Capacity expansion method, device and equipment of data security transmission server, medium and product

By installing a data sharing system and protocol in the data security transmission server, mounting a shared disk and generating a virtual access address, the problem of insufficient scalability and flexibility of the SFTP server is solved, and efficient storage resource management and dynamic expansion are achieved.

CN120705125APending Publication Date: 2025-09-26INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510802368.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Existing SFTP servers have deficiencies in scalability and flexibility, especially in the limited vertical expansion of a single node and the high management complexity in multi-node distributed deployment, resulting in reduced disk utilization of the storage system.

Method used

By installing the data sharing system and protocol in the data security transmission server, mounting the data sharing disk, generating a virtual access address, and creating an address root directory to achieve capacity expansion.

Benefits of technology

It improves the scalability and flexibility of servers, increases the disk utilization of storage systems, achieves data synchronization and consistency in multi-server deployments, and supports dynamic expansion and large-scale data growth.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705125A_ABST
    Figure CN120705125A_ABST
Patent Text Reader

Abstract

The invention discloses a capacity expansion method, device and equipment of a data security transmission server, a medium and a product, which are applied to the field of financial science and technology. Respectively installing and configuring a data sharing system and a data sharing protocol in each data security transmission server according to the obtained identification information of the data security transmission server; based on a data sharing system, mounting each data sharing disk to each data security transmission server; generating a first virtual access address for performing data access on each data sharing disk according to a data sharing protocol, the identification information of each data security transmission server and the identification information of each data sharing disk; and according to the first virtual access address, an address root directory of the first virtual access address is created in each data security transmission server, so that a client corresponding to the data security transmission server can perform data access on each data sharing disk through the address root directory, and the capacity expansion of the data security transmission server is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of financial technology, and in particular to a capacity expansion method, device, equipment, medium and product for a data security transmission server. Background Art

[0002] SFTP (Secure File Transfer Protocol) is a commonly used protocol for secure file transfer. Based on the SSH (Secure Shell) protocol, it features encrypted transmission and data integrity verification. SFTP servers are widely used within enterprises for data transfer, file sharing, and data exchange. With the growth of enterprise data volumes and the expansion of business needs, effectively scaling and managing SFTP servers has become a technical challenge.

[0003] In traditional SFTP server deployments, a single server node typically handles all file transfer requests. To cope with increasing data volumes, methods typically employed include vertical scaling of a single node, multi-node distributed deployment, or unified management based on a distributed file system. However, in single-node vertical scaling, storage capacity expansion is limited by the physical limitations of a single node, making it unable to cope with growing business demands. Multi-node distributed deployments, while improving overall performance, present high management complexity because each node may have an independent directory structure and storage path, making it difficult to achieve efficient use and flexible scheduling of shared storage resources across multiple nodes. Mounting storage resources through a distributed file system can easily lead to configuration inconsistencies and complex access paths, resulting in reduced disk utilization across the entire storage system and significantly impacting the server's scalability and flexibility.

[0004] Therefore, how to improve the scalability and flexibility of the server and increase the disk utilization of the storage system has become a technical problem that those skilled in the art urgently need to solve. Summary of the Invention

[0005] The present invention provides a method, device, equipment, medium and product for expanding a data security transmission server, so as to enhance the expandability and flexibility of the server and improve the disk utilization of the storage system.

[0006] According to one aspect of the present invention, a method for expanding the capacity of a data security transmission server is provided, comprising:

[0007] Obtaining identification information of at least one data security transmission server, and installing and configuring a data sharing system and a data sharing protocol in each of the data security transmission servers according to the identification information;

[0008] Obtain identification information of at least one data sharing disk, and based on the data sharing system, mount each of the data sharing disks to each of the data security transmission servers;

[0009] generating a first virtual access address for accessing data on each of the data sharing disks according to the data sharing protocol, the identification information of each of the data security transmission servers, and the identification information of each of the data sharing disks;

[0010] According to the first virtual access address, an address root directory is created in each of the data security transmission servers, so that the client of the data security transmission server can access data on each of the data shared disks through the address root directory, thereby expanding the capacity of the data security transmission server.

