Configuration file protection method and device, equipment, storage medium and program product

By using preset time periods and periodically generated digest values ​​in configuration file protection, illegal modifications are identified and automatically restored, the problem that configuration files may still be illegally modified after identity authentication is leaked in the prior art is solved, and the security of configuration files is improved.

CN120012167APending Publication Date: 2025-05-16CETC JINCANG (BEIJING) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411934738.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the prior art, in configuration file protection, after the identity authentication method is leaked, the configuration file may still be illegally modified and cannot be automatically restored, which has poor security.

Method used

Through the preset time period and summary values ​​generated by each cycle, illegal modification identification and automatic recovery of configuration files are realized. The specific method includes periodically generating the summary value of the configuration file, recording the generation time, and obtaining the target summary value. If the summary value generated in the current period is inconsistent with the target summary value and the generation time is not in the preset time period, the configuration file is overwritten as the configuration file when the target summary value is generated.

Benefits of technology

It reduces the possibility that the configuration file is illegally modified, improves the security of the configuration file, and realizes automatic recovery of the configuration file.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012167A_ABST
    Figure CN120012167A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a configuration file protection method and device, equipment, a storage medium and a program product, and the method comprises the steps: periodically generating an abstract value of a configuration file, and recording a moment when the abstract value is generated; obtaining a target abstract value; the target digest value is a digest value generated at the latest moment in the stored digest values of which the generated moments are located in the preset time period; and if the digest value generated in the current period is not consistent with the target digest value and the moment of generating the digest value in the current period is not in the preset time period, covering the configuration file as a configuration file when the target digest value is generated. According to the method, whether modification is allowed or not is recognized through abstract comparison, whether modification is allowed or not is recognized through setting of the preset time period, active repairing of the configuration file is achieved by covering the configuration file which is illegally modified, and the safety of the configuration file is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a configuration file protection method, device, equipment, storage medium and program product. Background Art

[0002] Configuration files, such as database configuration files and software configuration files, are important system files. For example, the database configuration file stores multiple parameters such as database connection parameters and performance parameters, which are used to optimize database performance, improve security and enhance data consistency. It is a very important file for the database. If it is illegally modified, it will reduce the security of the database or even cause abnormal operation.

[0003] In the related art, the configuration files are often protected by encrypting them, and only authenticated users are allowed to view and modify the configuration files. This method still poses a risk of illegal modification of the configuration files after the authentication method is leaked, and has poor security. Summary of the invention

[0004] The configuration file protection method, apparatus, device, storage medium, and program product provided in the embodiments of the present application realize the identification and automatic recovery of illegal modification of the configuration file through the preset time period and the summary value generated in each period, thereby reducing the possibility of illegal modification of the configuration file and improving the security of the configuration file.

[0005] In a first aspect, an embodiment of the present application provides a configuration file protection method, including: periodically generating a summary value of a configuration file, and recording the time when the summary value is generated; obtaining a target summary value; the target summary value is the latest summary value generated at the time of generation among the stored summary values ​​whose generation time is within a preset time period; if the summary value generated in the current period is inconsistent with the target summary value, and the time when the summary value is generated in the current period is not within the preset time period, overwriting the configuration file with the configuration file when the target summary value is generated.

[0006] In a possible implementation, the configuration file protection method further includes: generating a first inspection record for the current period when the summary value generated in the current period is inconsistent with the target summary value and the time when the summary value is generated in the current period is not within a preset time period; the first inspection record stores the summary value generated in the current period and the time when it is generated, the first status value, and the target summary value.

[0007] In a possible implementation, the first inspection record also stores a configuration file when the target summary value is generated; overwriting the configuration file with the configuration file when the target summary value is generated includes: reading the configuration file when the target summary value is generated from the first inspection record of the current cycle; overwriting the configuration file with the configuration file when the target summary value is generated.

[0008] In a possible implementation, the configuration file protection method further includes: if the moment when the summary value is generated in the current period is within a preset time period, and the summary value generated in the current period is inconsistent with the target summary value, then generating a second inspection record for the current period; the second inspection record stores the summary value generated in the current period and the moment when it is generated, the second status value, and the target summary value.

