Computer implementation methods, systems, and computer programs
Patent Information
- Application Number
- JP2024518699
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-10-13
- Filing Date
- 2022-09-28
- Publication Date
- 2026-09-30
- Estimated Expiration
- 2042-09-28
Smart Images

Figure 0007927063000001 
Figure 0007927063000002 
Figure 0007927063000003
Abstract
Description
Technical Field
[0001] The present invention relates generally to data management, and more specifically to the management of custom structured objects in a hybrid cloud environment.
Background Art
[0002] Cloud computing refers to the practice of providing information computing services (i.e., cloud services) using a network of remote servers hosted on a public network (e.g., the Internet), instead of providing such services on a local server. A network architecture that provides these cloud services to service consumers (i.e., cloud service consumers) (e.g., a virtualized information processing environment including hardware and software) is referred to as a "cloud", and may be a public cloud (e.g., a cloud service publicly provided to cloud service consumers), a private cloud (e.g., a private network or data center that provides cloud services only to a specific group of cloud service consumers within an enterprise), a community cloud (e.g., a set of cloud services publicly provided to institutions having a limited set of cloud service consumers, for example, a specific state / region or set of states / regions), a dedicated / hosted private cloud, or other emerging cloud service delivery models. The underlying intent of cloud computing is to provide cloud service consumers with easy and scalable access to computing resources and information technology (IT) services.
[0003] Cloud services can be broadly divided into four categories: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), and Managed Services. Infrastructure as a Service refers to the virtualized computing infrastructure used when cloud services are provided (e.g., virtual server space, network connectivity, bandwidth, IP addresses, load balancers, etc.). Platform as a Service in the cloud refers to a set of software and product development tools hosted on the cloud to enable developers (i.e., one type of cloud service consumer) to build applications and services using the cloud. Software as a Service refers to applications hosted via the cloud and available on demand to cloud service consumers. Managed Services refer to services that a managed service provider enables for any cloud service, such as backup management, remote system management, application management, and security services.
[0004] Generally speaking, cloud services have three distinct characteristics that differentiate them from traditionally hosted services. The first of these is that they are sold to service consumers on demand (e.g., by the minute or hour). The second is that they are dynamic (e.g., service consumers can receive as much or as little service as they want at any given time). The third is that, specifically in the case of public clouds rather than private or hybrid clouds, the service is fully managed by the cloud service provider (e.g., service consumers only need suitably equipped client devices and network connectivity). This third characteristic is particularly relevant to public clouds. However, private clouds can be managed by an internal IT department or through an ITO (IT Outsourcing) contract. In these examples, the I&O (Infrastructure & Operations) manager acts as the cloud provider, and therefore this third characteristic has a similar relevance.
[0005] The cloud is being rapidly adopted by businesses and IT users as a way to enhance organizational effectiveness and save costs. Along with this opportunity, however, several new challenges and significant risks arise that businesses must address. For example, business users are rapidly investing in their own cloud capabilities (e.g., IaaS, PaaS, and SaaS) to meet their business needs, and application developers want to move quickly without involving IT in provisioning tools and environments. These movements pose a significant threat to IT administrators who are concerned about considerations such as management costs, chargebacks, capacity, and resources, as a result of unlimited / unplanned cloud expansion. [Overview of the Initiative]
[0006] Embodiments of the present invention relate to managing custom structured files in a hybrid cloud environment. Non-limiting and exemplary computer implementations include the steps of: receiving a first object from a first client; determining a first file format relating to the first object, wherein the first file format is operable to run on a first platform; generating a catalog relating to the first object, wherein the catalog comprises data associated with the first object, and wherein the catalog relating to the first object is stored on a first server; receiving a request from a second client to access the data associated with the first object; determining a second platform on which the second client operates; converting the first file format relating to the first object to a second file format on the second server, wherein the second file format is operable to run on a second platform; and sending the first object in the second file format to the second client.
[0007] Other embodiments of the present invention implement the features of the method described above in computer systems and computer program products.
