Data Isolation, Duplication Prevention, Analysis Method and Device for Payment SAAS Products

By introducing dynamic routing devices and message middleware into payment SAAS products, data isolation, weight prevention and analysis are realized, which solves the problem of insufficient flexibility and universality of data isolation and weight prevention in the prior art, and improves the scalability and fund security of the system.

CN115422566BActive Publication Date: 2025-06-13SHANGHAI HUIFU PAYMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211122654.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-15
Publication Date
2025-06-13
Estimated Expiration
2042-09-15

AI Technical Summary

Technical Problem

Existing payment SAAS products have insufficient flexibility and versatility in data isolation, reimbursement and database access methods, resulting in frequent code modification, resource waste and data governance complexity at all stages of data growth.

Method used

Using a data isolation, weight prevention and analysis method and device under payment SAAS products, the database is automatically connected to the dynamic routing device to realize data weight prevention and isolation, and the data is written to the data aggregation warehouse through message middleware for real-time streaming calculation and data governance.

Benefits of technology

It realizes the universality and flexibility of data isolation, heavy protection and analysis, reduces the need for resource waste and code modification, and improves the scalability and fund security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115422566B_ABST
    Figure CN115422566B_ABST
Patent Text Reader

Abstract

The present invention discloses a data isolation, anti-duplication, analysis method and device for payment SAAS products, which can not only meet the requirements of the payment SAAS product itself for business data isolation, data real-time, system security and stability, but also ensure the data anti-duplication and data routing solutions for the capital security, cost reduction and efficiency improvement of multiple tenants. The technical solution is as follows: The present invention has strong versatility, simple implementation and low resource consumption, and automatically routes to the corresponding databases and tables according to rules to achieve data isolation, data anti-duplication and data analysis under the payment SAAS product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of service governance, storage media, data analysis, data duplication prevention, data isolation, data security, etc., and particularly relates to a data isolation, duplication prevention, and analysis method and device for a payment SAAS (Software-as-a-Service) product. Background Art

[0002] With the continuous development of the Internet and the popularization of mobile payment, the volume of scanned code transactions has increased exponentially, and digitalization has accelerated. In the enterprise payment field, the data volume is large, the functions are complex, and the changes and concurrency are frequent. Tenants attach more and more importance to data, and have very high requirements for data real-time performance, capital security, data security, resource cost, and data processing capabilities.

[0003] To solve this problem and enable the system to have better elastic scaling capabilities, a distributed microservice architecture, a container (kubernetes) cloud management platform, and a partition unitary deployment scheme are usually used. The mainstream solution is vertical upgrade, but the cost is relatively high. When the request volume increases, in addition to quickly improving the overall request throughput by increasing the number of service instances, a sharding and partitioning method is also adopted to process transaction data. For a large volume of data, simply relying on traditional database association queries and manual comparison work can no longer meet the scalability requirements of data. In addition, there are also very high requirements for the performance of the database itself. The most popular technology currently is real-time streaming computing of data, and the data isolation and data governance solutions for the payment SAAS scenario are also relatively cumbersome. For the scenarios of multi-tenants and merchants on multi-cloud platforms, there is currently no good solution.

[0004] In the application of payment SAAS products, as the business develops, the system access volume is getting larger and larger, and at the same time, the accumulated data of the system is getting more and more. The originally designed duplication prevention mechanism and database architecture can no longer meet the performance and business requirements. Usually, the original database is horizontally partitioned, and at the same time, it may also be vertically partitioned according to business needs, that is, table partitioning and database partitioning. Along with the change of the database architecture, the database access method will also change accordingly, and the sharding and partitioning algorithms used in different stages are also different. The main problems are as follows:

[0005] (1) Data duplication prevention, data isolation, and database access methods change with the change of the architecture: As the accumulated data changes from less to more, and the corresponding database architecture changes, the original routing method will also change, and the database access method needs to be modified and configured accordingly. Then, a large amount of code modification and testing are required, which takes a long time and is prone to errors, resulting in a large amount of resource waste.

