Data cross-network synchronization method and device for configuration management database
By detecting security policies and encrypting transmissions during cross-network synchronization, the problem of data pollution during data synchronization in network environments with different security levels is solved, achieving secure, orderly data synchronization and consistency.
Patent Information
- Application Number
- CN202510961613.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-11-14
AI Technical Summary
In network environments with different security levels, existing technologies cannot achieve efficient and secure synchronization of configuration and management database data, which can easily lead to data pollution and information inconsistency.
By detecting security policies during cross-network synchronization, the system ensures that the data in the configuration management database conforms to the preset secure sending and import policies, employs encrypted transmission and digest verification, controls the direction of data synchronization, and avoids data contamination.
It achieves secure and orderly cross-network synchronization, avoids data pollution, and ensures data consistency and security in environments with different security levels.
Smart Images

Figure CN120950596A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and computer-readable medium for cross-network data synchronization of a configuration management database. Background Technology
[0002] In modern, complex IT environments, Configuration Management Databases (CMDBs) provide effective support for efficient IT service management and operations. By centrally managing all IT assets (such as servers, network devices, applications, and dependencies) and their relationships, CMDBs offer a unified asset view and dynamic relationships, enabling full lifecycle tracking of configuration items. This allows for rapid identification of root causes of failures, assessment of the impact of changes, and optimization of resource allocation.
[0003] CMDB provides the data foundation for automated operations and maintenance. Its core stored data includes configuration items for software, hardware, services, and logical objects, along with their attributes, relationships, and dependencies. This data collectively constitutes a complete configuration model of the IT environment. For medium to large-sized IT-driven enterprises, industries with high system stability requirements, and companies handling sensitive data, multiple environments such as development, testing, and production are typically separated through network and resource isolation. Each environment has different levels of information security requirements. Considering network security isolation and the adaptability of differentiated environments to business needs, regional deployment of CMDB can meet the differentiated needs of each region, effectively avoiding data contamination. Especially in integrated software development and operations models, CMDB is needed in testing and production environments, and there are scenarios where the testing environment consumes the production environment's CMDB. However, CMDBs built in different environments have different security levels, and direct information synchronization can easily lead to data contamination. Summary of the Invention
[0004] In view of this, on the one hand, embodiments of the present invention provide a method for cross-network data synchronization of a configuration management database. During the synchronization process, it detects whether the data complies with a security policy, thereby avoiding data corruption. Specifically, it is applied to a first synchronization system corresponding to a first configuration management database. The first configuration management database and the first synchronization system are located in a first network environment. The first configuration management database stores configuration management file information corresponding to various configurations. The method includes the following steps:
[0005] The task of cross-network synchronization of configuration management data is obtained. The information in the task includes the information of the source configuration management database, the information of the target configuration management database, and the configuration management file information to be synchronized. The source configuration management database is the first configuration management database, and the target configuration management database includes the second configuration management database. The second configuration management database is located in the second network environment. The second network environment is also configured with a second synchronization system corresponding to the second configuration management database. The security level information of the first network environment is different from that of the second network environment.
[0006] Determine whether the information in the source configuration management database and the target configuration management database conform to the preset security transmission policy;
[0007] In response to the information in the source configuration management database and the target configuration management database conforming to the preset security transmission policy, the configuration management file information to be synchronized is sent to the second synchronization system. After the second synchronization system determines that the configuration management file information to be synchronized conforms to the preset security import policy, it imports the configuration management file information to be synchronized into the second configuration management database.
[0008] In some embodiments of the present invention, the task of obtaining cross-network synchronization of configuration management data includes:
[0009] In response to changes in configuration management files in the first configuration management database, or in response to receiving a full cross-network synchronization task triggered at a predetermined time interval, information of the pre-associated second configuration management database and configuration management file information to be synchronized are obtained.
[0010] Generate a cross-network synchronization task for configuration management data. The configuration management file information to be synchronized includes the changed configuration management file information in the first configuration management database, or the full configuration management file information in the first configuration management database.
[0011] In some embodiments of the present invention, the configuration management file information includes configuration unique identifier information, security level information, and configuration management data.
[0012] In some embodiments of the present invention, the method further includes:
[0013] Obtain the security level information of the first network environment and the configuration management file information in the first configuration management database;
[0014] If the security level information in the configuration management file is lower than the security level information of the first network environment, delete the configuration management file information.
[0015] In some embodiments of the present invention, the information in the source configuration management database includes security level information of a first network environment, and the information in the target configuration management database includes security level information of a second network environment; determining whether the information in the source configuration management database and the information in the target configuration management database conform to a preset secure transmission policy includes:
[0016] When the security level information of the first network environment is higher than that of the second network environment, the information in the source configuration management database and the information in the target configuration management database conform to the preset security transmission policy.
[0017] When the security level information of the first network environment is lower than that of the second network environment, the information in the source configuration management database and the information in the target configuration management database do not conform to the preset security transmission policy.
[0018] In some embodiments of the present invention, the information of the target configuration management database further includes the address of the second synchronization system; sending the configuration management file information to be synchronized to the second synchronization system includes:
[0019] Generate a first digest value based on the configuration management file information to be synchronized;
[0020] The configuration management file information to be synchronized and the first digest value are encrypted to generate encrypted configuration management file information to be synchronized.
[0021] Based on the address of the second synchronization system, send the encrypted configuration management file information to be synchronized to the second synchronization system.
[0022] In some embodiments of the present invention, the file naming of the configuration management file information includes the timestamp information when the configuration management data cross-network synchronization task is generated; sending the encrypted configuration management file information to be synchronized to the second synchronization system includes:
[0023] In accordance with the timestamp information, the encrypted configuration management file information to be synchronized is sent to the second synchronization system.
[0024] On the other hand, this invention also provides a method for cross-network data synchronization of a configuration management database. During the synchronization process, it checks whether the data complies with a security policy to avoid data corruption. This method is applied to a second synchronization system corresponding to the second configuration management database. The second configuration management database and the second synchronization system are located in a second network environment. The second configuration management database stores configuration management file information. The method includes the following steps:
[0025] Obtain the configuration management file information to be synchronized sent by the first synchronization system, wherein the first synchronization system corresponds to the first configuration management database, the first synchronization system and the first configuration management database are in the first network environment, and the security level information of the first network environment is different from the security level information of the second network environment;
[0026] Determine whether the configuration management file information to be synchronized conforms to the preset security import policy;
[0027] When the configuration management file information to be synchronized meets the preset security import policy, the configuration management file information to be synchronized is imported into the second configuration management database.
[0028] In some embodiments of the present invention, the configuration management file information includes configuration unique identifier information, security level information, and configuration management data; determining whether the configuration management file information to be synchronized conforms to a preset security import strategy includes:
[0029] Obtain security level information for the second network environment;
[0030] When the security level of the configuration management file information to be synchronized is higher than the security level of the second network environment, the configuration management file information to be synchronized is indicated to conform to the preset security import policy.
[0031] When the security level of the configuration management file information to be synchronized is lower than the security level of the second network environment, it indicates that the configuration management file information to be synchronized does not conform to the preset security import policy.
[0032] In some embodiments of the present invention, obtaining the configuration management file information to be synchronized sent by the first synchronization system includes:
[0033] Receive encrypted configuration management file information to be synchronized from the first synchronization system;
[0034] Decrypt the encrypted configuration management file information to be synchronized to obtain the decrypted configuration management file information to be synchronized and the first digest value;
[0035] Generate a second digest value based on the decrypted configuration management file information to be synchronized;
[0036] When the first digest value matches the second digest value, the decrypted configuration management file information to be synchronized will be used as the configuration management file information to be synchronized.
