Regional data access methods, devices, equipment and products

By verifying user identifiers through the registration center and accurately locating regional data centers, combined with data tiered storage and transmission optimization strategies, the problem of compliance requirements being difficult to meet in multi-regional data management has been solved, improving data access efficiency and compliance.

CN121750376BActive Publication Date: 2026-05-26SHENZHEN EMEET TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN EMEET TECH CO LTD
Filing Date
2026-02-26
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing technologies are insufficient to meet compliance requirements in multi-regional data management, resulting in inefficient data access, compliance risks, complex operations and maintenance, high costs, and low efficiency.

Method used

By linking user terminal identifiers with compliance information from multiple regions through the registration center, the verification process directly adapts to the corresponding regional compliance requirements, accurately locates the local data center, enables localized data processing, avoids cross-regional transmission delays and redundancy, and adopts strategies such as data tiered storage, automatic scaling, and data transmission optimization.

Benefits of technology

It improves the efficiency of regional data access, meets compliance requirements in multiple regions, reduces operational complexity and costs, and provides high-quality data access services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121750376B_ABST
    Figure CN121750376B_ABST
Patent Text Reader

Abstract

This application discloses a regional data access method, apparatus, device, and product, relating to the field of data security technology. The method is applied to a management end and includes: receiving a data access request sent by a first user terminal; extracting the first user terminal identifier from the data access request and verifying the first user terminal identifier through a registration center; if the verification is successful, determining the regional data center of the first user terminal, and processing the data access request through the regional data center to obtain a processing result. This solves the problem of low data access efficiency in existing technologies when managing data across multiple regions due to the difficulty in meeting compliance requirements in each region, thus improving the efficiency of regional data access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and in particular to a method, apparatus, device, and product for accessing regional data. Background Technology

[0002] In the existing technology, user information platforms, as core Internet applications, are facing severe challenges in data compliance in multiple regions. Current international regulations have put forward stringent requirements for the collection, storage, processing and transmission of personal data. Generally, data must be stored locally, and cross-regional transmission must meet specific compliance conditions. Within the scope of existing technology, the solutions for enterprises to deal with this problem mainly cover the following four types: centralized storage in a single data center, deployment of independent registration centers in multiple regions, data replication and synchronization, and manual configuration of compliance policies.

[0003] However, all of the above solutions have significant drawbacks. First, while a single data center deployment offers the advantage of ease of management, it cannot meet the requirements for data localization and poses compliance risks. Second, multiple independent registration centers in different regions require cross-regional data synchronization, which leads to complex operation and maintenance, data delays, and inconsistent user experiences. Third, data replication and synchronization can easily cause data redundancy, resulting in a significant increase in costs and making it difficult to meet localization compliance requirements. Finally, manual policy configuration is inefficient, prone to errors, and cannot adapt to dynamic updates in regulations.

[0004] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main objective of this application is to provide a regional data access method, apparatus, device, and product, which aims to solve the technical problem of low data access efficiency in the prior art when managing data in multiple regions due to the difficulty in meeting the compliance requirements of multiple regions.

[0006] To achieve the above objectives, this application proposes a regional data access method, which is applied to a management terminal and includes:

[0007] Receive data access requests sent by the first user client;

[0008] Extract the first user terminal identifier from the data access request, and verify the first user terminal identifier through the registration center;

[0009] If the verification is successful, the regional data center of the first user terminal is determined, and the data access request is processed through the regional data center to obtain the processing result.

[0010] In one embodiment, before the step of receiving a data access request sent by the first user terminal, the method further includes:

[0011] Receive a registration request sent by a second user terminal, and extract the second user terminal identifier and the region information from the registration request;

[0012] The target data center corresponding to the home region information is determined according to the pre-configured region mapping rules.

[0013] The second user terminal identifier, the home region information, and the target region data center are stored in the registration center.

[0014] In one embodiment, before the step of determining the target data center corresponding to the home region information according to a pre-configured region mapping rule, the method further includes:

[0015] Collect access addresses, data storage ranges, and compliance permission information for data centers in several regions;

[0016] The basic data center profile is constructed using the access address, data storage range, and compliance permission information.

[0017] The association between access addresses and access regions is determined based on the data center basic profile, and region mapping rules are configured through the association.

[0018] In one embodiment, the step of verifying the first user terminal identifier through the registration center includes:

[0019] The matching result is obtained by matching the associated records of the registration center using the first user terminal identifier;

[0020] If the matching result indicates the existence of an associated record, then verify whether the associated record is in a valid state, and if the associated record is in a valid state, extract the first home region information and the regional data center corresponding to the first user terminal identifier;

[0021] According to the compliance management rules, the access type and access scope of the data access request are verified through the permission scope of the first home region information to obtain the compliance verification result;

[0022] Availability verification is performed on the regional data center. If the availability verification passes, the qualification verification is performed on the regional data center using the first user terminal identifier to obtain the qualification verification result.

[0023] If the compliance verification result and the qualification verification result are both passed, the verification result of the first user terminal identifier is obtained as passed.

[0024] In one embodiment, the step of processing the data access request through the regional data center to obtain a processing result includes:

[0025] The data access request is verified for violations using the local data compliance rules corresponding to the regional data center.

[0026] If it is determined that the data access request is not an illegal operation, the data in the regional data center is isolated according to the compliance level corresponding to the first user terminal identifier and the tenant information to obtain the open data range;

[0027] The data operations in the data access request are performed through the open data scope to obtain the processing result.

[0028] In one embodiment, the step of performing data operations in the data access request through the open data scope to obtain a processing result includes:

[0029] Determine whether the data access request involves cross-regional data query;

[0030] If the data access request involves cross-regional data query, a query request is initiated to the regional data center of the target region through the regional gateway layer;

[0031] Based on the query request, obtain cross-regional data from the regional data center of the target region;

[0032] Sensitive data filtering is performed on the cross-regional data according to the local data compliance rules to obtain compliant data;

[0033] The data operations are performed using the compliant data and the scope of open data to obtain the processing results.

