Cross-cloud migration method and device of object
By conducting dynamic security evaluation and performance monitoring during the data migration process, we ensure that the data migration between public and private clouds is safe and reliable, and the problem of mismatch in the existing technology is solved, and efficient and secure data migration effect is achieved.
Patent Information
- Application Number
- CN202510183258.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the process of data migration between public and private clouds, the prior art cannot effectively match the security standards of both, resulting in data security risks.
Through the data migration trigger module, data sensitivity analysis module, data security encryption and decryption module, public cloud platform selection monitoring module, public cloud platform security evaluation module and data storage scheduling module, dynamically monitor and evaluate the security and performance in the data migration process to ensure the security of data during transmission and storage.
It realizes secure and reliable data migration between public and private clouds, reduces the risk of data leakage, improves data access speed and storage efficiency, and reduces storage costs.
Smart Images

Figure CN120011024A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cross-cloud data migration, and in particular to a method and device for cross-cloud migration of an object. Background Art
[0002] With the rapid development and widespread use of cloud computing, more and more users are storing data on cloud platforms. When the amount of data is not large, users can store data by building an internal data center (i.e., a private cloud platform). However, with the advent of the big data era, some users' existing private cloud platforms can no longer meet their data storage needs. For these users, there are only two ways to solve the problem of insufficient data storage space: continue to build private cloud platforms or rent storage services from other companies (i.e., public cloud platforms). Continuing to build private cloud platforms greatly increases user costs. Therefore, more and more users distribute some applications and data in public and private clouds, and adopt cross-cloud application deployment and migration to meet business needs.
[0003] A Chinese patent discloses a hybrid cloud data migration method and system based on privacy and security (authorization announcement number CN114510742B). The patented technology comprehensively considers the sensitivity and distribution characteristics of the data, and uses it and the hotness and coldness of the data to construct a migration function, which is used to migrate data sets in or out, thereby ensuring data privacy while improving the utilization rate of the hybrid cloud. However, it does not disclose the matching of public cloud and private cloud security standards, which may lead to data leakage and cause security risks. Summary of the invention
[0004] The purpose of the present invention is to provide a method and device for cross-cloud migration of objects to solve the problems raised in the above background technology.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A cross-cloud migration method for an object includes the following steps:
[0007] S1. Data migration trigger: According to the attribute characteristics of the data, the data stored in the private cloud platform is classified through the data migration trigger module, so that the data with the same attribute characteristics form a data set, and the migration function is used to evaluate and calculate each set of data sets. If the calculated migration function value is less than the set value, it is determined as the data set to be migrated. If it is greater than the set value, the data set will not be migrated at the current moment;
[0008] S2. Data sensitivity analysis: The sensitivity of the dataset to be migrated is analyzed through the data sensitivity analysis module. If the sensitivity is less than the set sensitivity threshold, it is judged as a dataset that can be migrated; if the sensitivity is greater than the set sensitivity threshold, it is judged as a dataset that cannot be migrated;
[0009] S3, Data security encryption and decryption: The importance of the migratable data set is analyzed through the data security encryption and decryption module to determine whether the data set needs to be encrypted. If encryption is required, the encryption algorithm is used to encrypt the data during transmission so that only authorized users can obtain complete and authentic data after decryption.
[0010] S4. Public cloud platform selection monitoring: Use the public cloud platform selection monitoring module to upload or download small files to multiple public cloud platforms at the same time, detect the response time of the public cloud platforms, and dynamically monitor their network performance;
[0011] S5. Public cloud platform security assessment: The public cloud platform security assessment module is used to determine whether the security level of the public cloud platform to be selected matches that of the user's private cloud platform. If so, the public cloud platform security meets the migration requirements; if not, the public cloud platform does not meet the migration conditions.