[0006] (2) The algorithms for data duplication prevention, data isolation, and database sharding cannot be flexibly configured: As the access volume and data volume of the application system accumulate, different duplication prevention mechanisms and table sharding methods are required at different stages. Without flexible configuration, the solution lacks generality.

[0007] (3) Data duplication prevention and data isolation are not flexible enough to allocate resources separately for high-traffic tenants, solve storage data isolation, and are complex to implement and difficult to access.

[0008] (4) In new specific business scenarios, it is impossible to perform data isolation for multi-tenants and configure resources for separate routing of specific merchants under member tenants. Data governance, data analysis, data security, and stability cannot be guaranteed.

[0009] In summary, how to design a data duplication prevention and data routing solution that can not only meet the data isolation, data real-time, system security and stability of the payment SAAS product itself, but also ensure the capital security of multi-tenants, reduce costs and increase efficiency, so that the database access method is fixed at each stage of data growth, without the need to modify the code on a large scale, and can flexibly configure the sharding algorithm, data isolation, data duplication prevention, and data analysis methods, is an urgent problem to be solved in the industry. Summary of the Invention

[0010] The following presents a brief overview of one or more aspects to provide a basic understanding of these aspects. This overview is not an exhaustive survey of all contemplated aspects, and is neither intended to identify key or decisive elements of all aspects nor to define the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to a more detailed description to follow.

[0011] The object of the present invention is to solve the above problems, and provides a data isolation, duplication prevention, and analysis method and device under a payment SAAS product, which has strong generality, simple implementation, and low resource consumption, and automatically routes to the corresponding database and table according to rules to achieve data isolation, data duplication prevention, and data analysis under the payment SAAS product.

[0012] The technical solution of the present invention is as follows: The present invention discloses a data isolation, duplication prevention, and analysis method under a payment SAAS product, and the method includes:

[0013] In the first stage, after the business application is started, the business request enters the routing device of the database through the application controller to dynamically read the database index. After the processing process of the routing device starts, the business request first enters the routing device. The routing device starts and is in the initial ready state, and automatically connects to the corresponding database according to the parameters passed in during startup. When the routing device successfully connects to the database, the ready state where the routing device is currently located is updated to the normal state by the routing control device, and the business request switches the data traffic to the routing device;

[0014] In the second stage, the database index of the routing control device will disconnect from the routing device and the database. The database index of the routing control device is completely replaced by a new routing device. At the same time, the old routing device stops processing and disconnects from the database;

[0015] In the third stage, the new routing device in the original business application starts to read the routing configuration of the sharded data, and performs data deduplication prevention, data source switching, and database routing processing, and then performs data warehousing. During the data warehousing process, the database index in the new routing device enters the non-ready state from the ready state. After the ready state is enabled, the business request enters the database through the new database routing device, and the new database routing device enters the ready state, and then enters the new service through the new database routing device;

[0016] In the fourth stage, the routing control device will no longer process, and the traffic will be processed by the new database routing;

[0017] In the final stage, through the data control device, all payment transaction data is uniformly sent to the message middleware by collecting the database log files, and the message middleware then writes the data into the data aggregation warehouse according to the routing configuration of the member tenant and the non-member tenant.

[0018] According to an embodiment of the data isolation, deduplication prevention, and analysis method under the payment SAAS product of the present invention, the first stage further includes:

[0019] First, the routing device processes data through the database index and the dynamic addressing algorithm, reads the sharded database list configuration, dynamically reads the configuration mapping library, and obtains the specified unit database according to the current partition and the unit group where it is located;

[0020] The routing device performs the data deduplication prevention processing process, converts all sharded mapping keys and unit database mapping tables into a single-layer mapping relationship, and searches for the converted single-layer mapping relationship in the redis buffer;

[0021] If there is no single-layer mapping relationship in the Redis cache area, query the single-layer mapping relationship converted from the index database. If no single-layer mapping relationship is found in both the Redis cache area and the index database, directly store the shard mapping key and the single-layer mapping relationship into the index database. Otherwise, intercept duplicate data;

[0022] According to the database sharding algorithm, calculate the data source name from the sharded data source, parse the SQL, and use the primary key and the corresponding index mapping relationship data as conditions to compare with the unit database passed in, and finally route to the specified database. When it is checked that the current data comes from the default database in the parsed query conditions, the data enters the default database.

