Method and system for NFS authentication enhancement based on file handle, electronic device, and storage medium
Through the file handle-based NFS authentication enhancement method, combined with user and terminal unique flags for authentication, the complex configuration and management of existing NFS authentication solutions is solved, and the effect of high security, simplification of processes and cost reduction is achieved.
Patent Information
- Application Number
- PCT/CN2024/138190
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-13
- Filing Date
- 2024-12-10
- Publication Date
- 2025-06-19
AI Technical Summary
Existing NFS authentication solutions such as Kerberos authentication and NFSv4 protocols are complex to configure and manage, requiring additional server support, making it difficult to meet the needs of simplifying the authentication process and reducing deployment costs.
The NFS authentication enhancement method based on file handles is adopted. By responding to the user's activation of the file system and obtaining the exclusive mount address, combining the user and terminal's unique flag for authentication, the authentication process is simplified and the corresponding authentication procedures are implemented on the client and server side.
It improves the security and reliability of the NFS protocol, simplifies the authentication process, reduces deployment and maintenance costs, and is suitable for a variety of application scenarios, such as cloud storage, big data analysis, etc.
Smart Images

Figure CN2024138190_19062025_PF_FP_ABST
Abstract
Description
NFS authentication enhancement method, system, electronic device and storage medium based on file handle
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on December 13, 2023, with application number 202311712764.9 and invention name “NFS authentication enhancement method based on file handle”, the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the technical field of network file systems, and more specifically, to a method, system, electronic device, and storage medium for enhancing NFS authentication based on file handles. Background Art
[0004] NFS (Network File System) is a distributed file system protocol that allows computers on a network to share files and directories through the TCP / IP protocol. The basic principle of the NFS protocol is to map a file system to the file system of another computer, allowing the remote computer to access shared files and directories just like a local computer. The NFS protocol has a wide range of application scenarios, especially in large-scale computing and storage environments.
[0005] Currently, common NFS authentication schemes include Kerberos authentication and NFSv4 protocol;
[0006] Kerberos authentication is a ticket-based authentication protocol that provides a secure identity authentication mechanism to protect data transmission and access on the network. However, its disadvantage is that it is complex to configure and manage and requires additional server support.
[0007] NFSv4 is an RPC (Remote Procedure Call)-based protocol that provides a secure file sharing mechanism and supports encrypted transmission, access control, and other functions. However, its disadvantages are that the protocol is complex, difficult to implement and configure, and requires additional server support.
[0008] Kerberos authentication and NFSv4 protocol are both relatively mature NFS authentication schemes. They can both provide secure identity authentication and data encryption mechanisms, but their configuration and management are relatively complex and require additional server support.
[0009] In view of this, the present application proposes an enhanced NFS authentication method based on file handle to solve the above problems. Summary of the Invention
[0010] In order to overcome the above-mentioned defects of the prior art, embodiments of the present application provide a method, system, electronic device and storage medium for NFS authentication enhancement based on file handles.
[0011] To achieve the above objectives, this application provides the following technical solutions:
[0012] The file handle-based NFS authentication enhancement method includes:
[0013] S10: In response to the user activating the file system, a first dedicated mount address corresponding to the file system is obtained, where the first dedicated mount address includes the file system to be mounted and a user unique identifier, the user unique identifier is encrypted, and the encrypted identifier is concatenated with the first dedicated mount address to generate a second dedicated mount address;
[0014] S20: Perform an actual mount operation according to the mount call by the client and obtain a terminal unique identifier, and concatenate the terminal unique identifier to the second exclusive mount address to generate a third exclusive mount address;
[0015] S30: After receiving the request, the mount service forwards the third exclusive mount address to the management module for authentication. The terminal is authenticated according to the third exclusive mount address and the user's unique identifier is used to determine whether the user has permission to mount. If yes, the process proceeds to S40. If no, an early warning is issued.
[0016] S40: After the mnt program passes the verification, it needs to return the filehandle of the root path and write the terminal unique flag into the filehandle;
[0017] S50: The server responds to the request and determines whether the terminal has permission to operate according to the filehandle and preset rules, where the preset rules are set based on file granularity.
[0018] Optionally, the method of encrypting the user unique identifier includes:
[0019] The user's unique identifier is added with a salt value, and the user's unique identifier with the added salt value is encrypted through a hash function.