[0037] In some embodiments of the present invention, importing the configuration management file information to be synchronized into a second configuration management database includes:
[0038] In response to the existence of a target configuration management file in the second configuration management database that has the same configuration unique identifier as the configuration management file information to be synchronized;
[0039] Replace the target configuration management file information with the configuration management file information to be synchronized.
[0040] Thirdly, embodiments of the present invention also provide a cross-network data synchronization device for a configuration management database, applied to a first synchronization system corresponding to the first configuration management database. The first configuration management database and the first synchronization system are located in a first network environment. The first configuration management database stores configuration management file information corresponding to various configurations. The device includes a synchronization task acquisition module, a security judgment module, and a sending module.
[0041] The synchronization task acquisition module is configured to acquire cross-network synchronization tasks for configuration management data. The information in the cross-network synchronization task for configuration management data includes information about the source configuration management database, information about the target configuration management database, and information about the configuration management files to be synchronized. The source configuration management database is the first configuration management database, and the target configuration management database includes the second configuration management database. The second configuration management database is located in the second network environment, and the second network environment is also configured with a second synchronization system corresponding to the second configuration management database. The security level information of the first network environment is different from that of the second network environment.
[0042] The security assessment module is configured to determine whether the information in the source configuration management database and the information in the target configuration management database conform to the preset security transmission policy.
[0043] The sending module is configured to send the configuration management file information to be synchronized to the second synchronization system in response to the information in the source configuration management database and the target configuration management database conforming to the preset security sending policy. This allows the second synchronization system to import the configuration management file information to be synchronized into the second configuration management database after determining that it conforms to the security import policy.
[0044] Fourthly, embodiments of the present invention also provide a cross-network data synchronization device for a configuration management database, applied to a second synchronization system corresponding to the second configuration management database. The second configuration management database and the second synchronization system are located in a second network environment. The second configuration management database stores configuration management file information. The device includes a configuration management file information acquisition module, a security judgment module, and an import module.
[0045] The configuration management file information acquisition module is configured to acquire configuration management file information to be synchronized sent by the first synchronization system. The first synchronization system corresponds to the first configuration management database. The first synchronization system and the first configuration management database are located in the first network environment. The security level information of the first network environment is different from that of the second network environment.
[0046] The security assessment module determines whether the configuration management file information to be synchronized conforms to the preset security import policy;
[0047] The import module is configured to import the configuration management file information to be synchronized into the second configuration management database in response to the configuration management file information to be synchronized conforming to the preset security import policy.
[0048] According to another aspect of the present invention, an electronic device is provided, comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method of the above embodiments of the present invention.
[0049] According to another aspect of the present invention, a computer-readable medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method provided in the above embodiments of the present invention.
[0050] One embodiment of the above invention has the following advantages or beneficial effects: In this embodiment, when the first configuration management database synchronizes configuration management file information to the second configuration management database across networks, it checks whether the information conforms to a preset secure transmission policy. If it does, the first synchronization system sends the configuration management file information to be synchronized from the first configuration management data to the second synchronization system. The second synchronization system checks whether the configuration management file information to be synchronized conforms to a preset secure import policy. If it does, it imports the configuration management file to be synchronized into the second configuration management data. This ensures orderly synchronization of configuration management files across networks, avoiding the generation of dirty data and thus preventing data pollution.
[0051] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description
[0052] The accompanying drawings are provided to better understand the invention and are not intended to unduly limit the scope of the invention. Wherein:
[0053] Figure 1 This is a schematic diagram of a network system architecture for implementing a cross-network data synchronization method for a configuration management database according to some embodiments of the present invention;
[0054] Figure 2This is a flowchart illustrating a method for cross-network data synchronization of a configuration management database according to some embodiments of the present invention;
[0055] Figure 3a This is a flowchart illustrating a method for obtaining cross-network synchronization tasks in a configuration management database data cross-network synchronization method according to some embodiments of the present invention;
[0056] Figure 3b This is another flowchart illustrating the process of obtaining cross-network synchronization tasks in the configuration management database data cross-network synchronization method according to some embodiments of the present invention;
[0057] Figure 4 This is a flowchart illustrating the process of determining whether a preset secure transmission strategy is met in the cross-network data synchronization method for configuring and managing databases according to some embodiments of the present invention.
[0058] Figure 5 This is a flowchart illustrating the process of sending configuration management file information to be synchronized in the cross-network data synchronization method for configuration management database according to some embodiments of the present invention.
[0059] Figure 6 This is a schematic diagram of the process of the second synchronization system obtaining the configuration management file information to be synchronized in the cross-network synchronization method of configuration management database data according to some embodiments of the present invention;
[0060] Figure 7 This is a flowchart illustrating the process of determining whether the configuration management file information to be synchronized conforms to a preset secure import strategy in the cross-network synchronization method for configuration management database data according to some embodiments of the present invention.
[0061] Figure 8 This is a schematic diagram of the process of importing configuration management file information to be synchronized into the second synchronization system in the cross-network synchronization method of configuration management database data according to some embodiments of the present invention;
[0062] Figure 9 This is a schematic diagram of functional modules applied to a CMDB data cross-network synchronization system according to some embodiments of the present invention;
[0063] Figure 10 This is a schematic diagram of the architecture applied to a CMDB data cross-network synchronization system according to some embodiments of the present invention;
[0064] Figure 11 This is a schematic diagram of the data initialization process applied to a CMDB data cross-network synchronization system according to some embodiments of the present invention;
[0065] Figure 12 This is a schematic diagram of the process for cross-network data synchronization applied to a CMDB data cross-network synchronization system according to some embodiments of the present invention;
[0066] Figure 13 This is a functional structure diagram of a configuration management database cross-network data synchronization device according to some embodiments of the present invention;
[0067] Figure 14 This is a functional structure diagram of a configuration management database cross-network data synchronization device according to other embodiments of the present invention;
[0068] Figure 15 This is an exemplary system architecture diagram in which embodiments of the present invention can be applied;
[0069] Figure 16 This is a schematic diagram of the structure of a computer system suitable for implementing terminal devices or servers of the present invention. Detailed Implementation
[0070] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of the present invention, including various details to aid understanding. These details should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0071] In this embodiment of the invention, "CMDB" refers to Configuration Management Database, which is used to store and manage information about various configuration items in IT infrastructure; "mongoDB" refers to an open-source document-oriented database that uses a JSON-like document model to store data, which makes data storage very flexible.
[0072] In complex IT environments, configuration management databases (CMDBs) are typically used to manage configuration items and their relationships for IT assets. Due to varying security gradients and requirements across different network environments, physical or logical isolation exists between them. However, depending on development and operational needs, CMDBs are often deployed in different network environments, such as production and testing environments. The inventors have discovered that this may lead to the following problems:
[0073] 1. Data consistency requirements. In high-security network environments, frequent data changes can lead to discrepancies between data and reality in low-security network environments if data synchronization lags. Differences in data models between different network zones can also result in information loss.
[0074] 2. Data security requirements. When data flows in a network environment with security gradations, appropriate security control strategies must be followed.
