Access control authorization method and device, equipment and storage medium
By using the preset target access policy table in the access control mechanism, the problem of slow authorization decision-making process in the existing technology under complex policies is solved, and fast and efficient authorization decision-making and security guarantee are achieved.
Patent Information
- Application Number
- CN202411959916.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-13
AI Technical Summary
While ensuring security, existing access control mechanisms are difficult to make authorization decisions quickly and efficiently under complex policies, resulting in system performance being affected.
By obtaining the target application's access request to the target resource object, the preset target access policy table is used to determine the location of the target element based on the identification information of the application and resource object, thereby quickly determining the operation permissions of the target operation.
On the premise of ensuring data security, shorten the time required for the authorization decision-making process, improve access experience, and improve system resource access throughput, and reduce the additional consumption introduced by security checks.
Smart Images

Figure CN119989378A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to an access control authorization method, apparatus, device and storage medium. Background Art
[0002] Access control mechanisms are a core component in the field of computer security, ensuring that only authorized users or applications can access specific resources.
[0003] Access control mechanisms need to ensure security while maximizing data access speed. However, complex access control policies may increase system overhead and affect the overall performance of the system. How to find a balance between security and speed and efficiency is a major challenge facing access control mechanisms. Summary of the invention
[0004] The present invention provides an access control authorization method, apparatus, device and storage medium to shorten the time required for the authorization decision process while ensuring security.
[0005] The technical solution of the present disclosure is achieved as follows:
[0006] The present application provides an access control authorization method, which includes: obtaining an access request initiated by a target application to a target resource object; the access request is used to indicate a target operation requested by the target application to the target resource object, and the access request carries first identification information of the target application and second identification information of the target resource object; according to the first identification information and the second identification information, determining the position of a target element in a preset target access policy table; the target element is used to indicate the type of operation that the target application is allowed to perform on the target resource object and the operation authority corresponding to each operation type; according to the target element, determining the operation authority of the target operation.
[0007] In some possible implementations, the access request also carries type information, and the type information is used to indicate the program type of the target application and the resource type of the target resource object; before locating the target element in a preset target access policy table using the first identification information and the second identification information as indexes, the above method also includes: determining, from multiple access policy tables, a target access policy table corresponding to the resource type of the target resource object.
[0008] In some possible implementations, the target access policy table is implemented in the form of an m×n two-dimensional array; wherein, m≥1, m is an integer, and n≥1, n is an integer; based on the first identification information and the second identification information, the position of the target element is determined in the preset target access policy table, including: based on the first identification information, determining that the i-th row element in the target policy table is used to indicate the target application's operating authority over all resource objects; 0≤i≤m-1, i is an integer; based on the second identification information, determining that the j-th column element in the target policy table is used to indicate the operating authority of all applications over the target resource object; 0≤j≤n-1, j is an integer; determining the element in the i-th row and j-th column as the target element.
[0009] In some possible implementations, the access request also carries type information, where the type information is used to indicate the program type of the target application and the resource type of the target resource object; based on the target element, the operation permission of the target operation is determined, including: based on the type information, obtaining the corresponding target permission index table; the target permission index table is used to indicate the index of operations that an application with a program type is allowed to perform on a resource object with a resource type; based on the target permission index table and the target element, the operation permission of the target operation is determined.
[0010] In some possible implementations, the target element is implemented in the form of a bitmap; each bit in the target element corresponds to an operation and its operation authority; the bits in the target element correspond one-to-one to the indexes in the target authority index table; the operation authority of the target operation is determined according to the target authority index table and the target element, including: according to the target authority index table and the target element, determining the target bit corresponding to the target operation among all bits of the target element; when the value of the target bit is a first value, determining that the operation authority of the operation corresponding to the target operation in the target authority index table is allowed; when the value of the target bit is a second value, determining that the operation authority of the operation corresponding to the target operation in the target authority index table is denied.
[0011] In some possible implementations, the operation permission of the target operation is determined based on the target element, including: when the operation permission of the target operation is allowed, sending authorization information to the target application; the authorization information is used to instruct the target application to perform the target operation on the target resource object; when the operation permission of the target operation is denied, sending rejection information to the target application; the rejection information is used to reject the access request initiated by the target application to the target resource object.
[0012] The present disclosure provides an access control authorization device, which includes: a request acquisition module, which is used to acquire an access request initiated by a target application to a target resource object; the access request is used to indicate the target operation requested by the target application to the target resource object, and the access request carries first identification information of the target application and second identification information of the target resource object; a data processing module, which is used to determine the position of a target element in a preset target access policy table according to the first identification information and the second identification information; the target element is used to indicate the type of operation that the target application is allowed to perform on the target resource object and the operation authority corresponding to each operation type; and a permission determination module, which is used to determine the operation authority of the target operation according to the target element.
[0013] In some possible implementations, the access request also carries type information, and the type information is used to indicate the program type of the target application and the resource type of the target resource object; the device also includes: a data acquisition module, which is used to determine the target access policy table corresponding to the resource type of the target resource object from multiple access policy tables.
[0014] In some possible implementations, the target policy table is implemented in the form of an m×n two-dimensional array; wherein, m≥1, m is an integer, and n≥1, n is an integer; a data processing module is used to determine, based on the first identification information, that the i-th row element in the target policy table is used to indicate the target application's operating authority over all resource objects; 0≤i≤m-1, i is an integer; based on the second identification information, determine that the j-th column element in the target policy table is used to indicate the operating authority of all applications over the target resource object; 0≤j≤n-1, j is an integer; and determine the element in the i-th row and j-th column as the target element.
