Method and device for verifying device management authority, electronic device, medium and program product

By detecting the identity of network element devices and their authentication requests, the system automatically identifies fake network administrators, solving the problem of insufficient identity verification for fake network administrators in existing technologies and improving network security and authentication efficiency.

CN122437661APending Publication Date: 2026-07-21ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZTE CORP
Filing Date
2025-01-21
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively identify fake network administrators, leading to cybersecurity threats and impacting the data security of enterprises and individuals.

Method used

By performing identity verification on the first device requesting management of network elements, and if the identity is unknown, an authentication request is sent to the network management device with management authority. Based on the authentication result, it is determined whether to grant management authority, thereby achieving automated identification of intruding devices.

Benefits of technology

It improves the accuracy of identifying fake network administrators, ensures network security, prevents fake network administrators or intrusion tools from accessing the network, and enhances identification efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122437661A_ABST
    Figure CN122437661A_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a device management permission verification method and device, electronic equipment, medium and program product. The device management permission verification method comprises the following steps: in response to receiving a device management request of a first device to a network element device, detecting the device identity of the first device; in response to detecting that the device identity of the first device is an unknown device, sending a first authentication request to a first network management device; the first network management device is a device that establishes a communication connection with the network element device and has management permission for the network element device; the first authentication request is used to request the first network management device to authenticate the management permission of the first device; and according to a first authentication result sent by the first network management device, it is determined whether the first device is allowed to manage the network element device. The application can improve the identification accuracy of the counterfeit network management and ensure the network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, electronic device, medium, and program product for verifying device management permissions. Background Technology

[0002] With the rapid development of network technology, network security issues are becoming increasingly prominent. Network management is a crucial component in ensuring the normal operation of a network, including monitoring, controlling, and planning network resources. Malicious actors often impersonate network administrators and exploit network management protocols (such as SNMP and NetConf) to perform illegal operations, such as obtaining sensitive information or causing network paralysis. Clearly, intrusions by impersonating network administrators seriously threaten the data security of enterprises and individuals, necessitating an effective method for identifying impersonating network administrators. Summary of the Invention

[0003] The purpose of this application is to provide a method, apparatus, electronic device, medium, and program product for verifying device management permissions, so as to improve the accuracy of identifying fake network administrators and ensure network security.

[0004] To solve the above-mentioned technical problems, the embodiments of this application are implemented as follows: On one hand, embodiments of this application provide a method for verifying device management permissions, including: In response to receiving a device management request from the first device for a network element device, the device identity of the first device is detected; In response to detecting that the device identity of the first device is an unknown device, a first authentication request is sent to the first network management device; the first network management device is a device that has established a communication connection with the network element device and has management authority over the network element device; the first authentication request is used to request the first network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the first network management device, determine whether to allow the first device to manage the network element device.

[0005] On the other hand, embodiments of this application provide a device for verifying device management permissions, including: The detection module is used to detect the device identity of the first device in response to receiving a device management request from the first device for the network element device; The sending module is configured to send a first authentication request to a first network management device in response to detecting that the device identity of the first device is an unknown device; the first network management device is a device that has established a communication connection with the network element device and has management authority over the network element device; the first authentication request is used to request the first network management device to authenticate the management authority of the first device. The determining module is used to determine whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device.

[0006] In another aspect, embodiments of this application provide an electronic device, including a processor and a memory electrically connected to the processor, the memory storing a computer program, and the processor being used to call and execute the computer program from the memory to implement the aforementioned device management permission verification method.

[0007] In another aspect, embodiments of this application provide a computer-readable storage medium for storing a computer program that can be executed by a processor to implement the aforementioned device management permission verification method.

[0008] In another aspect, embodiments of this application provide a computer program product, including a computer program, which is executed by a processor to implement the aforementioned device management permission verification method.

