A device account management method and a device account management system

By establishing a communication connection between the central server and devices, and utilizing a set of master and associated accounts, trusted accounts are automatically bound and information is encrypted and decrypted using symmetric keys. This solves the problems of high deployment difficulty and low efficiency in account management deployment and updates in large-scale device clusters, and achieves efficient and secure account management.

CN121502744BActive Publication Date: 2026-03-24ZHEJIANG DAHUA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-14
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing device account management methods suffer from difficulties in deployment and updates, as well as low efficiency, when the cluster of devices is large.

Method used

By establishing a communication connection between the central server and the managed devices, and by automatically binding trusted accounts using a set of master and associated accounts, the device account configuration process is simplified. Symmetric keys are used for information encryption and decryption to ensure security and update efficiency.

Benefits of technology

It enables automatic binding and updating of device accounts, simplifies the deployment of large-scale device clusters, improves deployment efficiency, and ensures the security of account management and the convenience of updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121502744B_ABST
    Figure CN121502744B_ABST
Patent Text Reader

Abstract

The application relates to a device account management method and a device account management system. The method is applied to a device to be managed in a device account management system, and the device account management system further comprises a central server, the central server is provided with a master account, and the master account is associated with an account set. The method comprises the following steps: in response to received configuration information input by a user, establishing a connection with the central server and sending the configuration information to the central server; in response to a selection operation of the user on the associated account set based on an application scenario, determining a target account set in the associated account set and pulling set information of the target account set from the central server; storing the set information of the target account set and binding account data in the set information of the target account set as a trusted account. The method can solve the problem that, when the scale of the device to be managed is large, the existing device account management method has the problems of great deployment and updating difficulty and low efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of account management technology, and in particular to a device account management method and a device account management system. Background Technology

[0002] With the rapid development of the Internet of Things (IoT), cloud computing, and edge computing, the deployment of large-scale device clusters has become commonplace in data centers, smart manufacturing, smart cities, and security monitoring. As cluster devices become more widely used, their secure and efficient management is receiving increasing attention. To ensure the secure operation of the system, each device in a cluster typically requires independent account authentication and access control.

[0003] Existing device account management methods employ a decentralized account management model. This means each device independently deploys and maintains its own local account, requiring system administrators to log in to each device individually to manually create, configure, and maintain user accounts and their permissions. When the cluster of devices is large, this results in significant deployment and update difficulties and low efficiency.

[0004] Existing device account management methods suffer from difficulties in deployment and updates, as well as low efficiency, when the cluster of devices is large. Currently, no effective solution has been proposed. Summary of the Invention

[0005] Therefore, it is necessary to provide a device account management method and a device account management system to address the aforementioned technical problems.

[0006] Firstly, this application provides a device account management method. The method applies to devices to be managed within a device account management system, which further includes a central server. The central server is equipped with at least one master account, each master account is associated with at least one account set, and each account set includes at least two accounts. The method includes:

[0007] In response to the received configuration information input by the user, a communication connection is established with the central server, and the configuration information is sent to the central server; the configuration information is used to instruct the central server to return a set of associated accounts associated with the main account in the configuration information;

[0008] In response to the received user selection operation of the associated account set based on the application scenario, the target account set in the associated account set is determined, and the set information of the target account set is retrieved from the central server;

[0009] Store the set information of the target account set, and bind the account data in the set information of the target account set as a trusted account; the trusted account is an account that can be used to log in to the currently managed device.

[0010] In one embodiment, after establishing a communication connection with the central server in response to received user input configuration information and sending the configuration information to the central server, the process includes:

[0011] The system receives the set of associated accounts returned by the central server in response to the main account in the configuration information, and displays the set of associated accounts.

[0012] In one embodiment, after responding to a received user selection operation based on an application scenario of the associated account set, determining the target account set within the associated account set, and retrieving the set information of the target account set from the central server, the method further includes:

[0013] The central server receives a symmetric key generated in response to the set information of the target account set; the symmetric key is used to decrypt the update information received from the central server when updating the set information of the target account set.

[0014] In one embodiment, updating the set information of the target account set includes:

[0015] In response to the received set information to be updated broadcast from the central server, the target account set to be updated and the update information corresponding to the target account set to be updated are determined; the target account set to be updated is the set of accounts in the target account set whose set information needs to be updated.

[0016] Using the symmetric key, the update information corresponding to the target account set to be updated is decrypted to obtain the decrypted update information;

[0017] The set information of the target account set to be updated is updated using the decrypted update information.