[0009] In one possible implementation, obtaining a target summary value includes: obtaining a newly generated inspection record; storing summary values ​​corresponding to a first period and a second period in the inspection record, the first period being the period when the inspection record is generated; if the modification status in the inspection record is a first status value, obtaining a summary value corresponding to the second period stored in the inspection record; if the modification status in the inspection record is a second status value, obtaining a summary value corresponding to the first period stored in the inspection record.

[0010] In a possible implementation, the configuration file protection method further includes: obtaining protection configuration information of the configuration file; reading a period for generating a summary value and a preset time period from the protection configuration information; wherein the preset time period includes a start time and an end time, and the start time and the end time are on the same day.

[0011] In a second aspect, an embodiment of the present application provides a configuration file protection device, characterized in that it includes: a periodic summary generation module, which is used to periodically generate a summary value of a configuration file and record the time when the summary value is generated; a target summary value acquisition module, which is used to obtain a target summary value; the target summary value is the latest summary value generated at the time of generation among the stored summary values ​​whose generation time is within a preset time period; a configuration file recovery module, which is used to overwrite the configuration file with the configuration file when the target summary value is generated if the summary value generated in the current period is inconsistent with the target summary value and the time when the summary value is generated in the current period is not within the preset time period.

[0012] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a memory, a processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory, so that the processor executes the first aspect above and / or various possible implementations of the first aspect.

[0013] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementations of the first aspect.

[0014] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.

[0015] The configuration file protection method, device, equipment, storage medium and program product provided in the embodiment of the present application realize the periodic inspection of the configuration file through a configurable period. Specifically, first determine whether the generation time of the summary value of the current period is within the preset time period allowed for modification. If it is not within the preset time period, obtain the summary value corresponding to the last modification stored within the preset time period, that is, obtain the target summary value; compare whether the summary value generated in the current period is consistent with the target summary value; if they are inconsistent, it indicates that the configuration file has been modified in the time period not allowed for modification, and restore the modified configuration file to the configuration file when the target summary value was generated. The flexibility of configuration file protection is improved through configurable periods and preset time periods; by modifying the configuration of the allowed time, summary comparison and configuration file overwriting, the automatic recovery of illegally modified configuration files is realized, and the security of configuration files is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0017] Figure 1 A schematic diagram of an application scenario provided for this application;

[0018] Figure 2 A flowchart of a configuration file protection method provided in an embodiment of the present application;

[0019] Figure 3 A flowchart of another configuration file protection method provided in an embodiment of the present application;

[0020] Figure 4 Schematic diagram of two inspection records provided in an embodiment of the present application;

[0021] Figure 5 For this application Figure 3 A schematic diagram of the process of step S304 in the illustrated embodiment;

[0022] Figure 6 A flowchart of another configuration file protection method provided in an embodiment of the present application;

[0023] Figure 7 A schematic diagram of the structure of a configuration file protection device provided in an embodiment of the present application;

[0024] Figure 8A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0025] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0026] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0027] Configuration files are important files of the system. In order to improve the security of configuration files, a series of protection measures need to be formulated to prevent configuration files from being tampered with.

[0028] Take the database configuration file as an example. Figure 1 A schematic diagram of an application scenario provided for this application, such as Figure 1 As shown, the database configuration file is generally stored in plain text in the database installation directory. In order to improve the security of the database configuration file, the configuration file is usually protected by the operating system, allowing users authenticated by the operating system to view and modify the configuration file.

[0029] In order to further improve the security of the configuration file, encryption technology, such as transparent encryption technology, may be used to encrypt the configuration file.

[0030] However, after the identity authentication, key, etc. are leaked, the configuration files are at risk of being tampered with and cannot be automatically restored.

[0031] In order to overcome the problems of poor security and inability to automatically recover configuration files, the present application implements the provided configuration file protection method, which implements regular checking of configuration files through configurable cycles and preset time periods. It determines whether the configuration file of this cycle has been modified by checking whether the summary value generated during each cycle check is consistent with the summary value of the configuration file recorded previously. It determines whether the modification is allowed by determining whether the moment of generating the summary is within the time period where modification is allowed, i.e., the preset time period. When an unallowed modification is identified, the modified configuration file is automatically overwritten with the configuration file that was allowed to be modified last time, i.e., the configuration file corresponding to the target summary value.

