Domain management system-based operating system policy life cycle management method and system

By implementing an operating system policy lifecycle management method in the domain management system, supporting the creation, modification, cancellation, and deletion of policies, and customizing policy distribution based on priority rules, the problem of incomplete lifecycle management and insufficient priority configuration in existing technologies is solved, thereby improving the flexibility of policy management and user experience.

CN122137746APending Publication Date: 2026-06-02KYLIN CORP

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
KYLIN CORP
Filing Date
2026-03-17
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

The existing domain management system has an incomplete lifecycle management mechanism, which cannot support the cancellation or deletion of policies, and lacks flexible policy priority configuration, making it impossible to issue policies with different priorities based on different objects.

Method used

This paper provides a method for operating system policy lifecycle management based on a domain management system. It includes server-side response to administrators' lifecycle management operations, supports the creation, modification, cancellation, deletion and restoration of operating system policies, monitors client requests through heartbeat cycles, and distributes and cancels policies according to priority rules. It also supports custom management of various distribution objects such as organizations, clients and users.

Benefits of technology

It implements complete operating system policy lifecycle management, supports flexible issuance and cancellation for different objects, improves policy control performance, meets management needs in complex environments, and provides a better user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137746A_ABST
    Figure CN122137746A_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on domain management system's operating system policy life cycle management method and system, the present application method includes server response administrator's operating system policy life cycle management operation and the selection of issue object, according to the issue object selected, the operating system policy of update after execution management operation is issued and stored to policy database, server monitors the acquisition policy request initiated by client to server according to preset heartbeat cycle, if receiving the acquisition policy request initiated by a certain client, in policy database, the operating system policy corresponding to the client is inquired to obtain, the operating system policy found is encapsulated as policy message and sent to the client.The present application aims to improve the policy control performance of domain management system, meet the operating system policy life cycle management needs of administrator in complex working environment, provide better user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of operating system technology, and specifically to an operating system policy lifecycle management method and system based on a domain management system. Background Technology

[0002] To meet the unified and secure requirements for managing and controlling employee client usage within an enterprise or department, the domain management system needs to support a policy management platform for domain clients and users, and it needs to support complete policy lifecycle management. Currently, the lifecycle management mechanisms of existing domain management systems have the following shortcomings: 1. Incomplete lifecycle: They only support policy issuance but lack policy cancellation or deletion capabilities. 2. Inability to support different priorities: Existing solutions typically do not provide flexible policy priority configuration options, and cannot issue policies with different priorities based on different objects (such as departments, clients, group tags, and users). Furthermore, they lack the ability to make lower-priority policies take effect after the cancellation of a policy with a different priority. In summary, existing technologies have many shortcomings in policy lifecycle management, and a new solution is urgently needed to meet user needs and improve user experience. Summary of the Invention

[0003] The technical problem to be solved by this invention is to provide a method and system for operating system policy lifecycle management based on a domain management system, which addresses the above-mentioned problems in the prior art. This invention aims to improve the policy control performance of the domain management system, meet the needs of administrators for operating system policy lifecycle management in complex working environments, and provide a better user experience.

[0004] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows: A method for operating system policy lifecycle management based on a domain management system includes the following steps: S101, the server responds to the administrator's lifecycle management operation of the operating system policy and the selection of the distribution object. Based on the selected distribution object, the updated operating system policy after the lifecycle management operation is distributed and stored in the policy database. The lifecycle management operation includes some or all of the following: create, modify, cancel, delete and restore. The selected distribution object includes some or all of the following: organization, client, user, user group, client group, exceptional client, and exceptional user. S102, the server monitors the acquisition strategy requests initiated by the client according to the preset heartbeat cycle. If an acquisition strategy request is received from a client, the process jumps to step S103. S103, the server queries the policy database to obtain the operating system policy corresponding to the client. If the operating system policy corresponding to the client is found, the server encapsulates the operating system policy corresponding to the client into a policy message and sends it to the client.

[0005] Optionally, in step S101, when the server responds to the administrator's lifecycle management operation of the operating system policy and the selection of the target object, the server also records the administrator's lifecycle management operation of the operating system policy completely in the system log.

[0006] Optionally, in step S102, when the server monitors the client's request for the acquisition strategy initiated by the client according to the preset heartbeat cycle, the heartbeat cycles of each client are different, or the start time of the heartbeat cycle timer is different, so that the time when different clients initiate the request for the acquisition strategy to the server is staggered.

