A service system configuration method and a terminal

By packaging business systems and operating environments into sandboxes and mounting peripherals using virtual device files, the environmental adaptation and security issues in the migration of information technology innovation in the financial industry are resolved, enabling efficient and secure business system migration.

CN117608654BActive Publication Date: 2025-11-07FUJIAN CENTM INFORMATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311438462.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-01
Publication Date
2025-11-07
Estimated Expiration
2043-11-01

AI Technical Summary

Technical Problem

The financial industry faces challenges such as operating system fragmentation, complex business systems, difficulty in compatibility and adaptation, insufficient peripheral support, and serious network dependence during the migration process of information technology innovation, resulting in low migration efficiency.

Method used

The business system and its operating environment are packaged into a sandbox, and peripheral devices are mounted through virtual device files and access interfaces are configured to achieve isolation and secure access between the sandbox and peripheral devices.

Benefits of technology

There is no need to modify business systems for different operating environments. Sandboxes can be deployed directly to adapt to various environments, ensuring security and peripheral support, and improving migration efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117608654B_ABST
    Figure CN117608654B_ABST
Patent Text Reader

Abstract

The application discloses a service system configuration method and a terminal, which packs a service system and a running environment corresponding to the service system into a sandbox; acquires peripheral devices, counts the number of service systems needing to call the peripheral devices for each peripheral device; creates a virtual device file corresponding to the peripheral device according to the number, and mounts the virtual device file into the sandbox where the service system needing to call the peripheral device is located; configures an access interface for the sandbox; the application packs the service system and the corresponding running environment into the sandbox respectively, mounts the peripheral devices into the sandbox corresponding to the service system needing to use the peripheral devices through the virtual device file, and configures the access interface for the sandbox, so that when the service system needs to be online, the service system itself does not need to be reformed for different running environments, and the complete sandbox can be directly arranged.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of computer software, and in particular to a business system configuration method and a terminal. BACKGROUND

[0002] At present, in order to solve the problem of security and avoid important data from being misused and stolen, domestic software enterprises are developing information technology application innovation industry (referred to as "China creation") to achieve the goal of independent controllability by localization, and avoid being subject to certain technology. From the industry point of view, the financial industry belongs to the first echelon of China creation promotion, and the requirement of China creation migration is the most urgent. However, there are often the following problems and difficulties in the process of migrating the business system to China creation within the industry:

[0003] 1. The China creation localization ecological environment is complex, and there are many different operating systems, such as UOS, Kylin, and CSD, although they are all based on Linux development, but affected by different distributors, different versions, and different third-party software installation, the fragmentation of software system environment is serious, so it will increase the difficulty and workload of business system migration to China creation.

[0004] 2. Compared with other industries, the financial industry has a variety of business systems, and the individual customization of business systems is generally implemented, and the technical architecture used is complex, and the continuity and stability of business are good, so it is difficult to migrate the business system, and it is difficult to adapt and compatible, and the responsibility for security and stability is great.

[0005] 3. In some consumer service scenarios, tablets are used with professional business equipment to provide services, but there is a lack of China creation software and hardware technical solutions with good operation experience on devices such as tablets that are close to consumer use habits. The business system runs on such devices, and it is difficult to ensure the independent controllability of information systems and services.

[0006] The above problems greatly affect the efficiency of business system migration in the financial industry in the China creation scenario, greatly increasing the difficulty and workload. The existing solution to the complex and diverse China creation software and hardware environment and the troublesome business system migration is to use cloud desktop to realize the migration and deployment of business systems to China creation terminal server clusters, and users use corresponding cloud desktop software to access and run business systems on remote servers. Through this way, users can use cloud desktop software to access and use business systems in different China creation scenarios on different software and hardware environments, avoiding the migration work caused by the complexity of China creation localization ecological environment. However, this solution is not good for peripheral support, and needs to map local peripherals to the cloud through network, and there are compatibility problems for some special peripherals, and the overall use effect is seriously affected by the network. SUMMARY

[0007] The technical problem solved by the present application is to provide a service system configuration method and terminal, and to realize the adaptation of a service system to different operation environments.

[0008] To solve the above technical problem, one technical solution adopted by the present application is:

[0009] A service system configuration method comprises the following steps:

[0010] Packing a service system and a running environment corresponding to the service system into a sandbox;

[0011] Obtaining peripheral devices, and counting the number of service systems that need to call each peripheral device;

[0012] Creating a virtual device file corresponding to the peripheral device according to the number, and mounting the virtual device file into the sandbox where the service system that needs to call the peripheral device is located;

[0013] Configuring an access interface for the sandbox.