[0034] In one embodiment, after the step of determining the regional data center of the first user terminal upon successful verification, processing the data access request through the regional data center, and obtaining the processing result, the method further includes:

[0035] Extract the operation subject, operation event, data range, and compliance verification result from the processing result;

[0036] An operation audit log is generated based on the operation subject, operation event, data range, and compliance verification results.

[0037] The operation audit log is audited through the strategy management center.

[0038] If the audit result is satisfactory, the processing result is encrypted through the regional gateway layer and then transmitted to the first user terminal.

[0039] Furthermore, to achieve the above objectives, this application also proposes a regional data access device, which is applied to a management terminal, and the regional data access device includes:

[0040] The receiving module is used to receive data access requests sent by the first user terminal;

[0041] The extraction module is used to extract the first user terminal identifier from the data access request and verify the first user terminal identifier through the registration center;

[0042] The processing module is used to determine the regional data center of the first user terminal when the verification is successful, and to process the data access request through the regional data center to obtain the processing result.

[0043] In addition, to achieve the above objectives, this application also proposes a regional data access device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the regional data access method as described above.

[0044] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and which, when executed by a processor, implements the steps of the area data access method described above.

[0045] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the area data access method as described above.

[0046] One or more technical solutions proposed in this application have at least the following technical effects:

[0047] This application proposes a regional data access method, apparatus, device, and product. The method, applied to a management terminal, involves receiving a data access request from a first user terminal; extracting the first user terminal identifier from the data access request; verifying the first user terminal identifier through a registration center; and, if verification is successful, determining the regional data center of the first user terminal. The data access request is then processed through the regional data center to obtain a processing result. Thus, by associating the first user terminal identifier with multi-regional compliance information through the registration center, the verification process directly adapts to the corresponding regional compliance requirements, and then accurately locates the local regional data center, achieving localized data processing. This avoids cross-regional transmission delays and redundancy, satisfying multi-regional compliance requirements and improving data access efficiency. It solves the problem of low data access efficiency in existing technologies when managing data across multiple regions due to the difficulty in meeting multi-regional compliance requirements, thereby improving the efficiency of regional data access. Attached Figure Description

[0048] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0049] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0050] Figure 1 This is a flowchart illustrating an embodiment of the regional data access method of this application.

[0051] Figure 2 This is a schematic diagram of the regional logical layer involved in the regional data access method of this application;

[0052] Figure 3 This is a schematic diagram of the regional data center structure involved in the regional data access method of this application;

[0053] Figure 4 This is a schematic diagram illustrating the data processing flow of the gateway logic layer involved in the regional data access method of this application;

[0054] Figure 5 This is a flowchart illustrating Embodiment 2 of the method for accessing regional data in this application.

[0055] Figure 6 This is a schematic diagram illustrating the compliance policy management center involved in the regional data access methods of this application;

[0056] Figure 7A simplified flowchart illustrating the regional data access method provided in Embodiment 2 of this application;

[0057] Figure 8 This is a schematic diagram of the module structure of the area data access device according to an embodiment of this application;

[0058] Figure 9 This is a schematic diagram of the device structure of the hardware operating environment involved in the regional data access method in this application embodiment.

[0059] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0060] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0061] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0062] The main solution of this application embodiment is as follows: A registration request is received from a second user terminal; the second user terminal identifier and the home region information are extracted from the registration request; the target regional data center corresponding to the home region information is determined according to a pre-configured regional mapping rule; the second user terminal identifier, the home region information, and the target regional data center are stored in the registration center. Access addresses, data storage ranges, and compliance permission information of several regional data centers are collected; a basic data center profile is constructed using the access addresses, data storage ranges, and compliance permission information; the association between the access address and the access region is determined based on the basic data center profile, and regional mapping rules are configured based on the association. The data access request is checked for violations using the local data compliance rules corresponding to the regional data center; if the data access request is determined not to be a violation, the regional data center is isolated according to the compliance level and tenant information corresponding to the first user terminal identifier to obtain an open data range; the data operation in the data access request is executed through the open data range to obtain a processing result. The process involves determining whether the data access request involves cross-regional data querying. If so, a query request is initiated to the regional data center of the target region through the regional gateway layer. Cross-regional data from the regional data center of the target region is obtained based on the query request. Sensitive data filtering is performed on the cross-regional data according to the local data compliance rules to obtain compliant data. The data operation is performed using the compliant data and the open data scope to obtain the processing result. The operation subject, operation event, data scope, and compliance verification result are extracted from the processing result. An operation audit log is generated based on the operation subject, operation event, data scope, and compliance verification result. The operation audit log is audited through the policy management center. If the audit result is satisfactory, the processing result is encrypted through the regional gateway layer and transmitted to the first user terminal. This solves the problem of low data access efficiency in existing technologies when managing data across multiple regions due to the difficulty in meeting compliance requirements in each region, thus enabling access to regional data and improving the efficiency of regional data access. Based on the present invention, this invention addresses the challenges faced by enterprises in managing data across multiple regions, particularly in terms of data compliance and access efficiency. Different regions have varying data compliance regulations, localized storage requirements, and cross-regional transmission conditions. If existing data management solutions fail to adapt to the multi-regional compliance characteristics and efficient access needs, they cannot guarantee both data compliance and access efficiency, leading to high compliance risks, complex operations and maintenance, increased costs, and low efficiency. Therefore, this invention designs a regional data access method and verifies its effectiveness when accessing regional data. Finally, the efficiency of regional data access using this method is significantly improved.

[0063] In this embodiment, for ease of description, the following description uses a regional data access device as the execution subject.

