Strategy configuration method and device, storage medium and terminal

By displaying the visual configuration interface of the policy template on the display interface, obtaining and deploying the target policy, the operational complexity and conflict problems caused by the discrete policy configuration resources are solved, the centralization and visualization of policy configuration are achieved, and efficiency and consistency are improved.

CN120743330APending Publication Date: 2025-10-03BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510804468.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

In existing technologies, policy configuration resources are discretely distributed, which requires operation and maintenance personnel to frequently switch between different business modules, increasing the complexity of the operation path, and easily causing policy conflicts and priority confusion, making it difficult to achieve the expected execution effect of the global policy.

Method used

A policy configuration method is provided. By displaying a visual configuration interface of a policy template in a display interface, the policy configuration information input by the user is obtained, and the target policy is generated and deployed in response to the user's request. A unified policy template framework is used for centralized configuration and management, supporting visual interaction and dynamic orchestration of multi-dimensional policies.

Benefits of technology

It achieves the centralization and visualization of policy configuration, simplifies the operation process, reduces configuration time, avoids policy conflicts, improves configuration efficiency and consistency, and supports the full life cycle management of policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120743330A_ABST
    Figure CN120743330A_ABST
Patent Text Reader

Abstract

The invention discloses a strategy configuration method and device, a storage medium and a terminal. In response to a strategy configuration request triggered by a user, a visual configuration interface of a strategy template is displayed in a display interface, and the strategy template is used for indicating a strategy configuration process and at least one configurable strategy item for the user; acquiring strategy configuration information input by a user based on the strategy template; and in response to a strategy application request triggered by a user, generating a target strategy according to the strategy configuration information, and deploying the target strategy to a corresponding scene. According to the method, a strategy configuration process and a configurable module are subjected to unified templating, and a user can directly configure and manage a strategy according to a standardized strategy template framework through visualization processing of a strategy template; a target strategy can be generated according to strategy configuration information input by a user and deployed to a corresponding scene; in this way, scattered strategy configuration functions are aggregated, so that a user can perform centralized configuration of multi-dimensional strategies according to own requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a policy configuration method, device, storage medium, and terminal. Background Art

[0002] In the current system architecture, the configuration modules for various policies are primarily distributed, with each business module having its own built-in independent policy configuration portal and logic implementation. This functional model results in a discrete distribution of policy configuration resources, requiring operations and maintenance personnel to frequently switch between different business modules to maintain target policies. This increases the complexity of operational paths and makes policy management and control difficult. Furthermore, when business scenarios involve cross-module linkage, the decentralized configuration approach can easily lead to policy conflicts and priority confusion, making it difficult for global policies to achieve the desired execution results. Summary of the Invention

[0003] The present application provides a policy configuration method, device, storage medium and terminal, which can solve the technical problems of low policy configuration efficiency and inconvenient operation in related technologies.

[0004] In a first aspect, an embodiment of the present application provides a policy configuration method, the method comprising:

[0005] In response to a policy configuration request triggered by a user, a visual configuration interface of a policy template is displayed in a display interface, where the policy template is used to indicate the policy configuration process and at least one configurable policy item to the user;

[0006] Obtaining the policy configuration information input by the user based on the policy template;

[0007] In response to the policy application request triggered by the user, a target policy is generated according to the policy configuration information, and the target policy is deployed to the corresponding scenario.

[0008] In a possible implementation, the above method also includes: for at least one policy type, constructing a basic model for each type of policy based on the policy rules of each type of policy, the above basic model at least includes the programs, interfaces and data structures required for policy execution; generating visual description information for the policy of the existing basic model, and adding each visual description information to the above policy template.

[0009] In a possible implementation, the policy configuration process at least includes inputting basic policy information, inputting policy content, and specifying an application scope.

[0010] In a possible implementation, the above-mentioned acquisition of the policy configuration information input by the above-mentioned user based on the above-mentioned policy template includes: in the above-mentioned process of inputting basic policy information, obtaining the basic information of the above-mentioned target policy input by the above-mentioned user, and the above-mentioned basic information includes at least one of the policy name, client type, policy description, and execution priority; in the above-mentioned process of inputting policy content, obtaining the customized policy content input by the above-mentioned user after selecting the target policy type; in the above-mentioned process of specifying the application scope, obtaining the target application scope specified by the above-mentioned user for the above-mentioned target policy.

[0011] In a possible implementation, in the above-mentioned process of specifying the application scope, obtaining the target application scope specified by the above-mentioned user for the above-mentioned target policy includes: in the above-mentioned process of specifying the application scope, displaying at least two optional application dimensions in the above-mentioned policy template, and the above-mentioned optional application dimensions include at least two of the terminal, user, and label; according to the target application dimension selected by the above-mentioned user in the above-mentioned optional application dimensions, displaying the application scope configuration interface corresponding to the above-mentioned target application dimension, and obtaining the target application scope entered by the above-mentioned user in the above-mentioned application scope configuration interface.

[0012] In a possible implementation, the method further includes: in response to a policy draft storage request triggered by the user, storing the policy configuration information input by the user based on the policy template as a policy draft, so that the user can continue to operate the current policy based on the policy draft.

[0013] In a possible implementation, after displaying the visual configuration interface of the policy template in the display interface, the method further includes: displaying guidance information for at least one operation module on the visual configuration interface, wherein the guidance information includes at least a description of the current operation module and an explanation of the user operation.