[0075] 3. Technical challenges of data synchronization. Currently, there is no one-stop cross-environment CMDB data synchronization system or method that can securely and efficiently synchronize updated CMDB data in one network environment to CMDBs in other network environments.
[0076] In view of the above problems, embodiments of the present invention provide a method and system for cross-network data synchronization of a configuration management database. This method enables the synchronization of configuration management data from a first network environment to a second network environment. During the cross-network synchronization process, a security control policy is used to ensure compliance with the policy and prevent reverse contamination by dirty data.
[0077] In embodiments of the present invention, the security control strategy may include the following strategies:
[0078] A: Irrelevant and redundant data is prohibited in high-security network environments. High-security network environments contain configuration data specific to that level of security, but not configuration data specific to low-security network environments.
[0079] B: Data flowing from a high-security network environment to a low-security network environment needs to undergo data filtering and detection, and then flow under security protection.
[0080] C: Data must not be modified across network environments, and reverse pollution of dirty data must be avoided.
[0081] See Figure 1 This invention provides a network system 100 for implementing the methods described in this embodiment, including a first synchronization system 110 and a first configuration management database 120 located in a first network environment ID1, and a second synchronization system 130 and a second configuration management database 140 located in a second network environment ID2. The first synchronization system 110 corresponds to the first configuration management database 120, and the second synchronization system 130 corresponds to the second configuration management database 140. The security level information of the first network environment ID1 is different from that of the second network environment ID2. The first configuration management database 120 stores configuration management file information corresponding to various configurations of the IT infrastructure in the first network environment ID1.
[0082] In software development and operations scenarios, network environments are often divided into development, testing, and production environments, with security levels increasing sequentially. In some embodiments of this invention, operations personnel can configure the identifiers, security level information, and mutual security control policies of each network environment into the synchronization system of each network environment. For example, the security level information of the first network environment ID1 can be configured as SL_idA, and the security level information of the second network environment ID2 can be configured as SL_idB. SL_idA represents a security level of A, and SL_idB represents a security level of B. The security level represented by SL_idA is higher than that represented by SL_idB, with the network levels decreasing sequentially using English letters. Another example is configuring security control policies as follows: A. Configuration management file information in this network environment can only be synchronized across networks to network environments with a lower security level than this network environment; B. The security level information of the configuration management file information in this network environment cannot be lower than the security level information of this network environment.
[0083] In some embodiments of the present invention, the operation and maintenance personnel may also configure the information of the second synchronization system 130 in the associated second network environment ID2 in the first synchronization system 110, such as configuring the security level information of the network environment where the second synchronization system is located, and the address information of the second synchronization system 130, such as IP address information.
[0084] In some embodiments of the present invention, the first configuration management database 120 and the second configuration management database 140 may be non-relational databases. For example, in some embodiments, MongoDB may be used to store configuration management data. In some embodiments, the configuration management file information stores field information, including configuration unique identifier information, security level information, and configuration management data. The configuration unique identifier information is used to identify the configuration management file information, the security level information is used to identify the network environment at which the configuration management file information originates, and the configuration management data is used to store specific configuration data. For example, the format of the configuration management file information can be expressed as:
[0085] {"Config_ID":1234, / / Configure unique identifier information as 1234}
[0086] "Security_Level":SL_idA, / / Indicates that the security level is A.
[0087] "Config_Data":{"device_name":Server1,"ip_addresses":172.21,1.1} / / Configuration management data
[0088] }
[0089] In some embodiments of the present invention, based on the network system 100 described above, a method for cross-network synchronization of configuration management data is provided, such as... Figure 2 As shown, the synchronization method includes the following steps:
[0090] S210: The first synchronization system 110 acquires a cross-network synchronization task for configuration management data. The information in the cross-network synchronization task for configuration management data includes information about the source configuration management database, information about the target configuration management database, and information about the configuration management files to be synchronized. The source configuration management database is the first configuration management database, and the target configuration management database includes the second configuration management database.
[0091] In some embodiments of the present invention, the first synchronization system 110 monitors change events in the first configuration management database and generates a cross-network synchronization task for configuration management data, such as... Figure 3a As shown, step S210 includes:
[0092] S211a: In response to a change in the configuration management file in the first configuration management database, the first synchronization system 110 obtains information from the pre-associated second configuration management database and the configuration management file information to be synchronized.
[0093] S212a: The first synchronization system 110 generates a cross-network synchronization task for configuration management data, wherein the configuration management file information to be synchronized includes the configuration management file information that has been changed in the first configuration management database.
[0094] In some embodiments of the present invention, the first synchronization system 110 has a configuration data acquisition function. When the IT infrastructure configuration information in the first network environment ID1 is changed, the first synchronization system 110 acquires and generates configuration management file information according to a preset data model and stores it in the first configuration management database.
[0095] In some embodiments of the present invention, the first synchronization system 110 may also generate a cross-network synchronization task for configuration management data based on a timed full synchronization task, such as... Figure 3b As shown, step S210 includes:
[0096] S211b: The first synchronization system 110 responds to receiving a full cross-network synchronization task triggered at a predetermined time interval by obtaining information of the preset associated second configuration management database and configuration management file information to be synchronized.
[0097] S212b: The first synchronization system 110 generates a cross-network synchronization task for configuration management data, wherein the configuration management file information to be synchronized includes the full configuration management file information in the first configuration management database.
[0098] In embodiments of the present invention, the first synchronization system 110 uses the information of the first configuration management data as the information of the source configuration management database in the cross-network synchronization task of configuration management data, and uses the information of one or more second configuration management data as the information of the target configuration management data in the cross-network synchronization task of configuration management data. In some embodiments, the target configuration management database may include multiple configuration management databases, that is, the first synchronization system 110 can simultaneously send configuration management file information to be synchronized to multiple second synchronization systems.
[0099] In some embodiments of the present invention, the information of the second configuration management database can be pre-configured into the first synchronization system 110. In some embodiments, the information of the second configuration management database includes the address of the second synchronization system 130. Since the second synchronization system 130 corresponds to the second configuration management database 140, data can be synchronized to the second configuration management database 140 through the second synchronization system 130. The first synchronization system 110 subsequently sends information to the second synchronization system 130 through the address information of the second synchronization system 130. In some embodiments of the present invention, the predetermined time interval can be one month or one quarter.
[0100] S220: The first synchronization system 110 determines whether the information in the source configuration management database and the information in the target configuration management database conform to a preset secure transmission policy. In some embodiments of the present invention, the preset secure transmission policy is pre-configured in the first synchronization system 110. In some embodiments, the preset secure transmission policy is: configuration management file information in this network environment can only be synchronized across networks to network environments with a lower security level than this network environment.
[0101] In some embodiments of the present invention, in high-security areas (such as core production networks and classified networks), the presence of any unnecessary data will expand the attack surface and increase the risk of exploitation. In high-security network environments, configuration data from low-security network environments will not be used. It should be ensured that configuration data from low-security network environments cannot be transmitted to high-security network environments. A preset secure transmission strategy ensures that configuration management file information can only be synchronized from high-security network environments to low-security network environments, thus preventing the synchronization of low-security configuration management file information to high-security network environments.
[0102] In some embodiments of the present invention, the information in the source configuration management database includes security level information of a first network environment, and the information in the target configuration management database includes security level information of a second network environment; such as Figure 4 As shown, step S220 includes:
[0103] S221: The first synchronization system 110 acquires the security level information of the first network environment and the security level information of the second network environment. In this embodiment of the invention, the security level information of the first network environment and the security level information of the second network environment are pre-configured in the first synchronization system 110.