[0064] Due to the limitations of existing multi-regional data management solutions, enterprises' data compliance and efficient operation needs during business expansion are difficult to meet. One issue is localization adaptation: a single data center or data replication and synchronization solution cannot meet the localized storage requirements of multiple regions, posing compliance risks. Another issue is cross-regional collaboration: multiple independent registration centers in different regions require cross-regional data synchronization, resulting in complex operation and maintenance, data latency, and inconsistent user experience. Yet another issue is policy adaptation: manually configuring compliance policies is inefficient, error-prone, and cannot adapt to dynamic regulatory updates, leading to data redundancy and increased costs. Therefore, it is clear that because different regions have different compliance regulations, storage requirements, and data transmission conditions, if data management solutions are not specifically adapted to the compliance and operational characteristics of multiple regions, it will lead to high compliance risks, inefficient operation and maintenance, and high costs.

[0065] This application provides a solution that associates the first user terminal identifier with multi-regional compliance information through a registration center. During the verification process, it directly adapts to the corresponding regional compliance requirements and then accurately locates the local regional data center, achieving localized data processing. This avoids cross-regional transmission delays and redundancy, satisfying multi-regional compliance while improving data access efficiency. It solves the problem of low data access efficiency caused by the difficulty in meeting multi-regional compliance requirements in existing technologies when managing data in multiple regions, thereby improving the efficiency of regional data access and providing users with better services.

[0066] Based on this, embodiments of this application provide a method for accessing regional data, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the regional data access method of this application.

[0067] In this embodiment, the regional data access method is applied to the management terminal, and the regional data access method includes steps S01~S03:

[0068] Step S01: Receive a data access request sent by the first user terminal;

[0069] Before the implementation of this embodiment, it should be clear that in the prior art, user information platforms need to meet the compliance requirements of localized storage of data in multiple regions and cross-regional transmission. Existing solutions all have drawbacks, including compliance risks, complex / delayed operation and maintenance, high costs, and low efficiency and error-proneness.

[0070] Therefore, in order to solve the above problems, this embodiment receives a data access request sent by a first user terminal in the management terminal. The data access request carries a first user terminal identifier, which is used to uniquely identify the user terminal that initiated the data access request. After receiving the data access request, the management terminal will subsequently perform a series of compliance verification and data location operations based on the first user terminal identifier.

[0071] Step S02: Extract the first user terminal identifier from the data access request and verify the first user terminal identifier through the registration center;

[0072] Subsequently, the first user terminal identifier is extracted from the data access request and verified through the registration center. The registration center pre-stores the legitimate identifier information of all registered user terminals. During the verification process, the management end will accurately compare the extracted first user terminal identifier with the identifier information in the registration center. If the comparison result shows that the first user terminal identifier exists in the list of legitimate identifiers in the registration center, the verification is deemed successful, indicating that the user terminal has the initial permission to initiate a data access request. Conversely, if no matching identifier information is found, the verification fails, the management end will directly reject the data access request, and return a response message indicating that the identifier verification failed to the first user terminal. This ensures that only legitimate user terminals that have been registered and filed can proceed with the subsequent data access process, thus guaranteeing the security and compliance of data access from the source.

[0073] Step S03: If the verification is successful, determine the regional data center of the first user terminal, process the data access request through the regional data center, and obtain the processing result.

[0074] Once verification is successful, the management system will determine the corresponding regional data center for the user client and process the data access request through that regional data center to obtain the final processing result. The determination of the regional data center is based on a pre-configured mapping relationship between the user client identifier and the regional data center. This mapping relationship typically takes into account factors such as the user client's physical location, network affiliation, or business needs to achieve data processing and efficient access based on proximity. When the data access request is forwarded to the corresponding regional data center, the regional data center will perform a series of processing operations such as retrieval, extraction, calculation, or updating based on the specific data identifier, operation type (such as query, read, write, etc.) and relevant permission information carried in the request. During the processing, the regional data center will strictly follow the preset data processing rules and security policies to ensure the integrity, confidentiality, and availability of the data in the processing stage. After processing is completed, the regional data center will feed back the generated processing result to the management system, which will then return the result to the user client that initiated the request, thus completing the closed-loop process of the entire regional data access and processing.

[0075] In addition, this embodiment also reduces operating costs through reasonable resource allocation, and configures the following optimization strategies:

[0076] (1) Data tiered storage: Based on the data access frequency, the data is divided into hot data, warm data and cold data. Hot data (access frequency ≥ 10 times / day in the past 3 months) is stored on high-speed SSD disks, warm data (access frequency 1-9 times / day) is stored on ordinary mechanical disks, and cold data (access frequency < 1 time / day) is migrated to low-cost object storage and automatically archived periodically.

[0077] (2) Automatic scaling up and down: The number of service instances in the regional logical layer is dynamically adjusted based on the system load. During peak periods (such as when user access volume is 50% higher than the average), instances are automatically added, and during off-peak periods (such as from 1 to 5 a.m.), instances are automatically reduced to avoid resource idleness.

[0078] (3) Data transmission optimization: When querying across regions, data compression technology is used to reduce the amount of data transmitted. Priority is given to transmitting the query result summary rather than the complete dataset. Unnecessary data is not transmitted across regions to reduce network bandwidth costs.

[0079] Specifically, before step S01 above, which involves receiving a data access request sent by the first user terminal, the method further includes:

[0080] Step S011: Receive the registration request sent by the second user terminal, and extract the second user terminal identifier and the home region information from the registration request;

[0081] Step S012: Determine the target region data center corresponding to the home region information according to the pre-configured region mapping rules;

[0082] Step S013: Store the second user terminal identifier, home region information, and target region data center in the registration center.

