File query method and device, equipment, medium and program product

By encrypting the file identifiers in the file query instructions in the operating system based on the virtual memory management mechanism and matching them in the encrypted identification database, the problem of rapid identification and positioning of applications in massive applications is solved, and efficient and accurate file query is achieved.

CN120067050APending Publication Date: 2025-05-30BEIJING ESWIN COMPUTING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510179808.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In an operating system based on virtual memory management mechanism, it is difficult to quickly identify and locate applications that need to be called in a large number of applications, resulting in inefficient query and waste of storage space.

Method used

By using the encryption algorithm to process the file identification in the file query instruction, the encryption identification is obtained, and matched in the encryption identification database determined by the multi-process file based on the Internet protocol to determine the target file.

Benefits of technology

It realizes accurate and fast search of target files in multiple process files, improves the efficiency and accuracy of file queries, and avoids query results errors caused by the same default initial address.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120067050A_ABST
    Figure CN120067050A_ABST
Patent Text Reader

Abstract

The invention provides a file query method and device, equipment, a medium and a program product, and can be applied to the technical field of computers. The method is applied to an operating system based on a virtual memory management mechanism, and comprises the following steps: in response to a received file query instruction, processing a file identifier in the file query instruction by using an encryption algorithm to obtain an encrypted identifier; the encryption identifiers are matched in an encryption identifier library, a matching result is obtained, and the encryption identifier library is determined based on a plurality of process files supported by the Internet protocol. And after the matching result is determined, under the condition that the matching result represents that a target encryption identifier matched with the encryption identifier exists in the encryption identifier library, determining a process file corresponding to the target encryption identifier in the plurality of process files as a target file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and particularly to a file query method, apparatus, device, medium, and program product. Background Art

[0002] Operating systems that use virtual memory management mechanisms for file management, such as the Linux system, have a large number of users in the computer field due to their security, flexibility, and system resource efficiency. In the current field of computer technologies, with the continuous growth of computer software and hardware, the amount of application programs and data stored in computer systems has increased rapidly. To ensure the operating efficiency of the Linux system, it is necessary to quickly identify and locate the application programs to be called among a large number of application programs. Summary of the Invention

[0003] The present disclosure provides a file query method, apparatus, device, medium, and program product.

[0004] According to a first aspect of the present disclosure, there is provided a file query method applied to an operating system based on a virtual memory management mechanism, including: in response to receiving a file query instruction, processing a file identifier in the file query instruction using an encryption algorithm to obtain an encrypted identifier; matching the encrypted identifier in an encrypted identifier library to obtain a matching result, where the encrypted identifier library is determined based on multiple process files supported by the Internet protocol; and in the case where the matching result indicates that there is a target encrypted identifier in the encrypted identifier library that matches the encrypted identifier, determining the process file corresponding to the target encrypted identifier among the multiple process files as the target file.

[0005] A second aspect of the present disclosure provides a file query apparatus applied to an operating system based on a virtual memory management mechanism, including: an identifier processing module configured to, in response to receiving a file query instruction, process a file identifier in the file query instruction using an encryption algorithm to obtain an encrypted identifier; an identifier matching module configured to match the encrypted identifier in the encrypted identifier library to obtain a matching result, where the encrypted identifier library is determined based on multiple process files supported by the Internet protocol; and a file determination module configured to, in the case where the matching result indicates that there is a target encrypted identifier in the encrypted identifier library that matches the encrypted identifier, determine the process file corresponding to the target encrypted identifier among the multiple process files as the target file.

[0006] A third aspect of the present disclosure provides an electronic device, including: one or more processors; a memory configured to store one or more computer programs, where the above one or more processors execute the above one or more computer programs to implement the steps of the above method.

[0007] The fourth aspect of the present disclosure further provides a computer-readable storage medium, on which a computer program or instruction is stored, and when the computer program or instruction is executed by a processor, the steps of the above method are implemented.

