Database Access Method and Related Devices Based on Edge-Cloud System

By deploying enterprise metadata knowledge base, AI model and enterprise database in the end-edge cloud system, and using intelligent proxy and programmatic processing to generate database executable code, the problem of inflexible enterprise database deployment in the existing technology is solved, and efficient and flexible database access and management is achieved.

CN119917578BActive Publication Date: 2025-06-13深圳渊联技术有限公司

Patent Information

Application Number
CN202510415961.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-13
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

The existing technology is difficult to achieve flexible deployment of enterprise databases, resulting in high enterprise costs and high development difficulties.

Method used

By building an end-edge cloud system for terminals, edge gateways and cloud servers, the enterprise metadata knowledge base, AI model and enterprise database are deployed based on customer needs, and local gateways or cloud deployment is adopted. The intelligent agent receives user-entered demand prompt words, and performs programmatic processing through routing processing policies, edge gateways and cloud servers to generate database executable code to access enterprise databases.

Benefits of technology

It reduces the difficulty of development, realizes the flexible deployment of enterprise metadata knowledge base, AI model and enterprise database, improves the adaptability and efficiency of the system, and meets the diversified needs of enterprises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119917578B_ABST
    Figure CN119917578B_ABST
Patent Text Reader

Abstract

The present invention provides a database access method and related devices based on an edge-cloud-end system. The method includes constructing an edge-cloud-end system of a terminal, an edge gateway, and a cloud server; deploying an enterprise metadata knowledge base, an AI model, and an enterprise database in the edge-cloud-end system based on customer requirements; receiving a demand prompt word input by a user through an intelligent agent in the terminal; obtaining a routing policy through the intelligent agent based on the deployment scenarios of the enterprise metadata knowledge base, the AI model, and the enterprise database and with the principle of giving priority to local gateway processing; and programmatically processing the demand prompt word based on the routing processing policy, the edge gateway, and the cloud server. The database access method of the present invention borrows an AI model for code generation, reduces the development difficulty, and the enterprise metadata knowledge base, the AI model, and the enterprise database are flexibly deployed based on customer requirements, and the terminal intelligent agent can flexibly route. The present invention has better adaptability and can better meet the enterprise requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of database technology, and in particular, to a database access method and related devices based on an edge-cloud-end system. Background Art

[0002] With the continuous acceleration of digitalization, digital technology has profoundly changed the way humans think, work, and learn. Through easy-to-use and convenient digital tools, users can quickly obtain data and enable data to better empower business. Currently, in order to better manage and utilize enterprise data, enterprises usually build a database system. However, the construction of an enterprise database is a complex project that requires developers to have professional database knowledge and is difficult to develop. In addition, existing enterprise databases cannot be flexibly deployed to reduce enterprise costs.

[0003] Therefore, the prior art still needs to be improved and developed. Summary of the Invention

[0004] The present invention provides a database access method and related devices based on an edge-cloud-end system. The main purpose of the present invention is to solve the technical problems mentioned in the background art of the prior art.

[0005] The first aspect of the present invention provides a database access method based on an edge-cloud-end system, including:

[0006] Construct an edge-cloud-end system of a terminal, an edge gateway, and a cloud server;

[0007] Deploy an enterprise metadata knowledge base, an AI model, and an enterprise database in the edge-cloud-end system based on customer requirements. The enterprise database is deployed using a local gateway, and the enterprise metadata knowledge base and the AI model are deployed using a local gateway or in the cloud;

[0008] Receive a demand prompt word input by a user through an intelligent agent in the terminal;

[0009] Obtain a routing processing strategy for the demand prompt word through the intelligent agent based on the deployment scenarios of the enterprise metadata knowledge base, the AI model, and the enterprise database and with the criterion of giving priority to local gateway processing;

[0010] Programmatically process the demand prompt word based on the routing processing strategy, the edge gateway, and the cloud server. The programmatic processing includes obtaining a metadata template corresponding to the demand prompt word based on the enterprise metadata knowledge base, inferring database executable code through the AI model based on the metadata template, and accessing the enterprise database based on the database executable code.

[0011] In an alternative embodiment of the first aspect of the present invention, taking the deployment scenario where the enterprise metadata knowledge base and the enterprise database are deployed in the edge gateway and the AI model is deployed in the cloud server, the programmatic processing of the demand prompt word based on the routing processing policy, the edge gateway, and the cloud server includes:

[0012] Send the demand prompt word to the edge gateway and receive the metadata template returned by the edge gateway based on the query of the enterprise metadata knowledge base;

[0013] Send the demand prompt word and the metadata template to the cloud server and receive the database executable code generated by the cloud server based on the AI model;

[0014] Send the database executable code to the edge gateway and receive the database execution result returned by the edge gateway based on the enterprise database.

[0015] In an alternative embodiment of the first aspect of the present invention, the sending the demand prompt word to the edge gateway and receiving the metadata template returned by the edge gateway based on the query of the enterprise metadata knowledge base includes:

[0016] Obtain the request meta-information based on the demand prompt word;

[0017] Construct a template query request based on the request meta-information and the demand prompt word;

[0018] Unify the template query request into the enterprise internal processing format through a pre-set protocol conversion middleware and send it to the edge gateway after lightweight encoding;

[0019] Perform hierarchical retrieval on the template query request by the edge gateway based on the enterprise metadata knowledge base to obtain business metadata, technical metadata, and operation metadata;

[0020] Automatically assemble the business metadata, the technical metadata, and the operation metadata based on the context to obtain a metadata template;

[0021] Receive the metadata template returned by the edge gateway.

