Data soft switching system and method based on tenant space and electronic equipment

By using a tenant-space-based data softswitch system, and leveraging a trusted computing environment and sandbox mechanism for data resources, the difficulties and security issues of large-scale cross-departmental data sharing have been resolved, achieving controllability and security in cross-departmental data sharing.

CN121833240APending Publication Date: 2026-04-10DIGITAL ZHEJIANG TECH OPERATION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-15
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Cross-departmental data sharing faces difficulties in large-scale data fusion analysis, statistics, and collision scenarios, and also suffers from poor data security.

Method used

A tenant-space-based data softswitch system is adopted, which provides a sandbox mechanism through a trusted computing environment for data resources to restrict task access to system resources, and enables cross-departmental data sharing through the data softswitch transmission channel. Combined with resource access control components, data security is ensured.

Benefits of technology

It achieves controllability and data security in cross-departmental data sharing, breaks down data silos, supports data sharing and utilization in a wider range of scenarios, and ensures the security and independent management of data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121833240A_ABST
    Figure CN121833240A_ABST
Patent Text Reader

Abstract

The invention provides a data soft switching system and method based on tenant space and electronic equipment. The data soft switching system comprises the first tenant space deployed by a public data competent department, the second tenant space deployed by a data use department, a data soft switching transmission channel and a data resource trusted computing environment. Wherein the first tenant space, the second tenant space and the data soft switch transmission channel are deployed in the data resource trusted computing environment, and the data resource trusted computing environment provides a sandbox mechanism for running tasks; the first tenant space and the second tenant space are used for storing and calculating data resources; and during data sharing, the second tenant space reads the data resources of the first tenant space through the data soft switch transmission channel. According to the method, the problems of difficulty in sharing and using large-scale data among different departments and poor data security are solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of batch data sharing, in particular to a data soft switching system and method based on tenant space and electronic equipment. BACKGROUND

[0002] With the rapid development of digital construction, the demand for sharing and using public data of other departments by each department is increasing. The traditional solution mainly provides a front-end library by setting up a public data supervisor, gathers data of each department, and then provides it to the data using department as needed through the interface. This sharing method solves the problem of sharing cross-department data for real-time query of department application systems. However, in practice, there are more and more needs for cross-department data fusion analysis, data statistics, data collision and other business scenarios, and there are deep concerns about large-scale data sharing and data security, which makes it extremely difficult to share and use data between departments. SUMMARY

[0003] Therefore, the purpose of the present application is to provide a data soft switching system and method based on tenant space and electronic equipment to improve the problem of difficulty in large-scale data sharing and use between departments and poor data security.

[0004] In order to achieve the above purpose, the technical scheme adopted by the present application is as follows: In a first aspect, the present application provides a data soft switching system based on tenant space, comprising: a first tenant space deployed by a public data supervisor, a second tenant space deployed by a data using department, a data soft switching transmission channel and a data resource trusted computing environment; wherein the first tenant space, the second tenant space and the data soft switching transmission channel are deployed in the data resource trusted computing environment, and the data resource trusted computing environment provides a sandbox mechanism for running tasks; the first tenant space and the second tenant space are used for storage and calculation of data resources; when sharing data, the second tenant space reads the data resources of the first tenant space through the data soft switching transmission channel.

[0005] Optionally, it further comprises a resource access permission control component, which is deployed in the data resource trusted computing environment and is used to set the tenant space access permission of the first tenant space to the data resources of the second tenant space.

[0006] Optionally, the first tenant space comprises at least one first data resource package, and the first data resource package comprises at least one first data table; the second tenant space comprises at least one second data resource package, and the second data resource package comprises at least one second data table.

[0007] Optionally, the second tenant space is configured to determine, based on a business requirement, a source data resource package and source data tables to be accessed, and to call a resource access permission control component to determine, based on tenant space access permissions, whether the second tenant space is authorized to access the source data resource package and the source data tables; if the second tenant space is authorized to access the source data resource package and the source data tables, a mapping relationship between the source data resource package and the source data tables and the second data resource package is established; wherein the source data resource package is one or more of the first data resource package; and the source data tables are one or more of the second data tables.

[0008] Optionally, the second tenant space is further configured to read the source data tables of the first tenant space through a data soft exchange transmission channel based on the mapping relationship.