[0011] According to another aspect of the present invention, there is provided a capacity expansion device for a data security transmission server, comprising:

[0012] A server configuration module, configured to obtain identification information of at least one data security transmission server, and install and configure a data sharing system and a data sharing protocol in each of the data security transmission servers according to the identification information;

[0013] A disk mounting module, configured to obtain identification information of at least one data sharing disk and mount each of the data sharing disks to each of the data security transmission servers based on the data sharing system;

[0014] a virtual access address generating module, configured to generate a first virtual access address for accessing data to each of the data sharing disks according to the data sharing protocol, the identification information of each of the data security transmission servers, and the identification information of each of the data sharing disks;

[0015] A root directory creation module is used to create an address root directory of the first virtual access address in each of the data security transmission servers based on the first virtual access address, so that the client corresponding to the data security transmission server can access data on each of the data shared disks through the address root directory, so as to achieve capacity expansion of the data security transmission server.

[0016] According to another aspect of the present invention, an electronic device is provided, comprising:

[0017] at least one processor; and

[0018] a memory communicatively connected to the at least one processor; wherein,

[0019] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the capacity expansion method of the data security transmission server described in any embodiment of the present invention.

[0020] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the method for expanding the data security transmission server described in any embodiment of the present invention when executed.

[0021] According to another aspect of the present invention, a computer program product is provided. The computer program product includes a computer program. When the computer program is executed by a processor, the computer program implements the method for expanding the data security transmission server according to any embodiment of the present invention.

[0022] The technical solution of an embodiment of the present invention obtains identification information of at least one data security transmission server, and installs and configures a data sharing system and a data sharing protocol in each data security transmission server according to each identification information; obtains identification information of at least one data sharing disk, and mounts each data sharing disk to each data security transmission server based on the data sharing system; generates a first virtual access address for data access to each data sharing disk according to the data sharing protocol, the identification information of each data security transmission server and the identification information of each data sharing disk; creates an address root directory of the first virtual access address in each data security transmission server according to the first virtual access address, so that the client of the data security transmission server can access data to each data sharing disk through the address root directory, so as to achieve capacity expansion of the data security transmission server. This technical solution obtains the identification information of each data security transmission server and each data sharing disk, and generates a first virtual access address for accessing data on each data sharing disk based on the obtained identification information of each data security transmission server and each data sharing disk. This solves the problems of data synchronization and consistency among servers in a multi-server deployment, the inability to dynamically expand servers, and the low disk utilization of the storage system, thereby improving the scalability and flexibility of the server. Furthermore, each data sharing disk can be mounted to each data security transmission server according to the data sharing system, thereby improving the utilization rate of the data sharing disk.

[0023] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0025] Figure 1 This is a flow chart of a method for expanding the capacity of a data security transmission server provided according to the first embodiment of the present invention;

[0026] Figure 2 This is a flow chart of a method for expanding the capacity of a data security transmission server provided according to the second embodiment of the present invention;

[0027] Figure 3 This is a structural diagram of a capacity expansion device for a data security transmission server provided in accordance with a third embodiment of the present invention;

[0028] Figure 4 It is a structural diagram of an electronic device for implementing the capacity expansion method of a data security transmission server according to an embodiment of the present invention. DETAILED DESCRIPTION

[0029] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0030] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0031] Example 1

[0032] Figure 1A flowchart of a method for expanding the capacity of a data security transmission server is provided for the first embodiment of the present invention. This embodiment is applicable to the case where data is accessed simultaneously to each data sharing disk deployed in the system through at least one data security transmission server. The method can be executed by an expansion device of the data security transmission server. The expansion device of the data security transmission server can be implemented in the form of hardware and / or software, and the expansion device of the data security transmission server can be configured in an electronic device. Figure 1 As shown, the method includes:

[0033] S110: Obtain identification information of at least one data security transmission server, and install and configure a data sharing system and a data sharing protocol in each data security transmission server according to each identification information.

[0034] The identification information may be an identifier used to identify and distinguish system devices. Specifically, the identification information of a secure data transmission server may include a host name, IP address, operating system, and server serial number. For example, the method for expanding the capacity of secure data transmission servers described in this solution may be targeted at a scenario where there are three secure data transmission servers. Specifically, the IP addresses of the secure data transmission servers may be determined and used to distinguish the three secure data transmission servers, such as Server 1, Server 2, and Server 3. This embodiment does not impose any specific limitations on this.

[0035] Specifically, upon obtaining the identifiers of each secure data transmission server, a data sharing system can be installed and a data sharing protocol configured on each secure data transmission server based on the identifiers of the secure data transmission. This ensures that each secure data transmission server can provide the same data service capabilities through the data sharing system and data sharing protocol. Furthermore, each secure data transmission server can be configured to enable a custom file system and assign access rights to the server.

