File access control method, device, electronic device, medium and program product

By generating target file access rules in the virtual file system, the problems of file access security policy management and performance consumption in the prior art are solved, and precise settings and security guarantees for file access rights are realized.

CN114372282BActive Publication Date: 2025-05-09BEIJING VRV SOFTWARE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111663378.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-31
Publication Date
2025-05-09
Estimated Expiration
2041-12-31

AI Technical Summary

Technical Problem

Existing autonomous access control and mandatory access control have problems with the management and performance consumption of file access security policies, including file leakage risks, excess monitoring of non-file access controls, and system performance consumption.

Method used

A file access control method is provided, applied to a virtual file system, obtains file path information in response to a security policy input by the administrator, acquires and saves the initial file access rules, and generates target file access rules based on the initial rules and security policies. The target rules include at least a first target flag bit and a second target flag bit for indicating the access request mode, including the file read-only mode.

Benefits of technology

By setting target file access rules in the file virtual system, precise settings of file access rights can be achieved, system performance consumption is reduced, files are not modified, and file access control is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114372282B_ABST
    Figure CN114372282B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the field of communication technology, and provides a file access control method, device, electronic device, medium and program product. The method comprises: in response to the security policy input by the administrator, obtaining the path information of the file; based on the path information, obtaining the initial file access rule corresponding to the file, and saving the initial file access rule; based on the initial file access rule and the security policy, obtaining the target file access rule, wherein the target file access rule at least includes a first target flag bit and a second target flag bit, the first target flag bit is used to indicate the reading of the second target flag bit, and the second target flag bit is used to indicate the access request mode corresponding to the file, and the access request mode at least includes a file read-only mode. The use of this method can reduce the performance consumption of the system, and ensure that the file will not be modified, thereby improving the security of file access control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a file access control method, device, electronic device, medium and program product. Background Art

[0002] At present, in Linux systems, file access control technology can be divided into autonomous access control and mandatory access control. Autonomous access control is an access control service. The subject has the right to access the files, data tables and other access objects created by itself, and can grant its access rights to other subjects, or revoke its access rights. Mandatory access control refers to the control of the subject's authority and access to the operation object by the system according to the prescribed rules for the objects created by the subject, mainly through the implementation of mandatory access control on all subjects and the objects such as processes and files they control.

[0003] However, the existing autonomous access control and mandatory access control have the following problems: for autonomous access control, users can view and change file access security policies, which may lead to file leakage, and autonomous access control only supports some file system types under Linux systems, resulting in unavailability for file system types such as FAT, FAT32, and NTFS; for mandatory access control, the subject needs to monitor both file access control and non-file access control, but the monitoring of non-file access control is redundant and irrelevant, thereby increasing the consumption of system performance. Summary of the invention

[0004] Based on this, it is necessary to provide a file access control method, device, electronic device, medium and program product to address the above technical issues.

[0005] In a first aspect, an embodiment of the present disclosure provides a file access control method, which is applied in a virtual file system, and the method includes:

[0006] Responding to the security policy input by the administrator, obtaining path information of the file;

[0007] Based on the path information, obtaining an initial file access rule corresponding to the file, and saving the initial file access rule;

[0008] Based on the initial file access rules and the security policy, target file access rules are obtained, wherein the target file access rules include at least a first target flag bit and a second target flag bit, the first target flag bit is used to indicate reading the second target flag bit, and the second target flag bit is used to indicate an access request mode corresponding to the file, and the access request mode includes at least a file read-only mode.

[0009] In one embodiment, the acquiring the initial file access rule corresponding to the file based on the path information includes:

[0010] Based on the path information, obtaining a first initial node structure member and a second initial node structure member corresponding to the file;

[0011] Based on the first initial node structure member, read the first initial flag bit corresponding to the first initial node structure member, and based on the second initial node structure member, read the second initial flag bit corresponding to the second initial node structure member to obtain the initial file access rule corresponding to the file.

