Multi-enterprise archive storage method, system, equipment and medium

Through a multi-enterprise archive storage system with microservice architecture and multi-tenant architecture, combined with object storage, relational databases and Elasticsearch, the storage capacity, scalability, security and retrieval efficiency of traditional archive management systems are solved, efficient and secure archive management and rapid retrieval are achieved, and user experience is improved.

CN120371923APending Publication Date: 2025-07-25赛昇数字经济研究中心(深圳)有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510469679.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

When facing massive data, traditional archive management systems have problems such as limited storage capacity, poor scalability, insufficient security, low retrieval efficiency, and poor user experience, which are difficult to meet the needs of digital transformation in manufacturing.

Method used

Using a microservice architecture and a multi-tenant architecture, a hybrid storage model of object storage systems and relational databases is built with Elasticsearch to build an intelligent search engine to achieve data isolation and permissions, and SSL/TLS encryption and access control are adopted to configure a friendly web interactive interface.

Benefits of technology

It realizes efficient storage and rapid retrieval of multiple enterprise files, ensures data security, lowers the threshold for user use, and improves the scalability and user experience of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120371923A_ABST
    Figure CN120371923A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-enterprise archive storage system, system and equipment and a medium. The method comprises the following steps: deploying a user service module, an archive service module, a retrieval service module, a security service module, a monitoring service module and an API gateway module through a micro-service architecture; an independent storage space and an authority management system are configured for each enterprise through a multi-tenant architecture, and data and authority isolation is achieved; storing the archive file to an object storage system; storing the metadata into a relational database, and establishing a correlation index between the archive file and the metadata; an intelligent retrieval engine is constructed on the basis of Elasticsearch; the SSL / TLS is adopted to encrypt and transmit data, the access authority is controlled through the ACL, all operation logs for the archives are recorded, and the data are backed up regularly; and configuring a Web interactive interface, and supporting a user to customize an operation process and an interface layout. According to the invention, centralized management of multi-enterprise archives is realized, data isolation and safety guarantee are realized, efficient storage and rapid retrieval of data are supported, archive management efficiency is improved, and data leakage, tampering and loss are effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data management, and in particular, to a multi-enterprise file storage method, system, device and medium. Background Art

[0002] With the deep promotion of the digital transformation of the manufacturing industry, the digital files generated by enterprises in production and operation have grown exponentially, covering core information resources such as design drawings, process documents, production data, and quality inspection records. However, the traditional file management methods have problems such as low efficiency, poor security, and low utilization rate, and are difficult to meet the needs of digital transformation.

[0003] Currently, enterprises generally adopt a file management system based on a centralized architecture, relying on a centralized database or file server to achieve unified storage and management of files. Such an architecture has significant bottlenecks when dealing with massive data scenarios: Firstly, the storage capacity is limited, the system architecture lacks flexibility and scalability, it is difficult to adapt to changing business needs, and the function expansion and performance improvement are restricted; Secondly, there is a lack of an efficient file storage and retrieval mechanism, it is difficult to meet the storage and fast retrieval needs of massive data, and the file management efficiency is low; Thirdly, the centralized storage is prone to insufficient data security guarantee, and the existing system cannot effectively prevent data leakage, tampering and loss, and there are relatively large security risks; Fourthly, there is a lack of effective data analysis and mining functions, it is impossible to fully explore the value of file data, and it is difficult to provide strong support for enterprise decision-making.

[0004] Fifthly, the user interface interaction is complex, the operation process is long, there is a high usage threshold, and the user experience is affected. Summary of the Invention

[0005] The present invention provides a multi-enterprise file storage method, system, device and medium to solve the problem of how to manage files safely and efficiently.