[0009] The technical solution of this application embodiment detects the device identity of a first device requesting to manage a network element device. In response to detecting that the first device's device identity is unknown, a first authentication request is sent to a first network management device. The first network management device is a device that has established a communication connection with the network element device and has management authority over it. The first authentication request is used to request the first network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the first network management device, it is determined whether the first device is allowed to manage the network element device. This effectively identifies whether the first device has management authority over the network element device, accurately identifies intruding devices, prevents network element devices from being accessed by fake network management systems or other intrusion tools, and improves the data security of the network element device. Furthermore, the authorization verification process for the first device does not require manual intervention, thus achieving automated identification of intruding devices and improving the efficiency of intrusion device identification. Attached Figure Description

[0010] To more clearly illustrate the technical solutions in one or more embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in one or more embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a schematic flowchart of a device management permission verification method according to an embodiment of this application; Figure 2 This is an illustrative application scenario diagram of a device management permission verification method according to an embodiment of this application; Figure 3 This is a schematic flowchart of a device management permission verification method according to another embodiment of this application; Figure 4 This is a schematic block diagram of a device management permission verification device according to an embodiment of this application; Figure 5 This is a schematic block diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0012] This application provides a method, apparatus, electronic device, medium, and program product for verifying device management permissions, in order to improve the accuracy of identifying fake network administrators and ensure network security.

[0013] To enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this application.

[0014] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and are not used to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein.

[0015] The device management permission verification method provided in this application embodiment can be executed by an electronic device or by software installed in an electronic device. Specifically, the electronic device can be a terminal device or a server device. The terminal device can include smartphones, laptops, smart wearable devices, vehicle terminals, etc., and the server device can include an independent physical server, a server cluster consisting of multiple servers, or a cloud server capable of cloud computing.

[0016] Figure 1 This is a schematic flowchart illustrating a device management permission verification method according to an embodiment of this application, such as... Figure 1 As shown, this method can be applied to network element devices and includes the following steps: S102, in response to receiving the device management request from the first device for the network element device, the device identity of the first device is detected.

[0017] Optionally, the device management request sent by the first device includes the device identification information of the first device. The device identification information may include at least one of the following: device name, device type, device model, and a unique device ID (Identity number). When verifying the device identity of the first device, the following steps may be performed: First, a pre-configured first network management information database is retrieved. This database records the device identification information of the second network management device, which has management authority over network element devices. In other words, the first gateway information database records the device identification information of network management devices with management authority over network element devices. This first network management information database is stored locally on the network element device.

[0018] Optionally, the device identification information of the network management device can be stored encrypted in the first network management information database to improve the security of the device identification information. The encryption method can be any commonly used encryption method, and this embodiment does not limit this. The device identification information of the network management device in the first network management information database can be automatically generated by the network management device, as long as it can uniquely identify the network management device.

[0019] Secondly, the device identification information of the first device is matched with the first network management information database to determine whether the device identification information of the first device is recorded in the first network management information database. If the device identification information of the first device is not recorded in the first network management information database, the device identity of the first device is determined to be an unknown device.

[0020] Taking device identification information as device ID as an example, network management devices with management authority over network element devices pre-send their respective device IDs to the network element devices. The network element devices store these device IDs in their local first network management information database. When the first device sends a device management request, the network element device matches the first device's device ID with the device IDs stored in the first network management information database. If the first network management information database contains the first device's device ID, it indicates that the first device has previously managed the network element device, and thus it can be determined that the first device has management authority over the network element device. If the first network management information database does not contain the first device's device ID, it indicates that the first device has not managed the network element device, and further verification of the first device's management authority is required. In this case, the first device can be determined to be an unknown device. Therefore, for cases where the first device's device ID is stored in the first network management information database, this embodiment can quickly verify the first device's management authority based on the local database (i.e., the first network management information database), improving the verification efficiency of the first device's management authority.

[0021] S104, in response to detecting that the device identity of the first device is an unknown device, a first authentication request is sent to the first network management device.

[0022] The first network management device is a device that establishes a communication connection with the network element device and has management authority over the network element device. In other words, the first network management device is the device currently managing the network element device.

[0023] The first authentication request is used to request the first network management device to authenticate the management authority of the first device. After authenticating the management authority of the first device, the first network management device obtains the first authentication result and sends the first authentication result to the network element device.

[0024] Optionally, the first network management device pre-stores device identification information for each of the second network management devices. The second network management device is a device with management authority over network elements. The device identification information may include at least one of the following: device name, device type, device model, and a unique device ID (Identity Number). The device identification information pre-stored in the first network management device may or may not be the same as the device identification information stored in the local database of the network elements (such as the first network management database).

[0025] The device identification information pre-stored in the first network management device can be automatically generated by the first network management device, for example, randomly generated device identification information that can uniquely identify each second network management device. The device identification information pre-stored in the first network management device can also be manually configured by the user, for example, configuring a unique device identification information for each second network management device and storing it in the first network management device.

