A dual mode operating system
Patent Information
- Application Number
- CN202611000711.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-07
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2046-07-07
AI Technical Summary
[0003]现有小程序商城系统存在部署形态割裂的技术缺陷,同一套服务程序无法兼容并动态支持多租户与私有化单实例两种部署模式;跨模式切换需依赖代码分支改造与独立流水线维护,导致版本迭代不同步且运维成本高昂
[0015]本公开的一种双模式运行系统,通过网关层利用域名识别租户,服务层利用查询键查询配置中心自动识别处于第一模式或第二模式的租户,并在运行时加载对应策略,基于租户模式切换数据源、租户上下文、隔离策略和资源路由策略,实现双模兼容,并提供了一种数据迁移方法,选定处于第一模式下的租户后,自动生成迁移计划并执行数据、配置与资源的一键迁移,完成私有化单实例部署,并提供幂等校验与失败回滚能力。同一套服务程序即可兼容SaaS多租户与私有化单实例两种部署形态,避免维护两套核心代码与发布链路,显著降低开发和运维成本。通过运行时自动识别与切换,可在不重新打包、不重启服务的情况下完成模式切换,快速响应业务需求变化。
Smart Images

Figure CN122513276B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of software engineering, and more particularly to a dual-mode operating system. Background Technology
[0002] In the existing technical architecture, the deployment models for e-commerce systems are mainly divided into two categories: Software as a Service (SaaS) multi-tenant mode and private single-instance mode. The multi-tenant mode serves multiple tenants through a single code instance, offering advantages such as high resource utilization, low operation and maintenance costs, and rapid iteration and updates. On the other hand, the private single-instance mode provides a dedicated deployment environment for specific customers, meeting their stringent requirements for data privacy, system customization, and independent operation and maintenance.
[0003] The existing mini-program e-commerce system has a technical defect of fragmented deployment modes. The same service program cannot be compatible with and dynamically support both multi-tenant and private single-instance deployment modes. Cross-mode switching requires code branch modification and independent pipeline maintenance, resulting in asynchronous version iteration and high operation and maintenance costs. Summary of the Invention
[0004] This disclosure provides a dual-mode operating system to at least solve the above-mentioned technical problems existing in the prior art.
[0005] According to a first aspect of this disclosure, a dual-mode operating system is provided, the system comprising: The gateway layer is used to identify the target tenant identifier corresponding to the external business request, and encapsulate the target tenant identifier into the external business request to obtain the update request. The service layer is used to obtain the update request, determine the corresponding tenant mode profile based on the update request, and assemble a set of strategies based on the tenant mode profile. The strategy layer is used to store and output the set of strategies; The data access layer is used to intercept data access requests based on the first interface and to execute corresponding isolation strategies on the intercepted data access requests based on the tenant mode profile. The migration and configuration layer is used to respond to migration requests by migrating the first-mode tenant from the first mode to the second mode by switching the runtime environment configuration of the first-mode tenant.
[0006] In one possible implementation, the gateway layer includes: The gateway entry point is used to obtain external business requests and determine the corresponding external domain name based on the external business requests. The tenant identification module is used to query the domain name mapping table based on the external domain name, determine the target tenant identifier based on the domain name mapping table, and encapsulate the target tenant identifier into the request header of the external business request to obtain the update request; The domain name mapping table is used to store the correspondence between domain names and tenant identifiers.
[0007] In one possible implementation, the service layer includes: The service scheduling module is used to obtain the update request and forward the update request to the pattern recognition module; The pattern recognition module is used to determine a first query key based on the update request, obtain the target tenant's environment information from the configuration center in the migration and configuration layer based on the first query key, and construct the tenant pattern profile based on the environment information. The strategy assembly module is used to obtain the set of strategies corresponding to the tenant pattern profile from the strategy layer and assemble them.
