data of the target docking platform, that is, to process the distribution of dependent configuration files or jar packages, and the third configuration module is used to process the user configuration data of the target docking platform, that is, to process the creation and permission allocation of user accounts. By accurately calling modules according to different data types, confusion of different configuration logics can be avoided, and the distribution efficiency and accuracy can be improved.

[0044] In an embodiment of the present application, the first configuration module is used to: identify the Kerberos subject data of the target docking platform or the user of the target docking platform; identify the Kerberos key distribution center of the target data warehouse; send the subject data to the key distribution center of the target data warehouse, wherein the key distribution center generates a key file based on the subject data, key version number, encryption type and encryption key; and send the key file to the target directory of the target machine of the target docking platform, wherein the target machine and target directory of the target docking platform are determined based on the configuration dictionary.

[0045] Among them, KDC (Key Distribution Center) is the core component of the Kerberos system, responsible for generating and managing keys; the keytab file stores the Kerberos Principal and its encryption key file, which is used for server authentication.

[0046] It can be understood that the embodiments of the present application can obtain the Kerberos principal data of the target docking platform or user, and determine the Kerberos key distribution center address or configuration of the data warehouse. The key distribution center generates a keytab file based on the principal data, key version number, encryption type and key, and sends the keytab file to the specified directory of the target machine through the platform distribution tool.

[0047] Specifically, the first configuration module is responsible for processing Kerberos-related logic, and ultimately generates a keytab file containing an encryption key through the first configuration module, and distributes it to a specified directory of a specified machine through a platform distribution tool.

[0048] In the embodiment of the present application, the second configuration module is used to: identify the target configuration file in the dependent configuration data; and send the target configuration file to the target directory of the target machine of the target docking platform.

[0049] It can be understood that the embodiment of the present application can identify the target configuration file in the dependent configuration data from the configuration dictionary and transfer the target configuration file to the specified directory of the target machine. By automating the dependent configuration required by the platform, manual copying and configuration files of operation and maintenance can be avoided, reducing time consumption.

[0050] Specifically, the second configuration module is responsible for processing the configuration files or JAR dependencies of the data warehouse big data components that the access platform depends on. According to the configuration dictionary, it obtains the JAR or configuration files under the specified directory and finally distributes the configuration files to the directory of the specified machine through the platform distribution tool.

[0051] In an embodiment of the present application, the third configuration module is used to: identify user configuration data; create a user on a target machine of a target docking platform based on the user configuration data, and set corresponding permissions for the user based on the user configuration data.

[0052] It can be understood that the third configuration module of the embodiment of the present application can identify user configuration data, create users on the target machine of the target docking platform based on the user configuration data, and set corresponding permissions for users based on the user configuration data, thereby realizing automated management of user accounts of data warehouse nodes and avoiding the tedious process of manually creating accounts and the risks of password management.

[0053] Specifically, the third configuration module handles the accounts for the data warehouse compute nodes that the access platform relies on during task execution. By invoking platform-delivered tools, it ultimately generates designated accounts within the data warehouse compute nodes. Because some systems may rely on account passwords, a random password is assigned to the designated account. Some middleware relies on the user's home directory, so users can also be created in a specified home directory location.

[0054] In summary, because the Kerberos KDC varies across data warehouses and big data environments, this application first needs to identify the Kerberos KDC when issuing configurations. After obtaining the principle, it issues a command to the KDC to generate a keytab entry containing the principal name, key version number, encryption type, and the encryption key itself, and writes it to a specified file. After obtaining the authentication file, it is issued to the designated directory on each platform and assigned the specified permissions.

[0055] In addition, although different access platforms have different processing logics for data processing, the ultimate goal of the access platform is to access the data warehouse big data cluster and process different data through different components of the big data cluster. Therefore, each access platform relies on different component configuration files, and the locations that need to be sent to the access platform are also different. After receiving the configuration command sent by the access platform, this application will send the configuration to the specified directory and assign relevant permission bits based on the requirements of different platforms for configuration files of different big data components.

[0056] The access platform relies on the data warehouse computing node account when executing tasks. After receiving the configuration command issued by the access platform, this application will generate a specified account in the data warehouse computing node. Because some systems may rely on account passwords, a random password will be assigned to the specified account.

[0057] The following describes the configuration delivery method based on Kerberos authentication of this application through a specific embodiment. The process is as follows: Figure 2 As shown, the following steps are included:

[0058] 1. First, set up a configuration dictionary, which contains the docking configurations for different access platforms.

[0059] For example, the ds (Dispatch System, offline scheduling platform) platform connection relies on keytab, jar, conf files, and Python 3.8 environment, which can be configured as follows:

[0060]

[0061] 2. Determine whether the tool specifies the platform for connecting to the data warehouse (that is, whether a dictionary key is specified). Iterate through the keys in the configuration dictionary and determine which module needs to be selected and processed based on the value corresponding to the key.

[0062] 3. The processing module mainly includes the following three.