[0014] In a second aspect, an embodiment of the present application provides a policy configuration device, the device comprising:

[0015] A visualization display module is used to display a visualization configuration interface of a policy template in a display interface in response to a policy configuration request triggered by a user, wherein the policy template is used to indicate the policy configuration process and at least one configurable policy item to the user;

[0016] A configuration input module is used to obtain the policy configuration information input by the user based on the policy template;

[0017] The policy application module is used to respond to the policy application request triggered by the user, generate a target policy according to the policy configuration information, and deploy the target policy to the corresponding scenario.

[0018] In a possible implementation, the above-mentioned policy configuration device also includes: a configuration method integration module, which is used to construct a basic model of each type of policy based on the policy rules of each type of policy for at least one policy type, and the above-mentioned basic model at least includes the programs, interfaces and data structures required for policy execution; generates visual description information for the policy of the existing basic model, and adds each visual description information to the above-mentioned policy template.

[0019] In a possible implementation, the policy configuration process at least includes inputting basic policy information, inputting policy content, and specifying an application scope.

[0020] In a possible implementation, the configuration input module is further used to obtain the basic information of the target policy input by the user in the process of inputting basic policy information, where the basic information includes at least one of the policy name, client type, policy description, and execution priority; in the process of inputting policy content, to obtain the customized policy content input by the user after selecting the target policy type; in the process of specifying the application scope, to obtain the target application scope specified by the user for the target policy.

[0021] In a possible implementation, the configuration input module is further used to display at least two optional application dimensions in the policy template in the process of specifying the application scope, where the optional application dimensions include at least two of the terminal, user, and label; based on the target application dimension selected by the user in the optional application dimensions, the application scope configuration interface corresponding to the target application dimension is displayed, and the target application scope entered by the user in the application scope configuration interface is obtained.

[0022] In a possible implementation, the policy configuration device further includes: a draft storage module for storing the policy configuration information input by the user based on the policy template as a policy draft in response to a policy draft storage request triggered by the user, so that the user can continue to operate the current policy based on the policy draft.

[0023] In a possible implementation, the policy configuration device further includes: a guidance module configured to display guidance information for at least one operation module on the visual configuration interface, wherein the guidance information includes at least a description of the current operation module and an explanation of the user operation.

[0024] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the above method.

[0025] In a fourth aspect, an embodiment of the present application provides a terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is suitable for being loaded by the processor and executing the steps of the above method.

[0026] The beneficial effects of the technical solutions provided by some embodiments of the present application include at least:

[0027] The present application provides a policy configuration method, which responds to a policy configuration request triggered by a user, displays a visual configuration interface of a policy template in a display interface, and the policy template is used to indicate the policy configuration process and at least one configurable policy item to the user; obtains the policy configuration information input by the user based on the policy template; responds to the policy application request triggered by the user, generates a target policy according to the policy configuration information, and deploys the target policy to the corresponding scenario. The embodiment of the present application uniformly templates the policy configuration process and the configurable module, and through the visualization of the policy template, enables the user to configure and manage the policy directly on the display interface according to the standardized policy template framework when the policy configuration is required; when the user needs to apply the configured policy, the target policy can be generated according to the policy configuration information input by the user in the policy template, and the target policy can be deployed to the corresponding scenario; in this way, through a unified policy management central structure, the scattered policy configuration functions are aggregated, so that the user can centrally configure multi-dimensional policies according to their own needs, and realize the dynamic arrangement of policy parameters through a visual interactive interface, so that the user can achieve the whole life cycle management of the policy, such as creation, debugging, and release, through simple operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0029] Figure 1 An exemplary system architecture diagram of a policy configuration method provided in an embodiment of the present application;

[0030] Figure 2 A flowchart of a policy configuration method provided in an embodiment of the present application;

[0031] Figure 3 A flowchart of a policy configuration method provided in an embodiment of the present application;

[0032] Figure 4 An example diagram of a visual configuration interface for a policy template provided in an embodiment of the present application;

[0033] Figure 5 An example diagram of a guide interface for a policy template provided in an embodiment of the present application;

[0034] Figure 6 An example diagram of a configuration process of a policy template provided in an embodiment of the present application;

[0035] Figure 7 A structural block diagram of a policy configuration device provided in an embodiment of the present application;

[0036] Figure 8 A schematic diagram of the structure of a terminal provided in an embodiment of the present application. DETAILED DESCRIPTION

[0037] To make the features and advantages of this application more obvious and easy to understand, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.

[0038] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims. And in the description of the embodiments of the present application, unless otherwise indicated, " / " means or, for example, A / B can mean A or B: "and / or" in the text is only a way to describe the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" refers to two or more than two.

[0039] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.

[0040] In the existing system architecture, the policy configuration functions related to business scenarios (such as risk policies, security policies, etc.) are vertically characterized, that is, each business department builds a policy management module based on an independent technology stack. In this isolated and decentralized policy management method, the policy configuration entrance is deeply nested in the functional modules of different business systems. Operations and maintenance personnel often need to switch between multiple management systems, business middle platforms and other multi-level interfaces when configuring policies. At the operational level, the distributed operation mode leads to increased time consumption and low efficiency in policy configuration. In general, the configuration functions of various business policies are fragmented and distributed. This decentralized management mode requires operations and maintenance personnel to adjust policy parameters across multiple subsystem interfaces, which not only increases the complexity of operations, but also easily leads to policy version confusion and configuration conflicts.

