Network account process permission level-to-level management method and device and storage medium
By building an account management policy table and dynamically adjusting process permissions, the flexibility and security issues of account management in the ONU network system are solved, and precise permission control and system stability are achieved.
Patent Information
- Application Number
- CN202510639953.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-08-08
AI Technical Summary
Account management in the existing ONU network system lacks flexibility, unclear permission definition, excessive core process permissions and difficult to dynamically adjust, resulting in insufficient system security and adaptability.
By building an account management policy table, obtain the identification data of the application process, dynamically adjust its operation permissions, and perform error detection and processing to achieve hierarchical management and precise control.
Improve system security and flexibility, meet different customer groups and business needs, reduce system risks and abuse of permissions, and improve response speed.
Smart Images

Figure CN120455100A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of access network communication technology, and in particular to a method, device and storage medium for hierarchical management of network account process permissions. Background Art
[0002] With the continuous development of network technology, the application of ONUs (Optical Network Units) in network architectures is becoming increasingly widespread. In the use of ONU network systems, the management of login accounts and the control of permissions for related processes play a vital role in ensuring system security and meeting different user needs and business scenarios.
[0003] Traditional account management and permission control methods are often relatively simple and difficult to flexibly adapt to diverse customer needs and complex operation scenarios. They also have the following problems:
[0004] (1) Lack of flexibility in account management: Traditional ONU network system account management models typically use a fixed permission allocation method, which is difficult to adapt to the diverse needs of different customers and complex and changing operation scenarios. For example, in some enterprise network environments, ordinary employees, department heads, and IT operations personnel have completely different operational requirements for ONU network systems. Existing technologies cannot easily provide customized account permission settings for different roles.
[0005] (2) Account authority confusion: Existing technologies may have unclear account authority definitions, which can easily lead to authority abuse or misoperation. For example, some low-level accounts may accidentally obtain high-level operation permissions due to improper permission settings, or the permissions of multiple accounts may interfere with each other, affecting the normal operation of the system and data security.
[0006] (3) Excessive privileges of core processes: In traditional network systems, core processes often run with root privileges for a long time, which poses a huge security risk. Once a core process is attacked maliciously or exploited due to a software vulnerability, due to its highest privileges, the attacker may cause devastating damage to the entire system, including tampering with system configurations and stealing sensitive data.
[0007] (4) Process permissions are difficult to adjust dynamically: Existing technologies lack an effective dynamic mechanism for adjusting process permissions. Changing process permissions often requires restarting the system or performing complex manual configurations, which is extremely inconvenient in practical applications, especially for scenarios that require real-time response to business changes. Summary of the Invention
[0008] In view of this, the present invention provides a method, device and storage medium for hierarchical management of network account process permissions, aiming to solve the problems existing in account management and permission control in existing network systems.
[0009] Specifically, the present invention is achieved through the following technical solutions:
[0010] According to a first aspect of the present invention, a method for hierarchical management of network account process permissions is provided, the method comprising the steps of:
[0011] Get the account management policy table;
[0012] Get the application process;
[0013] Obtaining identification data corresponding to the application process in the account management policy table;
[0014] Adjusting the running permissions of the application process according to the identification data;
[0015] The application process is run according to the execution permission.
[0016] Optionally, obtaining the account management policy table includes the steps of:
[0017] Get the network account type;
[0018] Obtaining the operation scenarios corresponding to each of the network account types;
[0019] Constructing an account management policy table template according to the network account type and the corresponding operation scenario;
[0020] Obtain information parameters corresponding to the network account type and the corresponding operation scenario;
[0021] Write each of the information parameters into the account management policy table template.
[0022] Optionally, the obtaining of information parameters corresponding to the network account type and the corresponding operation scenario includes the steps of:
[0023] Obtaining the network account type and user identification information corresponding to the corresponding operation scenario;
[0024] Obtaining the network account type and the group identification information corresponding to the corresponding operation scenario;
[0025] Obtain the network account type and process permission information corresponding to the corresponding operation scenario.
[0026] Optionally, obtaining identification data corresponding to the application process in the account management policy table includes the steps of:
[0027] Obtaining account data corresponding to the application process;
[0028] Obtaining user identification information corresponding to the application process;
[0029] Obtain group identification information corresponding to the application process.
[0030] Optionally, adjusting the execution permission of the application process according to the identification data includes the steps of:
[0031] Obtaining process permission information corresponding to the identification data in the account management policy table;
[0032] Adjusting the running permissions of the application process according to the process permission information;
[0033] An error detection process is performed on the adjustment of the running permissions of the application process.
