Method, apparatus, storage medium, and processor for data processing

The target account is generated through the file transfer management platform and the asymmetric encryption algorithm is used to solve the problem of low file transfer efficiency caused by different encryption methods between different institutions, and standardized management and security of file transfer are achieved.

CN115396425BActive Publication Date: 2025-07-18DUXIAOMAN TECH (BEIJING) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210978305.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-16
Publication Date
2025-07-18
Estimated Expiration
2042-08-16

AI Technical Summary

Technical Problem

The encryption methods between different institutions are different, resulting in complex exchange and decryption management of decryption passwords and low file transfer efficiency.

Method used

Through the file transfer management platform, the target account is generated and the key is generated using asymmetric encryption algorithms to realize standardized management of file transfer, including deploying file transfer services and encrypted transmission on the host device.

Benefits of technology

It improves the efficiency of file transfer, reduces operation and maintenance management costs, and enhances the security and reliability of file transfer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115396425B_ABST
    Figure CN115396425B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, apparatus, storage medium, and processor for data processing. Among them, the method includes: in response to a service deployment instruction from a client, determining at least one set of file transfer service data to be sent to the host device where the client is located; generating at least one target account based on the file transfer service data, where each target account is used to identify the file transfer service data; and sending the file to be transferred to the file receiving end based on the at least one target account. The present invention solves the technical problem of low file transfer efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computers, and in particular, to a method, device, storage medium, and processor for data processing. Background Art

[0002] Currently, files are mainly transmitted through pre-encryption methods. However, the encryption methods vary among different institutions, and the operations of decrypting password exchange and decryption management are relatively complex, which easily leads to file transmission failures, thus resulting in the technical problem of low file transmission efficiency.

[0003] In view of the above technical problem of low efficiency faced during the file transmission process, no effective solution has been proposed yet. Summary of the Invention

[0004] Embodiments of the present invention provide a method, device, storage medium, and processor for data processing to at least solve the technical problem of low file transmission efficiency.

[0005] According to one aspect of the embodiments of the present invention, a method for data processing is provided. The method includes: in response to a service deployment instruction from a client, determining at least one set of file transfer service data to be sent to the host device where the client is located; generating at least one target account based on the file transfer service data, where each target account is used to identify the file transfer service data; and sending the file to be transmitted to the file receiving end based on the at least one target account.

[0006] Optionally, generating at least one target account based on the file transfer service data includes: in response to an account creation request from a client, obtaining first attribute information of the target account, where the first attribute information includes at least one of the following: name information of the target account, and file transfer service data corresponding to the target account; and generating the target account based on the first attribute information.

[0007] Optionally, display the status information of the target account on an image display interface, where the status information is used to represent the generation status of the target account, and the generation status includes at least one of the following: to-be-generated status, being-generated status, and generated status.

[0008] Optionally, after sending at least one set of file transfer service data to the host device where the client is located, it includes: in response to the successful deployment of the file transfer service on the host device, obtaining the domain name of the host device and the login port of the host device; and sending the domain name and the login port to the client.

[0009] Optionally, in response to a key generation instruction from a client, obtain second attribute information of the key, where the second attribute information is used to characterize the valid time period of the key and the usage scenario of the key; based on the second attribute information, generate at least one pair of keys for the target account, where the key at least includes a private key, and the private key is used to log in to the target account on the host device.

[0010] Optionally, if the time period for logging in to the target account with the private key is greater than the target time period, send a prompt message to the client, where the target time period is one of the time periods within the valid time period. The prompt message is used to prompt the client to update the key.

[0011] Optionally, in response to a service offline instruction from the client, delete the file transfer service data on the host device.

[0012] According to another aspect of the embodiments of the present invention, there is also provided a data processing device. The device includes: a determination unit, configured to determine at least one set of file transfer service data to be sent to the host device where the client is located in response to a deployment instruction from the client; a generation unit, configured to generate at least one target account based on the file transfer service data; and a sending unit, configured to send the file to be transferred to the file receiving end based on at least one target account.

[0013] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium. The computer-readable storage medium includes a stored program, where when the program runs, it controls the device where the computer-readable storage medium is located to execute the data processing method of the embodiments of the present invention.

[0014] According to another aspect of the embodiments of the present invention, there is also provided a processor. The processor is used to run a program, where when the program runs, it executes the data processing method of the embodiments of the present invention.