[0014] To solve the above technical problem, another technical solution adopted by the present application is:

[0015] A service system configuration terminal comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor realizes the following steps when executing the computer program:

[0016] Packing a service system and a running environment corresponding to the service system into a sandbox;

[0017] Obtaining peripheral devices, and counting the number of service systems that need to call each peripheral device;

[0018] Creating a virtual device file corresponding to the peripheral device according to the number, and mounting the virtual device file into the sandbox where the service system that needs to call the peripheral device is located;

[0019] Configuring an access interface for the sandbox.

[0020] The application has the beneficial effects that: the business system and the corresponding running environment thereof are packaged into a sandbox respectively, and the peripheral device is mounted into the sandbox corresponding to the business system requiring the peripheral device in the form of a virtual device file, and the sandbox is configured with an access interface, so that when the business system needs to be online, the business system itself does not need to be modified for different running environments, and a complete sandbox can be directly arranged. The user accesses the business system in the sandbox and can also call the corresponding peripheral device, and the sandbox is used to arrange the business system to adapt to different environments, and the sandbox is used to isolate the business system, which can also ensure the security of access. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1 A step flow chart of a business system configuration method of an embodiment of the application;

[0022] Figure 2 An architecture diagram corresponding to a business system configuration method of an embodiment of the application;

[0023] Figure 3 A structural schematic diagram of a business system configuration terminal of an embodiment of the application;

[0024] Label explanation:

[0025] 1. A business system configuration terminal; 2. A processor; 3. A memory. DETAILED DESCRIPTION

[0026] To explain the technical content, the achieved purposes and effects of the application in detail, the following will be explained in combination with the embodiments and the drawings.

[0027] Please refer to Figure 1 A business system configuration method, comprising the steps of:

[0028] Packaging a business system and a running environment corresponding to the business system into a sandbox;

[0029] Obtaining a peripheral device, and counting the number of business systems requiring the peripheral device for each peripheral device;

[0030] Creating a virtual device file corresponding to the peripheral device according to the number, and mounting the virtual device file into the sandbox where the business system requiring the peripheral device is located;

[0031] Configuring an access interface for the sandbox.

[0032] From the above description, the beneficial effects of the present application are that: the business system and its corresponding running environment are packaged into a sandbox respectively, and the peripheral device is mounted into the sandbox corresponding to the business system which needs to use the peripheral device through the virtual device file, and the sandbox is configured with an access interface, so that when the business system needs to be online, the business system itself does not need to be modified for different running environments, and the complete sandbox can be directly arranged. The user accesses the business system in the sandbox, and can also call the corresponding peripheral device. When arranging the business system, the sandbox is used to adapt to different environments, and the sandbox is used to isolate the business system, which can also ensure the security of access.

[0033] Further, the business system and the running environment corresponding to the business system are packaged into a sandbox, which comprises:

[0034] Each business system and the running environment corresponding to the business system are packaged into an independent sandbox.

[0035] From the above description, each business system and its corresponding running environment are packaged into an independent sandbox, that is, the sandbox and the business system are one-to-one, and the running of multiple business systems does not interfere with each other.

[0036] Further, the business system and the running environment corresponding to the business system are packaged into an independent sandbox, which comprises:

[0037] A file system namespace corresponding to the business system is created, and the business system and the running environment corresponding to the business system are packaged and stored into the file system namespace;

[0038] A host name namespace, a process number namespace, a network card namespace, a process communication namespace and a user namespace corresponding to the business system are created;

[0039] An independent sandbox is obtained according to the file system namespace, the host name namespace, the process number namespace, the network card namespace, the process communication namespace and the user namespace corresponding to the business system.

[0040] From the above description, an independent sandbox is constructed by means of namespace, wherein the file system namespace creates an independent operable file directory for the sandbox, the host name namespace enables the sandbox to have its own host name, so that the sandbox can be accessed by the host name, the process number namespace enables the sandbox to have independent process management, the network card namespace enables the sandbox to have independent network cards, IP addresses, routes and other resources, and the process communication namespace enables the sandbox to have its own shared memory and semaphore to realize inter-process communication, avoiding conflicts with the host and other containers.