[0041] Therefore, an embodiment of the present application provides a policy configuration method to solve the above-mentioned technical problems of low policy configuration efficiency and inconvenient operation.

[0042] See also Figure 1 , Figure 1 This is an exemplary system architecture diagram of a policy configuration method provided in an embodiment of the present application.

[0043] like Figure 1 As shown, the system architecture may include a terminal 101, a network 102, and a server 103. The network 102 is used to provide a medium for a communication link between the terminal 101 and the server 103. The network 102 may include various types of wired communication links or wireless communication links, for example, a wired communication link may include an optical fiber, a twisted pair, or a coaxial cable, and a wireless communication link may include a Bluetooth communication link, a Wireless-Fidelity (Wi-Fi) communication link, or a microwave communication link.

[0044] The terminal 101 can interact with the server 103 through the network 102 to receive a message from the server 103 or send a message to the server 103, or the terminal 101 can interact with the server 103 through the network 102 to receive a message or data sent by other users to the server 103. The terminal 101 can be hardware or software. When the terminal 101 is hardware, it can be various electronic devices, including but not limited to smart watches, smart phones, tablet computers, laptop portable computers and desktop computers. When the terminal 101 is software, it can be installed in the electronic devices listed above, which can be implemented as multiple software or software modules (for example: for providing distributed services), or it can be implemented as a single software or software module, which is not specifically limited here.

[0045] In an embodiment of the present application, when the user is configuring a policy, the terminal 101 first responds to the policy configuration request triggered by the user, and displays a visual configuration interface of the policy template in the display interface. The policy template is used to indicate the policy configuration process and at least one configurable policy item to the user; further, the terminal 101 can obtain the policy configuration information input by the user based on the policy template; when the user completes the configuration and wants to apply the configured policy, the terminal 101 responds to the policy application request triggered by the user, generates a target policy according to the policy configuration information, and deploys the target policy to the corresponding scenario.

[0046] The server 103 may be a business server that provides various services. It should be noted that the server 103 may be hardware or software. When the server 103 is hardware, it may be implemented as a distributed server cluster consisting of multiple servers, or it may be implemented as a single server. When the server 103 is software, it may be implemented as multiple software or software modules (for example, for providing distributed services), or it may be implemented as a single software or software module, which is not specifically limited herein.

[0047] Alternatively, the system architecture may also not include the server 103. In other words, the server 103 may be an optional device in the embodiments of this specification, that is, the method provided in the embodiments of this specification may be applied to a system structure that only includes the terminal 101, and the embodiments of this application do not limit this.

[0048] It should be understood that Figure 1 The number of terminals, networks, and servers in the figure is only for illustration and any number of terminals, networks, and servers may be used according to implementation requirements.

[0049] See also Figure 2 , Figure 2 This is a flowchart of a policy configuration method provided in an embodiment of the present application. The execution subject of this embodiment of the present application can be a terminal executing the policy configuration, a processor within the terminal executing the policy configuration method, or a policy configuration service within the terminal executing the policy configuration method. For ease of description, the specific execution process of the policy configuration method is described below using the terminal processor as an example.

[0050] like Figure 2 As shown, the policy configuration method may at least include:

[0051] S202: In response to a policy configuration request triggered by a user, a visual configuration interface of a policy template is displayed in a display interface, where the policy template is used to indicate a policy configuration process and at least one configurable policy item to the user.

[0052] Optionally, in order to improve the efficiency of policy configuration, the embodiment of the present application integrates the policy configuration modules under all business scenarios into a unified configuration interface. During the specific implementation process, when it is detected that the user triggers a policy configuration request through a human-computer interaction device (such as a mobile terminal, a computer terminal, etc.), the front end can immediately call the preset interface rendering engine to generate a visual configuration interface of the policy template on the display interface of the device. In a feasible implementation example, the interface can adopt a three-column layout structure, with a process navigation bar on the upper side, which can display the various process nodes in the policy configuration process in a tree structure; below the process navigation bar is the main workspace, which is used to load the standardized policy template associated with the currently selected process node. At least one configurable policy item can also be dynamically displayed through the property panel in the main workspace.

[0053] Specifically, the policy template contains global process instructions and modular configuration units, where the global process instructions correspond to the predefined configuration stages and mark the execution order; the modular configuration units are presented in the form of a list, and each module is logically connected through a standardized interface. Users can clearly know the policy types that can be configured at present through the policy template, and configure specific execution parameters for this policy through the parameter input panel. This not only realizes the centralization and visualization of policy configuration, but also helps to provide a reusable policy execution framework for the business system through standardized policy service output capabilities, and supports the rapid policy iteration requirements in complex business scenarios. In a feasible implementation example, a dynamic verification mechanism can be implemented during the parameter input process, that is, when a parameter type mismatch or a logical conflict is detected, a red warning sign is immediately displayed next to the parameter input box, accompanied by haptic feedback information such as vibration and sound.

[0054] S204: Obtain policy configuration information input by the user based on the policy template.