[0083] Upon receiving a registration request from the second user client, the system first extracts the user client identifier and region information from the request, and then combines this information with other relevant data. Figure 2 The regional gateway layer shown is deployed in each region and serves as the sole entry and exit point for data flow. It is responsible for receiving, routing, encrypting and decrypting data, and performing preliminary compliance checks. Based on the multi-regional division system observed in the regional network, it verifies the legality and validity of the information belonging to the region to ensure that it complies with the jurisdiction of each region and the coverage boundaries of the data center.

[0084] In the subsequent registration process, based on the basic profile built in advance by collecting access addresses, data storage ranges, and compliance permission information of data centers in various regions, the pre-configured regional mapping rule module is called. By accurately matching the belonging region information with the rule base, the corresponding target regional data center is located, and the local compliance rules (such as GDPR, PIPL) and access permission thresholds corresponding to that data center are associated.

[0085] Subsequently, the user terminal identifier, the region information, the target region data center access address, and the associated compliance permission information are processed according to... Figure 2 The data storage specification for the regional gateway layer stores data in a key-value pair format with a regional prefix to the unified registration center cluster. Simultaneously, user IDs are segmented and stored in association using Redis queues to ensure a unique correspondence between user identifiers and their respective regions. Furthermore, registration information is synchronized to the compliance policy management center for record-keeping, forming a three-dimensional association of "user-region-compliance rule." This provides a complete data support chain for subsequent first-end user identification verification, regional data center location, and compliance verification. The registration center also synchronizes data to each regional gateway layer in real time to ensure efficient routing of subsequent access requests.

[0086] In addition, after the compliance policy management center is configured, the following security measures must be deployed simultaneously to ensure the security of data storage, transmission, and access throughout the entire chain:

[0087] (1) Enhanced identity authentication: Multi-factor authentication (MFA) is adopted. The user identification verification process requires the combination of multiple factors such as password, dynamic verification code or device fingerprint. Only after all factors are verified can the subsequent qualification verification process be entered.

[0088] (2) Fine-grained access control: Role-based access control (RBAC) model, assign exclusive roles to different user terminal identifiers, clarify the access permissions of each role to the regional data center (such as read-only, read-write, modification, etc.), and verify the matching of role permissions and data operation types during the qualification verification stage.

[0089] (3) Full-scenario data encryption: Transmitted data is encrypted end-to-end using the TLS / SSL protocol. Static data in the regional data center is stored using the AES-256 encryption standard. Encryption keys are managed uniformly through KMS (Key Management Service) and are automatically rotated periodically.

[0090] (4) Immutable audit logs: After the audit logs are generated, the content is solidified using blockchain or similar immutable log technology. The logs contain core information such as the operating entity, timestamp, data range, and compliance verification results. Only appending is supported, and modification or deletion is not allowed to ensure the accuracy of audit traceability.

[0091] (5) Vulnerability protection mechanism: Regularly perform vulnerability detection on the regional gateway layer, logic layer and data center through security scanning tools. The detection frequency is no less than once a month. After high-risk vulnerabilities are found, an alarm will be automatically triggered. Known vulnerabilities can be quickly repaired through automated tools.

[0092] More specifically, before step S012 above, which determines the target data center corresponding to the home region information according to the pre-configured region mapping rules, the method further includes:

[0093] Step S0121: Collect access addresses, data storage ranges, and compliance permission information for several regional data centers;

[0094] Step S0122: A basic data center profile is constructed using the access address, data storage range, and compliance permission information.

[0095] Step S0123: Determine the association between the access address and the access area based on the data center basic file, and configure the area mapping rules through the association.

[0096] First, during the process of collecting access addresses, data storage ranges, and compliance permission information for data centers in several regions, the completeness and validity of each piece of information are simultaneously verified. Then, combined with... Figure 3 The regional data center structure diagram shown uses a master-slave synchronization method to associate the corresponding compliance regulations (such as GDPR, CCPA, PIPL) of each region, and marks the compliance permission boundaries and data storage restrictions of different regional data centers.

[0097] Secondly, based on the verified information, a basic data center profile is constructed according to a hierarchical structure of "regional code - access address - storage scope - compliance permissions", and an index module is embedded to enable rapid information retrieval. At the same time, the profile is synchronized to the compliance policy management center for associated storage, thus forming an initial linkage between "profile and compliance rules".

[0098] Subsequently, based on this foundational data, a unique mapping relationship between the access addresses of each regional data center and their corresponding jurisdictional access regions is established. This is then combined with a rule configuration engine, incorporating user ID segmentation routing logic and cross-regional access restrictions, to generate dynamically adaptable regional mapping rules that meet compliance requirements across multiple regions. Once generated, these rules are synchronously updated to the registry center and regional gateway layer to ensure that subsequent registration requests accurately match the target regional data center and to support rapid rule iteration in response to regulatory updates.

[0099] To support the rapid expansion of data centers in new regions, this embodiment also includes an automated deployment toolchain, including:

[0100] (1) Containerized deployment: Docker is used to encapsulate the service components of the regional gateway layer and logic layer, and Kubernetes is used to implement container orchestration, supporting automatic scheduling, scaling up and down and fault self-healing of service instances.

[0101] (2) Continuous Integration / Continuous Deployment (CI / CD): Based on Jenkins or GitLab CI / CD tools, an automated process is built. After code is submitted, compilation and testing are automatically triggered. After the test is passed, it can be deployed to the data center of the target region with one click without manual intervention.

[0102] (3) Automated configuration: By using configuration management tools such as Ansible, standardized configuration templates (including compliance rules, security policies, network configurations, etc.) for data centers in each region are preset. When deploying in a new region, the templates are directly called to quickly complete the environment configuration.

[0103] Furthermore, step S02 above, the step of verifying the first user terminal identifier through the registration center, includes:

[0104] Step S021: Match the associated records of the registration center using the first user terminal identifier to obtain the matching result;

[0105] Step S022: If the matching result is that there is an associated record, then verify whether the associated record is in a valid state, and if the associated record is in a valid state, extract the first home region information and the regional data center corresponding to the first user terminal identifier.