[0008] Further technical features and benefits are realized by the techniques of the present invention. Embodiments and aspects of the present invention are described in detail herein and are considered to be part of the subject matter claimed. For a better understanding, please refer to the detailed description and drawings. [Brief explanation of the drawing]
[0009] Details of the exclusive rights described herein are specifically set forth and expressly claimed in the claims at the end of the specification. The above-mentioned and other features and advantages of embodiments of the present invention are evident from the following detailed description, which is provided in conjunction with the accompanying drawings.
[0010] [Figure 1] This is a diagram of a system for managing proprietary structured files in a hybrid cloud environment, according to one or more embodiments of the present invention.
[0011] [Figure 2] This is a diagram of a system for managing proprietary structured files in a hybrid cloud environment, according to one or more embodiments of the present invention.
[0012] [Figure 3] This is a diagram of a system for managing proprietary structured files in a hybrid cloud environment, according to one or more embodiments of the present invention.
[0013] [Figure 4] This is a diagram illustrating an exemplary structured object according to one or more embodiments of the present invention.
[0014] [Figure 5] This is a flowchart of a method for managing custom structured files in a hybrid cloud environment according to one or more embodiments of the present invention.
[0015] [Figure 6] This is a diagram of a cloud computing environment according to one or more embodiments of the present invention.
[0016] [Figure 7] This figure shows an abstraction model layer according to one or more embodiments of the present invention.
[0017] [Figure 8] This is a diagram illustrating a computer system in general according to one embodiment.
[0018] The figures shown herein are illustrative. Many variations may exist to the figures or actions described herein without departing from the scope of the invention. For example, actions may be performed in a different order, or actions may be added, deleted, or modified. Furthermore, the term “coupled” and its inflections describe the existence of a communication path between two elements, and do not imply a direct connection between elements without an intervening element / connection. All of these variations are considered part of this specification. [Modes for carrying out the invention]
[0019] One or more embodiments of the present invention provide a system and method for accessing and protecting proprietary structured files operating under different platforms in a hybrid cloud environment. The embodiments include encrypting the structured files using a public key and storing the files in a hybrid cloud environment, including public and private clouds. In a public cloud environment, the cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services. In a private cloud environment, the cloud infrastructure is operated solely for a specific organization. It may be managed by that organization or a third party and may reside on-premises or off-premises. In one or more embodiments of the present invention, the organization may store structured files in this hybrid cloud, where the data for each file is stored (and encrypted) in the private cloud environment, and a catalog of the structured files may be available on the public cloud environment. Each structured file may contain an access control list (ACL) specifying access rights and permissions for the structured file. The ACL specifies both subjects and operations for the structured file. For example, the subject may be a specified user, and the operations may be permissions, such as read, write, edit, and so on.
[0020] In one or more embodiments of the present invention, a structured file is unique in that it can only be manipulated by a specific platform. A unique structured file refers to a file format for a company, organization, and / or individual, containing data ordered and stored according to a specific encoding scheme, and designed to be secret by the company or organization so that decoding and interpretation of the stored data can only be achieved using specific software or hardware developed by that company. Due to the breadth of the unique file format, an organization storing files in a cloud environment may find it difficult to allow individuals within and / or outside the organization to access the data for each individual file (object) with the unique format. Furthermore, given the size of some of these files, downloading files from a cloud environment can take an enormous amount of time for a client computer accessing the cloud. If the client computer does not have a suitable software platform to open the unique file, this download time is wasted.
[0021] One or more embodiments of the present invention address the above-mentioned drawbacks of storing proprietary structured files in a hybrid cloud computing environment by providing a system environment and an associated method that enable secure access to these files using different platforms. The cloud computing environment may include a public cloud that contains a directory of encrypted files available in the private cloud, wherein the files may be proprietary structured files. When accessed by a client computer, the accessing platform can be determined, and the structured file in an appropriate format can be transmitted to the client computer. The cloud computing environment may utilize public / private key cryptography and an access control list (ACL) to protect files in the private cloud. A client computer can upload a structured file, encrypt the file using a public key, and the file is then stored in the cloud environment. When a second client computer, typically operating a second platform, attempts to access the file, the cloud computing environment determines that the second client computer is operating the second platform and returns the file in a format accessible using the second platform. The encrypted file is transmitted to the second client computer, which decrypts the file using a private key and accesses it using the second platform.