[0104] S222: When the first synchronization system 110 determines that the security level information of the first network environment is higher than the security level information of the second network environment, it instructs the information of the source configuration management database and the information of the target configuration management database to conform to the preset security transmission strategy.
[0105] S223: The first synchronization system 110 determines that when the security level information of the first network environment is lower than the security level information of the second network environment, it instructs that the information of the source configuration management database and the information of the target configuration management database do not conform to the preset security transmission strategy.
[0106] For example, when the security level information of the first network environment ID1 is SL_idA and the security level information of the second network environment ID2 is SL_idB, since the security level information represented by SL_idA is higher than the security level information represented by SL_idB, the information in the source configuration management database and the information in the target configuration management database conform to the preset security transmission policy.
[0107] For example, when the security level information of the first network environment ID1 is SL_idB and the security level information of the second network environment ID2 is SL_idA, since the security level information represented by SL_idB is lower than the security level information represented by SL_idA, the information in the source configuration management database and the information in the target configuration management database do not conform to the preset security transmission policy.
[0108] S230: The first synchronization system 110, in response to the information in the source configuration management database and the information in the target configuration management database conforming to the preset security transmission policy, sends the configuration management file information to be synchronized to the second synchronization system.
[0109] In some embodiments of the present invention, the information in the target configuration management database also includes the address of the second synchronization system; such as Figure 5 As shown, step S230 includes:
[0110] S231: The first synchronization system 110 generates a first digest value based on the configuration management file information to be synchronized. In some embodiments of the present invention, a hash algorithm may be used to generate the first digest value.
[0111] S232: Encrypt the configuration management file information to be synchronized and the first digest value to generate encrypted configuration management file information to be synchronized.
[0112] S233: Based on the address of the second synchronization system, send the encrypted configuration management file information to be synchronized to the second synchronization system.
[0113] Since configuration management files often contain sensitive information, this embodiment of the invention uses encrypted transmission and digest verification to prevent the leakage or tampering of sensitive information. Subsequently, after receiving the configuration management file information to be synchronized, the second synchronization system 130 decrypts it and performs digest verification, which verifies whether the information has been leaked or tampered with, thus improving data security.
[0114] In some embodiments of the present invention, since the configuration information of the network environment or infrastructure changes frequently, changes occur in the first configuration management database 120 over time. In order to ensure that the configuration management file information synchronized to the target configuration management database is consistent with the file information in the source configuration management database, in this embodiment of the present invention, the order in which the first synchronization system 110 sends the configuration management file information to be synchronized to the second synchronization system 130 is consistent with the change order of the configuration management file information in the first configuration management database 120.
[0115] In some embodiments of the present invention, the file naming of the configuration management file information includes timestamp information when the configuration management data cross-network synchronization task is generated; step S233 includes:
[0116] The first synchronization system 110 sends the encrypted configuration management file information to be synchronized to the second synchronization system in the order of timestamp information.
[0117] In an embodiment of the present invention, the configuration management file information in the first configuration management database 120 is stored according to the format in the configuration management database. To facilitate the separate transmission of a specific configuration management file, when generating a cross-network data synchronization task, the first synchronization system 110 also adjusts the format of the configuration management file information in the first configuration management database 120 according to the data transmission protocol, generates a separate file, and names the file according to the timestamp information. When sending the configuration management file information to be synchronized in the specified file format, the first synchronization system 110 sends it according to the order of the timestamps in the file name, ensuring that the sending order is consistent with the task generation order. This ensures that the subsequent import order by the second synchronization system 130 is consistent with the task generation order, achieving data consistency during the cross-network synchronization of configuration management file information.
[0118] S240: The second synchronization system 130 obtains the configuration management file information to be synchronized.
[0119] In some embodiments of the present invention, to ensure the security of configuration management file information transmission, the file information is encrypted during transmission, and its integrity is verified based on the digest value. For example... Figure 6As shown, step S240 includes:
[0120] S241: The second synchronization system 130 receives the encrypted configuration management file information to be synchronized sent by the first synchronization system 110.
[0121] S242: The second synchronization system 130 decrypts the encrypted configuration management file information to be synchronized and obtains the decrypted configuration management file information to be synchronized and the first digest value.
[0122] S243: The second synchronization system 130 generates a second digest value based on the decrypted configuration management file information to be synchronized.
[0123] S244: The second synchronization system 130 determines that if the first digest value and the second digest value are consistent, the decrypted configuration management file information to be synchronized will be used as the configuration management file information to be synchronized. If the determination is consistent, the data is verified to have not been tampered with.
[0124] S250: The second synchronization system 130 determines whether the configuration management file information to be synchronized conforms to the preset security import policy. In some embodiments of the present invention, the operation and maintenance personnel pre-configure the preset security import policy into the second synchronization system 130. In some embodiments, the preset security import policy is: the security level information of the configuration management file information in this network environment cannot be lower than the security level information of this network environment. In order to maintain the authority and consistency of data in a high-security environment and avoid configuration drift or malicious tampering caused by operations in a low-security environment, when the security level information of the sent configuration management file information is lower than the security level of this network, it is rejected for import, thereby avoiding data pollution.
[0125] In some embodiments of the present invention, configuration management file information includes configuration unique identifier information, security level information, and configuration management data; such as Figure 7 As shown, step S250 includes:
[0126] S251: The second synchronization system 130 obtains the security level information of the second network environment ID2.
[0127] S252: The second synchronization system 130 determines that when the security level of the configuration management file information to be synchronized is higher than the security level of the second network environment, it instructs the configuration management file information to be synchronized to conform to the preset security import strategy.
[0128] S253: The second synchronization system 130 determines that when the security level of the configuration management file information to be synchronized is lower than the security level of the second network environment, it indicates that the configuration management file information to be synchronized does not conform to the preset security import strategy.
[0129] For example, if the security level information of the second network environment ID2 is SL_idB, and the security level information of the configuration management file information to be synchronized is SL_idA, then the security level information of the configuration management file information to be synchronized is higher than the security level information of the second network environment ID2, and the configuration management file information to be synchronized conforms to the preset security import policy.
[0130] For example, if the security level information of the second network environment ID2 is SL_idA, and the security level information of the configuration management file information to be synchronized is SL_idB, then the security level information of the configuration management file information to be synchronized is lower than the security level information of the second network environment ID2, and therefore the configuration management file information to be synchronized does not conform to the preset security import policy.
[0131] In some embodiments of the present invention, the first network environment ID1 can be a production environment, and the second network environment can be a test environment. The security level of the production environment is higher than that of the test environment. Generally, the first synchronization system 110 synchronizes the configuration management file information in the production environment to the second synchronization system 130. In some embodiments of the present invention, the first synchronization system 110 can not only synchronize the configuration information of the devices in the first network environment ID1 to the second synchronization system 130, but also synchronize configuration management data obtained from other network environments to the second synchronization system 130. In some embodiments, if the network environment is divided into multiple types, for example, into a development environment, a test environment, and a production environment, the first network environment ID1 is a test environment, the second network environment ID2 is a development environment, and the first network environment ID1 also stores configuration management file information synchronized from the production environment, that is, the security level information of the second network environment ID2 is SL_idC, and the security level information of the configuration management file information to be synchronized is SL_idA, then the security level information of the configuration management file information to be synchronized is higher than the security level information SL_idB of the second network environment ID2, and the configuration management file information to be synchronized conforms to the preset security import strategy.
