A password dynamic management method, device and equipment in operation and maintenance management work and a storage medium
By constructing a cryptographic instance set and management system model, the problems of shared untraceability, plaintext storage, lack of hierarchical policies, and asynchronous operation with external systems in cryptographic management are solved, achieving efficient and secure unified cryptographic management and business continuity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- STATE GRID HUNAN ELECTRIC POWER COMPANY LIMITED
- Filing Date
- 2026-05-27
- Publication Date
- 2026-07-31
AI Technical Summary
Existing technologies for password management suffer from problems such as shared and untraceable passwords, plaintext storage and transmission, lack of hierarchical strategies, lack of hierarchical permissions, rampant weak passwords, asynchronous credentials from external systems, and lack of a unified management platform. These issues lead to high security risks, difficulty in tracing incidents, low update efficiency, and business interruptions.
By constructing a set of cryptographic instances, generating a set of encapsulated cryptographic instances, and generating a cryptographic management system model based on the encapsulated cryptographic instances, a decentralized audit, encryption protection, real-time synchronization, and compliance detection are implemented to achieve unified management and automated operation of cryptography.
It improves the efficiency of batch updates and the accuracy of unified management, enhances the confidentiality and security of passwords, ensures decentralized control, guarantees password compliance and business continuity, and supports automated auditing and panoramic visualization management.
Smart Images

Figure CN122293437B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer information security, and in particular to a method, apparatus, device, and storage medium for dynamic password management in operation and maintenance. Background Technology
[0002] Password management faces numerous challenges in information system operation and maintenance. First, password sharing and lack of traceability: multiple users sharing the same account password makes it difficult to clarify operational responsibility; in case of data misoperation or damage, it's hard to pinpoint the responsible party. Second, plaintext storage and transmission of passwords pose a risk of leakage: passwords stored in plaintext in maintenance documents or scripts are easily intercepted; the lack of encrypted storage mechanisms allows attackers to easily obtain core system credentials; once leaked, the threat is widespread and can easily lead to security incidents. Third, the lack of a hierarchical password strategy results in excessively broad or concentrated permissions: all personnel use the same level of password permissions, violating the principle of least privilege; the absence of password security management that differentiates between resources of different importance levels makes risk isolation ineffective; high-risk operations such as password recovery and export lack permission distinctions, making them prone to abuse. Furthermore, weak passwords are rampant, and password usage is non-compliant: the system allows simple passwords (such as admin / 123456), lacking complexity control; passwords are not changed for extended periods, leading to reuse issues; and during security level protection and internal audits, frequent notices or rectification orders are issued due to weak passwords or compliance problems. Furthermore, the lack of synchronization between credentials and external systems causes business interruptions: changes to server passwords are not synchronized with the monitoring system, leading to monitoring failure; reliance on manual updates carries risks of delays and errors; and a malfunctioning alarm system prevents the timely detection of critical events, compromising business continuity. Finally, the lack of a unified management platform results in scattered and uncontrolled passwords: passwords are stored in Excel, WeChat, Notepad, and other channels, making centralized management impossible; multiple people maintain passwords, leading to inconsistent standards and information chaos; new employees have difficulty accessing passwords, while departing employees still possess them, posing significant security risks.
[0003] Currently, the aforementioned password management issues are typically handled manually or through simple scripts, lacking a systematic, automated, and secure mechanism. This results in inefficiency, significant security risks, and an inability to meet corporate audit and compliance requirements. Summary of the Invention
[0004] The main objective of this invention is to provide a method, apparatus, device, and storage medium for dynamic password management in operation and maintenance management, aiming to solve the technical problems in existing operation and maintenance management, such as high security risks, difficulty in tracing incidents, low password update efficiency, and business interruption caused by asynchronous credentials from external systems due to scattered password storage, plaintext transmission, and lack of reliable hierarchical strategies.
[0005] To achieve the above objectives, this invention provides a method for dynamic password management in operation and maintenance management, the method comprising the following steps: Obtain multiple password items from the target operation and maintenance management scenario, including network device password resources and server password resources; A set of cryptographic instances is constructed based on multiple cryptographic items. The set of cryptographic instances includes multiple cryptographic instances, and each cryptographic instance carries basic attributes and auxiliary attributes. A set of encapsulated cryptographic instances is generated based on each cryptographic instance in the set of cryptographic instances. The set of encapsulated cryptographic instances includes multiple encapsulated cryptographic instances, and each encapsulated cryptographic instance represents an object after abstracting and encapsulating the cryptographic instance. A password management system model is generated based on the functional attributes of each encapsulated password instance in the encapsulated password instance set. The password management system model is configured to manage the relationships between each encapsulated password instance. The relationships include group update relationships, password binding relationships, encryption protection relationships, hierarchical audit relationships, and real-time synchronization relationships. Based on the password management system model, password management operations are performed on the password instance to generate operation results and compliance reports. The password management operations include password update operations, password eviction operations, compliance detection operations, and external credential synchronization operations.
[0006] Optionally, constructing a set of cryptographic instances based on multiple cryptographic items includes: Generate resource identification information, credential data, and permission configuration information corresponding to each password item; The basic attributes of the password instance are generated based on the resource identification information, the credential data, and the permission configuration information. The basic attributes include the password name, associated resource, and access permissions. The associated attributes of the password instance are generated based on the preset security policy configuration rules. The associated attributes include binding script attributes, random key attributes, role model attributes, weak password library attributes, status verification attributes, and scheduling mechanism attributes. A password instance is generated based on the basic attribute and the auxiliary attribute, and a password instance set is generated based on multiple password instances.
[0007] Optionally, generating an encapsulated cryptographic instance set based on each cryptographic instance in the cryptographic instance set includes: A first encapsulated object with bound script attributes is generated based on the preset password group configuration rules and password instances; Based on the preset encryption mechanism configuration rules and the first encapsulation object, a second encapsulation object with encryption protection function is generated. The second encapsulation object includes random key parameters and encryption algorithm parameters. Based on the preset permission control configuration rules and the second encapsulated object, a third encapsulated object with the function of hierarchical auditing is generated. The third encapsulated object is associated with role model data and audit log template. Based on the preset compliance detection configuration rules and the third encapsulation object, a fourth encapsulation object with compliance verification function is generated. The fourth encapsulation object loads the weak password feature library and the historical record table. A set of encapsulated password instances is generated based on the fourth encapsulation object, and a set of encapsulated password instances is generated based on all encapsulated password instances.
[0008] Optionally, generating the cryptographic management system model based on the functional attributes of each encapsulated cryptographic instance in the encapsulated cryptographic instance set includes: Generate script identification information based on each encapsulated cryptographic instance in the encapsulated cryptographic instance set; Generate a subset of target encapsulated cryptographic instances based on multiple encapsulated cryptographic instances with the same script identification information; Based on the target encapsulated cryptographic instance subset, generate group update identifiers and group binding configuration information; Based on the group binding configuration information, generate the association links between each target encapsulation cryptographic instance in the target encapsulation cryptographic instance subset; A group update relationship is generated based on the associated link and the group update identifier; Based on the binding script attributes of the encapsulated cryptographic instance, a group update relationship is generated between multiple target encapsulated cryptographic instances with the same batch update requirement; Based on the group update relationship, generate password binding relationship data between multiple target encapsulated password instances and nodes in the same password group; Based on the random key attributes and encryption algorithm parameters of the encapsulated cryptographic instance, generate encryption protection relationship data between the source cryptographic instance and the target cryptographic instance; Based on the role model attributes and audit log template of the encapsulated password instance, generate the hierarchical audit relationship data between the access subject instance and the accessed password instance; A password management system model is generated based on the password binding relationship data, the encryption protection relationship data, and the decentralized audit relationship data.
[0009] Optionally, the step of performing password management operations on the password instance based on the password management system model and generating operation results and compliance reports includes: Based on the group update relationship in the password management system model, generate password update records for multiple password instances associated with password group nodes; Based on the hierarchical audit relationship in the password management system model, the permission operation log and revoke status information of the password instance are generated; Compliance test result data for password instances is generated based on a preset compliance policy form; Based on the real-time synchronization relationship in the password management system model, generate synchronization status data between password instances and external system credentials; Based on the preset report template configuration information, the password update record, the permission operation log, and the recycling status information, an operation log summary data is generated; Based on the compliance test results data, a compliance statistical chart is generated, and based on the compliance statistical chart data and the operation log summary data, the main body of the report is generated; Based on the synchronization status data, business continuity assessment information is generated, and based on the business continuity assessment information and the report content, enhanced report content is generated. A compliance report is generated based on the preset scheduling mechanism attributes and the enhanced report content; An operation result is generated based on the password update record, the permission operation log, the revocation status information, the compliance detection result data, and the synchronization status data, and the operation result is associated with the compliance report.
[0010] Optionally, the compliance detection result data of the password instance generated based on the preset compliance policy form includes: The first policy rule corresponding to the attribute information is obtained by querying the preset compliance policy form based on the attribute information of the source cryptographic instance. Based on the first strategy rule, the usage record of the source password instance is obtained from the historical record table. Based on the usage record, it is determined whether the source password instance has a weak password mark. If there is no weak password mark, a detection threshold is generated based on the complexity table. If the first policy rule does not meet the target compliance requirements, a second policy rule is obtained from the compliance policy form based on the detection threshold, and a compliance path query result is generated based on the second policy rule. Based on the compliance path query results, iteratively query the next-hop policy rules until the target compliance requirement is matched, and generate the actual matching path between the source cryptographic instance and the target compliance requirement based on all the policy rules obtained from the query. Based on the actual matching path, the weak password marker, and the detection threshold, the compliance detection result data of the password instance is generated.
[0011] Optionally, generating synchronization status data between the password instance and external system credentials based on the real-time synchronization relationship in the password management system model includes: The existence determination result of the synchronization node is generated based on the interface identifier of the external credentials; When the existence determination result of the synchronization node indicates that the synchronization node information does not exist, a direct connection synchronization state is generated based on the password instance and the external credentials. When the existence determination result of the synchronization node indicates that the synchronization node information exists, a verification status parameter and the interface of the next hop synchronization node are generated based on the synchronization node information. A synchronization node path is generated based on the next-hop synchronization node interface, and the synchronization node path contains all the queried synchronization nodes; Synchronization status data is generated based on the direct connection synchronization status or the synchronization node path.
