Key file protection method and device based on custom directory tree

By establishing a custom directory tree based on the critical file path in the kernel, preventing the upper directory of key files from being moved, the problem of insufficient protection of key files in the existing technology is solved, and stricter protection and security enhancement of key files is achieved.

CN120217436APending Publication Date: 2025-06-27NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510324982.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing technology lacks protection from the upper directory of the key files when protecting critical files, resulting in the risk that the protection mechanism will be bypassed by the attacker.

Method used

By establishing a custom directory tree in the kernel based on the path of the key file, preventing the upper directory of the key file from being moved, thereby achieving stricter protection of key files.

Benefits of technology

Effectively enhance the security of existing key file protection methods, preventing attackers from bypassing the protection mechanism through mobile directories, and achieving stricter protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217436A_ABST
    Figure CN120217436A_ABST
Patent Text Reader

Abstract

The invention discloses a key file protection method and device based on a user-defined directory tree, and relates to the technical field of network security, and the method comprises the steps: initializing a root node of a top directory, obtaining the path information of a key file needing to be protected, analyzing the path information, and determining the directory name of each level corresponding to the key file, determining a target key file name in the directory name, traversing all hierarchies of a path corresponding to the target key file name, entering the current directory under the condition that the directory name of the current hierarchy exists, and recursively creating a complete directory tree so as to protect the target key file. By establishing the directory tree in the kernel according to the key file path, the upper directory of the key file is prevented from being moved, so that the security of the existing key file protection method is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and particularly relates to a method and device for protecting critical files based on a custom directory tree. Background Art

[0002] Critical files usually refer to files that are crucial for the system and application programs, and these files may contain configuration settings, system code, or other important data.

[0003] In the related art, critical files can be specified by users. Attackers can achieve attacks on the system and application programs by means of tampering with, deleting, or replacing critical files, thereby reducing the credibility of the system. Therefore, it is very necessary to provide security protection for critical files against tampering, deletion, and replacement. For the Linux operating system, existing methods mainly implement the anti-tampering, anti-deletion, and anti-replacement of critical files based on the Linux Security Module (LSM). However, the existing solutions lack the protection of the upper-level directories of critical files, making the protection mechanism at risk of being bypassed by attackers. Summary of the Invention

[0004] In view of the above problems, this application provides a method and device for protecting critical files based on a custom directory tree. By establishing a directory tree in the kernel according to the critical file path, the upper-level directory of the critical file is prevented from being moved, thereby realizing the security enhancement of the existing critical file protection method.

[0005] In a first aspect, an embodiment of this application provides a method for protecting critical files based on a custom directory tree. The method for protecting critical files based on a custom directory tree includes:

[0006] Initializing the root node of the top-level directory and obtaining the path information of the critical files to be protected;

[0007] Parsing the path information to determine the directory names of each level corresponding to the critical files;

[0008] Determining the target critical file name in the directory names;

[0009] Traversing all levels of the path corresponding to the target critical file name. When the directory name of the current level already exists, enter the current directory and recursively create a complete directory tree to protect the target critical file.

[0010] In some embodiments, the protection of the target critical file includes:

[0011] When it is determined that a file movement event occurs, determining the movement type of the file movement event;

[0012] Establish a protection policy based on the directory tree and the movement type to protect target critical files.

[0013] In some embodiments, the method for protecting critical files based on a custom directory tree further includes:

[0014] Traverse all levels of the path corresponding to the target critical file name, and create corresponding nodes if they do not exist at the current level.

[0015] In some embodiments, the method for protecting critical files based on a custom directory tree further includes:

[0016] Obtain the first path information of the critical file that needs to cancel protection;

[0017] Parse the first path information to determine the first directory names of each level corresponding to the critical file for which protection is to be cancelled;

[0018] Determine the first target critical file name in the directory names;

[0019] Traverse from the bottommost level to the top level, and judge the category to which the level belongs;

[0020] If the level is a file, delete the node and continue the traversal process.

[0021] In some embodiments, the movement type includes: moving the target critical file to a preset file, moving the target critical file to a preset directory, and moving the target critical directory to a target directory.

