Dynamic authority management method and device, equipment and storage medium
By dynamically managing the permissions of the task process through the main process, and allocating and reclaiming permissions according to the needs of the execution phase, it solves the security risks caused by the centralization of permissions in traditional DAC permission management and achieves more precise permission control and system stability.
Patent Information
- Application Number
- CN202510860749.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-09-26
AI Technical Summary
The security risks and management complexity caused by the centralization of permissions in traditional DAC permission management, especially in the management of high-privilege tasks, exist, leading to permission abuse and system security threats.
The main process configures permissions for the task process, generates permission configuration information, and dynamically allocates and reclaims permissions when the task is executed. This ensures that the task process only has the corresponding permissions when needed, according to the needs of the execution phase.
It improves the security and stability of the system, reduces the risk of permission abuse, improves the accuracy of permission configuration and resource utilization efficiency, and enhances the system's adaptability.
Smart Images

Figure CN120705865A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a dynamic rights management method, apparatus, device and storage medium. Background Art
[0002] In modern computer security systems, permission management is a core element of system security and resource controllability. In such systems, permission control for task execution typically relies on the DAC (Discretionary Access Control) mechanism. However, as computer systems scale and task complexity increase, traditional DAC technology has gradually introduced a series of limitations in managing high-privilege tasks. These issues not only increase system management complexity but also expose the system to greater security risks. One of the most prominent limitations of the DAC permission model is the centralization of permissions. When a process needs to perform high-privilege tasks (such as system configuration, network management, or sensitive data manipulation), it typically requires root privileges. Since root has almost all permissions, this centralized permission design poses significant security risks. Any task process with root privileges can perform arbitrary operations on the system, including modifying system configurations, accessing sensitive data, and even deleting critical files. Once a malicious program successfully obtains root privileges, the security of the entire system is threatened.
[0003] To address these issues, some solutions require pre-configuring all possible permissions before a task begins. However, this approach can also lead to the risk of excessive abuse of permissions. Improving the precision of permission management within task programs is an urgent issue. Summary of the Invention
[0004] In view of this, the present invention provides a dynamic rights management method to solve the problem of inaccurate rights management of task programs.
[0005] In the first aspect, the present invention provides a dynamic permission management method, which includes: configuring permissions for each system task process through a main process to generate permission configuration information; when a target task process is executed, reading the target permissions required for the execution of the target task process from the permission configuration information through the main process, and allocating the target permissions to the target task process; detecting whether the target task process has been completed through the main process, and reclaiming the target permissions when the target task process has been completed.
[0006] According to the above technical means, when a target task process needs to be executed, the main process will read the target permissions required by the target task process from the permission configuration information. The main process assigns these target permissions to the target task process so that it can perform the required operations normally. During the execution of the target task process, the main process will continuously monitor the execution status of the process. When it detects that the target task process has completed execution, the main process will immediately revoke all target permissions previously assigned to the process to ensure that the permissions will not be occupied for a long time or maliciously exploited. Through this dynamic permission management method, the system can ensure that the task process has the corresponding permissions only when needed, and immediately revoke the permissions when they are no longer needed, thereby minimizing the risk of permission abuse and improving the security and stability of the system.
[0007] In some optional implementations, the permission configuration of each system task process is performed through the main process to generate permission configuration information, including: independently configuring the permissions required by each system task process in different execution stages through the main process to obtain the stage permissions corresponding to each system task process in different execution stages; and generating the permission configuration information based on the configured stage permissions.
[0008] Using these technical measures, the permission configuration information includes a list of specific permissions required by each task process at each execution stage, forming a multi-dimensional permission configuration matrix. This fine-grained permission configuration allows the system to more precisely control the permissions of task processes at different execution stages, further reducing the risk of over-configuration of permissions and improving system security.
[0009] In some optional embodiments, when the target task process is executed, the target permission required for the execution of the target task process is read from the permission configuration information through the main process, and the target permission is allocated to the target task process, including: determining the execution stage of the target task process; reading the corresponding target stage permission from the permission configuration information according to the execution stage; and allocating the target stage permission to the target task process.