[0018] Secondly, this application also provides a device account management method applied to a central server of a device account management system. The device account management system further includes devices to be managed. The central server is equipped with at least one master account, each master account is associated with at least one account set, and each account set includes at least two accounts. The method includes:

[0019] In response to receiving configuration information from the device under management, a set of associated accounts associated with the main account in the configuration information is determined, and the set of associated accounts is sent to the device under management; the configuration information is the configuration information input by the user received by the device under management.

[0020] In response to receiving a target account set from the device to be managed, the set information of the target account set is determined; the target account set is the set of accounts determined by the device to be managed from the associated account set based on the user's selection operation of the associated account set based on the application scenario; the set information is used to provide the device to be managed with accounts that can be used to log in to the current device to be managed.

[0021] In one embodiment, after determining the set information of the target account set in response to receiving the target account set from the device to be managed, the method further includes:

[0022] Generate a symmetric key corresponding to the set information of the target account set, and send the symmetric key to the device to be managed; the symmetric key is used to decrypt the updated information when the set information of the target account set is updated.

[0023] In one embodiment, updating the set information of the target account set includes:

[0024] In response to a received user account modification instruction, determine the set of accounts to be updated corresponding to the account modification instruction and the update information corresponding to the set of accounts to be updated;

[0025] Using the update information corresponding to the set of accounts to be updated, the set information of the set of accounts to be updated is updated, and the set of accounts to be updated and the update information corresponding to the set of accounts to be updated are encrypted to obtain the set information to be updated; the set information to be updated is then broadcast.

[0026] Thirdly, this application also provides a device account management method applied to a device account management system, the device account management system including a central server and devices to be managed, the central server being equipped with at least one master account, each master account being associated with at least one account set, and each account set including at least two accounts, the method comprising:

[0027] The device under management, in response to the configuration information input by the user, establishes a communication connection with the central server and sends the configuration information to the central server;

[0028] In response to receiving configuration information from the device to be managed, the central server determines a set of associated accounts related to the master account in the configuration information and sends the set of associated accounts to the device to be managed.

[0029] The device to be managed receives a set of associated accounts related to the main account returned by the central server in response to the main account in the configuration information, and displays the set of associated accounts.

[0030] The device to be managed, in response to the received user selection operation of the associated account set based on the application scenario, determines the target account set in the associated account set;

[0031] The central server, in response to receiving the target account set from the device under management, determines the set information of the target account set; the set information is used to provide the device under management with accounts that can be used to log in to the current device under management;

[0032] The device to be managed retrieves the set information of the target account set from the central server; stores the set information of the target account set, and binds the account data in the set information of the target account set as a trusted account; the trusted account is an account that can be used to log in to the current device to be managed.

[0033] In one embodiment, the method further includes:

[0034] The central server generates a symmetric key corresponding to the set information of the target account set and sends the symmetric key to the device to be managed; the symmetric key is used to decrypt the updated information when the set information of the target account set is updated.

[0035] The device to be managed receives the symmetric key generated by the central server in response to the set information of the target account set;

[0036] The central server, in response to a received user account modification instruction, determines the set of accounts to be updated corresponding to the account modification instruction and the update information corresponding to the set of accounts to be updated; uses the update information corresponding to the set of accounts to be updated to update the set information of the set of accounts to be updated, and encrypts the set of accounts to be updated and the update information corresponding to the set of accounts to be updated to obtain the set information to be updated; and broadcasts the set information to be updated.

[0037] The device to be managed receives the set information to be updated broadcast by the central server, and uses the symmetric key to decrypt the update information corresponding to the target account set to be updated in the received set information to be updated, to obtain the decrypted update information; and uses the decrypted update information to update the set information of the target account set to be updated.

[0038] Fourthly, this application also provides a device account management system. The system includes: a central server and devices to be managed;

[0039] The device to be managed is used to execute the device account management method described in the first aspect above;

[0040] The central server is used to execute the device account management method described in the second aspect above.

[0041] The aforementioned device account management method and system establish a communication connection with a central server in response to received user-input configuration information. The system sends configuration information to the central server, instructing it to return a set of associated accounts linked to the master account in the configuration information. Then, in response to a user's selection of the associated account set based on the application scenario, the system determines the target account set within the associated account set and retrieves the target account set information from the central server. By directly retrieving the required target account set information from the central server and binding the account data in the retrieved target account set information as trusted accounts, the system automatically completes the binding of the logonable accounts for the currently managed devices. This avoids manual configuration of device accounts, facilitating the deployment of managed devices. When the number of managed devices is large, it simplifies deployment difficulty and improves deployment efficiency. This solves the problems of high deployment and update difficulty and low efficiency in existing device account management methods when the cluster size is large.