[0008] The fifth aspect of the present disclosure further provides a computer program product, including a computer program or instruction, and when the computer program or instruction is executed by a processor, the steps of the above method are implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, the above content and other objects, features and advantages of the present disclosure will become clearer. In the drawings:

[0010] Figure 1 Schematically shows an application scenario diagram of a file query method, device, equipment, medium and program product according to an embodiment of the present disclosure;

[0011] Figure 2 Schematically shows a flowchart of a file query method according to an embodiment of the present disclosure;

[0012] Figure 3 Schematically shows the process of encrypting a file identifier according to a file query method of an embodiment of the present disclosure;

[0013] Figure 4 Schematically shows the process of using binary numbers to perform an AND operation to control the length of an encrypted identifier;

[0014] Figure 5 Schematically shows a structural block diagram of a file query device according to an embodiment of the present disclosure; and

[0015] Figure 6 Schematically shows a block diagram of an electronic device suitable for implementing a file query method according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are only exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.

[0017] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the present disclosure. The terms "comprising", "including" and the like as used herein indicate the presence of the stated features, steps, operations and / or components, but do not preclude the presence or addition of one or more other features, steps, operations or components.

[0018] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those of ordinary skill in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0019] In cases where expressions such as "at least one of A, B, and C, etc." are used, generally, it should be interpreted according to the meaning commonly understood by those of ordinary skill in the art (for example, "a system having at least one of A, B, and C" should include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).

[0020] In the technical solutions of the present disclosure, the user information involved (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) are all information and data authorized by the user or fully authorized by all parties. Moreover, the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, all comply with relevant laws, regulations, and standards, adopt necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or reject.

[0021] In one example, an application can be identified by the serial number of the application, and the directory where the application is located can be located using the serial number. However, since the path obtained by the above technology cannot be specific to the application itself. Therefore, when there are multiple applications in the same path, the positioning accuracy using the above technology is insufficient.

[0022] Therefore, after locating the folder where the application is located, the file name can be used as a search term to perform another query, so as to achieve an accurate query of the application. However, the above operation requires two queries, with low query efficiency and long time consumption. In addition, since the length of the file name may be very long, using the file name as a search term requires storing all file names in each folder in the database, resulting in a waste of storage space.

[0023] Since an operating system that manages files based on a virtual memory management mechanism has features such as process isolation, each process has an independent virtual address space in the system. When querying Executable and Linkable Format (ELF) files in the above operating system, since different ELF files may use the same shared library and ELF files usually have default loading addresses, querying different ELF files may result in the same virtual address without enabling address space layout randomization, leading to incorrect query results.

[0024] Embodiments of the present disclosure provide a file query method, which is applied to an operating system based on a virtual memory management mechanism, and includes: in response to receiving a file query instruction, processing the file identifier in the file query instruction by using an encryption algorithm to obtain an encrypted identifier; matching the encrypted identifier in an encrypted identifier library to obtain a matching result, where the encrypted identifier library is determined based on multiple process files supported by the Internet protocol; and in the case where the matching result indicates that there is a target encrypted identifier matching the encrypted identifier in the encrypted identifier library, determining the process file corresponding to the target encrypted identifier in the multiple process files as the target file.

[0025] Figure 1 Schematically shows an application scenario diagram of a file query method, device, device, medium and program product according to an embodiment of the present disclosure.

[0026] As Figure 1 shown, the application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, a server 105, and a database 106. The network 104 is used to provide a medium for a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0027] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103.

[0028] The first terminal device 101, the second terminal device 102, and the third terminal device 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.

[0029] Server 105 can be a server that provides various services, such as a server that responds to file query instructions submitted by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The server can analyze and process the received file query instructions and feedback the processing results (such as the file address of the target file obtained according to the file query instructions) to the terminal device.

[0030] Database 106 can be a key-value database that provides data support for the file queries that server 105 needs to perform. For example, it can be a database that stores key-value pairs composed of the Key of the file query and the query result Value. Among them, the Key can be obtained by server 105 analyzing and processing the file query instructions sent by the user through the terminal device, and the query result Value can include information such as the name of the target file and / or the file address of the target file.