[0106] Step S023: According to the compliance management rules, the access type and access scope of the data access request are verified through the permission scope of the first home region information to obtain the compliance verification result.

[0107] Step S024: Perform availability verification on the regional data center. If the availability verification passes, perform qualification verification on the regional data center using the first user terminal identifier to obtain the qualification verification result.

[0108] Step S025: If the compliance verification result and the qualification verification result are both passed, the verification result of the first user terminal identifier is obtained as passed.

[0109] The search is initiated starting with the first user terminal identifier, and is linked with the key-value pair storage system with regional prefixes in the registration center. The method of combining precise matching and fuzzy screening is used to match related records, while simultaneously filtering invalid identifiers and duplicate records, thereby obtaining the matching results.

[0110] like Figure 4The gateway logic layer shown can logically or physically isolate data of different compliance levels or different tenants within each region. In this embodiment, the gateway logic layer can also query associated records. If associated records exist, the system first verifies whether the records are in a valid state of not being cancelled or expired. If the records are valid, the system extracts the corresponding first home region information and regional data center, and simultaneously links the registration center and the regional data center, and retrieves the basic configuration information of the regional data center.

[0111] Subsequently, with the help of the compliance strategy management center, the GDPR, CCPA, PIPL and other compliance management rules of the corresponding region are retrieved. Based on the scope of permissions, the operation type (add, delete, modify, query) and the scope of accessed data are verified one by one. At the same time, sensitive data access permissions are marked, thereby obtaining the compliance verification results.

[0112] Then, through the regional data center monitoring node, multi-dimensional availability verification is carried out on the data center's operating status, network connectivity, and resource load. After the verification is passed, based on the RBAC permission model, the first user terminal identifier is used to verify whether it has the preset qualifications to access the regional data center, and finally the qualification verification result is generated.

[0113] When both of the above verification results pass, the first user terminal identifier verification is completed, and the verification process log is simultaneously uploaded to the audit module for record-keeping, so as to retain traceability evidence for subsequent data access operations.

[0114] This embodiment, through the above-described scheme, specifically receives a data access request sent by a first user terminal; extracts the first user terminal identifier from the data access request; verifies the first user terminal identifier through a registration center; if the verification is successful, determines the regional data center of the first user terminal; and processes the data access request through the regional data center to obtain the processing result. Thus, by associating the first user terminal identifier with multi-regional compliance information through the registration center, the verification process directly adapts to the corresponding regional compliance requirements, and then accurately locates the local regional data center, achieving localized data processing, avoiding cross-regional transmission delays and redundancy. This satisfies multi-regional compliance requirements and improves data access efficiency, solving the problem of low data access efficiency in existing technologies when managing data in multiple regions due to the difficulty in meeting multi-regional compliance requirements, thereby improving the efficiency of regional data access.

[0115] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to the first embodiment described above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 5In step S03, where the data access request is processed through the regional data center to obtain the processing result, the regional data access method further includes steps S031-S033:

[0116] Step S031: Verify the data access request for violations using the local data compliance rules corresponding to the regional data center;

[0117] Step S032: If it is determined that the data access request is not an illegal operation, the data in the regional data center is isolated according to the compliance level corresponding to the first user terminal identifier and the tenant information to obtain the open data range;

[0118] Step S033: Perform the data operation in the data access request through the open data range to obtain the processing result.

[0119] First, the system invokes pre-stored local data compliance rules (covering region-specific provisions such as GDPR, CCPA, and PIPL) in the regional data center and synchronizes them with real-time updated rules issued by the compliance policy management center. Combined with the data classification and grading module, it performs sensitive pre-identification of the data involved in the access request. Through dual verification, it checks whether the request operation type and data scope violate localized storage and permission requirements, thereby completing the violation verification.

[0120] After confirming that there are no violations, a physical isolation boundary is constructed based on the tenant information associated with the first user terminal identifier. Subsequently, logical access permissions are divided according to compliance level, and the tenant data permission matrix is ​​integrated with the compliance level threshold to implement hierarchical isolation of user data within the regional data center. This precisely defines the scope of open data that matches user permissions, thereby preventing unauthorized access.

[0121] Data operations are performed based on the scope of open data. During the operation, static data is protected using AES-256 encryption, and a real-time compliance review mechanism is enabled to dynamically verify whether the operation deviates from the open scope and compliance rules. After the operation is completed, the processing result is generated, and the operation details and compliance review log are recorded and synchronized to the audit module for filing. This achieves both localized data processing and hierarchical isolation, and enhances compliance security through the dual protection mechanism of "pre-identification and real-time review".

[0122] In addition, to ensure business continuity, this embodiment also establishes a multi-level disaster recovery mechanism, specifically including:

[0123] (1) Data backup strategy: Each regional data center adopts the "local multiple copies and off-site backup" mode. Local data generates 3 copies in real time and stores them on different physical nodes. Data is automatically backed up to the backup data center in the same region every day at midnight, and off-site cross-regional backup is performed once a week.

[0124] (2) Fast failover: When the primary data center fails, the system automatically detects the fault status and triggers the switchover of the backup data center within 1 minute. During the switchover process, the faulty node is shielded through the regional gateway layer to ensure that users are unaware of the fault.

[0125] (3) Data recovery mechanism: It supports data recovery by time point, and the recovery range can be accurate to the hour. During the recovery process, the data integrity is automatically verified. After the recovery is completed, it is synchronously updated to the registration center to ensure accurate access routing in the future.

[0126] (4) Disaster recovery drills: Conduct a disaster recovery drill once a quarter to simulate scenarios such as main data center failure, network interruption, and data corruption, verify the effectiveness of the disaster recovery plan, generate a drill report, and optimize and improve it.

