An SSH key proxy operation and maintenance method based on an operation and maintenance management system
Patent Information
- Application Number
- CN202511205478.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2026-08-18
- Estimated Expiration
- 2045-08-27
AI Technical Summary
[0004]现有的运维管理系统在一定程度上可以完成对SSH和SFTP协议运维代理过程,但由于SSH和SFTP协议本身并不具备基于SSH秘钥的原生代理支持,仍存在结构上的适配局限;同时在实际运维过程中,各类协议运维参数需在多个代理节点之间同步传播,而这一过程高度依赖统一的时钟基准以保证状态的一致性和操作顺序的正确性,若系统缺乏有效的时钟同步机制,不同节点会在非一致的时间点上对同一参数进行操作,从而会因时间偏差导致超时、以及协议参数冲突等问题
[0052]1. This invention uses SSH key proxy to operate and maintain SSH and SFTP protocols, so that the target server is not limited to password-based login mechanisms. While ensuring security, it significantly optimizes the authentication and connection process. The key has higher resistance to cracking than traditional passwords, effectively preventing brute-force attacks and man-in-the-middle attacks, thereby avoiding security vulnerabilities caused by password leakage, password cracking, and password expiration management.
Smart Images

Figure CN120915447B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of key proxy operation and maintenance, and more specifically, to an SSH key proxy operation and maintenance method based on an operation and maintenance management system. Background Technology
[0002] With the rapid development of internet information technology, various information systems are emerging in an endless stream, making the operation and maintenance of IT equipment by IT operations and maintenance departments increasingly complex and technically challenging. The traditional model of relying solely on manual operation and maintenance is no longer sufficient to meet current needs. In this environment, various operation and maintenance management systems have emerged.
[0003] As an intermediary layer between the operations and maintenance (O&M) client and the target device, the core of the O&M management system is the proxying of the O&M process. In existing technologies, this functionality is typically achieved through browser-hosted Windows applications or local browser proxies, enabling the connection between the web O&M client and the O&M management system, and between the O&M management system and the target device. This allows the client's operational information to be smoothly forwarded to the target device through the O&M management system.
[0004] Existing operation and maintenance management systems can, to some extent, handle the operation and maintenance proxy process for SSH and SFTP protocols. However, since SSH and SFTP protocols themselves do not have native proxy support based on SSH keys, there are still structural adaptation limitations. In addition, during actual operation and maintenance, operation and maintenance parameters of various protocols need to be synchronously propagated among multiple proxy nodes. This process relies heavily on a unified clock reference to ensure consistency of status and correctness of operation sequence. If the system lacks an effective clock synchronization mechanism, different nodes will operate on the same parameter at inconsistent times, which will lead to timeouts and protocol parameter conflicts due to time deviations.
[0005] No effective solutions have yet been proposed to address the problems in the relevant technologies. Summary of the Invention
[0006] To address the problems in related technologies, this invention proposes an SSH key proxy operation and maintenance method based on an operation and maintenance management system, in order to overcome the aforementioned technical problems existing in the current related technologies.
[0007] Therefore, the specific technical solution adopted by the present invention is as follows:
[0008] An SSH key proxy operation and maintenance method based on an operation and maintenance management system, the method includes:
[0009] S1. Generate an SSH key using the key management device in the front-end operation and maintenance management page, authorize the operation and maintenance target server, and obtain the protocol operation and maintenance parameters through the background service program when the operation and maintenance target server is clicked.
[0010] S2. After the background service program performs the initial verification of the protocol operation and maintenance parameters, it passes them to the operation and maintenance agent program. The operation and maintenance agent program performs cross-node consistency synchronization and storage of the protocol operation and maintenance parameters, and saves the SSH key to a temporary file. After the SSH key is saved, it returns to the listening port.
[0011] S3. Pass the listening port and protocol operation and maintenance parameters to the front-end client management program. The front-end client management program parses the protocol operation and maintenance parameters and performs secondary verification. After secondary verification, it calls the operation and maintenance tool. The client accesses the temporary proxy service based on the authentication credentials in the protocol operation and maintenance parameters.
[0012] S4. The temporary proxy service receives and parses the client request, matches the client request with the protocol proxy service for protocol capabilities, selects the target protocol proxy service based on the matching result and stores it in the resource pool, and monitors the connection status of the target protocol proxy service through the resource pool.
[0013] S5, the target protocol proxy service establishes a connection with the target server for operation and maintenance through the SSH key and forwards client requests. After the proxy operation and maintenance is completed, the SSH key is deleted.
[0014] Preferably, after the background service program performs initial verification of the protocol operation and maintenance parameters, it transmits them to the operation and maintenance agent program. The operation and maintenance agent program performs cross-node consistency synchronization and storage of the protocol operation and maintenance parameters, and saves the SSH key to a temporary file. After the SSH key is saved, it returns the listening port, including:
[0015] S21. The background service program performs structural and semantic checks on the protocol operation and maintenance parameters in sequence, and then passes the protocol operation and maintenance parameters that have completed the initial check to the operation and maintenance agent program.
[0016] S22. The operation and maintenance agent program receives the protocol operation and maintenance parameters and, in combination with the status variables of the protocol operation and maintenance parameters, realizes cross-node consistent synchronous storage of the protocol operation and maintenance parameters in the multi-node environment of the distributed operation and maintenance cluster.
[0017] S23. Create a temporary file in the background, store the SSH key in the temporary file, and return to the listening port after the SSH key is stored.
[0018] Preferably, the protocol operation and maintenance parameters include operation and maintenance parameters for SSH and SFTP protocols. The operation and maintenance management system uses SSH key proxy to operate and maintain SSH and SFTP protocols, so that the target server can disable password-based login mechanisms.
[0019] Preferably, the operation and maintenance agent program receives the protocol operation and maintenance parameters, and, in conjunction with the state variables of the protocol operation and maintenance parameters, implements cross-node consistent synchronization and storage of the protocol operation and maintenance parameters in a multi-node environment of a distributed operation and maintenance cluster, including:
[0020] S221. Obtain the status variables of the protocol operation and maintenance parameters after the initial verification is completed, and the status variables include parameter integrity, parameter propagation rate, parameter consistency deviation and parameter strength factor.