[0055] Optionally, users can enter policy configuration information in the policy template's visual configuration interface by clicking, dragging, etc. Policy configuration information includes, but is not limited to, policy metadata definitions, validation conditional expressions, resource scheduling rules, and exception handling mechanisms. Conditional expressions are composed of logical operators and business object attributes to form parsable rules.

[0056] In a feasible implementation, in order to ensure the feasibility and compliance of the configured policy, as the user inputs, the backend of the device will continue to monitor the user's operations on the frontend, and convert the user's operation traces on interactive elements such as input boxes, drop-down selectors, and logical relationship connection lines into incremental configuration data streams, and transmit the data stream to the background verification module in the form of asynchronous messages. The received configuration information is verified using a preset verification mechanism (such as JSON Schema). Verification dimensions include policy conflict detection, resource dependency verification, field integrity, data type compliance, permission compliance review, etc. When abnormal input is detected, an abnormal prompt mechanism is introduced to trigger a visual alarm mark in real time at the front-end interface layer. Furthermore, the correction module can also analyze historical compliance policy data and dynamically generate correction suggestion prompts when triggering the alarm mark. Users can modify and adjust the current input through the correction suggestion prompts. In addition, the correction suggestion prompts can also provide users with recommended input information, so that users can directly click on the suggestion items to automatically replace and re-verify the abnormal input information.

[0057] S206 : In response to the policy application request triggered by the user, generate a target policy according to the policy configuration information, and deploy the target policy to the corresponding scenario.

[0058] Optionally, after the user completes the configuration, the policy application request can be triggered through the control on the interface. When applying the current configuration according to the policy configuration information, it is first necessary to compile the target policy according to the policy configuration information to convert the visual configuration information into an executable policy. In an embodiment of the present application, the policy compilation process includes at least three stages: first, in the syntax parsing stage, the configuration data is converted into an abstract syntax tree; further in the semantic verification stage, the policy logic loop and permission boundaries are checked; finally, in the optimization stage, redundant configuration items are merged. The policy compilation process converts discrete configuration information into a standardized policy description file that meets the requirements of the policy execution rules, thereby generating a policy metadata package, which includes but is not limited to control metadata such as version identifier, effective time window, application scenario label, and release policy.

[0059] Furthermore, after the policy file of the target policy is prepared, the target policy needs to be deployed to the corresponding application scenario to achieve the expected policy application purpose. During the policy deployment phase, the target execution environment is automatically matched according to the application scenario label in the policy file, and the policy package is distributed to the corresponding node through the configuration center. The scope of the policy can be roughly divided into two categories, one is global and the other is local. In this embodiment of the present application, the push path can be selected according to the type of policy scope. For globally effective policies, multi-node synchronous push can be performed through the distributed configuration center; and for local effective policies, the service grid architecture can be used for targeted policy injection.

[0060] In a feasible implementation, when the policy is deployed, the full-link log of the policy loading is also collected in real time, including key node information such as the policy issuance status, node reception confirmation, and execution result feedback, as well as recording and verifying the relationship between the policy instance and the original configuration information, to ensure the version consistency of the online policy and the configuration terminal in the application environment. When a deployment anomaly is detected, the rollback process can be automatically triggered and an alarm notification can be pushed to the operation and maintenance management end. After the policy takes effect, the policy execution status can also be continuously and dynamically monitored, and runtime data such as policy execution time and resource consumption can be collected through a preset monitoring indicator system. If it is detected that the policy execution deviation exceeds the preset threshold, a policy optimization suggestion is further generated and pushed to the policy management node. The policy optimization suggestion can include specific improvement measures such as module replacement solutions, parameter adjustment intervals, and dependency optimization to form a closed-loop optimization mechanism for policy management.

[0061] In an embodiment of the present application, a policy configuration method is provided. In response to a policy configuration request triggered by a user, a visual configuration interface of a policy template is displayed in a display interface. The policy template is used to indicate the policy configuration process and at least one configurable policy item to the user; obtain the policy configuration information input by the user based on the policy template; in response to a policy application request triggered by the user, a target policy is generated according to the policy configuration information, and the target policy is deployed to the corresponding scenario. The embodiment of the present application uniformly templates the policy configuration process and the configurable module, and through the visualization of the policy template, when the user needs to configure the policy, the policy can be directly configured and managed according to the standardized policy template framework on the display interface; when the user needs to apply the configured policy, the target policy can be generated according to the policy configuration information input by the user in the policy template, and the target policy can be deployed to the corresponding scenario; in this way, through a unified policy management central structure, the scattered policy configuration functions are aggregated, so that the user can centrally configure the multi-dimensional policy according to his own needs, and realize the dynamic arrangement of policy parameters through a visual interactive interface, so that the user can achieve the whole life cycle management of the policy, such as creation, debugging, and release, through simple operations.

[0062] See also Figure 3 , Figure 3 A flowchart of a policy configuration method provided in an embodiment of the present application.

[0063] like Figure 3 As shown, the policy configuration method may at least include:

[0064] S302: For at least one policy type, construct a basic model for each policy type based on the policy rules of each policy type. The basic model at least includes the program, interface, and data structure required for policy execution.

