Multi-tenant management and control system of big data platform
By combining encrypted data and logical partitions in the multi-tenant environment of the big data platform, dynamically adjusting the partition size and performing data compression, the problems of insufficient data isolation, low access control security and uneven allocation of storage resources in the multi-tenant environment are solved, and more efficient and secure data storage and processing services are achieved.
Patent Information
- Application Number
- CN202510142136.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-05-30
AI Technical Summary
The existing online leasing platform has problems such as insufficient data isolation, low access control security, and uneven allocation of storage resources in a multi-tenant environment.
The multi-tenant management and control system of the big data platform is adopted, combining encrypted data and logical partitions, dynamically adjust the partition size, optimize the utilization of storage space, and further optimize the utilization of storage space through the compression of encrypted data.
It effectively solves the problems of insufficient data isolation, low access control security, and uneven allocation of storage resources, and provides a more flexible, more efficient and safe big data platform environment, ensuring that multiple tenants can enjoy stable, independent and secure data storage and processing services on the same platform.
Smart Images

Figure CN120068149A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer application technologies, and particularly to a multi-tenant management and control system for a big data platform. Background Art
[0002] Online electronic device rental platforms can facilitate customers to quickly rent various electronic devices (such as mobile phones, computers, cameras, office equipment, etc.). Tenants can select their favorite devices online according to their own needs, enjoy flexible lease terms and convenient online services, which are especially suitable for individuals or enterprises that need to use certain devices for short or long periods but do not want to bear high purchase costs or equipment maintenance. Since the needs of each tenant are different, the platform needs to provide customized services according to the actual needs of each tenant to ensure that the usage experience of each tenant is not affected by other tenants and independently and efficiently manage their own devices and services. Therefore, the rental platform must have a multi-tenant management and control mechanism.
[0003] With the increase in rental users, multiple independent tenants share the same platform or system resources. In a multi-tenant environment, it is particularly important to ensure the security of data isolation, access control, and session management. Existing multi-tenant databases use logical partitioning to isolate the data of different tenants, but these partitions cannot fully guarantee the physical isolation of data or prevent potential access risks. In addition, the storage space of online rental platforms is limited, and the data sizes of different tenants may vary greatly. How to more efficiently utilize storage resources is also a challenge.
[0004] The present invention proposes a multi-tenant management and control system and method for a big data platform, which can combine encrypted data with logical partitioning, dynamically adjust the partition size according to the actual needs of each tenant, avoid storage waste, and further optimize the utilization of storage space through data compression means for encrypted data. Summary of the Invention
[0005] In view of this, the present invention provides a multi-tenant management and control system for a big data platform to solve the technical problems of uneven allocation of tenant user data storage resources, insufficient tenant data isolation, and low security in existing online rental platforms.
[0006] To achieve the above technical objectives, the present invention adopts the following technical solutions:
[0007] In a first aspect, the present invention provides a multi-tenant management and control system for a big data platform, including:
[0008] An information acquisition module, a dynamic allocation module, a data processing module, and a database module; the information acquisition module, the dynamic allocation module, and the data processing module are all connected to the database module;
[0009] An information acquisition module, which is used to acquire the username and login password input by the currently logged-in user, search for the first key corresponding to the username in the database module, verify the user based on the username, the first key, and the login password, and obtain the user's login information, registration information, access data, and rental history data after successful verification;
[0010] A dynamic allocation module, which is used to determine the priority coefficient of the user according to the user's registration information, access data, and rental history data, determine the risk coefficient according to the user's login information, and formulate a dynamic allocation strategy for storage resources and an encryption strategy for user data based on the priority coefficient and the risk coefficient;
[0011] A data processing module, which is used to encrypt and compress the data uploaded by the user according to the dynamic allocation strategy and the encryption strategy, and transmit the processed data to the database module;
[0012] A database module, which is designed with a distributed database architecture, is used to store user data according to the dynamic allocation strategy, and is also used to encrypt and store the first key of each user.
