Data processing method, cloud storage system

By configuring request interception policies in the cloud storage system, utilizing one-click silent read/write functionality and path information matching, the problem of data leakage in cloud storage was solved, data security and access report generation were achieved, and the risk of data leakage was reduced.

CN122339716APending Publication Date: 2026-07-03ALIBABA CLOUD COMPUTING CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ALIBABA CLOUD COMPUTING CO LTD
Filing Date
2025-01-03
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Existing cloud storage services pose a risk of data breaches, especially in object storage scenarios where data importance is protected. Increased public and private network requests can lead to financial losses and data breaches, and existing solutions cannot effectively restrict private network access or provide data access reports.

Method used

By blocking public access and using a one-click silent read/write function, a request interception strategy is configured using a matching algorithm of buckets, prefixes, and filenames. Data processing requests are intercepted based on path information and the interception strategy to ensure data security.

Benefits of technology

It effectively reduces the risk of data leakage in cloud storage systems, avoids data leakage caused by data processing requests, provides data access reports for evaluation, and ensures data security and controllability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122339716A_ABST
    Figure CN122339716A_ABST
Patent Text Reader

Abstract

The embodiment of the present specification provides a data processing method and a cloud storage system. The data processing method is applied to a cloud storage server in a cloud storage system. The method comprises the following steps: receiving a data processing request for target data, wherein the data processing request is sent through a data storage address corresponding to the target data; determining a unit identifier of a target storage unit and path information of the target data based on the data storage address, wherein the target storage unit is used for storing the target data, and the path information represents a storage position of the target data in the target storage unit; determining a target request interception strategy corresponding to the target storage unit from a plurality of request interception strategies based on the unit identifier; determining the to-be-intercepted path information corresponding to the target request interception strategy, and performing interception processing on the data processing request in the case that the to-be-intercepted path information is consistent with the path information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of cloud storage technology, and in particular to a data processing method. One or more embodiments of this specification also relate to a cloud storage system, a computing device, a computer-readable storage medium, and a computer program product. Background Technology

[0002] With the continuous development of computer technology, massive amounts of data are generated during data processing, requiring extensive storage. While cloud storage services can currently handle this data storage, they also carry the risk of data leakage. Therefore, mitigating this risk is a pressing technical challenge. Summary of the Invention

[0003] In view of the above, embodiments of this specification provide a data processing method. One or more embodiments of this specification also relate to a cloud storage system, a data processing apparatus, a computing device, a computer-readable storage medium, and a computer program product, to address the technical deficiencies existing in the prior art.

[0004] According to a first aspect of the embodiments of this specification, a data processing method is provided, applied to a cloud storage service terminal in a cloud storage system, the method comprising: Receive a data processing request for target data, wherein the data processing request is sent through the data storage address corresponding to the target data; Based on the data storage address, the unit identifier of the target storage unit and the path information of the target data are determined, wherein the target storage unit is used to store the target data, and the path information indicates the storage location of the target data in the target storage unit; Based on the unit identifier, a target request interception policy corresponding to the target storage unit is determined from multiple request interception policies; Determine the path information to be intercepted corresponding to the target request interception strategy, and if the path information to be intercepted is consistent with the path information, perform interception processing on the data processing request.

[0005] According to a second aspect of the embodiments of this specification, a data processing apparatus is provided, applied to a cloud storage service terminal in a cloud storage system, the apparatus comprising: The request receiving module is configured to receive a data processing request for target data, wherein the data processing request is sent through the data storage address corresponding to the target data; The path information determination module is configured to determine the unit identifier of the target storage unit and the path information of the target data based on the data storage address, wherein the target storage unit is used to store the target data, and the path information indicates the storage location of the target data in the target storage unit; The strategy determination module is configured to determine, based on the unit identifier, a target request interception strategy corresponding to the target storage unit from multiple request interception strategies; The request interception module is configured to determine the path information to be intercepted corresponding to the target request interception strategy, and to perform interception processing on the data processing request if the path information to be intercepted is consistent with the path information.

[0006] According to a third aspect of the embodiments of this specification, a cloud storage system is provided, the system comprising a cloud storage service client and a client, wherein... The client is configured to send a data processing request for the target data to the cloud storage service client via the data storage address corresponding to the target data. The cloud storage service client is configured to receive the data processing request for the target data, determine the unit identifier of the target storage unit and the path information of the target data based on the data storage address, wherein the target storage unit is used to store the target data, and the path information indicates the storage location of the target data in the target storage unit, determine the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier, determine the path information to be intercepted corresponding to the target request interception policy, and perform interception processing on the data processing request if the path information to be intercepted is consistent with the path information.

[0007] According to a fourth aspect of the embodiments of this specification, a computing device is provided, comprising: Memory and processor; The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions, which, when executed by the processor, implement the steps of the above-described data processing method.

[0008] According to a fifth aspect of the embodiments of this specification, a computer-readable storage medium is provided that stores a computer program / instructions that, when executed by a processor, implement the steps of the data processing method described above.

[0009] According to a sixth aspect of the embodiments of this specification, a computer program product is provided, including a computer program / instructions that, when executed by a processor, implement the steps of the data processing method described above.

[0010] This specification provides one or more embodiments of a data processing method for a cloud storage service client applied in a cloud storage system. Considering the potential risk of data leakage in cloud storage systems, this method, upon receiving a data processing request for target data stored in a target storage unit, determines a target request interception policy corresponding to the target storage unit from multiple request interception policies; and, if it is determined that the path information to be intercepted corresponding to the target request interception policy is consistent with the path information in the data storage address, performs interception processing on the data processing request, thereby avoiding the problem of data leakage caused by the data processing request and reducing the risk of data leakage in the cloud storage system. Attached Figure Description

[0011] Figure 1 This is a schematic diagram illustrating the application of a data processing method provided in one embodiment of this specification; Figure 2 This is a flowchart illustrating a data processing method provided in one embodiment of this specification; Figure 3 This is a schematic diagram of the one-click silent function of the object storage service in a data processing method provided in one embodiment of this specification; Figure 4 This is a flowchart illustrating the processing procedure of a data processing method provided in one embodiment of this specification. Figure 5 This is a schematic diagram of the structure of a cloud storage system provided in one embodiment of this specification; Figure 6 This is a schematic diagram of the structure of a data processing apparatus provided in one embodiment of this specification; Figure 7 This is a structural block diagram of a computing device provided in one embodiment of this specification. Detailed Implementation

[0012] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.

[0013] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.

[0014] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0015] Furthermore, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0016] First, the terms and concepts used in one or more embodiments of this specification will be explained.