[0015] In some possible implementations, the access request also carries type information, and the type information is used to indicate the program type of the target application and the resource type of the target resource object; the permission determination module is used to obtain the corresponding target permission index table based on the type information; the target permission index table is used to indicate the index of operations that an application with a program type is allowed to perform on a resource object with a resource type; and the operation permission of the target operation is determined based on the target permission index table and the target element.
[0016] In some possible implementations, the target element is implemented in the form of a bitmap; each bit in the target element corresponds to an operation permission of an operation type; the bits in the target element correspond one-to-one to the indexes in the target permission index table; a permission determination module is used to determine the target bit corresponding to the target operation among all bits of the target element according to the target permission index table and the target element; when the value of the target bit is a first value, the operation permission of the operation corresponding to the target operation in the target permission index table is determined to be allowed; when the value of the target bit is a second value, the operation permission of the operation corresponding to the target operation in the target permission index table is determined to be denied.
[0017] In some possible implementations, the permission determination module is used to: send authorization information to the target application when the operation permission of the target operation is allowed; the authorization information is used to instruct the target application to perform the target operation on the target resource object; send rejection information to the target application when the operation permission of the target operation is rejected; the rejection information is used to reject the access request initiated by the target application to the target resource object.
[0018] The present disclosure provides an electronic device, comprising: a memory for storing executable instructions; and a processor for executing the executable instructions stored in the memory to implement the method provided by the present disclosure.
[0019] The present disclosure provides a computer storage medium storing executable instructions for implementing the method provided by the present disclosure when the executable instructions are executed by a processor.
[0020] The present disclosure provides a computer program product, including a computer program or instructions, for implementing the method provided by the present disclosure when the computer program or instructions are executed by a processor.
[0021] The present disclosure has the following beneficial effects:
[0022] In the present disclosure, based on the first identification information of the target application and the second identification information of the target resource object, the position of the target element is directly determined in the preset target access policy table, and based on the target element, the operation permission of the target operation is determined. This allows the authorization decision process to be performed quickly and efficiently, while ensuring data security. The time required for the authorization decision process is shortened, thereby improving the access experience and increasing the system resource access throughput, and minimizing the additional consumption introduced by security checks.
[0023] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0025] Figure 1 A first schematic diagram of an access control architecture provided by an embodiment of the present disclosure;
[0026] Figure 2 A schematic diagram of the access control policy of selinux provided in the embodiment of the present disclosure;
[0027] Figure 3 A schematic diagram of the access control strategy of Smack and Tomoyo provided in an embodiment of the present disclosure;
[0028] Figure 4 A second schematic diagram of an access control architecture provided by an embodiment of the present disclosure;
[0029] Figure 5 A schematic diagram of a first embodiment of the access control authorization method provided by the present disclosure;
[0030] Figure 6 A schematic diagram of a target access policy table provided in an embodiment of the present disclosure;
[0031] Figure 7 A schematic diagram of a bitmap in a target access strategy table provided in an embodiment of the present disclosure;
[0032] Figure 8 A schematic diagram of a second embodiment of the access control authorization method provided by the present disclosure;
[0033] Fig. 9 A schematic diagram of the structure of an access control authorization device in an embodiment of the present disclosure;
[0034] Fig.10 A hardware entity schematic diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0035] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of devices consistent with some aspects of the present disclosure as detailed in the appended claims.
[0036] In order to illustrate the technical solution disclosed in the present invention, a specific embodiment is provided below for illustration.
[0037] A lot of private or confidential data is stored in computer systems such as car computers, mobile phones, tablet computers, and personal computers (PCs), such as personal identity information, photos, videos, account passwords, geographic locations, emails, payment bills, etc. To protect data security, private and confidential data should not be accessed arbitrarily by applications in the system, but only by a few necessary applications in the system in the necessary way. Usually, the system will use access control mechanisms to implement permission control for different applications to access different data, thereby achieving the goal of ensuring data security.
[0038] In some embodiments, Figure 1 The first schematic diagram of the access control architecture provided by the embodiment of the present disclosure. Figure 1 As shown, the subject 11 and the object 13 are isolated from each other (see Figure 1 The reference monitor 12 located between the subject 11 and the object 13 is responsible for applying the access request from the subject 11 to the object 13, and all access requests must pass through the reference monitor 12. The specific process of access control is: the reference monitor 12 first authenticates the identity of the subject 11, and then determines whether the subject 11 has the right to access the object 13 according to the preset access policy, and chooses to authorize or deny. However, access control will introduce additional performance loss, and the amount of performance loss depends largely on the data structure used for the maintenance and management of the access control rules (i.e., access control policies) and the authorization decision process that matches it.