[0013] Furthermore, the dynamic allocation module includes a tenant analysis module, a risk coefficient calculation module, and a resource allocation module;
[0014] The tenant analysis module is used to calculate the stability score according to the user's registration information, calculate the status score according to the access data in a preset time period, calculate the behavior score according to the rental history data, and determine the priority coefficient of the user based on the stability score, the status score, and the behavior score;
[0015] The risk coefficient calculation module is used to calculate the consistency score and the location change score according to the current login information and the historical login information, determine the location anomaly score according to the preset blacklist IP address, and determine the risk coefficient of the user based on the consistency score, the location change score, and the location anomaly score;
[0016] The resource allocation module is used to formulate a dynamic allocation strategy for storage resources based on the priority coefficient and the risk coefficient.
[0017] Furthermore, formulating a dynamic allocation strategy for storage resources based on the priority coefficient and the risk coefficient includes:
[0018] The storage capacity allocated to the tenant is expressed by the formula:
[0019] S = M·(1 + α·P)·(1 - β·Y)
[0020] Among them, M represents the basic data capacity, α represents the performance coefficient related to the database module, β represents the risk-related coefficient, and P and Y are the impact weights of tenant priority and risk on the storage capacity respectively.
[0021] Furthermore, the calculation method of the basic data capacity M is as follows:
[0022] M = f(k, L, T)
[0023] Among them, k represents the level where the user is located, L represents the number of lease times, T represents the stability score corresponding to the registration duration, and f(·) represents the capacity calculation function.
[0024] Furthermore, calculating the consistency score and the location change score according to the current login information and the historical login information includes:
[0025] Calculating the consistency score according to the great circle distance between the geographical location corresponding to the current login IP address and the geographical location with the highest historical login frequency, which is expressed by the formula:
[0026]
[0027]
[0028] Among them, Q 1 represents the consistency score, d represents the distance between the current login IP geographical location and the historical highest frequency login geographical location, D max represents the maximum distance threshold, U represents the conversion score, φ 1 and φ 2 respectively represent the latitudes of the current login IP geographical location and the historical highest frequency login geographical location, R is the radius of the earth, Δλ is the difference in longitude between the two locations, and Δφ is the difference in latitude between the two locations;
[0029] Determining the risk coefficient of the user based on the consistency score, the location change score and the location anomaly score, which is expressed by the formula:
[0030]
[0031] Among them, w 1 、w 2 and w 3 respectively represent the weight coefficients of the consistency score, the location change score and the location anomaly score, Q 1 represents the consistency score, Q 3 represents the regional risk value corresponding to the current location, represents the average value of the distance between the historical geographical location and the latitude of the historical highest frequency login geographical location.
[0032] Further, the method for formulating the encryption policy includes:
[0033] When the risk coefficient C > Z n select the AES-256 encryption algorithm;
[0034] When the risk coefficient C ≤ Z n select the AES-128 encryption algorithm;
[0035] where Z n is a preset risk threshold.
[0036] Further, the database module includes a user data layer and a key management layer;
[0037] The user data layer includes multiple storage nodes. Each storage node is divided into a public data storage node and a private data storage node. The encrypted and compressed data shards of each user are stored in different private data storage nodes;
[0038] The key management layer is used to store the first key of each user. For users with a priority coefficient greater than the preset security threshold, the first key of the user is encrypted using the second key according to the preset encryption algorithm.
[0039] Further, the encrypted and compressed data shards of each user are stored in different private data storage nodes, including:
[0040] Based on the hash sharding algorithm, the user data is divided into multiple data blocks. An independent virtual space is provided for each user according to the user name. Each virtual space is bound to a unique user name to achieve physical isolation of each user's data.
[0041] Further, the system further includes a monitoring and reporting module;
[0042] The monitoring and reporting module is used to monitor the user login information, the database query speed, and the encryption response time in real time, and generate a storage resource allocation and user management report for the operator to consult.