[0008] In one possible implementation, the data access layer includes: The core business module is used to generate data access requests; The data access adaptation module is used to intercept the data access request based on the first interface and encapsulate the target tenant context into the intercepted data access request. The data access adaptation module is further configured to: when the current tenant mode is determined to be the first mode based on the tenant mode profile, determine the first data source corresponding to the tenant mode profile or insert the first condition into the encapsulated data access request; when the current tenant mode is determined to be the second mode based on the tenant mode profile, disable the first logic for the encapsulated data access request; when it is determined that the encapsulated data access request does not contain the target tenant context, refuse to execute the encapsulated data access request; and in response to the administrator data access request, perform explicit authorization verification and audit recording on the administrator data access request.
[0009] In one possible implementation, the strategy layer includes: The data source strategy is used to respond to data access operations triggered by external business requests. When it is determined that the target tenant is in the first mode, the first query key of the target tenant is determined, the tenant configuration is determined based on the first query key, the tenant route is determined based on the tenant configuration, and the first data source is dynamically selected based on the tenant route. The data source strategy is also used to route the external business request to the second data source when it is determined that the target tenant is in the second mode, skipping the tenant routing table query operation; A tenant context policy is used to respond to an external business request, and when it is determined that the target tenant is in the first mode, read the target tenant identifier in the external business request and load the tenant context in the service layer based on the target tenant identifier. The tenant context policy is also used to, when determining that the target tenant is in the second mode, read the target tenant identifier in the external service request and limit the target tenant identifier to the fixed identifier of the second mode; An isolation strategy is used to insert a first condition into the external business request when it is determined that the target tenant is in the first mode in response to an external business request. The isolation strategy is also used to, when the target tenant is in the second mode, bind the external business request to the second data source or isolate the path prefix or object storage bucket based on the target tenant, and verify the external business request based on the target tenant's authorization; A resource routing strategy is used to respond to external business requests and, when the target tenant is in the first mode, to access static resources, callback addresses, and third-party configurations based on tenant routing. The resource routing policy is also used to bind the tenant's resources to the second mode domain name and resource location of the target tenant when it is determined that the target tenant is in the second mode.
[0010] According to a second aspect of this disclosure, a data migration method is provided, the method being implemented based on a dual-mode operating system, the method comprising: In response to a migration request, record the relevant data for the first-mode tenant; Based on the relevant data, a consistency snapshot of the first mode tenant is determined, and a snapshot migration package is determined based on the consistency snapshot; Obtain the incremental change event stream from the database, filter the incremental change event stream based on the tenant identifier of the first mode tenant, and determine the target incremental change event stream of the first mode tenant; Data synchronization of the target environment is achieved through the idempotent replay mechanism of the snapshot migration package initialization and the target incremental change event stream; After completing the data synchronization of the target environment, a consistency check is performed, which includes at least one of the following: business object reconciliation, data integrity comparison, and business link availability verification. In response to the successful consistency check, the domain name resolution of the first mode tenant is switched to the target environment, the mode corresponding to the first query key is switched to the second mode in the target environment, and the configuration activation mechanism is triggered.
[0011] In one possible implementation, the step of idempotent replay mechanism for initializing the snapshot migration package and the target incremental change event stream to achieve data synchronization of the target environment includes: The target environment is initialized, and the snapshot migration package is sent to the target environment for decompression to build a full data foundation; Identify the key business objects in the target incremental change event stream, and determine the business primary keys corresponding to the key business objects; In the target environment, the target incremental change event stream is replayed based on the full data base, and the key business object is idempotent based on the business primary key.
[0012] In one possible implementation, after completing data synchronization with the target environment, the method further includes: Based on the synchronized target environment, task checkpoints are set, which are used to record the status of security tasks. When performing a consistency check, the consistency check process is interrupted in response to a check failure. Read the data from the task checkpoints and update the process to a safe task state based on the data from the task checkpoints.
[0013] According to a third aspect of this disclosure, an electronic device is provided, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the methods described in this disclosure.
