SSH secret key proxy operation and maintenance method based on operation and maintenance management system

By using the SSH key proxy operation and maintenance method, the problem of inconsistent parameter synchronization between SSH and SFTP protocols in the operation and maintenance management system is solved, realizing secure and efficient operation and maintenance connection and adaptive quality of service assurance, ensuring protocol consistency and stability in the distributed environment.

CN120915447AActive Publication Date: 2025-11-07HAINAN HUADIAN JIANGDONG INVESTMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511205478.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2025-11-07
Estimated Expiration
2045-08-27

AI Technical Summary

Technical Problem

Existing operation and maintenance management systems lack native proxy support based on SSH keys during SSH and SFTP protocol operation and maintenance proxy processes, which leads to inconsistent protocol parameter synchronization, timeout and protocol conflict issues. Furthermore, the lack of a synchronization mechanism that relies on a unified clock reference results in insufficient security and stability.

Method used

The SSH key proxy operation and maintenance method is adopted. The SSH key is generated in the front end and the protocol operation and maintenance parameters are verified and cross-node consistent synchronization is stored in the background. The parameter synchronization is optimized by using a four-state synchronization model and extended Kalman filter. Combined with mode group and adaptive clock reset algorithm, the high consistency and synchronization of parameters in the distributed environment are ensured. Intelligent matching and connection monitoring of protocol proxy services are realized through multi-attribute decision and virtual force model.

Benefits of technology

It achieves secure and efficient connection to the target server, avoids password leakage and man-in-the-middle attacks, ensures the consistency and controllability of protocol behavior, optimizes the authentication and connection process, and provides adaptive control and service quality assurance throughout the entire connection lifecycle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915447A_ABST
    Figure CN120915447A_ABST
Patent Text Reader

Abstract

The invention discloses an SSH secret key proxy operation and maintenance method based on an operation and maintenance management system, and relates to the field of secret key proxy operation and maintenance, and the method comprises the steps: generating an SSH secret key, and obtaining protocol operation and maintenance parameters through a background service program; the background service program verifies the protocol operation and maintenance parameters for the first time and then transmits the protocol operation and maintenance parameters to the operation and maintenance agent program, and meanwhile, the SSH secret key is stored in a temporary file; the foreground client management program analyzes the protocol operation and maintenance parameters and performs secondary verification, and the client accesses the temporary proxy service according to the authentication credential in the protocol operation and maintenance parameters; selecting a target protocol proxy service based on a matching result and storing the service in a resource pool; and the target protocol proxy service establishes connection with the operation and maintenance target server through the SSH secret key and forwards a client request. According to the invention, the SSH secret key is adopted for proxy operation and maintenance of the SSH protocol and the SFTP protocol, so that the authentication and connection process is obviously optimized while the security is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of key agent operation and maintenance, in particular to an SSH key agent operation and maintenance method based on an operation and maintenance management system. BACKGROUND

[0002] With the rapid development of Internet information technology, various information systems emerge in an endless stream, and the operation and maintenance of IT equipment by the IT operation and maintenance department becomes more and more complex and technically more and more difficult. The previous mode of directly operating and maintaining equipment by manpower cannot meet the current needs. In such an environment, various operation and maintenance management systems have emerged.

[0003] As an intermediate layer between the operation and maintenance client and the operation and maintenance target device, the most core part of the operation and maintenance management system is the proxy of the operation and maintenance process. In the prior art of this function, the docking between the WEB operation and maintenance client and the operation and maintenance management system and the operation and maintenance management system and the target device is usually realized by the method of Windows application hosting or local browser proxy through a browser, so that the operation information of the client can be successfully forwarded to the operation and maintenance target device through the operation and maintenance management system.

[0004] The existing operation and maintenance management system can complete the SSH and SFTP protocol operation and maintenance proxy process to a certain extent, but due to the fact that the SSH and SFTP protocols themselves do not have native proxy support based on SSH keys, there are still structural adaptation limitations. At the same time, in the actual operation and maintenance process, various protocol operation and maintenance parameters need to be synchronized between multiple proxy nodes, and this process highly depends on a unified clock reference to ensure the consistency of the state and the correctness of the operation sequence. If the system lacks an effective clock synchronization mechanism, different nodes will operate on the same parameter at different time points, which will cause problems such as time-out and protocol parameter conflict due to time deviation.

[0005] At present, no effective solution has been proposed for the problems in the related art. SUMMARY

[0006] In view of the problems in the related art, the present application proposes an SSH key agent operation and maintenance method based on an operation and maintenance management system to overcome the above technical problems existing in the prior art.

[0007] To this end, the specific technical solutions adopted by the present application are as follows:

[0008] An SSH key agent operation and maintenance method based on an operation and maintenance management system, the method comprising:

[0009] S1, generating an SSH key by using a key management device in a foreground operation and maintenance management page, authorizing an operation and maintenance target server, and when the operation and maintenance target server is clicked, obtaining protocol operation and maintenance parameters through a background service program;

[0010] S2, the background service program transmits the protocol operation and maintenance parameters to an operation and maintenance agent program after initial verification, the operation and maintenance agent program performs cross-node consistent synchronization storage on the protocol operation and maintenance parameters, and saves the SSH key to a temporary file, and returns a listening port after the SSH key is saved;

[0011] S3, transmitting the listening port and the protocol operation and maintenance parameters to a foreground client management program, the foreground client management program parses and performs secondary verification on the protocol operation and maintenance parameters, and calls an operation tool after the secondary verification, and the client accesses a temporary agent service according to an authentication credential in the protocol operation and maintenance parameters;

[0012] S4, the temporary agent service receives and parses a client request, matches the client request with a protocol agent service, selects a target protocol agent service based on a matching result, stores the target protocol agent service to a resource pool, and monitors a connection state of the target protocol agent service through the resource pool;

[0013] S5, the target protocol agent service establishes a connection with the operation and maintenance target server through the SSH key and forwards the client request, and deletes the SSH key after the proxy operation and maintenance is completed.

