File transmission method and device, electronic equipment and nonvolatile storage medium

By verifying user permissions in the file transfer system and dynamically managing SFTP service instances, the problem of difficulty in fine-grained control of permission management in the prior art is solved, and higher file transfer security and management efficiency are achieved.

CN120200790APending Publication Date: 2025-06-24CHINA TELECOM INTELLIGENT NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510293071.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the prior art, the permission management of file transfer services is usually based on the file system level, and it is difficult to perform refined controls for different services and users, resulting in reduced file security and potential risk of misoperation.

Method used

By obtaining the authentication information entered by the user when receiving the access request, verifying its permissions, and verifying whether the user account has the permission to access the target instance based on the access permission information of the target instance, thereby allowing or denying the user access and transmitting the data files of the target instance.

Benefits of technology

It realizes refined permission control for different services and users, improves file transfer security, avoids the risk of misoperation, and solves the problem of configuration and management complexity in multiple SFTP service instance environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200790A_ABST
    Figure CN120200790A_ABST
Patent Text Reader

Abstract

The invention discloses a file transmission method and device, electronic equipment and a nonvolatile storage medium. The method comprises the following steps: under the condition that an access request is received, acquiring authentication information input by a user; the authentication information is verified, a target instance corresponding to the access request is determined under the condition that the authentication information passes verification, and the target instance is a service instance which the access request plans to request to access; according to the access permission information corresponding to the target instance, verifying whether the user account has the permission to access the target instance; and under the condition of judging that the user account has the permission to access the target instance, allowing the user account to access the target instance, and transmitting a data file corresponding to the target instance. According to the method and the device, the technical problem of difficulty in fine control for different services and users due to the fact that authority management for file transmission services is generally based on file system levels in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of network technology and security technology. Specifically, it relates to a file transfer method, apparatus, electronic device, and non-volatile storage medium. Background Art

[0002] With the development of 5G (5th Generation Mobile Communication Technology) technology, a large number of configuration files, log files, and statistical files are generated by network element services in the 5GC (Fifth Generation Core Network) network, such as AMF (Access and Mobility Management Function), SMF (Session Management Function), and UPF (User Plane Function). These files need to be transferred frequently and securely between different network elements and with the data center.

[0003] Files generated by different services require independent access and operation permission management to ensure the security and privacy of the files. For example, operation and maintenance personnel need to remotely access the log files of a specific service for fault troubleshooting, but at the same time, it is necessary to ensure that they cannot access the sensitive files of other services.

[0004] However, the SFTP (Secure File Transfer Protocol) solution in the related art can only deploy a single service instance and cannot provide customized services for different network element services or user requirements; in an environment that requires multiple SFTP service instances, configuring and managing these instances is usually very complex and requires manual setting and adjustment. The problem of difficulty in fine-grained control for different services and different users leads to a reduction in file security and potential risks of misoperation.

[0005] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention

[0006] Embodiments of this application provide a file transfer method, apparatus, electronic device, and non-volatile storage medium to at least solve the technical problem that it is difficult to perform fine-grained control for different services and users due to the fact that the permission management for file transfer services in the related art is usually based on the file system level.

[0007] According to one aspect of the embodiments of the present application, a file transfer method is provided, including: when receiving an access request, obtaining authentication information input by a user, where the authentication information includes: a user account and a password; verifying the authentication information, and when the authentication information is verified successfully, determining a target instance corresponding to the access request, where the target instance is the service instance that the access request plans to access; verifying whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance; when it is determined that the user account has the permission to access the target instance, allowing the user account to access the target instance, and transferring the data file corresponding to the target instance.

[0008] Optionally, the access permission information includes: an authentication mode; verifying whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance includes: determining the authentication mode corresponding to the target instance, and obtaining the access permission list corresponding to the user account, where the authentication mode includes: a whitelist mode and a blacklist mode; when the authentication mode is the whitelist mode and the information corresponding to the target instance exists in the access permission list, determining that the user account has the permission to access the target instance; when the authentication mode is the blacklist mode and the information corresponding to the target instance does not exist in the access permission list, determining that the user account has the permission to access the target instance.

