Intra-organization strategy generation method and device, equipment and storage medium

By receiving policy requests in the organization management system and determining the real policy hash in the cache area, the problems of poor universality and insufficient convenience during policy allocation and generation are solved, and fast and accurate policy determination and optimization of transmission efficiency are achieved.

CN120218762APending Publication Date: 2025-06-27BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311823727.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the process of organizational management, the existing technology is difficult to effectively solve the problems of poor universality and insufficient convenience in strategy allocation and generation.

Method used

By receiving policy requests initiated by the client, the real policy hash is determined in the cache according to the target policy identification, and the target policy is returned based on the real policy hash and historical policy hash, avoiding complex policy priority overlay operations.

Benefits of technology

The rapid and accurate determination of the target strategy is achieved, network traffic is reduced, transmission efficiency is optimized, and policy generation is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120218762A_ABST
    Figure CN120218762A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an intra-organization strategy generation method and device, equipment and a storage medium. The intra-organization strategy generation method comprises the following steps: receiving a strategy request initiated by a client, wherein the strategy request comprises a target strategy identifier and historical strategy hash; according to the target policy identifier, determining a corresponding real policy hash in a cache region; and returning a corresponding target policy to the client according to the real policy hash and the historical policy hash. According to the technical scheme of the embodiment of the invention, after the client initiates the policy request, the real policy hash is determined in the cache region according to the target policy identifier in the policy request, and then the corresponding target policy is locked according to the real policy hash and the historical policy hash and is returned to the client. Therefore, complex superposition operation of strategy priorities does not need to be carried out, rapid and accurate determination of the target strategy is achieved, meanwhile, network flow is reduced, and transmission efficiency is optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and more particularly, to a method, apparatus, device, and storage medium for generating policies within an organization. Background Art

[0002] Currently, with the development of computer technology, more and more enterprises manage permission policies through computer systems. However, within an organization's (enterprise, group, social organization, etc.) system, there are many management levels and many people to manage. For example, within an organizational system, there are several departments with hierarchical relationships; there are several end-users who belong to the departments; there are several end-devices that also belong to the departments. Then, there will be corresponding several enterprise policy items for the departments, users, and devices. For the distribution and generation of these enterprise policy items, administrators need to perform complex superposition operations on policy priorities, and the resulting results have poor generality and are not convenient enough. Summary of the Invention

[0003] Embodiments of this application provide a method, apparatus, device, and storage medium for generating policies within an organization, aiming to solve the problems of poor generality and inconvenience in the process of organizational management.

[0004] Other features and advantages of this application will become apparent through the following detailed description, or be learned in part through the practice of this application.

[0005] According to one aspect of the embodiments of this application, a method for generating policies within an organization is provided, including: receiving a policy request initiated by a client, where the policy request includes a target policy identifier and a historical policy hash; determining a corresponding real policy hash in a buffer according to the target policy identifier; and returning a corresponding target policy to the client according to the real policy hash and the historical policy hash.

[0006] In some embodiments of this application, the returning a corresponding target policy to the client according to the real policy hash and the historical policy hash specifically includes: comparing the real policy hash and the historical policy hash; if the real policy hash and the historical policy hash are the same, returning information indicating that the policy has not been updated to the client; if the real policy hash and the historical policy hash are different, returning the target policy corresponding to the real policy hash to the client.

[0007] In some embodiments of this application, the determining a corresponding real policy hash according to the target policy identifier specifically includes: looking up a corresponding policy hash in a buffer according to the target policy identifier; and using the corresponding policy hash as the real policy hash.

[0008] In some embodiments of the present application, the real policy hash includes a group policy hash and a normal policy hash. The step of looking up the corresponding policy hash in the buffer according to the target policy identifier specifically includes: looking up the corresponding group policy hash in the buffer according to the target policy identifier; if there is no corresponding group policy hash in the buffer, then looking up the corresponding normal policy hash.

[0009] In some embodiments of the present application, after determining the corresponding real policy hash according to the target policy identifier, the method for generating an in-organization policy further includes: if there is no corresponding real policy hash for the target policy identifier, then querying the corresponding target policy in the database; caching the target policy and associating the corresponding policy hash; returning the target policy to the client.