[0026] Therefore, when the first network management device authenticates the management authority of the first device, it can match the device identification information of the first device with the device identification information pre-stored in the first network management device. If the device identification information of the first device is pre-stored in the first network management device, it means that the first device has been pre-configured as a device with management authority over network element devices, and the first authentication result can be determined as authentication passed. If the device identification information of the first device is not pre-stored in the first network management device, it means that the first device has not been pre-configured as a device with management authority over network element devices, and the first authentication result can be determined as authentication failed.

[0027] S106, based on the first authentication result sent by the first network management device, determine whether to allow the first device to manage the network element device.

[0028] The first authentication result includes authentication passed or authentication failed. Optionally, step S106 can be executed as follows: in response to the first authentication result being authentication passed, the first device is allowed to manage the network element device; in response to the first authentication result being authentication failed, the first device is denied management of the network element device.

[0029] Optionally, in response to allowing the first device to manage network element devices, the device identification information of the first device is stored in the first network management information database. By storing the device identification information of the first device in the first network management information database locally on the network element device, when the first device requests to manage the network element device again, it can directly verify the management authority of the first device based on the device identification information stored locally on the network element device, without needing to verify through the first network management device. This reduces the interaction process of authorization verification and greatly improves the efficiency of verifying the management authority of the first device.

[0030] The technical solution of this application embodiment detects the device identity of a first device requesting to manage a network element device. In response to detecting that the first device's device identity is unknown, a first authentication request is sent to a first network management device. The first network management device is a device that has established a communication connection with the network element device and has management authority over it. The first authentication request is used to request the first network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the first network management device, it is determined whether the first device is allowed to manage the network element device. This effectively identifies whether the first device has management authority over the network element device, accurately identifies intruding devices, prevents network element devices from being accessed by fake network management systems or other intrusion tools, and improves the data security of the network element device. Furthermore, the authorization verification process for the first device does not require manual intervention, thus achieving automated identification of intruding devices and improving the efficiency of intrusion device identification.

[0031] In one embodiment, when determining whether to allow the first device to manage network elements based on the first authentication result sent by the first network management device, the following steps A1-A3 may be performed: Step A1: In response to receiving the second authentication request sent by the first network management device, generate authentication information for the first device.

[0032] The second authentication request is generated by the first network management device if the first authentication result is that the authentication failed. The authentication information includes the reason for the authentication failure.

[0033] Step A2: Based on the authentication information, determine whether the first device has management authority over the network element device, and obtain the second authentication result.

[0034] Step A3: Based on the second authentication result, determine whether the first device is allowed to manage network element devices.

[0035] Optionally, when performing step A3, in response to the second authentication result being successful, the second authentication result is sent to the first network management device. After receiving confirmation of the second authentication result from the first network management device, the first device is allowed to manage network element devices.

[0036] In this embodiment, if the second authentication result is successful, the first network management device further confirms the second authentication result, and only after confirmation is the first device allowed to manage the network element device. This multi-factor authentication method improves the accuracy of verifying the management permissions of the first device, especially when the second authentication result is provided by the user (e.g., authentication information is displayed on the network element device's interface, and the user determines whether the first device has management permissions based on the authentication information). Confirming the second authentication result through the first network management device prevents user error leading to incorrect verification of the first device's permissions, such as accidentally clicking the "Allow" or "Deny" button on the network element device's interface, thereby improving the accuracy of verifying the management permissions of the first device.

[0037] In one embodiment, the first network management device includes multiple devices. When determining whether to allow the first device to manage network elements based on the first authentication result sent by the first network management device, the following method can be used: if multiple first authentication results meet preset conditions, the first device is allowed to manage network elements. The preset conditions include at least one of the following: the number of first authentication results that pass authentication is greater than or equal to a preset number threshold; the percentage of first authentication results that pass authentication is greater than or equal to a preset percentage threshold.

[0038] There are multiple first network management devices, meaning that multiple first network management devices are currently managing network element devices. In this case, a network element device can send a first authentication request to multiple first network management devices. The multiple first network management devices jointly verify the management authority of the first device, and each first network management device sends a first authentication result to the network element device. The higher the number and / or percentage of successful first authentication results, the higher the credibility of the first device.