[0012] Furthermore, to achieve the above objectives, the present invention also proposes a password dynamic management device for operation and maintenance management that applies the password dynamic management method described above. The password dynamic management device for operation and maintenance management includes: The password acquisition module is used to acquire multiple password items in the target operation and maintenance management scenario, including network device password resources and server password resources. An instance construction module is used to construct a set of cryptographic instances based on multiple cryptographic items. The set of cryptographic instances includes multiple cryptographic instances, and each cryptographic instance carries basic attributes and auxiliary attributes. An instance encapsulation module is used to generate an encapsulated cryptographic instance set based on each cryptographic instance in the cryptographic instance set. The encapsulated cryptographic instance set includes multiple encapsulated cryptographic instances, and each encapsulated cryptographic instance represents an object after abstracting and encapsulating the cryptographic instance. The cryptographic modeling module is used to generate a cryptographic management system model based on the functional attributes of each encapsulated cryptographic instance in the encapsulated cryptographic instance set. The cryptographic management system model is configured to manage the relationships between each encapsulated cryptographic instance, including group update relationships, cryptographic binding relationships, encryption protection relationships, hierarchical audit relationships, and real-time synchronization relationships. The management execution module is used to perform password management operations on the password instance based on the password management system model, and generate operation results and compliance reports. The password management operations include password update operations, password eviction operations, compliance detection operations, and external credential synchronization operations.
[0013] Furthermore, to achieve the above objectives, this application also proposes a password dynamic management device for operation and maintenance management. The device includes: a memory, a processor, and a password dynamic management program for operation and maintenance management stored in the memory. The processor is used to run the password dynamic management program for operation and maintenance management. The computer program is configured to implement the steps of the password dynamic management method for operation and maintenance management as described above.
[0014] In addition, to achieve the above objectives, this application also proposes a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the dynamic password management method in the operation and maintenance management work described above.
[0015] The present invention has the following technical effects: Improve batch update efficiency and unified management accuracy: This invention combines and encapsulates scripts with multiple password instances through a "password group" mechanism to achieve one-click batch password updates, effectively solving the problem of password dispersion and loss of control, significantly improving batch update efficiency, avoiding manual configuration omissions, ensuring the uniformity and accuracy of multi-instance password management, and reducing operation and maintenance costs.
[0016] Enhancing the confidentiality of passwords throughout their entire lifecycle: This invention employs a random key combination mechanism, requiring dual authentication using both ciphertext and dynamic keys during the decryption process. This effectively prevents the risk of plaintext password storage and transmission leakage, ensuring that even if data is leaked, the password cannot be directly recovered. This safeguards the confidentiality and security of passwords throughout their entire lifecycle and blocks attackers from obtaining core credentials using leaked data.
[0017] Strengthening decentralized management and operational traceability: This invention implements a super administrator permission isolation and dual audit mechanism, restricting highly sensitive operations such as password backup and recovery to be initiated only by the super administrator and subject to audit authorization. This effectively solves the problem of excessive or overly centralized permissions, implements the principle of least privilege, achieves full traceability of the operation process, avoids the risk of permission abuse, and enhances the level of precision in decentralized management.
[0018] Ensuring password compliance and security baseline: This invention introduces a system-level weak password interception and historical detection mechanism. It actively identifies and intercepts weak passwords through a built-in weak password database, while recording historical usage to prevent password reuse. This effectively solves the problems of rampant weak passwords and non-compliant password use, achieves password complexity control and compliance detection, meets audit requirements, and improves the overall security baseline of the system.
[0019] Ensuring consistency of external credentials and business continuity: This invention constructs a closed-loop mechanism for real-time synchronization and status verification. After a password update, it automatically triggers the synchronization of external system credentials and performs status verification, effectively solving the business interruption problem caused by the lack of synchronization of external system credentials, ensuring the consistency of configuration status and business continuity, avoiding the delay and misoperation risks caused by manual synchronization, and ensuring the effectiveness of the monitoring and alarm system.
[0020] Achieving automated auditing and panoramic visualization management: This invention supports the automatic generation of regular compliance reports based on a built-in scheduling mechanism, and realizes the automated summarization and generation of report content through policy forms, effectively solving the problem of lack of unified management and compliance reports. It provides chart display and data export functions that meet audit requirements, supports panoramic visualization of operation and maintenance password management, and improves auditing efficiency and management transparency. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a schematic diagram of the structure of the password dynamic management device in the operation and maintenance management of the hardware operating environment involved in the embodiments of the present invention; Figure 2 This is a flowchart illustrating the first embodiment of the dynamic password management method in the operation and maintenance management of the present invention. Figure 3 This is a schematic diagram of the password dynamic management process in one embodiment of the password dynamic management method in the operation and maintenance management of the present invention; Figure 4 This is a diagram of the password management system model structure in one embodiment of the password dynamic management method in the operation and maintenance management of the present invention; Figure 5 This is a flowchart illustrating the second embodiment of the dynamic password management method in the operation and maintenance management of the present invention. Figure 6 This is a flowchart illustrating the third embodiment of the dynamic password management method in the operation and maintenance management of the present invention. Figure 7 This is a flowchart illustrating the fourth embodiment of the dynamic password management method in the operation and maintenance management of the present invention. Figure 8 This is a flowchart illustrating the fifth embodiment of the dynamic password management method in the operation and maintenance management of the present invention. Figure 9 This is a structural block diagram of the first embodiment of the password dynamic management device in the operation and maintenance management of the present invention.
[0023] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0024] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.
[0025] Reference Figure 1 , Figure 1 This is a schematic diagram of the structure of the password dynamic management device in the operation and maintenance management of the hardware operating environment involved in the embodiments of the present invention.
[0026] like Figure 1 As shown, the password dynamic management device in this operation and maintenance management work may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen and an input unit such as a keyboard. The user interface 1003 may also include standard wired interfaces and wireless interfaces. The network interface 1004 may optionally include standard wired interfaces and wireless interfaces (such as Wireless-Fidelity (Wi-Fi) interfaces). The memory 1005 may be high-speed random access memory (RAM) or stable non-volatile memory (NVM), such as a disk storage device. The memory 1005 may also optionally be a storage device independent of the aforementioned processor 1001.
[0027] Those skilled in the art will understand that Figure 1 The structure shown does not constitute a limitation on the dynamic password management device in operation and maintenance management. It may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0028] like Figure 1 As shown, the memory 1005, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a password dynamic management program for operation and maintenance.
[0029] exist Figure 1 In the password dynamic management device shown in the operation and maintenance management work, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and memory 1005 in the password dynamic management device in the operation and maintenance management work of the present invention can be set in the password dynamic management device in the operation and maintenance management work. The password dynamic management device in the operation and maintenance management work calls the password dynamic management program in the operation and maintenance management work stored in the memory 1005 through the processor 1001 and executes the password dynamic management method in the operation and maintenance management work provided in the embodiment of the present invention.
[0030] This invention provides a method for dynamic password management in operation and maintenance management, referring to... Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the dynamic password management method in the operation and maintenance management of the present invention.
[0031] In this embodiment, the dynamic password management method in the operation and maintenance management work includes the following steps: Step S10: Obtain multiple password items in the target operation and maintenance management scenario, including network device password resources and server password resources.
[0032] It should be understood that the executing entity of this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or a terminal electronic device capable of performing the above functions. The following description uses a password dynamic management device (hereinafter referred to as password management device) in operation and maintenance management as an example to illustrate this embodiment and the following embodiments.
[0033] It should be noted that the password item refers to the original credential data unit collected or entered in the operation and maintenance management scenario, which includes authentication information used to access specific resources and their associated resource identifiers.
[0034] Network device cryptographic resources can be account credential data used to authenticate network infrastructure devices such as routers, switches, firewalls, and load balancers.
[0035] Server password resources can be credential data used to authenticate physical servers, virtual servers, operating system accounts, database instances, and application service accounts.
[0036] Understandably, password management devices can collect password items from external sources (such as operation and maintenance logs or device APIs), convert them into system instances, and label their basic attributes. Through data mapping and import, instance uniqueness is ensured. Addressing the issues of untraceable password sharing and excessive permissions in existing solutions, this step introduces instance-based management, with each password item independently identified, facilitating subsequent traceability and access control.
[0037] In its implementation, the password management device can scan device nodes within the target network range through a preset device discovery protocol or application programming interface, read device configuration files, or call authentication service interfaces to obtain login credential information; receive server account information and corresponding authentication credentials entered by the administrator through the management interface, or import credential data from existing operation and maintenance logs and asset databases; perform format verification and deduplication on the obtained credential information, identify the device type and resource identifier to which the credential belongs, generate password item data containing resource type tags, and temporarily store the password items in a pending queue for subsequent instantiation.
[0038] Step S20: Construct a set of cryptographic instances based on multiple cryptographic items.
[0039] It should be noted that a password instance refers to an entity object generated internally by object-oriented modeling of a password item. It has a unique identifier and encapsulates attribute data and operation interfaces.
[0040] The set of cryptographic instances includes multiple cryptographic instances, each carrying basic attributes and auxiliary attributes.
[0041] Basic attributes refer to the fundamental information fields used for identification and management in a password instance, including password name, associated resource identifier, and access permission level.
[0042] Additional attributes refer to configuration fields in a cryptographic instance used to extend security functions and management capabilities, including binding script attributes, random key attributes, role model attributes, weak password library attributes, status verification attributes, and scheduling mechanism attributes.
[0043] In its implementation, the password management device assigns a unique instance identifier to each password item and creates a corresponding password instance object in memory or persistent storage. It maps and populates the resource identifier, credential data, and permission configuration information from the password item into the basic attribute fields of the password instance, completing the structured storage of basic information. Based on preset security policy templates and operational requirements, it dynamically loads auxiliary attribute configurations for each password instance, including binding script identifiers, random key parameters, encryption algorithm selection, role-based permission model references, weak password detection rule references, status verification flags, and scheduling cycle parameters. All initialized password instance objects are aggregated and stored in the instance database, forming a structured collection of password instances, and an instance index is established to support fast retrieval.
[0044] Step S30: Generate a set of encapsulated cryptographic instances based on each cryptographic instance in the set of cryptographic instances.
[0045] It should be noted that the encapsulated cryptographic instance set includes multiple encapsulated cryptographic instances, and each encapsulated cryptographic instance represents an object after the cryptographic instance has been abstracted and encapsulated.