[0010] In some embodiments of the present application, the step of querying the corresponding target policy in the database specifically includes: querying whether there is a group policy in the database according to the target policy identifier; if there is a group policy, then using the group policy as the target policy; if there is no group policy, then obtaining the corresponding normal policy; using the normal policy as the target policy.

[0011] In some embodiments of the present application, the target policy identifier includes a department identifier, a device identifier, and a user identifier. The step of obtaining the corresponding normal policy specifically includes: obtaining the corresponding user policy according to the user identifier; obtaining the corresponding device policy according to the device identifier; obtaining the corresponding department policy according to the department identifier; fitting the user policy, the device policy, and the department policy to obtain the corresponding normal policy.

[0012] In some embodiments of the present application, the step of caching the target policy and associating the corresponding policy hash specifically includes: determining the policy hash corresponding to the target policy according to the target policy; setting a target cache according to the policy hash; setting an associated key value for the target policy.

[0013] According to one aspect of the embodiments of the present application, there is provided an in-organization policy generation device, including: a request receiving module, configured to receive a policy request initiated by a client, where the policy request includes a target policy identifier and a historical policy hash; a hash determination module, configured to determine a corresponding real policy hash according to the target policy identifier; and a policy return module, configured to return a corresponding target policy to the client according to the real policy hash and the historical policy hash.

[0014] In some embodiments of the present application, the policy return module specifically includes: a hash comparison sub-module for comparing the real policy hash and the historical policy hash; a first return sub-module for returning information that the policy has not been updated to the client if the real policy hash is the same as the historical policy hash; and a second return sub-module for returning the target policy corresponding to the real policy hash to the client if the real policy hash is different from the historical policy hash.

[0015] In some embodiments of the present application, the hash determination module specifically includes: a hash lookup sub-module for looking up the corresponding policy hash in the buffer according to the target policy identifier; and a hash determination sub-module for using the corresponding policy hash as the real policy hash.

[0016] In some embodiments of the present application, the real policy hash includes a group policy hash and a general policy hash. The hash lookup sub-module specifically includes: a first hash lookup unit for looking up the corresponding group policy hash in the buffer according to the target policy identifier; and a second hash lookup unit for looking up the corresponding general policy hash if there is no corresponding group policy hash in the buffer.

[0017] In some embodiments of the present application, the in-organization policy generation device further includes: a policy lookup module for querying the corresponding target policy in the database if there is no corresponding real policy hash for the target policy identifier; a policy caching module for caching the target policy and associating the corresponding policy hash; and a policy sending module for returning the target policy to the client.

[0018] In some embodiments of the present application, the policy lookup module specifically includes: a first policy lookup sub-module for querying in the database whether there is a group policy according to the target policy identifier; a first policy determination sub-module for using the group policy as the target policy if there is a group policy; a second policy lookup sub-module for obtaining the corresponding general policy if there is no group policy; and a second policy determination sub-module for using the general policy as the target policy.

[0019] In some embodiments of the present application, the target policy identifier includes a department identifier, a device identifier, and a user identifier. The second policy lookup sub-module specifically includes: a user policy unit for obtaining the corresponding user policy according to the user identifier; a device policy unit for obtaining the corresponding device policy according to the device identifier; a department policy unit for obtaining the corresponding department policy according to the department identifier; and a policy fitting unit for fitting the user policy, the device policy, and the department policy to obtain the corresponding general policy.

[0020] In some embodiments of the present application, the policy cache module specifically includes: a policy hash sub-module, configured to determine a policy hash corresponding to the target policy according to the target policy; a cache setting sub-module, configured to set a target cache according to the policy hash; and an associated key-value sub-module, configured to set an associated key-value for the target policy.

[0021] According to one aspect of the embodiments of the present application, there is provided a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the method for generating an in-organization policy as described in the above embodiments.

[0022] According to one aspect of the embodiments of the present application, there is provided an electronic device, including: one or more processors; a storage device, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the method for generating an in-organization policy as described in the above embodiments.

