File management all-in-one machine cross-region management system and method based on hybrid architecture
By building a hybrid-architecture archive management system and adopting federal authentication and multi-level protection technology, the problems of authentication islands and weak security in cross-domain archive scheduling are solved, and efficient and secure cross-regional archive scheduling is achieved.
Patent Information
- Application Number
- CN202511204826.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-08-27
AI Technical Summary
The existing technology lacks a collaborative scheduling mechanism and integrated security control framework among multi-regional archive nodes, resulting in authentication islands, scattered resources, opaque paths and weak scheduling security in the cross-domain archive scheduling process, affecting the continuity, timeliness and security assurance capabilities of cross-regional archive scheduling.
A cross-regional archive management system based on a hybrid architecture is adopted. Through federal authentication, path optimization and multi-level protection, a hybrid archive management architecture integrating joint authentication, path optimization, multi-level protection and trusted evidence is constructed to achieve efficient and secure response of cross-domain archive scheduling.
It improves the linkage response efficiency, identity authentication accuracy, data transmission security and traceability of the entire process in the cross-regional archive scheduling process, ensuring the continuity and security of cross-domain archive scheduling.
Smart Images

Figure CN120705855A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of archive management, and in particular to a cross-regional management system and method for an all-in-one archive management machine based on a hybrid architecture. Background Art
[0002] An increasing number of enterprises, institutions, universities, and government agencies are deploying integrated archive management machines to achieve centralized storage, efficient access, and intelligent classification of archival data. However, with the expansion of business scale and the multi-regional distribution of organizational structures, traditional stand-alone machines or local area network architectures are no longer able to meet the needs of cross-regional archive sharing, remote access, and collaborative processing.
[0003] At present, most traditional systems rely on centralized architecture or single-node scheduling mechanisms, and lack systematic support for the linkage scheduling capabilities between multi-regional archive nodes. As a result, the scheduling link is easily interrupted when facing high-concurrency or highly sensitive archive requests, and link performance optimization and risk reconstruction cannot be performed. As a result, when users need to retrieve archive resources across domains, authentication islands, scattered resources, opaque paths, large scheduling delays, and weakened security measures often occur.
[0004] To sum up, the existing technology has problems such as authentication islands, resource dispersion, path opacity and weak scheduling security in the cross-domain archive scheduling process due to the lack of a collaborative scheduling mechanism and integrated security control framework among multi-regional archive nodes, which further affects the continuity, timeliness and security assurance capabilities of cross-regional archive scheduling. Summary of the Invention
[0005] The purpose of this application is to provide a cross-regional management system and method for an all-in-one archive management machine based on a hybrid architecture, so as to solve the problems existing in the prior art, such as the lack of a collaborative scheduling mechanism and an integrated security control framework between multi-regional archive nodes, which leads to authentication islands, scattered resources, opaque paths and weak scheduling security in the cross-domain archive scheduling process, further affecting the continuity, timeliness and security assurance capabilities of cross-regional archive scheduling.
[0006] In view of the above problems, the present application provides a cross-regional management system and method for an all-in-one archive management machine based on a hybrid architecture.
[0007] In the first aspect, the present application provides a cross-regional management system of an archive management all-in-one machine based on a hybrid architecture, including: an archive scheduling request receiving module, which is used to build an archive management hybrid architecture based on multiple archive management all-in-one machines, and receive the user's cross-domain archive scheduling request based on the archive management hybrid architecture; a federal authentication module, which is used to perform federal authentication on the user through a joint identity authentication mechanism, generate a scheduling authorization token, and construct a cross-domain scheduling guidance vector based on the cross-domain archive scheduling request; a scheduling search module, which is used to activate a cross-domain scheduling evaluation model, perform a scheduling search on the archive management hybrid architecture in combination with the scheduling authorization token and the cross-domain scheduling guidance vector, and determine a first cross-domain scheduling channel and a first scheduling archive resource; a protection configuration optimization module, which is used to perform protection configuration optimization on the first cross-domain scheduling channel to obtain a second cross-domain scheduling channel; a cross-domain scheduling response module, which is used to perform multi-level protection on the first scheduling archive resource, obtain a second scheduling archive resource, and perform a cross-domain scheduling response in combination with the second cross-domain scheduling channel.
[0008] Preferably, the cross-regional management system of the archive management all-in-one machine based on the hybrid architecture also includes: an archive scheduling constraint condition construction unit, which is used to construct the archive scheduling constraint condition according to the scheduling authorization token and the cross-domain scheduling guidance vector; a scheduling path decision unit, which is used to make a scheduling path decision on the archive management hybrid architecture according to the archive scheduling constraint condition, and obtain the first archive scheduling path space; an optimal search unit, which is used to perform an optimal search on the first archive scheduling path space according to the cross-domain scheduling evaluation model, and generate the first cross-domain scheduling channel; an archive search unit, which is used to perform an archive search on the first cross-domain scheduling channel according to the archive scheduling constraint condition, and generate the first scheduling archive resource.
[0009] Preferably, the cross-regional management system of the archive management all-in-one machine based on the hybrid architecture also includes: an evaluation layer, which is used to evaluate each archive scheduling path in the first space of the archive scheduling path according to the cross-domain scheduling evaluation model, and establish a scheduling path evaluation space, and the cross-domain scheduling evaluation model includes a multidimensional scheduling evaluation index, and the multidimensional scheduling evaluation index includes archive scheduling efficiency and archive scheduling disconnection rate; a scheduling path evaluation constraint construction layer, which is used to construct a scheduling path evaluation constraint according to the multidimensional scheduling evaluation index; an optimization analysis layer, which is used to perform optimization analysis on the first space of the archive scheduling path based on the scheduling path evaluation space and the scheduling path evaluation constraint, and generate a second space of the archive scheduling path; a vectorized weight allocation layer, which is used to perform vectorized weight allocation according to the multidimensional scheduling evaluation index and generate a scheduling path optimality function; an optimization layer, which is used to perform scheduling path optimality maximization optimization on the second space of the archive scheduling path according to the scheduling path optimality function to obtain the first cross-domain scheduling channel.
[0010] Preferably, the cross-regional management system of the archive management all-in-one machine based on the hybrid architecture also includes: a protection configuration parameter collection unit, used to collect the protection configuration parameters of the first cross-domain scheduling channel to generate a current protection configuration scheme; a risk prediction unit, used to perform risk prediction on the first cross-domain scheduling channel according to the current protection configuration scheme to obtain a protection configuration risk coefficient; a configuration optimization adjustment unit, used to perform configuration optimization adjustment on the current protection configuration scheme according to the protection configuration risk threshold if the protection configuration risk coefficient is greater than or equal to the protection configuration risk threshold to obtain a protection configuration optimization result; a protection configuration optimization unit, used to perform protection configuration optimization on the first cross-domain scheduling channel according to the protection configuration optimization result to generate the second cross-domain scheduling channel.
