System and method for controlling access to cloud service provider based on SSH tunneling
The system leverages SSH tunneling to provide secure, agent-free access to CSPs, overcoming the limitations of traditional on-premises access control methods and enabling flexible, efficient access to diverse cloud environments.
Patent Information
- Application Number
- PCT/KR2024/000829
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-22
- Filing Date
- 2024-01-17
- Publication Date
- 2025-05-30
AI Technical Summary
Existing cloud computing services require a server for access control to be located on-premises and necessitate expensive dedicated lines and VPN agents, limiting access to cloud service providers (CSPs) and restricting flexibility.
A system and method utilizing SSH tunneling to enable access to and control of an operating system (OS) and database (DB) within a CSP, independent of on-premises locations and without a separate agent, by employing a DB server, web server, connection server, and log server to manage authentication, access determination, and SSH tunneling connections.
This solution allows for efficient access control and automation of CSP environments without the need for on-premises servers or separate agents, enabling seamless connections to various CSPs, including AWS, Azure, and GCP, and supporting environments like Linux, Windows, and DB.
Smart Images

Figure KR2024000829_30052025_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR CONTROLLING ACCESS TO CLOUD SERVICE PROVIDER BASED ON SSH TUNNELING
[0001] The present invention relates to a system and method for controlling an access to a cloud service provider using a secure shell (SSH) tunneling. More specifically, the present invention relates to a system and method for enabling an access to (and control thereof) an operating system (OS) and a database (DB) of a cloud service provider and its automation, independently of On-Premise and without a separate agent.
[0002] A cloud computing service is a service that provides resources (server, memory, CPU, storage, etc.) required to build up a computing infrastructure environment to computing nodes at physically different locations by utilizing a virtualization technology and a distributed processing technology.
[0003] The cloud computing service can provide a user with the user's desired computing environment regardless of time and place as long as an Internet connection is provided, and all services such as after-sales service for hardware / software can be provided in the cloud computing environment, and thus the effects of savings in system maintenance costs, hardware / software purchase costs, and energy, etc. can be expected.
[0004] As this cloud computing service has attracted great attention, cloud service providers (hereinafter referred to as 'CSP') such as Google, Amazon, Apple, Microsoft, Alibaba, and Tencent are releasing their own cloud computing services (e.g. Google cloud, AWS, iCloud, Azure, Aliyun, Tengxunyun, etc.) thereby opening the era of the cloud computing.
[0005] Meanwhile, existing cloud computing services implement an access control and authorization policies in different ways for each CSP. In order for a user to access the CSP, an agent for an expensive dedicated line and VPN connection is required. Resultantly, there exists a limitation that a server for controlling the user's access to the CSP must be located in an On-Premise manner or physically connected.
[0006] Unlike a conventional method which requires a server that controls an user’s access to the OS and DB within a CSP to be located within an On-Premises environment and requires an expensive dedicated line and an agent for VPN connection, the problem that the present invention aims to solve is to provide a technology for enabling an access to (and control thereof) an operating system (OS) and a database (DB) of a cloud service provider as well as its automation, independently of the On-Premise and without a separate agent.
[0007] Meanwhile, the technical problems of the present invention are not limited to that mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art from the description below.
[0008] The system according to one embodiment may comprise a DB server for storing authentication information related to a CSP access authority of a user terminal; a web server, upon acquiring a request for access to the CSP from the user terminal, for determining whether the access to the CSP is permitted by checking the access authority of the user terminal to the CSP through the DB server; and a connection server for performing a connection to the CSP based on SSH tunneling according to the determination of the web server and for transmitting log information of the user terminal created according to the connection to a log server.
[0009] Additionally, the connection server may perform SSH tunneling with a Linux host located in the CSP to thereby perform a connection between the user terminal and the target server included in the CSP based on a web socket.
[0010] Additionally, the web server may store predefined script information for each CSP regarding information to be delivered to the connection server, and deliver the predefined script information to the connection server according to the CSP selection of the user terminal.
[0011] Additionally, the script information may include preset information about the IP / Port of the Linux host, Keyfile / Username / Password of the Linux host, OS of the target server, IP / Port of the target server, and Keyfile / Username / Password of the target server.