[0009] Optionally, the second tenant space is further configured to obtain result data by performing association calculation on the source data tables and the second data tables of the second tenant space.

[0010] In a second aspect, the present application provides a data soft exchange method based on tenant spaces, which is applied to the data soft exchange system based on tenant spaces provided in any of the first aspect, and the method comprises the following steps: a second tenant space determines, based on a business requirement, data resources to be accessed of a first tenant space; and the second tenant space reads the data resources to be accessed of the first tenant space through a data soft exchange transmission channel.

[0011] Optionally, after the second tenant space determines, based on a business requirement, the data resources to be accessed of the first tenant space, the method further comprises the following steps: a resource access permission control component is called to determine, based on tenant space access permissions set in the resource access permission control component, whether the second tenant space is authorized to access the data resources to be accessed of the first tenant space.

[0012] In a third aspect, the present application provides an electronic device comprising a processor and a memory, wherein the memory stores computer executable instructions capable of being executed by the processor, and the processor executes the computer executable instructions to implement the steps of the method provided in any of the second aspect.

[0013] In a fourth aspect, the present application provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the method provided in any of the second aspect.

[0014] The present application has the following advantages: The application provides a data soft switching system, method and electronic equipment based on a tenant space.

[0015] Additional features and advantages of the application will be set forth in the description that follows, and in part will be apparent from the description, or can be learned by practice of the application. The objectives and other advantages of the application will be realized and attained by the structure particularly pointed out in the description and claims.

[0016] In order to make the above-mentioned objectives, characteristics and advantages of the present application more apparent, clear and easy to understand, the following will be described in detail with reference to the preferred embodiments and the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0018] Figure 1 A structure schematic diagram of a data soft switching system based on a tenant space provided by an embodiment of the present application; Figure 2 Another structure schematic diagram of a data soft switching system based on a tenant space provided by an embodiment of the present application; Figure 3 A flowchart of a data soft switching method based on a tenant space provided by an embodiment of the present application; Figure 4 A structure schematic diagram of an electronic equipment provided by an embodiment of the present application.

[0019] Icon: 101-first tenant space; 102-second tenant space; 103-data soft exchange transmission channel; 104-data resource trusted computing environment; 105-resource access permission control component. DETAILED DESCRIPTION

[0020] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions of the present application will be described clearly and completely below with reference to the drawings. Obviously, the described embodiments are some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.

[0021] At present, in the practice process, there are more and more requirements for cross-department data fusion analysis, data statistics, data collision and other business scenarios, and there are deep concerns about mass data sharing and data security, which makes it extremely difficult to share and use data between cross-departments.

[0022] Based on this, the data soft exchange system, method and electronic equipment based on tenant space provided by the embodiments of the present application can improve the problems of difficult large-scale data sharing and use between cross-departments and poor data security.

[0023] In order to facilitate the understanding of the present embodiment, first, a data soft exchange system based on tenant space disclosed by the embodiments of the present application will be described in detail. Referring to Figure 1 The structure diagram of a data soft exchange system based on tenant space is shown in the figure, which shows that the system mainly includes: a first tenant space 101 deployed by a public data supervisor department, a second tenant space 102 deployed by a data user department, a data soft exchange transmission channel 103 and a data resource trusted computing environment 104; wherein the first tenant space 101, the second tenant space 102 and the data soft exchange transmission channel 103 are deployed in the data resource trusted computing environment 104, and the data resource trusted computing environment 104 provides a sandbox mechanism for running tasks; the first tenant space 101 and the second tenant space 102 are used for storage and calculation of data resources; when data is shared, the second tenant space 102 reads the data resources of the first tenant space 101 through the data soft exchange transmission channel 103.

[0024] In specific implementation, the first tenant space 101 includes: at least one first data resource package, and the first data resource package includes at least one first data table; the second tenant space 102 includes: at least one second data resource package, and the second data resource package includes at least one second data table.

[0025] The data soft switching system based on the tenant space provided by the embodiment of the application can provide a sandbox mechanism for running tasks, the second tenant space of the data use department can read the data resources of the first tenant space through the data soft switching transmission channel, so that the access of the tasks to the system resources can be limited, and the data security when the multi-tenant shares the computing resources can be ensured; the tenant space can independently manage the data resources thereof, the cross-department data sharing can be controlled in the range, and the problems of difficulty in large-scale data sharing and use between the cross-department and poor data security are improved.

