CMS system file protection method, device and system and storage medium
By inheriting Java's SecurityManager class to configure the security manager and using the Map data structure to define access permissions, the problems of high security risks and resource consumption in existing CMS system file protection technology are solved, and precise control and security management of CMS system files are achieved.
Patent Information
- Application Number
- CN202510301737.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-09-16
AI Technical Summary
Existing CMS system file protection technology has security risks in policy file storage, transmission and processing. The file integrity verification system cannot detect file tampering in real time. The file protection solution based on access control lists has high resource consumption and high maintenance costs.
By inheriting Java's SecurityManager class to configure the security manager, asymmetric encryption is performed on binary files, access permissions are defined using the Map data structure, and the security manager is applied through the Java reflection mechanism to achieve precise control of access requests.
Enhances the security of CMS system files, ensuring that only applications with appropriate permissions can access system resources, reducing security risks and improving system stability and reliability.
Smart Images

Figure CN120654260A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of file protection technology, and in particular relates to a CMS system file protection method, device, system and storage medium. Background Art
[0002] As a content management system, CMS files are crucial for its proper operation. If content files are not secure, they risk unauthorized access, tampering, or leakage. This not only compromises user privacy but can also lead to legal disputes and severely damage the system's reputation. Secondly, unstable system files can lead to functional anomalies, such as slow page loading and incorrect content display, directly impacting user experience and potentially causing user churn. Finally, insufficient file reliability threatens data integrity and consistency. Once data is compromised, recovery becomes difficult, impacting business continuity and data recovery capabilities.
[0003] In the prior art, CMS system files are typically protected through a policy-based access control system (PBAC), a file integrity verification system (FIV), and an access control list (ACL)-based file protection scheme. A PBAC utilizes a policy file to define, manage, and enforce access control rules. The system evaluates user access requests based on the rules in the policy file and decides whether to grant access to specific resources. These rules can be based on the user's identity, role, attributes, and access context. The policy file is the core component of the system, containing all access control rules. These rules are typically written in a structured format (such as XML or JSON) for easy system parsing and execution. A FIV system regularly verifies the integrity of files to ensure that their hash values or signatures match expected values. If a file is found to be tampered with or corrupted, the system immediately issues an alert and takes appropriate recovery measures. An ACL-based file protection scheme restricts user access rights by defining an ACL for each file. An ACL can contain multiple entries, each specifying a user or role and its corresponding access rights. When a user attempts to access a file, the system checks the ACL to determine whether the user has the appropriate permissions.
[0004] However, policy file-based access control systems face security risks in the storage, transmission, and processing of policy files. Physical environments, permission management, network attacks, and insufficient encryption can all lead to policy file leaks. Policy definition and management can become extremely complex, especially in large-scale CMS systems, which require processing a large number of policies and rules. Different policies may conflict or be redundant, increasing the difficulty of policy management and potentially leading to security vulnerabilities. File integrity verification systems, beyond verifying file integrity, typically lack the ability to manage other types of resources. These systems cannot directly support or verify other types of resources (such as network requests and user permissions). If verification systems cannot detect file tampering or corruption in real time, there is a certain lag, which can lead to serious consequences for the CMS system, such as data loss, system failure, and legal disputes. In file protection solutions based on access control lists, ACL checks consume system resources, especially during peak traffic periods. Overly complex ACLs can affect device performance, leading to data transmission delays or packet loss. Furthermore, ACLs require constant updates to adapt to new security requirements, which can result in high maintenance costs and time investment. Summary of the Invention
[0005] The purpose of this application is to provide a CMS system file protection method, device, system and storage medium, which enhances the file protection capabilities of the CMS system through a customized security manager, ensures that only applications with appropriate permissions can access system files, and provides logging and alarm mechanisms to track and respond to abnormal problems.
[0006] In order to achieve the above objectives, the solution of this application is:
[0007] In a first aspect, an embodiment of the present application provides a CMS system file protection method, comprising:
[0008] Configure the security manager by inheriting Java's SecurityManager class;
[0009] Compile the security manager into a binary file, perform asymmetric encryption on the binary file, and generate a dat file;
[0010] Start the CMS system, decrypt the dat file using the private key, restore it to a binary file, decode the binary file to obtain the security manager, and apply the security manager to the application through Java's reflection mechanism;
[0011] Define access permissions through the Map data structure, start the application, read the permission information of the security manager, and load the permission information of the security manager into the Map data structure;
[0012] When an application sends an access request to the CMS system, the corresponding permission information is searched in the Map through the Key. If the corresponding permission information is found, the Value is checked and verified to obtain the verification result, and the access request is processed according to the verification result; if the corresponding permission information is not found, the access request is rejected.