[0020] Optionally, the method of concatenating the user unique identifier to the first dedicated mount address to generate the second dedicated mount address includes:
[0021] Convert the string corresponding to the user's unique identifier into a path;
[0022] Concatenate the path to the end of the first dedicated mount address.
[0023] Optionally, the method of splicing the terminal unique identifier onto the second dedicated mounting address to generate a third dedicated mounting address includes:
[0024] Convert the string corresponding to the terminal's unique identifier into a path;
[0025] Concatenate the path to the end of the second dedicated mount address.
[0026] Optionally, the logic for determining whether the user has permission to mount based on the unique user identifier includes:
[0027] Determine whether the user's unique flag is a preset flag. When the user's unique flag is a preset flag, the user has permission to mount. When the user's unique flag is not a preset flag, the user does not have permission to mount.
[0028] Optionally, the method for creating a preset rule includes:
[0029] Three new folders are created in the root directory of the file system. The three folders are a shared folder, a first exclusive folder, and a second exclusive folder. The shared folder is associated with the first user and the second user, the first exclusive folder is associated with the first user, and the second exclusive folder is associated with the second user.
[0030] Optionally, the first exclusive folder is used for reading and writing by the first user, the first exclusive folder is used for reading by the second user, the second exclusive folder is used for reading by the first user, and the second exclusive folder is used for reading and writing by the second user.
[0031] The NFS authentication enhancement system based on file handles is used to implement the above-mentioned NFS authentication enhancement method based on file handles, including:
[0032] The client module responds to the user's activation of the file system and obtains a first dedicated mount address corresponding to the file system, where the first dedicated mount address includes the file system to be mounted and a user's unique identifier, encrypts the user's unique identifier, and concatenates it with the first dedicated mount address to generate a second dedicated mount address.
[0033] Mount module: performs the actual mount operation based on the client's call to mount and obtains the terminal's unique identifier. It then concatenates the terminal's unique identifier to the second dedicated mount address to generate a third dedicated mount address.
[0034] Management Verification Module: After receiving the request, the mount service forwards the third-party mount address to the management module for authentication. The terminal is authenticated based on the third-party mount address and the user's unique identifier is used to determine whether the mount permission is granted. If so, the module proceeds to the write module. If not, an alert is issued.
[0035] Write module: After the mnt program passes the verification, it needs to return the filehandle of the root path and write the terminal unique flag into the filehandle;
[0036] Verification module: The server responds to the request and determines whether the terminal has permission to operate based on the filehandle and preset rules. The preset rules are set based on file granularity.
[0037] An electronic device comprises a memory, a processor, and a computer program stored in the memory and running on the processor, wherein when the processor executes the computer program, the processor implements any one of the above-mentioned file handle-based NFS authentication enhancement methods.
[0038] A computer-readable storage medium stores a computer program, which, when executed, implements any of the above-mentioned file handle-based NFS authentication enhancement methods.
[0039] Compared with the prior art, the present invention has the following advantages:
[0040] (1) This application improves the security of the NFS protocol: This solution adopts a file handle-based authentication mechanism, which can effectively prevent file tampering and forgery, thereby improving the security and reliability of the NFS protocol;
[0041] (2) This application does not require additional server support. It only needs to implement the corresponding authentication procedures on the client and server. This can simplify the authentication process and improve the usability and maintainability of the NFS protocol.
[0042] (3) This application is applicable to a variety of application scenarios, such as cloud storage, big data analysis, virtualized environments, etc., and has broad application prospects, improving the data management and security level of enterprises: This solution can improve the data management and security level of enterprises, meet the requirements of modern enterprises for data security and privacy protection, and bring commercial benefits to enterprises;
[0043] (4) This application does not require additional server support, which can reduce the deployment and maintenance costs of the NFS protocol and improve the economy and feasibility of the NFS protocol. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] FIG1 is a schematic diagram of an NFS authentication enhancement method based on file handles in this application;
[0045] FIG2 is a schematic diagram of a scenario in which the NFS protocol is used in the prior art;
[0046] Figure 3 is a schematic diagram of the enhanced NFS authentication process based on filehandle in this application. DETAILED DESCRIPTION
[0047] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0048] Example 1
[0049] As shown in FIG1 , this embodiment discloses an NFS authentication enhancement method based on a file handle, including:
[0050] S10: In response to the user activating the file system, a first dedicated mount address corresponding to the file system is obtained, where the first dedicated mount address includes the file system to be mounted and a user unique identifier, the user unique identifier is encrypted, and the encrypted identifier is concatenated with the first dedicated mount address to generate a second dedicated mount address;
[0051] It should be noted that NFS (Network File System) is a protocol for sharing file systems on the network. In NFS, authentication is a process that ensures that the client has the right to access shared resources. NFS supports multiple authentication mechanisms. The user's unique identifier refers to information that represents the user, such as the user ID. In addition, users can also open different file systems. The first exclusive mount address corresponding to different file systems will also be different. In this way, different terminals will obtain different file system mount addresses after opening the file system. The user's unique identifier must be added to the mount address, which can effectively prevent file tampering and forgery, thereby improving the security and reliability of the NFS protocol.