[0014] According to a fourth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions for causing the computer to perform the methods described in this disclosure.
[0015] This disclosed dual-mode operating system identifies tenants through domain names at the gateway layer and automatically identifies tenants in either the first or second mode by querying the configuration center using a query key at the service layer. Corresponding policies are loaded at runtime, and data sources, tenant contexts, isolation policies, and resource routing policies are switched based on tenant mode to achieve dual-mode compatibility. A data migration method is also provided: after selecting a tenant in the first mode, a migration plan is automatically generated and a one-click migration of data, configuration, and resources is executed, completing the private single-instance deployment. Idempotent verification and failure rollback capabilities are also provided. A single service program can be compatible with both SaaS multi-tenant and private single-instance deployment models, avoiding the maintenance of two sets of core code and release chains, significantly reducing development and operation costs. Through automatic identification and switching at runtime, mode switching can be completed without repackaging or restarting the service, quickly responding to changes in business needs.
[0016] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0017] The above and other objects, features, and advantages of this disclosure will become readily apparent from the following detailed description of exemplary embodiments, taken in conjunction with the accompanying drawings. Several embodiments of this disclosure are illustrated in the drawings by way of example and not limitation, in which: In the accompanying drawings, the same or corresponding reference numerals indicate the same or corresponding parts.
[0018] Figure 1 A schematic diagram of a dual-mode operation system according to an embodiment of the present disclosure is shown; Figure 2 A flowchart illustrating a method for target tenant identification and tenant pattern profile generation according to an embodiment of this disclosure is shown. Figure 3 A flowchart of a data migration method according to an embodiment of this disclosure is shown; Figure 4 A schematic diagram of the composition structure of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation
[0019] To make the objectives, features, and advantages of this disclosure more apparent and understandable, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.
[0020] Figure 1 A schematic diagram of a dual-mode operating system according to an embodiment of this disclosure is shown, such as... Figure 1 As shown in the figure, an embodiment of this disclosure provides a dual-mode operating system comprising: a gateway layer 101, a service layer 102, a policy layer 103, a data access layer 104, and a migration and configuration layer 105. The gateway layer 101 includes: a gateway entry point, a tenant identification module, and a domain name mapping table. The service layer 102 includes: a service scheduling module, a pattern recognition module, and a policy assembly module. The policy layer 103 includes: data source policies, tenant context policies, isolation policies, and resource routing policies. The data access layer 104 includes: a core business module and a data access adaptation module. The migration and configuration layer 105 includes: a migration orchestration module and a configuration center and key management module.
[0021] In this embodiment, the gateway layer 101 is used to identify the target tenant identifier corresponding to the external business request, and encapsulate the target tenant identifier into the external business request to obtain an update request. Specifically, the gateway entry point is used to obtain the external business request and determine the corresponding external domain name (e.g., the requested access domain name, Host) based on the external business request; the tenant identification module is used to query the domain name mapping table based on the external domain name, determine the target tenant identifier based on the domain name mapping table, encapsulate the target tenant identifier into the request header of the external business request to obtain the update request, preferably, the target tenant identifier is written into the request header of the external business request to obtain the update request, and the update request is forwarded to the service layer 102; the domain name mapping table is used to store the correspondence between domain names and tenant identifiers.