[0022] In some embodiments, establishing a protection policy based on the directory tree and the movement type to protect target critical files includes:

[0023] Determine the target critical file according to the directory tree. When it is determined that the movement type is to move the target critical file to a preset file, execute a first restriction condition, and the first restriction condition prohibits moving the target critical file to the preset file;

[0024] Determine the target critical file according to the directory tree. When it is determined that the movement type is to move the target critical file to a preset directory, execute a second restriction condition, and the second restriction condition prohibits moving the target critical file;

[0025] Determine the target critical directory according to the directory tree. When it is determined that the movement type is to move the target critical directory to a target directory, execute a third restriction condition, and the third restriction condition prohibits triggering the movement operation.

[0026] In some embodiments, the method for protecting critical files based on a custom directory tree further includes:

[0027] If the layer is a directory, when it is determined that there are subdirectories or other files in the directory, the traversal process ends;

[0028] When it is determined that there are no subdirectories or other files in the directory, the node is deleted and the traversal process continues.

[0029] In a second aspect, an embodiment of the present application provides a key file protection device based on a custom directory tree, including:

[0030] An acquisition module, configured to initialize the root node of the top-level directory and acquire the path information of the key files to be protected;

[0031] A parsing module, configured to parse the path information to determine the directory names of each layer corresponding to the key files;

[0032] A determination module, configured to determine the target key file name in the directory names;

[0033] A protection module, configured to traverse all layers of the path corresponding to the target key file name. When the directory name of the current layer already exists, enter the current directory and recursively create a complete directory tree to protect the target key file.

[0034] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor. A program code that can run on the processor is stored on the memory. When the program code is executed by the processor, the key file protection method based on a custom directory tree introduced in any implementation manner of the first aspect is implemented.

[0035] In a fourth aspect, an embodiment of the present application provides a computer storage medium. The computer storage medium stores one or more programs, and the one or more programs can be executed by the electronic device introduced in the third aspect to implement the key file protection method based on a custom directory tree introduced in any implementation manner of the first aspect.

[0036] A key file protection method and device based on a custom directory tree provided by an embodiment of the present application initialize the root node of the top-level directory, acquire the path information of the key files to be protected, parse the path information to determine the directory names of each layer corresponding to the key files, determine the target key file name in the directory names, traverse all layers of the path corresponding to the target key file name. When the directory name of the current layer already exists, enter the current directory and recursively create a complete directory tree to protect the target key file, so as to realize establishing a directory tree according to the key file path in the kernel, prevent the upper directory of the key file from being moved, and thus realize the security enhancement of the existing key file protection method.

[0037] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The present application will be described in more detail hereinafter based on embodiments with reference to the accompanying drawings.

[0039] Figure 1 FIG. shows a schematic flowchart of a key file protection method based on a custom directory tree proposed in an embodiment of the present application;

[0040] Figure 2 FIG. shows a schematic flowchart of an exemplary directory tree creation process proposed in an embodiment of the present application;

[0041] Figure 3 FIG. shows a schematic flowchart of an exemplary directory tree deletion process proposed in an embodiment of the present application;

[0042] Figure 4 FIG. shows a schematic diagram of an exemplary directory tree structure proposed in an embodiment of the present application;

[0043] Figure 5 FIG. shows a block diagram of an exemplary key file protection device based on a custom directory tree proposed in an embodiment of the present application;

[0044] Figure 6 FIG. shows a block diagram of an electronic device for executing the key file protection method based on a custom directory tree according to an embodiment of the present application;

[0045] Figure 7 FIG. shows a computer-readable storage medium for storing or carrying the implementation of the key file protection method based on a custom directory tree according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the embodiments and the accompanying drawings. The illustrative embodiments and descriptions thereof of the present invention are only used to explain the present invention and are not intended to limit the present invention.

[0047] In the Linux operating system, existing solutions mainly utilize hook functions in the Linux Security Module (LSM) to intercept operations such as reading, modifying, deleting, and replacing any file. By comparing the absolute path of the file with the path of a critical file, if they are the same, it is a critical file and operations such as modification, deletion, and replacement are not allowed, thereby achieving functions such as anti-tampering, anti-deletion, and anti-replacement.