[0014] Preferably, the background service program transmits the protocol operation and maintenance parameters to the operation and maintenance agent program after initial verification, the operation and maintenance agent program performs cross-node consistent synchronization storage on the protocol operation and maintenance parameters, and saves the SSH key to a temporary file, and returns a listening port after the SSH key is saved, including:

[0015] S21, the background service program sequentially performs structure verification and semantic verification on the protocol operation and maintenance parameters, and transmits the protocol operation and maintenance parameters after the initial verification to the operation and maintenance agent program;

[0016] S22, the operation and maintenance agent program receives the protocol operation and maintenance parameters, combines state variables of the protocol operation and maintenance parameters, and realizes cross-node consistent synchronization storage of the protocol operation and maintenance parameters in a multi-node environment of a distributed operation and maintenance cluster;

[0017] S23, constructing a temporary file in the background, storing the SSH key to the temporary file, and returning the listening port after the SSH key is stored.

[0018] Preferably, the protocol operation and maintenance parameters include operation and maintenance parameters of an SSH protocol and an SFTP protocol, and the operation and maintenance management system proxies operation and maintenance of the SSH protocol and the SFTP protocol through the SSH key, so that the operation and maintenance target server closes a password-based login mechanism.

[0019] Preferably, the operation and maintenance agent receives the protocol operation and maintenance parameters, combines the state variables of the protocol operation and maintenance parameters, and realizes cross-node consistent synchronization storage of the protocol operation and maintenance parameters in the multi-node environment of the distributed operation and maintenance cluster, including:

[0020] S221, the state variables of the protocol operation and maintenance parameters after the initial verification are obtained, and the state variables include parameter integrity, parameter propagation rate, parameter consistency deviation and parameter strength factor;

[0021] S222, the state variables are taken as inputs of the four-state synchronization model, and the protocol operation and maintenance parameters are synchronized and propagated to the agent nodes for preliminary storage by using the four-state synchronization model combined with the pre-defined clock synchronization rule, to obtain the synchronized protocol parameters stored in the agent nodes;

[0022] S223, the synchronized protocol parameters are taken as inputs of the extended Kalman filter, and the state prediction value of the agent node is output by the extended Kalman filter;

[0023] S224, based on the state prediction value of the agent node, the agent nodes with similar characteristics are divided into the same modal group, and a Kalman filter instance is run for each modal group to obtain the state evaluation value of each modal group;

[0024] S225, based on the state evaluation value of the modal group, the transition node in the agent node is selected, the four-state synchronization model parameters are optimized by using the adaptive clock reset algorithm, and the protocol operation and maintenance parameters preliminarily stored in the transition node are propagated to the remaining agent nodes by using the optimized four-state synchronization model, to realize consistent synchronization storage of the protocol operation and maintenance parameters in the agent nodes.

[0025] Preferably, based on the state evaluation value of the modal group, the transition node in the agent node is selected, and the four-state synchronization model parameters are optimized by using the adaptive clock reset algorithm, including:

[0026] The state evaluation value of the modal group is compared with a preset threshold value, if the state evaluation value of the modal group is greater than or equal to the preset threshold value, the agent node corresponding to the current modal group is taken as the transition node;

[0027] The time delay characteristics of the synchronized protocol parameters stored in the transition node are extracted, each time delay characteristic value is calculated one by one on the time axis, and the clock reset interval and the noise interval are identified according to the time delay characteristic value;

[0028] Any adjacent state interval of the four-state synchronization model is selected, if the endpoints of the adjacent state interval are the same, the current state interval is determined as the noise interval, if the endpoints of the adjacent state interval are different, the current state interval is determined as the clock reset interval, and the four-state synchronization model parameters are updated.

[0029] Preferably, the temporary proxy service receives and parses the client request, matches the client request with the protocol proxy service, selects a target protocol proxy service based on the matching result, stores the target protocol proxy service to the resource pool, and monitors the connection state of the target protocol proxy service through the resource pool, including:

[0030] S41, the temporary proxy service receives and parses the client request, matches the client request with the protocol proxy service, selects a target protocol proxy service based on the matching result, stores the target protocol proxy service to the resource pool, and monitors the connection state of the target protocol proxy service through the resource pool, including:

[0031] S42, the request information of the operation and maintenance target server is matched with the protocol proxy service, the protocol proxy service that matches successfully is taken as the target protocol proxy service, and the target protocol proxy service is stored in the resource pool;

[0032] S43, a corresponding resource item is established for the target protocol proxy service in the resource pool, and the temporary proxy service monitors the connection of the target protocol proxy service through the resource item.

[0033] Preferably, the request information of the operation and maintenance target server is matched with the protocol proxy service, the protocol proxy service that matches successfully is taken as the target protocol proxy service, and the target protocol proxy service is stored in the resource pool, including:

[0034] S421, after receiving the client request, the protocol field in the request information of the operation and maintenance target server is extracted by using the sticking mechanism to form a structured protocol feature set;

[0035] S422, the structured protocol feature set is matched with the protocol proxy service, and the protocol proxy service that matches successfully is selected as a candidate protocol proxy service;

[0036] S423, the authentication connection quality of the candidate protocol proxy service is evaluated, the target protocol proxy service is selected and stored in the resource pool.

[0037] Preferably, the structured protocol feature set is matched with the protocol proxy service, and the protocol proxy service that matches successfully is selected as a candidate protocol proxy service, including:

[0038] S4221, the structured protocol feature set is matched with the protocol proxy service, including:

[0039] If the structured protocol feature set has specified a protocol proxy service, a connection is directly established with the specified protocol proxy service, and if the structured protocol feature set does not specify a protocol proxy service, step S4222 is executed;

[0040] S4222, performing secondary matching between the structured protocol feature set and the protocol proxy service, and selecting a protocol proxy service matched successfully as a candidate protocol proxy service according to a predefined priority order.

[0041] Preferably, the step of performing secondary matching between the structured protocol feature set and the protocol proxy service, and selecting a protocol proxy service matched successfully as a candidate protocol proxy service according to a predefined priority order comprises:

[0042] S42221, performing item-by-item checking on the protocol type, authentication mode and coordination compatibility between the structured protocol feature set and the protocol proxy service, and obtaining a candidate list;

[0043] S42222, extracting feature indicators in the candidate list, constructing a multi-attribute decision matrix based on the feature indicators, and introducing a weight vector into the multi-attribute decision matrix to obtain a weighted matrix;

[0044] S42223, calculating the distance from each candidate in the candidate list to the positive ideal solution and the negative ideal solution based on the weighted matrix, and calculating the preference degree based on the positive ideal solution and the negative ideal solution;

[0045] S42224, sorting the candidates according to the preference degree from high to low, and selecting the candidates within a preset sorting range as the candidate protocol proxy service.