[0022] In this embodiment, the service layer 102 is used to obtain the update request, determine the corresponding tenant mode profile based on the update request, and assemble a policy set based on the tenant mode profile. Specifically, the service scheduling module is used to obtain the update request and forward it to the pattern recognition module; the pattern recognition module is used to determine a first query key based on the update request, wherein the first query key is obtained by reading the target tenant identifier (tenant_id) and external domain name (host) in the request header, and using the target tenant identifier and external domain name (tenant_id, host) as the first query key. Based on the first query key, the environment information of the target tenant is obtained from the configuration center in the migration and configuration layer 105, and the tenant mode profile is constructed based on the environment information, wherein the tenant mode profile includes: deployment mode field mode: the value is SaaS multi-tenant mode or private single instance mode, running policy identifier field policy_id: used to locate the policy set version, data source selection parameters: including default data source, tenant routing data source, private independent data source identifier, etc., and tenant scope field tenant_scope: a fixed value for a single tenant in private single instance mode, and a dynamically resolved value in SaaS mode. The strategy assembly module is used to obtain and assemble a set of strategies corresponding to the tenant pattern profile from the strategy layer. The strategy set includes at least data source strategies, tenant context strategies, isolation strategies, and resource routing strategies. Specifically, based on the generated tenant pattern profile, the system loads the corresponding "SaaS strategy set" or "private strategy set" to achieve dynamic binding of runtime strategies.
[0023] Figure 2 This illustration shows a flowchart of a method for target tenant identification and tenant pattern profile generation according to an embodiment of the present disclosure, as follows: Figure 2 As shown, the process of a target tenant identification and tenant pattern profile generation method according to an embodiment of this disclosure includes the following steps: Step 201: Request to enter the phase.
[0024] In this embodiment of the disclosure, external business requests enter the system through an external domain name (host=host_a), and the gateway layer 101 performs domain name mapping and matching.
[0025] Step 202, gateway route determination.
[0026] In this embodiment of the disclosure, if the external domain name matches the preset tenant mapping rule, the corresponding tenant identifier (tenant_id=T1) is extracted; if it does not match, a 404 error is returned or the user is redirected to the default tenant page.
[0027] Step 203, tenant context injection.
[0028] In this embodiment of the disclosure, for a hit request, the tenant identifier is written into the request header (X-Tenant-Id: T1) of the external business request to obtain an update request, and then the update request is forwarded to the service layer 102.
[0029] Step 204, Service layer 102 reads the context.
[0030] In this embodiment of the disclosure, after receiving the update request, the service layer 102 parses the tenant_id=T1 and the external domain name host=host_a in the request header, and uses them as the first query key for subsequent configuration queries.
[0031] Step 205: Configure the center to query and obtain environment information.
[0032] In this embodiment of the disclosure, a query is sent to the configuration center based on the first query key to obtain the environment information of the target tenant.
[0033] Step 206: Pattern determination and profile generation.
[0034] In this embodiment of the disclosure, the branch judgment is made based on the deployment mode field 'mode' returned by the configuration center. If mode=SaaS, a tenant mode profile for SaaS mode is generated, which includes mode=SaaS and policy_id=v1; if mode=private, a profile for private mode is generated, which includes mode=private and policy_id=v1.
[0035] In this embodiment of the disclosure, the strategy layer 103 is used to store and output the strategy set, specifically, when the strategy assembly module requests entry, it uses the tenant pattern profile strategy set, specifically: A data source strategy is used to respond to data access operations triggered by external business requests. When the target tenant is determined to be in the first mode, wherein the first mode is SaaS mode, the strategy determines the first query key of the target tenant, determines the tenant configuration based on the first query key, determines the tenant route based on the tenant configuration, and dynamically selects a first data source based on the tenant route. The first data source is one of a shared library, an independent schema, or an independent library data source. The data source strategy is also used to route the external business request to the second data source and skip the tenant routing table query operation when the target tenant is determined to be in the second mode, wherein the second mode is private mode. The second data source is a private single-instance data source.
[0036] A tenant context policy is used to respond to an external business request. When it is determined that the target tenant is in the first mode, the policy reads the target tenant identifier from the external business request and loads the tenant context in the service layer 102 based on the target tenant identifier. Preferably, the tenant context is loaded in the service scheduling module in the service layer 102. The tenant context policy is also used to, when it is determined that the target tenant is in the second mode, read the target tenant identifier from the external business request and restrict the target tenant identifier to a fixed identifier for the second mode, disallowing cross-tenant access.
