WO2020034162A1 - 一种集群通信的方法、服务器、终端设备以及存储介质 - Google Patents
一种集群通信的方法、服务器、终端设备以及存储介质 Download PDFInfo
- Publication number
- WO2020034162A1 WO2020034162A1 PCT/CN2018/100883 CN2018100883W WO2020034162A1 WO 2020034162 A1 WO2020034162 A1 WO 2020034162A1 CN 2018100883 W CN2018100883 W CN 2018100883W WO 2020034162 A1 WO2020034162 A1 WO 2020034162A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- user
- preset
- authentication request
- terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
Definitions
- the present application relates to the field of communication technologies, and in particular, to a method, a server, a terminal device, and a storage medium for cluster communication.
- MCPTT Mobility, Critical, Push, Talk, LTE, Key Tasks of Push-to-Talk Function Based on LTE Network
- MCPTT defines the implementation standard of the next push-to-talk service of LTE network. Since the MCPTT in the prior art can log in on any terminal with the same MC ID and password, it is necessary to improve the security level of the important MC ID to ensure the security of the MC ID in the cluster communication.
- the technical problem mainly solved by the present application is to provide a method for cluster communication, a server, a terminal device, and a storage medium. Can ensure the security of MC ID in cluster communication.
- a technical solution adopted in the present application is to provide a method for cluster communication, the method includes:
- the user's authentication request is passed and the first calibration authority is given.
- a server including a processor, a memory, and program data stored in the storage, and the processor is coupled to the memory, The processor executes the program data in order to implement the method described above.
- the terminal includes a processor, a memory, and program data stored in the storage, and the processor is coupled to the memory.
- the processor cooperates with the server as described above to execute the program data during the work to implement the method as described above.
- another technical solution adopted in the present application is to provide a storage medium that stores program data, and when the program data is executed, the method as described above is implemented.
- the obtained authentication request information from the terminal is compared with the information in the first preset database to determine the identity category of the user.
- the request The terminal sends preset identification information, and compares the identification information with information in a second preset database. After the comparison is successful, it passes the user's authentication request and grants the first calibration authority.
- FIG. 1 is a schematic flowchart of an embodiment of a cluster communication method according to the present application
- FIG. 2 is a schematic structural diagram of an embodiment of a server of the present application.
- FIG. 3 is a schematic structural diagram of a terminal device according to an embodiment of the present application.
- FIG. 4 is a schematic structural diagram of an embodiment of a storage medium of the present application.
- an embodiment herein means that a particular feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the present application.
- the appearances of this phrase in various places in the specification are not necessarily all referring to the same embodiment, nor are they independent or alternative embodiments that are mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.
- FIG. 1 is a schematic flowchart of an embodiment of a cluster communication method in this application. Specifically, a method for trunking communication in this application includes steps S10 to S50. among them:
- Step S10 acquires the authentication request information sent from the terminal, wherein the acquired authentication request information sent from the terminal includes: user ID address and password verification information. It can be understood that, in other implementations, the authentication request information from the terminal may also include other contents, which will be further detailed below.
- S20 Compare the authentication request information with the information in the first pre-stored database to determine the identity category of the user.
- step S20 the obtained authentication request information sent from the terminal is compared with the information in the first pre-stored database to determine the identity category of the current user. It can be known from the above that the content of the authentication request information includes multiple contents. It is understandable that in step S20, the content of each item in the authentication request information is compared with the corresponding information in the first pre-stored database to determine Its identity category.
- the user ID address and the password verification information corresponding to the current user ID address are compared with the first pre-stored database in step S20.
- the corresponding information is compared to determine whether the current user ID address and the corresponding password verification information match successfully with one or more pieces of information stored in the first pre-stored database to determine the identity category of the user, that is, determine the Whether the user has the permissions corresponding to the current authentication request.
- the authentication request information sent by the user excludes the above-mentioned user ID address and password verification information and also includes other types of information
- the user ID address and password verification information are compared after the comparison. It also compares other types of information. Only after the user ID address, password verification information, and other types of information are successfully compared in the first pre-stored database, the current user authentication request is passed. It can be understood that when the authority of the authentication request sent by the user does not necessarily have an associated relationship with other types of information, only the user ID address and password verification information need to be compared.
- the first pre-stored database stores at least a user ID address and password verification information corresponding to the user ID address in advance. It can be understood that in other embodiments, the first pre-stored database may further include other information, which is specifically based on the initial database setting, and is not limited here.
- step S20 When the authentication request information sent by the user is compared in step S20, the identity type of the user is further determined according to the comparison result in step S20.
- the authentication request information sent by the user is successfully compared with the information in the first pre-stored database, the user's authentication request for the current authority is passed. Further, when the authentication request information sent by the user is successfully compared and it is determined that the user is a user with a preset authority, a request is further sent to the terminal to request the terminal to send preset identity tag information.
- the ordinary authority is defined as Second, calibration authority.