[0042] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description

[0043] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0044] Figure 1 A hardware structure block diagram of a terminal for a device account management method provided in an embodiment of this application;

[0045] Figure 2A flowchart of the device account management method provided in Embodiment 1 of this application;

[0046] Figure 3 A schematic diagram illustrating secure communication between a cluster device and a central server according to an embodiment of this application;

[0047] Figure 4 A flowchart of the device account management method provided in Embodiment 2 of this application;

[0048] Figure 5 A flowchart of the device account management method provided in Embodiment 3 of this application;

[0049] Figure 6 This is a structural block diagram of a device account management system provided in an embodiment of this application. Detailed Implementation

[0050] To better understand the purpose, technical solution, and advantages of this application, the application is described and illustrated below in conjunction with the accompanying drawings and embodiments.

[0051] Unless otherwise defined, the technical or scientific terms used in this application shall have the general meaning understood by one of ordinary skill in the art to which this application pertains. Words such as “a,” “an,” “an,” “the,” “the,” and “these” used in this application do not indicate quantitative limitation and may be singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or modules (units) is not limited to the listed steps or modules (units) but may include steps or modules (units) not listed, or may include other steps or modules (units) inherent to these processes, methods, products, or devices. Words such as “connected,” “linked,” and “coupled” used in this application are not limited to physical or mechanical connections but may include electrical connections, whether direct or indirect. “Multiple” used in this application refers to two or more. “And / or” describes the relationship between related objects, indicating that three relationships may exist; for example, “A and / or B” can represent: A alone, A and B simultaneously, and B alone. Normally, the character " / " indicates that the objects before and after it are in an "or" relationship. The terms "first," "second," "third," etc., used in this application are merely to distinguish similar objects and do not represent a specific order of objects.

[0052] The method embodiments provided in this example can be executed on a terminal, computer, or similar computing device. For example, it can run on a terminal. Figure 1This is a hardware structure block diagram of the terminal for the device account management method in this embodiment. For example... Figure 1 As shown, a terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 and a memory 104 for storing data are also included. The processor 102 may be, but is not limited to, a microprocessor (MCU) or a programmable logic device (FPGA). The terminal may also include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that… Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the terminal described above. For example, the terminal may also include components that are larger than... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown are illustrated.

[0053] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the device account management method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0054] The transmission device 106 is used to receive or send data via a network. This network includes a wireless network provided by the terminal's communication provider. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 can be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0055] This embodiment provides a device account management method, which is applied to the devices to be managed in the device account management system. The device account management system also includes a central server, which is equipped with at least one master account. Each master account is associated with at least one account set, and each account set includes at least two accounts. Figure 2 This is a flowchart of the device account management method in Embodiment 1, as follows: Figure 2 As shown, the process includes the following steps:

[0056] Step S210: In response to the received configuration information input by the user, establish a communication connection with the central server and send the configuration information to the central server; the configuration information is used to instruct the central server to return a set of associated accounts related to the master account in the configuration information.

[0057] The aforementioned managed device can be one of the cluster devices that requires account management and is subject to unified account management by a central server. The aforementioned cluster device can be a group of terminal or node devices with independent computing and network communication capabilities, specifically a collection of devices of a certain scale (tens or hundreds) that are similar or related in function, model, or business role. Figure 3 This diagram illustrates secure communication between cluster devices and the central server. (Example) Figure 3 As shown, the central server can communicate with multiple cluster devices. This central server manages metadata related to accounts and permissions, and is responsible for creating, storing, and modifying accounts, distributing them to various managed devices, and providing login access for those devices. The central server can also establish secure communication with the managed devices within the cluster. The master account is an administrator account stored on the central server, used for device registration and policy retrieval. The master account can represent the management permissions of a class or group of managed devices. The master account acts as the "key" for establishing a management connection between the managed device and the central server. That is, the managed device can establish secure communication with the central server using the master account and its password. The account set can be a collection of multiple related accounts. For ease of communication and differentiation, each account set is equipped with a corresponding set ID (Identification). Each account set includes set information, which may include the username, password hash, set ID, and set permissions. The account represents the user identity that allows login and operation on the device. It should be noted that the entire lifecycle of the aforementioned accounts, including creation, modification, and deletion, is controlled by a central server. The devices under management can only read and use the accounts, but cannot modify them. It should also be noted that each account set can be associated with one or more master accounts.