[0010] Based on the above technical measures, the permission allocation process for the target task process during execution has been further refined. The main process dynamically allocates and revoks permissions based on the target task process's current execution stage. This dynamic permission allocation based on execution stage ensures that the task process only obtains the permissions required for each execution stage, rather than all permissions at once, further improving system security and resource utilization efficiency.
[0011] In some optional implementations, determining the execution phase of the target task process includes: determining the execution phase to be executed in advance by a preset time before each execution phase of the target task process is executed.
[0012] Using these technical measures, the master process predicts the start time of each execution phase based on the execution patterns and historical data of the task process. At a preset time before the start of each execution phase, the master process determines the upcoming phase and prepares the required permissions in advance. By pre-setting the execution phase at a preset time, the system can more smoothly allocate permissions, reducing task execution interruptions or delays caused by delayed permission allocation, thereby improving overall system performance and user experience.
[0013] In some optional implementations, detecting whether the target task process has been completed through the main process and reclaiming the target permission when the target task process has been completed includes: detecting whether the current execution stage of the target task process has been completed; and reclaiming the corresponding target stage permission when the current execution stage is completed.
[0014] Based on the above technical means, the permission recovery process has been further refined. The main process will recover permissions for each execution phase of the task process. Based on the dynamic permission recovery method of the execution phase, the system can recover no longer needed permissions more promptly, reducing the risk of permission abuse and improving system security and resource utilization efficiency.
[0015] In some optional implementations, the permissions required by each system task process at different execution stages are independently configured through the main process to obtain the stage permissions corresponding to each system task process at different execution stages, including: obtaining the historical logs of the system task processes; calling the large model to analyze the historical logs to predict the permissions required by each system task process at different execution stages; independently configuring the permissions required by each system task process at different execution stages based on the prediction information; when each system task process is executed, obtaining the error message of each system task process, and adjusting the configured stage permissions based on the error message.
[0016] Using the aforementioned technical means, the master process utilizes a large model to analyze historical logs and predict the permissions required by task processes at different execution stages. Based on the large model's predictions, the master process independently configures the permissions required by each system task process at different execution stages, forming an initial stage-by-stage permission configuration. During task process execution, the master process monitors the execution of the task process, specifically collecting error messages caused by insufficient permissions. If a task process encounters an error indicating insufficient permissions at a particular execution stage, the master process adjusts the permission configuration for that task process based on the error message to ensure normal execution. Through a permission configuration approach based on large model analysis and dynamic adjustment, the system can more intelligently predict and meet the permission requirements of task processes, reducing the workload of manual configuration and improving the accuracy of permission configuration and the system's adaptability.
[0017] In some optional embodiments, before the target task process is executed, the main process reads the target permission required for the target task process to execute from the permission configuration information and assigns the target permission to the target task process, the method further includes: sending a confirmation message to each of the system task processes through the main process, so that each of the system task processes feeds back the permission configuration data; verifying the correctness of the permission configuration data based on the comparison between the permission configuration information and the permission configuration data; if the verification is successful, continuing to execute the step of reading the target permission required for the target task process to execute from the permission configuration information through the main process and assigning the target permission to the target task process; if the verification fails, reconfiguring the permissions.
[0018] Based on the above technical means, a permission verification process is further added. The main process will verify the correctness of the permission configuration before configuring it, ensuring the security and accuracy of the permission configuration.
[0019] In the second aspect, the present invention provides a dynamic permission management device, which includes: a basic permission configuration module, which is used to configure permissions for each system task process through a main process and generate permission configuration information; a dynamic permission allocation module, which is used to read the target permissions required for the execution of the target task process from the permission configuration information through the main process when the target task process is executed, and allocate the target permissions to the target task process; a dynamic permission recovery module, which is used to detect whether the target task process has been executed through the main process, and to reclaim the target permissions when the target task process has been executed.
