A method for accessing computer system resources based on user entities

By updating the access permission scope of user entities in real time, dynamically adjusting the access permissions of computer system resources based on program tracking tree and environment deviation data, solving the problem of singularity of traditional access control methods and improving the security and stability of system resources.

CN115964689BActive Publication Date: 2025-07-18GUOCHENG TECH (CHENGDU) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310051230.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-02
Publication Date
2025-07-18
Estimated Expiration
2043-02-02

AI Technical Summary

Technical Problem

The traditional computer system resource access control method is relatively single, which leads to a high probability of system resources being tampered with and damaged, which may cause information security accidents and program operation abnormalities.

Method used

By obtaining the initial access permission range of the user entity in the system resource memory block, based on program operation tracking data and environmental deviation data, the access permission range is updated in real time, and access feedback results are generated to dynamically adjust access permissions.

Benefits of technology

It improves the security of system resource access process, reduces the risk of system resources being tampered with, and ensures information security and the normal operation of applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115964689B_ABST
    Figure CN115964689B_ABST
Patent Text Reader

Abstract

The present invention provides a method for accessing computer system resources based on a user entity, including: S1: obtaining the initial access permission range of the user entity in the system resource memory block; S2: building a program trace tree based on all program operation trace data of the user entity obtained recently within a preset period; S3: determining a reference program trace tree of the user entity in the current running environment based on the environmental deviation data between the current running environment and the standard running environment of the user entity; S4: updating the initial access permission range in real time based on the feature deviation between the program trace tree and the reference program trace tree to obtain the current access permission range; S5: generating an access feedback result based on the access request instruction of the user entity and the current access permission range; for analyzing the deviation of the running environment of the user entity and the program operation trace data, realizing real-time dynamic adjustment of the access permission range of the system resources, and making the security degree of the system resource access process higher.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data management, and particularly to a method for accessing computer system resources based on user entities. Background Art

[0002] Currently, when an application program runs in a computer system, the computer system must track the running of the application program in real time and store the program running tracking information in a memory block called a heap. For example, the User Resource Heap, the Graphical Device Interface Resource Heap. The User Resource Heap and the GDI Resource Heap are collectively called the System Resource Heap, and conventionally they are called System Resources. The existing access control of computer system resources mostly controls the access rights of user entities to computer system resources by based on the access scope pre-assigned to user entities.

[0003] However, system resources are related to the information security of user entities and the normal operation of application programs. The traditional access control method of computer system resources is relatively single. Simply controlling the access to system resources based on preset access rights greatly increases the probability of system resources being tampered with and damaged, and may cause various problems such as information security incidents and abnormal program operations.

[0004] Therefore, the present invention proposes a method for accessing computer system resources based on user entities. Summary of the Invention

[0005] The present invention provides a method for accessing computer system resources based on user entities, which is used to analyze the deviation of the current running environment of user entities and program operation tracking data, and realize the real-time dynamic adjustment of the access right range of system resources, so that the security degree of the system resource access process is higher.

[0006] The present invention provides a method for accessing computer system resources based on user entities, including:

[0007] S1: Obtain the initial access right range of the user entity in the system resource memory block;

[0008] S2: Based on all the program operation tracking data of the user entity obtained recently within a preset period, build a program tracking tree;

[0009] S3: Determine the reference program tracking tree of the user entity in the current running environment based on the environmental deviation data between the current running environment of the user entity and the standard running environment;

[0010] S4: Based on the feature deviation between the program trace tree and the reference program trace tree, update the initial access permission range in real time to obtain the current access permission range;

[0011] S5: Generate an access feedback result based on the access request instruction of the user entity and the current access permission range.

[0012] Preferably, for the computer system resource access method based on a user entity, S1: Obtain the initial access permission range of the user entity in the system resource memory block, including:

[0013] S101: Based on the original user information of the user entity and the access permission rules of each sub-memory block in the system resource memory block, determine the sub-initial access permission range of each sub-memory block;

[0014] S102: Aggregate the sub-initial access permission ranges of all sub-memory blocks to obtain the initial access permission range.

[0015] Preferably, for the computer system resource access method based on a user entity, S2: Based on all the program operation trace data of the user entity obtained recently within a preset period, construct a program trace tree, including:

[0016] S201: Based on the preset program subordination relationship and the program category, determine the hierarchical relationship among all the application programs, the general name of program subordination, and the program category in the current running environment of the user entity;

[0017] S202: Generate virtual storage nodes for each application program, the general name of program subordination, and the program category, and construct a program subordination relationship tree of the current running environment based on the hierarchical relationship and all the virtual storage nodes;

[0018] S203: Import all the program operation trace data of the user entity obtained recently within a preset period into the corresponding virtual storage nodes in the program subordination relationship tree to obtain the program trace tree.

[0019] Preferably, for the computer system resource access method based on a user entity, S3: Based on the environmental deviation data between the current running environment and the standard running environment of the user entity, determine the reference program trace tree of the user entity in the current running environment, including:

[0020] Retrieve a group of similar user entity trace records in the standard running environment from the user entity trace record library based on the original user information of the user entity;

[0021] Generate the comprehensive representative program trace data of the user entity in the standard running environment based on the program operation trace data in all the similar user entity trace records in the group of similar user entity trace records;

[0022] Based on the quantified relationships among the comprehensive representation program trace data, the environmental deviation data, and the operating environment data and program operation trace data, a reference program trace tree of the user entity in the current operating environment is constructed.

