Document storage method and device, computer equipment and program product
By monitoring process creation operations and using isolated container technology, documents are automatically stored to the server, solving the problem that documents cannot be stored in time in the enterprise office environment, and achieving unified management and secure storage of documents.
Patent Information
- Application Number
- CN202510738829.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-07-04
AI Technical Summary
In a modern enterprise office environment, documents cannot be stored on the network in a timely manner, resulting in difficulties in unified management. The existing technology relies on users to actively upload, and cannot guarantee the timely storage of important documents, and there is a risk of data leakage.
By listening to process creation operations, using process attributes and software process whitelists to determine whether to perform containerization processing, creating isolated containers to take over application processes and operating system data interfaces, using network storage technology to generate replacement saving paths on the server side, and automatically store documents to the server side.
It realizes timely and unified storage of documents, improves document management efficiency and security, avoids the problem of timely uploading important documents, and reduces the risk of data leakage.
Smart Images

Figure CN120256543A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technologies, and in particular, to a document storage method, apparatus, computer device, and program product. Background Art
[0002] In a modern enterprise office environment, document management is a key link to ensure file security and promote collaboration. With the popularization of the distributed office model, each employee usually edits documents by using a personal terminal, which results in enterprise-related documents being scattered on the terminals of each employee, bringing difficulties to the unified management of documents.
[0003] To facilitate the unified management of documents, the usual approach is to require employees to actively upload the edited documents to a cloud server for unified storage. However, this approach completely relies on the employees' active upload behavior and cannot ensure that all important documents will be stored in the cloud server in a timely manner, with relatively large drawbacks. Summary of the Invention
[0004] Embodiments of the present disclosure at least provide a document storage method, apparatus, computer device, and program product to solve the problem that documents cannot be stored in the network in a timely manner.
[0005] In a first aspect, an embodiment of the present disclosure provides a document storage method, including: In response to creating an application process, determining whether to perform containerization processing on the application process according to the process attribute of the application process and a software process whitelist obtained from a server; the application process is used to open and edit a target document; If so, creating an isolation container for the application process; the isolation container is used to isolate and take over the data interface between the application process and the operating system; In response to detecting a save operation of the application process, using the isolation container to generate a target save path for replacing the local save path in a local mapped disk corresponding to the server on the service side according to the local save path of the save operation by using network storage technology; Storing the target document that has been edited in the application process to the target save path.
[0006] In a possible implementation manner, the determining whether to perform containerization processing on the application process according to the process attribute of the application process and a software process whitelist obtained from a server includes: Determining whether the target document opened in the application process after creating the application process is a new document; If so, determine whether to perform containerization processing on the application process according to whether the target process attribute consistent with the process attribute of the application process is stored in the software process whitelist.
[0007] In a possible implementation manner, the method further includes: If the target document is not a new document, determine whether the historical save path of the target document is located in the local mapped disk; If not, use the document analysis model to perform importance analysis on the existing content of the target document to obtain the importance score of the target document; Determine whether to perform containerization processing on the application process according to the importance score.
[0008] In a possible implementation manner, the using the isolation container to generate a target save path for replacing the local save path in the corresponding local mapped disk on the server side by using network storage technology according to the local save path of the save operation includes: Use the isolation container to determine the save directory structure according to the local save path, and extract the relative save path except the local disk from the local save path; Obtain the save path template corresponding to the application process from the software process whitelist; According to the save directory structure, use network storage technology to generate the target save path in the local mapped disk according to the relative save path and the save path template.
[0009] In a possible implementation manner, the storing the target document edited in the application process to the target save path includes: Detect whether there is a network connection with the server; If not, establish a temporary save path locally and associate the temporary save path with the target save path; Store the edited target document to the temporary save path until the network connection is restored, and use the network connection to synchronize the document content stored in the temporary save path to the target save path.
[0010] In a possible implementation manner, the storing the target document edited in the application process to the target save path includes: Perform structure analysis and semantic analysis on the document content of the edited target document to determine the document structure feature and document content feature of the target document; Determine the document type according to the document attribute feature, the document structure feature and the document content feature of the edited target document; Determine the document encryption level and the encryption method matching the document encryption level according to the editing features of the edited target document and the document type; Encrypt and store the edited target document in the target save path according to the encryption method matching the document encryption level.
[0011] In a possible implementation, after encrypting and storing the edited target document in the target save path, it further includes: In response to a viewing operation of any first user on the target document stored in the target save path, obtain the authentication information of the first user; Send the authentication information of the first user to the server; the server is used to authenticate the first user and determine the permission level according to the authentication information, and decrypt the target document stored in the target save path in the case of successful authentication, and feedback the decrypted target document and the display duration matching the permission level; Obtain the decrypted target document and the display duration, and display the decrypted target document according to the display duration.
[0012] In a possible implementation, after storing the target document edited in the application process in the target save path, it further includes: Determine the target index information of the target document according to the document source information, document structure features, and document content features of the edited target document; Determine the association degree information between the target document and other documents already stored in the server according to the target index information and the already stored index information in the database corresponding to the server; Associatively store the target index information, the association degree information, and the target save path of the target document in the database; In response to a retrieval operation of any second user, determine the matching document with the highest matching degree with the retrieval operation according to the retrieval information and the already stored index information in the database; Obtain the matching document according to the save path associated with the matching document; Display the matching document, and recommend each other document associated with the matching document to the second user according to the association degree information associated with the matching document.
[0013] In a possible implementation, the storing the target document edited in the application process in the target save path includes: Obtain the current network environment, the current location information of the user, and the editing features of the target document; Using a security assessment service, determine whether to block the isolated container according to the current network environment, the current location information, and the editing feature; If not, store the edited target document to the target save path.
[0014] In a possible implementation manner, the method further includes: If it is determined to block the isolated container, store the edited target document to the local save path and display a prompt message; the prompt message includes storage method information and the reason for blocking; In response to canceling the blocking of the isolated container, merge and store the target document stored in the local save path into the target document already stored in the target save path, and display a new prompt message.
[0015] In a second aspect, an embodiment of the present disclosure further provides a document storage device, including: A determination module, configured to, in response to creating an application process, determine whether to perform containerization processing on the application process according to the process attribute of the application process and the software process whitelist obtained from the server; the application process is used to open and edit a target document; A creation module, configured to, if so, create an isolated container for the application process; the isolated container is used to isolate and take over the data interface between the application process and the operating system; A generation module, configured to, in response to detecting a save operation of the application process, use the isolated container to generate a target save path for replacing the local save path in the corresponding local mapped disk on the server by using network storage technology according to the local save path of the save operation; A storage module, configured to store the edited target document in the application process to the target save path.
[0016] In a third aspect, an alternative implementation of the present disclosure further provides a computer device, including a processor and a memory, where the memory stores machine-readable instructions executable by the processor, and the processor is configured to execute the machine-readable instructions stored in the memory. When the machine-readable instructions are executed by the processor, the steps in the first aspect, or any possible implementation manner in the first aspect are performed.
[0017] In a fourth aspect, an alternative implementation of the present disclosure further provides a computer program product, including a computer program, where when the computer program is run, the steps in the first aspect, or any possible implementation manner in the first aspect are implemented.
[0018] The document storage method, apparatus, computer device, and program product provided by the embodiments of the present disclosure can, by listening for process creation operations, determine in a timely manner whether to perform containerization processing on an application process based on the process attributes of the newly created application process and the software process whitelist. Since containerization processing can be used to force the target document to be stored on the server, it is possible to determine in a timely manner whether to store the target document in the application process on the server based on the process attributes and the software process whitelist. In the case where containerization processing is determined to be required, by creating an isolated container to take over the data interface between the application process and the operating system, it is possible to create a target save path for replacing the local save path using the isolated container when a save operation is detected. Then, by storing the edited target document in the target save path, it is possible to uniformly store the target documents edited by different users on the server without the user actively uploading the documents to the server, thereby facilitating the unified management and storage of the documents edited by different users and improving document security. Moreover, the process of uploading the edited target document of the user to the server is automatically executed when a local save behavior is detected, so that the problem that important documents cannot be uploaded to the server in a timely manner can be effectively avoided, and the efficiency and timeliness of unified document storage are improved.
[0019] For the effect descriptions of the above-mentioned document storage device, computer device, and computer program product, refer to the descriptions of the above-mentioned document storage method, which will not be elaborated here.