[0039] In some embodiments, common mandatory access control mechanisms include selinux, smack, tomoyo, etc. These access control mechanisms all follow the above access control architecture. The main differences lie in the structural design of the access control policy and the authorization decision process that matches the policy structure. Figure 2 A schematic diagram of the access control policy of selinux provided by the embodiment of the present disclosure. Figure 2As shown, the access control strategy of selinux mainly adopts a chained hash table data structure, which includes an array 23 and a chained list 22. The chained list 22 may include multiple nodes 21. According to the codes such as avtab_search_node() and avc_search_node(), when making authorization decisions, the key value of the hash table must first be calculated through the subject label (sid), the object label (tid) and the object type (tclass), and the calculated key may conflict. In the case of a conflict, it is necessary to traverse the chained list to find the correct node, and then the operation authority of the subject to the object can be obtained through the node, and subsequent checks can be performed. When the conflict is not considered, the efficiency is high, and the time complexity is O(1); but when a hash conflict occurs, the efficiency is low, and the time required is proportional to the length of the chained list, and the time complexity is O(len(list)). Figure 3 A schematic diagram of the access control policy of Smack and Tomoyo provided in the embodiment of the present disclosure. Figure 3 As shown in the figure, the access control strategy of Smack mainly adopts the linked list data structure. According to the smk_access_entry() function, each subject needs to maintain its own access rule list (rule list). When making authorization decisions, it is necessary to traverse the rule list and compare whether the subject label and object label of each rule are equal at the same time; the time complexity is O(length(rulelist)). Figure 3 As shown in the figure, tomoyo's access control strategy also mainly uses linked list data structure. According to the tomoyo_check_acl() function, it is necessary to traverse domain->acl_info_list when making authorization decisions, and the time complexity is O(length(domain->acl_info_list)).
[0040] In some embodiments, the access control policy is used to express the authority relationship between the subject and the object. The organization form of the access control policy and the data structure it adopts largely determine the authorization decision process of the access control. A complex and inefficient access decision process will seriously increase the overall access time and increase the system load. In particular, in scenarios with high real-time requirements, there will be a very poor access experience, and even cause the system to be unavailable. As mentioned above, common mandatory access control schemes such as SELinux, Smack, and Tomoyo all have problems such as access time or at least in some cases.
[0041] To solve the above problems, the embodiments of the present disclosure provide an access control authorization method, apparatus, device and storage medium to shorten the time required for the authorization decision process while ensuring security.
[0042] In some embodiments, Figure 4 A second schematic diagram of the access control architecture provided by the embodiment of the present disclosure. Figure 4 As shown, the subject 11 in the operating system initiates an access request to the object 13, and the reference monitor 12 intercepts the access request. The reference monitor 12 verifies the identity of the subject 11, which can be done by username and password, biometrics, digital certificates, etc. After the identity of the subject 11 is confirmed, the access control decision module 121 in the reference monitor 12 confirms whether the subject 11 has the authority to access the requested object 13 according to the preset access control policy. According to the access control policy, if the request of the subject 11 meets the preset access rights, the request will be authorized; if the request of the subject 11 does not meet the preset access rights, the request will be rejected.
[0043] In some embodiments, the subject in the operating system is the application process running in the system, and the object being accessed is the resource object in the system. There are many types of resource objects, including: files, processes, sockets, keys, services, etc.; the operations that can be applied to each type of object are different. In order to provide fine-grained access control, the access control authorization method provided in the embodiment of the present disclosure designs different permissions for different operations of each type of object to control them.
[0044] Figure 5 A schematic diagram of a first embodiment of the access control authorization method provided by the present disclosure is shown in FIG. Figure 5 As shown, the method may include:
[0045] S501, obtaining an access request initiated by a target application to a target resource object, wherein the access request is used to indicate a target operation requested by the target application to the target resource object, and the access request carries first identification information of the target application and second identification information of the target resource object.
[0046] It can be understood that the above access control authorization method is applied to the reference monitor. The access request initiated by the target application to the target resource object will pass through the reference monitor.
[0047] In some embodiments, the access request indicates the target operation requested by the target application on the target resource object. Taking the target resource object as a file as an example, the target application can initiate target operations such as opening the file, reading the file, and writing the file on the target resource object.
[0048] In some embodiments, the operating system includes multiple applications and multiple resource objects. Each application and resource object has corresponding identification information, and the identification information is used to distinguish and identify different applications and different resource objects. The first identification information is used to identify the target application, and the second identification information is used to represent the target resource object.
[0049] S502: Determine the position of a target element in a preset target access policy table according to the first identification information and the second identification information, wherein the target element is used to indicate the type of operation that the target application is allowed to perform on the target resource object and the operation authority corresponding to each operation type.
[0050] It is understandable that the access policy library of the operating system stores a preset target access policy table. The target access policy table may include multiple elements, wherein the target element is used to represent the permission relationship between the target application and the target resource object, that is, the type of operation that the target application is allowed to perform on the target resource object and the operation permission corresponding to each operation type.
[0051] In some embodiments, the position of each element in the target access policy table is associated with identification information of the application program and the resource object. According to the first identification information and the second identification information, the position of the target element can be directly located among the multiple elements in the target access policy table.
[0052] S503: Determine the operation authority of the target operation according to the target element.
[0053] It can be understood that after determining the position of the target element in the target access policy table, the access control authorization device can further obtain the permission relationship between the target application and the target resource object indicated by the target element, and determine the operation permission of the target operation based on the permission relationship.
[0054] In an example, the target element is element A, the target application is program A, and the target resource object is file A. Element A indicates that application A can perform the following operations on file A: open file, write file, mount file, and query. The target operation requested by the access request initiated by application A to file A is "query". According to the information indicated by element A, it can be determined that application A is allowed to perform the "query" operation on file A.
[0055] In some possible implementations, the access request also carries type information, and the type information is used to indicate the program type of the target application and the resource type of the target resource object; before S502 is executed, the above method may also include: determining a target access policy table corresponding to the resource type of the target resource object from multiple access policy tables.