[0058] The aforementioned configuration information can be the information entered by the user when logging into the managed device. This configuration information includes the main account username, main account password, central server IP (Internet Protocol) address, and central server port. The central server IP address is the Internet Protocol address of the central server. The central server port is a logical channel number used to distinguish different network applications or services on the central server's network communication endpoint. Together, the central server IP address and central server port constitute the central server's complete network connection addressing information. That is, by using the central server IP address and central server port entered by the user when logging into the managed device, the managed device can establish a communication connection with the central server. Specifically, in response to the received user-input configuration information, establishing a communication connection with the central server can be achieved by the managed device initiating a network connection request (such as a TCP (Transmission Control Protocol) connection) to the central server based on the central server IP address and central server port in the configuration information. The main account password can be a confidential authentication credential bound to the main account username, granting access to or viewing of the set of accounts associated with the main account.

[0059] Step S220: In response to the received user's selection operation of the associated account set based on the application scenario, determine the target account set in the associated account set, and pull the set information of the target account set from the central server.

[0060] The above application scenario can be the actual application scenario of the device to be managed. The above target account set is the set of accounts selected by the user from multiple associated account sets based on the application scenario. The above response to the received user selection operation on the associated account set based on the application scenario, determining the target account set in the associated account set, and retrieving the set information of the target account set from the central server can be the device to be managed responding to the received user selection operation on the associated account set based on the application scenario, determining the target account set in the associated account set, and retrieving the set information of the target account set from the central server.

[0061] Step S230: Store the set information of the target account set, and bind the account data in the set information of the target account set as a trusted account; a trusted account is an account that can be used to log in to the currently managed device.

[0062] The aforementioned storage of target account set information and binding of account data within this set of information to trusted accounts can be achieved by the managed device storing the target account set information on local non-volatile storage media (such as a hard drive or security chip storage area) and binding the account data within this set of information to trusted accounts. Once the managed device binds the account data within the target account set information to trusted accounts, user operation permissions are no longer statically determined by the device's local configuration file, but are dynamically controlled by a structured permission policy issued from a central server and bound to the accounts. At this point, the managed device needs to complete the corresponding operations according to the permissions granted to each trusted account.

[0063] Steps S210 to S230, in response to received user input configuration information, establish a communication connection with the central server and send configuration information to the central server to instruct it to return a set of associated accounts related to the main account in the configuration information. Then, in response to the user's selection operation of the associated account set based on the application scenario, determine the target account set within the associated account set and retrieve the set information of the target account set from the central server. By directly retrieving the required target account set information from the central server and binding the account data in the retrieved target account set information as trusted accounts, the binding of the logonable accounts of the currently managed devices can be automatically completed, avoiding manual configuration of device accounts and facilitating the deployment of managed devices. When the number of managed devices is large, this simplifies deployment difficulty and improves deployment efficiency. This solves the problems of high deployment and update difficulty and low efficiency in existing device account management methods when the cluster device scale is large.

[0064] In one embodiment, after step S210, the following is included:

[0065] Step S211: Receive the set of associated accounts returned by the central server in response to the main account in the configuration information, and display the set of associated accounts.

[0066] The aforementioned receiving and displaying of the set of associated accounts returned by the central server in response to the main account in the configuration information can enable the managed device to receive the set of associated accounts returned by the central server in response to the main account in the configuration information and display a list of the associated account sets of the main account on the display interface of the managed device, so that users (operators or administrators) can select the account set according to the actual application scenario.

[0067] Specifically, in one embodiment, after step S220, the method further includes:

[0068] Step S221: Receive the symmetric key generated by the central server in response to the set information of the target account set; the symmetric key is used to decrypt the update information received from the central server when updating the set information of the target account set.

[0069] The aforementioned symmetric key can be a persistent symmetric key. This symmetric key is bound to the set ID of the target account set. When the managed device needs to update the set information of the target account set, it determines the corresponding symmetric key based on the received set ID and decrypts the update information corresponding to the set ID.

[0070] In one embodiment, updating the set information of the target account set includes:

[0071] Step S1: In response to the received set information to be updated broadcast from the central server, determine the target account set to be updated and the update information corresponding to the target account set to be updated; the target account set to be updated is the set of accounts in the target account set whose set information needs to be updated.

[0072] The aforementioned set of information to be updated can be the information determined by the central server based on the user's account modification instructions. This information includes the set of accounts to be updated and the corresponding update information for that set. When one or more accounts need information updates (e.g., adding an account, updating a password, modifying a note, modifying permissions, deleting an account, restricting IP addresses for account login, allowing login time for an account, automatic logout time for an account, etc.), the user logs into the central server to modify these accounts, generating an account modification instruction. Based on the user's account modification instruction, the central server automatically detects and determines the set of accounts to which the modified account belongs, and updates the account information in the set of accounts to which the modified account belongs based on the account modification instruction. The aforementioned response to the received update information broadcast from the central server, determining the target account set to be updated and the update information corresponding to the target account set, can be achieved by the managed device automatically detecting whether the set ID of the target account set matches the set ID of account set D in the update information. When the set ID of the target account set matches the set ID of the account set in the update information, the account set corresponding to the matching set ID is determined as the target account set to be updated, and then the update information corresponding to the target account set to be updated is determined.