[0046] Preferably, the corresponding resource item is established for the target protocol proxy service in the resource pool, and the temporary proxy service monitors the connection of the target protocol proxy service through the resource item, comprising:

[0047] S431, performing fault root cause analysis on the target protocol proxy service in the resource pool, and identifying the target protocol proxy service with abnormal connection state;

[0048] S432, generating a strategy action table of the abnormal target protocol proxy service based on the abnormal target protocol proxy service and the current state of the resource item in the resource pool;

[0049] S433, taking the strategy action table as the input of the pre-constructed virtual force model, taking the abnormal target protocol proxy service as a force particle, simulating the gravitational force and repulsive force between the force particle and each candidate protocol proxy service through the virtual force model, and obtaining a meta-learning migration path;

[0050] S434, calling a resource item interface to execute a connection migration behavior based on the meta-learning migration path, and updating the resource item, wherein the connection migration behavior at least includes connection reconstruction and protocol proxy service update.

[0051] The beneficial effects of the present application are:

[0052] 1. The SSH key proxy operation and maintenance method of the present application optimizes the authentication and connection process while ensuring security by using SSH key proxy operation and maintenance of SSH protocol and SFTP protocol, so that the target server for operation and maintenance is not limited to password-based login mechanism.

[0053] 2. The present application uses core synchronization algorithm to keep protocol operation and maintenance parameters synchronized in distributed operation and maintenance environment, ensures that all proxy nodes receive consistent and high-quality parameter configuration in multi-point and multi-task operation and maintenance scenarios, thereby ensuring the uniformity and controllability of protocol behavior, and driving a four-state synchronization model by extracting the state variables of the parameters, realizing high-consistency parameter synchronization distribution between distributed nodes, and further improving the accuracy and real-time performance of synchronization by adaptive optimization of synchronization path based on modal grouping and clock reset mechanism, providing a stable and reliable parameter basis for subsequent proxy service execution.

[0054] 3. The present application filters the optimal service from a plurality of protocol proxy services through a one-level matching and multi-attribute decision-driven two-level matching mechanism, ensures the compatibility, stability and response performance of the service, selects the target proxy service through authentication quality evaluation, and realizes state controllability and connection monitoring by registering resource items in the resource pool, when the connection is abnormal, the system can also calculate the intelligent migration path through the strategy action table and virtual force model, automatically execute connection migration and service replacement, and realize adaptive control of the whole link connection life cycle and service quality guarantee. BRIEF DESCRIPTION OF DRAWINGS

[0055] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0056] Figure 1 is a flow chart of an SSH key proxy operation and maintenance method based on an operation and maintenance management system according to an embodiment of the present application;

[0057] Figure 2 is a specific implementation schematic diagram of an SSH key proxy operation and maintenance method based on an operation and maintenance management system according to an embodiment of the present application. DETAILED DESCRIPTION

[0058] To further explain the embodiments, the present application provides the accompanying drawings which are part of the disclosure of the present application, mainly used to illustrate the embodiments, and can be explained in combination with the related description of the specification to understand the operation principle of the embodiments. Those skilled in the art should understand other possible implementations and advantages of the present application by referring to these contents.

[0059] According to an embodiment of the present application, an SSH key proxy operation and maintenance method based on an operation and maintenance management system is provided.

[0060] The present application will be further described in combination with the accompanying drawings and specific embodiments. As shown in the drawings, according to the SSH key proxy operation and maintenance method based on the operation and maintenance management system of the embodiment of the present application, the method comprises: Figure 1

[0061] S1, generating an SSH key by using a key management device in a foreground operation and maintenance management page, authorizing an operation and maintenance target server, and when the operation and maintenance target server is clicked, acquiring protocol operation and maintenance parameters through a background service program.

[0062] Among them, the protocol operation and maintenance parameters include operation and maintenance parameters of SSH protocol and SFTP protocol, and the operation and maintenance management system proxies the operation and maintenance of SSH protocol and SFTP protocol through the SSH key, so as to make the operation and maintenance target server close the password-based login mechanism.

[0063] S2, the background service program transmits the protocol operation and maintenance parameters to the operation and maintenance proxy program after the initial verification, and the operation and maintenance proxy program performs cross-node consistent synchronization storage on the protocol operation and maintenance parameters, and saves the SSH key to a temporary file, and returns to the listening port after the SSH key saving is completed.

[0064] It should be noted that the purpose of the operation and maintenance proxy program in receiving the protocol operation and maintenance parameters and using the core synchronization algorithm to maintain the protocol parameter synchronization storage in the distributed operation and maintenance environment is to ensure that all proxy nodes receive consistent and complete operation and maintenance instructions in the multi-task, high-concurrency or cross-domain operation scene, so as to prevent the problems of behavior deviation, control conflict or data inconsistency caused by asynchronous parameters, and form consistent parameter snapshot copies in multiple proxy nodes, so that any node can rely on the same parameter context when executing operation and maintenance operations.

[0065] Among them, the background service program transmits the protocol operation and maintenance parameters to the operation and maintenance proxy program after the initial verification, and the operation and maintenance proxy program performs cross-node consistent synchronization storage on the protocol operation and maintenance parameters, and saves the SSH key to a temporary file, and returns to the listening port after the SSH key saving is completed.

[0066] S21, the background service program sequentially performs structure verification and semantic verification on the protocol operation and maintenance parameters, and transmits the protocol operation and maintenance parameters after the initial verification to the operation and maintenance proxy program. ​

[0067] It should be noted that the background service program sequentially performs structural verification and semantic verification on the protocol operation and maintenance parameters, and delivers the protocol operation and maintenance parameters after the initial verification to the operation and maintenance agent program, including:

[0068] The protocol operation and maintenance parameter field is extracted, and structural verification is performed according to the data model to ensure that all mandatory fields exist, the field type is correct, and the format conforms to the specification (such as IP, port, protocol name, action type, etc.). After the structural verification is passed, the semantic verification stage is entered, and the background program will analyze the logical relationship and legality between the fields, such as confirming whether the protocol matches the target port, whether the target host supports the selected operation, whether the operation instruction conflicts with the current context, whether the parameter combination meets the business policy, etc. After the semantic verification is completed, the system will standardize the parameters that have passed the verification, package them into a standard data structure or context object, and deliver them to the downstream operation and maintenance agent program for initiating specific operation and maintenance behaviors.

[0069] S22, the operation and maintenance agent program receives the protocol operation and maintenance parameters, and combines the state variables of the protocol operation and maintenance parameters to realize cross-node consistent synchronization storage of the protocol operation and maintenance parameters in the multi-node environment of the distributed operation and maintenance cluster.

