A data synchronization method and device, computer equipment and readable storage medium

By setting up a firewall and performing encryption/decryption operations within the synchronization container, combined with certificate authentication and vulnerability checks, the problem of poor security during data synchronization is solved, achieving security and integrity of data transmission.

CN115967531BActive Publication Date: 2025-11-11AGRICULTURAL BANK OF CHINA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211447491.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-18
Publication Date
2025-11-11
Estimated Expiration
2042-11-18

AI Technical Summary

Technical Problem

Data synchronization between existing systems is easily intercepted, resulting in poor data synchronization security.

Method used

By setting up a firewall in the synchronization container, access to downstream systems is restricted, and encryption and decryption operations are performed during data transmission, including decrypting table data of the upstream system and encrypting target table data of the downstream system, while also performing certificate authentication and vulnerability checks.

Benefits of technology

This ensures information security during the process from the upstream system to the synchronization container and from the synchronization container to the downstream system, eliminates the risk of information leakage caused by data interception during the synchronization process, and improves the security of data synchronization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115967531B_ABST
    Figure CN115967531B_ABST
Patent Text Reader

Abstract

This application provides a data synchronization method, apparatus, computer device, and readable storage medium, comprising: receiving table data sent by an upstream system, decrypting the table data, and saving the decrypted table data to a preset synchronization container; wherein the table data is an object of message storage in a database according to a preset structure, and the message is a data document with fixed fields and format; receiving a download request sent by a downstream system, obtaining target table data from the synchronization container according to the download request, encrypting the target table data, and sending the encrypted target table data to the downstream system. This application ensures information security in the process from the upstream system to the synchronization container, and from the synchronization container to the downstream system, eliminating the risk of information leakage due to data interception during the synchronization process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to a data synchronization method, apparatus, computer equipment, and readable storage medium. Background Technology

[0002] Currently, when a large number of upstream systems synchronize table data with one or more downstream systems, they usually provide an intermediate server. The upstream systems send the table data to the intermediate server, and the downstream systems retrieve it from the intermediate server periodically or irregularly.

[0003] While this method can achieve data synchronization between different systems, the inventors discovered that the current data synchronization process between different systems is easily intercepted, resulting in poor data synchronization security. Summary of the Invention

[0004] This application provides a data synchronization method, apparatus, computer device, and readable storage medium to solve the problem that data synchronization between different systems is easily intercepted, resulting in poor data synchronization security.

[0005] Firstly, this application provides a data synchronization method, including:

[0006] The system receives table data sent from the upstream system, decrypts the table data, and saves the decrypted table data to a preset synchronization container; wherein, the table data is an object in the database that stores messages according to a preset structure, and the message is a data document with fixed fields and format;

[0007] The system receives a download request from a downstream system, retrieves target table data from the synchronization container according to the download request, encrypts the target table data, and sends the encrypted target table data to the downstream system.

[0008] In the above scheme, before receiving the table data sent by the upstream system, the method further includes:

[0009] Create a daemon process, create a container through the daemon process, and create a data warehouse in the container to store table data;

[0010] Set the daemon process and the container with the data warehouse as the synchronization container;

[0011] The daemon process is connected to the upstream system and the downstream system.

[0012] In the above scheme, after connecting the daemon process with the upstream system and the downstream system, the method further includes:

[0013] A firewall is configured in the synchronization container; wherein the firewall is used to restrict downstream systems that can access the synchronization container and to filter the target table data.

[0014] In the above scheme, setting up a firewall in the synchronization container includes:

[0015] Connect the pre-configured orchestration system to the daemon process in the synchronization container; wherein, the orchestration system is the management terminal used to operate the synchronization container;

[0016] The orchestration system creates the firewall in the daemon process, creates filtering rules in the firewall, and writes the IP address of the downstream system into the firewall; wherein, the filtering rules are used to define the conditions under which the target table data is allowed to pass through the firewall and be sent to the downstream system;

[0017] The firewall is subject to rule locking, wherein the rule locking is used to control the firewall to reject configuration modification requests issued by the orchestration system and / or the synchronization container; the configuration modification requests are used to modify the filtering rules within the firewall.