[0052] Methods for encrypting a user's unique identifier include:
[0053] Add the salt value to the user's unique identifier and encrypt the user's unique identifier after adding the salt value through a hash function;
[0054] The salt value is a random string used to increase password security and ensure that the same user ID will produce different results after encryption. Encrypting a string using a hash function is a prior art and will not be described in detail in this embodiment.
[0055] The method of splicing the user unique identifier onto the first dedicated mount address to generate the second dedicated mount address includes:
[0056] Convert the string corresponding to the user's unique identifier into a path;
[0057] Concatenate the path to the end of the first dedicated mount address;
[0058] It should be noted that in this example, the user's unique identifier is converted into a string and encrypted, and the string is converted into a path, which is finally concatenated at the end of the first dedicated mount address. Similarly, the path can also be concatenated at other locations of the first dedicated mount address. This embodiment is only for simple explanation and is not limiting.
[0059] S20: Perform an actual mount operation according to the mount call by the client and obtain a terminal unique identifier, and concatenate the terminal unique identifier to the second exclusive mount address to generate a third exclusive mount address;
[0060] In this embodiment, "mount" refers to the process of connecting a storage device or file system to the computer's file system hierarchy. Through the mount operation, the operating system makes the file system on the storage device available to a directory in the file system hierarchy, allowing users and applications to access the files and directories on the storage device.
[0061] The current terminal unique identifier is recorded in the terminal, such as the device's SN and other information. "SN" usually refers to the device's serial number (Serial Number). The serial number is a unique identifier assigned to each device to uniquely identify the device. The serial number is usually assigned by the manufacturer during the production process and is used to track and manage the device's life cycle. The splicing method is the same as the splicing method above. Splicing is performed according to the agreement on the path of the address provided by the server. The main purpose is to enable more fine-grained differentiation of device information on the server.
[0062] The method of splicing the terminal unique identifier onto the second exclusive mount address to generate a third exclusive mount address includes:
[0063] Convert the string corresponding to the terminal's unique identifier into a path;
[0064] Concatenate the path to the end of the second dedicated mount address;
[0065] Similarly, the path can also be spliced to other locations of the second dedicated mount address. This embodiment is just a simple explanation and is not limiting.
[0066] S30: After receiving the request, the mount service forwards the third exclusive mount address to the management module for authentication. The terminal is authenticated according to the third exclusive mount address and the user's unique identifier is used to determine whether the user has permission to mount. If yes, the process proceeds to S40. If no, an early warning is issued.
[0067] The third exclusive mount address includes the user's unique flag and the terminal's unique flag. The arbitrary management module can use the user's unique flag to determine whether it has permission to mount;
[0068] The logic for determining whether a mount is authorized based on the user's unique flag includes:
[0069] Determine whether the user's unique flag is a preset flag. If the user's unique flag is a preset flag, the user has permission to mount. If the user's unique flag is not a preset flag, the user does not have permission to mount.
[0070] It is understandable that the preset flag is set by those skilled in the art according to actual conditions. The present solution is further explained through the following content:
[0071] After receiving the mount information from the client, the server can obtain the user and terminal information. This depends on the permission configuration rules of the current business system and is flexible and configurable. For example, if the permission rules are set to allow user A to mount but user B cannot, when A and B use the mount address provided by the server to mount, user A's terminal can mount successfully, but user B cannot.
[0072] S40: After the mnt program passes the verification, it needs to return the filehandle of the root path and write the terminal unique flag into the filehandle;
[0073] In NFS (Network File System), each file or directory has a unique identifier called a "filehandle". A filehandle is an opaque identifier used to uniquely identify a file or directory in the file system. It is assigned by the NFS server to each file or directory and is used for communication between the client and the server.