[0017] OSS (Object Storage Service): Refers to object storage service. OSS is an internet cloud storage service primarily used for the storage and management of massive amounts of data.

[0018] An object is a basic unit of data stored in OSS. Each object is a file, which can be of any format, such as a text file, image, or video. An object consists of three parts: metadata, a key, and the actual data content.

[0019] Bucket: A bucket is a logical container used in OSS to store objects. You can think of a bucket as a folder or directory, except that this "folder" exists in the cloud and can store a large number of files (objects).

[0020] Error code: A string used to further describe the specific error type. For example: NoSuchBucket indicates that the requested bucket does not exist.

[0021] AccessDenied indicates that you do not have sufficient permissions to perform the operation.

[0022] One-click silent read / write: This refers to the ability to configure data storage with a single click, controlling the dataset to enter read-prohibited (prohibited reading), write-prohibited (prohibited writing), and read-and-write-prohibited (prohibited reading and writing) modes, and providing subsequent data access statistics reports.

[0023] Public access refers to accessing OSS resources without specific permissions or authentication. Public access can easily lead to data leaks and the risk of malicious access resulting in a large amount of external network downlink traffic.

[0024] Block public access: This means prohibiting access to OSS resources without specific permissions or authentication. After enabling block public access, existing public access permissions will be ignored and the creation of new public access permissions will not be allowed, thereby closing the public access channels to the data and ensuring data security.

[0025] A URL (Uniform Resource Locator) is an address used to identify and locate resources on the Internet. It can point to various types of resources such as web pages, images, videos, and files. Every file on the Internet has a unique URL, containing information indicating the file's location and how the browser should handle it. A URL can contain the following parts: 1. Protocol: Specifies the protocol used to access the resource, such as `http` or `https` (Hypertext Transfer Protocol and its secure version), `ftp` (File Transfer Protocol), etc. 2. Subdomain (optional): Some websites use subdomains to organize content or services, such as `mail` in `mail.google.com`. 3. Main domain: This is the main part of the URL, usually representing the organization or entity to which the website belongs, such as `google.com`. 4. Path: Specifies the specific location or resource name on the server, such as ` / search` for the search page.

[0026] ECS (Elastic Compute Service): refers to cloud servers. ECS is a simple, efficient, secure, reliable computing service with elastically scalable processing capabilities.

[0027] RDS (Relational Database Service): A relational cloud database.

[0028] With the continuous development of computer technology, massive amounts of data are generated during data processing, requiring extensive storage. While cloud storage services can currently handle this data storage, they also carry the risk of data leakage. For example, in object storage scenarios involving data importance protection, one potential scenario is malicious data access. A surge in requests across public and private networks can lead to substantial financial losses, and public network access also carries the risk of data leakage.

[0029] For example, in the context of data importance protection in object storage, another scenario is that when a customer needs to transfer data, delete data, or cancel an account, the company's account administrator may not know whether the data has been used, resulting in data loss when deleting accounts and data.

[0030] To address the aforementioned issues, this manual provides a solution by blocking public access. Since public access easily leads to data leaks and the risk of malicious access generating significant external network downlink traffic, enabling public access blocking ignores existing public access permissions and prevents the creation of new public access permissions, thereby closing public access channels and ensuring data security. However, this solution has drawbacks: it does not restrict access to private networks (such as ECS and RDS cloud services) and does not provide data access reports for evaluation.

[0031] Based on this, a data processing method is provided in this specification. One or more embodiments of this specification also relate to a cloud storage system, a data processing apparatus, a computing device, a computer-readable storage medium, and a computer program product, which will be described in detail in the following embodiments.

[0032] See Figure 1 , Figure 1 This diagram illustrates an application illustration of a data processing method according to an embodiment of this specification, based on... Figure 1 As can be seen, server 10 (i.e., cloud storage service client) can connect to one or more client devices 20 via a local area network (LAN), wide area network (WAN), internet connection, or other types of data network. These client devices 20 may include, but are not limited to, smartphones, tablets, laptops, PDAs, personal computers, smart home devices, and in-vehicle devices. Client devices 20 can interact with users through a graphical user interface to implement the methods provided in the embodiments of this specification.

[0033] In the embodiments of this specification, the system consisting of client device 20 and server 10 can perform the following steps: client device 20 sends a read data access request (i.e., a data processing request) to server 10; server 10 receives the request and performs a check using the one-click silent read / write function; wherein, receiving the request means that server 10 receives the read data access request using the object storage server access layer; performing a check using the one-click silent read / write function means that the read data access request is checked using the configured one-click silent function, and the read data access request is intercepted if the check fails.

[0034] It should be noted that server 10 intercepts read and write requests sent by client device 20 by using a bucket name matching algorithm, a bucket + prefix name matching algorithm, and a bucket + prefix + filename matching algorithm to see if a rule is matched. If a rule is matched, the request is executed; otherwise, the request is allowed.

[0035] See Figure 2 , Figure 2 A flowchart of a data processing method according to an embodiment of this specification is shown. This data processing method is applied to a cloud storage service in a cloud storage system and specifically includes the following steps.

[0036] Step 202: Receive a data processing request for the target data, wherein the data processing request is sent through the data storage address corresponding to the target data.

[0037] In this context, a cloud storage system can be understood as a system that provides cloud storage services. For example, the cloud storage system can be an OSS system, an object storage service (OSS) system, or an object storage system.

[0038] A cloud storage service client can be understood as the server-side component of a cloud storage system. For example, this cloud storage service client can be an object storage service client. This cloud storage service client can be hardware devices such as servers, or software modules such as cloud servers and applications.

[0039] The target data can be understood as data stored in a cloud storage system. For example, the target data can be any type of data such as text, image, video, or audio, without specific limitations. In the embodiments of this specification, the target data can be an object in an object storage service system.

[0040] A data processing request can be understood as a request to process the target data. For example, a data processing request can be a data read request, a data write request, a data update request, or a data deletion request.

[0041] A data storage address can be understood as an address that represents the storage location of target data. The target data can be retrieved through this data storage address; for example, the data storage address can be a URL.

[0042] A target storage unit can be understood as a unit in a cloud storage system used to store target data. For example, the target storage unit can be a bucket, a folder, or other hardware device for storing target data, such as a hard drive or disk.

[0043] In one or more embodiments provided in this specification, receiving a data processing request for target data includes: Receive a data processing request for target data sent by a client, wherein the data processing request is sent by the client when the user performs a data processing operation based on the data processing interface, and the data storage address is confirmed by the user when performing the data processing operation; The data processing interface can be understood as a human-computer interaction interface used to process target data. For example, the data processing interface can be understood as a webpage or application interface; the data processing operation can be understood as a data read operation or data write operation performed on the target data based on the data processing interface.

