Object storage-based data isolation method, device and equipment and storage medium

CN117155632BActive Publication Date: 2026-09-29YIQIQIFUNETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311100531.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-29
Publication Date
2026-09-29
Estimated Expiration
2043-08-29

AI Technical Summary

Technical Problem

[0003]现有技术中,通常通过硬编码的方式实现多租户的数据隔离存储,通过现有技术的方案需要将租户ID(Identity document,身份标识)作为方法的参数进行传参,然后在需要的时候根据租户ID构建Bucket存储容器实例,通过现有技术中硬编码的方法会影响处理效率

Benefits of technology

[0034]本申请中,首先获取所有本地存储的租户标识以及租户域名,建立所述租户标识与所述租户域名之间的对应关系,并将所述租户标识存入预设存储容器,然后判断是否接收到租户请求,若是,则对接收到的租户请求进行预处理,并确定预处理后请求中包含的请求域名,确定与所述请求域名相对应的目标租户域名,以基于所述对应关系从所述预设存储容器中确定与所述目标租户域名对应的目标租户标识,最后确定所述目标租户标识对应的目标存储容器配置信息,并基于所述目标存储容器配置信息构建与所述目标租户标识对应的目标存储容器,以基于所述目标存储容器对通过所述目标租户标识上传的数据进行单独存储。由此可见,通过本申请所述基于对象存储的数据隔离方法,可以建立获取到的租户标识以及租户域名之间的对应关系,并在接收到租户请求之后,基于对应关系确定预租户请求中请求域名对应的目标租户标识,然后确定与目标租户标识对应的目标存储容器配置信息,以基于目标存储容器配置信息创建目标存储容器,通过目标存储容器对通过目标租户标识上传的数据进行单独存储。这样一来,可以通过租户域名确定租户标识,并通过租户标识确定存储容器配置信息,以基于确定的存储容器配置信息创建存储容器来对通过所述租户标识上传的数据进行单独存储,避免了通过硬编码的方法创建存储容器进行数据隔离,有效提高了数据隔离的效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117155632B_ABST
    Figure CN117155632B_ABST
Patent Text Reader

Abstract

The application discloses an object storage-based data isolation method and device, equipment and a storage medium, and relates to the technical field of computers, which comprises the following steps: acquiring all locally stored tenant identifiers and tenant domain names, establishing a corresponding relationship between the tenant identifiers and the tenant domain names, and storing the tenant identifiers in a preset storage container; preprocessing a received tenant request and determining a request domain name; determining a target tenant domain name corresponding to the request domain name, determining a target tenant identifier corresponding to the target tenant domain name based on the corresponding relationship; determining target storage container configuration information corresponding to the target tenant identifier, and constructing a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to separately store data uploaded through the target tenant identifier based on the target storage container. In this way, the storage container can be determined through tenant information, the isolation of tenant data can be realized based on the determined storage container, and hard coding is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a data isolation method, apparatus, device, and storage medium based on object storage. Background Technology

[0002] Object storage is a general term used to describe methods for solving and processing discrete units called objects. Similar to files, objects contain data, but unlike files, objects do not have a hierarchical structure within a single layer. Each object resides at the same level in a flat address space called a storage pool; one object does not belong to a lower level of another. Both files and objects have metadata associated with the data they contain, but objects are characterized by extended metadata. Each object is assigned a unique identifier, allowing a server or end user to retrieve it. OSS (Object Storage Service) is a network-based data access service that allows various data files, including text, images, audio, and video, to be stored and accessed at any time over a network. After uploading a file to a Bucket storage container, the file (object) can be downloaded locally or shared with third parties for download or preview.

[0003] In existing technologies, multi-tenant data isolation storage is usually achieved through hard coding. This method requires passing the tenant ID (Identity document) as a parameter to the method and then constructing a Bucket storage container instance based on the tenant ID when needed. Hard coding in existing technologies can affect processing efficiency. Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide a data isolation method, apparatus, device, and storage medium based on object storage, which can determine the storage container through tenant information, and achieve tenant data isolation based on the determined storage container, avoiding hard coding. The specific solution is as follows:

[0005] In a first aspect, this application discloses a data isolation method based on object storage, including:

[0006] Obtain all tenant identifiers and tenant domain names in local storage, establish the correspondence between the tenant identifiers and the tenant domain names, and store the tenant identifiers in a preset storage container;

[0007] Determine whether a tenant request has been received. If so, preprocess the received tenant request and determine the request domain name contained in the preprocessed request.