[0020] To make the above-mentioned objects, features, and advantages of the present disclosure more obvious and understandable, the following specific embodiments are given, and in conjunction with the accompanying drawings, the detailed description is as follows. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings required for the embodiments will be briefly introduced below. The accompanying drawings are incorporated into the specification and form a part of the specification. These drawings show embodiments that conform to the present disclosure and are used together with the specification to illustrate the technical solutions of the present disclosure. It should be understood that the following drawings only show some embodiments of the present disclosure and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0022] Figure 1 Shows a flowchart of a document storage method provided by an embodiment of the present disclosure; Figure 2 Shows a schematic diagram of a document storage device provided by an embodiment of the present disclosure; Figure 3 Shows a schematic diagram of the structure of a computer device provided by an embodiment of the present disclosure. Detailed implementation manners
[0023] To make the objectives, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are only some, but not all, of the embodiments of the present disclosure. Components of the embodiments of the present disclosure described and illustrated herein can be arranged and designed in a variety of different configurations. Therefore, the following detailed description of the embodiments of the present disclosure is not intended to limit the scope of the claimed present disclosure, but is merely representative of the selected embodiments of the present disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of the present disclosure without creative efforts fall within the scope of the present disclosure.
[0024] In addition, the terms "first", "second", etc. in the description and claims of the embodiments of the present disclosure and the above-mentioned accompanying drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order different from that shown or described herein.
[0025] As used herein, "a plurality of" or "several" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.
[0026] It has been found through research that the enterprise document management goals mainly adopt two types of technical routes. One is the traditional file server system, such as Windows shared folders, File Transfer Protocol (FTP) servers, etc.; the other is the professional document management system, such as Product Data Management (PDM) systems, Product Life-Cycle Management (PLM) systems, and various enterprise knowledge bases. These two types of technical routes usually require users to actively upload files to a specified network location to achieve the preservation of documents in the cloud. However, the method of active upload by users has the drawback that it cannot ensure that all important documents are centrally stored. To reduce the dependence on user upload behavior and avoid the problem of documents not being uploaded in a timely manner, a forced save technology based on user behavior monitoring has emerged. This technology installs client software on the user terminal to monitor the file save behavior of specific application programs. After detecting a specific behavior, it allows users to save the file locally first, and then uses the method of copying from the local later, or intercepts the file handle in the operating system to copy the locally saved file to the network storage location in the cloud. However, in this way, the corresponding document is still stored on the user terminal, which may become a data leakage source, and the drawbacks are relatively obvious.
[0027] Based on the above research, the present disclosure provides a document storage method, device, computer device, and program product. By listening to the process creation operation, it is possible to timely determine whether to perform containerization processing on the application process according to the process attributes of the newly created application process and the software process whitelist. Since the target document can be forced to be stored on the server after containerization processing, it is possible to timely determine whether the target document in the application process needs to be stored on the server through the process attributes and the software process whitelist. In the case where containerization processing is determined to be required, by creating an isolation container to take over the data interface between the application process and the operating system, it is possible to create a target save path for replacing the local save path when a save operation is detected. Then, by storing the edited target document to the target save path, it is possible to achieve the unified storage of the target documents edited by different users to the server without the need for users to actively upload documents to the server, thereby facilitating the unified management and storage of the documents edited by different users and improving document security. Moreover, the process of uploading the edited target document of the user to the server is automatically executed when a local save behavior is detected, so it is possible to effectively avoid the problem that important documents cannot be uploaded to the server in a timely manner, and improve the efficiency and timeliness of unified document storage. In addition, since the document can be actively uploaded to the network storage resource, the problem of document leakage caused by local storage of the document can be avoided.
[0028] Regarding the defects existing in the above solutions, they are all the results obtained by the inventors after practice and careful research. Therefore, the process of discovering the above problems and the solutions proposed by the present disclosure for the above problems in the following text should both be the contributions made by the inventors to the present disclosure during the process of the present disclosure.
[0029] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0030] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to users and the authorization of users should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0031] For the convenience of understanding this embodiment, first, a document storage method disclosed in the embodiments of the present disclosure will be introduced in detail. The execution subject of the document storage method provided by the embodiments of the present disclosure is generally a terminal device or other processing device with certain computing capabilities. The terminal device may be a user equipment (UE), a mobile device, a user terminal, a terminal, a personal digital assistant device (PDA), a handheld device, a computer device, etc.; in some possible implementation manners, the document storage method may be implemented by a processor invoking computer-readable instructions stored in a memory.
[0032] Next, the document storage method provided by the embodiments of the present disclosure will be described by taking the execution subject as a terminal device as an example.
[0033] As Figure 1 shown, it is a flowchart of a document storage method provided by the embodiments of the present disclosure, which may include the following steps: S101: In response to creating an application process, determine whether to perform containerization processing on the application process according to the process attribute of the application process and the software process whitelist obtained from the server; the application process is used to open and edit a target document.
[0034] Here, the process attribute is used to indicate the process type information of the application process, and the containerization processing is used to isolate and take over the data interface between the application process and the operating system, so as to implement forcibly saving the document edited in the application process to the server. For the convenience of understanding, after the containerization processing, the document edited in the application process will be stored on the network, that is, stored on the server. If the containerization processing is not performed, the document edited in the application process will be stored locally, that is, stored locally on the terminal device.
[0035] The data interface may include various interfaces related to the application process, such as a file I / O interface. The operating system is the operating system deployed for the terminal device that creates the application process, such as the Windows system, the Linux system, etc. The target document is the document opened by using the application process, and the user can use the application process to edit and save the content of the target document.
[0036] The present disclosure designs and implements a whitelist management module for creating, storing, and managing a software whitelist of software processes that need to forcibly save documents. Then, a whitelist data structure is established, which contains key information such as software process attributes (such as process names, such as word.exe, excel.exe, PowerPoint.exe, cad.exe, etc.), software types, document type identifiers, forced storage target path templates, etc. Specifically, the software process whitelist is related to the application process that needs to perform forced network storage of documents. The information in the software process whitelist can be implemented through the provided whitelist configuration interface. For example, it supports administrators to add, modify, and delete the whitelist through a Web interface or a configuration tool. After the application process is created on the terminal device, the latest software process whitelist can be obtained based on the communication protocol with the server. Or, a timed push function of the whitelist can be set, and the server periodically pushes the latest software process whitelist to the terminal device. A local caching mechanism for the software process whitelist is implemented on the terminal device side, and the most recently synchronized software process whitelist data can still be used to continue working in case of a network interruption.
[0037] Perform containerization processing on the application process, specifically, a dedicated isolation container can be created for the application.
[0038] In specific implementation, a background service program can be set in the user's terminal device. When the background service program detects that the user has created an application process, it can obtain the process attributes of the application process. For example, when the user needs to open or create a target document, the corresponding application process can be created and the target document can be opened and edited using the application process. Then, according to the process attributes of the application process and the latest stored software process whitelist in the terminal device, it can be determined whether the process attributes are in the whitelist. If so, it is determined that containerization processing is required, and the following step S102 is executed. If not, it can be determined that containerization processing is not required and the target document does not need to be stored on the server; then when the save operation of the application process is detected, the edited target document is stored in the local save path of the terminal device. That is, in the case where containerization processing is not required, the user can save the target document locally on the terminal device.
[0039] Among them, the background service program is a pre-written system-level program, which serves as the core component for monitoring and intercepting terminal devices and is set to run automatically when the operating system of the terminal device starts to ensure continuous monitoring services. Then, the background service program is used to implement the process creation event listening function. By hooking the system process creation hook, it can monitor the currently running application processes and newly started application processes in real time, subscribe to the process creation event, and obtain notifications of new processes. When a new process is detected to start, the background service program will extract information such as the executable file path, other identification information, and process type of the process, and use this information as process attributes. Based on the process attributes of the newly created application process and the obtained software process whitelist, it is determined whether to perform containerization processing on the application process.
[0040] In one embodiment, the step of determining whether to perform containerization processing on the application process in S101 above can be implemented according to the following steps: S101-1: Determine whether the target document opened in the application process after the application process is created is a new document.
[0041] Specifically, after the application process is created, it can be determined whether the target document is a new document according to whether the target document is a blank document or whether the operation of the user when opening the target document is a file creation operation.
[0042] S101-2: If so, determine whether to perform containerization processing on the application process according to whether there is a target process attribute consistent with the process attributes of the application process stored in the software process whitelist.
[0043] Specifically, in the case of determining that it is a new document, the locally recently stored software process whitelist can be obtained, and it is judged whether there is a target process attribute consistent with the process attributes of the application process among the various process attributes stored in the software process whitelist. For example, it is judged whether there is a target process name consistent with the process name of the application process stored in the software process whitelist. If so, it is determined to perform containerization processing on the application process; if not, it is determined that there is no need to perform containerization processing on the application process.
[0044] Optionally, after the user creates an application process, the operation of determining whether the target document is a new document may not be performed, and the locally recently stored software process whitelist can be directly obtained. Then, in the case where there is a target process attribute consistent with the process attributes of the application process stored in the software process whitelist, it is determined to perform containerization processing on the application process, so that each document opened and edited by the application process subsequently will be stored on the server; otherwise, it is determined that there is no need to perform containerization processing on the application process.