[0007] Optionally, in step S101, when distributing and storing the updated operating system policy after performing lifecycle management operations to the policy database according to the selected distribution object, distributing and storing the updated operating system policy after performing lifecycle management operations to the policy database according to the selected organization includes: S201, obtain the operating system policy, its policy scenarios and effective conditions, the selected organization, and its exception clients and exception users; S202, determine whether the selected strategy scenario, effective conditions or organizational changes are valid. If valid, proceed to step S203; otherwise, proceed to step S204. S203, if the selected policy scenario and effective conditions have changed and there are selected policy scenarios and effective conditions that have been deleted, then the policy for the organization that was originally affected by the deleted policy scenario and effective conditions will be cancelled; if the selected organization has changed and there are users in the deleted organization, then the policy for the users in the deleted organization will be cancelled; the updated operating system policy after the policy cancellation will be issued and stored in the policy database, then the process ends and exits. The process of canceling the issuance of updated operating system policies and storing them in the policy database includes: Based on the rule that the priority of operating system policies issued to users > the priority of operating system policies issued to user groups > the priority of operating system policies issued to organizations, determine the operating system policies currently in effect for each user, and update the user policy table in the policy database that records the operating system policies currently in effect for each user. Based on the rule that the priority of operating system policies issued to clients > the priority of operating system policies issued to client groups > the priority of operating system policies issued to the organization, determine the currently effective operating system policies for each client, and update the host policy table in the policy database that records the currently effective operating system policies for each client. S204, Write the operating system policy and its selected organization into the policy group association table, write the operating system policy and its policy scenarios and effective conditions into the policy conditions table, and write the operating system policy and its exception clients and exception users into the policy group exception object table. S205, issue operating system policies to clients and users in the selected organizations recorded in the policy group association table; issuing operating system policies to clients in the selected organizations includes: obtaining all clients in the selected organizations according to the policy group association table; excluding exception clients from the selected organizations according to the policy group exception object table; for each remaining client: reading the host policy table in the policy database that records the currently effective operating system policies for each client; determining whether the priority of the currently effective operating system policy for the client in the host policy table is greater than the priority of issuing the operating system policy; if so, not issuing the operating system policy to the client; otherwise, updating the currently effective operating system policy for the client in the host policy table, and updating the operating system policy and its policy value recorded in the policy condition table. The scenario and effective conditions are written into the policy execution information table in the policy database. For users in the selected organization, the following steps are taken: All users in the selected organization are retrieved from the policy group association table; exception users are excluded from the selected organization based on the policy group exception object table; for each remaining user: the user policy table, which records the currently effective operating system policies for each user, is read from the policy database; it is determined whether the priority of the currently effective operating system policy for that user in the user policy table is greater than the priority of the issued operating system policy; if so, no operating system policy is issued to that user; otherwise, the currently effective operating system policy for that user is updated in the user policy table, and the policy scenario and effective conditions of the operating system policy recorded in the policy condition table are written into the policy execution information table in the policy database.

[0008] Optionally, in step S101, when distributing and storing the updated operating system policy after performing the management operation to the policy database according to the selected distribution object, distributing and storing the updated operating system policy after performing the management operation to the policy database according to the selected client or user includes: S301, obtain the operating system policy, its policy scenarios and effective conditions, and the selected client or user; S302, Write the operating system policy and its selected organization into the policy group association table, and write the operating system policy, its policy scenario, and its effective conditions into the policy condition table. S303, For the selected clients or users recorded in the policy group association table, the operating system policy is issued. Issuing the operating system policy to the selected clients includes: For each selected client: The host policy table, which records the currently effective operating system policies for each client, is read from the policy database. It is determined whether the priority of the currently effective operating system policy for that client in the host policy table is greater than the priority of the issued operating system policy. If so, no operating system policy is issued to that client; otherwise, the currently effective operating system policy for that client is updated in the host policy table. The operating system policy, its policy scenario, and its activation conditions recorded in the policy condition table are written into the policy execution information table in the policy database. Issuing the operating system policy to the selected users includes: For each selected user: The user policy table, which records the currently effective operating system policies for each user, is read from the policy database. It is determined whether the priority of the currently effective operating system policy for that user in the user policy table is greater than the priority of the issued operating system policy. If so, no operating system policy is issued to that user; otherwise, the currently effective operating system policy for that user is updated in the user policy table. The policy scenario and activation conditions of the operating system policy recorded in the policy condition table are written into the policy execution information table in the policy database.

[0009] Optionally, in step S101, when distributing and storing the updated operating system policy after performing the management operation to the policy database according to the selected distribution object, distributing and storing the updated operating system policy after performing the management operation to the policy database according to the selected user group includes: S401, obtain the operating system policy, its policy scenarios and effective conditions, the selected user group and its exception users; S402, write the operating system policy and its selected user group into the policy group association table, write the operating system policy and its policy scenario and effective conditions into the policy condition table, and write the operating system policy and its exception users into the policy group exception object table. S403: Based on the selected user group recorded in the policy group association table, retrieve all users in the user group. Based on the policy group exception object table, exclude exception users from the selected user group. For each remaining user: read the user policy table in the policy database, which records the operating system policies currently in effect for each user. Determine whether the priority of the operating system policy currently in effect for the user in the user policy table is greater than the priority of the issued operating system policy. If it is true, do not issue an operating system policy to the user. Otherwise, update the operating system policy currently in effect for the user in the user policy table, and write the policy scenario and effective conditions of the operating system policy recorded in the policy condition table into the policy execution information table in the policy database.