[0011] Preferably, the cross-regional management system of the archive management all-in-one machine based on the hybrid architecture also includes: an archive scheduling simulation layer, which is used to perform archive scheduling simulation on the first cross-domain scheduling channel according to the current protection configuration scheme to obtain archive scheduling simulation data; a risk association detection layer, which is used to perform risk association detection on the archive scheduling simulation data to obtain a scheduling risk association feature sequence; a scheduling risk assessment model input layer, which is used to input the scheduling risk association feature sequence into P scheduling risk assessment models to obtain P scheduling risk assessment coefficients, where P is a positive integer greater than 1; a centralized value calculation layer, which is used to calculate the centralized value of the P scheduling risk assessment coefficients to generate the protection configuration risk coefficient.
[0012] Preferably, the cross-regional management system of the archive management all-in-one machine based on the hybrid architecture also includes: a privacy-sensitive detection unit, which is used to perform privacy-sensitive detection on the first scheduled archive resource to obtain an archive privacy-sensitive detection sequence; a data value detection unit, which is used to perform data value detection on the first scheduled archive resource to obtain an archive data value detection sequence; a desensitizing encryption protection parsing unit, which is used to perform desensitizing encryption protection parsing on the first scheduled archive resource based on the archive privacy-sensitive detection sequence and the archive data value detection sequence to obtain a first archive protection strategy; a permission embedding protection parsing unit, which is used to perform permission embedding protection parsing on the first scheduled archive resource based on the archive privacy-sensitive detection sequence and the archive data value detection sequence to obtain a second archive protection strategy; a multi-level protection processing unit, which is used to perform multi-level protection processing on the first scheduled archive resource according to the first archive protection strategy and the second archive protection strategy to generate the second scheduled archive resource.
[0013] Preferably, the cross-regional management system of the integrated archive management machine based on the hybrid architecture also includes: a joint authentication factor activation unit, used to activate the joint authentication factor, the joint authentication factor includes role identity, basic password, biometrics, geographic location, network trust and terminal credibility; an authentication unit, used to authenticate the user according to the joint authentication factor based on the federal authentication protocol, obtain a joint authentication result, and generate the scheduling authorization token according to the joint authentication result, the scheduling authorization token includes the archive scheduling right confirmation scope.
[0014] Preferably, the cross-regional management system of the archive management all-in-one machine based on the hybrid architecture also includes: an archive scheduling analysis system construction unit, which is used to construct an archive scheduling analysis system according to the archive scheduling intention indicator set; an intention analysis unit, which is used to perform intent analysis on the cross-domain archive scheduling request according to the archive scheduling analysis system to obtain an archive scheduling analysis result; a cross-domain scheduling guidance vector establishment unit, which is used to establish the cross-domain scheduling guidance vector according to the archive scheduling analysis result.
[0015] Preferably, the cross-regional management system of the integrated archive management machine based on a hybrid architecture also includes: the cross-domain scheduling response module is also used to monitor the cross-domain scheduling process of the user in real time, obtain cross-domain scheduling monitoring data, and encrypt and store the cross-domain scheduling monitoring data according to the blockchain.
[0016] In the second aspect, the present application also provides a cross-regional management method of an archive management all-in-one machine based on a hybrid architecture, including: building an archive management hybrid architecture based on multiple archive management all-in-one machines, and receiving a user's cross-domain archive scheduling request based on the archive management hybrid architecture; federally authenticating the user through a joint identity authentication mechanism, generating a scheduling authorization token, and constructing a cross-domain scheduling guidance vector based on the cross-domain archive scheduling request; activating a cross-domain scheduling evaluation model, performing a scheduling search on the archive management hybrid architecture in combination with the scheduling authorization token and the cross-domain scheduling guidance vector, and determining a first cross-domain scheduling channel and a first scheduling archive resource; performing protection configuration optimization on the first cross-domain scheduling channel to obtain a second cross-domain scheduling channel; performing multi-level protection on the first scheduling archive resource to obtain a second scheduling archive resource, and performing a cross-domain scheduling response in combination with the second cross-domain scheduling channel.
[0017] The technical solution provided in this application has at least the following technical effects or advantages: by achieving the technical goal of building a hybrid archive management architecture that integrates joint authentication, path optimization, multi-level protection and trusted evidence storage, the technical effect of improving the linkage response efficiency, identity authentication accuracy, data transmission security and traceability of the entire process in the cross-regional archive scheduling process is achieved.
[0018] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, which can be implemented in accordance with the contents of the description, and to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are specifically listed below. It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easy to understand through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in this application or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely exemplary, and a person of ordinary skill in the art can obtain other drawings based on the provided drawings without creative work.
[0020] Figure 1 This is a structural diagram of the cross-regional management system of the integrated archive management machine based on a hybrid architecture in this application.
[0021] Figure 2 This is a flowchart of the cross-regional management method of the integrated archive management machine based on a hybrid architecture in this application.
[0022] Explanation of the reference numerals: archive scheduling request receiving module 1, federation authentication module 2, scheduling search module 3, protection configuration optimization module 4, cross-domain scheduling response module 5. DETAILED DESCRIPTION
[0023] This application provides a cross-regional management system and method for archive management based on a hybrid architecture, which solves the existing technical problems that exist in the cross-region archive scheduling process due to the lack of a collaborative scheduling mechanism and integrated security control framework between multi-region archive nodes, resulting in authentication islands, scattered resources, opaque paths, and weak scheduling security, further affecting the continuity, timeliness, and security assurance capabilities of cross-regional archive scheduling. The technical goal of building a hybrid archive management architecture that integrates joint authentication, path optimization, multi-level protection, and trusted evidence is achieved, achieving the technical effect of improving the linkage response efficiency, identity authentication accuracy, data transmission security, and full process traceability of the cross-regional archive scheduling process.
[0024] Below, the technical solutions in this application will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this application, rather than all the embodiments of this application. It should be understood that this application is not limited to the example embodiments described herein. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. It should also be noted that, for the convenience of description, only the parts related to this application, rather than all of them, are shown in the accompanying drawings.
[0025] For example 1, please refer to the attached Figure 1 This application provides a cross-regional management system for archive management based on a hybrid architecture, specifically including: The file scheduling request receiving module 1 is used to build a file management hybrid architecture based on multiple file management integrated machines, and receive a user's cross-domain file scheduling request based on the file management hybrid architecture.
[0026] Specifically, an all-in-one archive management machine is a hardware device that integrates archive collection, storage, processing, and scheduling functions. It can complete comprehensive archive management in a local environment and is deployed on archive management units or business nodes. Multiple all-in-one archive management machines refer to the distributed deployment of multiple devices in different geographical areas. There are situations where multiple devices are not interconnected or have weak connections. Therefore, unified management must be achieved through technical means, and then a hybrid archive management architecture is built. The hybrid archive management architecture is a system design method that combines centralized architecture and distributed architecture. On the one hand, the hybrid archive management architecture has a unified management central platform for scheduling and authority control. On the other hand, it retains the local autonomy of the archive management all-in-one machines in various places, achieving a balance between resource scheduling flexibility and management efficiency.