[0021] S222. Using the state variables as input to the four-state synchronization model, and combining them with predefined clock synchronization rules, the four-state synchronization model is used to synchronously propagate the protocol operation and maintenance parameters to the agent node for initial storage, thereby obtaining the synchronization protocol parameters stored in the agent node.
[0022] S223. Use the synchronization protocol parameters as input to the extended Kalman filter, and output the state prediction value of the agent node through the extended Kalman filter;
[0023] S224. Based on the state prediction values of the agent nodes, agent nodes with similar characteristics are divided into the same mode group, and a Kalman filter instance is run for each mode group to obtain the state evaluation value of each mode group.
[0024] S225. Based on the state evaluation value of the modal group, the transition nodes in the agent nodes are selected, the parameters of the four-state synchronization model are optimized by the adaptive clock reset algorithm, and the protocol operation and maintenance parameters initially stored in the transition nodes are propagated to the other agent nodes by the optimized four-state synchronization model, so as to achieve consistent synchronous storage of protocol operation and maintenance parameters in the agent nodes.
[0025] Preferably, the transition nodes in the proxy nodes are selected based on the state evaluation values of the mode group, and the parameters of the four-state synchronization model are optimized using an adaptive clock reset algorithm, including:
[0026] The state evaluation value of the modal group is compared with a preset threshold. If the state evaluation value of the modal group is greater than or equal to the preset threshold, the agent node corresponding to the current modal group is used as the transition node.
[0027] Extract the delay characteristics of the synchronization protocol parameters stored in the jump node, calculate each delay characteristic value one by one on the time axis, and identify the clock reset interval and noise interval based on the delay characteristic values;
[0028] Arbitrarily select adjacent state intervals of the four-state synchronization model. If the endpoints of the adjacent state intervals are the same, the current state interval is determined to be a noise interval. If the endpoints of the adjacent state intervals are different, the current state interval is determined to be a clock reset interval, and the parameters of the four-state synchronization model are updated.
[0029] Preferably, the temporary proxy service receives and parses the client request, matches the client request with the protocol proxy service for protocol capabilities, selects a target protocol proxy service based on the matching result and stores it in the resource pool, and monitors the connection status of the target protocol proxy service through the resource pool, including:
[0030] S41. After receiving the client request, the temporary proxy service parses it and obtains the request information of the target server from the parsed client request.
[0031] S42. Match the request information of the target server with the protocol proxy service for protocol capabilities, use the successfully matched protocol proxy service as the target protocol proxy service, and store the target protocol proxy service in the resource pool;
[0032] S43. Create a corresponding resource item for the target protocol proxy service in the resource pool. The temporary proxy service monitors the connection of the target protocol proxy service through the resource item.
[0033] Preferably, the process of matching the request information of the target server for operation and maintenance with the protocol proxy service to determine the protocol capabilities, selecting the successfully matched protocol proxy service as the target protocol proxy service, and storing the target protocol proxy service in the resource pool includes:
[0034] S421. After receiving the client request, use the sticky mechanism to extract the protocol fields from the request information of the target server and form a structured protocol feature set.
[0035] S422. Perform hierarchical matching between the structured protocol feature set and the protocol proxy service, and select the successfully matched protocol proxy service as the candidate protocol proxy service;
[0036] S423. Evaluate the authentication connection quality of the candidate protocol proxy services, select the target protocol proxy service, and store it in the resource pool.
[0037] Preferably, the hierarchical matching between the structured protocol feature set and the protocol proxy service, and the selection of successfully matched protocol proxy services as candidate protocol proxy services, includes:
[0038] S4221. Perform a first-level matching between the structured protocol feature set and the protocol proxy service, specifically including:
[0039] If a protocol proxy service is specified in the structured protocol feature set, a connection is established directly with the specified protocol proxy service; if no protocol proxy service is specified in the structured protocol feature set, step S4222 is executed.
[0040] S4222. Perform a two-level matching between the structured protocol feature set and the protocol proxy service, and select the successfully matched protocol proxy service as the candidate protocol proxy service according to the predefined priority order.
[0041] Preferably, a two-stage matching process is performed between the structured protocol feature set and the protocol proxy service, and the successfully matched protocol proxy service is selected as a candidate protocol proxy service according to a predefined priority order, including:
[0042] S42221. Verify the protocol type, authentication method, and coordination compatibility between the structured protocol feature set and the protocol proxy service item by item to obtain a candidate list;
[0043] S42222 Extract feature indicators from the candidate list, construct a multi-attribute decision matrix based on the feature indicators, and introduce weight vectors into the multi-attribute decision matrix to obtain a weighted matrix;
[0044] S42223. Calculate the distance from each candidate in the candidate list to the positive ideal solution and the negative ideal solution based on the weighted matrix, and calculate the preference degree based on the positive ideal solution and the negative ideal solution.
[0045] S42224. Sort the candidate options from high to low according to preference, and select the candidate options within the preset sorting range as candidate protocol proxy services.
[0046] Preferably, a corresponding resource item is created for the target protocol proxy service in the resource pool, and the temporary proxy service monitors the connection of the target protocol proxy service through the resource item, including:
[0047] S431. Perform root cause analysis on the target protocol proxy services in the resource pool to identify target protocol proxy services with abnormal connection status.
[0048] S432. Based on the current resource item status in the abnormal target protocol proxy service and resource pool, generate the policy action table for the abnormal target protocol proxy service.
[0049] S433. Using the policy action table as input to the pre-built virtual force model, and the abnormal target protocol agent service as the force-bearing particle, the attraction and repulsion between the force-bearing particle and each candidate protocol agent service are simulated and calculated through the virtual force model to obtain the meta-learning transfer path.
[0050] S434. Based on the meta-learning migration path, call the resource item interface to execute the connection migration behavior and update the resource item. The connection migration behavior includes at least connection reconstruction and protocol proxy service update.