[0132] S260: The second synchronization system 130 imports the configuration management file information to be synchronized into the second configuration management database 140.
[0133] In some embodiments of the present invention, since the configuration management file information to be synchronized can be a converted file format, directly importing it into the second configuration management data 140 will cause inconsistencies in data format versions. In some embodiments, the second synchronization system 130 also performs format conversion on the configuration management file information to be synchronized so as to make it consistent with the information format in the second configuration management database. For example, the configuration management file information to be synchronized is converted into JSON-like format information and stored in the second configuration management database 140.
[0134] In some embodiments of the present invention, the first synchronization system 110 triggers a cross-network data synchronization task based on changes in configuration items. After receiving the configuration management file information to be synchronized, the second synchronization system 130 will overwrite the configuration management file information of the same configuration type in the second configuration management database 140, thus maintaining data consistency. Figure 8 As shown, step S260 includes:
[0135] S261: The second synchronization system 130 responds to the existence of a target configuration management file information in the second configuration management database 140 that matches the configuration unique identifier information of the configuration management file information to be synchronized.
[0136] S262: The second synchronization system 130 replaces the target configuration management file information with the configuration management file information to be synchronized.
[0137] For example, the configuration management file information in the second configuration management database 140 is as follows:
[0138] {“Config_ID”:1211,
[0139] "Security_Level":SL_idA,
[0140] "Config_Data":{"device_name":Server1,"ip_addresss":172.21,1.1}
[0141] }
[0142] The configuration management file information to be synchronized is as follows:
[0143] {“Config_ID”:1211,
[0144] "Security_Level":SL_idA,
[0145] "Config_Data":{"device_name":Server1,"ip_addresss":172.21,1.10}
[0146] }
[0147] Then the configuration management file information in the second configuration management database 140 is replaced with:
[0148] {“Config_ID”:1211,
[0149] "Security_Level":SL_idA,
[0150] "Config_Data":{"device_name":Server1,"ip_addresss":172.21,1.10}
[0151] }
[0152] In some embodiments of the present invention, in order to avoid data corruption, the first synchronization system 110 and the second synchronization system 120 also perform data corruption detection on the configuration management file information in the corresponding configuration management database. For example, the first synchronization system 110 obtains the security level information of the first network environment and the configuration management file information in the first configuration management database 120; in response to the fact that the security level information in the configuration management file information is lower than the security level information of the first network environment, the first synchronization system 110 deletes the configuration management file information.
[0153] For example, if the security level information of the first network environment is SL_idB, when the first synchronization system 110 detects that the security level information of the configuration management file information in the first configuration management database 120 is SL_idC, it deletes that configuration management file information; when the first synchronization system 110 detects that the security level information of the configuration management file information in the first configuration management database 120 is SL_idA, it retains that configuration management file information. Regularly monitoring for polluted data can reduce the security risks to the database.
[0154] In some embodiments of the present invention, after the second synchronization system 130 imports the configuration management file information to be synchronized, it retains its original security level information.
[0155] In the system and method of this invention, during the process of the first synchronization system 110 synchronizing configuration management data across networks to the second synchronization system 130, a preset security control strategy is detected to ensure the directionality of data synchronization, control the synchronization direction, and avoid the problem of data pollution.
[0156] From a computer network implementation perspective, other embodiments of the present invention also provide a method and system for cross-network data synchronization in CMDB, such as... Figure 9 As shown, the data synchronization system 300 mainly includes a standardization module 310, a data acquisition module 320, a data storage module 330, a data processing module 340, a security protection module 350, and a data exchange module 360.
[0157] The method by which this system 300 achieves cross-network synchronization of CMDB data is as follows:
[0158] The first step is to initialize and standardize the data transmission strategy (as an example of a preset secure transmission strategy and a preset secure import strategy), the network environment and its security level through the standardization module, and establish a baseline and corresponding standards.
[0159] The second step involves acquiring configuration items and related data through the data acquisition module based on the data model built in the CMDB, and then updating the collected configuration data to the CMDB in this network environment through the data storage module.
[0160] The third step involves determining whether the updated configuration data needs to be synchronized to other network environments based on the security level and data transmission policy obtained from the standardization module during initialization and updates. If synchronizing the updated configuration data to other network environments complies with the data transmission policy, proceed to the next step; otherwise, end the synchronization process.
[0161] The fourth step is to obtain the changed configuration data in the CMDB through the data processing module and convert the configuration data into a JSON format configuration file.
[0162] The fifth step involves encrypting the file using a security protection module and hashing the encrypted data to verify the file's integrity.
[0163] The sixth step is to synchronize the configuration files through the data exchange module.
[0164] The seventh step involves the security module decrypting the received configuration file into configuration data and verifying its integrity. If the data matches, proceed to the next step; otherwise, the data exchange module controls data retransmission.
[0165] Step 8: Push the configuration items that need to be updated to the data storage module through the data processing module, and update the configuration data to the CMDB.
[0166] The architecture of system 300 in this embodiment of the invention is as follows: Figure 10 As shown, the front-end presentation layer provides the core interface for users to interact with the CMDB cross-network data synchronization system. The business logic layer handles user requests, processes related core business logic, and executes corresponding business tasks. The business logic layer includes standardized modules, data acquisition modules, data storage modules, data processing modules, and capabilities covering historical records and exception handling for CMDB data synchronization. The security layer ensures the confidentiality and integrity of data through end-to-end encryption, integrity verification, and sensitive information auditing in the security protection module, thereby ensuring the security of the CMDB cross-network data synchronization system. The data transmission layer is responsible for the cross-network transmission of CMDB data, realizing the acquisition, synchronization, and distribution of multi-source data, and ensuring the real-time performance and consistency of data flow through the data exchange module.
[0167] The functional modules of system 300 in this embodiment of the invention are described as follows:
[0168] The standardization module 310 is used to determine the data transmission policy, and to perform initialization and standardization functions such as setting the identifier ID of the network environment and setting its security level (Security_Level).
[0169] The data acquisition module 320 is used to collect and integrate configuration data of IT assets (such as servers, network devices, applications and dependencies) in real time through automated tools (such as agents, SSH, APIs, etc.), and pushes the collected raw data to the data storage module after data processing, ensuring the real-time performance and accuracy of the data.
[0170] The data storage module 330 is responsible for the centralized management of configuration items (CI) and related information. It performs single or batch additions, deletions, and updates of configuration information in the CMDB, and centrally stores information on all configuration items (such as servers, network devices, software, and services) in the IT environment. This module provides fundamental data support for IT Service Management (ITSM).
[0171] The data processing module 340 is used to acquire changed configuration data, convert the data format into a standardized structure, and perform reverse pollution control for dirty data. The data processing module is a core component ensuring the availability, accuracy, and consistency of configuration data.
[0172] The security protection module 350 is responsible for end-to-end encryption of the data to be transmitted, ensuring that the data is not stolen or tampered with during transmission through encryption technology. Secondly, this module uses a hash algorithm to verify the integrity of the transmitted data. Furthermore, in a network-isolated environment, by interfacing with the data exchange module, it enables the filtering and transmission control of sensitive information.
[0173] The data exchange module 360 enables the directed flow of data between two CMDBs in a network-isolated environment, as well as handling anomalies such as data retransmission. This module is the core hub for realizing the dynamic flow of configuration data. Encrypted communication is used to prevent data leakage.