[0056] It is understandable that the operating system may include multiple resource objects of different types. For example, according to different resource types, resource objects may be divided into the following categories: files, processes, sockets, keys, services, etc. The access policy library of the operating system stores multiple access policy tables according to different resource types, and each access policy table corresponds to a resource type.
[0057] In some embodiments, the target access policy table corresponds to the resource type of the target resource object. According to the resource type of the target resource object, the target access policy table can be determined from multiple access policy tables.
[0058] In other embodiments, according to different program types, the application programs can be divided into the following categories: system application programs, user application programs, service programs, driver programs, etc. The access policy library of the operating system stores multiple access policy tables according to different program types and resource types, and each access policy table corresponds to a resource type and a program type. The target access policy table corresponds to the program type of the target application program and the resource type of the target resource object. According to the program type of the target application program and the resource type of the target resource object, the target access policy table can be determined from the multiple access policy tables.
[0059] In one example, according to the number of resource types (such as files, processes, services, sockets, keys, etc.) of resource objects accessible in the operating system, the same number of access policy tables will be maintained in the access policy library of the operating system, and each access policy table corresponds to a resource object. For example, if the number of resource types of resource objects is OBJECT_CATEGORY_NUM, the number of access policy tables is also OBJECT_CATEGORY_NUM.
[0060] In some possible implementations, the target access policy table is implemented in the form of an m×n two-dimensional array; wherein, m≥1, m is an integer, and n≥1, n is an integer; the above S502 may include: determining, based on the first identification information, that the i-th row element in the target policy table is used to indicate the target application's operating authority over all resource objects; 0≤i≤m-1, i is an integer; determining, based on the second identification information, that the j-th column element in the target policy table is used to indicate the operating authority of all applications over the target resource object; 0≤j≤n-1, j is an integer; determining the element in the i-th row and j-th column as the target element.
[0061] It can be understood that the target access policy table can be designed as an m×n two-dimensional array, in which there are m application programs and n resource objects.
[0062] In some embodiments, the first identification information may indicate a target application in m applications, and the second identification information may indicate a target resource object in n resource objects. According to the first identification information and the second identification information, the position of the target element in the target access policy table can be directly located in the target access policy table.
[0063] In one example, Figure 6 A schematic diagram of a target access policy table provided by an embodiment of the present disclosure. Figure 6 As shown, the two-dimensional array includes m row elements and n column elements. It can also be said that the target access policy table corresponds to m applications and n resource objects. The subscripts of the elements in the two-dimensional array correspond to the first identification information of the application and the second identification information of the resource object, respectively. For example, the first subscript [0] of a[0][2] represents the first application among m applications, and the second subscript [2] of a[0][2] represents the third resource object among n resource objects. Then, a[0][2] is used to indicate the operation permission of the first application to the third resource object; the first subscript [3] of a[3][0] represents the fourth application among m applications, and the second subscript [0] of a[3][0] represents the first resource object among n resource objects. Then, a[3][0] is used to indicate the operation permission of the fourth application to the first resource object; the first subscript [1] of a[1][5] represents the second application among m applications, and the second subscript [5] of a[1][5] represents the sixth resource object among n resource objects. Then, a[1][5] is used to indicate the operation permission of the second application to the sixth resource object.
[0064] In some embodiments, the subscripts of the two-dimensional array represent the first identification information and the second identification information, respectively. The first identification information and the second identification information are associated with the field of the instance used to represent the identification information when initializing the instance of the application and the resource object. When the target application subsequently initiates an access request to the target resource object, the identity information of the target application initiating the access request to the target resource object can be associated and obtained through the access request.
[0065] In some possible implementations, the above-mentioned determination of the operation permission of the target operation based on the target element may include: obtaining the corresponding target permission index table based on the type information; the target permission index table is used to indicate the index of operations that applications with the same program type as the target application are allowed to perform on resource objects with the same resource type as the target resource object; determining the operation permission of the target operation based on the target permission index table and the target element.
[0066] It is understandable that in an operating system, the types of operations that can be performed by applications are different for different types of resource objects. The target permission index table records the types of operations that can be performed on the target resource object and the permission index corresponding to each operation type. The target element has an association with the permission index recorded in the target permission index table, that is, the target element can represent the authorization status of a certain permission index, and by querying the target permission index table, it can be determined what the operation type corresponding to the permission index is.
[0067] In some embodiments, Table 1 is a schematic diagram of a list of file operation permissions and their indexes, and Table 2 is a schematic diagram of a list of socket operation permissions and their indexes. As shown in Table 1, an application can perform 10 operations on a file, and each operation type corresponds to an index; for example, the create file operation is controlled by the "create permission", and the permission index is 1, and the read file operation is controlled by the "read permission", and the permission index is 2. As shown in Table 2, an application can perform 10 operations on a socket, and each operation type corresponds to an index.
