A control method and system for sandbox external devices
By deploying peripheral monitoring processes on the host, using Inotify and udev device monitoring configurations, dynamically obtaining external device information and controlling their access and uninstallation, the problem of being unable to dynamically control external devices in the existing technology is solved, and flexible and secure dynamic management of sandbox external devices is achieved.
Patent Information
- Application Number
- CN202410009541.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-03
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-01-03
AI Technical Summary
The existing technology cannot realize the dynamic control of external devices by terminal sandbox products, especially the dynamic access and pop-up of USB drives, optical drives, handwriting boards and other devices, which cannot meet the actual needs of users.
By deploying peripheral monitoring processes on the host, using Inotify and udev device monitoring configurations, dynamically obtain external device information, and controlling the access and uninstallation of devices according to sandbox policies, and using transmission services to transmit device information and policy change notifications, realizing dynamic control.
It realizes dynamic access and pop-up of external devices, meets users' dynamic control needs for external sandbox devices, and improves the flexibility and security of sandboxes.
Smart Images

Figure CN117972678B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computers, and particularly relates to a method and system for controlling external devices outside a sandbox. Background Art
[0002] Currently, most terminal sandbox products either do not support the control of external devices such as USB drives, optical drives, and graphics tablets, or cannot dynamically control the access and ejection of external devices. However, in real user scenarios, the dynamic control of terminal external devices is a practical production requirement for users. For example, some office software is released as a sandbox application and can only be used within the sandbox, so it is required that the external devices it uses must support access to the sandbox. Another example is that the files in the sandbox cannot be stored on the host computer and can only be directly transferred between the sandbox and the specified external device.
[0003] Currently, the existing technology modifies the terminal sandbox product based on docker. In this way, by mapping external devices before docker starts, the external devices can be used inside docker. If docker is started first and then external devices are mapped, the external devices cannot be used in docker. Therefore, this method cannot dynamically control the access of external devices to the sandbox. Summary of the Invention
[0004] Aiming at the deficiencies in the prior art, the present invention provides a method and system for controlling external devices outside a sandbox, which can dynamically control the access and ejection of external devices.
[0005] In a first aspect, a method for controlling external devices outside a sandbox includes:
[0006] When the host computer monitors the access of an external device, obtain the device information of the external device;
[0007] When the external device policy of the sandbox is not to allow external devices to access, the process ends;
[0008] When the external device policy of the sandbox is to allow external devices to access, the host computer transmits the device information to the sandbox; the sandbox creates a block device according to the device information and mounts the block device so that the applications in the sandbox can call the external device;
[0009] When the external device policy of the sandbox changes to not allow external devices to access, the host computer generates a policy change notice and sends the policy change notice to the sandbox. After receiving the policy change notice, the sandbox deletes the corresponding block device.
[0010] Further, the device information includes device type, access path, device major and minor numbers, device driver name, and / or device identification number ID.
[0011] Further, the method for the host computer to monitor external devices includes:
[0012] The peripheral monitoring process obtains the monitoring policy; the peripheral monitoring process is deployed on the host machine;
[0013] The peripheral monitoring process generates the udev device monitoring configuration;
[0014] The peripheral monitoring process uses Inotify to monitor the mount directory according to the monitoring policy. When a new external device is detected on the mount directory, a notification event is generated and sent to the peripheral monitoring process;
[0015] The peripheral monitoring process determines whether the new external device is allowed to access according to the udev device monitoring configuration. If so, it obtains the device information of the external device; if not, the process ends.
[0016] Further, the monitoring policy includes monitoring the device mount directory, device type, device manufacturer, device driver version, and device driver name on the mount directory;
[0017] The udev device monitoring configuration includes the device information of the peripheral devices allowed or not allowed to access.
[0018] Further, the method for the peripheral monitoring process to determine whether the new external device is allowed to access includes:
[0019] After receiving the notification event, the peripheral monitoring process parses the notification event to obtain the device information of the new external device; it determines whether the device information of the new external device belongs to the device information of the peripheral devices allowed to access in the udev device monitoring configuration.
[0020] In a second aspect, a control system for sandbox external devices includes:
[0021] The peripheral monitoring process: deployed on the host machine; the peripheral monitoring process is used to obtain the device information of the external device when it monitors that an external device accesses the host machine; when the external device policy of the sandbox is not to allow external devices to access, the process ends; when the external device policy of the sandbox is to allow external devices to access, it transmits the device information to the sandbox through the first transmission service; when the external device policy of the sandbox changes to not allow external devices to access, it generates a policy change notification and sends the policy change notification to the sandbox through the first transmission service,
[0022] The first transmission service: deployed on the host machine; the first transmission service is used to transmit the device information or the policy change notification to the sandbox;
[0023] Second Transmission Service: Deployed on a sandbox; the Second Transmission Service is used to receive device information from the First Transmission Service, create a block device according to the device information, and mount the block device so that applications within the sandbox can call external devices; the Second Transmission Service is used to delete the corresponding block device after receiving a policy change notification from the First Transmission Service.