[0174] In this embodiment of the invention, the CMDB of each security level network environment needs to be initialized before synchronization, such as... Figure 11 As shown, the specific process is as follows:
[0175] S410: Use standardized modules to determine the data transmission policy and preset the network environment ID and security level (Security_Level).
[0176] 1. Develop a data transmission strategy (Policy{policy1,policy2,...}) for cross-network synchronization of CMDB data, and use standardized modules to determine the data transmission strategy.
[0177] Cross-network data transmission of CMDB must adhere to the principle of "matching data with security levels and isolating data based on security level differences." The specific policy is as follows:
[0178] Policy 1: Irrelevant and redundant data is prohibited in high-security network environments. High-security network environments contain configuration data specific to that level of security, but not configuration data specific to low-security network environments.
[0179] Policy 2: Data flowing from a high-security network environment to a low-security network environment must undergo data filtering and detection, and be transferred under security protection.
[0180] Policy 3: Data is prohibited from being modified across network environments, while also preventing the reverse contamination of dirty data.
[0181] 2. Determine the Security Level (Security_Level) for each network environment. Each network environment has a unique identifier (ID) to distinguish its security level (Security_Level{SL_id1,SL_id2,...}). Network environments are sorted alphabetically according to their security level, decreasing from the highest level. For example, high-security-level networks are assigned Level A, medium-security-level networks are assigned Level B, low-security-level networks are assigned Level C, and so on. Initialize the network environment security levels in the CMDB cross-network synchronization system. After determining the network environment security levels, record the levels using a standardized module. This article uses CMDB data synchronization between high-security-level A and low-security-level B as an example.
[0182] S420: In each network environment, configuration item data is acquired through the data acquisition module, and stored in MongoDB through the data storage module, with the Security_Level set. CMDB uses MongoDB for underlying data storage. In network environments of different levels, configuration item-related data is acquired through the data acquisition module, and the data storage module stores this data as documents in a JSON-like format. In the IDn network environment, a field named "Security_Level" is set in each document, and its value is set to SL_idn.
[0183] In this embodiment of the invention, the specific process for CMDB data synchronization in a multi-network environment is as follows:
[0184] 1. When data changes occur in the CMDB, such as addition, update, or deletion, the data storage module processes the data in the CMDB, including but not limited to single or batch insertion, update, replacement, and deletion of documents. The documents are stored in the collection in BSON format.
[0185] 2. When the configuration data in the IDX network environment is updated, it is necessary to determine the relationship between the security level of the IDX network environment and the security level of other network environments.
[0186] 3. Execute the corresponding data transmission policy (Policy{policy1,policy2,...}) according to the security level tier.
[0187] The following uses ID1 and ID2 network environments as examples to introduce the specific process of data synchronization, such as... Figure 12 As shown, the process includes the following steps.
[0188] S510: When CMDB data changes in the ID1 network environment, the configuration item "document" in that environment can be inserted, updated, replaced, or deleted individually or in batches through the data storage module. The document is stored in the collection in BSON format.
[0189] S520: Determine whether the security level of environment ID1 is greater than that of environment ID2.
[0190] 1. When the security level of ID1 is lower than that of ID2, according to policy1, CMDB data in the ID1 environment should not be synchronized to the ID2 environment.
[0191] 2. When the security level of ID1 is greater than that of ID2, according to policy2, the CMDB data in the ID1 environment should be synchronized to the ID2 environment.
[0192] S530: In the ID1 environment, the data processing module processes data, retrieves configuration items and other data from the CMDB, and outputs them in JSON format. When the CMDB data in the ID1 network environment changes, the data processing module pulls the changed configuration item data, i.e., the changed configuration item document, and uses mongoexport to output the document in JSON format as a JSON file named File_timestamp (where timestamp is timestamp information).
[0193] S540: In the ID1 environment, the security protection module calculates the hash value HASH_File_timestamp_ID1 of the JSON file, and encrypts HASH_File_timestamp_ID1 together with the File_timestamp file to generate File_ID1_ID2. Because the configuration data is sensitive information, the security protection module encrypts this data, verifies its integrity using a hash algorithm, and encrypts the file to be transmitted and the hash value to generate File_ID1_ID2.
[0194] S550: Through the data exchange module, the File_ID1_ID2 file in the ID1 environment is exchanged to the ID2 environment.
[0195] S560: In an ID2 network environment, the security protection module decrypts the file to be transmitted and calculates the hash value HASH_File_timestamp_ID2 of the JSON file.
[0196] S570: Determine if HASH_File_timestamp_ID1 is equal to HASH_File_timestamp_ID2. If HASH_File_timestamp_ID1 and HASH_File_timestamp_ID2 are the same, then the data integrity can be proven.
[0197] S580: If consistent, in the ID2 network environment, the configuration item data that needs to be synchronized is pushed through the data processing module, verifying whether the value of field "Network_domain" (security level information) is higher than the value of "Network_domain" in this environment. If it conforms to the security policy configured in the standardization module, the configuration item that needs to be updated is pushed to the data storage module, and the JSON file is imported into MongoDB using mongoimport, thereby achieving data synchronization.
[0198] S590: If there is a discrepancy, the data exchange module controls the data retransmission.
[0199] This invention provides a one-stop solution for solving CMDB data synchronization problems in different network environments; it automatically synchronizes data, thereby ensuring data efficiency and consistency without waiting for manual intervention or relying on experience; it meets security control requirements and allows for the setting of data transmission strategies, thereby ensuring data security.
[0200] like Figure 13This invention also provides a cross-network data synchronization device 600 for a configuration management database, applied to a first synchronization system corresponding to the first configuration management database. The first configuration management database and the first synchronization system are located in a first network environment. The first configuration management database stores configuration management file information corresponding to various configurations. The device 600 includes a synchronization task acquisition module 610, a security judgment module 620, and a sending module 630.
[0201] The synchronization task acquisition module 610 is configured to acquire cross-network synchronization tasks for configuration management data. The information in the cross-network synchronization task for configuration management data includes information about the source configuration management database, information about the target configuration management database, and information about the configuration management files to be synchronized. The source configuration management database is a first configuration management database, and the target configuration management database includes a second configuration management database. The second configuration management database is located in a second network environment, and a second synchronization system corresponding to the second configuration management database is also configured in the second network environment. The security level information of the first network environment is different from that of the second network environment.
[0202] The security judgment module 620 is configured to determine whether the information in the source configuration management database and the information in the target configuration management database conform to the preset security transmission policy;
[0203] The sending module 630 is configured to send configuration management file information to be synchronized to the second synchronization system in response to the information in the source configuration management database and the information in the target configuration management database conforming to the preset security sending policy. This enables the second synchronization system to import the configuration management file information to be synchronized into the second configuration management database after determining that the information conforms to the security import policy.
[0204] In some embodiments of the present invention, the synchronization task acquisition module 610 is further configured to...
[0205] In response to changes in configuration management files in the first configuration management database, or in response to receiving a full cross-network synchronization task triggered at a predetermined time interval, information of the pre-associated second configuration management database and configuration management file information to be synchronized are obtained.
[0206] Generate a cross-network synchronization task for configuration management data. The configuration management file information to be synchronized includes the changed configuration management file information in the first configuration management database, or the full configuration management file information in the first configuration management database.