[0010] Optionally, in step S101, when distributing and storing the updated operating system policy after performing the management operation to the policy database according to the selected distribution object, distributing and storing the updated operating system policy after performing the management operation to the policy database according to the selected client group includes: S501, obtain the operating system policy, its policy scenarios and effective conditions, the selected client group and its exception clients; S502, write the operating system policy and its selected client group into the policy group association table, write the operating system policy and its policy scenario and effective conditions into the policy condition table, and write the operating system policy and its exception clients into the policy group exception object table. S503: Based on the selected client group recorded in the policy group association table, obtain all clients in the client group. Based on the policy group exception object table, exclude exception clients from the selected client group. For each remaining client: read the host policy table in the policy database, which records the currently effective operating system policies for each client. Determine whether the priority of the currently effective operating system policy for the client in the host policy table is greater than the priority of the issued operating system policy. If it is true, do not issue an operating system policy to the client. Otherwise, update the currently effective operating system policy for the client in the host policy table. Write the operating system policy, its policy scenario, and the effective conditions recorded in the policy condition table into the policy execution information table in the policy database.

[0011] The present invention also provides an operating system policy lifecycle management system based on a domain management system, comprising a microprocessor and a memory interconnected thereto, wherein the microprocessor is programmed or configured to execute the operating system policy lifecycle management method based on the domain management system.

[0012] The present invention also provides a computer-readable storage medium storing a computer program or instructions that are programmed or configured to execute the operating system policy lifecycle management method based on a domain management system via a processor.

[0013] The present invention also provides a computer program product, including a computer program or instructions, which are programmed or configured to execute the operating system policy lifecycle management method based on the domain management system via a processor.

[0014] Compared with existing technologies, the present invention mainly achieves the following beneficial effects: The operating system policy lifecycle management method of the present invention based on the domain management system includes the server responding to the administrator's lifecycle management operation of the operating system policy and the selection of the distribution object. According to the selected distribution object, the updated operating system policy after the management operation is performed is distributed and stored in the policy database. The server monitors the client's policy retrieval request initiated by the client according to the preset heartbeat cycle. If a policy retrieval request is received from a client, the server queries the policy database to retrieve the corresponding operating system policy for that client, encapsulates the found operating system policy into a policy message and sends it to the client. The present invention can provide a complete operating system policy lifecycle management solution, realize the lifecycle management operation of various operating system policies such as creation, modification, cancellation, deletion and restoration, and support the specified distribution to various distribution objects including organizations, clients, users, user groups, client groups, exception clients, and exception users, thereby realizing unified policy management and display for different hosts and users, effectively improving the policy control performance of the domain management system, meeting the needs of administrators for operating system policy lifecycle management in complex working environments, and providing a better user experience. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of the basic process of the method in an embodiment of the present invention.

[0016] Figure 2 This is a schematic diagram of the server topology in an embodiment of the present invention.

[0017] Figure 3 This is a schematic diagram illustrating the process of distributing operating system policies to a selected organization in an embodiment of the present invention.

[0018] Figure 4 This is a schematic diagram illustrating the process of issuing operating system policies to clients and users in a selected organization in an embodiment of the present invention. Detailed Implementation

[0019] To enable those skilled in the art to better understand the technical solutions of the present invention, the technical solutions of the present invention will be further described in detail below with reference to the accompanying drawings in the embodiments of the present invention.