[0037] An isolation strategy is used to respond to external business requests. When the target tenant is determined to be in the first mode, row-level isolation is performed, and a first condition is inserted into the external business request. The first condition is a tenant identifier filtering condition. Preferably, the tenant_id filtering condition is injected into all business SQL statements in the data access adaptation module. The isolation strategy is also used to perform schema isolation / library isolation when the target tenant is determined to be in the second mode, binding the external business request to a second data source. The second data source is an independent schema or an independent library data source. Alternatively, resource isolation is performed, isolating path prefixes or object buckets based on the target tenant, and validating the external business request based on the target tenant's authorization. Preferably, object buckets or path prefixes are isolated by tenant, and file access credentials are authorized by tenant.
[0038] The resource routing strategy is used to respond to external business requests and, when the target tenant is determined to be in the first mode, to access static resources, callback addresses, and third-party configurations based on tenant routing; the resource routing strategy is also used to, when the target tenant is determined to be in the second mode, to bind tenant resources to the second mode domain name and resource location of the target tenant, wherein the second mode domain name is a customer's private domain name.
[0039] In this embodiment, the data access layer 104 is used to intercept data access requests based on the first interface and execute corresponding isolation strategies on the intercepted data access requests based on the tenant pattern profile. Specifically, the core business module is used to generate data access requests to realize the e-commerce platform's business capabilities such as products, orders, members, and marketing; this module does not include tenant identification, data source selection, and white-label customization (Original Equipment Manufacturer, OEM) logic that is strongly coupled with the deployment form.
[0040] The data access adaptation module is used to intercept the data access request based on the first interface, and encapsulate the target tenant context into the intercepted data access request. The first interface is one of a repository or Data Access Object (DAO) base class, an Object-Relational Mapping (ORM) plugin, or a Structured Query Language (SQL) interceptor, and the data access request is an ORM or SQL access request. For example, a unified entry point encapsulation for ORM or SQL access can be provided, supporting policy-driven switching of data sources and injection of tenant conditions to prevent unauthorized access.
[0041] The data access adaptation module is further configured to: when determining the current tenant mode as the first mode based on the tenant mode profile, determine the first data source corresponding to the tenant mode profile or insert the first condition into the encapsulated data access request; when determining the current tenant mode as the second mode based on the tenant mode profile, disable the first logic for the encapsulated data access request, wherein the first logic is multi-tenant SQL injection logic, which can avoid introducing additional overhead while maintaining interface consistency; when determining that the encapsulated data access request does not contain the target tenant context, refuse to execute the encapsulated data access request or downgrade it to restricted access; and in response to the administrator data access request, perform explicit authorization verification and audit recording on the administrator data access request.
[0042] The OEM adaptation module enables parameterized configuration of brand, domain name, theme, copyright, etc. in a non-intrusive manner, and retrieves values in SaaS or private mode according to the strategy.
[0043] In this embodiment of the disclosure, the migration and configuration layer 105 includes a migration orchestration module, which is used to generate a migration object list and migration plan when a SaaS (multi-tenant coexistence) tenant migrates to a private environment, and to perform export, verification, import, switching and rollback; and a configuration center and key management module, which stores runtime policy parameters, tenant configuration, migration task status, key / certificate references, etc.
[0044] Figure 3 A flowchart of a data migration method according to an embodiment of this disclosure is shown, as follows: Figure 3 As shown, an embodiment of the present disclosure provides a data migration method based on the aforementioned dual-mode operating system, particularly the migration and configuration layer 105. The implementation process of the data migration method in this embodiment includes the following steps: Step 301: In response to the migration request, record the relevant data of the first mode tenant.
[0045] In this embodiment of the disclosure, a migration request is received, and a unique migration identifier migration_id is generated. The relevant data includes: first mode tenant_id, target private environment identifier, policy version_id, and migration object list version.
[0046] Step 302: Determine the consistency snapshot of the first mode tenant based on the relevant data, and determine the snapshot migration package based on the consistency snapshot.
