Data management method and device, equipment and storage medium

By introducing the permission verification mechanism of interceptors and tag files in the distributed file system, the problem of insufficient data security management in the existing technology is solved, and fine-grained permission control for data is realized, which improves the flexibility and security of data protection.

CN120216477APending Publication Date: 2025-06-27JINAN INSPUR DATA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510396833.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing distributed file storage system has insufficient data precision management in terms of data security management, and cannot be refined for specific data directories, resulting in insufficient flexibility in data security management.

Method used

By introducing an interceptor in the distributed file system, the data requests of the upper-level clients are intercepted and the requested data directory to be accessed is parsed. Permission verification is performed based on the corresponding tag files in this directory, the tag files are maintained using metadata services, and the latest tag files are pushed to the interceptor to achieve fine-grained permission control for data requests.

Benefits of technology

It realizes finer-grained permission management of data in distributed file systems, improves the flexibility and security of data protection, and can more accurately control access to specific data directories, preventing the destruction of important data by unknown operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120216477A_ABST
    Figure CN120216477A_ABST
Patent Text Reader

Abstract

The invention discloses a data management method, device and equipment and a storage medium, is applied to a distributed file system, and relates to the technical field of data processing.The method comprises the steps that a data request issued by an upper-layer client is intercepted through an interceptor, and a to-be-accessed data directory corresponding to the data request is obtained through analysis; performing permission verification on the data request according to a tag file corresponding to the to-be-accessed data directory to obtain a corresponding verification result; a mapping relation exists between the tag file and a local data directory, and the tag file comprises a verification rule for related parameters of the data request; and responding to the data request based on the verification result. In this way, in the distributed file system, the authority verification with finer granularity is used for managing the data; more accurate access control of partial data is realized by accessing the data catalog, and the flexibility of data protection is improved; and in addition, more data request related parameters can be combined for permission verification, so that the data security is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular, to a data management method, apparatus, device, and storage medium. Background Art

[0002] HDFS (Hadoop Distributed File System) is a distributed file storage system that supports the safe mode function. In this mode, all stored data is in a read-only state and is protected, and cannot be written, modified, or deleted. This safe mode cannot protect the data under a certain path, and its coverage range is the entire service level, that is, the HDFS data is in an unavailable state, further paralyzing other upper-layer services and blocking the entire big data platform service. Therefore, currently, this function can only be used for cluster maintenance requirements and cannot be used for data security management in the daily operation and maintenance process. On the other hand, existing security management components for big data include kerberos (a computer network authorization protocol), ranger (an open-source project focusing on access control and data masking), etc. Permission users may interfere with or damage the path where important data is located by taking some unknown operations on different client nodes. Although HDFS supports the IP (Internet Protocol, generally referring to network addresses) whitelist function, it is global for cluster data and cannot be refined to specific data directories.

[0003] It can be seen from this that how to achieve precise management of data is a problem to be solved in this field. Summary of the Invention

[0004] The purpose of the embodiments of the present invention is to provide a data management method, apparatus, device, and storage medium, which can solve the problem of precise management of data in a distributed file storage system.

[0005] To solve the above technical problems, on the one hand, the embodiments of the present invention provide a data management method applied to a distributed file system, including:

[0006] Intercepting a data request sent by an upper-layer client through an interceptor, and parsing to obtain a to-be-accessed data directory corresponding to the data request;

[0007] Performing permission verification on the data request according to a tag file corresponding to the to-be-accessed data directory to obtain a corresponding verification result; the tag file has a mapping relationship with a local data directory and contains verification rules for relevant parameters of the data request;

[0008] Responding to the data request based on the verification result.

[0009] In some embodiments, intercepting the data request sent by the upper-layer client by the interceptor includes:

[0010] When the data request sent by the upper-layer client is obtained, determine whether the interception function of the interceptor of the current client interface is in the enabled state;

[0011] If the interception function is in the enabled state, intercept the data request through the interceptor to obtain the data request.

[0012] In some embodiments, parsing to obtain the data directory to be accessed corresponding to the data request includes:

[0013] Parse the data request to obtain the corresponding parsed parameters, and determine the data directory to be accessed corresponding to the data request from the parsed parameters;

[0014] Among them, the parsed parameters include the access data directory, access time, network address of the upper-layer client, and the target operation type of the data request.