[0045] In this way, based on the precise control mechanism of the software process whitelist, the effective identification and directional control of the document saving behavior of specific application processes are realized. Moreover, by using the process monitoring and file I / O interface interception technology, the real-time monitoring and dynamic intervention of the document saving process are realized.
[0046] In another embodiment, when the target document is not a new document, the following steps 1 to 3 can also be implemented: Step 1: If the target document is not a new document, determine whether the historical saving path of the target document is located in the local mapped drive.
[0047] In specific implementation, if the target document is not a new document, then this document may be an old document opened by the user using an application process, and this document may come from other places. Therefore, it can be determined whether the historical saving path of the target document is located in the local mapped drive corresponding to the server, that is, it is determined whether the target document has been saved in the local mapped drive. If so, it can be explained that the target document has been forcibly saved to the server before, so it can be determined that containerization processing needs to be performed on the application process. If not, then proceed to the following Step 2.
[0048] Step 2: If not, use the document analysis model to perform importance analysis on the existing content of the target document to obtain the importance score of the target document.
[0049] Here, the document analysis model can be a neural network model pre-deployed on the server, and this analysis model has the function of analyzing the importance of the document. The importance score is used to represent the importance of the target document, and the higher the importance score, the higher the importance of the document. Specifically, the document analysis model uses natural language processing technology and is trained in combination with a preset specific corpus, and can identify the key business information, sensitive data and knowledge value contained in the document. Specifically, the document analysis model will consider the following dimensions: the frequency of business keywords contained in the document, the presence of sensitive information (such as labels like "confidential", "internal", "top secret", etc.), the formality of the document structure (such as whether it has a standard document format), the data density (such as the number of numbers, charts and tables contained), and the document editing history (such as the modification frequency and modification amount, etc.), and through the information under these dimensions, the document is comprehensively scored to obtain the importance score of the document.
[0050] In specific implementation, when it is determined that the historical saving path is not located in the local mapped drive, the document analysis model can be called, and the existing content of the target document is input into the document analysis model for importance analysis, so as to output the importance score of the target document.
[0051] Step 3: According to the importance score, determine whether to perform containerization processing on the application process.
[0052] Exemplarily, the importance score can be compared with a preset score threshold, and based on the comparison result, it can be determined whether to perform containerization processing. For example, when the importance score is greater than the preset score threshold, it is determined that containerization processing of the application process is required; when the importance score is not greater than the preset score threshold, it is determined that containerization processing of the application process is not required.
[0053] Optionally, the saving method of the target document can also be determined by combining the importance score and the saving method of the historical documents edited by the user. For example, according to the saving methods of the respective historical documents edited by the user, the target proportion (or target quantity or the maximum number of consecutive network storages of the document) of the documents with the determined saving method being network storage can be determined. Then, when the importance score is greater than the preset score threshold and the target proportion is greater than the preset proportion (or the target quantity is greater than the preset quantity or the maximum number is greater than the preset number), it is determined that containerization processing of the application process is required; in other cases, it is determined that containerization processing of the application process is not required.
[0054] S102: If so, create an isolation container for the application process; the isolation container is used to isolate and take over the data interface between the application process and the operating system.
[0055] Here, the isolation container is a container created for the application process, and this container is used to isolate and take over the data interface between the application process and the operating system, so as to facilitate the conversion of the local saving operation of the target document in the application process into a network storage operation.
[0056] In specific implementation, if it is determined that containerization processing is required, a related isolation container can be created separately for the application process using container creation technology, so as to control the document IO interface of the application process and achieve dynamic monitoring and interception of document saving behaviors. For example, the isolation container can adopt hook technology (Hook) or API interception technology to intercept the commonly used document editing interfaces in the application process. Among them, the document editing interfaces can include, for example, document writing interfaces, document saving interfaces, document undo interfaces, document output interfaces, etc. Then, design and implement interface interception logic to provide the ability to check and modify paths without affecting the original interface function, so as to achieve the conversion of the call of the file IO interface to the call of the interface for the server. Or, the isolation container can create a controlled file system layer by implementing a file system filter driver (File SystemFilter Driver), and this driver is located between the application program and the operating system and can intercept and process all file operation requests in the application process, so as to achieve the conversion of the call of the file IO interface to the call of the interface for the server.
[0057] For example, if it is confirmed that the created application process belongs to the processes in the software process whitelist, the background service program needs to inject a library containing interception logic into the memory space of the application process and perform API Hooking settings. The specific API Hooking settings can be as follows: locate the address of the key Windows API function responsible for file operations in the memory of the application process, execute the custom function interception function, and check the passed parameters, especially the file path and access permissions, to determine whether it is a write operation.
[0058] S103: In response to detecting a save operation of the application process, use the isolation container to generate a target save path for replacing the local save path in the corresponding local mapped disk on the server side according to the local save path of the save operation by using network storage technology.
[0059] Here, the save operation is an operation indicating to save the target document, and this operation indicates the local save path of the target document on the local terminal device. The save operation can be triggered by the user. For example, the save operation can be that the user triggers the save button corresponding to the application process or the user triggers the save shortcut key, etc. The local save path is the document save path indicated by the user on the local terminal device.
[0060] The network storage technology is a technology for storing documents on the network. For example, the network storage technology can be a shared file system, a dokan virtual drive, etc. Among them, Dokan is a file system driver running in user mode, and its core function is to provide an abstraction layer, enabling developers to implement custom file system functions in user mode.
[0061] The local mapped disk is a storage disk on the terminal device that maps the network storage resources provided by the server in advance. For example, through the network drive mapping function provided by the operating system, the network storage resources can be mapped as the local mapped disk. When storing a document in the local mapped disk, it means that the document is stored on the server. In this way, through the local path mapping technology, the transparent representation of the network storage resources on the user terminal device is realized, providing a basic environment for the forced centralized storage of documents. The server can be, for example, a file server, a Network Attached Storage (NAS) server, etc.
[0062] Moreover, an automated implementation mechanism for network storage resource mapping can be designed. For example, first, through group policies or login scripts, the network drive mapping operation can be automatically executed when the user logs in to the system, mapping the network storage resources to local mapped drives, thereby ensuring the persistence and consistency of the mapping. Second, for possible network connection interruptions, an automatic re - mapping function after disconnection and reconnection can be implemented, and a local caching mechanism can be provided to reduce the impact of network fluctuations on the user experience. Finally, a mapping status monitoring mechanism can be established to detect the mapping status in real - time and provide user prompts and automatic repair options when the mapping fails, to ensure the persistence and consistency of the network storage resource mapping.
[0063] In addition, to ensure the reliability of the mapping, the background service program also needs to handle network connection interruptions. For example, when the user's terminal device switches from a wired network to a wireless network, the network connection may be temporarily interrupted, causing the network drive mapping to fail. For this situation, a timed detection task can be designed to check the connection status of the local mapped drive every 5 minutes. If the connection is found to be disconnected, an attempt will be made to automatically re - establish the mapping.
[0064] The target save path is the save path corresponding to the exclusive storage space created for the user in the local mapped drive.
[0065] In specific implementation, when the user triggers the save operation for the target document, it can be detected that the application process triggers the save operation. Therefore, an external request can be sent to the isolation container, and this request is used to indicate path redirection and generate the save path on the server side. After receiving the external request, the isolation container, based on the isolation and takeover of the data interface between the application process and the operating system, intercepts the call operation of the save interface according to the interception logic and obtains the local save path of the save operation. Then, using network storage technology in the local mapped drive, it judges and redirects the location to modify the file path parameter to generate the target save path for replacing the local save path. For example, path analysis and replacement algorithms can be used to extract the original save directory from the local save path and determine information such as the document name and extension name of the target document. According to the original save directory, document name, extension name, and user information, etc., the local save path is modified to the target save path located in the local mapped drive, and the modified target save path is passed to the original file operation function to achieve transparent path redirection. Among them, the user information is used to represent information such as the user's identification and name. The storage drive letter in the target save path is the local mapped drive, and the path carries the user's information, thus ensuring the isolation of user resources.
[0066] For example, the local mapped drive letter is M:\, the user information is xiaoming, and the local save path is C:\XXX\XXXX, where C represents the local drive letter of the terminal device. The target save path can be M:\xiaoming\XXX\XXXX. In this way, through transparent path replacement, the document can be forcibly saved to the network storage location without changing the user's usage habits.
[0067] Alternatively, in the case where it is not necessary to create an isolation container for the application process, if a save operation of the application process is detected, the target document that has been edited in the application process can be directly saved to the local storage space corresponding to the local save path of the terminal device. Here, the edited target document refers to all the content edited by the user in the target document and the original content of the target document after the target document is opened until the save operation is triggered.