[0068] Table 1
[0069] File permissions index Opening a file 0 Create a file 1 Reading Files 2 Writing files 3 Execute File 4 Deleting files 5 Mounting Files 6 Query 7 Modify file mode 8 Modify file owner 9
[0070] Table 2
[0071]
[0072]
[0073] In some possible implementations, the target element is implemented in the form of a bitmap; each bit in the target element corresponds to an operation and its operation authority, and the bits in the target element correspond one-to-one to the index in the target authority index table. The above-mentioned determination of the operation authority of the target operation based on the target authority index table and the target element may include: determining the target bit corresponding to the target operation among all the bits of the target element based on the target authority index table and the target element; when the value of the target bit is a first value, determining that the operation authority of the operation corresponding to the target operation in the target authority index table is allowed; when the value of the target bit is a second value, determining that the operation authority of the operation corresponding to the target operation in the target authority index table is denied.
[0074] It can be understood that each element in the access policy table is implemented in the form of a bitmap. The size of the bitmap corresponding to each element depends on the number of operation types that can be applied to the resource object. For example, an application can perform 10 operations on a file. Then, the size of the bitmap corresponding to each element in the access policy table corresponding to the file is 10 bits, and each bit corresponds to a permission index. Each bit has a corresponding value. When the bit is assigned a first value, it means that the operation type of the permission index corresponding to the bit is allowed; when the bit is assigned a second value, it means that the operation type of the permission index corresponding to the bit is rejected.
[0075] In some embodiments, the target permission index corresponding to the target operation is searched according to the target permission index table. According to the target permission index, the bit corresponding to the target permission index is found in the target element; and the operation permission of the target operation is determined according to the value of the bit.
[0076] In one example, Figure 7 A schematic diagram of a bitmap in a target access strategy table provided by an embodiment of the present disclosure. Figure 7 As shown, taking the target resource object as a file as an example, the application can perform 10 operations on the file, then the bitmap of each element is 10 bits. Element a[m-1][0] represents the operation permission of the mth application on the 1st resource object. The corresponding bitmap of element a[m-1][0] is a string of binary characters, specifically "0010000100". The 0th bit in the bitmap corresponds to the permission with index 0 in the target permission index table (i.e. Table 1), the 1st bit corresponds to the permission with index 1 in the target permission index table, ..., the 9th bit corresponds to the permission with index 9 in the target permission index table. It should be noted that for ease of explanation, the operation type of the index corresponding to each bit is indicated in the form of dotted lines and text. Figure 7 Indicated in. When the target operation requested by the target application for the target resource object is "read file", the index of "read file" is determined to be 2, and the value corresponding to the second bit (i.e., the target bit) is further determined; the value of the second bit is 1, indicating that the target application is allowed to perform the "read file" operation on the target resource object. According to the above bitmap, it can also be confirmed that the target application is allowed to perform the "query" operation on the target resource object. When the target operation is query, the operation permission of the target operation is allowed.
[0077] It should be noted that the value of a bit in the bitmap is 1, indicating permission; the value is 0, indicating rejection.
[0078] In one example, see Figure 7As shown, the operation permissions of the mth application on the 6th resource object are: allowing the "write file" operation and the "delete file" operation, and denying the "open file" operation, the "create file" operation, the "read file" operation, the "execute file" operation, the "mount file" operation, the "query file" operation, the "modify file mode" operation, and the "modify file owner" operation.
[0079] In some embodiments, when the reference monitor calculates permissions according to the access control policy in the access control decision module, the bitmap corresponding to the target element can be represented as perm_value; the index corresponding to the target operation in the target permission index table can be represented as perm_index.
[0080] In the embodiment of the present disclosure, the time complexity of the process of querying the target access policy table to obtain the bitmap corresponding to the target element is O(1); and the time complexity of the process of querying the index corresponding to the target operation in the target permission index table is also O(1); in this way, the time consumption of the authorization decision process can be greatly shortened.
[0081] In some possible implementations, the above S503 may include: when the operation permission of the target operation is allowed, sending authorization information to the target application; the authorization information is used to instruct the target application to perform the target operation on the target resource object; when the operation permission of the target operation is denied, sending rejection information to the target application; the rejection information is used to reject the access request initiated by the target application to the target resource object.
[0082] It can be understood that, when it is determined that the operation permission of the target operation is allowed, the reference monitor can send authorization information to the target application, and the target application can perform the target operation on the target resource object after receiving the authorization information. When it is determined that the operation permission of the target operation is denied, the reference monitor can send denial information to the target application, and the target application cannot perform the target operation on the target resource object after receiving the denial information.
[0083] In some embodiments, Figure 8 A flowchart of a second embodiment of the access control authorization method provided by the present disclosure. Figure 8 As shown, the above method may include:
[0084] S801, a target application initiates an access request to a target resource object, where the access request is used to instruct the target application to perform a file read operation and a file write operation on the target resource object.
[0085] S802. The access control decision module in the reference monitor intercepts the access request initiated by the target application, and extracts or calculates information such as the program type and the first identification information of the target application, the resource type and the second identification information of the target resource object, and the target operation requested by the target application on the target resource object for use in subsequent authorization decisions.
[0086] S803. The access control decision module first queries the target access policy table applicable to the target resource object of this resource type in the access policy library according to the resource type of the target resource object.
[0087] S804. The access control decision module queries the target access policy table with the first identification information and the second identification information as indexes, locates the position of the target element in the target access policy table, and obtains the permission data perm_value corresponding to the target element.
[0088] S805. The access control decision module queries the permission index perm_index corresponding to the target bit in the target element according to the resource type of the target resource object and the target operation.