[0048] Analyzing the above technical problems, the applicant found that existing solutions lack control over the upper-level directory of critical files, resulting in attackers being able to tamper with, delete, and replace critical files by moving the upper-level directory of the critical file, thereby bypassing existing security protection methods.

[0049] The present invention proposes an enhanced method for protecting critical files based on a custom directory tree. By establishing a directory tree in the kernel according to the critical file path, it prevents the upper-level directory of the critical file from being moved, thereby achieving security enhancement for existing critical file protection methods.

[0050] Analyzing and combining the above technical problems, the inventor proposes a method and device for protecting critical files based on a custom directory tree. By constructing a critical file directory tree and an effective matching strategy in the kernel, it can effectively solve the problem of lack of control over the upper-level directory of critical files in existing critical file protection systems, resulting in security deficiencies. By constructing a custom directory tree, it can ensure that the upper-level directory of critical files is not moved, thereby avoiding the risk of attackers bypassing the protection mechanism by moving the directory, and can more precisely control file movement and renaming operations, thereby providing more stringent protection. Among them, the method for protecting critical files based on a custom directory tree will be described in detail in subsequent embodiments.

[0051] The following introduces the application scenario of the method for protecting critical files based on a custom directory tree provided in the embodiments of the present application:

[0052] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a method for protecting critical files based on a custom directory tree provided in the embodiments of the present application. In this embodiment, the method for protecting critical files based on a custom directory tree can be applied to a critical file protection device 300 based on a custom directory tree as shown in Figure 4 and Figure 5In the electronic device 200 shown, the electronic device may include one or more. Information can be transmitted between multiple electronic devices in a wireless and / or wired manner. Multiple electronic devices can cooperate to complete the key file protection method based on a custom directory tree. Exemplarily, the electronic device can include a computer, a mobile terminal, a tablet, etc., which are not limited in this application. Next, for Figure 1 the process shown, the key file protection method based on a custom directory tree may include S110 to S140.

[0053] S110: Initialize the root node of the top-level directory and obtain the path information of the key files to be protected.

[0054] S120: Parse the path information to determine the directory names of each level corresponding to the key files.

[0055] S130: Determine the target key file names in the directory names.

[0056] S140: Traverse all levels of the path corresponding to the target key file names. When the directory name of the current level already exists, enter the current directory and recursively create a complete directory tree to protect the target key files.

[0057] In some embodiments, the key file protection method based on a custom directory tree further includes:

[0058] Traverse all levels of the path corresponding to the target key file names. When the current level does not exist, create the corresponding node.

[0059] In the embodiments of this application, refer to Figure 2 , a schematic diagram of an exemplary directory tree creation process provided in the embodiments of this application. First, the kernel initializes the root node of the top-level directory " / "; then, the user configures the path of the key files to be protected; secondly, the kernel parses the key path to parse out the directory names of each level. For example, " / root / dir1 / 1.txt" is parsed into four levels: " / ", "root", "dir1", "1.txt", where the leaf node "1.txt" of the directory tree is the final key file name; finally, traverse all levels of the key file path. If the current level does not exist, create the corresponding node. If the directory name of the current level already exists, enter the directory and recursively create a complete directory tree. Exemplarily, the structure of the directory tree can refer to Figure 4 an exemplary directory tree structure diagram shown.

[0060] In some embodiments, the key file protection method based on a custom directory tree further includes S141 to S142.

[0061] S141: When it is determined that a file moving event occurs, determine the moving type of the file moving event.

[0062] S142: Based on the directory tree and the moving type, establish a protection policy to protect the target critical files.

[0063] In the embodiments of the present application, in order to further distinguish critical files, ordinary files, critical directories, and ordinary directories, critical files are files configured or specified by users, and critical directories refer to the upper-level directories containing critical files. Therefore, for the above three moving types, this solution adopts different directory tree matching strategies respectively, which can effectively prevent critical files and their upper-level directories from being illegally moved.