[0012] In one embodiment, based on the initial file access rule and the security policy, obtaining the target file access rule includes:

[0013] Based on the security policy, rewriting the first initial flag bit in the initial file access rule to obtain the first target flag bit, and rewriting the second initial flag bit in the initial file access rule to obtain the second target flag bit;

[0014] The target file access rule is obtained based on the first target flag bit and the second target flag bit.

[0015] In one embodiment, it further includes:

[0016] In response to the security policy input by an administrator, the target file access rule is updated to the initial file access rule.

[0017] In one embodiment, before obtaining the first initial node structure member and the second initial node structure member corresponding to the file based on the path information, the method further includes:

[0018] Determine whether the initial node structure member corresponding to the file includes the first initial node structure member and the second initial node structure member;

[0019] If so, based on the path information, the first initial node structure member and the second initial node structure member corresponding to the file are obtained.

[0020] In one embodiment, it further includes:

[0021] When receiving a file access request input by a user, obtaining an access request mode corresponding to the file based on the target file access rule;

[0022] When the access request pattern is consistent with the file access request, the file access request is executed.

[0023] In a second aspect, an embodiment of the present disclosure provides a file access control device, including:

[0024] A path information acquisition module, used to obtain the path information of the file in response to the security policy input by the administrator;

[0025] A processing module, configured to obtain an initial file access rule corresponding to the file based on the path information, and save the initial file access rule;

[0026] A target file access rule obtaining module is used to obtain a target file access rule based on the initial file access rule and the security policy, wherein the target file access rule includes at least a first target flag bit and a second target flag bit, the first target flag bit is used to indicate reading the second target flag bit, and the second target flag bit is used to indicate an access request mode corresponding to the file, and the access request mode includes at least a file read-only mode.

[0027] In a third aspect, an embodiment of the present disclosure provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the file access control method described in the first aspect when executing the computer program.

[0028] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of the file access control method described in the first aspect are implemented.

[0029] In a fifth aspect, an embodiment of the present disclosure provides a computer program product, which, when executed on a computer, enables the computer to execute the steps of the file access control method described in the first aspect.

[0030] The present disclosure provides a file access control method, device, electronic device, medium and program product, which adopts this method to respond to the security policy input by the administrator to obtain the path information of the file; based on the path information, obtain the initial file access rule corresponding to the file, and save the initial file access rule; based on the initial file access rule and the security policy, obtain the target file access rule, wherein the target file access rule includes at least a first target flag bit and a second target flag bit, the first target flag bit is used to indicate the reading of the second target flag bit, and the second target flag bit is used to indicate the access request mode corresponding to the file, and the access request mode includes at least a file read-only mode. In this way, by setting the target file access rule in the file virtual system, the setting of the access rights of the file is realized according to the first target flag bit and the second target flag bit in the target file access rule, so as to reduce the performance consumption of the system, and ensure that the file will not be modified, thereby improving the security of file access control. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0032] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0033] Figure 1 A flowchart of a file access control method provided by an embodiment of the present disclosure;

[0034] Figure 2 A flowchart of another file access control method provided by an embodiment of the present disclosure;

[0035] Figure 3 A flowchart of another file access control method provided by an embodiment of the present disclosure;

[0036] Figure 4 A flowchart of another file access control method provided by an embodiment of the present disclosure;

[0037] Figure 5 A flowchart of another file access control method provided by an embodiment of the present disclosure;

[0038] Figure 6 A schematic diagram of the structure of a file access control device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0039] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0040] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.

[0041] At present, in Linux systems, file access control technology can be divided into autonomous access control and mandatory access control. Autonomous access control is an access control service. The subject has the right to access the files, data tables and other access objects created by itself, and can grant its access rights to other subjects, or revoke its access rights. Mandatory access control refers to the control of the subject's authority and access to the operation object by the system according to the prescribed rules for the objects created by the subject, mainly through the implementation of mandatory access control on all subjects and the objects such as processes and files they control.

