Operation authority management method, system and device and electronic equipment
By enabling a locking mode for network devices and combining it with time-window management of user permissions, the problem of fixed operation permissions in existing technologies is solved, enabling flexible and granular permission management and improving security and management efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2026-03-27
AI Technical Summary
In existing technologies, the operation permission management methods of network devices have been fixed for a long time, resulting in insufficient flexibility and an inability to adapt to the needs of user permission changes.
By enabling a lockout mode for network devices and combining key operation commands with time windows to manage user permissions, authorized operation commands can be executed within a specific time period, enabling flexible and granular permission management.
It improves the access security and flexibility of network devices, enabling more granular access control by adjusting time windows and authorization information as needed.
Smart Images

Figure CN121750249A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technology, and in particular to an operation permission management method, system, device and electronic device. Background Technology
[0002] With the development of network communication technology, network devices such as routers and switches have become more complex in their functions. Consequently, managing access permissions for network devices has become increasingly important for security reasons.
[0003] In related technologies, user access permissions to network devices are typically managed based on user roles or attributes. For example, when a network device receives an instruction corresponding to an operation performed by a user, it executes or denies the operation performed by the user based on the user's role information or attribute information and the corresponding access permissions.
[0004] However, under the above management method, the user's role or attributes are generally fixed for a long time. As a result, once the user's permissions are set, they will remain fixed for a long time, causing the problem of insufficient flexibility in operation permission management. Summary of the Invention
[0005] To address the aforementioned technical problems, this application provides an operation permission management method, system, device, and electronic device. In this operation permission management method, the network device manages user operation permissions more flexibly and precisely based on key operation commands and time windows.
[0006] In a first aspect, this application provides an operation permission management method applied to a network device. The method includes: enabling a lockout mode, wherein the lockout mode is used to instruct the network device to refuse to execute critical operation instructions and set target user information; executing an authorized operation instruction for a first user indicated by the target user information, wherein the authorized operation instruction is used to set authorization information, wherein the authorization information includes authorized user information and a time window corresponding to the authorized user information; and if a first critical operation instruction for a second user is received, wherein the first critical operation instruction is executed if the user information of the second user matches the authorized user information and the current time belongs to the time window.
[0007] This application embodiment enables a lock mode based on critical operation commands for network devices, restricting users from performing critical operations on the network devices, thereby ensuring the network device's access security requirements. Based on this, the network device authorizes users to perform critical operations based on the target user's authorized actions, combined with a time window. Thus, when it is necessary to change a user's operation permissions, this can be achieved by adjusting the time window, the critical operation commands, and the authorization information, thereby realizing more granular and flexible operation permission management for network devices.
[0008] According to the first aspect, the key operation instructions include one of the following operation instructions:
[0009] Operation instructions whose attributes satisfy preset attributes, operation instructions whose content matches preset content, and operation instructions whose attributes satisfy preset attributes and whose content matches preset content.
[0010] In this application embodiment, key operation instructions are determined by the attributes of operation instructions, thereby enabling batch processing and improving management efficiency; key operation instructions are determined by content matching, thereby enabling fine-grained setting of key operation instructions and further improving management flexibility; or, based on determining candidate operation instructions by the attributes of operation instructions, key operation instructions are determined from the candidate operation instructions by content matching, thereby balancing management efficiency and flexibility.
[0011] According to the first aspect, or any implementation of the first aspect above, the authorization information further includes preset operation instructions, the preset operation instructions including one or more of the key operation instructions; after executing the authorization operation instruction of the first user indicated by the target user information, the method further includes: if a second key operation instruction of the second user is received, then if the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time belongs to the time window, the second key operation instruction is executed.
[0012] In this embodiment of the application, the authorization information also includes one or more key operation instructions. In this way, the authorization of key operation instructions can achieve further refined management of user operations. Compared with directly authorizing all key operations, it can further improve access security and management flexibility.
[0013] According to the first aspect, or any implementation of the first aspect above, the first user and the second user send operation instructions to the network device through a client; after the lock mode is enabled, the method further includes: sending a notification corresponding to the user's operation instruction to the client; wherein, the user's operation instruction includes one or more of the following operation instructions: the lock mode enabling instruction, the first user's authorization operation instruction, and the second user's key operation instruction; the notification corresponding to the user's operation instruction is used to indicate whether the user's operation instruction was successfully executed, and the second user's key operation instruction includes the first key operation instruction or the second key operation instruction.
[0014] This application embodiment provides feedback on whether an operation was successful, thereby improving the controllability and visualization of operation management and further enhancing the flexibility of operation permission management. Specifically, when the user activates the lock mode, the operation can include activating the lock mode.
[0015] According to the first aspect, or any implementation of the first aspect above, the instructions of the key operation instructions and the authorized operation instructions include one of the following forms: command line CLI form, YANG form, and MIB form.
[0016] In this embodiment, the operation instructions are in the form of command line CLI, YANG, or MIB, thus making them suitable for diverse network operating systems and management protocols, and further improving the flexibility of operation permission management.
[0017] Secondly, this application provides an operation permission management method applied to a client. The method includes: sending an authorization operation instruction from a first user to a network device in a locked mode, wherein the locked mode is used to instruct the network device to refuse to execute a key operation instruction and to set target user information for the first user; the authorization operation instruction is used to set authorization information in the network device, wherein the authorization information includes authorized user information and a time window corresponding to the authorized user information; and sending a first key operation instruction from a second user to the network device, wherein the first key operation instruction is used to instruct the network device to execute the first key operation instruction when the user information of the second user matches the authorized user information and the current time belongs to the time window.
[0018] According to the second aspect, the key operation instructions include one of the following operation instructions:
[0019] Operation instructions whose attributes satisfy preset attributes, operation instructions whose content matches preset content, and operation instructions whose attributes satisfy preset attributes and whose content matches preset content.