[0015] In the embodiments of the present invention, in response to a service deployment instruction from a client, determine at least one file transfer service data to be sent to the host device where the client is located; generate at least one target account based on the file transfer service data; and send the file to be transferred to the file receiving end based on at least one target account. That is, the embodiments of the present invention implement the operations of deploying a file transfer service for the host device where the client is located, generating a target account for the client, and encrypting and transferring the file through an automated encrypted file transfer management platform, so as to achieve the purpose of standardizing the management of the file transfer service and the target account, thereby solving the technical problem of low file transfer efficiency and achieving the technical effect of improving the file transfer efficiency. Description of the Drawings

[0016] The accompanying drawings described herein are used to provide a further understanding of the present invention and form a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0017] Figure 1 is a flowchart of a data processing method according to an embodiment of the present invention;

[0018] Figure 2 is a flowchart of creating a file transfer service according to an embodiment of the present invention;

[0019] Figure 3 is a flowchart of creating an account on a file transfer management platform according to an embodiment of the present invention;

[0020] Figure 4 is a flowchart of taking a file transfer service offline according to an embodiment of the present invention;

[0021] Figure 5 is a schematic diagram of the architecture of a file transfer management platform according to an embodiment of the present invention;

[0022] Figure 6 is a schematic diagram of a data processing method device according to an embodiment of the present invention. Detailed Embodiments

[0023] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0025] First, some nouns or terms that appear during the description of the embodiments of the present invention are explained as follows:

[0026] Bare metal, a computing product that combines the elastic resources of virtual machines, minute-level delivery, fully automated operation and maintenance, and the performance lossless, complete characteristics, and hardware-level isolation of physical machines;

[0027] Secure File Transfer Protocol (SFTP), an encrypted file transfer protocol based on the Secure Shell Protocol (SSH). The SFTP in the embodiments of the present invention can be a software system that supports file transfer management using the SFTP protocol;

[0028] Change Root Directory (chroot): Also known as Change Root, it can change the root directory location that a program refers to when it is executed, which can enhance system security and limit what users can do;

[0029] Asymmetric Encryption Algorithm (RSA): An asymmetric encryption algorithm that can generate a pair of keys. The keys can include a public key and a private key. In scenarios where encryption is required, the public key can be used to encrypt data for the data provider, and the user can decrypt the encrypted data using the private key. Since the private key does not need to be transmitted externally throughout the process, the security is very high;

[0030] Process (agent): A process that resides in the file transfer management platform and can collect data information on the host device and report it to the file transfer management platform;

[0031] Root Directory (root): Also known as the root user, it is the only superuser in the Android and iOS device systems and can perform read, write, and execute operations on the root directory, having the highest permissions in the system.

[0032] Embodiment 1

[0033] According to the embodiments of the present invention, an embodiment of a data processing method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0034] Figure 1 It is a flowchart of a data processing method according to the embodiments of the present invention. As Figure 1 shown, the method may include the following steps:

[0035] Step S102, in response to a service deployment instruction from a client, determine at least one set of file transfer service data to be sent to the host device where the client is located.

[0036] In the technical solution provided in step S102 of the present invention, when the file transfer management platform receives a service deployment instruction from the client, it may send file transfer service data to the host device where the client is located according to the service deployment instruction. Among them, the host device may be a bare metal host, the client may be an organization that needs to transfer encrypted files, the service deployment instruction of the client may be an instruction generated based on the cooperation requirements of the cooperation organization, and the file transfer service data may be used to deploy a file transfer service on the host device. The file transfer service is used to perform encrypted transfer of the files to be transferred.

[0037] For example, when cooperating with a new financial institution, a new file transfer service can be built based on the cooperation requirements of the financial institution for file encrypted transfer. This is only for illustrative purposes and does not specifically limit the specific object of the client.

[0038] Optionally, a set of file transfer management platforms can manage multiple clients, classify and isolate all clients according to the cooperation requirements of different clients, and determine the number of file transfer services required for the deployed clients based on the number of clients, so as to manage the file transfer services of all clients.

[0039] Step S104, generate at least one target account based on the file transfer service data.

[0040] In the technical solution provided in step S104 of the present invention, the file transfer management platform can create a target account for the client to transfer files based on the file transfer service data sent to the client. Among them, each host where the client is located can apply for multiple target accounts to meet the management needs and transfer scenarios of the client itself.

[0041] Optionally, creating a target account to log in to the file transfer management platform may include: under manual operation, the operation and maintenance personnel need to find the host device where the file transfer service corresponding to the client is located, then new target accounts and target account groups can be added on the host device, and the configuration of the file transfer service can be modified to set that only the corresponding accounts are allowed to log in, and chroot to the corresponding data directory to ensure the accuracy of the data operation scope. Finally, the created accounts are delivered to the client so that the client can verify the login of the accounts and the correctness of the operation permissions.