[0044] Taking the application of the data processing method provided in this manual in a data read / write scenario as an example, this data processing method will be explained. In this method, the cloud storage service is an object storage service, the target data is an object, and the data processing request is a data read / write request.

[0045] Based on this, when users need to perform read or write operations on buckets in the cloud storage service (OSS), they can provide the URL of the target data through the human-computer interaction interface in the client, and send a data read / write request to the object storage service based on the URL, thereby instructing the object storage service to perform read or write operations on the objects in the bucket; thus meeting the user's needs for reading and writing target data.

[0046] It's important to note that in object storage, each object can be represented by a complete path (i.e., a URL). When used as a static website, this is what is presented externally as a URL. A typical URL naming format is https: / / BucketName.Endpoint / Object, where the object has a prefixed name.

[0047] For example, ABC Company created an AAA bucket in its object storage service system. Data in the AAA bucket can be accessed or written through the domain name https: / / aaa.oss-c***hou.ali**cs.com / .

[0048] For example, the finance department is prefixed with finance / . This finance / directory currently contains 10 files, from file1.jpg to file10.jpg. You can access file1.jpg using the following URL.

[0049] https: / / aaa.oss-c***hou.ali**cs.com / finance / file1.jpg Based on the above, we know that a bucket is a space in an object storage system that stores customer data (similar to a file cabinet), while an object is a specific file. The prefix can be understood as dividing the file cabinet (bucket) into several layers (the first layer stores financial documents, the second layer stores legal documents, the third layer stores R&D documents, and so on). In practice, it is represented by the domain name (the domain name formed by the aaa bucket in the example), the prefix (finance / in the example), and the file name (file1.jpg in the example).

[0050] In one or more embodiments provided in this specification, receiving a data processing request for target data includes: Receive a data processing request sent by a data processing device, wherein the data processing request is sent by the data processing device when performing a data processing operation.

[0051] Here, the data processing device can be understood as a device that needs to process the target data in the target storage unit. For example, the data processing device can be a server, cloud server, server, smart device (such as smartwatch, smart AI glasses, etc.), etc., without specific restrictions. The data processing request can be understood as a request to perform operations such as reading, writing, and updating the target data.

[0052] Step 204: Based on the data storage address, determine the unit identifier of the target storage unit and the path information of the target data, wherein the target storage unit is used to store the target data, and the path information indicates the storage location of the target data in the target storage unit.

[0053] The unit identifier can be understood as information that uniquely identifies a target storage unit. For example, the unit identifier can be the name, number, address, etc. of the target storage unit, without any specific restrictions.

[0054] Path information can be understood as information used to identify the storage location of target data in the target storage unit.

[0055] Using the previous example, when the object storage service receives a data read / write request, it can determine the URL (i.e., the data storage address) corresponding to the data read / write request, and obtain the identification information (i.e., the unit identifier) ​​of the bucket (i.e., the target storage unit) from the URL. This identification information can be aaa, as well as the path information of the object (i.e., the target data) (finance / file1.jpg).

[0056] Step 206: Based on the unit identifier, determine the target request interception policy corresponding to the target storage unit from multiple request interception policies.

[0057] Specifically, this method can pre-build corresponding request interception strategies for one or more storage units in the cloud storage system. When a data processing request for a target storage unit is received, the request interception strategy corresponding to the target storage unit can be determined from multiple request interception strategies. The target storage unit can be any one of the multiple storage units, or the target storage unit can be a storage unit in the cloud storage system.

[0058] In one or more embodiments provided in this specification, determining the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier includes: The policy construction unit identifier is determined from the policy parameters corresponding to each request interception policy, and the request interception policy whose policy construction unit identifier is consistent with the unit identifier is determined as the target request interception policy corresponding to the target storage unit.

[0059] The request interception strategy can be understood as a strategy used to intercept data processing requests. This request interception strategy can be a bucket strategy, a silent strategy, etc.

[0060] Among them, the strategy building unit identifier refers to the unit identifier of the storage unit corresponding to the request interception strategy. In the process of building the request interception strategy, the strategy building unit identifier in the strategy parameters is used to specify the storage unit corresponding to the request interception strategy.

[0061] The strategy parameter can be understood as the parameter corresponding to the request interception strategy. The request interception strategy can be constructed based on the strategy parameter. An illustration of the strategy parameter can be seen in Table 1 below.

[0062] Table 1

[0063] In Table 1, “UserID” represents the user identifier that builds the request interception policy; “ConfigId” refers to the identifier of the request interception policy.

[0064] In Table 1, "scopeType" represents the silent data range, and its value is the identifier of the silent data range. For example, scopeType 0 indicates all buckets, and the value of the corresponding subsequent field is 0; scopeType 1 indicates a single bucket, and the value of the corresponding subsequent field is the bucket name; scopeType 2 indicates a specified prefix, and the value of the corresponding subsequent field is the prefix name of the bucket; scopeType 3 indicates a specified object, and the value of the corresponding subsequent field is the object name of the bucket.

[0065] Based on this, it can be seen that the data interception scope of the request interception strategy in this method is: all buckets, a single bucket, a specified prefix, and a specified object.

[0066] The Mode in Table 1 represents the silent strategy: 0 means read is prohibited, 1 means write is prohibited, and 2 means both read and write are prohibited.

[0067] The values ​​in Table 1 indicate the start time of the request interception policy.

[0068] In Table 1, ReportPeriod refers to the reporting period: 0 indicates hourly, 1 indicates daily, 2 indicates weekly, and 3 indicates monthly.

[0069] Following the previous example, during request interception, the object storage service client determines the policy parameters (i.e., the contents of Table 1) of the pre-built multiple bucket policies (request interception policies), and determines the bucket name (e.g., policy building unit identifier) ​​corresponding to the bucket policy from the configuration parameters. This bucket name can be "aaa". Then, it compares the bucket name with the bucket name "aaa" (i.e., unit identifier) ​​carried in the URL. If the two bucket names match, the bucket policy corresponding to the bucket name "aaa" is determined as the bucket policy that needs to be executed for request interception. Subsequently, data processing requests are accurately intercepted based on this bucket policy.