[0020] According to the second aspect, or any implementation of the second aspect above, the authorization information further includes preset operation instructions, the preset operation instructions including one or more of the key operation instructions; after executing the authorization operation instruction of the first user indicated by the target user information, the method further includes: sending a second key operation instruction of the second user to the network device, the second key operation instruction being used to instruct the network device to execute the second key operation instruction when the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time belongs to the time window.
[0021] According to the second aspect, or any implementation of the second aspect above, after sending the user's operation instruction, the method further includes: receiving a notification from the network device indicating whether the user's operation instruction was successfully executed; and outputting the notification; wherein the user's operation instruction includes one or more of the following operation instructions: a lock mode enabling instruction sent to a network device that has not enabled lock mode, an authorization operation instruction of the first user, and a key operation instruction of the second user, wherein the key operation instruction of the second user includes the first key operation instruction or the second key operation instruction.
[0022] According to the second aspect, or any implementation of the second aspect above, the instructions of the key operation instructions and the authorized operation instructions include one of the following forms: command line CLI form, YANG form, and MIB form.
[0023] The second aspect and any implementation thereof correspond to the first aspect and any implementation thereof, respectively. The technical effects of the second aspect and any implementation thereof are similar to those of the first aspect and any implementation thereof, and will not be repeated here.
[0024] Thirdly, embodiments of this application provide an operation permission management system, which includes a network device and a client; the network device is configured to enable a lock mode, the lock mode being used to instruct the network device to refuse to execute critical operation instructions and to set target user information; the client is configured to send an authorization operation instruction for a first user indicated by the target user information to the network device, the authorization operation instruction being used to set authorization information in the network device, the authorization information including authorized user information and a time window corresponding to the authorized user information; the network device is configured to execute the authorization operation instruction of the first user; the client is configured to send a first critical operation instruction for a second user to the network device; the network device is configured to execute the first critical operation instruction when the user information of the second user matches the authorized user information and the current time belongs to the time window.
[0025] According to the third aspect, the key operation instructions include one of the following operation instructions: an operation instruction whose attributes satisfy a preset attribute, an operation instruction whose instruction content matches a preset content, and an operation instruction whose attributes satisfy a preset attribute and whose instruction content matches a preset content.
[0026] According to the third aspect, or any implementation of the third aspect above, the authorization information further includes preset operation instructions, which include one or more of the key operation instructions; the client is further configured to send the second key operation instruction of the second user to the network device; the network device is further configured to execute the second key operation instruction when the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time belongs to the time window.
[0027] According to the third aspect, or any implementation of the third aspect above, the network device is further configured to: after receiving the user's operation instruction sent by the client, send a notification to the client indicating whether the user's operation instruction was successfully executed; the client is further configured to receive the notification and output the notification; wherein, the user's operation instruction includes one or more of the following operation instructions: a lock mode enabling instruction sent by the client to the network device that has not enabled the lock mode, an authorization operation instruction of the first user, and a key operation instruction of the second user, wherein the key operation instruction of the second user includes the first key operation instruction or the second key operation instruction.
[0028] According to the third aspect, or any implementation of the third aspect above, the instructions of the key operation instructions and the authorized operation instructions include one of the following forms: command line CLI form, YANG form, and MIB form.
[0029] The third aspect and any implementation thereof correspond to the first aspect and any implementation thereof, respectively. The technical effects of the third aspect and any implementation thereof are similar to those of the first aspect and any implementation thereof, and will not be repeated here.
[0030] Fourthly, this application provides an operation permission management device applied to a network device. The device includes: a mode activation module for activating a lock mode, wherein the lock mode is used to instruct the network device to refuse to execute critical operation instructions and set target user information; an authorization setting module for executing an authorization operation instruction for a first user indicated by the target user information, wherein the authorization operation instruction is used to set authorization information, the authorization information including authorized user information and a time window corresponding to the authorized user information; and an operation management module for executing the first critical operation instruction if a first critical operation instruction from a second user is received, provided that the user information of the second user matches the authorized user information and the current time belongs to the time window.
[0031] According to the fourth aspect, the key operation instructions include one of the following operation instructions: an operation instruction whose attributes satisfy a preset attribute, an operation instruction whose instruction content matches a preset content, and an operation instruction whose attributes satisfy a preset attribute and whose instruction content matches a preset content.
[0032] According to the fourth aspect, or any implementation of the fourth aspect above, the authorization information further includes preset operation instructions, which include one or more of the key operation instructions; the operation management module is further configured to: if a second key operation instruction from the second user is received, and the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time belongs to the time window, execute the second key operation instruction.
[0033] According to the fourth aspect, or any implementation of the fourth aspect above, the first user and the second user send operation instructions to the network device through a client; the device further includes an operation feedback module, used to: provide feedback to the client to a notification corresponding to the user's operation instruction; wherein, the user's operation instruction includes one or more of the following operation instructions: the lock mode activation instruction, the first user's authorization operation instruction, and the second user's key operation instruction; the notification corresponding to the user's operation instruction is used to indicate whether the user's operation instruction was successfully executed, and the second user's key operation instruction includes the first key operation instruction or the second key operation instruction.
[0034] According to the fourth aspect, or any implementation of the fourth aspect above, the instructions of the key operation instructions and the authorized operation instructions include one of the following forms: command line CLI form, YANG form, and MIB form.
[0035] The fourth aspect and any implementation thereof correspond to the first aspect and any implementation thereof, respectively. The technical effects of the fourth aspect and any implementation thereof are similar to those of the first aspect and any implementation thereof, and will not be repeated here.
[0036] Fifthly, this application provides an operation permission management device applied to a client. The device includes: an authorization setting module, configured to send an authorization operation instruction from a first user to a network device in a locked mode, wherein the locked mode instructs the network device to refuse to execute a key operation instruction and to set target user information for the first user; the authorization operation instruction is configured to set authorization information in the network device, the authorization information including authorized user information and a time window corresponding to the authorized user information; and a device operation module, configured to send a first key operation instruction from a second user to the network device, wherein the first key operation instruction instructs the network device to execute the first key operation instruction when the second user's user information matches the authorized user information and the current time falls within the time window.