[0008] Determine the target tenant domain name corresponding to the requested domain name, and determine the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence;

[0009] Determine the target storage container configuration information corresponding to the target tenant identifier, and construct a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to store the data uploaded through the target tenant identifier separately based on the target storage container.

[0010] Optionally, the step of obtaining all local storage tenant identifiers and tenant domain names, establishing a correspondence between the tenant identifiers and the tenant domain names, and storing the tenant identifiers in a preset storage container includes:

[0011] Retrieve all tenant identifiers and tenant domain names from the local tenant configuration table, and determine the tenant domain name as the key and the tenant identifier as the value to establish the correspondence between the tenant identifier and the tenant domain name;

[0012] The tenant identifier is stored using mapping debugging context technology, and is stored in a preset storage container.

[0013] Optionally, the step of determining whether a tenant request has been received, and if so, preprocessing the received tenant request and determining the request domain name contained in the preprocessed request, includes:

[0014] Determine whether a tenant request has been received. If a tenant request has been received, perform data cleaning on the request data in the tenant request to obtain a preprocessed request.

[0015] Determine the request header of the preprocessed request, and determine the request domain name of the request based on the request header.

[0016] Optionally, determining the target tenant domain name corresponding to the requested domain name, and determining the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence, includes:

[0017] The target tenant domain name corresponding to the requested domain name is determined from the local tenant configuration table, and the tenant identifier corresponding to the target tenant domain name is determined from the preset storage container based on the correspondence.

[0018] The tenant identifier corresponding to the target tenant domain name is determined as the target tenant identifier.

[0019] Optionally, before determining the target storage container configuration information corresponding to the target tenant identifier, and constructing a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to separately store the data uploaded through the target tenant identifier based on the target storage container, the method further includes:

[0020] Retrieve all storage container configuration information corresponding to the tenant identifier from the local tenant configuration table, and establish a mapping relationship between the storage container configuration information and the tenant identifier, so as to save the storage container configuration information to a preset storage container mapping table based on the mapping relationship.

[0021] Optionally, determining the target storage container configuration information corresponding to the target tenant identifier, and constructing a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to separately store the data uploaded through the target tenant identifier based on the target storage container, includes:

[0022] Determine the target storage container configuration information corresponding to the target tenant identifier from the preset storage container mapping table, and construct the target storage container based on the external access domain name, access key identifier, access key and container name in the target storage container configuration information;

[0023] Determine whether data to be stored has been received via the target tenant identifier. If so, store the data to be stored via the target storage container.

[0024] Optionally, the target storage container is a container built on an object storage service.

[0025] Secondly, this application discloses a data isolation device based on object storage, comprising:

[0026] The relationship building module is used to obtain the tenant identifiers and tenant domain names of all local storage, establish the correspondence between the tenant identifiers and the tenant domain names, and store the tenant identifiers in a preset storage container;

[0027] The domain name determination module is used to determine whether a tenant request has been received. If so, the received tenant request is preprocessed and the request domain name contained in the preprocessed request is determined.

[0028] An identity determination module is used to determine the target tenant domain name corresponding to the requested domain name, so as to determine the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence;

[0029] The container building module is used to determine the target storage container configuration information corresponding to the target tenant identifier, and build a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to store the data uploaded through the target tenant identifier separately based on the target storage container.

[0030] Thirdly, this application discloses an electronic device, including:

[0031] Memory, used to store computer programs;

[0032] A processor for executing the computer program to implement the aforementioned object storage-based data isolation method.

[0033] Fourthly, this application discloses a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the aforementioned object-based data isolation method.