[0031] It should be noted that the file query method provided by the embodiments of the present disclosure can generally be executed by server 105. Correspondingly, the file query device provided by the embodiments of the present disclosure can generally be set in server 105. The file query method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster that is different from server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or server 105 and / or database 106. Correspondingly, the file query device provided by the embodiments of the present disclosure can also be set in a server or a server cluster that is different from server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or server 105 and / or database 106.

[0032] It should be understood that Figure 1 the numbers of terminal devices, networks, servers, and databases in

[0033] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, servers, and databases. Figure 1 are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, servers, and databases. Figures 2 to 4 The file query method of the embodiments of the present disclosure will be described in detail below based on the

[0034] Figure 2 A flowchart of the file query method according to an embodiment of the present disclosure is schematically shown.

[0035] As Figure 2 shown, the file query method applied to an operating system based on a virtual memory management mechanism in this embodiment includes operations S210 to S230.

[0036] In operation S210, in response to receiving a file query instruction, the file identifier in the file query instruction is processed using an encryption algorithm to obtain an encrypted identifier.

[0037] According to an embodiment of the present disclosure, the file query instruction may be sent by a client and may include an instruction stream. Among them, the instruction stream may include one or more file identifiers, and the file identifier may include an application name, a shared library (Shared Object) name, etc. After the server receives the file query instruction, it queries the file corresponding to one or more file identifiers therein based on the file query instruction.

[0038] In addition, when the server receives a Trace command, since it is necessary to trace and analyze the execution process of the application, it is necessary to query and locate the application, which may also trigger a file query instruction.

[0039] After the file query instruction triggered locally on the server or sent by the client is received, for each file identifier in the file query instruction, it is processed using an encryption algorithm to obtain an encrypted identifier, where the encryption algorithm is used to compress a file identifier of any length into a fixed-length encrypted identifier. Preferably, the fixed length is 32 bits, etc.

[0040] In operation S220, the encrypted identifier is matched in the encrypted identifier library to obtain a matching result.

[0041] The encrypted identifier library is determined based on multiple process files supported by the Internet protocol. Among them, the Internet protocol can be used to effectively manage and distribute process files in the system and improve the efficiency of development and deployment. The encrypted identifier library may include the results obtained by processing the file identifiers of multiple process files supported by the Internet protocol using an encryption algorithm.

[0042] The encryption algorithm used to encrypt the file identifier is the same as the encryption algorithm used to construct the encrypted identifier library. This encryption algorithm may be, for example, a hash algorithm, a Bloom filter, etc. Since the result obtained by processing the same input using the encryption algorithm is always the same, in the case where there is a process file corresponding to the file identifier in the file query instruction among multiple process files supported by the Internet protocol, there must be a result in the encrypted identifier library that is the same as the encrypted identifier.

[0043] In operation S230, in the case where the matching result indicates that there is a target encrypted identifier in the encrypted identifier library that matches the encrypted identifier, the process file corresponding to the target encrypted identifier among the multiple process files is determined as the target file.

[0044] Since the results of processing using an encryption algorithm for different inputs are often different, that is, the possibility of hash collision is extremely low. Therefore, in the case where there is a target encryption identifier matching the encryption identifier in the encryption identifier library, it can be considered that there is a process file corresponding to the file identifier in the file query instruction among the multiple process files supported by the Internet protocol.

[0045] Determine the process file corresponding to the target encryption identifier as the target file to be queried by the file query instruction. The file serial number corresponding to it can be determined according to the target encryption identifier, and the target file can be located and determined according to the file serial number. Among them, the file serial number can be generated when the file is executed, and the file serial number corresponding to each file is unique.