[0022] In an alternative embodiment of the first aspect of the present invention, the sending the demand prompt word and the metadata template to the cloud server and receiving the database executable code generated by the cloud server based on the AI model includes:

[0023] Encapsulate the demand prompt word and the metadata template using a serialization protocol to obtain a code acquisition request;

[0024] Perform dynamic protocol conversion on the code acquisition request to obtain a target format that can be processed by the AI model;

[0025] Send the code acquisition request in the target format to the cloud server;

[0026] Match the metadata template with the general metadata knowledge base based on retrieval augmentation generation technology to obtain template parameter fields;

[0027] Use Elasticsearch to build a vector index to obtain semantic parameter fields;

[0028] Input the template parameter fields and the semantic parameter fields into the AI model for multi-submodel collaborative reasoning to obtain database executable code, and the multi-submodels include a code generation submodel, a semantic verification submodel, and a performance optimization submodel.

[0029] In an optional implementation manner of the first aspect of the present invention, the sending the database executable code to the edge gateway and receiving the database execution result returned by the edge gateway based on the enterprise database includes:

[0030] Obtain the device attribute information of the terminal;

[0031] Generate a one-time verification code for the terminal through the PyOTP library;

[0032] Construct a data access request based on the device attribute information, the one-time verification code, and the database executable code;

[0033] Send the data access request to the edge gateway;

[0034] Perform multiple validations on the data access request through the edge gateway, and the multiple validations include static code analysis, code dynamic behavior analysis, and request authentication;

[0035] After the multiple validations pass, run the database executable code in the enterprise database of the edge gateway to obtain the database execution result corresponding to the database executable code.

[0036] In an optional implementation manner of the first aspect of the present invention, the performing multiple validations on the data access request through the edge gateway includes:

[0037] Perform request authentication of the terminal based on the device attribute information and the one-time verification code in the data access request;

[0038] Perform security vulnerability scanning, dependency review, sandbox execution monitoring, and running anomaly detection on the database executable code in the data access request.

[0039] In an alternative embodiment of the first aspect of the present invention, before running the database executable code corresponding to the database executable code in the enterprise database of the edge gateway, the following steps are included:

[0040] Determine whether there is a pseudo-metadata field in the database executable code;

[0041] If there is the pseudo-metadata field in the database executable code, perform real metadata field mapping processing on the pseudo-metadata field by using a preset dictionary matching method.

[0042] The second aspect of the present invention provides a database access device based on an edge-cloud-end system. The database access device based on the edge-cloud-end system includes:

[0043] An edge-cloud-end system construction module, configured to construct an edge-cloud-end system of a terminal, an edge gateway, and a cloud server;

[0044] A database / model deployment module, configured to deploy an enterprise metadata knowledge base, an AI model, and an enterprise database in the edge-cloud-end system based on customer requirements. The enterprise database is deployed using a local gateway, and the enterprise metadata knowledge base and the AI model are deployed using a local gateway or cloud deployment;

[0045] A prompt word input module, configured to receive a demand prompt word input by a user through an intelligent agent in the terminal;

[0046] A routing policy acquisition module, configured to obtain a routing processing policy for the demand prompt word through the intelligent agent based on the deployment situations of the enterprise metadata knowledge base, the AI model, and the enterprise database and with the criterion of giving priority to local gateway processing;

[0047] A programmed processing module, configured to perform programmed processing on the demand prompt word based on the routing processing policy, the edge gateway, and the cloud server. The programmed processing includes obtaining a metadata template corresponding to the demand prompt word based on the enterprise metadata knowledge base, inferring database executable code through the AI model based on the metadata template, and accessing the enterprise database based on the database executable code.

[0048] The third aspect of the present invention provides a database access device based on an edge-cloud-end system. The database access device based on the edge-cloud-end system includes: a memory and at least one processor. Instructions are stored in the memory, and the memory and the at least one processor are interconnected by a line;

[0049] The at least one processor invokes the instructions in the memory to cause the database access device based on the edge-cloud-terminal system to execute the database access method based on the edge-cloud-terminal system according to any one of the above first aspects of the present invention.

[0050] The fourth aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the database access method based on the edge-cloud-terminal system according to any one of the above first aspects of the present invention.

[0051] Beneficial effects: The present invention provides a database access method and related devices based on an edge-cloud-terminal system. The method includes constructing an edge-cloud-terminal system of a terminal, an edge gateway, and a cloud server; deploying an enterprise metadata knowledge base, an AI model, and an enterprise database in the edge-cloud-terminal system based on customer requirements; receiving a demand prompt word input by a user through an intelligent agent in the terminal; obtaining a routing policy through the intelligent agent based on the deployment of the enterprise metadata knowledge base, the AI model, and the enterprise database and with the principle of giving priority to local gateway processing; and programmatically processing the demand prompt word based on the routing processing policy, the edge gateway, and the cloud server. In the database access method of the present invention, an AI model is borrowed for code generation, which reduces the development difficulty, and the enterprise metadata knowledge base, the AI model, and the enterprise database are flexibly deployed based on customer requirements, and the terminal intelligent agent can flexibly route. The present invention has better adaptability and can better meet the enterprise requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 It is a schematic diagram of an embodiment of a database access method based on an edge-cloud-terminal system of the present invention;

[0053] Figure 2 It is a schematic diagram of an embodiment of a simple interaction process between multiple terminals of an edge-cloud-terminal system of the present invention;