[0020] In a third aspect, the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0021] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method of the first aspect or any corresponding embodiment thereof.
[0022] In a fifth aspect, the present invention provides a computer program product comprising computer instructions for causing a computer to execute the method of the first aspect or any corresponding embodiment thereof.
[0023] The technical solution provided by the present invention has the following advantages:
[0024] (1) According to the above technical means, when a target task process needs to be executed, the main process will read the target permissions required by the target task process from the permission configuration information. The main process assigns these target permissions to the target task process so that it can perform the required operations normally. During the execution of the target task process, the main process will continuously monitor the execution status of the process. When it detects that the target task process has completed execution, the main process will immediately revoke all target permissions previously assigned to the process to ensure that the permissions will not be occupied for a long time or maliciously exploited. Through this dynamic permission management method, the system can ensure that the task process has the corresponding permissions only when needed, and immediately revoke the permissions when not needed, thereby minimizing the risk of permission abuse and improving the security and stability of the system.
[0025] (2) Based on the above technical means, the permission configuration information includes a list of specific permissions required by each task process at each execution stage, forming a multi-dimensional permission configuration matrix. Through this fine-grained permission configuration method, the system can more accurately control the permissions of task processes at different execution stages, further reducing the risk of over-configuration of permissions and improving system security.
[0026] (3) Based on the above technical means, the permission allocation process during the execution of the target task process is further refined. The main process will dynamically allocate and reclaim permissions based on the current execution stage of the target task process. Through this dynamic permission allocation method based on the execution stage, the system can ensure that the task process only obtains the permissions required for each execution stage, rather than obtaining all permissions at once, further improving the security and resource utilization efficiency of the system.
[0027] (4) Based on the above technical means, the main process will predict the start time of each execution phase based on the execution patterns and historical data of the task process. At a preset time point before the start of each execution phase, the main process will determine the phase to be executed and prepare the permissions required for that phase in advance. By determining the execution phase at a preset time in advance, the system can more smoothly allocate permissions, reduce task execution interruptions or delays caused by delayed permission allocation, and improve the overall system performance and user experience.
[0028] (5) Based on the above technical means, the permission recovery process is further refined. The main process will recover permissions for each execution stage of the task process. Based on the dynamic permission recovery method of the execution stage, the system can recover no longer needed permissions more promptly, reduce the risk of permission abuse, and improve system security and resource utilization efficiency.
[0029] (6) According to the above technical means, the main process will use the large model to analyze historical logs and predict the permissions required by the task process at different execution stages. Based on the prediction results of the large model, the main process independently configures the permissions required by each system task process at different execution stages to form the initial stage permission configuration. During the execution of the task process, the main process will monitor the execution status of the task process, especially collecting error messages caused by insufficient permissions of the task process. When it is found that a task process has an error of insufficient permissions at a certain execution stage, the main process will adjust the permission configuration of the task process at that execution stage according to the error information to ensure that the task process can be executed normally. Through the permission configuration method based on large model analysis and dynamic adjustment, the system can more intelligently predict and meet the permission requirements of the task process, reduce the workload of manual configuration, and improve the accuracy of permission configuration and the system's adaptability.
[0030] (7) Based on the above technical means, a permission verification process is further added. The main process will verify the correctness of the permission configuration before configuring the permission to ensure the security and accuracy of the permission configuration. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0032] Figure 1 is a flow chart of a dynamic rights management method according to an embodiment of the present invention;
[0033] Figure 2is another flow chart of a dynamic rights management method according to an embodiment of the present invention;
[0034] Figure 3 This is a schematic structural diagram of a dynamic rights management device according to an embodiment of the present invention;
[0035] Figure 4 Schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0036] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.
[0037] According to an embodiment of the present invention, an embodiment of a dynamic rights management method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0038] In this embodiment, a dynamic rights management method is provided. Figure 1 1 is a flow chart of a dynamic rights management method according to an embodiment of the present invention, the flow includes the following steps:
[0039] Step S101, configuring permissions for each system task process through the main process to generate permission configuration information;
[0040] Step S102: When the target task process is executed, the main process reads the target permission required for the target task process from the permission configuration information and allocates the target permission to the target task process;
[0041] Step S103: The main process detects whether the target task process has been completed, and revokes the target permission when the target task process has been completed.