[0027] Based on the hybrid archive management architecture, users receive cross-domain archive dispatch requests. Users issue instructions to access or call archive resources in other regions through access nodes. Cross-domain archive dispatch requests include the type of required archive, permission verification information, and the dispatch target location.
[0028] The federation authentication module 2 is used to perform federation authentication on the user through a joint identity authentication mechanism, generate a scheduling authorization token, and construct a cross-domain scheduling guidance vector according to the cross-domain archive scheduling request.
[0029] Specifically, a federated authentication mechanism uses a multi-factor, multi-dimensional approach to verify user identity. This approach incorporates multiple authentication factors, including role recognition, password verification, biometrics, device trustworthiness, geographic location, and network environment. Compared to single authentication methods, it offers greater security and robustness. Federated authentication refers to the process of establishing a unified user identity across different systems, platforms, or regions through a shared authentication protocol. For example, a user's authentication results in one location can be trusted and inherited by an archival system in another region, thus avoiding duplicate logins and permission conflicts. After a user completes federated authentication, a scheduling authorization token is generated. This token is a data identifier that carries the authentication results and the scope of scheduling permissions. It records information such as the types of files a user can access, the permissions they have, and the validity period. For example, a certain archivist is allowed to access five administrative documents issued after 2021 within ten minutes. Subsequently, a cross-domain scheduling guidance vector is constructed based on the cross-domain file scheduling request submitted by the user. The cross-domain scheduling guidance vector is a set of numbers used in algorithm calculations to express the scheduling intent's time requirements, geographical span, priority, and security level, facilitating path optimization and resource matching in the scheduling algorithm. If a user wants to quickly download fifty engineering drawings after 2022, and the place where the request is initiated is 3,000 kilometers away from the archive storage location, the dimensions of the scheduling guidance vector will reflect characteristics such as "high scheduling speed", "large geographical span", and "high resource consumption" to guide the system to prioritize high-bandwidth and low-risk channels to ensure a balance between user experience and system load.
[0030] The scheduling search module 3 is used to activate the cross-domain scheduling evaluation model, perform a scheduling search on the archive management hybrid architecture in combination with the scheduling authorization token and the cross-domain scheduling guidance vector, and determine a first cross-domain scheduling channel and a first scheduling archive resource.
[0031] Specifically, activating the cross-domain scheduling evaluation model involves invoking an internal analysis mechanism for path evaluation and resource matching upon receiving a user scheduling request. This mechanism incorporates multiple evaluation metrics to score and rank different scheduling paths. A scheduling authorization token is a permission credential generated after user authentication. It records the user's role, access rights, scope of operation, and time limits, and serves as one of the criteria for executing scheduling operations. The cross-domain scheduling guidance vector structures the user's scheduling intent parameters, such as the target region, data type, and scheduling time limit, into a vector form, enabling rapid identification of resources and paths that meet the requirements during scheduling. The hybrid archive management architecture is a network system consisting of a central control unit and multiple geographically distributed archive nodes. It supports both centralized management and distributed response, making it suitable for cross-regional scheduling applications. During the scheduling search process, the evaluation model, scheduling token, and guidance vector are combined to traverse feasible paths and resource nodes within the hybrid architecture, comprehensively evaluating path performance and resource matching. Ultimately, the path with the highest overall score is selected as the first cross-domain scheduling channel. The archive collection that best meets the user's intent and authorization scope is also selected as the first scheduling archive resource.
[0032] The protection configuration optimization module 4 is used to optimize the protection configuration of the first cross-domain scheduling channel to obtain a second cross-domain scheduling channel.
[0033] Specifically, the protection configuration of the first cross-domain scheduling channel is optimized. Based on the assessed security risk coefficient, combined with the resource status and preset strategies, the security configuration parameters of the first cross-domain scheduling channel are systematically optimized and adjusted to improve its stability and risk resistance during the actual scheduling process. Protection configuration refers to various technical and policy configuration items that affect the security of the scheduling channel, including the data transmission encryption level, the complexity of the authentication mechanism, the access control model, the link redundancy design, etc., while optimization is to use algorithms to find a combination solution that minimizes risk or optimizes performance among multiple optional configurations. Ultimately, the optimized channel is the second cross-domain scheduling channel, which is superior to the first cross-domain scheduling channel in scheduling performance, risk protection capability, or resource utilization efficiency, and will replace the original path in subsequent scheduling executions.
[0034] The cross-domain scheduling response module 5 is used to perform multi-level protection on the first scheduling archive resource, obtain the second scheduling archive resource, and perform a cross-domain scheduling response in combination with the second cross-domain scheduling channel.
[0035] Specifically, the first scheduling archive resource is protected at multiple levels. Based on its privacy sensitivity level and data value level, multiple layers of security measures are applied, including desensitization, encrypted transmission, access control, operational permission restrictions, and dynamic tracking. This prevents illegal access to the archive or content leakage during transmission, thereby ensuring information compliance and security. The second scheduling archive resource generated after multi-level protection processing is a version of the original archive resource with added security packaging or control tags, which has higher tamper resistance and risk resistance. At the same time, the second cross-domain scheduling channel is an optimized data scheduling path with higher performance stability, more complete security configuration, and support for data transmission or cross-domain calls of sensitive archives. When the second scheduling archive resource is used in combination with the second cross-domain scheduling channel, a secure and reliable cross-domain scheduling response can be achieved. The cross-domain scheduling response not only includes the action of transmitting data from one management node to another, but also includes authorization verification, data verification, and transmission integrity assurance during the process.
[0036] Furthermore, the present application also includes: an archive scheduling constraint condition construction unit, which is used to construct an archive scheduling constraint condition based on the scheduling authorization token and the cross-domain scheduling guidance vector; a scheduling path decision unit, which is used to make a scheduling path decision on the archive management hybrid architecture based on the archive scheduling constraint condition to obtain a first archive scheduling path space; an optimal search unit, which is used to perform an optimal search on the first archive scheduling path space based on the cross-domain scheduling evaluation model to generate the first cross-domain scheduling channel; an archive search unit, which is used to perform an archive search on the first cross-domain scheduling channel based on the archive scheduling constraint condition to generate the first scheduling archive resource.