[0074] When a client requests access to a file or directory, it uses the filehandle of that file or directory to identify the object of the request. A filehandle is an identifier that is unique in the context of the file system, so it allows communication between the client and the server to be independent of the actual path of the file or directory;
[0075] The root path filehandle represents the entire file system on the NFS server. The root path filehandle allows the client to access any file or directory in the file system through it. In NFS, the root path filehandle is the entry point for the client, through which the client can browse and access the entire file system.
[0076] In the above, filehandle is a string whose parameters can be customized. The obtained terminal flag can be written into filehandle.
[0077] S50: The server responds to the request and determines whether the terminal has permission to operate based on the file handle and preset rules, where the preset rules are set based on file granularity;
[0078] Methods for creating preset rules include:
[0079] Create three folders in the root directory of the file system, the three folders being a shared folder, a first dedicated folder, and a second dedicated folder. The shared folder is associated with the first user and the second user, the first dedicated folder is associated with the first user, and the second dedicated folder is associated with the second user.
[0080] The following further explains this plan:
[0081] The server can completely determine whether the terminal has permission to operate based on a certain request. The specific judgment rules need to be pre-configured. This method is relatively flexible. For example, three new folders can be created under the root directory of the file system, namely a shared folder (both users A and B can read and write), a dedicated folder for user A (A can read and write, B can read only), and a dedicated folder for user B (A can read only, B can read and write). For the same folder, the filehandles obtained by user A and user B are different. When the server receives an NFS operation request, it can first find the corresponding user based on the filehandle, and then make a judgment based on the preset rules;
[0082] The granularity can be controlled to the file granularity, which means that the preset permission rules can be configured to the file granularity. For example, a file can be set to read-only or read-write for different users. The implementation principle is that different clients obtain inconsistent filehandles for the same file. The next business request will bring the filehandle to the server, and the server can then make a judgment.
[0083] Example 2
[0084] This embodiment discloses an NFS authentication enhancement system based on file handles on the basis of embodiment 1.
[0085] The client module responds to the user's activation of the file system and obtains a first dedicated mount address corresponding to the file system, where the first dedicated mount address includes the file system to be mounted and a user's unique identifier, encrypts the user's unique identifier, and concatenates it with the first dedicated mount address to generate a second dedicated mount address.
[0086] It should be noted that NFS (Network File System) is a protocol for sharing file systems on the network. In NFS, authentication is a process that ensures that the client has the right to access shared resources. NFS supports multiple authentication mechanisms. The user's unique identifier refers to information that represents the user, such as the user ID. In addition, users can also open different file systems. The first exclusive mount address corresponding to different file systems will also be different. In this way, different terminals will obtain different file system mount addresses after opening the file system. The user's unique identifier must be added to the mount address, which can effectively prevent file tampering and forgery, thereby improving the security and reliability of the NFS protocol.
[0087] Methods for encrypting a user's unique identifier include:
[0088] Add the salt value to the user's unique identifier and encrypt the user's unique identifier after adding the salt value through a hash function;
[0089] The salt value is a random string used to increase password security and ensure that the same user ID will produce different results after encryption. Encrypting a string using a hash function is a prior art and will not be described in detail in this embodiment.
[0090] The method of splicing the user unique identifier onto the first dedicated mount address to generate the second dedicated mount address includes:
[0091] Convert the string corresponding to the user's unique identifier into a path;
[0092] Concatenate the path to the end of the first dedicated mount address;
[0093] It should be noted that in this example, the user's unique identifier is converted into a string and encrypted, and the string is converted into a path, which is finally concatenated at the end of the first dedicated mount address. Similarly, the path can also be concatenated at other locations of the first dedicated mount address. This embodiment is only for simple explanation and is not limiting.
[0094] Mount module: performs the actual mount operation based on the client's call to mount and obtains the terminal's unique identifier. It then concatenates the terminal's unique identifier to the second dedicated mount address to generate a third dedicated mount address.
[0095] In this embodiment, "mount" refers to the process of connecting a storage device or file system to the computer's file system hierarchy. Through the mount operation, the operating system makes the file system on the storage device available to a directory in the file system hierarchy, allowing users and applications to access the files and directories on the storage device.