[0046] According to an embodiment of the present disclosure, after receiving a file query instruction, an encryption algorithm is used to encrypt the file identifier to be queried, so that the length of the encrypted encryption identifier is compressed to a preset fixed length, thereby reducing the amount of data used in the matching process and improving the utilization rate of storage resources. The encryption identifier is matched in the encryption identifier library. After determining that there is a target encryption identifier matching the encryption identifier, the process file corresponding to the target encryption identifier is determined as the target file, and the file search is completed. Thus, accurate and fast search is realized according to the corresponding relationship between the encryption identifier and the process file, and the efficiency and accuracy of file query are improved. In addition, using the encryption identifier as the basis for querying files to match and search for files avoids the problem of incorrect query results caused by the same default initial address, ensures that the file query results can be obtained, thereby improving the success rate of file query and further improving the accuracy of file query.

[0047] According to an embodiment of the present disclosure, in the process of processing the file identifier using an encryption algorithm, taking the hash algorithm as an example, the string corresponding to the file identifier can be segmented, and the following operation methods are used to iteratively calculate the multiple bit data obtained by segmentation in sequence.

[0048] When calculating the first bit data in the string, the first bit data is determined as the current hash result. For each subsequent bit data, calculate the product of the current hash result and the seed value of the hash algorithm respectively, and sum the product and the current bit data to update the current hash result. After the calculation of all the bit data in the string is completed, the current hash result is determined as the encryption identifier corresponding to the file identifier.

[0049] Figure 3 Schematically shows the process of encrypting a file identifier by the file query method according to an embodiment of the present disclosure.

[0050] As Figure 3As shown below, taking the encryption of "13237" as an example, the seed value is taken as 13, and the file identifier in string format is split using the string splitting method to obtain multiple bit data. For example, the file identifier can be converted into a list of multiple bit data through the list() function, and multiple bit data can be obtained by sequentially reading characters from the converted list, obtaining five bit data "1", "3", "2", "3", "7".

[0051] Read the bit data sequentially from the high bit to the low bit. First, read "1". Since the calculation is being performed on the first bit data, the current hash result is 0. Calculate the product of it and the seed value and then add 1, and use the result to update the current hash result. Similar iterative calculations are performed on subsequent bit data, obtaining current hash results 16, 210, 2733, and 35536 respectively. After calculating the last bit data, convert the current hash result 35536 from decimal to binary data "1000101011010000". Since this binary data is 16 bits, in the case of a preset fixed length of 32 bits, 0 can be padded on its left until the number of bits is the same as the preset fixed length, obtaining the encrypted identifier "00000000000000001000101011010000".

[0052] When implementing the above iterative process using source code, intermediate results can be utilized. For example, for each bit data in the file identifier in sequence, based on the current hash result and the seed value of the hash algorithm, determine the intermediate result. Among them, when the bit data is the first bit data in the file identifier, the current hash result is the preset hash value. Preferably, the preset hash value can be taken as 0. Based on the intermediate result and the bit data, determine the iterative result. In the case where there are still unprocessed bit data in the file identifier, use the iterative result as the current hash result and return to the step of determining the intermediate result. In the case where there are no unprocessed bit data in the file identifier, based on the iterative result, determine the encrypted identifier.

[0053] During the iterative calculation process, the intermediate result of each step can be determined according to the product of the current hash result and the seed value of the hash algorithm. The iterative result of each step can be determined according to the sum of the intermediate result and the bit data.

[0054] According to the embodiments of the present disclosure, by processing the file identifier through an improved hash algorithm, the file identifier can be quickly converted. Since the data is read bit by bit during processing, multiplied by the seed value, and then added to the next bit data, even a small change in the input data will cause a huge change in the output file identifier, further reducing the possibility of hash collisions.

[0055] According to an embodiment of the present disclosure, the seed value of the hash algorithm can be selected according to the length of the encrypted identification. For example, the file identification is encrypted respectively by using a plurality of alternative seed values in an alternative seed library, and a plurality of encrypted file identifications are obtained, wherein the alternative seed library is a prime number library; determining a target encrypted file identification among the plurality of encrypted file identifications, the number of digits of which is consistent with a preset value; and determining the alternative seed value corresponding to the target encrypted file identification among the plurality of alternative seed values as the seed value of the hash algorithm.