[0036] It should be noted that, in this embodiment, the number of data security transmission servers can be one or more.

[0037] S120: Obtain identification information of at least one data sharing disk, and mount each data sharing disk to each data security transmission server based on the data sharing system.

[0038] The identification information of the data sharing disk may include the disk model, disk type, and disk serial number. For example, the method for expanding the capacity of a data security transmission server described in this solution may be targeted at a situation where there are three data sharing disks. Specifically, the disk serial numbers of the data sharing disks may be determined and used to distinguish the three data sharing disks, such as data sharing disk A, data sharing disk B, and data sharing disk C. This embodiment does not impose any specific restrictions on this.

[0039] Specifically, each shared data disk can be mounted to each secure data transmission server through a data sharing system, where the data sharing system can be a network file system or a distributed file system. A specific mounting scheme can be to sequentially mount each shared data disk to each secure data transmission server. For example, shared data disks A, B, and C can be mounted to server 1, shared data disks A, B, and C can be mounted to server 2, and shared data disks A, B, and C can be mounted to server 3.

[0040] S130 : Generate a first virtual access address for accessing data on each data sharing disk according to the data sharing protocol, identification information of each data security transmission server, and identification information of each data sharing disk.

[0041] Among them, the data sharing agreement can be an execution specification used to ensure the flow and exchange of data between different system devices. Specifically, it may include data access rights and restrictions, the purpose and scope of data sharing, and the format and standards of data.

[0042] Specifically, according to a pre-configured data sharing protocol, the identification information of each data security transmission server and the identification information of each data sharing disk are linked, each data sharing disk is mapped to each data security transmission server, and a virtual address for accessing data to each data sharing disk is generated in each data security transmission server. For example, data sharing disks A, B, and C are all mounted on server 1. Then, a virtual address a for accessing data to data sharing disk A, a virtual address b for accessing data to data sharing disk B, and a virtual address c for accessing data to data sharing disk C can be generated in server 1. This embodiment does not impose any specific restrictions on this.

[0043] Optionally, based on the data sharing protocol, the identification information of each data security transmission server and the identification information of each data sharing disk, a first virtual access address for data access to each data sharing disk is generated, including: according to the data sharing protocol, associating the identification information of any data security transmission server and the identification information of any data sharing disk, and respectively obtaining the association relationship between each data sharing disk and the identification information of each data security transmission server; for the association relationship between any server and any disk, mapping the physical address of the disk to the server, respectively, to obtain the first virtual address for data access to the data sharing disk.

[0044] The physical address may be the location in the data sharing disk that is actually used to store data. Specifically, according to a pre-configured data sharing protocol, the identifier of any data security transmission server can be associated with the identifier information of any data sharing disk, thereby obtaining an association relationship between each data sharing disk and the identifier information of each data security transmission server. Based on this association relationship, the physical address of the data sharing disk can be mapped to the server, and the first virtual address for accessing data on the data sharing disk can be obtained in the data security transmission server. For example, continuing with the above example, if an association relationship can be established between data sharing disk A and servers 1, 2, and 3 through a data sharing protocol, the first virtual address for accessing data on shared disk A can be generated in servers 1, 2, and 3 based on this association relationship. For example, the first virtual address for accessing data on data sharing disk A generated in server 1 can be a1, the first virtual address for accessing data on data sharing disk A generated in server 2 can be a2, and the first virtual address for accessing data on data sharing disk A generated in server 3 can be a3. This embodiment does not impose specific restrictions on this.

[0045] This technical solution can establish an association between the identification information of each data security transmission server and the identification information of each data sharing disk, and generate a virtual address for data access to each data sharing disk in each data security transmission server based on the association, thereby realizing unified management of multiple data sharing disks without the need for complex configuration synchronization and file system adjustments, thereby improving the scalability and flexibility of the data security transmission service.

[0046] S140. Based on the first virtual access address, an address root directory of the first virtual access address is created in each data security transmission server, so that the client corresponding to the data security transmission server can access data on each data shared disk through the address root directory, thereby expanding the capacity of the data security transmission server.

[0047] The address root directory may refer to a primary directory within each data security transmission server that stores virtual addresses for accessing data on each shared data disk. Specifically, the address root directory may be pre-set by a technician based on experience, or may be automatically generated by the system based on pre-set directory generation logic.