[0042] Step S106, send the files to be transferred to the file receiving end based on at least one target account.

[0043] In the technical solution of step S106 of the present invention, a pair of keys can be generated by the file transfer management platform. The public key in the keys can be added to the target account corresponding to the client that logs in to the file transfer management platform, and then the file transfer management platform can be logged in with the private key to meet the requirements of data security.

[0044] Optionally, due to problems such as easy leakage, weak passwords, and difficulty in replacement in password management, the target account can use an asymmetric encryption key for login, and this key can be generated using the RSA encryption algorithm. The private key is kept by the cooperative institution throughout the process. Therefore, the risk of leakage in the key login method is smaller and it is more secure.

[0045] Optionally, under manual operation, the operation and maintenance personnel can find the encrypted file preset for the target account of the file transfer service corresponding to the client, and then a new public key can be added or deleted in the encrypted file, and then the client can be logged in with the private key.

[0046] Optionally, the file transfer management platform adds one or more public keys to each target account of the client to meet the access requirements of different clients.

[0047] In steps S102 to S106 of the present invention above, in response to a service deployment instruction from the client, at least one file transfer service data to be sent to the host device where the client is located is determined; based on the file transfer service data, at least one target account is generated; and based on at least one target account, the file to be transmitted is sent to the file receiving end. That is to say, the embodiment of the present invention realizes the operations of deploying the file transfer service for the host device where the client is located, generating a target account for the client, and encrypting and transmitting the file through an automated encrypted file transfer management platform, so as to achieve the purpose of standardizing the management of the file transfer service and the target account, thereby solving the technical problem of low file transfer efficiency and achieving the technical effect of improving the file transfer efficiency.

[0048] The above method of this embodiment will be further introduced below.

[0049] As an optional embodiment, step S102, after sending at least one set of file transfer service data to the host device where the client is located, includes: in response to the successful deployment of the file transfer service on the host device, obtaining the domain name of the host device and the login port of the host device; sending the domain name and the login port to the client.

[0050] In this embodiment, when the file transfer service has been deployed on the host device, the domain name and login port of the host device are obtained, and the obtained domain name and login port can be sent to the client. Among them, the login port can be used as the access entry for file transfer.

[0051] Optionally, when collaborating with a new client, the file transfer management platform will build a new file transfer service for encrypted file transfer based on the cooperation requirements of the client. In the manual operation scenario, the operation and maintenance personnel need to apply for a bare metal host, deploy and start the file transfer service on the host device, then bind the public network Internet protocol address, apply for a new domain name to resolve to this address, and finally provide a domain name and open port as the access entry for file transfer to the client.

[0052] Optionally, a new file transfer service can be built by setting the service deployment directory, data storage directory, listening port, etc.

[0053] As an optional embodiment, step S104, generating at least one target account based on the file transfer service data, includes: in response to an account creation request from a client, obtaining first attribute information of the target account; generating the target account based on the first attribute information.

[0054] In this embodiment, when the account creation request of the client is obtained, the first attribute information of the target account can be obtained. Among them, the target account can be a login account used by the user to transfer files on the file transfer management platform, and the first attribute information can be used to represent the required data of the client for the target account. For example, when creating a user account, basic information such as the account name, account purpose, and affiliated file transfer service can be specified on the file transfer management platform. It should be noted that the specific information included in the first attribute information of the obtained target account is only for illustrative purposes and is not specifically limited.

[0055] Optionally, after the user specifies the first attribute information on the file transfer management platform, a target account can be applied for creation. The file transfer management platform automatically identifies the file transfer service corresponding to the account and can find the corresponding host device, checks whether the target account to be created conflicts with the accounts already existing in the host device. After judgment, if there is no conflict, the target account can be added at the host device level and corresponding permissions can be provided for the target account.

[0056] As an optional embodiment, step S104, generating at least one target account based on the file transfer service data, includes: displaying the status information of the target account on the image display interface.

[0057] In this embodiment, during the process of creating the target account, the status information of the target account can be displayed on the image display interface. Among them, the status information of the target account can be used to represent the generation status of the target account. For example, the status information of the target account can include at least one of the following: pending generation status, generating status, and generated status. It should be noted that this is only for illustrative purposes and is not specifically limited.

[0058] For example, when the file transfer management platform detects an application for creating a user account, it can automatically identify the file transfer service corresponding to the account, find the corresponding bare metal host, create a file transfer account generation task, set the task status to the "pending execution status". After the agent process queries and perceives the task, it can set the task status to the "executing status", and can start creating the account on the local machine. After the account creation is completed, the task status can be set to the "generated status".