[0013] The above method according to the embodiment of the present application may also have the following additional technical features:
[0014] Furthermore, when an application sends an access request to the CMS system, the corresponding permission information is searched in the Map by the Key. If the corresponding permission information is found, the Value is checked and verified to obtain the verification result. The access request is processed according to the verification result, including:
[0015] If the verification result is that the Value is a permission judgment object, the permission setting of the permission judgment object is used for verification to determine whether the application's permissions meet the access request. If so, the access request is allowed; if not, the access request is denied.
[0016] If the verification result is that the Value is an empty string, the access request is allowed.
[0017] Furthermore, the method includes:
[0018] Start the monitoring function of the security manager, record access requests, generate record logs, and configure the storage location and format of the record logs. When an abnormal problem occurs, track and locate the abnormal problem by viewing the record logs.
[0019] Furthermore, the method includes:
[0020] Define the alarm mechanism and configure the sending method and receiving object of the alarm mechanism. When an abnormal problem is detected, the alarm mechanism will be triggered.
[0021] In a second aspect, an embodiment of the present application provides a CMS system file protection device, comprising:
[0022] The management definition module is configured to configure the security manager by inheriting the Java SecurityManager class;
[0023] Compile the encryption module, which is configured to compile the security manager into a binary file, and perform asymmetrical encryption on the binary file to generate a dat file;
[0024] The management application module is configured to start the CMS system, decrypt the dat file using the private key, restore it to a binary file, decode the binary file to obtain the security manager, and apply the security manager to the application through the Java reflection mechanism;
[0025] The permission loading module is configured to define access rights through a Map data structure, start the application, read permission information of the security manager, and load the permission information of the security manager into the Map data structure;
[0026] The permission verification module is configured to search for the corresponding permission information in the Map by using the Key when the application sends an access request to the CMS system. If the corresponding permission information is found, the Value check and verification are performed to obtain the verification result, and the access request is processed according to the verification result; if the corresponding permission information is not found, the access request is rejected;
[0027] If the verification result is that the Value is a permission judgment object, the permission setting of the permission judgment object is used for verification to determine whether the application's permissions meet the access request. If so, the access request is allowed; if not, the access request is denied.
[0028] If the verification result is that the Value is an empty string, the access request is allowed.
[0029] In a third aspect, an embodiment of the present application provides a CMS system file protection system, the system including a processor and a memory, the memory storing a computer program, and the computer program being loaded and executed by the processor to implement the CMS system file protection method provided in the first aspect of the embodiment of the present application.
[0030] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, it is used to implement the CMS system file protection method as described in the first aspect of the embodiment of the present application.
[0031] The CMS system file protection method provided by the embodiment of the present application has the following beneficial technical effects compared with the prior art:
[0032] The embodiment of the present application provides an additional security layer for the CMS system by inheriting Java's SecurityManager class and configuring a security manager. This method can control the application's access to system resources in a fine-grained manner and prevent unauthorized access and operation; asymmetric encryption of the security manager binary file ensures the security of the security manager itself and prevents the risk of malicious tampering or leakage.
[0033] The embodiment of the present application makes permission management more flexible and scalable by using a Map data structure to define access permissions. Administrators can easily add, modify, or delete permission rules as needed. By searching for corresponding permission information in the Map through the Key and verifying it based on the Value, precise control of access requests is achieved, which helps ensure that only applications with appropriate permissions can access specific system resources.
[0034] The embodiment of the present application starts the monitoring function of the security manager, records access requests, and generates a record log, which helps administrators track and audit the behavior of applications and ensure the compliance and security of the system; configures the storage location and format of the record log, and defines the alarm mechanism, so that when an abnormal problem occurs, the administrator can quickly locate the problem and take appropriate measures.