[0047] In this embodiment, a migration object list is generated based on the target tenant_id in the relevant data, including: tenant business data, tenant-level configurations (such as payment / SMS / third-party key references), OEM configurations (such as domain names, theme packages), resource objects (such as images / attachments), callback whitelists, and certificate references. A consistent snapshot is generated for the target tenant in the SaaS environment, including exporting relevant table data and necessary index information for the target tenant to form a snapshot migration package, and the snapshot migration package is then validated.
[0048] Step 303: Obtain the incremental change event stream from the database, filter the incremental change event stream based on the tenant identifier of the first mode tenant, and determine the target incremental change event stream of the first mode tenant.
[0049] In this embodiment of the disclosure, the binlog is fully parsed by subscribing to the database (binlog) to obtain the incremental change event stream in the database. At the replay end, the incremental change events are filtered according to the tenant_id, and only the incremental changes belonging to the first mode tenant are replayed.
[0050] Step 304: Data synchronization of the target environment is completed by initializing the snapshot migration package and using an idempotent replay mechanism for the target incremental change event stream.
[0051] In this embodiment, the target environment is initialized. The target environment is a private single-instance environment. The snapshot migration package is sent to the target environment for decompression to construct a full data foundation. The full data foundation is a target database instance or dataset restored through the snapshot migration package, maintaining strict isomorphism with the source data structure, and used to carry subsequent incremental data synchronization. Key business objects (e.g., orders) in the target incremental change event stream are determined, and the corresponding business primary key (e.g., order number) is determined. In the target environment, the target incremental change event stream is replayed based on the full data foundation, and idempotent processing is performed on the key business objects based on the business primary key.
[0052] Step 305: After completing the data synchronization of the target environment, perform a consistency check, which includes at least one of business object reconciliation, data integrity comparison, and business link availability verification.
[0053] In this embodiment of the disclosure, after the snapshot import and incremental replay are completed, at least the following three types of consistency checks are performed: reconciliation of key business objects: total quantity statistics and sampling reconciliation are performed on orders, payment flow / refunds, inventory (or inventory flow), and member balance / points; data integrity verification: row count / aggregated amount statistics verification is performed on core tables, and verification and correlation consistency checks are performed when necessary; business availability verification: key link smoke testing (order placement-payment callback-shipment / verification) is performed under a temporary domain name and the connectivity of third-party callbacks is checked. The three types of consistency checks constitute multi-dimensional consistency checks.
[0054] In this embodiment, if any step fails, the process rolls back to the previous available state based on the task checkpoint. The migration task uses migration_id to implement idempotent retry, preventing duplicate imports and cutovers. Specifically, after completing data synchronization of the target environment, a task checkpoint is set based on the synchronized target environment. The task checkpoint is used to record the security task status. When performing consistency verification, the consistency verification process is interrupted in response to verification failure. The data of the task checkpoint is read, and the process is updated to the security task status based on the data of the task checkpoint. The security status means that after the target environment completes the full base construction, it has the ability to receive and correctly process incremental data. Moreover, during incremental replay, the primary key idempotency mechanism can eliminate duplication and conflict, ensuring that the target data and the source data maintain logical consistency and integrity at any point in time, and that dirty data is not generated due to transmission anomalies or retry mechanisms.
[0055] Step 306: In response to the successful consistency check, the domain name resolution of the first mode tenant is switched to the target environment, the mode corresponding to the first query key is switched to the second mode in the target environment, and the configuration activation mechanism is triggered.
[0056] In this embodiment of the disclosure, during the migration, the temporary domain name is resolved to the private environment for testing and verification; after the consistency verification is passed, the domain name system (DNS) resolution of the original domain name is switched to the private environment to complete the cutover; in the private environment, the mode corresponding to (tenant_id, host) is switched to private and points to the private data source reference, and the configuration activation mechanism is triggered, wherein the activation mechanism is to restart the service.