[0024] Furthermore, the device information includes device type, access path, device major and minor numbers, device driver name, and / or device identification number ID.
[0025] Furthermore, the peripheral listening process is specifically used for:
[0026] Obtain a listening policy;
[0027] Generate a udev device listening configuration;
[0028] Use Inotify to listen to the mount directory according to the listening policy; when Inotify detects a new external device on the mount directory, it returns a notification event;
[0029] Judge whether the new external device is allowed to be accessed according to the udev device listening configuration. If so, obtain the device information of the external device; if not, end the process.
[0030] Furthermore, the listening policy includes the directory where the device is mounted on the mount directory, device type, device manufacturer, device driver version, and device driver name;
[0031] The udev device listening configuration includes the device information of the peripheral devices that are allowed or not allowed to be accessed.
[0032] Furthermore, the peripheral listening process is specifically used for:
[0033] After receiving the notification event, parse the notification event to obtain the device information of the new external device;
[0034] Judge whether the device information of the new external device belongs to the device information of the peripheral devices allowed to be accessed in the udev device listening configuration.
[0035] As can be seen from the above technical solutions, the method and system for controlling external devices in a sandbox provided by the present invention can dynamically control the access and ejection of external devices, meeting the user's requirements for dynamic control of external devices in the sandbox. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.
[0037] Figure 1 Flowchart of the control method for sandbox external devices provided for the embodiment.
[0038] Figure 2 Flowchart of the host monitoring method provided for the embodiment. Specific Embodiments
[0039] The following will describe in detail the embodiments of the technical solutions of the present invention with reference to the drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention, so they are only examples and cannot be used to limit the protection scope of the present invention. It should be noted that unless otherwise stated, the technical terms or scientific terms used in this application should have the ordinary meaning understood by those skilled in the art to which the present invention belongs.
[0040] It should be understood that when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or their combinations.
[0041] It should also be understood that the terms used in this specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in this specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms.
[0042] As used in this specification and the appended claims, the term "if" can be interpreted as "when", "once", "in response to determining" or "in response to detecting" according to the context. Similarly, the phrase "if determined" or "if [the described condition or event] is detected" can be interpreted as meaning "once determined", "in response to determining", "once [the described condition or event] is detected" or "in response to detecting [the described condition or event]" according to the context.
[0043] Embodiment:
[0044] A control method for sandbox external devices, see Figure 1 , including:
[0045] When the host machine detects the access of an external device, it obtains the device information of the external device;
[0046] When the external device policy of the sandbox is not to allow external devices to access, the process ends;
[0047] When the external device policy of the sandbox is to allow external devices to access, the host machine transmits the device information to the sandbox; the sandbox creates a block device according to the device information and mounts the block device so that the applications in the sandbox can call the external device;
[0048] When the external device policy of the sandbox changes to not allow external devices to access, the host machine generates a policy change notice and sends the policy change notice to the sandbox. After receiving the policy change notice, the sandbox deletes the corresponding block device.
[0049] In this embodiment, the method first has the host machine continuously monitor whether there is an external device accessing. If there is an external device accessing, the host machine obtains the device information of the external device. The device information includes device type, access path, device major and minor numbers, device driver name, device identification number ID, etc. The host machine can also obtain the external device policies of each sandbox. If the external device policy of the sandbox is not to allow external devices to access, the sandbox does not support external device access. If the external device policy of the sandbox is to allow external devices to access, the sandbox supports external device access. When the host machine detects the access of an external device and the external device policy is not to allow external devices to access, the process ends and the host machine does not allow the external device to access the sandbox. When the host machine detects the access of an external device and the external device policy is to allow external devices to access, the host machine transmits the device information to the sandbox. After receiving the device information from the host machine, the sandbox creates a block device according to the device information, for example, creates a block device according to the device major and minor numbers of the device information, and mounts it under the / dev / device path of the sandbox. At this time, other applications in the sandbox can use or call the external device. If the external device policy of the sandbox changes from allowing external devices to access to not allowing external devices to access and the external device needs to be unmounted in the sandbox, the host machine generates a policy change notice and sends it to the sandbox. After receiving the policy change notice, the sandbox deletes the corresponding block device, thus completing the unmounting of the external device in the sandbox.