[0009] Optionally, before obtaining the authentication information input by the user, the method further includes: obtaining a file transfer instance configuration table in the database of the configuration center component, where the file transfer instance configuration table contains at least one piece of instance data, and the instance data is used to represent the instance configuration information corresponding to the service instance; creating a service instance according to the file transfer instance configuration table, where each piece of instance data in the file transfer instance configuration table corresponds to an independent service instance.

[0010] Optionally, the method further includes: using the configuration center component to obtain the instance configuration information set by the user, and storing the instance configuration information into the file transfer instance configuration table in the database, where the instance configuration information includes at least one of the following: instance name, service root directory path, port number, authentication mode.

[0011] Optionally, creating a service instance according to the file transfer instance configuration table further includes: using the file transfer service management component to create a service instance, and configuring service attributes for each service instance according to the instance configuration information corresponding to each service instance, where the service instance includes: a service instance based on the secure file transfer protocol; using the file transfer service management component to monitor the service status of each created service instance.

[0012] Optionally, the method further includes: using a user management component to configure an access permission list corresponding to the user account according to the instance configuration information corresponding to the service instance and the user role corresponding to the user account, where the access permission list is used to indicate the access permission and / or operation permission of the user account for each service instance.

[0013] Optionally, the data files corresponding to each service instance are isolated from each other, and the permissions of each service instance only allow access to and operation on the data files corresponding to the service instance.

[0014] According to another aspect of the embodiments of the present application, there is also provided a file transfer device, including: an information acquisition module, configured to acquire authentication information input by a user when receiving an access request, where the authentication information includes: a user account and a password; a first verification module, configured to verify the authentication information, and determine a target instance corresponding to the access request when the authentication information is verified, where the target instance is the service instance that the access request plans to access; a second verification module, configured to verify whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance; a transmission operation module, configured to allow the user account to access the target instance and perform transmission on the data files corresponding to the target instance when it is determined that the user account has the permission to access the target instance.

[0015] According to still another aspect of the embodiments of the present application, there is also provided a file transfer system, including: a user management component, a configuration center component, and a file transfer service management component, where the configuration center component is configured to acquire instance configuration information set by a user and store the instance configuration information in a file transfer instance configuration table in a database, where the file transfer instance configuration table contains at least one piece of instance data, and the instance data is used to represent the instance configuration information corresponding to the service instance; the file transfer service management component is configured to acquire authentication information input by a user when receiving an access request and send the authentication information to the user management component for verification, where the authentication information includes: a user account and a password; when the authentication information is verified, determine a target instance corresponding to the access request, and when the user management component determines that the user account has the permission to access the target instance, allow the user account to access the target instance and perform transmission on the data files corresponding to the target instance, where the target instance is the service instance that the access request plans to access, and the service instance is created by the file transfer service management component according to the file transfer instance configuration table; the user management component is configured to verify the authentication information and verify whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance.

[0016] According to another aspect of the embodiments of the present application, an electronic device is further provided, including: a memory and a processor, where the processor is configured to run a program stored in the memory, and when the program runs, it executes a file transfer method.

[0017] According to another aspect of the embodiments of the present application, a non-volatile storage medium is further provided. The non-volatile storage medium includes a stored computer program, and the device where the non-volatile storage medium is located executes a file transfer method by running the computer program.

[0018] According to another aspect of the embodiments of the present application, a computer program product is further provided, including a computer program, and when the computer program is executed by a processor, it implements the steps of a file transfer method.

[0019] In the embodiments of the present application, in the case of receiving an access request, authentication information input by the user is obtained, where the authentication information includes: a user account and a password; the authentication information is verified, and in the case where the authentication information is verified successfully, a target instance corresponding to the access request is determined, where the target instance is the service instance that the access request plans to access; according to the access permission information corresponding to the target instance, it is verified whether the user account has the permission to access the target instance; in the case of determining that the user account has the permission to access the target instance, the user account is allowed to access the target instance, and the data file corresponding to the target instance is transferred. By providing an independent SFTP service for each service instance, the purpose of operation isolation between different service files is achieved, and further, the technical problem that it is difficult to perform refined control for different services and users due to the fact that the permission management for file transfer services in the related art is usually based on the file system level is solved. Description of the Drawings

[0020] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application, and do not constitute an improper limitation to the present application. In the drawings:

[0021] Figure 1 is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a file transfer method according to an embodiment of the present application;

[0022] Figure 2 is a schematic diagram of a file transfer method flow according to an embodiment of the present application;