[0037] According to the fifth aspect, the key operation instructions include one of the following operation instructions: an operation instruction whose attributes satisfy a preset attribute, an operation instruction whose instruction content matches a preset content, and an operation instruction whose attributes satisfy a preset attribute and whose instruction content matches a preset content.
[0038] According to the fifth aspect, or any implementation of the fifth aspect above, the authorization information further includes preset operation instructions, the preset operation instructions including one or more of the key operation instructions; the device operation module is further configured to: send a second key operation instruction of the second user to the network device, the second key operation instruction being used to instruct the network device to execute the second key operation instruction when the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time belongs to the time window.
[0039] According to the fifth aspect, or any implementation of the fifth aspect above, the device further includes an operation response module, configured to: receive a notification from the network device indicating whether the user's operation instruction has been successfully executed; and output the notification; wherein the user's operation instruction includes one or more of the following operation instructions: a lock mode enabling instruction sent to a network device that has not enabled the lock mode, an authorization operation instruction of the first user, and a key operation instruction of the second user, wherein the key operation instruction of the second user includes the first key operation instruction or the second key operation instruction.
[0040] According to the fifth aspect, or any implementation of the fifth aspect above, the instructions of the key operation instructions and the authorized operation instructions include one of the following forms: command line CLI form, YANG form, and MIB form.
[0041] The fifth aspect and any implementation thereof correspond to the second aspect and any implementation thereof, respectively. The technical effects of the fifth aspect and any implementation thereof are similar to those of the second aspect and any implementation thereof, and will not be repeated here.
[0042] In a sixth aspect, embodiments of this application provide an electronic device, including: a processor and a memory; the processor and the memory are connected; the memory is used to store one or more programs; when one or more programs are executed by one or more processors, the one or more processors implement the method as described in the first aspect and any implementation thereof.
[0043] In a seventh aspect, embodiments of this application provide a computer-readable medium for storing a computer program, the computer program including instructions for performing the method in the first aspect or any possible implementation thereof.
[0044] Eighthly, embodiments of this application provide a computer program including instructions for performing the method in the first aspect or any possible implementation thereof.
[0045] Ninthly, embodiments of this application provide a chip including a processing circuit and transceiver pins. The transceiver pins and the processing circuit communicate with each other via an internal connection path. The processing circuit executes the method in the first aspect or any possible implementation of the first aspect to control the receiving pin to receive signals and to control the transmitting pin to transmit signals. Attached Figure Description
[0046] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0047] Figure 1 This is an example diagram illustrating an application scenario of an operation permission management method provided in an embodiment of this application;
[0048] Figure 2 This is a structural block diagram of a network device provided in an embodiment of this application;
[0049] Figure 3 This is one of the flowcharts illustrating an operation permission management method provided in an embodiment of this application;
[0050] Figure 4This is one of the flowcharts illustrating an operation permission management method provided in an embodiment of this application;
[0051] Figure 5 This is a structural block diagram of an operation permission management system provided in an embodiment of this application;
[0052] Figure 6 This is one of the structural block diagrams of an operation permission management device provided in the embodiments of this application;
[0053] Figure 7 This is one of the structural block diagrams of an operation permission management device provided in the embodiments of this application;
[0054] Figure 8 This is a structural block diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0055] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0056] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0057] The terms "first" and "second," etc., used in the specification and claims of this application are used to distinguish different objects, not to describe a specific order of objects. For example, "first target object" and "second target object," etc., are used to distinguish different target objects, not to describe a specific order of target objects.
[0058] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0059] In the embodiments of this application
[0060] In the description, unless otherwise stated, "multiple" means two or more. For example, multiple processing units means two or more processing units; multiple systems means two or more systems.
[0061] To facilitate understanding of this embodiment, some technical terms and background technologies involved in this embodiment will be introduced first:
[0062] Network Operating System: A software program that can replace an operating system; it is the heart and soul of a network, and a special operating system that provides services to networked computers. Command-line Interface (CLI): The command line is a way for users to interact with a computer provided by the operating system.
[0063] YANG: A data modeling language used for operations based on network configuration management protocols (such as NETCONF / RESTCONF), including configuration, status data, remote procedure calls, and notifications. YANG operations are essentially configuring the network operating system using YANG.
[0064] MIB: A language used for the MIB Browser. MIB Browser: A network management tool used to monitor and manage network devices such as routers and switches. By using the MIB Browser, administrators can quickly understand the operating status and performance metrics of devices, and perform troubleshooting and optimization adjustments.
[0065] AAA (authentication, authorization, and accounting): An abbreviation for authentication and authorization response. It is a network communication protocol mainly used to provide authentication and authorization functions.
[0066] Configuration Manager (CFG): A framework for managing network operating system configurations.
[0067] Versatile Routing Platform (VRP): A universal network operating system for a full range of data communication products, including routers and switches, from low-end to high-end. VRP can run on various hardware platforms and has a consistent network interface, user interface, and management interface, providing users with flexible and rich application solutions.
[0068] In related technologies, access control in network operating systems typically relies on user roles or attributes to achieve access isolation and control for services. However, for network operating systems using this type of access control, once roles and permissions are determined, they cannot be flexibly changed. Furthermore, for some dangerous operations in network operating systems, such as powering off a single board, users often want to control their operational permissions. For example, the reliability of commonly used dangerous operations can be ensured through secondary authentication by maintenance personnel. However, due to the varying skill levels of maintenance personnel at different levels, relying solely on secondary authentication cannot guarantee the correctness of their operations. Therefore, an operational access control scheme that balances security, granularity, and flexibility is needed.