[0039] In one embodiment, after executing step S106, in response to the first device's refusal to manage the network element device, an alarm message for the first device is sent to the second network management device. The alarm message includes the device identification information of the first device and is used to notify the first device that it does not have management authority over the network element device.

[0040] The device identification information may include at least one of the following: device name, device type, device model, and a unique device ID. The second network management device is a device with management authority over network element devices.

[0041] If the first device refuses to manage the network element device, it means that the first device does not have management authority over the network element device. In this case, by reporting the device identification information of the first device to the second network management device, the second network management device can record the device identification information of the device that does not have management authority over the network element device. Thus, when it receives the first authentication request for the first device from the network element device in the future, it can quickly verify the management authority of the first device based on the locally recorded device identification information, thereby improving the verification efficiency of the management authority of the first device.

[0042] In one embodiment, before detecting the device identity of the first device (i.e., step S102), the following steps B1-B2 may be performed: Step B1: Establish a communication connection between the first network management device and the network element device, and obtain the device identification information of the first network management device based on the communication connection.

[0043] The device identification information may include at least one of the following: device name, device type, device model, and a unique device ID. The type of communication connection established between the first network management device and the network element device is not limited; for example, it could be a DCN (Data communication network).

[0044] Optionally, when establishing a communication connection between the first network management device and the network element device, an encrypted channel can be established. Transmitting data between the first network management device and the network element device through an encrypted channel can improve the security of the transmitted data. For example, transmitting the device identification information of the first network management device through an encrypted channel prevents intrusion devices from stealing the device identification information of the first network management device, thus preventing them from impersonating the first network management device to intrude into the network element device.

[0045] Step B2: Store the device identification information of the first network management device in the second network management information database. The second network management information database is used to store the device identification information of the network management device that is currently managing network element devices.

[0046] In this embodiment, by pre-storing the device identification information of the first network management device in a local database, namely the second network management database, when the network element device sends a first authentication request to the first network management device (i.e., step S104), it can send the first authentication request to the first network management device based on the device identification information of the first network management device recorded in the second network management database. This provides a simple and quick way to request the network management device currently managing the network element device to perform permission verification for the first device.

[0047] The following specific embodiment illustrates the device management permission verification method provided in this application.

[0048] Figure 2 This is an illustrative application scenario diagram of a device management permission verification method according to an embodiment of this application, such as... Figure 2 As shown, this application scenario includes: network element devices, network management devices with management authority over the network element devices, and a first device. The network management devices may include multiple devices, such as... Figure 2 The diagram shows network management devices A and B. Network element devices can also include multiple devices; two are schematically shown in the diagram. The network management devices and network element devices are connected via a DCN network. The DCN network can be implemented using a router or switch. The first device refers to the identity requiring management authorization verification. The first device can connect to the network element devices via the DCN network or directly to them.

[0049] Figure 3 This is a schematic flowchart illustrating a device management permission verification method according to an embodiment of this application. Figure 3 As shown, the device management permission verification method is applied to Figure 2 The scenario shown includes the following steps S301-S310: S301, establish a DCN network connection between the network management device and the network element device. The network management device sends its own device ID to the network element device through the DCN network. The network element device stores the device ID of the network management device in its local network management information database.

[0050] The network management information database stores the device identification information of the network management devices currently managing network elements. Network management device A and network management device B execute step S301 in the same way.

[0051] If the network management device is establishing a network connection with a network element for the first time, it needs to send its own device ID to the network element so that the network element can store the device ID in its local network management information database. If the network management device is not establishing a network connection with a network element for the first time, the network element already has its device ID pre-stored in its local network management information database, so it does not need to send its own device ID to the network element again.

[0052] Network element devices can use any encryption method to encrypt and store the device ID of the network management device to ensure the security of the device ID and prevent intrusion devices from stealing the device ID of the network management device.

[0053] S302, the network element device receives the device management request from the first device and matches the device ID of the first device with the local network management information database.

[0054] S303, the network element device determines whether the network management information database includes the device ID of the first device. If yes, proceed to S309; ​​otherwise, proceed to step S304.

[0055] S304, the network element device sends the first authentication request to the network management device.

[0056] Among them, network management equipment refers to the equipment currently managing network element devices, such as... Figure 2 The network management device A and / or network management device B are shown.

[0057] The first authentication request includes the device ID of the first device.