[0023] Figure 3 is a schematic diagram of the structure of a 5GC network element file transfer system based on SFTP according to an embodiment of the present application;

[0024] Figure 4It is a schematic diagram of the working timing of a file transfer service management component provided according to an embodiment of the present application;

[0025] Figure 5 It is a schematic diagram of the timing of the permission verification process for a user to access an SFTP service instance provided according to an embodiment of the present application;

[0026] Figure 6 It is a schematic diagram of the timing of a user's request for a file transfer operation provided according to an embodiment of the present application;

[0027] Figure 7 It is a schematic diagram of the structure of a file transfer device provided according to an embodiment of the present application;

[0028] Figure 8 It is a schematic diagram of the structure of a file transfer system provided according to an embodiment of the present application. Detailed implementation manners

[0029] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0031] In order to facilitate those skilled in the art to better understand the embodiments of the present application, some technical terms or noun explanations related to the embodiments of the present application are now described as follows:

[0032] SFTP (Secure File Transfer Protocol): A network protocol used to securely transfer files in a network. It protects the security of files during transmission through encrypted transmission.

[0033] 5GC (Fifth Generation Core Network): It is a key component of the 5G network, responsible for processing functions such as signaling, data transmission, and network security in the mobile network.

[0034] In related technologies, file transfer services usually manage permissions at the file system level, making it difficult to perform refined control for different services and different users. Moreover, file operations between individual files are not isolated. Under the same file system, files of different services may be stored in the same or adjacent directories, posing a risk of accidental operation or malicious access.

[0035] To solve the above problems, relevant solutions are provided in the embodiments of this application, which can be applied to scenarios that require refined control for different services and different users and need to isolate file access and operation permissions. Details are as follows.

[0036] According to the embodiments of this application, a method embodiment for file transfer is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0037] The method embodiments provided by the embodiments of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or electronic device) for implementing the file transfer method is shown. As Figure 1 shown, the computer terminal 10 (or electronic device) may include one or more processors 102 (the processors 102 may include, but are not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown, or have a different configuration from Figure 1 shown.

[0038] It should be noted that one or more of the above-mentioned processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" herein. The data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of other components in the computer terminal 10 (or electronic device). As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).

[0039] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the file transfer method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned file transfer method. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 can further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.

[0040] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network can include a wireless network provided by a communication provider of the computer terminal 10. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0041] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables a user to interact with the user interface of the computer terminal 10 (or electronic device).

[0042] Under the above operating environment, the embodiments of the present application provide a file transfer method. Figure 2 It is a schematic diagram of a method flow for file transfer provided according to the embodiments of the present application. As Figure 2 shown, the method includes the following steps:

[0043] Step S202: When receiving an access request, obtain the authentication information entered by the user. The authentication information includes: user account and password.

[0044] Step S204: Verify the authentication information, and when the authentication information is verified successfully, determine the target instance corresponding to the access request. The target instance is the service instance that the access request plans to access.

[0045] Step S206: According to the access permission information corresponding to the target instance, verify whether the user account has the permission to access the target instance.

[0046] Step S208: When it is determined that the user account has the permission to access the target instance, allow the user account to access the target instance and transfer the data file corresponding to the target instance.

[0047] Through the above steps, by providing an independent SFTP service for each service instance, the purpose of operation isolation between different service files is achieved, and thus the technical problem of difficult fine-grained control for different services and users caused by the fact that the permission management for file transfer services in the related technology is usually based on the file system level is solved.

[0048] Next, the file transfer method in steps S202 to S208 of the embodiment of the present application will be further introduced.

[0049] The file transfer method in the embodiment of the present application can be implemented in a 5GC network element file transfer system based on SFTP as shown in Figure 3 This system mainly includes three parts: a configuration center component, a file transfer service management component, and a user management component. These three components can communicate with each other using remote calls, such as Restful api or gRPC.

[0050] Among them, the configuration center component is mainly responsible for managing the entry and update of the file transfer instance configuration table, and storing the file transfer instance configuration table for subsequent instance creation and management; the file transfer service management component is mainly used to dynamically create SFTP service instances according to the configuration table information stored in the configuration center and monitor the running status of all SFTP service instances in real time; the user management component is mainly used to configure the access permission of the user to a specific SFTP service instance according to the authentication mode of the SFTP service instance.