[0020] like Figure 1As shown, the operating system policy lifecycle management method based on the domain management system in this embodiment includes the following steps: S101, the server responds to the administrator's lifecycle management operation on the operating system policy and the selection of the distribution object. Based on the selected distribution object, the updated operating system policy after performing the lifecycle management operation is distributed and stored in the policy database. The lifecycle management operation includes some or all of the following: creation, modification, cancellation, deletion, and restoration. The selected distribution object includes some or all of the following: organization, client, user, user group, client group, exceptional client, and exceptional user. Existing solutions typically lack the ability to customize distribution objects, failing to meet diverse user management needs. This embodiment supports policy distribution based on different distribution objects, including some or all of the following: organization, client, user, user group, client group, exceptional client, and exceptional user, such as organization, client, group label, user, etc. It supports adding exceptional clients / exceptional users, thus achieving special handling and providing flexible custom distribution options. The operating system policy refers to the control policy used by the domain management system to uniformly manage the client's operating system, such as watermarking, wallpaper, firewall, hotspot blacklist / whitelist, peripheral device control, control panel, and file distribution. S102, the server monitors the acquisition strategy requests initiated by the client according to the preset heartbeat cycle. If an acquisition strategy request is received from a client, the process jumps to step S103. S103, the server queries the policy database to obtain the operating system policy corresponding to the client. If the corresponding operating system policy is found, it is encapsulated into a policy message and sent to the client. To avoid excessive pressure on the server due to instantaneous traffic spikes, the system adopts a client-initiated polling mechanism instead of a server-initiated push method. Specifically, the client sends a heartbeat request to the server according to a preset heartbeat period. After receiving the heartbeat request, the server determines whether the corresponding client host has a policy instruction to be issued. If it does, the server returns the corresponding policy message in the response; otherwise, it returns an empty response, thereby achieving on-demand policy issuance and balanced control of communication load.

[0021] like Figure 2As shown, in this embodiment, the server includes a monit-web service, a monit-celery service, a Kafka message queue, a MySQL database, monit-worker processes, a Redis database, and a kim-server service. The monit-web service receives lifecycle management operations from the administrator for operating system policies and the selection of delivery targets. The monit-celery service then stores the task information in the MySQL database and places the administrator's operation messages into the Kafka message queue. The monit-worker processes retrieve operation messages from the Kafka message queue in a distributed manner, and based on the selected delivery targets, deliver the updated operating system policies after performing lifecycle management operations and store them in the policy database (Redis database). The server monitors policy retrieval requests initiated by clients according to a preset heartbeat cycle through the kim-server service. If a policy retrieval request is received from a client, the kim-server service queries the Redis database to retrieve the corresponding operating system policy for that client. If the corresponding operating system policy is found, it is encapsulated into a policy message and sent to the client. Furthermore, the monit-web service also supports querying the policy database to obtain the currently effective operating system policies for each client or user.

[0022] As an optional implementation, in step S101, when the server responds to the administrator's lifecycle management operations on the operating system policy and the selection of the distribution object, it also includes the server completely recording the administrator's lifecycle management operations on the operating system policy in the system log. The lifecycle management of the policy is logged; for example, the creation, modification, distribution, cancellation, and priority adjustment of the policy are all recorded in detail daily, facilitating administrator auditing.

[0023] As an optional implementation, in step S102, when the server monitors the client's request for the acquisition strategy initiated by the client according to the preset heartbeat cycle, the heartbeat cycles of each client are different, or the start time of the heartbeat cycle timer is different, so that the time when different clients initiate the request for the acquisition strategy to the server is staggered.

[0024] In this embodiment, the lifecycle of the operating system policy mainly consists of two parts. One part is the server's unified management of policies that should be effective on all hosts in all scenarios. For canceled policies, the server determines which policy should be effective on the host based on priority and issues the policy. If a host does not have a relevant configured policy, a server-side built-in policy message is issued, and a field is added to the message to indicate that this type of policy is deleted and the system is restored to the state of the issued built-in policy. For newly issued policies, the server determines whether the priority of the policy currently in effect on the host is higher than that of this policy. If it is higher, the policy is not issued; otherwise, it is issued. The other part is handled by the client. Based on the client's own scenario, the policy in the corresponding scenario is applied. If a watermarking policy exists in the online scenario but not in the offline scenario, no watermarking policy is executed when switching to the offline scenario.

[0025] like Figure 3 As shown, in step S101, when distributing and storing the updated operating system policy after performing lifecycle management operations to the policy database according to the selected distribution object, distributing and storing the updated operating system policy after performing lifecycle management operations to the policy database according to the selected organization includes: S201, obtain the operating system policy, its policy scenarios and effective conditions, the selected organization, and its exception clients and exception users; S202, determine whether the selected policy scenario, effective conditions or organizational changes are valid. If valid, proceed to step S203; otherwise, proceed to step S204. The policy scenario and effective conditions can be configured as needed. For example, the policy scenario can be configured as an online scenario and an offline scenario for domain management, and the effective conditions can be set as various events in the operating system as needed. S203, if the selected policy scenario and effective conditions have changed and there are selected policy scenarios and effective conditions that have been deleted, then the policy for the organization that was originally affected by the deleted policy scenario and effective conditions will be cancelled; if the selected organization has changed and there are users in the deleted organization, then the policy for the users in the deleted organization will be cancelled; the updated operating system policy after the policy cancellation will be issued and stored in the policy database, then the process ends and exits. The process of canceling the issuance of updated operating system policies and storing them in the policy database includes: Based on the rule that the priority of operating system policies issued to users > the priority of operating system policies issued to user groups > the priority of operating system policies issued to organizations, determine the operating system policies currently in effect for each user, and update the user policy table in the policy database that records the operating system policies currently in effect for each user. Based on the rule that the priority of operating system policies issued to clients > the priority of operating system policies issued to client groups > the priority of operating system policies issued to the organization, determine the currently effective operating system policies for each client, and update the host policy table in the policy database that records the currently effective operating system policies for each client. S204, Write the operating system policy and its selected organization into the policy group association table, write the operating system policy and its policy scenarios and effective conditions into the policy conditions table, and write the operating system policy and its exception clients and exception users into the policy group exception object table. S205, Deploy operating system policies to clients and users in the selected organization based on records in the policy group association table.