[0012] S6, data storage scheduling: The saturation of the storage space of the private cloud platform is detected through the data storage scheduling module. When the saturation is greater than the set saturation threshold, the migration condition is triggered to migrate the migratable data set to the public cloud platform;
[0013] S7. Front-end interface display: Set the corresponding threshold through the front-end interface display module, select the corresponding public cloud platform, and display the data migration status across clouds.
[0014] As a further solution of the present invention: in the step S1, the calculation formula of the migration function is as follows:
[0015]
[0016] In the above formula (1), t i is the length of time from the current moment to the moment when the data set is accessed; f k t k The frequency with which a data set is accessed within a time period; q is the size of the data set.
[0017] As a further solution of the present invention: in the step S3, the encryption algorithm of the data includes symmetric encryption method, asymmetric encryption method, SSL / TLS protocol method and digital certificate method.
[0018] As a further solution of the present invention: in the step S4, a multi-threaded method is used to upload or download small files, and the multi-threaded method includes a method of inheriting the Thread class, a method of implementing the Runnable interface, a method of implementing the Callable interface, and a method of using a thread pool.
[0019] As a further solution of the present invention: in the step S5, the specific evaluation method for the security level of the public cloud platform is as follows:
[0020] S51, collecting standard list parameters passed by the private cloud platform and loading them into the cloud security standard library;
[0021] S52. Determine whether the public cloud platform has passed all the standards that the private cloud platform has passed. If the standards passed by the public cloud platform cover all the standards passed by the private cloud platform, and the security level of the public cloud platform passing the standards is equal to or higher than that of the private cloud platform, it meets the user's cross-cloud migration needs; otherwise, it is determined that the public cloud platform cannot provide security protection requirements equivalent to those of the private cloud platform.
[0022] As a further solution of the present invention: in the step S7, the front-end interface display module includes a cloud platform selection unit, a standard customization unit and a result display unit.
[0023] A device for a cross-cloud migration method of an object includes a data migration trigger module, a data sensitivity analysis module, a data security encryption and decryption module, a public cloud platform selection monitoring module, a public cloud platform security assessment module, a data storage scheduling module and a front-end interface display module.
[0024] Compared with the prior art, the present invention has the following beneficial effects:
[0025] The present invention determines the data set to be migrated through a data migration trigger module, and then determines the migratable data set with low sensitivity through a data sensitivity analysis module; and encrypts the data set of the migratable data set as needed; and then dynamically monitors the network performance of the public cloud platform, and at the same time evaluates the security level of the public cloud platform; and then triggers the migration condition to migrate the migratable data set to the public cloud platform; it can reduce the probability of data being called from the public cloud platform, ensure the data access speed, reduce the data storage cost, and has good security and data is not easy to leak. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 The figure is a flowchart of a cross-cloud migration method for an object. DETAILED DESCRIPTION
[0027] See also Figure 1 In an embodiment of the present invention, a method for cross-cloud migration of an object includes the following steps:
[0028] S1. Data migration trigger: According to the attribute characteristics of the data, the data stored in the private cloud platform is classified through the data migration trigger module, so that the data with the same attribute characteristics form a data set, and each set of data sets is evaluated and calculated using the migration function. If the calculated migration function value is less than the set value, it is determined as the data set to be migrated. If it is greater than the set value, the data set will not be migrated at the current moment; since the value of data is related to the length of time the data is stored in the storage system and the frequency of data access, data with a small migration function value is migrated first. For example, when the data is just stored in the storage system, it is frequently called by users; and as time goes by, the number of times it is called by users decreases, which can reduce the probability of data being called from the public cloud platform, ensure the access speed of data, and reduce the cost of data storage;
[0029] S2. Data sensitivity analysis: The sensitivity of the dataset to be migrated is analyzed through the data sensitivity analysis module. If the sensitivity is less than the set sensitivity threshold, it is judged as a dataset that can be migrated; if the sensitivity is greater than the set sensitivity threshold, it is judged as a dataset that cannot be migrated. Even if the migration function value of the dataset is large, it cannot be migrated to prevent the dataset from being leaked and causing immeasurable risks. Important data is stored in the private cloud to ensure security.