[0035] The embodiment of the present application applies the security manager to the application through Java's reflection mechanism. This method is highly flexible and scalable, allowing the system to easily adapt to changing security requirements. The configuration of the alarm mechanism enables the administrator to be immediately notified when an abnormal problem is detected, so that timely measures can be taken to solve the problem and improve the reliability and stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 A schematic diagram showing a process flow of a CMS system file protection method according to an embodiment of the present application is shown;
[0037] Figure 2 A structural block diagram of a CMS system file protection device according to an embodiment of the present application is shown;
[0038] Figure 3 A structural block diagram of a computer device according to an embodiment of the present application is shown. DETAILED DESCRIPTION
[0039] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are described in detail below in conjunction with the accompanying drawings. It will be understood that the specific embodiments described herein are only used to explain the present application, rather than to limit the present application. It should also be noted that, for ease of description, only some, rather than all, structures related to the present application are shown in the accompanying drawings. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0040] As used herein, the terms "comprise," "comprising," and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.
[0041] References to "embodiments" in this application mean that a particular feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described in this application may be combined with other embodiments.
[0042] like Figure 1 As shown, the embodiment of the present application provides a CMS system file protection method, including the following steps:
[0043] Step 101: Configure the security manager by inheriting the Java SecurityManager class.
[0044] Java's SecurityManager class is a powerful security mechanism that allows developers to customize security policies by inheriting and overriding its methods. In the CMS system file protection method, inheriting the SecurityManager class and configuring the security manager are fundamental steps to enhancing system security.
[0045] The SecurityManager class provides several methods that are called when a Java program performs specific operations. By inheriting and overriding these methods, developers can customize security policies, such as restricting file and network access. File and data security is crucial in a CMS system. By configuring the security manager, developers can ensure that only applications with appropriate permissions can access sensitive files and data.
[0046] First, you need to create a new class that inherits from the SecurityManager class. In this new class, you can override the methods in the SecurityManager class to define your own security policy.
[0047] In a Java program, you can set a security manager by calling the System.setSecurityManager(SecurityManagers) method. This method accepts a SecurityManager object as a parameter and sets it as the security manager of the current Java virtual machine.
[0048] When configuring a security manager, you also need to define which operations are allowed and which are prohibited. This is usually achieved by defining permission classes (such as FilePermission, SocketPermission, etc.) and associating them with specific code sources (such as class loaders, code locations, etc.).
[0049] In the CMS system's file protection approach, the primary purpose of inheriting from the SecurityManager class and configuring a security manager is to ensure file and data security. By overriding methods in the SecurityManager class, developers can customize security policies, such as restricting access to specific files and monitoring file access requests. When an application attempts to access a file, the security manager checks whether the operation complies with the defined security policy and, based on the results, allows or denies the access request.
[0050] In summary, by inheriting Java's SecurityManager class and configuring a security manager, developers can customize security policies, enhance the security of the CMS system, and ensure that files and data are not accessed by unauthorized applications.
[0051] Step 102: compile the security manager into a binary file, and perform asymmetrical encryption on the binary file to generate a dat file.
[0052] In the CMS system file protection method, compiling the security manager into a binary file and performing asymmetrical encryption on the binary file to generate a dat file are important steps to enhance system security.
[0053] First, the security manager is configured by inheriting Java's SecurityManager class. This security manager is responsible for defining and enforcing security policies in the CMS system, ensuring that only authorized applications can access system resources.
[0054] Next, to embed this security manager into the CMS system, it needs to be compiled into a binary file. A binary file is a file format that can be directly executed by a computer. By compiling, the source code of the security manager can be converted into machine code that the computer can understand.
[0055] However, simply compiling the security manager into a binary file is not sufficient to ensure its security. If this binary file is obtained by unauthorized users, they may obtain the security manager's source code through decompilation and other means, thereby bypassing the security policy. Therefore, after compiling the security manager into a binary file, it must also be asymmetrically encrypted.
[0056] Asymmetric encryption is a method of encrypting and decrypting information using public and private keys. In this scenario, a binary file can be encrypted using a public key, generating an encrypted file (i.e., a .dat file). This way, even if an unauthorized user obtains the .dat file, they cannot directly read the contents because they do not have the corresponding private key to decrypt the file.
