Server data access control method, device, equipment and storage medium
By obtaining user attributes and bidding project prediction information, the resource scheduling and user matching of distributed servers are optimized, the flexibility problem of data access control in the distributed server architecture is solved, intelligent allocation and scheduling are realized, and the server access experience and resource utilization efficiency are improved.
Patent Information
- Application Number
- CN202510947652.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-10
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-07-10
AI Technical Summary
In a distributed server architecture, server data access control is affected by factors such as industry categories, regional differences, time peak differences, and strong regional correlations, resulting in limited flexibility in service user allocation and data scheduling, making it difficult to achieve reasonable resource scheduling and access control.
By obtaining user attribute information and tender project prediction information in the sub-service area, the resource scheduling and service user matching of the distributed server are optimized. The convolutional neural network model is used to predict the tender project requirements. Combined with the server hardware load and resource constraints, a data access control strategy is formulated to achieve resource scheduling and user matching in each access control cycle.
It improves the rationality of server data access control, realizes intelligent allocation and scheduling based on different industry categories, time peaks and regional correlations, and improves server access experience and resource utilization efficiency.
Smart Images

Figure CN120455171B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of server data access control, and in particular to a server data access control method, device, equipment and storage medium. Background Art
[0002] Server data access control is the process of restricting and managing user or application access to server data through a series of technical means and management strategies, ensuring that only authorized entities can access and manipulate data in a legal manner and within the prescribed scope of authority. In service platform applications based on a distributed server architecture, the service platform can ensure data security, data processing efficiency, efficient hardware resource utilization, and load balancing across distributed servers through the design of server data access control, thereby improving the service user experience and the overall platform performance.
[0003] However, in actual applications, server data access control in some scenarios needs to consider the influence of multiple factors, which leads to some limitations in server data access control: the startup and execution of tender application services have regional differences and time peak differences in industry categories, that is, different types of industry categories usually have different server access peaks. Different types of industry categories have regional differences, which leads to different access peaks for servers storing different tender project processing support data. The bidding content of some special industry categories may also have strong regional correlations. At the same time, distributed servers deployed in different regions are also affected by data storage capacity and network communication capabilities. These factors limit the flexibility of allocating service users of distributed servers to each sub-service area and scheduling tender project processing support data, which increases the difficulty of distributed server data access control.
[0004] Therefore, how to improve the rationality of server data access control planning, consider the regional differences, time peak differences, strong regional correlations and hardware resource limitations of distributed servers in different industry categories of bidding application services, and realize the intelligent allocation of service users from distributed servers to each sub-service area and the flexible scheduling of bidding project processing support data, is a technical problem that needs to be solved urgently. Summary of the Invention
[0005] The present invention provides a server data access control method, device, equipment and storage medium, aiming to solve at least one of the above technical problems.
[0006] To achieve the above object, the present invention provides a server data access control method, comprising the following steps:
[0007] Obtaining user attribute information of several sub-service areas within the target service range; wherein the user attribute information includes user industry categories and the number of service users in each user industry category;
[0008] Based on the user attribute information of each sub-service area and the bidding project forecast information of the target service scope during the target server access control period, the bidding project service demand of each sub-service area during each access control cycle during the target server access control period is estimated;
[0009] Query the distributed server deployment information within the target service range, consider the tender project service requirements of each sub-service area in each access control period, use the overall processing delay of the server executing the corresponding service user tender project, server hardware load and server resource scheduling restrictions as the constraint condition set, and take the service user's server access experience during the target server access control period as the optimization goal, and optimize and solve the server data access control policy of the distributed server;
[0010] Extracting the resource scheduling sub-strategy and service user matching sub-strategy of the server data access control policy, and executing resource scheduling and service user matching of the distributed server in each access control cycle of the target server access control period;
[0011] According to the resource scheduling of the distributed server and the result of matching the service users, each service user is controlled to restrict data access of the service user when the distributed server executes the bidding project service.
[0012] Optionally, the step of obtaining user attribute information of several sub-service areas within the target service range specifically includes:
[0013] Collect user information entered by service users in each sub-service area when they register or use the platform for the first time, and extract the first user industry category information from the user information;
[0014] Querying historical service information of a number of tender project services performed by service users in each sub-service area during a target historical period, extracting tender project service industry categories and the number of services for each tender project service industry category from the historical service information, and generating second user industry category information;
[0015] Summarize the user industry category information, count the user industry categories of each sub-service area and the service users involved in each user industry category, calculate the number of service users corresponding to each user industry category, and generate user attribute information of several sub-service areas within the target service range.
