A method, device and related equipment for access control list (ACL) policy management

By dividing the proxy module into policy execution groups and building a policy management tree, the problem of inefficient ACL policy configuration in complex network environments is solved, and batch configuration and efficient management of ACL policies are realized.

CN115603923BActive Publication Date: 2025-06-20SANGFOR TECH INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110722965.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-28
Publication Date
2025-06-20
Estimated Expiration
2041-06-28

AI Technical Summary

Technical Problem

In complex network environments, manual configuration of access control list (ACL) policies is inefficient, which can easily lead to configuration errors and redundancy.

Method used

By dividing multiple proxy modules into multiple policy execution groups, and abstracting the system network structure of the proxy module and policy execution group into a policy management tree, receiving the user's configuration policy and mapping it into a target ACL policy, and issuing it to the proxy module in the corresponding policy execution group.

Benefits of technology

The batch configuration of ACL policies is realized, the efficiency of policy configuration is improved, and manual errors and redundancy is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115603923B_ABST
    Figure CN115603923B_ABST
Patent Text Reader

Abstract

The present application discloses a method for managing access control list (ACL) policies. The ACL policy management method includes: dividing multiple proxy modules into multiple policy execution groups; wherein, the proxy module is a module in the client for executing ACL policies; abstracting the system network structure of the proxy module and the policy execution group into a policy management tree; wherein, the child nodes in the policy management tree inherit the ACL policies configured in the parent nodes; receiving user-configured policies, mapping the user-configured policies to target ACL policies based on the policy management tree, and sending the target ACL policies to the proxy modules in the corresponding policy execution groups. The present application can improve the configuration efficiency of ALC policies. The present application also discloses an access control list (ACL) policy management device, an electronic device, and a storage medium, which have the above beneficial effects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and particularly relates to a method and device for managing access control list (ACL) policies, an electronic device, and a storage medium. Background Art

[0002] In the current increasingly complex network environment with gradually increasing security issues, east-west security isolation in network systems has become a hot issue in current research. In related technologies, access control list (ACL) policies are usually configured in proxy modules to achieve access isolation control between internal networks. ACL is an access control technology based on packet filtering, which can filter data packets on an interface according to set conditions and allow them to pass or be discarded. Currently, in network system configuration, business personnel need to log in to different proxy modules to configure corresponding policies to make them effective. When the network scale becomes complex, the amount of manually configured policies will increase, resulting in errors and redundancies in policy configuration.

[0003] Therefore, how to improve the configuration efficiency of ALC policies is a technical problem that those skilled in the art need to solve currently. Summary of the Invention

[0004] The purpose of this application is to provide a method and device for managing access control list (ACL) policies, an electronic device, and a storage medium, which can improve the configuration efficiency of ALC policies.

[0005] To solve the above technical problems, this application provides a method for managing access control list (ACL) policies. The ACL policy management method includes:

[0006] Dividing multiple proxy modules into multiple policy execution groups; wherein, the proxy module is a module in the client for executing ACL policies;

[0007] Abstracting the system network structure of the proxy module and the policy execution group into a policy management tree; wherein, the child nodes in the policy management tree inherit the ACL policies configured in the parent nodes;

[0008] Receiving user-configured policies, mapping the user-configured policies to target ACL policies based on the policy management tree, and sending the target ACL policies to the proxy modules in the corresponding policy execution groups.

[0009] Optionally, the dividing multiple proxy modules into multiple policy execution groups includes:

[0010] Divide the multiple proxy modules into multiple policy execution groups according to the device attributes of the client where the proxy module is located; wherein, the device attributes include any one or a combination of several of device type, service type, and device location.

[0011] Optionally, sending the target ACL policy to the proxy module in the corresponding policy execution group includes:

[0012] Determine whether there is a conflict between the target ACL policy and the ACL policies that have taken effect in the policy management tree;

[0013] If so, return a prompt message indicating that the ACL policy setting fails;

[0014] If not, send the target ACL policy to the proxy module in the corresponding policy execution group.