[0006] To achieve the above object, the present application adopts the following technical solutions: In a first aspect, a multi-enterprise file storage method is provided, including: Deploying user services, file services, retrieval services, security services, monitoring services and API gateway modules through a microservices architecture; Configuring an independent storage space and permission management system for each enterprise through a multi-tenant architecture to achieve data and permission isolation; For file documents, storing them in an object storage system; for metadata, storing them in a relational database, and establishing an association index between the file documents and the metadata; Build an intelligent retrieval engine based on Elasticsearch; Adopt SSL / TLS to encrypt and transmit data, control access rights through ACL, record all operation logs of files and back up data regularly; Configure a Web interaction interface to support users to customize operation processes and interface layouts.

[0007] In the first possible implementation manner of the first aspect, the independent storage space and permission management system are configured for each enterprise through a multi-tenant architecture to achieve data and permission isolation, specifically including: In the object storage system MinIO, create an independent Bucket for each registered enterprise to store all file archives of the enterprise; In the relational database PostgreSQL, create an independent Schema for each enterprise to store the file metadata of the corresponding enterprise; Create an independent permission management system for each enterprise, and create roles with different permissions for the enterprise in the permission management system; Optionally share the set file resources with other enterprises according to permissions, and assign read-only or edit permissions to other enterprises.

[0008] In the second possible implementation manner of the first aspect, the intelligent retrieval engine built based on Elasticsearch specifically includes: Perform word segmentation on the uploaded file archives, build an inverted index, and store it in the Elasticsearch cluster; When querying, parse the natural language query, extract keywords and retrieval conditions, jointly query the meta database and the full-text index, and return the sorted results; correct input errors through a fuzzy matching algorithm to expand the retrieval scope.

[0009] Based on any possible implementation manner of the first aspect, in the third possible implementation manner of the first aspect, the user service module is used for user authentication, authorization, and permission management; The file service module is used for file storage, management, version control, and metadata management; The retrieval service module is used to provide full-text retrieval, conditional retrieval, advanced retrieval, and fuzzy retrieval functions; The security service module is used for data encryption, access control, operation logs, and data backup and recovery; The monitoring service module is used for functions such as system monitoring, log collection, and performance analysis; The API gateway module is used to provide a unified API interface and for request routing, load balancing, and security authentication.

[0010] In a second aspect, a multi-enterprise file storage system is provided, including: A microservice module for deploying user services, file services, retrieval services, security services, monitoring services, and an API gateway module through a microservice architecture; A storage space and permission management module for configuring an independent storage space and permission management system for each enterprise through a multi-tenant architecture to achieve data and permission isolation; A hybrid storage module for: storing archive files in an object storage system; storing metadata in a relational database, and establishing an association index between the archive files and the metadata; A retrieval engine module for building an intelligent retrieval engine based on Elasticsearch; A data security module for encrypting data transmission using SSL / TLS, controlling access permissions through ACL, recording all operation logs of archives, and backing up data regularly; An interactive interface module for configuring a Web interactive interface to support users in customizing operation processes and interface layouts.

[0011] In a first possible implementation manner of the second aspect, the storage space and permission management module is specifically used for: In the object storage system MinIO, creating an independent Bucket for each registered enterprise to store all archive files of the enterprise; In the relational database PostgreSQL, creating an independent Schema for each enterprise to store the archive metadata of the corresponding enterprise; Creating an independent permission management system for each enterprise, and creating roles with different permissions for the enterprise in the permission management system; Optionally sharing specified archive resources with other enterprises according to permissions, and assigning read-only or edit permissions to other enterprises.

[0012] In a second possible implementation manner of the second aspect, the retrieval engine module is specifically used for: Performing word segmentation processing on the uploaded archive files, building an inverted index, and storing it in the Elasticsearch cluster; When querying, parsing natural language queries, extracting keywords and retrieval conditions, jointly querying the metadata database and the full-text index, and returning sorted results; correcting input errors through a fuzzy matching algorithm and expanding the retrieval scope.