[0089] S806. The access control decision module performs an efficient bit operation: result = perm_value & (1 << perm_index) to obtain result; and determines whether result is 1. If result is 1, it means that the target application has the right to perform the target operation on the target resource object, and the access operation will continue normally and finally return a normal operation result to the target application; if result is 0, it means that the target application has no right to perform the target operation on the target resource object, the access will be aborted immediately, and an unauthorized error message will be returned to the target application.
[0090] In the embodiment of the present disclosure, according to the first identification information of the target application and the second identification information of the target resource object, the position of the target element is directly determined in the preset target access policy table, and according to the target element, the operation permission of the target operation is determined, which can quickly and efficiently perform the authorization decision process, while ensuring data security, shortening the time required for the authorization decision process, thereby improving the access experience and increasing the throughput of system resource access, and minimizing the additional consumption introduced by security checks.
[0091] Based on the same inventive concept, the embodiment of the present disclosure also provides an access control authorization device, which can be a chip or a system on chip of a server, or a functional module in the server for the method described in one or more of the above embodiments. Fig. 9 For a structural schematic diagram of the access control authorization device in the embodiment of the present disclosure, see Fig. 9As shown, the access control authorization device 900 may include: a request acquisition module 901, used to obtain an access request initiated by a target application to a target resource object; the access request is used to indicate the target operation requested by the target application to the target resource object, and the access request carries the first identification information of the target application and the second identification information of the target resource object; a data processing module 902, used to determine the position of the target element in a preset target access policy table according to the first identification information and the second identification information; the target element is used to indicate the type of operation that the target application is allowed to perform on the target resource object and the operation authority corresponding to each operation type; and a permission determination module 903, used to determine the operation authority of the target operation according to the target element.
[0092] In some possible implementations, the access request also carries type information, and the type information is used to indicate the program type of the target application and the resource type of the target resource object; the access control authorization device 900 also includes: a data acquisition module, which is used to determine the target access policy table corresponding to the resource type of the target resource object from multiple access policy tables.
[0093] In some possible implementations, the target policy table is implemented in the form of an m×n two-dimensional array; wherein, m≥1, m is an integer, and n≥1, n is an integer; a data processing module 902 is used to determine, based on the first identification information, that the i-th row element in the target policy table is used to indicate the target application's operating authority over all resource objects; 0≤i≤m-1, i is an integer; based on the second identification information, determine that the j-th column element in the target policy table is used to indicate the operating authority of all applications over the target resource object; 0≤j≤n-1, j is an integer; and determine the element in the i-th row and j-th column as the target element.
[0094] In some possible implementations, the access request also carries type information, and the type information is used to indicate the program type of the target application and the resource type of the target resource object; the permission determination module 903 is used to obtain the corresponding target permission index table based on the type information; the target permission index table is used to indicate the index of operations that an application with a program type is allowed to perform on a resource object with a resource type; and the operation permission of the target operation is determined based on the target permission index table and the target element.
[0095] In some possible implementations, the target element is implemented in the form of a bitmap; each bit in the target element corresponds to an operation permission of an operation type; the bits in the target element correspond one-to-one to the indexes in the target permission index table; the permission determination module 903 is used to determine the target bit corresponding to the target operation among all the bits of the target element according to the target permission index table and the target element; when the value of the target bit is a first value, the operation permission of the operation corresponding to the target operation in the target permission index table is determined to be allowed; when the value of the target bit is a second value, the operation permission of the operation corresponding to the target operation in the target permission index table is determined to be denied.
[0096] In some possible implementations, the permission determination module 903 is used to: send authorization information to the target application when the operation permission of the target operation is allowed; the authorization information is used to instruct the target application to perform the target operation on the target resource object; send rejection information to the target application when the operation permission of the target operation is denied; the rejection information is used to reject the access request initiated by the target application to the target resource object.
[0097] The description of the above device embodiment is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. In some embodiments, the functions or modules included in the device provided in the embodiments of the present disclosure can be used to execute the method described in the above method embodiment. For technical details not disclosed in the device embodiment of the present disclosure, please refer to the description of the method embodiment of the present disclosure for understanding.
[0098] It should be noted that in the embodiments of the present disclosure, if the above method is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present disclosure is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk. In this way, the embodiments of the present disclosure are not limited to any specific hardware, software or firmware, or any combination of hardware, software, and firmware.
[0099] Fig.10The hardware entity diagram of an electronic device provided in an embodiment of the present disclosure is shown in FIG. 1000. For example, the electronic device 1000 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.
[0100] Reference Fig.10 , the electronic device 1000 may include one or more of the following components: a processing component 1001, a memory 1002, a power component 1003, a multimedia component 1004, an audio component 1005, an input / output (I / O) interface 1006, a sensor component 1007, and a communication component 1008.
[0101] The processing component 1001 generally controls the overall operation of the electronic device 1000, such as operations associated with at least one of display, phone calls, data communications, camera operations, and recording operations. The processing component 1001 may include one or more processors 1009 to execute instructions to complete all or part of the steps of the above-mentioned method. In addition, the processing component 1001 may include one or more modules to facilitate the interaction between the processing component 1001 and other components. For example, the processing component 1001 may include a multimedia module to facilitate the interaction between the multimedia component 1004 and the processing component 1001.
[0102] The memory 1002 is configured to store various types of data to support operations on the electronic device 1000. Examples of such data include at least one of the following: instructions for any application or method operating on the electronic device 1000, contact data, phone book data, messages, pictures, and videos. The memory 1002 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0103] The power supply component 1003 provides power to various components of the electronic device 1000. The power supply component 1003 may include at least one of the following: a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the electronic device 1000.