[0022] Figure 1 shows a system for managing custom structured files in a hybrid cloud environment according to one or more embodiments of the present invention. System 100 includes a client infrastructure 102 which may include any number of physical and / or virtual computers that can access the cloud computing environment. The cloud computing environment includes both a public cloud 120 and a private cloud 130. The public 120 and private cloud 130 environments may be hosted on separate servers, the same server, and / or a mixture of different servers. For simplicity of explanation, the client infrastructure 102 may be, for example, a computing device running a platform used within a client organization. The platform may be a software application, an operating system, and / or any other platform. The computing device 102 includes an ACL service 104 which may be stored locally on the computing device 102 or on a server including the server hosting the public cloud 120 and / or private cloud 130. The computing device 102 may include encryption 106 and decryption services 108 which may utilize various encryption techniques for custom structured files. Furthermore, the computing device 102 may include a front-end service 110 that can be used to access the cloud computing environment. The front-end service 110 may be, for example, a client portal that provides access to the public 120 and private 130 clouds. The public cloud 120 may operate a similar front-end service 124 that can be used to access information from the public cloud 120. The public cloud 120 may include storage 128 and an identification service module 126 for determining the platform to operate any stored structured files in the private cloud 130. In addition, a catalog 122 (file directory) is maintained on the public cloud 120 that enables access to information about structured files stored on the private cloud 130.
[0023] In one or more embodiments of the present invention, the private cloud 130 comprises a platform service module 132, an encryption 136 and a decryption 134 service, and a storage 138 for storing structured files. Typically, the structured files are stored in the private cloud in an encrypted format using a public key from the client computer 102. The platform service module 132 is used to access structured files and convert them from one platform to another, as required for access by other client computers accessing the cloud.
[0024] Figure 2 shows a system for managing custom structured files in a hybrid cloud environment according to one or more embodiments of the present invention. For simplicity and consistency of illustration, the same numbering scheme is used to refer to the same components from Figure 1. Furthermore, system 200 shows a process flow for a first client device 102 (using platform A) to upload a structured file to the cloud environment and a second client device 202 (using platform B) to access the structured file. In one or more embodiments of the present invention, system 200 includes a first client device 102 operating platform A on device 102. Client device 102 includes a custom structured file (object) 220 containing an access control list specifying access rights to the file. Object 220 is encrypted using a public key 222 to create an encrypted object 224, which is sent to the cloud environment for storage. The second client 202 (using platform B) then requests access to object 220. However, the second client 202 does not use platform A, which is the platform for opening this structured file 220. The identification service module 126 determines the platform being used by the requesting client 202 and communicates this platform type to the platform service module 132 on the private cloud 130. The platform service 132 uses the stored platform A to convert object 220 from a file type for platform A to a file type for platform B. This converted file type is then encrypted using the public key and transferred to the second client device 202. The second client device 202 then receives the encrypted object 228 in the file type for platform B, which is then decrypted using the decryption service 208 along with the private key 224.At this point, object 220 is accessible by the second client device 202 in a file format appropriate for platform B. The second client device 202 can freely access object 220 based on the fact that the access control list has designated this second client 202 as having appropriate access.
[0025] In one or more embodiments of the present invention, the platform service module 132 converts a proprietary structured object 220 from a file accessible by platform A to a file accessible by platform B by first converting the object 220 to a common type file. Next, using platform B within the platform service module 132, it converts the common type file to a file type accessible by platform B. This can be implemented using the Zip format as the command type, but tar, gz, and other compression types are specific types of compressed data. A tar file can be converted to a common type zip, and then easily converted to another format.