[0026] In an embodiment, referring to Figure 2 The system further includes a resource access permission control component 105, which is deployed in the data resource trusted computing environment 104 and is configured to set the tenant space access permission of the first tenant space 101 to the data resources of the second tenant space 102.

[0027] In a specific implementation, the first tenant space 101 of the data computing node of the public data supervisor department is deployed, the local data resources, i.e., the first data resource package, are created in the first tenant space 101, the first data table is created in the first data resource package, and the corresponding data is loaded into the first data table; the second tenant space 102 of the data computing node of the data use department is deployed, the local data resources, i.e., the second data resource package, are created in the second tenant space 102, the second data table is created in the second data resource package, and the corresponding data is loaded into the second data table; the public data supervisor department can be one or more, the tenant space of the data use department can be one or more, and the tenant space is responsible for the data resource computing and storage of the data node.

[0028] The data soft switching transmission channel 103 is responsible for the secure transmission of the data resources between the first data resource package of the first tenant space 101 of the public data supervisor department and the second data resource package of the second tenant space 102 of the data use department.

[0029] The data resource trusted computing environment 104 provides a sandbox mechanism for running tasks, limits the access of the tasks to the system resources, and ensures the data security when the multi-tenant shares the resources.

[0030] The resource access permission control component 105 is responsible for setting the tenant space access permission of the data resources between the first tenant space 101 of the public data supervisor department and the second tenant space 102 of the data use department.

[0031] In an embodiment, the second tenant space 102 is configured to determine the source data resource package and the source data table to be accessed based on business requirements, and to call the resource access permission control component 105 to determine whether the second tenant space 102 is authorized to access the source data resource package and the source data table based on tenant space access permissions; if the second tenant space 102 is authorized to access the source data resource package and the source data table, a mapping relationship between the source data resource package and the source data table and the second data resource package is established; wherein the source data resource package is one or more of the first data resource package; and the source data table is one or more of the second data table.

[0032] Further, the second tenant space 102 is further configured to read the source data table of the first tenant space through the data soft switching transmission channel 103 based on the mapping relationship, and perform associated calculation on the source data table and the second data table of the second tenant space 102 to obtain result data.

[0033] In a specific implementation, the first data resource package is created by a public data supervisor in the first tenant space 101, and the data resource (the first data table, i.e., the data table 1 in the first data resource package) of the tenant space is put into the first data resource package, and the tenant space access permission that the second tenant space 102 of the data use department is allowed to access and read the first data table is set through the resource access permission control component 105. Figure 2

[0034] The second data resource package is created by the data use department in the second tenant space 102, and the data resource (the second data table, i.e., the data table 2 in the second data resource package) of the tenant space is put into the second data resource package, and it is judged by the resource access permission control component 105 whether the second tenant space 102 is authorized to access the first data resource package, and if authorized, a data resource mapping relationship is established with the first data resource package authorized by the public data supervisor. Figure 2

[0035] After the data resource package mapping relationship between the tenant spaces is established, the second tenant space 102 of the data use department can directly access the first data table authorized to access in the first data resource package, and associate the second data table of the space to realize cross-department data fusion analysis and calculation.

[0036] In order to facilitate understanding, the embodiment of the application also provides a method for realizing batch data sharing and use of different department libraries and tables by using the above system, which comprises the following steps 0 to 5: Step 0: The public data supervisor deploys the computing, storage resources and security configuration required by the tenant space in the data trusted computing environment; the public data supervisor creates the tenant space 1; and the data use department creates the tenant space 2.

[0037] ​​Step 1: the public data supervisor creates a data table 1 in the tenant space, and loads corresponding data resources into the data table 1.

[0038] Step 2: the public data supervisor creates a data resource package Package 3 in the tenant space, and puts the data table 1 into the data resource package Package 3, and then calls the resource access permission control component to set the tenant space access permission of the data resource package Package 3, and allows the data use department tenant space 2 to read the data table 1 of the resource package Package 3.

[0039] Step 3: the data use department determines the data resource package and resource table that need to be accessed according to business requirements and data requirements, calls the resource access permission control component, and establishes the mapping relationship between the data resource package Package 3 of the tenant space 1 and the target data resource package Package 6.