[0046] In the specific implementation, the password management device calls the encapsulation processing module to traverse the password instance set, read the basic and auxiliary attributes of each password instance, generate corresponding functional interfaces, and bind preset object methods to the instances; based on the bound script attribute, the batch update method is injected into the password instances to generate a first encapsulation layer with script execution capability; based on the random key attribute and encryption algorithm attribute, the encryption protection module is loaded to generate a second encapsulation layer with dual authentication and decryption function, and the key parameters and algorithm logic are hidden inside the encapsulation; based on the role model attribute and audit log attribute, the access control module is loaded to generate a hierarchical audit encapsulation layer, realizing the automatic binding of access control and log recording; the functional encapsulation layers of compliance detection, synchronization mechanism and report generation are sequentially superimposed to output an encapsulated password instance containing complete functional logic and security protection mechanism, finally forming a set of encapsulated password instances.
[0047] Step S40: Generate a cryptographic management system model based on the functional attributes of each encapsulated cryptographic instance in the encapsulated cryptographic instance set.
[0048] It should be noted that the cryptographic management system model can be a structured model composed of encapsulated cryptographic instances and their relationships, used to represent the functional dependencies and management logic between cryptographic instances. The cryptographic management system model is configured to manage the relationships between each encapsulated cryptographic instance, including group update relationships, cryptographic binding relationships, encryption protection relationships, hierarchical auditing relationships, and real-time synchronization relationships.
[0049] It should be noted that the group update relationship refers to the association established between multiple encapsulated password instances and the password group node by sharing the same binding script, which is used to support batch password update operations.
[0050] Password binding relationship refers to the hierarchical association between encapsulated password instances and password group nodes, which is used to realize the group management and unified scheduling of instances.
[0051] Encryption protection relationship refers to the association established between the source cryptographic instance and the target cryptographic instance based on key dependency and encryption algorithm, which is used to ensure the confidentiality and integrity of cryptographic data.
[0052] Decentralized auditing relationship refers to the association established based on role models and audit rules between the accessing subject instance and the accessed password instance, which is used to achieve permission isolation and operation traceability.
[0053] Real-time synchronization refers to the association established between a password instance and an external system credential node based on interface configuration and verification mechanisms, which is used to ensure the consistency of internal and external credentials.
[0054] In its implementation, the cryptographic management device traverses the set of encapsulated cryptographic instances, identifies multiple encapsulated cryptographic instances with the same binding script identifier, establishes cryptographic binding relationships between these instances and nodes in the same cryptographic group, and generates group update relationship links to support batch operations. Based on the key dependency information and encryption algorithm parameters in the cryptographic protection attributes, it establishes cryptographic protection relationship edges between the source cryptographic instance and the target cryptographic instance, defining the association path between ciphertext and key. It parses the role model attributes and audit log templates, constructs a hierarchical audit relationship mapping between the access subject instance and the accessed cryptographic instance, and clarifies the permission boundaries and audit responsibilities. It detects the external system interface configuration and verification rules in the synchronization mechanism attributes, establishes a real-time synchronization relationship path between the cryptographic instance and the external credential node, and configures a status feedback mechanism. Finally, it integrates all identified relationship data to construct a cryptographic management system model in the form of a graph structure or relationship table containing nodes and edges, used for global management of the association logic between instances.
[0055] In some embodiments, a password management system model is established to store multiple password instances of different types, and to perform encrypted storage and visual management of each password instance. The password instance includes the attributes of each password and the relationships between the passwords. The system model is initialized, taking operational requirements (such as password type and security requirements) as input and outputting an encrypted set of instances. This step works by achieving data persistence through an underlying database (such as a relational or graph database), supporting a visual interface to display node attributes and relationships. Addressing the lack of a unified management platform and the problem of scattered and uncontrolled passwords in existing solutions, this step provides a centralized management mechanism, avoiding the storage of passwords in dispersed channels such as Excel and WeChat, ensuring quick access for new employees and revocation of permissions for departing employees, reducing information chaos and security risks.
[0056] Step S50: Perform password management operations on the password instance based on the password management system model, and generate operation results and compliance reports.
[0057] It should be noted that the password management operations include password update operations, password eviction operations, compliance detection operations, and external credential synchronization operations.
[0058] Password management operations refer to a series of management actions performed on password instances based on the password management system model, including functional operations such as updating, recycling, testing, and synchronization.
[0059] Password update operation refers to the process of modifying the credential value of a password instance by calling the bound script or interface, and synchronously updating the associated system.
[0060] Password eviction refers to the process of revoking permissions, marking status, and generating audit logs for password instances that are no longer in use or need to be revoked.
[0061] Compliance testing refers to the process of identifying weak passwords, verifying complexity, and detecting historical reuse of password instances in accordance with compliance policies.
[0062] External credential synchronization refers to the process of publishing changes to password instances to external systems and verifying the synchronization status.
[0063] A compliance report is a structured document that summarizes the results of password management operations, compliance test results, and synchronization status information, and is used for auditing and visualization.
[0064] In its implementation, the password management device responds to password update commands, locates all encapsulated password instances associated with the target password group through the group update relationship in the password management system model, calls the bound script to perform batch password modifications, and records operation logs and update status. When executing the password eviction process, it verifies the permission level of the operating subject based on the hierarchical audit relationship, triggers the status change method of the encapsulated password instance, generates eviction credentials, and updates the audit record. It initiates a compliance detection task, loads the weak password library attribute and historical record attribute, performs complexity matching and historical reusability verification on the encapsulated password instances, and generates compliance judgment results and rectification suggestions based on the compliance policy form. It monitors password change events, pushes update information to the external system credential node through real-time synchronization relationship path, executes status verification methods to confirm successful synchronization, and handles abnormal situations. It summarizes operation logs, compliance judgment results, eviction status, and synchronization status data, and generates a compliance report containing statistical charts, detailed data, and business continuity assessment information according to the preset report template and scheduling mechanism attributes.
[0065] It should be noted that this embodiment is applied to dynamic password management in operation and maintenance management scenarios. It aims to achieve password authority-based, encryption, update, retrieval, and compliant management through dynamic password updates and retrieval during operation and maintenance management. (Refer to...) Figure 3 and Figure 4 , Figure 3 This is a flowchart illustrating the dynamic password management process. Figure 4 This is a diagram illustrating the structure of a password management system model, showing the attributes, relationships, and object method encapsulation of password instances.
[0066] like Figure 3 As shown, the overall process of the method of the present invention starts from the establishment of a password management system, and gradually proceeds to abstraction and encapsulation, association establishment, and final update, recycling and display, forming a closed-loop management. Figure 3In the code, each step is connected by arrows to indicate the data flow; the starting node is "Establish Password Management System" and the ending node is "Password Update, Revocation, and Report Display," with key inputs and outputs marked in between, such as "Password Item Attribute Configuration" and "Compliance Policy Query." The code allows adjusting the order of steps or adding branch conditions (such as rollback when permission verification fails).
[0067] like Figure 4 As shown, the password management system model structure diagram adopts a layered design. The upper layer consists of object-oriented encapsulated password item instances (represented by rectangular nodes, such as "Password Group" and "Encryption Mechanism"), while the lower layer consists of relational attributes (connected by arrow lines, such as "Group Update" and "Encryption Protection"), with inheritance relationships and attribute lists labeled. This structure diagram is editable and supports the expansion of new attributes or relationships to adapt to different operational scenarios.
[0068] This embodiment constructs a password management system model and implements abstract encapsulation and multi-dimensional relationship management, realizing centralized modeling and automated full lifecycle control of operation and maintenance password resources. It effectively solves the security risks and management chaos caused by decentralized password storage, improves the execution efficiency and accuracy of batch updates, compliance testing and external synchronization, reduces manual maintenance costs and operational risks, and enhances the traceability and data confidentiality of the system through decentralized auditing and encryption protection mechanisms, thereby ensuring the overall security, compliance and business continuity of operation and maintenance management.
[0069] refer to Figure 5 , Figure 5 This is a flowchart illustrating the second embodiment of the dynamic password management method in the operation and maintenance management of the present invention.
[0070] Based on the first embodiment described above, in this embodiment, step S20 further includes: Step S201: Generate resource identification information, credential data and permission configuration information corresponding to each password item.
[0071] It should be noted that resource identification information refers to data information used to uniquely identify target operation and maintenance resources, including network address, device serial number, host identifier or resource code.
[0072] Credential data refers to the original data content used for identity authentication, including account name, password string, digital certificate data, or token information.
[0073] Permission configuration information refers to configuration data that describes the permission level, operation scope, and role tags associated with password items, and is used to map the system's internal access control policies.
[0074] In the specific implementation, the password management device parses the original data of each password item, extracts the network address, device serial number or host identifier of the target resource, and generates unique resource identifier information; reads the authentication credential content in the password item, including account name, password string and digital certificate data, and generates credential data; analyzes the permission description information or role tag associated with the password item, maps it to the permission level and operation scope parameters defined internally by the system, and generates permission configuration information.
[0075] Step S202: Generate the basic attributes of the password instance based on the resource identification information, the credential data, and the permission configuration information.
[0076] It should be noted that the basic attributes include password name, associated resource, and access permissions.
[0077] In its implementation, the password management device assigns resource identification information to the associated resource field of the password instance, establishing a binding relationship between the password instance and the target resource; it generates a password name based on the combination of the account name and resource identification information in the credential data, and stores the credential data in the credential storage field of the password instance after processing it with an encryption algorithm; it maps the permission configuration information to the access permission field, defining the types of operations and access levels that the password instance is allowed to perform, thereby generating basic attributes that include the password name, associated resource, and access permissions.
[0078] Step S203: Generate the auxiliary attributes of the password instance based on the preset security policy configuration rules.
[0079] It should be noted that the aforementioned auxiliary attributes include binding script attributes, random key attributes, role model attributes, weak password library attributes, status verification attributes, and scheduling mechanism attributes.
[0080] Script binding attributes: refers to the configuration information associated with the batch update script, including script identifier, execution parameters and calling interface, to support unified update operations for multiple instances.
[0081] The random key attribute refers to the configuration information associated with the dynamic key generation and encryption algorithm, including random key parameters, key lifecycle and algorithm identifier, which is used to implement a dual authentication decryption mechanism.