[0054] Figure 3 It is a schematic diagram of an embodiment of a database access device based on an edge-cloud-terminal system of the present invention;

[0055] Figure 4 It is a schematic diagram of an embodiment of a database access device based on an edge-cloud-terminal system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0056] In the description of the present invention, the claims, and the above-mentioned drawings, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the term "comprising" or "having" and any variation thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0057] For ease of understanding, the specific process of the embodiments of the present invention will be described below. Please refer to Figure 1 , the first aspect of the present invention provides a database access method based on an edge-cloud-end system, including:

[0058] S100. Build an edge-cloud-end system of a terminal, an edge gateway, and a cloud server; the edge-cloud-end system is a distributed computing architecture that realizes efficient task allocation and collaboration by integrating the resources and capabilities of terminal devices (end), edge gateways (edge), and cloud servers (cloud), thereby optimizing data processing efficiency, reducing latency, and improving the overall performance of the system. Its core lies in dynamically allocating computing loads according to task characteristics (such as real-time performance and complexity), making full use of the advantages of each layer, and building an intelligent and flexible data query network. The present invention precisely utilizes the above characteristics of the edge-cloud-end system.

[0059] S200. Based on customer requirements, deploy an enterprise metadata knowledge base, an AI model, and an enterprise database in the edge-cloud-end system. The enterprise database is deployed using a local gateway, and the enterprise metadata knowledge base and the AI model are deployed using a local gateway or in the cloud. In the present invention, the enterprise metadata knowledge base stores a metadata graph (including table structure, field semantics, and data distribution characteristics). The enterprise metadata knowledge base can be flexibly deployed. For example, according to customer requirements, it can be deployed in an enterprise local AI all-in-one machine (i.e., the edge gateway), or when the customer's own local hardware resources are limited and the confidentiality requirements for enterprise metadata are not very high, the enterprise metadata knowledge base can be deployed in the cloud (i.e., the cloud server). The AI model can also be flexibly deployed. For example, according to customer requirements, it can be deployed in an enterprise local AI all-in-one machine or in the cloud. When the AI model is deployed in an enterprise local AI all-in-one machine, the AI model can be a streamlined AI model for better local operation. To improve the data security of the enterprise database, the enterprise database is deployed using a local gateway, and the enterprise database has a SQL / NoSQL dual-mode parsing engine.

[0060] S300. Receive the requirement prompt words input by the user through the intelligent agent in the terminal. In the present invention, an intelligent agent (AI Agent) is set in the terminal, and the intelligent agent can support roaming in three domains of the production network / office network / Internet. The exemplary process of step S300 of the present invention can be as follows. For example, the user inputs (the methods include input method or voice) the requirement prompt words in the intelligent agent (AI Agent) in the terminal, for example: "Please provide the production order information of yesterday". After receiving the requirement prompt words, the intelligent agent of the present invention will perform routing processing based on the actual deployment situation of the enterprise metadata knowledge base / AI model.

[0061] S400. Based on the deployment situations of the enterprise metadata knowledge base, the AI model, and the enterprise database through the intelligent agent and with the principle of giving priority to local gateway processing, obtain the routing processing strategy of the requirement prompt words. Specifically, in the present invention, the intelligent agent (AI Agent) can select a route through a flexible routing strategy. If the metadata knowledge base is locally deployed in the enterprise (such as an enterprise local AI all-in-one machine), the intelligent agent will preferentially route to the enterprise metadata knowledge base locally deployed in the enterprise, otherwise it will route to the enterprise metadata knowledge base in the cloud, that is, the intelligent agent (AI Agent) deployed on the terminal flexibly routes the enterprise metadata knowledge base according to the actual deployment strategy; similarly, the AI model deployment of the present invention is not necessarily in the cloud, and it may also be deployed in the customer's AI all-in-one machine. If the AI model is locally deployed, it will be preferentially routed to the local AI model for reasoning and summarization. Only when the AI model is not locally deployed or the answer to the question cannot meet the customer's requirements, will it be routed to the cloud AI model for further reasoning and summarization.

[0062] S500. Programatically process the demand prompt word based on the routing processing policy, the edge gateway, and the cloud server. The programmatic processing includes obtaining a metadata template corresponding to the demand prompt word based on the enterprise metadata knowledge base, inferring database executable code through the AI model based on the metadata template, and accessing the enterprise database based on the database executable code. In the present invention, the database executable code may be executable code for adding, deleting, modifying, or querying the database, or other executable code for operating on the database. The routing policy will first determine whether the processing object of the demand prompt word in the policy is sent to the edge gateway or the cloud server for processing to obtain a metadata template. Then, after obtaining the metadata template, it will determine whether the processing object of the metadata template in the policy is sent to the edge gateway or the cloud server for AI model processing to obtain database executable code. Finally, it will determine whether the database executable code in the policy is sent to the edge gateway or the cloud server for enterprise database access operations to obtain the access result of the enterprise database.