[0040] Step 4: the data use department tenant space 2 accesses the authorized data table 1 of the data resource package Package 3 through the data soft switching transmission channel, and performs associated calculation with the data table 2 in the space to obtain the final result data.

[0041] Step 5: end.

[0042] The above system provided by the embodiment of the application provides a sandbox mechanism for running tasks in a data trusted computing environment, limits the access of tasks to system resources, and guarantees the data security when multiple tenants share computing resources; a multi-tenant resource isolation mechanism is adopted, the tenant space can independently manage its own data resources, the business scenarios such as controllable range of cross-department data sharing, physical separation and logical concentration of data use are realized, and the data islands between various department business management systems are broken; the tenant space soft switching sharing improves the fault problem between centralized data management and decentralized data use, supports data sharing and data development and utilization in a wider scenario; and the data access control mechanism further guarantees the data security by controlling the access mode and data resource permission access control mechanism of the data resources across the tenant spaces.

[0043] For the data soft switching system based on the tenant space provided in the foregoing embodiment, the embodiment of the application provides a data soft switching method based on the tenant space, which is applied to the data soft switching system based on the tenant space provided in any one of the foregoing embodiments, and refers to a flowchart of a data soft switching method based on the tenant space as shown in the accompanying drawings. Figure 3 The method mainly includes the following steps S301 to S302: Step S301: the second tenant space determines the data resources to be accessed of the first tenant space based on business requirements.

[0044] In an embodiment, the public data authority creates a first tenant space, creates a first data table in the tenant space, loads corresponding data resources into the first data table, creates a first data resource package that needs to be shared across departments in the tenant space, puts the first data table into the first data resource package, and then calls a resource access permission control component to set the tenant space access permission of the first data resource package. The data using department creates a second tenant space, and creates a second data table in the tenant space and loads corresponding data resources into the second data table. The data using department can determine the data resources that need to be accessed according to business needs and data needs.

[0045] Further, the second tenant space can call the resource access permission control component to determine whether the second tenant space is authorized to access the data resources to be accessed in the first tenant space based on the tenant space access permission set in the resource access permission control component.

[0046] In a specific implementation, the second tenant space calls the resource access permission control component to determine whether the second tenant space is authorized to access the data resources to be accessed in the first tenant space. If authorized, a mapping relationship between the second data resource package of the second tenant space and the first data resource package is established.

[0047] Step S302: The second tenant space reads the data resources to be accessed in the first tenant space through a data soft switching transmission channel.

[0048] In an embodiment, the second tenant space of the data using department accesses the authorized first data table of the first data resource package through the data soft switching transmission channel, and obtains final result data after performing association calculation on the second data table of the second data resource package in the tenant space.

[0049] The above-mentioned data soft switching method based on tenant space provided by the embodiment of the present application can limit the access of a task to system resources and guarantee the data security when multiple tenants share computing resources, because the data trusted computing environment provides a sandbox mechanism for running tasks, and the second tenant space of the data using department can read the data resources in the first tenant space through a data soft switching transmission channel. The tenant space can independently manage its own data resources, and the cross-department data sharing is controllable in scope, which improves the problems of difficulty in large-scale data sharing and poor data security between departments.

[0050] It should be noted that the method provided by the embodiment of the present application has the same implementation principle and technical effects as the foregoing system embodiment, and for brevity, the part not mentioned in the method embodiment can be referred to the corresponding content in the foregoing system embodiment.

[0051] The embodiment of the present application further provides an electronic device, and specifically, the electronic device comprises a processor and a storage device; the storage device stores a computer program, and the computer program performs the method according to any one of the above embodiments when the computer program is run by the processor.

[0052] Figure 4 A structural schematic diagram of an electronic device provided by the embodiment of the present application is shown in the figure, and the electronic device 100 comprises a processor 40, a memory 41, a bus 42 and a communication interface 43, the processor 40, the communication interface 43 and the memory 41 are connected through the bus 42; the processor 40 is used for executing an executable module stored in the memory 41, for example, a computer program.

[0053] The memory 41 can contain a high-speed random access memory (RAM), and can also contain a non-volatile memory, for example, at least one disk memory. The communication connection between the system network element and at least one other network element is realized through the at least one communication interface 43 (which can be wired or wireless), and the Internet, a wide area network, a local area network, a metropolitan area network and the like can be used.