[0030] S3, Data security encryption and decryption: The importance of the migratable data set is analyzed through the data security encryption and decryption module to determine whether the data set needs to be encrypted. If encryption is required, the encryption algorithm is used to encrypt the data during transmission. Only authorized users can obtain complete and authentic data after decryption, thereby ensuring that data is protected during transmission and storage to avoid data leakage.
[0031] S4. Public cloud platform selection and monitoring: Use the public cloud platform selection and monitoring module to upload or download small files to multiple public cloud platforms at the same time, detect the response time of the public cloud platforms, and dynamically monitor their network performance. Then, you can select the public cloud platform with the best performance. Because the performance of the public cloud platform will fluctuate at different times, you cannot determine the performance of the public cloud platform based on its brand name.
[0032] S5. Public cloud platform security assessment: The public cloud platform security assessment module is used to determine whether the security level of the public cloud platform to be selected matches that of the user's private cloud platform. If so, the public cloud platform security meets the migration requirements. If not, the public cloud platform does not meet the migration conditions, and a public cloud platform with equal security protection capabilities is selected for deployment and migration.
[0033] S6. Data storage scheduling: The saturation of the storage space of the private cloud platform is detected through the data storage scheduling module. When the saturation is greater than the set saturation threshold, the migration condition is triggered to migrate the migratable data set to the public cloud platform; and after the migration is completed, the data in the private cloud platform is automatically deleted as needed, or it can be deleted manually;
[0034] S7. Front-end interface display: Set the corresponding threshold through the front-end interface display module, select the corresponding public cloud platform, and display the data migration status across clouds.
[0035] Preferably, in step S1, the calculation formula of the migration function is as follows:
[0036]
[0037] In the above formula (1), t i is the length of time from the current moment to the moment when the data set is accessed; f k t k The frequency with which the data set is accessed within a time period; q is the size of the data set;
[0038] From the above formula, we can conclude that: the longer the time from the current moment to the last access of a data set, the smaller the access frequency of the data set within the time period, the larger the data set, the smaller the migration function value, and these data sets are migrated first.
[0039] Preferably, in step S3, the data encryption algorithm includes symmetric encryption, asymmetric encryption, SSL / TLS protocol and digital certificate.
[0040] Preferably, in step S4, a multi-threaded method is used to upload or download small files. The multi-threaded method includes a method of inheriting the Thread class, a method of implementing the Runnable interface, a method of implementing the Callable interface, and a method of using a thread pool. When the user needs to upload data to a public cloud platform, a public cloud with better upload performance is selected; when the user needs to download data from a public cloud platform, a public cloud with better download performance is selected.
[0041] Preferably, in step S5, the specific evaluation method for the security level of the public cloud platform is as follows:
[0042] S51, collecting standard list parameters passed by the private cloud platform and loading them into the cloud security standard library;
[0043] S52. Determine whether the public cloud platform has passed all the standards that the private cloud platform has passed. If the standards passed by the public cloud platform cover all the standards passed by the private cloud platform, and the security level of the public cloud platform passing the standards is equal to or higher than that of the private cloud platform, it meets the user's cross-cloud migration needs; otherwise, it is determined that the public cloud platform cannot provide security protection requirements equivalent to those of the private cloud platform.
[0044] Preferably, the front-end interface display module includes a cloud platform selection unit, a standard customization unit and a result display unit. The corresponding public cloud platform, such as Alibaba Cloud, Baidu Cloud, Huawei Cloud, and Amazon Cloud, can be selected through the cloud platform selection unit; users can customize the migration function setting value, sensitivity threshold, and saturation threshold through the standard customization unit according to their own needs; the migration status of the data can be displayed through the result display unit.
[0045] A device for a cross-cloud migration method of an object includes a data migration trigger module, a data sensitivity analysis module, a data security encryption and decryption module, a public cloud platform selection monitoring module, a public cloud platform security assessment module, a data storage scheduling module and a front-end interface display module.