- the user authentication request requires only the user ID address and password verification information for verification, as long as at least one of the user ID address and password verification information is compared with the information in the first pre-stored database, When the pair fails, it is determined that the comparison between the user authentication request information and the information in the first pre-stored database fails at this time.
- any of the user ID address, password verification information, and other types of information when one or more comparisons with the information in the first pre-stored database fail, it is determined that the comparison of the authentication request information of the current user with the information in the first pre-stored database fails.
- the preset identity information of the received terminal is compared with the information of the second preset database red to further determine the identity of the user, to improve the security level of the user ID, and to further increase the security for users with high security levels.
- the preset identification information includes: an international mobile device identification code or an international user identification code. It can be understood that, in other embodiments, the preset identity information further includes other preset codes or symbols, which is not limited herein.
- the second preset database is a set of preset identity information corresponding to a user ID stored in a local storage area in advance, or may be a set of user information in the first pre-stored database that needs to further verify the preset identity tag information.
- the second preset database includes a user's ID address, password verification information corresponding to the user's ID address, and a set of preset identity information required for verification to obtain the first calibration authority. That is, it can be understood as a set of user information associated with a preset mark identity in the first pre-stored database. This part of users can be users with important permissions or users with special attention set in advance.
- step S40 After the preset identification information in step S40 is successfully compared with the information in the second preset database, the user's authentication request is passed, and the first calibration authority is given.
- the preset identification information sent by the user is requested to be an international mobile equipment identity
- the preset identity information corresponding to the user Andy.liu@hytera.com is "353581990000010”
- the preset identity information sent by the user is "353581990000010”
- the preset identification information is successfully compared with the information stored in the second pre-stored database. At this time, the current user's authentication request for the current authority is passed, and the first calibration authority is given.
- the first calibration authority is a authority different from the ordinary authority.
- the authentication request for the first calibration authority requires the user to send other preset identification information for verification after the authentication request information is successfully compared. It can be understood that when a certain user is in the process of authentication request, the authentication request information (including user ID address, password verification information) sent to the first pre-stored database is successfully compared, and only the second calibration will be obtained.
- the authority that is, the ordinary authority, can pass the authentication only after the preset identification information is successfully compared, and is given the first calibration authority.
- the first calibration authority can be a high-level operation authority, such as the authority to modify certain important parameters, or the authority to access the encrypted area. Therefore, the first calibration authority can be set as required. Here, the first calibration authority is set.
- the specific content of the authority is not limited in any way.
- the user's identity category is determined, and when the user is determined to be a user with preset permissions, the terminal is requested to send preset identity information, and further obtain the preset Comparing the identification information with the information in the second preset database can better improve the security level of important users, and provide a more secure communication method for user IDs with higher permissions.
- the first pre-stored database may include a variety of information of users with different rights, and is not specifically limited herein.
- the method further includes: when the preset identification information sent by the terminal is corresponding to the corresponding information in the second preset database.
- the comparison fails, it is determined that the current user does not have the qualification to be granted the first calibration authority, and the user's authentication request for the first calibration authority is further rejected, and the user is given the second calibration authority, that is, the user has obtained ordinary authority.
- the second calibration authority obtained by the user is not changed at this time.
- the terminal may also be initially set.
- the preset identity information sent by the terminal fails to compare with the information in the second preset database and the user ’s authentication request for the first calibration authority is rejected, Refuse to grant the user the second calibration right, or terminate the second calibration right that has been granted before.
- the terminal may be requested to send the preset identity again. The information is compared with the information in the second preset database again. Understandably, after the authentication request information sent by the user fails to be compared with the information in the first pre-stored database, it may be further requested that the terminal send the authentication request information again and compare with the information in the first pre-stored database.
- the user is locked, and the corresponding user information is notified to the administrator.
- locking the user means that the current user is no longer allowed to perform the operation, and the operation can be performed again only after the unlock operation by the administrator or the completion of the unlock operation according to the prompt information.
- the prompt information refers to a pre-stored identity verification code or other information that can more accurately verify the identity of the user, and is not specifically limited here. It can be understood that in different embodiments, different numbers of comparison failures may be set, which is not specifically limited herein. It should be noted that, in other embodiments, it is also possible to set a user who has failed to lock the authentication information for more than a preset number of times, which will not be described in detail here.
- the preset identification information includes: an international mobile device identification code and an international user identification code.
- the international mobile equipment identity code international mobile identity
- the international mobile equipment identity code corresponds to each mobile device, and the international mobile equipment identity code is unique in the world
- the international user identification code international mobile identity
- the step of comparing the preset identity information with the information in the second preset database in step S40 includes: comparing the international mobile device identification code or international user identification code sent by the terminal with the second preset database. The corresponding information is compared; and / or the dynamic check code sent by the terminal is compared with the dynamic check code sent by the system to the terminal.
- the received international mobile device identity code is compared with information in a second preset database, where the second preset database
- the international mobile device ID corresponding to each user ID address is stored in advance, and the received international mobile device ID is compared with the international mobile device ID stored in the second pre-stored database to determine whether the current user meets the A condition of calibration authority.