[0043] On the other hand, the present invention also provides a multi-tenant control method for a big data platform, which is implemented by using any one of the multi-tenant control systems of the big data platform described in the above technical solutions, including:
[0044] Obtain the user name and login password input by the currently logged-in user through the information acquisition module, search for the first key corresponding to the user name in the database module, verify the user according to the user name, the first key, and the login password, and obtain the login information, registration information, access data, and rental history data of the user after successful verification;
[0045] The dynamic allocation module determines the priority coefficient of the user based on the user's registration information, access data, and rental history data, determines the risk coefficient based on the user's login information, and formulates a dynamic allocation strategy for storage resources and an encryption strategy for user data based on the priority coefficient and risk coefficient;
[0046] The data processing module encrypts and compresses the data uploaded by the user according to the dynamic allocation strategy and the encryption strategy;
[0047] The database module stores the user data according to the dynamic allocation strategy.
[0048] Compared with the prior art, the advantages provided by the present invention are as follows:
[0049] (1) By formulating a storage resource allocation strategy based on the user's priority coefficient and risk coefficient, it is possible to optimize resource allocation according to the importance and potential risks of the user, flexibly allocate appropriate storage resources for each user, and ensure that the data of high-priority users is fully protected and low-risk users obtain appropriate resources.
[0050] (2) Adopting a distributed database architecture, the data of each tenant is well isolated, reducing the risk of data leakage between different tenants, ensuring the privacy and data independence of each tenant, and having high scalability and fault tolerance. It can easily handle the growth of data volume and avoid service interruption caused by a single point of failure.
[0051] (3) This system not only allocates resources according to static rules but also can be adjusted according to real-time data, can meet the personalized needs of different tenants in different situations, and automatically processes resource allocation and encryption without manual intervention, simplifying the management process and improving the management efficiency.
[0052] In summary, the present invention effectively solves the problems of data security, uneven resource allocation, and insufficient isolation of tenant data. Through dynamic resource allocation and encryption strategies, it provides a more flexible, efficient, and secure big data platform environment, ensuring that multiple tenants can enjoy stable, independent, and secure data storage and processing services on the same platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 It is a schematic structural diagram of a multi-tenant management and control system for a big data platform provided by the present invention;
[0054] Figure 2 It is a schematic structural diagram of a dynamic allocation module provided by the present invention;
[0055] Figure 3 It is a schematic structural diagram of a database module provided by the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0056] The preferred embodiments of the present invention will be specifically described below in conjunction with the accompanying drawings. The accompanying drawings form a part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, rather than to limit the scope of the present invention.
[0057] Please refer to Figure 1 , this embodiment provides a multi-tenant management and control system for a big data platform, including: an information acquisition module 101, a dynamic allocation module 102, a data processing module 103, and a database module 104; the information acquisition module 101, the dynamic allocation module 102, and the data processing module 103 are all connected to the database module 104;
[0058] The information acquisition module 101 is used to obtain the username and login password entered by the currently logged-in user, search for the first key corresponding to the username in the database module, verify the user based on the username, the first key, and the login password, and obtain the login information, registration information, access data, and rental history data of the user after successful verification;
[0059] The dynamic allocation module 102 is used to determine the priority coefficient of the user according to the user's registration information, access data, and rental history data, determine the risk coefficient according to the user's login information, and formulate a dynamic allocation strategy for storage resources and an encryption strategy for user data based on the priority coefficient and the risk coefficient;
[0060] The data processing module 103 is used to encrypt and compress the data uploaded by the user according to the dynamic allocation strategy and the encryption strategy, and transmit the processed data to the database module;
[0061] The database module 104 is designed with a distributed database architecture, used to store user data according to the dynamic allocation strategy, and also used to encrypt and store the first key of each user.
[0062] The system of this embodiment can dynamically allocate storage resources according to user needs and risks, avoid waste or shortage, store user data using a distributed database architecture, strictly isolate data and permissions, ensure the data privacy and independence of each tenant, and through dynamic resource allocation, combined with historical data for intelligent planning, meet personalized needs, and provide a secure, efficient, and flexible multi-tenant rental platform for users.