[0073] Step S2: Using the symmetric key, decrypt the update information corresponding to the target account set to be updated to obtain the decrypted update information.

[0074] Once the central server determines the set information of the target account set, it generates a symmetric key corresponding to the set information and sends the symmetric key to the managed device. When the managed device needs to update the set information of the target account set, it can determine the symmetric key based on the set ID of the target account set to be updated. Then, it uses the symmetric key to decrypt the update information corresponding to the target account set to be updated, obtaining the decrypted update information. In other words, this application, by configuring a unified key for the target account set, allows for the reading and updating of the set information of the target account set using the key.

[0075] Step S3: Use the decrypted update information to update the set information of the target account set to be updated.

[0076] The above-mentioned use of decrypted update information to update the set information of the target account set to be updated can be achieved by the device to be managed using the decrypted update information to update the set information of the target account set to be updated.

[0077] For example, if account 4 in account set 3 needs to be deleted, the central server will broadcast the information that account 4 in account set 3 needs to be deleted. When account set 3 is the target account set, after receiving the broadcast information from the central server, the device to be managed will determine account set 3 as the target account set to be updated, and use the symmetric key to decrypt the information that account 4 needs to be deleted, obtain the decrypted account 4 needs to be deleted, and delete account 4 in account set 3 stored in the device to be managed.

[0078] Steps S1 to S3 above involve the managed device responding to the updated set information broadcast from the central server, determining the target account set to be updated and the corresponding update information, and using a symmetric key to decrypt the update information corresponding to the target account set to be updated, obtaining the decrypted update information. The decrypted update information is then used to update the set information of the target account set to be updated. This process, where the managed device receives the updated set information broadcast from the central server and performs automatic matching and updating, simplifies the update process, solves the problem of complex account update processes in existing technologies, and ensures the security of account updates through the use of a symmetric key.

[0079] This second embodiment provides a device account management method, which is applied to the central server of the device account management system. The device account management system also includes devices to be managed. The central server is equipped with at least one master account, each master account is associated with at least one account set, and each account set includes at least two accounts. Figure 4 This is a flowchart of the device account management method in Embodiment 2, as follows: Figure 4 As shown, the process includes the following steps:

[0080] Step S410: In response to receiving configuration information from the device to be managed, determine the set of associated accounts associated with the master account in the configuration information, and send the set of associated accounts to the device to be managed; the configuration information is the configuration information input by the user received by the device to be managed.

[0081] In this process, the modern management device, in response to the configuration information received from the user input, establishes a communication connection with the central server and sends the configuration information to the central server. In response to the configuration information received from the device to be managed, the central server determines the set of associated accounts related to the main account in the configuration information based on the account name of the main account in the configuration information, and sends the set of associated accounts to the device to be managed.

[0082] Step S420: In response to receiving the target account set from the device to be managed, determine the set information of the target account set; the target account set is the set of accounts determined by the device to be managed from the associated account set based on the user's selection operation of the associated account set based on the application scenario; the set information is used to provide the device to be managed with accounts that can be used to log in to the current device to be managed.

[0083] In this step, the device under management determines the target account set from the associated account set based on the user's selection operation based on the application scenario, and sends the target account set to the central server. The central server responds by receiving the target account set from the device under management, determines the set information of the target account set, and sends it to the device under management, so that the device under management can bind the account data in the set information of the target account set as a trusted account.

[0084] Steps S410 to S420 above, in response to receiving configuration information from the device under management, determine the set of associated accounts related to the master account in the configuration information, and send the set of associated accounts to the device under management. The device under management then selects the target account set from the associated account set based on the received user selection operation based on the application scenario. Furthermore, in response to receiving the target account set from the device under management, it determines the set information of the target account set, allowing the device under management to bind the account data in the set information of the target account set as a trusted account. This achieves automatic binding of the currently managed device's logonable accounts by sending the set information of the target account set that can be used for binding to the device under management via a central server, avoiding manual configuration of device accounts, facilitating the deployment of the managed devices, simplifying deployment difficulty and improving deployment efficiency when the number of managed devices is large. It solves the problems of high deployment and update difficulty and low efficiency in existing device account management methods when the cluster size is large.

[0085] Additionally, in one embodiment, after step S420, the method further includes:

[0086] Step S430: Generate a symmetric key corresponding to the set information of the target account set, and send the symmetric key to the device to be managed; the symmetric key is used to decrypt the updated information when updating the set information of the target account set.