[0057] When the CMS system starts, it uses the corresponding private key to decrypt the dat file, restoring the original binary file. This binary file is then decoded to obtain an instance of the security manager. Finally, this security manager is applied to applications within the CMS system through Java reflection.
[0058] In summary, compiling the security manager into a binary file and performing asymmetrical encryption on the binary file to generate a .dat file is a crucial step in the CMS system file protection method. This step ensures the security and integrity of the security manager, thereby improving the overall security of the CMS system.
[0059] Step 103: Start the CMS system, decrypt the dat file using the private key, restore it to a binary file, decode the binary file to obtain a security manager, and apply the security manager to the application through Java's reflection mechanism.
[0060] In the CMS system file protection method, starting the CMS system and loading and applying the security manager through a series of steps is a key process.
[0061] First, the CMS (Content Management System) is launched. This is the starting point for the entire file protection method and the foundation for subsequent steps. After the CMS is launched, the next step is to decrypt the previously encrypted .dat file using the private key. This .dat file contains the binary representation of the security manager, but it has previously been asymmetrically encrypted to protect its security. Decryption using the private key is the key step in recovering the original binary file.
[0062] The decrypted dat file is actually a binary file that contains the security manager code. Therefore, the next step is to decode this binary file to recover the original security manager object. This process involves converting the binary data back into bytecode that can be understood by the Java virtual machine.
[0063] After obtaining the security manager object, the next step is to apply it to the application through Java's reflection mechanism. Reflection is a powerful feature of Java that allows programs to dynamically obtain class information, call methods, and access fields at runtime. In this scenario, reflection is used to inject the security manager object into the application context, enabling it to monitor and control the application's access to resources.
[0064] The security manager plays a crucial role in Java. It is a class that monitors and controls the security behavior of Java applications. By inheriting from the Java SecurityManager class and configuring appropriate permission policies, developers can fine-grainedly control the actions and resources that applications can access. This is particularly important for protecting CMS system files from unauthorized access or modification.
[0065] In practice, this process requires ensuring the secure storage and management of private keys to prevent unauthorized decryption and access. Furthermore, the process of decoding binary files and applying security managers through reflection also needs to be handled carefully to ensure that no new security risks or performance issues are introduced.
[0066] In summary, starting the CMS system, decrypting the .dat file using the private key, restoring and decoding the binary file, and applying the security manager through Java reflection are key steps in the CMS system file protection method. These steps together form the cornerstone of protecting CMS system file security.
[0067] Step 104 , defining access rights through a Map data structure, starting the application, reading the permission information of the security manager, and loading the permission information of the security manager into the Map data structure.
[0068] In the CMS system file protection method, this step ensures that the system can manage and verify application access requests to system resources in a structured and efficient manner.
[0069] First, the Map data structure is a collection of key-value pairs that allows for quick lookup of corresponding values by key. In this scenario, Maps are used to define and store access permissions. Each key represents a specific resource or operation, while each value represents the access permission granted to that resource or operation.
[0070] When an application is started, the system reads the security manager's permission information. These permissions are defined during the security manager configuration process and reflect the operations that the application is authorized to perform and the resources it can access.
[0071] Next, this permission information is loaded into a Map data structure. This means that each permission is assigned a unique key and associated with its corresponding value (i.e., access permission). In this way, when an application makes an access request to the CMS system, the system can quickly determine whether the application has the permission to perform the operation by looking up the Map.
[0072] The benefit of this process is that it provides a flexible and scalable way to manage access permissions. As the system evolves and new features are added, new key-value pairs can be easily added to the Map to define new access permissions. Furthermore, because Map lookups are typically very efficient, this step does not introduce significant performance overhead, ensuring that the system can manage application access permissions in a structured and efficient manner.
[0073] Step 105: When the application sends an access request to the CMS system, the corresponding permission information is searched in the Map through the Key. If the corresponding permission information is found, the Value is checked and verified to obtain the verification result, and the access request is processed according to the verification result; if the corresponding permission information is not found, the access request is rejected.
[0074] When an application sends an access request to the CMS system, the system first uses a Key (usually a specific identifier or path) to find the corresponding permission information in the Map data structure.
[0075] The Map data structure is predefined and is used to store various permission information, where the Key corresponds to the application or resource identifier and the Value corresponds to the specific permission information.