[0034] Optionally, obtaining the process permission information corresponding to the identification data in the account management policy table includes the steps of:
[0035] Obtaining account data, user identification information, and group identification information from the identification data;
[0036] Determine process permission information corresponding to the account data, the user identification information, and the group identification information in the account management policy table.
[0037] Optionally, the error detection process for adjusting the running permissions of the application process includes the steps of:
[0038] Determining whether an error occurs during loading of the account management policy table;
[0039] If so, perform a rollback operation and log an error message;
[0040] If not, determine whether an error occurs during the file writing process;
[0041] If so, perform a rollback operation and log an error message;
[0042] If not, determine whether an error occurs during the permission modification operation;
[0043] If so, switch to the backup permission mode;
[0044] If not, keep the application process in the current execution permission.
[0045] According to a second aspect of the present invention, there is provided a network account process authority hierarchical management device, comprising:
[0046] Policy table acquisition module, used to obtain the account management policy table;
[0047] Process acquisition module, used to obtain application processes;
[0048] A data acquisition module, configured to acquire identification data corresponding to the application process from the account management policy table;
[0049] An adjustment module, configured to adjust the running permissions of the application process according to the identification data;
[0050] A running module is used to run the application process according to the running permission.
[0051] According to a third aspect of the present invention, there is provided an electronic device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any of the aforementioned methods when executing the program.
[0052] According to a fourth aspect of the present invention, there is provided a storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the steps of any one of the aforementioned methods.
[0053] The technical solution provided by the present invention brings at least the following beneficial effects:
[0054] The present application provides a method, device and storage medium for hierarchical management of network account process permissions. By introducing innovative features such as hierarchical management strategies, dynamic adjustment mechanisms, error detection and processing, and multi-scenario adaptability, it can effectively manage network login accounts in a hierarchical manner and accurately control the permissions of core processes, thereby effectively solving the problems existing in account management and permission control in existing network systems, improving the security, flexibility and adaptability of the system, and meeting the diverse requirements of different customer groups and business needs. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0056] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0057] Figure 1 A flowchart of a method for hierarchical management of network account process permissions provided by an embodiment of the present invention;
[0058] Figure 2 A schematic diagram of the structure of a network account process authority hierarchical management device provided by an embodiment of the present invention;
[0059] Figure 3 A schematic structural diagram of an electronic device provided by an embodiment of the present invention;
[0060] Figure 4 A schematic structural diagram of a storage medium provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0061] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0062] Figure 1 The present invention schematically illustrates a flow chart of a method for hierarchical management of network account process permissions applicable to an embodiment of the present invention.
[0063] See also Figure 1 The embodiment of the present invention provides a method for hierarchical management of network account process permissions. The method can be applied to electronic devices such as PCs, servers, and terminals. The method may include the following steps:
[0064] S1: Get the account management policy table;
[0065] Exemplarily, the step of obtaining the account management policy table includes the following steps:
[0066] Get the network account type;
[0067] Obtaining the operation scenarios corresponding to each of the network account types;
[0068] Constructing an account management policy table template according to the network account type and the corresponding operation scenario;
[0069] Obtain information parameters corresponding to the network account type and the corresponding operation scenario;
[0070] Write each of the information parameters into the account management policy table template.
[0071] In the embodiment of the present application, first, based on the network account type of the ONU network system and the various operation scenarios that each network account type may face (such as ordinary user access, administrator configuration, special maintenance tasks, etc.), these templates should comprehensively cover the information parameters required by different account types in various scenarios, and write the information parameters into the account management policy table template for subsequent use.
[0072] Exemplarily, the obtaining of the network account type and the information parameters corresponding to the corresponding operation scenario includes the steps of:
[0073] Obtaining the network account type and user identification information corresponding to the corresponding operation scenario;
[0074] Obtaining the network account type and the group identification information corresponding to the corresponding operation scenario;
[0075] Obtain the network account type and process permission information corresponding to the corresponding operation scenario.
[0076] In an embodiment of the present application, the information parameters specifically include the network account type and the user identification information (UID), group identification information (GID) and related process permission information corresponding to the corresponding operation scenario.
[0077] Exemplarily, the design and construction process includes:
[0078] 1. Account Type and Operation Scenario Classification
[0079] 1. Classify network account types
[0080] Based on the actual needs of the ONU network system, account types are divided into: ordinary user account (basic access rights), administrator account (system configuration rights), maintenance account (special task rights), etc.