[0012] Additionally, if the OS of the target server is Linux, the connection server may perform the SSH Tunneling using a Linux host and Python SSH Tunnel Forwarder based on the script information received from the web server to thereby create a Connection Random Port to the target server, and create a channel based on Python Paramiko for connection to the Connection Random Port of the user terminal.
[0013] Additionally, if the OS of the target server is Windows, the connection server may perform SSH Tunneling using the Linux host and Python SSH Tunnel Forwarder based on the script information received from the web server to thereby create a Connection Random Port to the target server, and create a RDP connection file for connection to the Connection Random Port of the user terminal.
[0014] Additionally, if a computing resource of the target server is a database, the connection server may perform the SSH Tunneling using the Linux host and Python SSH Tunnel Forwarder based on the script information received from the web server to thereby create a Connection Random Port to the target server, and establish an ODBC connection for connection to the Connection Random Port of the user terminal.
[0015] Additionally, the connection server may create a virtual Bastion server consisting of preset information between the Linux host and the connection server and perform the SSH tunneling with the Linux host.
[0016] Additionally, the connection server may perform a connection by matching preset information on the Bastion server with preset information on the CSP where the Linux host is located.
[0017] Additionally, the connection server may perform a connection by matching information on Bastion name for management purpose, Bastion IP, SSH Port, Bastion authentication keyfile, OS type, Group for authority management and Bastion Username / Password as the preset information of the Bastion server to information on Bastion name for management purpose, IP of the target server, SSH Port, authentication keyfile of the target server, OS type, Group for authority management and Bastion Username / Password as the preset information on the CSP where the Linux is located.
[0018] Additionally, the system may further comprise a log server for storing log information related to the CSP access history of the user terminal.
[0019] A method of operating the SSH tunneling-based CSP access control system according to one embodiment may comprise the steps of storing, by a DB server, authentication information related to a CSP access authority of a user terminal; upon acquiring a request for access to the CSP from the user terminal, by a web server, determining whether the access to the CSP is permitted by checking the access authority of the user terminal to the CSP through the DB server; and performing, by a connection server, a connection to the CSP based on SSH tunneling according to the determination of the web server and transmitting log information of the user terminal created according to the connection to a log server.
[0020] The present invention can implement an environment that accesses a target server located in various CSP environments (AWS, Azure, GCP, NCP, On-Premise, etc.) and automate it without requiring a separate agent. In particular, the present invention performs a connection to a Linux host of the CSP through a connection server that performs a SSH tunneling function, allowing a user to efficiently utilize the access control function, easily access various environments such as Linux, Windows and DB and utilize resources.
[0021] Furthermore, the present invention can provide a connection between a user terminal and a target server by performing the SSH tunneling with a Linux host based on a web socket and can implement an SSH tunneling connection environment between target servers and can implement an SSH tunneling connection environment between a virtual Bastion server and the mapped target server by registering information on the target server to be connected based on the Bastion server.
[0022] Meanwhile, the effects of the present invention are not limited to those mentioned above, and other technical effects not mentioned will be clearly understood by those skilled in the art from the description below.
[0023] Figure 1 is an example diagram comparing the existing CSP access control system with the CSP access control system of the present invention.
[0024] Figure 2 is a configuration diagram of a system for controlling an access to an OS and DB within a CSP based on a SSH tunneling according to an embodiment.
[0025] Figure 3 is a configuration diagram of a server and a host constituting a system according to an embodiment.
[0026] Figure 4 is a flowchart showing the steps of the operation performed by the system configuration according to one embodiment.
[0027] Figure 5 is an example diagram of a system that performs a connection to the target server through script information according to an embodiment, if the target server is Linux.
[0028] Figure 6 is an example diagram of a system that performs a connection to a target server through script information according to an embodiment, when the target server is Windows.
[0029] Figure 7 is an example diagram of a system that performs a connection to the target server through script information according to an embodiment, if the target server is a database.
[0030] Figure 8 is an example diagram of an operation of mapping SSH tunneling information by registering an access server information based on Bastion server information according to an embodiment.