[0064] In some embodiments, the moving types include: moving the target critical file to a preset file, moving the target critical file to a preset directory, and moving the target critical directory to a target directory.

[0065] Among them, the directory tree matching depends on the file rename hook function of the Linux system to implement, and this hook function can intercept all moving events of the Linux file system. In the practical process, the moving events of Linux mainly include the following three types.

[0066] One type is moving from file A to file B, which is a file rename / overwrite operation, renaming file A to file B, and if file B exists, overwriting file B.

[0067] Another type is moving from file A to directory A, which is a file moving operation, moving file A to under directory A.

[0068] Another type is moving from directory A to directory B, which is a directory rename / moving operation, renaming directory A to directory B, and if directory B exists, making directory A a sub-directory of directory B.

[0069] In some embodiments, S142 includes S1421 to S1423, where:

[0070] S1421: Determine the target critical file according to the directory tree. When it is determined that the moving type is moving the target critical file to a preset file, execute the first restriction condition, and the first restriction condition prohibits moving the target critical file to the preset file;

[0071] S1422: Determine the target critical file according to the directory tree. When it is determined that the moving type is moving the target critical file to a preset directory, execute the second restriction condition, and the second restriction condition prohibits moving the target critical file;

[0072] S1423: Determine the target critical directory according to the directory tree. When it is determined that the movement type is to move the target critical directory to the target directory, execute the third restriction condition, which prohibits triggering the movement operation.

[0073] In this embodiment, for the above-mentioned type of processing method, whether it is file A or file B, as long as it is a critical file, this type of movement event is prohibited. This policy can directly and effectively prevent critical files from being renamed or overwritten; for the above-mentioned other type of processing method, if file A is a critical file, the movement is prohibited. This policy can effectively prevent critical files from being moved to other directories and getting out of the protection of the original critical file protection system. In addition, this policy allows ordinary files to be moved to the critical file directory, which can effectively reduce the impact on the system; for the above-mentioned yet another type of processing method, if directory A is a critical directory, the movement operation is prohibited. This policy can effectively prevent the movement or renaming of critical directories and prevent the critical files in their subdirectories from getting out of the protection of the existing critical file protection system.

[0074] Considering that in order to cancel the protection of the target critical file with protection.

[0075] In some embodiments, the critical file protection method based on the custom directory tree further includes S210 to S250, where:

[0076] S210: Obtain the first path information of the critical file that needs to cancel the protection;

[0077] S220: Parse the first path information to determine the first directory names of each level corresponding to the critical file whose protection is to be cancelled;

[0078] S230: Determine the first target critical file name in the directory name;

[0079] S240: Traverse from the bottommost level to the top level and judge the category to which the level belongs;

[0080] S250: If the level is a file, delete the node and continue the traversal process.

[0081] In some embodiments, the critical file protection method based on the custom directory tree further includes S260 to S270, where:

[0082] S260: If the level is a directory, when it is determined that the directory has subdirectories or other files, end the traversal process.

[0083] S270: When it is determined that the directory has no subdirectories or other files, delete the node and continue the traversal process.

[0084] In the embodiments of the present application, the key file directory tree is deleted based on the key file paths defined by the user. The specific process of deleting the directory tree is as follows: Figure 3 as shown Figure 3 in FIG. 1, which is a schematic diagram of an exemplary directory tree deletion process provided by the embodiments of the present application. First, the user configures the key file paths that need to be unprotected; then, the kernel parses the key paths to parse out the directory names at each level. For example, for " / root / dir1 / 1.txt", it is parsed into four levels: " / ", "root", "dir1", "1.txt", where the leaf node "1.txt" of the directory tree is the final key file name; finally, starting from the bottommost level, if the current level is a file, the node is directly deleted. If it is a directory, it is determined whether there are other subdirectories or files under the directory. If there are, it directly returns. If not, the directory is deleted and the traversal continues.

[0085] In the present application, by constructing a key file directory tree and an effective matching strategy in the kernel, the problem of lack of control over the upper-level directories of key files and thus lack of security in the existing key file protection systems can be effectively solved.