[0013] Based on any possible implementation manner of the second aspect, in a third possible implementation manner of the second aspect, the user service module is used for user authentication, authorization, and permission management; The file service module is used for file storage, management, version control, and metadata management; The retrieval service module is used to provide full-text retrieval, conditional retrieval, advanced retrieval, and fuzzy retrieval functions; The security service module is used for data encryption, access control, operation logs, and data backup and recovery; The monitoring service module is used for system monitoring, log collection, performance analysis, and other functions; The API gateway module is used to provide a unified API interface and is used for request routing, load balancing, and security authentication.

[0014] In a third aspect, an electronic device is provided, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the multi-enterprise file storage method described in the first aspect are implemented.

[0015] In a fourth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the multi-enterprise file storage method described in the first aspect are implemented.

[0016] The multi-enterprise file storage method of the present invention has the following advantages: The present invention realizes the centralized management of multi-enterprise files, adopts a multi-tenant architecture to provide independent storage space and permission management for each enterprise, realizes data isolation and security protection, and effectively solves the problem that the existing system cannot meet the sharing of file resources by multiple enterprises; adopts a hybrid storage mode, combines object storage and relational databases, supports the efficient storage and rapid retrieval of massive data, and improves the file management efficiency; constructs a multi-level data security system, effectively prevents data leakage, tampering, and loss, and ensures the security of file data; constructs an intelligent retrieval system based on Elasticsearch with multiple retrieval methods, improves the retrieval efficiency and accuracy, is conducive to mining the value of file data, and provides support for enterprise decision-making; adopts a microservices architecture, improves the scalability, maintainability, and reusability of the system, is conducive to adapting to changing business needs, and realizes function expansion and performance improvement; provides a friendly user interface and operation process, reduces the user's usage threshold, and improves the user experience.

[0017] The system, electronic device, and readable storage medium corresponding to the multi-enterprise file storage method of the present invention can achieve the same technical effects. To avoid repetition, they are not elaborated here. Description of the Drawings

[0018] Figure 1 It is a schematic flowchart of a multi-enterprise file storage method provided by an embodiment of the present application; Figure 2A schematic structural diagram of another multi-enterprise file storage system provided by an embodiment of the present application; Figure 3 A structural schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0019] To further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined purpose, the technical solutions in the embodiments of the present application are clearly described. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.

[0020] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the associated objects before and after.

[0021] In the present application, the description of the method flow in the specification and the steps in the flowchart in the accompanying drawings of the present invention do not necessarily have to be strictly executed according to the step numbers. The execution order of the method steps can be changed. Moreover, some steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution.

[0022] The multi-enterprise file storage method, system, device and medium provided by the embodiments of the present application are described in detail as follows in combination with the accompanying drawings and preferred embodiments.

[0023] Please refer to Figure 1-2 An embodiment of the present application provides a multi-enterprise file storage method. As Figure 1-2 shown, the storage method of the embodiment of the present application includes: Step S1, deploying user services, file services, retrieval services, security services, monitoring services and API gateway modules through a microservices architecture.

[0024] Adopting a microservices architecture to modularize the system functions, including a user service module, a file service module, a retrieval service module, a security service module, a monitoring service module and an API gateway module.

[0025] Step S2: Configure an independent storage space and a permission management system for each enterprise through a multi-tenant architecture to achieve data and permission isolation.

[0026] Allocate an independent storage space for each enterprise to achieve data isolation; allocate an independent permission management system for each enterprise to achieve permission isolation; thus supporting the sharing of archive resources between enterprises and providing a fine-grained access control mechanism.

[0027] Step S3: For archive files, store them in an object storage system; for metadata, store it in a relational database, and establish an association index between the archive files and the metadata.

[0028] In the specific implementation process of this step, the object storage system MinIO can be used to store a large amount of archive file data; the relational database PostgreSQL can be used to store archive metadata and index information; by establishing the association relationship between the archive files and the metadata, efficient storage and retrieval of data can be achieved.

