Method and device for terminal device management based on right control
Abstract
A method and a device for terminal device management based on right control are provided. The method includes the following steps. A Get command on an access control list (ACL) of a managed node in a device management tree (DMT) from a device management (DM) server is received, where the Get command includes a Unified Resource Identity (URI) of the managed node. It is determined whether the DM server has a direct right of executing the Get command on the managed node. The Get command is processed when it is determined that the DM server has the direct right of executing the Get command on the managed node. The method and the device simplify the complexity of right management, and reduce the number of times of message interaction between the DM server and a terminal device, thereby improving the efficiency and performance of terminal device management.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for terminal device management comprising:
receiving, from a device management server, a management command on a leaf node in a device management tree, wherein the device management server has no first direct right to execute the management command on the leaf node; determining that an ancestor node of the leaf node has an access control (ACL) property indicating that the device management server has a second direct right to execute the management command on the ancestor node; skipping endowing the device management server with a direct right to execute the management command on every managed node below the ancestor node till the leaf node; and executing the management command on the leaf node.
2 . The method according to claim 1 , wherein the leaf node has no ACL property for indicating the first direct right, or a value of an ACL property of the leaf node is empty.
3 . The method according to claim 1 , wherein an ACL property of the ancestor node comprises an identifier of the device management server.
4 . The method according to claim 1 , wherein the management command corresponds to a reading operation on the leaf node or a writing operation on the leaf node.
5 . The method according claim 1 , wherein skipping endowing the device management server with the direct right to execute the management command on every managed node below the ancestor node till the leaf node, comprises skipping changing any ACL property of the every managed node below the ancestor node till the leaf node.
6 . A terminal device comprising at least one processor, and one or more memories coupled to the at least one processor, wherein the one or more memories are configured to store non-transitory instructions, and wherein the at least one processor is configured to execute the non-transitory instructions to thereby cause the terminal device to:
receive, from a device management server, a management command on a leaf node in a device management tree in the terminal device, wherein the device management server has no first direct right to execute the management command on the leaf node; determine that an ancestor node of the leaf node has an access control (ACL) property indicating that the device management server has a second direct right to execute the management command on the ancestor node; skip endowing the device management server with a direct right to execute the management command on every managed node below the ancestor node till the leaf node; and execute the management command on the leaf node.
7 . The terminal device according to claim 6 , wherein the leaf node has no ACL property for indicating the first direct right, or a value of an ACL property of the leaf node is empty.
8 . The terminal device according to claim 6 , wherein an ACL property of the ancestor node comprises an identifier of the device management server.
9 . The terminal device according to claim 6 , wherein the management command corresponds to a reading operation on the leaf node or a writing operation on the leaf node.
10 . The terminal device according claim 6 , wherein the at least one processor is further configured to execute the non-transitory instructions to further cause the terminal device to skip changing any ACL property of the every managed node below the ancestor node till the leaf node.
11 . A method for terminal device management comprising:
sending, by a device management server, a management command on a leaf node in a device management tree, wherein the device management server has no first direct right to execute the management command on the leaf node; receiving, from the device management server, the management command; determining that an ancestor node of the leaf node has an access control (ACL) property indicating that the device management server has a second direct right to execute the management command on the ancestor node; skipping endowing the device management server with a direct right to execute the management command on every managed node below the ancestor node till the leaf node; and executing the management command on the leaf node.
12 . The method according to claim 11 , wherein the leaf node has no ACL property for indicating the first direct right, or a value of an ACL property of the leaf node is empty.
13 . The method according to claim 11 , wherein an ACL property of the ancestor node comprises an identifier of the device management server.
14 . The method according to claim 11 , wherein the management command corresponds to a reading operation on the leaf node or a writing operation on the leaf node.
15 . The method according claim 11 , wherein skipping endowing the device management server with the direct right to execute the management command on every managed node below the ancestor node till the leaf node, comprises skipping changing any ACL property of the every managed node below the ancestor node till the leaf node.
16 . A system for terminal device management comprising a device management server and a terminal device, wherein
the device management server is configured to send to the terminal device a management command on a leaf node in a device management tree in the terminal device, wherein the device management server has no first direct right to execute the management command on the leaf node; the terminal device is configured to:
receive, from the device management server, the management command;
determine that an ancestor node of the leaf node has an access control (ACL) property indicating that the device management server has a second direct right to execute the management command on the ancestor node;
skip endowing the device management server with a direct right to execute the management command on every managed node below the ancestor node till the leaf node; and
execute the management command on the leaf node.
17 . The system according to claim 16 , wherein the leaf node has no ACL property for indicating the first direct right, or a value of an ACL property of the leaf node is empty.
18 . The system according to claim 16 , wherein an ACL property of the ancestor node comprises an identifier of the device management server.
19 . The system according to claim 16 , wherein the management command corresponds to a reading operation on the leaf node or a writing operation on the leaf node.
20 . The system according claim 16 , wherein the terminal device is further configured to skip changing any ACL property of the every managed node below the ancestor node till the leaf node.Join the waitlist — get patent alerts
Track US2023275815A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.