[0016] Optionally, based on the user attribute information of each sub-service area and the forecast information of the tender items of the target service scope during the target server access control period, the step of estimating the tender item service demand of each sub-service area during each access control cycle during the target server access control period specifically includes:
[0017] Obtaining forecast information of tender items within the target service scope during the target server access control period; wherein the forecast information includes the forecast number of tender items for each project industry category within the target server access control period and the associated time period of the tender items;
[0018] Extracting the user industry category and the number of service users of each user industry category from the user attribute information of each sub-service area, and generating a quantitative value of the service demand of the bidding project for each user industry category;
[0019] Based on the quantitative value of the tender project service demand of each user industry category and the tender project associated time period of the project industry category corresponding to the user industry category, the tender project service demand of each sub-service area in each access control cycle within the target server access control period is estimated.
[0020] Optionally, the step of obtaining forecast information of bidding items within the target service scope during the target server access control period specifically includes:
[0021] Collect the effective time of each tender document project for each project industry category within the target service scope within several historical server access control periods;
[0022] Counting the number of tender documents published for each project industry category during each historical server access control period and the tender document project associated period to generate a tender document project sample set; wherein the tender document project associated period is configured as a period consisting of the effective time of tender documents for each project industry category covering a number of access control cycles exceeding a preset ratio within the corresponding historical server access control period;
[0023] Using the tender item training samples in the tender item samples to train the pre-built initial convolutional neural network model, to obtain a tender item prediction model that reaches the training number or training convergence;
[0024] By using the tender project prediction samples in the tender project samples and the trained tender project prediction model, the predicted number of tender projects and the tender project associated time period of each project industry category in the target service scope within the target server access control period are predicted.
[0025] Optionally, extracting the user industry category and the number of service users of each user industry category from the user attribute information of each sub-service area, and generating a quantitative value of the service demand of the bidding project for each user industry category, specifically includes:
[0026] Extracting the user industry category and the number of service users of each user industry category from the user attribute information of each sub-service area;
[0027] For user industry categories with strong regional associations, calculate the product of the number of service users of each user industry category in each sub-service area and the predicted number of tender projects of the project industry category corresponding to the user industry category in the same sub-service area, and use the product value as the quantitative value of the tender project service demand of the user industry category in each sub-service area;
[0028] For user industry categories that do not have strong geographical associations, calculate the product of the number of service users of each user industry category in each sub-service area and the predicted number of tender projects of the project industry category corresponding to the user industry category, and use the product value as the quantitative value of the tender project service demand of the user industry category in each sub-service area;
[0029] The quantitative value of the tender document project service demand of each user industry category is generated according to the quantitative value of the tender document project service demand of the user industry category with strong regional association and the quantitative value of the tender document project service demand of the user industry category with non-strong regional association.
[0030] Optionally, query the distributed server deployment information within the target service range, consider the tender project service requirements of each sub-service area in each access control period, use the overall processing delay of the server executing the corresponding service user tender project, server hardware load, and server resource scheduling restrictions as the constraint condition set, and use the service user's server access experience during the target server access control period as the optimization goal. The server data access control policy steps for the distributed server are optimized, specifically including:
[0031] Querying the distributed server deployment information within the target service range, and extracting the server deployment location and server hardware deployment resources from the distributed server deployment information;
[0032] After each distributed server is allocated a tender project processing support dataset of a user industry category in each access control cycle, the server demand quantity determined according to the preset conversion rule for the quantitative value of the tender project service demand of each user industry category in each sub-service area in each access control cycle is less than the number of servers deployed within the standard delay communication range that store the tender project processing support dataset of the corresponding user industry category. This is the first constraint condition. The storage space of the tender project processing support dataset occupied by each distributed server in each access control cycle is less than the hardware storage load upper limit of the distributed server. This is the third constraint condition. The amount of tender project processing support dataset newly added by the distributed server in each sub-service area in each access control cycle compared with the previous access control cycle is less than the upper limit of the data transmission volume between the distributed server and the cloud server during the idle period of each access control cycle. The optimization goal is to minimize the sum of the server allocation switching times between all two adjacent access control cycles in each sub-service area during the entire target server access control period. The resource scheduling sub-strategy and service user matching sub-strategy of the distributed server are optimized and solved.
