Identity verification method, apparatus, device, storage medium, and program product

By creating a dedicated application container for the personnel implementing the change during data center operation and maintenance and destroying it after the task is completed, the problem of long-term exposure of permissions and environment is solved, achieving higher security and proactive defense.

CN122268612APending Publication Date: 2026-06-23INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2026-02-04
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

In existing technologies, during data center operation and maintenance changes, permissions and the environment are exposed for a long time, resulting in a high risk of lateral movement attacks, a large attack surface, and easy abuse of permissions, which reduces security.

Method used

Before the change implementation window is launched, a dedicated application container is created for the change implementation personnel, and access permissions are granted within the window. The container destruction conditions are determined based on the task execution status and lifecycle to reduce permission residue and environment reuse.

Benefits of technology

By dynamically creating and destroying containers, the risk of privilege exposure is reduced, lateral movement attacks are mitigated, and the security and proactive defense capabilities of data center change operations are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122268612A_ABST
    Figure CN122268612A_ABST
Patent Text Reader

Abstract

This application provides an authentication method, apparatus, device, storage medium, and program product, relating to the fintech field or other related fields. The method includes: dynamically creating a dedicated application container for designated personnel before the change implementation window begins, granting them access permissions during the change implementation window, and destroying the container based on the execution status and window lifecycle after the task ends. This process reduces permission residue and environment reuse, effectively solving the security problems of high lateral attack risk, large attack surface, and easy permission abuse caused by long-term exposure of permissions and environment and lack of task-level isolation in traditional operation and maintenance models. The method of this application, while ensuring operational efficiency, enhances the inherent security and proactive defense capabilities of data center change operations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of financial technology or other related fields, and in particular to an authentication method, device, equipment, storage medium and program product. Background Technology

[0002] As enterprise IT infrastructure becomes increasingly complex and cloud-native technologies become more widespread, data center operations and maintenance are becoming more frequent and complex. When performing changes such as database configuration modifications, server expansion, and application deployments, operations and maintenance personnel need to obtain temporary access permissions to the corresponding systems through strict authentication mechanisms to complete authorized operations within a specific time window.

[0003] Current technologies typically verify identity by granting designated operations personnel appropriate operating accounts or temporary permissions on the target system after the change management process has been approved, based on pre-configured permission policies. These permissions are usually pre-configured before the change window begins and remain valid throughout the window. After logging in through a unified authentication portal, operations personnel can access the target system to perform change operations.

[0004] However, once permissions are granted, the corresponding access point and operating environment will remain online and detectable by the network throughout the entire change window. This provides unauthorized attackers with a stable attack interface and ample time window for attacks. When a single operation and maintenance node is compromised, unauthorized attackers may use the granted permissions to move laterally, reducing the security of data center operation and maintenance change processes. Summary of the Invention

[0005] This application provides an authentication method, apparatus, device, storage medium, and program product to improve the security of data center change and maintenance operations.

[0006] Firstly, this application provides an authentication method, including:

[0007] Obtain the approved change implementation plan application and corresponding change elements from the change process system;

[0008] Based on the change elements, before the change implementation window corresponding to the change implementation plan application is launched, a dedicated application container is created for the change implementer specified in the change implementation plan application. The dedicated application container is bound to the change implementer and the change task corresponding to the change implementation plan application.

[0009] Within the change implementation window, grant the personnel implementing the change access to the dedicated application container;

[0010] Based on the execution status of the change task and the lifecycle of the change implementation window, determine whether the preset container destruction conditions are met; if so, destroy the dedicated application container.

[0011] Secondly, this application provides an authentication device, comprising:

[0012] Obtain the approved change implementation plan application and corresponding change elements from the change process system;

[0013] Based on the change elements, before the change implementation window corresponding to the change implementation plan application is launched, a dedicated application container is created for the change implementer specified in the change implementation plan application. The dedicated application container is bound to the change implementer and the change task corresponding to the change implementation plan application.

[0014] Within the change implementation window, grant the personnel implementing the change access to the dedicated application container;

[0015] Based on the execution status of the change task and the lifecycle of the change implementation window, determine whether the preset container destruction conditions are met; if so, destroy the dedicated application container.