[0082] Role model attributes refer to the data information associated with the role permission model, including role definitions, minimum permission rules, and operation subject restrictions, which are used to realize decentralized management and audit authorization.
[0083] The weak password database attribute refers to the configuration information associated with weak password detection rules, including weak password feature database references, complexity thresholds, and historical detection rules, which are used to achieve proactive interception and compliance verification.
[0084] Status verification attributes refer to the configuration information associated with external systems for synchronous verification, including interface verification parameters, status feedback mechanisms, and exception handling rules, which are used to ensure credential consistency and business continuity.
[0085] The scheduling mechanism attributes refer to the configuration information associated with scheduled tasks and report generation, including execution cycle, trigger conditions, and report template parameters, which are used to achieve automated audit output.
[0086] In its implementation, the password management device loads preset security policy configuration rules and matches corresponding policy templates based on the resource type and permission level of the password instance. Based on the batch update configuration in the policy template, it assigns binding script identifiers to the password instance and generates binding script attributes. It calls the key management module to generate dynamic random key parameters and associates these parameters with encryption algorithm identifiers to generate random key attributes. It loads role definition data according to the principle of least privilege to generate role model attributes. It loads weak password feature library references and historical detection rules to generate weak password library attributes. It configures external system interface verification parameters and status feedback mechanisms to generate status verification attributes. It sets periodic execution cycles and report generation trigger conditions to generate scheduling mechanism attributes.
[0087] Step S204: Generate a password instance based on the basic attribute and the auxiliary attribute, and generate a password instance set based on multiple password instances.
[0088] In the specific implementation, the password management device calls the instantiation interface to encapsulate the completed basic attributes and auxiliary attributes into the same object structure, generating a password instance with a unique instance identifier; it performs integrity verification and attribute conflict detection on the password instance to ensure the validity of the configuration data; it writes the verified password instance into the instance database and adds it to the instance index list in memory; it iterates through all password items to be processed, repeats the attribute construction and instantiation process, and finally aggregates all password instances to form a password instance set.
[0089] This embodiment transforms raw cryptographic items into structured cryptographic instances, achieving standardized modeling and centralized storage of cryptographic data. This eliminates information silos and data chaos caused by decentralized management, providing an accurate data foundation for subsequent unified management. By binding random keys, role models, and weak password libraries to auxiliary attributes during the instance construction phase, security policies are deeply coupled with cryptographic objects. This ensures that each cryptographic instance possesses encryption protection, permission isolation, and compliance detection capabilities from creation, improving the security of cryptographic storage and use from the source and reducing the risk of leakage and abuse. By configuring and binding script attributes and scheduling mechanism attributes, an execution foundation is laid for subsequent batch update operations and automated report generation, significantly improving operational efficiency and reducing manual intervention costs. By clearly defining associated resources and access permissions in basic attributes, a precise mapping relationship and permission boundaries between instances and resources are established, supporting precise traceability and decentralized control of operational responsibilities, enhancing system maintainability and audit compliance. At the same time, integrity verification and conflict detection mechanisms ensure the validity of instance data and improve system stability.
[0090] refer to Figure 6 , Figure 6 This is a flowchart illustrating the third embodiment of the dynamic password management method in the operation and maintenance management of the present invention.
[0091] Based on the above embodiments, in this embodiment, step S30 further includes: Step S301: Generate a first encapsulated object with bound script attributes based on the preset password group configuration rules and password instance.
[0092] It should be noted that the first encapsulated object refers to the intermediate encapsulated object generated after injecting the batch update script identifier on the basis of the password instance. It has the attribute of binding script and is used to support subsequent group-level batch operations.
[0093] In a specific implementation, the password management device reads preset password group configuration rules, which include a mapping relationship between group identifier conditions and script binding; based on the group identifier conditions, it matches the resource type or function tag of the password instance to determine the target password group to which the password instance belongs; based on the script binding mapping relationship, it obtains the batch update script identifier corresponding to the target password group and injects the batch update script identifier into the password instance; based on the password instance injected with the batch update script identifier, it generates a first encapsulated object with bound script attributes.
[0094] Step S302: Based on the preset encryption mechanism configuration rules and the first encapsulation object, generate a second encapsulation object with encryption protection function. The second encapsulation object includes random key parameters and encryption algorithm parameters.
[0095] It should be noted that the second encapsulated object refers to the intermediate encapsulated object generated by associating the dynamic random key parameters and encryption algorithm parameters with the first encapsulated object. It has encryption protection function and is used to realize dual authentication and decryption of cryptographic data.
[0096] Encryption mechanism configuration rules refer to configuration data that defines the random key generation strategy and encryption algorithm selection criteria, and are used to guide the generation and configuration of encryption parameters.
[0097] The random key parameter can be key data generated based on a dynamic generation strategy, used in conjunction with the ciphertext to achieve dual authentication and decryption, ensuring the dynamism and security of the key.
[0098] Encryption algorithm parameters can be configuration data that specifies the encryption algorithm type and operation mode, used to guide the encryption and decryption of cryptographic data.
[0099] In a specific implementation, the password management device loads a preset encryption mechanism configuration rule, which defines a random key generation strategy and an encryption algorithm selection criterion. Based on the random key generation strategy, the key management module is invoked to generate dynamic random key parameters, and the dynamic random key parameters are associated with the first encapsulation object. Based on the encryption algorithm selection criterion, target encryption algorithm parameters are determined, and the target encryption algorithm parameters are configured to the encryption interface of the first encapsulation object. Based on the first encapsulation object associated with the dynamic random key parameters and configured with the target encryption algorithm parameters, a second encapsulation object with encryption protection function is generated. The second encapsulation object contains random key parameters and encryption algorithm parameters.
[0100] Step S303: Based on the preset permission control configuration rules and the second encapsulated object, generate a third encapsulated object with the function of hierarchical auditing. The third encapsulated object is associated with role model data and audit log template.
[0101] It should be noted that the third encapsulated object refers to the intermediate encapsulated object generated after binding role model data and audit log template on the basis of the second encapsulated object. It has the function of hierarchical auditing and is used to implement role-based access control and operation log recording.
[0102] Access control configuration rules refer to configuration data that includes role permission mapping tables and audit log format specifications, used to guide role model binding and audit log association.
[0103] Role model data can be data information that defines the role's permission level and scope of operation, used to implement role-based access control and least privilege management.
[0104] An audit log template can be a data template that defines the format and field structure of audit log records. It is used to standardize the generation and storage of operation logs and ensure the integrity and traceability of log content.
[0105] In its implementation, the password management device parses preset access control configuration rules, which include a role-permission mapping table and an audit log format specification. Based on the role-permission mapping table, it obtains role model data matching the access permission level of the second encapsulated object and binds the role model data to the second encapsulated object. Based on the audit log format specification, it loads an audit log template and associates the audit log template with the operation interface of the second encapsulated object. Based on the second encapsulated object bound to the role model data and associated with the audit log template, it generates a third encapsulated object with hierarchical auditing functionality, and the third encapsulated object is associated with both the role model data and the audit log template.
[0106] Step S304: Based on the preset compliance detection configuration rules and the third encapsulation object, a fourth encapsulation object with compliance verification function is generated. The fourth encapsulation object loads the weak password feature library and the historical record table.
[0107] It should be noted that the fourth encapsulated object refers to the intermediate encapsulated object generated after configuring the weak password feature library reference and the historical record table association on the basis of the third encapsulated object. It has compliance verification function and is used to realize weak password interception and historical reuse detection.
[0108] The compliance detection configuration rules can be configuration data that specifies weak password detection standards and historical record tracking requirements, and are used to guide the configuration of compliance verification functions.
[0109] A weak password feature database is a collection of data that stores weak password pattern features and samples of illegal passwords. It is used to identify and intercept passwords that do not meet complexity requirements.
[0110] A history table is a data table that records the history of password usage and changes. It is used to detect password reuse and track the lifecycle of passwords.
[0111] In its implementation, the password management device reads preset compliance detection configuration rules, which specify weak password detection standards and historical record tracking requirements. Based on these standards, it loads a weak password feature library and configures the reference address of the weak password feature library to the detection module of the third encapsulated object. Based on the historical record tracking requirements, it initializes a historical record table and associates the historical record table with the state management module of the third encapsulated object. Based on the third encapsulated object configured with the weak password feature library reference address and associated with the historical record table, it generates a fourth encapsulated object with compliance verification functionality. This fourth encapsulated object loads the weak password feature library and the historical record table.
[0112] Step S305: Generate a sealing password instance based on the fourth sealing object, and generate a sealing password instance set based on all sealing password instances.
[0113] In the specific implementation, each password item in the password management device is configured with corresponding attributes and corresponding preset object methods, and each configured password item is abstracted and encapsulated. Each password item includes a basic attribute, which includes the password name, associated resource, and access permissions. In addition to the basic attribute, each password item has a supplementary attribute and a corresponding preset object method. The specific configuration process is as follows: Configure a binding script attribute for the password group, and the password group will implement a unified update function for passwords of multiple instances according to a preset batch update method; Based on the cryptographic group, a random key attribute and an encryption algorithm attribute are configured for the encryption mechanism. The encryption mechanism uses a preset dual authentication decryption method to achieve confidential storage and transmission of the cryptographic data. Based on the encryption mechanism, a role model attribute and an audit log attribute are configured for access control. Access control is based on a preset least privilege principle to achieve decentralized management and operation traceability. Based on access control, a weak password database attribute and a history attribute are configured for compliance detection. Compliance detection uses a preset complexity check method to achieve weak password interception and reuse detection. Based on compliance testing, a status verification attribute is configured for the synchronization mechanism. The synchronization mechanism uses a preset real-time synchronization method to achieve consistency of external system credentials and business continuity. Based on the synchronization mechanism, a scheduling mechanism attribute is configured for report generation. The report generation follows a preset compliance reporting method to achieve automated audit report output.