[0018] In the above scheme, obtaining the target table data from the synchronization container according to the download request includes:

[0019] Extract the download field from the download request; wherein, the download field is the key of the table data that the downstream system needs to synchronize;

[0020] Scan the data warehouse of the synchronization container according to the download field;

[0021] If the data warehouse contains table data corresponding to the download field, then copy the table data corresponding to the download field to obtain the target table data, and download the target table data to a preset local server.

[0022] In the above scheme, before downloading the target table data to a preset local server, the method further includes:

[0023] The downstream system is certified; wherein, the certificate certification is used to verify whether the downstream system has the right to obtain the target table data;

[0024] If the downstream system is confirmed to have passed the certificate authentication, the target table data is downloaded to the preset local server;

[0025] If it is confirmed that the downstream system has failed the certificate authentication, then the target table data is deleted.

[0026] In the above scheme, before downloading the target table data to a preset local server, the method further includes:

[0027] Perform vulnerability checks on the target table data;

[0028] If the target table data is confirmed to pass the vulnerability check, the target table data is downloaded to a pre-configured local server.

[0029] If it is confirmed that the target table data fails the vulnerability check, the target table data is deleted and a vulnerability notification message is generated.

[0030] Secondly, this application provides a data synchronization device, comprising:

[0031] The upstream synchronization module is used to receive table data sent by the upstream system, decrypt the table data, and save the decrypted table data to a preset synchronization container; wherein, the table data is an object in the database that stores messages according to a preset structure, and the message is a data document with fixed fields and format;

[0032] The downstream synchronization module is used to receive download requests sent by downstream systems, obtain target table data from the synchronization container according to the download requests, encrypt the target table data, and send the encrypted target table data to the downstream system.

[0033] Thirdly, this application provides a computer device, including: a processor and a memory communicatively connected to the processor;

[0034] The memory stores computer-executed instructions;

[0035] The processor executes computer execution instructions stored in the memory to implement the data synchronization method described above.

[0036] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the above-described data synchronization method.

[0037] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the above-described data synchronization method.

[0038] This application provides a data synchronization method, apparatus, computer device, and readable storage medium. By receiving table data sent from an upstream system, decrypting the table data, and saving the decrypted table data to a preset synchronization container, and by receiving a download request from a downstream system, retrieving target table data from the synchronization container according to the download request, encrypting the target table data, and sending the encrypted target table data to the downstream system, this ensures information security throughout the process from the upstream system to the synchronization container and from the synchronization container to the downstream system, eliminating the risk of data interception and information leakage during the synchronization process. Attached Figure Description

[0039] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0040] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application;

[0041] Figure 2 A flowchart of Embodiment 1 of a data synchronization method provided in this application;

[0042] Figure 3 A flowchart illustrating Embodiment 2 of a data synchronization method provided in this application;

[0043] Figure 4 A schematic diagram of the program modules of Embodiment 3 of a data synchronization device provided in this application;

[0044] Figure 5 This is a schematic diagram of the hardware structure of the computer device in the computer device of the present invention.

[0045] Figure label:

[0046] 1. Data synchronization device 2. Server 3. Upstream system 4. Downstream system

[0047] 5. Computer equipment; 11. Container creation module; 12. Firewall module; 13. Upstream synchronization module

[0048] 14. Downstream synchronization module 51. Memory 52. ​​Processor

[0049] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0050] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0051] Please see Figure 1 The specific application scenario of this application is as follows:

[0052] Server 2, which runs a data synchronization method, is connected to upstream system 3 and downstream system 4;

[0053] Server 2 receives table data sent by upstream system 3, decrypts the table data, and saves the decrypted table data to a preset synchronization container 21; wherein, the table data is an object in the database that stores messages according to a preset structure, and the message is a data document with fixed fields and format;

[0054] Server 2 receives a download request from downstream system 4, retrieves target table data from the synchronization container 21 according to the download request, encrypts the target table data, and sends the encrypted target table data to downstream system 4.

[0055] In this embodiment, the upstream system 3 is an upstream model system, which is used to generate messages and send them to the downstream system 4;

[0056] Message: A data document with fixed fields and formats as required by regulatory agencies. Reporting is the process by which commercial banks send messages according to certain rules.