[0023] Preferably, for the computer system resource access method based on a user entity, based on the quantified relationships among the comprehensive representation program trace data, the environmental deviation data, and the operating environment data and program operation trace data, a reference program trace tree of the user entity in the current operating environment is constructed, including:

[0024] Based on the quantified relationship between the operating environment data and the program operation trace data and the environmental deviation data, the deviation of the program operation trace data is determined.

[0025] Based on the comprehensive representation program trace data and the deviation of the program operation trace data, the reference program operation trace data of the user entity in the current operating environment is determined, and a reference program trace tree of the user entity in the current operating environment is constructed based on the reference program operation trace data.

[0026] Preferably, for the computer system resource access method based on a user entity, S4: Based on the feature deviation between the program trace tree and the reference program trace tree, the initial access permission range is updated in real time to obtain the current access permission range, including:

[0027] Based on the preset program subordination relationship, program category, and preset label generation method, the first subordination label of each first subtree structure in the program trace tree and the second subordination label of each second subtree structure in the reference program trace tree are generated.

[0028] Based on the first subordination label and the second subordination label, the first subtree structure and the second subtree structure are corresponded to obtain the subtree structure correspondence result.

[0029] The local deviation structure in the program trace tree and the reference program trace tree and the deviation trace data between the program operation trace data in the corresponding virtual storage nodes in the program trace tree and the reference program trace tree are regarded as feature deviations.

[0030] Based on the feature deviation and the subtree structure correspondence result, the initial access permission range is updated in real time to obtain the current access permission range.

[0031] Preferably, for the computer system resource access method based on a user entity, based on the feature deviation and the subtree structure correspondence result, the initial access permission range is updated in real time to obtain the current access permission range, including:

[0032] The first overlapping structure in the first subtree structure that overlaps with the local deviation structure in the feature deviation is determined.

[0033] Based on the deviation tracking data between each first virtual storage node in the first overlapping structure and the corresponding second virtual storage node in the reference program trace tree, and the corresponding results of the subtree structure, calculate the membership deviation degree of each first virtual storage node in each first subtree structure to which it belongs;

[0034] Based on the membership deviation degree of each first virtual storage node in all first subtree structures to which it belongs, update the initial access permission range in real time to obtain the current access permission range.

[0035] Preferably, for the computer system resource access method based on user entities, based on the membership deviation degree of each first virtual storage node in all first subtree structures to which it belongs, update the initial access permission range in real time to obtain the current access permission range, including:

[0036] Take the average value of the membership deviation degrees of each first virtual storage node in all first subtree structures to which it belongs as the comprehensive deviation degree of the tracking data of the corresponding first virtual storage node;

[0037] Based on the comprehensive deviation degree of the tracking data of each first virtual storage node, determine the current access permission range in the initial access permission range of the sub-memory block corresponding to the corresponding first virtual storage node.

[0038] Preferably, for the computer system resource access method based on user entities, based on the comprehensive deviation degree of the tracking data of each first virtual storage node, determine the current access permission range in the initial access permission range of the sub-memory block corresponding to the corresponding first virtual storage node, including:

[0039] Divide the system resources in the sub-initial access permission range of the sub-memory block corresponding to the first virtual storage node to obtain multiple unit system resources, and determine the importance of each unit system resource. Sort all unit system resources based on the importance to obtain the unit system resource list of the sub-memory block;

[0040] Based on the comprehensive deviation degree of the tracking data, determine the current accessible unit system resource set in the unit system resource list of the sub-memory block corresponding to the corresponding first virtual storage node, and use the current accessible unit system resource set as the current access permission range.

[0041] Preferably, for the computer system resource access method based on user entities, S5: Generate an access feedback result based on the access request instruction of the user entity and the current access permission range, including:

[0042] Determine the target requested access resource based on the access request instruction;

[0043] Determine whether the target requested access resource is within the current access permission range. If so, grant the access permission of the target requested access resource to the user entity to obtain an access feedback result. Otherwise, send an access permission denied feedback instruction to the user entity to obtain an access feedback result.

[0044] Other features and advantages of the present invention will be described in the following specification, and in part will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained by the structures specifically pointed out in the written specification, claims, and drawings.

[0045] The technical solutions of the present invention will be further described in detail below through the drawings and embodiments. Description of the Drawings

[0046] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings:

[0047] Figure 1 It is a flowchart of a method for accessing computer system resources based on a user entity in an embodiment of the present invention;

[0048] Figure 2 It is a flowchart of another method for accessing computer system resources based on a user entity in an embodiment of the present invention;

[0049] Figure 3 It is a flowchart of yet another method for accessing computer system resources based on a user entity in an embodiment of the present invention. Detailed Embodiments

[0050] The following describes the preferred embodiments of the present invention with reference to the drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.

[0051] Embodiment 1:

[0052] The present invention provides a method for accessing computer system resources based on a user entity. Referring to Figure 1 , including:

[0053] S1: Obtain the initial access permission range of the user entity in the system resource memory block;

[0054] S2: Build a program trace tree based on all program operation trace data of the user entity obtained in the latest preset period;

[0055] S3: Determine the reference program trace tree of the user entity in the current operating environment based on the environmental deviation data between the current operating environment and the standard operating environment of the user entity;

[0056] S4: Update the initial access permission range in real time based on the feature deviation between the program trace tree and the reference program trace tree to obtain the current access permission range;

[0057] S5: Generate an access feedback result based on the access request instruction of the user entity and the current access permission range.