[0070] In one or more embodiments provided in this specification, before determining the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier, the method further includes: Receive an interception policy construction request, wherein the interception policy construction request is sent by the policy construction end when the user performs an interception policy construction operation based on the interception policy construction interface, and the interception policy construction request carries policy parameters for constructing the interception policy construction policy; Obtain the strategy construction unit identifier from the strategy parameters, and based on the strategy construction unit identifier, determine the strategy construction storage unit from multiple storage units on the cloud storage service side, wherein the strategy construction storage unit is any one of the multiple storage units; Based on the strategy parameters, a corresponding request interception strategy is constructed for the strategy storage unit.

[0071] Here, "interception policy construction request" can be understood as a request to construct the interception policy for this request, and "interception policy construction interface" can be understood as the human-computer interaction interface used to construct the interception policy for this request; for example, the interception policy construction interface can be understood as a webpage or application interface. "Interception policy construction operation" can be understood as the operation to construct the interception policy for this request, such as clicking, selecting, or entering policy parameters.

[0072] Among them, the policy construction storage unit can be understood as the storage unit among multiple storage units that needs to construct the request interception policy.

[0073] Following the previous example, based on Figure 3 It can be seen that, Figure 3 This is a schematic diagram of the one-click silent function in an object storage service client of a data processing method provided in one embodiment of this specification. This method can configure a "one-click silent function" module for the object storage service client. When the configuration takes effect, the client's request will be checked by the "one-click silent function" module. If the check fails, it will return failure. The one-click silent function module includes a policy generation module and a log reporting module.

[0074] The policy generation module refers to the module that generates bucket policies. In this method, a policy construction request can be sent through a configuration tool (human-computer interaction interface). The policy generation module will then generate a one-click silent function record according to the customer's requirements, and then generate a Bucket Policy for the bucket (target storage unit) selected by the customer and save it for effect. The one-click silent function requires saving the customer's configuration so that access requests can be correctly checked and log reports can be generated as required after the configuration is completed. Table 1 is the configuration saving table. Subsequent client requests will be checked and blocked by the bucket policy.

[0075] This policy generation module can configure three silent policies (prohibit reading, prohibit writing, and prohibit both reading and writing) based on four data ranges (all buckets, single bucket, specified prefix, and specified object), and then generate and save the Bucket Policy.

[0076] The log reporting module can collect and analyze access logs based on the configuration effective time, and generate reports on a periodic basis (hourly, daily, weekly, monthly, etc.) until the configuration expires.

[0077] Step 208: Determine the path information to be intercepted corresponding to the target request interception strategy, and if the path information to be intercepted is consistent with the path information, perform interception processing on the data processing request.

[0078] The path information to be intercepted can be understood as the path information corresponding to the data processing request that needs to be intercepted. Since the data processing request is sent through the data storage address, the data processing request has corresponding path information. The path information to be intercepted is the path information that needs to be intercepted. When the path information to be intercepted is consistent with the path information, it is determined that the data processing request needs to be intercepted.

[0079] In one or more embodiments provided in this specification, determining the path information to be intercepted corresponding to the target request interception strategy, and performing interception processing on the data processing request when the path information to be intercepted matches the path information, includes: The interception type is determined from the target policy parameters corresponding to the target request interception policy; When the interception type is path interception, the path information to be intercepted is obtained from the target policy parameters; If the path information to be intercepted is consistent with the path information, the data processing request will be intercepted.

[0080] Interception type can be understood as the type of interception method for data processing requests, that is, the range of intercepted data. For example, the interception type can be a silent (i.e., read and write prohibited) data range, which includes, but is not limited to: all buckets (i.e., all unit interception type), single bucket (i.e., target unit interception type), specified prefix (i.e., path interception type), specified object (i.e., target data interception type).

[0081] Path interception type can be understood as the type of interception of data processing requests based on path information.

[0082] Using the previous example, when the client sends a request, it will be checked by the "one-click silence function". The range of data to be silenced (prohibited from reading and writing) in this method can be a specified prefix (i.e. path information). If the prefix (i.e. path information) corresponding to the data read / write request is consistent with the prefix (i.e. path information to be intercepted) provided by the client, then it is determined that interception is required; if the check fails, a failure message (i.e. request interception prompt message) will be returned.

[0083] As can be seen from the above embodiments, this method can accurately intercept data processing requests by intercepting them through path information, thereby avoiding the risk of data leakage or improper data processing.

[0084] In one or more embodiments provided in this specification, the data processing request is a data read request or a data write request; After determining the path information to be intercepted corresponding to the target request interception policy, the method further includes: If the path information to be intercepted is inconsistent with the path information, in response to the data read request, the target data is determined from the target storage unit using the path information, and the target data is sent to the client corresponding to the data read request; or If the path information to be intercepted is inconsistent with the path information, the target data carried in the data processing request is stored in the target storage unit based on the path information.

[0085] Here, the data read request can be understood as a request to retrieve target data from the target storage unit; the data write request can be understood as a request to write target data into the target storage unit.

[0086] Using the previous example, if the prefix (path information) corresponding to the data read request is inconsistent with the prefix provided by the client (i.e., the path information to be intercepted), it is determined that no interception is needed. Then, by executing the data read request, the object is obtained from the bucket and sent to the client, which refers to the device that sends the data read request to the object storage service.

[0087] Alternatively, if the prefix (path information) corresponding to the data write request is inconsistent with the prefix provided by the client (i.e., the path information to be intercepted), it is determined that no interception is needed. In this case, the target data carried in the data write request is written into the bucket by executing the data processing request.

[0088] As can be seen from the above embodiments, this device can execute the data processing request when it is determined that there is no need to intercept the data processing request, thereby ensuring the smooth execution of data processing while avoiding the risk of data leakage or improper data processing.

[0089] When the path information to be intercepted matches the path information, the interception process for the data processing request includes: The request type of the data processing request is determined, and the request type to be intercepted is determined from the target policy parameters corresponding to the target request interception policy. The request type to be intercepted includes: read request type and / or write request type. The request type includes: read request type or write request type. If the type of the request to be intercepted corresponds to the request type and the path information to be intercepted is consistent with the path information, the data processing request will be intercepted.

[0090] The type of request to be intercepted can be understood as the type of data processing request that needs to be intercepted.

[0091] Following the previous example, this method configures three silent strategies (prohibit reading (read request interception strategy type), prohibit writing (write request interception strategy type), and prohibit both reading and writing (read and write request interception strategy type)). Based on this, when a data processing request is received from a client, the data processing request will be checked by the silent strategy. By configuring the silent "prohibit reading, prohibit writing, prohibit both reading and writing" mode, the request will be intercepted. In addition, the data processing request also needs to be intercepted through the data range to be intercepted configured by the bucket strategy.