[0048] Specifically, while obtaining the first virtual address for accessing data on each shared data disk, each secure data transmission server can set up a storage directory for storing the virtual address for accessing data on each shared data disk. The obtained virtual address for accessing data on each shared data disk is stored therein. Clients corresponding to each secure data transmission server can access data on each shared data disk through this directory, thereby achieving capacity expansion of the secure data transmission server.

[0049] Optionally, after creating the address root directory of the first virtual access address in each data security transmission server according to the first virtual access address, it also includes: extracting the directory identifier of at least one subdirectory contained in the address root directory to obtain the directory identifier of at least one subdirectory; determining at least one target client corresponding to the subdirectory according to the directory identifier, and establishing a mapping relationship between the directory identifier and at least one client; sending the virtual access address of the subdirectory to at least one target client according to the mapping relationship to generate a virtual address directory for data access to the data shared disk.

[0050] The subdirectory may be a secondary directory under the address root directory for storing data recorded in each data sharing disk. The directory identifier of the subdirectory may be a path for identifying a directory in the file system.

[0051] Specifically, the directory identifier of at least one subdirectory contained in the address root directory can be extracted to obtain the directory identifier of at least one subdirectory. Furthermore, based on the obtained directory identifier, at least one target client corresponding to the subdirectory can be determined, and a mapping relationship between the directory identifier and the at least one client can be established. Specifically, the mapping relationship between the directory identifier and the at least one client can be obtained by allocating the access rights to each subdirectory contained in the root directory to each corresponding client according to the role classification of the client or the data classification in the data security transmission server through a pre-set custom network interface. Furthermore, based on the mapping relationship, the virtual address for data access to the subdirectory can be sent to at least one target client, and the virtual address directory for the target client to access data on the data shared disk can be obtained.

[0052] This technical solution establishes a mapping relationship between subdirectories within the address root directory and at least one target client, generating the virtual address directory used by the client to access data on each shared disk. This enables permission management based on user roles and business logic, flexibly controlling access rights to directories and files for different users, and improving server security and management flexibility.

[0053] An optional solution of this embodiment can be combined with one or more solutions of this embodiment. Optionally, when a disk addition request for a data sharing disk is detected, based on the data sharing system, a new data sharing disk is determined, and the new data sharing disk is mounted to each server; the disk identification information of the new data sharing disk is obtained, and the obtained identification information is associated and stored with the identification information of each data security transmission server to obtain a second virtual access address for data access to the new shared disk; based on the second virtual access address, the address directory in each data security transmission server is updated so that the client can access data to the new data sharing disk through the updated address directory.

[0054] The disk addition request may be an operation request for adding a new data sharing disk to an existing data sharing disk, or an operation request for replacing a faulty data sharing disk with a new shared disk when an existing shared disk fails.

[0055] Specifically, when a request to add a new disk is detected, the data sharing system can identify the newly added data sharing disk, obtain the disk identification information of the newly added data sharing disk, and associate the obtained identification information with the identification information of each data security transmission server to obtain a virtual access address for accessing data on the newly added shared disk. For example, if the newly added data sharing disk can be determined to be data sharing disk D based on the obtained disk identification information of the newly added data sharing disk, then the virtual address d for accessing data on data sharing disk D can be obtained on servers 1, 2, and 3. This embodiment does not impose any specific restrictions on this.

[0056] Furthermore, based on the virtual address of the newly added data shared disk, the address directory of the virtual address for data access to each data shared disk stored in each data server is updated, so that the client can access data to the newly added data shared disk through the updated address directory. For example, if the disk addition request is an operation request to add a new data shared disk to an existing data shared disk, the virtual address for data access to the newly added data shared disk can be directly added to the address directory for the client to access data to the newly added shared disk; if the disk addition request is to replace the problem data shared disk with a new shared disk, the virtual access address for accessing the problem shared disk in the address directory can be directly replaced with the virtual address for data access to the newly added data shared disk, and the physical address of the newly added data shared disk can be mounted on each data security transmission server respectively.

[0057] This technical solution can obtain the disk identification of the newly added shared disk based on the request for the newly added data shared disk, and associate the disk identification information of the newly added shared disk with the identification information of each data security transmission server for storage, obtain the virtual access address for data access to the newly added shared disk, and update the address directory in each data security transmission server, so that the client can access data on the newly added data shared disk, and can easily add or remove data shared disks in the data security transmission server. It can support large-scale data growth and dynamic adjustment of storage resources, improve the scalability and flexibility of the server, and improve the utilization rate of data shared disks.