[0023] The present invention also discloses a data isolation, anti-duplication, and analysis device for a payment SAAS product. The device includes a data processing module, a support module, and a management module, where:

[0024] The support module includes a container cloud management platform and a database monitoring center. The container cloud management platform is responsible for managing the release of system applications, and the applications are in containers; the database monitoring center is responsible for monitoring whether the database is available, so as to ensure that data writing and updating are not affected, and at the same time is responsible for synchronously writing the data in the data writing layer to the data aggregation layer in a collected form;

[0025] The management module includes a data governance module, a billing module, a routing configuration center, and a routing asynchronous data module. The data governance module is used for data cleaning, the billing module is used for billing member tenants and ordinary tenants and for billing various system resources, the routing asynchronous data module is responsible for asynchronously writing database routing data into the index library, and the routing configuration center is responsible for routing configuration, and at the same time provides configuration reading and routing data support for the routing layer;

[0026] The data processing module includes an application layer, a routing layer, a data writing layer, and a data aggregation layer. The application layer is the original data entry, which cooperates with the framework interface, abstracts and outputs the original data after database routing and data anti-duplication device, and isolates multi-tenant data; the routing layer includes a cache area, a buffer area, and a data area; the data writing layer is the data passed through the database routing device, and writes to different databases according to the configurations of member tenants and ordinary tenants. The data retention time of the databases in this data writing layer is dynamically set according to real-time dynamic configuration of the business scenario; the data aggregation layer sends the data in the data writing layer to the message middleware by collecting database log files, and the message middleware then outputs according to member tenants and non-member tenants and writes to non-relational databases and relational databases, and then performs data governance and data analysis on the data written to the databases.

[0027] According to an embodiment of the data isolation, anti-duplication, and analysis device for the payment SAAS product of the present invention, in the routing layer, the routing device dynamically configures the database index of the routing data through the routing configuration center for database address indexing and dynamic addressing, performs data anti-duplication through the data area, and then switches the data source and routes to the specified partition database; dynamically and manually set whether the current database address index needs to be cached and buffered, and at the same time, the timeliness of the cache area and buffer area for different business scenarios is dynamically configurable and exclusive.

[0028] The present invention has the following beneficial effects compared with the prior art: The technical solution of the present invention includes the following innovative points.

[0029] (1) Based on the existing data isolation, data anti-duplication, and data analysis methods, the present invention makes full use of the database routing of single-object type metadata and multi-object type metadata, synchronously and dynamically configures the data source and seamlessly switches the database in real time, without causing additional resource waste. By collecting database log files, aggregating data into a data warehouse, performing real-time streaming computing on the data, and using a data governance platform, it provides one-stop data collection, processing, management, and application.

[0030] (2) The present invention adds databases arbitrarily in the application and expands the anti-duplication strategy of the library and the abstract table ID field infinitely. When summarizing the same table in multiple databases, it can avoid the situation where data is overwritten and lost, prevent duplicate payments, and provide guarantee for the capital security of tenants. Only need to assume the responsibility of manual configuration in the data routing configuration center.

[0031] (3) The data isolation, data anti-duplication, and data analysis methods and devices of the present invention can reduce costs and increase efficiency. Separate resources are allocated for large-traffic tenants, solving the problem of storage data isolation, and no additional transformation is required for the application service, which is simpler and easier to access in implementation.