[0058] Optionally, if a network element sends a first authentication request to multiple network management devices, it can obtain first authentication results returned by the multiple network management devices. The network element can determine whether to allow the network element to manage the first device based on the multiple first authentication results. If the multiple first authentication results meet preset conditions, the first device is allowed to manage the network element. The preset conditions include at least one of the following: the number of first authentication results that pass authentication is greater than or equal to a preset number threshold; the percentage of first authentication results that pass authentication is greater than or equal to a preset percentage threshold.

[0059] S305: Based on the first authentication request, the network management device matches the device ID of the first device with the pre-configured list of network management IDs locally to obtain the first authentication result, and sends the first authentication result to the network element device.

[0060] The network management device is pre-configured with a network management ID list, which stores the device IDs of devices with management authority over network elements.

[0061] The device IDs recorded in the pre-configured network management ID list in the network management device can be automatically generated by the network management device, for example, randomly generated device IDs that can uniquely identify each network management device with management authority. Alternatively, they can be manually configured by the user, for example, by configuring a unique device ID for each network management device with management authority and storing it in the network management device's network management ID list.

[0062] The network management device matches the device ID of the first device with a pre-configured list of network management IDs to determine whether the device ID of the first device is included in the pre-configured list, thus obtaining a first authentication result. The first authentication result includes authentication successful or unsuccessful. If the device ID of the first device is included in the list of network management IDs, the first authentication result is successful; if the device ID of the first device is not included in the list of network management IDs, the first authentication result is unsuccessful. The network management device sends the first authentication result to the network element device, which then determines whether to allow the first device to manage the network element device based on the first authentication result.

[0063] If the first authentication result is that the authentication fails, proceed to step S306; if the first authentication result is that the authentication succeeds, proceed to step S309.

[0064] S306, the network management device sends a second authentication request to the network element device.

[0065] The second authentication request is generated by the network management device when the first authentication result is that the authentication fails. The second authentication request includes the authentication information of the first device, and the authentication information includes the reason for the authentication failure.

[0066] S307, the network element device obtains the second authentication result based on the second authentication request.

[0067] The second authentication result can be provided by the user. Optionally, based on the second authentication request, the network element displays the authentication information and the input fields for the second authentication result on the network element's display interface. These input fields can be, for example, "Allow" and "Deny" buttons. If the user clicks the "Allow" button, it indicates that the second authentication result is successful; if the user clicks the "Deny" button, it indicates that the second authentication result is unsuccessful.

[0068] Optionally, before displaying the input fields for authentication information and the second authentication result, the network element device may first authenticate the user. The user referred to here is the user currently logged into the network element device. When authenticating the user, the network element device can verify whether the currently logged-in user information is pre-registered and legitimate. If it is legitimate, the verification passes, and the input fields for authentication information and the second authentication result are displayed on the interface. If it is not legitimate, the verification fails, and the device can directly refuse the first device's management of the network element device.

[0069] Optionally, if the second authentication result is successful, step S308 is executed; if the second authentication result is unsuccessful, step S310 is executed.

[0070] S308, the network element device sends the second authentication result to the network management device and obtains feedback information from the network management device regarding the second authentication result.

[0071] The network management device can send a second authentication result to network management device A and / or network management device B for confirmation. Confirming the second authentication result through the network management device prevents errors in the first device's permission verification due to user error, such as accidentally clicking the "Allow" or "Deny" button on the network element's display interface, thereby improving the accuracy of verifying the first device's management permissions.

[0072] Optionally, if the feedback information is confirmation of the second authentication result (i.e., agreement with the second authentication result), step S309 is executed; if the feedback information is rejection (i.e. disagreement with the second authentication result), step S310 is executed.

[0073] S309, Network element devices allow the first device to manage network element devices.

[0074] S310, network element devices refuse to allow the first device to manage network element devices.

[0075] Optionally, if a network element refuses to allow the first device to manage other network element devices, it indicates that the first device has been identified as an intrusion device. In this case, the network element can send an alarm message to the network management device to notify the first device that it does not have management authority over the network element. The alarm message includes the device ID of the first device. This allows the network management device to record the device ID of the device that does not have management authority over the network element. When it subsequently receives a first authentication request from the network element for the first device, it can quickly verify the first device's management authority based on the locally recorded device ID, thus improving the efficiency of verifying the first device's management authority.