[0058] In this embodiment, the user entity is a virtual internal user created by the user within the system, including: first name and last name, login name, email address, password (not in plain text), permissions, etc.

[0059] In this embodiment, the system resource memory block is a memory block used to store computer system resources, and the memory block is mainly in the form of a heap.

[0060] In this embodiment, the initial access permission range is the permission range for the user entity to access computer system resources determined based on the original user information of the user entity (such as: first name and last name, login name, email address, password (not in plain text), permissions, etc.).

[0061] In this embodiment, the preset period is the period for obtaining the program operation trace data of the user entity set in advance.

[0062] In this embodiment, the program operation trace data is the data obtained after tracking the operations performed by the user entity on the application programs in the computer system.

[0063] In this embodiment, the program trace tree is a tree structure representing the trace data of the operations performed by the user entity on all application programs within the preset period, built based on all the program operation trace data of the user entity obtained in the latest preset period.

[0064] In this embodiment, the current operating environment is the operating environment data of the user entity currently in the computer, and the operating environment data includes, for example, the hardware environment (such as the hard disk manufacturer, etc.) and the network environment (such as IT, WiFi, etc.).

[0065] In this embodiment, the standard operating environment is the operating environment data of the user entity in the ideal state (standard state) in the computer preset, and the operating environment data includes, for example, the hardware environment (such as the hard disk manufacturer, etc.) and the network environment (such as IT, WiFi, etc.).

[0066] In this embodiment, the environmental deviation data is the deviation data between the operating environment data corresponding to the current operating environment of the user entity and the operating environment data corresponding to the standard operating environment.

[0067] In this embodiment, the reference program tracking tree is a tree structure including program operation tracking data generated when the user entity normally operates in the current operating environment, which is determined based on the environment deviation data of the current operating environment of the user entity and the standard operating environment.

[0068] In this embodiment, the characteristic deviation is the deviation between the program tracking tree and the reference program tracking tree, specifically including: the local deviation structure in the program tracking tree and the reference program tracking tree and the deviation tracking data between the program operation tracking data in the corresponding virtual storage nodes in the program tracking tree and the reference program tracking tree.

[0069] In this embodiment, the current access permission scope is the access permission scope of the user entity to the computer system resources in the current state obtained after the initial access permission scope is updated in real time based on the feature deviation between the program tracking tree and the reference program tracking tree.

[0070] In this embodiment, the access request instruction is an instruction issued by a user entity to request a computer system resource access control program to access a computer system resource.

[0071] In this embodiment, the access feedback result is a result including feedback on the access request instruction, which is generated based on the access request instruction of the user entity and the current access permission scope.

[0072] The beneficial effects of the above technology are: through real-time deviation analysis of the program tracking tree of the user entity in the current operating environment and the reference program tracking tree of the user entity in the standard operating environment, real-time dynamic adjustment of the access permission scope of system resources is achieved, and the access permission scope of computer system resources is realized based on the dynamic conditions of the program operation tracking results of the user entity in the computer system, which overcomes the singleness of traditional computer system resource access control methods and makes the system resources more secure.

[0073] Embodiment 2:

[0074] Based on Example 1, the method for accessing computer system resources based on a user entity, S1: obtaining the initial access permission range of the user entity in the system resource memory block, referring to Figure 2 ,include:

[0075] S101: Determine a sub-initial access permission range of each sub-memory block based on original user information of the user entity and access permission rules of each sub-memory block in the system resource memory block;

[0076] S102: Summarize the sub-initial access permission ranges of all sub-memory blocks to obtain the initial access permission range.

[0077] In this embodiment, the sub-memory block is the memory block that stores the trace data of the operations performed by the user entity on a single application program in the system resource memory block.

[0078] In this embodiment, the access permission rule is a rule for determining the range of access permissions for the program operation trace data stored in each sub-memory block based on the original user information of the user entity, which is preset. For example: determining the range of access permissions that the user entity can have for the program operation trace data of application program A based on the user level in the original user information.

[0079] In this embodiment, the sub-initial access permission range is the range of access permissions of the user entity to the system resources (i.e., the program operation trace data of the corresponding application program) stored in the sub-memory block.

[0080] The beneficial effects of the above technology are as follows: Based on the access permission rule of the sub-memory block storing the program operation trace data of the corresponding application program and the original user information of the user entity, the sub-initial access permission range of each sub-memory block is determined, and further the initial access permission range of the system resource memory block is determined.

[0081] Embodiment 3:

[0082] Based on Embodiment 1, for the computer system resource access method based on user entities, S2: Based on all the program operation trace data of the user entity obtained recently within a preset period, a program trace tree is constructed, including:

[0083] S201: Based on the preset program subordination relationship and program category, determine the hierarchical relationship among all application programs, the general name of program subordination, and the program category in the current running environment of the user entity;

[0084] S202: Generate virtual storage nodes for each application program, the general name of program subordination, and the program category, and construct a program subordination relationship tree for the current running environment based on the hierarchical relationship and all virtual storage nodes;

[0085] S203: Import all the program operation trace data of the user entity obtained recently within a preset period into the corresponding virtual storage nodes in the program subordination relationship tree to obtain the program trace tree.