- the terminal when the terminal sends an international user identification code, similarly, the received international user identification code is compared with the information in the second preset database. At this time, the international user identification code bound to each user ID address is stored in the second database in advance, and others are similar to those in the foregoing embodiment, and details are not described herein again.
- the international user identification code and the international mobile device identification code will be verified at the same time.
- Other identification information may be included, and details are not described in detail one by one.
- the cluster communication method provided in this application compares the authentication request information sent by the terminal with the information in the first pre-stored database to determine whether the user is eligible to grant corresponding permissions, and at the same time determines whether the user is a user with preset permissions.
- the terminal is further requested to send preset identity information for further identity verification.
- the preset identity information sent by the terminal is successfully compared with the information in the second preset database, the terminal is further granted the User first calibration authority.
- the preset identity information is unique, and the application can verify the unique identity information to increase the security of the cluster communication.
- the user authentication request information is successfully compared with the information in the first pre-stored database in step S20, but when it is determined that the user is a user with a non-preset authority, the user's authentication request is passed and a second calibration authority is given.
- the non-predefined authority user is defined relative to the preset authority user, and the second calibration authority refers to the ordinary authority, that is, the authority that can be obtained only by verifying the user ID address and password verification information.
- the password verification information may be static, that is, the preset password verification information may also be dynamic password verification information.
- step S20 and / or S40 when the authentication request information sent by the user fails to compare with the information in the corresponding first pre-stored database, or when the preset identity information is in the second preset database, When the information comparison fails, it will further determine the cause of the current user authentication failure, and return the reason for the failure to the terminal.