[0069] This application provides an operation permission management method to solve the above-mentioned problems. This method restricts users from performing critical operations on network devices by enabling a locking mode based on critical operation instructions, thereby ensuring the security of network device access. Furthermore, the network device authorizes users to perform critical operations based on the target user's authorized actions and a time window. Thus, when it is necessary to change a user's operation permissions, this can be achieved by adjusting the time window, the critical operation instructions, and the authorization information, resulting in more granular and flexible operation permission management for network devices.
[0070] Before describing the technical solutions of the embodiments of this application, the application scenarios of the embodiments of this application will first be described with reference to the accompanying drawings. For example, Figure 1 This is an example diagram illustrating an application scenario of an operation permission management method provided in an embodiment of this application. For example... Figure 1 As shown, this operation permission management method can be applied to network devices such as routing devices and switches (not shown in the figure), or it can be applied to clients such as terminal tools for managing network devices, network management devices, or operation permission management systems formed by network devices and clients. Specifically, the client can be... Figure 1 The electronic devices shown include computers, mobile terminals, servers, etc., or specifically, client software installed on these electronic devices to manage devices on the network. Specifically:
[0071] Network devices are used to enable lockout mode, which instructs network devices to refuse to execute critical operation commands and set target user information.
[0072] The client is used to send the authorization operation instruction of the first user indicated by the target user information to the network device. The authorization operation instruction is used to set authorization information in the network device. The authorization information includes the authorized user information and the time window corresponding to the authorized user information.
[0073] Network devices are used to execute authorized operation instructions from the first user;
[0074] The client is used to send the second user's first key operation command to the network device;
[0075] The network device is used to execute the first critical operation instruction when the user information of the second user matches the authorized user information and the current time falls within the time window.
[0076] For ease of understanding and logical layout, the following will be combined with... Figure 1 , Figure 3 and Figure 4 The embodiment provides a detailed explanation of the implementation process of the operation permission management method in this scenario.
[0077] For example, Figure 2 This is a structural block diagram of a network device provided in an embodiment of this application. For example... Figure 2 As shown, the network device 200 includes a memory 201, a processor 202, an interface 203 (physical interface), and a power module 204. The interface 203 (physical interface) includes, but is not limited to, a local area network (LAN) interface, a wide area network (WAN) interface, and a network device configuration interface. The network device configuration interface may include a console port and an auxiliary port. The processor 202 interfaces with terminals via the interface 203. The number of LAN interfaces, WAN interfaces, and network device configuration interfaces is not limited to one. The LAN interface 3030 includes standard network interfaces such as Ethernet, Fast Ethernet, Gigabit Ethernet, and 10 Gigabit Ethernet. Within each network, it can support interfaces with different media standards, such as RJ45 interfaces, fiber optic interfaces, and thick coaxial cable interfaces. The network device 200 can connect to terminals via the RJ45 interface to achieve data communication with the terminals. The WAN interface includes synchronous serial interfaces and asynchronous serial interfaces. The network device 200 connects to a wide area network via the WAN interface to achieve cross-regional wide area network data communication. The console port is typically used to connect the interface to a terminal using a dedicated cable when performing basic configuration of network device 200. As a console port, it allows users or administrators to communicate with network device 200 using network-connected devices to complete network device configuration. As an auxiliary port, it also provides an EIA / TIA-232 asynchronous serial interface; however, it is often used to connect a modem for remote management of the network device.
[0078] In some embodiments of this application, memory 201 may be non-volatile memory, random access memory, flash memory, and read-only memory.
[0079] Processor 202 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, memory, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). Different processing units may be independent devices or integrated into one or more processors. The controller may serve as the central nervous system and command center of the network device 200. The controller can generate operation control signals based on instruction opcodes and timing signals to control instruction fetching and execution.
[0080] The power module 204 may include a power supply, a power management component, etc. The power management component is used to manage the charging of the power supply and the power supply to other modules.
[0081] Alternatively, for wireless network devices, Figure 2 The network device 200 shown also has a wireless communication module. Figure 2 (Not shown in the image). This enables wireless network devices to achieve, for example... Figure 1 The illustration shows wireless communication between smartphones, wireless speakers, portable computers, and tablets. Wireless communication modules can provide solutions for wireless communication applications on terminals, including wireless local area networks (WLANs) (such as Wireless Fidelity (Wi-Fi) networks), Bluetooth (BT), near field communication (NFC), and infrared (IR) technologies. A wireless communication module can be one or more devices integrating at least one communication processing module.
[0082] The wireless communication module can provide solutions for wireless communication applications on network devices 200, including WLAN such as Wi-Fi, BT, Global Navigation Satellite System (GNSS), Frequency Modulation (FM), NFC, IR, etc. The wireless communication module can be one or more devices integrating at least one communication processing module.
[0083] It is understood that the interface connection relationships between the modules illustrated in the embodiments of this application are merely illustrative and do not constitute a structural limitation on the network device 200. In other embodiments of this application, the network device 200 may also employ different interface connection methods or combinations of multiple interface connection methods as described in the above embodiments. In specific applications, the network device 200 may be an electronic device running a network operating system, such as a router or switch, that involves human-computer interaction in a network communication scenario.
[0084] The following is combined Figures 3 to 4 The operation permission management method provided in the embodiments of this application will be described in detail.
[0085] For example, Figure 3 This is one of the flowcharts illustrating an operation permission management method provided in an embodiment of this application. For example... Figure 3 As shown, this operation permission management method can be applied, for example, to... Figure 1 The operation permission management system formed by the routing device and network management system in this embodiment may include the following methods:
[0086] S301, the network device is in locked mode.
[0087] Lockout mode is used to instruct network devices to refuse to execute critical operation commands and set target user information. Critical operation commands can be set for the network device before enabling lockout mode. See also Figure 1 Similar to the operator's user information, the target user information may be one or more of the following: the device ID of the device to which the client belongs and the user account information of the logged-in client, such as username, role, etc.
[0088] For example, Figure 4 This is one of the flowcharts illustrating an operation permission management method provided in an embodiment of this application. For example... Figure 4 As shown, this operation permission management method may include:
[0089] S1, the user terminal sets key command lines for the router.