[0063] 3.1 Module 1 (i.e. the first configuration module) is responsible for processing Kerberos-related logic. Module 1 ultimately generates a keytab file containing the encryption key and distributes it to the designated directory of the designated machine through the platform distribution tool. The specific processing flow of Module 1 is as follows: Figure 3 shown.

[0064] 3.2 Module 2 (i.e., the second configuration module) is responsible for processing the configuration files or jar dependencies of the data warehouse big data components that the access platform relies on. According to the configuration dictionary, it obtains the jar or configuration files under the specified directory and finally distributes the configuration files to the directory of the specified machine through the platform distribution tool. The specific processing flow of Module 2 is as follows: Figure 4 shown.

[0065] 3.2 Module 3 is responsible for processing the accounts of the data warehouse computing nodes that the access platform relies on during the execution of tasks. By calling the platform's distribution tool, a specified account is finally generated in the data warehouse computing node. Because some systems may rely on account passwords, a random password will be assigned to the specified account; some middleware relies on the user's home directory, and users can also be created by specifying the home directory location. The specific processing flow of Module 3 is as follows Figure 5 shown.

[0066] According to the configuration distribution method based on Kerberos authentication proposed in the embodiment of the present application, a configuration dictionary including various types of configuration data required for multiple docking platforms to access the data warehouse can be constructed, and the configuration dictionary can be queried based on the target docking platform to determine the various types of configuration data required for the target docking platform to access the target data warehouse. Then, the corresponding configuration module is called according to the type of configuration data, and the corresponding configuration data is distributed to the target docking platform through the configuration module to enable the target platform to access, thereby realizing automated configuration management and one-click configuration distribution, avoiding manual configuration by operation and maintenance personnel, reducing configuration time, and based on dictionary structured data, the accuracy of configuration can be improved, while supporting multi-platform adaptation and managing the differentiated configuration requirements of different platforms through a unified dictionary.

[0067] Next, a configuration delivery device based on Kerberos authentication according to an embodiment of the present application will be described with reference to the accompanying drawings.

[0068] Figure 6 It is a block diagram of a configuration issuing device based on Kerberos authentication in an embodiment of the present application.

[0069] like Figure 6 As shown, the configuration issuing device 10 based on Kerberos authentication includes: a construction module 100 , a query module 200 and an issuing module 300 .

[0070] Among them, the construction module 100 is used to construct a configuration dictionary, wherein the configuration dictionary includes various types of configuration data required for multiple docking platforms to access the target data warehouse; the query module 200 is used to query the configuration dictionary based on the target docking platform to determine the various types of configuration data required for the target docking platform to access the target data warehouse; the sending module 300 is used to call the corresponding configuration module based on the type of configuration data, and the configuration module sends the corresponding configuration data to the target docking platform to enable the target docking platform to access the target data warehouse.

[0071] In the embodiment of the present application, the various types of configuration data include Kerberos principal data, dependency configuration data, and user configuration data.

[0072] In an embodiment of the present application, the sending module 300 is further used to: if the type of the configuration data is Kerberos principal data, call the first configuration module, and the first configuration module processes the principal data of the target docking platform; if the type of the configuration data is dependent configuration data, call the second configuration module, and the second configuration module processes the dependent configuration data of the target docking platform; if the type of the configuration data is user configuration data, call the third configuration module, and the third configuration module processes the user configuration data of the target docking platform.

[0073] In an embodiment of the present application, the first configuration module is used to: identify the Kerberos subject data of the target docking platform or the user of the target docking platform; identify the Kerberos key distribution center of the target data warehouse; send the subject data to the key distribution center of the target data warehouse, wherein the key distribution center generates a key file based on the subject data, key version number, encryption type and encryption key; and send the key file to the target directory of the target machine of the target docking platform, wherein the target machine and target directory of the target docking platform are determined based on the configuration dictionary.

[0074] In the embodiment of the present application, the second configuration module is used to: identify the target configuration file in the dependent configuration data; and send the target configuration file to the target directory of the target machine of the target docking platform.

[0075] In an embodiment of the present application, the third configuration module is used to: identify user configuration data; create a user on a target machine of a target docking platform based on the user configuration data, and set corresponding permissions for the user based on the user configuration data.

[0076] It should be noted that the above explanation of the embodiment of the configuration delivery method based on Kerberos authentication is also applicable to the configuration delivery device based on Kerberos authentication in this embodiment, and will not be repeated here.

[0077] According to the configuration distribution device based on Kerberos authentication proposed in the embodiment of the present application, a configuration dictionary including various types of configuration data required for multiple docking platforms to access the data warehouse can be constructed, and the configuration dictionary can be queried based on the target docking platform to determine the various types of configuration data required for the target docking platform to access the target data warehouse. Then, the corresponding configuration module is called according to the type of configuration data, and the corresponding configuration data is distributed to the target docking platform through the configuration module to enable the target platform to access, thereby realizing automated configuration management and one-click configuration distribution, avoiding manual configuration by operation and maintenance personnel, reducing configuration time, and based on dictionary structured data, the accuracy of configuration can be improved, while supporting multi-platform adaptation and managing the differentiated configuration requirements of different platforms through a unified dictionary.