[0063] As a preferred embodiment, as Figure 2 shown, the dynamic allocation module 102 includes a tenant analysis module 201, a risk coefficient calculation module 202, and a resource allocation module 203;
[0064] The tenant analysis module 201 is used to calculate a stability score based on the user's registration information, calculate a status score based on the access data within a preset time period, calculate a behavior score based on the rental history data, and determine the priority coefficient of the user based on the stability score, status score, and behavior score;
[0065] The risk coefficient calculation module 202 is used to calculate a consistency score and a location change score based on the current login information and historical login information, determine a location anomaly score based on the preset blacklist IP addresses, and determine the risk coefficient of the user based on the consistency score, location change score, and location anomaly score;
[0066] The resource allocation module 203 is used to formulate a dynamic allocation strategy for storage resources based on the priority coefficient and risk coefficient.
[0067] As a specific embodiment, the stability score mainly reflects the long-term stability of the user account and is calculated based on the user's registration information. The stability score comprehensively calculates the user's registration duration, user registration information (registration location, historical login area, basic information), etc. It should be noted that when calculating, for users who purchase VIP memberships or have rental history, corresponding scores can be added additionally, that is:
[0068] Stability score = user registration time (in years) / maximum number of years × 100 + registration information score + VIP membership or rental history bonus points; the maximum number of years here is the maximum number of years allowed for user registration up to now.
[0069] As a specific embodiment, the status score of the tenant is comprehensively calculated based on the login frequency, login IP address, login device, and login failure information (such as whether there is an incorrect password, account lockout, etc.) within a preset time period (such as the past 30 days, the past 90 days).
[0070] As a specific embodiment, the behavior score is calculated based on the rental history data. Specifically, it is calculated based on the number of rentals, rental item categories, and rental amounts within a preset time period (such as within the most recent six months). The number of rentals, item categories, and rental amounts each have corresponding influence weights. For example, higher scores are given to high-value items (such as high-price, scarce items), and the number of rentals of the user is compared with the value of the user with the most rentals to obtain the score corresponding to the number of rentals, and finally the behavior score is calculated based on the access data.
[0071] As a preferred embodiment, formulating a dynamic allocation strategy for storage resources based on the priority coefficient and risk coefficient includes:
[0072] The storage capacity allocated to the tenant is expressed by the formula:
[0073] S = M·(1 + α·P)·(1 - β·Y)
[0074] Among them, M represents the basic data capacity, α represents the performance coefficient related to the database module, β represents the risk-related coefficient, and P and Y are the tenant priority and the impact weight of risk on the storage capacity respectively.
[0075] As a preferred embodiment, the calculation method of the basic data capacity M is as follows:
[0076] M = f(k, L, T)
[0077] Among them, k represents the level where the user is located, L represents the number of lease times, T represents the stability score corresponding to the registration duration, and f(·) represents the capacity calculation function.
[0078] The storage resource dynamic allocation strategy determines the storage capacity allocated to tenants by comprehensively considering various factors, aiming to achieve more personalized and efficient resource allocation. According to the tenant's priority, risk status, basic data capacity, and related performance coefficients, this strategy can reasonably optimize the use of storage resources while ensuring system stability. On the basis of ensuring that the basic information can be stored, it provides dynamic adjustment of the storage space size according to the importance and stability of the tenant to meet the usage needs of different users.
[0079] As a preferred embodiment, calculating the consistency score and the location change score according to the current login information and the historical login information includes:
[0080] Calculating the consistency score according to the great circle distance between the geographical location corresponding to the current login IP address and the geographical location with the highest historical login frequency, which is expressed by the formula:
[0081]
[0082] Among them, Q 1 represents the consistency score, d represents the distance between the current login IP geographical location and the geographical location with the highest historical login frequency, D max represents the maximum distance threshold, U represents the conversion score, φ 1 and φ 2 respectively represent the latitudes of the current login IP geographical location and the geographical location with the highest historical login frequency, R is the radius of the earth, Δλ is the difference in longitude between the two positions, and Δφ is the difference in latitude between the two positions;
[0083] Calculate the consistency score by calculating the great circle distance between two points, that is, the spherical distance.