[0065] Optionally, in the process of building a unified policy configuration template, a rule-driven policy modeling mechanism needs to be established first for specific domain policy types. When building policy templates for various policies, this can be achieved through a template automatic construction engine. The template automatic construction engine can deconstruct the existing policy rule set through semantic analysis technology, identify the decision logic, constraints and execution paths implicit in the rules, and then extract the basic pattern elements of each type of policy. For example, in a network security policy scenario, access control list rules, intrusion detection rules and encryption protocol configurations can be parsed to extract rule templates containing core dimensions such as traffic direction, protocol type, port range, etc., thereby building a policy template suitable for network security policy scenarios. When users configure policies for network security scenarios, they can directly choose to use the corresponding type of policy template and enter specific parameter information to directly obtain the applicable target policy.

[0066] In the embodiment of the present application, the constructed basic model needs to include at least the core elements of the program, interface and data structure required for policy execution. Specifically, the program required for policy execution can be encapsulated by encapsulating a reusable decision engine and forming an efficient policy matching algorithm based on a precompiled rule set to encapsulate the general program; the standardized interface can ensure the seamless call and deployment of the policy by defining the interaction protocol with the external system; the data structure level can be designed by designing a policy metadata model, covering common attribute fields such as rule priority, effective period, associated resource identifier, etc., and at the same time building a runtime context container to store dynamic parameters during policy execution (such as session status, resource load indicators), so as to ensure the unification and standardization of the data structure of the same type of policy.

[0067] S304: Generate visual description information for the existing basic model policy, and add each visual description information to the policy template.

[0068] Optionally, after extracting the basic models of various types of policies, you can generate visual description information for the existing basic model policies and add each visual description information to the policy template, so that when configuring policies, users can directly enter customized parameters, data, etc. in the existing basic model policy template to achieve rapid configuration and application of policies. Figure 4 , Figure 4 This is an example diagram of a visual configuration interface of a policy template provided in an embodiment of the present application. Figure 4 As shown in the figure, the types of policies include asset-centric policy, risk management policy, terminal defense policy, detection and response policy, Internet access management policy, etc., and each type of policy template may also be divided into multiple sub-templates. For example, when the asset-centric policy is selected (in Figure 4 (A green box indicates the selected policy template). Next to the policy type selection area, the corresponding sub-templates of the selected policy template appear: Basic Settings, Terminal Customization, and so on. Each sub-template has its own specific content. For example, in the Basic Settings template, users can configure the client's mailing address and password protection; in the Terminal Customization template, users can customize the client logo, product name, and other features. This greatly facilitates policy configuration.

[0069] Specifically, in the stage of generating visual description information, multi-dimensional expressions can also be adopted according to the specific features contained in the policy template. For example, for policies with a correlation between input and output, the decision-making process can be displayed based on the construction of a state diagram, the input-output relationship can be presented using a data flow diagram, and the policy triggering timing can be depicted through a timing diagram, so that users can understand the relationship between the nodes in the policy and configure the policy information in each node in compliance.

[0070] S306 . In response to a policy configuration request triggered by the user, display a visual configuration interface of a policy template in a display interface. The policy template is used to indicate a policy configuration process and at least one configurable policy item to the user.

[0071] Regarding step S306, please refer to the detailed description in step S202, which will not be repeated here.

[0072] S308: Displaying guidance information for at least one operation module on the visual configuration interface, where the guidance information at least includes a description of the current operation module and an explanation of the user operation.

[0073] Optionally, when the user triggers a policy configuration request, the visual configuration interface of the policy template displayed in the display interface is as follows: Figure 4As shown, it includes multiple types of configurable strategies, and in the visual configuration interface, it includes multiple operation modules that can interact with users. These operation modules are used for users to perform various operations such as selecting strategy types and inputting strategy information.

[0074] Specifically, see Figure 5 , Figure 5 This is an example diagram of a guide interface for a policy template provided in an embodiment of the present application. Figure 5 As shown in FIG, when a user enters the visual configuration interface, guidance information can be displayed for at least one operation module. The guidance information is used to provide the user with a description of the current operation module, an explanation of the user's operation, etc. Figure 5 In the example, the non-guide area (gray area) is reduced in brightness to highlight the guide area (white primary color area), and a white guide box pointing to the guide area is used to display the introduction and functions of the module: for example, "Currently, it is the asset center strategy classification; click to configure the strategy under this type." In addition, for first-time users, the guide box can also include more detailed introduction dimensions, such as functional positioning, core usage, and typical application scenarios; and for old users with configuration records, more complex and advanced module linkage relationship descriptions and advanced configuration tips can be displayed in the guide box, so as to help both new and old users quickly get started and improve the efficiency of strategy configuration. Figure 5 As shown, for a continuous operation sequence, the guidance steps can be expanded in stages. Specifically, the user is prompted to use the streaming step number to indicate the order of use of each operation module, so that the user understands the order of steps in the policy configuration process. Taking a total of 4 steps as an example, the embodiment of the present application uses "1 / 4" to represent the first step, "2 / 4" to represent the second step, and so on. In this way, the user can quickly skip the guidance process by triggering the "Skip" control in the guidance box, or jump to the next guidance prompt by triggering the "Next" control.

[0075] S310 . In the process of inputting basic policy information, obtain basic information of the target policy input by the user, where the basic information includes at least one of the policy name, client type, policy description, and execution priority.