[0051] Next, the flow steps of the file transfer method will be specifically introduced in combination with each component in the above file transfer system.

[0052] First, the configuration center component can be used to create and update the file transfer instance configuration table. The specific steps are as follows.

[0053] In some embodiments of the present application, the method further includes the following steps: using a configuration center component to obtain instance configuration information set by a user, and storing the instance configuration information in a file transfer instance configuration table in a database, where the instance configuration information includes at least one of the following: instance name, service root directory path, port number, authentication mode.

[0054] Specifically, after the configuration center component is started, the user can enter or import instance configuration information of a file transfer service instance through an administrator interface or an API interface, including but not limited to: instance name, service root directory path, port number, authentication mode (for example, whitelist mode or blacklist mode), etc. These instance configuration information are stored in the database of the configuration center in the form of a file transfer instance configuration table for subsequent instance creation and management.

[0055] In the subsequent process, the file transfer service management component can create independent SFTP service instances by obtaining and loading the file transfer instance configuration table. The specific steps are as follows.

[0056] In some embodiments of the present application, before obtaining the authentication information input by the user, the method further includes the following steps: obtaining a file transfer instance configuration table in the database of the configuration center component, where the file transfer instance configuration table contains at least one piece of instance data, and the instance data is used to represent the instance configuration information corresponding to the service instance; creating a service instance according to the file transfer instance configuration table, where each piece of instance data in the file transfer instance configuration table corresponds to an independent service instance.

[0057] In some embodiments of the present application, creating a service instance according to the file transfer instance configuration table further includes: using a file transfer service management component to create a service instance, and configuring service attributes for each service instance according to the instance configuration information corresponding to each service instance, where the service instance includes: a service instance based on a secure file transfer protocol; using a file transfer service management component to monitor the service status of each created service instance.

[0058] Specifically, as Figure 4 shown, first, the file transfer service management component obtains file transfer instance configuration table information from the configuration center component. Then, the file transfer service management component loads the configuration table and dynamically creates independent SFTP service instances according to the instance configuration. After that, the file transfer service management component can set service attributes such as independent network ports and service root directories for each SFTP service instance, and real-time monitor the running status of all SFTP service instances to ensure the stability and availability of the service. This way of dynamically creating service instances enables the system to quickly respond to business changes, and new or adjusted service instances can be added without downtime, improving the flexibility and response speed of the system.

[0059] Further, in the embodiments of the present application, the user management component can also assign access and operation permissions of each SFTP service instance to relevant user accounts. The specific steps are as follows.

[0060] In some embodiments of the present application, the method further includes the following steps: using the user management component, configuring an access permission list corresponding to the user account according to the instance configuration information corresponding to the service instance and the user role corresponding to the user account, where the access permission list is used to indicate the access permissions and / or operation permissions of the user account for each service instance.

[0061] Specifically, the user management component can configure the access permission of the file transfer service instance for the user through the Restful api. According to the user role, the user management component can configure the access permissions of multiple specified SFTP instances for the user. Through the configuration of the user role and the permission list, fine-grained permission control is achieved, improving the security and management efficiency of the system.

[0062] Through the above SFTP-based method, in the embodiments of the present application, for the problems in file transfer permission management and operation isolation in the related art, by subscribing to the configuration table of the configuration center, multiple independent SFTP service instances are dynamically generated, and users or user groups can have access permissions to specific SFTP service instances and other methods to manage the file transfer service, realizing operation isolation between different service files and fine-grained permission control.

[0063] Next, the permission verification process during the file transfer in the embodiments of the present application will be further introduced.

[0064] Figure 5 is a timing schematic diagram of the permission verification process for a user to access an SFTP service instance provided according to the embodiments of the present application. As Figure 5 shown, when the file transfer service instance receives an access request, it will obtain the authentication information input by the user (including the user account and password), and send the authentication information to the user management component for authentication first; after the authentication is successful, it is further necessary to verify whether the user has the permission to access the target instance (taking the SFTP service instance A as an example) corresponding to the above access request;

[0065] When performing the above further verification, it is possible to verify whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance. The specific steps are as follows.