[0016] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0017] The memory stores the instructions that the computer executes;

[0018] The processor executes computer execution instructions stored in memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0019] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0020] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0021] The authentication method, apparatus, device, storage medium, and program products provided in this application dynamically create a dedicated application container for designated personnel before the change implementation window begins, grant them access during the change implementation window, and destroy the container based on the execution status and window lifecycle after the task ends. This process reduces permission residue and environment reuse, effectively solving the security problems of high lateral attack risk, large attack surface, and easy permission abuse caused by long-term exposure of permissions and environment and lack of task-level isolation in traditional operation and maintenance models. Thus, it achieves the effect of improving the inherent security and proactive defense capabilities of data center change operations while ensuring operational efficiency. Attached Figure Description

[0022] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0023] Figure 1 A schematic diagram illustrating the scenario of the authentication method provided in this application;

[0024] Figure 2 Flowchart of the authentication method provided in this application Figure 1 ;

[0025] Figure 3 Flowchart of the authentication method provided in this application Figure 2 ;

[0026] Figure 4 A schematic diagram of the identity verification device provided in this application;

[0027] Figure 5 A schematic diagram of the structure of the electronic device provided in this application.

[0028] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0029] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0030] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.

[0031] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.

[0032] It should be noted that the authentication methods, devices, equipment, storage media, and program products provided in this application can be used in the field of fintech or other related fields, or in any field other than fintech or other related fields. The application fields of the authentication methods, devices, equipment, storage media, and program products in this application are not limited.

[0033] This application applies to security operation and maintenance management scenarios for enterprise IT infrastructure such as data centers and cloud computing platforms. In this scenario, operation and maintenance personnel need to perform regular or emergency changes to servers, databases, network devices, etc., such as system upgrades, configuration modifications, vulnerability patching, and capacity expansion. These changes typically involve high-privilege access, so if these accounts are stolen or compromised by unauthorized individuals, it could lead to system paralysis, data breaches, or even financial losses. For example, a bank's operation and maintenance account might be used to manage payment systems, access customer privacy data, or execute high-value transactions, while an administrator account in the energy industry might directly control the operation of critical infrastructure. Currently, authentication for these high-privilege accounts typically relies on a combination of username and password, but simple static passwords are vulnerable to brute-force attacks or man-in-the-middle attacks.

[0034] Current technology typically verifies the identity of access personnel by granting designated operations and maintenance (O&M) personnel appropriate operation accounts or temporary permissions on the target system after the change management process has been approved, based on pre-configured permission policies. These permissions are usually pre-configured before the change window begins and remain valid throughout the window. After logging in through a unified authentication portal, O&M personnel can access the target system to perform change operations.

[0035] However, once permissions are granted, the corresponding access point and operating environment will remain online and detectable by the network throughout the entire change window. This provides unauthorized attackers with a stable attack interface and ample time window for attacks. When a single operation and maintenance node is compromised, unauthorized attackers may use the granted permissions to move laterally, reducing the security of data center operation and maintenance change processes.

[0036] In summary, under the traditional operation and maintenance model, operation and maintenance tools run continuously online, and operation and maintenance personnel perform operations through fixed accounts and access channels, which poses security risks such as a large attack surface, high risk of lateral movement, and lax access control.

[0037] The authentication method provided in this application is intended to solve the above-mentioned technical problems of the prior art.

[0038] The authentication method provided in this application obtains the approved change implementation plan application and corresponding change elements from the change process system. Based on the change elements, before the change implementation window corresponding to the change implementation plan application is launched, a dedicated application container is created for the change implementer specified in the change implementation plan application. This dedicated application container is bound to the change implementer and the change task corresponding to the change implementation plan application. Within the change implementation window, the change implementer is granted access to the dedicated application container. Based on the execution status of the change task and the lifecycle of the change implementation window, it is determined whether preset container destruction conditions are met. If met, the dedicated application container is destroyed. This process reduces permission residue and environment reuse, effectively solving the security problems of high lateral attack risk, large attack surface, and easy permission abuse caused by long-term exposure of permissions and environment and lack of task-level isolation in traditional operation and maintenance models. This achieves the effect of improving the inherent security and proactive defense capabilities of data center change operations while ensuring operational efficiency.