[0058] The technical solution of an embodiment of the present invention obtains identification information of at least one data security transmission server, and installs and configures a data sharing system and a data sharing protocol in each data security transmission server according to each identification information; obtains identification information of at least one data sharing disk, and mounts each data sharing disk to each data security transmission server based on the data sharing system; generates a first virtual access address for data access to each data sharing disk according to the data sharing protocol, the identification information of each data security transmission server and the identification information of each data sharing disk; creates an address root directory of the first virtual access address in each data security transmission server according to the first virtual access address, so that the client of the data security transmission server can access data to each data sharing disk through the address root directory, so as to achieve capacity expansion of the data security transmission server. This technical solution obtains the identification information of each data security transmission server and each data sharing disk, and generates a first virtual access address for accessing data on each data sharing disk based on the obtained identification information of each data security transmission server and each data sharing disk. This solves the problems of data synchronization and consistency among servers in a multi-server deployment, the inability to dynamically expand servers, and the low disk utilization of the storage system, thereby improving the scalability and flexibility of the server. Furthermore, each data sharing disk can be mounted to each data security transmission server according to the data sharing system, thereby improving the utilization rate of the data sharing disk.

[0059] Example 2

[0060] Figure 2 This is a flow chart of a method for expanding the capacity of a data security transmission server provided in the second embodiment of the present invention. Based on the above embodiments, this embodiment further optimizes the method for expanding the capacity of the data security transmission server.

[0061] Furthermore, after the step of "creating an address root directory of the first virtual access address in each data security transmission server according to the first virtual access address, so that the client corresponding to the data security transmission server can access data on each data shared disk through the address root directory, so as to expand the capacity of the data security transmission server", add the step of "when the client of the data security transmission server initiates a data access request to the server, the data access request is received by a pre-set proxy server, and the client identifier of the client of the data security transmission server is determined according to the data access request; according to the client identifier, the proxy server sends the data access request to the data security transmission server corresponding to the client identifier; the data access request is processed by the data security transmission server, a data access result is generated, and the data access result is fed back to the client of the data security transmission server." to improve the method of generating the user access permission list. Figure 2 As shown, the method includes:

[0062] S210: Obtain identification information of at least one data security transmission server, and install and configure a data sharing system and a data sharing protocol in each data security transmission server according to each identification information.

[0063] S220: Obtain identification information of at least one data sharing disk, and mount each data sharing disk to each data security transmission server based on the data sharing system.

[0064] S230 : Generate a first virtual access address for accessing data on each data sharing disk according to the data sharing protocol, identification information of each data security transmission server, and identification information of each data sharing disk.

[0065] S240. Based on the first virtual access address, an address root directory of the first virtual access address is created in each data security transmission server, so that the client of the data security transmission server can access data on each data shared disk through the address root directory, thereby expanding the capacity of the data security transmission server.

[0066] S250. When the client corresponding to the data security transmission server initiates a data access request to the server, the data access request is received by a pre-set proxy server, and the client identifier of the client corresponding to the data security transmission server is determined according to the data access request.

[0067] The data access request initiated to the server may specifically be a request initiated by the client through a virtual address for accessing data on the data shared disk, which is an access request to data recorded in the data shared disk.

[0068] The proxy server may be a server configured between the data security transmission server and the client, acting as a proxy for the client's access request and returning the response to the access request to the client. Proxy server types may include forward proxy, reverse proxy, and transparent proxy. Specifically, when a client sends a data access request to a shared data disk using a virtual address that can access data on the shared data disk, the reverse proxy server receives the data access request initiated by the client and determines the client identifier of each client based on the received data access request.

[0069] S260: According to the client identifier, the proxy server sends the data access request to the data security transmission server corresponding to the client identifier.

[0070] Specifically, when the reverse proxy server determines the client identifier of each client initiating each data access request, it will send the data access request to the corresponding data security transmission server based on the corresponding relationship between the client identifier of each client and each data security transmission server. For example, if the client identifier information obtained is client M, and it can be determined that the data security transmission server corresponding to client M is server 2, the reverse proxy server can send the data access request initiated by client M to server 2. This embodiment does not impose specific limitations on this.

[0071] Optionally, after the proxy server sends the data access request to the data security transmission server corresponding to the client identifier based on the client identifier, it also includes: detecting the service status of the data security transmission server through the proxy server to obtain the service status value of the data security transmission server; comparing the service status value with a pre-set service status threshold to obtain a service status comparison result of the data security transmission server; forwarding the data access request to other data security transmission servers based on the service status comparison result; the other servers are servers other than the data security transmission server corresponding to the client identifier.