[0086] In this embodiment, the preset program subordination relationship is the pre-specified subordination relationship between programs. For example: Microsoft Access and Microsoft Excel both belong to the Microsoft Office tool.

[0087] In this embodiment, the category to which a program belongs is the classification category of the program. For example, the categories to which Microsoft Excel and WPS belong are office tools, and the categories to which QQ and WeChat belong are chat tools.

[0088] In this embodiment, the hierarchical relationship is the order subordination relationship and the level relationship of the categories to which the programs belong among all the application programs in the current operating environment.

[0089] In this embodiment, the general name of program subordination is the general name of the program that includes multiple application programs determined based on the program subordination relationship. For example, both Microsoft Access and Microsoft Excel are subordinate to the Microsoft Office tool, so the Microsoft Office tool is the general name of program subordination for Microsoft Access and Microsoft Excel.

[0090] In this embodiment, based on the preset program subordination relationship and the category to which the program belongs, the hierarchical relationship among all the application programs, the general name of program subordination, and the category to which the program belongs in the current operating environment of the user entity is determined. For example:

[0091] Both Microsoft Access and Microsoft Excel are subordinate to the Microsoft Office tool. The categories to which the Microsoft Office tool and the WPS software belong are office tools, and the categories to which QQ and WeChat belong are chat tools.

[0092] Then, the chat tools and the office tools are at the same level. The office tools include the Microsoft Office tool and the WPS software (that is, both the Microsoft Office tool and the WPS software are at the next level of the office tools), and the chat tools include QQ and WeChat (that is, QQ and WeChat are at the next level of the chat tools).

[0093] In this embodiment, the virtual storage node is a virtual node used to store the program operation tracking data of the corresponding application program, the general name of program subordination, and the category to which the program belongs.

[0094] In this embodiment, the program subordination relationship tree of the current operating environment is built based on the hierarchical relationship and all the virtual storage nodes, which is:

[0095] Connect all virtual storage nodes based on the hierarchical relationship among all application programs, the general name of program subordination, and the category to which the program belongs. As for the virtual storage nodes of application programs, the general name of program subordination, and the category to which the program belongs that are at the same level in the hierarchical relationship, their sorting methods in the program subordination relationship tree are determined according to the preset sorting method, and the program subordination relationship tree of the current operating environment is obtained.

[0096] In this embodiment, the program subordination relationship tree is a tree structure that represents the hierarchical relationship among all application programs, the corresponding general name of program subordination, and the corresponding category to which the program belongs in the current operating environment (i.e., including the order subordination relationship among all application programs and the level relationship of the categories to which the programs belong).

[0097] The beneficial effects of the above technology are as follows: Based on the preset program subordination relationship and the category to which the program belongs, the hierarchical relationship among all application programs, the general name of program subordination, and the category to which the program belongs in the current operating environment of the user entity is determined. Then, based on the hierarchical relationship, the virtual storage nodes of all application programs are connected to build the program subordination relationship tree of the current operating environment. Next, all program operation tracking data of the user entity obtained recently within the preset period is imported into the corresponding virtual storage nodes in the program subordination relationship tree, and the program tracking tree of the user entity in the current operating environment is built.

[0098] Embodiment 4:

[0099] Based on the method for accessing computer system resources based on a user entity in Embodiment 1, S3: Determine the reference program tracking tree of the user entity in the current operating environment based on the environmental deviation data between the current operating environment and the standard operating environment of the user entity, including:

[0100] Retrieve a group of similar user entity tracking records in the standard operating environment from the user entity tracking record library based on the original user information of the user entity;

[0101] Generate the comprehensive representative program tracking data of the user entity in the standard operating environment based on the program operation tracking data in all similar user entity tracking records in the group of similar user entity tracking records;

[0102] Build the reference program tracking tree of the user entity in the current operating environment based on the comprehensive representative program tracking data, the environmental deviation data, and the relationship quantity between the operating environment data and the program operation tracking data.

[0103] In this embodiment, the user entity tracking record library is a database for storing the program operation tracking data of multiple user entities.

[0104] In this embodiment, the similar user entity tracking record group is a database containing the program operation tracking data of user entities similar to the user entity in the standard operating environment.

[0105] In this embodiment, based on the original user information of the user entity, a similar user entity tracking record group in the standard operating environment is retrieved from the user entity tracking record library, including:

[0106] Determine the total number of information items that are the same in the original user information of the user entity and the original user information of each user entity in the user entity tracking record library;

[0107] Based on the total number of information items that are the same in the original user information of the user entity and the original user information of the currently calculated user entity in the user entity tracking record library, calculate the similarity between the original user information of the user entity and the original user information of the currently calculated user entity in the user entity tracking record library:

[0108]

[0109] In the formula, s is the similarity between the original user information of the user entity and the original user information of the currently calculated user entity in the user entity tracking record library, and x same is the total number of information items that are the same in the original user information of the user entity and the original user information of the currently calculated user entity in the user entity tracking record library, x1 is the total number of information items in the original user information of the user entity, and x2 is the total number of information items in the original user information of the currently calculated user entity in the user entity tracking record library;

[0110] Based on the above formula, the similarity between the original user information of the user entity and the original user information of the currently calculated user entity in the user entity tracking record library can be accurately calculated;

[0111] Use the user entities whose similarity between the original user information is not less than the similarity threshold as the similar user entities of the user entity;

[0112] And summarize the program operation tracking data of all similar user entities to obtain the similar user entity tracking record group.