[0059] As an optional embodiment, step S106, sending the file to be transferred to the file receiving end based on at least one target account, includes: in response to a key generation instruction from the client, obtaining second attribute information of the key; based on the second attribute information, generating at least one pair of keys for the target account.

[0060] In this embodiment, when the key generation instruction from the client is obtained, the second attribute information of the key can be obtained. The second attribute information can be used to characterize the basic feature data of the key. For example, the second attribute information of the key can include basic information such as the user of the key, the effective usage time of the key, and the usage scenario of the key. It should be noted that this is only an example, and there is no specific limitation on the basic features of the key.

[0061] Optionally, based on the second attribute information of the key, at least one pair of keys can be generated for the target account. The key can include a private key and a public key. The private key can be used to log in to the target account on the host device, and the public key can be used to encrypt the file to be transferred provided by the client.

[0062] For example, in a scenario where encryption is required, the user discloses the public key to the file provider for encryption, transfers the encrypted file to another user, and the other user can decrypt the encrypted file with the private key.

[0063] As an optional embodiment, step S106, if the time period for logging in to the target account with the private key is greater than the target time period, then send a prompt message to the client.

[0064] In this embodiment, when the time period for logging in to the target account with the private key exceeds the target time period, the file transfer management platform can send a prompt message to the client. The target time period can be one of the valid time periods. The prompt message is used to prompt the client to update the key. The target time period can be a valid time period or a time period set by the client itself. It should be noted that this is only an example, and there is no specific limitation on the target time period.

[0065] Optionally, after generating a key for the target account, the file transfer management platform can manage the key and can update the key status of the target account in real time. If the expiration time of the private key is approaching, the file transfer management platform can send a replacement reminder to the user.

[0066] As an optional embodiment, in step S106, in response to a service offline instruction from the client, delete the file transfer service data on the host device.

[0067] In this embodiment, when the application scenario of the client changes, the client can send a service offline instruction to the file transfer management platform. After the file transfer management platform receives the service offline instruction from the client, the file transfer management platform can delete the file transfer service data on the host device to release and ensure the security of the file in a timely manner after the file transfer service is no longer used.

[0068] Optionally, the file transfer management platform can close the keep-alive file transfer service daemon and all file transfer service programs, and can move the data to a specified storage location for archiving for subsequent use, delete all accounts used by the file transfer service from the host account, and can delete the file transfer service deployment directory.

[0069] The embodiment of the present invention sends file transfer service data to the host device where the client is located based on obtaining the service deployment instruction of the client, generates a target account based on the file transfer service data, and then transfers the file to be transferred to the file receiving end, thereby solving the technical problem of low file transfer efficiency and achieving the technical effect of improving file transfer efficiency.

[0070] Embodiment 2

[0071] The technical solution of the embodiment of the present invention will be illustrated below in conjunction with the preferred implementation manner.

[0072] In response to the need for secure file transfer, after encrypting the file using an encryption algorithm, manual login to the machine is used for operation and maintenance management operations such as accounts, keys, and directories, and the file is transferred through conventional channels. As a result, the management cost for operation and maintenance personnel to manage the file transfer service is too high, the security of the file cannot be effectively guaranteed under conventional channels, and encryption and decryption will lead to a decrease in transfer efficiency. Therefore, the technical problem of low file transfer efficiency still exists.

[0073] However, the embodiment of the present invention proposes a data processing method. This method can greatly reduce the management cost of operation and maintenance personnel managing the file transfer service from three dimensions: multiple file transfer services, multiple accounts of the file transfer service, and multiple keys of the file transfer account, so as to solve the technical problem of low file transfer efficiency.

[0074] The data processing method of the embodiment of the present invention will be further introduced below. The method may include:

[0075] The first part is to build a file transfer management platform and manage host devices.

[0076] The file transfer management platform can manage multiple clients. According to the cooperation requirements of different clients, it can isolate and manage different clients, prepare appropriate machine resources according to the quantity of file transfer services required by different clients, connect the prepared host devices to the file transfer service management platform for management, and deploy the agent process of the file transfer management platform on the host devices.

[0077] For example, in the file transfer management platform, it can be seen how many hosts are connected for management, and it can obtain how many central processing units, memories, disks, and network resources are available for allocation on each host.

[0078] The second part is to build a file transfer service for a new client.

[0079] When a new client accesses, the file transfer administrator first needs to evaluate the expected usage of file transfer resources of the client according to the institutional usage scenario. The client inputs the basic information for building a file transfer service on the file transfer management platform. The file transfer management platform can provide two cluster building methods: manual allocation and automatic allocation.