[0029] Step S4: Build an intelligent retrieval engine based on Elasticsearch.

[0030] Build a full-text retrieval engine based on Elasticsearch, supporting full-text retrieval of the archive text content; supporting conditional retrieval of archive metadata, such as retrieving by archive type, creation time, keywords, etc.; supporting semantic retrieval to improve the retrieval accuracy through natural language processing technology; supporting fuzzy retrieval to improve the fault tolerance and flexibility of the retrieval.

[0031] Step S5: Use SSL / TLS to encrypt and transmit data, control access permissions through ACL, record all operation logs of the archives, and back up the data regularly.

[0032] Build a multi-level data security system, adopt SSL / TLS encryption technology to ensure the security of data during transmission; all requests sent through the Web interface or API interface will be encrypted and transmitted through the HTTPS protocol to prevent data from being stolen or tampered with. Adopt the access control list (ACL) mechanism to control users' access rights to file resources; only authorized users can access the corresponding files, and unauthorized users will not be able to view or operate on the file content; the access control policy can be configured based on conditions such as user roles and affiliated enterprises. Record all operation logs of files, including operations such as viewing, editing, deleting, and downloading, to achieve security auditing; if a data leak or malicious tampering occurs, the root cause of the problem can be traced based on the operation logs; the operation logs will be retained for a long time for future auditing needs. Regularly back up the file data, support the data recovery function to prevent data loss; for example, the system performs a full backup of the file data once a day, and the backup data will be stored in a storage system in a different location to prevent data loss caused by disasters in the data center. If data loss or damage occurs, the data can be recovered from the backup to ensure business continuity. The system also supports on-demand manual backup and recovery operations.

[0033] Step S6, configure the Web interaction interface to support users to customize the operation process and interface layout.

[0034] When this step is specifically implemented, a Web-based friendly user interface is provided, supporting access by various terminal devices; by designing a simple and clear operation process, the user learning cost is reduced; by providing online help documents and video tutorials, it is convenient for users to get started quickly; at the same time, personalized interface customization is supported to meet the usage habits of different users.

[0035] Furthermore, the above user service module, file service module, retrieval service module, security service module, monitoring service module, and API gateway module. Specifically: The user service module is responsible for functions such as user authentication, authorization, and permission management; when specifically implemented, users first register through the Web interface or mobile application, fill in basic information such as username, password, and enterprise information, and the system encrypts and stores the user information in the user database. When the user logs in, the system verifies the correctness of the username and password, and assigns corresponding access rights after passing. The system supports the role-based access control (RBAC) mechanism, and the administrator can create different roles, assign different permissions to each role, and then assign users to the corresponding roles.

[0036] The file service module is responsible for functions such as file storage, management, version control, and metadata management. Specifically, when implemented, users can upload file documents through a Web interface or an API interface. The system stores the files in an object storage system (such as MinIO) and stores the file metadata in a relational database (such as PostgreSQL). The system supports classified management of files, and users can customize classification tags. The system also supports file version control. Each time a file is modified, a new version is generated, and users can view and restore any version of the file.

[0037] The retrieval service module provides retrieval functions such as full-text retrieval, conditional retrieval, advanced retrieval, and fuzzy retrieval. Specifically, when implemented, the system builds a full-text retrieval engine based on Elasticsearch and supports full-text retrieval of the text content of files. Users can enter keywords, and the system returns all files containing the keywords. The system also supports conditional retrieval of file metadata, such as retrieving files according to conditions such as file type, creation time, and keywords. In addition, the system supports semantic retrieval, improving retrieval accuracy through natural language processing technology, and users can use natural sentences for retrieval. The system can also support fuzzy retrieval. Even if the entered keywords have spelling mistakes, the system can still return relevant results.