[0026] like Figure 4 As shown, the process of issuing operating system policies to clients in the selected organization includes: obtaining all clients in the selected organization based on the policy group association table; excluding exception clients from the selected organization based on the policy group exception object table; and for each remaining client: reading the host policy table in the policy database, which records the currently effective operating system policies for each client; determining whether the priority of the currently effective operating system policy for that client in the host policy table is greater than the priority of issuing the operating system policy; if so, not issuing the operating system policy to that client; otherwise, updating the currently effective operating system policy for that client in the host policy table; and writing the operating system policy, its policy scenario, and its effective conditions recorded in the policy condition table into the policy execution information table in the policy database.

[0027] like Figure 4 As shown, issuing operating system policies to users in the selected organization includes: obtaining all users in the selected organization based on the policy group association table; excluding exception users from the selected organization based on the policy group exception object table; and for each remaining user: reading the user policy table in the policy database, which records the currently effective operating system policies for each user; determining whether the priority of the currently effective operating system policy for that user in the user policy table is greater than the priority of issuing the operating system policy; if so, not issuing the operating system policy to that user; otherwise, updating the currently effective operating system policy for that user in the user policy table; and writing the policy scenario and effective conditions of the operating system policy recorded in the policy condition table into the policy execution information table in the policy database.

[0028] In step S205, when issuing operating system policies to clients and users in the selected organization recorded in the policy group association table, it is determined whether the priority of the currently effective operating system policy for that client / user in the host policy table is greater than the priority of the issued operating system policy. The required priority setting method can be adopted as needed. As an optional implementation, this embodiment uses the following judgment rules: ① Determine the currently effective operating system policy for each user based on the rule that the priority of the operating system policy issued to the user group > the priority of the operating system policy issued to the organization; ② Determine the currently effective operating system policy for each client based on the rule that the priority of the operating system policy issued to the client > the priority of the operating system policy issued to the client group > the priority of the operating system policy issued to the organization. Through the above judgment rules, it is easy to compare the priority of the currently effective operating system policy for the client / user in the host policy table with the priority of the issued operating system policy. This embodiment method supports policy cancellation, can cancel high-priority policies, and automatically issues the highest priority policy (excluding those already in effect) to the relevant clients; it also supports policy deletion, adding the function of deleting policies from the database in addition to the policy cancellation function. Specifically, in this embodiment, the priority setting method allows the system to configure a default policy group. The effective target is global, with a priority of 1. The priority range for policies issued to organizations is 5555-6666, for client groups it is 6666-7777, and for clients it is 7777-8888. The system also supports configuring single-point policies for each host, which have the highest priority and a value of 9999. For policies of the same type, priority sorting is supported: policy group A is issued to organization A first, followed by policy group b. Therefore, for organization A, the priority of policy group a is 5555, and the priority of policy group b is 5556. For policies of the same type, such as wallpaper, the wallpaper policy in policy group b takes effect. Policy priorities can be adjusted by dragging the mouse within an organization / client / client group. For example, the priority of policy group a can be adjusted to be higher than that of policy group b. Policies with lower priority are canceled, and those with higher priority are issued.

[0029] In step S101 of this embodiment, when the updated operating system policy after the management operation is executed is distributed and stored in the policy database according to the selected distribution object, the distribution and storage of the updated operating system policy after the management operation is executed in the policy database according to the selected client or user includes: S301, obtain the operating system policy, its policy scenarios and effective conditions, and the selected client or user; S302, Write the operating system policy and its selected organization into the policy group association table, and write the operating system policy, its policy scenario, and its effective conditions into the policy condition table. S303, For the selected clients or users recorded in the policy group association table, the operating system policy is issued. Issuing the operating system policy to the selected clients includes: For each selected client: The host policy table, which records the currently effective operating system policies for each client, is read from the policy database. It is determined whether the priority of the currently effective operating system policy for that client in the host policy table is greater than the priority of the issued operating system policy. If so, no operating system policy is issued to that client; otherwise, the currently effective operating system policy for that client is updated in the host policy table. The operating system policy, its policy scenario, and its activation conditions recorded in the policy condition table are written into the policy execution information table in the policy database. Issuing the operating system policy to the selected users includes: For each selected user: The user policy table, which records the currently effective operating system policies for each user, is read from the policy database. It is determined whether the priority of the currently effective operating system policy for that user in the user policy table is greater than the priority of the issued operating system policy. If so, no operating system policy is issued to that user; otherwise, the currently effective operating system policy for that user is updated in the user policy table. The policy scenario and activation conditions of the operating system policy recorded in the policy condition table are written into the policy execution information table in the policy database.

