Multi-computer room data isolation method, system and storage medium

By decoupling interface requests and determining the target access domain name based on the target computer room information, the possible mutual interference problem between multiple computer rooms is solved, and independent isolation and stability of multi-computer room data is achieved.

CN119520620BActive Publication Date: 2025-05-06BEIJING XINYIXIANGSHANG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510057915.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-05-06
Estimated Expiration
2045-01-14

AI Technical Summary

Technical Problem

In the prior art, mutual interference may occur between multiple computer rooms, resulting in the impact of data security and compliance.

Method used

By obtaining the login information generated by the user's login trigger, decoupling the interface request to form the access domain name part and the request path part, and determining the target access domain name based on the target computer room information, recombining it to form a new interface request path to ensure that the access domain name and the request path do not interfere with each other.

Benefits of technology

It effectively avoids interference from the request path between multiple computer rooms, ensures that problems in one computer room will not affect computer rooms in other different regions, and improves the independence and stability of data isolation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520620B_ABST
    Figure CN119520620B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data security technology, and in particular to a multi-computer room data isolation method, system and storage medium. The multi-computer room data isolation method provided by the present invention obtains login information generated by a user login trigger and receives an interface request; the login information includes target computer room information corresponding to a target company entity selected by the user; the interface request is decoupled to form an access domain name part and a request path part; based on the target computer room information, a target access domain name of the computer room to which the target company entity belongs is determined; the target access domain name and the request path part are recombined to form a new interface request path, and the target computer room corresponding to the new interface request path is accessed, so that the access domain name part and the request path part do not interfere with each other, thereby avoiding a problem in one computer room affecting the situation of other computer rooms in different regions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a multi-computer room data isolation method, system and storage medium. Background Art

[0002] At present, the data of domestic and overseas users needs to be stored in computer rooms in different regions to ensure data security and compliance.

[0003] Both domestic and overseas users are managed using the same SaaS (Software as a Service) application. However, for multiple companies distributed at home and abroad, in actual usage scenarios, multiple computer rooms may interfere with each other. Summary of the invention

[0004] In order to solve the problem that mutual interference may occur when multiple computer rooms are managed with the same SaaS application in the prior art, the present invention provides a multi-computer room data isolation method, system and storage medium.

[0005] The solution to the technical problem of the present invention is to provide a multi-computer room data isolation method, comprising the following steps:

[0006] Acquire login information generated by the user login trigger and receive an interface request; the login information includes the target computer room information corresponding to the target company entity selected by the user;

[0007] Decoupling the interface request to form an access domain name part and a request path part;

[0008] Determine the target access domain name of the computer room to which the target company belongs based on the target computer room information;

[0009] The target access domain name and the request path portion are recombined to form a new interface request path, and the target computer room corresponding to the new interface request path is accessed.

[0010] Preferably, before obtaining the login information generated by the user login trigger and initiating the interface request, the method further includes:

[0011] Obtain information about all different computer rooms and the corresponding access domain name for each computer room;

[0012] Store all different computer room information and the corresponding access domain names of the computer rooms.

[0013] Preferably, before obtaining the login information generated by the user login trigger and initiating the interface request, the method further includes:

[0014] Get the computer room to which the company entity to be created belongs; one company entity corresponds to one computer room;

[0015] Switch the current computer room to the computer room of the company to be created;

[0016] In the computer room where the company entity to be created belongs, create at least one management account corresponding to the company entity to be created.

[0017] Preferably, obtaining the login information generated by the user login trigger specifically includes:

[0018] Respond to the user's login trigger operation and determine the target company entity selected by the user;

[0019] Determine the corresponding computer room according to the target company entity, and obtain the target computer room information corresponding to the target company entity.

[0020] Preferably, determining the target access domain name of the computer room to which the target company belongs based on the target computer room information specifically includes:

[0021] Compare the target computer room information with all the stored computer room information in different regions one by one;

[0022] If the target computer room information is consistent with a stored computer room information, the access domain name corresponding to the computer room information consistent with the target computer room information is used as the target access domain name.

