An operation and maintenance access control method and system, electronic equipment and storage medium
By monitoring the real-time status of maintenance request tickets in the maintenance session and terminating the session when the status is invalid, the problem of the authorization status being disconnected from the lifecycle of the maintenance session is solved, thus improving the accuracy and efficiency of maintenance access control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- DIGITAL GUANGDONG NETWORK CONSTR CO LTD
- Filing Date
- 2026-04-28
- Publication Date
- 2026-08-04
AI Technical Summary
In existing technologies, the authorization status is disconnected from the lifecycle of the operation and maintenance session, resulting in low accuracy and efficiency of operation and maintenance access control.
After a target maintenance session is successfully established, the real-time status of the target maintenance application work order is monitored, and the maintenance session is terminated when the real-time status is determined to be invalid. An access control method based on the status of the maintenance application work order is adopted, and real-time constraints are implemented using the maintenance audit gateway, certificate server, asset credential vault, ITSM process engine and mapping conversion engine.
It enables real-time constraints on operation and maintenance sessions based on authorization status, improving the accuracy and efficiency of operation and maintenance access control.
Smart Images

Figure CN122513286A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer operation and maintenance technology, and in particular to an operation and maintenance access control method, system, electronic device and storage medium. Background Technology
[0002] In the field of enterprise IT operations and maintenance management, operations and maintenance personnel are required to configure, maintain, and troubleshoot IT assets such as servers, network devices, and databases within the data center. To ensure the security and auditability of the operations and maintenance process, it is typically necessary to perform identity authentication, access control, and operation auditing on the access behavior of operations and maintenance personnel.
[0003] Existing operation and maintenance access control technologies already manage operation and maintenance access behavior through methods such as account passwords, certificate authentication, and work order approval. However, the above-mentioned technical solutions generally focus on identity authentication or permission configuration itself, resulting in a disconnect between the authorization status and the lifecycle of the operation and maintenance session. Summary of the Invention
[0004] This invention provides an operation and maintenance access control method, system, electronic device, and storage medium to achieve real-time constraints on operation and maintenance sessions based on authorized status, thereby improving the accuracy and efficiency of operation and maintenance access control.
[0005] According to one aspect of the present invention, an operation and maintenance access control method is provided, applied to the operation and maintenance audit gateway of the operation and maintenance access control system, the method comprising:
[0006] After the target operation and maintenance session is successfully established, monitor the real-time status of the target operation and maintenance work order; the target operation and maintenance work order is the triggering condition for establishing the target operation and maintenance session.
[0007] If the real-time status is determined to be invalid, the target operation and maintenance session is terminated.
[0008] According to another aspect of the present invention, an operation and maintenance access control system is provided, the system comprising: an operation and maintenance audit gateway, a certificate server, an asset credential vault, an ITSM process engine, and a mapping and conversion engine, wherein the operation and maintenance audit gateway is deployed between the operation and maintenance personnel client and the assets, and the mapping and conversion engine is deployed between the ITSM process engine and the operation and maintenance audit gateway;
[0009] An operations and maintenance audit gateway is used to execute the operations and maintenance access control method as described in any one of claims 1-7;
[0010] A certificate server is used to issue identity authentication certificates to operations and maintenance personnel and to verify the identity authentication certificates during the establishment of operations and maintenance sessions.
[0011] An asset credential vault is used to store access credentials for assets.
[0012] The ITSM process engine is used for lifecycle management of operation and maintenance application work orders;
[0013] The mapping and transformation engine is used to convert the work order data of the operation and maintenance application work order into authorization rules that can be recognized by the operation and maintenance audit gateway.
[0014] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0015] At least one processor; and
[0016] A memory communicatively connected to the at least one processor; wherein,
[0017] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the operation and maintenance access control method according to any embodiment of the present invention.
[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the operation and maintenance access control method according to any embodiment of the present invention.