[0072] Specifically, detecting the service status of the secure data transmission server may involve receiving service status data from the secure data transmission server when the proxy server sends a client's data access request to the secure data transmission server. Furthermore, the proxy server may determine the service status value of the secure data transmission server based on the received service status data.

[0073] Specifically, when the proxy server determines the service status value of the data security transmission server based on the service status data fed back by the data security transmission service, it compares the service status value with the pre-set service status threshold, and forwards the data access request to other data security transmission servers based on the comparison result. Exemplarily, the service status threshold can be the threshold for the number of data access requests processed by the data security transmission server, such as 100. Then, when the proxy server obtains the service status data of the data security transmission server, it can obtain the number of data access requests in each data security transmission server, such as obtaining that the data access requests in server 1 are 101, the data access requests in server 2 are 90, and the data access requests in server 3 are 95. If the data access request value in server 1 is greater than the pre-set threshold for the number of data access requests, the received data access request can be sent to server 2 and server 3 first. This embodiment does not impose specific restrictions on this.

[0074] This technical solution compares the service status value of the data security transmission server with a pre-set service status threshold, and sends the data access request to other data security transmission servers based on the comparison result, thereby realizing cross-server traffic distribution and dynamic fault switching, improving server availability, and improving the efficiency of storage resource allocation and access request processing.

[0075] S270: Process the data access request through the data security transmission server, generate a data access result, and feed back the data access result to the client corresponding to the data security transmission server.

[0076] Specifically, the data security transmission server may read the data recorded in the data sharing disk according to the received data access request to generate an access result for the data access request, and return the access result to the corresponding client.

[0077] The technical solution of the embodiment of the present invention is that when a client corresponding to a data security transmission server initiates a data access request to a server, the data access request is received by a pre-set proxy server, and the client identifier of the client corresponding to the data security transmission server is determined according to the data access request; according to the client identifier, the proxy server sends the data access request to the data security transmission server corresponding to the client identifier; the data security transmission server processes the data access request, generates a data access result, and feeds back the data access result to the client corresponding to the data security transmission server. When a client initiates a data access request, the present technical solution can send the data access request to the corresponding data security transmission server according to the client identifier through the proxy server, generate a data access result for the data access request, and realize the unified management of multiple data security transmission services and multiple data shared disks, avoid the problem of inconsistent access paths when there are multiple servers, effectively improve the data access efficiency and user experience, and further improve the scalability and flexibility of the server.

[0078] Example 3

[0079] Figure 3 This is a schematic diagram of the structure of a capacity expansion device for a data security transmission server provided in the third embodiment of the present invention. The capacity expansion device for a data security transmission server provided in the embodiment of the present invention is applicable to the case where data is accessed simultaneously on each data sharing disk deployed in the system through at least one data security transmission server. The capacity expansion device for the data security transmission server can be implemented in the form of hardware and / or software, such as Figure 3 As shown, it specifically includes: server configuration module 310, disk mounting module 320, virtual access address generation module 330 and root directory creation module 340. Among them,

[0080] The server configuration module 310 is used to obtain identification information of at least one data security transmission server, and install and configure the data sharing system and data sharing protocol in each data security transmission server according to the identification information.

[0081] The disk mounting module 320 is configured to obtain identification information of at least one data sharing disk and mount each of the data sharing disks to each of the data security transmission servers based on the data sharing system.

[0082] The virtual access address generation module 330 is configured to generate a first virtual access address for accessing data to each of the data sharing disks according to the data sharing protocol, identification information of each of the data security transmission servers, and identification information of each of the data sharing disks.

[0083] The root directory creation module 340 is used to create an address root directory of the first virtual access address in each of the data security transmission servers based on the first virtual access address, so that the client corresponding to the data security transmission server can access data on each of the data shared disks through the address root directory, so as to achieve capacity expansion of the data security transmission server.

[0084] This technical solution obtains the identification information of each data security transmission server and each data sharing disk, and generates a first virtual access address for accessing data on each data sharing disk based on the obtained identification information of each data security transmission server and each data sharing disk. This solves the problems of data synchronization and consistency among servers in a multi-server deployment, the inability to dynamically expand servers, and the low disk utilization of the storage system, thereby improving the scalability and flexibility of the server. Furthermore, each data sharing disk can be mounted to each data security transmission server according to the data sharing system, thereby improving the utilization rate of the data sharing disk.