[0051] The beneficial effects of this invention are as follows:
[0052] 1. This invention uses SSH key proxy to operate and maintain SSH and SFTP protocols, so that the target server is not limited to password-based login mechanisms. While ensuring security, it significantly optimizes the authentication and connection process. The key has higher resistance to cracking than traditional passwords, effectively preventing brute-force attacks and man-in-the-middle attacks, thereby avoiding security vulnerabilities caused by password leakage, password cracking, and password expiration management.
[0053] 2. This invention utilizes a core synchronization algorithm to keep protocol operation and maintenance parameters synchronously stored in a distributed operation and maintenance environment, ensuring that all agent nodes receive consistent and high-quality parameter configurations in multi-point, multi-task operation and maintenance scenarios. This guarantees the uniformity and controllability of protocol behavior. Furthermore, by extracting the state variables of the parameters to drive a four-state synchronization model, highly consistent parameter synchronization and distribution are achieved among distributed nodes. At the same time, the synchronization path is adaptively optimized based on modal grouping and clock reset mechanisms, further improving the accuracy and real-time performance of synchronization, and providing a stable and reliable parameter foundation for subsequent agent service execution.
[0054] 3. This invention selects the optimal service from numerous protocol proxy services through a two-level matching mechanism driven by primary matching and multi-attribute decision-making, ensuring service compatibility, stability, and response performance. It also selects the target proxy service through authentication quality assessment and registers resource items in the resource pool to achieve controllable status and monitorable connection. When a connection anomaly occurs, the system can also calculate an intelligent migration path through the policy action table and virtual force model, automatically executing connection migration and service replacement, thus realizing adaptive control and service quality assurance throughout the entire connection lifecycle. Attached Figure Description
[0055] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0056] Figure 1 This is a flowchart of an SSH key proxy operation and maintenance method based on an operation and maintenance management system according to an embodiment of the present invention;
[0057] Figure 2 This is a schematic diagram illustrating a specific implementation of an SSH key proxy operation and maintenance method based on an operation and maintenance management system according to an embodiment of the present invention. Detailed Implementation
[0058] To further illustrate the various embodiments, the present invention provides accompanying drawings, which are part of the disclosure of the present invention. These drawings are mainly used to illustrate the embodiments and can be used in conjunction with the relevant descriptions in the specification to explain the operating principles of the embodiments. With reference to these drawings, those skilled in the art should be able to understand other possible implementation methods and the advantages of the present invention.
[0059] According to an embodiment of the present invention, an SSH key proxy operation and maintenance method based on an operation and maintenance management system is provided.
[0060] The present invention will now be further described in conjunction with the accompanying drawings and specific embodiments, such as... Figure 1 As shown, according to an embodiment of the present invention, an SSH key proxy operation and maintenance method based on an operation and maintenance management system includes:
[0061] S1. Generate an SSH key using the key management device in the front-end operation and maintenance management page, authorize the target server, and obtain the protocol operation and maintenance parameters through the background service program when the target server is clicked.
[0062] The protocol operation and maintenance parameters include the operation and maintenance parameters of the SSH protocol and the SFTP protocol. The operation and maintenance management system uses the SSH key proxy to operate and maintain the SSH protocol and the SFTP protocol, so that the target server can disable the password-based login mechanism.
[0063] S2. After the background service program performs the initial verification of the protocol operation and maintenance parameters, it passes them to the operation and maintenance agent program. The operation and maintenance agent program performs cross-node consistency synchronization and storage of the protocol operation and maintenance parameters, and saves the SSH key to a temporary file. After the SSH key is saved, it returns to the listening port.
[0064] It should be noted that after receiving the protocol operation and maintenance parameters, the operation and maintenance agent program uses the core synchronization algorithm to keep the protocol parameters synchronized in the distributed operation and maintenance environment. The purpose of this is to ensure that all agent nodes receive consistent and complete operation and maintenance instructions in multi-task, high-concurrency, or cross-domain operation scenarios. This is to prevent behavioral deviations, control conflicts, or data inconsistencies caused by parameter asynchrony. Consistent parameter snapshot copies are formed in multiple agent nodes, so that any node can rely on the same parameter context when performing operation and maintenance operations.
[0065] The background service program performs initial verification of the protocol operation and maintenance parameters and then transmits them to the operation and maintenance agent program. The operation and maintenance agent program performs cross-node consistency synchronization and storage of the protocol operation and maintenance parameters, and saves the SSH key to a temporary file. After the SSH key is saved, it returns the listening port, including:
[0066] S21. The background service program performs structural and semantic checks on the protocol operation and maintenance parameters in sequence, and then passes the protocol operation and maintenance parameters that have been checked for the first time to the operation and maintenance agent program.
[0067] It should be noted that the background service program performs structural and semantic checks on the protocol operation and maintenance parameters sequentially, and then passes the initially checked protocol operation and maintenance parameters to the operation and maintenance agent program, including:
[0068] Extract the protocol operation and maintenance parameter fields and perform structural validation based on the data model to ensure that all required fields exist, the field types are correct, and the format conforms to the specifications (such as IP, port, protocol name, action type, etc.). After the structural validation passes, the semantic validation stage begins. The background program analyzes the logical relationships and legality between fields, such as confirming whether the protocol matches the target port, whether the target host supports the selected operation, whether the operation command conflicts with the current context, and whether the parameter combination meets the business strategy. After the semantic validation is completed, the system will standardize and encapsulate the validated parameters into a standardized data structure or context object and pass it to the downstream operation and maintenance agent program to initiate specific operation and maintenance actions.
[0069] S22. The operation and maintenance agent program receives the protocol operation and maintenance parameters and, in conjunction with the status variables of the protocol operation and maintenance parameters, achieves cross-node consistent synchronous storage of the protocol operation and maintenance parameters in the multi-node environment of the distributed operation and maintenance cluster.
[0070] The operation and maintenance agent program receives protocol operation and maintenance parameters and, in conjunction with the status variables of these parameters, implements cross-node consistent synchronization and storage of these parameters in a multi-node environment of a distributed operation and maintenance cluster.