[0033] According to the resource scheduling sub-strategy of the distributed server and the service user matching sub-strategy, a server data access control policy of the distributed server is generated.
[0034] Optionally, based on the resource scheduling of the distributed server and the result of matching the service users, controlling each service user to restrict data access when the distributed server performs the bidding project service, specifically includes:
[0035] According to the resource scheduling of the distributed servers and the matching results of the service users, control each distributed server to execute the resource scheduling of the bid project processing support data set corresponding to the user industry category in each access control cycle, and generate a service user access list for each access control cycle;
[0036] Control the service users of each sub-service area to access the corresponding distributed server in each access control cycle according to the service user access list, and execute the bidding project processing of the service user.
[0037] In addition, in order to achieve the above-mentioned object, the present invention further provides a server data access control device, comprising:
[0038] An acquisition module is used to acquire user attribute information of several sub-service areas within the target service range; wherein the user attribute information includes user industry categories and the number of service users of each user industry category;
[0039] An estimation module, configured to estimate the tender project service demand of each sub-service area in each access control period of the target server based on user attribute information of each sub-service area and tender project prediction information of the target service scope in the access control period of the target server;
[0040] The query module is used to query the distributed server deployment information within the target service range. It considers the tender project service requirements of each sub-service area in each access control period, uses the overall processing delay of the server executing the corresponding service user tender project, server hardware load, and server resource scheduling restrictions as the constraint condition set, and takes the service user's server access experience during the target server access control period as the optimization goal, and optimizes the server data access control policy of the distributed server.
[0041] An extraction module is used to extract the resource scheduling sub-strategy and service user matching sub-strategy of the server data access control policy, and perform resource scheduling and service user matching of the distributed server in each access control cycle of the target server access control period;
[0042] The access module is used to control each service user to restrict data access when the distributed server performs the bidding project service according to the resource scheduling of the distributed server and the result of matching the service users.
[0043] In addition, in order to achieve the above-mentioned purpose, the present invention also provides a server data access control device, which includes: a memory, a processor, and a server data access control program stored on the memory and executable on the processor. When the server data access control program is executed by the processor, the steps of the server data access control method described above are implemented.
[0044] In addition, to achieve the above-mentioned purpose, the present invention further provides a storage medium, on which a server data access control program is stored. When the server data access control program is executed by a processor, the steps of the above-mentioned server data access control method are implemented.
[0045] The beneficial effects of the present invention are as follows: a server data access control method, apparatus, device and storage medium are proposed, which estimates the tender project service demand of each sub-service area, queries the distributed server deployment information, takes the overall processing delay of the server executing the corresponding service user tender project, the server hardware load and the server resource scheduling limit as the constraint condition set, takes the server access experience of the service user in the target server access control period as the optimization goal, solves the server data access control strategy, and uses the control strategy to realize the resource scheduling of the distributed server and the matching of service users in each access control cycle, thereby executing the tender project service. The present invention improves the rationality of server data access control planning by considering the regional differences, time peak differences, strong regional correlation and hardware resource limitations of the distributed server of tender application services in different industry categories. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 A schematic diagram of the device structure of the hardware operating environment involved in the embodiment of the present invention;
[0047] Figure 2 This is a flow chart of an embodiment of a method for controlling access to server data according to the present invention;
[0048] Figure 3 This is a structural block diagram of a server data access control device in an embodiment of the present invention. DETAILED DESCRIPTION
[0049] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0050] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0051] like Figure 1 As shown, Figure 1 It is a schematic diagram of the device structure of the hardware operating environment involved in the embodiment of the present invention.
[0052] like Figure 1As shown, the device may include: a processor 1001, such as a CPU, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory or a stable memory (non-volatile memory), such as a disk memory. The memory 1005 may optionally be a storage device independent of the aforementioned processor 1001.
[0053] Those skilled in the art will understand that Figure 1 The structure of the device shown in the figure does not constitute a limitation of the device, and the device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0054] like Figure 1 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a server data access control program.