[0076] If the corresponding permission information is found in the Map, the system will further check and verify the Value. The verification process will determine the specific verification logic based on the type and content of the Value.
[0077] Specifically, if the Value is a FilePermission object, the system verifies the request based on the permissions set in that object. FilePermission objects typically include permissions such as read, write, and execute permissions for a file or directory. The system then determines whether the application's permissions meet the access request requirements. If so, the access request is granted; otherwise, the access request is denied.
[0078] If the Value is an empty string, this typically indicates that the resource or operation has no specific permission restrictions. In this case, the system allows the access request.
[0079] Based on the verification results, the system will take appropriate action. If verification passes, the access request is allowed; if verification fails, the access request is denied. If an exception occurs during the permission search or verification process (such as the corresponding key not existing in the map, the value type being incorrect, etc.), the system will also take appropriate action, such as logging and triggering an alarm mechanism.
[0080] This permission verification process is one of the core aspects of CMS's system file protection method. It ensures that only applications with the appropriate permissions can access specific resources or perform specific operations. This helps to protect the security and stability of the system and prevent unauthorized access and operation.
[0081] In practical applications, this permission verification process can be used in various scenarios that require permission management, such as file system access control and database operation permission management. By properly configuring parameters such as the Map data structure and the FilePermission object, a flexible and sophisticated permission control strategy can be implemented.
[0082] In summary, this step ensures the security and stability of the system by searching for permission information in the Map, checking and verifying the Value, and processing the access request based on the verification result.
[0083] Furthermore, embodiments of the present application also include enabling the security manager's monitoring function, which is designed to record all access requests and generate corresponding logs. These logs not only record each access request in detail, but also include key information such as the time, source, and target resource of the request. Furthermore, users can configure the storage location and format of the logs, allowing them to be quickly found and viewed when needed.
[0084] Logging is a crucial component of system security. When an unexpected problem occurs, system administrators can quickly locate the source of the problem, understand its progression and impact, and take appropriate measures to fix or prevent it. This not only helps improve system security but also increases problem-solving efficiency.
[0085] In practice, logging can be used in a variety of scenarios requiring monitoring and auditing. For example, if the system detects that an application frequently attempts to access unprotected resources, administrators can confirm this behavior by viewing the logs and take appropriate measures to prevent potential security risks.
[0086] Furthermore, it also includes defining an alarm mechanism and configuring its sending method and recipients. When the system detects an abnormal problem, such as unauthorized access attempts or resource abuse, the alarm mechanism will be immediately triggered and the alarm information will be sent to the designated recipients via a preset method (such as SMS, email, instant messaging, etc.).
[0087] The alarm mechanism is another line of defense for system security. By sending timely alarm information, the system ensures that administrators or relevant responsible persons are immediately aware of the problem and can take prompt measures to respond, helping to reduce potential security risks and protect system integrity and data confidentiality.
[0088] Alarm mechanisms can be applied to a variety of scenarios requiring real-time monitoring and rapid response. For example, if the system detects unauthorized access or tampering with a critical resource, an alarm can be immediately triggered, notifying the responsible personnel for emergency action. Furthermore, the alarm mechanism can be integrated with other security systems (such as intrusion detection systems and firewalls) to achieve more comprehensive and efficient security protection.
[0089] In summary, the monitoring function of the security manager, the definition and configuration of the logging and alarm mechanisms together constitute a solid line of defense for system security, ensuring the stability of the system and the security of data.
[0090] like Figure 2 As shown, the embodiment of the present application provides a CMS system file protection device, including a management definition module 201, a compilation encryption module 202, a management application module 203, a permission loading module 204 and a permission verification module 205, wherein:
[0091] The management definition module 201 is configured to configure the security manager by inheriting the Java SecurityManager class;
[0092] The compile encryption module 202 is configured to compile the security manager into a binary file and perform asymmetrical encryption on the binary file to generate a dat file;
[0093] The management application module 203 is configured to start the CMS system, decrypt the dat file using the private key to restore it to a binary file, decode the binary file to obtain a security manager, and apply the security manager to the application through the Java reflection mechanism;
[0094] The permission loading module 204 is configured to define access rights through a Map data structure, start the application, read the permission information of the security manager, and load the permission information of the security manager into the Map data structure;
[0095] The permission verification module 205 is configured to, when an application sends an access request to the CMS system, search for the corresponding permission information in the Map using the Key. If the corresponding permission information is found, the module performs a Value check and verification to obtain a verification result, and processes the access request based on the verification result. If the corresponding permission information is not found, the module denies the access request.