[0071] S221. Obtain the status variables of the protocol operation and maintenance parameters after the initial verification is completed, and the status variables include parameter integrity, parameter propagation rate, parameter consistency deviation and parameter strength factor.
[0072] S222. Using the state variables as input to the four-state synchronization model, and combining them with predefined clock synchronization rules, the four-state synchronization model is used to synchronously propagate the protocol operation and maintenance parameters to the agent node for initial storage, thereby obtaining the synchronization protocol parameters stored in the agent node.
[0073] It should be noted that after the background service program completes the initial verification of the protocol operation and maintenance parameters, it will extract a set of state variables to describe the parameter quality and transmission characteristics, including parameter integrity, parameter propagation rate, parameter consistency deviation, and parameter strength factor. The functions of these state variables are as follows:
[0074] Parameter completeness measures whether parameter fields are complete and conform to structural rules. Parameter propagation rate reflects the transmission latency and efficiency of parameters from the verification end to the agent end. Parameter consistency deviation is used to detect whether parameters have semantic shifts or have been tampered with during multi-node propagation. Parameter strength factor comprehensively evaluates the instruction strength and priority of parameters to the target agent behavior.
[0075] These four types of state variables are input into the four-state synchronization model, whose structural components include: a state identifier (used to perceive the category to which the current protocol parameter state belongs), a synchronization clock controller (driving state synchronization according to a predefined global clock rhythm), a state transition matrix (determining how the current state evolves and propagates between nodes), and a storage mapper (mapping the final synchronization result into a snapshot of the protocol parameters of the proxy node).
[0076] This four-state synchronization model employs a Finite State Automaton (FSM) + Distributed Clock Synchronization algorithm architecture. The FSM provides four clearly defined states (e.g., Ready, Transmitting, Pending Confirmation, Completed) and state transition logic. Distributed clock synchronization, leveraging the logical clock, precisely aligns the state progression rhythm, ensuring consistent parameter transmission across nodes. In implementation, state variables serve as input feature vectors driving a state identifier to determine the current synchronization stage. Clock synchronization rules trigger state progression instructions, and the state transition matrix calculates the target state in real-time based on node feedback. Finally, a mapper stores the synchronized protocol parameters in the proxy node's local parameter buffer or persistent storage structure, forming a final, reusable protocol configuration snapshot.
[0077] It should be noted that a finite state automaton includes: defining the set of all possible states and the set of input events, such as the "ready state, transit state, acknowledged state, and completed state" in a four-state model; defining the state transition function, that is, the logical rule for transitioning from one state to another under specific input conditions; configuring a state register to record the current state, triggering the transition logic whenever the input state variable changes, updating the current state in the state register, and executing the associated action (such as sending data, writing to storage, initiating synchronization acknowledgment, etc.); throughout the process, the state transition is driven by the input, ensuring that the system progresses on a defined path.
[0078] Predefined clock synchronization rules refer to a unified timing coordination mechanism used in the parameter state propagation process to ensure that all participating nodes have a consistent understanding of the synchronization state. Common rules include: using a logical clock to timestamp each state operation to ensure that the operation order is comparable; or using a precise synchronization mechanism such as PTP or NTP to align the physical clocks of all nodes, so that the state advancement scheduling has a unified time base and forms time constraints in state synchronization triggering, acknowledgment timeout and retransmission control.
[0079] S223. Use the synchronization protocol parameters as input to the extended Kalman filter, and output the state prediction value of the agent node through the extended Kalman filter;
[0080] S224. Based on the state prediction values of the proxy nodes, proxy nodes with similar characteristics are divided into the same mode group, and a Kalman filter instance is run for each mode group to obtain the state evaluation value of each mode group, specifically including:
[0081] By using clustering algorithms (such as spectral clustering) to modally divide features, a set of agents that are highly similar in behavioral features or operating states can be obtained.
[0082] Instantiate an independent Kalman filter for each mode group, set the initial state estimate and covariance matrix, define the system state transition model and observation model for the group, and update the observation values at each time step based on the real-time running data of the agent node (such as latency, connection success rate, and error rate).
[0083] The Kalman filter sequentially performs a prediction step (predicting the current state based on the state transition equation) and an update step (correcting the prediction error based on the actual observations), thereby continuously outputting the state evaluation value of the mode group.
[0084] S225. Based on the state evaluation value of the modal group, the transition nodes in the agent nodes are selected, the parameters of the four-state synchronization model are optimized by the adaptive clock reset algorithm, and the protocol operation and maintenance parameters initially stored in the transition nodes are propagated to the other agent nodes by the optimized four-state synchronization model, so as to achieve consistent synchronous storage of protocol operation and maintenance parameters in the agent nodes.
[0085] Among them, transition nodes in the proxy nodes are selected based on the state evaluation values of the mode group, and the parameters of the four-state synchronization model are optimized using an adaptive clock reset algorithm, including:
[0086] The state evaluation value of the modal group is compared with a preset threshold. If the state evaluation value of the modal group is greater than or equal to the preset threshold, the agent node corresponding to the current modal group is used as the transition node.
[0087] Extract the delay characteristics of the synchronization protocol parameters stored in the jump node, calculate each delay characteristic value one by one on the time axis, and identify the clock reset interval and noise interval based on the delay characteristic values;
[0088] Arbitrarily select adjacent state intervals of the four-state synchronization model. If the endpoints of the adjacent state intervals are the same, the current state interval is determined to be a noise interval. If the endpoints of the adjacent state intervals are different, the current state interval is determined to be a clock reset interval, and the parameters of the four-state synchronization model are updated.
[0089] It should be noted that the purpose of setting the clock reset interval and noise interval is to accurately identify whether there is structural timing drift or instantaneous anomaly during the synchronization process of the agent node, so as to determine whether the time control parameters of the four-state synchronization model need to be updated.