[0023] In the technical solution provided by some embodiments of the present application, after a policy request is initiated by a client, a true policy hash is determined in a cache area according to a target policy identifier in the policy request, and then the corresponding target policy is locked according to the true policy hash and a historical policy hash and returned to the client, so that complex superposition operations of policy priorities do not need to be performed, the target policy can be determined quickly and accurately, at the same time, network traffic is reduced, and transmission efficiency is optimized.

[0024] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application. Obviously, the accompanying drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts. In the drawings:

[0026] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solution of the embodiments of the present application can be applied is shown.

[0027] Figure 2 A flowchart showing the process of a method for generating an in-organization policy provided by an embodiment of the present application is shown.

[0028] Figure 3 Shows according to Figure 2 A specific implementation flowchart of step S200 in the method for generating an in-organization policy shown in the corresponding embodiment is shown.

[0029] Figure 4 shows another flowchart of the method for generating in-organization policies according to Figure 2 the corresponding embodiment.

[0030] Figure 5 shows one specific implementation flowchart of step S400 in the method for generating in-organization policies according to Figure 4 the corresponding embodiment.

[0031] Figure 6 shows a policy management interface diagram provided by an embodiment of the present application.

[0032] Figure 7 shows a structural schematic diagram of an in-organization policy generation device provided by an embodiment of the present application.

[0033] Figure 8 shows a structural schematic diagram of a computer system of an electronic device suitable for implementing an embodiment of the present application. Detailed implementation manners

[0034] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.

[0035] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will recognize that the technical solutions of the present application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be employed. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.

[0036] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0037] The flowcharts shown in the accompanying drawings are merely illustrative and not necessarily inclusive of all content and operations / steps, nor are they necessarily to be executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined. Therefore, the actual execution order may change according to the actual situation.

[0038] Figure 1 The schematic diagram shows an exemplary system architecture to which the technical solution of the embodiment of the present application can be applied.

[0039] As Figure 1 shown, the system architecture may include terminal devices (such as Figure 1 one or more of the smart phone 101, tablet computer 102, and portable computer 103 shown in

[0040] It should be understood that Figure 1 the number of terminal devices, networks, and servers in

[0041] is merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. For example, the server 105 can be a server cluster composed of multiple servers, etc.

[0042] It should be noted that the method for generating an in-organization policy provided in the embodiment of the present application is generally executed by the server 105. Correspondingly, the in-organization policy generation device is generally set in the server 105. However, in other embodiments of the present application, the terminal device can also have a similar function as the server, so as to execute the in-organization policy generation solution provided in the embodiment of the present application.

[0043] The implementation details of the technical solution of the embodiment of the present application are elaborated in detail below:

[0044] Figure 2The flowchart of the in-organization policy generation method according to an embodiment of the present application is shown. The in-organization policy generation method can be executed by a server, which can be the Figure 1 server shown in. Refer to Figure 2 As shown, the in-organization policy generation method at least includes:

[0045] Step S100: Receive a policy request initiated by a client. The policy request includes a target policy identifier and a historical policy hash.

[0046] Step S200: Determine the corresponding real policy hash in the buffer according to the target policy identifier.

[0047] Step S300: Return the corresponding target policy to the client according to the real policy hash and the historical policy hash.

[0048] In the embodiment of the present application, after the client initiates a policy request, the real policy hash is determined in the buffer according to the target policy identifier in the policy request, and then the corresponding target policy is locked according to the real policy hash and the historical policy hash and returned to the client. There is no need to perform complex superposition operations on policy priorities, achieving fast and accurate determination of the target policy. At the same time, network traffic is reduced and transmission efficiency is optimized.

[0049] In step S100, first, the user initiates a policy request to the server through the client. When initiating the policy request, the target policy identifier such as the user's identifier, the client's identifier, and the identifiers of each hierarchical department to which the user and the client belong will be sent to the server together, so that the server can confirm the target policy according to the above target policy identifier. The target policy identifier can be an ID, an account, a label, or string information, etc. The present application does not make a limitation here.