[0034] In this application, firstly, all local storage tenant identifiers and tenant domain names are obtained, a correspondence between the tenant identifiers and the tenant domain names is established, and the tenant identifiers are stored in a preset storage container. Then, it is determined whether a tenant request has been received. If so, the received tenant request is preprocessed, and the request domain name contained in the preprocessed request is determined. The target tenant domain name corresponding to the request domain name is determined, and the target tenant identifier corresponding to the target tenant domain name is determined from the preset storage container based on the correspondence. Finally, the target storage container configuration information corresponding to the target tenant identifier is determined, and the target storage container corresponding to the target tenant identifier is constructed based on the target storage container configuration information, so as to separately store the data uploaded through the target tenant identifier. Therefore, the object storage-based data isolation method described in this application can establish a correspondence between the obtained tenant identifiers and tenant domain names, and after receiving a tenant request, determine the target tenant identifier corresponding to the request domain name in the pre-tenant request based on the correspondence, then determine the target storage container configuration information corresponding to the target tenant identifier, create the target storage container based on the target storage container configuration information, and separately store the data uploaded through the target tenant identifier through the target storage container. In this way, the tenant identifier can be determined by the tenant domain name, and the storage container configuration information can be determined by the tenant identifier. The storage container can be created based on the determined storage container configuration information to store the data uploaded by the tenant identifier separately, avoiding the need to create storage containers for data isolation through hard coding, and effectively improving the efficiency of data isolation. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0036] Figure 1 A flowchart of a data isolation method based on object storage is provided in this application;

[0037] Figure 2 This application provides a code diagram illustrating transparent transmission of tenant identifiers based on MDC.

[0038] Figure 3 A schematic diagram of a data isolation device based on object storage is provided in this application;

[0039] Figure 4 This application provides a structural diagram of an electronic device. Detailed Implementation

[0040] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0041] In existing technologies, multi-tenant data isolation storage is usually achieved through hard coding. This method requires passing the tenant ID as a parameter to the method and then constructing a Bucket storage container instance based on the tenant ID when needed. Hard coding in existing technologies can affect processing efficiency.

[0042] To address the aforementioned technical problems, the present invention aims to provide a data isolation method, apparatus, device, and storage medium based on object storage, which can determine the storage container through tenant information, thereby achieving isolation of tenant data based on the determined storage container and avoiding hard coding.

[0043] See Figure 1 As shown, this embodiment of the invention discloses a data isolation method based on object storage, including:

[0044] Step S11: Obtain the tenant identifiers and tenant domain names of all local storage, establish the correspondence between the tenant identifiers and the tenant domain names, and store the tenant identifiers in a preset storage container.

[0045] In this embodiment, obtaining all locally stored tenant identifiers and tenant domain names, establishing a correspondence between the tenant identifiers and the tenant domain names, and storing the tenant identifiers in a preset storage container includes: obtaining all tenant identifiers and tenant domain names from the local tenant configuration table, determining the tenant domain name as the key, and determining the tenant identifier as the value to establish a correspondence between the tenant identifiers and the tenant domain names; and storing the tenant identifiers based on mapping debugging context technology to store the tenant identifiers in the preset storage container. That is, in a SaaS (Software as a Service) system, a system deployment will be provided to multiple tenants. For the security and privacy of tenant usage, different tenants want to upload files to different OSS Buckets, thereby achieving file and data isolation within the Bucket and improving system security and flexibility. Furthermore, due to the need for tenant customization and personalization, tenants can bind their own domain names in the SaaS system to achieve personalization and customization. In the SaaS system, different domain names can be bound to different tenants, and the current tenant can be identified at runtime by obtaining the current domain name information. Therefore, if you want to create different Bucket storage containers for different tenants, you need to retrieve all tenant information from the tenant configuration table in the local database after the SaaS system starts. This includes retrieving all tenant IDs and tenant domains from the local tenant configuration table. After successfully retrieving all tenant IDs and tenant domains, you need to establish a mapping between each tenant ID and its corresponding tenant domain. This allows you to determine the tenant ID based on the established mapping after retrieving any tenant domain. When establishing the mapping, the tenant domain can be used as the key, and the tenant ID as the value. The established mapping can be saved using a Map, and the Map containing the mapping can be named `tenantMap`. Furthermore, to achieve transparent transmission of tenant IDs and avoid extra code development during method calls, you can use MDC (Mapped Diagnostic Context) technology to store the determined tenant IDs in an MDC container. In this way, on the one hand, by establishing a correspondence between tenant IDs and tenant domain names, the tenant ID corresponding to the tenant domain name can be determined directly based on the correspondence after the tenant domain name is determined, which effectively improves processing efficiency; on the other hand, transparent transmission of tenant IDs can be achieved based on MDC technology, avoiding the need to pass tenant IDs during method calls and causing additional code development.