[0032] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0033] Figure 2 A flowchart of a configuration file protection method provided in an embodiment of the present application is provided. The method can be executed by any electronic device with corresponding data processing capabilities, such as a configuration file protection device, such as Figure 2 As shown, the method comprises the following steps:

[0034] Step S201, periodically generate a summary value of a configuration file, and record the time when the summary value is generated.

[0035] The configuration file may be a configuration file of any system, such as a configuration file of a database. The digest value may be calculated using any digest algorithm, such as message digest algorithms such as SM3 and MD5.

[0036] Specifically, the summary value of the configuration file in each period may be generated with a preset time interval as a period, and the time when the summary value of each period is generated is recorded.

[0037] The preset time interval is a configurable parameter and can be adjusted through functions, interfaces, etc.

[0038] Exemplarily, the preset time interval may be 5 minutes, 10 minutes, 30 minutes or other values.

[0039] Taking a database as an example, the preset time interval may be configured by a database administrator.

[0040] Step S202, obtaining a target summary value.

[0041] The target summary value is the summary value with the latest generation time among the stored summary values ​​whose generation time is within the preset time period.

[0042] Step S203: if the digest value generated in the current period is inconsistent with the target digest value, and the time when the digest value is generated in the current period is not in the preset time period, the configuration file is overwritten with the configuration file when the target digest value is generated.

[0043] The preset time period is used to describe the time period during which the configuration file is allowed to be modified, and may be the time period during which the configuration file is allowed to be modified every day, such as 10:00-11:00, 15:00-16:00, and the like.

[0044] If the target summary value does not exist and the time when the summary value is generated in the current period is not in the preset time period, the configuration file is overwritten with the initial configuration file. If the target summary value does not exist and the time when the summary value is generated in the current period is in the preset time period, the summary value generated in the current period is updated to the target summary value without operating the configuration file.

[0045] If the moment when the summary value is generated in the current cycle is within the preset time period, the summary value generated in the current cycle is compared with the previous summary value of the stored configuration file. If the two are inconsistent, it means that the configuration file has been modified in the current cycle and the modification is allowed or compliant. In this case, the summary value generated in the current cycle is stored as the latest target summary value.

[0046] After each compliance modification of the configuration file, in addition to recording the corresponding target summary value, the modified configuration file also needs to be stored.

[0047] If the moment when the summary value is generated in the current cycle is not in the preset time period, then if the configuration file is found to be modified in the current cycle, the modification is not allowed and the configuration file needs to be overwritten. Specifically, in the current cycle, after the summary value of the current configuration file is generated, the target summary value of the latest record in the configuration file is obtained to determine whether the target summary value is consistent with the summary value generated in the current cycle; if it is inconsistent, it means that the configuration file has been modified during the period from the moment when the summary value of the current cycle is generated to the moment when the target summary value is generated; if the moment when the summary value is generated in the current cycle is not in the preset time period, it means that the modification of the current configuration file is not allowed, and the current configuration file is overwritten with the configuration file when the target summary value is generated, that is, the modified configuration file when the target summary value is generated. If the target summary value is consistent with the summary value generated in the current cycle, it means that the configuration file has not been modified during the period from the moment when the summary value of the current cycle is generated to the moment when the target summary value is generated, and there is no need to overwrite the configuration file.

[0048] The two digest values ​​are consistent, specifically, the two digest values ​​are equal.

[0049] Taking the use of the SM3 algorithm to generate the summary value of the configuration file as an example, first initialize a variable; fill, expand and iteratively compress the binary data of the configuration file, read 64 bytes or 512 bits of data from the binary file in each round, and after a round of expansion and compression, get the value of the corresponding bit of the variable. After compression is completed, the value of the variable is the calculated summary value.

[0050] Taking the database as an example, when the database is started, the configuration file protection process is started, and the configuration file protection process is used to execute the configuration file protection method provided by the present application. First, the cycle for generating the summary value and the time period allowed for modification, i.e., the preset time period, are read; based on the read cycle, the configuration file is checked periodically. In each cycle, the current configuration file is first obtained, and the summary value of the configuration file is generated, and the moment when the summary value is generated is recorded, which may be the current moment; the target summary value is obtained, and it is determined whether the summary value generated in the current cycle is consistent with the target summary value; if not, it is determined whether the moment when the summary value is generated is in the preset time period; if not, the current configuration file is overwritten with the configuration file when the target summary value is generated, thereby realizing automatic recovery of the configuration file. If the summary value generated in the current cycle is inconsistent with the target summary value and the current moment is in the preset time period, the target summary value is updated.