[0032] (4) In the new specific business scenario, the present invention performs data isolation for multiple tenants and separately routes and configures resources for specific merchants under member tenants, so as to reduce costs, improve efficiency, and ensure data security and stability. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] After reading the detailed description of the embodiments of the present disclosure in conjunction with the following drawings, the above features and advantages of the present invention can be better understood. In the drawings, the components are not necessarily drawn to scale, and components with similar related characteristics or features may have the same or similar reference numerals.

[0034] Figure 1 The flowchart of an embodiment of the data isolation, anti-duplication, and analysis method for the payment SAAS product of the present invention is shown.

[0035] Figure 2 shows Figure 1 the process flow chart of the method embodiment shown in a multi-tenant scenario.

[0036] Figure 3 shows the structural diagram of an embodiment of the data isolation, duplicate prevention, and analysis device under the payment SAAS product of the present invention. Detailed implementation manners

[0037] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. Note that the aspects described below in conjunction with the accompanying drawings and specific embodiments are merely exemplary and should not be construed as imposing any limitation on the protection scope of the present invention.

[0038] Figure 1 shows the process of an embodiment of the data isolation, duplicate prevention, and analysis method under the payment SAAS product of the present invention. Please refer to Figure 1 , and the implementation steps of the method of this embodiment are described in detail as follows.

[0039] In the first stage, after the business application is started, an external business request dynamically reads the db index (database index) through the application controller and enters the routing device of the database. After the processing of the routing device starts, ( Figure 1 mark ① in) the business request first enters the routing device (completed by the db index of the routing control device of the database), and the routing device starts and is in the initial ready state (determined by the db index and the routing monitoring center of the database). Among them, both the routing control device and the routing monitoring center of the database are located inside the routing device. After the routing device starts, it automatically connects to the corresponding database according to the parameters passed in during startup ( Figure 1 mark ② in). When the routing device successfully connects to the database, the ready state where the routing device is currently located is updated to the normal state by the routing control device (db index combined with routing configuration). The business request switches the data traffic to the routing device (mark ③ in the figure).

[0040] The details of the processing process in the above first stage are as follows.

[0041] In a routing device, first, the routing device processes data through a db index and a dynamic addressing algorithm (the dynamic addressing algorithm stores the sharding database sharding key and the corresponding database in the database, which can also be called a distributed dynamic addressing algorithm), reads the sharded database list configuration, dynamically reads the configuration mapping library, and obtains a specified dbUint (unit database) according to the current partition and the unit group where it is located. Then, the routing device performs a data deduplication process, converts all sharding mapping keys and the k-v mapping table (unit database mapping table) into a single-layer mapping relationship, and looks up the converted single-layer mapping relationship in the redis buffer. If there is no single-layer mapping relationship in the redis buffer, it queries the converted single-layer mapping relationship from the index database. If no single-layer mapping relationship is found in both the redis buffer and the index database, it directly stores the sharding mapping key and the single-layer mapping relationship into the index database. Otherwise, it intercepts duplicate data (the duplicate data is the primary key and dbUnit index mapping relationship data). Then, according to the database sharding algorithm (for example, the precise sharding and database sharding algorithm), it calculates the data source name from the sharded data source, parses the SQL, and uses the primary key and the corresponding dbUint index mapping relationship data (the key and value conditions in where) as conditions to compare with the unit database passed in, and finally routes to the specified database. When it checks that the current data comes from the default database in the parsed query conditions, the data enters the default database.

[0042] Note that at this time, only a small part of the tenant traffic goes to the new service, and most of the traffic still enters the database through the routing device of the old database. The advantages of doing this are as follows: First, if there are problems during this process, only the traffic requests of a small part of the tenants will be affected; Second, by allowing a small part of the tenant traffic to enter the new database routing device, it can give the database a warm-up process. After that, if there are no abnormal situations, the database routing control device will gradually increase the proportion of traffic entering the new routing device until all traffic enters the new application service through the database routing device.