[0080] In the manual management scenario, the information corresponding to each client of the file transfer service is generally registered manually. The platform management requires that the information can be improved at the beginning of creating the service to ensure subsequent maintainability. The platform management requires additional registration of file transfer service information at the beginning of creating the service.

[0081] After the client completes the cluster creation application on the file transfer management platform, the file transfer management platform locks the corresponding host device resources, can create a file transfer service construction task, and sets the task status to the "to be executed" status. The agent process regularly reports the working status to the file transfer management platform and queries whether there is a task to be executed on the host where it is located. The agent process creates a file transfer service. After the agent process completes the service creation, it reports the creation information and results to the file transfer management platform, and sets the file transfer service construction task to "execution successful" or "execution failed".

[0082] For example, a user inputs the basic information for setting up a file transfer service on the platform. Here, the basic information may include: cluster name, open port, CPU requirements, memory requirements, disk requirements, network bandwidth requirements, etc. It should be noted that this is only an example, and there is no limitation on the basic information that the file transfer service to be set up by the user needs to meet.

[0083] For another example, manual allocation means that the user retrieves the resource status of all managed bare metal hosts, selects a bare metal host that meets the resource requirements, and then can create a file transfer service on this host. After the platform records the resources used by this file transfer service, the resources of this bare metal host are deducted for the next cluster allocation; automatic allocation means that the user only inputs the resources required for the file transfer service, and the platform automatically selects a host that meets the requirements according to the resource status of the managed bare metal hosts for file transfer service deployment.

[0084] As an optional example, the corresponding information of the client of some file transfer services is generally manually registered using emails, communication software, or the company's internal knowledge base, and there are often cases of incorrect or missing records. At the beginning of service creation managed by the platform, information such as the client corresponding to the service, the purpose of the transferred file, the file retention time, and the acceptable downtime for maintenance can be improved. It should be noted that this is only an example, and there is no specific limitation on the information that needs to be improved at the initial stage of service creation.

[0085] For example, the agent process generally reports its working status to the file transfer management platform at an interval of ten seconds. In scenarios with high timeliness requirements, the user can set a shorter query interval. When the agent process of the target host device queries the file transfer service construction task, it downloads the basic information of the file transfer service to the local and notifies the file transfer management platform to set the task status to "in execution".

[0086] Figure 2 is a flowchart of creating a file transfer service according to an embodiment of the present invention. As Figure 2 shown, it may include the following steps:

[0087] Step S201, pre-check.

[0088] In the technical solution provided in step S201 of the present invention above, the file transfer management platform needs to check whether the port is occupied, whether there is a file transfer service with the same name deployed on the host, and whether the host resources are sufficient.

[0089] Step S202, deploy the file transfer program.

[0090] In the technical solution provided in step S202 of the present invention, the platform can deploy a pre-prepared file transfer program to a uniformly specified directory. For example, the directory can be uniformly " / home / file transfer / name"; and the file transfer name needs to be globally unique.

[0091] Step S203, create a data directory.

[0092] In the technical solution provided in step S203 of the present invention, on the disk allocated by the platform, a data directory for file transfer is established; the data directory also needs to follow a unified specification. For example, the data directory can be uniformly " / home / disk1 / file transfer data / name".

[0093] Step S204, generate the server key.

[0094] In the technical solution provided in step S204 of the present invention, the file transfer management platform can host the server key. For the first time, a dedicated key for the file transfer service can be deployed and generated. For example, the dedicated key can be deployed as / ssh_host_rsa_key / , / ssh_host_ecdsa_key / , and it is specified that the file transfer service deployed this time uses these keys. These keys can be saved in a specified directory. For example, they can be saved in the directory / home / file transfer / name / hostkey, and the key information is reported to the file transfer management platform for record retention.

[0095] Step S205, configure the security policy.

[0096] In the technical solution provided in step S205 of the present invention, it is set to prohibit root login, other users with login permissions can be set to be refused, password login is closed, and other function points that are not used for file transfer are closed.

[0097] Step S206, configure the basic service.

[0098] In the technical solution provided in step S206 of the present invention, the service listening port can be set, the user password directory can be set, and the log level can be set.

[0099] Step S207, start the service.

[0100] In the technical solution provided in step S207 of the present invention, the program startup script can be run to start the program, and the daemon process for keeping the file transfer program alive can be started to automatically restart when the file transfer service exits abnormally.

[0101] Step S208, post-check.

[0102] In the technical solution provided in step S208 of the present invention, a test account is created and the test account is used to log in to verify the service status.