[0113] In this embodiment, the comprehensive representation of the program tracking data is the program operation tracking data determined based on the program operation tracking data in all similar user entity tracking records in the similar user entity tracking record group, which represents the program operation tracking data when the user is running normally in the standard operating environment.

[0114] In this embodiment, the similar user entity is a user entity similar to the user entity.

[0115] In this embodiment, the relational quantity between the running environment data and the program operation trace data is the preset corresponding relationship representing the running environment data and the program operation trace data.

[0116] The beneficial effects of the above technologies are as follows: Retrieving a group of similar user entity trace records in the standard running environment from the original user information of the user entity in the user entity trace record library, generating the comprehensive representation program trace data of the user entity in the standard running environment based on the program operation trace data in all similar user entity trace records in the group of similar user entity trace records, and combining the environmental deviation data and the relational quantity between the running environment data and the program operation trace data, a tree structure containing the program operation trace data generated when the user entity operates normally in the current running environment can be built.

[0117] Embodiment 5:

[0118] Based on the comprehensive representation program trace data, the environmental deviation data, and the relational quantity between the running environment data and the program operation trace data, on the basis of Embodiment 4, building a reference program trace tree of the user entity in the current running environment, including:

[0119] Determining the program operation trace data deviation based on the relational quantity between the running environment data and the program operation trace data and the environmental deviation data;

[0120] Determining the reference program operation trace data of the user entity in the current running environment based on the comprehensive representation program trace data and the program operation trace data deviation, and building a reference program trace tree of the user entity in the current running environment based on the reference program operation trace data.

[0121] In this embodiment, the program operation trace data deviation is the data deviation determined after substituting the environmental deviation data into the relationship function corresponding to the relational quantity between the running environment data and the program operation trace data, representing the program operation trace data when the user entity operates normally in the standard running environment and the program operation trace data when the user entity operates normally in the current running environment.

[0122] In this embodiment, determining the reference program operation trace data of the user entity in the current running environment based on the comprehensive representation program trace data and the program operation trace data deviation is:

[0123] Taking the sum of the comprehensive representation program trace data and the program operation trace data deviation as the reference program operation trace data of the user entity in the current running environment.

[0124] In this embodiment, the reference program operation trace data is the program operation trace data when the user entity operates normally in the current operating environment.

[0125] In this embodiment, based on the reference program operation trace data, a reference program trace tree of the user entity in the current operating environment is constructed as follows:

[0126] Generate virtual storage nodes for all application programs, program affiliation general names, and program categories included in the reference program operation trace data, and import the program operation trace data corresponding to each application program, program affiliation general name, and program category in the reference program operation trace data into the virtual storage nodes of the corresponding application programs to obtain the reference program trace tree.

[0127] The beneficial effects of the above technology are as follows: Based on the relationship quantity between the operating environment data and the program operation trace data and the environmental deviation data, accurately determine the deviation of the program operation trace data, and combine the comprehensive representation of the program trace data to determine the reference program operation trace data of the user entity in the current operating environment, and then construct a tree structure containing the program operation trace data generated when the user entity operates normally in the current operating environment.

[0128] Embodiment 6:

[0129] Based on the computer system resource access method based on user entities in Embodiment 1, S4: Based on the feature deviation between the program trace tree and the reference program trace tree, update the initial access permission range in real time to obtain the current access permission range, including:

[0130] Based on the preset program affiliation relationship, program category, and preset label generation method, generate the first affiliation label for each first subtree structure in the program trace tree and the second affiliation label for each second subtree structure in the reference program trace tree;

[0131] Based on the first affiliation label and the second affiliation label, correspond the first subtree structure and the second subtree structure to obtain the subtree structure correspondence result;

[0132] Regard the local deviation structure in the program trace tree and the reference program trace tree and the deviation trace data between the program operation trace data in the corresponding virtual storage nodes in the program trace tree and the reference program trace tree as feature deviations;

[0133] Based on the feature deviation and the subtree structure correspondence result, update the initial access permission range in real time to obtain the current access permission range.

[0134] In this embodiment, the preset label generation method is a method for presetting the generation of the first membership label for each first subtree structure in the program trace tree or the second membership label for each second subtree structure in the reference program trace tree. For example: For example, the root node in the program trace tree (or reference program trace tree) is regarded as the first level, the node representing the program category to which the application program belongs is regarded as the second category, the node representing the general name to which the program belongs (for example, Microsoft Access and Microsoft Excel both belong to the Microsoft Office tool, then the Microsoft Office tool is the general name to which Microsoft Access and Microsoft Excel belong) is regarded as the third level, the node where the application program is located is regarded as the fourth level, and based on the preset sorting method, the sequential numbers from left to right among the nodes at the same level in the program trace tree (or reference program trace tree) are determined. The label composed of the level and sequential number of the node with the highest level in each first subtree structure (or second subtree structure) is used as the first membership label (or second membership label) corresponding to the first subtree structure (or second subtree structure).

[0135] In this embodiment, the first subtree structure is the subtree structure in the program trace tree, and the subtree structure is a partial tree structure in the program trace tree.

[0136] In this embodiment, the first membership label is a label that represents the membership relationship between the nodes in the first subtree structure and the program category to which the program belongs, generated based on the preset program membership relationship, the program category to which the program belongs, and the preset label generation method.