[0078] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include:

[0079] Memory 701 , processor 702 , and computer programs stored in the memory 701 and executable on the processor 702 .

[0080] When the processor 702 executes the program, the configuration delivery method based on Kerberos authentication provided in the above embodiment is implemented.

[0081] Furthermore, the electronic device further includes:

[0082] The communication interface 703 is used for communication between the memory 701 and the processor 702 .

[0083] The memory 701 is used to store computer programs that can be run on the processor 702 .

[0084] The memory 701 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0085] If the memory 701, processor 702, and communication interface 703 are implemented independently, the communication interface 703, memory 701, and processor 702 can be interconnected via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be divided into address buses, data buses, control buses, etc. For ease of representation, Figure 7 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0086] Optionally, in a specific implementation, if the memory 701, the processor 702 and the communication interface 703 are integrated on a chip, the memory 701, the processor 702 and the communication interface 703 can communicate with each other through an internal interface.

[0087] The processor 702 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0088] An embodiment of the present application further provides a computer-readable storage medium having a computer program or instruction stored thereon. When the computer program or instruction is executed by a processor, the configuration delivery method based on Kerberos authentication as described above is implemented.

[0089] An embodiment of the present application further provides a computer program product, including a computer program or instructions, which, when executed, implements the above-mentioned configuration delivery method based on Kerberos authentication.

[0090] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.

[0091] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Thus, a feature specified as "first" or "second" may explicitly or implicitly include at least one such feature. In the description of this application, "N" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0092] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or N executable instructions for implementing a custom logical function or process step, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed in a different order than shown or discussed, including performing functions in a substantially simultaneous manner or in a reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application pertain.

[0093] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiment, the N steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, it can be implemented using any one or a combination of the following technologies known in the art: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array, a field programmable gate array, etc.

[0094] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

Claims

1. A configuration delivery method based on Kerberos authentication, characterized in that: The following steps are involved: Constructing a configuration dictionary, where the configuration dictionary includes various types of configuration data required for multiple docking platforms to access the target data warehouse; Querying the configuration dictionary based on the target docking platform to determine multiple types of configuration data required for the target docking platform to access the target data warehouse; A corresponding configuration module is called based on the type of the configuration data, and the configuration module sends the corresponding configuration data to the target docking platform, so that the target docking platform is connected to the target data warehouse.

2. The configuration delivery method based on Kerberos authentication according to claim 1, characterized in that: The multiple types of configuration data include Kerberos principal data, dependency configuration data, and user configuration data.

3. The configuration delivery method based on Kerberos authentication according to claim 2, characterized in that: The calling of a corresponding configuration module based on the type of the configuration data includes: If the type of the configuration data is the Kerberos principal data, calling a first configuration module, the first configuration module processes the principal data of the target docking platform; If the type of the configuration data is the dependent configuration data, calling a second configuration module, the second configuration module processes the dependent configuration data of the target docking platform; If the type of the configuration data is the user configuration data, a third configuration module is called, and the third configuration module processes the user configuration data of the target docking platform.

4. The configuration delivery method based on Kerberos authentication according to claim 3, characterized in that: The first configuration module is used to: Kerberos principal data identifying the target docking platform or a user of the target docking platform; Identify the Kerberos key distribution center of the target data warehouse; Sending the subject data to the key distribution center of the target data warehouse, wherein the key distribution center generates a key file based on the subject data, key version number, encryption type, and encryption key; The key file is sent to a target directory of a target machine of the target docking platform, wherein the target machine and the target directory of the target docking platform are determined based on the configuration dictionary.

5. The configuration delivery method based on Kerberos authentication according to claim 3, characterized in that: The second configuration module is used for: Identifying a target configuration file in the dependency configuration data; The target configuration file is sent to the target directory of the target machine of the target docking platform.

6. The configuration delivery method based on Kerberos authentication according to claim 3, characterized in that: The third configuration module is used for: identifying the user configuration data; A user is created on a target machine of the target docking platform based on the user configuration data, and corresponding permissions are set for the user based on the user configuration data.

7. A configuration issuing device based on Kerberos authentication, characterized in that: include: A construction module is used to construct a configuration dictionary, wherein the configuration dictionary includes various types of configuration data required for multiple docking platforms to access the target data warehouse; A query module, configured to query the configuration dictionary based on a target docking platform to determine various types of configuration data required for the target docking platform to access the target data warehouse; The sending module is used to call the corresponding configuration module based on the type of the configuration data, and the configuration module sends the corresponding configuration data to the target docking platform so that the target docking platform can access the target data warehouse.

8. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the configuration delivery method based on Kerberos authentication according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: The computer program or instruction is executed by a processor to implement the configuration delivery method based on Kerberos authentication according to any one of claims 1 to 6.

10. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed, the configuration delivery method based on Kerberos authentication is implemented as described in any one of claims 1 to 6.