[0051] When the summary value generated in the current cycle is inconsistent with the target summary value, it means that the configuration file has been modified from the time when the target summary value is generated to the time when the summary value is generated in the current cycle, and it is necessary to further determine whether the modification is allowed. Specifically, it is determined whether the modification is allowed by whether the time when the summary value is generated in the current cycle is in the preset time period. If it is in the preset time period, the modification is allowed, and the summary value generated in the current cycle is stored, so that the target summary value is updated to the summary value generated in the current cycle. At the same time, the configuration file of the current cycle can also be saved, such as saving the binary data of the configuration file. If it is not in the preset time period, the modification is not allowed, and the configuration file needs to be restored, that is, the current configuration file is overwritten with the configuration file when the target summary value is generated.

[0052] After each update of the target summary value, that is, each time the configuration file modification is allowed, the preset time period can be adjusted for checking of subsequent periodic configuration files.

[0053] For example, taking a 5-minute cycle and assuming that the preset time period is 10:00-10:30, assuming that the current cycle is 10:20-10:25, the summary value of the configuration file generated in the current cycle is v1, and the time is 10:20:25; the target summary value is v2, v1≠v2, and the time when v1 is generated is in the preset time period, then the modification of the current cycle is legal or allowed, and the target summary value is updated to v1. Afterwards, the preset time period can also be modified to 9:00-9:30.

[0054] The configuration file protection method provided in this embodiment realizes the periodic inspection of the configuration file through a configurable period. Specifically, firstly, it is determined whether the generation time of the summary value of the current period is within the preset time period that allows modification. If it is not within the preset time period, the summary value corresponding to the last modification within the preset time period that is stored is obtained, that is, the target summary value is obtained; the summary value generated in the current period is compared with the target summary value to see whether they are consistent; if they are inconsistent, it indicates that the configuration file has been modified in the time period that is not allowed to be modified, and the modified configuration file is restored to the configuration file when the target summary value was generated. The flexibility of configuration file protection is improved through configurable periods and preset time periods; by modifying the configuration of the allowed time, summary comparison, and configuration file overwriting, the automatic recovery of illegally modified configuration files is realized, thereby improving the security of configuration files.

[0055] The configuration file may be one or more, and each configuration file is protected by the configuration file protection method provided in this application to reduce the probability of the configuration file being tampered with, improve the security of the configuration file, and ensure the operation of the system.

[0056] Figure 3 A flowchart of another configuration file protection method provided in an embodiment of the present application. Figure 2 On the basis of the embodiment shown, the steps of reading the cycle and the preset time period are added, the situation when the moment of the current cycle generation is in the preset time period, and the related steps of generating the inspection record are added, such as Figure 3 As shown, the configuration file protection method provided in this embodiment may specifically include the following steps:

[0057] Step S301, obtaining protection configuration information of the configuration file.

[0058] Step S302: Read the cycle for generating the summary value and the preset time period from the protection configuration information.

[0059] The preset time period includes a start time and an end time, and the start time and the end time are on the same day.

[0060] The configuration file is the configuration file of the database. The protection configuration information is provided by the database administrator. The protection configuration information includes the period of periodic inspection of the configuration file and the time period for legal modification of the configuration file.

[0061] The database administrator can provide new protection configuration information each time the configuration file is modified, and synchronize the new protection configuration information to the configuration file protection device of the database.

[0062] The database administrator can modify the protection configuration information of the configuration file through a preset interface. The preset interface can be an application programming interface (Application Programming Interface, API) provided by the database for modifying the protection mechanism of the configuration file.

[0063] You can get the protection configuration information of the configuration file by calling the function and using the function's return value.

[0064] The protection configuration information may include the name of the configuration file, the checking period, the start time allowed for modification, and the end time allowed for modification.

[0065] Based on the name of the configuration file, the protection configuration information of the configuration file can be searched from multiple protection configuration information, and the inspection cycle and preset time period of the configuration file can be read from the protection configuration information of the configuration file. The inspection cycle is the cycle for generating the summary value of the configuration file.

[0066] Step S303: periodically generate a summary value of the configuration file based on the read cycle, and record the time when the summary value is generated.