[0015] Optionally, after constructing the policy management tree according to the corresponding relationship between the proxy module and the policy execution group, it further includes:

[0016] Determine the ACL policy to be deleted according to the received policy deletion instruction;

[0017] If there is a target leaf node corresponding to the ACL policy to be deleted in the policy management tree, and there is policy information in the target leaf node, then delete the policy information in the target leaf node.

[0018] Optionally, it further includes:

[0019] Display the policy management tree on the visualization interface;

[0020] If an ACL policy is added or deleted in the policy management tree, update the policy management tree displayed on the visualization interface.

[0021] Optionally, mapping the user configuration policy to the target ACL policy based on the policy management tree and sending the target ACL policy to the proxy module in the corresponding policy execution group includes:

[0022] Generate a node corresponding to the user configuration policy in the policy management tree, and determine the target ACL policy corresponding to the user configuration policy according to the policy information recorded in the node corresponding to the user configuration policy; wherein, the root node of the policy management tree is the policy action, and the child nodes include the source port, destination port, and policy execution group label, and the policy execution group label includes the source label and the destination label;

[0023] Swap the source label and the destination label in the target ACL policy to obtain the reverse ACL policy, and send the target ACL policy and the reverse ACL policy to the proxy module in the corresponding policy execution group.

[0024] Optionally, before constructing the policy management tree according to the correspondence between the proxy module and the policy execution group, it further includes:

[0025] Binding a unique corresponding identity identifier to the proxy module;

[0026] Correspondingly, the five-tuple configuration information of the target ACL policy includes the identity identifier of the source proxy module, the identity identifier of the destination proxy module, the source port, the destination port, and the communication protocol.

[0027] The present application also provides an access control list (ACL) policy management device, which includes:

[0028] A grouping module, configured to divide multiple proxy modules into multiple policy execution groups; wherein, the proxy module is a module in the client for executing the ACL policy;

[0029] A management tree construction module, configured to abstract the system network structure of the proxy module and the policy execution group into a policy management tree; wherein, the child nodes in the policy management tree inherit the ACL policies configured in the parent nodes;

[0030] A policy configuration module, configured to receive user-configured policies, map the user-configured policies to target ACL policies based on the policy management tree, and send the target ACL policies to the proxy modules in the corresponding policy execution groups.

[0031] The present application also provides a storage medium, on which a computer program is stored, and when the computer program is executed, the steps executed by the above-mentioned access control list (ACL) policy management method are implemented.

[0032] The present application also provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps executed by the above-mentioned access control list (ACL) policy management method are implemented.

[0033] The present application provides an access control list (ACL) policy management method, including: dividing multiple proxy modules into multiple policy execution groups; wherein, the proxy module is a module in the client for executing the ACL policy; abstracting the system network structure of the proxy module and the policy execution group into a policy management tree; wherein, the child nodes in the policy management tree inherit the ACL policies configured in the parent nodes; receiving user-configured policies, mapping the user-configured policies to target ACL policies based on the policy management tree, and sending the target ACL policies to the proxy modules in the corresponding policy execution groups.

[0034] In this application, the proxy modules for executing ACL policies are divided into multiple policy execution groups, and then a policy management tree is constructed based on the correspondence between the proxy modules and the policy groups. After receiving the user-configured policy, the user-configured policy can be mapped to the target ACL policy, and the target ACL policy is sent to the proxy modules in the corresponding policy execution group, so as to realize that multiple proxy modules can be configured by issuing an ACL policy once. This application issues ACL policies to the policy execution groups based on the policy management tree, without having to log in to each proxy module and configure the ACL policy one by one, and can batch-configure the ACL policies for the proxy modules in the policy execution group. Therefore, this application can improve the configuration efficiency of ALC policies. This application also provides an access control list (ACL) policy management device, an electronic device, and a storage medium, which have the above beneficial effects and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] To more clearly illustrate the embodiments of this application, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0036] Figure 1 It is a flowchart of a method for managing access control list (ACL) policies provided by an embodiment of this application;