[0037] Specifically, a scheduling authorization token is a digital identity and permission certificate generated by a user after joint authentication. It records the user's role permissions, the types of files that can be scheduled, the access scope, operation restrictions, and validity period. The cross-domain scheduling guidance vector is a structured expression of the user's scheduling intention, including multi-dimensional parameters such as scheduling timeliness, geographical span, scheduling priority, and risk tolerance. Based on the scheduling authorization token and the cross-domain scheduling guidance vector, file scheduling constraints are constructed to form a set of logical rules that limit the scope of scheduling behavior. For example, access to low-confidentiality files 300 kilometers away is only allowed within eight minutes, and copying is prohibited.
[0038] After the archive scheduling constraints are constructed, scheduling path decisions are made for the archive management hybrid architecture. The archive management hybrid architecture is a technical architecture that organizes archive management nodes in multiple regions through a combination of central control and edge autonomy, supporting the establishment of temporary or permanent scheduling connections between different regions. Scheduling path decisions refer to evaluating feasible paths according to the current constraints, thereby forming the first space of archive scheduling paths, that is, a set of candidate paths that meet the scheduling request. For example, a user can access a document from node A via a high-bandwidth link, or access the same content from node B via a low-load link. Both belong to the first space.
[0039] Next, the cross-domain scheduling evaluation model is used to analyze and screen each path in the first space of archive scheduling paths. The cross-domain scheduling evaluation model is a multi-dimensional comprehensive evaluation mechanism that establishes a scheduling path evaluation space and uses optimization search methods to find the optimal path under the current conditions, namely the first cross-domain scheduling channel.
[0040] After obtaining the first cross-domain scheduling channel, a resource search is performed within the first cross-domain scheduling channel based on the original archive scheduling constraints. Archive search involves searching for archive resources matching the requested content within the target path node. This process is filtered and matched based on the archive type and permission level specified in the scheduling token, ultimately outputting the first scheduled archive resource, which is the optimal set of archives available for call under the current conditions.
[0041] Furthermore, the present application also includes: an evaluation layer, which is used to evaluate each archive scheduling path in the first space of the archive scheduling path according to the cross-domain scheduling evaluation model, and establish a scheduling path evaluation space, wherein the cross-domain scheduling evaluation model includes a multidimensional scheduling evaluation index, and the multidimensional scheduling evaluation index includes archive scheduling efficiency and archive scheduling disconnection rate; a scheduling path evaluation constraint construction layer, which is used to construct a scheduling path evaluation constraint according to the multidimensional scheduling evaluation index; an optimization analysis layer, which is used to perform optimization analysis on the first space of the archive scheduling path based on the scheduling path evaluation space and the scheduling path evaluation constraint, and generate a second space of the archive scheduling path; a vectorized weight allocation layer, which is used to perform vectorized weight allocation according to the multidimensional scheduling evaluation index and generate a scheduling path optimality function; an optimization layer, which is used to perform scheduling path optimality maximization optimization on the second space of the archive scheduling path according to the scheduling path optimality function to obtain the first cross-domain scheduling channel.
[0042] Specifically, the cross-domain scheduling evaluation model is a computational mechanism used to measure the quality of different archive scheduling paths. It scores or ranks the archive scheduling paths based on their performance under different indicators, thereby helping to screen out the optimal solution. The first space of archive scheduling paths refers to the set of all possible paths that can be used for scheduling while satisfying basic constraints. Each archive scheduling path in the first space of archive scheduling paths is substituted into the cross-domain scheduling evaluation model for scoring one by one, forming a scheduling path evaluation space containing all scoring results. The scheduling path evaluation space is a multidimensional structure that records the performance of each archive scheduling path in various evaluation dimensions, including the archive scheduling efficiency and archive scheduling disconnection rate corresponding to each archive scheduling path, providing a data basis for subsequent screening. The multidimensional scheduling evaluation indicators included in the cross-domain scheduling evaluation model are used to measure the comprehensive performance of the path. Among them, the archive scheduling efficiency measures the time required, throughput capacity and response delay in the scheduling process, while the archive scheduling disconnection rate measures the probability of connection interruption in the historical operation of the path, reflecting its stability.
[0043] After the evaluation is completed, it is necessary to construct scheduling path evaluation constraints based on multi-dimensional scheduling evaluation indicators, including file scheduling efficiency constraints and file scheduling disconnection rate constraints, that is, to bind performance evaluation with scheduling goals.
[0044] After establishing the scheduling path evaluation constraints, the original first space of archival scheduling paths is optimized and analyzed, eliminating paths that do not meet the scheduling path evaluation constraints, thereby forming a second space of archival scheduling paths. This second space of archival scheduling paths is a subset of the first space of archival scheduling paths. The paths in this second space not only meet the basic scheduling conditions but also have performance that is closer to the user's scheduling goals.
[0045] Next, we use multidimensional scheduling evaluation metrics to assign vectorized weights to the archive scheduling paths in the second space. Each evaluation metric is converted into a computable set of vector dimensions, and weights are assigned to each dimension to reflect user preferences or default policies. A scheduling path quality function integrates the performance of each path across multiple dimensions and outputs a quality score for ranking and decision-making. The quality of a scheduling path is calculated as: archive scheduling efficiency × scheduling efficiency weight - archive scheduling disconnection rate × scheduling disconnection rate weight.
[0046] Finally, based on the scheduling path fitness function, the archive scheduling path in the second space of the archive scheduling path is maximized, that is, the path with the highest score is found and determined as the first cross-domain scheduling channel. It is the best path in terms of performance, stability and policy preference, and will serve as the main data transmission channel used in actual scheduling.
[0047] Furthermore, the present application also includes: a protection configuration parameter collection unit, used to collect the protection configuration parameters of the first cross-domain scheduling channel to generate a current protection configuration scheme; a risk prediction unit, used to perform risk prediction on the first cross-domain scheduling channel according to the current protection configuration scheme to obtain a protection configuration risk coefficient; a configuration optimization adjustment unit, used to perform configuration optimization adjustment on the current protection configuration scheme according to the protection configuration risk threshold if the protection configuration risk coefficient is greater than or equal to the protection configuration risk threshold to obtain a protection configuration optimization result; a protection configuration optimization unit, used to perform protection configuration optimization on the first cross-domain scheduling channel according to the protection configuration optimization result to generate the second cross-domain scheduling channel.
[0048] Specifically, collecting the protection configuration parameters for the first cross-domain scheduling channel involves extracting information about the security mechanisms within the first cross-domain scheduling channel after the scheduling path is determined. This includes information about encryption levels, authentication mechanisms, access control policies, redundant backup settings, and link reinforcement levels. These protection configuration parameters reflect the current security capabilities of the first cross-domain scheduling channel and provide foundational data for subsequent risk assessment and adjustments.
[0049] After the protection configuration plan is generated, a risk assessment is performed on the first cross-domain scheduling channel to determine whether the current protection capabilities can cope with potential risks. This risk assessment simulates possible anomalies that may arise during the scheduling process, such as network attacks, link interruptions, or privilege leaks, and evaluates them based on historical failure data. The final output, called the protection configuration risk coefficient, is a quantitative score of the security status, with higher scores indicating greater risk.