[0076] In this embodiment, by detecting the device identity of the first device requesting management of network elements, and if the device ID of the first device is not available, a first authentication request is sent to the network management device to request the network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the network management device, it is determined whether the first device is allowed to manage the network elements. This effectively identifies whether the first device has management authority over the network elements, accurately identifies intruding devices, and prevents network elements from being accessed by fake network management systems or other intrusion tools, thus improving the data security of the network elements. Furthermore, if the second authentication result is successful, the network management device further confirms the second authentication result before allowing the first device to manage the network elements. This multi-verification method improves the accuracy of verifying the management authority of the first device, especially when the second authentication result is provided by the user. Confirming the second authentication result through the network management device prevents user error from causing incorrect verification of the first device's authority, thereby improving the accuracy of verifying the management authority of the first device.

[0077] In summary, specific embodiments of this subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing can be advantageous.

[0078] The above is a method for verifying device management permissions provided in the embodiments of this application. Based on the same idea, the embodiments of this application also provide a device for verifying device management permissions.

[0079] Figure 4 This is a schematic block diagram of a device management permission verification device according to an embodiment of this application, such as... Figure 4 As shown, the device includes: Detection module 41 is used to detect the device identity of the first device in response to receiving a device management request from the first device for the network element device; Sending module 42 is configured to send a first authentication request to a first network management device in response to detecting that the device identity of the first device is an unknown device; the first network management device is a device that has established a communication connection with the network element device and has management authority over the network element device; the first authentication request is used to request the first network management device to authenticate the management authority of the first device. The determining module 43 is used to determine whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device.

[0080] In one embodiment, when the determining module 43 determines whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device, it performs the following steps: In response to the first authentication result being successful, the first device is allowed to manage the network element device; In response to the first authentication result being that authentication failed, the first device is denied management of the network element device.

[0081] In one embodiment, when the determining module 43 determines whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device, it performs the following steps: In response to receiving a second authentication request from the first network management device, authentication information for the first device is generated; the second authentication request is generated by the first network management device if the first authentication result is authentication failure; the authentication information includes the reason for the authentication failure. Based on the authentication information, determine whether the first device has management authority over the network element device, and obtain the second authentication result; Based on the second authentication result, determine whether the first device is allowed to manage the network element device.

[0082] In one embodiment, when the determining module 43 determines whether to allow the first device to manage the network element device based on the second authentication result, it performs the following steps: In response to the second authentication result being successful, the second authentication result is sent to the first network management device; After receiving confirmation information from the first network management device regarding the second authentication result, the first device is allowed to manage the network element device.

[0083] In one embodiment, the first network management device includes multiple devices; When determining whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device, the determining module 43 performs the following steps: If multiple first authentication results meet preset conditions, the first device is allowed to manage the network element device; the preset conditions include at least one of the following: the number of first authentication results that pass authentication is greater than or equal to a preset number threshold, and the percentage of first authentication results that pass authentication is greater than or equal to a preset percentage threshold.

[0084] In one embodiment, the device management request includes the device identification information of the first device; When the detection module 41 detects the device identity of the first device, it performs the following steps: Obtain a pre-configured first network management information database, which is used to record the device identification information of the second network management device; the second network management device has management authority over the network element device. The first network management information database is matched with the device identification information of the first device to determine whether the device identification information of the first device is recorded in the first network management information database. Since the device identification information of the first device is not recorded in the first network management information database, the device identity of the first device is determined to be an unknown device. In one embodiment, the apparatus further includes: The first storage module is configured to, after determining whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device, store the device identification information of the first device in the first network management information database in response to allowing the first device to manage the network element device.

[0085] In one embodiment, the apparatus further includes: The second sending module is configured to, after determining whether the first device is allowed to manage the network element device based on the first authentication result sent by the first network management device, in response to denying the first device's management of the network element device, send an alarm message for the first device to the second network management device; the alarm message includes the device identification information of the first device; the alarm message is used to notify the first device that it does not have management authority over the network element device.

[0086] In one embodiment, the apparatus further includes: The establishment and acquisition module is used to establish a communication connection between the first network management device and the network element device before the device identity of the first device is detected in response to receiving a device management request from the first device for the network element device, and to acquire the device identification information of the first network management device based on the communication connection. The second storage module is used to store the device identification information of the first network management device in the second network management information database; the second network management information database is used to store the device identification information of the network management device currently managing the network element device; When the sending module 42 sends the first authentication request to the first network management device, it performs the following steps: Based on the device identification information of the first network management device recorded in the second network management information database, the first authentication request is sent to the first network management device.