[0042] However, the existing autonomous access control and mandatory access control have the following problems: for autonomous access control, users can view and change file access security policies, which may lead to file leakage, and autonomous access control only supports some file system types under Linux systems, resulting in unavailability for file system types such as FAT, FAT32, and NTFS; for mandatory access control, the subject needs to monitor both file access control and non-file access control, but the monitoring of non-file access control is redundant and irrelevant, thereby increasing the consumption of system performance.

[0043] Therefore, the present disclosure provides a file access control method, which is applied in a virtual file system, and obtains the path information of the file by responding to the security policy input by the administrator; based on the path information, obtains the initial file access rule corresponding to the file, and saves the initial file access rule; based on the initial file access rule and the security policy, obtains the target file access rule, wherein the target file access rule includes at least a first target flag bit and a second target flag bit, the first target flag bit is used to indicate reading the second target flag bit, and the second target flag bit is used to indicate the access request mode corresponding to the file, and the access request mode includes at least a file read-only mode. In this way, by setting the target file access rule in the file virtual system, the setting of the file access permission is realized according to the first target flag bit and the second target flag bit in the target file access rule, so as to reduce the performance consumption of the system, and ensure that the file will not be modified, thereby improving the security of the file access control.

[0044] The above-mentioned Virtual File System (VFS) refers to a distributed file system used in a network environment. It is an interface layer between the physical file system and the service, which can abstract each file system under the Linux system, so that different file systems appear the same in the core of the Linux system and other processes running in the system. VFS is not an actual file system. It only exists in the memory and not in any external storage space. VFS is established when the system starts and disappears when the system shuts down.

[0045] The file system refers to the method and data structure used by the terminal operating system to indicate files on a disk or partition. Usually, the organizational structure of the file system is a tree structure, in which each node is a file or a directory. Files or directories in the file system may be accessed.

[0046] In one embodiment, Figure 1 As shown, Figure 1 A flowchart of a file access control method provided by an embodiment of the present disclosure specifically includes the following steps:

[0047] S00: In response to the security policy input by the administrator, the path information of the file is obtained.

[0048] The file path information refers to the path information corresponding to the file that the user wants to access. For example, for the file A that the user wants to access, the corresponding path information is / usr / local / A, but it is not limited to this. The present disclosure does not specifically limit this. A file access request refers to an access request issued by a user to a file, mainly including read, write, and executable access requests.

[0049] Security policy refers to the rules set to implement security protection for files. The access rights of the corresponding files can be set by the administrator, but are not limited to this. The present disclosure does not specifically limit this, and those skilled in the art can set it according to actual conditions.

[0050] Specifically, when the administrator inputs a security policy, the terminal device such as a computer responds to the security policy and obtains the path information of the file corresponding to the security policy input by the administrator.

[0051] Exemplarily, when a terminal device such as a computer receives a security policy entered by an administrator, it responds to the security policy entered by the administrator. At this time, a kernel module is created in the kernel space, and a character device is established at the same time. The user space sends the path information of the file to the kernel module through the character device to obtain the path information of the file, but is not limited to this and the present disclosure does not specifically limit it.

[0052] It should be noted that the above-mentioned user space refers to the application running space, and the kernel space refers to the running space used to execute the driver program. When the user space needs to implement operations on the kernel, for example, when using the read() function to implement a request to access a file, since the user space cannot directly operate the kernel, the "system call" method must be used to implement operations from the user space to the kernel space, thereby realizing the access request to the file.

[0053] Character devices are used to implement communication between user space and kernel space.

[0054] S01: Based on the path information, an initial file access rule corresponding to the file is obtained, and the initial file access rule is saved.

[0055] Among them, the initial file access rule refers to the original file access rule of the system default in a terminal device such as a computer. For example, for file A, its initial access rule can be, for example, a read-only mode, that is, only read requests for file A are allowed, but it is not limited to this and the present disclosure does not specifically limit it.

[0056] Specifically, the terminal device such as a computer obtains the initial file access rule corresponding to the file by calling a corresponding function according to the obtained path information, and after obtaining the initial file access rule, the initial file access rule is saved.