[0067] Step S304, obtaining a target summary value; the target summary value is the latest summary value generated at a time among the stored summary values ​​generated at a time within a preset time period.

[0068] The target summary value can be obtained from the last inspection record generated before the current cycle.

[0069] Step S305: when the summary value generated in the current cycle is inconsistent with the target summary value and the time when the summary value is generated in the current cycle is not within the preset time period, a first inspection record of the current cycle is generated.

[0070] The first inspection record stores the summary value generated in the current period and the time when it was generated, the first state value, and the target summary value.

[0071] If the digest value generated in the current cycle is inconsistent with the target digest value, it indicates that the configuration file of the current cycle has been modified. If the moment when the digest value is generated in the current cycle is not in the preset time period, it indicates that the modification of the configuration file of the current cycle is illegal or not allowed, and a first inspection record is generated. The first status value in the first inspection record is used to indicate that the modification of the current cycle is illegal or not allowed, that is, the digest value generated in the current cycle recorded in the first inspection record is the digest value of the illegally modified configuration file.

[0072] Exemplarily, the first state value may be 0, 2 or other values.

[0073] The first inspection record may also include the name of the configuration file, and may also include the type and description information of each item of recorded data.

[0074] For each inspection record, including the first inspection record and the second inspection record, it includes the name of the configuration file, the summary value of the configuration file generated in the current cycle, the time when the summary value is generated in the current cycle, and the target summary value (if it does not exist, it is defaulted, such as null) and the binary data of the configuration file when the target summary value is generated.

[0075] Inspection records can be stored in system tables of the database.

[0076] Step S306: Overwrite the configuration file with the configuration file used when the target digest value was generated.

[0077] Optionally, the first inspection record also stores a configuration file when the target summary value is generated.

[0078] The binary data of the configuration file when the target digest value is generated may be saved to the inspection record, including the first inspection record and the second inspection record. If the target digest value does not exist, this item may be left blank.

[0079] Optionally, overwriting the configuration file with the configuration file used when the target summary value was generated includes: reading the configuration file used when the target summary value was generated from the first inspection record of the current cycle; and overwriting the configuration file with the configuration file used when the target summary value was generated.

[0080] In the inspection record, including the first inspection record and the subsequent second inspection record, the configuration file of the current cycle and the configuration file when the target summary value is generated, such as the binary data of the configuration file, can also be saved. Therefore, in the subsequent cycle, the configuration file when the target summary value is generated can be overwritten by the inspection record, the first inspection record or the second inspection record, and when the modification of the current cycle is allowed, the configuration file when the target summary value is generated can be updated based on the configuration file of the current cycle.

[0081] By saving the configuration files before and after modification in the inspection records and continuously updating the inspection records, the efficiency of configuration file coverage is improved.

[0082] Step S307: if the time when the summary value is generated in the current cycle is in the preset time period, and the summary value generated in the current cycle is inconsistent with the target summary value, then a second inspection record of the current cycle is generated.

[0083] The second check record stores the summary value generated in the current period and the time when it was generated, the second state value, and the target summary value. The second state value is used to indicate whether the modification in the current period is legal or allowed.

[0084] Exemplarily, the second state value may be 1.

[0085] For example, Figure 4 Schematic diagram of two inspection records provided in the embodiment of the present application. Assuming that the modification of the i-th cycle is allowed and the configuration file has not been modified before the i-th cycle, the second inspection record generated in the i-th cycle is as follows: Figure 4 As shown, the configuration file has not been modified from the i-th period to the j-1th period, and modification in the j-th period is not allowed. The first inspection record generated in the j-th period is as follows: Figure 4 The check record contains the configuration file name (confname), the check time of the current cycle (checktime), the digest value calculated in the current cycle (curconfdigest), the saved current configuration file (curconf), the saved previous configuration file (oldconf), the digest value calculated by the saved previous configuration file (oldconfdigest), and the modification status (status).

[0086] The data types of various data can also be stored in the inspection record, such as timestampz (timestamp), text (text), clob (Character Large Object, character large object), int (signed integer) and other types.