[0066] In some embodiments of the present application, the access permission information includes: an authentication mode; verifying whether a user account has the permission to access a target instance according to the access permission information corresponding to the target instance includes the following steps: determining the authentication mode corresponding to the target instance, and obtaining the access permission list corresponding to the user account, wherein the authentication mode includes: a whitelist mode and a blacklist mode; determining that the user account has the permission to access the target instance when the authentication mode is the whitelist mode and the information corresponding to the target instance exists in the access permission list; determining that the user account has the permission to access the target instance when the authentication mode is the blacklist mode and the information corresponding to the target instance does not exist in the access permission list.

[0067] For example, if the authentication mode of the service instance A is the blacklist mode, all user accounts can access the service instance A by default. However, if the access permission list of a user account configures the SFTP instance A (equivalent to adding the user account to the blacklist corresponding to the service instance A), then this user account is not allowed to access the service instance A; conversely, if the authentication mode of the service instance A is the whitelist mode, all user accounts are not allowed to access the service instance A by default. However, if the access permission list of a user account configures the SFTP instance A (equivalent to adding the user account to the whitelist corresponding to the service instance A), then this user account can access the service instance A. This flexible configuration of the authentication mode enables the system to select the most suitable authentication method according to different business requirements and security policies, improving the adaptability of the system. At the same time, through strict user authentication and permission control, illegal access is effectively prevented, ensuring the security of data transmission.

[0068] In addition, it should be noted that the data files corresponding to each service instance in this embodiment are isolated from each other, and the permissions of each service instance only allow access to and operation on the data files corresponding to the service instance. This isolation mechanism of data files ensures the data independence between different service instances, avoids data confusion and misoperation, and improves the integrity and security of data.

[0069] For example. As Figure 6 shown, when a user requests to access the SFTP service instance 1 and the verification is passed, the user can operate on the type A data files corresponding to the SFTP service instance 1. However, due to directory isolation, the user cannot operate on the type B data files corresponding to the SFTP service instance 2. If the user needs to operate on the type B data files, the user needs to request to access the SFTP service instance 2 and perform permission verification.

[0070] The solution of this application provides an independent SFTP service for each service instance, realizing the operation isolation between different service files and effectively improving data security. The independence of different service instances means that the failure of one instance will not affect other instances, thus improving the stability of the entire system; according to the role arrangements of users and user groups, the access permissions of specific SFTP service instances can be allocated, with the access and operation permissions for specific categories of files, endowing different users and user groups with flexible and independent access permissions, and realizing the operation isolation between different service files and fine-grained permission control; the centralized management of the configuration center makes the configuration and maintenance of SFTP service instances more efficient, reducing manual intervention and improving the operation and maintenance efficiency.

[0071] According to an embodiment of the present application, an embodiment of a file transfer device is further provided. Figure 7 It is a schematic structural diagram of a file transfer device provided according to an embodiment of the present application. As Figure 7 shown, the device includes:

[0072] An information acquisition module 70, configured to acquire authentication information input by a user when receiving an access request, where the authentication information includes: a user account and a password;

[0073] A first verification module 72, configured to verify the authentication information and, when the authentication information is verified to be passed, determine a target instance corresponding to the access request, where the target instance is a service instance that the access request plans to request access to;

[0074] A second verification module 74, configured to verify whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance;

[0075] A transmission operation module 76, configured to allow the user account to access the target instance and perform transmission on the data file corresponding to the target instance when it is determined that the user account has the permission to access the target instance.

[0076] Optionally, the access permission information includes: an authentication mode; verifying whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance includes: determining the authentication mode corresponding to the target instance and acquiring the access permission list corresponding to the user account, where the authentication mode includes: a whitelist mode and a blacklist mode; when the authentication mode is the whitelist mode and the information corresponding to the target instance exists in the access permission list, it is determined that the user account has the permission to access the target instance; when the authentication mode is the blacklist mode and the information corresponding to the target instance does not exist in the access permission list, it is determined that the user account has the permission to access the target instance.

[0077] Optionally, before obtaining the authentication information input by the user, the file transfer device is further configured to: obtain a file transfer instance configuration table in the database of the configuration center component, where the file transfer instance configuration table includes at least one piece of instance data, and the instance data is used to represent the instance configuration information corresponding to the service instance; create a service instance according to the file transfer instance configuration table, where each piece of instance data in the file transfer instance configuration table corresponds to an independent service instance.