[0092] If a data processing request fails to pass the checks of the silent policy and the path information to be intercepted, the data processing request will be intercepted. This dual-interception strategy can more accurately intercept data processing requests and ensure data security.

[0093] In one or more embodiments provided in this specification, after determining the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier, the method further includes: From the target policy parameters corresponding to the target request interception policy, the interception type is determined, wherein the interception type includes all unit interception type, target unit interception type, and target data interception type; If the interception type is one of the all-unit interception types, the data processing request will be intercepted. When the interception type is the target unit interception type, the identifier of the storage unit to be intercepted is obtained from the target policy parameters, and if the identifier of the storage unit to be intercepted is consistent with the unit identifier, the data processing request is intercepted. When the interception type is the target data interception type, the data identifier to be intercepted is obtained from the target policy parameters, and if the data identifier to be intercepted is consistent with the data identifier of the target data, the data processing request is intercepted.

[0094] Following the previous example, the client's request will be checked by the "one-click silence function". The scope of data to be silenced by this method can be: all buckets (all unit interception type), a single bucket (target object interception type), or a specified object (target data interception type). If the bucket identifier corresponding to the data read / write request is consistent with the bucket identifier (all buckets or a single bucket) provided by the client, then it is determined that interception is required; or if the object name corresponding to the data read / write request is consistent with the object name (specified object) provided by the client, then it is determined that interception is required.

[0095] As can be seen from the above embodiments, this method can also configure various data ranges such as all buckets (all unit interception types), single bucket (target object interception type), and specified object (target data interception type) during the interception of data processing requests, thereby providing the applicability and flexibility of this method.

[0096] In one or more embodiments provided in this specification, determining the interception type from the target policy parameters corresponding to the target request interception policy includes: The request type of the data processing request is determined, and the request interception strategy type is determined from the target strategy parameters corresponding to the target request interception strategy. The interception strategy type includes: read request interception strategy type, write request interception strategy type, and read-write request interception strategy type. The request type includes: read request type and write request type. If the request interception policy type is the read request interception policy type and the request type is a read request type, the interception type is determined from the target policy parameters; If the request interception policy type is the write request interception policy type and the request type is a write request type, the interception type is determined from the target policy parameters; When the request interception policy type is the read / write request interception policy type, the interception type is determined from the target policy parameters.

[0097] Following the previous example, the method configures three silent strategies (prohibit read (read request interception strategy type), prohibit write (write request interception strategy type), and prohibit both read and write (read and write request interception strategy type)). Based on this, client requests will be checked by the strategies. By configuring the silent "prohibit read, prohibit write, prohibit both read and write" mode, the request is checked. After the request passes the check, subsequent operations based on the silent data range will be executed. Thus, through the dual interception strategy, data processing requests are intercepted more accurately, ensuring data security.

[0098] In one or more embodiments provided in this specification, after performing interception processing on the data processing request when the path information to be intercepted is consistent with the path information, the method further includes: Determine the request information of the data processing request and store the request information in an information storage object.

[0099] The request information can be understood as the information corresponding to the data processing request. For example, the request information includes, but is not limited to, information such as IP address, request type, and request sending time.

[0100] An information storage object can be understood as an object used to store the requested information. This information storage object can be a log file, a cache area, etc.

[0101] Following the previous example, after the client request is checked and blocked by the policy, the object storage service will store the request information in the log file, which will facilitate the generation of reports in the future.

[0102] In one or more embodiments provided in this specification, after storing the request information in the information storage object, the method further includes: Determine the policy parameters corresponding to the target request interception policy, and determine the information feedback time based on the feedback period information in the policy parameters; If the current time is consistent with the information feedback time, the request information in the information storage object is sent to the policy construction end corresponding to the target request interception policy.

[0103] The policy building end can be understood as the client that builds the policy for intercepting the target request. This policy building end can be a terminal device, application, etc.

[0104] The information feedback time can be defined as the time when the request information is fed back to the policy building end. During the process of building the target request interception policy, the policy building end will configure the feedback cycle information of the intercepted request information. Therefore, this method can calculate the information feedback time of the next request information based on the feedback cycle information, so as to accurately send the request information to the policy building end according to the requirements.

[0105] Following the previous example, after the client request is checked and blocked by the policy, the object storage service server generates a silent read / write statistics report by analyzing the access logs according to the configured reporting period, and sends the statistics report to the policy building end as required.

[0106] In one or more embodiments provided in this specification, after performing interception processing on the data processing request when the path information to be intercepted is consistent with the path information, the process includes: Determine the request interception prompt information corresponding to the data processing request, and send the request interception prompt information to the client.

[0107] Using the previous example, when the client sends a request, it will be checked by the "one-click silent function". If the check fails, a failure message will be returned. This failure message can be an error code, indicating that the silent read / write function is in effect, thus promptly reminding the user.

[0108] Furthermore, in one or more embodiments provided in this specification, after performing interception processing on the data processing request when the path information to be intercepted is consistent with the path information, the process includes: The request interception prompt information corresponding to the data processing request is determined, and the request interception prompt information is sent to the data processing device.

[0109] This specification provides one or more embodiments of a data processing method for a cloud storage service client applied in a cloud storage system. Considering the potential risk of data leakage in cloud storage systems, this method, upon receiving a data processing request for target data stored in a target storage unit, determines a target request interception policy corresponding to the target storage unit from multiple request interception policies; and, if it is determined that the path information to be intercepted corresponding to the target request interception policy is consistent with the path information in the data storage address, performs interception processing on the data processing request, thereby avoiding the problem of data leakage caused by the data processing request and reducing the risk of data leakage in the cloud storage system.

[0110] The following is in conjunction with the appendix Figure 4 Taking the application of the data processing method provided in this specification in an object storage scenario as an example, the data processing method will be further explained. Figure 4 A flowchart illustrating the processing procedure of a data processing method provided in one embodiment of this specification is shown.

[0111] It should be noted that this method can be applied to "accidental deletion of accounts and data" and "malicious data access". In the "accidental deletion of accounts and data" scenario, when a customer needs to transfer data, delete data, or cancel an account, the company's account administrator may not know whether the data has been used, resulting in data loss when deleting accounts and data. In the "malicious data access" scenario, the number of requests on the public and private networks increases significantly, resulting in huge financial losses.

[0112] The issues in the two scenarios mentioned above can be addressed through one-click silent read / write. In the "accidental deletion of accounts and data" scenario, a silent "read-blocked, write-blocked, read-and-write-blocked" mode can be configured, and statistical reports of data access can be submitted to identify access activity and take further action, thereby reducing accidental operations. In the "malicious data access" scenario, although there is a "block public access" feature, internal network access still occurs, resulting in additional access costs. Configuring a silent "read-blocked, write-blocked, read-and-write-blocked" mode and submitting statistical reports of data access can reduce financial losses.