[0042] Specifically, this embodiment provides a dynamic permission management method, which performs dynamic permission management on system task processes through a main process, thereby achieving accurate allocation and timely recovery of permissions, and effectively improving system security.
[0043] In this embodiment, the master process serves as the core control process in the system, responsible for managing the permissions of each system task process. The master process first configures permissions for each task process in the system and records the configuration results in permission configuration information. This permission configuration information can be stored in a database, configuration file, or in-memory data structure, containing a list of permissions required for each task process.
[0044] For example, when configuring firewall rules, administrators need to analyze which operations are required and determine the required permissions for the task. For example, the CAP_NET_ADMIN permission is primarily used in the following scenarios: 1. Configuring network interfaces (such as enabling or disabling an interface); 2. Modifying routing tables to optimize network traffic paths; and 3. Configuring firewall rules to protect against system shell network attacks. This analysis allows administrators to accurately identify the minimum permissions required for the task, avoiding security risks or task interruptions caused by improper permission configuration.
[0045] After completing the requirements analysis, the system needs to configure basic permissions for specific tasks and include them in the task script to ensure that the program has the basic capabilities to perform the task. Taking Linux as an example, this step uses the setcap command in Linux to set the required permissions for the program through the capabilities mechanism. For example, when configuring tasks within firewall rules, the CAP_NET_ADMIN permission needs to be configured for the firewall program. Use the setcap command: sudo setcap cap_net_admin=+ep / usr / local / bin / firewall . This grants the CAP_NET_ADMIN permission to the firewall program, allowing it to manage network settings.
[0046] When a target task process needs to be executed, the master process reads the target permissions required by the target task process from the permission configuration information. These permissions can include file read / write permissions, network access permissions, device operation permissions, and other system resource access permissions. The master process assigns these permissions to the target task process, enabling it to perform the required operations.
[0047] For example, in conjunction with the libcap library operation permissions of the Linux system, before the task is executed, the program dynamically loads the required permissions according to the task requirements. The CAP_NET_ADMIN permission is loaded by calling the following code:
[0048] #include<sys / capability.h>
[0049] void enable_capability(cap_value_t cap)
[0050] {
[0051] cap_t caps=cap_get_proc();
[0052] cap_set_flag(caps,CAP_EFFECTIVE,1,&cap,CAP_SET);
[0053] cap_set_proc(caps); / / Application permission settings
[0054] cap_free(caps); / / release permission object
[0055] }
[0056] After loading permissions, the program can perform tasks related to network settings, such as adding or modifying firewall rules. After the task is completed, the loaded permissions are immediately released to ensure that the permissions are not retained for a long time, thereby reducing security risks. The code implementation of permission release is as follows:
[0057] void disable_capability(cap_value_t cap){
[0058] cap_t caps=cap_get_proc();
[0059] cap_set_flag(caps,CAP_EFFECTIVE,1,&cap,CAP_CLEAR); /
[0060] cap_set_proc(caps);
[0061] cap_free(caps);
[0062] }
[0063] During the execution of the target task process, the main process will continuously monitor the execution status of the process. When it detects that the target task process has completed execution, the main process will immediately revoke all target permissions previously assigned to the process, ensuring that permissions are not occupied for a long time or used maliciously.
[0064] Through this dynamic permission management method, the system can ensure that the task process has the corresponding permissions only when needed, and immediately revoke the permissions when not needed, thereby minimizing the risk of permission abuse and improving the security and stability of the system.
[0065] The process of assigning and revoking permissions described above relies on the Script Automation Management Module. Through this module, users gain direct access to complex permission management configuration files. Simply running an initial script fully automates the entire process of assigning, loading, and executing permissions, eliminating the need for manual intervention and significantly improving the flexibility of permission management.