[0090] The user terminal can be either an administrator terminal or an operator terminal, depending on the application scenario. Administrator terminals and operator terminals are... Figure 1 In this embodiment, the network management system, or router, is... Figure 1In this embodiment, a routing device is used. For example, the first user indicated by the target user information, i.e., the administrator, can set critical command lines by recording command lines in a blacklist and / or whitelist on the network device. The blacklist records commands that are critical, while the whitelist records commands that are not critical. Setting critical command lines can be done via factory settings, allowing the manufacturer to directly operate the network device; alternatively, the setting can be user-configured, allowing the administrator to configure it on the network device via a client.
[0091] Optionally, the instructions for critical operation instructions and authorized operation instructions may include one of the following forms: command line CLI form, YANG form, and MIB form.
[0092] For ease of understanding and description, Figure 1 The following embodiments will be specifically described using command line as an example. In the embodiments of this application, the form of operation instructions is one of the following: command line CLI, YANG, and MIB, thereby being applicable to diverse network operating systems and management protocols, and further improving the flexibility of operation permission management.
[0093] Optionally, key operation instructions include one of the following operation instructions:
[0094] Operation instructions whose attributes satisfy preset attributes, operation instructions whose content matches preset content, and operation instructions whose attributes satisfy preset attributes and whose content matches preset content.
[0095] For example, key command lines can be configured according to different rules:
[0096] The first method is to define key command lines in batches based on their attributes. For example, set command lines with attributes of read, write, execute, and / or debug as key command lines.
[0097] The second approach is to define key command lines based on view-command line prefixes: command lines whose content matches a preset condition are set as key command lines. For example, command lines whose content matches a preset condition and can be retrieved from all command lines using longest prefix matching, regular expressions, or other content matching mechanisms are set as key command lines. Here, view-command line is a structure of command lines, also known as a command line view. The longest prefix matching algorithm is a routing lookup mechanism that is used by default in almost all routers in the industry.
[0098] The third method is to define candidate command lines in batches based on the attributes of the command lines, and to define key command lines from the candidate command lines based on the view-command line prefix definition.
[0099] In this application embodiment, key operation instructions are determined by the attributes of operation instructions, thereby enabling batch processing and improving management efficiency; key operation instructions are determined by content matching, thereby enabling fine-grained setting of key operation instructions and further improving management flexibility; or, based on determining candidate operation instructions by the attributes of operation instructions, key operation instructions are determined from the candidate operation instructions by content matching, thereby balancing management efficiency and flexibility.
[0100] In practical applications, the lockout mode can be pre-configured in the network device, so that the network device can automatically activate the lockout mode when it is working. Alternatively, the lockout mode can be activated by a user, such as an administrator or a second user, i.e., an operator. For example, ... Figure 4 As shown, the method may further include:
[0101] S2, enable lockout mode, configure administrator.
[0102] For example, the lock mode can be activated via a switch, which can be a mechanical switch or a command-line instruction. With the lock mode activated, the user can also configure an administrator, i.e., set target user information. Specifically, such as... Figure 4 As shown, the method also includes:
[0103] S3, the terminal's CLI module will distribute the configuration to the CFG module. This configuration specifically includes instructions to enable lockout mode, key command lines, and target user information.
[0104] S4, the AAA subscription administrator. Specifically, the AAA module records target user information and key command lines.
[0105] Optionally, the method may also include: S5, CLI subscription lock mode. Specifically, the router can display a notification to the user that the lock mode has been successfully enabled via the terminal's CLI module.
[0106] At this point, no user has permission to execute critical command lines. For example, such as... Figure 4 As shown, the method also includes:
[0107] S6, the operator terminal sends command lines to the router without authorization;
[0108] S7, the terminal's CLI module recognizes that the command line is a critical command line;
[0109] S8, the AAA module authenticates users who send command lines;
[0110] The S9, AAA module will identify the user sending the command line as an unauthorized operator.
[0111] Understandably, since the administrator has not yet performed any authorization, user authentication for sending command lines can be based on whether the user is an administrator. If not, the user is identified as an unauthorized operator. In one example, if the administrator performs authorization, user authentication for sending command lines can be based on authentication information to determine if the user is authorized. If not, the user is identified as an unauthorized operator.
[0112] Optionally, such as Figure 4 As shown, the method may further include:
[0113] S10, notification of authentication failure.
[0114] S11, error message; for example, lack of permission to execute.
[0115] S302, the client sends the authorization operation instruction for the first user indicated by the target user information to the network device.
[0116] See also Figure 4 The method may further include: S12, whereby the administrator terminal sends an authorization command to the router via the terminal's CLI module.
[0117] The authorization operation command is used to set authorization information in the network device. This authorization information includes authorized user information and the corresponding time window. For example, see... Figure 1 The authorization information, i.e. the permission request content, may include user information (e.g., device ID: 123 and / or username: huawei 123) and the corresponding time window (e.g., 6 hours).
[0118] Optionally, the authorization information may also include preset operation instructions, which may include one or more key operation instructions;
[0119] The client is also used to send a second key operation command from a second user to the network device.
[0120] For example, see Figure 1 At this point, the authorization information, i.e., the permission request content, can include user information (e.g., device ID: 123 and / or username: huawei 123), the time window corresponding to this user information (e.g., 6h), and the preset operation command (e.g., request command: sysnamehuawei). In specific applications, the authorization information can be in the form of key-value pairs, such as username-time window or username-time window-command.
[0121] In this embodiment of the application, the authorization information also includes one or more key operation instructions. In this way, the authorization information can be used to achieve further refined management of user operations. Compared with directly authorizing all key operations, it can further improve access security and management flexibility.