[0037] Figure 2 It is a flowchart of a method for adding an ACL policy to a policy management tree provided by an embodiment of this application;

[0038] Figure 3 It is a flowchart of a method for deleting an ACL policy from a policy management tree provided by an embodiment of this application;

[0039] Figure 4 It is a schematic diagram of grouping proxy modules provided by an embodiment of this application;

[0040] Figure 5 It is a schematic diagram of the structure of a policy management tree provided by an embodiment of this application;

[0041] Figure 6 It is a schematic diagram of the effective state under an ACL policy provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Apparently, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0043] Please refer to the following Figure 1 , Figure 1 , which is a flowchart of a method for managing access control list (ACL) policies provided by an embodiment of this application.

[0044] The specific steps may include:

[0045] S101: Divide multiple proxy modules into multiple policy execution groups;

[0046] Among them, this embodiment can be applied to a centralized management platform, which can be connected to multiple clients. The proxy module (Agent) is the smallest entity unit in the client for executing ACL policies. This embodiment can pre-obtain the device attributes of the clients where multiple proxy modules are located, and divide the multiple proxy modules into multiple policy execution groups based on the above device attributes. As a feasible implementation manner, the above device attributes include any one or a combination of several of device type, service type, and device location.

[0047] This embodiment does not limit the number of proxy modules in a policy execution group. One proxy module can belong to any number of policy execution groups at the same time. Further, any number of sub-policy execution groups can be included in one policy execution group.

[0048] S102: Construct a policy management tree according to the correspondence between the proxy modules and the policy execution groups;

[0049] Among them, based on dividing multiple proxy modules into multiple policy execution groups, this embodiment can abstract each proxy module and policy execution group into a policy management tree according to the correspondence between the proxy modules and the policy execution groups.

[0050] The root node of the policy management tree is the action of policy execution (such as allow or deny). The child nodes of the policy management tree include source port, destination port, and policy execution group label. The policy execution group label is a unique label set according to the policy execution group division rule. The proxy modules in the policy execution group can be determined according to the policy execution group label. The child nodes in the policy management tree inherit the ACL policies configured in the parent node. Therefore, by configuring the ACL policies of the parent node, all child nodes of the parent node can be configured with corresponding ACL policies.

[0051] S103: receiving a user configuration policy, mapping the user configuration policy to a target ACL policy based on the policy management tree, and sending the target ACL policy to a proxy module in a corresponding policy execution group.

[0052] Among them, after receiving the user's configuration policy, this embodiment can generate a node corresponding to the user configuration policy based on the tree algorithm of the policy management tree, so as to add the target ACL policy to the policy management tree. Specifically, the user configuration policy may include the policy execution group label of the policy execution group that needs to configure the ACL and the action that the policy needs to perform. For example, the user configuration policy can be to allow all devices in place A to send information to all devices in place B. At this time, a node corresponding to the user configuration policy can be generated according to the policy management tree to add the target ACL policy, and the target ACL policy can be sent to all proxy modules in the policy execution group corresponding to places A and B to make the target ACL policy effective.

[0053] This embodiment divides the proxy modules used to execute ACL policies into multiple policy execution groups, and then constructs a policy management tree based on the correspondence between the proxy modules and the policy groups. After receiving the user configuration policy, the user configuration policy can be mapped to the target ACL policy, and the target ACL policy can be sent to the proxy module in the corresponding policy execution group, so that multiple proxy modules can be configured by delegating the ACL policy once. This embodiment can send the target ACL policy to some or all proxy modules in the policy execution group. This embodiment sends the ACL policy to the policy execution group based on the policy management tree. There is no need to log in to the proxy module one by one and configure the ACL policy. The ACL policy configuration operation can be performed on the proxy modules in the policy execution group in batches. Therefore, this embodiment can improve the configuration efficiency of the ALC policy.