[0207] In some embodiments of the present invention, the configuration management file information includes configuration unique identifier information, security level information, and configuration management data.
[0208] In some embodiments of the present invention, a dirty data clearing module 640 is also included, configured as follows:
[0209] Obtain the security level information of the first network environment and the configuration management file information in the first configuration management database; in response to the fact that the security level information in the configuration management file information is lower than the security level information of the first network environment, delete the configuration management file information.
[0210] In some embodiments of the present invention, the information in the source configuration management database includes security level information of a first network environment, and the information in the target configuration management database includes security level information of a second network environment; the security judgment module 620 is configured as follows:
[0211] When the security level information of the first network environment is higher than that of the second network environment, the information in the source configuration management database and the information in the target configuration management database conform to the preset security transmission policy.
[0212] When the security level information of the first network environment is lower than that of the second network environment, the information in the source configuration management database and the information in the target configuration management database do not conform to the preset security transmission policy.
[0213] In some embodiments of the present invention, the information in the target configuration management database also includes the address of the second synchronization system; the sending module 630 is configured as follows:
[0214] Generate a first digest value based on the configuration management file information to be synchronized;
[0215] The configuration management file information to be synchronized and the first digest value are encrypted to generate encrypted configuration management file information to be synchronized.
[0216] Based on the address of the second synchronization system, send the encrypted configuration management file information to be synchronized to the second synchronization system.
[0217] In some embodiments of the present invention, the sending module 630 is further configured to send encrypted configuration management file information to be synchronized to the second synchronization system in the order of timestamp information.
[0218] like Figure 14 This invention also provides a cross-network data synchronization device 700 for a configuration management database, applied to a second synchronization system corresponding to the second configuration management database. The second configuration management database and the second synchronization system are located in a second network environment. The second configuration management database stores configuration management file information. The device 700 includes a configuration management file information acquisition module 710, a security judgment module 720, and an import module 730.
[0219] The configuration management file information acquisition module 710 is configured to acquire configuration management file information to be synchronized sent by the first synchronization system. The first synchronization system corresponds to the first configuration management database. The first synchronization system and the first configuration management database are in a first network environment. The security level information of the first network environment is different from that of the second network environment.
[0220] The security judgment module 720 is configured to determine whether the configuration management file information to be synchronized conforms to the preset security import strategy;
[0221] Import module configuration 730 imports the configuration management file information to be synchronized into the second configuration management database in response to the configuration management file information to be synchronized conforming to the preset security import policy.
[0222] In some embodiments of the present invention, the configuration management file information includes configuration unique identifier information, security level information, and configuration management data; the security judgment module 720 is configured as follows:
[0223] Obtain security level information for the second network environment;
[0224] When the security level of the configuration management file information to be synchronized is higher than the security level of the second network environment, the configuration management file information to be synchronized is indicated to conform to the preset security import policy.
[0225] When the security level of the configuration management file information to be synchronized is lower than the security level of the second network environment, it indicates that the configuration management file information to be synchronized does not conform to the preset security import policy.
[0226] In some embodiments of the present invention, the configuration management file information acquisition module 710 is configured as follows:
[0227] Receive encrypted configuration management file information to be synchronized from the first synchronization system;
[0228] Decrypt the encrypted configuration management file information to be synchronized to obtain the decrypted configuration management file information to be synchronized and the first digest value;
[0229] Generate a second digest value based on the decrypted configuration management file information to be synchronized;
[0230] When the first digest value matches the second digest value, the decrypted configuration management file information to be synchronized will be used as the configuration management file information to be synchronized.
[0231] In some embodiments of the present invention, the import module 730 is further configured as follows:
[0232] In response to the existence of a target configuration management file in the second configuration management database that has the same configuration unique identifier as the configuration management file information to be synchronized;
[0233] Replace the target configuration management file information with the configuration management file information to be synchronized.
[0234] The features of the apparatus and system in the embodiments of the present invention can be referenced to the features of the methods and steps in the embodiments of the present invention, and the system embodiments can be combined with the features of the method embodiments to obtain new embodiments, and vice versa, and will not be repeated here.
[0235] An embodiment of the present invention provides an electronic device comprising: a processor and a memory storing a computer program, the processor being configured to implement any method according to an embodiment of the present invention when running the computer program. Additionally, means for implementing an embodiment of the present invention may also be provided.
[0236] Figure 15 An exemplary system architecture 1500 is shown for a system to which the methods of embodiments of the present invention can be applied.
[0237] like Figure 15 As shown, system architecture 1500 may include terminal devices 1501, 1502, and 1503, network 1504, and server 1505. Network 1504 is used as a medium to provide a communication link between terminal devices 1501, 1502, and 1503 and server 1505. Network 1504 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.
[0238] Users can use terminal devices 1501, 1502, and 1503 to interact with server 1505 via network 1504 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 1501, 1502, and 1503, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0239] Terminal devices 1501, 1502, and 1503 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0240] Server 1505 can be a server that provides various services, such as a backend management server that supports shopping websites browsed by users using terminal devices 1501, 1502, and 1503 (for example only). The backend management server can analyze and process data such as received product information query requests, and feed back the processing results (such as target push information and product information - for example only) to the terminal devices.
[0241] It should be noted that the cross-network data synchronization method for configuration management database provided in this embodiment of the invention is generally executed by server 1505, and correspondingly, the implementation device for cross-network data synchronization of configuration management database is generally set in server 1505.
[0242] It should be understood that Figure 15 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0243] The following is for reference. Figure 16 It shows a schematic diagram of the structure of a computer system 1600 suitable for implementing terminal devices or servers of the present invention. The methods or apparatus for implementing the methods in the embodiments of the present invention can be implemented on the computer system 1600. Figure 12 The terminal device or server shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present invention.
[0244] like Figure 16 As shown, the computer system 1600 includes a central processing unit (CPU) 1601, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 1602 or programs loaded from storage portion 1608 into random access memory (RAM) 1603. The RAM 1603 also stores various programs and data required for the operation of the system 1600. The CPU 1601, ROM 1602, and RAM 1603 are interconnected via a bus 1604. An input / output (I / O) interface 1605 is also connected to the bus 1604.
[0245] The following components are connected to I / O interface 1605: an input section 1606 including a keyboard, mouse, etc.; an output section 1607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1608 including a hard disk, etc.; and a communication section 1609 including a network interface card such as a LAN card, modem, etc. The communication section 1609 performs communication processing via a network such as the Internet. A drive 1610 is also connected to I / O interface 1605 as needed. Removable media 1611, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 1610 as needed so that computer programs read from them can be installed into storage section 1608 as needed.
[0246] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1609, and / or installed from removable medium 1611. When the computer program is executed by central processing unit (CPU) 1601, it performs the functions defined above in the system of this invention.
[0247] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0248] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0249] The units or modules described in the embodiments of the present invention can be implemented in software or hardware. The described units or modules can also be housed in a processor; for example, a processor can be described as including a sending unit (or "module"), an acquisition unit, a determining unit, and a first processing unit. The names of these units or modules do not necessarily limit the specific unit or module itself; for example, a sending unit can also be described as "a unit that sends an image acquisition request to a connected server."
[0250] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to perform the cross-network data synchronization method for the configuration management database described in the above embodiments.