[0084] Determine the risk coefficient of the user based on the consistency score, the location change score, and the location anomaly score, which is expressed by the formula:
[0085]
[0086] Among them, w 1 、w 2 and w 3 respectively represent the weight coefficients of the consistency score, the position change score, and the position anomaly score. Q 1 represents the consistency score, and Q 3 represents the regional risk value corresponding to the current position. represents the average value of the distances between the historical geographical locations and the latitudes of the historical most frequently logged-in geographical locations.
[0087] It should be noted that the position change score is used to reflect the ratio between the user's current login address and the historical maximum geographical gap, and is used to detect whether there is an abnormal geographical distribution. In addition, the address distribution of the blacklist IP is set in this system. If the IP address is in the blacklist (including high-risk countries, regions, or IP addresses listed as high-risk), the score is directly returned as 0.
[0088] As a preferred embodiment, the method for formulating the encryption policy includes:
[0089] When the risk coefficient C > Z n , select the AES-256 encryption algorithm;
[0090] When the risk coefficient C ≤ Z n , select the AES-128 encryption algorithm;
[0091] Among them, Z n is a preset risk threshold.
[0092] AES-256 is the Advanced Encryption Standard with a 256-bit key length, providing high security and being suitable for scenarios with high security requirements. Select the AES-128 encryption algorithm. AES-128 is an Advanced Encryption Standard with a 128-bit key length. Although its security is slightly lower than that of AES-256, it is still sufficient to meet most security requirements.
[0093] As a specific embodiment, the encrypted data usually occupies more storage space than the original data. At this time, it is necessary to use a data processing module to adopt a compression algorithm (such as Gzip, Snappy, etc.) to optimize the storage space. By compressing the encrypted data, the storage cost can be significantly reduced and the utilization rate of storage resources can be improved.
[0094] As a preferred embodiment, as Figure 3 shown, the database module 104 includes a user data layer and a key management layer;
[0095] The user data layer includes multiple storage nodes. Each storage node is divided into a public data storage node and a private data storage node. The encrypted and compressed data shards of each user are stored in different private data storage nodes.
[0096] The key management layer is used to store the first key of each user. For users with a priority coefficient greater than a preset security threshold, the second key is used to encrypt the first key of the user according to a preset encryption algorithm.
[0097] As a specific embodiment, for some users with higher priorities (i.e., users with a priority coefficient greater than a certain preset security threshold), the system will assign a second key to these users. The second key is not directly used to encrypt user data, but to encrypt the first key. That is to say, the second key is used to encrypt the first key to enhance the security of the key. If a user's priority coefficient is greater than the preset security threshold (such as the user has a high credit score, a high identity authentication level, etc.), the system will consider that the user has higher security requirements, so the second key needs to be used to encrypt the first key of the user. To ensure that even if the key is leaked, the user's first key can only be obtained after being decrypted by the second key, thus further protecting the user's sensitive information.
[0098] The preset encryption method here usually adopts an asymmetric encryption algorithm with higher security (such as RSA or ECC). When encrypting the data of users with higher priorities (such as credit records, passwords, and basic information), the user needs to input a second password generated according to the first key, the second key, and the username for verification to further ensure the security of the user's information.
[0099] In the database module, the storage nodes can be distributed on different physical servers, and the nodes are connected through a network. Each storage node stores part of the user's data, and is divided into different types according to the data type and access requirements. The public data storage node is used to store the public data shared by all users. The public data can be publicly accessed by users and usually has lower security requirements. The private data storage node: is used to store the private data of each user, such as sensitive files, password information, etc. The private data requires higher security and encryption protection.
[0100] For example, the public data of the user is stored in the namespace userID / public, and the private data is stored in userID / private. By this means, it can be ensured that the public data and private data of each user are isolated, and who can access which namespace is controlled according to the access rights.
[0101] As a preferred embodiment, the encrypted and compressed data shards of each user are stored in different private data storage nodes, including:
[0102] Based on the hash sharding algorithm, the user data is divided into multiple data blocks, and an independent virtual space is provided for each user according to the username. Each virtual space is bound to a unique username to achieve physical isolation of each user's data.
[0103] In some embodiments, to prevent data loss, each data shard will retain redundant copies on multiple storage nodes. For example, using a three-copy mechanism, data copies are retained on three different storage nodes.