[0043] In the second stage, at this time, no tenant traffic enters the database through the old routing device. The db index of the routing control device will disconnect the connection with the routing device and the database ( Figure 1 marker ④ in). After that, the db index of the routing control device will be completely replaced by the new routing device. At this time, the old routing device will stop processing and disconnect the connection with the database ( Figure 1 marker ⑤ in).

[0044] Then, the db index of the routing control device replaces and uses the new routing device according to the configuration (marker ⑥ in the third stage), and then enters the third stage.

[0045] In the third stage, the new routing device in the original business application starts to read the routing configuration for the sharded data, and performs processing for data deduplication, data source switching, and database routing. Then, data is stored in the database. During the process of data storage (steps ⑥, ⑦, and ⑧), the db index in the new routing device will start to change from the ready state to the non-ready state. In step ⑦, the ready state will be enabled and data will enter the database through the new database routing device. The new database routing device enters the ready state, and then the new database routing device is connected to the new service.

[0046] In the fourth stage, steps ⑨, ⑩, and 11 are similar to steps ④, ⑤, and ⑥ in the second stage. In steps ⑨ and ⑩, the state changes from the ready state to the non-ready state. In step 11, the routing control device will no longer process the traffic, and the traffic will be processed by the new database routing.

[0047] In the final stage, through the data control device, all payment transaction data is uniformly sent to the message middleware by collecting the database log files, and then the message middleware writes the data into the data aggregation warehouse according to the routing configurations for member tenants and non-member tenants.

[0048] Figure 2 Yes Figure 1 This is the processing flow of the method in a multi-tenant scenario. Multi-tenant technology, also known as multi-tenancy technology, abbreviated as SaaS, is a software architecture technology that realizes how to share the same system or program components in a multi-user environment (here, multi-tenants generally refer to enterprise users), and can ensure the isolation of data between tenants. Simply put: a single application instance runs on a server, providing services for multiple tenants (customers). From the definition, we can understand that multi-tenancy is an architecture aimed at enabling the use of the same set of programs in a multi-tenant environment and ensuring data isolation between tenants. Then, the key point is very easy to understand. The key point of multi-tenancy is to achieve the isolation of multi-user data under the same set of programs.

[0049] Please refer to Figure 2, There are two major categories in the process, namely member tenants and ordinary tenants. After the transaction traffic enters the system, the database routing method is used to determine whether the traffic data belongs to a member tenant or an ordinary tenant, dynamically read the data of the tenant management platform, and then route through the tenant management platform. The data sources are divided into member tenants and ordinary tenants. For member tenants, the system separately establishes resource data, including independent high - configuration servers, high - level database routing policies, member - specific databases, and other additional services. The data is tenant - isolated. For ordinary tenants, the database routing device routes the data to the unified standard resource data established by the ordinary tenant usage platform, with only standard servers, standard database routing policies, etc., and no additional services. There is only one copy of this data for the entire platform and it is invisible to tenants by default. Through the tenant management platform, it is dynamically combined. The data authorization method is to authorize the unified standard data to the tenant, which then becomes the tenant's private resource, that is, the member tenant.

[0050] The core idea of multi - tenant is to simplify complex problems. Since the system involves modules for permission isolation, and there are only differences in isolation between single - tenant and multi - tenant, the unified resources are converted into tenant - private resources through tenant data authorization, thus forming a single - tenant permission isolation logic, and then forming a unified standardized data isolation logic.

[0051] In Figure 2 's method, it can be seen that in the new specific business scenario, data isolation for multi - tenant and separate routing configuration of resources for specific merchants under member tenants are carried out, so as to reduce costs, improve efficiency, and ensure data security and stability.

[0052] Figure 3 Figure [0000124] shows the structure of an embodiment of the data isolation, anti - duplication, and analysis device in the payment SAAS product of the present invention. Please refer to Figure 3 , The device of this embodiment includes: a data processing module (further including an application layer, a routing layer, a data writing layer, and a data aggregation layer), a support module (further including a container cloud management platform and a database monitoring center), and a management module (further including a routing configuration center, a routing asynchronous data module, a data governance module, and a billing module). The above three modules are interdependent.