[0055] exist Figure 1 In the terminal shown, the network interface 1004 is mainly used to connect to the backend server and communicate data with the backend server; the user interface 1003 is mainly used to connect to the client (user end) and communicate data with the client; and the processor 1001 can be used to call the server data access control program stored in the memory 1005 and perform the following operations:
[0056] Obtaining user attribute information of several sub-service areas within the target service range; wherein the user attribute information includes user industry categories and the number of service users in each user industry category;
[0057] Based on the user attribute information of each sub-service area and the bidding project forecast information of the target service scope during the target server access control period, the bidding project service demand of each sub-service area during each access control cycle during the target server access control period is estimated;
[0058] Query the distributed server deployment information within the target service range, consider the tender project service requirements of each sub-service area in each access control period, use the overall processing delay of the server executing the corresponding service user tender project, server hardware load and server resource scheduling restrictions as the constraint condition set, and take the service user's server access experience during the target server access control period as the optimization goal, and optimize and solve the server data access control policy of the distributed server;
[0059] Extracting the resource scheduling sub-strategy and service user matching sub-strategy of the server data access control policy, and executing resource scheduling and service user matching of the distributed server in each access control cycle of the target server access control period;
[0060] According to the resource scheduling of the distributed server and the result of matching the service users, each service user is controlled to restrict data access of the service user when the distributed server executes the bidding project service.
[0061] The specific embodiments of the present invention applied to the device are basically the same as the embodiments of the application server data access control method described below, and are not described in detail here.
[0062] The embodiment of the present invention provides a server data access control method, referring to Figure 2 , Figure 2 This is a flow chart of an embodiment of a method for controlling access to server data according to the present invention.
[0063] In this embodiment, a server data access control method includes the following steps:
[0064] S100: Acquire user attribute information of several sub-service areas within the target service range; wherein the user attribute information includes user industry categories and the number of service users of each user industry category;
[0065] S200: estimating the tender project service demand of each sub-service area in each access control cycle within the target server access control period based on user attribute information of each sub-service area and tender project prediction information of the target service scope within the target server access control period;
[0066] S300: Querying the distributed server deployment information within the target service range, considering the tender project service requirements of each sub-service area in each access control period, using the overall processing delay of the server executing the corresponding service user's tender project, server hardware load, and server resource scheduling restrictions as the constraint condition set, and taking the service user's server access experience during the target server access control period as the optimization goal, to optimize and solve the server data access control policy of the distributed server;
[0067] S400: extracting the resource scheduling sub-strategy and service user matching sub-strategy of the server data access control policy, and executing distributed server resource scheduling and service user matching in each access control cycle of the target server access control period;
[0068] S500: According to the resource scheduling of the distributed server and the result of matching the service users, control each service user to restrict data access when the distributed server executes the tender project service.
[0069] It should be noted that server data access control in some scenarios needs to consider the influence of multiple factors, which leads to some limitations in server data access control: the startup and execution of tender application services have regional differences and time peak differences in industry categories, that is, different types of industry categories usually have different server access peaks, and different types of industry categories have regional differences, resulting in servers storing different tender project processing support data having different access peaks. The bidding content of some special industry categories may also have strong regional correlations. At the same time, distributed servers deployed in different regions are also affected by data storage capabilities and network communication capabilities. These factors limit the allocation of service users of distributed servers to each sub-service area and the flexibility of tender project processing support data scheduling, which increases the difficulty of distributed server data access control.
[0070] To solve the above problems, this embodiment estimates the tender project service demand in each sub-service area, queries the distributed server deployment information, takes the overall processing delay of the server executing the corresponding service user tender project, the server hardware load and the server resource scheduling limit as the constraint condition set, takes the service user's server access experience during the target server access control period as the optimization goal, solves the server data access control policy, and uses the control policy to achieve distributed server resource scheduling and service user matching in each access control cycle, thereby executing the tender project service. The present invention improves the rationality of server data access control planning by considering the regional differences, time peak differences, strong regional correlation and hardware resource limitations of tender application services in different industry categories.
[0071] In a preferred embodiment, the step of obtaining user attribute information of several sub-service areas within the target service range specifically includes:
[0072] S110: Collecting user information entered by service users in each sub-service area when they register or use the platform for the first time, and extracting first user industry category information from the user information;
[0073] S120: Querying historical service information of a number of tender project services performed by service users in each sub-service area during a target historical period, extracting tender project service industry categories and the number of services for each tender project service industry category from the historical service information, and generating second user industry category information;
[0074] S130: Summarize the user industry category information, count the user industry categories of each sub-service area and the service users involved in each user industry category, calculate the number of service users corresponding to each user industry category, and generate user attribute information of several sub-service areas within the target service range.