[0068] In one embodiment, the step of generating the target save path in S103 above can be implemented according to the following steps: S103-1: Use the isolation container to determine the save directory structure according to the local save path, and extract the relative save path except for the local disk from the local save path.
[0069] Here, the directory structure is used to indicate the structure of the path target under the local save path. Using the target structure can maintain the user's target habits when generating the target save path, reduce the adaptation cost for the user to obtain the document from the server later, and when multiple users collaborate on the same project, the similar directory structures help to establish a unified resource organization specification.
[0070] The relative save path is the save path after removing the disk letter corresponding to the local disk. For example, if the local save path is C:\XXX\XXXX, the relative save path is XXX\XXXX.
[0071] Specifically, during implementation, the isolation container can be used to perform directory analysis on the local save path to obtain the save directory structure, and determine the drive letter corresponding to the local disk in the local save path, and delete the drive letter to obtain the relative save path.
[0072] S103-2: Obtain the save path template corresponding to the application process from the software process whitelist.
[0073] Here, the software process whitelist stores the forced save path templates corresponding to each application process. The forced save path templates corresponding to different application processes are different.
[0074] Exemplarily, the save path template corresponding to the application process created by the user can be obtained from the software process whitelist.
[0075] S103-3: According to the saved directory structure, use network storage technology to generate a target save path in the local mapped drive based on the relative save path and the save path template.
[0076] In specific implementation, to maintain the consistency of the user experience, network storage technology can be used to automatically create a "homogeneous directory" corresponding to the saved directory structure in the local mapped drive corresponding to the network storage resource according to the relative save path, user information, and the save path template, so as to obtain the target save path.
[0077] For example, if the user (xiaoming) attempts to save a target document of the word type to "D:\Project\Design Drawings\Solution 1.docx", network storage technology can be used to automatically create a directory structure of "M:\xiaoming\Project\Design Drawings\word / net" on the server side and actually save the target document as "M:\xiaoming\Project\Design Drawings\Solution 1.docx".
[0078] In addition, for possible abnormal situations during the path replacement process, a fault tolerance processing mechanism can also be set up to implement the file conflict handling logic. For example, when there is already a document with the same name in the target save path of the local mapped drive, the conflict can be resolved by automatically renaming or prompting the user to select. The automatic renaming method can be, for example, adding a timestamp or adding a digital identifier in ascending order.
[0079] In addition, a user feedback mechanism can also be designed. After the path replacement operation is successfully executed, operation feedback can be provided to the user in the form of a status bar icon or a small hint, etc., to enhance the user's perception of the whereabouts of the target document.
[0080] S104: Store the target document that has been edited in the application process to the target save path.
[0081] In specific implementation, after determining the target save path, all the content of the target document edited by the user when the save operation is triggered can be stored to the target save path, so as to realize the active storage of the document edited by the user locally on the terminal device to the server side, thereby achieving the network centralized storage of the user-edited document.
[0082] It is understandable that during the process of editing a target document, a user may trigger multiple save operations. If the local save paths for multiple save operations are the same, then the edited target documents after each save operation will be stored in the same target save path. If there are two different paths among the local save paths for multiple save operations, then during the most recent save, all the content of the edited target document can be stored in the target save path corresponding to the most recent save. Meanwhile, compare the differences between the document content in the target save path corresponding to the previous save and the document content in the target save path corresponding to the most recent save, and store these differences in the target save path corresponding to the most recent save, so as to facilitate the user's subsequent differential analysis of the document content at different save times.
[0083] For example, after determining the target save path, an original API call and return operation can be executed to intercept the function and pass the modified parameters back to the original API, thereby achieving the active storage of the document edited locally by the user on the terminal device to the server.
[0084] In this way, the present disclosure uses the API Hooking technology to force the document to be saved to the server. Compared with the Sandboxing technology in the prior art, it has at least the following advantages: 1. Finer control granularity: Hooking can very precisely intercept and modify only specific API calls, with almost no impact on all other behaviors of the application. The control point is at the function call level. While Sandboxing usually provides coarser-grained control, such as restricting access to a certain branch of the entire file system or virtualizing the entire file system. To achieve "only redirecting specific write operations of a specific application to a specific network path while keeping other access unchanged" may require very complex sandbox policy configurations.
[0085] 2. Better user experience and compatibility: Hooking is almost transparent to the user. The user operates according to the habit ("File" -> "Save" -> select local path), and the file is finally saved to the network storage (i.e., stored in the server). While Sandboxing may change the behavior mode of the application. For example, the file dialog box may only be able to see the virtual file system inside the sandbox, or the application may not be able to access local resources expected by the user (such as fonts, plugins, temporary files, etc.), resulting in abnormal functions or user confusion. There may be compatibility issues between the sandbox environment and some application programs or system components.
[0086] 3. Lower performance overhead: The main overhead of Hooking lies in injecting the Dynamic Link Library (DLL) and the additional jumps and logical processing each time the Hook API is called. For Hooks with clear goals and simple logic, the performance impact is relatively small. Sandboxing usually involves deeper system interception, virtualization, or emulation, which may bring more significant performance overhead, especially when there are intensive file I / O operations.
[0087] In one embodiment, for S104, it can be implemented according to the following steps: S104-1: Detect whether there is a network connection with the server.
[0088] Specifically, it can actively detect whether there is a network connection between the server and the user terminal device. If there is, the edited target document can be directly stored in the target save path based on this network connection, thus realizing the forced storage of the document to the server.
[0089] S104-2: If not, establish a temporary save path locally and associate the temporary save path with the target save path.
[0090] Specifically, when there is no network connection, a temporary save path can be constructed in the local disk of the terminal device. For example, the temporary save path can be C:\ProgramData\DocSyncTemp. At the same time, the temporary save path and the target save path can be associated together.
[0091] S104-3: Store the edited target document in the temporary save path until the network connection is restored, and then use the network connection to synchronize the document content stored in the temporary save path to the target save path.
[0092] Specifically, the edited target document can be first stored in the temporary save path, and then wait for the network connection between the server and the user terminal device to be restored. Once the network is restored, based on the association relationship between the temporary save path and the target save path, the document content stored in the temporary save path can be synchronized to the target save path. And if new edited content is generated for the target document during the network restoration period, the new edited content can be integrated with the document content stored in the temporary save path and then synchronized to the target save path together.
[0093] In one embodiment, for the step of storing the target document in S104, it can also achieve encrypted storage through the following steps A to D, thereby improving the document security: Step A: Perform structural analysis and semantic analysis on the document content of the edited target document to determine the document structure features and document content features of the target document.
[0094] Here, the document content refers to all the content in the edited target document. The structural analysis may specifically include, but is not limited to, detecting whether there is a specific title format in the document, detecting the layout method of the document, detecting the table structure in the document, including media information, etc. The semantic analysis may specifically include, but is not limited to, identifying keywords, technical terms, expression patterns, subject words, entity names (such as product names, project codes, etc.) in the document.
[0095] The document structure features are used to characterize the document structure information of the target document, and the document content features are used to characterize the document content information of the target document.
[0096] Specifically in implementation, a document analysis service can be called to perform structural analysis and semantic analysis on the document content of the edited target document, determine various document structures and various important content information possessed by the target document, and obtain the document structure features and document content features based on the document structure and important content information.
[0097] Step B: Determine the document type according to the document attribute features, document structure features, and document content features of the edited target document.
[0098] Here, the document attribute features indicate the initial type of the document, and this feature can be determined based on the document extension name of the target document and the Multipurpose Internet Mail Extensions (MIME) type.
[0099] The document type is used to indicate the final document type of the target document. The document type may include, for example, contract document type, financial statement type, product design document type, technical specification type, market analysis report type, personnel file type, etc.
[0100] Exemplarily, according to the initial type characterized by the document attribute features, it can be judged the type of the document that can have the above-mentioned document structure features and document content features among the documents with the initial type, and this type is used as the document type.
[0101] Step C: Determine the document encryption level and the encryption method matching the document encryption level according to the editing features and document type of the edited target document.
[0102] Here, the editing features are used to indicate the features corresponding to various editing operations when editing the target document. For example, the editing features may include, but are not limited to, editing duration, editing frequency, the amount of modification of the document content, editing mode, collaboration situation, etc. Among them, the editing duration is the total duration for the user to edit the target document; the editing frequency is used to indicate the number of editing operations on the document per unit time; the modification amount is used to indicate the change ratio of the document content of the target document, such as the character addition and deletion ratio, structural changes, etc.; the editing mode is used to indicate whether the target document is continuously edited, whether it is batch modified, whether it is a small - scale content modification, etc.; the collaboration situation is used to indicate the information about the number of editors of the target document.