[0122] S303, the network device executes the authorized operation command of the first user;
[0123] For example, see Figure 4 The method may also include:
[0124] S13, the AAA module authenticates the user who sends the authorization command;
[0125] S14, the AAA module will identify the user who sent the authorization command as an administrator and authorize the operator indicated by the authorization command;
[0126] Optionally, in S15, the AAA module sends a notification of successful authorization via the terminal's CLI module.
[0127] S304, the client sends the second user's first key operation command to the network device;
[0128] For example, see Figure 4 The method may also include:
[0129] S16, the authorized operator sends command lines to the router through the terminal's CLI module.
[0130] S305, if the network device executes the first critical operation instruction when the user information of the second user matches the authorized user information and the current time is within the time window.
[0131] Optionally, when the client sends the second user's first key operation instruction to the network device, the network device may execute the second key operation instruction if the second user's user information matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time falls within the time window.
[0132] For example, see Figure 4 The method may also include:
[0133] S17, the terminal's CLI module recognizes that the command line is a critical command line.
[0134] S18, the AAA module authenticates users who send command lines;
[0135] S19, the AAA module will authenticate the user who sent the command line as an authorized operator;
[0136] Optionally, in S20, the AAA module sends a notification of successful authentication to the operator terminal via the terminal's CLI module.
[0137] For example, when an authorized user, such as an operator, sends a first key operation command, the AAA module, if the current time falls within the authorization time window (i.e., the time window corresponding to the authorized user's user information), identifies the user as an authorized operator and sends a successful authentication notification to the operator's client. When an authorized user, such as an operator, sends a second key operation command, the AAA module, if the current time falls within the authorization time window (i.e., the time window corresponding to the authorized user's user information) and the second key operation command matches a preset operation command, identifies the user as an authorized operator and sends a successful authentication notification to the operator's client.
[0138] Understandably, if any item in the operator's authentication information (such as user information and current time) does not match the authorization information—for example, the current time exceeds the time window, the user information does not match the authorized user's user information, or the operation command sent by the operator does not match the preset operation command—the AAA module will identify the user as an unauthorized operator, i.e., authentication fails. In this case, similar to S10, the AAA module can send an authentication failure notification to the operator's terminal.
[0139] Optionally, after receiving the user's operation command sent by the client, the network device sends a notification to the client indicating whether the user's operation command was executed successfully.
[0140] The client receives the notification and outputs the notification.
[0141] The user's operation instructions may include one or more of the following: a lockout mode enable instruction sent by the client to a network device that has not enabled the lockout mode, an authorization operation instruction from the first user, and a key operation instruction from the second user, wherein the key operation instruction from the second user includes either the first key operation instruction or the second key operation instruction.
[0142] For example, the notification in this embodiment may be... Figure 4 The information fed back from one or more of steps S5, S30, S15, and S20 shown. It is understandable that... Figure 4 This is merely an example of the feedback notification. The specific feedback method, data structure, and output format on the client side can be set according to the application scenario, and this application embodiment does not impose any restrictions on them.
[0143] In this embodiment, the network device provides feedback to the client regarding the success of an operation, thereby improving the controllability and visibility of operation management and further enhancing the flexibility of operation permission management. Specifically, when the user enables the lock mode, the operation may include enabling the lock mode.
[0144] For ease of understanding, the operation permission management methods provided in the above embodiments of this application are described in conjunction with application scenarios. For example, please refer to... Figure 1 The operation permission management method provided in this application embodiment is applied to Figure 1 In the scenario shown, the specific steps may include, but are not limited to, the following:
[0145] 0. The network administrator sets up key command lines to enable the locked mode of the routing device; this step can be performed by the administrator, operator, or... Figure 1 The user operation network management is configured as shown in the diagram.
[0146] 1. The operator requests operation permissions from the administrator; Example of permission request content: Device ID:123 Username:huawei123 Time window:6h Request command:sysnamehuawei.
[0147] For example, operators and administrators can communicate through their respective clients, allowing operators to request operating permissions via their clients. This application embodiment does not limit the method by which operators request operating permissions.
[0148] 2. The administrator operates the network management / terminal tool; this step is used for the administrator to perform authorization operations, which is the subsequent step 3.
[0149] 3. The network management system sends an authorization request to the device;
[0150] 4. The routing device replies to the network management system to confirm whether the authorization was successful;
[0151] 5. The network management system outputs a notification of successful authorization;
[0152] 6. Notify the operator that authorization was successful; for example, this step can be a notification from the routing device to the device the operator logged into, or a notification from the administrator's network management system to the device the operator logged into. This embodiment does not limit the specific notification method.
[0153] 7. The operator logs in to the device with device ID 123 using the account name huawei123 and executes the corresponding command sysnamehuawei.
[0154] In one example, this application embodiment also provides an operation permission management system. Figure 5 This is a structural block diagram of an operation permission management system provided in an embodiment of this application, such as... Figure 5 As shown, the system includes network devices and clients;
[0155] Network devices are used to enable lockout mode, which instructs network devices to refuse to execute critical operation commands and set target user information.
[0156] The client is used to send the authorization operation instruction of the first user indicated by the target user information to the network device. The authorization operation instruction is used to set authorization information in the network device. The authorization information includes the authorized user information and the time window corresponding to the authorized user information.
[0157] Network devices are used to execute authorized operation instructions from the first user;
[0158] The client is used to send the second user's first key operation command to the network device;
[0159] The network device is used to execute the first critical operation instruction when the user information of the second user matches the authorized user information and the current time falls within the time window.
[0160] In one example, this application embodiment also provides an operation permission management device. Figure 6 This is one of the structural block diagrams of an operation permission management device provided in an embodiment of this application. For example... Figure 6 As shown, this device is used in network equipment and specifically includes:
[0161] The mode startup module is used to enable the lockout mode, which instructs network devices to refuse to execute critical operation commands and set target user information.
[0162] The permission management module is used to execute the authorization operation instructions for the first user indicated by the target user information. The authorization operation instructions are used to set authorization information, which includes authorized user information and the time window corresponding to the authorized user information.