[0090] Among them, the noise interval reflects the frequent oscillation of parameter states in a short period of time without producing effective state transitions, which is a non-deterministic jitter. The clock reset interval represents the segment where the node state actually transitions and has a timing offset, which needs to be corrected by adjusting the time base of the synchronization model (such as the state transition threshold or waiting window).
[0091] By filtering modal group agent nodes (transition nodes) whose state evaluation values exceed the threshold, and combining their stored protocol parameter delay characteristics to locate time anomaly segments, and determining whether the synchronization model is inaccurate based on the differences between the endpoints of the state intervals, the timing parameters of the four-state model are dynamically optimized in principle through an adaptive clock reset algorithm.
[0092] S23. Create a temporary file in the background, store the SSH key in the temporary file, and return to the listening port after the SSH key is stored.
[0093] S3. Pass the listening port and protocol operation and maintenance parameters to the front-end client management program. The front-end client management program parses the protocol operation and maintenance parameters and performs secondary verification. After secondary verification, it calls the operation and maintenance tool. The client accesses the temporary proxy service based on the authentication credentials in the protocol operation and maintenance parameters.
[0094] S4. The temporary proxy service receives and parses the client request, matches the client request with the protocol proxy service for protocol capabilities, selects the target protocol proxy service based on the matching result and stores it in the resource pool, and monitors the connection status of the target protocol proxy service through the resource pool.
[0095] The temporary proxy service receives and parses client requests, matches the client requests with the protocol proxy service to determine their protocol capabilities, selects a target protocol proxy service based on the matching results, stores it in the resource pool, and monitors the connection status of the target protocol proxy service through the resource pool, including:
[0096] S41. After receiving the client request, the temporary proxy service parses it and obtains the request information of the target server from the parsed client request.
[0097] S42. Match the request information of the target server with the protocol proxy service to determine the protocol capabilities. Use the successfully matched protocol proxy service as the target protocol proxy service and store the target protocol proxy service in the resource pool.
[0098] This includes matching the request information of the target server with the protocol proxy service to determine its protocol capabilities, using the successfully matched protocol proxy service as the target protocol proxy service, and storing the target protocol proxy service in the resource pool.
[0099] S421. After receiving the client request, use the sticky mechanism to extract the protocol fields from the request information of the target server and form a structured protocol feature set.
[0100] It should be noted that the process involves listening to and capturing the client's raw request data stream, and then using a consolidation mechanism to aggregate and parse fields related to the target server and protocol in the request message. This consolidation mechanism refers to merging multiple scattered but related fields during the protocol field extraction process through context binding, semantic association, or data location reconstruction to avoid field fragmentation or misidentification and ensure that logically consistent protocol features are extracted. Subsequently, the extracted results are structurally transformed using syntax templates or field mapping rules to organize them into a protocol feature set in a unified format (such as a JSON object or feature vector).
[0101] The core purpose of this standardized transformation logic, which converts protocol-related fields (such as IP, port, protocol identifier, path, header, SNI, etc.) extracted from the original request into a structured protocol feature set, is to uniformly map scattered, heterogeneous, and non-fixed-location fields to predefined semantic sites, forming a unified representation that can be recognized and processed by the system. Field mapping rules include:
[0102] Field name mapping (e.g., mapping scheme in header to protocol type), field type conversion (e.g., converting string port number to integer), field combination mapping (e.g., combining host and port to the target address), field missing default filling (e.g., defaulting to HTTP / 1.1 when no protocol is specified), field conflict resolution strategy (e.g., taking the higher priority when both header and URI specify protocols). Mapping rules can be implemented based on static tables, dynamic matching templates (e.g., regular expression templates + context association), or rule engines (e.g., DSL configuration).
[0103] S422. Perform hierarchical matching between the structured protocol feature set and the protocol proxy service, and select the successfully matched protocol proxy service as the candidate protocol proxy service.
[0104] This involves hierarchical matching between structured protocol feature sets and protocol proxy services, with successfully matched protocol proxy services selected as candidate protocol proxy services, including:
[0105] S4221. Perform a first-level matching between the structured protocol feature set and the protocol proxy service, specifically including:
[0106] If a protocol proxy service is specified in the structured protocol feature set, a connection is established directly with the specified protocol proxy service; if no protocol proxy service is specified in the structured protocol feature set, step S4222 is executed.
[0107] S4222. Perform a two-level matching between the structured protocol feature set and the protocol proxy service, and select the successfully matched protocol proxy service as the candidate protocol proxy service according to the predefined priority order.
[0108] It should be noted that the purpose of first-level matching is to directly establish a connection when the protocol proxy service has been explicitly specified in the structured protocol feature set, avoiding repeated identification and scheduling operations, thereby improving response speed and processing efficiency; while the purpose of second-level matching is to filter and intelligently match candidate proxy services by priority order when the protocol proxy service has not been explicitly specified, ensuring that the most suitable proxy service can still be automatically selected in the absence of explicit guidance.
[0109] This involves a two-stage matching process between the structured protocol feature set and the protocol proxy service, selecting the successfully matched protocol proxy service as a candidate protocol proxy service based on a predefined priority order.
[0110] S42221. Verify the protocol type, authentication method, and coordination compatibility between the structured protocol feature set and the protocol proxy service item by item to obtain a candidate list;
[0111] S42222 Extract feature indicators from the candidate list, construct a multi-attribute decision matrix based on the feature indicators, and introduce weight vectors into the multi-attribute decision matrix to obtain a weighted matrix;
[0112] S42223. Calculate the distance from each candidate in the candidate list to the positive ideal solution and the negative ideal solution based on the weighted matrix, and calculate the preference degree based on the positive ideal solution and the negative ideal solution.
[0113] S42224. Sort the candidate options from high to low according to preference, and select the candidate options within the preset sorting range as candidate protocol proxy services.
[0114] The following describes a specific implementation method for performing a two-stage matching between structured protocol feature sets and protocol proxy services, selecting successfully matched protocol proxy services as candidate protocol proxy services based on a predefined priority order:
[0115] Step 1: Verify the protocol type, authentication method, and coordination compatibility item by item. Based on the content of the structured protocol feature set, perform the first round of precise filtering on the registered protocol proxy services. The execution logic includes:
[0116] Protocol type matching: If the feature set is SSH, only retain proxy services that support SSH.