[0050] If the risk factor is greater than or equal to the preset protection configuration risk threshold, the current configuration presents a security risk and requires optimization and adjustment. The protection configuration risk threshold is a risk tolerance limit set based on business needs, security levels, and historical experience. When the protection configuration risk factor reaches or exceeds this value, the configuration optimization process is triggered, adjusting the current solution based on existing policies and rules to improve overall security.
[0051] Finally, based on the optimization results, the protection configuration of the first cross-domain scheduling channel is optimized. This essentially restructures the original channel or upgrades its policies, ultimately generating a second cross-domain scheduling channel. This second cross-domain scheduling channel is an alternative path built on a more secure configuration. It retains the scheduling characteristics of the first cross-domain scheduling channel while enhancing its protection capabilities, thereby reducing the risk of scheduling interruptions or information leakage.
[0052] Furthermore, the present application also includes: an archive scheduling simulation layer, which is used to perform archive scheduling simulation on the first cross-domain scheduling channel according to the current protection configuration scheme to obtain archive scheduling simulation data; a risk association detection layer, which is used to perform risk association detection on the archive scheduling simulation data to obtain a scheduling risk association feature sequence; a scheduling risk assessment model input layer, which is used to input the scheduling risk association feature sequence into P scheduling risk assessment models to obtain P scheduling risk assessment coefficients, where P is a positive integer greater than 1; a centralized value calculation layer, which is used to calculate the centralized value of the P scheduling risk assessment coefficients to generate the protection configuration risk coefficient.
[0053] Specifically, the current protection configuration scheme refers to an overall description of the encryption strategy, authentication mechanism, transmission control method, and node security protection measures set in the first cross-domain scheduling channel, which is used to guide the security simulation of the subsequent scheduling process. Archive scheduling simulation refers to the virtual execution of the scheduling process of the archive of the first cross-domain scheduling channel from the initiating node to the target node through the system's internal logic or simulation mechanism without actually triggering the real scheduling operation. This includes multiple dimensions such as data transmission path, access permission verification, and channel stability assessment. The final result is archive scheduling simulation data, which reflects the behavioral characteristics and potential weaknesses of the first cross-domain scheduling channel in the simulated scheduling, such as the number of delays, authentication failure rate, and link packet loss.
[0054] After obtaining the archive scheduling simulation data, the archive scheduling simulation data is further subjected to risk association detection, that is, analyzing whether the problems encountered in the simulation match the known risk patterns, identifying factors that may cause security incidents, and forming a scheduling risk association feature sequence. Each element represents a potential risk factor, such as authentication delay exceeding five seconds, path jitter frequency greater than once per second, etc.
[0055] Subsequently, the sequence of scheduling risk-related feature sequences is input into P scheduling risk assessment models for evaluation. P is a positive integer greater than 1, indicating the use of multiple models with different structures or algorithms to assess risk, thereby enhancing the accuracy and robustness of the prediction results. These P scheduling risk assessment models may include models based on statistical analysis, prediction models based on neural networks, and reasoning models based on rule bases. They calculate the potential risk level of the scheduling process from different dimensions and output P scheduling risk assessment coefficients.
[0056] Finally, the P dispatch risk assessment coefficients are aggregated and a representative centralized value is obtained by calculating the average, median, or weighted aggregation. This is the final protection configuration risk coefficient, which is used to measure the overall risk level of the dispatch channel under the current configuration scheme. Table 1 shows a partial record of the most recent cross-domain dispatch protection configuration evaluation.
[0057] Table 1: Partial record of the most recent cross-domain scheduling protection configuration evaluation Scheduling channel number Summary of current protection configuration scheme Summary of Archive Scheduling Simulation Data Risk-associated feature sequences P-value List of risk assessment models List of risk assessment coefficients for each model T-20250620-01 AES128 encryption, single-factor authentication Authentication delay 3 seconds, link interruption 1 time [Certification delay, interruption risk] 5 [Model A, Model B, Model C, Model D, Model E] [0.55,0.62,0.58,0.60,0.59] T-20250620-02 AES256 encryption, two-factor authentication Stable throughout, no packet loss [High path security] 4 [Model A, Model B, Model C, Model D] [0.21,0.25,0.22,0.24] T-20250620-03 Plain text transmission, no authentication mechanism Multiple interruptions, access failed 2 times [Path is unstable and access failure rate is high] 6 [Model A~F] [0.78,0.82,0.81,0.79,0.84,0.80] Furthermore, the present application also includes: a privacy-sensitive detection unit, used to perform privacy-sensitive detection on the first scheduling archive resource to obtain an archive privacy-sensitive detection sequence; a data value detection unit, used to perform data value detection on the first scheduling archive resource to obtain an archive data value detection sequence; a desensitizing encryption protection analysis unit, used to perform desensitizing encryption protection analysis on the first scheduling archive resource based on the archive privacy-sensitive detection sequence and the archive data value detection sequence to obtain a first archive protection strategy; a permission embedding protection analysis unit, used to perform permission embedding protection analysis on the first scheduling archive resource based on the archive privacy-sensitive detection sequence and the archive data value detection sequence to obtain a second archive protection strategy; a multi-level protection processing unit, used to perform multi-level protection processing on the first scheduling archive resource according to the first archive protection strategy and the second archive protection strategy to generate the second scheduling archive resource.
[0058] Specifically, the system performs privacy sensitivity testing on the first-dispatched archive resources to identify whether they contain sensitive information, such as personal identity information, contact information, bank account numbers, and health records. The system then scores or labels the sensitivity, ultimately generating a privacy sensitivity test sequence for the archives. Next, the system performs data value testing on the first-dispatched archive resources, assessing the importance of each first-dispatched archive resource at the business, legal, or strategic level. For example, it assesses the impact of a financial statement on tax audits or the criticality of a contract to a company's equity. The system then outputs a data value test sequence, representing the application value level of the archive.
[0059] After obtaining the two detection sequences, the first scheduled archive resources are desensitized and encrypted for protection and analysis based on the two sequences. The identified sensitive fields are replaced, masked, or blurred, and high-value or high-risk portions are processed using encryption algorithms, forming the first archive protection strategy. Subsequently, based on the archive privacy sensitivity detection sequence and the archive data value detection sequence, the first scheduled archive resources are subjected to permission embedding and protection analysis. That is, according to the sensitivity and value level of the archive, corresponding access permission labels and operation restrictions are assigned to each archive, generating the second archive protection strategy, including permission dimensions such as who can access, when can view, whether copying is allowed, and whether downloading is supported.
[0060] Finally, the first and second archive protection strategies are applied together to the first scheduled archive resource, achieving multi-level protection processing and generating the second scheduled archive resource. Multi-level protection processing not only secures the archive data itself but also embeds access management into the overall scheduling process, maintaining high security control before, during, and after data transmission.