[0057] Exemplarily, the above-mentioned saving of the initial file access rules can be achieved by using a kernel module to send the initial file access rules to the user space through a character device and saving them in the user space, but is not limited to this. The present disclosure does not specifically limit this, and technical personnel in this field can make specific settings according to actual conditions.

[0058] On the basis of the above embodiments, in some embodiments of the present disclosure, further, as Figure 2 As shown, one possible implementation method of S01 is:

[0059] S011, based on the path information, obtaining a first initial node structure member and a second initial node structure member corresponding to the file.

[0060] The initial node structure member refers to each file, which is regarded as a node in the file system, and each node stores the structure member corresponding to the file, such as the file's access rights, access time and other information.

[0061] Exemplarily, after receiving the path information of a file, the kernel module in a terminal device such as a computer calls the function kern_path() according to the file virtual system and the path information of the file to obtain the first initial node structure member such as i_opflags, and the second initial node structure member i_flags, wherein the first initial node structure member and the second initial node structure member are used to set the access rights of the file, but are not limited to this. The present disclosure does not specifically limit this, and those skilled in the art can set it according to actual conditions.

[0062] S012, based on the first initial node structure member, read the first initial flag bit corresponding to the first initial node structure member, and based on the second initial node structure member, read the second initial flag bit corresponding to the second initial node structure member to obtain the initial file access rule corresponding to the file.

[0063] Among them, the first initial flag bit and the second initial flag bit are used to set the access rights to the file. For example, the first initial flag bit, such as the IOP_FASTPERM bit, is used to indicate to ignore the control effect of the second initial flag bit and directly execute the access request to the file. The second initial flag bit, such as the S_IMMUTABLE bit, is used to indicate the access request mode of the file. For example, for file A, the access request mode of file A can be set to read-only by setting the S_IMMUTABLE bit, but it is not limited to this. The present disclosure does not specifically limit it, and technical personnel in this field can make specific settings according to actual conditions.

[0064] Specifically, after obtaining the first initial node structure member and the second initial node structure member corresponding to the file, the first initial flag bit and the second initial flag bit corresponding to the first initial node structure member and the second initial node structure member are read respectively to obtain the initial file access rule corresponding to the file.

[0065] S02: Based on the initial file access rule and the security policy, a target file access rule is obtained.

[0066] Among them, the target file access rule includes at least a first target flag and a second target flag, the first target flag is used to indicate reading the second target flag, and the second target flag is used to indicate an access request mode corresponding to the file, and the access request mode includes at least a file read-only mode.

[0067] Specifically, after obtaining the initial file access rule, the terminal device such as a computer processes the initial file access rule according to the security policy input by the administrator to obtain the target file access rule corresponding to the file.

[0068] On the basis of the above embodiments, in some embodiments of the present disclosure, further, as Figure 3 As shown, a possible implementation method of S02 is:

[0069] S021, based on the security policy, rewrite the first initial flag bit in the initial file access rule to obtain the first target flag bit, and rewrite the second initial flag bit in the initial file access rule to obtain the second target flag bit.

[0070] S022, obtaining a target file access rule based on the first target flag bit and the second target flag bit.

[0071] Specifically, according to the security policy input by the administrator, the first initial flag bit read from the first initial structure member and the second initial flag bit read from the second initial structure member are rewritten to obtain the corresponding first target flag bit and second target flag bit, thereby obtaining the target file access rule.

[0072] Exemplarily, the above-mentioned first initial flag bit, such as the IOP_FASTPERM bit, is used to indicate the rapid implementation of the file access request. When the IOP_FASTPERM bit is rewritten, the first target flag bit is obtained, so that after the kernel module of the terminal device such as a computer reads the first target flag bit, it no longer quickly implements the file access request, but executes the operation of reading the second target flag bit.