[0046] What is described above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.
Claims
1. A cross-cloud migration method for an object, characterized in that: The following steps are involved: S1. Data migration trigger: According to the attribute characteristics of the data, the data stored in the private cloud platform is classified through the data migration trigger module, so that the data with the same attribute characteristics form a data set, and the migration function is used to evaluate and calculate each set of data sets. If the calculated migration function value is less than the set value, it is determined as the data set to be migrated. If it is greater than the set value, the data set will not be migrated at the current moment; S2. Data sensitivity analysis: The sensitivity of the dataset to be migrated is analyzed through the data sensitivity analysis module. If the sensitivity is less than the set sensitivity threshold, it is judged as a dataset that can be migrated; if the sensitivity is greater than the set sensitivity threshold, it is judged as a dataset that cannot be migrated; S3, Data security encryption and decryption: The importance of the migratable data set is analyzed through the data security encryption and decryption module to determine whether the data set needs to be encrypted. If encryption is required, the encryption algorithm is used to encrypt the data during transmission so that only authorized users can obtain complete and authentic data after decryption. S4. Public cloud platform selection monitoring: Use the public cloud platform selection monitoring module to upload or download small files to multiple public cloud platforms at the same time, detect the response time of the public cloud platforms, and dynamically monitor their network performance; S5. Public cloud platform security assessment: The public cloud platform security assessment module is used to determine whether the security level of the public cloud platform to be selected matches that of the user's private cloud platform. If so, the public cloud platform security meets the migration requirements; if not, the public cloud platform does not meet the migration conditions. S6, data storage scheduling: The saturation of the storage space of the private cloud platform is detected through the data storage scheduling module. When the saturation is greater than the set saturation threshold, the migration condition is triggered to migrate the migratable data set to the public cloud platform; S7. Front-end interface display: Set the corresponding threshold through the front-end interface display module, select the corresponding public cloud platform, and display the data migration status across clouds.
2. The cross-cloud migration method of an object according to claim 1, characterized in that: In the step S1, the calculation formula of the migration function is as follows: In the above formula (1), t i is the length of time from the current moment to the moment when the data set is accessed; f k t k The frequency with which a data set is accessed within a time period; q is the size of the data set.
3. The cross-cloud migration method of an object according to claim 1, characterized in that: In the S3 step, the data encryption algorithm includes symmetric encryption, asymmetric encryption, SSL / TLS protocol and digital certificate.
4. The cross-cloud migration method of an object according to claim 1, characterized in that: In the step S4, a multi-threaded method is used to upload or download small files. The multi-threaded method includes a method of inheriting the Thread class, a method of implementing the Runnable interface, a method of implementing the Callable interface, and a method of using a thread pool.
5. The cross-cloud migration method of an object according to claim 1, characterized in that: In the step S5, the specific evaluation method for the security level of the public cloud platform is as follows: S51, collecting standard list parameters passed by the private cloud platform and loading them into the cloud security standard library; S52. Determine whether the public cloud platform has passed all the standards that the private cloud platform has passed. If the standards passed by the public cloud platform cover all the standards passed by the private cloud platform, and the security level of the public cloud platform passing the standards is equal to or higher than that of the private cloud platform, it meets the user's cross-cloud migration needs; otherwise, it is determined that the public cloud platform cannot provide security protection requirements equivalent to those of the private cloud platform.
6. The cross-cloud migration method of an object according to claim 1, characterized in that: In the step S7, the front-end interface display module includes a cloud platform selection unit, a standard customization unit and a result display unit.
7. A device for implementing the cross-cloud migration method of the object according to claim 1, characterized in that: It includes data migration trigger module, data sensitivity analysis module, data security encryption and decryption module, public cloud platform selection monitoring module, public cloud platform security assessment module, data storage scheduling module and front-end interface display module.
Citation Information
Patent Citations
A privacy-preserving hybrid cloud data migration method and system
CN114510742B