[0057] In this configuration, a NAS server is used as server 2. A NAS is a special type of dedicated data storage server, comprising storage devices (such as disk arrays, drives, and removable storage media) and embedded system software, providing cross-platform file sharing capabilities. A NAS typically occupies its own node on a LAN, eliminating the need for application servers and allowing users to store data on the network. In this configuration, the NAS centrally manages and processes all data on the network, offloading the load from application or enterprise servers and effectively reducing the cost of ownership. NAS supports multiple protocols (such as NFS, CIFS, FTP, HTTP, etc.) and various operating systems. A NAS is a special device that connects directly to the network medium to implement a data storage mechanism. Because these devices are assigned IP addresses, all client machines can access them through a server acting as a gateway; in some cases, clients can even access these devices directly without any intermediary media.

[0058] In one scenario, a commercial bank, acting as an upstream system 3, sends table data of messages to a bank, acting as a downstream system 4. The upstream system 3 generates at least one table data based on business statistics, encrypts the table data, and sends the encrypted table data to the synchronization container 21. The server 2 decrypts the table data and stores it in the synchronization container 21.

[0059] The target table data corresponding to the download request is obtained from the synchronization container 21, the target table data is encrypted, and it is sent to the downstream system 4. The downstream system 4 obtains the content of the target table data by decrypting it.

[0060] Typically, the upstream system 3 exports the database table data it produces and uploads it to the server. The reporting system then periodically reads the server data and loads it into its local database.

[0061] This application combines NAS and Docker container technologies to achieve cross-server synchronization of suspicious and large-amount early warning database table data. It integrates the high-speed storage of NAS with the lightweight security of containers, further improving the efficiency of data synchronization and reporting in downstream reporting systems.

[0062] The technical solution of this application and how the technical solution of this application solves the problems of the prior art will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0063] Example 1:

[0064] Please see Figure 2 This application provides a data synchronization method, which runs on a NAS server, including:

[0065] S101: Receive table data sent by the upstream system, decrypt the table data, and save the decrypted table data to a preset synchronization container; wherein, the table data is an object in the database that stores messages according to a preset structure, and the message is a data document with fixed fields and format.

[0066] In this example, the upstream system encrypts table data using TLS. TLS employs asymmetric key encryption to exchange session keys and symmetric key encryption to encrypt information. This ensures information security throughout the process from the upstream system to the synchronization container, eliminating the risk of data interception and leakage during synchronization.

[0067] S102: Receive a download request sent by a downstream system, obtain target table data from the synchronization container according to the download request, encrypt the target table data, and send the encrypted target table data to the downstream system.

[0068] In this example, the synchronization container encrypts the target table data using TLS encryption. TLS uses asymmetric key encryption to exchange session keys and symmetric key encryption to encrypt the information. This ensures information security throughout the synchronization process from the synchronization container to the downstream system, eliminating the risk of data interception and leakage during synchronization.

[0069] In a preferred embodiment, obtaining the target table data from the synchronization container according to the download request includes:

[0070] Extract the download field from the download request; wherein, the download field is the key of the table data that the downstream system needs to synchronize;

[0071] Scan the data warehouse of the synchronization container according to the download field;

[0072] If the data warehouse contains table data corresponding to the download field, then copy the table data corresponding to the download field to obtain the target table data, and download the target table data to a preset local server.

[0073] In this example, by extracting the download field and scanning the data warehouse of the synchronization container based on the download field, it is ensured that the data that the downstream system needs to synchronize exists in the data warehouse, and the table data that the downstream system needs to synchronize is sent to the local server.

[0074] Optionally, before receiving the download request sent by the downstream system, the method further includes:

[0075] Extract the identity information of the downstream system and verify the identity information;

[0076] If the identity information is confirmed to have passed the identity verification, then the download request sent by the downstream system is received.

[0077] If it is confirmed that the identity information has failed the identity verification, a rejection request message is sent to the downstream system.