[0061] Furthermore, the present application also includes: a joint authentication factor activation unit, used to activate the joint authentication factor, the joint authentication factor including role identity, basic password, biometrics, geographic location, network trust and terminal credibility; an authentication unit, used to authenticate the user according to the joint authentication factor based on the federated authentication protocol, obtain a joint authentication result, and generate the scheduling authorization token according to the joint authentication result, the scheduling authorization token including the archive scheduling right confirmation scope.
[0062] Specifically, upon receiving a user's cross-domain archive access request, the joint authentication factor is activated, proactively retrieving a set of multi-dimensional authentication elements for identity verification. Joint authentication factors are a set of information elements covering multiple dimensions that can identify and confirm the authenticity and credibility of the user's identity from different perspectives. Role identity refers to the user's level of authority or functional label within an organization, such as system administrator, archive reader, or auditor; basic passwords are traditional user-defined identity information, consisting of a combination of numbers, letters, or symbols; biometrics include unique physical features such as fingerprints, faces, irises, or voices, used for accurate identity recognition; geographic location indicates the user's current physical location, determined by GPS, IP address, or base station data; network trustworthiness is an assessment of the security level of the user's network environment, such as whether it is a trusted local area network and whether there are proxy or man-in-the-middle risks; and terminal trustworthiness is a judgment of the trustworthiness of the user's device itself, such as whether a controlled terminal is used and whether there is jailbreak or malware.
[0063] The federated authentication protocol is a cross-system, cross-organizational authentication collaboration mechanism that allows multiple independent systems to collaborate on identity verification based on a shared authentication framework, avoiding duplicate logins and permission conflicts. Based on the federated authentication protocol, integrated archive management machines deployed in different regions or units can trust each other and share a common authentication system. During the authentication process, the user is fully verified using joint authentication factors, including checking password correctness, geographic location compliance, and network security. The result of the joint authentication is a pass, reject, or pass with permission status.
[0064] Based on the joint authentication results, a dispatch authorization token is generated. This is a structured information carrier used to identify the user's identity, permissions, and operational boundaries throughout the cross-domain dispatch process. The dispatch authorization token contains the scope of file dispatch authorization, which includes the types, number, and level of files the user is authorized to access during the current session or operation, as well as the specific actions permitted. For example, only files from a specific city and year are allowed to be viewed, and downloading or copying is prohibited.
[0065] Furthermore, the present application also includes: an archive scheduling analysis system construction unit, which is used to construct an archive scheduling analysis system based on the archive scheduling intention indicator set; an intention analysis unit, which is used to perform intent analysis on the cross-domain archive scheduling request according to the archive scheduling analysis system to obtain an archive scheduling analysis result; and a cross-domain scheduling guidance vector establishment unit, which is used to establish the cross-domain scheduling guidance vector based on the archive scheduling analysis result.
[0066] Specifically, the archive scheduling intention indicator set is a set of parameters used to characterize the user's scheduling behavior intentions, including factors such as scheduling time requirements, geographical scope, archive type, priority level, and access method. The archive scheduling intention indicator set can be extracted from the user's scheduling request content, past operating habits, or system preset rules. The goal is to more accurately understand how users wish to schedule archives, and then build an archive scheduling parsing system. This logically organizes the archive scheduling intention indicator set into a standardized, callable parsing framework to support semantic understanding and purpose identification of scheduling requests.
[0067] When a user submits a cross-domain file dispatch request, the file dispatch parsing system is invoked to analyze and match the natural language, structured fields, or operation commands in the original request one by one, extracting the core dispatch intent elements. The intent parsing process outputs a file dispatch parsing result in a structured representation. For example, a user may wish to download financial files after 2021 via a high-speed channel and want the dispatch to take no more than 5 minutes.
[0068] The cross-domain scheduling guidance vector is generated by mapping the results of the archival scheduling analysis. It has clear dimensions and can participate in computation. For example, if the archival scheduling analysis results indicate high priority, a large geographical span, and high bandwidth requirements, the corresponding value in the cross-domain scheduling guidance vector will reflect the preference or restriction, guiding the subsequent scheduling path optimization model to make accurate response decisions. The cross-domain scheduling guidance vector is a numerical encoding of the scheduling intent, which is used to drive the scheduling path selection and resource matching process within the system.
[0069] Furthermore, the present application also includes: the cross-domain scheduling response module is also used to monitor the cross-domain scheduling process of the user in real time, obtain cross-domain scheduling monitoring data, and encrypt and store the cross-domain scheduling monitoring data based on the blockchain.
[0070] Specifically, real-time monitoring of the user's cross-domain scheduling process means continuously collecting key data such as scheduling path status information, user access behavior, resource call records, and scheduling result feedback during the entire process of the user's cross-regional archive scheduling operation, so as to achieve dynamic tracking and security supervision of the entire operation, and form cross-domain scheduling monitoring data, including timestamp, user ID, access path ID, scheduling status code, error prompt information, security alarm records, etc.
[0071] The cross-domain dispatch monitoring data is then encrypted and stored via blockchain. Blockchain is a distributed ledger technology characterized by immutability, full traceability, and multi-party consensus, making it suitable for storing critical operational data to ensure transparency and trustworthiness. Encrypted storage involves encrypting the data before writing it to the blockchain, creating a chained record.
[0072] To sum up, the cross-regional management system of the archive management all-in-one machine based on the hybrid architecture provided by this application has the following technical effects: by realizing the technical goal of building an archive management hybrid architecture that integrates joint authentication, path optimization, multi-level protection and trusted evidence storage, the technical effect of improving the linkage response efficiency, identity authentication accuracy, data transmission security and traceability of the cross-regional archive scheduling process is achieved.
[0073] In the second embodiment, based on the same inventive concept as the cross-regional management system of the integrated archive management machine based on the hybrid architecture in the above embodiment, this application also provides a cross-regional management method of the integrated archive management machine based on the hybrid architecture, please refer to the attached Figure 2 , including: S1: building a hybrid archive management architecture based on multiple archive management integrated machines, and receiving a user's cross-domain archive scheduling request based on the hybrid archive management architecture; S2: federally authenticating the user through a joint identity authentication mechanism, generating a scheduling authorization token, and building a cross-domain scheduling guidance vector based on the cross-domain archive scheduling request; S3: activating a cross-domain scheduling evaluation model, performing a scheduling search on the hybrid archive management architecture in combination with the scheduling authorization token and the cross-domain scheduling guidance vector, and determining a first cross-domain scheduling channel and a first scheduling archive resource; S4: performing protection configuration optimization on the first cross-domain scheduling channel to obtain a second cross-domain scheduling channel; S5: performing multi-level protection on the first scheduling archive resource, obtaining a second scheduling archive resource, and performing a cross-domain scheduling response in combination with the second cross-domain scheduling channel.