- the cause of the current user authentication failure will be further determined. Because the current authentication failure is due to an incorrect verification of the international mobile device identity code, and the corresponding international mobile device identity code corresponding to each terminal is unique, it will further output a judgment result of authentication failure as "UELOST", that is, the terminal The device is lost, and then the judgment result is formed into a push notification return value terminal, and it is sent back to the system in a certain form to inform the administrator.
- UMLOST judgment result of authentication failure
- FIG. 2 is a schematic structural diagram of an embodiment of a server 100 provided in this application.
- the server 100 includes a processor 101, a memory 102, and program data stored on the storage 102.
- the processor 101 is coupled to the memory 102.
- the processor 101 executes program data with the cooperation of a terminal during work to implement the cluster communication method of the foregoing embodiments.
- the present application also provides a terminal device.
- the terminal device 200 provided in this application is a schematic structural diagram of an embodiment.
- the terminal device 200 includes a processor 201, a memory 202, and a storage device 202.
- Program data is coupled to the memory 202, and the processor 201 cooperates with the server 100 as described above to execute program data during the work to implement the cluster communication method in the foregoing embodiment.
- the present application further provides a storage medium, as shown in FIG. 4, which is a schematic structural diagram of an embodiment of the storage medium 300 provided in the present application.
- the storage device 300 stores program data 301, and when the program data 301 stored in the storage device 300 is executed, the method for implementing cluster communication as described above is implemented.
- the device 300 having a storage function may be one of a memory of a terminal device, a personal computer, a server, a network device, or a U disk, and is not limited herein.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Telephonic Communication Services (AREA)
Abstract
本发明公开了一种集群通信的方法,该方法包括:获取来自终端的认证请求信息;将认证请求信息与第一预存数据库中的信息比对,以判断用户的身份类别;当比对成功且判断用户是预设权限用户时,请求终端发送预设身份标识信息;将预设身份标识信息与第二预设数据库中的信息进行比对,比对成功后,通过用户的认证请求,并赋予第一标定权限。通过上述方法,可以较好地提高用户的安全等级,保证用户在集群通信中的安全性。本发明还提供了一种服务器、一种终端设备及一种存储介质。
Description
本申请涉及通信技术领域,特别是涉及一种集群通信的方法、服务器、终端设备以及存储介质。
MCPTT(Mission Critical Push To Talk over LTE,基于LTE网的一键通功能关键任务)定义了LTE网络下一键通功能业务的实现标准。现有技术中的MCPTT由于同一套MC ID和密码可以在任意终端上登录,所以需要提高重要的MC ID的安全等级,以保证MC ID在集群通信中的安全性。
发明内容
本申请主要解决的技术问题是提供一种集群通信的方法、服务器、终端设备以及存储介质。能够保证MC ID在集群通信中的安全性。
为解决上述技术问题,本申请采用的一个技术方案是:提供一种集群通信的方法,所述方法包括:
获取来自终端的认证请求信息;
将所述认证请求信息与第一预存数据库中的信息比对,以判断用户的身份类别;
当比对成功且判断所述用户是预设权限用户时,请求所述终端发送预设身份标识信息;
将所述预设身份标识信息与第二预设数据库中的信息进行比对,
对比成功后,通过用户的认证请求,并赋予第一标定权限。
为解决上述技术问题,本申请采用的另一个技术方案是:提供一种服务器,该服务器包括:处理器、存储器以及存储在所述储存器上的程序数据,所述处理器耦合所述存储器,所述处理器在工作时执行所述程序数据以实现如上所述的方法。
为解决上述技术问题,本申请采用的又一个技术方案是:提供一种 终端设备,该终端包括:处理器、存储器以及存储在所述储存器上的程序数据,所述处理器耦合所述存储器,所述处理器在工作时配合如上所述的服务器执行所述程序数据以实现如上所述的方法。