[0086] First, by constructing a custom directory tree, it can be ensured that the upper-level directories of key files are not moved, thus avoiding the risk that attackers bypass the protection mechanism by moving directories.

[0087] Second, by distinguishing key files from ordinary files and key directories from ordinary directories and adopting different matching strategies, the present invention can more precisely control the operations of moving and renaming files, thereby providing more stringent protection.

[0088] The present invention provides a key file protection method, device, electronic device, and storage medium based on a custom directory tree, which can effectively control the moving operations of the upper-level directories of key files and has important practical application value for improving the security and credibility of the system.

[0089] Please refer to Figure 4 FIG. 2 Figure 4 which is a structural block diagram of a key file protection device based on a custom directory tree provided by the present application. The key file protection device 300 based on a custom directory tree includes: an acquisition module 310, a parsing module 320, a confirmation module 330, and a protection module 340, where:

[0090] The acquisition module 310 is used to initialize the root node of the top-level directory and acquire the path information of the key files to be protected.

[0091] The parsing module 320 is used to parse the path information to determine the directory names at each level corresponding to the key files.

[0092] A confirmation module 330 for determining a target key file name in a directory name.

[0093] A protection module 340 for traversing all levels of the path corresponding to the target key file name, entering the current directory when the directory name at the current level already exists, and recursively creating a complete directory tree to protect the target key file.

[0094] The device embodiments in this application may also include other modules, which specifically correspond to some content in the above method part.

[0095] It should be noted that the device embodiments in this application correspond to the foregoing method embodiments. The specific principles in the device embodiments can be referred to the content in the foregoing method embodiments, and will not be elaborated here.

[0096] In several embodiments provided in this embodiment, the coupling between modules may be electrical, mechanical, or other forms of coupling.

[0097] In addition, in each embodiment of the present invention, the functional modules may be integrated into a processing module, or each module may exist physically alone, or two or more modules may be integrated into one module. The above integrated modules may be implemented in the form of hardware or in the form of software functional modules.

[0098] Please refer to Figure 5 , Figure 5 which is a structural block diagram of an electronic device 200 that can execute the above-mentioned key file protection method based on a custom directory tree provided by an embodiment of this application. The electronic device 200 may be a smart phone, a tablet computer, a computer, or a portable computer, etc.

[0099] The electronic device 200 further includes a processor 202 and a memory 204. Among them, the memory 204 stores a program that can execute the content in the foregoing embodiments, and the processor 202 can execute the program stored in the memory 204.

[0100] Among them, the processor 202 may include one or more cores for processing data and a message matrix unit. The processor 202 connects various parts within the entire electronic device 200 through various interfaces and circuits, and executes various functions of the electronic device 200 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 204, and by calling data stored in the memory 204. Optionally, the processor 202 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 202 may integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem decoder, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the display content; the modem is used to process wireless communication. It can be understood that the above-mentioned modem decoder may not be integrated into the processor and may be implemented separately through a communication chip.

[0101] The memory 204 may include a random access memory (RAM) and may also include a read-only memory. The memory 204 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 204 may include a program storage area and a data storage area. The program storage area may store instructions for implementing the operating system, instructions for implementing at least one function (such as instructions for a user to obtain a random number), instructions for implementing the following various method embodiments, etc. The data storage area may also store data created during the use of the terminal (such as random numbers), etc.

[0102] The electronic device 200 may further include a network module and a screen. The network module is used to receive and send electromagnetic waves, implement the mutual conversion between electromagnetic waves and electrical signals, so as to communicate with a communication network or other devices, such as communicating with an audio playback device. The network module may include various existing circuit elements for performing these functions, such as antennas, radio frequency transceivers, digital signal processors, encryption / decryption chips, subscriber identity module (SIM) cards, memories, and so on. The network module can communicate with various networks such as the Internet, enterprise intranets, wireless networks or communicate with other devices through wireless networks. The above-mentioned wireless networks may include cellular phone networks, wireless local area networks or metropolitan area networks. The screen can display interface content and perform data interaction.