[0087] The apparatus according to this application embodiment detects the device identity of a first device requesting to manage a network element device. In response to detecting that the first device's device identity is unknown, it sends a first authentication request to a first network management device. The first network management device is a device that has established a communication connection with the network element device and has management authority over it. The first authentication request is used to request the first network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the first network management device, it is determined whether the first device is allowed to manage the network element device. This effectively identifies whether the first device has management authority over the first device, accurately identifies intruding devices, prevents network element devices from being accessed by fake network management systems or other intrusion tools, and improves the data security of the network element devices. Furthermore, the authorization verification process for the first device does not require manual intervention, thus achieving automated identification of intruding devices and improving the efficiency of intrusion device identification.

[0088] Those skilled in the art will understand that Figure 4 The device management permission verification device in the document can be used to implement the device management permission verification method described above. The details of the verification should be similar to those described in the method section above. To avoid being too complicated, they will not be repeated here.

[0089] Following the same line of thought, embodiments of this application also provide an electronic device, such as... Figure 5As shown. Electronic devices can vary considerably due to differences in configuration or performance, and may include one or more processors 501 and memory 502. Memory 502 may store one or more application programs or data. Memory 502 may be temporary or persistent storage. The application programs stored in memory 502 may include one or more modules (not shown), each module may include a series of computer-executable instructions for the electronic device. Furthermore, processor 501 may be configured to communicate with memory 502 and execute the series of computer-executable instructions in memory 502 on the electronic device. The electronic device may also include one or more power supplies 503, one or more wired or wireless network interfaces 504, one or more input / output interfaces 505, and one or more keyboards 506.

[0090] Specifically, in this embodiment, the electronic device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for use in the electronic device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following: In response to receiving a device management request from the first device for a network element device, the device identity of the first device is detected; In response to detecting that the device identity of the first device is an unknown device, a first authentication request is sent to the first network management device; the first network management device is a device that has established a communication connection with the network element device and has management authority over the network element device; the first authentication request is used to request the first network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the first network management device, determine whether to allow the first device to manage the network element device.

[0091] The technical solution of this application embodiment detects the device identity of a first device requesting to manage a network element device. In response to detecting that the first device's device identity is unknown, a first authentication request is sent to a first network management device. The first network management device is a device that has established a communication connection with the network element device and has management authority over it. The first authentication request is used to request the first network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the first network management device, it is determined whether the first device is allowed to manage the network element device. This effectively identifies whether the first device has management authority over the network element device, accurately identifies intruding devices, prevents network element devices from being accessed by fake network management systems or other intrusion tools, and improves the data security of the network element device. Furthermore, the authorization verification process for the first device does not require manual intervention, thus achieving automated identification of intruding devices and improving the efficiency of intrusion device identification.

[0092] This application also proposes a computer-readable storage medium that stores one or more computer programs, each computer program including instructions that, when executed by an electronic device including multiple applications, enable the electronic device to perform various processes of the above-described device management permission verification method embodiments, specifically for executing: In response to receiving a device management request from the first device for a network element device, the device identity of the first device is detected; In response to detecting that the device identity of the first device is an unknown device, a first authentication request is sent to the first network management device; the first network management device is a device that has established a communication connection with the network element device and has management authority over the network element device; the first authentication request is used to request the first network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the first network management device, determine whether to allow the first device to manage the network element device.

[0093] The technical solution of this application embodiment detects the device identity of a first device requesting to manage a network element device. In response to detecting that the first device's device identity is unknown, a first authentication request is sent to a first network management device. The first network management device is a device that has established a communication connection with the network element device and has management authority over it. The first authentication request is used to request the first network management device to authenticate the management authority of the first device. Based on the first authentication result sent by the first network management device, it is determined whether the first device is allowed to manage the network element device. This effectively identifies whether the first device has management authority over the network element device, accurately identifies intruding devices, prevents network element devices from being accessed by fake network management systems or other intrusion tools, and improves the data security of the network element device. Furthermore, the authorization verification process for the first device does not require manual intervention, thus achieving automated identification of intruding devices and improving the efficiency of intrusion device identification.