[0103] The encryption method is used to indicate the method of encrypting the target document, and the document encryption level is used to indicate the encryption level of the target document. Different document encryption levels correspond to different encryption methods. For example, the encryption level may include multiple preset levels, such as levels 0 - 4. Different levels correspond to encryption methods with different complexities. For example, level 0: no special encryption is required; level 1: basic encryption using a standard encryption algorithm; level 2: enhanced encryption using a high - strength encryption algorithm; level 3: strict encryption using multiple encryption technologies; level 4: encryption using the highest - level encryption algorithm, and the highest - level encryption algorithm can be a preset algorithm.
[0104] In specific implementation, for each document type, the basic encryption level is preset according to its sensitivity and business value. For example, the basic encryption level of a contract document may be 2, while the basic level of a general meeting record may be 0. According to the document type, the basic encryption level is determined, and then the editing features are used to dynamically adjust the basic encryption level to obtain the final document encryption level. For example, highly intensive editing (continuous editing, batch modification) will increase the encryption level, while simple browsing or small - scale content modification will maintain the original encryption level. After determining the document encryption level, the encryption method for the target document can be determined according to the association relationship between the encryption level and the encryption method.
[0105] Step D: Encrypt and store the edited target document to the target save path according to the encryption method matching the document encryption level.
[0106] In specific implementation, if the encryption level is 0, the encryption method is no encryption required, and the edited target document can be directly stored to the target save path. If the encryption level is not 0, the edited target document can be encrypted using the encryption algorithm matching the encryption method, and the encrypted target document is stored to the target save path.
[0107] Among them, the specific process of encrypted storage may include: generating an encryption key according to an encryption method matching the document encryption level, and encrypting the document content of the target document. Store the key and encryption parameters associated with the target document in the secure key management system of the server. This system needs to be integrated with the identity authentication system to ensure that only authorized users can obtain the key for document access. In addition, an access audit log can be created to record encryption operations and each subsequent access attempt.
[0108] It is understandable that if the target document has been stored on the server before, the previously stored encryption method can be obtained, and the document content of the target document can be encrypted according to this encryption method, so as to ensure the consistency of the encryption method when the user stores the target document multiple times.
[0109] In one implementation example, after encrypting and storing the edited target document to the target save path, the encrypted document can be displayed according to the following steps P1 to P3: P1: In response to a viewing operation of any first user on the target document stored in the target save path, obtain the authentication information of the first user.
[0110] Here, the first user can be any enterprise user, and the authentication information can be the user identity information and password information of the first user.
[0111] Specifically, the terminal device can generate an authentication information pop-up window and display it to the first user in response to the operation of any first user viewing the target document in the target save path, and then obtain the authentication information submitted by the first user.
[0112] P2: Send the authentication information of the first user to the server; the server is used to authenticate the first user and determine the permission level according to the authentication information, and in the case of successful authentication, decrypt the target document stored in the target save path and feedback the decrypted target document and the display duration matching the permission level.
[0113] Here, to ensure the secure use of encrypted documents, strict access control and audit mechanisms need to be implemented. For example, role-based access control can be set, and differentiated access permissions can be implemented according to user roles and document encryption levels. And when a user accesses a document, multi-factor authentication (such as password + fingerprint or USB token, etc.) can be implemented. At the same time, the access duration can be controlled, and when the access times out, it will be automatically closed and re-authentication will be required.
[0114] During specific implementation, the terminal device may send the authentication information of the first user to the security key management system of the server, and the system may authenticate the first user according to the authentication information. For example, according to the user identity information and password information in the authentication information, it is determined whether the user has access rights. If not, it is determined that the user authentication fails and the user does not have access rights, and an authentication failure message is fed back to the user terminal. Then, the terminal device may display a prompt message indicating authentication failure to the first user. If so, it is determined that the user authentication is successful, and according to the user identity information and the mapping relationship between the identity information and the access rights, the permission level of the first user and the display duration matching the permission level are determined. After that, the server may obtain the secret key and encryption parameters of the target document from the security key management system, and use the secret key and encryption parameters to decrypt the target document stored in the target save path to obtain the decrypted target document. The decrypted target document and the display duration are fed back to the terminal device.
[0115] P3: Obtain the decrypted target document and the display duration, and display the decrypted target document according to the display duration.
[0116] During specific implementation, the terminal device may obtain the decrypted target document and the display duration sent by the server, and display the decrypted target document to the first user according to the display duration.
[0117] In addition, the terminal device may generate an access log according to the access, download, print, and modification operations of the first user on the decrypted target document, and store the access log to the server.
[0118] Optionally, security analysis may also be performed on various operations of the first user on the displayed target document to determine whether there are abnormal operation behaviors. If so, a security prompt message is generated and displayed to the user.
[0119] In this way, it can be ensured that after the document is encrypted and stored, its access and use are still under strict supervision, thus comprehensively ensuring document security.
[0120] In one embodiment, to facilitate the retrieval of documents stored in network storage resources, after storing the target document edited in the application process to the target save path, the construction of document indexing and document retrieval may also be performed according to the following steps T1~T6: T1: Determine the target index information of the target document according to the document source information, document structure characteristics, and document content characteristics of the edited target document.
[0121] Here, the document source information may include the user identification or work department of the target user. The target user may be the user who creates and / or edits the target document, the application process and version used to edit the target document, the location of the terminal device and network address information when editing the target document.
[0122] The document structure features and document content features can be obtained by analyzing the edited target document using the document analysis service described above.
[0123] In specific implementation, each piece of data in the document source information, each feature in the document structure features, and each feature in the document content features can be directly used as the target index information of the target document. Alternatively, the document source information, document structure features, and document content features can be first subjected to structured processing and deduplication processing, and the target index information can be determined based on the processing results.
[0124] T2: Determine the association degree information between the target document and other documents stored in the corresponding database of the server according to the target index information and the stored index information in the server.
[0125] Here, the stored index information is the index information of each document stored in the server. The association degree information is used to characterize the high or low association degree between documents.
[0126] In specific implementation, the stored index information of each other document in the corresponding database of the server can be obtained. Then, by performing similarity and association degree analysis on the target index information and each stored index information, the association degree information between the target document and each other document stored in the server is determined. It can be understood that when determining the association degree information, the association degree information corresponding to each stored other document can also be referred to.
[0127] For example, the process of determining the association degree information may include entity recognition and linking, that is, standardizing and linking the entities (such as product names, technical terms, etc.) extracted from the target document to the documents corresponding to the standard entities in the enterprise knowledge base, identifying the relationships between different entities in different documents (such as "Product A is used in Project B", "Technology C is applied to Product D", etc.), and determining the association degree information between the documents.
[0128] T3: Associatively store the target index information, the association degree information, and the target save path of the target document in the database.
[0129] Exemplarily, the target index information, the association degree information, and the target save path of the target document can be associatively stored in the database corresponding to the network storage resource for subsequent retrieval of the target document.
[0130] T4: In response to the retrieval operation of any second user, determine the matching document with the highest matching degree according to the retrieval information and the stored index information in the database.
[0131] Here, the second user can be any enterprise user. Embodiments of the present disclosure can provide an intelligent retrieval page and provide various retrieval methods on the page. For example, it can include keyword retrieval, natural language retrieval, and guided filtering retrieval. Among them, natural language retrieval allows users to describe their needs in daily language. For example, the second user inputs "find all technical documents about product A written by user A last month". Guided filtering retrieval provides multi-dimensional filtering conditions (such as document type, time range, department, keywords, etc.) to help the second user gradually narrow the retrieval scope.
[0132] The retrieval operation can be an operation initiated by any second user on the intelligent retrieval page, and the retrieval information is the retrieval content submitted by the second user using any retrieval method.
[0133] Exemplarily, the terminal device can, in response to the retrieval operation of any second user, obtain the retrieval information of the second user and obtain the stored index information from the database of the server. Then, calculate the matching degree between the retrieval information and the stored index information, and use the document corresponding to the stored index information with the highest matching degree as the matching document with the highest matching degree.
[0134] Optionally, a personalized retrieval experience can also be provided based on the permissions and historical retrieval behaviors of the second user. For example, record and analyze the user's retrieval patterns and document access history, and optimize the sorting algorithm to use the document most relevant to the user's retrieval information as the matching document. At the same time, integrate with the permission management system to ensure that the second user can only see the matching documents that they have permission to access. This requires marking the access control list for each document during the index construction phase and performing permission filtering during the retrieval process to ensure that the finally retrieved matching documents are all within the user's permissions. To improve the user experience, the terminal device can display the number of documents that have been filtered out and allow the second user to apply for temporary access permissions through an authentication process.
[0135] T5: Obtain the matching document according to the save path associated with the matching document.
[0136] During specific implementation, the save path associated with the stored index information of the matching document can be obtained from the database of the server, and then the matching document can be requested from the server according to this save path.