为解决上述技术问题,本申请采用的又一个技术方案是:提供一种存储介质,该存储介质存储有程序数据,所述程序数据被执行时实现如上所述的方法。
以上方案,通过将所获取的来自终端的认证请求信息与第一预设数据库中的信息比对,以判断用户的身份类别,当比对成功且判断所述用户是预设权限用户时,请求所述终端发送预设身份标识信息,并将所述身份标识信息与第二预设数据库中的信息进行比对,在比对成功后,通过用户的认证请求,并赋予第一标定权限。通过上述流程,对于具有预设权限的用户需要经过多次认证核实才赋予第一标定权限,可以较好地保证重要用户的安全性,提高了用户的可靠性。
图1是本申请一种集群通信的方法在一实施例中流程示意图;
图2是本申请服务器在一实施例中结构示意图;
图3是本申请终端设备在一实施例中的结构示意图;
图4是本申请存储介质在一实施例中的结构示意图。
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述。可以理解的是,此处所描述的具体实施例仅用于解释本申请,而非对本申请的限定。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请中的术语“第一”、“第二”、“第三”仅用于描述目的,而不能理解为指示或暗示相对重要性或者隐含指明所指示的技术特征的数量。
在本文中提及“实施例”意味着,结合实施例描述的特定特征、结 构或特性可以包含在本申请的至少一个实施例中。在说明书中的各个位置出现该短语并不一定均是指相同的实施例,也不是与其它实施例互斥的独立的或备选的实施例。本领域技术人员显式地和隐式地理解的是,本文所描述的实施例可以与其它实施例相结合。
请参见图1,图1为本申请一种集群通信的方法在一实施例中的流程示意图。具体的,本申请一种集群通信的方法包括步骤S10至步骤S50。其中:
S10:获取来自终端的认证请求信息。
步骤S10获取来自终端发送的认证请求信息,其中,所获取到来自终端发送的认证请求信息包括:用户ID地址和密码校验信息。可以理解的是,在其它实施中,来自终端的认证请求信息还可以包括其他的内容,具体的将在下文进一步详述。
S20:将认证请求信息与第一预存数据库中的信息比对,以判断用户的身份类别。
步骤S20是将获取的来自终端发送的认证请求信息与第一预存数据库中的信息进行比对,以此来判断当前用户的身份类别。由上可以得知,认证请求信息的内容包括多项内容,可以理解的,步骤S20中是将认证请求信息中的每一项的内容与第一预存数据库中对应的信息进行比对,以判断其身份类别。
在一实施例中,当用户发送的认证请求信息包括用户ID地址、密码校验信息时,在步骤S20中将用户ID地址、及当前用户ID地址对应的密码校验信息与第一预存数据库中对应信息进行比对,以判断当前的用户ID地址及其对应的密码校验信息是否与第一预存数据库中所存储的某一或多条信息匹配成功,以判断用户的身份类别,即判断该用户是否具有当前认证请求所对应的权限。
在另一实施例中,当用户发送的认证请求信息除去上述的用户ID地址、密码校验信息还包括其他类别的信息时,则在比对完上述的用户ID地址、密码校验信息之外,还会对其他类别的信息进行比对,只有在用户ID地址、密码校验信息以及其他的类别的信息均在第一预存数据 库中比对成功之后,则通过当前的用户的认证请求。可以理解的,当用户所发送的认证请求的权限与其他类别信息的不存在必然的关联关系时,则只需对用户ID地址、密码校验信息进行比对。
其中,第一预存数据库是预先至少存储有用户ID地址、用户ID地址对应的密码校验信息。可以理解的,在其他实施例中,第一预存数据库中还可以包含其他的信息,具体依据初始的数据库设定,在此不做任何的限定。
S30:当比对成功且判断用户是预设权限用户时,请求终端发送预设身份标识信息。
当步骤S20对用户所发送的认证请求信息进行比对,依据步骤S20的比对结果,进一步判断用户的身份类别。当用户发送的认证请求信息与第一预存数据库中的信息比对成功时,通过用户对当前权限的认证请求。进一步的,当用户发送的认证请求信息比对成功后,且判断用户为预设权限用户时,进一步向终端发送请求,请求终端发送预设身份标记信息。
进一步的,当步骤S20中的用户发送的认证请求信息与第一预存数据库中的信息比对失败时,拒绝赋予用户相关权限,也就是拒绝赋予用户普通权限,本申请中定义该普通权限为第二标定权限。
具体的,在一实施例中,当用户认证请求的权限只需要用户ID地址、密码校验信息时进行验证时,只要用户ID地址、密码校验信息至少一个与第一预存数据库中的信息比对失败时,则判定此时用户认证请求信息与第一预存数据库中的信息比对失败。
在另一实施例中,当用户认证请求的权限需要对用户ID地址、密码检验信息以及其他类别的信息进行验证时,则在用户ID地址、密码校验信息、以及其他类别的信息中任意一个或多个与第一预存数据库中的信息比对失败时,则判定当前的用户的认证请求信息与第一预存数据库中的信息比对失败。
在其他实施例中,当用户认证请求的权限仅需要对用户的ID地址进行验证时,则在用户ID地址与第一预存数据库中对应的ID地址比对 失败时,判断当前用户比对失败,拒绝赋予用户第二标定权限。
S40:将预设身份标识信息与第二预设数据库中的信息进行比对。
将所收到终端的预设身份标识信息与第二预设数据库红的信息进行比对,以进一步判断用户的身份,以提高用户ID的安全等级,为高保密级别的用户进一步增加安全性。
在一实施例中,预设身份标识信息包括:国际移动设备身份码或国际用户识别码。可以理解的,在其他的实施例中,预设身份标识信息还包括其他预设的编码或符号,在此不做任何限定。其中,第二预设数据库是预先存储在本地存储区中对应用户ID的预设身份标识信息的集合,也可以是第一预存数据库中部分需要进一步验证预设身份标记信息的用户信息的集合。第二预设数据库中包括用户的ID地址、对应用户ID地址的密码校验信息、以及获取第一标定权限的所需验证的预设身份标识信息的集合。即可以理解成第一预存数据库中关联了预设标记身份的用户信息的集合。其中这一部分用户可以是具有重要权限的用户,也可以是预先设置的特殊关注的用户。
S50:比对成功后,通过用户的认证请求,并赋予第一标定权限。
当步骤S40中的预设身份标识信息与第二预设数据库中的信息比对成功后,通过用户的认证请求,并赋予第一标定权限。
例如,在一实施例中,当判断某一用户“Andy.liu@hytera.com”为预设权限的用户,请求该用户发送的预设身份标记信息为国际移动设备身份码(international mobile equipment identity),在第二设数据库中用户
Andy.liu@hytera.com对应的预设身份标识信息为“353581990000010”,只有当用户发送的预设身份标记信息为“353581990000010”时,才判断该用户发送的预设身份标识信息与第二预存数据库中存储的信息比对成功,此时通过当前用户对于当前权限的认证请求,并赋予第一标定权限。