[0031] Figure 9 is an example diagram of an operation of performing SSH tunneling and implementing an SSH access environment, when accessing a target server based on the relationship between the mapped Bastion server and the target server according to an embodiment.
[0032] Details regarding the object, technical configuration and its acting effect will be more clearly understood by the following detailed description with reference to the drawings attached to the specification of the present invention. Embodiments according to the present invention will be described in detail with reference to the attached drawings.
[0033] The embodiments disclosed herein should not be construed or used as limiting the scope of the present invention. It is obvious to those skilled in the art that the description, including embodiments, of this specification has various applications. Accordingly, any embodiments described in the detailed description of the present invention are illustrative to better explain the present invention and are not intended to limit the scope of the present invention to the described embodiments.
[0034] The functional blocks shown in the drawings and described below are only examples of possible implementations. Other functional blocks may be used in other implementations without departing from the spirit and scope of the present invention. Additionally, although one or more functional blocks of the present invention are shown as individual blocks, one or more of the functional blocks of the present invention may be the combination of various hardware and software components that execute the same function.
[0035] Additionally, the expression including certain components is an “open” expression and simply refers to the presence of the relevant components and should not be understood as excluding additional components.
[0036] Furthermore, when a component is referred to as being “connected” or “coupled” to another component, it should be understood that although it may be directly connected or coupled to the other component, other components may exist in between.
[0037] Various embodiments of the present invention are described below with reference to the accompanying drawings. However, this is not intended to limit the present invention to specific embodiments and it should be understood to encompass various modifications, equivalents, and / or alternatives to the embodiments of the present invention.
[0038] Figure 1 is an example diagram comparing the existing CSP access control system with the CSP access control system of the present invention.
[0039] Referring to Figure 1(a), because in the existing CSP access control system, policies that grant access control and authority in different ways are implemented for each CSP, an agent for an expensive dedicated line and VPN connection is required to access the CSP, and the access control solution for CSP must be located within On-Premise.
[0040] Referring to Figure 1(b), the CSP access control system of the present invention can provide an environment capable of accessing the target server located in various CSP environments (AWS, Azure, GCP, NCP, On-Premise, etc.) without a separate agent. To this end, the embodiment of the present invention may allow a user to efficiently utilize the access control function by connecting to a Linux host through the SSH tunneling function, and provide a function in which the user can access a target server in various environments (Linux, Windows, DB).
[0041] Hereinafter, the CSP access control system of the present invention will be discussed in detail with reference to Figures 2 to 9.
[0042] Figure 2 is a configuration diagram of a CSP access control system (hereinafter referred to as “system”) according to an embodiment.
[0043] Referring to Figure 2, a system according to one embodiment may include a user terminal 10, an access control solution and a CSP.
[0044] The user terminal 10 is a terminal used by a user who wishes to receive a cloud computing service. The cloud computing service is a computing service that provides computing resources to a remote user by utilizing virtualization technology and distributed processing technology. The user terminal 10 can be provided with a desired computing environment from the CSP through the Internet environment. The user terminal 10 may be implemented as various types of devices capable of performing a calculation through a processor and transmitting and receiving information through a network. For example, the user terminal may include a portable communication device, a smart phone, a computer device, a portable multimedia device, a laptop, a tablet PC, etc.
[0045] The access control solution may include one or more servers 20, 30, 40 and 50 that are independent of the On-Premise and that provide a solution of an access control function for the CSP to the user terminal 10 without a separate agent.
[0046] The access control solution according to one embodiment may include a DB server 20, a web server 30, a connection server 40 and a log server 50.
[0047] The DB server 20 may store authentication information related to the CSP access authority of the user terminal 10. The DB server 20 may include a database that stores data and that transmits and receives information to and from an external server.
[0048] Upon receiving a request for access to the CSP from the user terminal 10, the web server 30 may check the access authority of the user terminal 10 to the CSP through the DB server 20 and determine whether or not access to the CSP is permitted.
[0049] The connection server 40 may perform a connection to the CSP based on SSH tunneling according to the determination of the web server 30 and transmit the log information of the user terminal 10 created by the connection between the user terminal 10 and the CSP to the server 50.
[0050] The log server 50 may store the log information related to the CSP access history of the user terminal 10. The log server 50 may include a database that stores data and that transmits and receives information to and from the external server.