[0137] Optionally, if the matching document is encrypted, an authentication information pop-up window can be generated first and displayed to the second user, and then the authentication information submitted by the second user can be obtained. Based on the authentication information, a request is sent to the server to obtain the matching document at the saved path. When the server authenticates the user based on the authentication information, the decrypted target document and the display duration are sent to the terminal device.
[0138] T6: Display the matching document, and recommend each other document associated with the matching document to the second user according to the degree of association information associated with the matching document.
[0139] Specifically, after the terminal device obtains the matching document, it can display the matching document, obtain the degree of association information associated with the stored index information of the matching document from the server's database, and recommend each other document associated with the matching document to the second user in order according to the degree of association indicated by the degree of association information. For example, the document identifiers corresponding to each other document associated with the matching document can be recommended to the second user in order. When the second user clicks on any document identifier, the document corresponding to the document identifier is obtained from the server and displayed to the second user.
[0140] Optionally, if the terminal device obtains the display duration, the matching document can be displayed according to the display duration.
[0141] In one embodiment, for S104, it can also be implemented according to the following steps A1 to A3: A1: Obtain the current network environment, the current location information of the user, and the editing characteristics of the target document.
[0142] The user here is the user who edits the target document. The current network environment is used to indicate the network connection type, connection security, and network quality between the terminal device and the server. Among them, the network connection type is, for example, a company intranet, a home network, a public Wi-Fi, etc. The connection security is, for example, whether to use an encrypted channel such as a Virtual Private Network (VPN) or a Secure Socket Layer (SSL). The network quality can include network bandwidth, network latency, network stability, etc.
[0143] The current location information is used to indicate the geographical location information and / or network address of the terminal device used by the user, and it can be specifically obtained through GPS, Wi-Fi positioning, or IP address resolution.
[0144] The editing characteristics can include, but are not limited to, editing duration, editing frequency, the amount of modification of the document content, editing mode, collaboration situation, editing time period, etc.
[0145] In specific implementation, with the user's authorization, the current network environment, the user's current location information, and the editing features of the target document can be determined.
[0146] Optionally, the status of the terminal device can also be obtained, such as device type (enterprise management device or personal device), security status (whether the latest security patch is installed, whether security software is running), power status (whether the battery is used, remaining battery power), etc.
[0147] A2: Use the security assessment service to determine whether to shield the isolation container based on the current network environment, current location information, and editing features.
[0148] Here, the security assessment service can be a decision engine built based on rules and machine learning, which can determine the security of the current environment. If the isolation container is shielded, it means that even if the isolation container is created, the isolation container will not be used to generate a replacement path, but instead, the target document will still be selected to be stored in the local save path of the terminal device. That is, if the isolation container is shielded, the network storage method will be switched to the local storage method.
[0149] Exemplarily, the security assessment service can be used to determine the risk score of the current environment based on the current network environment, whether the current location information is in a preset safe area (such as an enterprise office, a specified place, etc.), and the editing features, and determine whether to shield the isolation container according to the risk score. For example, in an environment of "enterprise intranet + enterprise device + working hours", the risk score can be determined to be 0, that is, the current environment is a safe environment, and it is determined that there is no need to shield the isolation container. In an environment of "home network + personal device + holiday time", the risk score can be determined to be relatively high (such as 90), that is, the current environment is an insecure environment, and it is determined that the isolation container needs to be shielded.
[0150] Optionally, the historical work mode of the user can also be combined to determine whether the current working environment belongs to the user's regular working environment or an abnormal working environment, and determine whether to switch to the local storage method according to the working environment and the risk score.
[0151] A3: If not, store the edited target document in the target save path.
[0152] Exemplarily, in the case of determining that there is no need to shield the isolation container, the edited target document can be stored in the target save path, thereby implementing server-side storage.
[0153] In another embodiment, if it is determined to shield and isolate the container, the edited target document is stored in the local save path and a prompt message is displayed; the prompt message includes storage method information and the reason for shielding; in response to canceling the shielding of the isolated container, the target document stored in the local save path is merged and stored into the target document already stored in the target save path, and a new prompt message is displayed.
[0154] Here, the storage method information may include, for example, the status of the mode indication icon displayed on the terminal, which indicates different document storage methods in different states. The document storage methods include two types: local storage method and network storage method. For example, different document storage methods are indicated by the color change and shape change of the mode indication icon. The reason for shielding is used to indicate the specific reason for shielding or canceling shielding. For example, due to being in a high-risk environment, network storage is unavailable to protect the documents already stored in the network, so the isolated container is shielded; when entering a safe environment from a high-risk environment and network storage is adopted, the shielding of the isolated container is canceled, etc.
[0155] Exemplarily, if it is determined to shield and isolate the container, the edited target document can be stored in the local save path, and at the same time, a prompt message can be generated and displayed to the user. If it is determined that there is no need to shield and isolate the container, the edited target document can be stored in the target save path. During the process of the user continuing to edit the target document, the above A1 and A2 can be executed cyclically. Once it is determined that the user has entered a non-safe environment and then entered a safe environment, at this time, the state will first switch from the state of not shielding and isolating the container to the state of shielding and isolating the container, and then switch to the state of canceling the shielding of the isolated container, that is, first switch from network storage to local storage and then switch to network storage. At this time, the target document may be stored in both the target save path and the local save path, then the target document stored in the local save path can be merged and stored into the target document already stored in the target save path, and a new prompt message is displayed. The new prompt message may include new storage method information and a new reason for shielding (such as entering a safe environment again).
[0156] Optionally, when the user modifies the target document in the offline state, if there is a version difference between the target document stored in the target save path of the server and the local target document, a file comparison and conflict resolution interface can be provided after reconnecting to the network to store the latest version of the target document in the target save path in a timely manner.
[0157] In this way, through comprehensive environmental analysis, the intelligent switching of the storage mode is realized, which improves the user experience while ensuring data security. By establishing a perfect fault tolerance and feedback mechanism, the stability in abnormal situations such as network fluctuations is improved.
[0158] Optionally, in the case of dynamic mode switching and multi-environment work, document version conflicts are an inevitable challenge. Therefore, it may also be necessary to implement an intelligent conflict detection and resolution mechanism. Specifically, change tracking can be performed: record all change operations of the target document during the local work of the application process, including timestamps and modified content. Conflict detection: When it is necessary to synchronize the local document to the network storage resource, the version of the local target document can be compared with the version of the target document on the server to determine whether there is a conflict. If there is a conflict, the synchronization method can be determined according to the conflict content. For example, for simple conflicts (such as character modifications in different document locations), the changes can be automatically merged into the server. For large-scale batch conflicts, a user-friendly interface can be provided to display the differences and guide the user to select which version to keep or how to merge. At the same time, all version histories will be retained during the conflict resolution process, allowing the user to roll back to a previous version when needed.
[0159] In addition, to avoid the problem of the storage method not matching the user's needs, the user can also be allowed to manually select whether to use an isolation container or whether to shield the isolation container, that is, the user can be allowed to manually select whether to switch the document storage method. At the same time, the security assessment service can be optimized according to the user's manual switching records to adapt to the user's preferences. In this way, the saving mode can be dynamically adjusted according to the working environment to ensure security, and the user's work habits and special needs can be respected to achieve a balance between security and experience.
[0160] To facilitate the understanding of the document storage method provided by the embodiments of the present disclosure, a specific embodiment is provided below: In an actual application scenario, an enterprise usually has already deployed a file server or a network attached storage (NAS) device as the server corresponding to the network storage resource. Taking an enterprise that has a Windows Server file server with an IP address of 192.168.1.100 as an example, a shared folder named "CompanyDocs" has been created on the server, and a sub-folder named after each employee's name has been created under it. To achieve network sharing mapping, first, the "\192.168.1.100\CompanyDocs" needs to be mapped to the M drive on the employee's terminal local through the mapping network drive function of Windows. After that, the M drive seen by the employee in the resource manager is actually a mapping pointing to the network server, and the M:\xiaoming\ folder is the exclusive storage space of this user on the server.
[0161] To ensure the reliability of mapping, it is also necessary to handle the situation of network connection interruption. For example, when an employee's laptop switches from a wired network to a wireless network, the network connection may be temporarily interrupted, resulting in the failure of network drive mapping. In response to this situation, a timed detection task can be designed to check the connection status of drive M every 5 minutes. If it is found that the connection has been disconnected, an attempt will be made to automatically re - establish the mapping. At the same time, to reduce the impact of network fluctuations on the user experience, the Windows Offline Files function can be utilized to cache the files that the user has recently accessed locally. In this way, even during a short - term network interruption, the user can still access these files and they will be automatically synchronized to the server after the network is restored.
[0162] Build a software whitelist management mechanism: In an enterprise environment, employees in different departments may use different software tools to create and edit documents. For example, the engineering department mainly uses AutoCAD (acad.exe) to create engineering drawings, the design department uses Solidworks (sldworks.exe) for 3D modeling, and the administrative department mainly uses the Microsoft Office suite (such as word.exe, excel.exe) to process daily documents. In response to this situation, a software process whitelist in JSON format can be created on the server side. This whitelist not only contains the names of the application processes that need to be monitored but also defines the file types and target save path templates.