[0078] In this example, the identity information is compared with a pre-defined identity whitelist. If the identity information belongs to the whitelist, the identity information is confirmed to have passed authentication. If the identity information does not belong to the whitelist, the identity information is confirmed to have failed authentication.

[0079] Preferably, before downloading the target table data to a preset local server, the method further includes:

[0080] The downstream system is certified; wherein, the certificate certification is used to verify whether the downstream system has the right to obtain the target table data;

[0081] If the downstream system is confirmed to have passed the certificate authentication, the target table data is downloaded to the preset local server;

[0082] If it is confirmed that the downstream system has failed the certificate authentication, then the target table data is deleted.

[0083] In this embodiment, CA certification is used as the certificate authentication method. CA certification, or electronic authentication service, refers to the activity of providing authenticity and reliability verification for all parties involved in electronic signatures. A Certificate Authority (CA) is an organization that issues digital certificates. It is the authoritative body responsible for issuing and managing digital certificates and, as a trusted third party in e-commerce transactions, assumes the responsibility for verifying the legitimacy of public keys in the public key system.

[0084] Specifically, the SSL protocol version information is sent to the downstream system according to the download request;

[0085] Receive the public key certificate (server.crt) sent by the downstream system according to the SSL protocol version information and send it to the client;

[0086] The digital signature of the public key certificate will be verified using a pre-set public key;

[0087] If the verification passes, the downstream system is confirmed to have passed certificate authentication. The SSL protocol version information refers to the SSL protocol, i.e., Secure Sockets Layer. It can be used to protect any application protocol running on top of TCP, such as HTTP, FTP, SMTP, or Telnet communications. Most commonly, SSL is used to protect HTTP communications. Public keys are typically used to encrypt session keys, verify digital signatures, or encrypt data that can be decrypted using the corresponding private key. A public key certificate, often simply called a certificate, is a digitally signed statement that binds the value of a public key to the identity of the individual, device, or service holding the corresponding private key.

[0088] Preferably, before downloading the target table data to a preset local server, the method further includes:

[0089] Perform vulnerability checks on the target table data;

[0090] If the target table data is confirmed to pass the vulnerability check, the target table data is downloaded to a pre-configured local server.

[0091] If it is confirmed that the target table data fails the vulnerability check, the target table data is deleted and a vulnerability notification message is generated.

[0092] In this example, a pre-configured CVE database is used to perform vulnerability checks on the target table data. CVE stands for "Common Vulnerabilities & Exposures." A CVE acts like a dictionary, providing a common name for widely recognized information security vulnerabilities or exposed weaknesses. Using a common name helps users share data across their various independent vulnerability databases and vulnerability assessment tools, even though these tools are difficult to integrate. This makes CVE a "keyword" for security information sharing. If a vulnerability report specifies a vulnerability with a CVE name, you can quickly find corresponding patch information in any other CVE-compatible database to resolve the security issue.

[0093] Alternatively, you can use Anchore Engine to perform vulnerability checks on the target table data. Anchore Engine is a Docker vulnerability scanning tool that can download images from a repository and then perform security scans and analyses on the images.

[0094] Example 2:

[0095] Please see Figure 3 This application provides a data synchronization method, which runs on a NAS server, including:

[0096] S201: Create a daemon process, create a container through the daemon process, and create a data warehouse in the container to store table data; set the daemon process and the container with the data warehouse as the synchronization container; connect the daemon process to the upstream system and the downstream system.

[0097] In this example, a container is a series of system processes isolated from the rest of the system, running from another image, and supported by all the files provided by that image. The container image contains all the application's dependencies, thus ensuring portability and consistency throughout the entire process from development to testing to production. The synchronized container is built on Docker containerization technology; the daemon is the Docker daemon, the container is a Container, and the data repository is a Docker image repository. Docker is an open-source application container engine that allows developers to package their applications and dependencies into a portable container and then deploy it to any popular Linux or Windows machine, achieving virtualization. Docker containers use a completely sandboxed mechanism, with no interfaces between them.