[0038] The security service module is responsible for functions such as data encryption, access control, operation logs, data backup and recovery. Specifically, when implemented, the system uses SSL / TLS encryption technology to ensure the security of data during transmission. The system adopts an access control list (ACL) mechanism, and only authorized users can access the corresponding file resources. The system records all operation logs of files to achieve security auditing. The system performs a full backup of file data once a day, and the backup data is stored in a remote location to prevent data loss. If data loss or damage occurs, the data can be restored from the backup.

[0039] The monitoring service module is responsible for functions such as system monitoring, log collection, and performance analysis. Specifically, when implemented, the system can deploy the Prometheus monitoring system to collect the running status data of each microservice and display it through Grafana. The system uses the ELK (Elasticsearch, Logstash, Kibana) technology stack to collect and analyze system logs to help quickly locate and solve system problems. The system also integrates an APM (Application Performance Management) tool to monitor and optimize performance metrics such as the throughput, response time, and error rate of the system.

[0040] The API gateway module provides a unified API interface and is responsible for functions such as request routing, load balancing, and security authentication. Specifically, when implemented, the system can use Nginx as the API gateway, and all access requests to the system need to be routed through Nginx. Nginx forwards requests to the corresponding microservices according to the URL path of the request. Nginx can also provide load balancing functions, evenly distributing requests to multiple microservice instances to improve the throughput and availability of the system. Nginx interfaces with the security service module to authenticate the identity and verify the permissions of all requests to prevent unauthorized access.

[0041] Furthermore, in step S2, an independent storage space and permission management system are configured for each enterprise through a multi-tenant architecture to achieve data and permission isolation. Specifically, it includes: Step S201, in the object storage system MinIO, create an independent Bucket for each registered enterprise to store all the archive files of that enterprise. The said Bucket stores all the archive files of the corresponding enterprise, ensuring that the archive files between different enterprises are physically isolated from each other.

[0042] Step S202, in the relational database PostgreSQL, create an independent Schema for each enterprise to store the archive metadata of the corresponding enterprise. The said Schema is specifically used to store the archive metadata of that enterprise, further ensuring data isolation between enterprises.

[0043] In this way, the data of different enterprises is physically isolated and does not interfere with each other.

[0044] Step S203, create an independent permission management system for each enterprise, and create roles with different permissions for the enterprise in the permission management system.

[0045] Administrators can create different roles in this permission system and assign different permissions to each role, including permissions such as viewing, editing, deleting, and downloading. Then, assign the users within the enterprise to different roles. In this way, permission management and control within the enterprise are achieved.

[0046] Step S204, selectively share the set archive resources with other enterprises according to the permissions and assign read-only or edit permissions to other enterprises.

[0047] Enterprise administrators can choose to share certain archive resources with other enterprises and assign read-only or edit permissions to other enterprises. The system adopts a fine-grained access control mechanism, which can control down to the level of a single archive file. Based on this, although the data of different enterprises is isolated, the system supports sharing of archive resources between enterprises.

[0048] Further, in step S3, the archival files of each enterprise are stored in the object storage system, and the corresponding metadata is stored in the relational database, and an association index is established between the archival files and the metadata. Specifically: The system uses the object storage system MinIO to store a large amount of archival file data. MinIO has high scalability, high concurrency, and high fault tolerance, and is very suitable for storing a large amount of unstructured data. The system stores each archival file as an object in MinIO, and the metadata of the file is stored as the metadata of the object.

[0049] The system uses the object storage system MinIO to store a large amount of archival file data. MinIO has high scalability, high concurrency, and high fault tolerance, and is very suitable for storing a large amount of unstructured data. The system stores each archival file as an object in MinIO, and the metadata of the file is stored as the metadata of the object.

[0050] The system uses the relational database PostgreSQL to store the structured metadata and index information of the archives. The metadata includes information such as the name, type, creation time, and affiliated enterprise of the archives. The index information is used to support fast retrieval, and the system will build an inverted index to accelerate keyword search.