[0050] In step S200, after obtaining the target policy identifier, first find the corresponding hash cache in the buffer, and then find the cache of the corresponding target policy according to the hash cache, avoiding obtaining a large amount of policy data for superposition operations, and then achieving the purpose of quickly, efficiently, and accurately obtaining the target policy, reducing network traffic and optimizing transmission efficiency.

[0051] Specifically, in some embodiments, the specific implementation manner of step S200 can refer to Figure 3 . Figure 3 is Figure 2 the detailed description of step S200 in the in-organization policy generation method shown in the corresponding embodiment. In the in-organization policy generation method, step S200 may include the following steps:

[0052] Step S210: Search for the corresponding policy hash in the buffer according to the target policy identifier.

[0053] Step S220: Use the corresponding policy hash as the actual policy hash.

[0054] In the embodiments of the present application, first, search for the corresponding policy hash in the buffer according to the target policy identifier. If the corresponding policy hash is found, then this policy hash is the actual policy hash.

[0055] In step S210, since there are multiple target policy identifiers, and they respectively represent different levels, it is necessary to search for the corresponding policy hash in the buffer one by one in sequence.

[0056] Specifically, in some embodiments, the specific implementation manner of step S220 can refer to the following embodiments. This embodiment is based on Figure 3 the detailed description of step S220 in the method for generating in-organization policies shown in the corresponding embodiment. In the method for generating in-organization policies, the actual policy hash includes a group policy hash and a general policy hash. Step S220 may include the following steps:

[0057] Search for the corresponding group policy hash in the buffer according to the target policy identifier.

[0058] If there is no corresponding group policy hash in the buffer, then search for the corresponding general policy hash.

[0059] In the embodiments of the present application, first, it is necessary to determine whether there is a corresponding group policy hash in the buffer according to the target policy identifier. The group policy hash corresponds to a group policy. The group policy is the policy with the highest priority. One group policy corresponds to one virtual group. This virtual group may not belong to any department, and the users or devices included therein may come from different departments. When a user or device is assigned to a virtual group, its control policy is only related to the virtual group where it is located. The group policy is mainly used to configure a set of policies for some special user groups with multiple positions in the enterprise, such as the leaders of each department, the leaders of branch companies, and key devices, etc. The group policy has the highest priority.

[0060] If there is no group policy hash in the buffer, then further search for the general policy with a lower priority. When searching for the general policy, it is necessary to comprehensively determine according to each target policy identifier.

[0061] In step S220, on the premise that the corresponding policy hash is found, the corresponding policy hash can be directly used as the actual policy hash.

[0062] In some other embodiments of the present application, if the corresponding policy hash cannot be found in the buffer, there is no real policy hash, and other methods need to be used to determine the target policy. Specifically, please refer to Figure 4 After step S200, the method for generating the in-organization policy may further include:

[0063] Step S400, if there is no corresponding real policy hash for the target policy identifier, query the corresponding target policy in the database.

[0064] Step S500, cache the target policy and associate the corresponding policy hash.

[0065] Step S600, return the target policy to the client.

[0066] In the embodiments of the present application, if the corresponding policy hash cannot be found in the buffer, there is no real policy hash, which proves that the corresponding target policy is not cached in the buffer. At this time, the target policy needs to be obtained from the database, and then the target policy is cached to generate a policy hash so that the client can directly obtain the target policy cache from the cache in the subsequent process.

[0067] In step S400, if the corresponding policy hash cannot be found in the buffer, there is no real policy hash, which proves that the corresponding target policy is not cached in the buffer. At this time, the policy needs to be obtained from the database and calculated to determine the corresponding target policy.

[0068] Specifically, in some embodiments, the specific implementation manner of step S400 can be referred to Figure 5 . Figure 5 It is based on Figure 4 The details of step S400 in the method for generating the in-organization policy shown in the corresponding embodiment. In the method for generating the in-organization policy, step S400 may include the following steps:

[0069] Step S410, query whether there is a group policy in the database according to the target policy identifier.

[0070] Step S420, if there is a group policy, use the group policy as the target policy.

[0071] Step S430, if there is no group policy, obtain the corresponding general policy.

[0072] Step S440, use the general policy as the target policy.