[0051] The CSP is a cloud service provider that provides a cloud computing service according to the request of the user terminal 10. The CSP may include one or more servers for providing a computing resource to a remote user by utilizing virtualization technology and distributed processing technology.
[0052] The CSP according to one embodiment may include a Linux host 60 and a target server (for example, Linux server, Windows server, database, etc.).
[0053] The Linux host 60 is a host that performs SSH tunneling with the connection server 40. The Linux host 60 may perform a role of allowing access and control from the user terminal 10 to the target server. A detailed description of SSH tunneling between the Linux host 60 and the connection server 40 will be described later with reference to Figures 4 to 7.
[0054] The target server may provide various computing resources (for example, server, memory, CPU, storage, etc.) requested by the user terminal 10 to the CSP. A detailed description of the connection process from the user terminal 10 to the target server will be described later with reference to Figures 4 to 7.
[0055] The user terminal 10, the access control solution, and the CSP are operably connected through a communication network to transmit and receive information. For example, the communication network may include wired and wireless communication networks such as a local area network (LAN), a wide area network (WAN), a virtual network and a remote communication.
[0056] Hereinafter, before explaining the specific operations performed by the system configuration according to one embodiment, the configuration of the server and hosts 20, 30, 40, 50 and 60 that constitute a system according to one embodiment will be discussed.
[0057] Figure 3 is a configuration diagram of a server and hosts 20, 30, 40, 50 and 60 that constitute a system according to an embodiment.
[0058] Referring to Figure 3, the server and the hosts 20, 30, 40, 50, and 60 according to an embodiment may include a memory 110, a processor 120, an input / output interface 130 and a communication interface 140, respectively.
[0059] The memory 110 may store data acquired from an external device or data created itself. The memory 110 may store commands that cause the processor 120 to be operated.
[0060] The processor 120 is a computing device that controls overall operations. The processor 120 may execute commands stored in the memory 110. The operations of the server and hosts 20, 30, 40, 50 and 60 according to the embodiment of the present invention may be understood as operations performed by the processor 120.
[0061] The input / output interface 130 may include a hardware interface or a software interface that inputs or outputs information.
[0062] The communication interface 140 allows information to be transmitted and received through a communication network. To this end, the communication interface 140 may include a wireless communication module or a wired communication module.
[0063] The server and hosts 20, 30, 40, 50 and 60 that constitute the system according to one embodiment may be implemented as various types of devices capable of performing calculations through the processor 120 and transmitting receiving information through a network. For example, they may be implemented in the form of a computer device, a portable communication device, a smart phone, a portable multimedia device, a laptop, a tablet PC, etc., but is not limited to this example.
[0064] Hereinafter, specific examples of operations performed by the server and hosts 20, 30, 40, 50 and 60 that constitute the system in one embodiment will be discussed with reference to Figures 4 to 9.
[0065] Figure 4 is a flowchart showing the steps of the operation performed by the configuration of the system according to one embodiment.
[0066] Referring to Figure 4, in step S1010, the DB server 20 may store authentication information related to the CSP access authority of the user terminal 10. For example, the authentication information may include information on the CSP used by the user, ID for accessing the CSP, password, type of computing service, authority for each user group and detailed information about the CSP.
[0067] In step S1020, upon receiving an access request to the CSP from the user terminal 10, the web server 30 may check, through the DB server 20, the access authority of the user terminal 10 that has requested the access to the CSP and determine whether or not it is permitted for the user terminal 10 to access the CSP. If the web server 30 determines that the access to the CSP of the user terminal 10 is permitted, the web server 30 may request the connection server 40 to connect the user terminal 10 to the CSP.
[0068] In step S1030, the connection server 40 may perform a connection to the Linux host 60 of the CSP through SSH tunneling based on the access determination of the web server 30. The SSH tunneling is a technology that relays a network communication using a secure shell (SSH) protocol. The SSH tunneling enhances security and privacy and allows to remotely access other systems or use network services.
[0069] As an example, the connection server 40 may relay the connection between the user terminal 10 and the target server of the CSP by performing the SSH tunneling based on a web socket with the Linux host 60 located in the CSP. Accordingly, the connection server 40 may transmit log information created by the connection between the user terminal 10 and the CSP to the log server 50.