[0127] Specifically, step S033 above, which involves performing data operations in the data access request through the open data scope to obtain the processing result, includes:

[0128] Step S0331: Determine whether the data access request involves cross-regional data query;

[0129] Step S0332: If the data access request involves cross-regional data query, then a query request is initiated to the regional data center of the target region through the regional gateway layer;

[0130] Step S0333: Obtain cross-regional data from the regional data center of the target region according to the query request;

[0131] Step S0334: Perform sensitive data filtering on the cross-regional data according to the local data compliance rules to obtain compliant data;

[0132] Step S0335: Perform the data operation using the compliant data and the open data range to obtain the processing result.

[0133] First, the system combines the home region information associated with the first user terminal identifier with the target data range of the data access request, and links the user ID segmentation routing logic with the regional data center storage boundary to determine whether the request involves cross-regional data query from a dual dimension, thereby accurately identifying cross-regional access scenarios.

[0134] If the query is determined to be a cross-regional query, the regional gateway layer will be used as the unified entry point. The query request will be sent to the regional data center of the target region through the encrypted remote procedure call (RPC) service. This request must carry local compliance verification credentials and data access permission instructions to ensure the security and traceability of the link transmission. At the same time, the principle of local data retention will be followed, and only the result query will be initiated instead of physical data migration.

[0135] Based on the query request, the regional data center of the target region extracts the corresponding cross-regional data according to its own open data scope, and transmits the data to the regional gateway layer of the initiating end through encrypted transmission using Transport Layer Security (TLS) / Secure Sockets Layer (SSL) protocol, thereby avoiding the risk of data leakage during transmission.

[0136] Subsequently, a dynamic sensitive data filtering engine is invoked, combining local data compliance rules (such as the General Data Protection Regulation (GDPR) and the Personal Information Protection Act (PIPL)) with supplementary compliance provisions of the target region to perform tiered filtering of cross-regional data. Specifically, sensitive fields are first identified using a data classification and grading module, then non-compliant data is removed based on the scope of permissions, while the access permission level of compliant data is simultaneously marked, ultimately obtaining compliant data.

[0137] Finally, the compliant data is aligned with the local open data scope for permissions and data fusion. Based on the fused dataset, corresponding data operations are performed. During the operation, a real-time compliance review mechanism is enabled to dynamically verify whether the operation behavior meets the compliance requirements of both regions. After the operation is completed, the processing result is generated and the cross-regional query link, data filtering details and compliance review logs are recorded simultaneously to provide a complete basis for subsequent audits, thereby improving the compliance and accuracy of cross-regional access.

[0138] More specifically, after step S03 above, which involves determining the regional data center of the first user terminal upon successful verification, processing the data access request through the regional data center, and obtaining the processing result, the method further includes:

[0139] Step S04: Extract the operation subject, operation event, data range, and compliance verification result from the processing result;

[0140] Step S05: Generate an operation audit log based on the operation subject, operation event, data range, and compliance verification results;

[0141] Step S06: Perform operation audit on the operation audit log through the strategy management center;

[0142] Step S07: If the audit result is satisfactory, the processing result is encrypted through the regional gateway layer and then transmitted to the first user terminal.

[0143] First, extract the operation subject, operation event, data range, and compliance verification results from the processing results, and simultaneously supplement the operation timestamp, data encryption status, and regional data center identifier to construct a multi-dimensional audit element set.

[0144] Subsequently, a structured operation audit log is generated based on this set of elements. The log content is then solidified using blockchain immutability technology. Figure 6 The compliance management platform shown in the diagram stores audit data in accordance with the regional compliance rules. Logs are then synchronously uploaded to the audit module of the policy management center and the backup node of the regional gateway layer to ensure that the logs are traceable and tamper-proof.

[0145] Next, relying on the audit rule engine pre-set in the strategy management center, and linking multiple regional compliance and legal databases, real-time cross-audits are conducted on the compliance of operations, the reasonableness of data range, and the consistency of verification results in the logs. At the same time, abnormal audit nodes are marked and a second review is triggered.

[0146] When the audit result shows "passed," the regional gateway layer invokes the TLS / SSL encryption protocol to perform end-to-end encryption on the processing result and accurately transmits it to the first user terminal through the gateway routing link. Simultaneously, the encrypted transmission record and audit pass certificate are added to the audit log, forming a complete "operation-audit-transmission" data link, thereby improving the security and traceability of the link.

[0147] It should be noted that, in order to monitor the system's operational status and compliance risks in real time, this embodiment is configured with a comprehensive monitoring and alarm system, including:

[0148] (1) Performance monitoring: Real-time monitoring of indicators such as CPU utilization, memory utilization, disk I / O, and network bandwidth in each regional data center, and setting a threshold alarm mechanism to trigger an alarm when the indicator exceeds the preset threshold (such as CPU utilization of 80%) for 5 consecutive minutes.

[0149] (2) Compliance event monitoring: Monitor compliance risk events such as illegal operations, cross-regional access attempts, and abnormal reading of sensitive data in data access. Once illegal behavior is detected, logs are immediately recorded and high-priority alarms are triggered.

[0150] (3) Data link monitoring: Monitor the request response time of cross-regional queries, data transmission integrity, and data synchronization status between the registration center and the gateway layer of each region. An alarm is issued when the synchronization delay exceeds 3 seconds.

[0151] (4) Multi-channel alarm notification: Supports multiple alarm channels such as email and SMS. The notification method is automatically matched according to the alarm level (low, medium and high). High-risk alarms must be pushed to relevant maintenance personnel within 5 minutes.