[0163] To facilitate the maintenance of this whitelist, a web - based management interface can be provided, allowing administrators to add, edit, or delete whitelist items through a browser. When the administrator updates the whitelist, the server can notify all terminals to update. On the terminal side, it can be checked regularly (such as every 30 minutes) whether there is a new version of the software process whitelist on the server side. If so, it will be automatically downloaded and the local cache will be updated. In this way, even in the case of a temporary network disconnection, the terminal can still continue to work using the cached software process whitelist.
[0164] Implement terminal monitoring and interception services: In a Windows operating system environment, the terminal monitoring and interception service can be implemented as a Windows background service program, set to start automatically when the system boots and run with system privileges. When a new application process starts, the background service program will obtain its process attributes (such as "word.exe") and then compare them with the locally cached software process whitelist to determine whether the process needs to be monitored, that is, whether the process needs to be containerized.
[0165] Assume that the newly created application process is in the software process whitelist, and the background service program needs to intercept the file operations of this process. Redirect the calls of the functions of these operations to the custom implementation functions. In this way, whenever the user tries to save a file, in fact, the custom function provided by the background service program is called instead of the system native function. By creating an isolation container for this process, the corresponding interception purpose is achieved.
[0166] For the convenience of troubleshooting and auditing, the background service program will also record the logs of all intercepted operations. For example, when the user edits a document in Word and clicks the "Save" button, the log will record the original save path, the application process identifier, the user information, and the target save path after path replacement, etc. These logs can be saved in the local file of the terminal and uploaded to the server for centralized storage regularly. The administrator can analyze the user's document usage and troubleshoot possible problems through these logs.
[0167] Execute file path transparent replacement: When the user finishes editing a document in the application process, clicks the "Save" button and selects to save the file to the "My Documents" folder on the local D drive (such as D:\My Documents\Project Plan.docx), since the application process is in the software process whitelist, the background service program will intercept this save operation. First, the background service program will use the isolation container to analyze the local save path, extract the file name (Project Plan.docx) and the file extension (.docx). Then, according to the configuration in the software process whitelist and the information of the currently logged-in user, use network storage technology to generate the target save path in the local mapped drive. For example, for the user xiaoming, the new path may be "M:\xiaoming\Documents\Word\Project Plan.docx".
[0168] When performing the actual path replacement, the background service program needs to consider various special cases. For example, if the path "M:\xiaoming\Documents\Word" does not exist, it will automatically create the necessary folder structure using network storage technology. If there is already a file with the same name in the target save path, it can automatically add a timestamp to the file name using network storage technology to avoid overwriting. And when it detects that the network connection is unavailable, the background service program can temporarily save the file to the local temporary directory and automatically synchronize these files to the target save path after the network is restored.
[0169] During the entire path replacement process, users can hardly perceive this change because, from the user's perspective, they still save files in the habitual operation manner. However, in fact, the documents in all processes that conform to the software process whitelist have been automatically redirected to the server. To enhance the user experience, a prompt message such as "Your document 'Project Plan.docx' has been safely saved to the network" can also be displayed in the system task bar after the file is successfully saved, so that users can know the actual storage location of the document without confusion. Through this transparent path replacement mechanism, centralized management and storage of documents can be achieved without changing the user's usage habits.
[0170] Those skilled in the art can understand that in the above method of the specific implementation manner, the writing order of each step does not mean a strict execution order and does not constitute any limitation to the implementation process. The specific execution order of each step should be determined according to its function and possible internal logic.
[0171] Based on the same inventive concept, the present disclosure embodiments also provide a document storage device corresponding to the document storage method. Since the principle of solving problems by the device in the present disclosure embodiments is similar to the above document storage method of the present disclosure embodiments, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.
[0172] As Figure 2 shown, it is a schematic diagram of a document storage device provided by an embodiment of the present disclosure, including: A determination module 201, configured to determine whether to perform containerization processing on the application process in response to the creation of the application process, according to the process attribute of the application process and the software process whitelist obtained from the server; the application process is used to open and edit a target document; A creation module 202, configured to, if so, create an isolation container for the application process; the isolation container is used to isolate and take over the data interface between the application process and the operating system; A generation module 203, configured to, in response to detecting a save operation of the application process, use the isolation container to generate a target save path for replacing the local save path in the local mapped disk corresponding to the server according to the local save path of the save operation by using network storage technology; A storage module 204, configured to store the target document that has been edited in the application process to the target save path.
[0173] In a possible implementation manner, when the determination module 201 determines whether to perform containerization processing on the application process according to the process attribute of the application process and the software process whitelist obtained from the server, it is configured to: Determine whether the target document opened in the application process after the creation of the application process is a new document; If so, determine whether to perform containerization processing on the application process according to whether the target process attribute consistent with the process attribute of the application process is stored in the software process whitelist.
[0174] In a possible implementation manner, the determining module 201 is further configured to: If the target document is not a new document, determine whether the historical save path of the target document is located in the local mapped disk; If not, use the document analysis model to perform importance analysis on the existing content of the target document to obtain the importance score of the target document; Determine whether to perform containerization processing on the application process according to the importance score.
[0175] In a possible implementation manner, when the generating module 203 uses the network storage technology to generate a target save path for replacing the local save path in the corresponding local mapped disk on the server side according to the local save path of the save operation by using the isolation container, it is configured to: Use the isolation container to determine the save directory structure according to the local save path, and extract the relative save path except the local disk from the local save path; Obtain the save path template corresponding to the application process from the software process whitelist; According to the save directory structure, use the network storage technology to generate the target save path in the local mapped disk according to the relative save path and the save path template.
[0176] In a possible implementation manner, when the storage module 204 stores the target document that has been edited in the application process to the target save path, it is configured to: Detect whether there is a network connection with the server; If not, establish a temporary save path locally and associate the temporary save path with the target save path; Store the edited target document to the temporary save path until the network connection is restored, and use the network connection to synchronize the document content stored in the temporary save path to the target save path.
[0177] In a possible implementation manner, when the storage module 204 stores the target document that has been edited in the application process to the target save path, it is configured to: Perform structural analysis and semantic analysis on the document content of the edited target document to determine the document structure features and document content features of the target document; Determine the document type according to the document attribute features, the document structure features, and the document content features of the edited target document; Determine the document encryption level and the encryption method matching the document encryption level according to the editing features of the edited target document and the document type; Encrypt and store the edited target document in the target save path according to the encryption method matching the document encryption level.
[0178] In a possible implementation manner, the device further includes a first display module 205, which is used for: after encrypting and storing the edited target document in the target save path, In response to a viewing operation of any first user on the target document stored in the target save path, obtain the authentication information of the first user; Send the authentication information of the first user to the server; the server is used for authenticating the first user and determining the permission level according to the authentication information, and decrypting the target document stored in the target save path and feeding back the decrypted target document and the display duration matching the permission level in the case of successful authentication; Obtain the decrypted target document and the display duration, and display the decrypted target document according to the display duration.
[0179] In a possible implementation manner, the device further includes a second display module 206, which is used for: after storing the target document edited in the application process in the target save path, Determine the target index information of the target document according to the document source information, the document structure features, and the document content features of the edited target document; Determine the association degree information between the target document and other documents stored in the server according to the target index information and the stored index information in the database corresponding to the server; Associatively store the target index information, the association degree information, and the target save path of the target document in the database; In response to a retrieval operation of any second user, determine the matching document with the highest matching degree with the retrieval operation according to the retrieval information and the stored index information in the database; Obtain the matching document according to the save path associated with the matching document; Display the matching document, and recommend each other document associated with the matching document to the second user according to the degree of association information associated with the matching document.
[0180] In a possible implementation manner, when storing the target document edited in the application process to the target save path, the storage module 204 is configured to: Obtain the current network environment, the current location information of the user, and the editing features of the target document; Use a security assessment service to determine whether to block the isolation container according to the current network environment, the current location information, and the editing features; If not, store the edited target document to the target save path.
[0181] In a possible implementation manner, the storage module 204 is further configured to: If it is determined to block the isolation container, store the edited target document to the local save path and display a prompt message; the prompt message includes storage method information and the reason for blocking; In response to canceling the blocking of the isolation container, merge and store the target document stored in the local save path into the target document stored in the target save path, and display a new prompt message.
[0182] The description of the processing flow of each module in the device and the interaction flow between the modules can refer to the relevant description in the above method embodiment, and will not be elaborated here.