[0054] As for Figure 1 Further introduction to the corresponding embodiment: since the policy management tree records the effective ACL policy, the newly added ACL policy may conflict with the effective ACL policy. Therefore, before sending the target ACL policy to the proxy module in the corresponding policy execution group, it can be determined whether the target ACL policy conflicts with the effective ACL policy in the policy management tree; if so, a prompt message indicating that the ACL policy setting failed is returned; if not, the target ACL policy is sent to the proxy module in the corresponding policy execution group.

[0055] Furthermore, this embodiment can pre-set corresponding rules to determine whether two ACL policies conflict. For example, the ACL policy fields can be traversed to see if they are repeated. If they are repeated, it means that the two ACL policies conflict, and then the ACL policy adding process ends. Figure 2 , Figure 2This is a flow chart of a method for adding ACL policies to a policy management tree provided by an embodiment of the present application. In this embodiment, a new policy can be input first, and a tree node can be generated by traversing the policy field. If the policy is repeated, the policy adding process ends; if the policy is not repeated, the policy addition is determined to be successful.

[0056] As for Figure 1 Further introduction to the corresponding embodiment: in actual applications, users have the need to delete the effective ACL policy in the policy management tree. Therefore, after constructing the policy management tree according to the correspondence between the proxy module and the policy execution group, the ACL policy to be deleted can also be determined according to the received policy deletion instruction; if there is a target leaf node corresponding to the ACL policy to be deleted in the policy management tree, and there is policy information in the target leaf node, the policy information in the target leaf node is deleted.

[0057] See also Figure 3 , Figure 3 A flowchart of a method for deleting an ACL policy from a policy management tree provided in an embodiment of the present application. Figure 3 As shown in the figure, after determining the policy to be deleted, match each field information of the policy to be deleted with the nodes in the policy management tree one by one. If there is an unmatched field node, it means that the policy to be deleted is not in the policy management tree, and the deletion fails. If there is a completely matched field node, and the corresponding policy information exists in the corresponding leaf node, the deletion operation is performed.

[0058] Furthermore, this embodiment can also display the policy management tree in a visual interface so that the user can analyze the ACL policy configuration layout. Correspondingly, if an ACL policy is added or deleted from the policy management tree, the policy management tree displayed in the visual interface is updated.

[0059] The process described in the above embodiment is explained below through an embodiment in actual application.

[0060] See also Figure 4 , Figure 4 A schematic diagram of a proxy module grouping provided in an embodiment of the present application, such as Figure 4 As shown, in this embodiment, multiple agent modules can be divided into a group, and the division rules can be divided according to attributes such as region and business. In this embodiment, by grouping agent modules of the same type or running the same business, the agent modules will inherit the policies of the group to which they belong, and expand the scope of policy effectiveness. In traditional solutions, multiple policies need to be configured, but in this embodiment, configuring one policy can cover multiple agent modules, reducing the number of policy configurations and reducing the difficulty of operation and maintenance for managers.

[0061] Before constructing the policy management tree according to the correspondence between the proxy module and the policy execution group, this embodiment can also bind a unique corresponding identity identifier to the proxy module; correspondingly, the five-tuple configuration information of the target ACL policy includes the identity identifier of the source proxy module, the identity identifier of the destination proxy module, the source port, the destination port, and the communication protocol. For example, the proxy module and the policy execution group can be uniformly abstracted to construct a policy management tree, where the policy execution group is represented by a group id and the proxy module is represented by an agent id. The advantage of doing this is that unified modeling can be performed and changes in the attributes of network units can be shielded. In a cloud scenario, the proxy module is a specific virtual machine, and its IP address and the group it belongs to will change. Using a unified and abstract identity identifier can ensure the availability and scalability of the solution. After using the abstract identity identifier, the original ACL policy becomes an abstracted policy, and the specific format is {source identity identifier, destination identity identifier, source port, destination port, protocol}, which simplifies the ACL policy configuration process.