[0098] Docker is a containerization technology based on a client / server architecture, used to support the creation of LXC containers. Containers can be used as lightweight, modular virtual machines. The Docker daemon is responsible for building, running, and distributing Docker containers. The Docker daemon listens for requests from upstream and downstream systems and manages Docker objects such as images, containers, and networks. The Docker Registry (a centralized image storage and distribution service) stores Docker image repositories. An image is a template containing Docker container specifications; generally, images are built upon other base images to deploy user-defined images. A container is a runnable instance of an image. Essentially, a container is a process, but it has its own independent namespace. Therefore, a container has its own root file system, network configuration, and process space. The image inside the container runs in an isolated environment, appearing as if it were operating independently of the host operating system. This characteristic makes containerized applications more secure than running directly on the host.

[0099] This example combines a NAS server with Docker container technology. Docker is deployed on the NAS server, and the upstream model system encapsulates exported table data into containers and stores it on the NAS. The downstream system retrieves the database table data through these containers. Because containers do not require hardware virtualization or the overhead of running a full operating system, Docker has higher utilization of system resources. Whether it's application execution speed, memory consumption, or file storage speed, this technology leverages Docker's advantages to make table data scanning and loading operations more efficient and faster.

[0100] LXC: Linux Container is a solution that implements container technology using a set of simple templates.

[0101] S202: Configure a firewall in the synchronization container; wherein the firewall is used to limit downstream systems that can access the synchronization container and to filter the target table data.

[0102] In this example, a packet-filtering firewall is used as the firewall configured in the synchronization container. This packet-filtering firewall, also known as a packet filtering router or network-level firewall, operates at the network layer. When a data packet originates from the source and needs to pass through the firewall, it typically determines whether to allow the packet to pass by checking information such as the source address, destination address, encapsulated protocol (TCP, UDP, etc.), port, ICMP packet type, and input / output interface of each individual packet. The packet-filtering firewall also checks the routing table in the data packet, specific IP options, and verifies special IP segmentation parameters to prevent electronic spoofing attacks.

[0103] Therefore, by defining the addresses of downstream systems that can access the synchronization container in the firewall, access to downstream systems that can access the synchronization container is restricted, thus preventing the synchronization container from restricting access to previous devices and improving the data security of the synchronization container.

[0104] At the same time, the packet filtering firewall can also decide whether to allow a certain data packet to pass through the firewall, thereby preventing confidential and sensitive data in the synchronization container from being directly sent to the downstream system, further improving data security.

[0105] In a preferred embodiment, setting up a firewall in the synchronization container includes:

[0106] Connect the pre-configured orchestration system to the daemon process in the synchronization container; wherein, the orchestration system is the management terminal used to operate the synchronization container;

[0107] The orchestration system creates the firewall in the daemon process, creates filtering rules in the firewall, and writes the IP address of the downstream system into the firewall; wherein, the filtering rules are used to define the conditions under which the target table data is allowed to pass through the firewall and be sent to the downstream system;

[0108] The firewall is subject to rule locking, wherein the rule locking is used to control the firewall to reject configuration modification requests issued by the orchestration system and / or the synchronization container; the configuration modification requests are used to modify the filtering rules within the firewall.

[0109] In this example, the external interface of the synchronization container is first closed to prevent the synchronization container from connecting directly to external devices;

[0110] An orchestration system is used to manage the synchronization containers. This system creates firewalls within the containers and defines filtering rules. These rules specify the source address of the synchronization container, the encapsulation protocol (TCP, UDP, etc.) of the target table data, the packet type (ICMP packet type), the input / output interface, and fields within the packets. The filtering rules determine whether to allow a packet to pass through the firewall. The IP addresses of downstream systems are written into the firewall as target addresses, enabling them to access the firewall. The "iptables-restore" command is used to apply the filtering rules and the downstream system's IP address to the firewall.

[0111] Run an "iptables=false" command to lock the firewall rules, preventing configuration modification requests from the orchestration system and / or the synchronization container.

[0112] S203: Receive table data sent by the upstream system, decrypt the table data, and save the decrypted table data to a preset synchronization container; wherein, the table data is an object in the database that stores messages according to a preset structure, and the message is a data document with fixed fields and format.

[0113] This step is the same as S101 in Example 1, so it will not be described again here.