[0087] The symmetric key corresponding to the set information of the target account set mentioned above can be generated by the central server for each target account set (the set of accounts to be distributed to devices or updated). This symmetric key is used to encrypt the complete data of the account set, ensuring confidentiality and isolation between sets during data transmission and storage. The symmetric key corresponding to the set information of the target account set can be generated by the central server according to a preset key generation method. This preset key generation method can be one or more of the following: cryptographic random number generation method, key derivation function method, etc. Furthermore, the preset key generation method can be specifically set based on specific needs and application scenarios; this embodiment does not impose specific limitations on it.

[0088] Furthermore, in one embodiment, updating the set information of the target account set further includes:

[0089] Step S4: In response to the received user account modification instruction, determine the set of accounts to be updated corresponding to the account modification instruction and the update information corresponding to the set of accounts to be updated.

[0090] The aforementioned response to a received user account modification instruction, determining the set of accounts to be updated corresponding to the account modification instruction and the update information corresponding to the set of accounts to be updated, can be achieved by the central server responding to the received user account modification instruction, determining the set of accounts corresponding to the user account modification instruction, i.e., determining the set of accounts to be updated, and determining the update information corresponding to the set of accounts to be updated.

[0091] Step S5: Using the update information corresponding to the set of accounts to be updated, update the set information of the set of accounts to be updated, and encrypt the set of accounts to be updated and the update information corresponding to the set of accounts to be updated to obtain the set information to be updated; broadcast the set information to be updated.

[0092] In this embodiment, the central server uses the update information corresponding to the set of accounts to be updated to update the set information of the set of accounts to be updated, and saves the updated set information of the set of accounts. The encryption of the set of accounts to be updated and its corresponding update information is to ensure the security of transmitting and broadcasting the set of accounts to be updated and its corresponding update information. Specifically, it can be that only the update information corresponding to the set of accounts to be updated is encrypted, or that both the set of accounts to be updated and its corresponding update information are encrypted to obtain the set information to be updated. The set information to be updated can be displayed in the form of a list of set IDs of the set of accounts to be updated. The broadcasting of the set information to be updated can be done by broadcasting the set IDs of the set of accounts to be updated. When a managed device receives the set information to be updated broadcast from the central server, it directly obtains the set ID of the account set to be updated. Then, based on the set ID of the account set to be updated, it determines whether there is a set ID with the same set ID among the managed devices. If there is a set ID with the same set ID, the account set corresponding to the same set ID is determined as the account set to be updated. Based on the symmetric key corresponding to the set ID, the encrypted account set to be updated and the update information corresponding to the account set to be updated are decrypted. Then, the set information of the account set to be updated is updated using the decrypted information.

[0093] In steps S4 to S5 above, in response to the received user account modification instruction, the set of accounts to be updated and the update information corresponding to the set of accounts to be updated are determined. Then, the set information of the set of accounts to be updated is updated using the update information corresponding to the set of accounts to be updated. The set of accounts to be updated and the update information corresponding to the set of accounts to be updated are encrypted to obtain the set information to be updated. The central server determines the set information to be updated and broadcasts the set information to be updated so that the managed device can determine the target set of accounts to be updated based on the received broadcast content and update the set information of the target set of accounts to be updated.

[0094] This embodiment provides a device account management method, which is applied to a device account management system. The device account management system includes a central server and devices to be managed. The central server is equipped with at least one master account, each master account is associated with at least one account set, and each account set includes at least two accounts. Figure 5 This is a flowchart of the device account management method in Embodiment 3, as follows: Figure 5 As shown, the process includes the following steps:

[0095] In step S510, the device to be managed, in response to the configuration information input by the user, establishes a communication connection with the central server and sends the configuration information to the central server.

[0096] In step S520, the central server, in response to receiving configuration information from the device to be managed, determines the set of associated accounts related to the master account in the configuration information and sends the set of associated accounts to the device to be managed.

[0097] Step S530: The device to be managed receives the set of associated accounts returned by the central server in response to the main account in the configuration information, and displays the set of associated accounts.

[0098] In step S540, the device to be managed, in response to the received user's selection operation of the associated account set based on the application scenario, determines the target account set in the associated account set.

[0099] Step S550: The central server, in response to receiving a set of target accounts from the device to be managed, determines the set information of the target account set; the set information is used to provide the device to be managed with accounts that can be used to log in to the current device to be managed.

[0100] Step S560: The device to be managed retrieves the set information of the target account set from the central server; stores the set information of the target account set, and binds the account data in the set information of the target account set as a trusted account; the trusted account is an account that can be used to log in to the current device to be managed.