[0113] Based on the above, it can be seen that by adding a one-click silent read / write function to the object storage service, the problems of "accidental deletion of accounts and data" and "malicious access to data" can be effectively solved, providing business value to customers.

[0114] By configuring a "one-click silence function" for object storage, once the configuration takes effect, client requests will be checked by the "one-click silence function". If the check fails, a failure will be returned, and access logs will be recorded for future report generation. The specific execution process includes the following steps.

[0115] Step 402: Send a read data access request.

[0116] Specifically, the client can send a read data access request to the object storage receiving module through the object storage server access layer.

[0117] Step 404: Silent function check, read-blocking is enabled.

[0118] Specifically, the object storage server access layer checks read data access requests through a configured one-click silent function, and the specific execution method is as follows: 1. The object storage server access layer determines the target bucket corresponding to the request from multiple buckets based on the URL of the read data access request; 2. Determine the bucket policy corresponding to the target bucket (the silent policy is read-free, and the data range is a specified prefix bucket policy).

[0119] 3. Check the read data access request according to the bucket policy. If it is determined that the read data access request is a read request and the specified prefix (finance / ) corresponding to the request is consistent with the prefix (finance / ) configured in the bucket policy, then the read data access request will be blocked.

[0120] Step 406: Returns a failure message.

[0121] The error code displayed in the failure message indicates that the silent read / write function is not enabled.

[0122] Step 408: Record the request information to the access log.

[0123] Specifically, after intercepting the read data access request, the IP address of the read data access request, the time the request was sent, the request type, and other information are recorded in the access log.

[0124] Subsequently, based on the reporting period (ReportPeriod) configured in the bucket policy, a silent read / write statistics report can be generated by analyzing the access logs and then sent to the customer administrator.

[0125] It should be noted that the statistical report will record information such as the visitor (anonymous visitor, designated user visitor), the IP address of the visitor (internal IP address and public IP address), the visit time, and the target of the visit.

[0126] After receiving the statistical report, the account administrator can perform the following actions: 1. For scenarios involving account and data deletion, notify visitors to migrate the data and specify which objects need to be migrated.

[0127] 2. For malicious access scenarios, based on the visitor information (anonymous access, specified user access), first configure access blocking to reduce financial losses, and then retain the ability to further pursue accountability based on the visitor and source IP.

[0128] In addition, the bucket policy in this method is generated by the customer providing configuration parameters for the one-click silent function through the configuration tool. The bucket policy is then generated based on these configuration parameters. The one-click silent function needs to save the customer's configuration so that access requests can be correctly checked after the configuration is completed.

[0129] The one-click silent function includes a policy generation module and a log reporting module.

[0130] The policy generation module is used to generate bucket policies. Based on the four data ranges configured by the customer (all buckets, single bucket, specified prefix, specified object) and the three silent policies configured (prohibit reading, prohibit writing, prohibit both reading and writing), the policy generation module generates a Bucket Policy and saves the customer configuration for subsequent access request checks based on the bucket policy.

[0131] For this configuration reference, please refer to the contents recorded in Table 1 above.

[0132] The log reporting module is used to report logs to customers. Based on the effective time of the configuration configured by the user, the log reporting module collects and analyzes access logs. Then, it generates reports on a periodic basis (hourly, daily, weekly, monthly, etc.) and feeds them back to the customer until the configuration expires.

[0133] Based on the above steps, the data processing method in one or more embodiments of this specification provides a solution for controlling silent read and write operations for object storage; it provides comprehensive control over public and private networks through a policy generation module; and it offers four data range configurations (all buckets, single bucket, specified prefix, specified object) and three silent policies (prohibit read, prohibit write, prohibit both read and write) to accurately detect requests. Furthermore, the log reporting module collects and analyzes access logs based on the configuration's effective time, generating reports periodically (hourly, daily, weekly, monthly, etc.) to allow customers to clearly understand the data access status after the silent operation.

[0134] In summary, the one-click silent read / write function in this method provides a rich set of data silencing strategies. It supports four data ranges (all buckets, single bucket, specified prefix, specified object) and three silencing strategies (prohibit read, prohibit write, prohibit both read and write); it also provides a silencing report function, which can collect and analyze access logs based on the configuration effective time, and generate reports on a periodic basis (hourly, daily, weekly, monthly, etc.), allowing customers to clearly understand the data intent access statistics after silencing, including but not limited to access targets, access frequency, and access source IP.

[0135] Corresponding to the above method embodiments, this specification also provides cloud storage system embodiments. Figure 5 A schematic diagram of the structure of a cloud storage system provided in one embodiment of this specification is shown. Figure 5 As shown, the system includes a cloud storage service client 504 and a client 502, wherein, The client 502 is configured to send a data processing request for the target data to the cloud storage service client 504 through the data storage address corresponding to the target data, wherein the target data is stored in the target storage unit in the cloud storage service client 504; The cloud storage service client 504 is configured to receive the data processing request for the target data, determine the unit identifier of the target storage unit and the path information of the target data based on the data storage address, wherein the target storage unit is used to store the target data, and the path information indicates the storage location of the target data in the target storage unit, determine the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier, determine the path information to be intercepted corresponding to the target request interception policy, and perform interception processing on the data processing request if the path information to be intercepted is consistent with the path information.

[0136] This specification provides one or more embodiments of a cloud storage system. Considering the potential risk of data leakage, the cloud storage service client of this system can, after receiving a data processing request from a client for target data stored in a target storage unit, determine the target request interception policy corresponding to the target storage unit from multiple request interception policies; and if it is determined that the path information to be intercepted corresponding to the target request interception policy is consistent with the path information in the data storage address, it will perform interception processing on the data processing request, thereby avoiding the problem of data leakage caused by the data processing request and reducing the risk of data leakage in the cloud storage system.

[0137] The above is an illustrative scheme of a cloud storage system according to this embodiment. It should be noted that the technical solution of this cloud storage system and the technical solution of the data processing method described above belong to the same concept. For details not described in detail in the technical solution of the cloud storage system, please refer to the description of the technical solution of the data processing method described above.