[0046] Step S12: Determine whether a tenant request has been received. If so, preprocess the received tenant request and determine the request domain name contained in the preprocessed request.

[0047] In this embodiment, determining whether a tenant request has been received involves preprocessing the received tenant request and determining the request domain name contained in the preprocessed request. This includes: determining whether a tenant request has been received; if so, cleaning the request data in the tenant request to obtain the preprocessed request; and determining the request header of the preprocessed request to determine the request domain name based on the request header. That is, if different Bucket storage containers are to be created for different tenants, the current tenant ID needs to be determined based on the received tenant request. Therefore, it is necessary to determine whether a tenant request has been received. If a tenant request has been received, a Spring Filter needs to be created to clean the received tenant request data to achieve preprocessing. Specifically, OncePerRequestFilter can be used to filter the request to obtain the preprocessed request. Furthermore, it is necessary to determine the request domain name contained in the preprocessed request. The doFilterInternal abstract method can be used to determine the HTTP (Hypertext Transfer Protocol) request header of the preprocessed request, and the request domain name of the received tenant request can be obtained from the determined request header.

[0048] Step S13: Determine the target tenant domain name corresponding to the requested domain name, so as to determine the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence.

[0049] In this embodiment, determining the target tenant domain name corresponding to the requested domain name, and determining the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence, includes: determining the target tenant domain name corresponding to the requested domain name from the local tenant configuration table, and determining the tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence; and determining the tenant identifier corresponding to the target tenant domain name as the target tenant identifier. That is, after receiving a tenant request and determining the requested domain name contained in the tenant request, it is necessary to determine the tenant domain name corresponding to the requested domain name from the local tenant configuration table, and determine the determined tenant domain name as the target tenant domain name. Further, after obtaining the target tenant domain name, it is necessary to determine the target tenant identifier, i.e., the target tenant ID, corresponding to the target tenant domain name from the preset storage container, i.e., the MDC storage container, based on the correspondence stored in the tenantMap.

[0050] Step S14: Determine the target storage container configuration information corresponding to the target tenant identifier, and construct a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to store the data uploaded through the target tenant identifier separately based on the target storage container.

[0051] In this embodiment, before determining the target storage container configuration information corresponding to the target tenant identifier and constructing a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to separately store the data uploaded through the target tenant identifier based on the target storage container, the method further includes: obtaining all storage container configuration information corresponding to the tenant identifier from the local tenant configuration table, and establishing a mapping relationship between the storage container configuration information and the tenant identifier, so as to save the storage container configuration information to a preset storage container mapping table based on the mapping relationship. That is, when creating a storage container for a target user identifier, the target storage container configuration information corresponding to the target tenant identifier is required. Therefore, before creating a storage container for a target tenant identifier, it is necessary to first obtain the storage container configuration information corresponding to the locally stored tenant identifier. Specifically, configuration information such as EndPoint, AccessKeyId, AccessKeySecret, and BucketName corresponding to the tenant identifier, i.e., the tenant ID, can be obtained from the local tenant configuration table. Among them, AccessKey, abbreviated as AK, refers to AccessKeyId and AccessKeySecret used in access authentication. OSS verifies the sender's identity for a request using symmetric encryption with AccessKeyId and AccessKeySecret. AccessKeyId identifies the tenant and serves as the access key identifier; AccessKeySecret is the key used by the tenant to encrypt the signature string and by OSS to verify it—this is the access key and must be kept secret; Endpoint represents the domain name for OSS's external services; and BucketName is the name of the Bucket storage container. After obtaining the storage container configuration information corresponding to all tenant IDs, a mapping relationship needs to be established between the storage container configuration information and the tenant IDs. Based on this mapping, the storage container configuration information is saved to a pre-defined storage container mapping table.