[0070] Among them, the operation and maintenance agent program receives the protocol operation and maintenance parameters, and combines the state variables of the protocol operation and maintenance parameters to realize cross-node consistent synchronization storage of the protocol operation and maintenance parameters in the multi-node environment of the distributed operation and maintenance cluster.

[0071] S221, obtaining the state variables of the protocol operation and maintenance parameters after the initial verification, and the state variables include parameter completeness, parameter propagation rate, parameter consistency deviation, and parameter strength factor;

[0072] S222, taking the state variables as the input of the four-state synchronization model, and combining the pre-defined clock synchronization rules, using the four-state synchronization model to synchronize and propagate the protocol operation and maintenance parameters to the agent node for preliminary storage, to obtain the synchronized protocol parameters stored by the agent node.

[0073] It should be noted that after the background service program completes the initial verification of the protocol operation and maintenance parameters, it will extract a set of state variables for describing the parameter quality and transmission characteristics, including parameter completeness, parameter propagation rate, parameter consistency deviation, and parameter strength factor. The functions of these state variables are as follows:

[0074] Parameter completeness measures whether the parameter fields are complete and conform to the structural rules, parameter propagation rate reflects the transmission delay and efficiency of the parameters from the verification end to the agent end, parameter consistency deviation is used to detect whether the parameters have semantic deviation or are tampered with during multi-node propagation, and parameter strength factor comprehensively evaluates the instruction strength and priority of the parameters to the target agent behavior.

[0075] The four types of state variables are input into a four-state synchronization model, which has structural components including: a state identifier (for perceiving the category to which the current protocol parameter state belongs), a synchronization clock controller (for driving state synchronization according to a predefined global clock rhythm), a state transition matrix (for determining how the current state evolves and propagates among nodes), and a storage mapper (for mapping the final synchronization result to a protocol parameter snapshot of the agent node).

[0076] The four-state synchronization model adopts a finite state machine (FSM) + distributed clock synchronization algorithm architecture, in which the finite state machine provides a clear definition of the four states (such as ready, in transmission, pending confirmation, and complete) and state transition logic, while the distributed clock synchronization can precisely align the state advance rhythm with the logical clock, ensuring consistent parameter transmission across nodes. In specific implementation, the state variables are used as input feature vectors to drive the state identifier to determine the current synchronization phase, the clock synchronization rules trigger the state advance instructions, the state transition matrix calculates the target state in real time based on node feedback, and finally the protocol parameters that have completed synchronization are stored in the parameter buffer or persistent storage structure of the agent node through the mapper, forming a final reusable protocol configuration snapshot.

[0077] It should be noted that the finite state machine includes: defining all possible state sets and input event sets, such as the "ready state, transmission state, confirmation state, and complete state" in the four-state model; explicitly defining the state transition function, i.e., the logical rules for transitioning from one state to another under specific input conditions; configuring a state register to record the current state, triggering the transition logic whenever the input state variable changes, updating the current state in the state register, and performing associated actions (such as sending data, writing to storage, initiating synchronization confirmation, etc.); throughout the process, state transition is driven by input, ensuring that the system progresses on a clear path.

[0078] The predefined clock synchronization rule refers to a unified timing coordination mechanism used in the parameter state propagation process, which is used to ensure that all participating nodes have consistent awareness of the synchronization state. Common rules include: using a logical clock to timestamp each state operation to ensure that the operation order is comparable; or using an accurate synchronization mechanism such as PTP or NTP to align the physical clocks of all nodes, so that the state advance schedule has a unified time base, forming time constraints in state synchronization triggering, confirmation timeout, and retransmission control.

[0079] S223, inputting the synchronization protocol parameters as inputs of the extended Kalman filter, and outputting state prediction values of the agent node through the extended Kalman filter;

[0080] S224, based on the state prediction value of the agent node, the agent nodes with similar characteristics are divided into the same modal group, and Kalman filter instances are run for each modal group to obtain state evaluation values of each modal group, specifically including:

[0081] A set of highly similar agent collections in behavior characteristics or running state is obtained by clustering algorithm (such as spectral clustering) for modal division of characteristics;

[0082] An independent Kalman filter is instantiated for each modal group, the initial state estimation and covariance matrix are set, the system state transition model and observation model of the group are defined, and the observation value is updated according to the real-time running data (such as delay, connection success rate, error rate) of the agent node at each time step;

[0083] The Kalman filter sequentially performs a prediction step (predicting the current state based on the state transition equation) and an update step (correcting the prediction error according to the actual observation value), thereby continuously outputting the state evaluation value of the modal group.

[0084] S225, based on the state evaluation value of the modal group, the transition node in the agent node is screened out, the adaptive clock reset algorithm is used to optimize the four-state synchronization model parameters, and the optimized four-state synchronization model is used to propagate the protocol operation and maintenance parameters preliminarily stored in the transition node to the remaining agent nodes, so as to realize consistent and synchronous storage of the protocol operation and maintenance parameters in the agent nodes.

[0085] Among them, based on the state evaluation value of the modal group, the transition node in the agent node is screened out, and the adaptive clock reset algorithm is used to optimize the four-state synchronization model parameters, including:

[0086] The state evaluation value of the modal group is compared with the preset threshold value, if the state evaluation value of the modal group is greater than or equal to the preset threshold value, the agent node corresponding to the current modal group is taken as the transition node;

[0087] The delay characteristics of the synchronization protocol parameters stored in the transition node are extracted, each delay characteristic value is calculated one by one on the time axis, and the clock reset interval and the noise interval are identified according to the delay characteristic value;

[0088] The adjacent state interval of the four-state synchronization model is selected at will, if the endpoints of the adjacent state interval are the same, the current state interval is determined as the noise interval, if the endpoints of the adjacent state interval are different, the current state interval is determined as the clock reset interval, and the four-state synchronization model parameters are updated.

[0089] It should be noted that the purpose of setting the clock reset interval and the noise interval is to accurately identify whether there is structural timing drift or instantaneous abnormality in the synchronization process of the agent node, so as to judge whether the time control parameters of the four-state synchronization model need to be updated.

[0090] Wherein, the noise interval reflects that the parameter state frequently fluctuates in a short time but does not produce an effective state transition, which belongs to non-deterministic jitter, and the clock reset interval represents a section in which the node state actually transitions and has a timing offset, which needs to be corrected by adjusting the time reference (such as state transition threshold or waiting window) of the synchronization model.