[0023] Preferably, after the target access domain name and the request path portion are recombined to form a new interface request path, and the target computer room corresponding to the new interface request path is accessed, the method further comprises:

[0024] In response to the user's switching operation on the company entity, obtain the information of the computer room to be switched corresponding to the company entity to be switched;

[0025] Determine the access domain name of the corresponding computer room to be switched based on the information of the computer room to be switched;

[0026] The access domain name of the to-be-switched computer room is combined with the request path portion to form a switching interface request path, and the to-be-switched computer room corresponding to the switching interface request path is accessed.

[0027] Preferably, before obtaining the login information generated by the user login trigger and initiating the interface request, the method further includes:

[0028] In each computer room, corresponding instruction request paths are set according to different preset request tasks.

[0029] Preferably, after entering the target computer room corresponding to the new interface request path for access, the method further includes:

[0030] Responding to a user's instruction triggering operation, and determining an instruction request path according to the instruction triggering operation;

[0031] The target access domain name and the instruction request path are combined to form a trigger request path, and the trigger request path is accessed in the target computer room.

[0032] In order to solve the above technical problems, the present invention further provides a multi-computer room data isolation system, which is used to implement the multi-computer room data isolation method as described in any one of the above items, comprising:

[0033] An information acquisition module is used to acquire login information generated by a user login trigger and initiate an interface request; the login information includes target computer room information corresponding to the target company entity selected by the user;

[0034] A request decoupling module, used to decouple the interface request to form an access domain name part and a request path part;

[0035] A domain name determination module, used to determine the target access domain name of the computer room to which the target company belongs based on the target computer room information;

[0036] The access request module is used to recombine the target access domain name and the request path part to form a new interface request path, and enter the target computer room corresponding to the new interface request path for access.

[0037] In order to solve the above technical problems, the present invention further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the multi-computer room data isolation method as described in any one of the above items is implemented.

[0038] Compared with the prior art, the multi-computer room data isolation method, system and storage medium provided by the present invention have the following advantages:

[0039] 1. The present invention is a multi-computer room data isolation method provided by an embodiment, comprising the following steps: obtaining login information generated by a user login trigger and initiating an interface request; the login information includes the target computer room information corresponding to the target company entity selected by the user; decoupling the interface request to form an access domain name part and a request path part; determining the target access domain name of the computer room to which the target company entity belongs based on the target computer room information; recombining the target access domain name and the request path part to form a new interface request path, and entering the target computer room corresponding to the new interface request path for access. By decoupling the interface request triggered by the user login to form an access domain name part and a request path part, the access domain name part and the request path part do not interfere with each other; and when forming a new interface request path, it is only necessary to recombinate the determined target access domain name with the decoupled request path part to form a new interface request path, that is, when the login is triggered, the target access domain name replaces the original split access domain name part, and the request path part remains unchanged, so that when the login is triggered, only the access domain name needs to be paid attention to, thereby avoiding interference between the request path parts between multiple computer rooms, and thus avoiding problems in one computer room affecting computer rooms in different regions.

[0040] 2. The embodiment of the present invention provides a method of obtaining all different computer room information and the access domain name corresponding to each computer room; storing all different computer room information and the access domain name corresponding to the computer room, so that the target access domain name is obtained from the pre-stored access domain name, rather than temporarily obtained, thereby improving the accuracy of the target access domain name. In addition, the independent storage of different access domain names corresponding to different computer rooms is realized. When a problem occurs in the domain name part of one computer room, it will not affect the domain name part of other computer rooms, thereby achieving non-interference between different computer rooms, and achieving that the failure of each computer room server will not affect the use of other computer room servers.

[0041] 3. The embodiment of the present invention provides a method for obtaining the computer room to which the company entity to be created belongs; one company entity corresponds to one computer room; the current computer room is switched to the computer room to which the company entity to be created belongs; in the computer room corresponding to the computer room to which the company entity to be created belongs, at least one management account corresponding to the company entity to be created is created, thereby realizing the creation of a new company entity and ensuring the accuracy of the computer room corresponding to the newly created company entity.

[0042] 4. The method for obtaining login information generated by a user login trigger provided by an embodiment of the present invention specifically includes: responding to the user's login trigger operation to determine the target company entity selected by the user; determining the corresponding computer room according to the target company entity, and obtaining the target computer room information corresponding to the target company entity, thereby achieving the ability to obtain the computer room information when the user logs in, facilitating more accurate determination of the target access domain name.