[0030] In step S101 of this embodiment, when the updated operating system policy after the management operation is executed is distributed and stored in the policy database according to the selected distribution object, the distribution and storage of the updated operating system policy after the management operation is executed in the policy database according to the selected user group includes: S401, obtain the operating system policy, its policy scenarios and effective conditions, the selected user group and its exception users; S402, write the operating system policy and its selected user group into the policy group association table, write the operating system policy and its policy scenario and effective conditions into the policy condition table, and write the operating system policy and its exception users into the policy group exception object table. S403: Based on the selected user group recorded in the policy group association table, retrieve all users in the user group. Based on the policy group exception object table, exclude exception users from the selected user group. For each remaining user: read the user policy table in the policy database, which records the operating system policies currently in effect for each user. Determine whether the priority of the operating system policy currently in effect for the user in the user policy table is greater than the priority of the issued operating system policy. If it is true, do not issue an operating system policy to the user. Otherwise, update the operating system policy currently in effect for the user in the user policy table, and write the policy scenario and effective conditions of the operating system policy recorded in the policy condition table into the policy execution information table in the policy database.

[0031] In step S101 of this embodiment, when the updated operating system policy after the management operation is executed is distributed and stored in the policy database according to the selected distribution object, the distribution and storage of the updated operating system policy after the management operation is executed in the policy database according to the selected client group includes: S501, obtain the operating system policy, its policy scenarios and effective conditions, the selected client group and its exception clients; S502, write the operating system policy and its selected client group into the policy group association table, write the operating system policy and its policy scenario and effective conditions into the policy condition table, and write the operating system policy and its exception clients into the policy group exception object table. S503: Based on the selected client group recorded in the policy group association table, obtain all clients in the client group. Based on the policy group exception object table, exclude exception clients from the selected client group. For each remaining client: read the host policy table in the policy database, which records the currently effective operating system policies for each client. Determine whether the priority of the currently effective operating system policy for the client in the host policy table is greater than the priority of the issued operating system policy. If it is true, do not issue an operating system policy to the client. Otherwise, update the currently effective operating system policy for the client in the host policy table. Write the operating system policy, its policy scenario, and the effective conditions recorded in the policy condition table into the policy execution information table in the policy database.

[0032] In summary, this embodiment provides a complete policy lifecycle management solution under a domain management system based on the operating system policy lifecycle management method. Specifically, this embodiment has the following advantages: 1. Policy creation, modification, distribution, and deletion are supported: In the prior art, operating system policies do not support deletion, that is, only policy configuration distribution is supported, and there is no mechanism for deletion and restoration. This embodiment provides a complete policy lifecycle management solution, supports user-defined policies, policy distribution, and policy cancellation for clients or users to be canceled, and can restore the client / user to the default policy configuration. 2. Flexible custom distribution options are provided: Existing solutions usually lack the function of custom distribution objects, which cannot meet the diverse management needs of users. This embodiment supports policy distribution according to different distribution objects, including some or all of the following: organizations, clients, users, user groups, client groups, exception clients, and exception users, such as organizations, clients, group tags, and users. It supports adding exception clients / exception users, thus achieving special handling and providing flexible custom distribution options. 3. Complete priority settings: Supports policy distribution groups, allowing selection of different distribution targets, such as organizations, clients, and client groups. Supports policy priority, with policies distributed to clients having higher priority than those distributed to client groups, which in turn have higher priority than those distributed to organizations. Supports canceling policy distribution targets, canceling high-priority policies, and automatically applying the highest priority policy other than the one distributed to the relevant clients. Supports deleting policies, adding the ability to delete policies from the database in addition to the policy cancellation function.