[0114] This embodiment employs a layered, progressive encapsulation mechanism to gradually assign functional attributes such as batch updates, encryption protection, distributed auditing, and compliance verification to cryptographic instances. This achieves modular construction and functional decoupling of cryptographic management objects, improving system scalability and maintenance efficiency. By introducing cryptographic group configuration rules and binding script attributes, it enables automatic association between cryptographic instances and batch update scripts, supporting unified scheduling and one-click batch operations at the group level, significantly improving cryptographic update efficiency and reducing the risk of human configuration oversights. By configuring random key parameters and encryption algorithm parameters, a dual authentication and decryption mechanism is constructed to ensure the confidentiality of cryptographic data during storage and transmission, effectively preventing the decryption of static keys. To mitigate the risk of data breaches and enhance overall system security, the system implements the principle of least privilege and a full traceability mechanism by binding role model data and audit log templates. This achieves refined decentralized management and audit compliance, preventing abuse of privileges and unclear responsibilities. By loading a weak password feature library and historical record table, proactive compliance detection and historical reuse interception are implemented, ensuring that password complexity meets security baseline requirements, satisfies audit standards, and reduces security risks caused by weak passwords. Through integrity verification and a unified registration mechanism, the system ensures the functional completeness and data consistency of encapsulated password instances, forming a standardized set of encapsulated password instances and improving the stability of system operation and the standardization of data management.
[0115] refer to Figure 7 , Figure 7 This is a flowchart illustrating the fourth embodiment of the dynamic password management method in the operation and maintenance management of the present invention.
[0116] Based on the above embodiments, in this embodiment, step S40 further includes: Step S401: Generate script identification information based on each encapsulated cryptographic instance in the encapsulated cryptographic instance set.
[0117] It should be noted that script identification information refers to unique identification data extracted from the binding script attributes of the encapsulated password instance, including script reference address, script hash value or script version number, which is used to distinguish different batch update scripts and serve as the basis for instance grouping.
[0118] In the specific implementation, the password management device traverses each encapsulated password instance in the encapsulated password instance set, reads the script reference address or script hash value contained in the bound script attribute of each encapsulated password instance, performs standardization processing on the script reference address or script hash value to generate unique script identification information, and maps and stores the script identification information with the instance identifier of the encapsulated password instance, thereby generating corresponding script identification information for each encapsulated password instance.
[0119] Step S402: Generate a subset of target encapsulation cipher instances based on multiple encapsulation cipher instances with the same script identification information.
[0120] It should be noted that the target encapsulated cipher instance subset refers to a set of instances formed by aggregating multiple encapsulated cipher instances with the same script identification information, representing a group of cipher objects that need to be executed with the same batch update strategy.
[0121] In the specific implementation, the password management device performs grouping and aggregation operations on the set of encapsulated password instances based on all generated script identification information. It compares the script identification information of each encapsulated password instance, merges multiple encapsulated password instances with the same script identification information into the same group container, performs integrity verification on the encapsulated password instances in each group container to exclude abnormal instances, and defines the group container that passes the verification as the target encapsulated password instance subset. Thus, one or more target encapsulated password instance subsets are generated based on multiple encapsulated password instances with the same script identification information.
[0122] Step S403: Generate group update identifier and group binding configuration information based on the target encapsulated cryptographic instance subset.
[0123] It should be noted that the group update identifier is a unique identifier assigned to each target encapsulated cipher instance subset, used to uniquely identify a cipher group and its corresponding batch update task in the system.
[0124] Group binding configuration information can be configuration data describing the collaborative execution strategy of instances within a cryptographic group, including execution order parameters, batch scheduling parameters, timeout settings, and exception handling rules, which are used to guide the execution logic of group-level batch operations.
[0125] In the specific implementation, the cryptographic management device assigns a globally unique group update identifier to each target encapsulated cryptographic instance subset, and generates group binding configuration information based on the number of encapsulated cryptographic instances, resource type distribution, and preset batch scheduling strategy contained in the target encapsulated cryptographic instance subset. The group binding configuration information includes batch execution order parameters, timeout control parameters, and exception rollback rules. The group update identifier and group binding configuration information are associated, stored, and bound to the target encapsulated cryptographic instance subset, thereby generating the group update identifier and group binding configuration information based on the target encapsulated cryptographic instance subset.
[0126] Step S404: Generate association links between target encapsulation cipher instances in the target encapsulation cipher instance subset based on the group binding configuration information.
[0127] It should be noted that the association link refers to the logical connection relationship established between instances within a subset of target encapsulated cryptographic instances. It represents the collaborative association formed between instances due to sharing the same batching strategy and is used to support the synchronization and linkage of states within the group.
[0128] Step S405: Generate group update relationships based on association links and group update identifiers.
[0129] It should be noted that group update relationship refers to the relationship data generated based on the association link and group update identifier, which represents the association state of each instance in the target encapsulated cryptographic instance subset that shares the same batch update strategy and is managed by the same group update identifier.
[0130] Step S406: Generate group update relationships between multiple target encapsulated cryptographic instances with the same batch update requirements based on the binding script attributes of the encapsulated cryptographic instances.
[0131] In the specific implementation, the cryptographic management device creates virtual cryptographic group nodes based on group update relationships and maps group update identifiers to cryptographic group nodes. It traverses each target encapsulated cryptographic instance in the subset of target encapsulated cryptographic instances associated with the group update relationship, establishes a membership mapping relationship between each target encapsulated cryptographic instance and the cryptographic group node, and associates the membership mapping relationship with the scheduling parameters in the group binding configuration information to form a binding record between the instance and the group node. All binding records are aggregated to generate cryptographic binding relationship data. The cryptographic binding relationship data represents the structural relationship of multiple target encapsulated cryptographic instances achieving unified scheduling and management through cryptographic group nodes, thereby generating cryptographic binding relationship data between multiple target encapsulated cryptographic instances and the same cryptographic group node based on the group update relationship.
[0132] Step S407: Generate cryptographic binding relationship data between multiple target encapsulated cryptographic instances and nodes in the same cryptographic group based on the group update relationship.
[0133] It should be noted that a cryptographic group node refers to a virtual node object created in the cryptographic management system model. It serves as an aggregation center for a subset of target encapsulated cryptographic instances, carries group update identifiers and group binding configuration information, and enables unified scheduling and management of multiple instances.
[0134] Cryptographic binding relationship data refers to the data that describes the affiliation mapping relationship between multiple target encapsulated cryptographic instances and the same cryptographic group node, representing the structural relationship of unified scheduling and management of instances through cryptographic group nodes.
[0135] Step S408: Generate encryption protection relationship data between the source cryptographic instance and the target cryptographic instance based on the random key attributes and encryption algorithm parameters of the encapsulated cryptographic instance.
[0136] It should be noted that the source cryptographic instance refers to the encapsulated cryptographic instance that holds dynamic random key parameters or cryptographic control in the cryptographic protection relationship, and is used to provide key support or cryptographic protection for the target cryptographic instance.
[0137] A target cryptographic instance refers to a packaged cryptographic instance that stores encrypted credential data within an encrypted protection relationship and relies on a key provided by the source cryptographic instance for decryption.
[0138] Encryption protection relationship data refers to data that describes the dependency relationship between the source cryptographic instance and the target cryptographic instance based on random key attributes and encryption algorithm parameters. It represents the protection path and verification information by which the source instance protects the confidentiality of the target instance through a dynamic key mechanism.
[0139] Step S409: Generate the hierarchical audit relationship data between the access subject instance and the accessed password instance based on the role model attributes of the encapsulated password instance and the audit log template.
[0140] It should be noted that the access subject instance refers to the role object or user account instance with operation permissions in the decentralized audit relationship, which is authorized to access specific password instances based on role model attributes.
[0141] An accessed password instance refers to a packaged password instance that is the access object in a hierarchical audit relationship. Its access behavior is subject to access control and must be recorded in the audit log.
[0142] Decentralized audit relationship data refers to data that describes the control relationship between the access subject instance and the accessed password instance based on role model attributes and audit log templates. It represents the authorized access path and log binding information of the subject accessing the instance under controlled permissions and whose operation behavior is forcibly recorded and audited.
[0143] Step S410: Generate a password management system model based on password binding relationship data, encryption protection relationship data, and decentralized audit relationship data.
[0144] In the specific implementation, the password management device establishes the association between each instance based on the function implemented by each password item, and determines the corresponding relationship attributes to obtain the final constructed password management system model; Each password item is associated with another password item at the group level based on a preset resource instance information, and the corresponding relationship attribute is password binding.
[0145] Establish associations between multiple cryptographic instances based on the source cryptographic instance, the target cryptographic instance, and the batch update function of cryptographic groups, with the corresponding relationship attribute being group update; and / or The association between the source and target cryptographic instances, and the dual authentication functionality of the encryption mechanism, is established, with the corresponding relationship attribute being encryption protection; and / or Establish the association between password access based on the source password instance, the target password instance, and the access control function, with the corresponding relationship attribute being decentralized auditing; Based on the synchronization status and the synchronization verification function, an association is established between the password instance and the external system, and the corresponding relationship attribute is real-time synchronization.
[0146] This embodiment automatically clusters target encapsulated cryptographic instances using script identification information to generate subsets and establishes group update and cryptographic binding relationship data. This achieves automatic grouping and unified binding of multiple instances, supports one-click batch scheduling based on cryptographic group nodes, avoids the tediousness and oversight of manual configuration on a per-unit basis, significantly improves batch update efficiency, and ensures consistency of instance configuration strategies within a group. By parsing random key attributes and encryption algorithm parameters to generate encryption protection relationship data, it clarifies the key dependency path between the source and target cryptographic instances, achieving separate storage of dynamic keys and ciphertext data and a dual authentication mechanism. This effectively prevents data breach risks due to static key leakage and enhances the confidentiality of the cryptographic throughout its lifecycle. Through role model attributes and... The audit log template generates hierarchical audit relationship data, establishes a fine-grained authorization path between the access subject instance and the accessed password instance, and forcibly binds audit log records. This enables role-based hierarchical management and real-time auditing of operational behaviors, effectively avoiding abuse of permissions and unclear responsibilities, and ensuring that all highly sensitive operations are traceable. By integrating password binding relationships, encryption protection relationships, and hierarchical audit relationships, a password management system model containing hierarchical topology, dependent networks, and permission mappings is generated, forming a global relational view. This supports cross-instance collaborative management and policy linkage, providing a structured basis for subsequent password updates, evictions, compliance checks, and external synchronization operations. This achieves an automated closed loop of operation and maintenance management, improving the overall controllability and stability of the system.
[0147] refer to Figure 8 , Figure 8 This is a flowchart illustrating the fifth embodiment of the dynamic password management method in the operation and maintenance management of the present invention.