[0101] In steps S510 to S560 above, the device under management, in response to the configuration information input by the user, establishes a communication connection with the central server and sends the configuration information to the central server. The central server, in response to receiving the configuration information from the device under management, determines the set of associated accounts related to the main account in the configuration information and sends the set of associated accounts to the device under management. Then, the device under management, in response to the user's selection operation of the set of associated accounts based on the application scenario, determines the target account set within the set of associated accounts and retrieves the set information of the target account set from the central server. By directly retrieving the required set information of the target account set from the central server, the device binds the account data in the retrieved set information of the target account set as trusted accounts, thus automatically completing the binding of the logonable accounts of the current device under management. This avoids manual configuration of device accounts, facilitating the deployment of the device under management. When the number of devices under management is large, it simplifies the deployment difficulty and improves deployment efficiency. This solves the problems of high deployment and update difficulty and low efficiency in existing device account management methods when the cluster device scale is large.

[0102] In one embodiment, the above device account management method further includes:

[0103] Step S570: The central server generates a symmetric key corresponding to the set information of the target account set and sends the symmetric key to the device to be managed; the symmetric key is used to decrypt the updated information when updating the set information of the target account set.

[0104] Step S571: The device to be managed receives the symmetric key generated by the central server in response to the set information of the target account set;

[0105] Step S572: The central server, in response to the received user account modification instruction, determines the set of accounts to be updated and the update information corresponding to the set of accounts to be updated; uses the update information corresponding to the set of accounts to be updated to update the set information of the set of accounts to be updated, and encrypts the set of accounts to be updated and the update information corresponding to the set of accounts to be updated to obtain the set information to be updated; and broadcasts the set information to be updated.

[0106] Step S573: The device to be managed receives the set information to be updated broadcast by the central server, and uses the symmetric key to decrypt the update information corresponding to the target account set to be updated in the received set information to be updated, to obtain the decrypted update information; and uses the decrypted update information to update the set information of the target account set to be updated.

[0107] In steps S570 to S573 above, the central server generates a symmetric key corresponding to the set information of the target account set and sends the symmetric key to the device to be managed. Then, in response to the received user account modification instruction, the central server determines the set of accounts to be updated and the corresponding update information. It encrypts the set of accounts to be updated and the corresponding update information to obtain the set information to be updated. This updated set information is then broadcast through the central server so that the device to be managed can receive the broadcasted updated set information and use the symmetric key to decrypt the update information corresponding to the target account set in the received updated set information, obtaining the decrypted update information. The decrypted update information is then used to update the set information of the target account set. This method of updating set information by receiving content from the central server through the device to be managed is convenient, avoids manual configuration of device accounts, and improves update efficiency. It solves the problem of high difficulty and low efficiency in existing device account management methods when the cluster of devices is large.

[0108] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0109] Based on the same inventive concept, this embodiment also provides a device account management system for implementing the above embodiments and preferred embodiments, which will not be repeated hereafter. The terms "module," "unit," "subunit," etc., used below refer to combinations of software and / or hardware that perform a predetermined function. Although the apparatus described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0110] In one embodiment, Figure 6 This is a structural block diagram of a device account management system provided in an embodiment of this application, as shown below. Figure 6 As shown, the device account management system includes: a central server 610 and a device to be managed 620; the device to be managed 620 is used to execute any one of the device account management methods in Embodiment 1 above; the central server 610 is used to execute any one of the device account management methods in Embodiment 2 above.

[0111] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0112] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0113] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for managing device accounts, characterized in that, The device to be managed is applied to a device account management system, which further includes a central server. The central server is equipped with at least one master account, each master account is associated with at least one account set, and each account set includes at least two accounts. The method includes: In response to the received configuration information input by the user, a communication connection is established with the central server, and the configuration information is sent to the central server; the configuration information is used to instruct the central server to return a set of associated accounts associated with the main account in the configuration information; In response to the received user selection operation of the associated account set based on the application scenario, the target account set in the associated account set is determined, and the set information of the target account set is retrieved from the central server; Store the set information of the target account set, and bind the account data in the set information of the target account set as a trusted account; the trusted account is an account that can be used to log in to the currently managed device.

2. The device account management method according to claim 1, characterized in that, After establishing a communication connection with the central server in response to received user input configuration information and sending the configuration information to the central server, the process includes: The system receives the set of associated accounts returned by the central server in response to the main account in the configuration information, and displays the set of associated accounts.