[0103] Part Three, account creation.

[0104] When the client needs to create an account, it can specify basic information such as the account name, account usage, and the file transfer service to which it belongs in the file transfer management platform. The management platform can automatically identify the file transfer service corresponding to the account, find the corresponding host device, create a "file transfer account creation task", and the task status can be set to "pending execution". After the agent process queries and senses the task, it sets the task status to "executing" and can start creating the account.

[0105] Figure 3 is a flowchart for creating an account in the file transfer management platform according to an embodiment of the present invention. As Figure 3 shown, creating an account in the file transfer management platform may include the following steps:

[0106] Step S301, pre-check.

[0107] In the technical solution provided in step S301 of the present invention, the file transfer management platform checks whether the account conflicts with the accounts already existing on the host, and checks whether there are conflicts in the account key directory and the account data directory.

[0108] Step S302, host account creation.

[0109] In the technical solution provided in step S302 of the present invention, an account can be added at the host device level, and the account can be set to be prohibited from logging in.

[0110] Step S303, account directory creation.

[0111] In the technical solution provided in step S303 of the present invention, the key directory of the account is created according to the directory specification, the data directory of the account is created according to the directory specification, both directories are created using root, the sub-directory of the data directory of the account is created according to the directory specification, and the created account needs to have read and write permissions for this directory.

[0112] Step S304, bind the account to the file transfer service.

[0113] In the technical solution provided in step S304 of the present invention, the file transfer service configuration is modified, Match.User can be set to specify the data directory for chroot after the account logs in, and the file transfer service is restarted to load the configuration.

[0114] Step S305, post-check.

[0115] In the technical solution provided in step S305 of the present invention, a test key is added to the account, and the account is used for login verification.

[0116] It should be noted that all process nodes from S301 to S305 of the above account creation process must be successful for the account to be created successfully. If any process node fails, the account creation fails, and the file transfer management platform is informed.

[0117] Part Four, key management.

[0118] The account login for file transfer requires corresponding keys to be configured before login. One account can configure one or more keys. The client registers the basic key information on the file transfer platform and applies for adding a new key. The file transfer management platform creates a "key addition task" or "key deletion task" and sets the task status to "pending execution". After the agent process queries the new task, it sets the task status to "executing" and can execute the key management process on the host where the file transfer service is located. The agent process reports the execution result and relevant information to the file transfer management platform. The file transfer management platform updates the key situation under this account and can set the task to "execution successful" or "execution failed". After the key expiration time, the file transfer management platform reminds the user for replacement.

[0119] The above execution of the key management process on the host where the file transfer service is located may include the following steps: The file transfer management platform checks the key file in the key directory (if it does not exist, it creates it). For the addition scenario, it checks whether there is a key to be added in the file (if there is, it skips; if not, it appends to the file). For the deletion scenario, it checks whether there is a key to be deleted in the file (if there is, it deletes the key; if not, it skips).

[0120] Part Five, file transfer service offline.

[0121] When the scenario cooperating with the client changes, the file transfer service may no longer be used. To release it in time and ensure data security, the file transfer service needs to be taken offline. The client initiates the file transfer service offline on the platform. The file transfer management platform creates a "file transfer service offline task" and sets the status to "pending execution". After the agent process queries the offline task, it sets the status to "executing" and executes the offline process on the machine where the file transfer service is located. Finally, the agent process reports the execution result and relevant information to the file transfer management platform. The file transfer management platform can update the status of the file transfer service and set the task status to "execution successful" or "execution failed".

[0122] Figure 4It is a flowchart of the offline of the file transfer service according to an embodiment of the present invention. As Figure 4 shown, the offline of the file transfer service may include the following steps:

[0123] S401, Process shutdown.

[0124] In the technical solution provided in step S401 of the present invention above, the file transfer management platform shuts down the keep-alive file transfer service daemon and all file transfer service programs.

[0125] S402, Data archiving.

[0126] In the technical solution provided in step S402 of the present invention above, all the data of the file transfer is moved to a specified storage location for archiving processing for subsequent use. All the access logs of the file transfer can be moved to the specified storage location for archiving together.

[0127] S403, Account cleaning.

[0128] In the technical solution provided in step S403 of the present invention above, all the accounts used by the file transfer service are deleted from the host account.

[0129] S404, Service cleaning.

[0130] In the technical solution provided in step S404 of the present invention above, the file transfer service deployment directory is deleted, which includes the program files, configuration files, host keys, and user keys of the file transfer service, and the files remaining after archiving in the data directory are deleted.