[0056] Since a composite number can be decomposed into the product of two positive integers other than 1, if the composite number is used as the seed value, the predictability of the hash algorithm process will be stronger, and the possibility of being attacked or having a hash collision will be higher. Therefore, selecting a prime number library as the alternative seed library can improve security and avoid hash collisions.

[0057] When selecting the seed value of the hash algorithm from a plurality of alternative seed values in the alternative seed library, the file identification for selecting the seed value can be determined first, and the file identification is encrypted by using a plurality of alternative seed values in the alternative seed library, wherein the encryption process is the same as the encryption process of the file identification described above.

[0058] After the file identification is encrypted respectively by using a plurality of alternative seed values, the encrypted file identification corresponding to each of the plurality of alternative seed values and the number of digits of each of the plurality of encrypted file identifications are determined. According to the number of digits of each of the plurality of encrypted file identifications, a target encrypted file identification with the number of digits consistent with the preset value is determined from the plurality of encrypted file identifications, and the alternative seed value that obtains the target encrypted file identification is determined as the seed value of the hash algorithm.

[0059] After the above calculations are completed, when it is determined that there is only one alternative seed value for which the number of digits of the encrypted file identification is consistent with the preset value, the alternative seed value is determined as the seed value of the hash algorithm. When there are multiple alternative seed values for which the number of digits of the encrypted file identification is consistent with the preset value, one can be randomly selected from the multiple alternative seed values as the seed value of the hash algorithm.

[0060] According to an embodiment of the present disclosure, screening the alternative seed values according to the preset value and the number of digits after encryption can ensure that the number of digits of the encrypted identification meets the requirements, so that the identification length is unified, the storage pressure is reduced, and the utilization rate of storage resources is improved.

[0061] According to an embodiment of the present disclosure, the seed value of the hash algorithm can also be arbitrarily selected from an alternative seed library. After selecting the seed value from the alternative seed library, the file identifier is processed using the seed value. When there is no unprocessed bit data in the file identifier after iterative processing, the iterative result is AND-operated with a binary number whose number of bits is a preset value and all bits are 1 to obtain an encrypted identifier, thereby ensuring that the length of the encrypted identifier is the preset value.

[0062] Figure 4 Schematically shows the process of controlling the length of the encrypted identifier using a binary number for AND operation.

[0063] As Figure 4 shown, taking the encryption of "103237" as an example, the seed value is taken as 131, and the file identifier in string format is split using the string splitting method to obtain six bit data "1", "0", "3", "2", "3", "7".

[0064] The bit data is read sequentially from the high order to the low order. First, "1" is read. Since the calculation is being performed on the first bit data, the current hash result is 0. After calculating the product of it and the seed value and then summing with 1, the current hash result is updated using the sum result. Similar iterative calculations are performed on the subsequent bit data to obtain the current hash result respectively. After calculating the last bit data, the current hash result 38586234324 is converted from decimal to binary data "100011111011111010110011010111010100". Since this binary data is 36 bits and in the case where the preset fixed length is 32 bits, it can be AND-operated with a 32-bit binary number all of whose bits are 1, which is equivalent to discarding the 4 leftmost bits in the binary data that exceed 32 bits, that is, discarding "1000", to obtain a 32-bit encrypted identifier "11111011111010110011010111010100".

[0065] According to an embodiment of the present disclosure, by setting a binary number all of whose bits are 1 and performing an AND operation with the iterative result to determine the encrypted identifier, it is possible to ensure that the length of the encrypted identifier is the preset value without the need for pre-trial calculation and comparison, thereby reducing the calculation load by omitting the trial calculation of alternative seed values and improving the determination efficiency of the hash algorithm.

[0066] According to an embodiment of the present disclosure, after determining the seed value of the hash algorithm, the encrypted identifier library can be determined using the following method. Determine the security attributes of multiple processes supported by the Internet protocol. Based on the multiple security attributes, determine multiple process files respectively. Based on the multiple process files, determine the encrypted identifier library.