[0051] The system has established an association relationship between the archival files and the metadata. When a user uploads a new archival file, the system stores the file in MinIO and inserts a new metadata record in PostgreSQL, and the two are associated through the file ID. When a user queries or retrieves an archive, the system first searches for the metadata records that meet the conditions in PostgreSQL, and then obtains the corresponding file data from MinIO according to the file ID. Through this hybrid storage mode, efficient storage and retrieval of data are achieved.

[0052] Further, in step S4, an intelligent retrieval engine is built based on Elasticsearch. Specifically: The uploaded archival files are tokenized, an inverted index is built, and stored in the Elasticsearch cluster; During query, the natural language query is parsed, keywords and retrieval conditions are extracted, the metadata database and the full-text index are jointly queried, and the sorted results are returned; the input errors are corrected through the fuzzy matching algorithm to expand the retrieval scope.

[0053] Exemplarily: The user can input keywords in the retrieval interface, and the system will search all archives containing the keywords in Elasticsearch and return a list of search results. The system also supports conditional retrieval of archive metadata; the user can select conditions such as archive type, creation time range, and affiliated enterprise for combined retrieval, and the system will query the archive metadata records that meet the conditions in the PostgreSQL database according to these conditions. In addition, the system supports semantic retrieval; by integrating natural language processing (NLP) technology, the system can understand the natural statements input by the user, extract keywords and retrieval intentions, and then convert them into appropriate query statements to improve the accuracy of retrieval. Finally, the system also supports fuzzy retrieval; when there are spelling mistakes in the keywords input by the user, the system can give similar entries according to the edit distance algorithm, so as to return relevant retrieval results, improving the fault tolerance and flexibility of retrieval.

[0054] Through the above method, the storage method of the embodiments of the present application realizes centralized management of multi-enterprise archives, adopts a multi-tenant architecture to provide independent storage space and permission management for each enterprise, realizes data isolation and security guarantee, and effectively solves the problem that the existing system cannot meet the sharing of archive resources by multiple enterprises; adopts a hybrid storage mode, combines object storage and relational database, supports efficient storage and fast retrieval of massive data, and improves the efficiency of archive management; constructs a multi-level data security system, including mechanisms such as data encryption, access control, security auditing, data backup and recovery, effectively prevents data leakage, tampering and loss, and guarantees the security of archive data; constructs an intelligent retrieval system based on Elasticsearch, supports multiple retrieval methods such as full-text retrieval, conditional retrieval, and semantic retrieval, improves the retrieval efficiency and accuracy, is conducive to mining the value of archive data, and provides support for enterprise decision-making; adopts a microservices architecture, improves the scalability, maintainability and reusability of the system, is conducive to adapting to changing business needs, and realizes function expansion and performance improvement; provides a friendly user interface and operation process, reduces the user's usage threshold, and improves the user experience.

[0055] See Figure 2 , corresponding to the above embodiments of the multi-enterprise archive storage method, the embodiments of the present application provide a multi-enterprise archive storage system, which includes: The microservices module 1001 is used to deploy user services, archive services, retrieval services, security services, monitoring services and API gateway modules through the microservices architecture; The storage space and permission management module 1002 is used to configure an independent storage space and permission management system for each enterprise through the multi-tenant architecture to realize data and permission isolation; The hybrid storage module 1003 is used for: storing archival files in an object storage system; storing metadata in a relational database, and establishing an association index between the archival files and the metadata; The retrieval engine module 1004 is used to build an intelligent retrieval engine based on Elasticsearch; The data security module 1005 is used to encrypt and transmit data using SSL / TLS, control access rights through ACL, record all operation logs of the archives, and back up data regularly; The interaction interface module 1006 is used to configure a Web interaction interface, supporting users to customize the operation process and interface layout.