[0073] In an embodiment of the present application, consistent with the idea of querying for a target policy in the buffer, first, according to the target policy identifier, it is determined whether there is a corresponding group policy in the database. If there is a group policy in the database, the group policy is used as the target policy. If there is no group policy, then the general policy is searched for and used as the target policy.

[0074] In step S410, first, according to the target policy identifier, it is queried in the database whether there is a group policy.

[0075] In step S420, if there is a group policy in the database, the group policy is directly used as the target policy, and the policies belonging to its department, the devices used, and the personal exclusive policies are no longer searched for.

[0076] In step S430, if there is no group policy in the database, it is necessary to determine the policies corresponding to the user, the device, and their departments one by one, and then obtain a complete general policy.

[0077] Specifically, in some embodiments, the specific implementation manner of step S430 can refer to the following embodiments. This embodiment is a detailed description of step S430 in the method for generating an in-organization policy shown in the corresponding embodiment. In the method for generating an in-organization policy, the target policy identifier includes a department identifier, a device identifier, and a user identifier. Step S200 may include the following steps: Figure 3 According to the user identifier, obtain the corresponding user policy.

[0078] According to the device identifier, obtain the corresponding device policy.

[0079] According to the department identifier, obtain the corresponding department policy.

[0080] According to the department identifier, obtain the corresponding department policy.

[0081] Fit the user policy, the device policy, and the department policy to obtain the corresponding general policy.

[0082] In an embodiment of the present application, first, the corresponding user policy, device policy, and department policy are determined according to the department identifier, the device identifier, and the user identifier respectively. Then, the above policies are fitted to obtain the corresponding general policy. When fitting, the priorities of the user policy, the device policy, and the department policy decrease one by one, with the user policy having the highest priority and the department policy having the lowest priority. It should be noted that among the department policies, the priority of the policy items configured by the lower-level departments is higher than that of the same policy items configured by the higher-level departments.

[0083] The following will illustrate the idea of policy fitting. In one embodiment, user U1 belongs to department D1.1.1.1. The user has configured policy item P1 and set it to XU5. The user's direct department D1.1.1.1 has configured policy item P2 with a policy value of YD4. The superior department D1.1.1 of department D1.1.1.1 has configured policy items P1 and P3. Among them, the priority of P1 is lower than that of the policy item of user U1 and is ignored. The superior department D1.1 of department D1.1.1 has configured policy item P2, and its priority is lower than that of the P2 policy of department D1.1.1.1 and is ignored. The superior department D1 (which is also the root department) of department D1.1 has configured policy item P1, and its priority is lower than that of the policy item of department D1.1.1 and is ignored.

[0084] Then the final general policy of user U1 is: {P1: XU5, P2: YD4, P3: ZD3}; where P1 is the policy directly defined on the user and is therefore called the custom policy; P2 is inherited from department D1.1.1.1; P3 is inherited from department D1.1.1.

[0085] Meanwhile, in some embodiments, as Figure 6 shown, in the policy management interface of the user, it will clearly show the administrator whether the configuration of each policy item is custom or inherited from the superior organization, what you see is what you get, which is convenient for the administrator to manage the policy.

[0086] In some embodiments of the present application, user policies, device policies, and department policies can be obtained one by one in the order of priority or simultaneously. When performing policy fitting, as shown in the above embodiments, it will be based on the user policy, and after comparison, the device policy and department policy will be superimposed one by one in the order of priority to obtain the corresponding general policy.

[0087] In step S440, after obtaining the general policy, the general policy can be returned to the client as the target policy.

[0088] In step S500, after obtaining the target policy, on the one hand, step S600 can be executed to return the full amount of the target policy to the client so that the client can execute the policy. On the other hand, since the corresponding target policy is not cached in the buffer, at this time, it is necessary to cache the target policy to generate a policy hash so that the client can directly obtain the target policy cache from the cache in the subsequent process.

[0089] Specifically, in some embodiments, the specific implementation manner of step S500 can refer to the following embodiments. This embodiment is a detailed description of step S500 in the method for generating intra-organization policies corresponding to the Figure 4 corresponding embodiment. In the method for generating intra-organization policies, step S500 may include the following steps:

[0090] Determine a policy hash corresponding to the target policy according to the target policy.