[0183] Based on the same inventive concept, an embodiment of the present application further provides a computer device. Refer to Figure 3 As shown, it is a schematic structural diagram of a computer device provided by an embodiment of the present application, including: A processor 301, a memory 302, and a bus 303. Among them, the memory 302 stores machine-readable instructions executable by the processor 301. The processor 301 is configured to execute the machine-readable instructions stored in the memory 302. When the machine-readable instructions are executed by the processor 301, the processor 301 performs the following steps: S101: In response to creating an application process, determine whether to perform containerization processing on the application process according to the process attributes of the application process and the software process whitelist obtained from the server; the application process is used to open and edit a target document; S102: If so, create an isolation container for the application process; the isolation container is used to isolate and take over the data interface between the application process and the operating system; S103: In response to detecting a save operation of the application process, use the isolation container to generate a target save path for replacing the local save path in the corresponding local mapped disk on the server using network storage technology according to the local save path of the save operation; and S104: Store the target document that has been edited in the application process to the target save path.
[0184] The above-mentioned memory 302 includes a memory 3021 and an external memory 3022; here, the memory 3021 is also called internal memory, which is used to temporarily store the operation data in the processor 301 and the data exchanged with the external memory 3022 such as a hard disk. The processor 301 exchanges data with the external memory 3022 through the memory 3021. When the computer device is running, the processor 301 communicates with the memory 302 through the bus 303, so that the processor 301 executes the execution instructions mentioned in the above method embodiments.
[0185] The embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the document storage method described in the above method embodiments. Among them, the storage medium can be a volatile or non-volatile computer-readable storage medium.
[0186] The embodiments of the present disclosure also provide a computer program product, which carries program codes. The instructions included in the program codes can be used to execute the steps of the software update method described in the above method embodiments. Specifically, reference can be made to the above method embodiments, which will not be elaborated here.
[0187] The computer program product can be specifically implemented in a manner of hardware, software, or a combination thereof. In an optional embodiment, the computer program product is specifically embodied as a computer storage medium. In another optional embodiment, the computer program product is specifically embodied as a software product, such as a Software Development Kit (SDK), etc.
[0188] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems and devices described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein. In several embodiments provided in the present disclosure, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some communication interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0189] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0190] In addition, in each embodiment of the present disclosure, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0191] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of the present disclosure, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present disclosure. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0192] If the technical solution of this application involves personal information, before the product applying the technical solution of this application processes personal information, it has clearly informed the personal information processing rules and obtained the personal's independent consent. If the technical solution of this application involves sensitive personal information, before the product applying the technical solution of this application processes sensitive personal information, it has obtained the personal's separate consent and at the same time meets the requirements of "express consent". For example, at personal information collection devices such as cameras, a clear and prominent sign is set to inform that the personal information collection scope has been entered and personal information will be collected. If an individual voluntarily enters the collection scope, it is regarded as consenting to the collection of their personal information; or on the device for personal information processing, when the personal information processing rules are informed by obvious signs / information, personal authorization is obtained through pop-up messages or by asking the individual to upload their personal information by themselves, etc.; among them, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.
[0193] Finally, it should be noted that the above embodiments are only specific implementation manners of the present disclosure, used to illustrate the technical solutions of the present disclosure, rather than limiting them. The protection scope of the present disclosure is not limited thereto. Although the present disclosure has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present disclosure can still modify the technical solutions recorded in the foregoing embodiments or can easily think of changes, or make equivalent replacements for some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure shall be subject to the protection scope of the claims.
Claims
1. A document storage method, characterized in that, Including: In response to creating an application process, determine whether to perform containerization processing on the application process according to the process attributes of the application process and the software process whitelist obtained from the server; The application process is used to open and edit a target document; If so, create an isolation container for the application process; the isolation container is used to isolate and take over the data interface between the application process and the operating system; In response to detecting a save operation of the application process, use the isolation container to generate a target save path for replacing the local save path in the local mapped disk corresponding to the server on the basis of the local save path of the save operation by using network storage technology; Store the target document that has been edited in the application process to the target save path.
2. The method according to claim 1, wherein The determining whether to perform containerization processing on the application process according to the process attributes of the application process and the software process whitelist obtained from the server includes: Judge whether the target document opened in the application process after creating the application process is a new document; If so, determine whether to perform containerization processing on the application process according to whether a target process attribute consistent with the process attributes of the application process is stored in the software process whitelist.
3. The method according to claim 1 or 2, characterized in that The method further includes: If the target document is not a new document, judge whether the historical save path of the target document is located in the local mapped disk; If not, use a document analysis model to perform importance analysis on the existing content of the target document to obtain an importance score of the target document; Determine whether to perform containerization processing on the application process according to the importance score.
4. The method according to claim 2, characterized in that The using the isolation container to generate a target save path for replacing the local save path in the local mapped disk corresponding to the server on the basis of the local save path of the save operation by using network storage technology includes: Use the isolation container to determine a save directory structure according to the local save path, and extract a relative save path except for the local disk from the local save path; Obtain a save path template corresponding to the application process from the software process whitelist; According to the save directory structure, use network storage technology to generate the target save path in the local mapped disk according to the relative save path and the save path template.
5. The method according to claim 1, wherein The storing the target document that has been edited in the application process to the target save path includes: Detect whether there is a network connection with the server; If not, establish a temporary save path locally and associate the temporary save path with the target save path; Store the edited target document to the temporary save path until the network connection is restored, and synchronize the document content stored in the temporary save path to the target save path by using the network connection.
6. The method according to claim 1, wherein The storing the target document that has been edited in the application process to the target save path includes: Perform structure analysis and semantic analysis on the document content of the edited target document to determine the document structure features and document content features of the target document; Determine the document type according to the document attribute characteristics, the document structure characteristics, and the document content characteristics of the edited target document; Determine the document encryption level and the encryption method matching the document encryption level according to the editing characteristics of the edited target document and the document type; Encrypt and store the edited target document to the target save path according to the encryption method matching the document encryption level; 7. The method according to claim 6, characterized in that, After encrypting and storing the edited target document to the target save path, it further includes: In response to a viewing operation of any first user on the target document stored in the target save path, obtain the authentication information of the first user; Send the authentication information of the first user to the server; the server is used to authenticate the first user and determine the permission level according to the authentication information, and decrypt the target document stored in the target save path in the case of successful authentication, and feedback the decrypted target document and the display duration matching the permission level; Obtain the decrypted target document and the display duration, and display the decrypted target document according to the display duration; 8. The method according to claim 6, characterized in that, After storing the edited target document in the application process to the target save path, it further includes: Determine the target index information of the target document according to the document source information, the document structure characteristics, and the document content characteristics of the edited target document; Determine the association degree information between the target document and other documents already stored in the server according to the target index information and the already stored index information in the database corresponding to the server; Associatively store the target index information, the association degree information, and the target save path of the target document in the database; In response to a retrieval operation of any second user, determine the matching document with the highest matching degree with the retrieval operation according to the retrieval information and the already stored index information in the database; Obtain the matching document according to the save path associated with the matching document; Display the matching document, and recommend each other document associated with the matching document to the second user according to the association degree information associated with the matching document; 9. The method according to claim 1, characterized in that, The storing the edited target document in the application process to the target save path includes: Obtain the current network environment, the current location information of the user, and the editing characteristics of the target document; Use the security assessment service to determine whether to block the isolation container according to the current network environment, the current location information, and the editing characteristics; If not, store the edited target document to the target save path; 10. The method according to claim 9, characterized in that, The method further includes: If it is determined to block the isolation container, store the edited target document to the local save path and display a prompt message; the prompt message includes storage method information and the reason for blocking; In response to canceling the blocking of the isolation container, merge and store the target document stored in the local save path into the target document already stored in the target save path, and display a new prompt message; 11. A document storage device, characterized in that, Include: A determination module, configured to determine whether to perform containerization processing on the application process in response to the creation of the application process, according to the process attributes of the application process and the software process whitelist obtained from the server; the application process is used to open and edit a target document; A creation module, configured to, if so, create an isolation container for the application process; the isolation container is used to isolate and take over the data interface between the application process and the operating system; A generation module, configured to, in response to detecting a save operation of the application process, use the isolation container to generate a target save path for replacing the local save path in the corresponding local mapped disk of the server using network storage technology according to the local save path of the save operation; A storage module, configured to store the target document that has been edited in the application process to the target save path.
12. A computer device, characterized in that, It includes: A processor and a memory, the memory stores machine-readable instructions executable by the processor, the processor is configured to execute the machine-readable instructions stored in the memory, and when the machine-readable instructions are executed by the processor, the processor executes the steps of the document storage method according to any one of claims 1 to 10.
13. A computer program product, comprising a computer program, characterized in that, When the computer program is run on a computer device, the computer device executes the steps of the document storage method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Online document management method, device, system, equipment and storage medium
CN113392070A
Storage isolation for containers
IN201947018464A
System and method of in-place content management
WO2023225763A1