[0091] By screening the mode group proxy nodes (transition nodes) whose state evaluation values exceed the threshold value, combining the stored protocol parameter delay characteristics to locate the time anomaly section, and determining whether the synchronization model is misaligned according to the difference between the state interval endpoints, the timing parameters of the four-state model are dynamically optimized by the adaptive clock reset algorithm in principle.

[0092] S23, build a temporary file in the background, store the SSH key to the temporary file, and return to the listening port after the SSH key storage is completed.

[0093] S3, pass the listening port and protocol operation and maintenance parameters to the foreground client management program, the foreground client management program parses the protocol operation and maintenance parameters and performs secondary verification, and calls the operation and maintenance tool after the secondary verification, and the client accesses the temporary proxy service according to the authentication credentials in the protocol operation and maintenance parameters;

[0094] S4, the temporary proxy service receives and analyzes the client request, matches the client request with the protocol proxy service, selects the target protocol proxy service based on the matching result, and stores it to the resource pool, and monitors the connection state of the target protocol proxy service through the resource pool.

[0095] Wherein, the temporary proxy service receives and analyzes the client request, matches the client request with the protocol proxy service, selects the target protocol proxy service based on the matching result, and stores it to the resource pool, and monitors the connection state of the target protocol proxy service through the resource pool.

[0096] S41, the temporary proxy service receives the client request and analyzes it, and obtains the request information of the operation and maintenance target server from the analyzed client request;

[0097] S42, match the request information of the operation and maintenance target server with the protocol proxy service, select the protocol proxy service that matches successfully as the target protocol proxy service, and store the target protocol proxy service in the resource pool.

[0098] Wherein, the temporary proxy service receives and analyzes the client request, matches the client request with the protocol proxy service, selects the target protocol proxy service based on the matching result, and stores it to the resource pool, and monitors the connection state of the target protocol proxy service through the resource pool.

[0099] S421、After receiving the client request, the protocol field in the request information of the operation and maintenance target server is extracted by using the sticking mechanism to form a structured protocol feature set.

[0100] It should be noted that the original request data stream of the client is monitored and captured, and the fields related to the target server and the protocol in the request message are aggregated and parsed through the sticking mechanism. The sticking mechanism refers to the process of merging multiple scattered but related fields through context binding, semantic association or data position reconstruction during protocol field extraction, avoiding field disassembly or misidentification, and ensuring that the extracted protocol features have logical consistency. Then, the extraction result is structured and converted through a syntax template or field mapping rule, and is organized into a unified format protocol feature set (such as a JSON object or a feature vector).

[0101] Among them, the protocol-related fields (such as IP, port, protocol identifier, path, header, SNI, etc.) extracted from the original request are converted into a structured protocol feature set by a standardized conversion logic. The core purpose is to map the scattered, heterogeneous and position-unfixed fields to a predefined semantic site to form a unified representation that can be recognized and processed by the system. The field mapping rule includes:

[0102] The field name mapping (such as mapping scheme in header to protocol type), field type conversion (such as converting string port number to integer), field combination mapping (such as combining host and port into target address), field default filling (such as defaulting to HTTP / 1.1 when no protocol is specified), and field conflict resolution strategy (such as taking the higher priority when header and URI specify the protocol at the same time). The mapping rule can be implemented based on a static table, a dynamic matching template (such as a regular template + context association) or a rule engine (such as a DSL configuration).

[0103] S422、Hierarchical matching between the structured protocol feature set and the protocol proxy service is performed, and the protocol proxy service that matches successfully is selected as a candidate protocol proxy service.

[0104] Among them, the hierarchical matching between the structured protocol feature set and the protocol proxy service includes:

[0105] S4221、The structured protocol feature set is matched with the protocol proxy service at a first level, specifically including:

[0106] If the structured protocol feature set specifies a protocol proxy service, a connection is established directly with the specified protocol proxy service. If the structured protocol feature set does not specify a protocol proxy service, step S4222 is executed;

[0107] S4222, performing secondary matching between the structured protocol feature set and the protocol agent service, and selecting a protocol agent service with a successful matching as a candidate protocol agent service according to a predefined priority order.

[0108] It should be noted that the purpose of the first-level matching is to directly establish a connection in the case where the protocol agent service is explicitly specified in the structured protocol feature set, so as to avoid repeated identification and scheduling operations, thereby improving the response speed and processing efficiency; and the purpose of the second-level matching is to filter and intelligently match the candidate agent service through the priority order when the protocol agent service is not explicitly specified, so as to ensure that the most suitable agent service can be automatically selected in the absence of explicit guidance.

[0109] The secondary matching between the structured protocol feature set and the protocol agent service includes:

[0110] S42221, performing item-by-item verification of the protocol type, the authentication method, and the coordination compatibility between the structured protocol feature set and the protocol agent service, and obtaining a candidate list;

[0111] S42222, extracting feature indicators in the candidate list, constructing a multi-attribute decision matrix based on the feature indicators, and introducing a weight vector into the multi-attribute decision matrix to obtain a weighted matrix;

[0112] S42223, calculating the distance from each candidate in the candidate list to the positive ideal solution and the negative ideal solution based on the weighted matrix, and calculating the preference degree based on the positive ideal solution and the negative ideal solution;

[0113] S42224, sorting the candidate items according to the preference degree from high to low, and selecting the candidate items within a preset sorting range as the candidate protocol agent service.

[0114] The secondary matching between the structured protocol feature set and the protocol agent service includes:

[0115] Step one, item-by-item verification of the protocol type, the authentication method, and the coordination compatibility, and performing a first round of accurate filtering on the registered protocol agent service according to the content in the structured protocol feature set, and the execution logic includes:

[0116] Protocol type matching: if the feature set is SSH, only the agent service supporting SSH is retained.

[0117] Authentication mode check: match passwordless, token-based, TLS handshake, etc. authentication capabilities.

[0118] Coordination compatibility: determine whether the agent service is compatible with the current target server network environment or load balancing strategy to get a preliminary candidate list.

[0119] Step two, build a multi-attribute decision matrix and a weighted matrix, and extract the key attributes (feature indicators) of each candidate from the candidate list:

[0120] r1: current connection success rate;

[0121] r2: response delay (ms);

[0122] r3: availability (current running state);

[0123] r4: historical stability coefficient;

[0124] r5: resource load occupancy rate;

[0125] Form a standardized decision matrix R = [r ij ], where x ij represents the value of the ith candidate in the jth attribute, and a weight vector W = [w1, w2...w n ] is introduced, which satisfies ∑w i = 1, for example, set by AHP or expert experience, multiply it by X to get the weighted matrix R = X·W.