[0050] The control method for the sandbox external device can dynamically control the access and ejection of external devices, meeting the user's need for dynamic control of sandbox external devices.
[0051] Further, in some embodiments, referring to Figure 2 , the method for the host machine to monitor external devices includes:
[0052] The peripheral monitoring process obtains the monitoring policy; the peripheral monitoring process is deployed on the host machine;
[0053] The peripheral monitoring process generates the udev device monitoring configuration;
[0054] The peripheral monitoring process uses Inotify to monitor the mounted directory according to the monitoring policy. When a new external device is detected on the mounted directory, a notification event is generated and sent to the peripheral monitoring process;
[0055] The peripheral monitoring process determines whether the new external device is allowed to access according to the udev device monitoring configuration. If so, it obtains the device information of the external device; if not, the process ends.
[0056] In this embodiment, Inotify is a set of efficient and real-time Linux file system event monitoring frameworks that can monitor changes in specified directories and files. The host can monitor whether an external device is connected to the host through inotify and udev. A peripheral monitoring process can run on the host. The peripheral monitoring process can obtain the monitoring policy from the server. The monitoring policy can include some fields in the monitored mounted directory, such as the directory where the device is mounted (such as / dev, etc.), the device type (tablet, printer, etc.), the device manufacturer (xxx manufacturer), the device driver version (version number 2.2.x), the device driver name, and so on. The peripheral monitoring process also generates the udev device monitoring configuration, which is used to configure the external devices allowed or prohibited from accessing. For example, the udev device monitoring configuration includes the system type of the external devices allowed or prohibited from accessing, the device driver name, the device identification number ID, the device mounting path, and so on. The host starts Inotify for monitoring. When an external device is connected to the host, Inotify generates a notification event and feeds it back to the peripheral monitoring process through the operating system. The peripheral monitoring process determines whether the new external device is allowed to access according to the udev device monitoring configuration. If so, it obtains the device information of the external device; if not, the process ends.
[0057] Further, in some embodiments, the method by which the peripheral monitoring process determines whether the new external device is allowed to access includes:
[0058] After receiving the notification event, the peripheral monitoring process parses the notification event to obtain the device information of the new external device; and determines whether the device information of the new external device belongs to the device information of the peripheral devices allowed to access in the udev device monitoring configuration. The udev device monitoring configuration includes the device information of the peripheral devices allowed or not allowed to access.
[0059] In this embodiment, udev is a Linux subsystem that provides device events for a computer. udev can detect whether a device is plugged in or unplugged from the current machine. The udev device listening configuration can be configured to allow or disallow specified external devices from accessing. Therefore, the method for controlling external devices in the sandbox can dynamically control the access of specified types of external devices through configuration. When the peripheral device listening process receives a notification event, it indicates that an external device has been plugged in. At this time, the peripheral device listening process parses the device information of the new external device, such as the device type, device driver version, etc. of the new external device. If the new external device belongs to the peripheral devices allowed to access in the udev device listening configuration or does not belong to the peripheral devices not allowed to access, the new external device is allowed to access the sandbox. If the new external device does not belong to the peripheral devices allowed to access in the udev device listening configuration or belongs to the peripheral devices not allowed to access, the new external device is not allowed to access the sandbox.
[0060] A control system for external devices in a sandbox, comprising:
[0061] A peripheral device listening process: deployed on the host; the peripheral device listening process is used to obtain the device information of an external device when it detects that an external device is plugged into the host; when the external device policy of the sandbox is not to allow external devices to access, the process ends; when the external device policy of the sandbox is to allow external devices to access, the device information is transmitted to the sandbox through the first transmission service; when the external device policy of the sandbox changes to not allow external devices to access, a policy change notification is generated and sent to the sandbox through the first transmission service.
[0062] The first transmission service: deployed on the host; the first transmission service is used to transmit the device information or the policy change notification to the sandbox.
[0063] The second transmission service: deployed on the sandbox; the second transmission service is used to receive the device information from the first transmission service, create a block device according to the device information, and mount the block device so that the applications in the sandbox can call the external device; the second transmission service is used to delete the corresponding block device after receiving the policy change notification from the first transmission service.
[0064] Further, in some embodiments, the device information includes device type, access path, device major and minor numbers, device driver name, and / or device identification number ID.
[0065] Further, in some embodiments, the peripheral device listening process is specifically used for:
[0066] Obtain the listening policy;
[0067] Generate the udev device listening configuration;
[0068] Use Inotify to monitor the mounted directory according to the monitoring policy; when Inotify detects a new external device on the mounted directory, it returns a notification event;
[0069] Judge whether the new external device is allowed to access according to the udev device monitoring configuration. If so, obtain the device information of the external device; if not, the process ends.