[0026] Figure 3 shows a system for managing custom structured files in a hybrid cloud environment according to one or more embodiments of the present invention. For simplicity and consistency of illustration, the same numbering scheme is used to refer to the same components from Figure 1 onwards. Furthermore, system 300 shows a process flow in which, for a file to be converted, a first client device 102 (utilizing platform A) uploads an unknown object 302, which is of an unknown file type, to the cloud environment, allowing the client device 102 to access object 302 using platform A. In one or more embodiments of the present invention, system 300 includes a client device 102 having a front-end service 110 that communicates with a front-end service 124 in a public cloud 120. The client device 102 may attempt to access object 302, which has an unknown or inaccessible file type, via platform A. In one or more embodiments of the present invention, the client device 102 sends a request to access the unknown object 302 to the cloud environment. The cloud environment uses an identification service module 126 on the public cloud 120 to determine the object type and which platform can access the object. In this example, the unknown object 302 may be accessed by Platform B within the Platform Service Module 132 on the private cloud 130. Platform B may access and open object 302 and send the object type and catalog to client device 102. The catalog contains information about the content of the structured object 302. Client device 102 may request access to one or more items within the unknown object 302. The requested items from the catalog may be converted to a common type and sent to client device 102 for access using Platform A on client device 102.
[0027] Figure 4 shows an exemplary structured object according to one or more embodiments of the present invention. The structured object 400 includes a header 402 along with items 404a, 404b stored within the structured object 400. Items 404a, 404b include associated headers, attributes, data, and / or ACL information. In one or more embodiments of the present invention, a catalog 122 (from Figure 1) may show information about items 404a, 404b as described herein, and any other information associated with the structured object 400. The structured object 400 also includes object attributes 406 about the object 400 as a whole, and ACLs 408 that indicate access rights about the object 400. As described in the process flow relating to Figures 2 and 3, the cloud environment includes a platform service module 132 that can access the object 400 and send descriptions of items 404a, 404b to the catalog for access by client devices 102 on the public cloud 120. If a client device does not have a suitable platform to access object 400 or just one or more items (data) 404a, 404b relating to the object, the cloud computing environment may translate object 400 and / or items 404 and send them to the requesting client device.
[0028] In one or more embodiments of the present invention, any components on the client device (client infrastructure) 102 and the public cloud 120 and private cloud 130, such as the identification service module 126, the platform server 132, and the decryption 134 and encryption 136 services, may be implemented on the processing system 800 shown in Figure 8. In addition, the cloud computing system 50 may be in wired or wireless electronic communication with one or all of the elements of systems 100, 200, and 300. The cloud 50 may complement, support, or replace some or all of the functions of the elements of systems 100, 200, and 300. In addition, some or all of the functions of the elements of systems 100, 200, and 300 may be implemented as nodes 10 of the cloud 50 (shown in Figures 6 and 7). The cloud computing node 10 is merely one example of a suitable cloud computing node and is not intended to imply any limitation on the scope of use or functionality of the embodiments of the present invention described herein.
[0029] Figure 5 shows a flowchart of Method 500 for managing proprietary structured files in a hybrid cloud environment according to one or more embodiments of the present invention. At least a portion of Method 500 may be executed by, for example, one or more servers, e.g., a public cloud 120 and / or a private cloud 130 shown in Figure 1. Method 500 includes the step of receiving a first object from a first client, as shown in block 502. The first object may be, for example, a proprietary structured file. In block 504, Method 500 includes the step of determining a first file format relating to the first object, where the first file format is operable to run on a first platform. The first platform may be proprietary software, an operating system, and / or a combination thereof. In block 506, Method 500 includes the step of generating a catalog relating to the first object, where the catalog comprises data associated with the first object, and where the catalog relating to the first object is stored on a first server. The first server may be a public cloud environment available for selecting a catalog containing data about the first object. In block 508, method 500 includes the step of receiving a request from a second client to access data associated with the first object. This second client may parse the catalog to determine what data is needed from the first object, even though the second client is operating on a different platform. In block 510, method 500 includes the step of determining the second platform operated by the second client. Also in block 512, method 500 includes the step of converting the first file format relating to the first object to a second file format on the second server, the second file format being operable to run on the second platform. In block 514, method 500 includes the step of sending the first object in the second file format to the second client.
[0030] Additionally, additional processes may be included. It should be understood that the processes shown in Figure 5 are illustrative and that other processes may be added, or existing processes may be removed, modified, or rearranged without departing from the scope of this disclosure.