[0056] Furthermore, the storage space and permission management module 1002 is specifically used for: In the object storage system MinIO, create an independent Bucket for each registered enterprise to store all the archival files of the enterprise; In the relational database PostgreSQL, create an independent Schema for each enterprise to store the archival metadata of the corresponding enterprise; Create an independent permission management system for each enterprise, and create roles with different permissions for the enterprise in the permission management system; Optionally share the set archival resources with other enterprises according to the permissions, and assign read-only or edit permissions to other enterprises.

[0057] Furthermore, the retrieval engine module 1004 is specifically used for: Perform word segmentation on the uploaded archival files, build an inverted index, and store it in the Elasticsearch cluster; When querying, parse the natural language query, extract keywords and retrieval conditions, jointly query the metadata database and the full-text index, and return the sorted results; correct input errors through a fuzzy matching algorithm and expand the retrieval range.

[0058] Furthermore, the user service module is used for user authentication, authorization, and permission management; The archival service module is used for the storage, management, version control, and metadata management of archives; The retrieval service module is used to provide full-text retrieval, conditional retrieval, advanced retrieval, and fuzzy retrieval functions; The security service module is used for data encryption, access control, operation logs, and data backup and recovery; The monitoring service module is used for functions such as system monitoring, log collection, and performance analysis; The API gateway module is used to provide a unified API interface, and for request routing, load balancing, and security authentication.

[0059] The above multi-enterprise file storage system implements the steps of the above multi-enterprise file storage system embodiment and each process of the embodiment, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0060] See Figure 3 , corresponding to the above multi-enterprise file storage system embodiment, an embodiment of the present application provides an electronic device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements the steps of the above multi-enterprise file storage system embodiment and each process of the embodiment, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0061] The memory 1009 can be used to store software programs and various data. The memory 1009 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area can store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 1009 may include volatile memory or non-volatile memory, or the memory 1009 may include both volatile and non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 1009 in the embodiments of the present application includes, but is not limited to, these and any other suitable types of memory.

[0062] The processor 1010 may include one or more processing units; optionally, the processor 1010 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor may not be integrated into the processor 1010 either.

[0063] Corresponding to the above embodiments of the multi-enterprise file storage system, an embodiment of the present application also provides a readable storage medium. A program or instruction is stored on the readable storage medium. When the program or instruction is executed by a processor, the steps and various processes of the above embodiments of the multi-enterprise file storage system are implemented, and the same technical effects can be achieved. To avoid repetition, they will not be elaborated here.

[0064] Among them, the processor is the processor in the electronic device described in the above embodiments of the present application. The readable storage medium includes computer-readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs, etc.

[0065] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article or device. Without more limitations, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be executed in an order different from that described, and various steps may be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0066] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0067] It can be understood that the embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative and not restrictive. Those skilled in the art know that, without departing from the spirit and scope of the present invention, various changes or equivalent replacements can be made to these features and embodiments. In addition, those of ordinary skill in the art can modify these features and embodiments under the inspiration or teaching of the present application to adapt to specific situations and materials without departing from the spirit and scope of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed herein, and all embodiments falling within the scope of the claims of the present application belong to the scope protected by the present invention.

Claims

1. A multi-enterprise file storage method, characterized in that, Including: Deploy user service, file service, retrieval service, security service, monitoring service and API gateway module through microservice architecture; Configure an independent storage space and permission management system for each enterprise through multi-tenant architecture to achieve data and permission isolation; For archival files, store them in an object storage system; for metadata, store it in a relational database, and establish an association index between archival files and metadata; Build an intelligent retrieval engine based on Elasticsearch; Adopt SSL / TLS to encrypt and transmit data, control access rights through ACL, record all operation logs of archives and back up data regularly; Configure a Web interaction interface to support users to customize operation processes and interface layouts.

2. The multi-enterprise archival storage method according to claim 1, characterized in that The configuration of an independent storage space and permission management system for each enterprise through multi-tenant architecture to achieve data and permission isolation specifically includes: In the object storage system MinIO, create an independent Bucket for each registered enterprise to store all archival files of the enterprise; In the relational database PostgreSQL, create an independent Schema for each enterprise to store the archival metadata of the corresponding enterprise; Create an independent permission management system for each enterprise, and create roles with different permissions for the enterprise in the permission management system; Optionally share the set archival resources with other enterprises according to permissions, and assign read-only or edit permissions to other enterprises.