[0138] Corresponding to the above method embodiments, this specification also provides data processing apparatus embodiments. Figure 6 A schematic diagram of the structure of a data processing apparatus according to one embodiment of this specification is shown. Figure 6 As shown, the data processing device is applied to the cloud storage service terminal of the cloud storage system, and the device includes: The request receiving module 602 is configured to receive a data processing request for target data, wherein the data processing request is sent through the data storage address corresponding to the target data; The path information determination module 604 is configured to determine the unit identifier of the target storage unit and the path information of the target data based on the data storage address, wherein the target storage unit is used to store the target data, and the path information indicates the storage location of the target data in the target storage unit; The strategy determination module 606 is configured to determine, based on the unit identifier, a target request interception strategy corresponding to the target storage unit from multiple request interception strategies; The request interception module 608 is configured to determine the path information to be intercepted corresponding to the target request interception strategy, and to perform interception processing on the data processing request if the path information to be intercepted is consistent with the path information.

[0139] Optionally, the strategy determination module 606 is further configured to: Determine the policy construction unit identifier from the policy parameters corresponding to each request interception policy, and determine the request interception policy whose policy construction unit identifier matches the unit identifier as the target request interception policy corresponding to the target storage unit; Optionally, the request interception module 608 is further configured to: The interception type is determined from the target policy parameters corresponding to the target request interception policy; When the interception type is path interception, the path information to be intercepted is obtained from the target policy parameters; If the path information to be intercepted is consistent with the path information, the data processing request will be intercepted.

[0140] Optionally, the data processing device further includes a data processing module configured to: If the path information to be intercepted is inconsistent with the path information, the target data is determined from the target storage unit based on the path information; The target data is processed based on the data processing request to obtain the data processing result.

[0141] Optionally, the data processing device further includes a second request interception module, configured to: From the target policy parameters corresponding to the target request interception policy, the interception type is determined, wherein the interception type includes all unit interception type, target unit interception type, and target data interception type; If the interception type is one of the all-unit interception types, the data processing request will be intercepted. When the interception type is the target unit interception type, the identifier of the storage unit to be intercepted is obtained from the target policy parameters, and if the identifier of the storage unit to be intercepted is consistent with the unit identifier, the data processing request is intercepted. When the interception type is the target data interception type, the data identifier to be intercepted is obtained from the target policy parameters, and if the data identifier to be intercepted is consistent with the data identifier of the target data, the data processing request is intercepted.

[0142] Optionally, the request interception module 608 is further configured to: The request type of the data processing request is determined, and the request interception strategy type is determined from the target strategy parameters corresponding to the target request interception strategy. The interception strategy type includes: read request interception strategy type, write request interception strategy type, and read-write request interception strategy type. The request type includes: read request type and write request type. When the request interception policy type is the read request interception policy type and the request type is a read request type, the interception path information corresponding to the target request interception policy is determined; When the request interception policy type is the write request interception policy type and the request type is a write request type, the interception path information corresponding to the target request interception policy is determined; When the request interception policy type is the read / write request interception policy type, the path information to be intercepted corresponding to the target request interception policy is determined.

[0143] Optionally, the second request interception module is further configured to: The request type of the data processing request is determined, and the request interception strategy type is determined from the target strategy parameters corresponding to the target request interception strategy. The interception strategy type includes: read request interception strategy type, write request interception strategy type, and read-write request interception strategy type. The request type includes: read request type and write request type. If the request interception policy type is the read request interception policy type and the request type is a read request type, the interception type is determined from the target policy parameters; If the request interception policy type is the write request interception policy type and the request type is a write request type, the interception type is determined from the target policy parameters; When the request interception policy type is the read / write request interception policy type, the interception type is determined from the target policy parameters.

[0144] Optionally, the data processing device further includes an information storage module, configured as follows: Determine the request information of the data processing request and store the request information in an information storage object.

[0145] Optionally, the data processing device further includes an information feedback module, configured to: Determine the policy parameters corresponding to the target request interception policy, and determine the information feedback time based on the feedback period information in the policy parameters; If the current time is consistent with the information feedback time, the request information in the information storage object is sent to the policy construction end corresponding to the target request interception policy.

[0146] Optionally, the data processing device further includes a strategy construction module, configured to: Receive an interception policy construction request, wherein the interception policy construction request is sent by the policy construction end when the user performs an interception policy construction operation based on the interception policy construction interface, and the interception policy construction request carries policy parameters for constructing the interception policy construction policy; Obtain the strategy construction unit identifier from the strategy parameters, and based on the strategy construction unit identifier, determine the strategy construction storage unit from multiple storage units on the cloud storage service side, wherein the strategy construction storage unit is any one of the multiple storage units; Based on the strategy parameters, a corresponding request interception strategy is constructed for the strategy storage unit.

[0147] Optionally, the request receiving module 602 is further configured to: Receive a data processing request for target data sent by a client, wherein the data processing request is sent by the client when the user performs a data processing operation based on the data processing interface, and the data storage address is confirmed by the user when performing the data processing operation; Optionally, the data processing device further includes a prompt message sending module, configured to: Determine the request interception prompt information corresponding to the data processing request, and send the request interception prompt information to the client.

[0148] This specification provides one or more embodiments of a data processing device for a cloud storage service client in a cloud storage system. Considering the potential risk of data leakage in cloud storage systems, this device, upon receiving a data processing request for target data stored in a target storage unit, determines a target request interception strategy corresponding to the target storage unit from multiple request interception strategies. If the path information to be intercepted corresponding to the target request interception strategy matches the path information in the data storage address, the device performs interception processing on the data processing request, thereby preventing data leakage caused by the data processing request and reducing the risk of data leakage in the cloud storage system.

[0149] The above is an illustrative scheme of a data processing apparatus according to this embodiment. It should be noted that the technical solution of this data processing apparatus and the technical solution of the data processing method described above belong to the same concept. For details not described in detail in the technical solution of the data processing apparatus, please refer to the description of the technical solution of the data processing method described above.

[0150] Figure 7 A structural block diagram of a computing device 700 according to one embodiment of this specification is shown. The components of the computing device 700 include, but are not limited to, a memory 710 and a processor 720. The processor 720 is connected to the memory 710 via a bus 730, and a database 750 is used to store data.

[0151] The computing device 700 also includes an access device 740, which enables the computing device 700 to communicate via one or more networks 760. Examples of these networks include Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or combinations of communication networks such as the Internet. The access device 740 may include one or more of any type of wired or wireless network interface (e.g., a network interface card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Wi-MAX (Worldwide Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, or a Near Field Communication (NFC) interface.

[0152] In one embodiment of this specification, the above-described components of the computing device 700 and Figure 7 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 7 The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.

[0153] The computing device 700 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 700 can also be a mobile or stationary server.

[0154] The processor 720 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the above-described data processing method.

[0155] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the computing device embodiments are basically similar to the data processing method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the data processing method embodiments.