[0031] While this disclosure includes a detailed description of cloud computing, it will be understood that implementations of the teachings described herein are not limited to cloud computing environments. Rather, embodiments of the present invention can be implemented in conjunction with any other type of computing environment that is currently known or may be developed in the future.
[0032] Cloud computing is a service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and deployed with minimal management effort or interaction with service providers. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models.
[0033] The characteristics are as follows:
[0034] On-demand self-service: Cloud consumers can unilaterally provision computing power, such as server time and network storage, automatically as needed, without requiring human interaction with service providers.
[0035] Broad network access: Capabilities are available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin client platforms or thick client platforms (e.g., mobile phones, laptops, and PDAs®).
[0036] Resource pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with various physical and virtual resources dynamically allocated and reallocated according to demand. Consumers generally have no control or knowledge of the exact location of the resources provided, although a certain degree of location independence exists in that they may be able to specify the location at a higher level of abstraction (e.g., country, state, or data center).
[0037] Rapid Scalability: Capabilities are provisioned quickly and flexibly, sometimes automatically, allowing for rapid scaling out or rapid release and rapid scaling in. Often, to consumers, the capacity available for provisioning appears unlimited and can be purchased at any quantity at any time.
[0038] Measured Services: Cloud systems automatically control and optimize resource usage by leveraging metric capabilities at an appropriate level of abstraction for each service type (e.g., storage, processing, bandwidth, and active user accounts). Resource utilization can be monitored, controlled, and reported, providing transparency to both service providers and consumers.
[0039] The service model is as follows:
[0040] Software as a Service (SaaS): The ability offered to consumers is the use of a provider's applications running on cloud infrastructure. These applications are accessible from various client devices via thin client interfaces such as web browsers (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, storage, or even individual application capabilities, with the exception of limited user-specific application configuration settings.
[0041] Platform as a Service (PaaS): The ability provided to consumers is to deploy applications they have created or acquired, written using programming languages and tools supported by the provider, onto cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but they have control over the deployed applications and, in some cases, the configuration of the application hosting environment.
[0042] Infrastructure as a Service (IaaS): The ability provided to consumers is to provision processing, storage, networking, and other basic computing resources, allowing consumers to deploy and run any software, which may include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but have control over the operating system, storage, deployed applications, and, in some cases, limited control over selected networking components (e.g., host firewalls).
[0043] The deployment model is as follows:
[0044] Private Cloud: Cloud infrastructure is operated exclusively for a specific organization. It may be managed by that organization or a third party, and may reside on-premises or off-premises.
[0045] Community Cloud: A cloud infrastructure is shared by multiple organizations to support a specific community that shares common interests (e.g., mission, security requirements, policies, and compliance considerations). It may be managed by those organizations or third parties and may reside on-premises or off-premises.
[0046] Public cloud: Cloud infrastructure is made available to the general public or large industry groups and is owned by organizations that sell cloud services.
[0047] Hybrid Cloud: This cloud infrastructure is a complex of two or more clouds (private, community, or public) that remain unique entities but are joined together by standardized or proprietary technologies that enable data and application portability (e.g., cloud bursting for load balancing across clouds).
[0048] Cloud computing environments are service-oriented, emphasizing statelessness, low coupling, modularity, and semantic interoperability. At the core of cloud computing lies an infrastructure that includes a network of interconnected nodes.
[0049] Referring here to Figure 6, an exemplary cloud computing environment 50 is shown. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 that can communicate with local computing devices used by cloud consumers, such as personal digital assistants (PDAs) or cellular phones 54A, desktop computers 54B, laptop computers 54C, and / or automotive computer systems 54N, etc. The nodes 10 may communicate with each other. They may be physically or virtually grouped (not shown) into one or more networks, such as private clouds, community clouds, public clouds, or hybrid clouds, or a combination thereof, as described above in this specification. This enables the cloud computing environment 50 to provide infrastructure, platforms and / or software as a service, which does not require cloud consumers to maintain resources on their local computing devices for that purpose. It should be understood that the types of computing devices 54A-N illustrated in Figure 6 are intended to be illustrative only, and that the computing nodes 10 and the cloud computing environment 50 can communicate with any type of computerized device through any type of network and / or network addressable connection (e.g., using a web browser).