[0085] Optionally, the virtual access address generation module 330 is specifically configured to:

[0086] According to the data sharing agreement, the identification information of any data server is associated with the identification information of any data sharing disk, and the association relationship between each data sharing disk and the identification information of each data security transmission server is obtained;

[0087] According to the association relationship between any server and any disk, the physical address of the disk is mapped to the server respectively to obtain a first virtual address for accessing data on the data sharing disk.

[0088] Optionally, the device further includes: a data access request processing module, including:

[0089] a client identification acquisition unit, configured to, after creating an address root directory of the first virtual access address in each of the data security transmission servers based on the first virtual access address, so that a client corresponding to the data security transmission server can access data on each of the data shared disks through the address root directory, receive the data access request through a pre-set proxy server when the client corresponding to the data security transmission server initiates a data access request to the server, and determine a client identification of the client corresponding to the data security transmission server based on the data access request;

[0090] a data access request sending unit, configured to control the proxy server to send the data access request to the data security transmission server corresponding to the client identifier according to the client identifier;

[0091] The data access request processing unit is used to process the data access request through the data security transmission server, generate a data access result, and feed back the data access result to the client corresponding to the data security transmission server.

[0092] Optionally, a data access request sending unit is specifically configured to, after causing the proxy server to send the data access request to the data security transmission server corresponding to the client identifier according to the client identifier, detect the service status of the data security transmission server through the proxy server to obtain a service status value of the data security transmission server;

[0093] Comparing the service status value with a preset service status threshold to obtain a service status comparison result of the data security transmission server;

[0094] According to the service status comparison result, the data access request is forwarded to other data security transmission servers; the other data security transmission servers are servers other than the data security transmission server corresponding to the client identifier.

[0095] Optionally, a root directory creation module 340 is specifically configured to, after creating an address root directory of the first virtual access address in each of the data security transmission servers according to the first virtual access address, extract a directory identifier from at least one subdirectory contained in the address root directory to obtain a directory identifier of the at least one subdirectory;

[0096] determining, according to the directory identifier, at least one target client corresponding to the sub-directory, and establishing a mapping relationship between the directory identifier and the at least one client;

[0097] According to the mapping relationship, the virtual access address of the subdirectory is sent to the at least one target client to generate a virtual address directory for accessing data on the data sharing disk.

[0098] Optionally, the device further includes a disk adding module, which is configured to, when a disk adding request for a data sharing disk is detected, determine a new data sharing disk based on the data sharing system, and mount the new data sharing disk to each of the data security transmission servers;

[0099] Obtaining disk identification information of the newly added data shared disk, and associating and storing the obtained identification information with identification information of each data security transmission server to obtain a second virtual access address for accessing data to the newly added shared disk;

[0100] According to the second virtual access address, the address directory in each of the data security transmission servers is updated, so that the client can access data on the newly added data sharing disk through the updated address directory.

[0101] The capacity expansion device of the data security transmission server provided in the embodiment of the present invention can execute the capacity expansion method of the data security transmission server provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0102] Example 4

[0103] Figure 4 A schematic diagram of the structure of an electronic device 40 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0104] like Figure 4 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., which is communicatively connected to the at least one processor 41. The memory stores a computer program that can be executed by the at least one processor, and the processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. Various programs and data required for the operation of the electronic device 40 can also be stored in the RAM 43. The processor 41, ROM 42, and RAM 43 are connected to each other via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0105] Multiple components in the electronic device 40 are connected to the I / O interface 45, including an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0106] Processor 41 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, digital signal processors (DSPs), and any appropriate processor, controller, microcontroller, etc. Processor 41 executes the various methods and processes described above, such as the method for expanding the capacity of a secure data transmission server.

[0107] In some embodiments, the method for expanding the capacity of the data transmission server can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded into the RAM 43 and executed by the processor 41, one or more steps of the method for expanding the capacity of the data transmission server described above can be performed. Alternatively, in other embodiments, the processor 41 can be configured to execute the method for expanding the capacity of the data transmission server in any other appropriate manner (for example, by means of firmware).