[0015] In some embodiments, before performing permission verification on the data request according to the label file corresponding to the data directory to be accessed to obtain the corresponding verification result, it further includes:

[0016] Obtain the interception rule operation instruction for the interceptor through a preset visual interaction interface;

[0017] Generate a corresponding label file according to the current timestamp and the interception rule operation instruction, and use the metadata service to maintain each label file; the label file includes the data directory, network address, permission effective time, and operation type;

[0018] Push the label file to the interceptor so as to perform permission verification on the data request according to the label file corresponding to the data directory to be accessed to obtain the corresponding verification result.

[0019] In some embodiments, pushing the label file to the interceptor includes:

[0020] When the interceptor is enabled or the label file changes, push the latest label file currently stored to the interceptor through the metadata service.

[0021] In some embodiments, performing permission verification on the data request according to the label file corresponding to the data directory to be accessed to obtain the corresponding verification result includes:

[0022] Determine a target tag file corresponding to the data request according to the matching situation between the data directory to be accessed and the data directories in a number of tag files corresponding to the interceptor;

[0023] If the access time of the data request is not within the permission effective time period in the target tag file, generate a first verification result indicating that the verification passes for the data request;

[0024] If the access time is within the permission effective time period, determine whether the client address of the data request matches the network address in the target tag file;

[0025] If the client address does not match the network address, generate a second verification result indicating that the verification fails for the data request;

[0026] If the client address matches the network address, determine the legality of the target operation type corresponding to the data request according to the target tag file, and obtain a corresponding judgment result;

[0027] If the judgment result indicates that the target operation type is legal, generate a third verification result indicating that the verification passes for the data request, otherwise generate a fourth verification result indicating that the verification fails for the data request.

[0028] In some embodiments, the responding to the data request based on the verification result includes:

[0029] For the first verification result and the third verification result, perform corresponding data operations based on the data request, and respond to the data request with the corresponding operation results;

[0030] For the second verification result and the fourth verification result, generate a prompt message indicating that there is an abnormality in the data request, and respond to the data request with the prompt message.

[0031] In a second aspect, an embodiment of the present invention provides a data management device, which is applied to a distributed file system and includes:

[0032] A data request parsing module, configured to intercept a data request sent by an upper-layer client through an interceptor, and parse to obtain a data directory to be accessed corresponding to the data request;

[0033] A permission verification module, configured to perform permission verification on the data request according to a tag file corresponding to the data directory to be accessed, and obtain a corresponding verification result; there is a mapping relationship between the tag file and a local data directory, and the tag file includes verification rules for relevant parameters of the data request;

[0034] A response module, configured to respond to the data request based on the verification result.

[0035] In a third aspect, an embodiment of the present invention provides an electronic device, including:

[0036] A memory, configured to store a computer program;

[0037] A processor, configured to execute the computer program to implement the steps of the data management method as described above.

[0038] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the data management method as described above are implemented.

[0039] It can be seen from the above technical solutions that in the distributed file system of the present application, a data request sent by an upper-layer client can be intercepted by an interceptor, and the data directory to be accessed corresponding to the data request can be parsed; then, based on the label file corresponding to the data directory to be accessed, a permission verification is performed on the data request to obtain a corresponding verification result; there is a mapping relationship between the label file and the local data directory, and the label file includes verification rules for relevant parameters of the data request; and then, the data request is responded to based on the verification result. The effect of this solution is that in the distributed file system, data is managed using a more fine-grained permission verification; by accessing the data directory, more precise access control is achieved for some data, improving the flexibility of data protection; and more relevant parameters of the data request can be combined for permission verification, further improving data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] To describe the embodiments of the present invention more clearly, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0041] Figure 1 It is a flowchart of a data management method disclosed in the present application;

[0042] Figure 2 It is a flowchart of a specific data management method disclosed in the present application;

[0043] Figure 3 It is a flowchart of another specific data management method disclosed in the present application;

[0044] Figure 4 It is a flowchart of yet another specific data management method disclosed in the present application;

[0045] Figure 5 Structural schematic diagram of a data management device disclosed in this application;

[0046] Figure 6 Structural diagram of an electronic device disclosed in this application. Detailed implementation manners

[0047] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0048] The terms "including" and "having" in the specification of the present invention and the accompanying drawings, and any variations related to "including" and "having", are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may include steps or units not listed.