[0053] In the support module, the container cloud management platform is responsible for managing the release of system applications, which are applied in containers. The use of the cloud container cloud management platform provides the possibility for products to access other cloud service providers, and the company's bargaining power with various cloud vendors will be improved. Reduce costs: Through resource sharing, staggered operation and other means, the overall resource utilization rate is effectively improved. Improve efficiency: There is no need to apply for powerless resources. Through declarative release definitions, the one-click deployment function of the application can be completed. Safe and stable: Strict release process definitions ensure the consistency of the environment, and standardized management of images ensures the safety of production releases. All operations are observable and traceable.

[0054] The database monitoring center is responsible for monitoring the availability of the database to ensure that data writing and updating are not affected. It is also responsible for synchronously writing the data in the data writing layer to the data aggregation layer through collection. Since multiple data may cause some data to be in a dead state due to database anomalies, or there is too much data in the current processor memory that cannot be processed in time, the database monitoring center needs to check and issue alarms.

[0055] In the data processing module, the application layer is the raw data entry point. It cooperates with the framework interface to abstractly output the raw data through database routing and data anti-duplication devices, isolates multi-tenant data, and is the cornerstone of data analysis.

[0056] The routing layer mainly includes: cache area (redis cluster), buffer area (rocketmq, blocking queue), data area (data anti-duplicate mechanism in database index), and the routing device dynamically configures the database index dbindex of the routing data through the routing configuration center to perform db address indexing, dynamic addressing, and data anti-duplicate through the data area, and then switches the data source and routes to the specified partition database. Dynamically manually set whether the current db address index needs to be cached and buffered. At the same time, the timeliness of the cache and buffer areas for different business scenarios can be dynamically configured and exclusive. The above-mentioned cache area (redis cluster) and buffer area (rocketmq, blocking queue) are not necessary and can be implemented in a variety of ways. For example, it can be implemented by directly writing to the database db, adding data db queries before 3 days to be directly routed to data warehouse queries. As long as the function of the database control device is simple and stable enough and does not consume too many resources, it will not affect data isolation, data anti-duplicate, and data analysis methods and devices.

[0057] In the data writing layer, the data prepared by the database routing device is written into different databases according to the configuration of member tenants and ordinary tenants. The database data retention time of the data writing layer can be dynamically set according to the real-time dynamic configuration of the business scenario.

[0058] In the data aggregation layer, the data from the data writing layer is sent to the message middleware through collecting database log files. The message middleware then outputs according to member tenants and non-member tenants and writes to non-relational databases (such as Hbase, Elasticsearch, MongoDB) and relational databases (such as PolarDB), and then conducts data governance and data analysis on the data written to the databases.

[0059] The data governance module in the management module is responsible for data cleaning. For the business needs of payment products, currently, data retrieval is difficult, data security information is scattered, and data quality management is semi-automated, which may not provide data support for multi-tenant support. Therefore, the construction of data governance is very important. The data governance module can form the ability of global data retrieval, practice data quality specification standards, and ensure the security of data use.

[0060] The billing module is used for the billing of major member tenants and ordinary tenants and the billing of various system resources. The billing module is a characteristic function of the cloud platform. Currently, the calculation method for multi-tenant and internal company resource billing is relatively old. With the billing function, the billing module automatically calculates the daily cost of each application resource by counting the running duration and occupied resources of each application in the container cloud. The calculated cost situation is grouped according to tenants and application personnel, and a weekly cost report will be automatically generated every day and week and sent to each tenant and operation personnel. The billing component configures different rates according to different cloud tenants, so it supports billing in a multi-cloud environment.

[0061] The routing asynchronous data module is responsible for asynchronously writing database routing data into the index library to facilitate data writing without being affected. Taking data as an example, due to the large amount of data, too much data may affect the network card of the entire physical machine. Even more, in the peak period, due to improper buffer layer configuration, situations such as memory overflow may occur. The routing asynchronous data module configures the data reading quantity, frequency, and interval, which takes effect dynamically.