[0070] In step S1040, the log server 50 may store log information related to the CSP access history of the user terminal 10.
[0071] Hereinafter, an embodiment specifically applicable among the operations of steps S1010 to S1040 will be discussed.
[0072] Referring again to Figure 3 and assuming that the first target server is a Linux server, an embodiment regarding the connection between the user terminal 10 and the first target server will be described.
[0073] If the user terminal 10 requests a connection to the first target server, the web server 30 may acquire authentication information of the user terminal 10 through the DB server 20 and deliver the authentication information to the connection server 40. For example, the authentication information may include a type of OS of server to be connected, Linux Host IP / Port, Linux Host Keyfile / Username / Password, Target Server IP / Port, Target Server Keyfile / Username / Password, etc. The connection server 40 may create a SSH tunneling using the Linux host 60 and the Python SSH Tunnel Forwarder based on the received information, and create a Connection Random Port for connecting to the first target server. Additionally, the connection server 40 may create a channel for Invoke shell to the Connection Random Port using Python Paramiko. When the connection is successful, the connection server 40 may provide an interface using xterm and Websocket to the user terminal 10. The user terminal 10 may enter commands or keyboard inputs like the same environment as the actual shell screen through the interface provided by the connection server 40. The connection server 40 transmits the entered commands or keyboard inputs and transmits the received results back to the user terminal 10, and the log server 50 may store the transmission and reception contents.
[0074] Referring again to Figure 3 and assuming that the second target server is a Windows server, an embodiment of the connection between the user terminal 10 and the second target server will be described.
[0075] If the user terminal 10 requests a connection to the second target server, the web server 30 may acquire authentication information of the user terminal 10 through the DB server 20 and deliver the authentication information to the connection server 40. For example, the authentication information may include a type of OS of a server to be connected, Linux Host IP / Port, Linux Host Keyfile / Username / Password, Target Server IP / Port, etc. The connection server 40 may create a SSH tunneling using the Linux host 60 and the Python SSH Tunnel Forwarder based on the received information, and create a Connection Random Port for connecting to the second target server. Additionally, the connection server 40 may create an RDP connection file for Windows connection that connects to the Connection Random Port. When the connection is successful, the connection server 40 may deliver a download path for the created RDP file to the user. The user terminal 10 may perform an RDP connection to the second target server by executing the RDP file provided by the connection server 40. The log server 50 may store the user's server connection time and history.
[0076] Referring again to Figure 3 and assuming that the third target server is a database, an embodiment of the connection between the user terminal 10 and a third target server will be described.
[0077] If the user terminal 10 requests a connection to a third target server, the web server 30 may acquire authentication information of the user terminal 10 through the DB server 20 and deliver the authentication information to the connection server 40. For example, the authentication information may include a type of OS of a server to be connected, Linux Host IP / Port, Linux Host Keyfile / Username / Password, Database IP / Port, etc. The connection server 40 may create SSH tunneling using the Linux host 60 and Python SSH Tunnel Forwarder based on the received information, and create a Connection Random Port for connecting to a third target server. The connection server 40 may configure an ODBC connection using the Connection Random Port for connection to the database. When the connection is successful, the connection server 40 may provide the ODBC information to the user. The user terminal 10 may perform a connection using a database management tool based on the ODBC information provided by the connection server 40. The log server 50 may store the user's server connection time and history of SQL commands.
[0078] Hereinafter, another embodiment specifically applicable among the operations of the steps S1010 to S1040 will be discussed.
[0079] According to one embodiment, the web server 30 may pre-store the pre-defined script information for each CSP regarding information to be delivered to the connection server 40, and deliver, to the connection server 40, the script information about the CSP to which the user terminal 10 has requested to access among the pre-defined script information for each CSP in accordance with the CSP selection of the user terminal 10. For example, the script information may include pre-set information for the IP / Port of the Linux host 60, Keyfile / Username / Password of the Linux host 60, OS of the target server, IP / Port of the target server, and Keyfile / Username / Password of the target server. Accordingly, the connection server 40 may perform a connection to the CSP's Linux host 60 through SSH tunneling based on pre-set script information.