[0081] 2. Define the operation scenario
[0082] Operation scenarios associated with account types, for example:
[0083] Ordinary user account: daily access, data query;
[0084] Administrator account: policy configuration, permission allocation;
[0085] Maintenance account: system debugging, log auditing.
[0086] 2. Structural design of strategy table template
[0087] 1. Template field definition
[0088] The core fields include:
[0089] Account type (such as ordinary user, administrator);
[0090] Operational scenarios (such as access, configuration, and maintenance);
[0091] Information parameters (UID, GID, process permissions);
[0092] Policy rules (such as password complexity, lockout threshold).
[0093] 2. Permission mapping rules
[0094] Dynamically bind information parameters to operation scenarios:
[0095] User ID (UID): uniquely identifies the user and is used for permission verification;
[0096] Group ID (GID): Associated with user group permissions (e.g., maintenance group can execute specific processes);
[0097] Process permissions: Limit the executable commands or services (for example, only administrators are allowed to start configuration scripts).
[0098] 3. Automatic Acquisition and Filling of Information Parameters
[0099] 1. Parameter source
[0100] System tool integration:
[0101] Use Windows secpol.msc or PowerShell commands to obtain password policies and account lockout thresholds;
[0102] Use SQL to query the MySQL user table to obtain the permission fields.
[0103] Custom script:
[0104] Combine C# to call the WMI interface or Python script to parse system logs and extract UID / GID and process permission information.
[0105] 2. Parameter standardization
[0106] Write the obtained parameters according to the template field format, for example:
[0107] Password policy field: minimum length = 8, complexity = enabled;
[0108] Process privilege field: restricts ordinary users from executing sudo commands (similar to the Update_priv field control of MySQL).
[0109] 4. Template Verification and Deployment
[0110] 1. Testing and Optimization
[0111] Scenario simulation test: Verify whether the permission restrictions of different account types in corresponding operation scenarios are effective (for example, whether the administrator account can modify the configuration and whether the ordinary account is rejected).
[0112] Policy conflict detection: Checks the compatibility of group policies with template parameters.
[0113] 2. Deployment method
[0114] Local deployment: Import policies through the Windows Group Policy Editor (gpmc.msc) or security templates;
[0115] Cloud synchronization: Combine with the CRM system or advertising platform API to achieve unified management of multi-account strategies.
[0116] 5. Dynamic Update and Maintenance
[0117] 1. Policy Iteration Mechanism
[0118] Regularly update templates based on audit logs, such as adjusting account lockout thresholds or adding new operation scenario permissions;
[0119] Use PowerShell scripts or MySQL GRANT / REVOKE statements to automate updates.
[0120] 2. Permission Revocation and Audit
[0121] Automatically disable the accounts of departing employees (refer to the CRM system process);
[0122] Record policy change logs to ensure traceability (similar to SQL system management policy auditing).
[0123] S2: Get the application process;
[0124] In the embodiment of the present application, the application process is a variety of application programs that can be started on the ONU network system.
[0125] S3: Obtaining identification data corresponding to the application process in the account management policy table;
[0126] Exemplarily, obtaining the identification data corresponding to the application process in the account management policy table includes the steps of:
[0127] Obtaining account data corresponding to the application process;
[0128] Obtaining user identification information corresponding to the application process;
[0129] Obtain group identification information corresponding to the application process.
[0130] In an embodiment of the present application, in the account management policy table, each account data, application process, user identification information, group identification information and running permissions are constructed into a one-to-one mapping relationship and stored in the account management policy table for subsequent use.
[0131] S4: adjusting the running permission of the application process according to the identification data;
[0132] Exemplarily, adjusting the execution permission of the application process according to the identification data includes the following steps:
[0133] Obtaining process permission information corresponding to the identification data in the account management policy table;
[0134] Adjusting the running permissions of the application process according to the process permission information;
[0135] An error detection process is performed on the adjustment of the running permissions of the application process.
[0136] In an embodiment of the present application, after the identification data has been obtained, the corresponding running permissions can be found based on the one-to-one mapping relationship between the identification data and the running permissions in the account management policy table, and the permissions of the application process can be adjusted based on the running permissions. An error detection process is also required during the adjustment process.
[0137] Exemplarily, obtaining the process permission information corresponding to the identification data in the account management policy table includes the steps of:
[0138] Obtaining account data, user identification information, and group identification information from the identification data;
[0139] Determine process permission information corresponding to the account data, the user identification information, and the group identification information in the account management policy table.