[0063] In an alternative implementation manner of the first aspect of the present invention, taking the deployment scenario where the enterprise metadata knowledge base and the enterprise database are deployed on the edge gateway and the AI model is deployed on the cloud server, the programmatic processing of the demand prompt word based on the routing processing policy, the edge gateway, and the cloud server includes:

[0064] S501. Send the demand prompt word to the edge gateway and receive the metadata template returned by the edge gateway based on the query of the enterprise metadata knowledge base. In the present invention, after receiving the demand prompt word, the edge gateway will request a metadata template (including pseudo-field names and data distribution characteristics) from the enterprise metadata knowledge base of the edge gateway. The enterprise metadata knowledge base mainly includes various form definitions of the production management system (such as sales orders, production orders, production work orders, quality inspection sheets), as well as ESOP operation manuals related to customers and specific professional technologies and knowledge related to the enterprise domain. Here, taking the demand prompt word "production order completed today" as an example, after querying the enterprise metadata knowledge base, the main metadata definitions of the production order will be supplemented after this demand prompt word: such as adding metadata table field definitions of key production order fields such as production order number, material code, material name, recording date, and planned number of finished products.

[0065] More specifically, in an alternative implementation manner of step S501 of the present invention, the sending the demand prompt word to the edge gateway and receiving the metadata template returned by the edge gateway based on the query of the enterprise metadata knowledge base includes:

[0066] S5011. Obtain request meta-information based on the demand prompt word. In this step of the present invention, it is to obtain meta-information such as the metadata association identifier (such as device ID, data label), query scope (business / technical / operation metadata), permission token, etc. that the demand prompt word needs to carry.

[0067] S5012. Construct a template query request based on the request meta-information and the demand prompt word. In this step of the present invention, it is to construct a template query request based on the request protocol used between the terminal and the edge gateway.

[0068] S5013. Unify the template query request into an internal processing format of the enterprise through a pre-set protocol conversion middleware and send it to the edge gateway after lightweight encoding. In the present invention, it is to unify the query request into an internal processing format through the protocol conversion middleware. For example, in an industrial scenario, an OPC UA protocol query needs to be converted into a JSON format instruction executable on the edge side, and lightweight encoding (such as CBOR or Protobuf) is used to compress the data volume, which can reduce bandwidth consumption.

[0069] S5014. Perform hierarchical retrieval on the template query request based on the enterprise metadata knowledge base through the edge gateway to obtain business metadata, technical metadata, and operation metadata. In the present invention, business metadata mainly analyzes the query intent based on natural language. For example, it calls a KB Insight class tool to generate semantic vectors and matches the SOP document summary in the knowledge base; technical metadata mainly parses structured metadata (such as data table field types, storage locations) through an SQL query engine and combines with a time series database cache to accelerate the response; operation metadata mainly verifies the user permission level, records access logs, and triggers an audit trail.

[0070] S5015. Automatically assemble the business metadata, the technical metadata, and the operation metadata based on the context to obtain a metadata template. In the present invention, this step mainly automatically assembles a metadata template according to the query context. For example, a device maintenance template needs to integrate technical parameters, historical maintenance records, and associated documents.

[0071] S5016. Receive the metadata template returned by the edge gateway. In the present invention, an intelligent compression strategy can be used during the return process of the metadata template. For example, for unstructured data (such as drawing documents), the LSTM time series compression algorithm (compression ratio 20:1) is adopted, and columnar storage optimization is used for structured data. Security transmission mechanism: For example, the template data is encrypted and transmitted through TLS 1.3. Sensitive fields (such as production process parameters) are desensitized on the edge side, and the national secret SM4 algorithm is used to encrypt the key content. Format standardization: For example, the returned metadata template follows the ISO / IEC 11179 metadata standard and supports dual-format output of JSON / XML to be compatible with business systems such as ERP and MES.

[0072] S502. Send the requirement prompt word and the metadata template to the cloud server, and receive the database executable code generated by the cloud server based on the AI model; in the present invention, after the terminal receives the metadata template returned by the edge gateway, a query request will be initiated to the cloud AI large model through the metadata template. The cloud AI large model performs AI summary and reasoning through the context of the metadata template and the general metadata knowledge base to generate executable code. The implementation process of generating the code mainly utilizes the capabilities of the large model itself. For example, reference learning cases are provided to the AI model in advance to describe the mapping relationship between the key prompt words and the generated executable code. The AI large model will learn these typical cases. Subsequently, when the customer proposes similar key prompt words, relevant executable code will be generated. The specific forms of the executable code are such as SQL scripts, executable exe files, etc. The main purpose of generating these executable scripts is to automatically generate code through AI inference with AI prompt words, eliminating the need for professional programmers to develop corresponding programs, improving production efficiency, and reducing the requirements for people.

[0073] In an optional implementation manner of step S502 of the present invention, the sending the requirement prompt word and the metadata template to the cloud server and receiving the database executable code generated by the cloud server based on the AI model includes:

[0074] S5021. Package the requirement prompt word and the metadata template using a serialization protocol to obtain a code acquisition request. In the present invention, the Protobuf or Avro serialization protocol can be used to package the query request, including metadata such as the metadata template version number, query range (such as time series data filtering conditions), and code generation language type (Python / SQL / Spark).

[0075] S5022. Perform dynamic protocol conversion on the code acquisition request to obtain a target format that can be processed by the AI model. In the present invention, Apache NiFi can be deployed as a protocol conversion middleware, supporting multiple access methods such as MQTT / HTTP / gRPC. For the structured metadata transmitted through the OPC UA protocol in the industrial scenario, it is automatically converted into the JSON Schema format that can be processed by the AI model.

[0076] S5023. Send the code acquisition request in the target format to the cloud server. In this step of the present invention, the TLS 1.3 encrypted transmission channel can also be used to ensure the secure transmission of sensitive query logic.