[0126] Step three, calculate the optimal and worst solutions of the weighted matrix:

[0127] Define the positive ideal solution A + and the negative ideal solution;

[0128] For each candidate i, calculate its Euclidean distance to the positive ideal solution and the negative ideal solution:

[0129]

[0130] The preference degree calculation formula is:

[0131]

[0132] In the formula, represents the Euclidean distance of the ith candidate to the positive ideal solution; represents the Euclidean distance of the ith candidate to the negative ideal solution; r ij represents the value of the ith candidate in the jth attribute in the multi-attribute decision matrix; represents the value of the jth attribute in all candidates (ideal value of the positive ideal solution in this dimension) ; represents the worst value of the jth attribute in all candidates (ideal value of the negative ideal solution in this dimension) ; n represents the total number of attributes, i.e. the number of dimensions of each candidate in the decision matrix, wherein the preference degree P i is larger, the better, P i ∈ [0, 1].

[0133] Step four, sort all candidates according to the preference degree P i from high to low, and take the top k (controlled by a preset range set by the system) as the final candidate proxy service list.

[0134] Step five, authentication connection quality assessment and target proxy selection, real-time connection quality test is performed on the sorted candidate proxy service, including: handshake time consumption, authentication success rate, connection jitter, and authentication protocol consistency verification.

[0135] Based on the comprehensive score, the current optimal quality is selected as the target protocol proxy service, and the meta information, connection ability and other data are written into the running resource pool for subsequent connection calling and operation and maintenance instruction issuing.

[0136] S423, evaluate the authentication connection quality of the candidate protocol proxy service, select the target protocol proxy service and store it in the resource pool.

[0137] S43, establish a corresponding resource item for the target protocol proxy service in the resource pool, and the temporary proxy service monitors the connection of the target protocol proxy service through the resource item.

[0138] Among them, the corresponding resource item is established for the target protocol proxy service in the resource pool, and the temporary proxy service monitors the connection of the target protocol proxy service through the resource item.

[0139] S431, pre-analyze the fault root cause of the target protocol proxy service in the resource pool, and identify the target protocol proxy service with abnormal connection state;

[0140] S432, based on the abnormal target protocol proxy service and the current resource item state in the resource pool, generate a strategy action table for the abnormal target protocol proxy service.

[0141] It should be noted that the policy action table includes: isolation actions (such as removing from the optional service list), degradation actions (such as switching to a low priority task, limiting the number of concurrent connections), reconnection or retry actions (such as initiating a quick reconnection attempt to confirm whether it is a transient exception), alarm actions (such as recording logs and pushing to the monitoring center), repair suggestion actions (such as suggesting to perform health checks, replace backend modules, refresh authentication keys, etc.), load transfer actions (such as forwarding the current proxy task to a substitute node with normal state), parameter resynchronization actions (such as re-pulling a consistent snapshot for protocol parameters that have failed or drifted, etc.

[0142] S433, input the policy action table as a pre-constructed virtual force model, and input the abnormal target protocol proxy service as a force particle, simulate the gravitational force and repulsive force between the force particle and each candidate protocol proxy service through the virtual force model, and obtain the meta-learning migration path.

[0143] It should be noted that the policy action table is input into the virtual force model, the abnormal target protocol proxy service is regarded as a force particle, the attractive force and repulsive force between the force particle and the candidate proxy node are simulated, and the optimal migration path (i.e. the meta-learning migration path) is calculated and output, so as to realize intelligent replacement and migration scheduling of the abnormal service.

[0144] Specifically, the model architecture of the virtual force model is based on the combination of physical modeling and graph embedding modeling, and is composed of the following three parts:

[0145] 1) Particle node representation layer: each protocol proxy service is abstracted as a node vector, the abnormal proxy service is initialized as a force particle, and all candidate nodes are a set of action points;

[0146] 2) Force field function layer: define the attractive force (such as high resource matching degree, policy action compatibility) and repulsive force (such as connection failure history, load conflict) as the calculation function of two-dimensional tensor;

[0147] 3) Path derivation layer: take the direction of the resultant force of all force vectors as the migration intention, combine the communication weight between nodes, the resource state and the historical performance index, and perform the shortest force path search (which can use graph search algorithms such as A* or Dijkstra) on the force graph to obtain the migration path of the force particle migrating to the best proxy node, which can be used as the execution sequence of the policy scheduling instruction.

[0148] Simulate the state evolution process of particles moving in the force field in real physics, encode "adaptive driving" in the form of abstract force, encourage migration to high adaptation nodes with attractive force, and repel low reliable nodes with repulsive force, to form a continuous and derivable migration decision path. It is different from rule matching scheduling, but has dynamic learning and direction guiding nature, especially suitable for complex, dynamic and uncertain distributed operation and maintenance environment.

[0149] In the implementation layer, each action in the policy action table is mapped to the candidate proxy node, the matching score vector is calculated, and then the "policy-node" action graph is constructed according to the availability, stability, authentication quality and other indicators of the current nodes in the resource pool. The virtual force function is used to evaluate the attractive and repulsive forces between each pair of nodes, and the global force field is synthesized. Finally, the meta-learning migration path is selected according to the optimal direction of the resultant force. This process can further fine-tune the force field function parameters through reinforcement learning or graph neural networks to improve the accuracy of adaptation prediction and migration robustness.

[0150] S434, based on the meta-learning migration path, calling the resource item interface to perform the connection migration behavior, and updating the resource item, wherein the connection migration behavior at least includes connection reconstruction and protocol proxy service update.

[0151] It should be noted that the connection migration behavior is driven by the meta-learning migration path, which replaces the originally abnormal or failed protocol proxy service with a candidate proxy node with better state, and updates the system resource state, thereby realizing high availability, low latency and intelligent fault-tolerant operation and maintenance connection switching without interrupting the service.

[0152] The "connection reconstruction" included in the connection migration behavior ensures that an effective communication link is established between the client and the new target proxy, and the "protocol proxy service update" ensures that the parameter synchronization, authentication mechanism and policy state are completely consistent with the new service. The resource item interface is called in this process to write new service information, release old resource binding, etc.