[0087] The inspection time of the current cycle is the moment when the summary value is calculated or generated for the current cycle corresponding to the inspection record. The current configuration file saved is the configuration file saved for the current cycle. The last configuration file saved is the configuration file saved for the last time before the current cycle, that is, the configuration file that was last allowed to be modified. The summary value calculated by the last saved configuration file, that is, the aforementioned target summary value, is the summary value calculated by the configuration file that was last allowed to be modified. The modification status status is used to characterize whether the inspection time of the current cycle is within a legal time period, that is, a preset time period, and may include two values, a first status value and a second status value, such as 2 and 1, which respectively indicate that it is not within the preset time period and is within the preset time period.

[0088] The last saved configuration file and the current saved configuration file are used to represent the configuration files before and after modification in the current cycle, respectively.

[0089] Since the configuration file has not been modified before the i-th cycle, the two items saved in the generated inspection record, oldconf (the previous configuration file) and oldconfdigest (the digest value calculated by the previous configuration file), are both default and assigned null values. The name of the configuration file is configuration file 4, the inspection time of the current cycle is 12:35, the digest value calculated by the current cycle is digest41, the inspection time of the current cycle is in the preset time period 12:00-14:00, the value of the modification status status is 1 (an example of the second status value), and the generated second inspection record is as follows: Figure 4 As shown, the current configuration file conf41 is saved.

[0090] In some embodiments, a last configuration file saved in the first inspection record and a digest value calculated from the last configuration file saved may be given.

[0091] In the i+1th cycle, digest41 is used as the target digest value to determine whether the digest value calculated in the i+1th cycle is consistent with digest41, so as to determine whether the configuration file has been modified in the i+1th cycle. If it has not been modified, there is no need to generate an inspection record. This is repeated until the jth cycle, and digest41 is still used as the target digest value to determine whether the digest value of the configuration file calculated in the jth cycle, i.e., digest42, is consistent with digest41. Since the configuration file has been modified, such as modified to conf42, digest42 is inconsistent with digest41. Then, it is determined whether the inspection time of the jth cycle is within the preset time period, i.e., whether 14:45 is within the 12:00-14:00 time period. If it is not, the modification of the jth cycle is not allowed or is illegal. The first inspection record generated is as follows: Figure 4 As shown, the value of the modification status status is 2 (an example of the first status value), and the configuration file is restored from conf42 to conf41 to prevent the configuration file from being tampered with.

[0092] In the j+1th cycle, digest41 is still used as the target digest value to perform digest value consistency determination to determine whether the configuration file in the subsequent cycle has been modified, and so on.

[0093] In this embodiment, by protecting the configuration information, flexible configuration of the configuration file inspection cycle and the time period allowed for modification is achieved, and flexible adjustment of parameters is supported. By continuously adjusting the cycle and the preset time period, the possibility of the configuration file being tampered with is further reduced; by generating inspection records for each period where modifications occur, including a first inspection record and a second inspection record, the modification record of the configuration file is continuously updated, which is convenient for inspection and verification, while improving the efficiency of determining the target summary value.

[0094] Figure 5 For this application Figure 3 The flowchart of step S304 in the embodiment shown is as follows: Figure 5 As shown, step S304 may specifically include the following steps:

[0095] Step S501, obtaining the latest generated inspection record.

[0096] The inspection record stores summary values ​​corresponding to a first period and a second period, and the first period is the period when the inspection record is generated.

[0097] Step S502: If the modification status in the inspection record is the first modification status, obtain the summary value corresponding to the second period stored in the inspection record.

[0098] Step S503: If the modification status in the inspection record is the second status value, obtain the summary value corresponding to the first cycle stored in the inspection record.

[0099] Each inspection record records the summary value of the configuration file calculated in two cycles, namely the first cycle and the second cycle, wherein the first cycle is the cycle in which the inspection record is generated, namely the current cycle; the second cycle is earlier than the first cycle, and is the cycle in which the summary value is generated within a preset time period, and is the cycle in which the configuration file is modified, and has the shortest interval with the first cycle.

[0100] The digest value corresponding to the first cycle can be obtained by checking the value of curconfdigest in the record, and the digest value corresponding to the second cycle can be obtained by checking the value of oldconfdigest in the record. The digest value corresponding to a cycle is the digest value calculated or generated within the cycle.

[0101] For each cycle, obtain the latest inspection record generated before the cycle, that is, the latest inspection record generated among the existing inspection records; read the value of the modification status in the inspection record, if the value of the modification status is the first modification status, then the summary value corresponding to the second cycle stored in the inspection record is the target summary value; conversely, if the value of the modification status is the second modification status, then the summary value corresponding to the first cycle stored in the inspection record is the target summary value.