[0080] An embodiment of an operation using the preset script information will be described with reference to Figures 5 to 7.
[0081] Figure 5 is an example diagram of a system that performs a connection to the target server through the script information according to an embodiment when the target server is a Linux server.
[0082] Referring to Figure 5, the user terminal 10 may select a Linux server on which the script will be executed among the list of connectable servers provided by the web server 30. The web server 30 may deliver a type of OS of a server to be connected, Linux Host IP / Port, Linux Host Keyfile / Username / Password, Target Server IP / Port, Target Server Keyfile / Username / Password, etc. to the connection server 40 in the POST scheme. Based on the received information, the connection server 40 may create SSH tunneling using the Linux host 60 and the Python SSH Tunnel Forwarder and create a Connection Random Port for connection to the target server. The connection server 40 may create a connection to the Connection Random Port using Python Paramiko. When the connection is successful, the connection server 40 may deliver and execute a script selected by the user through Python Paramiko. The user terminal 10 may check the actual result through the script execution result screen provided by the connection server 40. The log server 50 may store the script execution results as a log.
[0083] Figure 6 is an example diagram of a system that performs a connection to the target server through script information according to an embodiment, when the target server is a Windows server.
[0084] Referring to Figure 6, the user terminal 10 may select a Windows server on which the script will be executed among the list of connectable servers provided by the web server 30. The web server 30 may deliver a type of OS of a server to be connected, Linux Host IP / Port, Linux Host Keyfile / Username / Password, Target Server IP / Port, Target Server Keyfile / Username / Password, etc. to the connection server 40 in the POST scheme. Based on the received information, the connection server 40 may create SSH Tunneling using Linux Host and Python SSH Tunnel Forwarder and create a Connection Random Port for connection to the target server. The connection server 40 may create a connection to the Connection Random Port using Python pywinrm. When the connection is successful, the connection server 40 may deliver and execute a script selected by the user through Python Paramiko. The user terminal 10 may check the actual result through the script execution result screen provided by the connection server 40. The log server 50 may store script execution result as a log.
[0085] Figure 7 is an example diagram of a system that performs a connection to the target server through script information according to an embodiment, when the target server is a database.
[0086] Referring to Figure 7, the user terminal 10 may select a SQL on which the script will be executed from the list of connectable databases provided by the web server 30. The web server 30 may deliver a type of OS of a server to be connected, Linux Host IP / Port, Linux Host Keyfile / Username / Password, Target Server IP / Port, Target Server Keyfile / Username / Password, etc. to the connection server 40 in the POST scheme. Based on the received information, the connection server 40 may create SSH Tunneling using Linux Host and Python SSH Tunnel Forwarder and create a Connection Random Port for connection to the target server. The connection server 40 may create a connection to the Connection Random Port using Python pyodbc. When the connection is successful, the connection server 40 may deliver and execute a script selected by the user through Python pyodbc. The user terminal 10 may check the actual result through the SQL execution result screen provided by the connection server 40. The log server 50 may store the SQL execution result as a log.
[0087] Hereinafter, another embodiment specifically applicable among the operations of the steps S1010 to S1040 will be discussed.
[0088] According to one embodiment, the connection server 40 may perform SSH tunneling with the Linux host 60 by creating a virtual Bastion server consisting of preset information between the Linux host 60 and the connection server 40.
[0089] An embodiment of creating a virtual Bastion server and performing SSH tunneling with the Linux host 60 will be described with reference to Figures 8 and 9.
[0090] Figure 8 is an example diagram of an operation of pre-mapping and storing SSH tunneling information of a target server to be connected based on Bastion server information according to an embodiment.
[0091] Referring to Figure 8, the connection server 40 may map and store the information of the virtual Bastion server and the CSP. For example, the information on the virtual Bastion server may include Bastion name for management purpose, Bastion IP and SSH Port, Bastion authentication Keyfile, OS (Windows or Linux), Group for authority management, and Bastion Username / Password. For example, the CSP information may include Bastion name for management purpose, IP and SSH Port of the target server, authentication Keyfile of the target server, OS (Windows or Linux), Group for authority management and Bastion Username / Password. In other words, the connection server 40 may provide functions such as providing a connection environment directly through the script without having to follow the CSP standards for each individual connection by using a script preset to meet the standard of each CSP.