[0041] Further, the creating the virtual device file corresponding to the peripheral device according to the number comprises:

[0042] Compiling the kernel module by programming, loading the kernel module to obtain the virtual device file;

[0043] The process of configuring the receiving data in the write function of the virtual device file, and sending the data to the peripheral management module, so that the peripheral management module inserts the data into the task queue according to the priority and the receiving time sequence, and sends the data to the peripheral device for processing, and sends the processing result back to the virtual device file.

[0044] As can be known from the above description, the virtual device file capable of receiving data and sending the data to the peripheral management module is compiled by programming, and after the virtual device file is mounted into the sandbox, the virtual device file can undertake the data exchange between the actual peripheral device accessed by the host and the sandbox, and the processing process of the specific peripheral device is decoupled from the data channel, and the processing is performed through the task queue, which avoids the processing error caused by the simultaneous reception of multiple different tasks by the peripheral device, and improves the overall processing efficiency while ensuring the processing efficiency of the key task through the priority mode; meanwhile, a separate task queue can be created for each peripheral device, and since each peripheral device can independently process the task, the processing efficiency is further improved.

[0045] Further, after the sandbox is configured with the access interface, the method further comprises:

[0046] Receiving an access request, the access request comprising a user identifier and a target sandbox identifier;

[0047] Determining whether the user identifier is in the user ownership identity table corresponding to the target sandbox identifier, and if so, sending the access request to the target sandbox corresponding to the target sandbox identifier.

[0048] As can be known from the above description, when a user needs to access a business system, an access request comprising a user identifier and a target sandbox identifier is sent, and then it can be determined according to the target sandbox identifier whether the user corresponding to the user identifier has the access permission to the corresponding sandbox, so as to realize the configuration of the access permission of different business systems.

[0049] Please refer to Figure 3 A business system configuration terminal, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, the following steps are implemented:

[0050] Packing a business system and a running environment corresponding to the business system into a sandbox;

[0051] acquiring peripheral devices, counting the number of service systems needing to invoke the peripheral devices for each of the peripheral devices;

[0052] creating a virtual device file corresponding to the peripheral device according to the number, and mounting the virtual device file into the sandbox where the service system needing to invoke the peripheral device is located;

[0053] configuring an access interface for the sandbox.

[0054] The application has the advantages that: the service system and the corresponding running environment are packaged into a sandbox respectively, the peripheral device is mounted into the sandbox corresponding to the service system needing to use the peripheral device through a virtual device file, and an access interface is configured for the sandbox, so that when the service system needs to be online, the service system itself does not need to be modified for different running environments, and the complete sandbox can be directly arranged. The user can access the service system in the sandbox and also can invoke the corresponding peripheral device. When the service system is arranged, the sandbox can adapt to different environments, and the service system is isolated by the sandbox, which can ensure the security of access.

[0055] Further, the packaging of the service system and the running environment corresponding to the service system into a sandbox comprises:

[0056] packaging each service system and the running environment corresponding to the service system into an independent sandbox.

[0057] From the above description, it can be seen that each service system and the corresponding running environment are packaged into an independent sandbox, that is, the sandbox and the service system are one-to-one, and the running of multiple service systems does not interfere with each other.

[0058] Further, the packaging of each service system and the running environment corresponding to the service system into an independent sandbox comprises:

[0059] creating a file system namespace corresponding to the service system, and packaging the service system and the running environment corresponding to the service system into the file system namespace;

[0060] creating a host name namespace, a process number namespace, a network card namespace, a process communication namespace and a user namespace corresponding to the service system;

[0061] obtaining an independent sandbox according to the file system namespace, the host name namespace, the process number namespace, the network card namespace, the process communication namespace and the user namespace corresponding to the service system.

[0062] As can be seen from the above description, the independent sandbox is constructed by the way of namespace, in which the file system namespace creates independent operable file directory for the sandbox, the hostname namespace enables the sandbox to have its own hostname, and the process number namespace enables the sandbox to have independent process management, the network card namespace enables the sandbox to have independent network card, IP address, route and other resources, the process communication namespace enables the sandbox to have its own shared memory and semaphore to realize inter-process communication, and to avoid conflict with the host and other containers.

[0063] Further, the creating of the virtual device file corresponding to the peripheral device according to the number comprises:

[0064] The kernel module is compiled by programming to generate the virtual device file.

[0065] The process of configuring the receiving data in the write function of the virtual device file and sending the data to the peripheral management module, so that the peripheral management module inserts the data into the task queue according to the priority and the receiving time sequence, and sends the data to the peripheral device for processing, and sends the processing result back to the virtual device file.