[0074] Furthermore, the cross-regional management method of the archive management integrated machine based on the hybrid architecture also includes: constructing archive scheduling constraints based on the scheduling authorization token and the cross-domain scheduling guidance vector; making scheduling path decisions on the archive management hybrid architecture based on the archive scheduling constraints to obtain the first archive scheduling path space; performing optimal search on the first archive scheduling path space based on the cross-domain scheduling evaluation model to generate the first cross-domain scheduling channel; performing archive search on the first cross-domain scheduling channel based on the archive scheduling constraints to generate the first scheduling archive resource.
[0075] Furthermore, the cross-regional management method of the archive management all-in-one machine based on the hybrid architecture also includes: evaluating each archive scheduling path in the first space of the archive scheduling path according to the cross-domain scheduling evaluation model, and establishing a scheduling path evaluation space, the cross-domain scheduling evaluation model includes a multidimensional scheduling evaluation index, and the multidimensional scheduling evaluation index includes archive scheduling efficiency and archive scheduling disconnection rate; constructing a scheduling path evaluation constraint according to the multidimensional scheduling evaluation index; based on the scheduling path evaluation space, performing an optimization analysis on the first space of the archive scheduling path according to the scheduling path evaluation constraint to generate a second space of the archive scheduling path; performing vectorized weight allocation according to the multidimensional scheduling evaluation index to generate a scheduling path optimality function; performing scheduling path optimality maximization optimization on the second space of the archive scheduling path according to the scheduling path optimality function to obtain the first cross-domain scheduling channel.
[0076] Furthermore, the cross-regional management method of the archive management integrated machine based on the hybrid architecture also includes: collecting the protection configuration parameters of the first cross-domain scheduling channel to generate a current protection configuration plan; performing risk prediction on the first cross-domain scheduling channel according to the current protection configuration plan to obtain a protection configuration risk coefficient; if the protection configuration risk coefficient is greater than or equal to the protection configuration risk threshold, performing configuration optimization adjustment on the current protection configuration plan according to the protection configuration risk threshold to obtain a protection configuration optimization result; performing protection configuration optimization on the first cross-domain scheduling channel according to the protection configuration optimization result to generate the second cross-domain scheduling channel.
[0077] Furthermore, the cross-regional management method of the archive management integrated machine based on the hybrid architecture also includes: performing archive scheduling simulation on the first cross-domain scheduling channel according to the current protection configuration scheme to obtain archive scheduling simulation data; performing risk association detection on the archive scheduling simulation data to obtain a scheduling risk association feature sequence; inputting the scheduling risk association feature sequence into P scheduling risk assessment models to obtain P scheduling risk assessment coefficients, where P is a positive integer greater than 1; calculating the centralized value of the P scheduling risk assessment coefficients to generate the protection configuration risk coefficient.
[0078] Furthermore, the cross-regional management method of the archive management integrated machine based on the hybrid architecture also includes: performing privacy-sensitive detection on the first scheduled archive resource to obtain an archive privacy-sensitive detection sequence; performing data value detection on the first scheduled archive resource to obtain an archive data value detection sequence; performing desensitizing, encrypting and protecting analysis on the first scheduled archive resource based on the archive privacy-sensitive detection sequence and the archive data value detection sequence to obtain a first archive protection strategy; performing permission embedding and protecting analysis on the first scheduled archive resource based on the archive privacy-sensitive detection sequence and the archive data value detection sequence to obtain a second archive protection strategy; performing multi-level protection processing on the first scheduled archive resource according to the first archive protection strategy and the second archive protection strategy to generate the second scheduled archive resource.
[0079] Furthermore, the cross-regional management method of the archive management integrated machine based on the hybrid architecture also includes: activating joint authentication factors, the joint authentication factors including role identity, basic password, biometrics, geographic location, network trust and terminal credibility; based on the federal authentication protocol, authenticating the user according to the joint authentication factors, obtaining a joint authentication result, and generating the scheduling authorization token according to the joint authentication result, the scheduling authorization token including the archive scheduling right confirmation scope.
[0080] Furthermore, the cross-regional management method of the archive management integrated machine based on the hybrid architecture also includes: constructing an archive scheduling analysis system based on the archive scheduling intention indicator set; performing intent analysis on the cross-domain archive scheduling request based on the archive scheduling analysis system to obtain an archive scheduling analysis result; and establishing the cross-domain scheduling guidance vector based on the archive scheduling analysis result.
[0081] Furthermore, the cross-regional management method of the archive management all-in-one machine based on the hybrid architecture also includes: real-time monitoring of the user's cross-domain scheduling process, obtaining cross-domain scheduling monitoring data, and encrypting and storing the cross-domain scheduling monitoring data according to the blockchain.
[0082] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The cross-regional management system of the archive management all-in-one machine based on a hybrid architecture and the specific examples in the aforementioned embodiment 1 are also applicable to the cross-regional management method of the archive management all-in-one machine based on a hybrid architecture in this embodiment. Through the aforementioned detailed description of the cross-regional management system of the archive management all-in-one machine based on a hybrid architecture, those skilled in the art can clearly understand the cross-regional management method of the archive management all-in-one machine based on a hybrid architecture in this embodiment, so for the sake of brevity of the specification, it will not be described in detail here.
[0083] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
[0084] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalents, the present application is intended to include these modifications and variations.
Claims
1. A cross-regional management system for integrated archive management based on a hybrid architecture, characterized by: The system comprises: The file scheduling request receiving module is used to build a file management hybrid architecture based on multiple file management integrated machines, and receive the user's cross-domain file scheduling request based on the file management hybrid architecture; a federation authentication module, configured to perform federation authentication on the user through a joint identity authentication mechanism, generate a scheduling authorization token, and construct a cross-domain scheduling guidance vector according to the cross-domain archive scheduling request; a scheduling search module, configured to activate a cross-domain scheduling evaluation model, perform a scheduling search on the archive management hybrid architecture in combination with the scheduling authorization token and the cross-domain scheduling guidance vector, and determine a first cross-domain scheduling channel and a first scheduling archive resource; a protection configuration optimization module, configured to perform protection configuration optimization on the first cross-domain scheduling channel to obtain a second cross-domain scheduling channel; The cross-domain scheduling response module is used to perform multi-level protection on the first scheduling archive resource, obtain the second scheduling archive resource, and perform a cross-domain scheduling response in combination with the second cross-domain scheduling channel.