其中,第一标定权限为不同于普通权限的权限,第一标定权限的认证请求需要用户在发送认证请求信息比对成功之后,再次发送其他的预设标识信息进行验证。可以理解的是,当某一用户在认证请求的过程, 所发送的认证请求信息(包括用户ID地址、密码校验信息)与第一预存数据库中的信息比对成功,只会获得第二标定权限,也就是普通权限,只有在预设标识信息比对成功后才可以通过认证,被赋予第一标定权限。具体的,第一标定权限可以是高级别的操作权限,如对某些重要参数的修改权限,或者是访问加密区的权限,所以第一标定权限可以根据需要进行设置,在此对于第一标定权限的具体的内容并不做任何的限定。通过将用户发送的认证请求信息与第一预存数据库中的信息比对,判断用户的身份类别,当判断用户为预设权限用户时,请求终端发送预设身份标识信息,进一步所获取的预设身份标识信息与第二预设数据库中的信息进行比对,可以较好地提高重要用户的安全等级,为具有较高权限的用户ID提供一种更为安全的通信方法。
可以理解的,在第一预存数据库中可以包括多种具有不同权限用户的信息,具体在此不做任何限定。
在一实施例中,步骤S40将预设身份标识信息与第二预设数据库中的信息进行比对之后还包括:当终端所发送的预设身份标识信息与第二预设数据库中的对应信息比对失败时,判定当前用户不具有被赋予第一标定权限的资格,进一步拒绝用户对第一标定权限的认证请求,并赋予用户第二标定权限,也就是用户获得了普通的权限。但是在拒绝用户对第一标定权限认证请求后,如当前用户在认证请求第一标定权限之前已获得第二标定权限,此时对用户所获得的第二标定权限并不做任何改变。
可以理解的,在其他实施例中,也可以初始设定,当终端所发送的预设身份标识信息与第二预设数据库中信息比对失败,拒绝用户对第一标定权限的认证请求后,拒绝赋予用户第二标定权限,或者是终止之前已经赋予的第二标定权限。进一步的,在一实施例中,当预设身份标识信息与第二预设数据库中的信息比对失败,拒绝用户对于第一标定权限的认证请求后,还可以再次请求终端发送预设身份标识信息,再次与第二预设数据库中的信息进行比对。可以理解的,还可以设定在用户所发送认证请求信息与第一预存数据库中的信息比对失败后,进一步请求终 端再次发送认证请求信息与第一预存数据库中的信息再次比对。
进一步的,当预设身份信息与第二预设数据库中的信息比对失败超过预设次数后,锁定用户,并将对应的用户信息通知管理员。其中,锁定用户是指不再允许当前用户进行操作,只有在经过管理员的解锁操作或者是根据提示信息完成解锁操作后,方可再次进行操作。提示信息是指预存的身份校验码或者是其他可以更加准确验证用户身份的信息,具体在此不做任何限定。可以理解的,在不同的实施例中,可以设定不同的比对失败次数,具体在此不做任何的限定。需要说明的是,在其他实施例中,也可以设定锁定认证信息认证失败超过预设次数的用户,具体在此不做赘述。
进一步的,在一实施例中,预设身份标识信息包括:国际移动设备身份码和国际用户识别码。其中,国际移动设备身份码(international mobile equipment identity)与每一台移动设备一一对应,且该国际移动设备身份码是全世界唯一的;国际用户识别码(international mobile subscriber identification number)是用来区别用户的标志,存储在SIM卡或者是USIM中。则可以得知步骤S40将所预设身份标识信息与第二预设数据库中的信息进行比对的步骤包括:将终端发送的国际移动设备身份码或国际用户识别码与第二预设数据库中对应的信息比对;和/或将终端发送的动态校验码与系统发送至终端的动态校验码比对。
具体的,在一实施例中,当终端发送的是国际移动设备身份码时,将所收到国际移动设备身份码与第二预设数据库中的信息进行比对,其中第二预设数据库中预先存储有各个用户ID地址对应的国际移动设备身份码,将接收到的国际移动设备身份码与第二预存数据库中所存储的国际移动设备身份码进行比对,以判断当前用户是否符合赋予第一标定权限的条件。
在另一实施例中,当终端发送的是国际用户识别码时,同样的,将所接收到的国际用户识别码与第二预设数据库中的信息进行比对。此时,第二数据库中的预先存储有各个用户ID地址绑定的国际用户识别码,其他与上述实施例中类似,具体在此不做赘述。
在其他实施例中,设定对于需要认证请求第一标定权限的用户进行两个或者两个以上的预设身份标识信息验证,则会同时验证国际用户识别码和国际移动设备身份码,当然还可以包括其他的身份标识信息,具体在不一一赘述。
本申请所提供的集群通信的方法,通过对终端发送的认证请求信息与第一预存数据库中的信息进行比对,判断用户是否符合授予对应权限,同时判断用户是否是预设权限用户,当判断当前用户是权限用户时,进一步请求终端发送预设身份标识信息进行进一步的身份验证,当终端所发送的预设身份标识信息与第二预设数据库中的信息比对成功时,则进一步授予该用户第一标定权限。其中预设身份标识信息具有唯一性,本申请通过验证具有唯一性的身份标识信息,可以较好的增加集群通信的安全性。
进一步的,在步骤S20中用户认证请求信息与第一预存数据库中的信息比对成功后,但判断该用户是非预设权限用户时,通过用户的认证请求,并赋予第二标定权限。其中非预设权限用户是相对预设权限用户定义的,第二标定权限是指普通的权限,即只需要进行对用户ID地址和密码校验信息进行校验即可获得的权限。需要说明的是密码校验信息可以是静态的,即预先设置好的密码校验信息,也可以是动态的密码校验信息。进一步的,在步骤S20中和/或S40中,当用户发送的认证请求信息与对应的第一预存数据库中信息比对失败时,或者是当预设身份标识信息与第二预设数据库中的信息比对失败时,则会进一步判断当前用户认证失败的原因,并将失败的原因返回至终端。
在一实施例中,当终端发送的预设身份标识信息是国际移动设备身份码,且与第二数据库中的信息比对失败时,则会进一步判断当前用户认证失败的原因。由于当前认证失败是由于国际移动设备身份码校验错误,并联系每一个终端所对应的国际移动设备身份码是唯一的,所以会进一步输出认证失败的判断结果为“UE LOST”,即判断终端设备发生丢失,然后将判断结果形成推送通知返回值终端,同时以一定形式发回系统以告知管理员。
本申请还提供一种服务器,如图2所示为本申请所提供的服务器100在一实施例中的结构示意图,该服务器100包括处理器101、存储器102以及存储在储存器102上的程序数据,处理器101耦合存储器102。处理器101在工作时在终端的配合下执行程序数据以实现以上各实施例集群通信的方法。
本申请还提供一种终端设备,如图3所示为本申请所提供的终端设备200在一实施例汇总的结构示意图,该终端设备200包括处理器201、存储器202以及存储在储存器202上的程序数据。其中,处理器201耦合存储器202,处理器201在工作时配合如上所述的服务器100执行程序数据以实现上述实施例中的集群通信的方法。