[0137] In this embodiment, the second subtree structure is the subtree structure in the reference program trace tree, and the subtree structure is a partial tree structure in the reference program trace.

[0138] In this embodiment, the second membership label is a label that represents the membership relationship between the nodes in the second subtree structure and the program category to which the program belongs, generated based on the preset program membership relationship, the program category to which the program belongs, and the preset label generation method.

[0139] In this embodiment, the corresponding result of the subtree structure is the result obtained by corresponding the first subtree structure and the second subtree structure based on the first membership label and the second membership label.

[0140] In this embodiment, the local deviation structure is a partial tree structure in the program trace tree and the reference program trace tree with different structures.

[0141] In this embodiment, the deviation tracking data is the deviation data between the program operation tracking data in the corresponding virtual storage nodes in the program trace tree and the reference program trace tree.

[0142] The beneficial effects of the above technology are: generating affiliation labels of subtree structures in program tracking trees and reference program tracking trees based on preset program affiliations, program categories and preset label generation methods, and achieving correspondence of subtree structures based on affiliation labels, and then combining the local deviation structures in the program tracking tree and the reference program tracking tree as feature deviations and the deviation tracking data between the program operation tracking data in the corresponding virtual storage nodes in the program tracking tree and the reference program tracking tree to achieve real-time update of the initial access permission scope.

[0143] Embodiment 7:

[0144] On the basis of Example 6, the method for accessing computer system resources based on a user entity, updating the initial access permission scope in real time based on the feature deviation and the subtree structure corresponding result to obtain the current access permission scope, includes:

[0145] Determine a first overlapping structure in a first subtree structure that overlaps with a local deviation structure in a feature deviation;

[0146] Based on the deviation tracking data between each first virtual storage node in the first overlapping structure and the corresponding second virtual storage node in the reference program tracking tree and the corresponding result of the subtree structure, the membership deviation degree of each first virtual storage node in each first subtree structure to which it belongs is calculated;

[0147] The initial access permission range is updated in real time based on the membership deviation degree of each first virtual storage node in all the first subtree structures to which it belongs, to obtain the current access permission range.

[0148] In this embodiment, the first overlapping structure is a partial tree structure in the first subtree structure that overlaps with the local deviation structure in the feature deviation, that is, a structure in the first subtree structure that deviates from the reference program tracking tree structure.

[0149] In this embodiment, the second overlapping structure is a partial tree structure in the second subtree structure that overlaps with the local deviation structure in the feature deviation.

[0150] In this embodiment, the first virtual storage node is a virtual storage node in the first overlapping structure.

[0151] In this embodiment, the second virtual storage node is a virtual storage node in the reference program tracking tree.

[0152] In this embodiment, based on the deviation tracking data between each first virtual storage node in the first overlapping structure and the corresponding second virtual storage node in the reference program tracking tree and the corresponding result of the subtree structure, the membership deviation degree of each first virtual storage node in each first subtree structure to which it belongs is calculated, including:

[0153] Determine the second subtree structure corresponding to the currently calculated first subtree structure to which the first overlapping structure belongs based on the subtree corresponding result. Calculate the membership deviation degree of the first virtual storage node in the currently calculated first subtree structure to which it belongs based on the deviation tracking data between the currently calculated first subtree structure to which the first overlapping structure belongs, the corresponding second subtree structure, the currently calculated first virtual storage node, and the corresponding second virtual storage node in the reference program trace tree:

[0154]

[0155] In the formula, α Δ is the membership deviation degree of the currently calculated first virtual storage node in the currently calculated first subtree structure to which it belongs. i is the i-th layer in the currently calculated first subtree structure to which the currently calculated first virtual storage node belongs (or the second subtree structure corresponding to the currently calculated first subtree structure to which the first overlapping structure belongs), n is the total number of layers in the currently calculated first subtree structure to which the currently calculated first virtual storage node belongs, q ai is the total number of virtual storage nodes in the i-th layer of the currently calculated first subtree structure to which the currently calculated first virtual storage node belongs, q bi is the total number of virtual storage nodes in the i-th layer of the second subtree structure corresponding to the currently calculated first subtree structure to which the first overlapping structure belongs. ΔS is the numerical value of the deviation tracking data between the currently calculated first virtual storage node and the corresponding second virtual storage node in the reference program trace tree, and S0 is the numerical value of the program operation trace data of the corresponding second virtual storage node of the currently calculated first virtual storage node in the reference program trace tree;

[0156] Based on the above formula, the deviation degree of the program operation trace data between the first virtual storage node determined based on the membership degree of the first virtual storage node in the currently calculated first subtree structure to which it belongs and the corresponding second virtual storage node in the reference program trace tree can be accurately calculated.

[0157] The beneficial effects of the above technology are as follows: Determine the first overlapping structure in the first subtree structure that overlaps with the local deviation structure in the feature deviation, and calculate the membership deviation degree of each first virtual storage node in each first subtree structure to which it belongs based on the deviation tracking data between each first virtual storage node in the first overlapping structure and the corresponding second virtual storage node in the reference program trace tree and the subtree structure corresponding result. The initial access permission range is updated in real time based on the membership deviation degree of the first virtual storage node in all first subtree structures to which it belongs. Furthermore, the initial access permission range is correspondingly updated based on the feature deviation between the program trace tree and the reference program trace tree, realizing the precise dynamic update of the initial access permission range of the user entity to the system resources.