[0096] The current terminal unique identifier is recorded in the terminal, such as the device's SN and other information. "SN" usually refers to the device's serial number (Serial Number). The serial number is a unique identifier assigned to each device to uniquely identify the device. The serial number is usually assigned by the manufacturer during the production process and is used to track and manage the device's life cycle. The splicing method is the same as the splicing method above. Splicing is performed according to the agreement on the path of the address provided by the server. The main purpose is to enable more fine-grained differentiation of device information on the server.
[0097] The method of splicing the terminal unique identifier onto the second exclusive mount address to generate a third exclusive mount address includes:
[0098] Convert the string corresponding to the terminal's unique identifier into a path;
[0099] Concatenate the path to the end of the second dedicated mount address;
[0100] Similarly, the path can also be spliced to other locations of the second dedicated mount address. This embodiment is just a simple explanation and is not limiting.
[0101] Management Verification Module: After receiving the request, the mount service forwards the third-party mount address to the management module for authentication. The terminal is authenticated based on the third-party mount address and the user's unique identifier is used to determine whether the mount permission is granted. If so, the module proceeds to the write module. If not, an alert is issued.
[0102] The third exclusive mount address includes the user's unique flag and the terminal's unique flag. The arbitrary management module can use the user's unique flag to determine whether it has permission to mount;
[0103] The logic for determining whether a mount is authorized based on the user's unique flag includes:
[0104] Determine whether the user's unique flag is a preset flag. If the user's unique flag is a preset flag, the user has permission to mount. If the user's unique flag is not a preset flag, the user does not have permission to mount.
[0105] It is understandable that the preset flag is set by those skilled in the art according to actual conditions. The present solution is further explained through the following content:
[0106] After receiving the mount information from the client, the server can obtain the user and terminal information. This depends on the permission configuration rules of the current business system and is flexible and configurable. For example, if the permission rules are set to allow user A to mount but user B cannot, when A and B use the mount address provided by the server to mount, user A's terminal can mount successfully, but user B cannot.
[0107] Write module: After the mnt program passes the verification, it needs to return the filehandle of the root path and write the terminal unique flag into the filehandle;
[0108] In NFS (Network File System), each file or directory has a unique identifier called a "filehandle". A filehandle is an opaque identifier used to uniquely identify a file or directory in the file system. It is assigned by the NFS server to each file or directory and is used for communication between the client and the server.
[0109] When a client requests access to a file or directory, it uses the filehandle of that file or directory to identify the object of the request. A filehandle is an identifier that is unique in the context of the file system, so it allows communication between the client and the server to be independent of the actual path of the file or directory.
[0110] In the above, filehandle is a string whose parameters can be customized. The obtained terminal flag can be written into filehandle.
[0111] Verification module: The server responds to the request and determines whether the terminal has permission to operate based on the file handle and preset rules. The preset rules are set based on file granularity;
[0112] Methods for creating preset rules include:
[0113] Three new folders are created in the root directory of the file system. The three folders are a shared folder, a first exclusive folder, and a second exclusive folder. The shared folder is associated with the first user and the second user, the first exclusive folder is associated with the first user, and the second exclusive folder is associated with the second user.
[0114] Example 3
[0115] This embodiment discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements any one of the file handle-based NFS authentication enhancement methods provided by the above methods.
[0116] Since the electronic device described in this embodiment is an electronic device used to implement the NFS authentication enhancement method based on file handles in the embodiments of this application, those skilled in the art will be able to understand the specific implementation of the electronic device of this embodiment and its various variations based on the NFS authentication enhancement method based on file handles described in the embodiments of this application, so how the electronic device implements the method in the embodiments of this application will not be described in detail here. As long as those skilled in the art implement the electronic device used in the NFS authentication enhancement method based on file handles in the embodiments of this application, it falls within the scope of protection to be provided by this application.
[0117] Example 4
[0118] This embodiment discloses a computer-readable storage medium, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, any one of the file handle-based NFS authentication enhancement methods provided by the above methods is implemented.
[0119] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters, weights and thresholds in the formulas are set by technicians in this field according to actual conditions.