[0077] S5024. Match the metadata template with the general metadata knowledge base based on the retrieval augmented generation technology to obtain template parameter fields. In this step of the present invention, for example, based on the RAG (retrieval augmented generation) technology, the metadata template submitted by the user can be matched with the cloud knowledge base (such as enterprise data dictionary, API document library). For example, when the template contains the "equipment vibration frequency" field, the technical parameter document of the equipment model is automatically associated as the context.

[0078] S5025. Use Elasticsearch to build a vector index to obtain semantic parameter fields. In this step of the present invention, for example, Elasticsearch can be used to build a vector index to achieve semantic matching of metadata fields (such as the synonym mapping between "device ID" and "equipment_identifier"), improving the accuracy of code generation.

[0079] S5026. Input the template parameter fields and the semantic parameter fields into the AI model for multi-submodel collaborative reasoning to obtain database executable code. The multi-submodels include a code generation submodel, a semantic verification submodel, and a performance optimization submodel. In the present invention, the AI model can adopt a multi-model collaborative reasoning framework. Code generation model: Select Code Llama 70B, which is good at handling complex SQL / Spark code generation tasks, and optimize the inference speed through TensorRT-LLM; Semantic verification model (such as DeepSeek) is responsible for checking the syntax compliance and security risks of the generated code (such as SQL injection vulnerabilities); Performance optimization model: Trained based on historical execution logs, automatically add query cache strategies or index optimization suggestions. The AI model can execute a dynamic code generation strategy, automatically select a code template according to the query type (such as time series query → PromQL template, association query → GraphQL template), fill in dynamic parameters and output, and can collect the query code features generated by each edge node through the cloud to iteratively optimize the domain adaptation ability of the basic model.

[0080] S503. Send the database executable code to the edge gateway and receive the database execution result returned by the edge gateway based on the enterprise database. In the present invention, after receiving the request information containing the database executable code, the edge gateway obtains the query database query script information (i.e., the database executable code) from the message body of the request, then connects to the database, queries the database to obtain the return information of the database. Generally, there are three ways for the edge gateway to return the database execution result in the present invention, including text description, report, echart visualization chart, etc. The output methods of the answer results for different questions will be different.

[0081] In an optional implementation manner of step S503 of the present invention, the sending the database executable code to the edge gateway and receiving the database execution result returned by the edge gateway based on the enterprise database includes:

[0082] S5031. Obtain the device attribute information of the terminal. In the present invention, the device attribute information is mainly used for identity verification when the terminal requests enterprise data. The verification method uses attribute-based access control to verify the device fingerprint, role permissions of the request subject, and allows terminals within a specific IP range to initiate requests.

[0083] S5032. Generate a one-time verification code for the terminal through the PyOTP library. In the present invention, the query of the edge gateway enterprise database information by the terminal is limited to once. After obtaining the query result once, the verification code of the terminal will become invalid to further improve the security of accessing the edge gateway enterprise database information.

[0084] S5033. Construct a data access request based on the device attribute information, the one-time verification code, and the database executable code. In the present invention, the data access request can also be constructed in a serialized encapsulation manner to facilitate the edge gateway to quickly complete the identity verification of the terminal;

[0085] S5034. Send the data access request to the edge gateway. In this step of the present invention, the data access request can be transmitted through a double-encrypted channel of TLS 1.3 + national cipher SM4 to ensure that the data access request is protected against eavesdropping and tampering during transmission.

[0086] S5035. Perform multiple validations on the data access request through the edge gateway. The multiple validations include static code analysis, dynamic code behavior analysis, and request authentication. The main function of this step in the present invention is to verify the legality of the terminal identity and whether there are vulnerabilities in the database executable code. The specific process of the multiple validations can be as follows: perform request authentication of the terminal based on the device attribute information and the one-time verification code in the data access request; perform security vulnerability scanning, dependency review, sandbox execution monitoring, and runtime anomaly detection on the database executable code in the data access request. Among them, for security vulnerability scanning, tools such as integrated CodeQL / SonarQube can be used to detect vulnerabilities such as SQL injection and buffer overflow. Dependency review can automatically check the versions of introduced third-party libraries, compare with the CVE vulnerability database, and block high-risk dependencies. Sandbox execution monitoring: Deploy a lightweight container sandbox at the edge node to block malicious behaviors through system call filtering and resource quota restrictions. Runtime anomaly detection: Monitor process behaviors through eBPF technology to identify high-risk actions such as abnormal file operations and network connections. In the present invention, by performing multiple validations on the database executable code, the impact of AI-generated code on system operation is prevented.

[0087] S5036. After the multiple validations pass, run the database executable code in the enterprise database of the edge gateway to obtain the database execution result corresponding to the database executable code. In the present invention, it should be noted that on the cloud server side of the present invention, the cloud AI large model includes a process of generating abstract executable code based on pseudo-metadata for some information. The main purpose of this process is to improve information security, which is equivalent to desensitizing sensitive information. For example, for a pharmaceutical company, the raw materials of the drug formula are the core confidential information of the enterprise and cannot be made public; the raw materials need to be encrypted. For example, the main raw materials of penicillin drugs, "carbon source" and "inorganic salts", are encrypted through the RSA encryption algorithm or data dictionary mapping. For example, "carbon source" is mapped to "A55A" and "inorganic salts" is mapped to "C9F8", etc. The process of generating abstract executable code based on pseudo-metadata can adopt the data dictionary mapping table method, and this data dictionary is not made public. For example, "carbon source" is mapped to "A55A", and only "A55A" can be seen in the cloud, and the real raw materials cannot be seen.