[0156] An embodiment of this specification also provides a computer-readable storage medium storing a computer program / instructions that, when executed by a processor, implement the steps of the above-described data processing method.

[0157] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the computer-readable storage medium embodiments are basically similar to the data processing method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the data processing method embodiments.

[0158] An embodiment of this specification also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the above-described data processing method.

[0159] The above is an illustrative scheme of a computer program product according to this embodiment. It should be noted that the technical solution of this computer program product and the technical solution of the data processing method described above belong to the same concept. For details not described in detail in the technical solution of the computer program product, please refer to the description of the technical solution of the data processing method described above.

[0160] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0161] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or certain intermediate forms. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately added or removed according to the requirements of patent practice. For example, in some regions, according to patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.

[0162] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification.

[0163] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0164] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.

Claims

1. A data processing method applied to a cloud storage service in a cloud storage system, the method comprising: Receive a data processing request for target data, wherein the data processing request is sent through the data storage address corresponding to the target data; Based on the data storage address, the unit identifier of the target storage unit and the path information of the target data are determined, wherein the target storage unit is used to store the target data, and the path information indicates the storage location of the target data in the target storage unit; Based on the unit identifier, a target request interception policy corresponding to the target storage unit is determined from multiple request interception policies; Determine the path information to be intercepted corresponding to the target request interception strategy, and if the path information to be intercepted is consistent with the path information, perform interception processing on the data processing request.

2. The data processing method according to claim 1, wherein determining the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier includes: Determine the policy construction unit identifier from the policy parameters corresponding to each request interception policy, and determine the request interception policy whose policy construction unit identifier matches the unit identifier as the target request interception policy corresponding to the target storage unit; The step of determining the path information to be intercepted corresponding to the target request interception strategy, and performing interception processing on the data processing request when the path information to be intercepted matches the path information, includes: The interception type is determined from the target policy parameters corresponding to the target request interception policy; When the interception type is path interception, the path information to be intercepted is obtained from the target policy parameters; If the path information to be intercepted is consistent with the path information, the data processing request will be intercepted.

3. The data processing method according to any one of claims 1 or 2, wherein the data processing request is a data read request or a data write request; After determining the path information to be intercepted corresponding to the target request interception policy, the method further includes: If the path information to be intercepted is inconsistent with the path information, in response to the data read request, the target data is determined from the target storage unit using the path information, and the target data is sent to the client corresponding to the data read request; or If the path information to be intercepted is inconsistent with the path information, the target data carried in the data processing request is stored in the target storage unit based on the path information.

4. The data processing method according to any one of claims 1 or 2, further comprising, after determining the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier: From the target policy parameters corresponding to the target request interception policy, the interception type is determined, wherein the interception type includes all unit interception type, target unit interception type, and target data interception type; If the interception type is one of the all-unit interception types, the data processing request will be intercepted. When the interception type is the target unit interception type, the identifier of the storage unit to be intercepted is obtained from the target policy parameters, and if the identifier of the storage unit to be intercepted is consistent with the unit identifier, the data processing request is intercepted. When the interception type is the target data interception type, the data identifier to be intercepted is obtained from the target policy parameters, and if the data identifier to be intercepted is consistent with the data identifier of the target data, the data processing request is intercepted.

5. The data processing method according to claim 4, wherein determining the interception type from the target policy parameters corresponding to the target request interception policy includes: The request type of the data processing request is determined, and the request type to be intercepted is determined from the target policy parameters corresponding to the target request interception policy. The request type to be intercepted includes: read request type and / or write request type. The request type includes: read request type or write request type. If the type of request to be intercepted corresponds to the type of request, the interception type is determined from the target policy parameters.

6. The data processing method according to any one of claims 1 or 2, wherein when the path information to be intercepted is consistent with the path information, the step of performing interception processing on the data processing request includes: The request type of the data processing request is determined, and the request type to be intercepted is determined from the target policy parameters corresponding to the target request interception policy. The request type to be intercepted includes: read request type and / or write request type. The request type includes: read request type or write request type. If the type of the request to be intercepted corresponds to the request type and the path information to be intercepted is consistent with the path information, the data processing request will be intercepted.

7. The data processing method according to any one of claims 1 or 2, further comprising, after performing interception processing on the data processing request when the path information to be intercepted is consistent with the path information: Determine the request information of the data processing request and store the request information in an information storage object.

8. The data processing method according to claim 7, further comprising, after storing the request information in the information storage object: Determine the policy parameters corresponding to the target request interception policy, and determine the information feedback time based on the feedback period information in the policy parameters; If the current time is consistent with the information feedback time, the request information in the information storage object is sent to the policy construction end corresponding to the target request interception policy.

9. The data processing method according to claim 1, before determining the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier, further comprising: Receive an interception policy construction request, wherein the interception policy construction request is sent by the policy construction end when the user performs an interception policy construction operation based on the interception policy construction interface, and the interception policy construction request carries policy parameters for constructing the interception policy construction policy; Obtain the strategy construction unit identifier from the strategy parameters, and based on the strategy construction unit identifier, determine the strategy construction storage unit from multiple storage units on the cloud storage service side, wherein the strategy construction storage unit is any one of the multiple storage units; Based on the strategy parameters, a corresponding request interception strategy is constructed for the strategy storage unit.

10. The data processing method according to claim 1, wherein receiving a data processing request for target data includes: Receive a data processing request for target data sent by a client, wherein the data processing request is sent by the client when the user performs a data processing operation based on the data processing interface, and the data storage address is confirmed by the user when performing the data processing operation; After intercepting the data processing request when the path information to be intercepted matches the path information, the process includes: Determine the request interception prompt information corresponding to the data processing request, and send the request interception prompt information to the client.

11. A cloud storage system, the system comprising a cloud storage service client and a client, wherein, The client is configured to send a data processing request for the target data to the cloud storage service client via the data storage address corresponding to the target data. The cloud storage service client is configured to receive the data processing request for the target data, determine the unit identifier of the target storage unit and the path information of the target data based on the data storage address, wherein the target storage unit is used to store the target data, and the path information indicates the storage location of the target data in the target storage unit, determine the target request interception policy corresponding to the target storage unit from multiple request interception policies based on the unit identifier, determine the path information to be intercepted corresponding to the target request interception policy, and perform interception processing on the data processing request if the path information to be intercepted is consistent with the path information.

12. A computing device, comprising: Memory and processor; The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1 to 10.

13. A computer-readable storage medium storing a computer program / instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 10.

14. A computer program product comprising a computer program / instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 10.