[0019] The technical solution of this invention is applied to the operation and maintenance audit gateway of the operation and maintenance access control system. After the target operation and maintenance session is successfully established, the real-time status of the target operation and maintenance application work order is monitored. The target operation and maintenance application work order is the trigger condition for establishing the target operation and maintenance session. If the real-time status is determined to be invalid, the target operation and maintenance session is terminated. By adopting the technical means of operation and maintenance access control driven by the operation and maintenance application work order status, the problem of the disconnect between the authorization status and the operation and maintenance session lifecycle in the existing technology is solved. This realizes the real-time constraint of the authorization status on the operation and maintenance session, improves the accuracy of operation and maintenance access control, and improves control efficiency.
[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1aA flowchart of an operation and maintenance access control method provided in an embodiment of the present invention;
[0023] Figure 1b This embodiment provides a schematic diagram of a work order status linkage session control.
[0024] Figure 1c This is a complete schematic diagram of an operation and maintenance access control method provided in this embodiment;
[0025] Figure 1d This embodiment provides a flowchart of an operation and maintenance access control method based on an operation and maintenance access control system.
[0026] Figure 2 This is a schematic diagram of the structure of an operation and maintenance access control system provided in an embodiment of the present invention;
[0027] Figure 3 This is a schematic diagram of the structure of an electronic device that implements the operation and maintenance access control method of this invention. Detailed Implementation
[0028] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0029] It should be noted that the terms "comprising" and "having" and any variations thereof in the specification, claims and accompanying drawings of this invention are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such processes, methods, products or devices.
[0030] Figure 1a This is a flowchart illustrating an operation and maintenance access control method provided in an embodiment of the present invention. This embodiment is applicable to situations where operation and maintenance access needs to be controlled. The method can be executed by an operation and maintenance audit gateway within an operation and maintenance access control system. This operation and maintenance audit gateway can be implemented in hardware and / or software and can be configured within a server. The operation and maintenance access control system may also include a certificate server, an asset credential vault, an ITSM process engine, and a mapping and transformation engine.
[0031] like Figure 1a As shown, the operation and maintenance access control method includes:
[0032] S110. After the target operation and maintenance session is successfully established, monitor the real-time status of the target operation and maintenance application work order; the target operation and maintenance application work order is the trigger condition for establishing the target operation and maintenance session.
[0033] In this context, an operations and maintenance (O&M) session refers to a complete interaction process established between an O&M personnel and an asset (such as a server, database, or web application) through the O&M personnel's client when performing asset O&M management tasks. A target O&M session can refer to a specific O&M session among multiple O&M sessions managed by the O&M access control system. An O&M work order refers to an O&M work document generated by an O&M personnel when performing asset O&M management tasks. A target O&M work order can refer to a specific work order among multiple O&M work orders managed by the O&M access control system. The real-time status of a target O&M work order can indicate whether it is approved, withdrawn, rejected, or abnormally terminated.
[0034] In this embodiment, the work order data for an operation and maintenance application may include a work order identifier, an operation and maintenance personnel identifier, the requested operation and maintenance asset, the operation and maintenance type, the work order validity period, the operation and maintenance business reason, and the work order application time. For example, the work order data structure may be as follows:
[0035] json
[0036] {
[0037] "ticket_id": "INC20240115001",
[0038] "applicant": "zhangsan@company.com",
[0039] "target_assets": ["192.168.1.100", "192.168.1.101", "db-master-01"],
[0040] "action_type": ["ssh_shell", "sftp_upload"],
[0041] "requested_duration": "4h",
[0042] "business_reason": "Routine database inspection",
[0043] "apply_time": "2024-01-15T08:30:00Z"
[0044] }
[0045] In this context, INC20240115001 can represent the work order identifier, zhangsan@company.com can represent the operations and maintenance personnel identifier, "192.168.1.100", "192.168.1.101", and "db-master-01" can represent three assets requested for operations and maintenance, "ssh_shell" and "sftp_upload" can represent the types of operations and maintenance, the validity period of the work order can be 4 hours, the reason for operations and maintenance can be database rational inspection, and the work order application time can be 2024-01-15T08:30:00Z.
[0046] In this embodiment, after the operation and maintenance personnel submit the target operation and maintenance application work order and it is approved, the establishment of the target operation and maintenance session is triggered. Then, the status of the target operation and maintenance application work order can be monitored in real time after the target operation and maintenance session is successfully established.
[0047] S120. If the real-time status is determined to be invalid, terminate the target operation and maintenance session.