[0049] In order to enable those skilled in the art of this technology to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0050] As Figure 1 shown, an embodiment of this application discloses a data management method, which is applied to a distributed file system and includes:

[0051] Step S11: Intercept a data request sent by an upper-layer client through an interceptor, and parse to obtain a data directory to be accessed corresponding to the data request.

[0052] In this application, an interceptor can be embedded in the distributed file system to intercept data requests sent by the upper-layer client; in this way, some data requests can be filtered by the interceptor; and it will not affect the execution process of the distributed file system. After intercepting the data request sent by the upper-layer client through the interceptor, the data request can be parsed to obtain the corresponding data directory to be accessed.

[0053] In a specific embodiment, intercepting the data request sent by the upper-layer client by the interceptor may include: when the data request sent by the upper-layer client is obtained, determining whether the interception function of the interceptor of the current client interface is in an enabled state; if the interception function is in the enabled state, intercepting the data request by the interceptor to obtain the data request. Specifically, the interceptor in the distributed file system can be selectively enabled or disabled, that is, when the data request from the upper-layer client is obtained, the state of the interceptor corresponding to the current client interface can be determined; if the interception function of the interceptor is in the enabled state, the interceptor can be used to intercept the current data request to obtain the data request.

[0054] In another embodiment, parsing to obtain the data directory to be accessed corresponding to the data request may include: parsing the data request to obtain corresponding parsed parameters, and determining the data directory to be accessed corresponding to the data request from the parsed parameters; wherein, the parsed parameters include the access data directory, access time, network address of the upper-layer client, and the target operation type of the data request. Specifically, after the distributed file system obtains the data request sent by the upper-layer client through the interceptor, the data request can be parsed to parse out relevant parameters; such as the access data directory, access time, network address of the upper-layer client, and the operation type of the data request; among them, the operation type may include any operation such as listing, reading, writing, deleting, etc. Further, the data directory to be accessed corresponding to the data request is determined from the parsed parameters.

[0055] Step S12, performing a permission check on the data request according to the label file corresponding to the data directory to be accessed, and obtaining a corresponding check result; there is a mapping relationship between the label file and the local data directory, and the label file contains the check rules for the relevant parameters of the data request.

[0056] In the embodiment of the present application, the data directory to be accessed corresponding to the data request can be determined through the above steps; then, the label file corresponding to the data request can be further determined; the label file is a file that is preset and has a mapping relationship with the local data directory, and the file contains the check rules for the relevant parameters of the data request; it can be understood that the check rules may include the restriction conditions for the network address, the restriction conditions for the time, and the restriction conditions for the operation type. The label file can be queried based on the data directory to be accessed corresponding to the data request; then, the data request can be checked for legality based on the label file to obtain a corresponding check result.

[0057] It can be understood that in order to use the label file to verify the data request, several label files can be preset in advance for subsequent direct verification of the data request; in a specific embodiment, before performing permission verification on the data request according to the label file corresponding to the data directory to be accessed and obtaining a corresponding verification result, the following steps may further be included: obtaining an interception rule operation instruction for the interceptor through a preset visual interaction interface; generating a corresponding label file according to the current timestamp and the interception rule operation instruction, and maintaining each label file by using a metadata service; the label file includes a data directory, a network address, a permission effective time, and an operation type; pushing the label file to the interceptor so as to perform permission verification on the data request according to the label file corresponding to the data directory to be accessed and obtain a corresponding verification result. Specifically, during the process of setting the label file, relevant staff can input an operation instruction for configuring the interception rule through the visual interaction interface; in a distributed file system, a corresponding label file can be generated based on the current timestamp and each interception rule operation instruction; the label file includes a mapping relationship with the data directory, several network addresses for verifying the client network address, the permission effective time of the interception rule, and relevant policy information for verifying the operation type. And each label file is maintained by using a metadata service; for example, when the label file is updated, the previously saved label file can be replaced according to the timestamp. Further, the distributed file system can push the saved label file to the interceptor so that the interceptor can intercept and verify the data request based on the corresponding label file.