[0073] The above-mentioned second initial flag bit, such as the S_IMMUTABLE bit, is used to indicate the access request mode of the file. For example, for file A, the S_IMMUTABLE bit can be used to realize the access request mode of file A as a write-only mode, or the read, write, and executable modes can exist at the same time. When the S_IMMUTABLE bit is rewritten, the second target flag bit is obtained, so that after the kernel module of a terminal device such as a computer reads the second target flag bit, it can be known that the access request mode of file A is only a read-only mode, but it is not limited to this. The present disclosure does not specifically limit it, and those skilled in the art can make specific settings according to actual conditions.

[0074] In this way, this embodiment obtains the path information of the file by responding to the security policy input by the administrator; based on the path information, obtains the initial file access rule corresponding to the file, and saves the initial file access rule; based on the initial file access rule and the security policy, obtains the target file access rule, wherein the target file access rule includes at least a first target flag bit and a second target flag bit, the first target flag bit is used to indicate reading the second target flag bit, and the second target flag bit is used to indicate the access request mode corresponding to the file, and the access request mode includes at least a file read-only mode. In this way, by setting the target file access rule in the file virtual system, the file access permission is set according to the first target flag bit and the second target flag bit in the target file access rule, so as to reduce the performance consumption of the system, and ensure that the file will not be modified, thereby improving the security of file access control.

[0075] Figure 4 A flowchart of another file access control method provided by an embodiment of the present disclosure is shown below. Figure 4 is Figure 3 Based on the embodiment shown, Figure 4 As shown, it also includes:

[0076] S03: In response to the security policy input by the administrator, the target file access rule is updated to the initial file access rule.

[0077] Specifically, when a terminal device such as a computer receives a security policy input by an administrator, it uses the saved initial file access rule to update the target file access rule.

[0078] Exemplarily, when a terminal device such as a computer receives a security policy input by an administrator in the kernel module, if the security policy is to restore the file to the initial file access rules, the user space sends the saved initial file access rules to the kernel space through the character device. After the kernel space receives the initial file access rules, it updates the target file access rules to the initial file access rules.

[0079] On the basis of the above embodiments, in some embodiments of the present disclosure, further, based on the path information, before obtaining the first initial node structure member and the second initial node structure member corresponding to the file, the method further includes:

[0080] Determine whether the initial node structure member corresponding to the file includes the first initial node structure member and the second initial node structure member. If so, obtain the first initial node structure member and the second initial node structure member corresponding to the file based on the path information.

[0081] Exemplarily, to determine whether the initial node structure members corresponding to a file include a first initial node structure member and a second initial node structure member, the kernel version of the current terminal device, such as a computer, can be obtained. When it is determined that the kernel version is higher than version 3.1, it is determined that the initial node structure members corresponding to the file include the first initial node structure member and the second initial node structure member. When it is determined that the initial node structure members corresponding to the file include the first initial node structure member and the second initial node structure member, the first initial node structure member and the second initial node structure member corresponding to the file are obtained.

[0082] Figure 5 A flowchart of another file access control method provided by an embodiment of the present disclosure is shown below. Figure 5 is Figure 4 Based on the embodiment shown, Figure 4 As shown, further, it also includes:

[0083] S041: When receiving a file access request input by a user, obtaining an access request mode corresponding to the file based on a target file access rule.

[0084] S042: When the access request mode is consistent with the file access request, execute the file access request.

[0085] Specifically, when a terminal device such as a computer receives a file access request input by a user, the kernel module of the terminal device such as a computer reads the second target flag in the target file access rule to obtain the access request mode that the user needs to access the file, and determines whether the access request mode corresponding to the file is consistent with the file access request input by the user. When the access request mode is consistent with the file access request input by the user, the file access request is executed.

[0086] Exemplarily, for file A that the user needs to access, according to the second target flag in the target file access rule, the access request mode corresponding to file A is read-only. If the file access request input by the user is a read operation, it is determined that the access request mode corresponding to file A is consistent with the file access request input by the user, and the file access request input by the user is executed to implement the read operation on the file.

[0087] In this way, this embodiment sets the target file access rule of the file to achieve the setting of the file access permission. When receiving the file access request input by the user, it can be based on the target file access rule to ensure the security of the file.