3. The device account management method according to claim 1, characterized in that, After responding to the received user selection operation based on the application scenario of the associated account set, determining the target account set in the associated account set, and retrieving the set information of the target account set from the central server, the method further includes: The central server receives a symmetric key generated in response to the set information of the target account set; the symmetric key is used to decrypt the update information received from the central server when updating the set information of the target account set.

4. The device account management method according to claim 3, characterized in that, The step of updating the set information of the target account set includes: In response to the received set information to be updated broadcast from the central server, the target account set to be updated and the update information corresponding to the target account set to be updated are determined; the target account set to be updated is the set of accounts in the target account set whose set information needs to be updated. Using the symmetric key, the update information corresponding to the target account set to be updated is decrypted to obtain the decrypted update information; The set information of the target account set to be updated is updated using the decrypted update information.

5. A method for managing device accounts, characterized in that, A central server is used in a device account management system, the device account management system further including devices to be managed, the central server is equipped with at least one master account, each master account is associated with at least one account set, and each account set includes at least two accounts, the method comprising: In response to receiving configuration information from the device under management, a set of associated accounts associated with the main account in the configuration information is determined, and the set of associated accounts is sent to the device under management; the configuration information is the configuration information input by the user received by the device under management. In response to receiving a target account set from the device to be managed, the set information of the target account set is determined; the target account set is the set of accounts determined by the device to be managed from the associated account set based on the user's selection operation of the associated account set based on the application scenario; the set information is used to provide the device to be managed with accounts that can be used to log in to the current device to be managed.

6. The device account management method according to claim 5, characterized in that, After determining the set information of the target account set in response to receiving the target account set from the device to be managed, the method further includes: Generate a symmetric key corresponding to the set information of the target account set, and send the symmetric key to the device to be managed; the symmetric key is used to decrypt the updated information when the set information of the target account set is updated.

7. The device account management method according to claim 6, characterized in that, The step of updating the set information of the target account set includes: In response to a received user account modification instruction, determine the set of accounts to be updated corresponding to the account modification instruction and the update information corresponding to the set of accounts to be updated; Using the update information corresponding to the set of accounts to be updated, the set information of the set of accounts to be updated is updated, and the set of accounts to be updated and the update information corresponding to the set of accounts to be updated are encrypted to obtain the set information to be updated; the set information to be updated is then broadcast.

8. A method for managing device accounts, characterized in that, An application is made to a device account management system, the device account management system including a central server and devices to be managed, the central server being equipped with at least one master account, each master account being associated with at least one account set, and each account set including at least two accounts, the method comprising: The device under management, in response to the configuration information input by the user, establishes a communication connection with the central server and sends the configuration information to the central server; In response to receiving configuration information from the device to be managed, the central server determines a set of associated accounts related to the master account in the configuration information and sends the set of associated accounts to the device to be managed. The device to be managed receives a set of associated accounts related to the main account returned by the central server in response to the main account in the configuration information, and displays the set of associated accounts. The device to be managed, in response to the received user selection operation of the associated account set based on the application scenario, determines the target account set in the associated account set; The central server, in response to receiving the target account set from the device under management, determines the set information of the target account set; the set information is used to provide the device under management with accounts that can be used to log in to the current device under management; The device to be managed retrieves the set information of the target account set from the central server; stores the set information of the target account set, and binds the account data in the set information of the target account set as a trusted account; the trusted account is an account that can be used to log in to the current device to be managed.

9. The device account management method according to claim 8, characterized in that, The method further includes: The central server generates a symmetric key corresponding to the set information of the target account set and sends the symmetric key to the device to be managed; the symmetric key is used to decrypt the updated information when the set information of the target account set is updated. The device to be managed receives the symmetric key generated by the central server in response to the set information of the target account set; The central server, in response to a received user account modification instruction, determines the set of accounts to be updated corresponding to the account modification instruction and the update information corresponding to the set of accounts to be updated; uses the update information corresponding to the set of accounts to be updated to update the set information of the set of accounts to be updated, and encrypts the set of accounts to be updated and the update information corresponding to the set of accounts to be updated to obtain the set information to be updated; and broadcasts the set information to be updated. The device to be managed receives the set information to be updated broadcast by the central server, and uses the symmetric key to decrypt the update information corresponding to the target account set to be updated in the received set information to be updated, to obtain the decrypted update information; and uses the decrypted update information to update the set information of the target account set to be updated.

10. A device account management system, characterized in that, The system includes: a central server and devices to be managed; The device to be managed is used to execute the device account management method according to any one of claims 1 to 4; The central server is used to execute the device account management method according to any one of claims 5 to 7.

Citation Information

Patent Citations

  • Mapping account information to server authentication

    CN106716428A

  • Account management method and related product

    CN112464204A