[0039] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0040] Figure 1 A schematic diagram of the scenario for the authentication method provided in this application, such as... Figure 1As shown, the scenario includes a change process system, a change database, a change control system, and a dedicated application container cluster. The change process system and change database reside in a physically isolated, secure network zone, physically isolated from the implementation environment and preventing direct network connectivity. The change process system receives change implementation plan requests from operations personnel, executes multi-level approval processes, and ensures the compliance and necessity of change operations. The change database stores all structured data related to changes, including change request information, approval status, implementation time window, designated personnel, task details, and other change elements, providing data support for scheduling decisions. The change control system resides in the dynamic scheduling and management layer. It monitors the approval status of the change process system in real time, retrieves change elements from the change database, and executes core control logic according to preset security policies: precisely scheduling the creation of dedicated application containers before the change implementation window begins, managing access authorization during the window period, and triggering container destruction after the window ends or the task is completed. The change control system also handles security monitoring and early warning. The dedicated application container cluster is located in the execution domain and includes dedicated application container 1, ..., dedicated application container n, where n is a positive integer greater than 1. Dedicated application containers are used to dynamically generate and temporarily exist in isolated execution environments. Each dedicated application container strictly follows the binding principle of one person, one container, and one task, and can only be accessed by specific operations and maintenance personnel and specific change tasks.

[0041] Figure 2 Flowchart of the authentication method provided in this application Figure 1 ,like Figure 2 As shown, the method includes:

[0042] S201. Obtain the approved change implementation plan application and corresponding change elements from the change process system.

[0043] More specifically, the change control system uses a predefined secure data interface to poll or monitor the approval status change messages of the change process system in real time. When the status of a change task is updated to "approved," the change control system sends a query request to the change database to obtain the complete structured data (i.e., change elements) of the change task. These change elements include at least the user identifier of the approved change implementer, the precise implementation time window, the change task identifier, the target system resource information, and a summary of the operation instructions.

[0044] For example, after the application for "CPU expansion of database instance DB_01" submitted by the maintenance personnel "User_A" is approved, the change control system obtains a data packet containing elements such as "implementer: User_A", "window: 2024-01-01 02:00 to 03:00", and "task ID: TASK_2024001".

[0045] S202. Based on the change elements, before the change implementation window corresponding to the change implementation plan application is launched, create a dedicated application container for the change implementation personnel specified in the change implementation plan application.

[0046] More specifically, based on the change elements, before the change implementation window corresponding to the change implementation plan application is launched, a dedicated application container is created for the change implementer specified in the change implementation plan application. The dedicated application container is bound to the change implementer and the change task corresponding to the change implementation plan application.

[0047] Optionally, before the change implementation window corresponding to the change implementation plan application is launched, a dedicated application container is created for the change implementation personnel specified in the change implementation plan application. Specifically, this includes: determining the change implementation window based on the implementation time specified in the change implementation plan application; and triggering the creation of the dedicated application container after a first preset time before the start time of the change implementation window.

[0048] In one possible embodiment, the change control system parses the change element to obtain the implementation time as "2024-01-01 02:00 to 03:00", and determines the change implementation window based on this implementation time. Subsequently, the change control system calculates a first preset duration (e.g., 5 minutes) before the window's start time "02:00", i.e., at "01:55", and sends a command to the container orchestration engine to trigger the creation of a new application container instance dedicated to the current change task. This application container instance is initialized based on a pre-configured security operations image and assigned a temporary internal network identifier.

[0049] This embodiment triggers container creation at the moment corresponding to the first preset time before the change implementation window is about to begin, ensuring that the operation and maintenance environment is in a ready state only during the necessary operation period. This achieves precise compression of the attack surface from a time dimension and avoids exposure caused by premature container startup.

[0050] Optionally, before creating a new dedicated application container based on the change task, or when determining whether the preset container destruction conditions are met based on the execution status of the change task and the lifecycle of the change implementation window, the container reuse decision logic is executed; wherein, the container reuse decision logic includes: if the same change implementer has multiple change tasks to be executed, then determining whether the change implementation windows corresponding to the multiple change tasks are consecutive or overlapping; if the change implementation windows corresponding to the multiple change tasks are consecutive or overlapping, then performing a reuse operation.

[0051] In one possible implementation, after the change control system detects that the implementer "User_A" has completed the current change task "TASK_2024001" (change implementation window: 02:00-03:00), there is an approved follow-up task "TASK_2024002" (window: 03:00-04:00), indicating that the change implementation windows for these two change tasks are consecutive. Therefore, before the change control system executes the container creation decision for TASK_2024002, or when determining the container destruction conditions after TASK_2024001 is completed, it will decide to reuse the container created for TASK_2024001 instead of immediately destroying it and creating another container for the new task.