[0043] 5. The method provided by the embodiment of the present invention for determining the target access domain name of the computer room to which the target company belongs based on the target computer room information specifically includes: judging the target computer room information against the stored computer room information of all different regions one by one; if the target computer room information is consistent with a stored computer room information, the access domain name corresponding to the computer room information consistent with the target computer room information is used as the target access domain name, thereby achieving the acquisition of the target access domain name from the pre-stored access domain names, thereby avoiding the temporary determination of the target access domain name, and further improving the accuracy of the obtained target access domain name. In addition, since the target access domain name is determined from the pre-stored data, it avoids the problem of the domain name in the determination process, and directly locates the problem of the domain name part directly in the stored access domain name.

[0044] 6. The embodiment of the present invention provides a method for responding to a user's switching operation on a company entity, obtaining the information of the computer room to be switched corresponding to the company entity to be switched; determining the access domain name of the corresponding computer room to be switched based on the information of the computer room to be switched; combining the access domain name of the computer room to be switched with the request path part to form a switching interface request path, and accessing the computer room to be switched corresponding to the switching interface request path. By switching the access domain name, dynamic computer room switching is completed, and after logging in, the user can still switch between computer rooms in different regions and computer rooms in the same region for different company entities, making the operation easier.

[0045] 7. The embodiment of the present invention provides that corresponding instruction request paths are set in each computer room according to different preset request tasks, thereby splitting the overall data tasks and making the data tasks of different data independent, thereby avoiding mutual influence between interface services of different instruction request paths.

[0046] 8. The present invention also provides a multi-computer room data isolation system, which has the same beneficial effects as the above-mentioned multi-computer room data isolation method, and will not be elaborated here.

[0047] 9. A computer-readable storage medium has the same beneficial effects as the above-mentioned multi-computer room data isolation method, which will not be described in detail here. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0049] Figure 1 It is a flowchart of the steps of the multi-computer room data isolation method provided by the first embodiment of the present invention.

[0050] Figure 2 It is a specific step flow chart of step S11 of the multi-computer room data isolation method provided by the first embodiment of the present invention.

[0051] Figure 3 It is a specific step flow chart of step S30 of the multi-computer room data isolation method provided by the first embodiment of the present invention.

[0052] Figure 4 It is a block diagram of a multi-computer room data isolation system provided by the second embodiment of the present invention. DETAILED DESCRIPTION

[0053] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and implementation examples. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0054] See also Figure 1 The first embodiment of the present invention provides a multi-computer room data isolation method, comprising the following steps:

[0055] S10: Acquire login information generated by the user login trigger and receive an interface request; the login information includes the target computer room information corresponding to the target company entity selected by the user;

[0056] Specifically, the method in the embodiment of the present invention can be used for SaaS applications, such as the ESOP (Employee Stock Ownership Plan) system, which is mainly used to manage and implement a digital management system for employee stock ownership plans. It can sign, query, dynamically monitor the equity structure of employee shares, and manage and maintain online data, while managing the company's options, RSU and other data. The login information may include user information and the target computer room information corresponding to the target company entity selected by the user. User information includes but is not limited to basic information such as user name, mobile phone number, email address, etc., as well as access tokens, company lists, etc. The target company entity is the company entity that the user currently needs to perform management operations, that is, the company entity selected by the user. The computer room information includes the computer room to which the data of the company entity belongs, that is, the computer room where the data is stored.

[0057] It should be noted that a user can be the administrator of multiple company entities. The computer room information is stored in the company information, so after the user selects the company entity, the target computer room information corresponding to the target company entity can be obtained.

[0058] More specifically, when a user logs in to the ESOP system, the system not only obtains the login information, but also generates an interface request based on the user's login trigger operation, which is expressed in the form of a URL (Uniform Resource Locator). The interface request is used to request to log in to the system and enter the computer room of the company entity selected by the user to perform operations.

[0059] S20: Decoupling the interface request to form an access domain name part and a request path part;

[0060] Specifically, the interface request URL consists of two parts: the access domain origin part and the request pathname part. The access domain origin part points to different computer rooms, and the request pathname part represents different operations performed after logging into the system.

[0061] S30: Determine the target access domain name of the computer room to which the target company belongs based on the target computer room information;

[0062] Specifically, different computer rooms have different corresponding access domain names, and one computer room corresponds to one access domain name. Therefore, the corresponding access domain name needs to be determined based on the computer room information returned when the user logs in, and the access domain name is used as the target access domain name of the computer room to which the target company belongs.