[0057] This disclosure provides a complete migration mechanism including snapshot export, incremental change data capture (CDC), idempotent replay, and three types of consistency checks to ensure data integrity and business consistency for SaaS tenants migrating to private environments, and supports rollback in case of failure. In SaaS mode, data security is enhanced through mandatory tenant isolation and anti-private privilege escalation mechanisms; in private mode, multi-tenant overhead is disabled to improve performance and stability.
[0058] According to embodiments of this disclosure, this disclosure also provides an electronic device and a readable storage medium.
[0059] Figure 4 A schematic block diagram of an example electronic device 800 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0060] like Figure 4 As shown, the electronic device 800 includes a computing unit 801, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. The RAM 803 may also store various programs and data required for the operation of the electronic device 800. The computing unit 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0061] Multiple components in electronic device 800 are connected to I / O interface 805, including: input unit 806, such as keyboard, mouse, etc.; output unit 807, such as various types of displays, speakers, etc.; storage unit 808, such as disk, optical disk, etc.; and communication unit 809, such as network card, modem, wireless transceiver, etc. Communication unit 809 allows electronic device 800 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0062] The computing unit 801 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 performs the various methods and processes described above, such as a target tenant identification and tenant pattern profiling generation method and a data migration method. For example, in some embodiments, a target tenant identification and tenant pattern profiling generation method and a data migration method can be implemented as computer software programs tangibly contained in a machine-readable medium, such as storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 800 via ROM 802 and / or communication unit 809. When the computer program is loaded into RAM 803 and executed by the computing unit 801, one or more steps of the target tenant identification and tenant pattern profiling generation method and the data migration method described above can be performed. Alternatively, in other embodiments, the computing unit 801 may be configured by any other suitable means (e.g., by means of firmware) to perform a target tenant identification and tenant pattern profiling method and a data migration method.
[0063] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0064] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0065] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0066] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0067] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0068] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.
[0069] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this disclosure can be achieved, and this is not limited herein.
[0070] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this disclosure, "a plurality of" means two or more, unless otherwise explicitly specified.
[0071] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. A dual-mode operating system, characterized in that, The system includes: The gateway layer is used to identify the target tenant identifier corresponding to the external business request, and encapsulate the target tenant identifier into the external business request to obtain the update request. The service layer is used to obtain the update request, determine the corresponding tenant mode profile based on the update request, and assemble a set of strategies based on the tenant mode profile. The strategy layer is used to store and output the set of strategies; The data access layer is used to intercept data access requests based on the first interface and to execute corresponding isolation strategies on the intercepted data access requests based on the tenant mode profile. The migration and configuration layer is used to respond to migration requests and migrate the first-mode tenant from the first mode to the second mode by switching the runtime environment configuration of the first-mode tenant; The service layer includes: The service scheduling module is used to obtain the update request and forward the update request to the pattern recognition module; The pattern recognition module is used to determine a first query key based on the update request, obtain the target tenant's environment information from the configuration center in the migration and configuration layer based on the first query key, and construct the tenant pattern profile based on the environment information. The strategy assembly module is used to obtain and assemble a set of strategies corresponding to the tenant pattern profile from the strategy layer. The strategy layer includes: The data source strategy is used to respond to data access operations triggered by external business requests. When it is determined that the target tenant is in the first mode, the first query key of the target tenant is determined, the tenant configuration is determined based on the first query key, the tenant route is determined based on the tenant configuration, and the first data source is dynamically selected based on the tenant route. The data source strategy is also used to route the external business request to the second data source when it is determined that the target tenant is in the second mode, skipping the tenant routing table query operation; A tenant context policy is used to respond to an external business request, and when it is determined that the target tenant is in the first mode, read the target tenant identifier in the external business request and load the tenant context in the service layer based on the target tenant identifier. The tenant context policy is also used to, when determining that the target tenant is in the second mode, read the target tenant identifier in the external service request and limit the target tenant identifier to the fixed identifier of the second mode; An isolation strategy is used to insert a first condition into the external business request when it is determined that the target tenant is in the first mode in response to an external business request. The isolation strategy is also used to, when the target tenant is in the second mode, bind the external business request to the second data source or isolate the path prefix or object storage bucket based on the target tenant, and verify the external business request based on the target tenant's authorization; A resource routing strategy is used to respond to external business requests and, when the target tenant is in the first mode, to access static resources, callback addresses, and third-party configurations based on tenant routing. The resource routing policy is also used to bind the tenant's resources to the second mode domain name and resource location of the target tenant when it is determined that the target tenant is in the second mode.