[0048] In this embodiment, if the real-time status of the target maintenance application work order is detected to be invalid (such as revocation, rejection, or abnormal termination), the target maintenance session matched with the target maintenance application work order can be terminated.
[0049] In one optional implementation, terminating the target operation and maintenance session when the real-time status is determined to be invalid may include: determining that the real-time status of the target operation and maintenance application ticket corresponding to the target authorization rule is invalid when the target authorization rule is detected to have expired, or when a deletion instruction for the target authorization rule is received; wherein, the target authorization rule is established based on the target operation and maintenance application ticket, the target authorization rule is used to define the access permission rules for the target operation and maintenance personnel to the target resources, the target authorization rule includes an authorization rule identifier and an operation and maintenance application ticket identifier, and the deletion instruction includes the rule identifier of the target authorization rule; retrieving the target operation and maintenance session associated with the target authorization rule and terminating the target operation and maintenance session.
[0050] In one scenario, the operations and maintenance audit gateway can periodically check the pre-stored authorization rules. If it detects that a target authorization rule has expired normally, it can determine that the target operations and maintenance application work order corresponding to the rule is invalid due to the normal expiration of the target authorization rule. If the target operations and maintenance session associated with the rule is still active, the operations and maintenance audit gateway can send a warning message to the operations and maintenance personnel (e.g., "Your authorization has expired, and the session will be disconnected in 60 seconds"), and forcibly disconnect the front-end and back-end connections corresponding to the target operations and maintenance session after waiting for 60 seconds.
[0051] In another scenario, if the ITSM process engine sends a notification of a work order status change, the mapping and transformation engine, upon receiving the notification, identifies it as a revocation, rejection, or abnormal termination event. It can then send a rule deletion command to the operations and maintenance audit gateway (e.g., DELETE / api / acl / rules / ACL_INC20260115001, where INC20260115001 can represent a rule identifier). Upon receiving the rule deletion command, the operations and maintenance audit gateway can delete the corresponding rule from the ACL (Access Control Lists) table and retrieve all active sessions associated with that rule. A forced disconnect is then performed on each active session: a message is sent to the operations and maintenance personnel (e.g., "The work order has been revoked; the session is terminated immediately"), disconnecting the front-end and back-end connections.
[0052] Based on the above optional implementation methods, the target authorization rule can also be deleted from the preset rule storage table. The preset rule storage table can, for example, refer to an ACL table.
[0053] Optionally, audit logs can be generated for the target maintenance session and associated with the work order identifier of the target maintenance request work order. The audit log includes at least one of the following: audit time, maintenance personnel identifier, requested maintenance assets, and maintenance request command content. This setting associates the audit log with the maintenance request work order identifier and facilitates subsequent traceability.
[0054] To enable those skilled in the art to better understand the two situations described above, Figure 1b This embodiment provides a schematic diagram of a work order status linkage session control. During the operation and maintenance session, the authorization status is monitored; if the authorization time expires, the authorization rule is deleted, a warning is sent, the operation and maintenance session is forcibly disconnected, and an audit log is recorded; if the work order status changes (revoked, rejected, abnormal, etc.), the authorization rule is immediately deleted based on the notification information, the operation and maintenance session is forcibly disconnected without waiting time, and an audit log is recorded.
[0055] In an optional implementation, the target authorization rule of this embodiment can be stored in the preset rule storage table of the operation and maintenance audit gateway in the following way: receiving the target authorization rule pushed by the mapping and conversion engine and writing the target authorization rule into the preset rule storage table; wherein, the target authorization rule is generated by the mapping and conversion engine based on the work order data of the target operation and maintenance application work order, and the work order data is notified to the mapping and conversion engine after the ITSM process engine approves the target operation and maintenance application work order; the target authorization rule also includes the operation and maintenance personnel identifier, the applied operation and maintenance asset, the operation and maintenance operation type, the rule effective time and the rule expiration time, the rule effective time is the approval time of the target operation and maintenance application work order, and the rule expiration time is the sum of the rule effective time and the work order validity period.