[0066] In addition, in some optional implementations, a log audit module is also deployed to record detailed logs of each permission, assigned task execution, and permission recovery in the system. The log content recorded by this module includes: user identity, task type, assigned permission type and scope, time of permission loading and release, and the results of task execution. These log information is stored in an encrypted manner and does not allow authorized access or. In addition, the log audit module also provides search and analysis functions, which allows administrators to quickly locate relevant operation records by task number, user ID or time range, thereby more accurately evaluating permission usage and optimizing permission management strategies.
[0067] In some optional implementations, step S101 includes:
[0068] Step a1: independently configure the permissions required by each system task process at different execution stages through the main process to obtain the corresponding stage permissions of each system task process at different execution stages;
[0069] Step a2: Generate permission configuration information based on the configured stage permissions.
[0070] Specifically, the embodiment of the present invention further refines the permission configuration process based on step S101. In this embodiment, the main process not only performs overall permission configuration for each system task process, but also performs more detailed configuration for the permission requirements of the task process at different execution stages.
[0071] In this embodiment, the main process first analyzes the execution flow of each system task process and divides the execution process of each task process into multiple execution phases. For example, for a file processing task, it can be divided into three execution phases: file reading phase, file processing phase, and file writing phase.
[0072] The main process then determines the permissions required for each execution phase of each task process, forming the phase permissions. For example, the file reading phase only requires the file read permission, the file processing phase may require the memory operation permission, and the file writing phase requires the file write permission.
[0073] Finally, the master process integrates the stage permissions of all task processes at all execution stages to generate a complete permission configuration information. This permission configuration information contains a list of specific permissions required by each task process at each execution stage, forming a multi-dimensional permission configuration matrix.
[0074] Through this fine-grained permission configuration method, the system can more accurately control the permissions of the task process at different execution stages, further reducing the risk of excessive permission configuration and improving system security.
[0075] In some optional implementations, step S102 includes:
[0076] Step b1, determining the execution phase of the target task process;
[0077] Step b2: Read the corresponding target stage permissions from the permission configuration information according to the execution stage;
[0078] Step b3: Allocate the target stage authority to the target task process.
[0079] Specifically, based on the configuration of the above-mentioned stage permissions, the permission allocation process when the target task process is executed is further refined. In this embodiment, the main process will dynamically allocate and reclaim permissions according to the current execution stage of the target task process.
[0080] When the target task process begins execution, the main process first determines the current execution phase of the process. This can be achieved by monitoring the task process's execution status, analyzing its execution instructions, or receiving a phase identifier sent by the task process. After determining the execution phase, the main process searches the permission configuration information for the target phase permissions corresponding to the task process in the current execution phase. Target phase permissions refer to the set of permissions required by the task process in a specific execution phase and are a subset of the permission configuration information. The main process then assigns the target phase permissions to the target task process, enabling it to perform operations in the current phase. This assignment can be achieved through system calls, inter-process communication, or permission control interfaces. Through this dynamic permission allocation based on execution phase, the system ensures that the task process only obtains the permissions required for each execution phase, rather than all permissions at once, further improving system security and resource utilization efficiency.
[0081] In some optional embodiments, step b1 includes:
[0082] Step b11: Before each execution phase of the target task process is executed, the execution phase to be executed is determined in advance at a preset time.
[0083] Specifically, the embodiment of the present invention further refines the method for determining the execution phase of the target task process. In this embodiment, the main process will determine the execution phase of the task process in advance at a preset time so as to prepare and allocate permissions in a timely manner.
[0084] For example, the master process predicts the start time of each execution phase based on the execution patterns and historical data of the task process. At a preset time before the start of each execution phase, the master process determines the upcoming phase and prepares the permissions required for that phase in advance.
[0085] The preset time can be adjusted based on factors such as system performance, task complexity, and permission allocation overhead. For example, for systems with high permission allocation overhead, a longer preset time can be set to ensure permissions are ready before the execution phase begins. For systems with high real-time requirements, a shorter preset time can be set to reduce the impact of permission preparation on system response speed.