[0153] S5, the target protocol proxy service establishes a connection with the operation and maintenance target server through the SSH key and forwards the client request, and deletes the SSH key after the proxy operation and maintenance is completed.

[0154] As shown in Figure 2 The operation and maintenance management system is based on B / S architecture, and mainly includes a front-end management page, a front-end client management program, a client program, a temporary proxy service, a protocol proxy service, etc.

[0155] The front-end management page is mainly responsible for collecting information of the operation and maintenance target server, which mainly includes the IP address of the operation and maintenance target server, port information and the type of protocol used, adding key management and generation device, and providing a button to trigger the operation and maintenance process. The interaction process before and after the establishment of contact with the background service program can use the currently popular web server, such as lighted, nginx, apach, etc.

[0156] The front-end client management program is mainly responsible for calling different client login programs according to different protocols according to the parameters fed back by the background.

[0157] Client program: Different protocols require different client login programs. Existing SSH protocols can choose putty, crt, xshell tools, SFTP protocols can choose WINSCP tools, etc. The client does not need a secret key, and the operation and maintenance management system will use a secret key agent to log in.

[0158] Operation and maintenance agent program: manage the received operation and maintenance parameters through data structure management.

[0159] Temporary agent service: a temporary port service opened for operation and maintenance. The client operation and maintenance does not need a secret key and first connects to this temporary agent service. After connection, it is locked and other clients cannot connect again. The temporary agent service will be eliminated after operation and maintenance, and the port will be released.

[0160] Protocol agent service: different agent programs can be used according to different protocols. After connection, it is connected to the target server. In the transfer process, that is, the agent process, it will be securely connected to the target service through the secret key.

[0161] The SSH secret key agent operation and maintenance method based on the operation and maintenance management system includes:

[0162] First, generate an SSH secret key or upload a bound SSH secret key through the secret key management device in the front-end management page. Then authorize the operation and maintenance target server, click the operation and maintenance target SSH or SFTP server. At this time, through the interaction between the front and back, the back-end service program can obtain the related parameters of SSH or SFTP operation and maintenance, including operation and maintenance client IP, time, secret key, etc. The back-end service program checks the parameters and passes them to the operation and maintenance agent program. The operation and maintenance agent program manages the received operation and maintenance parameters using a certain data structure, and saves the secret key to a temporary file in the back-end. After success, return to the listening port, which is the externally open port (the port number range can be defined according to user demand).

[0163] The returned listening port and other SSH and SFTP operation and maintenance parameters are passed to the front-end client management program, which parses the corresponding parameters and performs verification. After success, it calls Putty (selects the corresponding different tools). The operation and maintenance client does not need to bind any secret key. The operation and maintenance client will access the temporary agent service according to the Token in the parameters.

[0164] After the temporary agent service parses the information such as the protocol used by the target machine, it will connect to the corresponding protocol agent service according to the information of the target host requested by the client. At this time, the entire link is a temporary operation and maintenance link. The temporary agent will be destroyed after the operation and maintenance is interrupted. External access is not allowed.

[0165] The protocol proxy service establishes a connection with the target machine and forwards the request according to the request. The original module is directly connected to the target server through a password, and here it is changed to be connected to the target server through a secret key. The secret key is saved to a temporary location when the operation is clicked on the front-end operation and maintenance page, and is used for operation and maintenance. The proxy secret key operation is completed and deleted. The security of the secret key is guaranteed.

[0166] The above merely describes the preferred embodiments of the present application and is not used to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. An operation and maintenance system based SSH key agent operation and maintenance method, characterized in that, The method comprises: S1, generating an SSH key by using a key management device in a foreground operation and maintenance management page, authorizing an operation and maintenance target server, and when the operation and maintenance target server is clicked, obtaining protocol operation and maintenance parameters through a background service program; S2, the background service program transmits the protocol operation and maintenance parameters to an operation and maintenance agent program after initial verification, the operation and maintenance agent program performs cross-node consistent synchronous storage on the protocol operation and maintenance parameters, and saves the SSH key to a temporary file, and returns a listening port after the SSH key is saved; S3, the listening port and the protocol operation and maintenance parameters are transmitted to a foreground client management program, the foreground client management program analyzes and performs secondary verification on the protocol operation and maintenance parameters, and calls an operation and maintenance tool after the secondary verification, and a client accesses a temporary agent service according to an authentication credential in the protocol operation and maintenance parameters; S4, the temporary agent service receives and analyzes a client request, matches the client request with a protocol agent service, selects a target protocol agent service based on a matching result, stores the target protocol agent service to a resource pool, and monitors a connection state of the target protocol agent service through the resource pool; S5, the target protocol agent service establishes a connection with the operation and maintenance target server through the SSH key and forwards the client request, and deletes the SSH key after the proxy operation and maintenance is completed. 2.The SSH key proxying method based on an operation and maintenance management system according to claim 1, wherein, The background service program transmits the protocol operation and maintenance parameters to the operation and maintenance agent program after initial verification, and the operation and maintenance agent program performs cross-node consistent synchronous storage on the protocol operation and maintenance parameters, and saves the SSH key to a temporary file, and returns a listening port after the SSH key is saved, which comprises: S21, the background service program sequentially performs structure verification and semantic verification on the protocol operation and maintenance parameters, and transmits the protocol operation and maintenance parameters after the initial verification to the operation and maintenance agent program; S22, the operation and maintenance agent program receives the protocol operation and maintenance parameters, combines state variables of the protocol operation and maintenance parameters, and realizes cross-node consistent synchronous storage of the protocol operation and maintenance parameters in a multi-node environment of a distributed operation and maintenance cluster; S23, a temporary file is built in the background, the SSH key is stored in the temporary file, and the listening port is returned after the SSH key is stored. 3.The SSH key proxying method based on an operation and maintenance management system according to claim 2, characterized in that, The protocol operation and maintenance parameters comprise operation and maintenance parameters of an SSH protocol and an SFTP protocol, and the operation and maintenance management system proxies operation and maintenance of the SSH protocol and the SFTP protocol through the SSH key, so that the operation and maintenance target server closes a password-based login mechanism.