[0148] Based on the above embodiments, in this embodiment, step S50 further includes: Step S501: Generate password update records for multiple password instances associated with password group nodes based on the group update relationship in the password management system model.
[0149] It should be noted that the password update record refers to a data set that records the process and results of batch update operations for password instances, including update timestamps, execution result status, new credential digest information, and associated password group node identifiers.
[0150] In the specific implementation, the password management device accesses the password management system model and locates the group update relationship, identifies the password group node and its associated multiple password instances, calls the batch update script bound to the password group node, and performs password modification operations on each password instance in sequence according to the execution order parameters in the group binding configuration information. After the operation is completed, the update timestamp, execution result status and new credential digest information of each password instance are recorded, and the execution records of all instances are aggregated to generate password update records for multiple password instances associated with the password group node.
[0151] Step S502: Generate the permission operation log and revoke status information of the password instance based on the hierarchical audit relationship in the password management system model.
[0152] It should be noted that the permission operation log refers to the operation behavior record data generated based on the hierarchical audit relationship, which includes operation type, operation subject identifier, operation time, operation result and associated audit log template information.
[0153] The recycling status information refers to the data information describing the status of the password instance recycling operation, including the recycling time, recycling reason, status change result, and recycling permission verification record.
[0154] In its implementation, the password management device identifies the authorized access path between the access subject instance and the accessed password instance based on the hierarchical audit relationship, verifies whether the role model attributes of the access subject instance meet the minimum permission requirements, executes the password operation after verification, and writes the operation type, operation subject identifier, operation time and operation result into the audit log template to generate the permission operation log. At the same time, for the password revoke operation, it checks the revoke permission and updates the status flag of the password instance, generating revoke status information including revoke time, revoke reason and status change result.
[0155] Step S503: Generate compliance detection result data for the password instance based on the preset compliance policy form.
[0156] It should be noted that the compliance test result data refers to the result data generated after testing password instances based on the compliance policy form, including weak password identification results, reuse test results, compliance judgment conclusions, and risk level markings.
[0157] In its implementation, the password management device loads a pre-defined compliance policy form and reads the basic and secondary attributes of the password instance. It matches the credential data of the password instance with the feature rules in the weak password database to identify weak password risks. At the same time, it queries the historical record table to detect password reuse. Based on the complexity threshold and historical reuse restriction rules in the compliance policy form, it generates a compliance judgment conclusion and integrates the weak password identification results, reuse detection results, and compliance judgment conclusion to generate compliance detection result data for the password instance.
[0158] Furthermore, to ensure accurate matching between the detection standards and cryptographic instance characteristics, and to improve detection accuracy and policy execution efficiency, step S503 may include: Step S5031: Based on the attribute information of the source cryptographic instance, query the preset compliance policy form to obtain the first policy rule corresponding to the attribute information.
[0159] It should be noted that attribute information refers to a data set that describes the characteristics of a password instance, including password name, associated resource type, access permission level, and resource identifier.
[0160] The compliance policy form is a configuration data table that stores the policy rules corresponding to password levels. It includes the policy rule index, compliance level target, policy jump logic, and complexity parameter definition.
[0161] The first policy rule refers to the initial policy entry obtained by matching the attribute information of the source cryptographic instance from the compliance policy form, which includes cryptographic complexity parameters and historical reuse restriction parameters.
[0162] Step S5032: Based on the first strategy rule, query the history table to obtain the usage record of the source password instance, determine whether the source password instance has a weak password mark based on the usage record, and generate a detection threshold based on the complexity table if there is no weak password mark.
[0163] It should be noted that the history table is a data table that stores the historical usage entries and change trajectory of password instances, including historical password value digests, usage timestamps, and weak password markers.
[0164] Weak password markers are information that indicates a password credential as a weak password in usage records, serving as a warning that the password poses a security risk.
[0165] A complexity table is a data table that stores the correspondence between password complexity parameters and numerical standards, including quantitative indicators such as minimum length, character types, and special character requirements.
[0166] The detection threshold refers to the parameter limits used to determine password compliance, which are parsed from the first policy rules and complexity table. These limits include the minimum length threshold, character complexity threshold, and historical reuse limit. Alternatively, the detection threshold can be a specific numerical standard used to quantitatively assess password strength and compliance status.
[0167] In the specific implementation, the historical record table is accessed according to the query conditions defined in the first policy rule. The historical usage entries of the source password instance stored in the historical record table are retrieved to generate a usage record. The usage record contains historical password digests, usage time, and risk marker information. The usage record is checked to see if it contains weak password markers to determine whether the source password instance has a weak password risk. If there are no weak password markers in the usage record, the password complexity parameter configured in the first policy rule is parsed and the corresponding numerical standard in the complexity table is queried to generate a detection threshold. The detection threshold includes a minimum length limit, character type requirements, and an upper limit on the allowed number of historical reuses. The usage record and the detection threshold are bound to the current detection session for subsequent judgment.
[0168] Step S5033: When the first policy rule does not meet the target compliance requirements, a second policy rule is obtained from the compliance policy form based on the detection threshold, and a compliance path query result is generated based on the second policy rule.
[0169] It should be noted that the target compliance requirement refers to the final compliance level standard or compliance status target defined in the compliance strategy form, which is used as the termination condition for the strategy matching path.
[0170] The second strategy rule refers to the subsequent strategy entries obtained from the compliance strategy form based on the detection threshold and strategy jump logic, which are used to provide further verification basis when the first strategy rule does not meet the target compliance requirements.
[0171] The compliant path query results refer to the data generated based on the second strategy rules, which includes path identifiers and jump conditions, including rule identifiers, path type markers, and next hop information.
[0172] Step S5034: Iteratively query the next-hop policy rules based on the compliance path query results until the target compliance requirement is matched, and generate the actual matching path between the source cryptographic instance and the target compliance requirement based on all the policy rules obtained from the query.
[0173] It should be noted that the actual matching path refers to the path structure composed of multiple policy rule nodes and jump relationships, which represents the complete verification process of the source cryptographic instance recursively matching from the first policy rule to the target compliance requirement.
[0174] Step S5035: Generate compliance detection result data for the password instance based on the actual matching path, the weak password marker, and the detection threshold.
[0175] In its implementation, the password management device retrieves the usage record corresponding to the first policy rule from a historical table based on the first policy rule, and determines the corresponding detection threshold; then, based on the detection threshold of the first policy rule, it queries the compliance path of the corresponding second policy rule. If no compliance path for the second policy rule is found, then the second policy rule cannot match the target compliance requirement; If the compliance path of the second strategy rule is a direct match, then the second strategy rule is the rule for the target compliance requirement; If the compliance path of the second policy rule is not a direct match, then the policy rule of the next hop of the second policy rule is determined according to the compliance policy form, until the policy rule of the next hop is the rule of the target compliance requirement.
[0176] Understandably, this embodiment achieves automated compliance detection based on compliance policy forms and historical records. It uses attribute information to match the first policy rule and combines it with a complexity table to generate a detection threshold, ensuring that the detection standards are accurately matched with password instance characteristics and resource levels, thereby improving detection accuracy and policy execution efficiency. By checking weak password markers in usage records, it proactively identifies and immediately blocks weak password risks, preventing passwords that do not meet the security baseline from being used, thus reducing security risks at the source. If the first policy rule does not meet the target compliance requirements, it iteratively queries the second policy rule and the next-hop policy rule based on the detection threshold and policy jump logic to generate the actual matching path. This supports dynamic matching of multi-level policies and step-by-step verification of complex compliance requirements, enhancing the flexibility and coverage of the detection mechanism.
[0177] Step S504: Generate synchronization status data between the password instance and the external system credentials based on the real-time synchronization relationship in the password management system model.
[0178] It should be noted that synchronization status data refers to data information describing the synchronization execution status between the password instance and external system credentials, including synchronization time, synchronization result, exception details, and consistency verification conclusion.
[0179] In its implementation, the password management device locates the synchronization path between the password instance and the external system credential node based on the real-time synchronization relationship, publishes the change information of the password instance to the external system credential node and calls the external system interface to perform credential updates, receives the update response returned by the external system and executes the verification logic defined by the status verification attribute to confirm the consistency between the external credentials and the password instance, and generates synchronization status data containing synchronization time, synchronization result and exception details based on the synchronization execution result and verification conclusion.
[0180] Furthermore, to enhance the flexibility and coverage of the synchronization mechanism, step S504 may include: Step S5041: Generate the existence determination result of the synchronization node based on the interface identifier of the external credentials.
[0181] It should be noted that external credentials can be account credential data stored outside the password management system and relying on password instances for authentication, including monitoring system credentials, alarm system credentials, and third-party application interface keys.
[0182] An interface identifier is a string of data used to uniquely identify the communication interface or access endpoint associated with external credentials, including the interface address, port number, and protocol type information.
[0183] The existence determination result of the synchronization node refers to the determination data generated after querying the synchronization node registry based on the interface identifier, which is used to characterize whether there is an intermediate synchronization node in the current synchronization link.
[0184] Step S5042: When the existence determination result of the synchronization node indicates that the synchronization node information does not exist, a direct connection synchronization state is generated based on the password instance and the external credentials.
[0185] It should be noted that the synchronization node information can be a data set describing the configuration and status of intermediate synchronization nodes, including node address, verification rule configuration, routing information, and node availability flags.
[0186] Direct connection synchronization status refers to the status data generated after the password instance and external credentials perform a synchronization operation directly without going through an intermediate node. It includes synchronization timestamp, synchronization result identifier and direct connection mode flag.
[0187] Understandably, when the determination result indicates that the synchronization node information does not exist, a direct communication channel is established between the password instance and the external credentials. The update interface provided by the external credentials is called to push the current credential data of the password instance to the external credentials. The update response returned by the external credentials is received and the response code is verified to confirm that the synchronization operation is successful. Based on the update response, a direct connection synchronization status containing a synchronization timestamp, a synchronization result identifier, and a direct connection mode marker is generated.
[0188] Step S5043: When the existence determination result of the synchronization node indicates that the synchronization node information exists, generate the verification status parameters and the interface of the next hop synchronization node based on the synchronization node information.
[0189] It should be noted that the verification status parameter can be parameter data generated based on the verification feedback returned by the synchronization node, which is used to characterize the current availability and data consistency status of the synchronization node.