[0063] S40: Recombining the target access domain name with the request path portion to form a new interface request path, and entering the target computer room corresponding to the new interface request path for access.

[0064] Specifically, the target access domain name and the request path are combined in such a way that the target access domain name replaces the position of the access domain name in the original interface request, thereby realizing the combination of the target access domain name and the request path. In the combined new interface request path, the target access domain name can be mapped to the corresponding target computer room according to the Internet protocol, so that after logging into the system, all subsequent operations in the system are performed under the target access domain name origin, that is, directly under the corresponding target computer room.

[0065] It can be understood that by decoupling the interface request triggered by the user login to form the access domain name part and the request path part, the access domain name part and the request path part do not interfere with each other; and when forming a new interface request path, it is only necessary to recombine the determined target access domain name with the decoupled request path part to form a new interface request path, that is, when the login is triggered, the target access domain name replaces the original split access domain name part, and the request path part remains unchanged, so that when the login is triggered, only the access domain name needs to be paid attention to, which not only avoids the interference of the request path part between multiple computer rooms during login, but also ensures the correctness of the computer room entered during login, thereby avoiding the problem of one computer room affecting the situation of other computer rooms in different regions. In addition, the interface request is decoupled to form the access domain name part and the request path part, which is convenient for timely determining which computer room problem is or the interface error problem when a problem occurs, and is convenient for debugging when a problem occurs. In addition, the interface request is decoupled to form the access domain name part and the request path part. Since the two do not interfere with each other, the scalability is good and it is convenient to add other computer room clusters.

[0066] Furthermore, before step S10, the method further includes:

[0067] S1: Obtain information about all different computer rooms and the corresponding access domain name of each computer room;

[0068] S2: Store all different computer room information and the corresponding access domain names of the computer rooms.

[0069] Specifically, since different company entities belong to different regions, computer room groups in different regions can be established according to different company entities. And the data of different company entities need to be stored separately. Therefore, each company entity corresponds to a computer room, and the data of multiple company entities in the same region belong to the same computer room group, such as the BJ computer room group and the HK computer room group. The BJ computer room group has multiple company entities whose computer rooms are the BJ computer rooms, and the HK computer room group has multiple company entities whose computer rooms are the HK computer rooms.

[0070] More specifically, the company entity, computer room information, and access domain name correspond one to one. That is, each company entity corresponds to a computer room, and a computer room corresponds to an access domain name. For example, the BJ computer room and the HK computer room. The BJ computer room and the HK computer room are physically separated. All information of the company tenants belonging to the BJ computer room is stored in the BJ computer room, and all information of the company tenants belonging to the HK computer room is stored in the BJ computer room. The computer room information and the corresponding access domain name origin are preset and stored in the front end in the form of a dictionary. That is, there is a mapping relationship between the computer room information and the corresponding access domain name origin. For example, in the preset dictionary OriginMap: BJ's access domain name is "https: / / xxx-bj.site.com", https: / / xxx-bj.site.com is mapped to the BJ computer room according to the Internet protocol, and HK's access domain name is "https: / / xxx-hk.site.com". https: / / xxx-hk.site.com is mapped to the HK computer room according to the Internet protocol.

[0071] It can be understood that all the information of different computer rooms and the access domain names corresponding to each different computer room are pre-stored, so that the target access domain name is obtained from the pre-stored access domain name, rather than being temporarily obtained or input, thereby improving the accuracy of the target access domain name. In addition, the independent storage of different access domain names corresponding to different computer rooms is realized. When a problem occurs in the domain name part of one computer room, it will not affect the domain name part of other computer rooms, thereby achieving non-interference between different computer rooms and achieving that the failure of the server in each computer room will not affect the use of the servers in other computer rooms.

[0072] Furthermore, before step S10, the method further includes:

[0073] S7: Obtain the computer room to which the company entity to be created belongs; one company entity corresponds to one computer room;

[0074] S8: Switch the current computer room to the computer room of the company to be created;

[0075] S9: Create at least one management account corresponding to the company entity to be created in the computer room to which the company entity to be created belongs.