[0062] Please refer to Figure 5 , Figure 5 FIG. is a schematic structural diagram of a policy management tree provided by an embodiment of the present application. The user-configured policy can be mapped into an ACL policy and sent to the proxy module and / or the policy execution group by using a high-performance tree algorithm to implement the security isolation function. Specifically, the process of mapping the user-configured policy to the target ACL policy may include: generating a node corresponding to the user-configured policy in the policy management tree, and determining the target ACL policy corresponding to the user-configured policy according to the policy information recorded in the node corresponding to the user-configured policy; wherein, the root node of the policy management tree is a policy action, and the child nodes include a source port, a destination port, and a policy execution group label, and the policy execution group label includes a source label and a destination label.

[0063] Such as Figure 5As shown, the root node is the action of the policy (permit or deny). Permit means that the current policy allows two hosts to communicate with each other, and deny means they cannot. In this embodiment, the source label and the destination label in the target ACL policy can be swapped to obtain a reverse ACL policy, and the target ACL policy and the reverse ACL policy are sent to the proxy modules in the corresponding policy execution groups. The reverse ACL policy is the target ACL policy with the source label and the target label swapped. When adding a new policy, since a policy has two labels, the source label and the destination label, this solution also swaps the source label and the destination label when adding a policy. Both the source label and the destination label record the current policy information, so that when the policy is sent, it can take effect on both the source label and the destination label machines. The connection between each layer and the lower layer is recorded using a hash table to speed up the query of child nodes. In this embodiment, all ACL policies can be managed using a policy management tree and then sent uniformly. This embodiment only requires one configuration entry to manage the policies of the proxy modules. Due to the characteristics of the tree structure, the policy management tree can conveniently provide conditional query of policies, such as querying all policies under a certain port or all policies under a certain label, which is convenient for administrators to analyze policies. In this embodiment, by swapping the source label and the destination label, a policy can be sent to both sides at the same time, reducing the amount of policies that need to be configured.

[0064] After performing management operations such as adding and deleting ACL policies based on the policy management tree, the configured policy is sent to the proxy module to take effect. In this method, the proxy modules in the system are grouped according to Figure 1 the method, and then the system network structure can be abstracted to obtain a policy management tree. As shown in Figure 6 , Figure 6 is a schematic diagram of the effective implementation of an ACL policy provided by an embodiment of the present application. Figure 6 As shown, the centralized management platform configures policy 1 as G - A. G and A are both corresponding policy execution groups. There are corresponding groups and proxy modules agent under the policy execution groups. Among them, E and F are proxy modules. In the policy management tree, E and F will inherit policy 1, that is, the proxy modules will inherit the policies configured by the centralized management platform, take effect on themselves for this policy, and complete the corresponding policy actions, and finally complete the configuration and effectiveness of the security policy.

[0065] This embodiment can also use the policy management tree to check whether there are conflicts in the configured ACL policies. If there are conflicts, the conflict range can be checked to improve the correctness of the configured policies and reduce policy redundancy. The above - mentioned embodiment can use software means on the centralized management platform to achieve the security isolation of the internal network, far exceeding the existing solutions in terms of usability and security. Users only need to customize security policies on the centralized platform, and the system will implement the corresponding ACL policies on the corresponding machines to complete the east - west security isolation configuration between internal networks.

[0066] The embodiment of the present application also provides an access control list (ACL) policy management device, which may include:

[0067] A grouping module, used to divide multiple proxy modules into multiple policy execution groups; wherein the proxy module is a module in the client for executing ACL policy;

[0068] A management tree construction module, used to abstract the system network structure of the proxy module and the policy execution group into a policy management tree; wherein the child nodes in the policy management tree inherit the ACL policy configured in the parent node;

[0069] The policy configuration module is used to receive a user configuration policy, map the user configuration policy to a target ACL policy based on the policy management tree, and send the target ACL policy to an agent module in a corresponding policy execution group.