[0054] The bus 42 can be an ISA bus, a PCI bus or an EISA bus and the like. The bus can be divided into an address bus, a data bus, a control bus and the like. For the convenience of representation, Figure 4 Only one bidirectional arrow is used in the figure, but it does not mean that there is only one bus or only one type of bus.

[0055] The memory 41 is used for storing a program, and the processor 40 executes the program after receiving an execution instruction; the method performed by the device defined by the flow process disclosed in any one of the above embodiments can be applied to the processor 40 or realized by the processor 40.

[0056] The processor 40 can be an integrated circuit chip with signal processing capability. In implementation, each step of the above method can be completed by integrated logic circuit of hardware in the processor 40 or by instructions in the form of software. The processor 40 described above can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component. Each method, step and logic block diagram disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium in the art. The storage medium is located in the memory 41, and the processor 40 reads the information in the memory 41, and combines the hardware to complete the steps of the above method.

[0057] The computer program product of the readable storage medium provided by the embodiments of the present application includes a computer readable storage medium storing program codes, and the program codes include instructions for executing the method described in the foregoing method embodiments. For specific implementation, reference can be made to the foregoing method embodiments, which will not be described here.

[0058] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the present application that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of software products. The computer software product is stored in a storage medium and includes instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in the embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0059] Finally, it should be noted that: the above-described embodiments are only specific embodiments of the present application, which are used to illustrate the technical solutions of the present application, but not to limit them. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily think of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed by the present application, or make equivalent replacements to some of the technical features. The modifications, changes or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A tenant-space-based data softswitch system, characterized in that, include: The system comprises a first tenant space deployed by the public data authority, a second tenant space deployed by the data user department, a data softswitch transmission channel, and a trusted computing environment for data resources; wherein the first tenant space, the second tenant space, and the data softswitch transmission channel are deployed in the trusted computing environment for data resources, and the trusted computing environment for data resources provides a sandbox mechanism for running tasks; The first tenant space and the second tenant space are used for the storage and computation of data resources; During data sharing, the second tenant space reads the data resources of the first tenant space through the data softswitch transmission channel.

2. The system according to claim 1, characterized in that, Also includes: A resource access permission control component, deployed in the trusted computing environment for data resources, is used to set the tenant space access permissions of the first tenant space for the data resources of the second tenant space.

3. The system according to claim 2, characterized in that, The first tenant space includes: at least one first data resource package, the first data resource package including at least one first data table; the second tenant space includes: at least one second data resource package, the second data package including at least one second data table.

4. The system according to claim 3, characterized in that, The second tenant space is used to determine the source data resource package and source data table to be accessed based on business needs, and to call the resource access permission control component to determine whether the second tenant space is authorized to access the source data resource package and the source data table based on the tenant space access permission. If the second tenant space is authorized to access the source data resource package and the source data table, a mapping relationship is established between the source data resource package and the source data table and the second data resource package; wherein, the source data resource package is one or more of the first data resource packages shown; and the source data table is one or more of the second data table.

5. The system according to claim 4, characterized in that, The second tenant space is also used to read the source data table of the first tenant space through the data softswitch transmission channel based on the mapping relationship.

6. The system according to claim 5, characterized in that, The second tenant space is also used to perform association calculations between the source data table and the second data table of the second tenant space to obtain the result data.

7. A data softswitch method based on tenant space, characterized in that, The method, applied to the tenant-space-based data softswitch system according to any one of claims 1 to 6, comprises: The second tenant space determines the data resources to be accessed in the first tenant space based on business needs; The second tenant space reads the data resources to be accessed from the first tenant space through the data softswitch transmission channel.

8. The method according to claim 7, characterized in that, After determining the data resources to be accessed in the first tenant space based on business needs, the second tenant space also includes: The resource access permission control component is invoked, and based on the tenant space access permission set in the resource access permission control component, it is determined whether the second tenant space is authorized to access the data resources to be accessed in the first tenant space.

9. An electronic device, characterized in that, The method includes a processor and a memory, the memory storing computer-executable instructions executable by the processor, the processor executing the computer-executable instructions to implement the steps of the method of any one of claims 7 to 8.

10. A computer-readable storage medium storing a computer program thereon, characterized in that, The computer program is executed by the processor to perform the steps of the method described in any one of claims 7 to 8.