[0067] Taking the Nexus protocol as an example of an Internet protocol, the Nexus protocol is an integrated application development protocol designed to solve the problem of cross-system function calls between a client and a function-as-a-service system in the case of separation of the user interface and logic.

[0068] The security context of the Nexus protocol can be used to determine access permissions for system objects such as processes and files. Therefore, based on this security context, security attributes such as the user account, user permissions, process file identifier, and security level of each of the multiple processes supported by this Internet protocol can be determined. And based on the process file identifier in the security attributes, the process file can be determined, and further the encryption identifier library can be determined.

[0069] After determining the security attributes, the multiple security attributes can be parsed respectively to determine storage information such as the file name and file address corresponding to the process file identifier. Based on the above storage information, the process file can be determined from multiple files under the file address of the system according to the file name.

[0070] Furthermore, after determining the process file, the encryption identifier library can be determined in the following manner. First, determine the process identifier of each of the multiple process files. Using the hash algorithm, encrypt the multiple process identifiers to obtain the process encryption identifier of the process identifier. Among them, the process of encrypting the process identifier is the same as the process of encrypting the process identifier in the above file query instruction. Based on the multiple process encryption identifiers, an encryption identifier library is constructed.

[0071] According to an embodiment of the present disclosure, determine the security attributes of multiple processes supported by the Internet protocol, further determine multiple process files based on the security attributes, and further use an encryption algorithm to process each of the multiple process files respectively to complete the construction of the encryption identifier library, so as to use the encryption identifier library to match subsequent encryption identifiers.

[0072] According to an embodiment of the present disclosure, the file query method further includes: loading a target file to execute an application program corresponding to the target file.

[0073] According to an embodiment of the present disclosure, after determining the target file, the client can load the target file so that the client executes an application program corresponding to the target file to implement a call to the function-as-a-service system, improving the call efficiency of the client and enhancing the user experience.

[0074] Based on the above file query method, the present disclosure also provides a file query device. The following will be combined with Figure 5 Describe this device in detail.

[0075] Figure 5 Schematically shows a structural block diagram of a file query device according to an embodiment of the present disclosure.

[0076] As shown Figure 5 in FIG. 1, the file query device 500 applied to an operating system based on a virtual memory management mechanism according to this embodiment includes an identification processing module 510, an identification matching module 520, and a file determination module 530.

[0077] The identification processing module 510 is configured to, in response to receiving a file query instruction, process the file identifier in the file query instruction by using an encryption algorithm to obtain an encrypted identifier. In one embodiment, the identification processing module 510 may be configured to perform the operation S210 described above, which will not be elaborated here.

[0078] The identification matching module 520 is configured to match the encrypted identifier in an encrypted identifier library to obtain a matching result, where the encrypted identifier library is determined based on multiple process files supported by an Internet protocol. In one embodiment, the identification matching module 520 may be configured to perform the operation S220 described above, which will not be elaborated here.

[0079] The file determination module 530 is configured to, when the matching result indicates that there is a target encrypted identifier in the encrypted identifier library that matches the encrypted identifier, determine the process file corresponding to the target encrypted identifier in the multiple process files as the target file. In one embodiment, the file determination module 530 may be configured to perform the operation S230 described above, which will not be elaborated here.

[0080] According to an embodiment of the present disclosure, the identification processing module 510 includes an intermediate result determination sub-module, an iterative result determination sub-module, an iterative processing sub-module, and an identification determination sub-module.

[0081] The intermediate result determination sub-module is configured to, for each bit data in the file identifier in sequence, determine an intermediate result based on the current hash result and the seed value of the hash algorithm, where, when the bit data is the first bit data in the file identifier, the current hash result is a preset hash value.

[0082] The iterative result determination sub-module is configured to determine an iterative result based on the intermediate result and the bit data.

[0083] The iterative processing sub-module is configured to, when there is still unprocessed bit data in the file identifier, use the iterative result as the current hash result and return to the step of determining the intermediate result.

[0084] The identification determination sub-module is configured to, when there is no unprocessed bit data in the file identifier, determine the encrypted identifier based on the iterative result.