本申请还提供一种存储介质,如图4所示为本申请中所提供的存储介质300在一实施例中的结构示意图。该存储装置300存储有程序数据301,存储装置300所存储的程序数据301被执行时实现如上所述的集群通信的方法。具体的,上述具有存储功能的装置300可以是终端设备的存储器、个人计算机、服务器、网络设备,或者U盘等其中的一种,在此不做限定。
以上所述仅为本申请的实施方式,并非因此限制本申请的专利范围,凡是利用本申请说明书及附图内容所作的等效结构或等效流程变换,或直接或间接运用在其他相关的技术领域,均同理包括在本申请的专利保护范围内。
Claims (13)
- 一种集群通信的方法,其中,所述方法包括:获取来自终端的认证请求信息;将所述认证请求信息与第一预存数据库中的信息比对,以判断用户的身份类别;当比对成功且判断所述用户是预设权限用户时,请求所述终端发送预设身份标识信息;将所述预设身份标识信息与第二预设数据库中的信息进行比对,比对成功后,通过所述用户的认证请求,并赋予第一标定权限。
- 根据权利要求1所述的集群通信的方法,其中,所述将所述认证请求信息与第一预存数据库中的信息比对,以判断用户的身份类别的步骤之后还包括:当比对成功且判断所述用户是非预设权限用户时,通过所述用户的认证请求,并赋予第二标定权限。
- 根据权利要求1或2所述的集群通信的方法,其中,所述认证请求信息包括:用户ID地址和密码校验信息。
- 根据权利要求1所述的集群通信的方法,其中,所述将所述认证请求信息与第一预存数据库中的信息比对,以判断用户的身份类别的步骤之后还包括:当比对失败时,拒绝所述用户的认证请求。
- 根据权利要求4所述的集群通信的方法,其中,所述当比对失败时,拒绝所述用户的认证请求的步骤之后还包括:进一步判断所述用户认证失败的原因,并将所述原因返回至所述终端。
- 根据权利要求1所述的集群通信的方法,其中,所述将所述预设身份标识信息与第二预设数据库中的信息进行比对的步骤之后还包括:当所述预设身份标识信息与所述第二预设数据库中的信息比对失败,拒绝所述用户对第一标定权限的认证请求,并赋予所述用户第二标定权限。
- 根据权利要求1所述的集群通信的方法,其中,所述将所述预设 身份标识信息与第二预设数据库中的信息进行比对的步骤之后还包括:当所述预设身份标识信息与所述第二预设数据库中的信息比对失败,拒绝赋予所述用户所述第二标定权限。
- 根据权利要求6或7所述的集群通信的方法,其中,所述当所述预设身份标识信息与所述第二预设数据库中的信息比对失败的步骤之后还包括:进一步请求所述终端发送预设身份信息,再次与所述第二预设数据库中的信息进行比对。
- 根据权利要求7所述的集群通信的方法,其中,当所述预设身份信息与所述第二预设数据库中的信息比对失败超过预设次数后,锁定所述用户。
- 根据权利要求1所述的集群通信的方法,其中,所述将所述预设身份标识信息与第二预设数据库中的信息进行比对的步骤具体包括:将所述终端发送的国际移动设备身份码或国际用户识别码与所述第二预设数据库中对应的信息比对;和/或将所述终端发送的动态校验码与系统发送至终端的动态校验码比对。
- 一种服务器,其中,所述服务器包括:处理器、存储器以及存储在所述储存器上的程序数据,所述处理器耦合所述存储器,所述处理器在工作时执行所述程序数据以实现如权利要求1~10任一项所述的方法。
- 一种终端设备,其中,所述终端设备包括:处理器、存储器以及存储在所述储存器上的程序数据,所述处理器耦合所述存储器,所述处理器在工作时配合如权利要求11所述的服务器执行所述程序数据以实现如权利要求1~10任一项所述的方法。
- 一种存储介质,其中,所述存储介质存储有程序数据,所述程序数据被执行时实现如权利要求1~10任一项所述的方法。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2018/100883 WO2020034162A1 (zh) | 2018-08-16 | 2018-08-16 | 一种集群通信的方法、服务器、终端设备以及存储介质 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2018/100883 WO2020034162A1 (zh) | 2018-08-16 | 2018-08-16 | 一种集群通信的方法、服务器、终端设备以及存储介质 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020034162A1 true WO2020034162A1 (zh) | 2020-02-20 |
Family
ID=69524975
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2018/100883 Ceased WO2020034162A1 (zh) | 2018-08-16 | 2018-08-16 | 一种集群通信的方法、服务器、终端设备以及存储介质 |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2020034162A1 (zh) |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112148714A (zh) * | 2020-09-30 | 2020-12-29 | 珠海格力电器股份有限公司 | 数据监控方法、系统、存储介质及电子设备 |
| CN113672881A (zh) * | 2021-08-06 | 2021-11-19 | 江苏欧迈科技有限公司 | 一种服务器权限控制的方法、系统及介质 |
| CN116383206A (zh) * | 2023-03-28 | 2023-07-04 | 深圳市正浩创新科技股份有限公司 | 数据保存方法及数据保存设备 |
| CN116610738A (zh) * | 2023-06-14 | 2023-08-18 | 宁波浙鼎教育科技有限公司 | 一种云端数据调取方法、系统、存储介质及智能终端 |
| CN117596006A (zh) * | 2022-08-17 | 2024-02-23 | 波音公司 | 用于控制零信任架构内的计算资产的方法和设备 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101370191A (zh) * | 2008-09-19 | 2009-02-18 | 中兴通讯股份有限公司 | 一种群组外用户发起群组呼叫的方法和系统 |