[0094] This application provides a computer program product, including a computer program that is executed by a processor to implement the various processes of the device management permission verification method embodiment described above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0095] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0096] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.

[0097] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0098] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0099] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0100] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0101] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0102] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0103] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0104] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0105] This application can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0106] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0107] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for verifying device management permissions, comprising: In response to receiving a device management request from the first device for a network element device, the device identity of the first device is detected; In response to detecting that the device identity of the first device is an unknown device, a first authentication request is sent to the first network management device; The first network management device is a device that establishes a communication connection with the network element device and has management authority over the network element device; The first authentication request is used to request the first network management device to authenticate the management authority of the first device; Based on the first authentication result sent by the first network management device, determine whether to allow the first device to manage the network element device.

2. The method according to claim 1, wherein determining whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device includes: In response to the first authentication result being successful, the first device is allowed to manage the network element device; In response to the first authentication result being that authentication failed, the first device is denied management of the network element device.

3. The method according to claim 1, wherein determining whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device includes: In response to receiving a second authentication request sent by the first network management device, authentication information for the first device is generated; The second authentication request is generated by the first network management device if the first authentication result is that the authentication failed; the authentication information includes the reason for the authentication failure; Based on the authentication information, determine whether the first device has management authority over the network element device, and obtain the second authentication result; Based on the second authentication result, determine whether the first device is allowed to manage the network element device.

4. The method according to claim 3, wherein determining whether to allow the first device to manage the network element device based on the second authentication result includes: In response to the second authentication result being successful, the second authentication result is sent to the first network management device; After receiving confirmation information from the first network management device regarding the second authentication result, the first device is allowed to manage the network element device.

5. The method according to claim 1, wherein the first network management device comprises a plurality of devices; The step of determining whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device includes: If multiple first authentication results meet preset conditions, the first device is allowed to manage the network element device; The preset conditions include at least one of the following: the number of successful authentications in the first authentication result is greater than or equal to a preset number threshold; the percentage of successful authentications in the first authentication result is greater than or equal to a preset percentage threshold.

6. The method according to claim 1, wherein the device management request includes the device identification information of the first device; The detection of the device identity of the first device includes: Obtain a pre-configured first network management information database, which is used to record the device identification information of the second network management device; The second network management device has management authority over the network element devices; The first network management information database is matched with the device identification information of the first device to determine whether the device identification information of the first device is recorded in the first network management information database. Since the device identification information of the first device is not recorded in the first network management information database, the device identity of the first device is determined to be an unknown device.

7. The method according to claim 6, further comprising, after determining whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device: In response to allowing the first device to manage the network element device, the device identification information of the first device is stored in the first network management information database.

8. The method according to claim 6, further comprising, after determining whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device: In response to the first device refusing to manage the network element device, an alarm message is sent to the second network management device for the first device; The alarm information includes the device identification information of the first device; the alarm information is used to notify the first device that it does not have management authority over the network element device.

9. The method according to claim 1, further comprising, before detecting the device identity of the first device in response to receiving a device management request from the first device for a network element device: Establish a communication connection between the first network management device and the network element device, and obtain the device identification information of the first network management device based on the communication connection; The device identification information of the first network management device is stored in the second network management information database; The second network management information database is used to store the device identification information of the network management device currently managing the network element device; Sending the first authentication request to the first network management device includes: Based on the device identification information of the first network management device recorded in the second network management information database, the first authentication request is sent to the first network management device.

10. A device for verifying device management permissions, comprising: The detection module is used to detect the device identity of the first device in response to receiving a device management request from the first device for the network element device; The sending module is configured to send a first authentication request to the first network management device in response to detecting that the device identity of the first device is an unknown device; The first network management device is a device that establishes a communication connection with the network element device and has management authority over the network element device; The first authentication request is used to request the first network management device to authenticate the management authority of the first device; The determining module is used to determine whether to allow the first device to manage the network element device based on the first authentication result sent by the first network management device.

11. An electronic device, comprising a processor and a memory electrically connected to the processor, the memory storing a computer program, the processor being configured to call and execute the computer program from the memory to implement the device management authority verification method as claimed in any one of claims 1-9.

12. A computer-readable storage medium for storing a computer program that can be executed by a processor to implement the device management authority verification method as described in any one of claims 1-9.

13. A computer program product comprising a computer program executed by a processor to implement the device management authority verification method as described in any one of claims 1-9.