[0085] According to an embodiment of the present disclosure, the file query device 500 further includes an identification conversion module and an identification segmentation module.

[0086] The identification conversion module is configured to convert the file identifier into a string format.

[0087] An identification splitting module, configured to split a file identification in string format to obtain multiple bit data of the file identification.

[0088] According to an embodiment of the present disclosure, the file query device 500 further includes an identification calculation module, a digit determination module, and a seed value determination module.

[0089] The identification calculation module is configured to encrypt the file identification respectively by using multiple alternative seed values in an alternative seed library to obtain multiple encrypted file identifications, where the alternative seed library is a prime number library.

[0090] The digit determination module is configured to determine a target encrypted file identification among the multiple encrypted file identifications, where the number of digits is consistent with a preset value.

[0091] The seed value determination module is configured to determine, among the multiple alternative seed values, the alternative seed value corresponding to the target encrypted file identification as the seed value of the hash algorithm.

[0092] According to an embodiment of the present disclosure, the file query device 500 further includes an attribute determination module, a file determination module, and an identification library determination module.

[0093] The attribute determination module is configured to determine the security attributes of multiple processes supported by the Internet protocol.

[0094] The file determination module is configured to respectively determine multiple process files based on the multiple security attributes.

[0095] The identification library determination module is configured to determine an encrypted identification library based on the multiple process files.

[0096] According to an embodiment of the present disclosure, the identification library determination module includes a process determination sub-module, an identification encryption sub-module, and an identification library determination sub-module.

[0097] The process determination sub-module is configured to determine the process identification of each of the multiple process files.

[0098] The identification encryption sub-module is configured to encrypt the multiple process identifications by using the hash algorithm to obtain the process encryption identifications of the process identifications.

[0099] The identification library determination sub-module is configured to determine an encrypted identification library based on the multiple process encryption identifications.

[0100] According to an embodiment of the present disclosure, the file determination module includes an attribute parsing sub-module.

[0101] The attribute parsing sub-module is configured to respectively parse the multiple security attributes, and determine the process file corresponding to each security attribute from multiple fields.

[0102] According to an embodiment of the present disclosure, the file query device 500 further includes a file loading module.

[0103] The file loading module is configured to load a target file so as to execute an application program corresponding to the target file.

[0104] According to an embodiment of the present disclosure, any multiple of the identification processing module 510, the identification matching module 520, and the file determination module 530 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the identification processing module 510, the identification matching module 520, and the file determination module 530 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the identification processing module 510, the identification matching module 520, and the file determination module 530 may be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding functions may be executed.

[0105] Figure 6 A block diagram of an electronic device suitable for implementing the file query method according to an embodiment of the present disclosure is schematically shown.

[0106] As Figure 6 shown, the electronic device 600 according to an embodiment of the present disclosure includes a processor 601, which can perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603. The processor 601 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 601 may also include on-board memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0107] In the RAM 603, various programs and data required for the operation of the electronic device 600 are stored. The processor 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. The processor 601 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 602 and / or the RAM 603. It should be noted that the programs can also be stored in one or more memories other than the ROM 602 and the RAM 603. The processor 601 can also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0108] According to an embodiment of the present disclosure, the electronic device 600 may further include an input / output (I / O) interface 605, and the input / output (I / O) interface 605 is also connected to the bus 604. The electronic device 600 may further include one or more of the following components connected to the input / output (I / O) interface 605: an input portion 606 including a keyboard, a mouse, etc.; an output portion 607 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 608 including a hard disk, etc.; and a communication portion 609 including a network interface card such as a LAN card, a modem, etc. The communication portion 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the input / output (I / O) interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read therefrom can be installed into the storage portion 608 as needed.

[0109] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.

[0110] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the above-described ROM 602 and / or RAM 603 and / or one or more memories other than ROM 602 and RAM 603.

[0111] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiment of the present disclosure.