[0066] As can be seen from the above description, the virtual device file capable of receiving data and sending the data to the peripheral management module is compiled by programming, and then the virtual device file mounted in the sandbox can undertake the data exchange between the actual accessed peripheral device of the host and the sandbox, while the processing process of the specific peripheral device and the data channel are decoupled, and the processing is performed by the way of task queue, which avoids processing error caused by the peripheral device receiving multiple different tasks at the same time, and improves the overall processing efficiency while ensuring the processing efficiency of critical tasks by the way of priority; meanwhile, a separate task queue can be created for each peripheral device, and each peripheral device can independently process tasks, which further improves the processing efficiency of the kernel module as the virtual device file.

[0067] Further, the configuring of the access interface for the sandbox further comprises:

[0068] Receiving an access request, the access request comprising a user identifier and a target sandbox identifier;

[0069] Judging whether the user identifier is in the user ownership identity table corresponding to the target sandbox identifier, if yes, sending the access request to the target sandbox corresponding to the target sandbox identifier.

[0070] From the above description, when a user needs to access a business system, an access request including a user identifier and a target sandbox identifier is sent, and whether the user corresponding to the user identifier has access permission of the corresponding sandbox can be determined according to the target sandbox identifier, so that the access permission of different business systems is configured.

[0071] The business system configuration method and the terminal described above can be applied to the following description by means of a specific embodiment.

[0072] Please refer to Figures 1-2 Embodiment one of the present application is:

[0073] A business system configuration method, specifically comprising:

[0074] S1, packaging a business system and a running environment corresponding to the business system into a sandbox, specifically:

[0075] Packaging each business system and the running environment corresponding to the business system into an independent sandbox, comprising:

[0076] S11, creating a file system namespace (namespace) corresponding to the business system, and packaging and storing the business system and the running environment corresponding to the business system into the file system namespace;

[0077] In an optional embodiment, a mount namespace method is used to create an independent file system namespace for the sandbox;

[0078] S12, creating a host name namespace (UTS namespace), a process number namespace (PID namespace), a network card namespace (Network namespace), a process communication namespace (IPC namespace) and a user namespace (User namespace) corresponding to the business system;

[0079] S13, obtaining an independent sandbox according to the file system namespace, the host name namespace, the process number namespace, the network card namespace, the process communication namespace and the user namespace corresponding to the business system;

[0080] S14, using the cgroup mechanism to limit and allocate the resources such as CPU, memory, network and the like used by the sandbox, avoiding unlimited occupation of the resources by the sandbox, affecting the normal operation of the host and other sandboxes; using the cgroup mechanism in the Linux system to limit, control and separate the resources (such as CPU, memory, disk input and output and the like) of a single sandbox, avoiding that a single sandbox occupies too much resources, affecting the processing efficiency of other sandboxes and the host; realizing separation of a piece of resources and a logically independent space from the host for running a business system;

[0081] In an optional embodiment, the step S1 is completed by executing the sandbox module to create and manage the sandbox;

[0082] S2, obtaining peripheral devices, counting the number of business systems needing to call the peripheral devices for each of the peripheral devices;

[0083] In an optional embodiment, the peripheral devices are devices needed for business, such as a fingerprint instrument, a password keyboard, a card reader, a camera, a scanner and the like;

[0084] S3, creating a virtual device file corresponding to the peripheral device according to the number, and mounting the virtual device file into the sandbox where the business system needing to call the peripheral device is located;

[0085] The creating of the virtual device file corresponding to the peripheral device according to the number includes:

[0086] S31, generating a kernel module by programming, and loading the kernel module to obtain a virtual device file;

[0087] The programming can be kernel programming or other programming capable of generating a kernel module, which is not limited herein; the virtual device file is loaded into the host and allocated as a host resource for use by the sandbox;

[0088] S32, the process of configuring the virtual device file to receive data of the business system in the mounted sandbox and send the data to the peripheral management module, and the process of receiving the processing result sent by the peripheral management module and sending the processing result to the business system, so that the peripheral management module inserts the data into a task queue according to the priority and the time sequence of receiving the data, sends the data to the peripheral device for processing in a queue, and sends the processing result back to the virtual device file; specifically, the data of the business system includes a read operation or a write operation; the business system in the sandbox can obtain the processing result through the virtual device file, realizing scheduling management when multiple sandboxes use the same peripheral device;

[0089] In an alternative embodiment, the priority is determined according to whether the service system in the corresponding sandbox occupies the input focus (windows-oriented system waits for user information passively);