[0120] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired network or a wireless network. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD) or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0121] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0122] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0123] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is only one type. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0124] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0125] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0126] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0127] Finally: The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. The NFS authentication enhancement method based on file handle is characterized in that: include: S10: In response to the user opening a file system, a first exclusive mount address corresponding to the file system is obtained, where the first exclusive mount address includes the file system to be mounted and a user unique identifier, the user unique identifier is encrypted, and the encrypted identifier is concatenated with the first exclusive mount address to generate a second exclusive mount address; S20: Perform an actual mounting operation according to the call of mount by the client and obtain a terminal unique flag, and splice the terminal unique flag to the second exclusive mounting address to generate a third exclusive mounting address; S30: After receiving the request, the mount service forwards the third exclusive mount address to the management module for authentication, performs authentication operation on the terminal according to the third exclusive mount address, and determines whether the user has the authority to mount based on the user's unique identifier. If yes, proceed to S40, if not, issue an early warning; S40: After the mnt program passes the verification, it needs to return the filehandle of the root path and write the terminal unique mark into the filehandle; S50: The server responds to the request and determines whether the terminal has permission to operate according to the filehandle and preset rules, where the preset rules are set based on file granularity.
2. The NFS authentication enhancement method based on file handle according to claim 1, characterized in that: Methods for encrypting a user's unique identifier include: The user's unique identifier is added with a salt value, and the user's unique identifier with the added salt value is encrypted through a hash function.
3. The NFS authentication enhancement method based on file handle according to claim 2, characterized in that: The method of splicing the user unique identifier onto the first exclusive mount address to generate the second exclusive mount address includes: Convert the string corresponding to the user's unique identifier into a path; Concatenate the path to the end of the first dedicated mount address.
4. The NFS authentication enhancement method based on file handle according to claim 1, characterized in that: The method of splicing the terminal unique identifier to the second exclusive mounting address to generate a third exclusive mounting address includes: Convert the string corresponding to the terminal's unique flag into a path; Concatenate the path to the end of the second dedicated mount address.
5. The NFS authentication enhancement method based on file handle according to claim 1, characterized in that: The logic for determining whether there is permission to mount based on the user's unique flag includes: Determine whether the user's unique flag is a preset flag. When the user's unique flag is a preset flag, you have permission to mount. When the user's unique flag is not a preset flag, you do not have permission to mount.
6. The NFS authentication enhancement method based on file handle according to claim 1, characterized in that: The methods for creating preset rules include: Three new folders are created in the root directory of the file system, the three folders are a shared folder, a first exclusive folder, and a second exclusive folder, the shared folder is associated with the first user and the second user, the first exclusive folder is associated with the first user, and the second exclusive folder is associated with the second user.
7. The NFS authentication enhancement method based on file handle according to claim 6, characterized in that: The first exclusive folder is used for reading and writing by the first user, the first exclusive folder is used for reading by the second user, the second exclusive folder is used for reading by the first user, and the second exclusive folder is used for reading and writing by the second user.
8. A file handle-based NFS authentication enhancement system, which is used to implement the file handle-based NFS authentication enhancement method described in any one of claims 1 to 7, characterized in that: include: The client module: responds to the user opening the file system, and obtains the first exclusive mount address corresponding to the file system, wherein the first exclusive mount address includes the file system to be mounted and the user's unique identifier, encrypts the user's unique identifier, and splices it to the first exclusive mount address to generate a second exclusive mount address; Mount module: performs the actual mounting operation according to the mount call by the client and obtains the terminal unique flag, and splices the terminal unique flag to the second exclusive mounting address to generate the third exclusive mounting address; Management verification module: After receiving the request, the mount service forwards the third exclusive mount address to the management module for authentication. The terminal is authenticated according to the third exclusive mount address, and the user's unique flag is used to determine whether the user has the permission to mount. If yes, the module is transferred to the write module. If no, an early warning is issued. Write module: After the mnt program passes the verification, it needs to return the filehandle of the root path and write the terminal unique flag into the filehandle; Verification module: The server responds to the request and determines whether the terminal has permission to operate based on the filehandle and preset rules. The preset rules are set based on the file granularity.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the file handle-based NFS authentication enhancement method described in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the NFS authentication enhancement method based on file handle described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Method and system for achieving sharing
CN107172061A
An nfs client mount permission control method
CN108989295A
File system authority authentication mode compatible with IP and ID
CN116541863A
NFS authentication enhancement method based on file handle
CN117857132A
Method and apparatus for improving file system proxy performance and security by distributing information to clients via file handles
US20050210072A1
Cited By
NVMe storage device data placement method, product, device and medium
CN120406857A