3. The multi-enterprise archival storage method according to claim 1, characterized in that The construction of an intelligent retrieval engine based on Elasticsearch specifically includes: Perform word segmentation processing on the uploaded archival files, build an inverted index, and store it in the Elasticsearch cluster; During query, parse the natural language query, extract keywords and retrieval conditions, jointly query the metadata database and the full-text index, and return the sorted results; correct input errors through a fuzzy matching algorithm and expand the retrieval scope.

4. The multi-enterprise archival storage method according to any one of claims 1-3, characterized in that The user service module is used for user authentication, authorization, and permission management; The file service module is used for storage, management, version control, and metadata management of archives; The retrieval service module is used to provide full-text retrieval, conditional retrieval, advanced retrieval, and fuzzy retrieval functions; The security service module is used for data encryption, access control, operation logs, and data backup and recovery; The monitoring service module is used for functions such as system monitoring, log collection, and performance analysis; The API gateway module is used to provide a unified API interface, and for request routing, load balancing, and security authentication.

5. A multi-enterprise file storage system, characterized in that, Including: The microservice module is used to deploy user service, file service, retrieval service, security service, monitoring service and API gateway module through microservice architecture; The storage space and permission management module is used to configure an independent storage space and permission management system for each enterprise through multi-tenant architecture to achieve data and permission isolation; Hybrid storage module, configured to: store archival files in an object storage system; store metadata in a relational database, and establish an association index between the archival files and the metadata; Retrieval engine module, configured to build an intelligent retrieval engine based on Elasticsearch; Data security module, configured to encrypt and transmit data using SSL / TLS, control access rights through ACL, record all operation logs of the archives, and backup data regularly; Interactive interface module, configured to configure a Web interactive interface, and support users to customize the operation process and interface layout.

6. The multi-enterprise archival storage system according to claim 5, wherein The storage space and permission management module is specifically configured to: In the object storage system MinIO, create an independent Bucket for each registered enterprise to store all archival files of the enterprise; In the relational database PostgreSQL, create an independent Schema for each enterprise to store the archival metadata of the corresponding enterprise; Create an independent permission management system for each enterprise, and create roles with different permissions for the enterprise in the permission management system; Optionally share the set archival resources with other enterprises according to the permissions, and assign read-only or edit permissions to other enterprises.

7. The multi-enterprise archival storage system according to claim 5, wherein The retrieval engine module is specifically configured to: Perform word segmentation on the uploaded archival files, build an inverted index, and store it in the Elasticsearch cluster; During query, parse the natural language query, extract keywords and retrieval conditions, jointly query the metadata database and the full-text index, and return the sorted results; correct input errors through a fuzzy matching algorithm and expand the retrieval range.

8. The multi-enterprise archival storage system according to any one of claims 5-7, wherein The user service module is used for user authentication, authorization, and permission management; The archival service module is used for archival storage, management, version control, and metadata management; The retrieval service module is used to provide full-text retrieval, conditional retrieval, advanced retrieval, and fuzzy retrieval functions; The security service module is used for data encryption, access control, operation logs, and data backup and recovery; The monitoring service module is used for functions such as system monitoring, log collection, and performance analysis; The API gateway module is used to provide a unified API interface, and for request routing, load balancing, and security authentication.

9. An electronic device, characterized in that, The electronic device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the multi-enterprise archival storage method according to any one of claims 1 to 4 are implemented.

10. A readable storage medium, characterized in that, A program or instruction is stored on the readable storage medium. When the program or instruction is executed by the processor, the steps of the multi-enterprise archival storage method according to any one of claims 1 to 4 are implemented.