[0088] It should be understood that although Figure 1-Figure 5The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1-Figure 5 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.

[0089] In one embodiment, Figure 6 As shown, a file access control device is provided, comprising: a path information acquisition module 00, a processing module 01 and a target file access rule acquisition module 02.

[0090] The path information acquisition module 00 is used to obtain the path information of the file in response to the security policy input by the administrator;

[0091] Processing module 01 is used to obtain the initial file access rule corresponding to the file based on the path information, and save the initial file access rule.

[0092] The target file access rule obtaining module 02 is used to obtain the target file access rule based on the initial file access rule and the security policy, wherein the target file access rule includes at least a first target flag bit and a second target flag bit, the first target flag bit is used to indicate reading the second target flag bit, and the second target flag bit is used to indicate the access request mode corresponding to the file, and the access request mode includes at least a file read-only mode.

[0093] In an implementation of an embodiment of the present invention, processing module 01 is specifically used to obtain a first initial node structure member and a second initial node structure member corresponding to a file based on path information; based on the first initial node structure member, read a first initial flag bit corresponding to the first initial node structure member; and based on the second initial node structure member, read a second initial flag bit corresponding to the second initial node structure member, so as to obtain an initial file access rule corresponding to the file.

[0094] In one implementation of an embodiment of the present invention, the target file access rule obtaining module 02 is specifically used to rewrite the first initial flag bit in the initial file access rule based on the security policy to obtain the first target flag bit, and to rewrite the second initial flag bit in the initial file access rule to obtain the second target flag bit; based on the first target flag bit and the second target flag bit, the target file access rule is obtained.

[0095] In one implementation of the embodiment of the present invention, the device further includes: an updating module, configured to update the target file access rule to the initial file access rule in response to a security policy input by an administrator.

[0096] In one implementation of an embodiment of the present invention, the device also includes: a judgment module, used to judge whether the initial node structure members corresponding to the file include the first initial node structure member and the second initial node structure member; a processing module 01, specifically used to obtain the first initial node structure member and the second initial node structure member corresponding to the file based on the path information if the initial node structure members corresponding to the file include the first initial node structure member and the second initial node structure member.

[0097] In one embodiment of the present invention, the device also includes: an execution module, which is used to obtain an access request mode corresponding to the file based on the target file access rule when receiving a file access request input by the user; when the access request mode is consistent with the file access request, execute the file access request.

[0098] In the above embodiment, the path information acquisition module 00 is used to obtain the path information of the file in response to the security policy input by the administrator; the processing module 01 is used to obtain the initial file access rule corresponding to the file based on the path information, and save the initial file access rule. The target file access rule acquisition module 02 is used to obtain the target file access rule based on the initial file access rule and the security policy, wherein the target file access rule at least includes a first target flag bit and a second target flag bit, the first target flag bit is used to indicate the reading of the second target flag bit, and the second target flag bit is used to indicate the access request mode corresponding to the file, and the access request mode at least includes a file read-only mode. In this way, by setting the target file access rule in the file virtual system, the setting of the access rights to the file is implemented according to the first target flag bit and the second target flag bit in the target file access rule, so as to reduce the performance consumption of the system, and ensure that the file will not be modified, thereby improving the security of file access control.

[0099] For the specific definition of the file access control device, please refer to the definition of the file access control method above, which will not be repeated here. Each module in the above server can be implemented in whole or in part by software, hardware and a combination thereof. Each of the above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0100] The present disclosure provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the file access control method provided by the present disclosure can be implemented. For example, when the processor executes the computer program, the file access control method provided by the present disclosure can be implemented. Figures 1 to 5 The technical solution of any of the method embodiments shown has similar implementation principles and technical effects, which will not be repeated here.

[0101] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the file access control method provided by the embodiment of the present disclosure can be implemented. For example, when the computer program is executed by a processor, the file access control method provided by the embodiment of the present disclosure can be implemented. Figures 1 to 5 The technical solution of any of the method embodiments shown has similar implementation principles and technical effects, which will not be repeated here.