[0090] In an alternative embodiment, the creation of the virtual device file in step S2 and the receiving of the data and saving to the task queue in step S3 are queued according to time and priority order and sent to the real device file processing in the peripheral management module; in this way, the use of the peripheral by the service system in the sandbox is relatively independent, and the peripheral module is not occupied by a service system for a long time, the tasks to be performed by the service peripheral are managed and scheduled by the peripheral management module, and the efficient use of the peripheral module is ensured;

[0091] S4, configuring an access interface for the sandbox; step S4 can be completed in the sandbox module and does not limit the specific execution order, and can be completed before the creation of the sandbox and the receiving of the access request;

[0092] S5, receiving an access request, the access request including a user identifier and a target sandbox identifier;

[0093] S6, judging whether the user identifier is in the user ownership identity table corresponding to the target sandbox identifier, if yes, sending the access request to the target sandbox corresponding to the target sandbox identifier;

[0094] In an alternative embodiment, the access client is configured to implement the data transmission of steps S5-S6 and the sandbox module, the access client can be installed in the same device as the sandbox module and the peripheral management module, or can be installed in different devices and communicate with the sandbox through a network to realize data interaction; the support of the graphical interface protocol (X protocol, Wayland protocol) and the remote desktop protocol (such as RDP, VNC, SPICE) in the access client enables the access to the sandbox through the network, displays the service system interface in the sandbox on the screen of the access client through the graphical interface protocol, and enables the user to operate, or the device where the sandbox is located can also be directly used as an access client for local access, which is suitable for different business scenarios, such as customer data that needs to be kept secret, which can be loaded into the customer's device, and the access client is installed in the device to realize local access;

[0095] X protocol, i.e. X Window graphical user interface, is a software window system displayed in bitmap mode, which was originally a research result of Massachusetts Institute of Technology in 1984, and then became a standardized software toolkit and display architecture operation protocol consistent with UNIX, UNIX-like, and OpenVMS operating systems;

[0096] In an optional embodiment, a security control module is further included, local storage data associated with all the sandboxes are respectively saved in independent directories, and independent user ownership identities are configured, only the ownership user can access; when a user accesses a business system in a sandbox through an access client, the security control module checks the access user right, only when the client user has the corresponding sandbox access right, can the user connect to the business system in the sandbox, so as to realize the security protection of the business system.

[0097] Please refer to Figure 2 In an optional embodiment, the sandbox module 102, the peripheral device 103, the business peripheral management module 104 and the security control module 106 are installed on the national security terminal device 101, the national security terminal device 101 is constructed by using a domestic embedded application level processor and a domestic mobile operating system; the access client is installed on a user operation terminal, and the user operation terminal and the national security terminal device can be the same terminal.

[0098] Please refer to Figure 3 Embodiment two of the present application is:

[0099] A business system configuration terminal 1, comprising a processor 2, a memory 3, and a computer program stored in the memory 3 and executable on the processor 2, wherein the processor 2 executes the computer program to realize each step in embodiment one.

[0100] In summary, the application provides a service system configuration method and terminal, which deploys the service system and the environment corresponding to the service system into a sandbox, uses the sandbox mode, and can quickly migrate the service system and the corresponding dependent environment to the device, without the need for adaptation to the used XG (Xin Guo) system of the device, greatly reducing the migration workload in the XG scenario, and compared with the virtual machine mode, the creation and start are fast, the required resources are less, and the performance efficiency is greatly advantageous. Compared with the cloud desktop scheme, the peripheral and the service system are actually running on the same device, and the peripheral can be well supported, and the security reinforcement of the service system is ensured through the management of resources and the detection of user permissions; the operating system used by the customer business is diverse, and the sandbox technology is used to directly migrate the operating system used by the business to the XG terminal device, so that the customer can directly operate the original business system in the sandbox, without the need for the business system to adapt to the operating system type used by the XG terminal, greatly reducing the workload of migration and adaptation. At the same time, a set of independent and unified software environment can be provided for the business system, the deployment and installation of the business system in the XG environment can be quickly completed, and the maturity and online of the business system can be accelerated. The business peripheral and the business system run on the same hardware, and the communication is reliable; and the business peripheral does not need to adapt to the software and hardware environment of multiple business systems, the adaptation cost is low, and the process of business online can be accelerated. Through the management and scheduling of the business peripheral, the use efficiency of the peripheral device is improved; and through the use of the security control module, complete control measures are provided for the sandbox to obtain data and user access, and the information security of the business system can be ensured. Since the client can be arranged on the customer device, the scheme can be used with any consumer-level terminal such as a tablet, and the device ensures the security of the business system, so the industry application can be conveniently migrated to a consumer-oriented service scenario, and it is beneficial to help the industry service to expand its service scenario and business scope.