[0108] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0109] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0110] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0111] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0112] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0113] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0114] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0115] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for expanding the capacity of a data security transmission server, characterized in that: include: Obtaining identification information of at least one data security transmission server, and installing and configuring a data sharing system and a data sharing protocol in each of the data security transmission servers according to the identification information; Obtain identification information of at least one data sharing disk, and based on the data sharing system, mount each of the data sharing disks to each of the data security transmission servers; generating a first virtual access address for accessing data on each of the data sharing disks according to the data sharing protocol, the identification information of each of the data security transmission servers, and the identification information of each of the data sharing disks; According to the first virtual access address, an address root directory of the first virtual access address is created in each of the data security transmission servers, so that the client corresponding to the data security transmission server can access data on each of the data shared disks through the address root directory, thereby realizing the expansion of the data security transmission server.

2. The method according to claim 1, characterized in that Generating a first virtual access address for accessing data on each of the data sharing disks according to the data sharing protocol, the identification information of each of the data security transmission servers, and the identification information of each of the data sharing disks, including: According to the data sharing agreement, the identification information of any data security transmission server is associated with the identification information of any data sharing disk, and the association relationship between each data sharing disk and the identification information of each data security transmission server is obtained; According to the association relationship between any server and any disk, the physical address of the disk is mapped to the server respectively to obtain a first virtual address for accessing data on the data sharing disk.

3. The method according to claim 1, characterized in that After creating an address root directory of the first virtual access address in each of the data security transmission servers according to the first virtual access address, so that a client corresponding to the data security transmission server can access data on each of the data shared disks through the address root directory, the method further includes: When a client corresponding to the data security transmission server initiates a data access request to the server, the data access request is received by a pre-set proxy server, and a client identifier of the client corresponding to the data security transmission server is determined according to the data access request; According to the client identifier, the proxy server sends the data access request to the data security transmission server corresponding to the client identifier; The data access request is processed by the data security transmission server to generate a data access result, and the data access result is fed back to the client corresponding to the data security transmission server.

4. The method according to claim 3, characterized in that After causing the proxy server to send the data access request to the data security transmission server corresponding to the client identifier according to the client identifier, the method further includes: Detecting the service status of the data security transmission server through the proxy server to obtain a service status value of the data security transmission server; Comparing the service status value with a preset service status threshold to obtain a service status comparison result of the data security transmission server; According to the service status comparison result, the data access request is forwarded to other data security transmission servers; the other servers are servers other than the data security transmission server corresponding to the client identifier.

5. The method according to claim 1, wherein After creating an address root directory of the first virtual access address in each of the data security transmission servers according to the first virtual access address, the method further includes: Extracting a directory identifier of at least one subdirectory contained in the address root directory to obtain a directory identifier of the at least one subdirectory; determining, according to the directory identifier, at least one target client corresponding to the sub-directory, and establishing a mapping relationship between the directory identifier and the at least one client; According to the mapping relationship, the virtual access address of the subdirectory is sent to the at least one target client to generate a virtual address directory for accessing data on the data sharing disk.

6. The method according to claim 1, characterized in that The method further comprises: When a disk addition request for a data sharing disk is detected, a new data sharing disk is determined based on the data sharing system, and the new data sharing disk is mounted to each of the servers; Obtaining disk identification information of the newly added data shared disk, and associating and storing the obtained identification information with identification information of each data security transmission server to obtain a second virtual access address for accessing data to the newly added shared disk; According to the second virtual access address, the address directory in each of the data security transmission servers is updated, so that the client can access data on the newly added data sharing disk through the updated address directory.

7. A capacity expansion device for a data security transmission server, characterized in that: include: A server configuration module, configured to obtain identification information of at least one data security transmission server, and install and configure a data sharing system and a data sharing protocol in each of the data security transmission servers according to the identification information; A disk mounting module, configured to obtain identification information of at least one data sharing disk and mount each of the data sharing disks to each of the data security transmission servers based on the data sharing system; a virtual access address generating module, configured to generate a first virtual access address for accessing data to each of the data sharing disks according to the data sharing protocol, the identification information of each of the data security transmission servers, and the identification information of each of the data sharing disks; A root directory creation module is used to create an address root directory of the first virtual access address in each of the data security transmission servers based on the first virtual access address, so that the client corresponding to the data security transmission server can access data on each of the data shared disks through the address root directory, so as to achieve capacity expansion of the data security transmission server.

8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the capacity expansion method of the data security transmission server described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the capacity expansion method of the data security transmission server according to any one of claims 1 to 6 when executed.

10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the computer program implements the capacity expansion method of the data security transmission server according to any one of claims 1 to 6.