[0190] The next-hop synchronization node interface refers to the communication interface identifier of the subsequent synchronization node determined based on the routing information of the current synchronization node. It is used to guide the recursive query and data forwarding of the synchronization link.
[0191] Understandably, when the determination result indicates that the synchronization node information exists, the node address and verification rule configuration in the synchronization node information are extracted, a verification request containing the password instance identifier is sent to the synchronization node and the verification feedback returned by the node is received, and a verification status parameter representing the current availability and data consistency of the node is generated based on the verification feedback. At the same time, the routing information in the synchronization node configuration is read to determine the direction of the subsequent synchronization link, and the next-hop synchronization node interface is generated based on the routing information.
[0192] Step S5044: Generate a synchronization node path based on the next-hop synchronization node interface, wherein the synchronization node path contains all the queried synchronization nodes.
[0193] It should be noted that the synchronization node path can be a link structure data consisting of multiple synchronization nodes connected in sequence, including the identifiers of all queried synchronization nodes, the node order, and the connection relationships between nodes.
[0194] In the specific implementation, the password management device initiates a recursive query operation based on the next-hop synchronization node interface, adds the current synchronization node to the path list and calls the next-hop synchronization node interface to obtain subsequent node information. The node query and path appending process is repeated until the queried node information indicates that the link terminates or there are no subsequent nodes. All synchronization node identifiers, node order and connection relationships accumulated in the path list are serialized and encapsulated to generate a synchronization node path containing complete link topology information.
[0195] Step S5045: Generate synchronization status data based on the direct connection synchronization status or the synchronization node path.
[0196] In the specific implementation, the password management device selects the corresponding status generation logic according to the synchronization link type. When the direct connection mode is adopted, the synchronization result and timestamp information in the direct connection synchronization status are extracted to construct the status data. When the multi-node path mode is adopted, each synchronization node in the synchronization node path is traversed and the verification status parameters and transmission delay indicators of each node are aggregated. The aggregated path status information is associated and encapsulated with the password instance identifier and external credential identifier to generate synchronization status data containing synchronization mode, link details, final synchronization result and anomaly diagnosis information.
[0197] Understandably, this embodiment generates synchronization status data based on real-time synchronization relationships, automatically determines the existence of synchronization nodes using interface identifiers, and distinguishes between direct connection and multi-node path modes. This enables adaptive synchronization support for external systems with different topologies, improving the flexibility and coverage of the synchronization mechanism. When synchronization nodes exist, by generating verification status parameters and recursively constructing synchronization node paths, it achieves step-by-step verification of intermediate node states and complete link tracing, ensuring data consistency and traceability during the synchronization process, effectively identifying abnormal nodes in the link, and locating synchronization failures. By integrating direct connection synchronization status and synchronization node paths, it generates structured synchronization status data, providing detailed evidence for business continuity assessment and anomaly handling. This ensures real-time consistency between external system credentials and password instances, avoiding business interruptions or monitoring failures due to credential asynchrony, significantly reducing manual maintenance costs and operational risks, and guaranteeing business continuity and system stability in operation and maintenance management.
[0198] Step S505: Generate operation log summary data based on the preset report template configuration information, the password update record, the permission operation log, and the recycling status information.
[0199] It should be noted that the operation log summary data refers to the summary data generated after summarizing and statistically analyzing password update records, permission operation logs, and recycling status information based on the report template configuration information. It includes an update overview, operation statistics, and recycling summary information.
[0200] In the specific implementation, the password management device reads the preset report template configuration information to determine the format and field requirements of the log summary, extracts the batch execution overview and abnormal statistics information from the password update record, integrates the high-frequency operation types and risk operation markers from the permission operation log, and combines the status change statistics from the recycling status information to generate operation log summary data containing update overview, operation statistics and recycling summary according to the layout rules defined in the report template configuration information.
[0201] Step S506: Generate compliance statistical chart data based on the compliance test result data, and generate the report body content based on the compliance statistical chart data and the operation log summary data.
[0202] It should be noted that compliance statistics charts refer to visualized statistical data generated based on compliance test results, including the percentage of weak passwords, compliance pass rate, risk distribution indicators, and corresponding chart structure information.
[0203] The main body of the report refers to the core text content of the report generated after integrating compliance statistical charts and data with operation log summary data. It includes structured text and charts in the compliance analysis section and the operation and maintenance section.
[0204] In practice, the password management device performs statistical analysis on the compliance test results data to calculate the proportion of weak passwords, compliance pass rate and risk distribution indicators. Based on the statistical indicators, it generates compliance statistical chart data, integrates the compliance statistical chart data with the operation log summary data, organizes the text and charts according to the chapter structure in the report template configuration information, and generates the report body content including the compliance analysis chapter and the operation and maintenance chapter.
[0205] Step S507: Generate business continuity assessment information based on the synchronization status data, and generate enhanced report content based on the business continuity assessment information and the report body content.
[0206] It should be noted that business continuity assessment information refers to assessment data generated based on synchronization status data, including external system credential consistency indicators, synchronization delay indicators, and an explanation of the impact of synchronization risks on business monitoring and alarm functions.
[0207] Enhanced report content refers to the expanded report content generated by incorporating business continuity assessment information into the main report content, including a business impact analysis section and a panoramic management view.
[0208] In practice, the password management device parses the synchronization status data to assess the consistency and synchronization delay indicators of external system credentials. Based on the assessment results, it generates business continuity assessment information, inserts the business impact analysis section of the report body, supplements the description of the potential impact of synchronization risks on business monitoring and alarm functions, and generates enhanced report content that includes business continuity assessment dimensions.
[0209] Step S508: Generate a compliance report based on the preset scheduling mechanism attributes and the enhanced report content.
[0210] It should be noted that a compliance report is a structured document generated based on the scheduling mechanism attributes and enhanced report content. It contains complete audit evidence, compliance analysis conclusions, operational statistics, and business continuity assessment results, and is used for audit presentation and archiving.
[0211] Step S509: Generate an operation result based on the password update record, the permission operation log, the revocation status information, the compliance detection result data, and the synchronization status data, and associate the operation result with the compliance report.
[0212] In the specific implementation, the password management device summarizes password update records, permission operation logs, revoke status information, compliance test result data and synchronization status data, constructs an operation result object containing full operation details and status indicators, extracts the unique identifier of the compliance report and establishes a reference link between the operation result object and the compliance report, and writes the reference link into the metadata field of the operation result object to realize the association storage of operation results and compliance reports.
[0213] This embodiment executes multi-dimensional password management operations and generates structured reports through a password management system model, achieving automated closed-loop management and visualized audit output for the entire lifecycle of operation and maintenance passwords. It drives batch update record generation through group update relationships, supporting one-click batch scheduling and execution tracking, significantly improving password update efficiency and ensuring operational traceability. It generates permission operation logs and revoke status information through hierarchical audit relationships, implementing the principle of least privilege and a full operation recording mechanism, effectively preventing permission abuse and enhancing accountability. It automatically generates compliance detection result data through compliance policy forms, enabling proactive interception of weak passwords and historical reuse detection, ensuring password complexity meets security baselines and audit requirements. It generates synchronization status data through real-time synchronization relationships, ensuring consistency of credentials in external systems and business continuity, reducing the risk of business interruption due to credential asynchrony. By integrating operation records, compliance data, and synchronization status, it generates compliance reports including business continuity assessments, providing panoramic and visualized audit evidence and management insights, improving compliance management efficiency and decision support capabilities. Simultaneously, it establishes a correlation mechanism between operation results and reports, supporting data linkage queries and in-depth analysis, further enhancing system maintainability and management transparency.
[0214] Furthermore, this embodiment of the invention also proposes a computer-readable storage medium storing a password dynamic management program for operation and maintenance management. When the password dynamic management program is executed by a processor, it implements the steps of the password dynamic management method for operation and maintenance management as described above.
[0215] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0216] The aforementioned computer-readable storage medium may be included in the password dynamic management device during operation and maintenance; or it may exist independently and not be assembled into the password dynamic management device during operation and maintenance.
[0217] Furthermore, this invention also proposes a computer program product, including a password dynamic management program for operation and maintenance management. When the password dynamic management program for operation and maintenance management is executed by a processor, it implements the steps of the password dynamic management method for operation and maintenance management as described above.
[0218] The specific implementation of the computer program product of the present invention is basically the same as the various embodiments of the dynamic password management method in the above-mentioned operation and maintenance management work, and will not be repeated here.
[0219] Reference Figure 9 , Figure 9 This is a structural block diagram of the first embodiment of the password dynamic management device in the operation and maintenance management of the present invention.
[0220] like Figure 9 As shown in the embodiment of the present invention, the password dynamic management device in the operation and maintenance management work includes: The password acquisition module 10 is used to acquire multiple password items in the target operation and maintenance management scenario, the password items including network device password resources and server password resources; Instance construction module 20 is used to construct a set of cryptographic instances based on multiple cryptographic items. The set of cryptographic instances includes multiple cryptographic instances, and each cryptographic instance carries basic attributes and auxiliary attributes. Instance encapsulation module 30 is used to generate an encapsulated cryptographic instance set based on each cryptographic instance in the cryptographic instance set. The encapsulated cryptographic instance set includes multiple encapsulated cryptographic instances, and each encapsulated cryptographic instance represents an object after abstracting and encapsulating the cryptographic instance. The cryptographic modeling module 40 is used to generate a cryptographic management system model based on the functional attributes of each encapsulated cryptographic instance in the encapsulated cryptographic instance set. The cryptographic management system model is configured to manage the association relationships between each encapsulated cryptographic instance. The association relationships include group update relationships, cryptographic binding relationships, encryption protection relationships, hierarchical audit relationships, and real-time synchronization relationships. The management execution module 50 is used to perform password management operations on the password instance based on the password management system model, and generate operation results and compliance reports. The password management operations include password update operations, password eviction operations, compliance detection operations, and external credential synchronization operations.
[0221] This embodiment constructs a password management system model and implements abstract encapsulation and multi-dimensional relationship management, realizing centralized modeling and automated full lifecycle control of operation and maintenance password resources. It effectively solves the security risks and management chaos caused by decentralized password storage, improves the execution efficiency and accuracy of batch updates, compliance testing and external synchronization, reduces manual maintenance costs and operational risks, and enhances the traceability and data confidentiality of the system through decentralized auditing and encryption protection mechanisms, thereby ensuring the overall security, compliance and business continuity of operation and maintenance management.