[0076] Specifically, the company entity to be created is the newly added company entity. Each company entity corresponds to a computer room, and each company entity corresponds to at least one management account. The number of management accounts corresponding to a company entity can be set according to specific management personnel, that is, one company entity corresponds to one management account, or one company entity corresponds to multiple management accounts, and these management accounts can log in to the ESOP system of the company entity. This embodiment does not limit this. A management account can also have at least one company entity, that is, one management account can manage one company entity, or multiple company entities, and this embodiment does not limit this.

[0077] It can be understood that if a new company entity needs to be added to the ESOP system, it is necessary to first identify the computer room to which the company entity to be created belongs, switch the backend management system to the corresponding computer room, and then create the company entity of the corresponding computer room under the computer room, thereby directly associating the current newly created company entity with the corresponding computer room, thereby realizing the creation of a new company entity and ensuring the accuracy of the computer room corresponding to the newly created company entity.

[0078] It should be noted that the computer room corresponding to each company entity is determined when it is created. Therefore, when the user selects the company entity each time he logs in, the corresponding target computer room information can be determined based on the company entity, thereby improving the accuracy of the obtained computer room information.

[0079] See also Figure 2 , further, step S11: obtaining login information generated by the user login trigger, specifically including:

[0080] S111: responding to the user's login trigger operation and determining the target company entity selected by the user;

[0081] S112: Determine the corresponding computer room according to the target company entity, and obtain the target computer room information corresponding to the target company entity.

[0082] Specifically, the ESOP system is provided with a login interface. When logging in, the login interface can display at least one company entity corresponding to the current management account, and the user can select the company entity and then log in. Thus, the system can determine the corresponding computer room according to the company entity selected by the user to obtain the target computer room information corresponding to the target company entity, thereby realizing that the computer room information can be obtained when the user logs in, which is convenient for determining the target access domain name more accurately and quickly in the future.

[0083] See also Figure 3 Further, step S30 specifically includes:

[0084] S31: comparing the target computer room information with all stored computer room information in different regions one by one;

[0085] S32: If the target computer room information is consistent with a stored computer room information, the access domain name corresponding to the computer room information consistent with the target computer room information is used as the target access domain name.

[0086] Specifically, the target computer room information obtained when the user logs in is compared with all the pre-stored computer room information one by one, and it is specifically determined whether there is a computer room information in all the pre-stored computer room information that is the same as the target computer room information obtained when the user logs in. If the target computer room information is the same as one of the stored computer room information, the access domain name corresponding to the computer room information that is consistent with the target computer room information is taken from the preset dictionary as the target access domain name. In this way, the target access domain name can be directly obtained from the preset dictionary without having to input a domain name separately, thereby improving the accuracy of the obtained target domain name.

[0087] It can be understood that by obtaining the target access domain name from the pre-stored access domain names, the temporary determination or input of the target access domain name is avoided, so as to further improve the accuracy of the obtained target access domain name. In addition, since the target access domain name is determined from the pre-stored data, when there is a problem with the domain name part, the problem with the domain name part can be directly located in the stored access domain name.

[0088] It should be noted that since the access domain name is pre-stored, the accuracy of the target access domain name comes from the preset value pre-stored in the preset dictionary. The preset value needs to reach the designated computer room server after being parsed by the Internet protocol. If the preset value is wrong or the computer room server fails, all interface services will fail. For example, the HK computer room and the BJ computer room do not affect each other, and the failure of the HK computer room server will not affect the use of the BJ computer room server.

[0089] Furthermore, after step S40, the method further includes:

[0090] S51: Responding to the user's switching operation on the company entity, obtaining information of the computer room to be switched corresponding to the company entity to be switched;

[0091] S52: Determine the access domain name of the corresponding computer room to be switched based on the information of the computer room to be switched;

[0092] S53: Combining the access domain name of the to-be-switched computer room with the request path portion to form a switching interface request path, and entering the to-be-switched computer room corresponding to the switching interface request path for access.

[0093] Specifically, since each company entity has corresponding computer room information, when the company entity is switched, the corresponding computer room will also be switched. When the login is completed, if the user wants to switch the company entity, the switching operation can be performed. The switching operation is the operation of the company entity reselected by the user after logging into the system. The company entity reselected by the user after logging into the system is the company entity to be switched. The ESOP system can respond to the user's switching operation, obtain the computer room information to be switched corresponding to the company entity to be switched reselected by the user, and determine the corresponding access domain name of the computer room to be switched based on the computer room information to be switched, use the access domain name as the access domain name to be switched, and splice the access domain name to be switched with the request path part to form a switching interface request path, and finally reinitialize the system with the switching interface request path to enter the computer room to be switched corresponding to the switching interface request path for access.