[0088] Therefore, before running the database executable code corresponding to the database executable code in the enterprise database of the edge gateway in the present invention, it further includes: determining whether there is a pseudo-metadata field in the database executable code; if there is a pseudo-metadata field in the database executable code, perform real metadata field mapping processing on the pseudo-metadata field in a preset dictionary matching manner.

[0089] Generally speaking, the simple interaction process between multiple terminals of the edge-cloud system corresponding to the examples of steps S500 to S503 of the present invention can be as follows Figure 2 As shown, the database access method based on the edge-cloud system of the present invention has the following characteristics:

[0090] 1. An implementation process method for automatically generating code to securely access enterprise database data according to input prompt words in edge-cloud collaboration.

[0091] 2. The enterprise's metadata knowledge base and database are separately deployed. The metadata knowledge base can select a suitable deployment method according to the customer's security and local hardware resources, and can choose to be deployed locally by the enterprise or in the cloud.

[0092] 3. The AI model can also be deployed in the cloud or locally according to the actual needs of the customer. If the customer has high security requirements and sufficient local resources, a lightweight AI model can be deployed locally.

[0093] 4. The AI model can also be deployed in the cloud or locally according to the actual needs of the customer. If the customer has high security requirements and sufficient local resources, a lightweight AI model can be deployed locally.

[0094] 5. The intelligent agent (AI Agent) can intelligently select the cloud AI large model or the local lightweight large model according to the customer's security and accuracy.

[0095] 6. For the enterprise's private return data, the cloud large model cannot directly use the private data for relevant large model data training to ensure the security of the enterprise's private return data. However, it can disguise the metadata (such as encrypting through a key or mapping and disguising through a data dictionary) and send it to the cloud large model, and then replace it with the real metadata locally at the enterprise for corresponding processing.

[0096] 7. The local execution agent performs security checks on the AI production code, such as only allowing queries and not allowing operations such as addition, deletion, and modification. At the same time, it performs sandbox management on the execution code to limit its use of hardware resources within a certain range.

[0097] See Figure 3 , the second aspect of the present invention provides a database access device based on the edge-cloud system. The database access device based on the edge-cloud system includes:

[0098] The edge-cloud system construction module 10 is used to construct an edge-cloud system of a terminal, an edge gateway, and a cloud server;

[0099] A database / model deployment module 20, which is used to deploy an enterprise metadata knowledge base, an AI model, and an enterprise database in the edge-cloud system based on customer requirements. The enterprise database is deployed using a local gateway, and the enterprise metadata knowledge base and the AI model are deployed using a local gateway or cloud deployment;

[0100] A prompt input module 30, which is used to receive a demand prompt word input by a user through an intelligent agent in the terminal;

[0101] A routing policy acquisition module 40, which is used to obtain a routing processing policy for the demand prompt word through the intelligent agent based on the deployment scenarios of the enterprise metadata knowledge base, the AI model, and the enterprise database and with the criterion of giving priority to local gateway processing;

[0102] A programmed processing module 50, which is used to perform programmed processing on the demand prompt word based on the routing processing policy, the edge gateway, and the cloud server. The programmed processing includes obtaining a metadata template corresponding to the demand prompt word based on the enterprise metadata knowledge base, inferring database executable code through the AI model based on the metadata template, and accessing the enterprise database based on the database executable code.

[0103] In an optional implementation manner of the second aspect of the present invention, the programmed processing module includes: a metadata template acquisition sub-module, which is used to send the demand prompt word to the edge gateway and receive the metadata template returned by the edge gateway based on a query of the enterprise metadata knowledge base;

[0104] A database executable code acquisition sub-module, which is used to send the demand prompt word and the metadata template to the cloud server and receive the database executable code generated by the cloud server based on the AI model;

[0105] A database execution result feedback sub-module, which is used to send the database executable code to the edge gateway and receive the database execution result returned by the edge gateway based on the enterprise database.

[0106] In an optional implementation manner of the second aspect of the present invention, the metadata template acquisition sub-module includes:

[0107] A meta-information acquisition unit, which is used to obtain request meta-information based on the demand prompt word;

[0108] A first request construction unit, which is used to construct a template query request based on the request meta-information and the demand prompt word;

[0109] A first request sending unit, configured to unify the template query request into an internal enterprise processing format through a pre-set protocol conversion middleware, and send it to the edge gateway after lightweight encoding;

[0110] A hierarchical retrieval unit, configured to perform hierarchical retrieval on the template query request based on the enterprise metadata knowledge base through the edge gateway, and obtain business metadata, technical metadata, and operation metadata;

[0111] A template obtaining unit, configured to automatically assemble the business metadata, the technical metadata, and the operation metadata based on the context to obtain a metadata template;

[0112] A template receiving unit, configured to receive the metadata template returned by the edge gateway.

[0113] In an optional implementation manner of the second aspect of the present invention, the database executable code obtaining sub-module includes:

[0114] A second request constructing unit, configured to encapsulate the requirement prompt word and the metadata template using a serialization protocol to obtain a code obtaining request;

[0115] A format conversion unit, configured to perform dynamic protocol conversion on the code obtaining request to obtain a target format processable by the AI model;

[0116] A second request sending unit, configured to send the code obtaining request in the target format to the cloud server;

[0117] A template parameter field obtaining unit, configured to match the metadata template with a general metadata knowledge base based on retrieval enhancement generation technology to obtain a template parameter field;

[0118] A semantic parameter field obtaining unit, configured to construct a vector index using Elasticsearch to obtain a semantic parameter field;

[0119] An AI code inference unit, configured to input the template parameter field and the semantic parameter field into the AI model for multi-submodel collaborative inference to obtain database executable code, and the multi-submodels include a code generation submodel, a semantic verification submodel, and a performance optimization submodel.

[0120] In an optional implementation manner of the second aspect of the present invention, the database execution result feedback sub-module includes:

[0121] A device attribute information obtaining unit, configured to obtain the device attribute information of the terminal;

[0122] A one-time verification code obtaining unit, configured to generate a one-time verification code for the terminal through the PyOTP library;

[0123] A third request construction unit, configured to construct a data access request based on the device attribute information, the one-time verification code, and the database executable code;

[0124] A third request sending unit, configured to send the data access request to the edge gateway;

[0125] A multiple verification unit, configured to perform multiple verifications on the data access request through the edge gateway, where the multiple verifications include static code analysis, code dynamic behavior analysis, and request authentication;

[0126] A code execution unit, configured to run the database executable code in the enterprise database of the edge gateway after the multiple verifications are passed, to obtain a database execution result corresponding to the database executable code.

[0127] In an optional implementation manner of the second aspect of the present invention, the multiple verification unit includes:

[0128] An authentication subunit, configured to perform request authentication of the terminal based on the device attribute information and the one-time verification code in the data access request;

[0129] A code verification subunit, configured to perform security vulnerability scanning, dependency review, sandbox execution monitoring, and running anomaly detection on the database executable code in the data access request.

[0130] In an optional implementation manner of the second aspect of the present invention, the database execution result feedback sub-module further includes:

[0131] A code field judgment unit, configured to judge whether there is a pseudo metadata field in the database executable code;

[0132] A field mapping conversion unit, configured to, if there is the pseudo metadata field in the database executable code, perform real metadata field mapping processing on the pseudo metadata field by using a preset dictionary matching method.

[0133] Figure 4FIG. 0 is a schematic structural diagram of a database access device based on an edge-cloud-end system provided by an embodiment of the present invention. The database access device based on the edge-cloud-end system may vary greatly due to configuration or performance differences, and may include one or more processors 60 (central processing units, CPUs) (for example, one or more processors) and a memory 70, and one or more storage media 80 (for example, one or more mass storage devices) for storing applications or data. Among them, the memory and the storage media may be transient storage or persistent storage. The programs stored in the storage media may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the database access device based on the edge-cloud-end system. Further, the processor may be configured to communicate with the storage media and execute a series of instruction operations in the storage media on the database access device based on the edge-cloud-end system.

[0134] The database access device based on the edge-cloud-end system of the present invention may further include one or more power supplies 90, one or more wired or wireless network interfaces 100, one or more input / output interfaces 110, and / or one or more operating systems, such as Windows Serve, Mac OS X, Unix, Linux, FreeBSD, and so on. Those skilled in the art can understand that Figure 4 The shown structural diagram of the database access device based on the edge-cloud-end system does not constitute a limitation on the database access device based on the edge-cloud-end system, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0135] The present invention also provides a computer-readable storage medium, which may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium, and when the instructions run on a computer, the computer is caused to execute the steps of the database access method based on the edge-cloud-end system.

[0136] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described system or system and unit can refer to the corresponding processes in the foregoing method embodiments and will not be described herein again.

[0137] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0138] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A database access method based on a device-edge-cloud system, characterized in that: include: Build an end-edge-cloud system of terminals, edge gateways, and cloud servers; Based on customer needs, the enterprise metadata knowledge base, AI model and enterprise database are deployed in the edge-cloud system. The enterprise database is deployed using a local gateway, and the enterprise metadata knowledge base and AI model are deployed using a local gateway or in the cloud. Receiving a demand prompt word input by a user through the intelligent agent in the terminal; Obtaining, by the intelligent agent, a routing processing strategy for the demand prompt word based on the enterprise metadata knowledge base, the AI ​​model, and the deployment situation of the enterprise database and taking local gateway processing as a priority; Based on the routing processing strategy, the edge gateway and the cloud server, the demand prompt word is processed programmatically, wherein the programmatic processing includes obtaining a metadata template corresponding to the demand prompt word based on the enterprise metadata knowledge base, obtaining a database executable code based on the metadata template and through the AI ​​model reasoning, and accessing the enterprise database based on the database executable code; In the deployment scenario where the enterprise metadata knowledge base and the enterprise database are deployed on the edge gateway, and the AI ​​model is deployed on the cloud server, the programmatic processing of the demand prompt words based on the routing processing strategy, the edge gateway and the cloud server includes: sending the demand prompt words to the edge gateway, and receiving the metadata template returned by the edge gateway based on the enterprise metadata knowledge base query; sending the demand prompt words and the metadata template to the cloud server, and receiving the database executable code generated by the cloud server based on the AI ​​model; sending the database executable code to the edge gateway, and receiving the database execution result returned by the edge gateway based on the enterprise database; The sending of the database executable code to the edge gateway and receiving the database execution result returned by the edge gateway based on the enterprise database includes: obtaining the device attribute information of the terminal; generating a one-time verification code of the terminal through the PyOTP library; constructing a data access request based on the device attribute information, the one-time verification code and the database executable code; sending the data access request to the edge gateway; performing multiple verifications on the data access request through the edge gateway, the multiple verifications including static code analysis, code dynamic behavior analysis and request identity authentication; after the multiple verifications are passed, running the database executable code in the enterprise database of the edge gateway to obtain the database execution result corresponding to the database executable code.

2. The database access method based on the end-edge cloud system according to claim 1, characterized in that: The sending of the demand prompt word to the edge gateway and receiving the metadata template returned by the edge gateway based on the enterprise metadata knowledge base query includes: Obtaining request meta information based on the demand prompt word; Constructing a template query request based on the request meta information and the demand prompt word; The template query request is unified into an enterprise internal processing format through a preset protocol conversion middleware and sent to the edge gateway after lightweight encoding; Performing a hierarchical search on the template query request based on the enterprise metadata knowledge base through the edge gateway to obtain business metadata, technical metadata and operation metadata; Automatically assembling the business metadata, the technical metadata, and the operation metadata based on context to obtain a metadata template; Receive the metadata template returned by the edge gateway.

3. The database access method based on the end-edge cloud system according to claim 2 is characterized in that: The sending of the demand prompt word and the metadata template to the cloud server and receiving the database executable code generated by the cloud server based on the AI ​​model includes: The requirement prompt word and the metadata template are encapsulated using a serialization protocol to obtain a code acquisition request; Dynamically convert the code acquisition request to a target format that can be processed by the AI ​​model; Sending the code acquisition request in the target format to the cloud server; Matching the metadata template with a general metadata knowledge base based on a search enhancement generation technology to obtain a template parameter field; Use Elasticsearch to build a vector index and obtain semantic parameter fields; The template parameter field and the semantic parameter field are input into the AI ​​model for multi-sub-model collaborative reasoning to obtain database executable code, wherein the multi-sub-model includes a code generation sub-model, a semantic verification sub-model and a performance optimization sub-model.

4. The method for accessing a database based on a device-edge-cloud system according to claim 1, characterized in that: The performing multiple verifications on the data access request by the edge gateway includes: Performing identity authentication of the terminal based on the device attribute information and the one-time verification code in the data access request; The database executable code in the data access request is scanned for security vulnerabilities, reviewed for dependencies, monitored for sandbox execution, and detected for operational anomalies.

5. The method for accessing a database based on a device-edge-cloud system according to claim 1, characterized in that: Before the enterprise database of the edge gateway runs the database executable code corresponding to the database executable code, the process includes: Determining whether there is a pseudo metadata field in the database executable code; If the pseudo metadata field exists in the database executable code, the pseudo metadata field is mapped to the real metadata field by using a preset dictionary matching method.

6. A database access device based on a terminal-edge-cloud system, characterized in that: The database access device based on the end-edge cloud system includes: The device-edge-cloud system building module is used to build the device-edge-cloud system of terminals, edge gateways, and cloud servers; A database / model deployment module, which is used to deploy an enterprise metadata knowledge base, an AI model, and an enterprise database in the edge-cloud system based on customer needs. The enterprise database is deployed using a local gateway, and the enterprise metadata knowledge base and the AI ​​model are deployed using a local gateway or in the cloud. A prompt word input module, used for receiving a demand prompt word input by a user through an intelligent agent in the terminal; A routing strategy acquisition module, used to obtain the routing processing strategy of the demand prompt word through the intelligent agent based on the enterprise metadata knowledge base, the AI ​​model and the deployment situation of the enterprise database and taking local gateway processing as the priority criterion; A program processing module, used for performing program processing on the demand prompt word based on the routing processing strategy, the edge gateway and the cloud server, wherein the program processing includes obtaining a metadata template corresponding to the demand prompt word based on the enterprise metadata knowledge base, obtaining a database executable code based on the metadata template and through the AI ​​model reasoning, and accessing the enterprise database based on the database executable code; The programmed processing module includes: a metadata template acquisition submodule, which is used to send the demand prompt word to the edge gateway and receive the metadata template returned by the edge gateway based on the enterprise metadata knowledge base query; A database executable code acquisition submodule, used to send the demand prompt word and the metadata template to the cloud server, and receive the database executable code generated by the cloud server based on the AI ​​model; A database execution result feedback submodule, used to send the database executable code to the edge gateway and receive the database execution result returned by the edge gateway based on the enterprise database; The database execution result feedback submodule includes: A device attribute information acquisition unit, used to acquire device attribute information of the terminal; A one-time verification code acquisition unit, used to generate a one-time verification code of the terminal through a PyOTP library; A third request construction unit, configured to construct a data access request based on the device attribute information, the one-time verification code and the database executable code; A third request sending unit, configured to send the data access request to the edge gateway; A multiple verification unit, used to perform multiple verifications on the data access request through the edge gateway, wherein the multiple verifications include static code analysis, code dynamic behavior analysis, and request identity verification; A code execution unit is used to run the database executable code in the enterprise database of the edge gateway after the multiple verifications are passed, and obtain a database execution result corresponding to the database executable code.

7. A database access device based on an edge-cloud system, characterized in that: The database access device based on the end-edge cloud system includes: a memory and at least one processor, the memory stores instructions, and the memory and the at least one processor are interconnected via a line; The at least one processor calls the instructions in the memory so that the database access device based on the edge-cloud system executes the database access method based on the edge-cloud system as described in any one of claims 1-5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the database access method based on the end-edge cloud system as described in any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Chart generation method and device, equipment and storage medium

    CN117931929A

  • IoT security knowledge-based chatbot system

    US20250077511A1

Cited By

  • AI model dynamic fragmentation deployment and incremental updating method based on intelligent gateway

    CN121664653A