[0058] In a specific embodiment, each configuration maps a set of interception rules, including four basic dimensions: IP, data path, operation type, and time. Among them, the IP is the client IP that issues the request. The operation types include a series of operations supported by native protocols such as listing (ls), reading (cat, get, etc.), writing (put, etc.), deleting (rm), and attribute setting (such as chmod, setfacl, etc.). The time is the permission effective time and expiration time, supporting delayed effectiveness. The visual interaction interface can communicate with the metadata service in real time. When relevant personnel submit each configuration, a data structure such as {ip:xxx; path:xxx; option:xxx; authtimes:xxx; timestamp:xxx} will be encapsulated, that is, in addition to including IP, path, operation word, and permission effective time, it also includes a latest timestamp, which is sent to each node of the metadata service to support real-time addition, deletion, and modification of verification rules. And, based on the former two, more convenient configuration operations are further provided, such as supporting a certain IP segment, supporting fuzzy regular expressions for path paths, supporting forward and reverse filtering of operation types, etc. In a specific embodiment, the metadata service maintains the verification rules submitted by relevant personnel from the interaction interface. At the same time, as a bridge for interaction, it maintains real-time communication with the upstream management page and the downstream interceptor, and can include the following functions: The metadata service is deployed in a multi-node manner in a decentralized way, and the nodes communicate with each other in real time through heartbeats. When the service process is interrupted, it will be automatically awakened; Each node of the metadata service will receive the requests sent by the visual interface, save the verification rules configured by the user in the configuration file of the local node for persistent maintenance. When the service node is disconnected and restarted, it will automatically load the local configuration file to obtain the current verification rules. At the same time, during the real-time communication process of each node, the latest data will be verified based on the timestamp with each other, and the lagging nodes will be automatically updated; The metadata service interacts with the request interceptor in real time and passes the latest verification rules downstream.

[0059] In another specific embodiment, the pushing of the label file to the interceptor may include: when the interceptor is started or the label file changes, the latest label file currently stored is pushed to the interceptor through the metadata service. Specifically, in order to save resources, the distributed file system can choose to push the latest label file to the interceptor when the interceptor is started or when the label file changes (updated, deleted, etc.); During this process, based on the timestamps corresponding to each label file, the lagging label files are automatically updated.

[0060] In yet another specific embodiment, the permission verification of the data request according to the label file corresponding to the data directory to be accessed, and obtaining the corresponding verification result may include: determining a target label file corresponding to the data request according to the matching situation between the data directory to be accessed and the data directories in several label files corresponding to the interceptor; if the access time of the data request is not within the permission effective time period in the target label file, generating a first verification result indicating that the verification is passed for the data request; if the access time is within the permission effective time period, determining whether the client address of the data request matches the network address in the target label file; if the client address does not match the network address, generating a second verification result indicating that the verification fails for the data request; if the client address matches the network address, determining the legality of the target operation type corresponding to the data request according to the target label file, and obtaining the corresponding determination result; if the determination result indicates that the target operation type is legal, generating a third verification result indicating that the verification is passed for the data request, otherwise generating a fourth verification result indicating that the verification fails for the data request. Specifically, in the process of verifying the data request based on the label file, first determine the target label file corresponding to the data directory to be accessed by the data request, and according to the mapping relationship between each label file and the data path, determine a label file that matches the data directory to be accessed, denoted as the target label file. Then, according to the restriction strategy of each parameter in the target label file, verify the access time, network address, and operation type of the data request respectively.

[0061] Furthermore, since the permission effective time in the label file indicates whether it is necessary to verify the data request, therefore, if the current time does not match the permission effective time, it can be directly released, and a verification result indicating that the verification is passed is generated. Correspondingly, if the permission effective time indicates that the current verification is required, the upper-layer client network address of the data request is further verified. If it does not match the network address saved in the label file, it means that the client network address is illegal, and a verification result indicating that the verification fails is generated. Further, if the network address verification passes, the operation type of the data request can be further verified to determine whether the restriction strategy in the label file allows or prohibits the operation type; it can be understood that if it indicates that the operation type is allowed, it means that the verification passes, otherwise a verification result indicating that the verification fails is generated.

[0062] In a specific embodiment, such as Figure 2As shown, the user configures the verification rules through the visual interface, and persists the configured verification rules through the metadata service, that is, converts the verification rules into tag files in combination with the time stamp, and maintains each tag file; when needed later, push the tag file to the request interceptor so that the interceptor can verify the data requests sent to different clients, and the legitimate requests after passing the verification will continue to be processed; the distributed file system server can respond to the corresponding legitimate data requests in combination with data storage.

[0063] Step S13, respond to the data request based on the verification result.