[0094] It should be noted that the switching between the computer rooms of two company entities belonging to the same region and the switching between the computer rooms of two company entities belonging to different regions are done in the same way, and the splicing method of the switching interface request path and the new interface request path obtained at login is also the same, that is, the request path part is kept unchanged, and only the access domain name is changed.

[0095] It can be understood that by switching the access domain name, dynamic switching of computer rooms is completed, so that after logging in, users can still switch between two computer rooms in different regions or two computer rooms in the same region for different company entities, making the operation easier.

[0096] Furthermore, before step S10, the method further includes:

[0097] S4: In each computer room, corresponding instruction request paths are set according to different preset request tasks.

[0098] It can be understood that the preset request tasks are different operations on the data of a company entity, such as but not limited to requesting all participant information, requesting company information, executing participant addition operations, executing participant deletion operations, etc., which can be performed after logging into the system. By setting corresponding instruction request paths in each computer room according to different preset request tasks, the overall data tasks are split, so that the data tasks of different data can be independent, thereby avoiding the mutual influence between the interface services of different instruction request paths.

[0099] Furthermore, after step S40, the method further includes:

[0100] S61: responding to a user's instruction triggering operation, and determining an instruction request path according to the instruction triggering operation;

[0101] S62: Combine the target access domain name with the instruction request path to form a trigger request path, and access the trigger request path in the target computer room.

[0102] Specifically, in the interface request at login, the access domain name part is not determined, and the request path part remains unchanged; after logging into the system, the computer room has been determined, and the access domain name part is the target access domain name. At this time, the target access domain name remains unchanged. If the user needs to complete the instruction trigger operation in the system, the corresponding request path part will change. For example, if the user's instruction trigger operation is to request all participant information, the instruction request path pathname is / employee / list; if the user's instruction trigger operation is to request company information, the instruction request path pathname is / corporation / info, etc. This ensures that after login, the domain name part can be kept unchanged to ensure isolation between computer rooms, avoid interference of the domain name part with different request tasks, and ensure that the user only operates in the target computer room.

[0103] It should be noted that by decoupling the interface request, the domain name part and the request path part do not interfere with each other; at login, the request path remains unchanged to avoid interference from other computer rooms’ request paths; after login, the domain name part remains unchanged to avoid interference from the domain name part with different request tasks, thus enabling the computer room to be used in an isolated state during actual use by users, further avoiding interference from other computer rooms with different request tasks. Thus, by keeping the domain name part and the request path part unchanged and changing at login and after login, it is ensured that multiple computer rooms are in an isolated state during the entire user use process, thereby achieving mutual non-interference between computer rooms in different regions, and the failure of a server in one computer room will not affect the use of a server in another computer room. For example, the HK computer room and the BJ computer room do not affect each other, and the failure of a server in the HK computer room will not affect the use of a server in the BJ computer room.

[0104] See also Figure 4 The second embodiment of the present invention provides a multi-computer room data isolation system 1, which is used to implement the multi-computer room data isolation method as described in any one of the first embodiments, including:

[0105] The information acquisition module 10 is used to acquire the login information generated by the user login trigger and initiate an interface request; the login information includes the target computer room information corresponding to the target company entity selected by the user;

[0106] A request decoupling module 20, used to decouple the interface request to form an access domain name part and a request path part;

[0107] A domain name determination module 30, configured to determine a target access domain name of a computer room to which a target company belongs based on the target computer room information;

[0108] The access request module 40 is used to recombine the target access domain name with the request path part to form a new interface request path, and enter the target computer room corresponding to the new interface request path for access.

[0109] It can be understood that the multi-computer room data isolation system 1 is used to implement the multi-computer room data isolation method described in any one of the first embodiments, and has the same beneficial effects as the above-mentioned multi-computer room data isolation method, which will not be described in detail here.

[0110] A third embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the multi-computer room data isolation method as described in any one of the first embodiments is implemented, and has the same beneficial effects as the above-mentioned multi-computer room data isolation method, which will not be elaborated here.

[0111] In the embodiments provided by the present invention, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean determining B only according to A, and B can also be determined according to A and / or other information.