[0101] The above is only an embodiment of the application, and does not limit the patent scope of the application, and any equivalent transformation or direct or indirect application in the related technical field using the content of the application specification and drawings is also included in the patent protection scope of the application.

Claims

1. A business system configuration method characterized by, The method comprises the steps of: packaging a business system and a running environment corresponding to the business system into a sandbox; obtaining peripheral devices, counting the number of business systems that need to call the peripheral devices for each of the peripheral devices; creating a virtual device file corresponding to the peripheral device according to the number, and mounting the virtual device file into the sandbox where the business system that needs to call the peripheral device is located; configuring an access interface for the sandbox; the step of creating the virtual device file corresponding to the peripheral device according to the number comprises: generating a kernel module by programming, and loading the kernel module to obtain a virtual device file; in the write function of the virtual device file, data is received and sent to a peripheral management module, so that the peripheral management module inserts the data into a task queue according to a priority and a receiving time sequence, and sends the data to the peripheral device for processing, and sends the processing result back to the virtual device file; after the step of configuring the access interface for the sandbox, the method further comprises the steps of: receiving an access request, the access request comprising a user identifier and a target sandbox identifier; judging whether the user identifier is in a user ownership identity table corresponding to the target sandbox identifier, and if yes, sending the access request to a target sandbox corresponding to the target sandbox identifier.

2. The method of claim 1, wherein the step of packaging the business system and the running environment corresponding to the business system into the sandbox comprises: packaging each business system and the running environment corresponding to the business system into an independent sandbox.

3. The method of claim 2, wherein the step of packaging each business system and the running environment corresponding to the business system into an independent sandbox comprises: creating a file system namespace corresponding to the business system, and packaging the business system and the running environment corresponding to the business system into the file system namespace; creating a host name namespace, a process number namespace, a network card namespace, a process communication namespace and a user namespace corresponding to the business system; obtaining an independent sandbox according to the file system namespace, the host name namespace, the process number namespace, the network card namespace, the process communication namespace and the user namespace corresponding to the business system.

4. A business system configuration terminal comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, when the processor executes the computer program, the following steps are implemented: packaging a business system and a running environment corresponding to the business system into a sandbox; obtaining peripheral devices, counting the number of business systems that need to call the peripheral devices for each of the peripheral devices; creating a virtual device file corresponding to the peripheral device according to the number, and mounting the virtual device file into the sandbox where the business system that needs to call the peripheral device is located; configuring an access interface for the sandbox; the step of creating the virtual device file corresponding to the peripheral device according to the number comprises: generating a kernel module by programming, and loading the kernel module to obtain a virtual device file; in the write function of the virtual device file, data is received and sent to a peripheral management module, so that the peripheral management module inserts the data into a task queue according to a priority and a receiving time sequence, and sends the data to the peripheral device for processing, and sends the processing result back to the virtual device file; The process of receiving data in the write function of the virtual device file and sending the data to the peripheral management module, so that the peripheral management module inserts the data into a task queue according to priorities and receiving time sequences, sends the data to the peripheral device for processing, and sends the processing result back to the virtual device file; The method further comprises: receiving an access request, the access request comprising a user identifier and a target sandbox identifier; determining whether the user identifier is in a user ownership identity table corresponding to the target sandbox identifier, and if so, sending the access request to a target sandbox corresponding to the target sandbox identifier.

5. A service system configuration terminal according to claim 4, characterized in that, The method further comprises: packaging each business system and a running environment corresponding to the business system into an independent sandbox.

6. A service system configuration terminal according to claim 5, wherein The method further comprises: creating a file system namespace corresponding to the business system, and packaging the business system and the running environment corresponding to the business system into the file system namespace; creating a host name namespace, a process number namespace, a network card namespace, a process communication namespace, and a user namespace corresponding to the business system; obtaining an independent sandbox according to the file system namespace, the host name namespace, the process number namespace, the network card namespace, the process communication namespace, and the user namespace corresponding to the business system.

Citation Information

Patent Citations

  • Application starting method and device

    CN113378154A

  • Method and device for creating sandbox environment for plug-in operation and computing equipment

    CN114816707A