[0152] This embodiment, through the above-described scheme, specifically verifies the data access request for violations using the local data compliance rules corresponding to the regional data center. If the data access request is determined not to be a violation, the regional data center is isolated based on the compliance level corresponding to the first user terminal identifier and tenant information to obtain an open data range. The data operation in the data access request is then executed within this open data range to obtain the processing result. Therefore, by associating the first user terminal identifier with multi-regional compliance information through the registration center, the verification process directly adapts to the corresponding regional compliance requirements and accurately locates the local regional data center, achieving localized data processing. This avoids cross-regional transmission delays and redundancy, satisfying multi-regional compliance requirements and improving data access efficiency. This solves the problem of low data access efficiency in existing technologies when managing data across multiple regions due to the difficulty in meeting multi-regional compliance requirements, thus improving the efficiency of regional data access.

[0153] For example, to help understand the implementation flow of the regional data access method obtained by combining this embodiment with the above embodiment one, please refer to... Figure 7 , Figure 7 A simplified flowchart of a regional data access method is provided, specifically:

[0154] Before the first user initiates a data access request, the user first submits a registration application through the registration interface. After extracting the user identifier and the region information, the system combines the region mapping rules pre-set by the rule configuration engine (which are built based on the data center basic file) to match the data center of the target region. Then, the user identifier, the region information, and the associated information of the target data center are stored in the unified registration center. At the same time, the user ID is segmented and allocated and compliance permission is filed, providing preliminary data support for subsequent data access.

[0155] When the first user initiates a data access request, the request is routed through the regional gateway layer. The system extracts the user's identifier and, in conjunction with the registration center, matches related records. After verifying the record's validity, it extracts the region information and the target data center. Relying on the compliance policy management center, it retrieves the corresponding region's compliance rules (such as GDPR, CCPA, PIPL, etc.) to complete compliance verification of the access type and scope. Simultaneously, it verifies the availability of the target data center and the user's access qualifications through data center monitoring nodes. After both verifications pass, the system accurately locates the data center in the target region.

[0156] Once the data processing phase begins, the regional logic layer forwards the request to the corresponding regional data center. First, it performs violation verification through local compliance rules. Then, it isolates the data based on the user's compliance level and tenant information, defining the scope of open data.

[0157] If the request involves cross-regional queries, the regional gateway layer serves as the unified entry point. It initiates an encrypted query request to the data center of the target region through encrypted RPC services. Following the principle of "data retention locally," it only obtains the query results. After the sensitive data filtering engine filters the data according to dual-region compliance rules, it integrates local open data to perform corresponding data operations and generate the processing results.

[0158] After processing, core elements such as the operating entity, operating events, data scope, and compliance verification results are extracted to generate a blockchain-based, fixed operation audit log. This log is then synchronized to the audit module and the compliance policy management center to complete the compliance audit. After the audit passes, the regional gateway layer encrypts the processing result using TLS / SSL protocol and transmits it to the first user terminal along a pre-defined link. Simultaneously, the transmission record is added to the audit log, forming a complete closed loop that balances compliance requirements across multiple regions, access efficiency, and data security.

[0159] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the data access method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0160] This application also provides a regional data access device; please refer to... Figure 8 The area data access device is used in the management terminal, and the area data access device includes:

[0161] The receiving module 10 is used to receive a data access request sent by the first user terminal;

[0162] Extraction module 20 is used to extract the first user terminal identifier from the data access request and verify the first user terminal identifier through the registration center;

[0163] Processing module 30 is used to determine the regional data center of the first user terminal when the verification is successful, and to process the data access request through the regional data center to obtain the processing result.

[0164] The regional data access device provided in this application, employing the regional data access method described in the above embodiments, can solve the technical problem of low data access efficiency in existing technologies when managing data across multiple regions due to the difficulty in meeting compliance requirements in each region. Compared with the prior art, the beneficial effects of the regional data access device provided in this application are the same as those of the regional data access method provided in the above embodiments, and other technical features in the regional data access device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0165] This application provides a regional data access device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the regional data access method in Embodiment 1 above.

[0166] The following is for reference. Figure 9 This document illustrates a structural diagram of a regional data access device suitable for implementing embodiments of this application. The regional data access device in these embodiments may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 9 The area data access device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0167] like Figure 9As shown, the area data access device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in the read-only memory 1002 or a program loaded from the storage device 1003 into the random access memory 1004. The random access memory 1004 also stores various programs and data required for the operation of the area data access device. The processing unit 1001, the read-only memory 1002, and the random access memory 1004 are interconnected via a bus 1005. An input / output interface 1006 is also connected to the bus. Typically, the following systems can be connected to the input / output interface 1006: input devices 1007 including, for example, touchscreens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the area data access device to communicate wirelessly or wiredly with other devices to exchange data. While the figure shows area data access devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0168] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from read-only memory 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0169] The regional data access device provided in this application, employing the regional data access method described in the above embodiments, can solve the technical problem of low data access efficiency in existing technologies when managing data across multiple regions due to the difficulty in meeting compliance requirements in each region. Compared with the prior art, the beneficial effects of the regional data access device provided in this application are the same as those of the regional data access method provided in the above embodiments, and other technical features of this regional data access device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0170] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0171] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0172] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the area data access method in the above embodiments.

[0173] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0174] The aforementioned computer-readable storage medium may be included in a regional data access device; or it may exist independently and not assembled into a regional data access device.

[0175] The aforementioned computer-readable storage medium carries one or more programs. When the aforementioned one or more programs are executed by the regional data access device, the regional data access device causes the following: to receive a data access request sent by a first user terminal; to extract the first user terminal identifier from the data access request and to verify the first user terminal identifier through a registration center; if the verification is successful, to determine the regional data center of the first user terminal and to process the data access request through the regional data center to obtain a processing result.

[0176] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0177] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0178] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0179] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned regional data access method. This solves the technical problem of low data access efficiency in existing technologies when managing data across multiple regions due to difficulties in meeting compliance requirements in each region. Compared to existing technologies, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the regional data access method provided in the above embodiments, and will not be elaborated upon here.

[0180] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the area data access method described above.