[0158] Example 8:

[0159] Based on Example 7, for the computer system resource access method based on user entities, the initial access permission range is updated in real time based on the membership deviation degree of each first virtual storage node in all the first sub-tree structures it belongs to, and the current access permission range is obtained, including:

[0160] Taking the average value of the membership deviation degrees of each first virtual storage node in all the first sub-tree structures it belongs to as the comprehensive deviation degree of the tracking data corresponding to the first virtual storage node;

[0161] Based on the comprehensive deviation degree of the tracking data of each first virtual storage node, the current access permission range is determined within the initial access permission range of the sub-memory block corresponding to the first virtual storage node.

[0162] In this embodiment, the comprehensive deviation degree of the tracking data is the average value of the membership deviation degrees of the first virtual storage node in all the first sub-tree structures it belongs to, and it is also the comprehensive deviation degree of the program operation tracking data between the first virtual storage node and the corresponding virtual storage node in the reference program tracking tree determined based on the membership degree determined by the membership relationship of the first virtual storage node under all the first sub-tree structures (corresponding to the program category and the general name of the program membership). The update range of the initial access permission range can be accurately determined based on the tracking data deviation degree.

[0163] The beneficial effects of the above technology are as follows: realizing the comprehensive deviation degree of the tracking data of the deviation tracking data between the first virtual storage node and the corresponding virtual storage node in the reference program tracking tree determined based on the membership degree determined by the membership relationship of the first virtual storage node under all the first sub-tree structures (corresponding to the program category and the general name of the program membership), and performing real-time and accurate update of the initial access permission range.

[0164] Example 9:

[0165] Based on Example 8, for the computer system resource access method based on user entities, based on the comprehensive deviation degree of the tracking data of each first virtual storage node, the current access permission range is determined within the initial access permission range of the sub-memory block corresponding to the first virtual storage node, including:

[0166] Dividing the system resources in the sub-initial access permission range of the sub-memory block corresponding to the first virtual storage node (i.e., the operation of dividing the system resources in the sub-initial access permission range of the sub-memory block into multiple unit system resources), obtaining multiple unit system resources, determining the importance of each unit system resource, and sorting all the unit system resources based on the importance to obtain the unit system resource list of the sub-memory block;

[0167] Based on the comprehensive deviation degree of the tracking data, determine the current accessible unit system resource set in the unit system resource list corresponding to the sub-memory block corresponding to the first virtual storage node, and use the current accessible unit system resource set as the current access permission range.

[0168] In this embodiment, the unit system resource is the unit amount of system resources obtained by dividing the system resources in the sub-initial access permission range of the sub-memory block corresponding to the first virtual storage node, and the specific unit amount is determined according to the system resource management precision requirement.

[0169] In this embodiment, the importance degree represents the importance level of the corresponding unit system resource.

[0170] In this embodiment, the unit system resource list is the list obtained by sorting all unit system resources based on the importance degree.

[0171] In this embodiment, based on the comprehensive deviation degree of the tracking data, determining the current accessible unit system resource set in the unit system resource list corresponding to the sub-memory block corresponding to the first virtual storage node is as follows:

[0172] Take the difference between the maximum comprehensive deviation degree of the tracking data (for example, 1) and the comprehensive deviation degree of the tracking data as the accessible proportion (for example, eighty percent), and take the system resources ranked in the top accessible proportion in the unit system resource list corresponding to the sub-memory block corresponding to the first virtual storage node as the current accessible unit system resource set (for example, the unit system resources ranked in the top eighty percent in the unit system resource list).

[0173] In this embodiment, the current accessible unit system resource set is the set composed of all unit system resources that the user entity can currently access determined in the unit system resource list corresponding to the sub-memory block corresponding to the first virtual storage node based on the comprehensive deviation degree of the tracking data.

[0174] The beneficial effects of the above technology are as follows: By dividing and sorting the system resources in the sub-initial access permission range of the sub-memory block corresponding to the first virtual storage node, a unit system resource list is obtained, and based on the comprehensive deviation degree of the tracking data, the current accessible unit system resource set is determined in the unit system resource list, thereby realizing the determination of the current access permission range of the user entity based on the comprehensive deviation degree of the tracking data and the importance of the unit system resources.

[0175] Embodiment 10:

[0176] Based on the method for accessing computer system resources based on a user entity in Embodiment 1, S5: Generate an access feedback result based on the access request instruction of the user entity and the current access permission range, including:

[0177] Determine the target requested access resource based on the access request instruction;

[0178] Determine whether the target requested access resource is within the current access permission range. If so, grant the access permission of the target requested access resource to the user entity to obtain an access feedback result. Otherwise, send an instruction of no access permission feedback to the user entity to obtain an access feedback result.

[0179] In this embodiment, the target requested access resource is the system resource that the user entity wants to request access to included in the access request instruction.

[0180] In this embodiment, granting the access permission of the target requested access resource to the user entity means allowing the user to access the target requested access resource.

[0181] In this embodiment, the instruction of no access permission feedback is an instruction that represents that the user has no access permission to all or part of the system resources in the target requested access resource.

[0182] The beneficial effects of the above technologies are as follows: It realizes the access judgment feedback on the access request instruction of the user entity based on the current access permission range, and further realizes the access control of the user entity to the computer system resources, greatly increasing the security of the system resources.