[0056] In this embodiment, the mapping and transformation engine obtains the work order data of the target maintenance application work order based on the notification from the ITSM process engine, and calculates the rule effective time and rule expiration time based on the work order data. This then generates a five-tuple authorization rule (i.e., the target authorization rule) that can be recognized by the maintenance audit gateway. Its structure can be exemplarily as follows:
[0057] json
[0058] {
[0059] "rule_id": "ACL_INC20240115001", (Authorization rule number)
[0060] "principal": "zhangsan@company.com",
[0061] "assets": ["asset_id_100", "asset_id_101", "asset_id_db01"],
[0062] "actions": ["ssh_shell", "sftp_upload"],
[0063] "valid_from": "2024-01-15T09:15:00Z",
[0064] "valid_until": "2024-01-15T13:15:00Z",
[0065] "source_ticket": "INC20240115001"
[0066] }
[0067] Among them, INC20240115001 can represent the rule identifier, the valid_from field can represent the rule effective time, the valid_until field can represent the rule expiration time, and the source_ticket field can represent the traceability certificate (i.e., the associated work order identifier).
[0068] The mapping and transformation engine can push the authorization rule to the operation and maintenance audit gateway through the application programming interface, and the operation and maintenance audit gateway will write the rule into the in-memory ACL table.
[0069] This embodiment embeds the absolute time window (i.e., the rule's effective time and expiration time) into the authorization rule. The validity of permissions can be determined simply by comparing the current time, eliminating the need for external scheduled tasks to poll and delete. The authorization rule also retains the `source_ticket` field, enabling bidirectional traceability between the authorization rule and the work order.
[0070] In one optional implementation, the target operation and maintenance session of this embodiment can be established in the following way: receiving a session connection request from the operation and maintenance personnel's client; sending a certificate verification request to the certificate server for certificate verification based on the identity authentication certificate carried in the session connection request, wherein the identity authentication certificate is obtained by the operation and maintenance personnel through the client from the certificate server; if the certificate verification is successful, instructing the client to display a list of accessible assets to the operation and maintenance personnel and receiving asset access requests from the client; sending a credential retrieval request to the asset credential vault based on the target asset identifier carried in the asset access request to query the credential mapping relationship and obtain the asset access credential of the target asset; connecting to the target asset according to the asset access credential of the target asset to successfully establish the target operation and maintenance session.
[0071] Based on the above optional implementation methods, determining that the certificate verification is successful may include: performing signature verification on the identity authentication certificate; verifying the certificate validity period of the identity authentication certificate if the signature verification is successful; determining that the certificate verification is successful if the certificate validity period verification is successful; before querying the credential mapping relationship and obtaining the asset access credential of the target asset, it may further include: verifying the validity of the current request time of the credential acquisition request, verifying the permission of the requested target asset of the credential acquisition request, and verifying the permission of the request operation type of the credential acquisition request according to the target authorization rules; if all verifications are successful, triggering the operation of querying the credential mapping relationship and obtaining the asset access credential of the target asset.
[0072] The authentication method in this embodiment can be implemented using SSH CA certificates, FIDO2 / WebAuthn hardware keys, mTLS client certificates, or Kerberos tickets.
[0073] The asset access credential acquisition method in this embodiment can also be implemented using SSH certificate issuance, API (Application Programming Interface) key injection, and other methods.
[0074] To enable those skilled in the art to better understand the operation and maintenance access control method of this embodiment. Figure 1cThis is a complete schematic diagram of an operation and maintenance access control method provided in this embodiment. The process includes: operation and maintenance personnel applying for an SSH certificate; certificate issuance; submission of an operation and maintenance work order to request access to the target asset; ITSM approval process; generation of a five-tuple authorization rule upon approval of the work order; pushing the authorization rule to the operation and maintenance audit gateway and writing it into the ACL table; the operation and maintenance personnel connecting to the operation and maintenance audit gateway via SSH with the certificate; the gateway verifying the certificate and checking ACL permissions; if the permission verification passes, the gateway obtains the asset access credentials, connects to the target asset to establish an operation and maintenance session, and the session is bridged to full-fledged auditing; if the permission verification fails, access to the target asset is denied.
[0075] To enable those skilled in the art to better understand the operation and maintenance access control method of this embodiment, Figure 1d This embodiment provides a flowchart of the implementation of an operation and maintenance access control method based on an operation and maintenance access control system.