[0091] Set a target cache according to the policy hash.

[0092] Set an associated key-value for the target policy.

[0093] In an embodiment of the present application, first obtain a policy hash corresponding to the target policy according to the target policy, and then set a target cache according to the policy hash. The target cache may be a pb cache to cache the policy hash and the target policy in an associated manner. Then, based on the policy hash, generate key-value pairs in the data structure of a hashmap, where the primary key contains the corresponding target identifier and the value is the hash value.

[0094] For example, a key-value pair has policy_{organization identifier}_hset as the key, where the organization identifier represents the organization identifier, and hashmap as the value. There are two types of keys in this hashmap: one is in the format of pb_gp_{o identifier}_{u identifier}_{d identifier} for group policies; the other is in the format of pb_user_{identifier} or pb_device_{identifier} for ordinary policies. The value of the hashmap is policy_ver_xxx, that is, the policy hash.

[0095] After generating the key-value pairs, a hash table can be formed according to department classification. The policies of devices and users under each department form a hash table with the department to which they belong as the key.

[0096] When the department policy changes, delete the corresponding cache key, and all the policy caches of devices and users cached in the hash table under this key will be deleted.

[0097] Under the policy of the inheritance mode, when editing a policy in any department, it may affect the policies of that department and all its descendant departments, as well as the policies of users and devices under that department and its descendant departments. By forming a hash table with the department to which they belong as the key, the relevant caches can be quickly cleared, thereby realizing real-time update of the cache.

[0098] In step S600, after obtaining the target policy, return the full amount of the target policy to the client so that the client can execute the policy. When returning the target policy to the client, the policy hash obtained in step S500 will also be returned to the client to enable the client to update the storage. When the client needs to obtain the target policy again, it needs to send the policy hash together with the target policy identifier to the server.

[0099] In step S300, the real policy hash is compared with the historical policy hash to determine whether the target policy of the client has changed, and further determine the result returned to the client.

[0100] Specifically, in some embodiments, the specific implementation manner of step S300 can refer to the following embodiments. This embodiment is based on Figure 2 the detailed description of step S300 in the intra-organization policy generation method shown in the corresponding embodiment. In the intra-organization policy generation method, step S300 may include the following steps:

[0101] Compare the real policy hash and the historical policy hash.

[0102] If the real policy hash and the historical policy hash are the same, return information that the policy has not been updated to the client.

[0103] If the real policy hash and the historical policy hash are different, return the target policy corresponding to the real policy hash to the client.

[0104] In the embodiments of the present application, when the real policy hash and the historical policy hash are the same, it proves that the target policy corresponding to the client has not changed. At this time, an empty policy is directly returned for the client user to cache locally, so as to reduce network traffic. Specifically, the buffer returns a null value to the interface, and the interface responds to the null value and returns information that the policy has not been updated to the client. This information can be sent in the form of an empty policy. When the real policy hash and the historical policy hash are different, it proves that the target policy corresponding to the client has changed. At this time, it is necessary to reconfirm the corresponding target policy based on the real policy hash, and then return the target policy to the client, and at the same time, the real policy hash should also be returned to the client for storage. Specifically, since there are two types of keys in the hashmap: one is the format of the group policy pb_gp_{o identifier}_{u identifier}_{d identifier}; the other is the format of the ordinary policy, pb_user_{identifier} or pb_device_{identifier}, according to the real policy hash, the corresponding key is found, and according to the key, its policy form can be known, and then the corresponding target policy is found and returned to the client.

[0105] The following introduces the device embodiments of the present application, which can be used to execute the intra-organization policy generation method in the above embodiments of the present application. For the details not disclosed in the device embodiments of the present application, please refer to the embodiments of the intra-organization policy generation method above of the present application.

[0106] Figure 7 shows a block diagram of an intra-organization policy generation device according to an embodiment of the present application. Refer to Figure 7As shown, the in-organization policy generation device 700 according to an embodiment of the present application includes: a request receiving module 710, a hash determination module 720, and a policy return module 730.