[0104] The multimedia component 1004 includes a screen that provides an output interface between the electronic device 1000 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 1004 includes a front camera and / or a rear camera. When the electronic device 1000 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera may receive external multimedia data. Each front camera and the rear camera may be a fixed optical lens system or have a focal length and optical zoom capability.
[0105] The audio component 1005 is configured to output and / or input audio signals. For example, the audio component 1005 includes a microphone (MIC), and when the electronic device 1000 is in an operation mode, such as a call mode, a recording mode, and a speech recognition mode, the microphone is configured to receive an external audio signal. The received audio signal can be further stored in the memory 1002 or sent via the communication component 1008. In some embodiments, the audio component 1005 also includes a speaker for outputting audio signals.
[0106] I / O interface 1006 provides an interface between processing component 1001 and peripheral interface modules, which may be keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, a home button, a volume button, a start button, and a lock button.
[0107] The sensor assembly 1007 includes one or more sensors for providing various aspects of status assessment for the electronic device 1000. For example, the sensor assembly 1007 can detect the open / closed state of the electronic device 1000, the relative positioning of the components, such as the display and keypad of the electronic device 1000, and the sensor assembly 1007 can also detect the position change of the electronic device 1000 or a component in the electronic device 1000, the presence or absence of contact between the user and the electronic device 1000, the orientation or acceleration / deceleration of the electronic device 1000, and the temperature change of the electronic device 1000. The sensor assembly 1007 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 1007 may also include an optical sensor, such as a complementary metal oxide semiconductor (CMOS) or a charge coupled device (CCD) image sensor, for use in imaging applications. In some embodiments, the sensor assembly 1007 may also include, but is not limited to, at least one of the following: an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, and a temperature sensor.
[0108] The communication component 1008 is configured to facilitate wired or wireless communication between the electronic device 1000 and other devices. The electronic device 1000 can access a wireless network based on a communication standard, such as Wi-Fi, 4G, 5G, or a combination thereof. In an exemplary embodiment, the communication component 1008 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 1008 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, UWB technology, Bluetooth (BT) technology and other technologies.
[0109] In an exemplary embodiment, the electronic device 1000 may be implemented by one or more application specific integrated circuits (ASICs), DSPs, DSPDs, programmable logic devices (PLDs), FPGAs, controllers, microcontrollers, microprocessors, or other electronic components.
[0110] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 1002 including executable instructions or a computer program, which can be executed by a processor 1009 of the electronic device 600 to perform the above method.
[0111] An embodiment of the present disclosure provides an electronic device, including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the program, some or all of the steps in the above method are implemented.
[0112] The embodiment of the present disclosure provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, some or all of the steps in the above method are implemented. The computer-readable storage medium can be transient or non-transient.
[0113] An embodiment of the present disclosure provides a computer program, including a computer-readable code. When the computer-readable code is executed in a computer device, a processor in the computer device executes some or all of the steps for implementing the above method.
[0114] The present disclosure provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and when the computer program is read and executed by a computer, some or all of the steps in the above method are implemented. The computer program product can be implemented specifically by hardware, software, or a combination thereof. In some embodiments, the computer program product is specifically embodied as a computer storage medium, and in other embodiments, the computer program product is specifically embodied as a software product, such as a software development kit (SDK), etc.
[0115] It should be noted here that the description of the various embodiments above tends to emphasize the differences between the various embodiments, and the same or similar aspects can be referenced to each other. The description of the above device, storage medium, computer program and computer program product embodiments is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the embodiments of the device, storage medium, computer program and computer program product disclosed in the present invention, please refer to the description of the method embodiment disclosed in the present invention for understanding.
[0116] It should be understood that "one embodiment" or "an embodiment" mentioned throughout the specification means that specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present disclosure. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in the various embodiments of the present disclosure, the size of the serial numbers of the above-mentioned steps / processes does not mean the order of execution. The execution order of each step / process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present disclosure. The serial numbers of the embodiments of the present disclosure are for description only and do not represent the advantages and disadvantages of the embodiments.
[0117] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0118] In the several embodiments provided in the present disclosure, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0119] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units; they may be located in one place or distributed on multiple network units; some or all of the units may be selected based on actual needs to achieve the purpose of the present embodiment.
[0120] In addition, all functional units in the embodiments of the present disclosure may be integrated into one processing unit, or each unit may be separately configured as a unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0121] A person of ordinary skill in the art can understand that all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROMs, magnetic disks or optical disks.
[0122] Alternatively, if the above-mentioned integrated unit of the present disclosure is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure can essentially or in other words, the part that contributes to the relevant technology can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROMs, magnetic disks, or optical disks.
[0123] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are to be considered exemplary only, and the true scope and spirit of the present disclosure are indicated by the following claims.
[0124] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. An access control authorization method, characterized in that: The method comprises: Obtaining an access request initiated by a target application to a target resource object; the access request is used to indicate a target operation requested by the target application to the target resource object, and the access request carries first identification information of the target application and second identification information of the target resource object; Determine the position of a target element in a preset target access policy table according to the first identification information and the second identification information; the target element is used to indicate the type of operation that the target application is allowed to perform on the target resource object and the operation permission corresponding to each operation type; According to the target element, the operation permission of the target operation is determined.