[0140] In this embodiment, during the initialization phase of the ONU network system startup, the system bootloader is responsible for writing the account information, along with the UID and GID information, from the policy table to the / etc / group and / etc / passwd files according to established file writing specifications before the core application process starts. Subsequently, when the core process starts and reaches the main function, the built-in policy reader module retrieves the corresponding UID and GID from the policy table and then calls the setuid and setgid functions to modify the application process's permissions.
[0141] Exemplarily, the error detection process for adjusting the running permissions of the application process includes the following steps:
[0142] Determining whether an error occurs during loading of the account management policy table;
[0143] If so, perform a rollback operation and log an error message;
[0144] If not, determine whether an error occurs during the file writing process;
[0145] If so, perform a rollback operation and log an error message;
[0146] If not, determine whether an error occurs during the permission modification operation;
[0147] If so, switch to the backup permission mode;
[0148] If not, keep the application process in the current execution permission.
[0149] In the embodiments of the present application, strict error detection and handling are required throughout the entire process of loading the account management policy table, writing files, and modifying the permissions of application processes to ensure system stability and reliability. For example, if an error occurs when writing to the / etc / group or / etc / passwd file, the operation can be rolled back and the error information can be recorded so that the system administrator can investigate and repair it; if an error occurs when calling the setuid or setgid function, the process can be terminated; if an error occurs during a permissions modification operation, a switch to an alternative permissions mode can be performed.
[0150] S5: Execute the application process according to the execution permission.
[0151] In an embodiment of the present application, the application process is run according to the permission settings in the selected policy table, thereby effectively limiting the permission scope of the core process.
[0152] In summary, the present invention provides a method for hierarchical management of network account process permissions. The principles are as follows:
[0153] 1. Account Management Policy Table: Build an account management policy table template that includes network account types, operation scenarios, and corresponding information parameters (user identification information, group identification information, and process permission information). Based on the actual network account type and operation scenario, these information parameters are written into the account management policy table template to form the final account management policy table.
[0154] 2. Permission Adjustment Mechanism: This mechanism obtains the account data, user identification information, and group identification information corresponding to the application process. It searches the account management policy table for the corresponding process permissions and adjusts the application process's running permissions accordingly. It also performs error detection during the permission adjustment process to ensure accuracy and system stability.
[0155] 3. Operation mechanism: Run the application process according to the adjusted operation permissions to ensure that the process performs operations within the prescribed permission range.
[0156] This method has the following effects:
[0157] 1. Improved system security: By hierarchically managing network accounts and precisely controlling the permissions of core processes, we effectively prevent abuse and misoperation, reducing the risk of malicious attacks. This reduces the security risks associated with core processes running with root permissions for extended periods of time, improving overall system security.
[0158] 2. Enhanced system flexibility: Account permissions can be flexibly adjusted to meet diverse requirements based on the needs of different customer groups and business scenarios. Dynamic adjustment of process permissions is supported without restarting the system or performing complex manual configuration, improving system responsiveness and flexibility.
[0159] 3. Optimize user experience: Provide customized account permission settings, allowing users to operate according to their actual needs, improving user experience.
[0160] like Figure 2 This application provides a network account process permission hierarchical management device, including:
[0161] A policy table acquisition module 10 is used to acquire an account management policy table;
[0162] The process acquisition module 20 is used to acquire the application process;
[0163] A data acquisition module 30 is used to obtain identification data corresponding to the application process from the account management policy table;
[0164] An adjustment module 40, configured to adjust the execution permission of the application process according to the identification data;
[0165] The running module 50 is configured to run the application process according to the running permission.
[0166] The network account process permission hierarchical management device provided in this application can execute the network account process permission hierarchical management method provided in the above steps.
[0167] It should be understood that the above-described specific embodiments of the present invention are merely illustrative or illustrative of the principles of the present invention and do not constitute limitations of the present invention. Therefore, any modifications, equivalent substitutions, improvements, etc. made without departing from the spirit and scope of the present invention should be included within the scope of protection of the present invention. In addition, the appended claims are intended to cover all variations and modifications that fall within the scope and metes and bounds of the appended claims, or equivalents thereof.
[0168] Reference below Figure 3 , which shows a schematic structural diagram of an electronic device 100 suitable for implementing an embodiment of the present disclosure. The electronic devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 3The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0169] like Figure 3 As shown, the electronic device 100 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 101, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 102 or a program loaded from a storage device 108 into a random access memory (RAM) 103. Various programs and data required for the operation of the electronic device 100 are also stored in the RAM 103. The processing device 101, the ROM 102, and the RAM 103 are connected to each other via a bus 104. An input / output (I / O) interface 105 is also connected to the bus 104.