[0062] The routing configuration center is responsible for routing configuration and also provides routing layer with configuration reading and routing data support. The routing configuration center mainly sets multi-scenario dynamically configurable data such as unit partitions, data db index rule lists, multi-data source lists, data anti-duplication rule data, and multi-tenant data isolation rules.

[0063] The routing configuration center and data governance module achieve database routing using single-object-type metadata and multi-object-type metadata, synchronize dynamic configuration data sources, and perform real-time seamless database switching without causing additional resource waste. By collecting database log files, aggregating data into a data warehouse, performing real-time streaming calculations on the data, and using a data governance platform, it provides one-stop data collection, processing, management, and application.

[0064] In Figure 3 the system, anti-duplication policies for adding databases arbitrarily in the application and infinitely expanding the library and the ID fields of abstract tables are implemented. When summarizing the same table in multiple databases, it can avoid the situation where data is overwritten and lost, prevent duplicate payments, and provide guarantee for the financial security of tenants. Only the responsibility of manual configuration in the data routing configuration center needs to be borne.

[0065] In addition, the system's use of data isolation, data anti-duplication, data analysis methods and devices can reduce costs and be effective. Resources are separately allocated for large-traffic tenants to solve storage data isolation, and no additional transformation is required for application services, making it simpler and easier to access in implementation.

[0066] Although the above methods are illustrated and described as a series of actions for simplicity of explanation, it should be understood and appreciated that these methods are not limited by the order of the actions, because according to one or more embodiments, some actions may occur in a different order and / or concurrently with other actions that are illustrated and described herein or that are not illustrated and described herein but are understandable to those skilled in the art.

[0067] Those skilled in the art will further appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of the two. To clearly illustrate this interchangeability of hardware and software, the various illustrative components, blocks, modules, circuits, and steps are described above in terms of their functionality in a generalized form. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. Skilled artisans may implement the described functionality in different ways for each specific application, but such implementation decisions should not be construed as causing a departure from the scope of the present invention.

[0068] The various illustrative logical blocks, modules, and circuits described in connection with the embodiments disclosed herein can be implemented or performed with a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.

[0069] The steps of a method or algorithm described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. The software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read from, and write to, the storage medium. In the alternative, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. In the alternative, the processor and the storage medium may reside as discrete components in a user terminal.

[0070] In one or more exemplary embodiments, the described functionality may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software as a computer program product, the functions may be stored on or transmitted via a computer-readable medium as one or more instructions or code. The computer-readable medium includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. The storage media may be any available media that can be accessed by a computer. By way of example and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a web site, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray disc, where disks typically reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0071] The foregoing description of the disclosure has been provided to enable any person skilled in the art to make or use the disclosure. Various modifications to the disclosure will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other variations without departing from the spirit or scope of the disclosure. Thus, the disclosure is not intended to be limited to the examples and designs described herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for data isolation, duplicate prevention, and analysis in a payment SAAS product, characterized in that, the method includes: In the first stage, after the business application is started, the business request dynamically reads the database index through the application controller and enters the routing device of the database. After the processing of the routing device starts, the business request first enters the routing device. The routing device starts and is in the initial ready state, and automatically connects to the corresponding database according to the parameters passed in during startup. When the routing device successfully connects to the database, the ready state where the routing device is currently located is updated to the normal state by the routing control device, and the business request switches the data traffic to the routing device; In the second stage, the database index of the routing control device disconnects from the routing device and the database, and the database index of the routing control device is completely replaced by a new routing device. At the same time, the old routing device stops processing and disconnects from the database; In the third stage, the new routing device in the original business application starts to read the routing configuration of the sharded data, and performs processing of data duplicate prevention, data source switching, and database routing, and then performs data warehousing. During the data warehousing process, the database index in the new routing device enters the non-ready state from the ready state, and after the ready state is enabled, the business request enters the database through the new database routing device, and the new database routing device enters the ready state, and then enters the new service through the new database routing device; In the fourth stage, the routing control device will no longer process, and the traffic will be processed by the new database routing; In the final stage, all payment transaction data is uniformly sent to the message middleware by the data control device through collecting the database log file, and the message middleware then writes the data into the data aggregation warehouse according to the routing configuration of member tenants and non-member tenants.