[0112] When the computer program is executed by the processor 601, it executes the above functions defined in the system / apparatus of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0113] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and is downloaded and installed through the communication part 609, and / or installed from the removable medium 611. The program code contained in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0114] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 609, and / or installed from the removable medium 611. When the computer program is executed by the processor 601, it executes the above functions defined in the system of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0115] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).

[0116] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0117] Those skilled in the art can understand that the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0118] The above describes the embodiments of the present disclosure. However, these embodiments are only for illustrative purposes and are not intended to limit the scope of the present disclosure. Although the embodiments are described separately above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.

Claims

1. A file query method, characterized in that: The method is applied to an operating system based on a virtual memory management mechanism, and the method comprises: In response to receiving the file query instruction, the file identifier in the file query instruction is processed using an encryption algorithm to obtain an encrypted identifier; Matching the encryption identifier in an encryption identifier library to obtain a matching result, wherein the encryption identifier library is determined based on a plurality of process files supported by an Internet protocol; and When the matching result indicates that there is a target encryption identifier matching the encryption identifier in the encryption identifier library, a process file corresponding to the target encryption identifier among the multiple process files is determined as a target file.

2. The method according to claim 1, wherein: The encryption algorithm includes a hash algorithm; The step of processing the file identifier by using an encryption algorithm to obtain an encrypted identifier includes: For each bit of data in the file identifier, Determine an intermediate result based on a current hash result and a seed value of the hash algorithm, wherein, when the bit data is the first bit data in the file identifier, the current hash result is a preset hash value; Determine an iteration result based on the intermediate result and the bit data; In the case that there is still unprocessed bit data in the file identifier, taking the iteration result as the current hash result and returning to the step of determining the intermediate result; and In the case that there is no unprocessed bit data in the file identifier, the encryption identifier is determined based on the iteration result.

3. The method according to claim 2, further comprising: Convert the file identifier into a string format; as well as The file identifier in a character string format is segmented to obtain a plurality of bit data of the file identifier.

4. The method according to claim 2, wherein: The seed value of the hash algorithm is determined as follows: The file identifier is encrypted using multiple candidate seed values ​​of a candidate seed library to obtain multiple encrypted file identifiers, wherein the candidate seed library is a prime number library; Determine a target encrypted file identifier among the multiple encrypted file identifiers, the number of bits of which is consistent with a preset value; and The candidate seed value corresponding to the target encrypted file identifier among the multiple candidate seed values ​​is determined as the seed value of the hash algorithm.

5. The method according to claim 1, wherein: The encryption identification library is determined in the following manner: determining security attributes of a plurality of processes supported by said Internet protocol; Based on the plurality of security attributes, respectively determining the plurality of process files; and Based on the plurality of process files, the encryption identification library is determined.

6. The method according to claim 5, wherein: The step of determining the encryption identification library based on the plurality of process files comprises: Determine the process identifier of each of the plurality of process files; Using the hash algorithm, encrypting the plurality of process identifiers to obtain encrypted process identifiers of the process identifiers; and The encryption identification library is determined based on the plurality of process encryption identifications.

7. The method according to claim 5, characterized in that The security attribute includes multiple fields, and the multiple fields include user account, user authority, process file identifier and security level; The determining the process files based on the plurality of security attributes respectively includes: The plurality of security attributes are parsed respectively, and a process file corresponding to each of the security attributes is determined from the plurality of fields.

8. The method according to any one of claims 1 to 7, further comprising: The target file is loaded so as to execute an application program corresponding to the target file.

9. A file query device, characterized in that: The device is applied to an operating system based on a virtual memory management mechanism, and the device comprises: The identification processing module is used for processing the file identification in the file query instruction by using an encryption algorithm in response to receiving the file query instruction to obtain an encrypted identification; an identification matching module, used to match the encrypted identification in an encrypted identification library to obtain a matching result, wherein the encrypted identification library is determined based on a plurality of process files supported by an Internet protocol; and The file determination module is used to determine the process file corresponding to the target encryption identifier among the multiple process files as the target file when the matching result indicates that there is a target encryption identifier matching the encryption identifier in the encryption identifier library.

10. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.

11. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.

12. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.