[0052] This embodiment determines the window relationship of continuous task changes by the same person, and introduces container reuse decision logic based on the window relationship. This effectively reduces the number of unnecessary container start-stop operations, reduces system resource consumption and task switching latency, and improves operation and maintenance efficiency while ensuring safe isolation.

[0053] Optionally, the reuse operation includes: before creating a new dedicated application container based on the change task, reusing the same existing or pending dedicated application container for the current change task and other change tasks; and when determining whether the preset container destruction conditions are met based on the execution status of the change task and the lifecycle of the change implementation window, delaying the destruction of the existing dedicated application container so that it can be used to execute other change tasks.

[0054] In one possible embodiment, for the scenario of continuous task changes for the implementer "User_A" mentioned above, the specific reuse operation steps are as follows: before creating a container for the subsequent task TASK_2024002, it is determined that the reuse conditions are met, so the instruction to create a new container for TASK_2024002 is canceled, and it is planned to point the implementation entry of TASK_2024002 to the existing container created for TASK_2024001.

[0055] In one possible embodiment, for the continuous change task scenario of the aforementioned implementer "User_A", the specific reuse operation steps are as follows: After the current change task TASK_2024001 is completed at 02:50, the change control system could originally prepare to destroy the container based on the condition of "task completed and window not closed". However, in this embodiment, the destruction is delayed by selecting the reuse decision, that is, the container is kept running until the window start time of TASK_2024002 (i.e., 03:00), and the context environment of TASK_2024002 is rebound for the container.

[0056] This embodiment ensures that the resource optimization strategy can be executed safely and accurately by applying reuse decisions to executable control actions that suppress the creation of easily created and delayed destruction containers.

[0057] S203. In the change implementation window, grant the change implementer access to the exclusive application container.

[0058] More specifically, when the change control system determines that the current time has reached the start time of the change implementation window, it activates the access control policy for that container. The change control system generates a one-time access token or a dynamically generated temporary access address (URL) and sends it to the designated change implementer via a secure communication method independent of public notification channels (e.g., encrypted email, internal secure messaging system). This change implementer can only access the corresponding dedicated application container using a pre-registered device that has passed endpoint security checks, wielding this token or address.

[0059] Optionally, before granting access to the dedicated application container to the change implementer, the access permissions and network address of the dedicated application container are bound to the change implementer's user identity information, the task identifier of the change task, and the network address of the terminal used by the change implementer.

[0060] In one possible implementation, before the change control system sends the access address of the dedicated application container to the implementer "User_A", a record is created in the access control list, binding the network entry point and access credentials of the dedicated application container with "User ID: User_A", "Task ID: TASK_2024001", and "Authorized Terminal IP: 10.0.0.101". Any access request must match all three elements to be allowed to the dedicated application container by the load balancer or firewall.

[0061] This embodiment constructs a one-person-one-container-one-task-one-terminal permission model by binding the access permissions, network address, terminal, and personnel involved in the change of the exclusive application container to multiple information. This makes it difficult for access permissions to be transferred, shared, or used on other terminals, reducing the risk of horizontal diffusion of permissions and improving the accuracy of access control.

[0062] S204. Based on the execution status of the change task and the lifecycle of the change implementation window, determine whether the preset container destruction conditions are met; if so, destroy the dedicated application container.

[0063] More specifically, the change control system continuously monitors the execution status of change tasks (e.g., "in progress," "completed," "failed") and the relationship between the current system time and the change implementation window. Combining these two pieces of information, a conditional judgment is made based on a preset destruction strategy. When any destruction condition is met, a destruction command is sent to the container orchestration engine to completely remove the dedicated application container corresponding to the change task and all its related storage and network configurations.

[0064] Optionally, after destroying the dedicated application container, the network access permissions bound to the dedicated application container are automatically disabled.

[0065] In one possible implementation, when the dedicated application container is destroyed, all access rules associated with the IP address and port of that dedicated application container are immediately removed or disabled by changing the control system's synchronous operation of network devices (e.g., firewalls, load balancers) or updating the access control list. This makes it difficult to establish any valid network connection even if previously issued access tokens are intercepted.

[0066] This embodiment synchronizes the destruction of the exclusive application container with the expiration of network permissions, ensuring the immediacy and thoroughness of permission revokement and reducing security risks caused by residual permissions.