[0070] Further, in some embodiments, the monitoring policy includes monitoring the directory where the device is mounted, the device type, the device manufacturer, the device driver version, and the device driver name on the mounted directory;
[0071] The udev device monitoring configuration includes the device information of the peripheral devices that are allowed or not allowed to access.
[0072] Further, in some embodiments, the peripheral device monitoring process is specifically used for:
[0073] After receiving the notification event, parse the notification event to obtain the device information of the new external device;
[0074] Judge whether the device information of the new external device belongs to the device information of the peripheral devices allowed to access in the udev device monitoring configuration.
[0075] For the system provided by the embodiments of the present invention, for the sake of brief description, for the parts not mentioned in the embodiment part, reference may be made to the corresponding content in the foregoing embodiments.
[0076] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered by the scope of the claims and the description of the present invention.
Claims
1. A control method for sandbox external devices, characterized in that, including: When the host machine monitors the access of an external device, obtain the device information of the external device; When the external device policy of the sandbox does not allow external devices to access, the process ends; When the external device policy of the sandbox allows external devices to access, the host machine transmits the device information to the sandbox; the sandbox creates a block device according to the device information and mounts the block device so that the applications in the sandbox can call the external device; When the external device policy of the sandbox changes to not allow external devices to access, the host machine generates a policy change notice and sends the policy change notice to the sandbox. After receiving the policy change notice, the sandbox deletes the corresponding block device; The device information includes device type, access path, device major and minor numbers, device driver name, and / or device identification number ID; The method for the host machine to monitor external devices includes: The peripheral monitoring process obtains the monitoring policy; the peripheral monitoring process is deployed on the host machine; The peripheral monitoring process generates a udev device monitoring configuration; The peripheral monitoring process uses Inotify to monitor the mounting directory according to the monitoring policy. When a new external device is detected on the mounting directory, a notification event is generated and sent to the peripheral monitoring process; The peripheral monitoring process determines whether the new external device is allowed to access according to the udev device monitoring configuration. If so, obtain the device information of the external device; if not, the process ends.
2. The method for controlling external devices of the sandbox according to claim 1, wherein The monitoring policy includes the directory for monitoring device mounting on the mounting directory, device type, device manufacturer, device driver version, and device driver name; The udev device monitoring configuration includes the device information of the peripheral devices allowed or not allowed to access.
3. The control method for sandbox external devices according to claim 2, wherein The method for the peripheral monitoring process to determine whether the new external device is allowed to access includes: When receiving the notification event, the peripheral monitoring process parses the notification event to obtain the device information of the new external device; determines whether the device information of the new external device belongs to the device information of the peripheral devices allowed to access in the udev device monitoring configuration.
4. A control system for sandbox external devices, characterized in that, including: Peripheral monitoring process: deployed on the host machine; The peripheral monitoring process is used to obtain the device information of the external device when it monitors the access of an external device to the host machine; When the external device policy of the sandbox does not allow external devices to access, the process ends; When the external device policy of the sandbox allows external devices to access, transmit the device information to the sandbox through the first transmission service; when the external device policy of the sandbox changes to not allow external devices to access, generate a policy change notice and send the policy change notice to the sandbox through the first transmission service, First transmission service: deployed on the host machine; the first transmission service is used to transmit the device information or policy change notice to the sandbox; Second transmission service: deployed on the sandbox; The second transmission service is used to receive device information from the first transmission service, create a block device according to the device information, and mount the block device so that the applications in the sandbox can call the external device; the second transmission service is used to delete the corresponding block device after receiving a policy change notification from the first transmission service; The device information includes device type, access path, device major and minor numbers, device driver name, and / or device identification number ID; The peripheral listening process is specifically used for: Obtain the listening policy; Generate udev device listening configuration; Use Inotify to listen to the mount directory according to the listening policy; when Inotify detects a new external device on the mount directory, it returns a notification event; Judge whether the new external device is allowed to access according to the udev device listening configuration. If so, obtain the device information of the external device; if not, the process ends.
5. The control system for sandbox external devices according to claim 4, wherein The listening policy includes the directory for listening to device mounting on the mount directory, device type, device manufacturer, device driver version, and device driver name; The udev device listening configuration includes the device information of the peripheral devices allowed or not allowed to access.
6. The control system for the sandbox external device according to claim 5, characterized in that, The peripheral listening process is specifically used for: After receiving the notification event, parse the notification event to obtain the device information of the new external device; Judge whether the device information of the new external device belongs to the device information of the peripheral devices allowed to access in the udev device listening configuration.
Citation Information
Patent Citations
Application program starting method and device and computer readable storage medium
CN107832105A