[0104] As a specific embodiment, in traditional storage technologies, a large data platform shares a storage pool, which is inconvenient for data access. In this system, physical storage resources are divided into multiple virtual storage partitions through virtualization technology. Each tenant independently uses its own storage partition, and at the same time, the system can dynamically adjust the size of the partition according to the tenant's needs.
[0105] As a preferred embodiment, the system further includes a monitoring and reporting module;
[0106] The monitoring and reporting module is used to monitor the user login information, database query speed, and encryption response time in real time, and generate storage resource allocation and user management reports for operators to consult.
[0107] In some embodiments, the monitoring and reporting module can also track and monitor various operation data in the system, including user behavior, storage resource usage, data access and processing, etc. Through real-time monitoring, the system can timely detect potential abnormal activities or performance bottlenecks to ensure the stability and security of the multi-tenant platform.
[0108] Furthermore, the system can also use tools such as Prometheus, Grafana, or Zabbix to collect metrics such as CPU usage rate, memory consumption, storage space, and network bandwidth in real time.
[0109] This embodiment also provides a multi-tenant management method for a large data platform, which is implemented by using any of the multi-tenant management systems for a large data platform described in the above technical solutions, including:
[0110] Obtain the username and login password input by the currently logged-in user through the information acquisition module, search for the first key corresponding to the username in the database module, verify the user according to the username, the first key, and the login password, and obtain the user's login information, registration information, access data, and rental history data after successful verification;
[0111] The dynamic allocation module determines the priority coefficient of the user based on the user's registration information, access data, and rental history data, determines the risk coefficient based on the user's login information, and formulates a dynamic allocation strategy for storage resources and an encryption strategy for user data based on the priority coefficient and the risk coefficient;
[0112] The data processing module encrypts and compresses the data uploaded by the user according to the dynamic allocation strategy and the encryption strategy;
[0113] The database module stores the user data according to the dynamic allocation strategy.
[0114] The multi-tenant management and control system of the big data platform provided by the present invention provides a more flexible, efficient, and secure big data platform environment through dynamic resource allocation and encryption strategies, ensuring that multiple tenants can enjoy stable, independent, and secure data storage and processing services on the same platform, solving the problems of user data security, uneven resource allocation, and insufficient tenant data isolation, and providing a more secure online rental platform for users.
[0115] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention.
Claims
1. A multi-tenant management and control system for a big data platform, characterized in that: include: Information acquisition module, dynamic allocation module, data processing module and database module; the information acquisition module, dynamic allocation module and data processing module are all connected to the database module; An information acquisition module is used to obtain the user name and login password input by the current login user, search the database module for the first key corresponding to the user name, verify the user according to the user name, the first key and the login password, and obtain the user's login information, registration information, access data and rental history data after the verification is passed; A dynamic allocation module, used to determine the priority coefficient of the user according to the user's registration information, access data and rental history data, determine the risk coefficient according to the user's login information, and formulate a dynamic allocation strategy for storage resources and an encryption strategy for user data based on the priority coefficient and risk coefficient; A data processing module, used to encrypt and compress the data uploaded by the user according to the dynamic allocation strategy and encryption strategy, and transmit the processed data to the database module; The database module adopts a distributed database architecture design and is used to store user data according to the dynamic allocation strategy and is also used to encrypt and store the first key of each user.
2. The multi-tenant management and control system of the big data platform according to claim 1 is characterized in that: The dynamic allocation module includes a tenant analysis module, a risk coefficient calculation module and a resource allocation module; A tenant analysis module, used to calculate a stability score based on the user's registration information, calculate a status score based on the access data of a preset time period, calculate a user's behavior score based on the rental history data, and determine the user's priority coefficient based on the stability score, status score and behavior score; A risk coefficient calculation module, used to calculate a consistency score and a location change score based on the current login information and the historical login information, and determine a location anomaly score based on a preset blacklist IP address, and determine the risk coefficient of the user based on the consistency score, location change score and location anomaly score; The resource allocation module is used to formulate a dynamic allocation strategy for storage resources based on the priority coefficient and the risk coefficient.