[0076] 1. Certificate Application: When an operations and maintenance (O&M) personnel joins the company, the system administrator can create their identity record in the certificate server, including the user's unique identifier (e.g., employee ID abc_12345), department or role (e.g., DBA, network administrator), and the maximum allowed certificate validity period (e.g., a maximum of 8 hours). When the O&M personnel need to perform O&M operations, a key pair can be generated on the O&M personnel's local client. The private key is kept locally, and the public key is used for subsequent signing. The O&M personnel submit a signing request to the certificate server, which includes the public key content, the validity period of the request (e.g., 4 hours), and identity credentials.
[0077] 2. Certificate Issuance: The certificate service verifies identity credentials. If the credentials are valid, the server's private key is used to sign the user's public key, generating an identity certificate containing the user's identity information and setting its validity period. The certificate server returns the signed certificate to the operations and maintenance personnel. Example: Operations and maintenance personnel Zhang San applies for a certificate. The identity certificate issued by the certificate server contains: the operations and maintenance personnel identifier zhangsan@company.com, and the certificate validity period is from 2026-01-15T09:00:00 to 2026-01-15T17:00:00 (8-hour validity period). The certificate is signed with the server's private key.
[0078] 3. Submit a maintenance request work order.
[0079] 4. Once the operation and maintenance work order is approved, the authorization rules will be pushed to the operation and maintenance audit gateway.
[0080] 5. Initiate an operations and maintenance session connection: Operations and maintenance personnel use a client to connect to the operations and maintenance audit gateway, for example, bash ssh -i ~ / .ssh / user_cert zhangsan@jumpserver.company.com -p 2222.
[0081] 6. Certificate Verification: After receiving the identity certificate sent by the client, verify the validity of the certificate signature using the pre-configured server public key. If the signature is invalid, refuse the connection and return an error. After the signature verification is successful, check the certificate's expiration field. If the current time is not within the validity period, refuse the connection. After the expiration verification is successful, extract the operations personnel identification field (e.g., zhangsan@company.com) from the certificate and pass this identity information to subsequent modules. After all front-end authentications are successful, display the list of accessible assets to the operations personnel. This list is dynamically generated based on the rules in the ACL table that match the current Principal and whose current time is within the validity period.
[0082] 7. Obtain Asset Access Credentials: The gateway displays a list of assets that the operations and maintenance personnel are authorized to access. The personnel select the target asset (e.g., 192.168.1.100). The gateway checks whether the current time is within the validity period of the authorization rule, whether the target asset is in the assets list of the authorization rule, and whether the requested operation type is in the actions list of the rule. If any verification fails, the request is rejected. The gateway queries the mapping relationship between the asset and the credentials in the asset credential vault based on the target asset identifier, and sends a credential retrieval request to the asset credential vault through the application programming interface (e.g., POST / v1 / secret / data / assets / 192.168.1.100). The asset credential vault returns the privileged account and password for the asset (e.g., {"username": "root", "password": "P@ssw0rd!2026"}).
[0083] 8. Establish an operation and maintenance session connection: The gateway constructs an authentication message in memory and injects the obtained credentials into the message. Key security requirements: credentials are not written to disk or cached, and are immediately cleared from memory after use; the constructed authentication message is used to connect to the target asset, and a session is established after the target asset verifies the account and password.
[0084] 9. Work order expires and authorization rules are deleted.
[0085] 10. Disconnect the operation and maintenance session.
[0086] The technical solution of this invention is applied to the operation and maintenance audit gateway of the operation and maintenance access control system. After the target operation and maintenance session is successfully established, the real-time status of the target operation and maintenance application work order is monitored. The target operation and maintenance application work order is the trigger condition for establishing the target operation and maintenance session. If the real-time status is determined to be invalid, the target operation and maintenance session is terminated. By adopting the technical means of operation and maintenance access control driven by the operation and maintenance application work order status, the problem of the disconnect between the authorization status and the operation and maintenance session lifecycle in the existing technology is solved. This realizes the real-time constraint of the authorization status on the operation and maintenance session, improves the accuracy of operation and maintenance access control, and improves control efficiency.