[0064] In the embodiments of the present application, through the above steps, the data requests can be intercepted by the interceptor, and the legality of the data requests can be verified based on the tag files to obtain the corresponding verification results; further, it can be determined whether to execute the data requests based on the verification results. In a specific embodiment, the responding to the data request based on the verification result may include: for the first verification result and the third verification result, performing corresponding data operations based on the data request, and responding to the data request with the corresponding operation results; for the second verification result and the third verification result, generating a prompt message indicating that the data request is abnormal, and responding to the data request with the prompt message. Specifically, if the verification result is the first verification result or the third verification result indicating that the verification is passed, the data request can be normally executed, and the upper-layer service corresponding to the data request can be completed using the relevant local data; correspondingly, if the verification result is the second verification result or the third verification result indicating that the verification fails, it means that the data request is illegal, and the data request does not need to be executed. A prompt message indicating that the data request is abnormal can be generated, and the data request can be responded to with the prompt message.

[0065] In another specific embodiment, such as Figure 3As shown in the figure, the server of the distributed file system can embed interceptors in the form of code segments, introduce the code module of the interceptor before each interface for processing the original data requests initiated by the client, and at the same time provide a new configuration item to globally switch the interceptor. If it is turned off, the execution process will automatically skip the code module of the interceptor. It can be understood that the interceptor needs to parse the data requests of the client and verify the parameters obtained from the parsing, namely the client IP, operation field, permission effective time, and data directory path. Requests that do not meet the verification will be sent back by reporting an exception, and requests that meet the requirements will continue to be executed after passing the verification. It should be noted that the interceptor can obtain the interception policy (i.e., the tag file containing the interception rules) through the active push of the metadata service. At the same time, in order to avoid the additional performance loss caused by frequent interactions, the push will only be triggered when the service is started for the first time or the interception policy changes. The interceptor will save this data in the distributed file system service process variables for verification and judgment.

[0066] It can be seen that in the distributed file system, this application uses more fine-grained permission verification to manage data; through accessing the data directory, more precise access control is achieved for some data, improving the flexibility of data protection; and permission verification can be combined with more data request-related parameters, which can prevent some unknown services from damaging important data and does not affect the access behavior of general data; while further improving data security, the visual configuration also reduces the operation cost of the operation and maintenance personnel.

[0067] As Figure 4 shown, the embodiment of this application discloses a data management method, which specifically includes:

[0068] In this embodiment, the upper-layer client service can send a data request to HDFS (Distributed File System). This data request is intercepted by an interceptor, and necessary parameters are parsed from it, including the directory to be accessed, the current access time, the source IP of the upper-layer service, and the operation type. At the same time, according to the directory path to be accessed in the data request, the corresponding tag file can be obtained. This tag file is a data structure formed when the user configures on the visualization page and has only a logical mapping relationship with the data directory. In fact, it is stored as metadata in the metadata service module. In a specific embodiment, an example of the tag data structure: directory path: / xxx / dir1; IP or IP segment: xx.xx.xx.xx; IP permission policy: allow / block; operation type: read / write, etc.; operation permission policy: allow / block; permission time: including the effective time and the expiration time; multiple non-conflicting tags can be bound to one directory. It can be understood that the customer can configure permissions for each data directory at the front end, forming a data structure including the path of the directory, IP or IP segment (including matching policies of allow or prohibit, i.e., white and black lists), operation type (including matching policies of allow or prohibit), permission effective time, and expiration time for metadata storage.

[0069] Further, after obtaining the relevant data of the tag file, permission verification can be performed with the parameters of the upper-layer data request. During the permission verification process, first compare whether the current time matches the permission effective time in the tag. If the effective time has not started or has expired, the data request is directly released and allowed to access. If the current time is within the permission effective period of the directory, according to the IP configuration in the tag file, verify the IP source of the data request. If it passes, then verify the operation type. If all pass, the verification is completed and access is allowed. If not, an exception is returned to the client.

[0070] It can be seen that this application is mainly applied to more fine-grained protection of data in the distributed file system. The data requests of the client can be intercepted by an interceptor set in the distributed file system to filter out illegal services. The filtering principles include the IP of the requestor, the accessed data directory path, and the operation type. And combined with a decentralized metadata service, it can be deployed in each node in a cluster manner to maintain the access restriction rules for data requests configured by relevant personnel and synchronize these rules to the request interceptor. The interceptor can intercept request access according to these rules. By accessing the data directory, more accurate access control of some data can be achieved, improving the flexibility of data protection. And permission verification can be combined with more data request-related parameters, improving data security.