[0070] This embodiment divides the proxy modules used to execute ACL policies into multiple policy execution groups, and then constructs a policy management tree based on the correspondence between the proxy modules and the policy groups. After receiving the user configuration policy, the user configuration policy can be mapped to the target ACL policy, and the target ACL policy can be sent to the proxy module in the corresponding policy execution group, so that multiple proxy modules can be configured by sending the ACL policy once. This embodiment sends the ACL policy to the policy execution group based on the policy management tree. There is no need to log in to the proxy module one by one and configure the ACL policy. The ACL policy configuration operation can be performed on the proxy modules in the policy execution group in batches. Therefore, this embodiment can improve the configuration efficiency of the ALC policy.

[0071] Furthermore, the grouping module is used to divide the plurality of proxy modules into the plurality of policy execution groups according to device attributes of the client where the proxy modules are located; wherein the device attributes include any one or a combination of any several of the device type, service type and device location.

[0072] Furthermore, the policy configuration module includes:

[0073] The conflict detection unit is used to determine whether the target ACL policy conflicts with the effective ACL policy in the policy management tree; if so, return a prompt message indicating that the ACL policy setting fails; if not, send the target ACL policy to the proxy module in the corresponding policy execution group.

[0074] Furthermore, it also includes:

[0075] A policy deletion module, which is used to determine the ACL policy to be deleted according to the received policy deletion instruction after constructing a policy management tree based on the correspondence between the proxy module and the policy execution group; and is further used to delete the policy information in the target leaf node if there is a target leaf node corresponding to the ACL policy to be deleted in the policy management tree and there is policy information in the target leaf node.

[0076] Furthermore, it further includes:

[0077] A visualization module, which is used to display the policy management tree on a visualization interface; and is further used to update the policy management tree displayed on the visualization interface if an ACL policy is added or deleted in the policy management tree.

[0078] Furthermore, a policy configuration module is used to generate a node corresponding to the user-configured policy in the policy management tree, and determine the target ACL policy corresponding to the user-configured policy according to the policy information recorded in the node corresponding to the user-configured policy; wherein, the root node of the policy management tree is a policy action, and the child nodes include a source port, a destination port, and a policy execution group label, and the policy execution group label includes a source label and a destination label; and is further used to swap the source label and the destination label in the target ACL policy to obtain a reverse ACL policy, and send the target ACL policy and the reverse ACL policy to the proxy module in the corresponding policy execution group.

[0079] Furthermore, it further includes:

[0080] An identity binding module, which is used to bind a uniquely corresponding identity identifier to the proxy module before constructing a policy management tree according to the correspondence between the proxy module and the policy execution group; correspondingly, the five-tuple configuration information of the target ACL policy includes the identity identifier of the source proxy module, the identity identifier of the destination proxy module, the source port, the destination port, and the communication protocol.

[0081] Since the embodiments in the device part correspond to the embodiments in the method part, for the embodiments in the device part, please refer to the description of the embodiments in the method part, and will not be elaborated here.

[0082] This application also provides a storage medium, on which a computer program is stored, and when the computer program is executed, the steps provided in the above embodiments can be implemented. The storage medium may include: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

[0083] The present application further provides an electronic device, which may include a memory and a processor. A computer program is stored in the memory. When the processor calls the computer program in the memory, the steps provided in the above embodiments can be implemented. Of course, the electronic device may further include various network interfaces, power supplies and other components.

[0084] The various embodiments in the specification are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part. It should be noted that for those of ordinary skill in the art in the technical field of the present application, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.

[0085] It should also be noted that in this specification, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "including one..." does not exclude the existence of another identical element in the process, method, article or device including the said element.