[0131] Figure 5 It is a schematic diagram of the architecture of the file transfer management platform according to an embodiment of the present invention. As Figure 5 shown, based on the above construction of the management platform for file transfer, the architecture of the file transfer management platform can be obtained. The architecture in the figure includes host device - 1501, file transfer management platform 502, host device - 2 503, and database 504. In the current management mode, due to a large number of associated clients, for the consideration of data security and cost, multiple host device servers are adopted. Each host device deploys multiple file transfer services for different clients. In order to achieve unified platform management, a file transfer agent process is deployed on each host device. This agent process is responsible for collecting the file transfer service information on the host and actual management operations. The agent process reports information to the file transfer management platform regularly and queries whether there are change operations. Users can operate through the file transfer management platform without paying attention to the details of the underlying host device used and the deployment of the file transfer service. The file transfer management platform maintains the management information of all file transfer services and records the management operation behaviors of users.

[0132] In an embodiment of the present invention, in response to a service deployment instruction from a client, at least one file transfer service data to be sent to the host device where the client is located is determined; based on the file transfer service data, at least one target account is generated; and based on the at least one target account, the file to be transferred is sent to the file receiving end, thereby solving the technical problem of low file transfer efficiency and achieving the technical effect of improving file transfer efficiency.

[0133] Embodiment 3

[0134] According to an embodiment of the present invention, there is also provided a data processing device. It should be noted that this data processing device can be used to execute the data processing method in Embodiment 1.

[0135] Figure 6 is a schematic diagram of a data processing device according to an embodiment of the present invention. As Figure 6 shown, the data processing device 600 may include: a determination unit 602, a generation unit 604, and a sending unit 606.

[0136] The determination unit 602 is configured to, in response to a service deployment instruction from a client, determine at least one set of file transfer service data to be sent to the host device where the client is located, where the file transfer service data is used to deploy a file transfer service on the host device, and the file transfer service is used to perform encrypted transmission on the file to be transferred.

[0137] The generation unit 604 is configured to generate at least one target account based on the file transfer service data, where each target account is used to identify the file transfer service data.

[0138] The sending unit 606 is configured to send the file to be transferred to the file receiving end based on the at least one target account.

[0139] Optionally, the generation unit 604 includes: a first acquisition module, configured to acquire first attribute information of the target account in response to an account creation request from the client, where the first attribute information includes at least one of the following: the name information of the target account, and the file transfer service data corresponding to the target account.

[0140] Optionally, the generation unit 604 further includes: a display module, configured to display the status information of the target account on an image display interface, where the status information is used to characterize the generation status of the target account, and the generation status includes at least one of the following: a to-be-generated status, a generated status, and a being-generated status.

[0141] Optionally, the sending unit 606 includes: a second acquisition module, configured to acquire the domain name of the host device and the login port of the host device in response to the successful deployment of the file transfer service on the host device.

[0142] Optionally, the sending unit 606 further includes: a first sending module, configured to send a domain name and a login port to the client.

[0143] Optionally, the apparatus further includes a first obtaining unit, configured to obtain second attribute information of a key in response to a key generation instruction from the client, where the second attribute information is used to characterize a valid time period of the key and a usage scenario of the key; the apparatus further includes a first generating unit, configured to generate at least one pair of keys for a target account based on the second attribute information, where the key at least includes a private key, and the private key is used to log in to the target account on the host device.

[0144] Optionally, the first obtaining unit further includes: a second sending module, configured to send a prompt message to the client if a time period for logging in to the target account with the private key is greater than a target time period, where the target account time period is one of the time periods within the valid time period, and the prompt message is used to prompt the client to update the key.

[0145] Optionally, the apparatus further includes a deleting unit, configured to delete file transfer service data on the host device in response to a service off-line instruction from the client.

[0146] In an embodiment of the present invention, a determining unit is configured to determine at least one set of file transfer service data to be sent to a host device where the client is located in response to a service deployment instruction from the client, where the file transfer service data is used to deploy a file transfer service on the host device, and the file transfer service is used to perform encrypted transmission on a file to be transmitted; a generating unit is configured to generate at least one target account based on the file transfer service data, where each target account is used to identify the file transfer service data; a sending unit is configured to send the file to be transmitted to a file receiving end based on the at least one target account, thereby solving the technical problem of low file transfer efficiency and achieving the technical effect of improving file transfer efficiency.

[0147] Embodiment 4

[0148] According to an embodiment of the present invention, there is also provided a computer-readable storage medium, where the storage medium includes a stored program, and the program executes the data processing method described in Embodiment 1.

[0149] Embodiment 5

[0150] According to an embodiment of the present invention, there is also provided a processor, where the processor is used to run a program, and when the program runs, it executes the data processing method described in Embodiment 1.