[0087] Figure 2 This is a schematic diagram of the structure of an operation and maintenance access control system provided in an embodiment of the present invention. Figure 2 As shown, the system includes: an operation and maintenance audit gateway 210, a certificate server 220, an asset credential vault 230, an ITSM process engine 240, and a mapping and conversion engine 250. The operation and maintenance audit gateway is deployed between the operation and maintenance personnel's client and the assets, and the mapping and conversion engine is deployed between the ITSM process engine and the operation and maintenance audit gateway.
[0088] The operation and maintenance audit gateway 210 is used to execute the operation and maintenance access control method as described in any embodiment of the present invention;
[0089] Certificate server 220 is used to issue identity authentication certificates to operation and maintenance personnel and to verify the identity authentication certificates during the establishment of operation and maintenance sessions;
[0090] Asset credential safe 230 is used to store access credentials for assets;
[0091] ITSM Process Engine 240 is used for lifecycle management of operation and maintenance work orders;
[0092] The mapping and transformation engine 250 is used to convert the work order data of the operation and maintenance application work order into authorization rules that can be recognized by the operation and maintenance audit gateway.
[0093] The technical solution of this invention is applied to the operation and maintenance audit gateway of the operation and maintenance access control system. After the target operation and maintenance session is successfully established, the real-time status of the target operation and maintenance application work order is monitored. The target operation and maintenance application work order is the trigger condition for establishing the target operation and maintenance session. If the real-time status is determined to be invalid, the target operation and maintenance session is terminated. By adopting the technical means of operation and maintenance access control driven by the operation and maintenance application work order status, the problem of the disconnect between the authorization status and the operation and maintenance session lifecycle in the existing technology is solved. This realizes the real-time constraint of the authorization status on the operation and maintenance session, improves the accuracy of operation and maintenance access control, and improves control efficiency.
[0094] Figure 3A schematic diagram of an electronic device 300 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers or various forms of mobile devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0095] like Figure 3 As shown, electronic device 300 includes at least one electronic device 301 and a memory, such as a read-only memory (ROM) 302 or a random access memory (RAM) 303, communicatively connected to the at least one electronic device 301. The memory stores computer programs executable by at least one processor. Electronic device 301 can perform various appropriate actions and processes based on the computer program stored in the ROM 302 or loaded into the RAM 303 from storage unit 308. The RAM 303 can also store various programs and data required for the operation of electronic device 300. Electronic device 301, ROM 302, and RAM 303 are interconnected via bus 304. Input / output (I / O) interface 305 is also connected to bus 304.
[0096] Multiple components in electronic device 300 are connected to I / O interface 305, including: input unit 306, such as keyboard, mouse, etc.; output unit 307, such as various types of displays, speakers, etc.; storage unit 308, such as disk, optical disk, etc.; and communication unit 309, such as network card, modem, wireless transceiver, etc. Communication unit 309 allows electronic device 300 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0097] Electronic device 301 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of electronic device 301 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Electronic device 301 performs the various methods and processes described above, such as operational access control methods.
[0098] In some embodiments, the maintenance access control method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 308. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 300 via ROM 302 and / or communication unit 309. When the computer program is loaded into RAM 303 and executed by electronic device 301, one or more steps of the maintenance access control method described above may be performed. Alternatively, in other embodiments, electronic device 301 may be configured to perform the maintenance access control method by any other suitable means (e.g., by means of firmware).
[0099] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0100] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0101] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0102] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0103] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0104] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0105] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0106] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. An operation and maintenance access control method, applied to the operation and maintenance audit gateway of an operation and maintenance access control system, characterized in that, include: After the target maintenance session is successfully established, monitor the real-time status of the target maintenance work order. The target maintenance request work order is the trigger condition for establishing the target maintenance session; If the real-time status is determined to be invalid, the target operation and maintenance session is terminated.