[0076] See also Figure 6 , Figure 6 This is an example diagram of a configuration process of a policy template provided in an embodiment of the present application. In an embodiment of the present application, the policy configuration process may specifically include three steps: inputting basic policy information, inputting policy content, and specifying the application scope. First, when the user configures the policy, such as Figure 6As shown in (A), you first need to enter the basic information of this policy. During the process of entering the basic policy information, users can enter the basic information of the policy being configured, including the policy name, select the client type, policy description, and execution priority. When selecting the client type, users can develop exclusive policies based on different device types (such as computers, mobile phones, tablets, etc.) and operating systems (such as Windows, macOS, Android, iOS, etc.) in the terminal dimension to ensure that each terminal meets the standards in terms of security, performance, and functionality. Regarding the execution priority, users specifically determine whether the policy is mandatory based on the priority of this policy.

[0077] S312: In the process of inputting policy content, obtain the customized policy content input by the user after selecting the target policy type.

[0078] Alternatively, as Figure 6 As shown in (B), after completing the basic information input, the user enters the policy content input process. In this step, the user can select a specific policy type and customize the policy they need under the template of the specific policy type. That is, the terminal obtains the customized policy content entered by the user after selecting the target policy type through user operation.

[0079] S314. In the process of specifying the application scope, obtain the target application scope specified by the user for the target policy.

[0080] Furthermore, if Figure 6 As shown in (C), when the user has completed the configuration of the detailed content in the policy, the process of specifying the application scope will be entered. In this step, the user can specify the target application scope for the target policy. Specifically, in the process of specifying the application scope, at least two optional application dimensions are displayed in the policy template. In the embodiment of the present application, the specific optional application dimensions include terminal, user, and label. The user can first select the application dimension according to the configuration requirements so as to perform a more detailed configuration based on the application dimension. That is, in the display interface of the terminal, the application scope configuration interface corresponding to the target application dimension is displayed according to the target application dimension selected by the user in the optional application dimension, and the target application scope entered by the user in the application scope configuration interface is obtained based on the user's further operation.

[0081] S316 . In response to a policy draft storage request triggered by the user, the policy configuration information input by the user based on the policy template is stored as a policy draft, so that the user can continue to operate the current policy based on the policy draft.

[0082] Optionally, in order to facilitate users to configure policies, considering that users may need to modify and pre-store configurations of policies multiple times, the embodiment of the present application also supports users to store current configuration information as policy drafts, so that users can configure and modify policies at any time. In the interactive scenario where the user triggers a policy draft storage request, when the user performs a save operation in the policy configuration interface (which can be triggered automatically by a shortcut key combination, a floating button click, or a timer), the policy configuration system can first perform a format compliance check on the configuration parameters input by the user based on the policy template through a multi-dimensional data verification method. After the verification is passed, the current policy configuration information is encapsulated as a structured draft object, which not only contains a snapshot of the policy parameters, but also records temporary annotation information, unfinished logical branch marks, and user-defined remarks during the configuration process.

[0083] Furthermore, a hierarchical storage architecture can be specifically adopted when storing policy drafts. The base layer uses a version control engine to generate a unique timestamp version node for each save operation, supporting historical version rollback and difference comparison. The extension layer generates a semantic fingerprint of the policy configuration through a feature vector extraction algorithm, which is used to detect duplicate drafts and similar policy patterns. When persistently storing, the system implements a dynamic encryption strategy based on the user permission system to ensure the confidentiality of data during transmission and static storage. In addition, for team collaboration scenarios, the draft editing function also supports multi-dimensional concurrency control during policy configuration. When multiple users edit the same policy draft at the same time, the system uses an operation conversion algorithm (such as an OT algorithm) to merge changes in real time, distinguish the modifications of different editors through color marking, and trigger intelligent merge suggestions when save conflicts occur.

[0084] In an embodiment of the present application, a policy configuration method is provided. For at least one policy type, a basic model for each type of policy is constructed based on the policy rules of each type of policy. The basic model includes at least the programs, interfaces, and data structures required for policy execution. Visual description information is generated for the existing basic model policy and added to the policy template to ensure the unification and standardization of the data structure of the same type of policy, which greatly facilitates user policy configuration. Guidance information for at least one operation module is displayed on the visual configuration interface. The guidance information includes at least a description of the current operation module and an explanation of user operations, helping both new and old users to quickly get started and improve policy configuration efficiency. The policy configuration process can specifically include three steps: entering basic policy information, entering policy content, and specifying the scope of application. The decentralized policy configuration functions are aggregated and reconstructed to support centralized configuration of multi-dimensional and multi-process policies. Dynamic orchestration of policy parameters is achieved through a visual interactive interface, helping users easily configure policies, gain clear insights into policy operation, and manage policies in a fine-grained manner. This meets the collaborative needs of different roles in policy formulation, review, and release, ultimately forming a closed-loop management capability covering the entire policy lifecycle.

[0085] See also Figure 7 , Figure 7 This is a structural block diagram of a policy configuration device provided in an embodiment of the present application.

[0086] like Figure 7 As shown, the policy configuration device 700 includes:

[0087] A visualization display module 710 is configured to display a visualization configuration interface of a policy template in a display interface in response to a policy configuration request triggered by a user, where the policy template is used to indicate a policy configuration process and at least one configurable policy item to the user;

[0088] Configuration input module 720, used to obtain policy configuration information input by the user based on the policy template;

[0089] The policy application module 730 is configured to generate a target policy according to the policy configuration information in response to a policy application request triggered by a user, and deploy the target policy to a corresponding scenario.