[0092] Figure 9 is an example of an operation of performing SSH tunneling when connecting to a target server and implementing an SSH connection environment based on the relationship between the mapped bastion server and the target server according to an embodiment.
[0093] Referring to Figure 9, the left side of the dotted line refers to information on the Bastion server, and the right side of the dotted line refers to information on the mapped CSP. The connection server 40 may perform an SSH tunneling connection with the target server based on the Bastion server information registered in Figure 8 and provide a connection environment using the Bastion server and the mapped information without the need to enter information according to the CSP standard for each individual connection.
[0094] According to the above-described embodiment, the present invention can implement an environment that accesses to a target server located in various CSP environments (AWS, Azure, GCP, NCP, On-Premise, etc.) without a separate agent. In particular, the present invention can perform a connection to a Linux host 60 of the CSP through a connection server 40 that performs a SSH tunneling function, allowing a user to efficiently utilize the access control function, easily access various environments such as Linux, Windows and DB and utilize resources.
[0095] Furthermore, the present invention can provide a connection between the user terminal 10 and the target server by performing SSH tunneling with the Linux host 60 based on a web socket and can implement an SSH tunneling connection environment between the Bastion server and the mapped target server by registering information on the target server to be connected based on the virtual Bastion server.
[0096] The various embodiments of this document and the terms used herein are not intended to limit the technical features described in this document to specific embodiments, and should be understood to include various changes, equivalents, or replacements of the relevant embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related elements. The singular form of a noun corresponding to an item may include a single item or a plurality of items, unless the relevant context clearly indicates otherwise.
[0097] In this document, each of the phrases such as “A or B,” “at least one of A and B,” “at least one of A or B,” “A, B or C,” “at least one of A, B and C,” and “at least one of A, B or C” may include all possible combinations of the items listed together with the corresponding phrase among these phrases. Terms such as "first", "second", or "firstly" or "secondary" may be used simply to distinguish one element from other elements and do not limit the corresponding elements in other aspects (importance or order). If any (e.g., first) element is said to be “coupled” or “connected” to another (e.g. second) element, with or without the terms “functionally” or “communicatively”, it means that one element can be connected to another element directly (e.g. wired), wirelessly, or through a third element.
[0098] The term “module” used in this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, part, or circuit, for example. A module may be an integrated part or a minimum unit of parts or a portion thereof that performs one or more functions. For example, according to one embodiment, the module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0099] Various embodiments in this document may be implemented as software (e.g., program) including one or more instructions stored in a storage medium (e.g., memory) that can be read by a machine (e.g., electronic device). The storage medium may include a random access memory (RAM), a memory buffer, a hard drive, a database, an erasable programmable read-only memory (EPROM), an electrically erasable read-only memory (EEPROM), a read-only memory (ROM), and / or the like.
[0100] Additionally, the processor in the embodiments of this document may call from a storage medium at least one instruction among one or more instructions stored therein and execute it. This allows the device to be operated to perform at least one function according to at least one instruction called. The one or more instructions may include code created by a compiler or code that can be executed by an interpreter. The processor may be a general-purpose processor, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a digital signal processor (DSP), and / or the like.
[0101] A storage medium that can be read by a machine may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' only means that the storage medium is a tangible device and does not contain signals (e.g. electromagnetic waves). This term does not distinct a case where data is stored semi-permanently in the storage medium and a case where data is stored temporarily therein.
[0102] Methods according to various embodiments disclosed in this document may be included and provided in a computer program product. The computer program product can be traded between a seller and a buyer as commodities. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read only memory (CD-ROM)) or via an application store (e.g., play store) or on two user devices (e.g., smartphones) may be distributed (e.g., downloaded or uploaded) directly or online. In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as a manufacturer's server, an application store's server, or a server's memory.