Claims

1. A method for managing access control list (ACL) policies, characterized in that Including: Dividing multiple proxy modules into multiple policy execution groups; wherein, the proxy module is a module in the client for executing ACL policies; Abstracting the system network structure of the proxy module and the policy execution group into a policy management tree; wherein, the child nodes in the policy management tree inherit the ACL policies configured in the parent nodes; Receiving user-configured policies, mapping the user-configured policies to target ACL policies based on the policy management tree, and sending the target ACL policies to the proxy modules in the corresponding policy execution groups.

2. The method for managing access control list (ACL) policies according to claim 1, characterized in that The dividing multiple proxy modules into multiple policy execution groups includes: Dividing multiple proxy modules into multiple policy execution groups according to the device attributes of the clients where the proxy modules are located; wherein, the device attributes include any one or a combination of several of device type, service type, and device location.

3. The method for managing access control list (ACL) policies according to claim 1, characterized in that Sending the target ACL policy to the proxy module in the corresponding policy execution group includes: Judging whether there is a conflict between the target ACL policy and the ACL policies that have taken effect in the policy management tree; If so, returning a prompt message indicating that the ACL policy setting fails; If not, sending the target ACL policy to the proxy module in the corresponding policy execution group.

4. The method for managing access control list (ACL) policies according to claim 1, characterized in that After constructing the policy management tree according to the corresponding relationship between the proxy module and the policy execution group, it further includes: Determining the ACL policy to be deleted according to the received policy deletion instruction; If there is a target leaf node corresponding to the ACL policy to be deleted in the policy management tree, and there is ACL policy information in the target leaf node, deleting the ACL policy information in the target leaf node.

5. The method for managing access control list (ACL) policies according to claim 1, characterized in that It further includes: Displaying the policy management tree on a visual interface; If an ACL policy is added or deleted in the policy management tree, updating the policy management tree displayed on the visual interface.

6. The method for managing access control list (ACL) policies according to any one of claims 1 to 5, characterized in that Mapping the user-configured policy to a target ACL policy based on the policy management tree, and sending the target ACL policy to the proxy module in the corresponding policy execution group includes: Generating a node corresponding to the user-configured policy in the policy management tree, and determining the target ACL policy corresponding to the user-configured policy according to the policy information recorded in the node corresponding to the user-configured policy; wherein, the root node of the policy management tree is a policy action, and the child nodes include a source port, a destination port, and a policy execution group label, and the policy execution group label includes a source label and a destination label; Swapping the source label and the destination label in the target ACL policy to obtain a reverse ACL policy, and sending the target ACL policy and the reverse ACL policy to the proxy modules in the corresponding policy execution groups.

7. The method for managing access control list (ACL) policies according to claim 6, characterized in that Before constructing the policy management tree according to the corresponding relationship between the proxy module and the policy execution group, it further includes: Binding a unique corresponding identity identifier to the proxy module; Correspondingly, the five-tuple configuration information of the target ACL policy includes the identity identifier of the source proxy module, the identity identifier of the destination proxy module, the source port, the destination port, and the communication protocol.

8. An access control list (ACL) policy management device, characterized in that Including: A grouping module, configured to divide multiple proxy modules into multiple policy execution groups; wherein, the proxy module is a module in the client for executing ACL policies; A management tree construction module, configured to abstract the system network structure of the proxy module and the policy execution group into a policy management tree; wherein, the child nodes in the policy management tree inherit the ACL policies configured in the parent nodes; A policy configuration module, configured to receive user-configured policies, map the user-configured policies to target ACL policies based on the policy management tree, and send the target ACL policies to the proxy modules in the corresponding policy execution groups.

9. An electronic device, characterized in that It includes a memory and a processor. A computer program is stored in the memory. When the processor calls the computer program in the memory, the steps of the access control list ACL policy management method according to any one of claims 1 to 7 are implemented.

10. A storage medium, characterized in that Computer-executable instructions are stored in the storage medium. When the computer-executable instructions are loaded and executed by the processor, the steps of the access control list ACL policy management method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Maintenance method of device management tree and terminal device

    CN101080077A

  • Cloud based dynamic access control list management architecture

    US20140379915A1