2. The method according to claim 1, characterized in that, If the real-time status is determined to be invalid, the target operation and maintenance session is terminated, including: If a target authorization rule is detected to have expired, or if a deletion instruction for a target authorization rule is received, the real-time status of the target maintenance application work order corresponding to the target authorization rule is determined to be invalid; wherein, the target authorization rule is established based on the target maintenance application work order, the target authorization rule is used to define the access permission rules for target maintenance personnel to target resources, the target authorization rule includes an authorization rule identifier and a maintenance application work order identifier, and the deletion instruction includes the rule identifier of the target authorization rule; Retrieve the target operation and maintenance session associated with the target authorization rule, and terminate the target operation and maintenance session.
3. The method according to claim 2, characterized in that, Also includes: Delete the target authorization rule from the preset rule storage table.
4. The method according to claim 3, characterized in that, The operation and maintenance access control system also includes an ITSM process engine and a mapping and transformation engine; The target authorization rule is stored in the preset rule storage table in the following manner: Receive the target authorization rule pushed by the mapping conversion engine, and write the target authorization rule into the preset rule storage table; The target authorization rule is generated by the mapping and conversion engine based on the work order data of the target operation and maintenance application work order. The work order data is notified to the mapping and conversion engine by the ITSM process engine after the target operation and maintenance application work order is approved. The work order data includes work order identifier, maintenance personnel identifier, requested maintenance asset, maintenance operation type, work order validity period, maintenance business reason, and work order application time. The target authorization rule also includes the operation and maintenance personnel identifier, the applied operation and maintenance asset, the operation and maintenance type, the rule effective time and the rule expiration time. The rule effective time is the approval time of the target operation and maintenance application work order, and the rule expiration time is the sum of the rule effective time and the validity period of the work order.
5. The method according to claim 1, characterized in that, The operation and maintenance access control system also includes a certificate server and an asset credential vault. The target operation and maintenance session is established in the following way: Receive session connection requests from the operations and maintenance personnel's client; Based on the authentication certificate carried in the session connection request, a certificate verification request is sent to the certificate server to perform certificate verification, wherein the authentication certificate is obtained by the operation and maintenance personnel through the client from the certificate server; Once the certificate verification is successful, instruct the system to display the list of accessible assets to the operations and maintenance personnel through the client and receive asset access requests from the client. Based on the target asset identifier carried in the asset access request, a credential retrieval request is sent to the asset credential vault to query the credential mapping relationship and obtain the asset access credential of the target asset. Connect to the target asset based on the target asset's asset access credentials to successfully establish the target operation and maintenance session.
6. The method according to claim 5, characterized in that, The certificate verification is confirmed to be successful, including: Perform signature verification on the identity authentication certificate; If the signature verification passes, the validity period of the identity authentication certificate is verified. The certificate verification is deemed successful if the certificate validity period verification is passed. Before querying the credential mapping relationship and obtaining the asset access credentials for the target asset, the process also includes: The validity of the current request time of the credential acquisition request, the permission of the target asset of the credential acquisition request, and the permission of the request operation type of the credential acquisition request are verified according to the target authorization rules. If all verifications pass, the operation of querying the credential mapping relationship and obtaining the asset access credentials of the target asset is triggered.
7. The method according to claim 5, characterized in that, Also includes: An audit record is generated for the target maintenance session, and the audit record is associated with the work order identifier of the target maintenance application work order; The audit record includes at least one of the following: audit time, maintenance personnel identification, application for maintenance assets, and content of maintenance application command.
8. An operation and maintenance access control system, characterized in that, include: The system includes an operations and maintenance audit gateway, a certificate server, an asset credential vault, an ITSM process engine, and a mapping and conversion engine. The operations and maintenance audit gateway is deployed between the operations and maintenance personnel's client and the assets, and the mapping and conversion engine is deployed between the ITSM process engine and the operations and maintenance audit gateway. An operations and maintenance audit gateway is used to execute the operations and maintenance access control method as described in any one of claims 1-7; A certificate server is used to issue identity authentication certificates to operations and maintenance personnel and to verify the identity authentication certificates during the establishment of operations and maintenance sessions. An asset credential vault is used to store access credentials for assets. The ITSM process engine is used for lifecycle management of operation and maintenance application work orders; The mapping and transformation engine is used to convert the work order data of the operation and maintenance application work order into authorization rules that can be recognized by the operation and maintenance audit gateway.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform an operation and maintenance access control method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute and implement the operation and maintenance access control method according to any one of claims 1-7.