[0117] Authentication method verification: Matches authentication capabilities such as passwordless authentication, token-based authentication, and TLS handshake authentication.
[0118] Coordination and compatibility: Determine whether the proxy service is compatible with the current target server's network environment or load balancing strategy to obtain a preliminary candidate list.
[0119] Step 2: Construct a multi-attribute decision matrix and a weighted matrix, and extract the key attributes (feature indicators) of each candidate from the candidate list:
[0120] r1: Current connection success rate;
[0121] r2: Response latency (ms);
[0122] r3: Availability (current running status);
[0123] r4: Historical stability coefficient;
[0124] r5: Resource load occupancy rate;
[0125] Form a standardized decision matrix R = [r ij ], where x ij Let the value of the i-th candidate on the j-th attribute be represented by a weight vector W = [w1, w2, ... wj]. n ], satisfying ∑w i =1, for example, by setting it through AHP or expert experience, multiply it by X to obtain the weighted matrix R = X·W.
[0126] Step 3: Calculate the superior and inferior solutions for the weighted matrix:
[0127] Define the ideal solution A + and negative ideal solution;
[0128] For each candidate i, calculate its Euclidean distance to the positive ideal solution and the negative ideal solution:
[0129]
[0130] The formula for calculating preference is:
[0131]
[0132] In the formula, This represents the Euclidean distance from the i-th candidate to the positive ideal solution; r represents the Euclidean distance from the i-th candidate to the negative ideal solution; ij This represents the value of the i-th candidate in the j-th attribute of a multi-attribute decision matrix; This represents the optimal value of the j-th attribute among all candidates (the ideal value of the positive ideal solution in this dimension); Let represent the worst value of the j-th attribute among all candidates (the ideal value of the negative ideal solution in that dimension); n represents the total number of attributes, i.e., the number of dimensions for each candidate option in the decision matrix, where the preference degree P i The larger the value, the better. i ∈[0,1].
[0133] Step 4: Sort all candidates according to their preference level P. i Sort the services from highest to lowest quality, and select the top k (controlled by a preset range set by the system) as the final candidate proxy service list.
[0134] Step 5: Authentication connection quality assessment and target proxy selection. Real-time connection quality testing is performed on the ranked candidate proxy services, including: handshake time, authentication success rate, connection jitter, and authentication protocol consistency verification.
[0135] Based on the comprehensive score, the one with the best current quality is selected as the target protocol proxy service, and its metadata, connectivity, and other data are written into the runtime resource pool for use in subsequent connection calls and operation and maintenance instructions.
[0136] S423. Evaluate the authentication connection quality of the candidate protocol proxy services, select the target protocol proxy service, and store it in the resource pool.
[0137] S43. Create a corresponding resource item for the target protocol proxy service in the resource pool. The temporary proxy service monitors the connection of the target protocol proxy service through the resource item.
[0138] Specifically, this involves creating corresponding resource items for the target protocol proxy service within the resource pool, and the temporary proxy service monitoring the connection to the target protocol proxy service through these resource items, including:
[0139] S431. Perform root cause analysis on the target protocol proxy services in the resource pool to identify target protocol proxy services with abnormal connection status.
[0140] S432. Based on the current resource item status in the abnormal target protocol proxy service and resource pool, generate the policy action table for the abnormal target protocol proxy service.
[0141] It should be noted that the policy action table includes: isolation actions (such as removing from the list of available services), degradation actions (such as switching to a low-priority task, limiting the number of concurrent connections), reconnection or retry actions (such as initiating a fast reconnection attempt to confirm whether it is a transient anomaly), alarm actions (such as logging and pushing to the monitoring center), repair suggestion actions (such as suggesting to perform health checks, replace backend modules, refresh authentication keys, etc.), load balancing actions (such as forwarding the current proxy task to a normal alternative node), and parameter resynchronization actions (for protocol parameters that have failed to synchronize or have drifted, such as re-pulling a consistent snapshot, etc.).
[0142] S433. Using the policy action table as input to the pre-built virtual force model, and the abnormal target protocol agent service as the force-bearing particle, the attraction and repulsion between the force-bearing particle and each candidate protocol agent service are simulated and calculated through the virtual force model to obtain the meta-learning transfer path.
[0143] It should be noted that by inputting the policy action table into the virtual force model and treating the abnormal target protocol agent service as a force-bearing particle, the attractive and repulsive forces between it and the candidate agent nodes are simulated to calculate and output the optimal migration path (i.e., the meta-learning migration path), thereby realizing the intelligent replacement and migration scheduling of abnormal services.
[0144] Specifically, the virtual force model's architecture is based on a combination of physical modeling and graph embedding fusion modeling, and its core consists of the following three parts:
[0145] 1) Particle Node Representation Layer: Each protocol proxy service is abstracted as a node vector, abnormal proxy services are initialized as force-bearing particles, and all candidate nodes are the set of action points;
[0146] 2) Force field function layer: Define attractive forces (such as high resource matching degree, strategy action compatibility) and repulsive forces (such as connection failure history, load conflict) as calculation functions of two-dimensional tensors;
[0147] 3) Path deduction layer: Taking the resultant force direction of all force vectors as the migration intention, and combining the communication weights between nodes, resource status and historical performance indicators, the shortest resultant force path search is performed on the force graph (graph search algorithms such as A* or Dijkstra can be used) to obtain the migration path of the force particles to the best agent node, which can be used as the execution sequence of policy scheduling instructions.
[0148] This approach simulates the evolution of particle states in a force field in real-world physics, encoding "adaptive driving" through abstract forces. It uses attractive forces to encourage migration to highly adaptable nodes and repulsive forces to exclude less reliable nodes, forming a continuous and differentiable migration decision path. Unlike rule-based matching scheduling, it possesses dynamic learning and directional guidance capabilities, making it particularly suitable for complex, dynamic, and uncertain distributed operation and maintenance environments.