3. The multi-tenant management and control system of the big data platform according to claim 1 is characterized in that: Formulate a dynamic allocation strategy for storage resources based on the priority coefficient and the risk coefficient, including: The storage capacity allocated to a tenant is expressed as: S=M·(1+α·P)·(1-β·Y) Among them, M represents the basic data capacity, α represents the performance coefficient related to the database module, β represents the risk-related coefficient, and P and Y are the impact weights of tenant priority and risk on storage capacity, respectively.
4. The multi-tenant management and control system of the big data platform according to claim 3 is characterized in that: The calculation method of the basic data capacity M is: M=f(k,L,T) Where k represents the user’s level, L represents the number of rentals, T represents the stability score corresponding to the registration duration, and f(·) represents the capacity calculation function.
5. The multi-tenant management and control system of the big data platform according to claim 2 is characterized in that: The calculation of the consistency score and the location change score based on the current login information and the historical login information includes: The consistency score is calculated based on the great circle distance between the geographical location corresponding to the current login IP address and the geographical location with the highest historical login frequency. The formula is: Among them, Q1 represents the consistency score, d represents the distance between the current login IP location and the historical highest frequency login location, and D max represents the maximum distance threshold, U represents the conversion score, φ1 and φ2 represent the latitude of the current login IP location and the historical highest frequency login location respectively, R is the radius of the earth, Δλ is the difference in longitude between the two locations, and Δφ is the difference in latitude between the two locations; The risk factor of the user is determined based on the consistency score, the location change score and the location anomaly score, and is expressed as follows: Among them, w1, w2 and w3 represent the weight coefficients of consistency score, location change score and location anomaly score respectively, Q1 represents the consistency score, Q3 represents the regional risk value corresponding to the current location, Indicates the average distance between the historical geographic locations and the latitude of the historical most frequently logged-in geographic location.
6. The multi-tenant management and control system of the big data platform according to claim 5 is characterized in that: The method for formulating the encryption strategy includes: When the risk factor C>Z n When, select AES-256 encryption algorithm; When the risk factor C≤Z n When, select AES-128 encryption algorithm; Among them, Z n is the preset risk threshold.
7. The multi-tenant management and control system of the big data platform according to claim 4 is characterized in that: The database module includes a user data layer and a key management layer; The user data layer includes multiple storage nodes, each of which is divided into a public data storage node and a private data storage node. The encrypted and compressed data of each user is stored in different private data storage nodes. The key management layer is used to store the first key of each user. For users whose priority coefficient is greater than a preset security threshold, the second key is used to encrypt the first key of the user according to a preset encryption algorithm.
8. The multi-tenant management and control system of the big data platform according to claim 7 is characterized in that: Each user’s encrypted and compressed data is sharded and stored in different private data storage nodes, including: Based on the hash sharding algorithm, user data is divided into multiple data blocks, and an independent virtual space is provided for each user according to the user name. Each virtual space is bound to a unique user name to achieve physical isolation of each user's data.
9. The multi-tenant management and control system of the big data platform according to claim 7, characterized in that: It also includes a monitoring and reporting module; The monitoring and reporting module is used to monitor user login information, database query speed and encryption response time in real time, and generate storage resource allocation and user management reports for operators to review.
10. A multi-tenant management and control method for a big data platform, characterized in that: The multi-tenant management and control system of any big data platform as described in claims 1 to 9 is used for implementation, including: The user name and login password input by the current login user are obtained through the information acquisition module, the first key corresponding to the user name is searched in the database module, the user is verified according to the user name, the first key and the login password, and the login information, registration information, access data and rental history data of the user are obtained after the verification is passed; Determine the user's priority coefficient according to the user's registration information, access data and rental history data through the dynamic allocation module, determine the risk coefficient according to the user's login information, and formulate a dynamic allocation strategy for storage resources and an encryption strategy for user data based on the priority coefficient and risk coefficient; The data processing module encrypts and compresses the data uploaded by the user according to the dynamic allocation strategy and encryption strategy; The user data is stored according to the dynamic allocation strategy through the database module.