[0112] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. Those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present invention.

[0113] In various embodiments of the present invention, it should be understood that the size of the serial numbers of the above-mentioned processes does not necessarily mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0114] The flow chart and block diagram in the accompanying drawings of the present invention illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, which is determined based on the functions involved. It should be particularly noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs a specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0115] Compared with the prior art, the multi-computer room data isolation method, system and storage medium provided by the present invention have the following advantages:

[0116] 1. The present invention is a multi-computer room data isolation method provided by an embodiment, comprising the following steps: obtaining login information generated by a user login trigger and initiating an interface request; the login information includes the target computer room information corresponding to the target company entity selected by the user; decoupling the interface request to form an access domain name part and a request path part; determining the target access domain name of the computer room to which the target company entity belongs based on the target computer room information; recombining the target access domain name and the request path part to form a new interface request path, and entering the target computer room corresponding to the new interface request path for access. By decoupling the interface request triggered by the user login to form an access domain name part and a request path part, the access domain name part and the request path part do not interfere with each other; and when forming a new interface request path, it is only necessary to recombinate the determined target access domain name with the decoupled request path part to form a new interface request path, that is, when the login is triggered, the target access domain name replaces the original split access domain name part, and the request path part remains unchanged, so that when the login is triggered, only the access domain name needs to be paid attention to, thereby avoiding interference between the request path parts between multiple computer rooms, and thus avoiding problems in one computer room affecting computer rooms in different regions.

[0117] 2. The embodiment of the present invention provides a method of obtaining all different computer room information and the access domain name corresponding to each computer room; storing all different computer room information and the access domain name corresponding to the computer room, so that the target access domain name is obtained from the pre-stored access domain name, rather than temporarily obtained, thereby improving the accuracy of the target access domain name. In addition, the independent storage of different access domain names corresponding to different computer rooms is realized. When a problem occurs in the domain name part of one computer room, it will not affect the domain name part of other computer rooms, thereby achieving non-interference between different computer rooms, and achieving that the failure of each computer room server will not affect the use of other computer room servers.

[0118] 3. The embodiment of the present invention provides a method for obtaining the computer room to which the company entity to be created belongs; one company entity corresponds to one computer room; the current computer room is switched to the computer room to which the company entity to be created belongs; in the computer room corresponding to the computer room to which the company entity to be created belongs, at least one management account corresponding to the company entity to be created is created, thereby realizing the creation of a new company entity and ensuring the accuracy of the computer room corresponding to the newly created company entity.

[0119] 4. The method for obtaining login information generated by a user login trigger provided by an embodiment of the present invention specifically includes: responding to the user's login trigger operation to determine the target company entity selected by the user; determining the corresponding computer room according to the target company entity, and obtaining the target computer room information corresponding to the target company entity, thereby achieving the ability to obtain the computer room information when the user logs in, facilitating more accurate determination of the target access domain name.

[0120] 5. The method provided by the embodiment of the present invention for determining the target access domain name of the computer room to which the target company belongs based on the target computer room information specifically includes: judging the target computer room information against the stored computer room information of all different regions one by one; if the target computer room information is consistent with a stored computer room information, the access domain name corresponding to the computer room information consistent with the target computer room information is used as the target access domain name, thereby achieving the acquisition of the target access domain name from the pre-stored access domain names, thereby avoiding the temporary determination of the target access domain name, and further improving the accuracy of the obtained target access domain name. In addition, since the target access domain name is determined from the pre-stored data, it avoids the problem of the domain name in the determination process, and directly locates the problem of the domain name part directly in the stored access domain name.

[0121] 6. The embodiment of the present invention provides a method for responding to a user's switching operation on a company entity, obtaining the information of the computer room to be switched corresponding to the company entity to be switched; determining the access domain name of the corresponding computer room to be switched based on the information of the computer room to be switched; combining the access domain name of the computer room to be switched with the request path part to form a switching interface request path, and accessing the computer room to be switched corresponding to the switching interface request path. By switching the access domain name, dynamic computer room switching is completed, and after logging in, the user can still switch between computer rooms in different regions and computer rooms in the same region for different company entities, making the operation easier.

[0122] 7. The embodiment of the present invention provides that corresponding instruction request paths are set in each computer room according to different preset request tasks, thereby splitting the overall data tasks and making the data tasks of different data independent, thereby avoiding mutual influence between interface services of different instruction request paths.