[0170] Typically, the following devices may be connected to the I / O interface 105: an input device 106 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 107 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 108 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 109. The communication device 109 may allow the electronic device 100 to communicate with other devices wirelessly or by wire to exchange data. Although the figure shows the electronic device 100 with various devices, it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively.
[0171] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network via the communication device 109, or installed from the storage device 108, or installed from the ROM 102. When the computer program is executed by the processing device 101, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0172] Reference below Figure 4 , which shows a structural schematic diagram of a computer-readable storage medium suitable for implementing the embodiments of the present disclosure, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it can implement the network account process permission hierarchical management method as described in any of the above.
[0173] The present application also provides a computer program product, including a computer program / computer executable instructions, which, when executed by a processor of an electronic device, implements the steps of any of the aforementioned methods for hierarchical management of network account process permissions.
[0174] The present application provides a method, device, and storage medium for hierarchical management of network account process permissions, which can effectively manage network login accounts in a hierarchical manner and accurately control the permissions of core processes, thereby improving the security, flexibility, and adaptability of network systems in multiple application scenarios and meeting the diverse requirements of different customer groups and business needs.
[0175] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0176] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is intended to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A method for hierarchical management of network account process permissions, characterized in that: The method comprises the steps of: Get the account management policy table; Get the application process; Obtaining identification data corresponding to the application process in the account management policy table; Adjusting the running permissions of the application process according to the identification data; The application process is run according to the execution permission.
2. The method for hierarchical management of network account process permissions according to claim 1, characterized in that: The step of obtaining the account management policy table includes the following steps: Get the network account type; Obtaining the operation scenarios corresponding to each of the network account types; Constructing an account management policy table template according to the network account type and the corresponding operation scenario; Obtain information parameters corresponding to the network account type and the corresponding operation scenario; Write each of the information parameters into the account management policy table template.
3. The method for hierarchical management of network account process permissions according to claim 2, characterized in that: The step of obtaining the network account type and the information parameters corresponding to the corresponding operation scenario includes the following steps: Obtaining the network account type and the user identification information corresponding to the corresponding operation scenario; Obtaining the network account type and the group identification information corresponding to the corresponding operation scenario; Obtain the network account type and process permission information corresponding to the corresponding operation scenario.
4. The method for hierarchical management of network account process permissions according to claim 1, characterized in that: The step of obtaining the identification data corresponding to the application process in the account management policy table includes the following steps: Obtaining account data corresponding to the application process; Obtaining user identification information corresponding to the application process; Obtain group identification information corresponding to the application process.
5. The method for hierarchical management of network account process permissions according to claim 1, characterized in that: The step of adjusting the execution permission of the application process according to the identification data comprises the following steps: Obtaining process permission information corresponding to the identification data in the account management policy table; Adjusting the running permissions of the application process according to the process permission information; An error detection process is performed on the running permission adjustment of the application process.
6. The method for hierarchical management of network account process permissions according to claim 5, characterized in that: The step of obtaining the process permission information corresponding to the identification data in the account management policy table includes the following steps: Obtaining account data, user identification information, and group identification information from the identification data; Determine process permission information corresponding to the account data, the user identification information, and the group identification information in the account management policy table.
7. The method for hierarchical management of network account process permissions according to claim 5, characterized in that: The error detection process for adjusting the running permission of the application process includes the following steps: Determining whether an error occurs during loading of the account management policy table; If so, perform a rollback operation and log an error message; If not, determine whether an error occurs during the file writing process; If so, perform a rollback operation and log an error message; If not, determine whether an error occurs during the permission modification operation; If so, switch to the backup permission mode; If not, keep the application process in the current execution permission.
8. A network account process authority hierarchical management device, characterized in that: include: Policy table acquisition module, used to obtain the account management policy table; Process acquisition module, used to obtain application processes; A data acquisition module, configured to acquire identification data corresponding to the application process from the account management policy table; An adjustment module, configured to adjust the running permissions of the application process according to the identification data; A running module is used to run the application process according to the running permission.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Illegal privilege lifting detection method and device, electronic equipment and storage medium
CN113987435A
Multi-user management system based on communication management machine
CN119995961A
Strategy and method for realizing minimum privilege control in safety operating system
CN1854961A
Information processing device and method, and program
JP2011043912A