[0149] At the implementation level, each action in the strategy action table is mapped to a candidate agent node, and a matching score vector is calculated. Then, based on the availability, stability, authentication quality, and other indicators of the current node in the resource pool, a "strategy-node" interaction graph is constructed. The magnitude of the attraction and repulsion between each pair of nodes is evaluated using a virtual force function, and a global force field is synthesized. Finally, the meta-learning transfer path is selected based on the optimal direction of the resultant force. This process can be further fine-tuned through reinforcement learning or graph neural networks to improve the accuracy of fitness prediction and transfer robustness.
[0150] S434. Based on the meta-learning migration path, call the resource item interface to execute the connection migration behavior and update the resource item. The connection migration behavior includes at least connection reconstruction and protocol proxy service update.
[0151] It should be noted that by driving connection migration behavior through meta-learning migration paths, the original abnormal or failed protocol proxy services are replaced with candidate proxy nodes in better condition, and the system resource status is updated, thereby achieving high availability, low latency, and intelligent fault-tolerant operation and maintenance connection switching without interrupting services.
[0152] The "connection reconstruction" process included in the connection migration ensures that a valid communication link is established between the client and the new target proxy. The "protocol proxy service update" ensures that the parameters are synchronized, the authentication mechanism and policy state are completely consistent with the new service. During this process, the resource item interface is called to write new service information, release old resource bindings, and so on.
[0153] S5, the target protocol proxy service establishes a connection with the target server for operation and maintenance through the SSH key and forwards client requests. After the proxy operation and maintenance is completed, the SSH key is deleted.
[0154] like Figure 2 As shown, the operation and maintenance management system is based on a B / S architecture and mainly includes a front-end management page, a front-end client management program, a client program, a temporary proxy service, and a protocol proxy service.
[0155] The front-end management page is primarily responsible for collecting information about the target server being maintained. This information includes the target server's IP address, port information, and protocol type. It also includes a key management and generation device and provides a button to trigger the maintenance process and establish communication with the back-end service program. The interaction between the front-end and back-end can utilize popular web servers such as Lightned, Nginx, and Apache.
[0156] Front-end client management program: mainly responsible for calling different client login programs according to different protocols based on the parameters returned from the back-end.
[0157] Client programs: Different protocols require different client login programs. For the existing SSH protocol, you can choose tools such as PuTTY, CRT, and Xshell. For the SFTP protocol, you can choose tools such as WinSCP. The client does not require a key; the operation and maintenance management system will use a key proxy to log in.
[0158] Operation and maintenance agent program: manages the received operation and maintenance parameters through data structure management.
[0159] Temporary proxy service: This service provides a temporary port for operations and maintenance personnel. Client-side maintenance personnel can connect to this temporary proxy service without a key. Once connected, the port is locked, preventing other clients from connecting again. The temporary proxy service is removed and the port is released after the maintenance is completed.
[0160] Protocol proxy service: Depending on the protocol, different proxy programs can be used to relay and connect to the target server after the connection is established. During the relay process, i.e., the proxy process, a secure connection and login are established using the target service's key.
[0161] The SSH key proxy operation and maintenance method based on the operation and maintenance management system includes:
[0162] First, generate or upload an SSH key using the key management device on the front-end management page. Then, authorize the target server by clicking on the target SSH or SFTP server. Through front-end and back-end interaction, the backend service program obtains relevant SSH or SFTP operation parameters, including the operation client IP, time, and key. After verifying the parameters, the backend service program passes them to the operation agent program. The operation agent program manages the received operation parameters using a specific data structure, and the key is saved to a temporary file in the backend. Upon successful completion, the listening port is returned; this port is the publicly accessible port (the range of this port number can be defined according to user needs).
[0163] The returned listening port and other SSH and SFTP operation and maintenance parameters are passed to the front-end client management program. The front-end client management program parses the corresponding parameters and performs verification. If successful, it calls PuTTY (selecting the appropriate tool). The operation and maintenance client does not need to bind any key; the operation and maintenance client will access the temporary proxy service based on the token in the parameters.
[0164] After the temporary proxy service parses the protocol and other information used by the target machine, it connects to the corresponding protocol proxy service based on the target host information requested by the client. At this point, the entire connection is temporary. The temporary proxy will be destroyed if the maintenance is interrupted. External access is then impossible.
[0165] The protocol proxy service establishes a connection with the target machine and forwards the request. The original module connected directly to the target server using a password; this has been changed to connect using a key. The key is saved to a temporary location when an operation is clicked on the front-end operations page for use during operations. The proxy key is deleted after the operations are completed, ensuring key security.