[0075] In this embodiment, the first user industry category information is determined by collecting the user information entered by each service user during user registration or first use of the platform. The second user industry category information is then determined by considering the historical service information of the bidding project services executed in the historical period. The information of both is summarized and supplemented to obtain the user industry categories of several sub-service areas within the target service scope and the number of service users of each user industry category.
[0076] In a preferred embodiment, based on the user attribute information of each sub-service area and the bidding project prediction information of the target service scope during the target server access control period, the step of estimating the bidding project service demand of each sub-service area during each access control cycle during the target server access control period specifically includes:
[0077] S210: Obtaining tender project forecast information for the target service scope during the target server access control period; wherein the tender project forecast information includes the forecast number of tender projects for each project industry category within the target server access control period and the tender project associated time period;
[0078] S220: extracting the user industry category and the number of service users of each user industry category from the user attribute information of each sub-service area, and generating a quantitative value of the service demand of the bidding project of each user industry category;
[0079] S230: Estimate the tender project service demand of each sub-service area in each access control cycle within the target server access control period based on the quantified value of the tender project service demand of each user industry category and the tender project associated time period of the project industry category corresponding to the user industry category.
[0080] In this embodiment, by considering the user attribute information of each sub-service area and the bidding project prediction information of the target service scope during the target server access control period, the bidding project service demand of each sub-service area in each access control cycle within the target server access control period is estimated, thereby providing data support for user needs for subsequent planning of server data access control strategies.
[0081] Furthermore, the steps of obtaining the bidding project forecast information of the target service scope during the target server access control period specifically include:
[0082] S211: Collect the effective time of each tender document project for each project industry category within the target service scope within several historical server access control periods;
[0083] S212: Counting the number of tender documents published for each project industry category during each historical server access control period and the tender document project associated period to generate a tender document project sample set; wherein the tender document project associated period is configured as a period consisting of the effective time of tender documents for each project industry category covering a number of access control cycles exceeding a preset ratio within the corresponding historical server access control period;
[0084] S213: Using the tender item training samples in the tender item samples to train the pre-built initial convolutional neural network model, to obtain a tender item prediction model that reaches the training number or training convergence;
[0085] S214: Using the tender project prediction samples in the tender project samples and the trained tender project prediction model, predict the predicted number of tender projects and tender project associated time periods for each project industry category within the target service scope within the target server access control period.
[0086] Furthermore, the steps of extracting the user industry category and the number of service users of each user industry category from the user attribute information of each sub-service area and generating the quantitative value of the bidding project service demand of each user industry category include:
[0087] S221: extracting the user industry category and the number of service users of each user industry category from the user attribute information of each sub-service area;
[0088] S222: For user industry categories with strong regional associations, calculate the product of the number of service users of each user industry category in each sub-service area and the predicted number of tender projects of the project industry category corresponding to the user industry category in the same sub-service area, and use the product value as the quantitative value of the tender project service demand of the user industry category in each sub-service area;
[0089] S223: For user industry categories that do not have a strong geographical association, calculate the product of the number of service users of each user industry category in each sub-service area and the predicted number of tender items of the project industry category corresponding to the user industry category, and use the product value as the quantitative value of the tender item service demand of the user industry category in each sub-service area;
[0090] S224: Generate a quantitative value of the tender document project service demand for each user industry category based on the quantitative value of the tender document project service demand for the user industry category with strong regional association and the quantitative value of the tender document project service demand for the user industry category with non-strong regional association.
[0091] In this embodiment, a pre-built initial convolutional neural network model is used for training to generate a tender project prediction model, which is used to predict the predicted number of tender projects and the tender project associated time period for each project industry category within the target service scope within the target server access control period; thereafter, by considering the strong regional association and non-strong regional association of the user industry category, the quantitative value of the tender project service demand of the user industry category in each sub-service area is calculated respectively, so as to provide data support for the subsequent allocation of distributed servers to each sub-service area and the distributed server resource scheduling.