[0067] Optionally, the preset container destruction conditions include at least one of the following: the change task is completed and the change implementation window ends; the change task is completed and the time elapsed since the start of the change implementation window for the next change task belonging to the same change implementer exceeds a second preset time.

[0068] For example, if User_A's change task is completed at 02:45, and the system waits until the change implementation window ends at 03:00, then the "task completed and window ended" condition is met, triggering the destruction of the exclusive application container.

[0069] For example, if User_A's task is completed at 02:45 and its next change task window starts at 04:00, with an interval exceeding the second preset time (e.g., 30 minutes), the system will not wait until 03:00, but will destroy the dedicated application container immediately after the task is completed (or after a short cleanup), without maintaining the dedicated application container in an idle state.

[0070] This embodiment improves the flexibility and efficiency of container lifecycle management by setting composite destruction conditions. While ensuring that the container remains available within the necessary working window, it avoids unnecessary resource consumption and security exposure caused by excessive waiting time between tasks, thus achieving an optimal balance between security and resource utilization.

[0071] Optionally, within the change implementation window, when the dedicated application container is running, network access requests to the dedicated application container are monitored in real time; by analyzing the access patterns of the monitored network connection requests, it is possible to identify whether port scanning behavior exists; wherein, port scanning behavior refers to making more than a preset number of connection attempts from the same network address to multiple different ports of the application container within a preset time period; if port scanning behavior is identified and the port scanning behavior comes from an unauthorized network address, a security warning is triggered.

[0072] In one possible implementation, during the operation of the dedicated application container, a security agent deployed on the same host machine or network layer continuously collects all network connection logs arriving at the dedicated application container. The analysis engine performs statistical analysis in 5-second time windows. If connection attempts from IP address "XXXX" cover multiple ports (such as 22, 3389, and 8080) of the container within the window, and the total number of attempts exceeds 10, it is determined to be port scanning behavior. Then, it is verified whether the IP address is in the authorized terminal IP list for this task. If not, a high-level alert is immediately sent to the security operations center, and subsequent access from that IP address is blocked.

[0073] This embodiment improves the accuracy of identifying unauthorized scanning behavior in the initial reconnaissance stage by introducing behavior pattern recognition based on frequency and port dispersion in real-time monitoring of container network traffic, thus advancing the security defense checkpoint and enhancing the system's proactive defense capabilities.

[0074] The authentication method provided in this application constructs a dynamically isolated secure execution environment by associating a change implementation plan application with a dedicated application container created on demand and bound to tasks, and limiting the lifecycle of the change implementation plan application container to within the change implementation window. This reduces the unauthorized attack surface, lowers the possibility of lateral movement of permissions, and enables precise traceability of operational behavior, thereby improving the security of data center change and maintenance operations.

[0075] Figure 3 Flowchart of the authentication method provided in this application Figure 2 ,like Figure 3As shown, if a data center plans to perform a batch of server maintenance operations on the night of December 17, 2025, involving three maintenance personnel: Zhang San, Wang Wu, and Li Si, then Zhang San, as the change applicant, will first log in to the change process system, create a change request, and submit a detailed implementation plan. The plan clearly specifies that Zhang San is the implementer of this change task, and the implementation time is from 22:00 to 23:00 on December 17, 2025. When this request enters the change approval process, it is marked as "Change ID: 001". After the approver approves it, the status of the change process system is updated to "Approved", and the key information of the implementation plan (i.e., change elements) is uploaded to the system backend (i.e., the change database) for storage.

[0076] The change control system continuously monitors the status of the change process system. When "Change ID: 001" is approved, the system retrieves the change approval status of the corresponding change task and further obtains the detailed change implementation plan application. By parsing the change implementation plan application, it confirms that the implementer is Zhang San and the implementation window is 22:00-23:00. Therefore, at a preset time before 22:00 (e.g., 21:58), the change control system executes a container creation operation, dynamically generating a dedicated application container (i.e., the maintenance phase) for Zhang San. Figure 3 As shown below Zhang San's diagram, a change implementation system with container ID "001" was successfully created, and the container's metadata clearly identifies the implementer: Zhang San. Similarly, the change control system will also create a dedicated change implementation system with container ID "002" for Wang Wu, who has change tasks at the same time (assuming Wang Wu's change plan is also approved). The above process achieves physical isolation of one person, one container. Figure 3 The fact that Zhong Lisi has multiple containers (ID: 003, 004) demonstrates that the same implementer may be assigned different container instances when handling different tasks or at different times.