[0114] S204: Receive a download request sent by a downstream system, obtain target table data from the synchronization container according to the download request, encrypt the target table data, and send the encrypted target table data to the downstream system.

[0115] This step is the same as S102 in Example 1, so it will not be described again here.

[0116] Example 3:

[0117] Please see Figure 4 This application provides a data synchronization device 1, installed in a NAS server, comprising:

[0118] The upstream synchronization module 13 is used to receive table data sent by the upstream system and save the table data to a preset synchronization container; wherein, the table data is an object in the database that stores messages according to a preset structure, and the message is a data document with fixed fields and format;

[0119] The downstream synchronization module 14 is used to receive download requests sent by the downstream system, obtain target table data from the synchronization container according to the download request, and send the target table data to the downstream system.

[0120] Optionally, the data synchronization device 1 further includes:

[0121] The container creation module 11 is used to create a daemon process, create a container through the daemon process, create a data warehouse in the container for storing table data, set the daemon process and the container with the data warehouse as the synchronization container, and connect the daemon process to the upstream system and the downstream system.

[0122] Firewall module 12 is used to set up a firewall in the synchronization container; wherein the firewall is used to limit downstream systems that can access the synchronization container and to filter the target table data.

[0123] Example 4:

[0124] To achieve the above objectives, this application also provides a computer device 5, including: a processor 52 and a memory 51 communicatively connected to the processor 52; the memory stores computer execution instructions;

[0125] The processor executes the computer execution instructions stored in the memory 51 to implement the above-described data synchronization method. The components of the data synchronization device can be distributed across different computer devices. The computer device 5 can be a smartphone, tablet, laptop, desktop computer, rack server, blade server, tower server, or cabinet server (including standalone servers or server clusters composed of multiple application servers), etc. The computer device in this embodiment includes, but is not limited to, a memory 51 and a processor 52 that can communicate with each other via a system bus. Figure 5 As shown. It should be noted that, Figure 5Only computer devices with components are shown; however, it should be understood that it is not required to implement all of the shown components, and more or fewer components may be implemented instead. In this embodiment, memory 51 (i.e., readable storage medium) includes flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, memory 51 may be an internal storage unit of the computer device, such as the hard disk or memory of the computer device. In other embodiments, memory 51 may also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device. Of course, memory 51 may also include both internal storage units and external storage devices of the computer device. In this embodiment, memory 51 is typically used to store the operating system and various application software installed on the computer device, such as the program code of the data synchronization device in Embodiment 3. In addition, the memory 51 can also be used to temporarily store various types of data that have been output or will be output. In some embodiments, the processor 52 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 52 is typically used to control the overall operation of the computer device. In this embodiment, the processor 52 is used to run program code stored in the memory 51 or process data, for example, to run a data synchronization device to implement the data synchronization method of the above embodiments.

[0126] The integrated modules implemented as software functional modules described above can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of this application. It should be understood that the processor may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor. The memory may include high-speed RAM, and may also include non-volatile memory (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk, or optical disk, etc.

[0127] To achieve the above objectives, this application also provides a computer-readable storage medium, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, disk, optical disk, server, App application store, etc., which stores computer-executable instructions, and the program implements the corresponding function when executed by processor 52. The computer-readable storage medium of this embodiment is used to store computer-executable instructions for implementing the data synchronization method, and when executed by processor 52, it implements the data synchronization method of the above embodiment.

[0128] The aforementioned storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0129] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium can be an integral part of the processor. Both the processor and the storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components in an electronic device or host device.

[0130] This application provides a computer program product, including a computer program that, when executed by a processor, implements the above-described data synchronization method.