[0102] By checking the modification status in the record, it is possible to quickly determine whether the modification of the period corresponding to the inspection record is allowed; for different modification statuses, by reading the summary values ​​of different periods recorded in the inspection record, the target summary value can be quickly read, thereby improving the efficiency of determining whether the configuration file has been modified.

[0103] Figure 6 A flowchart of another configuration file protection method provided in an embodiment of the present application is shown as follows: Figure 6As shown, the configuration file protection method provided in this embodiment may specifically include the following steps:

[0104] Step S601: Periodically check the configuration file based on the configured period and the preset time period.

[0105] Step S602: In each cycle, calculate the summary value of the configuration file and record the current time.

[0106] Step S603, obtaining the last inspection record.

[0107] Step S604, determine whether the modification status of the last inspection record is 1; if so, execute step S605; if not, execute step S606.

[0108] Step S605, determining whether the digest value calculated in the current cycle is consistent with curconfdigest in the previous check record; if so, returning to step S602; if not, executing step S607.

[0109] Step S606: Determine whether the digest value calculated in the current cycle is consistent with oldconfdigest in the previous check record; if so, return to step S602; if not, execute step S607.

[0110] The curconfdigest in the check record is the digest value generated or calculated in the first cycle when the check record is generated, and the oldconfdigest is the target digest value generated or calculated in the second cycle (a cycle before the first cycle).

[0111] Step S607, determine whether the current time is within a preset time period; if so, execute step S608; if not, execute step S609.

[0112] Step S608: Generate a second inspection record.

[0113] Step S609: Generate a first inspection record.

[0114] Step S610, overwrite the current configuration file.

[0115] Specifically, when the modification status of the previous inspection record is 1 (an example of the first status value), overwriting the current configuration file is specifically to read the value of the curconf field in the previous inspection record to obtain the configuration file when the target summary value is generated; when the modification status of the previous inspection record is not 1, overwriting the current configuration file is specifically to read the value of the oldconf field in the previous inspection record to obtain the configuration file when the target summary value is generated; and the configuration file when the target summary value is generated is used to overwrite the current configuration file.

[0116] Corresponding to the configuration file protection method provided in the aforementioned embodiment, the embodiment of the present application further provides a configuration file protection device.

[0117] Figure 7 A schematic diagram of a configuration file protection device provided in an embodiment of the present application is shown in FIG. Figure 7 The configuration file protection device includes: a periodic summary generation module 710, a target summary value acquisition module 720 and a configuration file recovery module 730.

[0118] The periodic summary generation module 710 is used to periodically generate summary values ​​of the configuration file and record the time when the summary values ​​are generated; the target summary value acquisition module 720 is used to obtain the target summary value; the target summary value is the latest summary value generated at the time of generation among the stored summary values ​​whose generation time is within the preset time period; the configuration file recovery module 730 is used to overwrite the configuration file with the configuration file when the target summary value is generated if the summary value generated in the current period is inconsistent with the target summary value and the time when the summary value is generated in the current period is not within the preset time period.

[0119] Optionally, the configuration file protection device further includes a first inspection record generating module, which is used to:

[0120] When the summary value generated in the current period is inconsistent with the target summary value and the time when the summary value is generated in the current period is not within the preset time period, a first inspection record of the current period is generated; the first inspection record stores the summary value generated in the current period and the time when it is generated, the first status value, and the target summary value.

[0121] Optionally, the first inspection record also stores a configuration file when the target summary value is generated; the configuration file recovery module 730 is specifically used to: read the configuration file when the target summary value is generated from the first inspection record of the current cycle; and overwrite the configuration file with the configuration file when the target summary value is generated.

[0122] Optionally, the configuration file protection device also includes a second inspection record generating module, which is used to: generate a second inspection record of the current period if the moment when the summary value is generated in the current period is within a preset time period, and the summary value generated in the current period is inconsistent with the target summary value; the second inspection record stores the summary value generated in the current period and the moment when it is generated, the second status value, and the target summary value.

[0123] Optionally, the target summary value acquisition module 720 is specifically used to: obtain the latest generated inspection record; the inspection record stores summary values ​​corresponding to the first period and the second period, the first period being the period when the inspection record is generated; if the modification status in the inspection record is the first status value, then obtain the summary value corresponding to the second period stored in the inspection record; if the modification status in the inspection record is the second status value, then obtain the summary value corresponding to the first period stored in the inspection record.