[0092] In a preferred embodiment, the distributed server deployment information within the target service range is queried, the tender project service requirements of each sub-service area in each access control period are considered, the overall processing delay of the server executing the corresponding service user tender project, the server hardware load, and the server resource scheduling restrictions are used as the constraint condition set, and the server access experience of the service user during the target server access control period is used as the optimization goal. The steps of optimizing and solving the server data access control policy of the distributed server specifically include:
[0093] S310: Querying the distributed server deployment information within the target service range, and extracting the server deployment location and server hardware deployment resources from the distributed server deployment information;
[0094] S320: After each distributed server is allocated a tender project processing support dataset of a user industry category in each access control period, the server demand quantity determined according to the preset conversion rule for the quantified value of the tender project service demand of each user industry category in each sub-service area in each access control period is less than the number of servers deployed within the standard delay communication range that store the tender project processing support dataset of the corresponding user industry category, which is a first constraint condition; the storage space of the tender project processing support dataset occupied by each distributed server in each access control period is less than the hardware storage load upper limit of the distributed server, which is a second constraint condition; the amount of tender project processing support dataset newly added by the distributed server in each sub-service area in each access control period compared with the previous access control period is less than the upper limit of the data transmission volume between the distributed server and the cloud server during the idle period of each access control period, which is a third constraint condition; the sum of the number of server allocation switching times between all two adjacent access control periods in each sub-service area within the entire target server access control period is minimized as the optimization objective, and the resource scheduling sub-strategy and service user matching sub-strategy of the distributed server are optimized and solved;
[0095] S330: Generate a server data access control policy of the distributed server according to the resource scheduling sub-policy of the distributed server and the service user matching sub-policy.
[0096] In a preferred embodiment, the steps of controlling each service user to restrict data access when executing a tender project service on the distributed server based on the resource scheduling of the distributed server and the service user matching result specifically include:
[0097] S510: Based on the resource scheduling of the distributed servers and the matching results of the service users, control each distributed server to execute resource scheduling of the bid project processing support data set corresponding to the user industry category in each access control period, and generate a service user access list for each access control period;
[0098] S520: Control the service users in each sub-service area to access the corresponding distributed server in each access control period according to the service user access list, and execute the bidding project processing of the service user.
[0099] In this embodiment, by obtaining user attribute information of several sub-service areas within the target service scope, using the bid project prediction information of the target server access control period, estimating the bid project service demand of each sub-service area, querying the distributed server deployment information, considering the bid project service demand of each sub-service area in each access control period, taking the overall processing delay of the server executing the corresponding service user bid project, the server hardware load and the server resource scheduling limit as the constraint condition set, taking the service user's server access experience in the target server access control period as the optimization goal, solving the server data access control strategy, and using the resource scheduling sub-strategy and the service user matching sub-strategy to achieve distributed server resource scheduling and service user matching in each access control period, thereby executing the bid project service. By considering the regional differences, time peak differences, strong regional correlation and hardware resource limitations of bid application services in different industry categories, the present invention realizes the intelligent allocation of service users from distributed servers to each sub-service area and the flexible scheduling of bid project processing support data, thereby improving the rationality of server data access control planning.
[0100] Reference Figure 3 , Figure 3 This is a structural block diagram of an embodiment of a server data access control device of the present invention.
[0101] like Figure 3 As shown, the server data access control device proposed in the embodiment of the present invention includes:
[0102] An acquisition module 10 is configured to acquire user attribute information of a plurality of sub-service areas within a target service range; wherein the user attribute information includes user industry categories and the number of service users of each user industry category;
[0103] An estimation module 20 is configured to estimate the tender project service demand of each sub-service area in each access control cycle within the target server access control period based on the user attribute information of each sub-service area and the tender project prediction information of the target service scope within the target server access control period;
[0104] Query module 30 is used to query the distributed server deployment information within the target service range, consider the tender project service requirements of each sub-service area in each access control period, use the overall processing delay of the server executing the corresponding service user tender project, server hardware load and server resource scheduling restrictions as the constraint condition set, and use the service user's server access experience during the target server access control period as the optimization goal to optimize and solve the server data access control policy of the distributed server;
[0105] An extraction module 40 is configured to extract the resource scheduling sub-strategy and the service user matching sub-strategy of the server data access control policy, and perform resource scheduling and service user matching of the distributed server in each access control cycle of the target server access control period;
[0106] The access module 50 is used to control each service user to restrict data access when executing the tender project service on the distributed server according to the resource scheduling of the distributed server and the result of matching the service users.
[0107] Other embodiments or specific implementations of the server data access control device of the present invention can refer to the above-mentioned method embodiments and will not be described in detail here.
[0108] In addition, the present invention also proposes a server data access control device, which includes: a memory, a processor, and a server data access control program stored in the memory and executable on the processor. When the server data access control program is executed by the processor, the steps of the server data access control method described above are implemented.
[0109] The specific implementation of the server data access control device of the present application is basically the same as the various embodiments of the above-mentioned server data access control method, and will not be repeated here.