[0131] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0132] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0133] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A data synchronization method, characterized in that, include: The system receives table data sent from the upstream system, decrypts the table data, and saves the decrypted table data to a preset synchronization container; wherein the table data is an object in the database that stores messages according to a preset structure, and the message is a data document with fixed fields and format; wherein the table data is transmitted using TLS encryption. Receive a download request sent by a downstream system, obtain target table data from the synchronization container according to the download request, encrypt the target table data, and send the encrypted target table data to the downstream system; Before receiving table data sent by the upstream system, the method further includes: Create a daemon process, create a container through the daemon process, and create a data warehouse in the container to store table data; Set the daemon process and the container with the data warehouse as the synchronization container; Connect the daemon process to the upstream system and the downstream system; After connecting the daemon process to the upstream system and the downstream system, the method further includes: A firewall is configured in the synchronization container; wherein the firewall is used to limit the downstream systems that can access the synchronization container and to filter the target table data; Setting up a firewall in the synchronization container includes: Connect the pre-configured orchestration system to the daemon process in the synchronization container; wherein, the orchestration system is the management terminal used to operate the synchronization container; The orchestration system creates the firewall in the daemon process, creates filtering rules in the firewall, and writes the IP address of the downstream system into the firewall; wherein, the filtering rules are used to define the conditions under which the target table data is allowed to pass through the firewall and be sent to the downstream system; The firewall is subject to rule locking, wherein the rule locking is used to control the firewall to reject configuration modification requests issued by the orchestration system and / or the synchronization container; the configuration modification requests are used to modify the filtering rules within the firewall.

2. The data synchronization method according to claim 1, characterized in that, The step of obtaining target table data from the synchronization container according to the download request includes: Extract the download field from the download request; wherein, the download field is the key of the table data that the downstream system needs to synchronize; Scan the data warehouse of the synchronization container according to the download field; If the data warehouse contains table data corresponding to the download field, then copy the table data corresponding to the download field to obtain the target table data, and download the target table data to a preset local server.

3. The data synchronization method according to claim 2, characterized in that, Before downloading the target table data to a pre-configured local server, the method further includes: The downstream system is certified; wherein, the certificate certification is used to verify whether the downstream system has the right to obtain the target table data; If the downstream system is confirmed to have passed the certificate authentication, the target table data is downloaded to the preset local server; If it is confirmed that the downstream system has failed the certificate authentication, then the target table data is deleted.

4. The data synchronization method according to claim 2, characterized in that, Before downloading the target table data to a pre-configured local server, the method further includes: Perform vulnerability checks on the target table data; If the target table data is confirmed to pass the vulnerability check, the target table data is downloaded to a pre-configured local server. If it is confirmed that the target table data fails the vulnerability check, the target table data is deleted and a vulnerability notification message is generated.

5. A data synchronization device, characterized in that, include: The upstream synchronization module is used to receive table data sent by the upstream system, decrypt the table data, and save the decrypted table data to a preset synchronization container; wherein, the table data is an object in the database that stores messages according to a preset structure, and the message is a data document with fixed fields and format; The downstream synchronization module is used to receive download requests sent by the downstream system, obtain target table data from the synchronization container according to the download request, encrypt the target table data, and send the encrypted target table data to the downstream system. The container creation module is used to create a daemon process, create a container through the daemon process, and create a data warehouse in the container to store table data. Set the daemon process and the container with the data warehouse as the synchronization container; Connect the daemon process to the upstream system and the downstream system; A firewall module is used to set up a firewall in the synchronization container; wherein the firewall is used to limit the downstream systems that can access the synchronization container and to filter the target table data; The firewall module is specifically used to connect the pre-configured orchestration system with the daemon process in the synchronization container; wherein, the orchestration system is a management terminal used to operate the synchronization container; The orchestration system creates the firewall in the daemon process, creates filtering rules in the firewall, and writes the IP address of the downstream system into the firewall; wherein, the filtering rules are used to define the conditions under which the target table data is allowed to pass through the firewall and be sent to the downstream system; The firewall is subject to rule locking, wherein the rule locking is used to control the firewall to reject configuration modification requests issued by the orchestration system and / or the synchronization container; the configuration modification requests are used to modify the filtering rules within the firewall.

6. A computer device, characterized in that, include: A processor and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the data synchronization method as described in any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the data synchronization method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • A gateway accessory equipment upgrading method and device

    CN109743372A

  • Distributed deployment system, object management method and device, medium and electronic device

    CN110196679A

  • Modeling data synchronization method and device, computer equipment and readable storage medium

    CN111767345A

  • Resource acquisition, distribution and downloading methods and devices, equipment and storage medium

    CN112491972A