[0096] If the verification result is that the Value is a permission judgment object, the permission setting of the permission judgment object is used for verification to determine whether the application's permissions meet the access request. If so, the access request is allowed; if not, the access request is denied.
[0097] If the verification result is that the Value is an empty string, the access request is allowed. Figure 1 To avoid repetition, the various processes implemented in the embodiment of the CMS system file protection method are not described here.
[0098] The present application also provides a computer device, such as Figure 3 As shown, the computer device includes a processor 301 and a memory 302. The memory 302 stores programs or instructions that can be run on the processor 301. When the program or instruction is executed by the processor 301, the various steps of the above-mentioned CMS system file protection method are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0099] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned CMS system file protection method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0100] It should be noted that, in the present application, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0101] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
Claims
1. A CMS system file protection method, characterized in that: The method comprises: Configure the security manager by inheriting Java's SecurityManager class; Compile the security manager into a binary file, and perform asymmetrical encryption on the binary file to generate a dat file; Starting the CMS system, decrypting the dat file using a private key to restore the binary file, decoding the binary file to obtain the security manager, and applying the security manager to the application through Java's reflection mechanism; Defining access rights through a Map data structure, starting the application, reading permission information of the security manager, and loading the permission information of the security manager into the Map data structure; When the application sends an access request to the CMS system, the corresponding permission information is searched in the Map through the Key. If the corresponding permission information is found, the Value is checked and verified to obtain a verification result, and the access request is processed according to the verification result; if the corresponding permission information is not found, the access request is rejected.
2. The CMS system file protection method according to claim 1, characterized in that: When the application sends an access request to the CMS system, the corresponding permission information is searched in the Map by the Key. If the corresponding permission information is found, the Value is checked and verified to obtain a verification result. The access request is processed according to the verification result, including: If the verification result is that the Value is a permission judgment object, verification is performed based on the permission settings of the permission judgment object to determine whether the permissions of the application meet the access request. If so, the access request is allowed; if not, the access request is denied; If the verification result is that the Value is an empty string, the access request is allowed.
3. The CMS system file protection method according to claim 2, characterized in that: The method comprises: Start the monitoring function of the security manager, record the access request, generate a record log, and configure the storage location and format of the record log. When an abnormal problem occurs, track and locate the abnormal problem by viewing the record log.
4. The CMS system file protection method according to claim 3, characterized in that: The method comprises: Define an alarm mechanism and configure the sending method and receiving object of the alarm mechanism. When an abnormal problem is detected, the alarm mechanism is triggered.
5. A CMS system file protection device, characterized in that: The device comprises: The management definition module is configured to configure the security manager by inheriting the Java SecurityManager class; A compile encryption module is configured to compile the security manager into a binary file, and perform asymmetrical encryption on the binary file to generate a dat file; A management application module is configured to start the CMS system, decrypt the dat file using a private key to restore the binary file, decode the binary file to obtain the security manager, and apply the security manager to the application program through a Java reflection mechanism; a permission loading module configured to define access rights through a Map data structure, start the application, read permission information of the security manager, and load the permission information of the security manager into the Map data structure; The permission verification module is configured to, when the application sends an access request to the CMS system, search for corresponding permission information in the Map using a key; if the corresponding permission information is found, perform a value check and verification to obtain a verification result; and process the access request based on the verification result; if the corresponding permission information is not found, reject the access request; If the verification result is that the Value is a permission judgment object, verification is performed based on the permission settings of the permission judgment object to determine whether the permissions of the application meet the access request. If so, the access request is allowed; if not, the access request is denied; If the verification result is that the Value is an empty string, the access request is allowed.
6. A CMS system file protection system, the system comprising a processor and a memory, wherein the memory stores a computer program, characterized in that: The computer program is loaded and executed by the processor to implement the CMS system file protection method according to any one of claims 1 to 4.
7. A computer-readable storage medium storing a computer program, wherein: When the computer program is executed by a processor, it is used to implement the CMS system file protection method according to any one of claims 1 to 7.