[0103] According to various embodiments, each element (e.g., module or program) of the described elements may include a single entity or a plurality of entities. According to various embodiments, one or more of the elements described above or operations thereof may be omitted, or one or more other elements or operations thereof may be added. Alternatively or additionally, multiple elements (e.g., modules or programs) may be integrated into a single element. In this case, the integrated element may perform one or more functions of each element of the plurality of elements in the same or similar manner as that performed by the corresponding element of the plurality of elements prior to the integration. According to various embodiments, operations performed by a module, program, or other element may be executed sequentially, in parallel, iteratively, or heuristically, one or more of the operations may be executed in a different order or omitted, or one or more other operations may be added.
Claims
1.A system comprising:a DB server for storing authentication information related to a CSP access authority of a user terminal;a web server, upon acquiring a request for access to the CSP from the user terminal, for determining whether the access to the CSP is permitted by checking the access authority of the user terminal to the CSP through the DB server; anda connection server for performing a connection to the CSP based on SSH tunneling according to the determination of the web server and for transmitting log information of the user terminal created according to the connection to a log server.2.The system according to claim 1, wherein the connection server performs SSH tunneling with a Linux host located in the CSP to thereby perform a connection between the user terminal and the target server included in the CSP based on a web socket.3.The system according to claim 1, wherein the web server stores predefined script information for each CSP regarding information to be delivered to the connection server, and delivers the predefined script information to the connection server according to the CSP selection of the user terminal4.The system according to claim 3, wherein the script information includes preset information about the IP / Port of the Linux host, Keyfile / Username / Password of the Linux host, OS of the target server, IP / Port of the target server, and Keyfile / Username / Password of the target server.5.The system according to claim 3, wherein if the OS of the target server is Linux, the connection server performs the SSH Tunneling using the Linux host and Python SSH Tunnel Forwarder based on the script information received from the web server to thereby create a Connection Random Port to the target server, and create a channel based on Python Paramiko for connection to the Connection Random Port of the user terminal.6.The system according to claim 3, wherein if the OS of the target server is Windows, the connection server performs SSH Tunneling using the Linux host and Python SSH Tunnel Forwarder based on the script information received from the web server to thereby create a Connection Random Port to the target server, and creates a RDP connection file for connection to the Connection Random Port of the user terminal.7.The system according to claim 3, wherein if a computing resource of the target server is a database, the connection server performs the SSH Tunneling using the Linux host and Python SSH Tunnel Forwarder based on the script information received from the web server to thereby create a Connection Random Port to the target server, and establish ODBC connection for connection to the Connection Random Port of the user terminal.8.The system according to claim 1, wherein the connection server creates a virtual Bastion server consisting of preset information between the Linux host and the connection server and performs the SSH tunneling with the Linux host.9.The system according to claim 8, wherein the connection performs a connection by matching preset information on the Bastion server with preset information on the CSP where the Linux host is located.10.The system according to claim 9, wherein the connection server performs a connection by matching information on Bastion name for management purpose, Bastion IP, SSH Port, Bastion authentication keyfile, OS type, Group for authority management and Bastion Username / Password as the preset information of the Bastion server to information on Bastion name for management purpose, IP of the target server, SSH Port, authentication keyfile of the target server, OS type, Group for authority management and Bastion Username / Password as the preset information on the CSP where the Linux is located.11.The system according to claim 1, further comprising a log server for storing log information related to the CSP access history of the user terminal.12.A method of operating the SSH tunneling-based CSP access control system, comprising the steps of:storing, by a DB server, authentication information related to a CSP access authority of a user terminal;upon acquiring a request for access to the CSP from the user terminal, by a web server, determining whether the access to the CSP is permitted by checking the access authority of the user terminal to the CSP through the DB server; andperforming, by a connection server, a connection to the CSP based on SSH tunneling according to the determination of the web server and transmitting log information of the user terminal created according to the connection to a log server.
Citation Information
Patent Citations
Method for remote managing network devices in cloud platform and cloud terminal control server using them
KR102351795B1
Sludge Collector With Tension Control Structure For Preventing Wrong-movement Of Flight
KR102561797B1
Proxy-based security methods and security systems through SSH tunneling
KR102571612B1
Extensible Server Management Framework BASED ON REVERSE CONNECTION PROTOCOL AND ACCESs OPERATIONG METHOD THEREOF
KR102574464B1