[0103] Please refer to Figure 6 , Figure 6 shows a structural block diagram of a computer-readable storage medium provided by an embodiment of the present application. Program code 410 is stored in the computer-readable storage medium 400, and the program code 410 can be called by a processor to execute the method described in the above method embodiment.

[0104] The computer-readable storage medium 400 may be an electronic memory such as a flash memory, EEPROM (electrically erasable programmable read-only memory), EPROM, hard disk or ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium 400 has a storage space for the program code 410 that executes any method step in the above method. These program codes 410 can be read out from or written into one or more computer program products. The program code 410 can be compressed in an appropriate form, for example.

[0105] An embodiment of the present application also provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the key file protection method based on a custom directory tree described in the above various optional implementation manners.

[0106] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A key file protection method based on a custom directory tree, characterized in that: The method comprises: Initialize the root node of the top-level directory and obtain the path information of the key files that need to be protected; Parsing the path information to determine the directory names of each level corresponding to the key files; Determine the target key file name in the directory name; Traverse all levels of the path corresponding to the target key file name, and if the directory name of the current level already exists, enter the current directory and recursively create a complete directory tree to protect the target key file.

2. The key file protection method based on a custom directory tree according to claim 1 is characterized in that: The protection of the target key files includes: In the case of determining that a file move event is to be performed, determining a move type of the file move event; A protection strategy is established based on the directory tree and the movement type to protect the target key file.

3. The key file protection method based on a custom directory tree according to claim 1 is characterized in that: The method further comprises: Traverse all levels of the path corresponding to the target key file name, and create a corresponding node if the current level does not exist.

4. The key file protection method based on a custom directory tree according to claim 1 is characterized in that: The method further comprises: Get the first path information of the key file that needs to be unprotected; Parsing the first path information to determine the first directory names of each level corresponding to the key files to be unprotected; Determine the first target key file name in the directory name; Traverse from the lowest level to the highest level to determine the category to which the level belongs; If the level is a file, delete the node and continue traversal processing.

5. The key file protection method based on a custom directory tree according to claim 2 is characterized in that: The moving types include: moving the target key file to a preset file, moving the target key file to a preset directory, and moving the target key directory to a target directory.

6. The key file protection method based on a custom directory tree according to claim 5 is characterized in that: The step of establishing a protection strategy based on the directory tree and the movement type to protect the target key file includes: Determine the target key file according to the directory tree, and when it is determined that the move type is to move the target key file to a preset file, execute a first restriction condition, wherein the first restriction condition prohibits moving the target key file to the preset file; Determine the target key file according to the directory tree, and when it is determined that the moving type is to move the target key file to a preset directory, execute a second restriction condition, wherein the second restriction condition prohibits moving the target key file; The target key directory is determined according to the directory tree, and when it is determined that the movement type moves the target key directory to the target directory, a third restriction condition is executed, wherein the third restriction condition prohibits triggering the movement operation.

7. The key file protection method based on a custom directory tree according to claim 4 is characterized in that: The method further comprises: If the level is a directory, if it is determined that the directory has subdirectories or other files, the traversal process ends; When it is determined that the directory does not have any subdirectories or other files, the node is deleted and the traversal process continues.

8. A key file protection device based on a custom directory tree, characterized in that: The device comprises: The acquisition module is used to initialize the root node of the top-level directory and obtain the path information of the key files that need to be protected; A parsing module, used for parsing the path information to determine the directory names of each level corresponding to the key file; A determination module, used to determine the target key file name in the directory name; The protection module is used to traverse all levels of the path corresponding to the target key file name, and when the directory name of the current level already exists, enter the current directory and recursively create a complete directory tree to protect the target key file.

9. An electronic device, characterized in that: The electronic device includes a memory and a processor, wherein the memory stores program codes that can be run on the processor, and when the program codes are executed by the processor, the key file protection method based on a custom directory tree as described in any one of claims 1-7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program codes, and the program codes can be called by one or more processors to execute the key file protection method based on a custom directory tree as described in any one of claims 1-7.