[0090] Optionally, the policy configuration device 700 also includes: a configuration method integration module, which is used to construct a basic model for each type of policy based on the policy rules of each type of policy for at least one policy type, and the basic model includes at least the programs, interfaces and data structures required for policy execution; generates visual description information for the policy of the existing basic model, and adds each visual description information to the policy template.

[0091] Optionally, the policy configuration process at least includes inputting basic policy information, inputting policy content, and specifying an application scope.

[0092] Optionally, the configuration input module 720 is also used to obtain the basic information of the target policy input by the user in the process of inputting basic policy information, the basic information including at least one of the policy name, client type, policy description, and execution priority; in the process of inputting policy content, obtain the customized policy content entered by the user after selecting the target policy type; in the process of specifying the application scope, obtain the target application scope specified by the user for the target policy.

[0093] Optionally, the configuration input module 720 is also used to display at least two optional application dimensions in the policy template in the process of specifying the application scope, and the optional application dimensions include at least two of the terminal, user, and label; according to the target application dimension selected by the user in the optional application dimension, the application scope configuration interface corresponding to the target application dimension is displayed, and the target application scope entered by the user in the application scope configuration interface is obtained.

[0094] Optionally, the policy configuration device 700 further includes: a draft storage module for storing the policy configuration information input by the user based on the policy template as a policy draft in response to a policy draft storage request triggered by the user, so that the user can continue to operate the current policy based on the policy draft.

[0095] Optionally, the policy configuration device 700 further includes: a guidance module, configured to display guidance information for at least one operation module on the visual configuration interface, wherein the guidance information at least includes a description of the current operation module and an explanation of the user operation.

[0096] In an embodiment of the present application, a policy configuration device is provided, wherein a visual display module is used to display a visual configuration interface of a policy template in a display interface in response to a policy configuration request triggered by a user, wherein the policy template is used to indicate the policy configuration process and at least one configurable policy item to the user; a configuration input module is used to obtain policy configuration information input by the user based on the policy template; and a policy application module is used to generate a target policy according to the policy configuration information in response to the policy application request triggered by the user, and deploy the target policy to the corresponding scenario. The embodiment of the present application uniformly templates the policy configuration process and the configurable module, and through visual processing of the policy template, enables the user to configure and manage the policy directly on the display interface according to the standardized policy template framework when configuring the policy; when the user needs to apply the configured policy, the target policy can be generated according to the policy configuration information input by the user in the policy template, and the target policy can be deployed to the corresponding scenario; in this way, through a unified policy management central structure, the scattered policy configuration functions are aggregated, so that the user can centrally configure multi-dimensional policies according to their own needs, and realize dynamic arrangement of policy parameters through a visual interactive interface, so that the user can achieve full life cycle management such as creation, debugging, and release of policies through simple operations.

[0097] An embodiment of the present application further provides a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded by a processor and executing the steps of any method in the above embodiments.

[0098] See Figure 8 , Figure 8 This is a schematic diagram of the structure of a terminal provided in an embodiment of the present application. Figure 8 As shown, the terminal 800 may include: at least one terminal processor 801 , at least one network interface 804 , a user interface 803 , a memory 805 , and at least one communication bus 802 .

[0099] The communication bus 802 is used to implement the connection and communication between these components.

[0100] The user interface 803 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 803 may also include a standard wired interface and a wireless interface.

[0101] The network interface 804 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).

[0102] The terminal processor 801 may include one or more processing cores. The terminal processor 801 utilizes various interfaces and circuits to connect various components within the terminal 800. It executes instructions, programs, code sets, or instruction sets stored in the memory 805, and accesses data stored in the memory 805 to perform various functions and process data for the terminal 800. Optionally, the terminal processor 801 may be implemented using at least one of the following hardware forms: a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The terminal processor 801 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content displayed on the display screen; and the modem handles wireless communications. It is understood that the modem may not be integrated into the terminal processor 801 and may be implemented as a separate chip.

[0103] Among them, the memory 805 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 805 includes a non-transitory computer-readable storage medium. The memory 805 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 805 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 805 may also be optionally at least one storage device located away from the aforementioned terminal processor 801. As Figure 8 As shown, the memory 805 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a policy configuration program.

[0104] exist Figure 8In the terminal 800 shown, the user interface 803 is mainly used to provide an input interface for the user and obtain data input by the user; and the terminal processor 801 can be used to call the policy configuration program stored in the memory 805 and perform the following operations:

[0105] In response to a policy configuration request triggered by a user, a visual configuration interface of a policy template is displayed in a display interface, where the policy template is used to indicate a policy configuration process and at least one configurable policy item to the user;

[0106] Obtain policy configuration information entered by the user based on the policy template;

[0107] In response to a policy application request triggered by a user, a target policy is generated based on the policy configuration information and deployed to the corresponding scenario.

[0108] In some embodiments, the terminal processor 801 also specifically performs the following steps: for at least one policy type, construct a basic model for each type of policy based on the policy rules of each type of policy, and the basic model includes at least the programs, interfaces and data structures required for policy execution; generate visual description information for the policy of the existing basic model, and add each visual description information to the policy template.

[0109] In some embodiments, the policy configuration process at least includes inputting basic policy information, inputting policy content, and specifying an application scope.