[0163] The operation management module is used to execute the first key operation instruction if it receives a first key operation instruction from a second user, provided that the user information of the second user matches the authorized user information and the current time is within the time window.
[0164] In one example, this application embodiment also provides an operation permission management device. Figure 7 This is one of the structural block diagrams of an operation permission management device provided in the embodiments of this application, such as... Figure 7 As shown, this operation permission management device is applied to the client and specifically includes:
[0165] The authorization setting module is used to send the authorization operation instruction of the first user to the network device with the lock mode enabled. The lock mode is used to instruct the network device to refuse to execute the key operation instruction and to set the target user information for the first user. The authorization operation instruction is used to set the authorization information in the network device. The authorization information includes the authorized user information and the time window corresponding to the authorized user information.
[0166] The device operation module is used to send the first key operation instruction of the second user to the network device. The first key operation instruction is used to instruct the network device to execute the first key operation instruction when the user information of the second user matches the authorized user information and the current time is within the time window.
[0167] In one example, this application embodiment also provides an electronic device, which may be a network device such as a router or switch, or a device such as a computer, network management device, mobile terminal, or server running software client for managing network devices. Figure 8 This is a structural block diagram of an electronic device provided in an embodiment of this application, such as... Figure 8 As shown, the electronic device 800 may include a processor 801 and a transceiver / transceiver pin 802, and optionally, a memory 803.
[0168] The various components of electronic device 800 are coupled together via bus 804, which includes a data bus, a power bus, a control bus, and a status signal bus. However, for clarity, all buses are referred to as bus 804 in the figure.
[0169] Optionally, the memory 803 can be used for the instructions in the foregoing method embodiments. The processor 801 can be used to execute the instructions in the memory 803, control the receive pin to receive signals, and control the transmit pin to transmit signals.
[0170] The electronic device 800 may be the electronic device or the chip of the electronic device in the above method embodiments.
[0171] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0172] In addition, this application Figure 5 The system shown Figure 6 and Figure 7 The device shown and Figure 8The electronic device shown includes hardware and / or software modules for executing various functions in order to implement the operation permission management method described in the embodiments of this application. Based on the algorithm steps of the examples described herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application in conjunction with the embodiments, but such implementation should not be considered beyond the scope of this application.
[0173] This embodiment also provides a computer storage medium storing computer instructions. When the computer instructions are executed on an electronic device, the electronic device performs the aforementioned method steps to implement the operation permission management method described in the above embodiment.
[0174] This embodiment also provides a computer program product that, when run on a computer, causes the computer to perform the aforementioned related steps to implement the operation permission management method described in the above embodiment.
[0175] In this embodiment, the electronic device, computer storage medium, computer program product or chip are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding method provided above, and will not be repeated here.
[0176] Any content in the various embodiments of this application, as well as any content in the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.
[0177] Those skilled in the art will recognize that the functions described in the embodiments of this application in one or more of the above examples can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transfer of a computer program from one place to another. Storage media can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0178] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A method for managing access permissions, characterized in that, Applied to network devices, the method includes: Enable lockout mode, which instructs the network device to refuse to execute critical operation commands and set target user information; Execute the authorization operation instruction for the first user indicated by the target user information, wherein the authorization operation instruction is used to set authorization information, and the authorization information includes authorized user information and a time window corresponding to the authorized user information; If a first key operation instruction from a second user is received, and the user information of the second user matches the authorized user information, and the current time falls within the time window, the first key operation instruction is executed.
2. The method according to claim 1, characterized in that, The key operation instructions include one of the following: Operation instructions whose attributes satisfy preset attributes, operation instructions whose content matches preset content, and operation instructions whose attributes satisfy preset attributes and whose content matches preset content.
3. The method according to claim 1 or 2, characterized in that, The authorization information also includes preset operation instructions, which include one or more of the key operation instructions; After executing the authorization operation instruction for the first user indicated by the target user information, the method further includes: If a second key operation instruction from the second user is received, the second key operation instruction will be executed if the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time falls within the time window.
4. The method according to any one of claims 1 to 3, characterized in that, The first user and the second user send operation commands to the network device through the client; After the lock mode is activated, the method further includes: The client receives a notification corresponding to the user's operation command. The user's operation instructions include one or more of the following: the lock mode activation instruction, the first user's authorization operation instruction, and the second user's key operation instruction; the notification corresponding to the user's operation instruction is used to indicate whether the user's operation instruction was executed successfully, and the second user's key operation instruction includes the first key operation instruction or the second key operation instruction.
5. The method according to any one of claims 1 to 4, characterized in that, The key operation instructions and the authorized operation instructions include one of the following forms: command line CLI, YANG, and MIB.
6. A method for managing access permissions, characterized in that, Applied to a client, the method includes: Send the authorization operation instruction of the first user to the network device with the lockout mode enabled. The lockout mode is used to instruct the network device to refuse to execute the key operation instruction and to set the target user information for the first user. The authorization operation instruction is used to set authorization information in the network device. The authorization information includes authorized user information and a time window corresponding to the authorized user information. Send a first key operation instruction for the second user to the network device. The first key operation instruction is used to instruct the network device to execute the first key operation instruction when the user information of the second user matches the authorized user information and the current time is within the time window.
7. The method according to claim 6, characterized in that, The key operation instructions include one of the following: Operation instructions whose attributes satisfy preset attributes, operation instructions whose content matches preset content, and operation instructions whose attributes satisfy preset attributes and whose content matches preset content.
8. The method according to claim 6 or 7, characterized in that, The authorization information also includes preset operation instructions, which include one or more of the key operation instructions; After executing the authorization operation instruction for the first user indicated by the target user information, the method further includes: Send the second key operation instruction of the second user to the network device. The second key operation instruction is used to instruct the network device to execute the second key operation instruction when the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time belongs to the time window.