[0078] Optionally, the file transfer device is further configured to: use the configuration center component to obtain the instance configuration information set by the user, and store the instance configuration information in the file transfer instance configuration table in the database, where the instance configuration information includes at least one of the following: instance name, service root directory path, port number, authentication mode.

[0079] Optionally, creating a service instance according to the file transfer instance configuration table further includes: using the file transfer service management component to create a service instance, and configuring service attributes for each service instance according to the instance configuration information corresponding to each service instance, where the service instance includes: a service instance based on the secure file transfer protocol; using the file transfer service management component to monitor the service status of each created service instance.

[0080] Optionally, the file transfer device is further configured to: use the user management component to configure an access permission list corresponding to the user account according to the instance configuration information corresponding to the service instance and the user role corresponding to the user account, where the access permission list is used to indicate the access permission and / or operation permission of the user account for each service instance.

[0081] Optionally, the data files corresponding to each service instance are isolated from each other, and the permissions of each service instance only allow access to and operation on the data files corresponding to the service instance.

[0082] It should be noted that each module in the above file transfer device may be a program module (for example, a set of program instructions for implementing a specific function), or a hardware module. For the latter, it may be presented in the following forms, but not limited to this: the presentation form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.

[0083] It should be noted that the file transfer device provided in this embodiment can be used to execute Figure 2 the file transfer method shown, therefore, the relevant explanations of the above file transfer method also apply to the embodiments of the present application, and will not be repeated here.

[0084] According to the embodiments of the present application, an embodiment of a file transfer system is further provided. Figure 8It is a schematic structural diagram of a file transfer system provided according to an embodiment of the present application. As Figure 8 shown, the system includes:

[0085] A configuration center component 80, configured to obtain instance configuration information set by a user and store the instance configuration information in a file transfer instance configuration table in a database, where the file transfer instance configuration table contains at least one piece of instance data, and the instance data is used to represent the instance configuration information corresponding to a service instance;

[0086] A file transfer service management component 82, configured to obtain authentication information input by a user when receiving an access request, and send the authentication information to a user management component for verification, where the authentication information includes: a user account and a password; when the authentication information is verified to be passed, determine a target instance corresponding to the access request, and when the user management component determines that the user account has the permission to access the target instance, allow the user account to access the target instance, and transfer data files corresponding to the target instance, where the target instance is a service instance that the access request plans to request access to, and the service instance is created by the file transfer service management component according to the file transfer instance configuration table;

[0087] A user management component 84, configured to verify the authentication information and verify whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance.

[0088] It should be noted that the file transfer system provided in this embodiment can be used to execute Figure 2 the file transfer method shown. Therefore, the relevant explanations of the above file transfer method also apply to the embodiments of the present application, and will not be elaborated here.

[0089] The embodiments of the present application also provide a non-volatile storage medium. The non-volatile storage medium includes a stored computer program. Wherein, the device where the non-volatile storage medium is located executes the following file transfer method by running the computer program: when receiving an access request, obtain authentication information input by a user, where the authentication information includes: a user account and a password; verify the authentication information, and when the authentication information is verified to be passed, determine a target instance corresponding to the access request, where the target instance is a service instance that the access request plans to request access to; verify whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance; when it is determined that the user account has the permission to access the target instance, allow the user account to access the target instance, and transfer data files corresponding to the target instance.

[0090] The embodiments of the present application also provide a computer program product, including a computer program. When the computer program is executed by a processor, it implements the steps of the file transfer method described in each embodiment of the present application: in the case of receiving an access request, obtaining authentication information input by a user, where the authentication information includes a user account and a password; verifying the authentication information, and in the case where the authentication information is verified successfully, determining a target instance corresponding to the access request, where the target instance is a service instance that the access request plans to access; verifying whether the user account has the permission to access the target instance according to the access permission information corresponding to the target instance; in the case of determining that the user account has the permission to access the target instance, allowing the user account to access the target instance and transferring the data file corresponding to the target instance.

[0091] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.

[0092] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0093] In the several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0094] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0095] In addition, the functional units in the various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0096] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.