2. The system according to claim 1, characterized in that, The gateway layer includes: The gateway entry point is used to obtain external business requests and determine the corresponding external domain name based on the external business requests. The tenant identification module is used to query the domain name mapping table based on the external domain name, determine the target tenant identifier based on the domain name mapping table, and encapsulate the target tenant identifier into the request header of the external business request to obtain the update request; The domain name mapping table is used to store the correspondence between domain names and tenant identifiers.
3. The system according to claim 1, characterized in that, The data access layer includes: The core business module is used to generate data access requests; The data access adaptation module is used to intercept the data access request based on the first interface and encapsulate the target tenant context into the intercepted data access request. The data access adaptation module is further configured to: when the current tenant mode is determined to be the first mode based on the tenant mode profile, determine the first data source corresponding to the tenant mode profile or insert the first condition into the encapsulated data access request; when the current tenant mode is determined to be the second mode based on the tenant mode profile, disable the first logic for the encapsulated data access request; when it is determined that the encapsulated data access request does not contain the target tenant context, refuse to execute the encapsulated data access request; and in response to the administrator data access request, perform explicit authorization verification and audit recording on the administrator data access request.
4. A data migration method, characterized in that, This method is implemented based on the dual-mode operation system described in claim 1, and the method includes: In response to a migration request, record the relevant data for the first-mode tenant; Based on the relevant data, a consistency snapshot of the first mode tenant is determined, and a snapshot migration package is determined based on the consistency snapshot; Obtain the incremental change event stream from the database, filter the incremental change event stream based on the tenant identifier of the first mode tenant, and determine the target incremental change event stream of the first mode tenant; Data synchronization of the target environment is achieved through the idempotent replay mechanism of the snapshot migration package initialization and the target incremental change event stream; After completing the data synchronization of the target environment, a consistency check is performed, which includes at least one of the following: business object reconciliation, data integrity comparison, and business link availability verification. In response to the successful consistency check, the domain name resolution of the first mode tenant is switched to the target environment, the mode corresponding to the first query key is switched to the second mode in the target environment, and the configuration activation mechanism is triggered. The step of idempotent replay mechanism for initializing the snapshot migration package and the target incremental change event stream to achieve data synchronization of the target environment includes: The target environment is initialized, and the snapshot migration package is sent to the target environment for decompression to build a full data foundation; Identify the key business objects in the target incremental change event stream, and determine the business primary keys corresponding to the key business objects; In the target environment, the target incremental change event stream is replayed based on the full data base, and the key business object is idempotent based on the business primary key.
5. The method according to claim 4, characterized in that, After completing the data synchronization with the target environment, the method further includes: Based on the synchronized target environment, task checkpoints are set, which are used to record the status of security tasks. When performing a consistency check, the consistency check process is interrupted in response to a check failure. Read the data from the task checkpoints and update the process to a safe task state based on the data from the task checkpoints.
6. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 4-5.
7. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 4-5.
Citation Information
Patent Citations
Data migration method, device, computer device, and storage medium
CN109067823A
Data migration method, device and equipment and computer readable storage medium
CN110019140A
Data isolation method and system for multi-tenant platform based on micro-service architecture
CN115391828A
Multi-tenant implementation method based on new and old systems
CN116679978A