[0183] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and modifications.

Claims

1. A method for accessing computer system resources based on user entities, characterized in that, Including: S1: Obtain the initial access permission range of the user entity in the system resource memory block; S2: Based on all program operation trace data of the user entity obtained recently within a preset period, construct a program trace tree, including: S201: Based on the preset program subordination relationship and program category, determine the hierarchical relationship among all application programs, the general name of program subordination, and the program category in the current running environment of the user entity; S202: Generate virtual storage nodes for each application program, the general name of program subordination, and the program category, and construct a program subordination relationship tree of the current running environment based on the hierarchical relationship and all virtual storage nodes; S203: Import all program operation trace data of the user entity obtained recently within a preset period into the corresponding virtual storage nodes in the program subordination relationship tree to obtain a program trace tree; S3: Based on the environmental deviation data between the current running environment of the user entity and the standard running environment, determine the reference program trace tree of the user entity in the current running environment, including: Retrieve a group of similar user entity trace records in the standard running environment from the user entity trace record library based on the original user information of the user entity; Generate comprehensive representative program trace data of the user entity in the standard running environment based on the program operation trace data in all similar user entity trace records in the group of similar user entity trace records; Determine the deviation of program operation trace data based on the relationship quantity between the running environment data and the program operation trace data and the environmental deviation data; Based on the comprehensive representative program trace data and the deviation of program operation trace data, determine the reference program operation trace data of the user entity in the current running environment, and construct a reference program trace tree of the user entity in the current running environment based on the reference program operation trace data; S4: Based on the feature deviation between the program trace tree and the reference program trace tree, update the initial access permission range in real time to obtain the current access permission range, including: Generate the first subordination label of each first subtree structure in the program trace tree and the second subordination label of each second subtree structure in the reference program trace tree based on the preset program subordination relationship, program category, and preset label generation method; Correspond the first subtree structure and the second subtree structure based on the first subordination label and the second subordination label to obtain the subtree structure correspondence result; Regard the local deviation structure in the program trace tree and the reference program trace tree and the deviation trace data between the program operation trace data in the corresponding virtual storage nodes in the program trace tree and the reference program trace tree as feature deviations; Based on the feature deviation and the subtree structure correspondence result, update the initial access permission range in real time to obtain the current access permission range; S5: Generate an access feedback result based on the access request instruction of the user entity and the current access permission range.

2. The computer system resource access method based on a user entity according to claim 1, characterized in that, S1: Obtain the initial access permission range of the user entity in the system resource memory block, including: S101: Based on the original user information of the user entity and the access permission rules of each sub-memory block in the system resource memory block, determine the sub-initial access permission range of each sub-memory block; S102: Aggregate the initial access permission ranges of all sub - memory blocks to obtain the initial access permission range.

3. A method for accessing computer system resources based on a user entity according to claim 1, characterized in that, Update the initial access permission range in real - time based on the feature deviation and the corresponding results of the subtree structure to obtain the current access permission range, including: Determine the first overlapping structure in the first subtree structure that overlaps with the local deviation structure in the feature deviation; Based on the deviation tracking data between each first virtual storage node in the first overlapping structure and the corresponding second virtual storage node in the reference program trace tree, and the corresponding results of the subtree structure, calculate the membership deviation degree of each first virtual storage node in each of its affiliated first subtree structures; Update the initial access permission range in real - time based on the membership deviation degree of each first virtual storage node in all of its affiliated first subtree structures to obtain the current access permission range.

4. A method for accessing computer system resources based on a user entity according to claim 3, characterized in that, Update the initial access permission range in real - time based on the membership deviation degree of each first virtual storage node in all of its affiliated first subtree structures to obtain the current access permission range, including: Take the average value of the membership deviation degrees of each first virtual storage node in all of its affiliated first subtree structures as the comprehensive deviation degree of the tracking data corresponding to the first virtual storage node; Based on the comprehensive deviation degree of the tracking data of each first virtual storage node, determine the current access permission range within the initial access permission range of the sub - memory block corresponding to the first virtual storage node.

5. A computer system resource access method based on a user entity according to claim 4, characterized in that, Based on the comprehensive deviation degree of the tracking data of each first virtual storage node, determine the current access permission range within the initial access permission range of the sub - memory block corresponding to the first virtual storage node, including: Divide the system resources in the sub - initial access permission range of the sub - memory block corresponding to the first virtual storage node to obtain multiple unit system resources, and determine the importance of each unit system resource. Sort all unit system resources based on the importance to obtain the unit system resource list of the sub - memory block; Based on the comprehensive deviation degree of the tracking data, determine the current accessible unit system resource set in the unit system resource list of the sub - memory block corresponding to the first virtual storage node, and take the current accessible unit system resource set as the current access permission range.

6. A method for accessing computer system resources based on a user entity according to claim 1, characterized in that, S5: Generate an access feedback result based on the access request instruction of the user entity and the current access permission range, including: Determine the target requested access resource based on the access request instruction; Determine whether the target requested access resource is within the current access permission range. If so, grant the access permission of the target requested access resource to the user entity to obtain the access feedback result. Otherwise, send a no - access - permission feedback instruction to the user entity to obtain the access feedback result.

Citation Information

Patent Citations

  • Log tracking method, apparatus, electronic device and storage medium

    CN109086157A

  • Optimized authority control method for Web application

    CN110889126A