[0181] The computer program product provided in this application can solve the technical problem of low data access efficiency in the prior art when managing data in multiple regions due to the difficulty in meeting the compliance requirements of multiple regions. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the regional data access method provided in the above embodiments, and will not be repeated here.

[0182] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A method of accessing regional data, characterized by, The regional data access method is applied to the management terminal, and the regional data access method includes: Receive data access requests sent by the first user client; Extract the first user terminal identifier from the data access request, and verify the first user terminal identifier through the registration center; The step of verifying the first user terminal identifier through the registration center includes: The matching result is obtained by matching the associated records of the registration center using the first user terminal identifier; If the matching result indicates the existence of an associated record, then verify whether the associated record is in a valid state, and if the associated record is in a valid state, extract the first home region information and the regional data center corresponding to the first user terminal identifier; Link the registration center and the regional data center; The relevant compliance management rules are retrieved through the Compliance Strategy Management Center. These compliance management rules include the General Data Protection Regulation (GDPR) and the Personal Information Protection Regulation (PIPL). According to the compliance management rules, the access type and access scope of the data access request are verified through the permission scope of the first home region information to obtain the compliance verification result; Availability verification is performed on the regional data center. If the availability verification passes, the qualification verification is performed on the regional data center using the first user terminal identifier to obtain the qualification verification result. The step of performing availability verification on the regional data center, and, if the availability verification passes, performing qualification verification on the regional data center using the first user terminal identifier to obtain the qualification verification result includes: Based on the monitoring nodes of the regional data center, the availability of the regional data center is verified by the operating status, network connectivity, and resource load of the regional data center; If the availability verification passes, the first user terminal identifier is verified through the RBAC permission model to determine whether it has the preset qualifications of the regional data center. If it does, the qualification verification result is passed. If the compliance verification result and the qualification verification result are both passed, the verification result of the first user terminal identifier is obtained as passed. If the verification is successful, the regional data center of the first user terminal is determined, and the data access request is processed through the regional data center to obtain the processing result.

2. The regional data access method as described in claim 1, characterized in that, Before the step of receiving the data access request sent by the first user terminal, the method further includes: Receive a registration request sent by a second user terminal, and extract the second user terminal identifier and the region information from the registration request; The target data center corresponding to the home region information is determined according to the pre-configured region mapping rules. The second user terminal identifier, the home region information, and the target region data center are stored in the registration center.

3. The regional data access method as described in claim 2, characterized in that, Before the step of determining the target data center corresponding to the home region information according to the pre-configured region mapping rules, the method further includes: Collect access addresses, data storage ranges, and compliance permission information for data centers in several regions; The basic data center profile is constructed using the access address, data storage range, and compliance permission information. The association between access addresses and access regions is determined based on the data center basic profile, and region mapping rules are configured through the association.

4. The regional data access method as described in claim 1, characterized in that, The step of processing the data access request through the regional data center to obtain the processing result includes: The data access request is verified for violations using the local data compliance rules corresponding to the regional data center. If it is determined that the data access request is not an illegal operation, the data in the regional data center is isolated according to the compliance level corresponding to the first user terminal identifier and the tenant information to obtain the open data range; The data operations in the data access request are performed through the open data scope to obtain the processing result.

5. The regional data access method as described in claim 4, characterized in that, The step of performing data operations in the data access request through the open data scope to obtain the processing result includes: Determine whether the data access request involves cross-regional data query; If the data access request involves cross-regional data query, a query request is initiated to the regional data center of the target region through the regional gateway layer; Based on the query request, obtain cross-regional data from the regional data center of the target region; Sensitive data filtering is performed on the cross-regional data according to the local data compliance rules to obtain compliant data; The data operations are performed using the compliant data and the scope of open data to obtain the processing results.

6. The regional data access method as described in claim 1, characterized in that, After the step of determining the regional data center of the first user terminal upon successful verification, processing the data access request through the regional data center, and obtaining the processing result, the method further includes: Extract the operation subject, operation event, data range, and compliance verification result from the processing result; An operation audit log is generated based on the operation subject, operation event, data range, and compliance verification results. The operation audit log is audited through the strategy management center. If the audit result is satisfactory, the processing result is encrypted through the regional gateway layer and then transmitted to the first user terminal.

7. A regional data access device, characterized in that, The area data access device is used in the management terminal, and the area data access device includes: The receiving module is used to receive data access requests sent by the first user terminal; The extraction module is used to extract the first user terminal identifier from the data access request and verify the first user terminal identifier through the registration center; The extraction module is further configured to perform associated record matching on the registration center using the first user terminal identifier to obtain a matching result; If the matching result indicates the existence of an associated record, then verify whether the associated record is in a valid state, and if the associated record is in a valid state, extract the first home region information and the regional data center corresponding to the first user terminal identifier; Link the registration center and the regional data center; The relevant compliance management rules are retrieved through the Compliance Strategy Management Center. These compliance management rules include the General Data Protection Regulation (GDPR) and the Personal Information Protection Regulation (PIPL). According to the compliance management rules, the access type and access scope of the data access request are verified through the permission scope of the first home region information to obtain the compliance verification result; Availability verification is performed on the regional data center. If the availability verification passes, the qualification verification is performed on the regional data center using the first user terminal identifier to obtain the qualification verification result. Based on the monitoring nodes of the regional data center, the availability of the regional data center is verified by the operating status, network connectivity, and resource load of the regional data center; If the availability verification passes, the first user terminal identifier is verified through the RBAC permission model to determine whether it has the preset qualifications of the regional data center. If it does, the qualification verification result is passed. If the compliance verification result and the qualification verification result are both passed, the verification result of the first user terminal identifier is obtained as passed. The processing module is used to determine the regional data center of the first user terminal when the verification is successful, and to process the data access request through the regional data center to obtain the processing result.

8. A regional data access device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the area data access method as described in any one of claims 1 to 6.

9. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the area data access method as described in any one of claims 1 to 6.