[0071] As Figure 5 shown, an embodiment of this application discloses a data management device applied to a distributed file system, including:

[0072] A data request parsing module 11, configured to intercept a data request sent by an upper-layer client through an interceptor and parse to obtain a data directory to be accessed corresponding to the data request;

[0073] An authority verification module 12, configured to perform authority verification on the data request according to a label file corresponding to the data directory to be accessed, and obtain a corresponding verification result; there is a mapping relationship between the label file and a local data directory, and the label file includes verification rules for relevant parameters of the data request;

[0074] A response module 13, configured to respond to the data request based on the verification result.

[0075] It can be seen that in the present application, in a distributed file system, more fine-grained authority verification is used to manage data; by accessing the data directory, more accurate access control is implemented for some data, improving the flexibility of data protection; and more relevant parameters of the data request can be combined for authority verification, further improving data security.

[0076] In a specific embodiment, the data request parsing module 11 may include:

[0077] An interception function determination unit, configured to determine whether the interception function of the interceptor of the current client interface is in an enabled state when a data request sent by an upper-layer client is obtained;

[0078] A data request interception unit, configured to perform an interception operation on the data request through the interceptor to obtain the data request when the interception function is in the enabled state.

[0079] In another specific embodiment, the data request parsing module 11 may include:

[0080] A data request parsing unit, configured to parse the data request to obtain corresponding parsed parameters, and determine a data directory to be accessed corresponding to the data request from the parsed parameters;

[0081] Wherein, the parsed parameters include an access data directory, an access time, a network address of the upper-layer client, and a target operation type of the data request.

[0082] In a specific embodiment, the apparatus may further include:

[0083] An instruction acquisition module, configured to acquire an interception rule operation instruction for the interceptor through a preset visual interaction interface;

[0084] A label file maintenance module, configured to generate corresponding label files according to the current timestamp and the interception rule operation instructions, and maintain each of the label files by using the metadata service; the label files include a data directory, a network address, a permission effective time, and an operation type;

[0085] A label file pushing module, configured to push the label files to the interceptor, so as to perform permission verification on the data request according to the label file corresponding to the data directory to be accessed, and obtain corresponding verification results.

[0086] In another specific embodiment, the label file pushing module may include:

[0087] A label file pushing unit, configured to push the latest stored label files to the interceptor through the metadata service when the interceptor is started or the label files change.

[0088] In one specific embodiment, the permission verification module 12 may include:

[0089] A label file determination unit, configured to determine a target label file corresponding to the data request according to the matching condition between the data directory to be accessed and the data directories in several label files corresponding to the interceptor;

[0090] A time verification unit, configured to generate a first verification result indicating verification passed for the data request when the access time of the data request is not within the permission effective time period in the target label file;

[0091] A time verification unit, configured to, when the access time is within the permission effective time period, determine whether the client address of the data request matches the network address in the target label file;

[0092] An address verification unit, configured to generate a second verification result indicating verification failed for the data request when the client address does not match the network address;

[0093] An operation type verification unit, configured to, when the client address matches the network address, perform a legality judgment on the target operation type corresponding to the data request according to the target label file, and obtain a corresponding judgment result;

[0094] A verification result generation unit, configured to generate a third verification result indicating verification passed for the data request when the judgment result indicates that the target operation type is legal, and otherwise generate a fourth verification result indicating verification failed for the data request.

[0095] In one specific embodiment, the response module 13 may include:

[0096] A first response unit, configured to perform corresponding data operations on the basis of the data request according to the first verification result and the third verification result, and respond to the data request by using the corresponding operation result.

[0097] A second response unit, configured to generate a prompt message indicating that the data request is abnormal according to the second verification result and the third verification result, and respond to the data request by using the prompt message.

[0098] Furthermore, an embodiment of the present application also discloses an electronic device. Figure 6 It is a structural diagram of an electronic device shown according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation to the scope of use of the present application. The electronic device may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Wherein, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the data management method disclosed in any of the foregoing embodiments. In addition, the electronic device in this embodiment may specifically be an electronic computer.

[0099] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device; the communication interface 24 can create a data transmission channel between the electronic device and an external device, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed thereon herein; the input / output interface 25 is used to obtain external input data or output data to the outside, and the specific interface type thereof may be selected according to specific application requirements, and no specific limitation is imposed herein.