[0110] In addition, the present invention also proposes a readable storage medium, which includes a computer readable storage medium on which a server data access control program is stored. The readable storage medium may be Figure 1 The memory 1005 in the terminal may also be at least one of a ROM (Read-Only Memory) / RAM (Random Access Memory), a magnetic disk, and an optical disk. The readable storage medium includes a number of instructions for enabling a server data access control device having a processor to execute the server data access control method described in various embodiments of the present invention.
[0111] The specific implementation of the readable storage medium of the present application is basically the same as the various embodiments of the above-mentioned server data access control method, and will not be repeated here.
[0112] It should be understood that, in the description of this specification, reference to terms such as "one embodiment," "another embodiment," "other embodiments," or "first to Nth embodiments" means that the specific features, structures, materials, or characteristics described in conjunction with that embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any appropriate manner in any one or more embodiments or examples.
[0113] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.
[0114] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0115] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0116] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A server data access control method, characterized in that: The following steps are involved: Obtaining user attribute information of several sub-service areas within the target service range; wherein the user attribute information includes user industry categories and the number of service users in each user industry category; Based on the user attribute information of each sub-service area and the bidding project forecast information of the target service scope during the target server access control period, the bidding project service demand of each sub-service area during each access control cycle during the target server access control period is estimated; specifically, the following is included: Obtaining forecast information of tender items within the target service scope during the target server access control period; wherein the forecast information includes the forecast number of tender items for each project industry category within the target server access control period and the associated time period of the tender items; Extracting the user industry category and the number of service users of each user industry category from the user attribute information of each sub-service area, and generating a quantitative value of the service demand of the bidding project for each user industry category; Based on the quantitative value of the tender project service demand of each user industry category and the tender project associated time period of the project industry category corresponding to the user industry category, estimate the tender project service demand of each sub-service area in each access control cycle within the target server access control period; The acquisition of the bidding project forecast information for the target service scope during the target server access control period specifically includes: Collect the effective time of each tender document project for each project industry category within the target service scope within several historical server access control periods; Counting the number of tender documents published for each project industry category during each historical server access control period and the tender document project associated period to generate a tender document project sample set; wherein the tender document project associated period is configured as a period consisting of the effective time of tender documents for each project industry category covering a number of access control cycles exceeding a preset ratio within the corresponding historical server access control period; Using the tender item training samples in the tender item samples to train the pre-built initial convolutional neural network model, to obtain a tender item prediction model that reaches the training number or training convergence; Using the tender project prediction samples in the tender project samples and the trained tender project prediction model, predict the predicted number of tender projects and the tender project associated time periods for each project industry category within the target service scope within the target server access control period; The user industry category and the number of service users of each user industry category in the user attribute information of each sub-service area are extracted to generate the quantitative value of the bidding project service demand of each user industry category, specifically including: Extracting the user industry category and the number of service users of each user industry category from the user attribute information of each sub-service area; For user industry categories with strong regional associations, calculate the product of the number of service users of each user industry category in each sub-service area and the predicted number of tender projects of the project industry category corresponding to the user industry category in the same sub-service area, and use the product value as the quantitative value of the tender project service demand of the user industry category in each sub-service area; For user industry categories that do not have strong geographical associations, calculate the product of the number of service users of each user industry category in each sub-service area and the predicted number of tender projects of the project industry category corresponding to the user industry category, and use the product value as the quantitative value of the tender project service demand of the user industry category in each sub-service area; Generate a quantitative value of tender document project service demand for each user industry category based on the quantitative value of tender document project service demand for user industry categories with strong regional association and the quantitative value of tender document project service demand for user industry categories with non-strong regional association; Query the distributed server deployment information within the target service range, consider the tender project service requirements of each sub-service area in each access control period, use the overall processing delay of the server executing the corresponding service user tender project, server hardware load and server resource scheduling restrictions as the constraint condition set, and take the service user's server access experience during the target server access control period as the optimization goal, and optimize and solve the server data access control policy of the distributed server; Extracting the resource scheduling sub-strategy and service user matching sub-strategy of the server data access control policy, and executing resource scheduling and service user matching of the distributed server in each access control cycle of the target server access control period; According to the resource scheduling of the distributed server and the result of matching the service users, each service user is controlled to restrict data access of the service user when the distributed server executes the bidding project service.