9. The method according to any one of claims 6 to 8, characterized in that, After sending the user's operation command, the method further includes: Receive a notification from the network device indicating whether the user's operation command was executed successfully; Output the notification; The user's operation instructions include one or more of the following: a lock mode enable instruction sent to a network device that has not enabled the lock mode, an authorization operation instruction from the first user, and a key operation instruction from the second user, wherein the key operation instruction from the second user includes either the first key operation instruction or the second key operation instruction.
10. The method according to any one of claims 6 to 9, characterized in that, The key operation instructions and the authorized operation instructions include one of the following forms: command line CLI, YANG, and MIB.
11. An operation permission management system, characterized in that, The system includes network devices and clients; The network device is used to enable a lockout mode, which instructs the network device to refuse to execute critical operation commands and set target user information. The client is configured to send an authorization operation instruction for the first user indicated by the target user information to the network device. The authorization operation instruction is configured to set authorization information in the network device. The authorization information includes authorized user information and a time window corresponding to the authorized user information. The network device is used to execute the authorized operation instructions of the first user; The client is used to send the second user's first key operation command to the network device; The network device is configured to execute the first key operation instruction when the user information of the second user matches the authorized user information and the current time falls within the time window.
12. The system according to claim 11, characterized in that, The key operation instructions include one of the following: Operation instructions whose attributes satisfy preset attributes, operation instructions whose content matches preset content, and operation instructions whose attributes satisfy preset attributes and whose content matches preset content.
13. The system according to claim 11 or 12, characterized in that, The authorization information also includes preset operation instructions, which include one or more of the key operation instructions; The client is also configured to send the second key operation command of the second user to the network device; The network device is further configured to execute the second key operation instruction when the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time falls within the time window.
14. The system according to any one of claims 11 to 13, characterized in that, The network device is also used for: After receiving the user's operation instruction sent by the client, the system sends a notification to the client indicating whether the user's operation instruction was executed successfully. The client is also configured to receive the notification and output the notification; The user's operation instructions include one or more of the following: a lock-up mode enable instruction sent by the client to a network device that has not enabled the lock-up mode, an authorization operation instruction from the first user, and a key operation instruction from the second user, wherein the key operation instruction from the second user includes either the first key operation instruction or the second key operation instruction.
15. The system according to any one of claims 11 to 14, characterized in that, The key operation instructions and the authorized operation instructions include one of the following forms: command line CLI, YANG, and MIB.
16. An operation permission management device, characterized in that, Applied to network devices, the device includes: The mode activation module is used to enable the lock mode, which instructs the network device to refuse to execute critical operation commands and set target user information. The permission management module is used to execute the authorization operation instruction of the first user indicated by the target user information. The authorization operation instruction is used to set authorization information, which includes authorized user information and a time window corresponding to the authorized user information. The operation management module is used to execute the first key operation instruction if it receives a first key operation instruction from a second user, provided that the user information of the second user matches the authorized user information and the current time belongs to the time window.
17. The apparatus according to claim 16, characterized in that, The key operation instructions include one of the following: Operation instructions whose attributes satisfy preset attributes, operation instructions whose content matches preset content, and operation instructions whose attributes satisfy preset attributes and whose content matches preset content.
18. The apparatus according to claim 16 or 17, characterized in that, The authorization information also includes preset operation instructions, which include one or more of the key operation instructions; The operation management module is also used for: If a second key operation instruction from the second user is received, the second key operation instruction will be executed if the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time falls within the time window.
19. The apparatus according to any one of claims 16 to 18, characterized in that, The first user and the second user send operation commands to the network device through the client; The device further includes an operation feedback module for: The client receives a notification corresponding to the user's operation command. The user's operation instructions include one or more of the following: the lock mode activation instruction, the first user's authorization operation instruction, and the second user's key operation instruction; the notification corresponding to the user's operation instruction is used to indicate whether the user's operation instruction was executed successfully, and the second user's key operation instruction includes the first key operation instruction or the second key operation instruction.
20. The apparatus according to any one of claims 16 to 19, characterized in that, The key operation instructions and the authorized operation instructions include one of the following forms: command line CLI, YANG, and MIB.
21. An operation permission management device, characterized in that, Applied to a client, the device includes: The authorization setting module is used to send the authorization operation instruction of the first user to the network device with the lock mode enabled. The lock mode is used to instruct the network device to refuse to execute the key operation instruction and to set the target user information for the first user. The authorization operation instruction is used to set authorization information in the network device. The authorization information includes authorized user information and a time window corresponding to the authorized user information. The device operation module is used to send a first key operation instruction from the second user to the network device. The first key operation instruction is used to instruct the network device to execute the first key operation instruction when the user information of the second user matches the authorized user information and the current time belongs to the time window.
22. The apparatus according to claim 21, characterized in that, The key operation instructions include one of the following: Operation instructions whose attributes satisfy preset attributes, operation instructions whose content matches preset content, and operation instructions whose attributes satisfy preset attributes and whose content matches preset content.
23. The apparatus according to claim 21 or 22, characterized in that, The authorization information also includes preset operation instructions, which include one or more of the key operation instructions; the device operation module is further configured to: Send the second key operation instruction of the second user to the network device. The second key operation instruction is used to instruct the network device to execute the second key operation instruction when the user information of the second user matches the authorized user information, the second key operation instruction matches the preset operation instruction, and the current time belongs to the time window.
24. The apparatus according to any one of claims 21 to 23, characterized in that, The device further includes an operation response module for: Receive a notification from the network device indicating whether the user's operation command was executed successfully; Output the notification; The user's operation instructions include one or more of the following: a lock mode enable instruction sent to a network device that has not enabled the lock mode, an authorization operation instruction from the first user, and a key operation instruction from the second user, wherein the key operation instruction from the second user includes either the first key operation instruction or the second key operation instruction.
25. The apparatus according to any one of claims 21 to 24, characterized in that, The key operation instructions and the authorized operation instructions include one of the following forms: command line CLI, YANG, and MIB.