[0033] Those skilled in the art will understand that the technical solutions provided by this invention can take the form of methods, systems, or computer program products. For example, this invention can provide an operating system policy lifecycle management system based on a domain management system, including a microprocessor and a memory interconnected, wherein the microprocessor is programmed or configured to execute the operating system policy lifecycle management method based on the domain management system. This invention can provide a computer-readable storage medium storing a computer program or instructions programmed or configured to execute the operating system policy lifecycle management method based on the domain management system via a processor. This invention can provide a computer program product including a computer program or instructions programmed or configured to execute the operating system policy lifecycle management method based on the domain management system via a processor. Furthermore, this invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, this invention can take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of a flowchart and / or block diagram, and combinations of blocks in a flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing device, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The functions specified in one or more boxes. These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable apparatus for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0034] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A method for operating system policy lifecycle management based on a domain management system, characterized in that, Includes the following steps: S101, the server responds to the administrator's lifecycle management operation of the operating system policy and the selection of the distribution object. Based on the selected distribution object, the updated operating system policy after the lifecycle management operation is distributed and stored in the policy database. The lifecycle management operation includes some or all of the following: create, modify, cancel, delete and restore. The selected distribution object includes some or all of the following: organization, client, user, user group, client group, exceptional client, and exceptional user. S102, the server monitors the acquisition strategy requests initiated by the client according to the preset heartbeat cycle. If an acquisition strategy request is received from a client, the process jumps to step S103. S103, the server queries the policy database to obtain the operating system policy corresponding to the client. If the operating system policy corresponding to the client is found, the server encapsulates the operating system policy corresponding to the client into a policy message and sends it to the client.

2. The operating system policy lifecycle management method based on a domain management system according to claim 1, characterized in that, In step S101, when the server responds to the administrator's lifecycle management operations on the operating system policy and the selection of the target object, it also includes the server recording the administrator's lifecycle management operations on the operating system policy completely in the system log.

3. The operating system policy lifecycle management method based on a domain management system according to claim 1, characterized in that, In step S102, when the server monitors the client's request for the acquisition strategy initiated by the client according to the preset heartbeat cycle, the heartbeat cycles of each client are different, or the start time of the heartbeat cycle timer is different, so that the time when different clients initiate the request for the acquisition strategy to the server is staggered.

4. The operating system policy lifecycle management method based on a domain management system according to claim 1, characterized in that, In step S101, when distributing and storing the updated operating system policy after lifecycle management operations to the policy database according to the selected distribution target, distributing and storing the updated operating system policy after lifecycle management operations to the policy database according to the selected organization includes: S201, obtain the operating system policy, its policy scenarios and effective conditions, the selected organization, and its exception clients and exception users; S202, determine whether the selected strategy scenario, effective conditions or organizational changes are valid. If valid, proceed to step S203; otherwise, proceed to step S204. S203, if the selected policy scenario and effective conditions have changed and there are selected policy scenarios and effective conditions that have been deleted, then the policy for the organization that was originally affected by the deleted policy scenario and effective conditions will be cancelled; if the selected organization has changed and there are users in the deleted organization, then the policy for the users in the deleted organization will be cancelled; the updated operating system policy after the policy cancellation will be issued and stored in the policy database, then the process ends and exits. The process of canceling the issuance of updated operating system policies and storing them in the policy database includes: Based on the rule that the priority of operating system policies issued to users > the priority of operating system policies issued to user groups > the priority of operating system policies issued to organizations, determine the operating system policies currently in effect for each user, and update the user policy table in the policy database that records the operating system policies currently in effect for each user. Based on the rule that the priority of operating system policies issued to clients > the priority of operating system policies issued to client groups > the priority of operating system policies issued to the organization, determine the currently effective operating system policies for each client, and update the host policy table in the policy database that records the currently effective operating system policies for each client. S204, Write the operating system policy and its selected organization into the policy group association table, write the operating system policy and its policy scenarios and effective conditions into the policy conditions table, and write the operating system policy and its exception clients and exception users into the policy group exception object table. S205, issue operating system policies to clients and users in the selected organizations recorded in the policy group association table; issuing operating system policies to clients in the selected organizations includes: obtaining all clients in the selected organizations according to the policy group association table; excluding exception clients from the selected organizations according to the policy group exception object table; for each remaining client: reading the host policy table in the policy database that records the currently effective operating system policies for each client; determining whether the priority of the currently effective operating system policy for the client in the host policy table is greater than the priority of issuing the operating system policy; if so, not issuing the operating system policy to the client; otherwise, updating the currently effective operating system policy for the client in the host policy table, and updating the operating system policy and its policy value recorded in the policy condition table. The scenario and effective conditions are written into the policy execution information table in the policy database. For users in the selected organization, the following steps are taken: All users in the selected organization are retrieved from the policy group association table; exception users are excluded from the selected organization based on the policy group exception object table; for each remaining user: the user policy table, which records the currently effective operating system policies for each user, is read from the policy database; it is determined whether the priority of the currently effective operating system policy for that user in the user policy table is greater than the priority of the issued operating system policy; if so, no operating system policy is issued to that user; otherwise, the currently effective operating system policy for that user is updated in the user policy table, and the policy scenario and effective conditions of the operating system policy recorded in the policy condition table are written into the policy execution information table in the policy database.