[0050] Referring now to Figure 7, a set of functional abstraction layers provided by the cloud computing environment 50 (Figure 6) is shown. It should be understood in advance that the components, layers, and functions shown in Figure 7 are intended to be illustrative only, and embodiments of the present invention are not limited thereto. As illustrated, the following layers and corresponding functions are provided:
[0051] The hardware and software layer 60 comprises hardware and software components. Examples of hardware components include: a mainframe 61; a RISC (Reduced Instruction Set Computer) architecture-based server 62; a server 63; a blade server 64; a storage device 65; and network and networking components 66. In some embodiments, the software components include network application server software 67 and database software 68.
[0052] The virtualization layer 70 provides an abstraction layer from which virtual entities such as the following examples may be provided: virtual servers 71; virtual storage 72; virtual networks 73 including virtual private networks; virtual applications and operating systems 74; and virtual clients 75.
[0053] In one example, the management layer 80 may provide the functions described below. Resource provisioning 81 provides the dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Metering and pricing 82 provides cost tracking as resources are used within the cloud computing environment and accounting or billing for the consumption of these resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, as well as protection of data and other resources. User portal 83 provides consumers and system administrators with access to the cloud computing environment. Service level management 84 provides cloud computing resource allocation and management to ensure that required service levels are met. Service level agreement (SLA) planning and execution 85 provides pre-positioning and procurement of cloud computing resources where future requirements are anticipated in accordance with the SLA.
[0054] The workload layer 90 provides examples of functions that can be utilized in a cloud computing environment. Examples of workloads and functions that can be provided from this layer include: mapping and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analysis processing 94; transaction processing 95; and managing proprietary structured files within a hybrid cloud environment 96.
[0055] Turning to Figure 8, a computer system 800 is shown in general terms according to one embodiment. The computer system 800 may be an electronic computer framework that includes and / or uses any number and combination of computing devices and networks that utilize various communication technologies, as described herein. The computer system 800 may be easily scalable, extensible, and modular by its ability to change into different services or to reconfigure some features independently of others. The computer system 800 may be, for example, a server, desktop computer, laptop computer, tablet computer, or smartphone. In some examples, the computer system 800 may be a cloud computing node. The computer system 800 may be described in the general context of computer system executable instructions, such as program modules executed by the computer system. Generally, program modules may include routines, programs, objects, components, logic, data structures, etc., that perform a specific task or implement a specific abstract data type. The computer system 800 may be implemented in a distributed cloud computing environment where tasks are performed by remote processing devices linked through a communication network. In a distributed cloud computing environment, program modules can reside in both local computer system storage media, including memory storage devices, and remote computer system storage media.
[0056] As shown in Figure 8, the computer system 800 has one or more central processing units (CPUs) 801a, 801b, 801c, etc. (collectively referred to as processor 801). Processor 801 may be a single-core processor, a multi-core processor, a computing cluster, or any number of other configurations. Also referred to as processing circuits, processor 801 is coupled to system memory 803 and various other components via system bus 802. System memory 803 may include read-only memory (ROM) 804 and random access memory (RAM) 805. ROM 804 may include a basic input / output system (BIOS) coupled to system bus 802 that controls certain basic functions of computer system 800. RAM is read-write memory coupled to system bus 802 for use by processor 801. System memory 803 provides temporary memory space for the operation of instructions during operation. System memory 803 may include random access memory (RAM), read-only memory, flash memory, or any other suitable memory system.
[0057] The computer system 800 comprises an input / output (I / O) adapter 806 and a communication adapter 807 coupled to a system bus 802. The I / O adapter 806 may be a Small Computer System Interface (SCSI) adapter that communicates with a hard disk 808 and / or any other similar component. The I / O adapter 806 and the hard disk 808 are collectively referred to herein as mass storage 810.
[0058] Software 811 for execution on computer system 800 may be stored in mass storage 810. