Object storage service system based on bucket backup
By using automatic synchronous replication of data between the main storage module and the backup bucket module in the object storage service system, the problem that a single bucket mechanism cannot meet the continuous availability of data is solved, and the dual guarantee and high availability of data is achieved, ensuring data security and recoverability.
Patent Information
- Application Number
- CN202510118518.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The adoption of a single bucket mechanism in the prior art cannot meet the user's requirements for continuous data availability, especially in the event of a failure of the main bucket, which may lead to data loss or service interruption.
An object storage service system based on bucket backup is designed. Through automatic synchronous replication of data between the main storage module and the backup bucket module, redundant data storage is realized. When a storage module has problems, data is obtained from another storage module, providing double guarantees for the data.
It improves the continuous availability of the system and data recovery, ensures the security of data during transmission, prevents data loss or tampering, and protects the user's data security.
Smart Images

Figure CN119987676A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data storage transmission technology, and in particular to an object storage service system based on storage bucket backup. Background Art
[0002] As the amount of data continues to grow and the value of data becomes increasingly prominent, the requirements for object storage services are also getting higher and higher. On the one hand, users need storage services to have high availability to ensure that data is accessible at any time and to avoid service interruptions due to system failures; on the other hand, data security has become a top priority, and preventing data leakage, tampering, and loss is a problem that enterprises and organizations must solve. In a complex network environment, how to efficiently manage and schedule data transmission links to ensure the stability and efficiency of data transmission is also one of the challenges facing object storage services.
[0003] Traditional object storage service systems have many shortcomings when facing the above challenges. In particular, some systems use a single bucket mechanism. When the primary bucket fails, it may cause data loss or service interruption, which cannot meet users' requirements for continuous data availability. Summary of the invention
[0004] In view of the problem that the single storage bucket mechanism used in the prior art cannot meet the user's demand for continuous data availability, the present invention provides an object storage service system based on storage bucket backup, which can provide double protection for data and improve the continuous availability and recoverability of data in the system. The specific technical solution is as follows:
[0005] An object storage service system based on storage bucket backup includes:
[0006] The user end is used to send a write request to the system when the user needs to store data, and send a read request to the system when the user needs to read stored data;
[0007] The link selection and switching module is used to monitor the status of each link in real time and select and switch links according to the monitoring results;
[0008] The main storage module is used to receive the data storage requirements generated by the main write link to store data, and automatically and synchronously copy the stored data to the backup storage bucket module through intranet encrypted transmission;
[0009] The backup storage bucket module is used to receive the data storage requirements generated by the backup write link to store data, and automatically and synchronously copy the stored data to the main storage bucket module through intranet encrypted transmission;
[0010] The data security module is used to decrypt the encrypted data at the data sending end and feed the decrypted data back to the data receiving end.
[0011] Preferably, an object storage service system based on storage bucket backup also includes:
[0012] The cloud storage service client is used to store data for the data storage needs generated by the backup write link, and automatically synchronizes and copies the stored data to the primary storage bucket through VPN encrypted transmission.
[0013] Preferably, an object storage service system based on storage bucket backup also includes:
[0014] The CDN node module is used to cache data from the primary storage bucket module, the backup storage bucket module or the cloud storage service end, receive data access requests from the user end, and send the corresponding data to the user end.
[0015] Preferably, the link selection and switching module monitors the status of each link in real time, and selects and switches the link according to the monitoring result, including:
[0016] Real-time monitoring of the performance indicators of each link, including latency, packet loss rate, and bandwidth utilization;
[0017] Detect the signal strength and connection status of each write link and whether it reaches a preset threshold;
[0018] Based on the monitoring data of each link, determine whether the current link meets the preset quality requirements, and select the optimal link to switch to as the target link.
[0019] Preferably, the determining whether the current link meets the preset quality requirement and selecting the optimal link to switch as the target link includes:
[0020] If it is determined that the default primary write link does not meet the preset quality requirements, the current link is determined to be unavailable, and the backup write link is automatically switched to the target link.
[0021] Preferably, the backup storage bucket module is used to:
[0022] When the quality requirement of the primary write link corresponding to the primary storage bucket module is not met, the data storage demand generated by the backup write link is received to store data, and the stored data is automatically and synchronously copied to the primary storage bucket module through intranet encrypted transmission.
[0023] Preferably, the data security module decrypts the encrypted data of the data sending end and feeds back the decrypted data to the data receiving end, including:
[0024] The data security module receives a key encryption request from the main storage bucket module through the intranet, encrypts the key and feeds it back to the main storage bucket module;
[0025] The primary storage bucket module sends the encrypted key to the backup storage bucket module via the intranet, and the backup storage bucket module sends the encrypted key to the data security module for decryption;
[0026] The data security module returns the decrypted key to the backup storage bucket module.
[0027] Preferably, the data security module decrypts the encrypted data of the data sending end and feeds back the decrypted data to the data receiving end, including:
[0028] The data security module receives a key encryption request from the backup storage bucket module through the intranet, encrypts the key and feeds it back to the backup storage bucket module;
[0029] The backup storage bucket module sends the encrypted key to the primary storage bucket module via the intranet, and the primary storage bucket module sends the encrypted key to the data security module for decryption;
[0030] The data security module returns the decrypted key to the main storage bucket module.
[0031] Preferably, the data security module decrypts the encrypted data of the data sending end and feeds back the decrypted data to the data receiving end, including:
[0032] The data security module receives a key encryption request from the cloud storage service client through the VPN, encrypts the key and feeds it back to the cloud storage service client;
[0033] The cloud storage service client sends the encrypted key to the main storage bucket module through VPN, and the main storage bucket module sends the encrypted key to the data security module for decryption;
[0034] The data security module returns the decrypted key to the main storage bucket module.
[0035] Preferably, the receiving a data access request from a user terminal and sending corresponding data to the user terminal includes:
[0036] After receiving the data access request from the user terminal, the CDN node module sends a verification request to the data security platform; after the data security platform successfully verifies, it returns a verification result table to the CDN node module;
[0037] The CDN node module returns the acquired permission information / changed permission information to the user terminal, and the user terminal successfully accesses the corresponding data.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] The object storage service system based on storage bucket backup of the present invention utilizes the data between the main storage module and the backup storage bucket module to be automatically synchronized and replicated through intranet encrypted transmission, which not only realizes redundant storage of data, but also ensures that the data can be obtained from another storage module when a problem occurs in the main storage module or the backup storage bucket module, providing double protection for the data, further improving the continuous availability of the system and the recoverability of the data. At the same time, the encryption transmission method between different storage buckets ensures the security of data during transmission between storage buckets, prevents data from being stolen or tampered with during transmission, and protects the data security of users. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following is a brief introduction to the drawings required for the specific embodiments or the description of the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn according to the actual scale.
[0041] Figure 1 This is a schematic diagram of an object storage service system based on storage bucket backup according to the present invention.
[0042] Figure 2 A schematic diagram of an object storage service system based on storage bucket backup according to an embodiment of the present invention.
[0043] Figure 3 A schematic diagram of an object storage service system based on storage bucket backup according to an embodiment of the present invention.
[0044] Figure 4 A schematic diagram of an object storage service system based on storage bucket backup according to an embodiment of the present invention.
[0045] Figure 5 A schematic diagram of an object storage service system based on storage bucket backup according to an embodiment of the present invention. DETAILED DESCRIPTION
[0046] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0047] It should be understood that when used in this specification and the appended claims, the terms "include" and "comprises" indicate the presence of described features, integers, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or combinations thereof.
[0048] It should also be understood that the terms used in the present specification are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include plural forms.
[0049] It should be further understood that the term "and / or" used in the present description and the appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0050] See the following examples Figures 1 to 5 .
[0051] The embodiment of the present application provides an object storage service system based on storage bucket backup, including a user end, a link selection switching module, a primary storage module, a backup storage bucket module and a data security module;
[0052] The user end is used to send a write request to the system when the user needs to store data, and send a read request to the system when the user needs to read stored data;
[0053] The link selection and switching module is used to monitor the status of each link in real time and select and switch links according to the monitoring results;
[0054] The main storage module is used to receive the data storage requirements generated by the main write link to store data, and automatically and synchronously copy the stored data to the backup storage bucket module through intranet encrypted transmission;
[0055] The backup storage bucket module is used to receive the data storage requirements generated by the backup write link to store data, and automatically and synchronously copy the stored data to the main storage bucket module through intranet encrypted transmission;
[0056] The data security module is used to decrypt the encrypted data at the data sending end and feed the decrypted data back to the data receiving end.
[0057] In this embodiment, the user end serves as an interface for the user to interact with the system and is the initiator of the user's data storage needs and the need to read stored data. When the user needs to store data in the system, the user end will encapsulate the demand into a write request and send it to the system. The write request contains the data to be stored and related metadata, such as the type, size, storage location preference and other information of the data. When the user needs to read the stored data from the system, the user end will send a read request to the system. The read request contains the unique identifier or keyword of the data that the user wants to read.
[0058] The link selection and switching module monitors various status indicators of the main write link and the backup write link in real time, including but not limited to the link bandwidth occupancy, link delay, link packet loss rate, link connectivity, etc. By continuously sending detection packets or receiving link feedback information, the health status of the link can be timely grasped. According to the results of link monitoring, when the main write link performance degrades or fails, the write request will be automatically switched to the backup write link. For example, if the data access of the main storage module is normal but the performance of the main write link is poor, the backup link will be selected to read the data, and the user end and other related modules will be notified of the link switching status to ensure the continuity of data transmission. The link selection and switching module ensures that the user's write requests and read requests can continue to be processed, avoids service interruptions caused by link problems, and ensures business continuity.
[0059] The main storage module receives the write request (write request of the main write link) forwarded by the link selection switching module and performs storage operations on the data in the request. The data is stored on its internal storage medium, which can be a hard disk, flash memory or other storage device. Depending on the organization of the data, the data may be stored in different storage buckets or partitions, and a unique storage address or identifier will be assigned to the data to facilitate subsequent retrieval and management.
[0060] The stored data is automatically synchronized and copied to the backup bucket module through intranet encrypted transmission. When synchronizing data, encryption algorithms are used to encrypt the data to ensure the security of the data during transmission.
[0061] The backup storage bucket module receives the write request (write request of the backup write link) forwarded by the link selection switching module and stores the data in its own storage device. Its storage operation is similar to that of the main storage module.
[0062] The stored data is automatically synchronized and copied to the main storage bucket module through intranet encrypted transmission. The synchronization process also follows the principle of encrypted transmission, which is similar to the process of synchronizing data from the main storage module to it, further improving data security.
[0063] The data security module decrypts the encrypted data of the data sending end (which can be the main storage module or the backup storage bucket module) and feeds the decrypted data back to the data receiving end, ensuring that only the authorized data receiving end can obtain the correct plaintext data, playing an important role in security protection at both ends of data transmission. At the same time, the decryption operation within the system can ensure that the data remains encrypted when it is used and stored, preventing internal data leakage.
[0064] The object storage service system based on storage bucket backup of the present invention utilizes the data between the main storage module and the backup storage bucket module to be automatically synchronized and replicated through intranet encrypted transmission, which not only realizes redundant storage of data, but also ensures that the data can be obtained from another storage module when a problem occurs in the main storage module or the backup storage bucket module, providing double protection for the data, and further improving the continuous availability of the system and the recoverability of the data. At the same time, encrypted transmission is used between different storage buckets to ensure the security of data during transmission between storage buckets, prevent data from being stolen or tampered with during transmission, and protect user data security. In addition, through the effective management of the link by the link selection switching module, user requests can be allocated according to the link status, so as to realize the rational use of link resources and optimize the network resource configuration of the system.
[0065] Specifically, in a preferred implementation of the present application, an object storage service system based on storage bucket backup further includes:
[0066] The cloud storage service client is used to store data for the data storage needs generated by the backup write link, and automatically synchronizes and copies the stored data to the primary storage bucket through VPN encrypted transmission.
[0067] In this embodiment, the cloud storage service end can be the cloud storage service end within the enterprise, or it can be a cloud storage server rented or purchased from other vendors. By introducing cloud storage service ends from other vendors, redundant data of the storage backup link can be increased, and the cloud vendor and the second storage bucket configure the back-to-source strategy; in extreme cases, when both the primary storage bucket module and the backup storage bucket module are unable to connect at the same time, the primary storage bucket module can pull data from the storage backup link of the cloud vendor. The security and integrity of the object storage service is guaranteed.
[0068] See also Figure 4 The data security module decrypts the encrypted data of the data sending end and feeds the decrypted data back to the data receiving end, including:
[0069] The data security module receives a key encryption request from the cloud storage service client through the VPN, encrypts the key and feeds it back to the cloud storage service client;
[0070] The cloud storage service client sends the encrypted key to the main storage bucket module through VPN, and the main storage bucket module sends the encrypted key to the data security module for decryption;
[0071] The data security module returns the decrypted key to the main storage bucket module.
[0072] In this embodiment, VPN is used to request and transmit keys. During the entire key transmission process, VPN provides a secure channel to ensure that the keys are not stolen or tampered with during network transmission, thereby protecting the confidentiality and integrity of the keys. In a public network environment, the encryption feature of VPN can prevent the acquisition of keys through network monitoring, thereby avoiding security risks caused by key leakage. At the same time, the operations of encrypting, transmitting and decrypting keys provide stronger security for data storage and access in the system. Through the complex key processing process, the risk of illegal access to data is reduced. Even if the attacker obtains part of the encrypted data, the data cannot be decrypted because the correct key cannot be obtained, thereby ensuring the security of the data stored in the main storage bucket module. The collaboration between the data security module, the cloud storage service client and the main storage bucket module ensures the secure exchange and use of keys, thereby improving the security and reliability of the entire object storage service system.
[0073] Specifically, in a preferred implementation of the present application, an object storage service system based on storage bucket backup further includes:
[0074] The CDN node module is used to cache data from the primary storage bucket module, the backup storage bucket module or the cloud storage service end, receive data access requests from the user end, and send the corresponding data to the user end.
[0075] In specific implementations, when caching data, the CDN node module can store it according to a preset strategy, such as based on factors such as the popularity of the data (i.e., the frequency with which the data is accessed by users), the type of data, or the size of the data. The CDN node module will update the data in the cache periodically or based on specific events to ensure the timeliness of the cached data. Active updates can be set, that is, periodically checking with the source end (primary storage bucket module, backup storage bucket module, or cloud storage service end) to see if the data has been updated; passive updates can also be set, and when the data requested by the user is not in the cache or the data is expired, the latest data is obtained from the source end.
[0076] See also Figure 5 , the receiving a data access request from a user terminal and sending corresponding data to the user terminal includes:
[0077] After receiving the data access request from the user terminal, the CDN node module constructs an information summary based on the MAC verification code stored in itself and sends a verification request to the data security platform; after the data security platform successfully verifies the MAC code, it returns a verification result table to the CDN node module;
[0078] The CDN node module returns the acquired permission information / changed permission information to the user terminal, and the user terminal successfully accesses the corresponding data.
[0079] In specific implementation, when the CDN node module receives a data access request from the user, it will not process the request directly, but first send a verification request to the data security platform. This verification request may contain necessary information related to the user's access request, such as the user's identity information, the data requested for access, and possible timestamps, so that the data security platform can conduct a comprehensive legality check on the user's access.
[0080] For example, when a user sends a request to access a video file, the CDN node module will pass the request information and the user's identity information to the data security platform and request the data security platform to verify it.
[0081] After receiving the verification request, the data security platform will check the user's access according to the preset security rules and policies. These rules may include whether the user has the authority to access the data, whether the user's access is within the allowed time range, whether the user's access frequency is abnormal, etc.
[0082] For example, the data security platform checks whether the user is logged in, whether the user has permission to access the video file, and whether the user's request complies with the system's access frequency limit to prevent malicious access or abuse.
[0083] If the verification is successful, the data security platform will return the verification result table to the CDN node module. This verification result table may contain detailed user permission information, such as the data range accessible to the user, the user's access level, and the allowed operations (such as reading, writing, and modifying).
[0084] After receiving the verification result table, the CDN node module will return the obtained permission information or the permission information changed as needed to the user end.
[0085] Through the verification of the data security platform, the system can ensure that only legitimate users can access the corresponding data, prevent unauthorized users from obtaining or tampering with the data, and protect the security and privacy of the data. It can also identify and prevent malicious user attacks, such as DDoS attacks or brute force cracking, by checking the user's access frequency and time range.
[0086] At the same time, the user end can provide users with clear access prompts based on the returned permission information, such as displaying a list of resources accessible to users, guiding users to perform permission upgrade operations, etc., thereby improving the user experience.
[0087] Through the permission management of the data security platform, it is convenient to control the access rights of different users, have stronger control over the resource use and service provision of the system, and ensure that the system operates according to the expected rules. By setting the data access processing method in this embodiment, it is possible to ensure the smoothness of user data access while ensuring the system's data security and reasonable management of user permissions, making the object storage service system based on bucket backup more secure and reliable.
[0088] Specifically, in a preferred implementation of the present application, the link selection and switching module monitors the status of each link in real time, and selects and switches the link according to the monitoring result, including:
[0089] Real-time monitoring of the performance indicators of each link, including latency, packet loss rate, and bandwidth utilization;
[0090] Detect the signal strength and connection status of each write link and whether it reaches a preset threshold;
[0091] Based on the monitoring data of each link, determine whether the current link meets the preset quality requirements, and select the optimal link to switch to as the target link.