5. The operating system policy lifecycle management method based on a domain management system according to claim 1, characterized in that, In step S101, when the updated operating system policy after the management operation is executed is distributed and stored in the policy database according to the selected distribution object, distributing and storing the updated operating system policy after the management operation is executed and stored in the policy database according to the selected client or user includes: S301, obtain the operating system policy, its policy scenarios and effective conditions, and the selected client or user; S302, Write the operating system policy and its selected organization into the policy group association table, and write the operating system policy, its policy scenario, and its effective conditions into the policy condition table. S303, For the selected clients or users recorded in the policy group association table, the operating system policy is issued. Issuing the operating system policy to the selected clients includes: For each selected client: The host policy table, which records the currently effective operating system policies for each client, is read from the policy database. It is determined whether the priority of the currently effective operating system policy for that client in the host policy table is greater than the priority of the issued operating system policy. If so, no operating system policy is issued to that client; otherwise, the currently effective operating system policy for that client is updated in the host policy table. The operating system policy, its policy scenario, and its activation conditions recorded in the policy condition table are written into the policy execution information table in the policy database. Issuing the operating system policy to the selected users includes: For each selected user: The user policy table, which records the currently effective operating system policies for each user, is read from the policy database. It is determined whether the priority of the currently effective operating system policy for that user in the user policy table is greater than the priority of the issued operating system policy. If so, no operating system policy is issued to that user; otherwise, the currently effective operating system policy for that user is updated in the user policy table. The policy scenario and activation conditions of the operating system policy recorded in the policy condition table are written into the policy execution information table in the policy database.

6. The operating system policy lifecycle management method based on a domain management system according to claim 1, characterized in that, In step S101, when distributing and storing the updated operating system policy after performing the management operation to the policy database according to the selected distribution target, distributing and storing the updated operating system policy after performing the management operation to the policy database according to the selected user group includes: S401, obtain the operating system policy, its policy scenarios and effective conditions, the selected user group and its exception users; S402, write the operating system policy and its selected user group into the policy group association table, write the operating system policy and its policy scenario and effective conditions into the policy condition table, and write the operating system policy and its exception users into the policy group exception object table. S403: Based on the selected user group recorded in the policy group association table, retrieve all users in the user group. Based on the policy group exception object table, exclude exception users from the selected user group. For each remaining user: read the user policy table in the policy database, which records the operating system policies currently in effect for each user. Determine whether the priority of the operating system policy currently in effect for the user in the user policy table is greater than the priority of the issued operating system policy. If it is true, do not issue an operating system policy to the user. Otherwise, update the operating system policy currently in effect for the user in the user policy table, and write the policy scenario and effective conditions of the operating system policy recorded in the policy condition table into the policy execution information table in the policy database.

7. The operating system policy lifecycle management method based on a domain management system according to claim 1, characterized in that, In step S101, when the updated operating system policy after the management operation is executed is distributed and stored in the policy database according to the selected distribution target, distributing and storing the updated operating system policy after the management operation is executed and stored in the policy database according to the selected client group includes: S501, obtain the operating system policy, its policy scenarios and effective conditions, the selected client group and its exception clients; S502, write the operating system policy and its selected client group into the policy group association table, write the operating system policy and its policy scenario and effective conditions into the policy condition table, and write the operating system policy and its exception clients into the policy group exception object table. S503: Based on the selected client group recorded in the policy group association table, obtain all clients in the client group. Based on the policy group exception object table, exclude exception clients from the selected client group. For each remaining client: read the host policy table in the policy database, which records the currently effective operating system policies for each client. Determine whether the priority of the currently effective operating system policy for the client in the host policy table is greater than the priority of the issued operating system policy. If it is true, do not issue an operating system policy to the client. Otherwise, update the currently effective operating system policy for the client in the host policy table. Write the operating system policy, its policy scenario, and the effective conditions recorded in the policy condition table into the policy execution information table in the policy database.

8. An operating system policy lifecycle management system based on a domain management system, comprising interconnected microprocessors and memory, characterized in that, The microprocessor is programmed or configured to execute the operating system policy lifecycle management method based on any one of claims 1 to 7.

9. A computer-readable storage medium storing a computer program or instructions, characterized in that, The computer program or instructions are programmed or configured to execute, via a processor, the operating system policy lifecycle management method based on any one of claims 1 to 7.

10. A computer program product, comprising a computer program or instructions, characterized in that, The computer program or instructions are programmed or configured to execute, via a processor, the operating system policy lifecycle management method based on any one of claims 1 to 7.