[0123] 8. The present invention also provides a multi-computer room data isolation system, which has the same beneficial effects as the above-mentioned multi-computer room data isolation method, and will not be elaborated here.

[0124] 9. A computer-readable storage medium has the same beneficial effects as the above-mentioned multi-computer room data isolation method, which will not be described in detail here.

[0125] The above is a detailed introduction to a multi-computer room data isolation method, system and storage medium disclosed in an embodiment of the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, according to the idea of ​​the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention. Any modifications, equivalent substitutions and improvements made within the principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A multi-computer room data isolation method, characterized by: The following steps are involved: Acquire login information generated by the user login trigger and receive an interface request; the login information includes the target computer room information corresponding to the target company entity selected by the user; Decoupling the interface request to form an access domain name part and a request path part; Determine the target access domain name of the computer room to which the target company belongs based on the target computer room information; The target access domain name and the request path portion are recombined to form a new interface request path, and the target computer room corresponding to the new interface request path is accessed.

2. The multi-computer room data isolation method according to claim 1, characterized in that: Before obtaining the login information generated by the user login trigger and initiating an interface request, it also includes: Obtain information about all different computer rooms and the corresponding access domain name for each computer room; Store all different computer room information and the corresponding access domain names of the computer rooms.

3. The multi-computer room data isolation method according to claim 2, characterized in that: Before obtaining the login information generated by the user login trigger and initiating an interface request, it also includes: Get the computer room to which the company entity to be created belongs; one company entity corresponds to one computer room; Switch the current computer room to the computer room of the company to be created; In the computer room where the company entity to be created belongs, create at least one management account corresponding to the company entity to be created.

4. The multi-computer room data isolation method according to claim 3, characterized in that: Get the login information generated by the user login trigger, including: Respond to the user's login trigger operation and determine the target company entity selected by the user; Determine the corresponding computer room according to the target company entity, and obtain the target computer room information corresponding to the target company entity.

5. The multi-computer room data isolation method according to claim 4, characterized in that: Determining the target access domain name of the computer room to which the target company belongs based on the target computer room information specifically includes: Compare the target computer room information with all the stored computer room information in different regions one by one; If the target computer room information is consistent with a stored computer room information, the access domain name corresponding to the computer room information consistent with the target computer room information is used as the target access domain name.

6. The multi-computer room data isolation method according to claim 2, characterized in that: After the target access domain name and the request path portion are recombined to form a new interface request path, and the target computer room corresponding to the new interface request path is accessed, the method further includes: In response to the user's switching operation on the company entity, obtain the information of the computer room to be switched corresponding to the company entity to be switched; Determine the access domain name of the corresponding computer room to be switched based on the information of the computer room to be switched; The access domain name of the to-be-switched computer room is combined with the request path portion to form a switching interface request path, and the to-be-switched computer room corresponding to the switching interface request path is accessed.

7. The multi-computer room data isolation method according to claim 2, characterized in that: Before obtaining the login information generated by the user login trigger and initiating an interface request, it also includes: In each computer room, corresponding instruction request paths are set according to different preset request tasks.

8. The multi-computer room data isolation method according to claim 7, characterized in that: After entering the target computer room corresponding to the new interface request path for access, the method further includes: Responding to a user's instruction triggering operation, and determining an instruction request path according to the instruction triggering operation; The target access domain name and the instruction request path are combined to form a trigger request path, and the trigger request path is accessed in the target computer room.

9. A multi-computer room data isolation system, used to implement the multi-computer room data isolation method according to any one of claims 1 to 8, characterized in that: include: Information acquisition module, used to obtain login information generated by user login trigger and initiate interface request; The login information includes the target computer room information corresponding to the target company entity selected by the user; A request decoupling module, used to decouple the interface request to form an access domain name part and a request path part; A domain name determination module, used to determine the target access domain name of the computer room to which the target company belongs based on the target computer room information; The access request module is used to recombine the target access domain name and the request path part to form a new interface request path, and enter the target computer room corresponding to the new interface request path for access.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the multi-computer room data isolation method as described in any one of claims 1-8 is implemented.

Citation Information

Patent Citations

  • Policy-based network measurement method, system and measurement machine

    CN107347013A

  • Attack isolation method and system, and data processing method

    CN109660486A