[0092] Specifically, the determining whether the current link meets the preset quality requirement and selecting the optimal link to switch as the target link includes:
[0093] If it is determined that the default primary write link does not meet the preset quality requirements, the current link is determined to be unavailable, and the backup write link is automatically switched to the target link.
[0094] The system automatically monitors link quality and dynamically adjusts link usage based on link performance, avoiding the main write link from being in a poor state and affecting system performance, while also making reasonable use of backup write link resources. When a problem occurs in the main write link, the backup write link can be activated as a backup resource, achieving dynamic resource allocation and improving system resource utilization.
[0095] Specifically, the backup storage bucket module is used to:
[0096] When the quality requirement of the primary write link corresponding to the primary storage bucket module is not met, the data storage demand generated by the backup write link is received to store data, and the stored data is automatically and synchronously copied to the primary storage bucket module through intranet encrypted transmission.
[0097] When the primary write link does not meet the quality requirements and the demand for storing data is switched to the backup write link, the backup storage bucket module begins to receive data storage requirements and store data. At the same time, it automatically and synchronously copies the stored data to the primary storage bucket module through intranet encrypted transmission, which implements a dual backup mechanism for data. For example, when the data in the primary storage bucket module is lost or damaged (such as a hardware failure on the server where the primary storage bucket is located), the data can be restored from the backup storage bucket, providing reliable backup protection for the data and reducing the risk of data loss.
[0098] See also Figure 2 Specifically, in a preferred implementation of the present application, the data security module decrypts the encrypted data of the data sending end, and feeds back the decrypted data to the data receiving end, including:
[0099] The data security module receives a key encryption request from the main storage bucket module through the intranet, encrypts the key and feeds it back to the main storage bucket module;
[0100] The primary storage bucket module sends the encrypted key to the backup storage bucket module via the intranet, and the backup storage bucket module sends the encrypted key to the data security module for decryption;
[0101] The data security module returns the decrypted key to the backup storage bucket module;
[0102] Also, see Figure 3 The data security module decrypts the encrypted data of the data sending end and feeds the decrypted data back to the data receiving end, and further includes:
[0103] The data security module receives a key encryption request from the backup storage bucket module through the intranet, encrypts the key and feeds it back to the backup storage bucket module;
[0104] The backup storage bucket module sends the encrypted key to the primary storage bucket module via the intranet, and the primary storage bucket module sends the encrypted key to the data security module for decryption;
[0105] The data security module returns the decrypted key to the main storage bucket module.
[0106] In the specific implementation, for the encrypted data sent by the data sending end (including the main storage bucket module and the backup storage bucket module), the data security module is responsible for decrypting it and feeding back the decrypted data to the data receiving end. The data security module receives encrypted data from the main storage bucket module or the backup storage bucket module. Use the corresponding decryption algorithm to restore the encrypted data to the original plaintext data. The decrypted plaintext data is securely transmitted to the data receiving end to ensure that only the authorized data receiving end can obtain it. Through the encryption, transmission and decryption operations of the key, its security can be ensured even if the key is transmitted between the main storage bucket module and the backup storage bucket module. Since the key is the key to data encryption and decryption, protecting the key can prevent unauthorized users from obtaining and using the key to crack the encrypted data, greatly enhancing the system's ability to protect data.
[0107] In addition, for the data stored in the main storage bucket module and the backup storage bucket module, as well as the data transmitted between them, the operation of the data security module ensures that the data is always in an encrypted state and will not be decrypted until it is used by a legitimate user or module, which provides end-to-end security protection for the data, and guarantees its confidentiality and integrity throughout the entire process from data storage to transmission; when a system failure occurs (such as partial storage device failure, link problem, etc.), the encrypted data and securely managed keys can ensure the security of the data during the recovery process. Even if part of the data or keys are lost, they will not be easily leaked because they are in an encrypted state, providing security for the system's data recovery.
[0108] Those of ordinary skill in the art will appreciate that the units of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0109] In the embodiments provided by the present invention, it should be understood that the division of units is only a logical function division, and there may be other division methods in actual implementation, for example, multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored, etc.
[0110] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0111] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-0nlyMemory), random access memory (RAM, RandomAccessMemory), mobile hard disk, magnetic disk or optical disk, etc., which can store program code.
[0112] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. These modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention.