[0086] By presetting the execution phase in advance, the system can allocate permissions more smoothly, reduce task execution interruptions or delays caused by delayed permission allocation, and improve the overall system performance and user experience.
[0087] In some optional implementations, step S103 includes:
[0088] Step c1, detecting whether the current execution phase of the target task process is completed;
[0089] Step c2: When the current execution phase is completed, the corresponding target phase authority is revoked.
[0090] Specifically, based on the configuration of the above-mentioned stage permissions, the permission reclaiming logic when the target task process is executed is also adjusted. In this embodiment, the main process not only monitors the execution status of the entire task process, but also monitors the completion of the task process in each execution stage. When it is detected that a certain execution stage is completed, the main process will immediately reclaim the target stage permissions corresponding to that stage, rather than waiting until the entire task process is completed to reclaim all permissions. Detecting whether the execution stage is completed can be achieved in a variety of ways, such as monitoring the execution instructions of the task process, analyzing the resource usage of the task process, receiving the stage completion signal sent by the task process, etc. When it is confirmed that a certain execution stage is completed, the main process will immediately reclaim the permissions corresponding to that stage to ensure that the permissions will not be occupied for a long time. For example, the code process for loading and releasing a stage permission is:
[0091] enable_capability(CAP_NET_ADMIN) / / Execute network configuration;
[0092] disable_capability(CAP_NET_ADMIN);
[0093] enable_capability(CAP_DAC_READ_SEARCH) / / Perform backup operation;
[0094] disable_capability(CAP_DAC_READ_SEARCH).
[0095] Through the dynamic permission recovery method based on the execution phase in the embodiment of the present invention, the system can recover no longer needed permissions in a more timely manner, reduce the risk of permission abuse, and improve the security and resource utilization efficiency of the system.
[0096] In some optional implementations, the above step a1 includes:
[0097] Step a11, obtaining the historical log of the system task process;
[0098] Step a12: Call the big model to analyze historical logs and predict the permissions required by each system task process at different execution stages;
[0099] Step a13, independently configuring the permissions required by each system task process at different execution stages based on the prediction information;
[0100] Step a14: When each system task process is executed, an error message of each system task process is obtained, and the configured stage authority is adjusted according to the error message.
[0101] Specifically, in this embodiment, the main process will use the large model to analyze historical logs, predict the permissions required by the task process at different execution stages, and dynamically adjust the permission configuration according to the execution situation.
[0102] In this embodiment, the main process first collects the historical execution logs of the system task process, including the task process execution time, resource usage, permission request records, execution results, etc. These historical logs provide an important reference for permission configuration.
[0103] The main process then calls the big model to analyze the historical logs. The big model can be an intelligent analysis system based on machine learning or deep learning, capable of identifying patterns in the permissions requirements of task processes at different execution stages from historical data. For example, in some optional implementations, the big model can include, but is not limited to, the Hunyuan big model, the GPT big model, the Deepseek big model, etc. Through analysis, the big model can predict the permissions that each task process may require at each execution stage and provide permission configuration recommendations.
[0104] Based on the predictions from the large model, the master process independently configures the permissions required for each system task process at different execution stages, forming the initial stage-by-stage permission configuration. During task process execution, the master process also monitors the execution status of the task process, specifically collecting error messages caused by insufficient permissions. If a task process encounters an error indicating insufficient permissions at a particular execution stage, the master process adjusts the permission configuration for that stage based on the error message to ensure normal execution of the task process.
[0105] The embodiment of the present invention uses a permission configuration method based on large model analysis and dynamic adjustment, so that the system can more intelligently predict and meet the permission requirements of task processes, reduce the workload of manual configuration, and improve the accuracy of permission configuration and the system's adaptability.