4. The SSH key proxying method based on an operation and maintenance management system according to claim 3, characterized in that, The operation and maintenance agent program receives the protocol operation and maintenance parameters, combines state variables of the protocol operation and maintenance parameters, and realizes cross-node consistent synchronous storage of the protocol operation and maintenance parameters in a multi-node environment of a distributed operation and maintenance cluster, which comprises: S221, state variables of the protocol operation and maintenance parameters after the initial verification are obtained, and the state variables comprise parameter completeness, parameter propagation rate, parameter consistency deviation, and parameter strength factor; S222, the state variables are taken as inputs of a four-state synchronization model, a clock synchronization rule is predefined, the protocol operation and maintenance parameters are synchronously propagated to an agent node for preliminary storage by using the four-state synchronization model, and synchronous protocol parameters stored in the agent node are obtained. S223, taking the synchronization protocol parameters as inputs of the extended Kalman filter, outputting a state prediction value of the proxy node through the extended Kalman filter; S224, based on the state prediction value of the proxy node, dividing the proxy nodes with similar characteristics into the same modal group, and running a Kalman filter instance for each modal group to obtain a state evaluation value of each modal group; S225, based on the state evaluation value of the modal group, screening out a transition node in the proxy node, optimizing the four-state synchronization model parameters by using an adaptive clock reset algorithm, and propagating the protocol operation and maintenance parameters preliminarily stored in the transition node to the remaining proxy nodes by using the optimized four-state synchronization model, to realize consistent and synchronous storage of the protocol operation and maintenance parameters in the proxy nodes.

5. The SSH key proxying method based on an operation and maintenance management system according to claim 4, characterized in that, The adaptive clock reset algorithm includes: comparing the state evaluation value of the modal group with a preset threshold value, if the state evaluation value of the modal group is greater than or equal to the preset threshold value, the proxy node corresponding to the current modal group is taken as the transition node; extracting the time delay characteristics of the synchronization protocol parameters stored in the transition node, calculating each time delay characteristic value on the time axis one by one, and identifying the clock reset interval and the noise interval according to the time delay characteristic value; arbitrarily selecting adjacent state intervals of the four-state synchronization model, if the endpoints of the adjacent state intervals are the same, the current state interval is determined as the noise interval, if the endpoints of the adjacent state intervals are different, the current state interval is determined as the clock reset interval, and the four-state synchronization model parameters are updated.

6. The SSH key proxying method based on an operation and maintenance management system according to claim 1, characterized in that, The temporary proxy service receives and analyzes the client request, matches the client request with the protocol proxy service in terms of protocol capability, selects a target protocol proxy service based on the matching result, and stores the target protocol proxy service in the resource pool, and the connection state of the target protocol proxy service is monitored through the resource pool, including: S41, after the temporary proxy service receives the client request, the temporary proxy service analyzes the client request and obtains the request information of the operation and maintenance target server from the analyzed client request; S42, matching the request information of the operation and maintenance target server with the protocol proxy service in terms of protocol capability, taking the protocol proxy service that matches successfully as the target protocol proxy service, and storing the target protocol proxy service in the resource pool; S43, establishing a corresponding resource item for the target protocol proxy service in the resource pool, and monitoring the connection of the target protocol proxy service through the resource item.

7. The SSH key proxying method based on an operation and maintenance management system according to claim 6, characterized in that, The temporary proxy service receives and analyzes the client request, matches the client request with the protocol proxy service in terms of protocol capability, selects a target protocol proxy service based on the matching result, and stores the target protocol proxy service in the resource pool, and the connection state of the target protocol proxy service is monitored through the resource pool, including: S421, after receiving the client request, extracting the protocol field in the request information of the operation and maintenance target server by using the sticking mechanism to form a structured protocol feature set; S422, matching the structured protocol feature set with the protocol proxy service in terms of hierarchical level, and screening the protocol proxy service that matches successfully as the candidate protocol proxy service; S423, evaluating the authentication connection quality of the candidate protocol proxy service, selecting the target protocol proxy service, and storing the target protocol proxy service in the resource pool. 8.The SSH key proxying method based on an operation and maintenance management system according to claim 7, wherein, The hierarchical matching between the structured protocol feature set and the protocol proxy service includes: S4221, performing one-level matching between the structured protocol feature set and the protocol proxy service, specifically including: If the protocol proxy service has been specified in the structured protocol feature set, a connection is directly established with the specified protocol proxy service, and if the protocol proxy service has not been specified in the structured protocol feature set, step S4222 is performed; S4222, performing two-level matching between the structured protocol feature set and the protocol proxy service, and selecting the protocol proxy service that passes the matching as the candidate protocol proxy service according to a predefined priority order. 9.The SSH key proxying method based on an operation and maintenance management system according to claim 8, wherein, The two-level matching between the structured protocol feature set and the protocol proxy service includes: S42221, performing item-by-item verification of the protocol type, authentication method and coordination compatibility between the structured protocol feature set and the protocol proxy service to obtain a candidate list; S42222, extracting feature indicators in the candidate list, constructing a multi-attribute decision matrix based on the feature indicators, and introducing a weight vector into the multi-attribute decision matrix to obtain a weighted matrix; S42223, calculating the distance from each candidate in the candidate list to the positive ideal solution and the negative ideal solution based on the weighted matrix, and calculating the preference degree based on the positive ideal solution and the negative ideal solution; S42224, sorting the candidates according to the preference degree from high to low, and selecting the candidates within a preset sorting range as the candidate protocol proxy service. 10.The SSH key proxying method based on an operation and maintenance management system according to claim 9, wherein, The method for establishing a corresponding resource item for the target protocol proxy service in the resource pool and monitoring the connection of the target protocol proxy service by the temporary proxy service through the resource item includes: S431, performing fault root cause analysis on the target protocol proxy service in the resource pool to identify the target protocol proxy service with abnormal connection state; S432, generating a policy action table for the abnormal target protocol proxy service based on the abnormal target protocol proxy service and the current state of the resource item in the resource pool; S433, taking the policy action table as the input of the pre-constructed virtual force model, taking the abnormal target protocol proxy service as the force particle, simulating the gravitational force and repulsive force between the force particle and each candidate protocol proxy service through the virtual force model to obtain a meta-learning migration path; S434, calling the resource item interface to perform a connection migration behavior based on the meta-learning migration path, and updating the resource item, wherein the connection migration behavior at least includes connection reconstruction and protocol proxy service update.

Citation Information

Patent Citations

  • SSH-based operation and maintenance auditing method, proxy server and system

    CN117792682A

  • Method for realizing cross-local area network edge device connection by using SSH reverse proxy

    CN119341812A

  • Station area intelligent fusion terminal data processing system based on edge calculation

    CN119440800A

  • Proxy SSH public key authentication in cloud environment

    US20230101920A1