2. The server data access control method according to claim 1, wherein: The steps for obtaining user attribute information of several sub-service areas within the target service range include: Collect user information entered by service users in each sub-service area when they register or use the platform for the first time, and extract the first user industry category information from the user information; Querying historical service information of a number of tender project services performed by service users in each sub-service area during a target historical period, extracting tender project service industry categories and the number of services for each tender project service industry category from the historical service information, and generating second user industry category information; Summarize the user industry category information, count the user industry categories of each sub-service area and the service users involved in each user industry category, calculate the number of service users corresponding to each user industry category, and generate user attribute information of several sub-service areas within the target service range.
3. The server data access control method according to claim 1, wherein: Query the distributed server deployment information within the target service range, consider the tender project service requirements of each sub-service area in each access control cycle, use the overall processing delay of the server executing the corresponding service user tender project, server hardware load and server resource scheduling restrictions as the constraint condition set, and take the service user's server access experience during the target server access control period as the optimization goal. Optimize the steps to solve the server data access control policy of the distributed server, including: Querying the distributed server deployment information within the target service range, and extracting the server deployment location and server hardware deployment resources from the distributed server deployment information; After each distributed server is allocated a tender project processing support dataset of a user industry category in each access control cycle, the server demand quantity determined according to the preset conversion rule for the quantitative value of the tender project service demand of each user industry category in each sub-service area in each access control cycle is less than the number of servers deployed within the standard delay communication range that store the tender project processing support dataset of the corresponding user industry category. This is the first constraint condition. The storage space of the tender project processing support dataset occupied by each distributed server in each access control cycle is less than the hardware storage load upper limit of the distributed server. This is the third constraint condition. The amount of tender project processing support dataset newly added by the distributed server in each sub-service area in each access control cycle compared with the previous access control cycle is less than the upper limit of the data transmission volume between the distributed server and the cloud server during the idle period of each access control cycle. The optimization goal is to minimize the sum of the server allocation switching times between all two adjacent access control cycles in each sub-service area during the entire target server access control period. The resource scheduling sub-strategy and service user matching sub-strategy of the distributed server are optimized and solved. According to the resource scheduling sub-strategy of the distributed server and the service user matching sub-strategy, a server data access control policy of the distributed server is generated.
4. The server data access control method according to claim 1, wherein: According to the resource scheduling of the distributed server and the matching result of the service user, the steps of controlling each service user to restrict data access when the service user executes the bidding project service on the distributed server specifically include: According to the resource scheduling of the distributed servers and the matching results of the service users, control each distributed server to execute the resource scheduling of the bid project processing support data set corresponding to the user industry category in each access control cycle, and generate a service user access list for each access control cycle; Control the service users of each sub-service area to access the corresponding distributed server in each access control cycle according to the service user access list, and execute the bidding project processing of the service user.
5. A server data access control device, characterized in that: The server data access control method according to any one of claims 1 to 4, comprising: An acquisition module is used to acquire user attribute information of several sub-service areas within the target service range; wherein the user attribute information includes user industry categories and the number of service users of each user industry category; An estimation module, configured to estimate the tender project service demand of each sub-service area in each access control period of the target server based on user attribute information of each sub-service area and tender project prediction information of the target service scope in the access control period of the target server; The query module is used to query the distributed server deployment information within the target service range. It considers the tender project service requirements of each sub-service area in each access control period, uses the overall processing delay of the server executing the corresponding service user tender project, server hardware load, and server resource scheduling restrictions as the constraint condition set, and takes the service user's server access experience during the target server access control period as the optimization goal, and optimizes the server data access control policy of the distributed server. An extraction module is used to extract the resource scheduling sub-strategy and service user matching sub-strategy of the server data access control policy, and perform resource scheduling and service user matching of the distributed server in each access control cycle of the target server access control period; The access module is used to control each service user to restrict data access when the distributed server performs the bidding project service according to the resource scheduling of the distributed server and the result of matching the service users.
6. A server data access control device, characterized in that: The server data access control device includes: a memory, a processor, and a server data access control program stored in the memory and executable on the processor. When the server data access control program is executed by the processor, the steps of the server data access control method according to any one of claims 1 to 4 are implemented.
7. A storage medium, characterized in that: The storage medium stores a server data access control program, which implements the steps of the server data access control method according to any one of claims 1 to 4 when executed by a processor.
Citation Information
Patent Citations
Access control strategy construction method and device, electronic equipment and storage medium
CN119520147A