[0151] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.

[0152] In the above embodiments of the present invention, the descriptions of the respective embodiments each have their own focuses. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0153] In several embodiments provided by the present invention, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.

[0154] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0155] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0156] If the above-mentioned integrated units are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.

[0157] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A method for data processing, characterized in that, Including: In response to a service deployment instruction from a client, determining at least one set of file transfer service data to be sent to the host device where the client is located, where the file transfer service data is used to deploy a file transfer service on the host device, and the file transfer service is used to perform encrypted transmission of files to be transferred; Generating at least one target account based on the file transfer service data, where each target account is used to identify the file transfer service data; Sending the file to be transferred to the file receiving end based on at least one of the target accounts; Among them, the determining at least one set of file transfer service data to be sent to the host device where the client is located in response to a service deployment instruction from the client includes: in response to the service deployment instruction, determining the file transfer service data sent to the host device through a file transfer management platform, where the file transfer management platform is used to classify and isolate different clients according to the demand information of different clients for the file transfer service; Among them, the generating at least one target account based on the file transfer service data includes: in response to determining the host device where the file transfer service corresponding to the client is located, adding at least one of the target accounts in the host device based on the file transfer service data; The method further includes: in response to adding at least one of the target accounts in the host device, modifying the configuration information of the file transfer service to allow at least one of the target accounts to log in to the file transfer management platform; in response to the completion of the modification of the configuration information, sending at least one of the target accounts to the corresponding client.

2. The method according to claim 1, wherein Generating at least one target account based on the file transfer service data includes: In response to an account creation request from the client, obtaining first attribute information of the target account, where the first attribute information includes at least one of the following: name information of the target account, and the file transfer service data corresponding to the target account; Generating the target account based on the first attribute information.

3. The method according to claim 2, characterized in that, The method further includes: Displaying status information of the target account on an image display interface, where the status information is used to characterize the generation status of the target account, and the generation status includes at least one of the following: to-be-generated status, being-generated status, and generated status.

4. The method according to claim 1, wherein After sending at least one set of file transfer service data to the host device where the client is located, the method further includes: In response to the successful deployment of the file transfer service on the host device, obtaining the domain name of the host device and the login port of the host device; Sending the domain name and the login port to the client.

5. The method according to claim 1, wherein The method further includes: In response to a key generation instruction from the client, obtaining second attribute information of the key, where the second attribute information is used to characterize the valid time period of the key and the usage scenario of the key; Generate at least one pair of the keys for the target account based on the second attribute information, where the keys at least include a private key, and the private key is used to log in to the target account on the host device.

6. The method according to claim 5, wherein The method further includes: In response to the time period during which the target account is logged in using the private key being greater than a target time period, send a prompt message to the client, where the target time period is one of the time periods within the valid time period, and the prompt message is used to prompt the client to update the key.

7. The method according to claim 1, characterized in that, The method further includes: In response to a service offline instruction from the client, delete the file transfer service data on the host device.

8. A data processing device, characterized in that, Includes: A determination unit, configured to, in response to a service deployment instruction from a client, determine at least one set of file transfer service data to be sent to the host device where the client is located, where the file transfer service data is used to deploy a file transfer service on the host device, and the file transfer service is used to perform encrypted transmission of files to be transferred. The step of, in response to a service deployment instruction from a client, determining at least one set of file transfer service data to be sent to the host device where the client is located includes: in response to the service deployment instruction, determining the file transfer service data to be sent to the host device through a file transfer management platform, where the file transfer management platform is used to classify and isolate different clients according to the demand information of different clients for the file transfer service; A generation unit, configured to generate at least one target account based on the file transfer service data, where each target account is used to identify the file transfer service data; A sending unit, configured to send the file to be transferred to a file receiving end based on at least one of the target accounts; Wherein, the generation unit may further be configured to perform the following steps: in response to determining the host device where the file transfer service corresponding to the client is located, add at least one of the target accounts in the host device based on the file transfer service data; The apparatus may further be configured to perform the following steps: in response to adding at least one of the target accounts in the host device, modify the configuration information of the file transfer service to allow at least one of the target accounts to log in to the file transfer management platform; in response to the modification of the configuration information being completed, send at least one of the target accounts to the corresponding client.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, where when the program runs, it controls the device where the computer-readable storage medium is located to execute the data processing method according to any one of claims 1 to 7.

10. A processor, characterized in that, The processor is used to run a program, where when the program is run by the processor, it executes the data processing method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • SFTP file transparent transmission method and system

    CN107071060A