| US20170118635A1 (en) * | 2015-10-26 | 2017-04-27 | Nokia Solutions And Networks Oy | Key separation for local evolved packet core |
| CN106936817A (zh) * | 2017-02-16 | 2017-07-07 | 上海帝联信息科技股份有限公司 | 操作执行方法、跳板机、集群认证服务器和堡垒机系统 |
-
2018
- 2018-08-16 WO PCT/CN2018/100883 patent/WO2020034162A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101370191A (zh) * | 2008-09-19 | 2009-02-18 | 中兴通讯股份有限公司 | 一种群组外用户发起群组呼叫的方法和系统 |
| US20170118635A1 (en) * | 2015-10-26 | 2017-04-27 | Nokia Solutions And Networks Oy | Key separation for local evolved packet core |
| CN106936817A (zh) * | 2017-02-16 | 2017-07-07 | 上海帝联信息科技股份有限公司 | 操作执行方法、跳板机、集群认证服务器和堡垒机系统 |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112148714A (zh) * | 2020-09-30 | 2020-12-29 | 珠海格力电器股份有限公司 | 数据监控方法、系统、存储介质及电子设备 |
| CN112148714B (zh) * | 2020-09-30 | 2023-12-05 | 珠海格力电器股份有限公司 | 数据监控方法、系统、存储介质及电子设备 |
| CN113672881A (zh) * | 2021-08-06 | 2021-11-19 | 江苏欧迈科技有限公司 | 一种服务器权限控制的方法、系统及介质 |
| CN117596006A (zh) * | 2022-08-17 | 2024-02-23 | 波音公司 | 用于控制零信任架构内的计算资产的方法和设备 |
| CN116383206A (zh) * | 2023-03-28 | 2023-07-04 | 深圳市正浩创新科技股份有限公司 | 数据保存方法及数据保存设备 |
| CN116610738A (zh) * | 2023-06-14 | 2023-08-18 | 宁波浙鼎教育科技有限公司 | 一种云端数据调取方法、系统、存储介质及智能终端 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12579230B2 (en) | Multi-factor authentication with increased security | |
| CN110149328B (zh) | 接口鉴权方法、装置、设备及计算机可读存储介质 | |
| US9736131B2 (en) | Secure login for subscriber devices | |
| US9053318B2 (en) | Anti-cloning system and method | |
| CN108964885B (zh) | 鉴权方法、装置、系统和存储介质 | |
| WO2020034162A1 (zh) | 一种集群通信的方法、服务器、终端设备以及存储介质 | |
| US20120144202A1 (en) | Secure authentication for client application access to protected resources | |
| US11823007B2 (en) | Obtaining device posture of a third party managed device | |
| CN106936772A (zh) | 一种云平台资源的访问方法、装置及系统 | |
| US11799868B2 (en) | Device application access and user data management | |
| US8819427B2 (en) | Device specific secure licensing | |
| CN105721159A (zh) | 一种操作系统身份认证方法及系统 | |
| CN110365483A (zh) | 云平台认证方法、客户端、中间件及系统 | |
| US20200252389A1 (en) | Secure sign-on using personal authentication tag | |
| US20200218819A1 (en) | Sfs access control method and system, sfs and terminal device | |
| CN108965335B (zh) | 防止恶意访问登录接口的方法、电子设备及计算机介质 | |
| CN107404488A (zh) | 一种同一应用多终端设备互斥方法及装置 | |
| CN105592072A (zh) | 在智能终端中获取登陆凭证的方法、智能终端以及操作系统 | |
| CN114157438A (zh) | 网络设备管理方法、装置及计算机可读存储介质 | |
| CN110839215B (zh) | 一种集群通信的方法、服务器、终端设备以及存储介质 | |
| WO2016070611A1 (zh) | 一种数据处理方法、服务器及终端 | |
| CN105812314A (zh) | 一种用户登录互联网应用程序的方法和统一认证平台 | |
| US12380195B2 (en) | Using a digital badge to access managed devices | |
| CN117852005A (zh) | 一种图数据库与客户端之间的安全校验方法及系统 | |
| CN114444060B (zh) | 一种权限校验方法、装置、系统及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18930315 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 24/06/2021) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18930315 Country of ref document: EP Kind code of ref document: A1 |