[0124] Optionally, the configuration file protection device also includes a parameter reading module, which is used to: obtain protection configuration information of the configuration file; read the period for generating the summary value and the preset time period from the protection configuration information, so as to periodically generate the summary value of the configuration file based on the read period; wherein the preset time period includes a start time and an end time, and the start time and the end time are on the same day.

[0125] The device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and this embodiment will not be described in detail here.

[0126] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 8 As shown, the electronic device provided by this embodiment includes: at least one processor 801 and a memory 802.

[0127] Optionally, the device further includes a communication component 803 . The processor 801 , the memory 802 and the communication component 803 are connected via a bus 804 .

[0128] In a specific implementation process, at least one processor 801 executes the computer-executable instructions stored in the memory 802, so that at least one processor 801 executes the above method.

[0129] The specific implementation process of the processor 801 can be found in the above method embodiment, and its implementation principle and technical effect are similar, so this embodiment will not be repeated here.

[0130] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0131] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.

[0132] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special-purpose computer.

[0133] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (Application Specific Integrated Circuits, referred to as: ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.

[0134] The division of units is only a logical function division, and there may be other divisions in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0135] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0136] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0137] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0138] Those skilled in the art can understand that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk and other media that can store program codes.

[0139] Finally, it should be noted that those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses or adaptations of the present invention, which follow the general principles of the present invention and include common knowledge or customary technical means in the art not disclosed by the present invention, are not limited to the precise structure described above and shown in the drawings, and may be modified and changed in various ways without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A configuration file protection method, characterized in that: include: Periodically generate a summary value of the configuration file, and record the time when the summary value is generated; Get the target summary value; The target summary value is the latest summary value generated among the stored summary values ​​whose generation times are within the preset time period; If the digest value generated in the current cycle is inconsistent with the target digest value, and the time when the digest value is generated in the current cycle is not within the preset time period, the configuration file is overwritten with the configuration file when the target digest value is generated.

2. The method according to claim 1, characterized in that The method further comprises: When the summary value generated in the current cycle is inconsistent with the target summary value and the time when the summary value is generated in the current cycle is not within a preset time period, generating a first inspection record of the current cycle; The first inspection record stores the summary value generated in the current period and the time when it was generated, the first state value, and the target summary value.

3. The method according to claim 2, characterized in that The first inspection record also stores a configuration file when the target summary value is generated; Overwrite the configuration file with the configuration file used when the target digest value is generated, including: Reading a configuration file when the target summary value is generated from the first inspection record of the current cycle; Overwrite the configuration file with the configuration file used when the target digest value was generated.

4. The method according to claim 3, characterized in that The method further comprises: If the time when the summary value is generated in the current cycle is within the preset time period, and the summary value generated in the current cycle is inconsistent with the target summary value, then generating a second inspection record of the current cycle; The second inspection record stores the summary value generated in the current period and the time when it was generated, the second state value, and the target summary value.

5. The method according to claim 4, characterized in that The obtaining of the target summary value includes: Obtaining the latest inspection record generated; the inspection record stores summary values ​​corresponding to a first period and a second period, the first period being the period when the inspection record is generated; If the modification status in the inspection record is a first status value, obtaining a summary value corresponding to the second period stored in the inspection record; If the modification status in the inspection record is a second status value, a summary value corresponding to the first period stored in the inspection record is obtained.

6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: Obtaining protection configuration information of the configuration file; Reading a period for generating the summary value and the preset time period from the protection configuration information; The preset time period includes a start time and an end time, and the start time and the end time are on the same day.

7. A configuration file protection device, characterized in that: include: A periodic summary generation module, used to periodically generate a summary value of a configuration file and record the time when the summary value is generated; A target summary value acquisition module is used to obtain a target summary value; The target summary value is the latest summary value generated among the stored summary values ​​whose generation times are within the preset time period; The configuration file recovery module is used to overwrite the configuration file with the configuration file when the target summary value is generated if the summary value generated in the current cycle is inconsistent with the target summary value and the time when the summary value is generated in the current cycle is not within the preset time period.

8. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 6 when executed by a processor.

10. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 6 when being executed by a processor.