[0107] Among them, the request receiving module 710 is used to receive a policy request initiated by a client, and the policy request includes a target policy identifier and a historical policy hash; the hash determination module 720 is used to determine a corresponding real policy hash according to the target policy identifier; the policy return module 730 is used to return a corresponding target policy to the client according to the real policy hash and the historical policy hash.

[0108] In some embodiments of the present application, the policy return module specifically includes: a hash comparison sub-module, used to compare the real policy hash and the historical policy hash; a first return sub-module, used to return information that the policy has not been updated to the client if the real policy hash and the historical policy hash are consistent; a second return sub-module, used to return the target policy corresponding to the real policy hash to the client if the real policy hash and the historical policy hash are inconsistent.

[0109] In some embodiments of the present application, the hash determination module specifically includes: a hash search sub-module, used to search for a corresponding policy hash in the buffer according to the target policy identifier; a hash determination sub-module, used to use the corresponding policy hash as the real policy hash.

[0110] In some embodiments of the present application, the real policy hash includes a group policy hash and a general policy hash, and the hash search sub-module specifically includes: a first hash search unit, used to search for a corresponding group policy hash in the buffer according to the target policy identifier; a second hash search unit, used to search for a corresponding general policy hash if there is no corresponding group policy hash in the buffer.

[0111] In some embodiments of the present application, the in-organization policy generation device further includes: a policy search module, used to query the corresponding target policy in the database if there is no corresponding real policy hash for the target policy identifier; a policy cache module, used to cache the target policy and associate the corresponding policy hash; a policy sending module, used to return the target policy to the client.

[0112] In some embodiments of the present application, the policy lookup module specifically includes: a first policy lookup sub-module, configured to query in the database whether there is a group policy according to the target policy identifier; a first policy determination sub-module, configured to use the group policy as the target policy if there is a group policy; a second policy lookup sub-module, configured to obtain the corresponding general policy if there is no group policy; and a second policy determination sub-module, configured to use the general policy as the target policy.

[0113] In some embodiments of the present application, the target policy identifier includes a department identifier, a device identifier, and a user identifier. The second policy lookup sub-module specifically includes: a user policy unit, configured to obtain the corresponding user policy according to the user identifier; a device policy unit, configured to obtain the corresponding device policy according to the device identifier; a department policy unit, configured to obtain the corresponding department policy according to the department identifier; and a policy fitting unit, configured to fit the user policy, the device policy, and the department policy to obtain the corresponding general policy.

[0114] In some embodiments of the present application, the policy cache module specifically includes: a policy hash sub-module, configured to determine the policy hash corresponding to the target policy according to the target policy; a cache setting sub-module, configured to set a target cache according to the policy hash; and an associated key value sub-module, configured to set an associated key value for the target policy.

[0115] In the embodiments of the present application, after a policy request is initiated by a client, the real policy hash is determined in the cache area according to the target policy identifier in the policy request, and then the corresponding target policy is locked according to the real policy hash and the historical policy hash and returned to the client. There is no need to perform complex superposition operations on policy priorities, realizing the fast and accurate determination of the target policy. At the same time, network traffic is reduced and transmission efficiency is optimized.

[0116] Figure 8 The structure diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application is shown.

[0117] It should be noted that Figure 8 The computer system of the electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0118] Such as Figure 8As shown, the computer system includes a Central Processing Unit (CPU) 1801, which can perform various appropriate actions and processes according to a program stored in a Read-Only Memory (ROM) 1802 or a program loaded from a storage section 1808 into a Random Access Memory (RAM) 1803, such as executing the method described in the above embodiments. In the RAM 1803, various programs and data required for system operation are also stored. The CPU 1801, ROM 1802, and RAM 1803 are connected to each other via a bus 1804. An Input / Output (I / O) interface 1805 is also connected to the bus 1804.

[0119] The following components are connected to the I / O interface 1805: an input section 1806 including a keyboard, a mouse, etc.; an output section 1807 including, for example, a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), etc. and a speaker, etc.; a storage section 1808 including a hard disk, etc.; and a communication section 1809 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1809 performs communication processing via a network such as the Internet. A drive 1810 is also connected to the I / O interface 1805 as needed. A removable medium 1811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1810 as needed so that a computer program read from it can be installed into the storage section 1808 as needed.