[0052] It should be noted that determining the target storage container configuration information corresponding to the target tenant identifier, and constructing a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to separately store the data uploaded through the target tenant identifier based on the target storage container, includes: determining the target storage container configuration information corresponding to the target tenant identifier from the preset storage container mapping table, constructing the target storage container based on the external access domain name, access key identifier, access key, and container name in the target storage container configuration information; determining whether data to be stored has been received uploaded through the target tenant identifier, and if so, storing the data to be stored through the target storage container. That is, after determining the target tenant identifier, it is necessary to determine the target storage container configuration information corresponding to the target tenant identifier from the preset storage container mapping table, that is, to determine the AccessKeyId, AccessKeySecret, Endpoint, and BucketName corresponding to the target tenant ID, and create a target storage container based on the determined target storage container configuration information, that is, a target Bucket storage container for storing data for the target tenant ID, so as to store the data and files uploaded through the target tenant ID based on the target Bucket storage container. This allows for data isolation between tenants without hard-coding.

[0053] Therefore, in this embodiment, the first step is to obtain all local storage tenant identifiers and tenant domain names, establish a correspondence between the tenant identifiers and the tenant domain names, and store the tenant identifiers in a preset storage container. Then, it is determined whether a tenant request has been received. If so, the received tenant request is preprocessed, and the request domain name contained in the preprocessed request is determined. The target tenant domain name corresponding to the request domain name is then determined. Based on the correspondence, the target tenant identifier corresponding to the target tenant domain name is determined from the preset storage container. Finally, the target storage container configuration information corresponding to the target tenant identifier is determined, and a target storage container corresponding to the target tenant identifier is constructed based on the target storage container configuration information. Data uploaded via the target tenant identifier is then stored separately using the target storage container. Thus, the object storage-based data isolation method described in this application can establish a correspondence between the obtained tenant identifiers and tenant domain names. After receiving a tenant request, the target tenant identifier corresponding to the request domain name in the pre-tenant request is determined based on the correspondence. Then, the target storage container configuration information corresponding to the target tenant identifier is determined. A target storage container is created based on the target storage container configuration information, and data uploaded via the target tenant identifier is stored separately using the target storage container. In this way, on the one hand, by establishing a correspondence between tenant IDs and tenant domain names, the tenant ID corresponding to the tenant domain name can be determined directly based on the correspondence after the tenant domain name is determined, which effectively improves processing efficiency; on the other hand, transparent transmission of tenant IDs can be achieved based on MDC technology, avoiding the need to pass tenant IDs during method calls and causing additional code development; and on the other hand, it avoids the need to create storage containers for data isolation through hard-coding methods.

[0054] See Figure 2 As shown, this embodiment of the invention discloses a data isolation method based on object storage, including:

[0055] To achieve transparent transmission of tenant IDs and avoid the need for additional code development by passing the tenant ID during method calls, MDC technology can be used. An MDC container can store the tenant ID (tenantId) that corresponds to the request domain name in the received request. Specifically, for example... Figure 2As shown, `MDC.put("tenantId", tenantId)` puts the tenantId into an MDC container, and then `filterChain.doFilter(request, response)` executes other requests in the filter chain. It's important to note that since receiving tenant requests may not be a one-time event, when responding to the currently received request, `filterChain.doFilter(request, response)` must first execute other requests in the filter chain. Further explanation is needed regarding the response to other requests in the filter chain, which is the operational flow of the object storage-based data isolation method described in this application: creating corresponding Bucket storage containers for other requests in the filter chain. Finally, after all requests in the filter chain have been responded to, `MDC.clear()` clears all MDC data to receive and process the next batch of tenant requests. In this way, transparent transmission of the tenant ID can be achieved through MDC technology, avoiding the need to pass the tenant ID during method calls and causing additional code development.

[0056] See Figure 3 As shown, an embodiment of the present invention discloses a data isolation device based on object storage, comprising:

[0057] The relationship building module 11 is used to obtain the tenant identifiers and tenant domain names of all local storage, establish the correspondence between the tenant identifiers and the tenant domain names, and store the tenant identifiers in a preset storage container;

[0058] The domain name determination module 12 is used to determine whether a tenant request has been received. If so, the received tenant request is preprocessed and the request domain name contained in the preprocessed request is determined.