Claims
1. An object storage service system based on bucket backup, characterized in that: include: The user end is used to send a write request to the system when the user needs to store data, and send a read request to the system when the user needs to read stored data; The link selection and switching module is used to monitor the status of each link in real time and select and switch links according to the monitoring results; The main storage module is used to receive the data storage requirements generated by the main write link to store data, and automatically and synchronously copy the stored data to the backup storage bucket module through intranet encrypted transmission; The backup storage bucket module is used to receive the data storage requirements generated by the backup write link to store data, and automatically and synchronously copy the stored data to the main storage bucket module through intranet encrypted transmission; The data security module is used to decrypt the encrypted data at the data sending end and feed the decrypted data back to the data receiving end.
2. According to claim 1, an object storage service system based on storage bucket backup is characterized in that: Also includes: The cloud storage service client is used to store data for the data storage needs generated by the backup write link, and automatically synchronizes and copies the stored data to the primary storage bucket through VPN encrypted transmission.
3. The object storage service system based on storage bucket backup according to claim 2, characterized in that: Also includes: The CDN node module is used to cache data from the primary storage bucket module, the backup storage bucket module or the cloud storage service end, receive data access requests from the user end, and send the corresponding data to the user end.
4. The object storage service system based on bucket backup according to claim 3, characterized in that: The link selection and switching module monitors the status of each link in real time, and selects and switches the link according to the monitoring result, including: Real-time monitoring of the performance indicators of each link, including latency, packet loss rate, and bandwidth utilization; Detect the signal strength and connection status of each write link and whether it reaches a preset threshold; Based on the monitoring data of each link, determine whether the current link meets the preset quality requirements, and select the optimal link to switch to as the target link.
5. The object storage service system based on bucket backup according to claim 4, characterized in that: The determining whether the current link meets the preset quality requirement and selecting the optimal link to switch as the target link includes: If it is determined that the default primary write link does not meet the preset quality requirements, the current link is determined to be unavailable, and the backup write link is automatically switched to the target link.
6. The object storage service system based on storage bucket backup according to claim 5, characterized in that: The backup storage bucket module is used to: When the quality requirement of the primary write link corresponding to the primary storage bucket module is not met, the data storage demand generated by the backup write link is received to store data, and the stored data is automatically and synchronously copied to the primary storage bucket module through intranet encrypted transmission.
7. The object storage service system based on storage bucket backup according to claim 1, characterized in that: The data security module decrypts the encrypted data of the data sending end and feeds the decrypted data back to the data receiving end, including: The data security module receives a key encryption request from the main storage bucket module through the intranet, encrypts the key and feeds it back to the main storage bucket module; The primary storage bucket module sends the encrypted key to the backup storage bucket module via the intranet, and the backup storage bucket module sends the encrypted key to the data security module for decryption; The data security module returns the decrypted key to the backup storage bucket module.
8. The object storage service system based on storage bucket backup according to claim 1, characterized in that: The data security module decrypts the encrypted data of the data sending end and feeds the decrypted data back to the data receiving end, including: The data security module receives a key encryption request from the backup storage bucket module through the intranet, encrypts the key and feeds it back to the backup storage bucket module; The backup storage bucket module sends the encrypted key to the primary storage bucket module via the intranet, and the primary storage bucket module sends the encrypted key to the data security module for decryption; The data security module returns the decrypted key to the main storage bucket module.
9. The object storage service system based on storage bucket backup according to claim 2, characterized in that: The data security module decrypts the encrypted data of the data sending end and feeds the decrypted data back to the data receiving end, including: The data security module receives a key encryption request from the cloud storage service client through the VPN, encrypts the key and feeds it back to the cloud storage service client; The cloud storage service client sends the encrypted key to the main storage bucket module through VPN, and the main storage bucket module sends the encrypted key to the data security module for decryption; The data security module returns the decrypted key to the main storage bucket module.
10. The object storage service system based on storage bucket backup according to claim 3, characterized in that: The receiving a data access request from a user terminal and sending corresponding data to the user terminal comprises: After receiving the data access request from the user terminal, the CDN node module sends a verification request to the data security platform; after the data security platform successfully verifies, it returns a verification result table to the CDN node module; The CDN node module returns the acquired permission information / changed permission information to the user terminal, and the user terminal successfully accesses the corresponding data.
Citation Information
Patent Citations
Key encryption and storage method
CN103051446A
Data disaster recovery method, device and server
CN113419901A
Business data storage exception processing method and device and server
CN113849352A
Data object sync
US10951704B1
Secure data replication
US20170316075A1