2. The method according to claim 1, characterized in that The access request also carries type information, where the type information is used to indicate the program type of the target application and the resource type of the target resource object; Before locating the target element in the preset target access policy table by using the first identification information and the second identification information as indexes, the method further includes: The target access policy table corresponding to the resource type of the target resource object is determined from multiple access policy tables.
3. The method according to claim 1, characterized in that The target access strategy table is implemented in the form of a two-dimensional array of m×n; wherein m≥1, m is an integer, and n≥1, n is an integer; Determining the position of the target element in a preset target access policy table according to the first identification information and the second identification information includes: According to the first identification information, determining that the i-th row element in the target policy table is used to indicate the operation authority of the target application program for all resource objects; 0≤i≤m-1, i is an integer; According to the second identification information, determining that the j-th column element in the target policy table is used to indicate the operation authority of all applications on the target resource object; 0≤j≤n-1, j is an integer; The element at the i-th row and the j-th column is determined as the target element.
4. The method according to claim 1, characterized in that: The access request also carries type information, where the type information is used to indicate the program type of the target application and the resource type of the target resource object; The determining, according to the target element, the operation authority of the target operation includes: According to the type information, a corresponding target permission index table is obtained; the target permission index table is used to indicate the index of the operation that the application program with the program type is allowed to perform on the resource object with the resource type; The operation permission of the target operation is determined according to the target permission index table and the target element.
5. The method according to claim 4, characterized in that The target element is implemented in the form of a bitmap; each bit in the target element corresponds to an operation and its operation authority; the bits in the target element correspond one-to-one to the indexes in the target authority index table; The determining the operation permission of the target operation according to the target permission index table and the target element includes: Determine, according to the target permission index table and the target element, a target bit corresponding to the target operation among all bits of the target element; When the value of the target bit is the first value, determining that the operation permission of the operation corresponding to the target operation in the target permission index table is allowed; When the value of the target bit is the second value, it is determined that the operation permission of the operation corresponding to the target operation in the target permission index table is denied.
6. The method according to claim 1, characterized in that The determining, according to the target element, the operation authority of the target operation includes: When the operation authority of the target operation is allowed, sending authorization information to the target application; the authorization information is used to instruct the target application to perform the target operation on the target resource object; When the operation authority of the target operation is denied, a denial message is sent to the target application; the denial message is used to deny the access request initiated by the target application to the target resource object.
7. An access control authorization device, characterized in that: The device comprises: A request acquisition module, used to acquire an access request initiated by a target application to a target resource object; the access request is used to indicate a target operation requested by the target application to the target resource object, and the access request carries first identification information of the target application and second identification information of the target resource object; A data processing module, configured to determine the position of a target element in a preset target access policy table according to the first identification information and the second identification information; the target element is used to indicate the type of operation that the target application is allowed to perform on the target resource object and the operation permission corresponding to each operation type; The permission determination module is used to determine the operation permission of the target operation according to the target element.
8. The device according to claim 7, characterized in that The access request also carries type information, where the type information is used to indicate the program type of the target application and the resource type of the target resource object; The device further includes: a data acquisition module, configured to determine the target access policy table corresponding to the resource type of the target resource object from a plurality of access policy tables.
9. The device according to claim 7, characterized in that The target strategy table is implemented in the form of a two-dimensional array of m×n; wherein m≥1, m is an integer, and n≥1, n is an integer; The data processing module is used to determine, based on the first identification information, that the element in the i-th row of the target policy table is used to indicate the target application's operating authority over all resource objects; 0≤i≤m-1, i is an integer; based on the second identification information, determine that the element in the j-th column of the target policy table is used to indicate the operating authority of all applications over the target resource object; 0≤j≤n-1, j is an integer; and determine the element in the i-th row and j-th column as the target element.
10. The device according to claim 7, characterized in that The access request also carries type information, where the type information is used to indicate the program type of the target application and the resource type of the target resource object; The permission determination module is used to obtain a corresponding target permission index table according to the type information; The target permission index table is used to indicate the index of the operations that the application program of the program type is allowed to perform on the resource object of the resource type; The operation permission of the target operation is determined according to the target permission index table and the target element.
11. The device according to claim 10, characterized in that The target element is implemented in the form of a bitmap; each bit in the target element corresponds to an operation permission of an operation type; the bits in the target element correspond one-to-one to the indexes in the target permission index table; The permission determination module is used to determine a target bit corresponding to the target operation among all bits of the target element according to the target permission index table and the target element; When the value of the target bit is the first value, determining that the operation permission of the operation corresponding to the target operation in the target permission index table is allowed; When the value of the target bit is the second value, it is determined that the operation permission of the operation corresponding to the target operation in the target permission index table is denied.
12. The device according to claim 7, characterized in that The permission determination module is used to: send authorization information to the target application when the operation permission of the target operation is allowed; the authorization information is used to instruct the target application to perform the target operation on the target resource object; send rejection information to the target application when the operation permission of the target operation is rejected; the rejection information is used to reject the access request initiated by the target application to the target resource object.
13. An electronic device, characterized in that: The electronic device comprises: A memory for storing executable instructions; A processor, configured to implement the method according to any one of claims 1 to 6 when executing the executable instructions or computer programs stored in the memory.
14. A computer-readable storage medium storing executable instructions or a computer program, characterized in that: When the executable instructions are executed by a processor, the method according to any one of claims 1 to 6 is implemented.
15. A computer program product, comprising a computer program or instructions, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.