[0059] The identity determination module 13 is used to determine the target tenant domain name corresponding to the requested domain name, so as to determine the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence;

[0060] The container building module 14 is used to determine the target storage container configuration information corresponding to the target tenant identifier, and build a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to store the data uploaded through the target tenant identifier separately based on the target storage container.

[0061] Therefore, in this embodiment, the first step is to obtain all local storage tenant identifiers and tenant domain names, establish a correspondence between the tenant identifiers and the tenant domain names, and store the tenant identifiers in a preset storage container. Then, it is determined whether a tenant request has been received. If so, the received tenant request is preprocessed, and the request domain name contained in the preprocessed request is determined. The target tenant domain name corresponding to the request domain name is then determined. Based on the correspondence, the target tenant identifier corresponding to the target tenant domain name is determined from the preset storage container. Finally, the target storage container configuration information corresponding to the target tenant identifier is determined, and a target storage container corresponding to the target tenant identifier is constructed based on the target storage container configuration information. Data uploaded via the target tenant identifier is then stored separately using the target storage container. Thus, the object storage-based data isolation method described in this application can establish a correspondence between the obtained tenant identifiers and tenant domain names. After receiving a tenant request, the target tenant identifier corresponding to the request domain name in the pre-tenant request is determined based on the correspondence. Then, the target storage container configuration information corresponding to the target tenant identifier is determined. A target storage container is created based on the target storage container configuration information, and data uploaded via the target tenant identifier is stored separately using the target storage container. In this way, the tenant identifier can be determined by the tenant domain name, and the storage container configuration information can be determined by the tenant identifier. The storage container can be created based on the determined storage container configuration information to store the data uploaded by the tenant identifier separately, avoiding the need to create storage containers for data isolation through hard coding, and effectively improving the efficiency of data isolation.

[0062] In some embodiments, the relationship construction module 11 may specifically include:

[0063] The relationship building unit is used to obtain all tenant identifiers and tenant domain names from the local tenant configuration table, and determine the tenant domain name as the key and the tenant identifier as the value to establish the correspondence between the tenant identifier and the tenant domain name;

[0064] An identifier storage unit is used to store the tenant identifier based on mapping debugging context technology, so as to store the tenant identifier into a preset storage container.

[0065] In some embodiments, the domain name determination module 12 may specifically include:

[0066] The request preprocessing unit is used to determine whether a tenant request has been received. If a tenant request has been received, the request data in the tenant request is cleaned to obtain a preprocessed request.

[0067] A domain name determination unit is used to determine the request header of the preprocessed request, so as to determine the request domain name of the request based on the request header.

[0068] In some embodiments, the identity determination module 13 may specifically include:

[0069] The first identifier determination unit is used to determine the target tenant domain name corresponding to the requested domain name from the local tenant configuration table, and to determine the tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence.

[0070] The second identifier determination unit is used to determine the tenant identifier corresponding to the target tenant domain name as the target tenant identifier.

[0071] In some embodiments, the object storage-based data isolation device may further include:

[0072] The configuration information storage module is used to obtain all storage container configuration information corresponding to the tenant identifier from the local tenant configuration table, and establish a mapping relationship between the storage container configuration information and the tenant identifier, so as to save the storage container configuration information to a preset storage container mapping table based on the mapping relationship.

[0073] In some embodiments, the container building module 14 may specifically include:

[0074] The container building module is used to determine the target storage container configuration information corresponding to the target tenant identifier from the preset storage container mapping table, so as to build the target storage container based on the external access domain name, access key identifier, access key and container name in the target storage container configuration information.

[0075] Determine whether data to be stored has been received via the target tenant identifier. If so, store the data to be stored via the target storage container.

[0076] Furthermore, embodiments of this application also disclose an electronic device, Figure 4 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0077] Figure 4This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the object storage-based data isolation method disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0078] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0079] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0080] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the object storage-based data isolation method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.