2. The cross-regional management system of the integrated archive management machine based on hybrid architecture according to claim 1, characterized in that: The scheduling search module includes: a file scheduling constraint condition construction unit, configured to construct a file scheduling constraint condition according to the scheduling authorization token and the cross-domain scheduling guidance vector; a scheduling path decision unit, configured to make a scheduling path decision for the archive management hybrid architecture according to the archive scheduling constraint condition, and obtain a first archive scheduling path space; an optimization search unit, configured to perform an optimization search on the first space of the archive scheduling path according to the cross-domain scheduling evaluation model to generate the first cross-domain scheduling channel; The archive search unit is configured to perform an archive search on the first cross-domain scheduling channel according to the archive scheduling constraint condition to generate the first scheduling archive resource.
3. The cross-regional management system of the integrated archive management machine based on hybrid architecture according to claim 2, characterized in that: The optimization search unit includes: An evaluation layer, configured to evaluate each archive scheduling path in the first archive scheduling path space according to the cross-domain scheduling evaluation model to establish a scheduling path evaluation space, wherein the cross-domain scheduling evaluation model includes multidimensional scheduling evaluation indicators, and the multidimensional scheduling evaluation indicators include archive scheduling efficiency and archive scheduling disconnection rate; A scheduling path evaluation constraint construction layer, used to construct scheduling path evaluation constraints based on the multi-dimensional scheduling evaluation indicators; An optimization analysis layer, configured to perform optimization analysis on the first archive scheduling path space based on the scheduling path evaluation space and according to the scheduling path evaluation constraints, to generate a second archive scheduling path space; A vectorized weight allocation layer, configured to perform vectorized weight allocation according to the multi-dimensional scheduling evaluation index and generate a scheduling path optimality function; The optimization layer is used to optimize the second space of the archive scheduling path to maximize the scheduling path optimality according to the scheduling path optimality function, and obtain the first cross-domain scheduling channel.
4. The cross-regional management system of the integrated archive management machine based on hybrid architecture according to claim 1, characterized in that: The protection configuration optimization module includes: A protection configuration parameter collection unit, configured to collect protection configuration parameters of the first cross-domain scheduling channel and generate a current protection configuration scheme; a risk prediction unit, configured to perform risk prediction on the first cross-domain scheduling channel according to the current protection configuration scheme to obtain a protection configuration risk coefficient; a configuration optimization adjustment unit, configured to, if the protection configuration risk coefficient is greater than or equal to a protection configuration risk threshold, perform configuration optimization adjustment on the current protection configuration scheme according to the protection configuration risk threshold to obtain a protection configuration optimization result; A protection configuration optimization unit is used to optimize the protection configuration of the first cross-domain scheduling channel according to the protection configuration optimization result to generate the second cross-domain scheduling channel.
5. The cross-regional management system of the integrated archive management machine based on hybrid architecture according to claim 4, characterized in that: The risk prediction unit includes: A file scheduling simulation layer, configured to perform file scheduling simulation on the first cross-domain scheduling channel according to the current protection configuration scheme to obtain file scheduling simulation data; The risk association detection layer is used to perform risk association detection on the archive scheduling simulation data to obtain a scheduling risk association feature sequence; The scheduling risk assessment model input layer is used to input the scheduling risk association feature sequence into P scheduling risk assessment models to obtain P scheduling risk assessment coefficients, where P is a positive integer greater than 1; The centralized value calculation layer is used to calculate the centralized value of the P scheduling risk evaluation coefficients to generate the protection configuration risk coefficient.
6. The cross-regional management system of the integrated archive management machine based on hybrid architecture according to claim 1, characterized in that: The cross-domain scheduling response module includes: a privacy-sensitive detection unit, configured to perform a privacy-sensitive detection on the first scheduling archive resource to obtain an archive privacy-sensitive detection sequence; a data value detection unit, configured to perform data value detection on the first scheduling archive resource to obtain an archive data value detection sequence; a desensitizing encryption protection parsing unit, configured to perform desensitizing encryption protection parsing on the first scheduled archive resource based on the archive privacy sensitivity detection sequence and the archive data value detection sequence to obtain a first archive protection strategy; a permission embedding protection parsing unit, configured to perform permission embedding protection parsing on the first scheduling archive resource based on the archive privacy sensitivity detection sequence and the archive data value detection sequence to obtain a second archive protection policy; The multi-level protection processing unit is used to perform multi-level protection processing on the first scheduling archive resource according to the first archive protection strategy and the second archive protection strategy to generate the second scheduling archive resource.
7. The cross-regional management system of the integrated archive management machine based on hybrid architecture according to claim 1, characterized in that: The federal authentication module includes: A joint authentication factor activation unit, configured to activate joint authentication factors, including role identity, basic password, biometrics, geographic location, network trust, and terminal credibility; The authentication unit is used to authenticate the user according to the joint authentication factor based on the federated authentication protocol, obtain a joint authentication result, and generate the scheduling authorization token according to the joint authentication result, wherein the scheduling authorization token includes the file scheduling right confirmation scope.
8. The cross-regional management system of the integrated archive management machine based on hybrid architecture according to claim 1, characterized in that: The federal authentication module further includes: The file scheduling analysis system construction unit is used to construct the file scheduling analysis system according to the file scheduling intention indicator set; an intent parsing unit, configured to perform intent parsing on the cross-domain file scheduling request according to the file scheduling parsing system to obtain a file scheduling parsing result; The cross-domain scheduling guidance vector establishing unit is configured to establish the cross-domain scheduling guidance vector according to the file scheduling analysis result.
9. The cross-regional management system of the integrated archive management machine based on hybrid architecture according to claim 1, characterized in that: The cross-domain scheduling response module is also used to monitor the user's cross-domain scheduling process in real time, obtain cross-domain scheduling monitoring data, and encrypt and store the cross-domain scheduling monitoring data based on the blockchain.
10. A cross-regional management method for an integrated archive management machine based on a hybrid architecture, characterized in that: The method is executed by a cross-regional management system of an integrated archive management machine based on a hybrid architecture according to any one of claims 1 to 9, comprising: Building a hybrid archive management architecture based on multiple integrated archive management machines, and receiving a user's cross-domain archive scheduling request based on the hybrid archive management architecture; Performing federated authentication on the user through a joint identity authentication mechanism, generating a scheduling authorization token, and constructing a cross-domain scheduling guidance vector according to the cross-domain archive scheduling request; activating a cross-domain scheduling evaluation model, performing a scheduling search on the archive management hybrid architecture in combination with the scheduling authorization token and the cross-domain scheduling guidance vector, and determining a first cross-domain scheduling channel and a first scheduling archive resource; Performing protection configuration optimization on the first cross-domain scheduling channel to obtain a second cross-domain scheduling channel; The first scheduling archive resource is protected at multiple levels to obtain the second scheduling archive resource, and a cross-domain scheduling response is performed in combination with the second cross-domain scheduling channel.
Citation Information
Patent Citations
Automatic filing method and system for personnel archives
CN118710225A
Archive management system based on big data technology
CN120086884A
Archive data security integration management system
CN120257327A
Federated distributed computational graph architecture for biological system engineering and analysis
US20250258956A1