[0106] In some optional implementations, before step S102, the method further includes:
[0107] Step d1, sending a confirmation message to each system task process through the main process, so that each system task process feeds back the permission configuration data;
[0108] Step d2: Verify the correctness of the permission configuration data based on the comparison between the permission configuration information and the permission configuration data;
[0109] Step d3: If the verification is successful, then continue to execute the step of reading the target permission required for the target task process to execute from the permission configuration information by the main process when the target task process is executed, and assigning the target permission to the target task process;
[0110] Step d4: If the verification fails, reconfigure the permissions.
[0111] Specifically, if Figure 2 As shown, the embodiment of the present invention further adds a permission verification process. In this embodiment, the main process will verify the correctness of the permission configuration before configuring the permission to ensure the security and accuracy of the permission configuration.
[0112] Before configuring permissions, the master process sends a confirmation message to each system task process, requesting feedback on the current permission configuration status. This confirmation message can contain information such as the task process's identity and permission verification request, and is sent to each task process via the inter-process communication mechanism.
[0113] After receiving the confirmation message, each system task process checks its own permission configuration status and feeds the permission configuration data back to the master process. This permission configuration data includes the task process's current permissions list and permission status. Upon receiving the permission configuration data, the master process compares it with the permission configuration information to verify the correctness of the permission configuration. This comparison includes information such as permission type, scope, and validity period to ensure that the task process's actual permission configuration is consistent with the intended one.
[0114] If the verification passes, the permissions are configured correctly, and the main process will proceed to the subsequent permission allocation steps. If the verification fails, it indicates that there is an anomaly in the permissions configuration, and the main process will reconfigure the permissions to ensure system security and stability. Through this permission verification mechanism, the system can promptly detect and correct errors or anomalies in the permissions configuration, preventing security risks or system failures caused by improper permissions configuration, and improving system reliability and security.
[0115] For example, using the command getcap / usr / local / bin / firewall will return the current program's permissions: / usr / local / bin / firewall = cap_net_admin + ep, indicating that the CAP_NET_ADMIN permission has been successfully assigned to the program. If you discover a configuration error or missing permissions, you can reconfigure them using setcap or remove all configured capabilities using the setcap –r command (e.g., sudo setcap -r / usr / local / bin / firewall).
[0116] In this embodiment, a dynamic rights management device is also provided, which is used to implement the above-mentioned embodiments and preferred embodiments. The details that have been described will not be repeated here. As used below, the term "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0117] This embodiment provides a dynamic rights management device, such as Figure 3 Shown, including:
[0118] The basic permission configuration module 301 is used to configure the permissions of each system task process through the main process and generate permission configuration information;
[0119] The dynamic permission allocation module 302 is used to read the target permission required for the target task process to execute from the permission configuration information through the main process when the target task process is executed, and allocate the target permission to the target task process;
[0120] The dynamic permission recovery module 303 is used to detect whether the target task process has been completed through the main process, and to recover the target permission when the target task process has been completed.
[0121] In some optional implementations, the basic permission configuration module includes:
[0122] The stage authority configuration unit is used to independently configure the authority required by each system task process at different execution stages through the main process, and obtain the stage authority corresponding to each system task process at different execution stages;
[0123] The configuration information generating unit is used to generate permission configuration information based on the configured stage permission.
[0124] In some optional implementations, the dynamic permission allocation module includes:
[0125] A phase determination unit, used to determine the execution phase of the target task process;
[0126] A stage permission reading unit is used to read the corresponding target stage permission from the permission configuration information according to the execution stage;
[0127] The dynamic permission allocation unit is used to allocate the target stage permissions to the target task process.
[0128] In some optional implementations, the stage determination unit includes:
[0129] The pre-start unit is used to determine the execution phase to be executed in advance before each execution phase of the target task process is executed.
[0130] In some optional implementations, the dynamic permission recovery module includes:
[0131] The phase end detection unit is used to detect whether the current execution phase of the target task process has been completed;
[0132] The stage permission recovery unit is used to recover the corresponding target stage permission when the current execution stage is completed.