[0097] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. A file transmission method, characterized in that: include: Upon receiving an access request, obtaining authentication information input by the user, wherein the authentication information includes: a user account and a password; Verifying the authentication information, and if the authentication information is verified, determining a target instance corresponding to the access request, wherein the target instance is a service instance that the access request plans to request access to; Verify, based on the access permission information corresponding to the target instance, whether the user account has permission to access the target instance; In the case where it is determined that the user account has the authority to access the target instance, the user account is allowed to access the target instance, and the data file corresponding to the target instance is transmitted.

2. The file transmission method according to claim 1, characterized in that: The access permission information includes: an authentication mode; and verifying whether the user account has permission to access the target instance based on the access permission information corresponding to the target instance includes: Determine the authentication mode corresponding to the target instance, and obtain the access permission list corresponding to the user account, wherein the authentication mode includes: whitelist mode and blacklist mode; When the authentication mode is the whitelist mode and the information corresponding to the target instance exists in the access permission list, determining that the user account has permission to access the target instance; When the authentication mode is the blacklist mode and the information corresponding to the target instance does not exist in the access permission list, it is determined that the user account has the permission to access the target instance.

3. The file transmission method according to claim 1, characterized in that: Before obtaining the authentication information input by the user, the method further includes: Obtaining a file transfer instance configuration table in a database of a configuration center component, wherein the file transfer instance configuration table includes at least one instance data, and the instance data is used to represent instance configuration information corresponding to the service instance; A service instance is created according to the file transfer instance configuration table, wherein each instance data in the file transfer instance configuration table corresponds to an independent service instance.

4. The file transmission method according to claim 3, characterized in that: The method further comprises: The configuration center component is used to obtain the instance configuration information set by the user, and the instance configuration information is stored in the file transfer instance configuration table in the database, wherein the instance configuration information includes at least one of the following: instance name, service root directory path, port number, and authentication mode.

5. The file transmission method according to claim 3, characterized in that: According to the file transfer instance configuration table, creating a service instance further includes: Using a file transfer service management component, creating the service instance, and configuring service attributes for each service instance according to the instance configuration information corresponding to each service instance, wherein the service instance includes: a service instance based on a secure file transfer protocol; The file transfer service management component is used to monitor the service status of each of the created service instances.

6. The file transmission method according to claim 3, characterized in that: The method further comprises: A user management component is used to configure the access permission list corresponding to the user account based on the instance configuration information corresponding to the service instance and the user role corresponding to the user account, wherein the access permission list is used to indicate the access permission and / or operation permission of the user account for each of the service instances.

7. The file transmission method according to claim 1, characterized in that: The data files corresponding to each service instance are isolated from each other, and the authority of each service instance only allows access to and operation of the data files corresponding to the service instance.

8. A file transmission device, characterized in that: include: An information acquisition module, used to acquire authentication information input by a user when receiving an access request, wherein the authentication information includes: a user account and a password; A first verification module is used to verify the authentication information and, if the authentication information is verified, determine a target instance corresponding to the access request, wherein the target instance is a service instance that the access request plans to request access to; A second verification module, used to verify whether the user account has the authority to access the target instance according to the access permission information corresponding to the target instance; The transmission operation module is used to allow the user account to access the target instance and transmit the data file corresponding to the target instance when it is determined that the user account has the permission to access the target instance.

9. A file transfer system, characterized in that: include: User management component, configuration center component, file transfer service management component, among which, The configuration center component is used to obtain instance configuration information set by the user, and store the instance configuration information in a file transfer instance configuration table in the database, wherein the file transfer instance configuration table contains at least one instance data, and the instance data is used to represent the instance configuration information corresponding to the service instance; The file transfer service management component is used to, upon receiving an access request, obtain authentication information input by a user, and send the authentication information to the user management component for verification, wherein the authentication information includes: a user account and a password; if the authentication information is verified, determine the target instance corresponding to the access request, and if the user management component determines that the user account has the authority to access the target instance, allow the user account to access the target instance, and transfer the data file corresponding to the target instance, wherein the target instance is the service instance that the access request plans to request access, and the service instance is created by the file transfer service management component according to the file transfer instance configuration table; The user management component is used to verify the authentication information and verify whether the user account has the authority to access the target instance based on the access permission information corresponding to the target instance.

10. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the program executes the file transmission method according to any one of claims 1 to 7 when running.

11. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the file transfer method according to any one of claims 1 to 7 by running the computer program.

12. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the file transmission method according to any one of claims 1 to 7 are implemented.