[0077] At the start of the change implementation window (i.e., 22:00), Zhang San received a temporary access address and credentials for his dedicated application container (ID: 001) through a secure channel. Zhang San used these credentials to log in to the change implementation system and completed the planned server maintenance operations within the system. The entire operation was confined to this dedicated application container, completely isolated from Wang Wu's container (ID: 002) and other system environments.

[0078] If Zhang San's change task is completed ahead of schedule at 22:50, the change implementation status will be obtained through the change control system, confirming that the execution status of "Change ID: 001" is "Completed". Since the implementation window will close at 23:00, the system will initiate the container destruction decision logic. Because Zhang San has no consecutive tasks, the destruction conditions are met, and the dedicated application container ID: 001 will be destroyed at 23:00, all resources will be reclaimed, and its network access permissions will be immediately invalidated.

[0079] Throughout the change implementation window, continuous network monitoring of running containers (e.g., container 001 in Zhang San's container) is performed through the change control system. Suppose that at 22:30, a series of rapid, probing connections from an IP address not on the authorized list (unauthorized requests) to multiple ports of container 001 are detected. This behavior pattern is determined to match port scanning characteristics, triggering an alert mechanism. For example... Figure 3 As shown at the bottom, an unauthorized scan alert notification containing detailed information is generated and sent to the change implementation system, enabling real-time detection and alerting of potential attacks.

[0080] Figure 4 A schematic diagram of the authentication device provided in this application is shown below. Figure 4 As shown, the authentication device 40 provided in this embodiment includes:

[0081] Module 401 is used to obtain approved change implementation plan applications and corresponding change elements from the change process system.

[0082] Processing module 402 is used to create a dedicated application container for the change implementer specified in the change implementation plan application before the change implementation window corresponding to the change implementation plan application is started, based on the change elements. The dedicated application container is bound to the change implementer and the change task corresponding to the change implementation plan application.

[0083] The processing module 402 is also used to grant access permissions to the exclusive application container to the change implementer within the change implementation window;

[0084] The processing module 402 is also used to determine whether the preset container destruction conditions are met based on the execution status of the change task and the lifecycle of the change implementation window; if they are met, the exclusive application container is destroyed.

[0085] Optionally, the processing module 402 is also used to determine the change implementation window based on the implementation time specified in the change implementation plan application;

[0086] The creation of a dedicated application container is triggered after a first preset time before the start of the change implementation window.

[0087] Optionally, the processing module 402 is further configured to bind the access permissions and network address of the exclusive application container to the user identity information of the change implementer, the task identifier of the change task, and the network address of the terminal used by the change implementer before granting the change implementer access permissions to the exclusive application container.

[0088] Optionally, the processing module 402 is further configured to execute container reuse decision logic before creating a new dedicated application container based on the change task, or when determining whether preset container destruction conditions are met based on the execution status of the change task and the lifecycle of the change implementation window; wherein the container reuse decision logic includes:

[0089] If the same change implementer has multiple change tasks to be executed, then determine whether the change implementation windows corresponding to the multiple change tasks are consecutive or overlapping;

[0090] If the change implementation windows corresponding to multiple change tasks are consecutive or overlap, then a reuse operation will be performed.

[0091] Optionally, the processing module 402 is also configured to reuse the same existing or pending dedicated application container for the current change task and other change tasks before creating a new dedicated application container based on the change task.

[0092] Based on the execution status of the change task and the lifecycle of the change implementation window, when determining whether the preset container destruction conditions are met, the destruction of the existing dedicated application container is delayed so that it can be used to execute other change tasks.

[0093] Optionally, the preset container destruction conditions include at least one of the following:

[0094] The change task has been completed and the change implementation window has closed.

[0095] The change task has been completed, and the time elapsed since the start of the next change implementation window for the same change task belonging to the same change implementer has exceeded the second preset time.

[0096] Optionally, the processing module 402 is also configured to automatically invalidate the network access permissions bound to the dedicated application container after the dedicated application container is destroyed.

[0097] Optionally, the processing module 402 is also used to monitor network access requests to the dedicated application container in real time when the dedicated application container is running within the change implementation window.