[0120] Specifically, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1809, and / or installed from the removable medium 1811. When the computer program is executed by a Central Processing Unit (CPU) 1801, various functions defined in the system of the present application are executed.

[0121] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable computer program is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0122] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0123] The units involved in the embodiments described in this application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not, in some cases, constitute a limitation on the unit itself.

[0124] As another aspect, this application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiments; or may exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the methods described in the above embodiments.

[0125] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0126] From the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented in software or in a manner combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the methods according to the embodiments of this application.

[0127] After considering the specification and practicing the embodiments disclosed herein, those skilled in the art will readily conceive of other embodiments of this application. This application is intended to cover any variations, uses, or adaptations of this application, which follow the general principles of this application and include known common knowledge or conventional technical means in the technical field not disclosed in this application.

[0128] It should be understood that this application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is only limited by the appended claims.

Claims

1. A method for generating an in-organization strategy, characterized in that, The method for generating in-organization policies includes: Receiving a policy request initiated by a client, where the policy request includes a target policy identifier and a historical policy hash; Determining a corresponding real policy hash in a buffer according to the target policy identifier; Returning a corresponding target policy to the client according to the real policy hash and the historical policy hash.

2. The method for generating an in-organization policy according to claim 1, wherein The returning a corresponding target policy to the client according to the real policy hash and the historical policy hash specifically includes: Comparing the real policy hash and the historical policy hash; If the real policy hash and the historical policy hash are the same, returning information indicating that the policy has not been updated to the client; If the real policy hash and the historical policy hash are different, returning the target policy corresponding to the real policy hash to the client.

3. The method for generating an in-organization policy according to claim 1, wherein, The determining a corresponding real policy hash according to the target policy identifier specifically includes: Searching for a corresponding policy hash in the buffer according to the target policy identifier; Taking the corresponding policy hash as the real policy hash.

4. The method for generating an in-organization policy according to claim 3, wherein The real policy hash includes a group policy hash and a general policy hash. The searching for a corresponding policy hash in the buffer according to the target policy identifier specifically includes: Searching for a corresponding group policy hash in the buffer according to the target policy identifier; If there is no corresponding group policy hash in the buffer, searching for a corresponding general policy hash.

5. The method for generating an in-organization policy according to claim 1, wherein After determining a corresponding real policy hash according to the target policy identifier, the method for generating in-organization policies further includes: If there is no corresponding real policy hash for the target policy identifier, querying for a corresponding target policy in a database; Caching the target policy and associating a corresponding policy hash; Returning the target policy to the client.

6. The method for generating an in-organization policy according to claim 5, wherein, The querying for a corresponding target policy in the database specifically includes: Querying in the database whether there is a group policy according to the target policy identifier; If there is a group policy, taking the group policy as the target policy; If there is no group policy, obtaining a corresponding general policy; Taking the general policy as the target policy.

7. The method for generating an in-organization policy according to claim 6, wherein The target policy identifier includes a department identifier, a device identifier, and a user identifier. The obtaining a corresponding general policy specifically includes: Obtaining a corresponding user policy according to the user identifier; Obtaining a corresponding device policy according to the device identifier; Obtaining a corresponding department policy according to the department identifier; Fitting the user policy, the device policy, and the department policy to obtain a corresponding general policy.

8. An in-organization policy generation device, characterized in that, The in-organization policy generation device includes: A request receiving module, configured to receive a policy request initiated by a client, where the policy request includes a target policy identifier and a historical policy hash; A hash determining module, configured to determine a corresponding real policy hash according to the target policy identifier; A policy returning module, configured to return a corresponding target policy to the client according to the real policy hash and the historical policy hash.

9. A computer-readable medium having a computer program stored thereon, characterized in that, The computer program, when executed by a processor, implements the method for generating in-organization policies according to any one of claims 1 to 7.

10. An electronic device, characterized in that, Includes: One or more processors; A storage device for storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement the method for generating an in-organization policy according to any one of claims 1 to 7.