[0251] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for cross-network data synchronization of a configuration management database, characterized in that, The method is applied to a first synchronization system corresponding to a first configuration management database, wherein the first configuration management database and the first synchronization system are located in a first network environment, and the first configuration database stores configuration management file information corresponding to various configurations. The method includes the following steps: A cross-network synchronization task for configuration management data is obtained. The information in the cross-network synchronization task for configuration management data includes information about the source configuration management database, information about the target configuration management database, and information about the configuration management files to be synchronized. The source configuration management database is the first configuration management database, and the target configuration management database includes a second configuration management database. The second configuration management database is located in a second network environment, and a second synchronization system corresponding to the second configuration management database is also configured in the second network environment. The security level information of the first network environment is different from the security level information of the second network environment. Determine whether the information in the source configuration management database and the information in the target configuration management database conform to a preset secure transmission policy; In response to the information in the source configuration management database and the information in the target configuration management database conforming to the preset security transmission policy, the configuration management file information to be synchronized is sent to the second synchronization system, so that the second synchronization system determines that the configuration management file information to be synchronized conforms to the preset security import policy and then imports the configuration management file information to be synchronized into the second configuration management database.
2. The method according to claim 1, characterized in that, The cross-network synchronization task for obtaining configuration management data includes: In response to a change in the configuration management file in the first configuration management database, or in response to receiving a full cross-network synchronization task triggered at a predetermined time interval, information of the pre-associated second configuration management database and the configuration management file information to be synchronized are obtained. Generate the cross-network synchronization task for the configuration management data, wherein the configuration management file information to be synchronized includes the changed configuration management file information in the first configuration management database, or the full configuration management file information in the first configuration management database.
3. The method according to claim 1, characterized in that, The configuration management file information includes configuration unique identifier information, security level information, and configuration management data.
4. The method according to claim 3, characterized in that, The method further includes: Obtain the security level information of the first network environment and the configuration management file information in the first configuration management database; When the security level information in the configuration management file is lower than the security level information of the first network environment, the configuration management file information is deleted.
5. The method according to claim 1, characterized in that, The information in the source configuration management database includes the security level information of the first network environment, and the information in the target configuration management database includes the security level information of the second network environment; The step of determining whether the information in the source configuration management database and the information in the target configuration management database conform to the preset secure transmission policy includes: When the security level information of the first network environment is higher than that of the second network environment, it indicates that the information of the source configuration management database and the information of the target configuration management database conform to the preset security transmission policy; When the security level information of the first network environment is lower than that of the second network environment, it indicates that the information in the source configuration management database and the information in the target configuration management database do not conform to the preset secure transmission policy.
6. The method according to any one of claims 1 to 5, characterized in that, The target configuration management database information also includes the address of the second synchronization system; sending the configuration management file information to be synchronized to the second synchronization system includes: Generate a first digest value based on the configuration management file information to be synchronized; The configuration management file information to be synchronized and the first digest value are encrypted to generate encrypted configuration management file information to be synchronized. Based on the address of the second synchronization system, the encrypted configuration management file information to be synchronized is sent to the second synchronization system.
7. The method according to claim 6, characterized in that, The file name of the configuration management file information includes the timestamp information when the cross-network synchronization task of the configuration management data was generated; sending the encrypted configuration management file information to be synchronized to the second synchronization system includes: According to the order of the timestamp information, the encrypted configuration management file information to be synchronized is sent to the second synchronization system.
8. A method for cross-network data synchronization of a configuration management database, characterized in that, The method is applied to a second synchronization system corresponding to a second configuration management database, wherein the second configuration management database and the second synchronization system are located in a second network environment, and the second configuration management database stores configuration management file information. The method includes the following steps: Obtain the configuration management file information to be synchronized sent by the first synchronization system, wherein the first synchronization system corresponds to the first configuration management database, the first synchronization system and the first configuration management database are in a first network environment, and the security level information of the first network environment is different from the security level information of the second network environment; Determine whether the configuration management file information to be synchronized conforms to the preset security import policy; When the configuration management file information to be synchronized meets the preset security import policy, the configuration management file information to be synchronized is imported into the second configuration management database.
9. The method according to claim 8, characterized in that, The configuration management file information includes unique configuration identifier information, security level information, and configuration management data; Determining whether the configuration management file information to be synchronized conforms to the preset security import policy includes: Obtain security level information for the second network environment; When the security level of the configuration management file information to be synchronized is higher than the security level of the second network environment, the configuration management file information to be synchronized is indicated to conform to the preset security import strategy; When the security level of the configuration management file information to be synchronized is lower than the security level of the second network environment, it indicates that the configuration management file information to be synchronized does not conform to the preset security import strategy.
10. The method according to claim 8, characterized in that, The step of obtaining the configuration management file information to be synchronized sent by the first synchronization system includes: Receive the encrypted configuration management file information to be synchronized sent by the first synchronization system; The encrypted configuration management file information to be synchronized is decrypted to obtain the decrypted configuration management file information to be synchronized and the first digest value; Based on the decrypted configuration management file information to be synchronized, a second digest value is generated; When the first digest value matches the second digest value, the decrypted configuration management file information to be synchronized is used as the configuration management file information to be synchronized.
11. The method according to claim 9, characterized in that, The step of importing the configuration management file information to be synchronized into the second configuration management database includes: In response to the existence of a target configuration management file in the second configuration management database that matches the configuration unique identifier of the configuration management file information to be synchronized; Replace the target configuration management file information with the configuration management file information to be synchronized.
12. A cross-network data synchronization device for a configuration management database, characterized in that, The device is applied to a first synchronization system corresponding to a first configuration management database. The first configuration management database and the first synchronization system are located in a first network environment. The first configuration management database stores configuration management file information corresponding to various configurations. The device includes a synchronization task acquisition module, a security judgment module, and a sending module. The synchronization task acquisition module is configured to acquire a cross-network synchronization task for configuration management data. The information in the cross-network synchronization task for configuration management data includes information about the source configuration management database, information about the target configuration management database, and information about the configuration management file to be synchronized. The source configuration management database is the first configuration management database, and the target configuration management database includes a second configuration management database. The second configuration management database is located in a second network environment, and a second synchronization system corresponding to the second configuration management database is also configured in the second network environment. The security level information of the first network environment is different from the security level information of the second network environment. The security judgment module is configured to determine whether the information in the source configuration management database and the information in the target configuration management database conform to a preset security transmission policy. The sending module is configured to send the configuration management file information to be synchronized to the second synchronization system in response to the information of the source configuration management database and the information of the target configuration management database conforming to the preset security sending policy. This enables the second synchronization system to import the configuration management file information to be synchronized into the second configuration management database after determining that it conforms to the security import policy.
13. A cross-network data synchronization device for a configuration management database, characterized in that, The device is applied to a second synchronization system corresponding to a second configuration management database. The second configuration management database and the second synchronization system are located in a second network environment. The second configuration management database stores configuration management file information. The device includes a configuration management file information acquisition module, a security judgment module, and an import module. The configuration management file information acquisition module is configured to acquire configuration management file information to be synchronized sent by the first synchronization system. The first synchronization system corresponds to the first configuration management database. The first synchronization system and the first configuration management database are in a first network environment. The security level information of the first network environment is different from the security level information of the second network environment. The security judgment module is configured to determine whether the configuration management file information to be synchronized conforms to the preset security import strategy; The import module is configured to import the configuration management file information to be synchronized into the second configuration management database in response to the configuration management file information to be synchronized conforming to a preset security import strategy.
14. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-11.
15. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-11.