[0100] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be temporary storage or permanent storage.

[0101] Wherein, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device, and it may be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program capable of implementing the data management method executed by the electronic device disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.

[0102] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the data management method disclosed above. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated herein.

[0103] Furthermore, the present application also discloses a computer program product, including a computer program / instructions, which implements the data management method disclosed above when executed by a processor.

[0104] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.

[0105] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0106] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0107] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising said element.

[0108] The technical solutions provided in this application have been introduced in detail above. Specific examples are used in this text to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A data management method, characterized in that: Applicable to distributed file systems, including: The data request sent by the upper-layer client is intercepted by the interceptor, and the directory of data to be accessed corresponding to the data request is obtained by parsing; Performing permission verification on the data request according to the label file corresponding to the data directory to be accessed, and obtaining a corresponding verification result; there is a mapping relationship between the label file and the local data directory, and contains verification rules for relevant parameters of the data request; The data request is responded to based on the verification result.

2. The data management method according to claim 1, characterized in that: The interception of the data request sent by the upper-layer client by the interceptor includes: When obtaining the data request sent by the upper-layer client, determine whether the interception function of the interceptor of the current client interface is turned on; If the interception function is in the on state, the data request is intercepted by the interceptor to obtain the data request.

3. The data management method according to claim 1, characterized in that: The parsing obtains a directory of data to be accessed corresponding to the data request, including: Parsing the data request to obtain corresponding parsed parameters, and determining the to-be-accessed data directory corresponding to the data request from the parsed parameters; The parsed parameters include the access data directory, the access time, the network address of the upper-layer client, and the target operation type of the data request.

4. The data management method according to claim 1, characterized in that: Before performing permission verification on the data request according to the tag file corresponding to the to-be-accessed data directory and obtaining a corresponding verification result, the method further includes: Obtaining interception rule operation instructions for the interceptor through a preset visual interactive interface; Generate a corresponding label file according to the current timestamp and the interception rule operation instruction, and use the metadata service to maintain each label file; the label file contains the data directory, network address, permission effective time and operation type; The label file is pushed to the interceptor so as to perform permission verification on the data request according to the label file corresponding to the data directory to be accessed to obtain a corresponding verification result.

5. The data management method according to claim 4, characterized in that: The step of pushing the tag file to the interceptor includes: When the interceptor is turned on or the tag file changes, the latest tag file currently stored is pushed to the interceptor through the metadata service.

6. The data management method according to any one of claims 1 to 5, characterized in that: The performing permission verification on the data request according to the tag file corresponding to the data directory to be accessed to obtain a corresponding verification result includes: Determine the target label file corresponding to the data request according to the matching between the data directory to be accessed and the data directories in the several label files corresponding to the interceptor; If the access time of the data request is not within the permission effective time period in the target tag file, generating a first verification result indicating that the verification has passed for the data request; If the access time is within the permission effective time period, determining whether the client address of the data request matches the network address in the target tag file; If the client address does not match the network address, generating a second verification result indicating a verification failure for the data request; If the client address matches the network address, the legality of the target operation type corresponding to the data request is judged according to the target tag file to obtain a corresponding judgment result; If the judgment result indicates that the target operation type is legal, a third verification result indicating that the verification has passed is generated for the data request; otherwise, a fourth verification result indicating that the verification has failed is generated for the data request.

7. The data management method according to claim 6, characterized in that: The responding to the data request based on the verification result includes: performing corresponding data operations based on the data request for the first verification result and the third verification result, and responding to the data request using the corresponding operation results; Based on the second verification result and the third verification result, prompt information indicating that an abnormality exists in the data request is generated, and the prompt information is used to respond to the data request.

8. A data management device, characterized in that: Applicable to distributed file systems, including: A data request parsing module is used to intercept the data request sent by the upper-layer client through an interceptor, and parse to obtain the to-be-accessed data directory corresponding to the data request; A permission verification module is used to perform permission verification on the data request according to the label file corresponding to the data directory to be accessed, and obtain a corresponding verification result; there is a mapping relationship between the label file and the local data directory, and contains verification rules for relevant parameters of the data request; A response module is used to respond to the data request based on the verification result.

9. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to execute the computer program to implement the steps of the data management method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the data management method according to any one of claims 1 to 7 are implemented.