[0166] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An operation and maintenance system based SSH key agent operation and maintenance method, characterized in that, The method includes: S1. Generate an SSH key using the key management device in the front-end operation and maintenance management page, authorize the operation and maintenance target server, and obtain the protocol operation and maintenance parameters through the background service program when the operation and maintenance target server is clicked. S2. After the background service program performs the initial verification of the protocol operation and maintenance parameters, it passes them to the operation and maintenance agent program. The operation and maintenance agent program performs cross-node consistency synchronization and storage of the protocol operation and maintenance parameters, and saves the SSH key to a temporary file. After the SSH key is saved, it returns to the listening port. S3. Pass the listening port and protocol operation and maintenance parameters to the front-end client management program. The front-end client management program parses the protocol operation and maintenance parameters and performs secondary verification. After secondary verification, it calls the operation and maintenance tool. The client accesses the temporary proxy service based on the authentication credentials in the protocol operation and maintenance parameters. S4. The temporary proxy service receives and parses the client request, matches the client request with the protocol proxy service for protocol capabilities, selects the target protocol proxy service based on the matching result and stores it in the resource pool, and monitors the connection status of the target protocol proxy service through the resource pool. S5: The target protocol proxy service establishes a connection with the target server of operation and maintenance through the SSH key and forwards client requests. After the proxy operation and maintenance is completed, the SSH key is deleted. S2 includes: S21. The background service program performs structural and semantic checks on the protocol operation and maintenance parameters in sequence, and then passes the protocol operation and maintenance parameters that have completed the initial check to the operation and maintenance agent program. S22. The operation and maintenance agent program receives the protocol operation and maintenance parameters and, in combination with the status variables of the protocol operation and maintenance parameters, realizes cross-node consistent synchronous storage of the protocol operation and maintenance parameters in the multi-node environment of the distributed operation and maintenance cluster. S23. Create a temporary file in the background, store the SSH key in the temporary file, and return to the listening port after the SSH key is stored; S22 includes: S221. Obtain the status variables of the protocol operation and maintenance parameters after the initial verification is completed, and the status variables include parameter integrity, parameter propagation rate, parameter consistency deviation and parameter strength factor. S222. Using the state variables as input to the four-state synchronization model, and combining them with predefined clock synchronization rules, the four-state synchronization model is used to synchronously propagate the protocol operation and maintenance parameters to the agent node for initial storage, thereby obtaining the synchronization protocol parameters stored in the agent node. S223. Use the synchronization protocol parameters as input to the extended Kalman filter, and output the state prediction value of the agent node through the extended Kalman filter; S224. Based on the state prediction values of the agent nodes, agent nodes with similar characteristics are divided into the same mode group, and a Kalman filter instance is run for each mode group to obtain the state evaluation value of each mode group. S225. Based on the state evaluation value of the modal group, the transition nodes in the agent nodes are selected, the parameters of the four-state synchronization model are optimized by the adaptive clock reset algorithm, and the protocol operation and maintenance parameters initially stored in the transition nodes are propagated to the other agent nodes by the optimized four-state synchronization model, so as to achieve consistent synchronous storage of protocol operation and maintenance parameters in the agent nodes. S4 includes: S41. After receiving the client request, the temporary proxy service parses it and obtains the request information of the target server from the parsed client request. S42. Match the request information of the target server with the protocol proxy service for protocol capabilities, use the successfully matched protocol proxy service as the target protocol proxy service, and store the target protocol proxy service in the resource pool; S43. Create a corresponding resource item for the target protocol proxy service in the resource pool. The temporary proxy service monitors the connection of the target protocol proxy service through the resource item. S42 includes: S421. After receiving the client request, use the sticky mechanism to extract the protocol fields from the request information of the target server and form a structured protocol feature set. S422. Perform hierarchical matching between the structured protocol feature set and the protocol proxy service, and select the successfully matched protocol proxy service as the candidate protocol proxy service; S423. Evaluate the authentication connection quality of candidate protocol proxy services, select the target protocol proxy service and store it in the resource pool; S422 includes: S4221. Perform a first-level matching between the structured protocol feature set and the protocol proxy service, specifically including: If a protocol proxy service is specified in the structured protocol feature set, a connection is established directly with the specified protocol proxy service; if no protocol proxy service is specified in the structured protocol feature set, step S4222 is executed. S4222. Perform a two-level matching between the structured protocol feature set and the protocol proxy service, and select the successfully matched protocol proxy service as the candidate protocol proxy service according to the predefined priority order. S4222 includes: S42221. Verify the protocol type, authentication method, and coordination compatibility between the structured protocol feature set and the protocol proxy service item by item to obtain a candidate list; S42222 Extract feature indicators from the candidate list, construct a multi-attribute decision matrix based on the feature indicators, and introduce weight vectors into the multi-attribute decision matrix to obtain a weighted matrix; S42223. Calculate the distance from each candidate in the candidate list to the positive ideal solution and the negative ideal solution based on the weighted matrix, and calculate the preference degree based on the positive ideal solution and the negative ideal solution. S42224. Sort the candidate options from high to low according to preference, and select the candidate options within the preset sorting range as candidate protocol proxy services; S43 includes: S431. Perform root cause analysis on the target protocol proxy services in the resource pool to identify target protocol proxy services with abnormal connection status. S432. Based on the current resource item status in the abnormal target protocol proxy service and resource pool, generate the policy action table for the abnormal target protocol proxy service. S433. Using the policy action table as input to the pre-built virtual force model, and the abnormal target protocol agent service as the force-bearing particle, the attraction and repulsion between the force-bearing particle and each candidate protocol agent service are simulated and calculated through the virtual force model to obtain the meta-learning transfer path. S434. Based on the meta-learning migration path, call the resource item interface to execute the connection migration behavior and update the resource item. The connection migration behavior includes at least connection reconstruction and protocol proxy service update.
2. The SSH key proxy operation and maintenance method based on an operation and maintenance management system according to claim 1, characterized in that, The protocol operation and maintenance parameters include the operation and maintenance parameters of the SSH protocol and the SFTP protocol. The operation and maintenance management system uses the SSH key proxy to operate and maintain the SSH protocol and the SFTP protocol, so that the target server can disable the password-based login mechanism.
3. The SSH key proxy operation and maintenance method based on an operation and maintenance management system according to claim 1, characterized in that, The process of selecting transition nodes from proxy nodes based on the state evaluation values of the mode group and optimizing the parameters of the four-state synchronization model using the adaptive clock reset algorithm includes: The state evaluation value of the modal group is compared with a preset threshold. If the state evaluation value of the modal group is greater than or equal to the preset threshold, the agent node corresponding to the current modal group is used as the transition node. Extract the delay characteristics of the synchronization protocol parameters stored in the jump node, calculate each delay characteristic value one by one on the time axis, and identify the clock reset interval and noise interval based on the delay characteristic values; Arbitrarily select adjacent state intervals of the four-state synchronization model. If the endpoints of the adjacent state intervals are the same, the current state interval is determined to be a noise interval. If the endpoints of the adjacent state intervals are different, the current state interval is determined to be a clock reset interval, and the parameters of the four-state synchronization model are updated.
Citation Information
Patent Citations
Method for realizing cross-local area network edge device connection by using SSH reverse proxy
CN119341812A
Station area intelligent fusion terminal data processing system based on edge calculation
CN119440800A