[0081] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned object storage-based data isolation method. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0082] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0083] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0084] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0085] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0086] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A data isolation method based on object storage, characterized in that, include: Obtain all tenant identifiers and tenant domain names in local storage, establish the correspondence between the tenant identifiers and the tenant domain names, and store the tenant identifiers in a preset storage container; Determine whether a tenant request has been received. If so, preprocess the received tenant request and determine the request domain name contained in the preprocessed request. Determine the target tenant domain name corresponding to the requested domain name, and determine the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence; Determine the target storage container configuration information corresponding to the target tenant identifier, and construct a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to store the data uploaded through the target tenant identifier separately based on the target storage container; The step of determining the target storage container configuration information corresponding to the target tenant identifier, and constructing a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to separately store the data uploaded through the target tenant identifier based on the target storage container, further includes: Retrieve all storage container configuration information corresponding to the tenant identifier from the local tenant configuration table, and establish a mapping relationship between the storage container configuration information and the tenant identifier, so as to save the storage container configuration information to a preset storage container mapping table based on the mapping relationship.

2. The data isolation method based on object storage according to claim 1, characterized in that, The step of obtaining all local storage tenant identifiers and tenant domain names, establishing the correspondence between the tenant identifiers and the tenant domain names, and storing the tenant identifiers in a preset storage container includes: Retrieve all tenant identifiers and tenant domain names from the local tenant configuration table, and determine the tenant domain name as the key and the tenant identifier as the value to establish the correspondence between the tenant identifier and the tenant domain name; The tenant identifier is stored using mapping debugging context technology, and is stored in a preset storage container.

3. The data isolation method based on object storage according to claim 1, characterized in that, The step of determining whether a tenant request has been received, and if so, preprocessing the received tenant request and determining the request domain name contained in the preprocessed request, includes: Determine whether a tenant request has been received. If a tenant request has been received, perform data cleaning on the request data in the tenant request to obtain a preprocessed request. Determine the request header of the preprocessed request, and determine the request domain name of the request based on the request header.

4. The data isolation method based on object storage according to claim 2, characterized in that, The step of determining the target tenant domain name corresponding to the requested domain name, and determining the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence, includes: The target tenant domain name corresponding to the requested domain name is determined from the local tenant configuration table, and the tenant identifier corresponding to the target tenant domain name is determined from the preset storage container based on the correspondence. The tenant identifier corresponding to the target tenant domain name is determined as the target tenant identifier.

5. The data isolation method based on object storage according to claim 1, characterized in that, The step of determining the target storage container configuration information corresponding to the target tenant identifier, and constructing a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to separately store the data uploaded through the target tenant identifier based on the target storage container, includes: Determine the target storage container configuration information corresponding to the target tenant identifier from the preset storage container mapping table, and construct the target storage container based on the external access domain name, access key identifier, access key and container name in the target storage container configuration information; Determine whether data to be stored has been received via the target tenant identifier. If so, store the data to be stored via the target storage container.

6. The data isolation method based on object storage according to any one of claims 1 to 5, characterized in that, The target storage container is a container built on object storage services.

7. A data isolation device based on object storage, characterized in that, include: The relationship building module is used to obtain the tenant identifiers and tenant domain names of all local storage, establish the correspondence between the tenant identifiers and the tenant domain names, and store the tenant identifiers in a preset storage container; The domain name determination module is used to determine whether a tenant request has been received. If so, the received tenant request is preprocessed and the request domain name contained in the preprocessed request is determined. An identity determination module is used to determine the target tenant domain name corresponding to the requested domain name, so as to determine the target tenant identifier corresponding to the target tenant domain name from the preset storage container based on the correspondence; The container building module is used to determine the target storage container configuration information corresponding to the target tenant identifier, and build a target storage container corresponding to the target tenant identifier based on the target storage container configuration information, so as to store the data uploaded through the target tenant identifier separately based on the target storage container; The object storage-based data isolation device further includes: The configuration information storage module is used to obtain all storage container configuration information corresponding to the tenant identifier from the local tenant configuration table, and establish a mapping relationship between the storage container configuration information and the tenant identifier, so as to save the storage container configuration information to a preset storage container mapping table based on the mapping relationship.

8. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the object storage-based data isolation method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, Used to store computer programs, which, when executed by a processor, implement the object storage-based data isolation method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Multi-tenant database isolation method and system, electronic equipment and computer storage medium

    CN110765489A

  • Implementation method for public cloud object storage

    CN115587390A