[0222] The password dynamic management device for operation and maintenance management provided in this application, employing the password dynamic management method in the above embodiments, can solve the technical problem of password dynamic management in operation and maintenance management. Compared with the prior art, the beneficial effects of the password dynamic management device for operation and maintenance management provided in this application are the same as the beneficial effects of the password dynamic management method for operation and maintenance management provided in the above embodiments, and other technical features in the password dynamic management device for operation and maintenance management are the same as the features disclosed in the methods of the above embodiments, and will not be repeated here.
[0223] It should be understood that the above are merely illustrative examples and do not constitute any limitation on the technical solutions of the present invention. In specific applications, those skilled in the art can make settings as needed, and the present invention does not impose any restrictions on this.
[0224] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of this invention. In practical applications, those skilled in the art can select some or all of the workflow to achieve the purpose of this embodiment according to actual needs, and no restrictions are imposed here.
[0225] In addition, for technical details not described in detail in this embodiment, please refer to the password dynamic management method in operation and maintenance management provided in any embodiment of the present invention, which will not be repeated here.
[0226] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.
[0227] It should be noted that the user information (including but not limited to user device information, user personal information, user location information, user behavior information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0228] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0229] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as read-only memory / random access memory, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0230] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.
Claims
1. A method for dynamic password management in operation and maintenance management, characterized in that, The method includes: Obtain multiple password items from the target operation and maintenance management scenario, including network device password resources and server password resources; Generate resource identification information, credential data, and permission configuration information corresponding to each password item; The basic attributes of the password instance are generated based on the resource identification information, the credential data, and the permission configuration information. The basic attributes include the password name, associated resource, and access permissions. The associated attributes of the password instance are generated based on the preset security policy configuration rules. The associated attributes include binding script attributes, random key attributes, role model attributes, weak password library attributes, status verification attributes, and scheduling mechanism attributes. A password instance is generated based on the basic attribute and the auxiliary attribute, and a password instance set is generated based on multiple password instances. The password instance set includes multiple password instances, and each password instance carries a basic attribute and an auxiliary attribute. A set of encapsulated cryptographic instances is generated based on each cryptographic instance in the set of cryptographic instances. The set of encapsulated cryptographic instances includes multiple encapsulated cryptographic instances, and each encapsulated cryptographic instance represents an object after abstracting and encapsulating the cryptographic instance. A password management system model is generated based on the functional attributes of each encapsulated password instance in the encapsulated password instance set. The password management system model is configured to manage the relationships between each encapsulated password instance. The relationships include group update relationships, password binding relationships, encryption protection relationships, hierarchical audit relationships, and real-time synchronization relationships. Based on the password management system model, password management operations are performed on the password instance to generate operation results and compliance reports. The password management operations include password update operations, password eviction operations, compliance detection operations, and external credential synchronization operations.
2. The method for dynamic password management in operation and maintenance management as described in claim 1, characterized in that, The step of generating an encapsulated cryptographic instance set based on each cryptographic instance in the cryptographic instance set includes: A first encapsulated object with bound script attributes is generated based on the preset password group configuration rules and password instances; Based on the preset encryption mechanism configuration rules and the first encapsulation object, a second encapsulation object with encryption protection function is generated. The second encapsulation object includes random key parameters and encryption algorithm parameters. Based on the preset permission control configuration rules and the second encapsulated object, a third encapsulated object with the function of hierarchical auditing is generated. The third encapsulated object is associated with role model data and audit log template. Based on the preset compliance detection configuration rules and the third encapsulation object, a fourth encapsulation object with compliance verification function is generated. The fourth encapsulation object loads the weak password feature library and the historical record table. A set of encapsulated password instances is generated based on the fourth encapsulation object, and a set of encapsulated password instances is generated based on all encapsulated password instances.
3. The method for dynamic password management in operation and maintenance management as described in claim 1, characterized in that, The process of generating a cryptographic management system model based on the functional attributes of each encapsulated cryptographic instance in the encapsulated cryptographic instance set includes: Generate script identification information based on each encapsulated cryptographic instance in the encapsulated cryptographic instance set; Generate a subset of target encapsulated cryptographic instances based on multiple encapsulated cryptographic instances with the same script identification information; Based on the target encapsulated cryptographic instance subset, generate group update identifiers and group binding configuration information; Based on the group binding configuration information, generate the association links between each target encapsulation cryptographic instance in the target encapsulation cryptographic instance subset; A group update relationship is generated based on the associated link and the group update identifier; Based on the binding script attributes of the encapsulated cryptographic instance, a group update relationship is generated between multiple target encapsulated cryptographic instances with the same batch update requirement; Based on the group update relationship, generate password binding relationship data between multiple target encapsulated password instances and nodes in the same password group; Based on the random key attributes and encryption algorithm parameters of the encapsulated cryptographic instance, generate encryption protection relationship data between the source cryptographic instance and the target cryptographic instance; Based on the role model attributes and audit log template of the encapsulated password instance, generate the hierarchical audit relationship data between the access subject instance and the accessed password instance; A password management system model is generated based on the password binding relationship data, the encryption protection relationship data, and the decentralized audit relationship data.
4. The method for dynamic password management in operation and maintenance management as described in claim 1, characterized in that, The step of performing password management operations on the password instance based on the password management system model, and generating operation results and compliance reports, includes: Based on the group update relationship in the password management system model, generate password update records for multiple password instances associated with password group nodes; Based on the hierarchical audit relationship in the password management system model, the permission operation log and revoke status information of the password instance are generated; Compliance test result data for password instances is generated based on a preset compliance policy form; Based on the real-time synchronization relationship in the password management system model, generate synchronization status data between password instances and external system credentials; Based on the preset report template configuration information, the password update record, the permission operation log, and the recycling status information, an operation log summary data is generated; Based on the compliance test results data, a compliance statistical chart is generated, and based on the compliance statistical chart data and the operation log summary data, the main body of the report is generated; Based on the synchronization status data, business continuity assessment information is generated, and based on the business continuity assessment information and the report content, enhanced report content is generated. A compliance report is generated based on the preset scheduling mechanism attributes and the enhanced report content; An operation result is generated based on the password update record, the permission operation log, the revocation status information, the compliance detection result data, and the synchronization status data, and the operation result is associated with the compliance report.
5. The method for dynamic password management in operation and maintenance management as described in claim 4, characterized in that, The compliance detection result data for the password instance generated based on the preset compliance policy form includes: The first policy rule corresponding to the attribute information is obtained by querying the preset compliance policy form based on the attribute information of the source cryptographic instance. Based on the first strategy rule, the usage record of the source password instance is obtained from the historical record table. Based on the usage record, it is determined whether the source password instance has a weak password mark. If there is no weak password mark, a detection threshold is generated based on the complexity table. If the first policy rule does not meet the target compliance requirements, a second policy rule is obtained from the compliance policy form based on the detection threshold, and a compliance path query result is generated based on the second policy rule. Based on the compliance path query results, iteratively query the next-hop policy rules until the target compliance requirement is matched, and generate the actual matching path between the source cryptographic instance and the target compliance requirement based on all the policy rules obtained from the query. Based on the actual matching path, the weak password marker, and the detection threshold, the compliance detection result data of the password instance is generated.
6. The method for dynamic password management in operation and maintenance management as described in claim 4, characterized in that, The generation of synchronization status data between the password instance and external system credentials based on the real-time synchronization relationship in the password management system model includes: The existence determination result of the synchronization node is generated based on the interface identifier of the external credentials; When the existence determination result of the synchronization node indicates that the synchronization node information does not exist, a direct connection synchronization state is generated based on the password instance and the external credentials. When the existence determination result of the synchronization node indicates that the synchronization node information exists, a verification status parameter and the interface of the next hop synchronization node are generated based on the synchronization node information. A synchronization node path is generated based on the next-hop synchronization node interface, and the synchronization node path contains all the queried synchronization nodes; Synchronization status data is generated based on the direct connection synchronization status or the synchronization node path.
7. A dynamic password management device for operation and maintenance management, characterized in that, The device applies the dynamic password management method in operation and maintenance management as described in any one of claims 1 to 6, and the device comprises: The password acquisition module is used to acquire multiple password items in the target operation and maintenance management scenario, including network device password resources and server password resources. The instance construction module is used to generate resource identification information, credential data, and permission configuration information corresponding to each password item; and to generate basic attributes of the password instance based on the resource identification information, the credential data, and the permission configuration information, wherein the basic attributes include password name, associated resource, and access permissions; The system generates auxiliary attributes for password instances based on preset security policy configuration rules. These auxiliary attributes include binding script attributes, random key attributes, role model attributes, weak password library attributes, status verification attributes, and scheduling mechanism attributes. Password instances are generated based on these basic attributes and auxiliary attributes. A set of password instances is then generated based on these multiple password instances. The set of password instances includes multiple password instances, each of which carries basic attributes and auxiliary attributes. An instance encapsulation module is used to generate an encapsulated cryptographic instance set based on each cryptographic instance in the cryptographic instance set. The encapsulated cryptographic instance set includes multiple encapsulated cryptographic instances, and each encapsulated cryptographic instance represents an object after abstracting and encapsulating the cryptographic instance. The cryptographic modeling module is used to generate a cryptographic management system model based on the functional attributes of each encapsulated cryptographic instance in the encapsulated cryptographic instance set. The cryptographic management system model is configured to manage the relationships between each encapsulated cryptographic instance, including group update relationships, cryptographic binding relationships, encryption protection relationships, hierarchical audit relationships, and real-time synchronization relationships. The management execution module is used to perform password management operations on the password instance based on the password management system model, and generate operation results and compliance reports. The password management operations include password update operations, password eviction operations, compliance detection operations, and external credential synchronization operations.
8. A dynamic password management device for operation and maintenance management, characterized in that, The password dynamic management device in the operation and maintenance management process includes: a memory, a processor, and a password dynamic management program for operation and maintenance management stored on the memory. The processor is used to run the password dynamic management program for operation and maintenance management. The password dynamic management program for operation and maintenance management is configured to implement the password dynamic management method for operation and maintenance management as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a password dynamic management program for operation and maintenance management. When the password dynamic management program for operation and maintenance management is executed by the processor, it implements the password dynamic management method for operation and maintenance management as described in any one of claims 1 to 6.