[0110] In some embodiments, when the terminal processor 801 obtains the policy configuration information input by the user based on the policy template, it specifically performs the following steps: in the process of inputting basic policy information, the basic information of the target policy input by the user is obtained, and the basic information includes at least one of the policy name, client type, policy description, and execution priority; in the process of inputting policy content, the customized policy content entered by the user after selecting the target policy type is obtained; in the process of specifying the application scope, the target application scope specified by the user for the target policy is obtained.

[0111] In some embodiments, when the terminal processor 801 obtains the target application scope specified by the user for the target policy in the process of executing the specified application scope, it specifically performs the following steps: in the process of specifying the application scope, at least two optional application dimensions are displayed in the policy template, and the optional application dimensions include at least two of the terminal, user, and label; according to the target application dimension selected by the user in the optional application dimension, the application scope configuration interface corresponding to the target application dimension is displayed, and the target application scope entered by the user in the application scope configuration interface is obtained.

[0112] In some embodiments, the terminal processor 801 further specifically performs the following steps: in response to a policy draft storage request triggered by the user, storing the policy configuration information input by the user based on the policy template as a policy draft, so that the user can continue to operate the current policy based on the policy draft.

[0113] In some embodiments, after executing the visual configuration interface of the policy template displayed in the display interface, the terminal processor 801 further specifically performs the following steps: displaying guidance information for at least one operation module on the visual configuration interface, the guidance information including at least a description of the current operation module and an explanation of the user operation.

[0114] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.

[0115] Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of these modules may be selected to achieve the purpose of this embodiment based on actual needs.

[0116] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The above-mentioned computer program product includes one or more computer instructions. When the above-mentioned computer program instructions are loaded and executed on a computer, the above-mentioned process or function according to the embodiment of this specification is generated in whole or in part. The above-mentioned computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The above-mentioned computer instructions can be stored in a computer-readable storage medium or transmitted by the above-mentioned computer-readable storage medium. The above-mentioned computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The above-mentioned computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The above-mentioned available media can be magnetic media (for example, floppy disks, hard disks, tapes), optical media (for example, digital versatile discs (DVDs)), or semiconductor media (for example, solid state disks (SSDs)).

[0117] It should be noted that for the aforementioned method embodiments, for ease of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.

[0118] In addition, it should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in the embodiments of this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0119] The foregoing description describes specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0120] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0121] The above is a description of a policy configuration method, device, storage medium, and terminal provided in this application. For those skilled in the art, based on the ideas of the embodiments of this application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on this application.

Claims

1. A policy configuration method, characterized in that: The method comprises: In response to a policy configuration request triggered by a user, displaying a visual configuration interface of a policy template in a display interface, wherein the policy template is used to indicate a policy configuration process and at least one configurable policy item to the user; Acquiring policy configuration information input by the user based on the policy template; In response to the policy application request triggered by the user, a target policy is generated according to the policy configuration information, and the target policy is deployed to the corresponding scenario.

2. The method according to claim 1, characterized in that The method further comprises: For at least one policy type, construct a basic model for each policy type based on the policy rules of each policy type, wherein the basic model at least includes the program, interface, and data structure required for policy execution; Visual description information is generated for the existing basic model policy, and each piece of visual description information is added to the policy template.

3. The method according to claim 1, characterized in that The policy configuration process at least includes inputting basic policy information, inputting policy content, and specifying the application scope.

4. The method according to claim 3, characterized in that The acquiring of the policy configuration information input by the user based on the policy template includes: In the process of inputting basic policy information, obtaining basic information of the target policy input by the user, the basic information including at least one of a policy name, a client type, a policy description, and an execution priority; In the process of inputting policy content, obtaining the customized policy content input by the user after selecting the target policy type; In the process of specifying the application scope, the target application scope specified by the user for the target policy is obtained.

5. The method according to claim 4, characterized in that In the process of specifying the application scope, obtaining the target application scope specified by the user for the target policy includes: In the process of specifying the application scope, at least two optional application dimensions are displayed in the policy template, and the optional application dimensions include at least two of terminals, users, and tags; According to the target application dimension selected by the user from the optional application dimensions, an application range configuration interface corresponding to the target application dimension is displayed, and the target application range input by the user in the application range configuration interface is acquired.

6. The method according to claim 1, wherein The method further comprises: In response to a policy draft storage request triggered by the user, the policy configuration information input by the user based on the policy template is stored as a policy draft, so that the user can continue to operate the current policy based on the policy draft.

7. The method according to claim 1, characterized in that After displaying the visual configuration interface of the policy template on the display interface, the method further includes: Guidance information for at least one operation module is displayed on the visual configuration interface, wherein the guidance information at least includes a description of the current operation module and an explanation of the user operation.

8. A policy configuration device, characterized in that: The device comprises: A visual display module, configured to display a visual configuration interface of a policy template in a display interface in response to a policy configuration request triggered by a user, wherein the policy template is used to indicate a policy configuration process and at least one configurable policy item to the user; A configuration input module, configured to obtain policy configuration information input by the user based on the policy template; The policy application module is used to generate a target policy according to the policy configuration information in response to the policy application request triggered by the user, and deploy the target policy to the corresponding scenario.

9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the method according to any one of claims 1 to 7.

10. A terminal, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 7 when executing the program.