[0098] By analyzing the access patterns of monitored network connection requests, it is possible to identify whether port scanning behavior exists. Port scanning behavior refers to making more than a preset number of connection attempts from the same network address to multiple different ports of the application container within a preset time period.

[0099] If port scanning behavior is detected and the port scanning behavior originates from an unauthorized network address, a security alert will be triggered.

[0100] The authentication device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0101] Figure 5 A schematic diagram of the structure of the electronic device provided in this application. Figure 5 As shown, the electronic device 50 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus 504.

[0102] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.

[0103] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0104] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0105] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0106] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0107] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0108] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0109] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0110] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0111] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0112] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0113] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.

[0114] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.

[0115] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.

[0116] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0117] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.

[0118] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0119] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. An authentication method, characterized in that, include: Obtain the approved change implementation plan application and corresponding change elements from the change process system; Based on the change elements, before the change implementation window corresponding to the change implementation plan application is launched, a dedicated application container is created for the change implementer specified in the change implementation plan application, wherein the dedicated application container is bound to the change implementer and the change task corresponding to the change implementation plan application; Within the change implementation window, grant the change implementer access to the dedicated application container; Based on the execution status of the change task and the lifecycle of the change implementation window, determine whether the preset container destruction conditions are met; if so, destroy the exclusive application container.

2. The method according to claim 1, characterized in that, Before the change implementation window corresponding to the change implementation plan application is launched, a dedicated application container is created for the change implementation personnel specified in the change implementation plan application, specifically including: The change implementation window is determined based on the implementation time specified in the change implementation plan application; The creation of the exclusive application container is triggered after a first preset time period prior to the start time of the change implementation window.

3. The method according to claim 1, characterized in that, Also includes: Before granting the change implementer access to the dedicated application container, the access permissions and network address of the dedicated application container are bound to the change implementer's user identity information, the task identifier of the change task, and the network address of the terminal used by the change implementer.

4. The method according to claim 1, characterized in that, Also includes: Before creating a new dedicated application container based on the change task, or when determining whether preset container destruction conditions are met based on the execution status of the change task and the lifecycle of the change implementation window, container reuse decision logic is executed; wherein, the container reuse decision logic includes: If the same change implementer has multiple change tasks to be executed, then determine whether the change implementation windows corresponding to the multiple change tasks are consecutive or overlapping; If the change implementation windows corresponding to the multiple change tasks are consecutive or overlap, a reuse operation is performed.

5. The method according to claim 4, characterized in that, Performing reuse operations specifically includes: Before creating a new dedicated application container based on the change task, reuse the same existing or pending dedicated application container for the current change task and other change tasks. Based on the execution status of the change task and the lifecycle of the change implementation window, if it is determined whether the preset container destruction conditions are met, the destruction of the existing dedicated application container is delayed so that it can be used to execute other change tasks.

6. The method according to claim 1, characterized in that, The preset container destruction conditions include at least one of the following: The change task is completed and the change implementation window closes; The change task is completed, and the time elapsed since the start of the next change implementation window for the same change task belonging to the same change implementer exceeds the second preset time.

7. The method according to claim 1, characterized in that, Also includes: After the dedicated application container is destroyed, the network access permissions bound to the dedicated application container are automatically invalidated.

8. The method according to claim 1, characterized in that, Also includes: Within the change implementation window, when the dedicated application container is running, network access requests to the dedicated application container are monitored in real time. By analyzing the access patterns of monitored network connection requests, it is possible to identify whether port scanning behavior exists; wherein, the port scanning behavior refers to initiating more than a preset number of connection attempts from the same network address to multiple different ports of the application container within a preset time period; If port scanning behavior is detected and the port scanning behavior originates from an unauthorized network address, a security alert is triggered.

9. An identity verification device, characterized in that, include: The acquisition module is used to acquire approved change implementation plan applications and corresponding change elements from the change process system; The processing module is used to create a dedicated application container for the change implementer specified in the change implementation plan application before the change implementation window corresponding to the change implementation plan application is started, based on the change elements. The dedicated application container is bound to the change implementer and the change task corresponding to the change implementation plan application. The processing module is also used to grant the change implementer access rights to the exclusive application container within the change implementation window; The processing module is further configured to determine whether preset container destruction conditions are met based on the execution status of the change task and the lifecycle of the change implementation window; if met, the exclusive application container is destroyed.

10. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 8.

12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 8.