[0133] In some optional implementations, before the dynamic permission allocation module, the following is further included:
[0134] Configuration feedback module, used to send confirmation messages to each system task process through the main process, so that each system task process can feedback the permission configuration data;
[0135] Configuration verification module, used to verify the correctness of permission configuration data based on the comparison between permission configuration information and permission configuration data;
[0136] The verification module is used to continue to execute the steps of reading the target permission required for the target task process to execute from the permission configuration information through the main process and allocating the target permission to the target task process if the verification passes;
[0137] The verification failure module is used to reconfigure permissions if verification fails.
[0138] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0139] The embodiment of the present invention also provides a computer device having the above Figure 4 The dynamic rights management device shown.
[0140] See also Figure 4 , Figure 4 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 4 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 4 A processor 10 is taken as an example.
[0141] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0142] The memory 20 stores instructions that can be executed by at least one processor 10, so as to enable at least one processor 10 to execute the method shown in the above embodiment.
[0143] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0144] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0145] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or a communication network.
[0146] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0147] A portion of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium that can be accessed by the computer.
[0148] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A dynamic rights management method, characterized in that: The method comprises: Configure permissions for each system task process through the main process and generate permission configuration information; When the target task process is executed, the main process reads the target permission required for the target task process to execute from the permission configuration information, and allocates the target permission to the target task process; The main process detects whether the target task process has been completed, and reclaims the target permission when the target task process has been completed.
2. The method according to claim 1, characterized in that The process of configuring permissions for each system task process through the main process to generate permission configuration information includes: The main process independently configures the permissions required by each system task process at different execution stages, and obtains the corresponding stage permissions of each system task process at different execution stages; The permission configuration information is generated based on the configured stage permission.
3. The method according to claim 2, characterized in that When the target task process is executed, the main process reads the target permission required for the target task process to be executed from the permission configuration information, and allocates the target permission to the target task process, including: Determining the execution phase of the target task process; Reading the corresponding target stage authority from the authority configuration information according to the execution stage; Allocate the target stage authority to the target task process.
4. The method according to claim 3, characterized in that Determining the execution phase of the target task process includes: Before each execution phase of the target task process is executed, the execution phase to be executed is determined in advance at a preset time.
5. The method according to claim 3, characterized in that The detecting, by the main process, whether the target task process is completed, and reclaiming the target permission when the target task process is completed, includes: Detecting whether the current execution phase of the target task process has been completed; When the current execution stage is completed, the corresponding target stage authority is reclaimed.
6. The method according to claim 2, characterized in that The main process independently configures the permissions required by each system task process at different execution stages, and obtains the corresponding stage permissions of each system task process at different execution stages, including: Get the historical log of system task process; Calling the big model to analyze the historical logs and predict the permissions required by each system task process at different execution stages; Independently configure the permissions required by each system task process at different execution stages based on the prediction information; When each system task process is executed, an error message of each system task process is obtained, and the configured stage authority is adjusted according to the error message.
7. The method according to claim 1, characterized in that When the target task process is executed, the method further includes: reading the target permission required for the target task process to execute from the permission configuration information by the main process, and before allocating the target permission to the target task process. Sending a confirmation message to each of the system task processes through the main process, so that each of the system task processes feeds back permission configuration data; Verifying the correctness of the permission configuration data based on a comparison between the permission configuration information and the permission configuration data; If the verification is passed, then continue to execute the step of, when the target task process is executed, reading the target permission required for the execution of the target task process from the permission configuration information by the main process, and allocating the target permission to the target task process; If the verification fails, reconfigure the permissions.
8. A dynamic rights management device, characterized in that: The device comprises: The basic permission configuration module is used to configure the permissions of each system task process through the main process and generate permission configuration information; A dynamic permission allocation module is used to read the target permission required for the target task process to execute from the permission configuration information through a main process when the target task process is executed, and allocate the target permission to the target task process; The dynamic permission recovery module is used to detect whether the target task process has been completed through the main process, and to recover the target permission when the target task process has been completed.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 7.