2. The method for data isolation, duplicate prevention, and analysis in a payment SAAS product according to claim 1, characterized in that, the first stage further includes: First, the routing device processes data through the database index and the dynamic addressing algorithm, reads the sharded database list configuration, dynamically reads the configuration mapping library, and obtains the specified unit database according to the current partition and the unit group where it is located; The routing device performs the data duplicate prevention processing flow, converts all sharded mapping keys and unit database mapping tables into a single-layer mapping relationship, and looks up the converted single-layer mapping relationship in the redis cache area; If there is no single-layer mapping relationship in the redis cache area, the converted single-layer mapping relationship is queried from the index database. If no single-layer mapping relationship is found in both the redis cache area and the index database, the sharded mapping key and the single-layer mapping relationship are directly warehoused into the index database, otherwise duplicate data is intercepted; According to the database sharding algorithm, the data source name is calculated from the sharded data source, the SQL is parsed, and the primary key and the corresponding index mapping relationship data are passed in as conditions to compare with the specified unit database, and finally routed to the specified database. When it is checked that the current data comes from the default database in the parsed query conditions, the data enters the default database.

3. A data isolation, anti-duplication, and analysis device for a payment SAAS product, characterized in that, the device is used to implement the data isolation, anti-duplication, and analysis method for the payment SAAS product as described in claim 1 or 2. The device includes a data processing module, a support module, and a management module, where: The support module includes a container cloud management platform and a database monitoring center. The container cloud management platform is responsible for managing the release of system applications, and the applications are in containers; the database monitoring center is responsible for monitoring whether the database is available, so as to ensure that data writing and updating are not affected, and at the same time is responsible for synchronously writing the data in the data writing layer to the data aggregation layer in the form of collection; The management module includes a data governance module, a billing module, a routing configuration center, and a routing asynchronous data module. The data governance module is used for data cleaning, the billing module is used for billing members and ordinary tenants and billing various system resources, the routing asynchronous data module is responsible for asynchronously writing database routing data into the index library, and the routing configuration center is responsible for routing configuration, and at the same time provides routing layer for configuration reading and routing data support; The data processing module includes an application layer, a routing layer, a data writing layer, and a data aggregation layer. The application layer is the original data entry. Cooperating with the framework interface, it abstracts and outputs the original data through database routing and data anti-duplication devices, and isolates multi-tenant data; the routing layer includes a cache area, a buffer area, and a data area; the data writing layer is the data through the database routing device, and is written into different databases according to the configurations of member tenants and ordinary tenants. The data retention time of the databases in the data writing layer is dynamically set according to the real-time dynamic configuration of the business scenario; the data aggregation layer sends the data in the data writing layer to the message middleware by collecting database log files, and the message middleware then outputs according to member tenants and non-member tenants and writes into non-relational databases and relational databases, and then performs data governance and data analysis on the data written into the databases.

4. The data isolation, anti-duplication, and analysis device for the payment SAAS product according to claim 3, characterized in that, in the routing layer, the routing device dynamically configures the database index of the routing data through the routing configuration center for database address indexing and dynamic addressing, performs data anti-duplication through the data area, and then switches the data source and routes to the specified partition database; dynamically manually sets whether the current database address index needs to be cached in the cache area and the buffer area, and at the same time the timeliness of the cache area and the buffer area is dynamically configurable and can be exclusive for different business scenarios.

Citation Information

Patent Citations

  • Multi-tenant data isolation method for saas platform

    CN112069210A

  • Secure service isolation between instances of cloud products using a SaaS model

    US10817346B1