[0102] The present disclosure provides a computer program product. When the computer program product is run on a computer, the computer can implement the file access control method provided by the embodiment of the present disclosure when the computer executes the method. For example, the computer can implement Figures 1 to 5 The technical solution of any of the method embodiments shown has similar implementation principles and technical effects, which will not be repeated here.

[0103] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided by the present disclosure can include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in various forms, such as static random access memory (SRAM) and dynamic random access memory (DRAM).

[0104] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0105] The above-mentioned embodiments only express several implementation methods of the present disclosure, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present disclosure, and these all belong to the protection scope of the present disclosure. Therefore, the protection scope of the patent of the present disclosure shall be subject to the attached claims.

Claims

1. A file access control method, characterized in that: Applied to virtual file systems, including: Responding to the security policy input by the administrator, obtaining path information of the file; Based on the path information, obtaining an initial file access rule corresponding to the file, and saving the initial file access rule; Based on the initial file access rule and the security policy, a target file access rule is obtained, wherein the target file access rule includes at least a first target flag bit and a second target flag bit, the first target flag bit is used to indicate reading the second target flag bit, and the second target flag bit is used to indicate an access request mode corresponding to the file, and the access request mode includes at least a file read-only mode; Wherein, obtaining the initial file access rule corresponding to the file based on the path information includes: Based on the path information, obtaining a first initial node structure member and a second initial node structure member corresponding to the file; Based on the first initial node structure member, read the first initial flag bit corresponding to the first initial node structure member, and based on the second initial node structure member, read the second initial flag bit corresponding to the second initial node structure member to obtain the initial file access rule corresponding to the file.

2. The method according to claim 1, characterized in that Based on the initial file access rule and the security policy, the target file access rule is obtained, including: Based on the security policy, rewriting the first initial flag bit in the initial file access rule to obtain the first target flag bit, and rewriting the second initial flag bit in the initial file access rule to obtain the second target flag bit; The target file access rule is obtained based on the first target flag bit and the second target flag bit.

3. The method according to claim 1, characterized in that The method further comprises: In response to the security policy input by an administrator, the target file access rule is updated to the initial file access rule.

4. The method according to claim 1, characterized in that Before obtaining the first initial node structure member and the second initial node structure member corresponding to the file based on the path information, the method further includes: Determine whether the initial node structure member corresponding to the file includes the first initial node structure member and the second initial node structure member; If so, based on the path information, the first initial node structure member and the second initial node structure member corresponding to the file are obtained.

5. The method according to claim 1, characterized in that: The method comprises: When receiving a file access request input by a user, obtaining an access request mode corresponding to the file based on the target file access rule; When the access request pattern is consistent with the file access request, the file access request is executed.

6. A file access control device, characterized in that: include: A path information acquisition module, used to obtain the path information of the file in response to the security policy input by the administrator; A processing module, configured to obtain an initial file access rule corresponding to the file based on the path information, and save the initial file access rule; a target file access rule obtaining module, used for obtaining a target file access rule based on the initial file access rule and the security policy, wherein the target file access rule comprises at least a first target flag bit and a second target flag bit, the first target flag bit is used for indicating reading the second target flag bit, the second target flag bit is used for indicating an access request mode corresponding to the file, the access request mode comprises at least a file read-only mode; Wherein, obtaining the initial file access rule corresponding to the file based on the path information includes: Based on the path information, obtaining a first initial node structure member and a second initial node structure member corresponding to the file; Based on the first initial node structure member, read the first initial flag bit corresponding to the first initial node structure member, and based on the second initial node structure member, read the second initial flag bit corresponding to the second initial node structure member to obtain the initial file access rule corresponding to the file.

7. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the file access control method according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the file access control method according to any one of claims 1 to 5 are implemented.

9. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is enabled to execute the steps of the file access control method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Protected RAM filesystem

    US20040268084A1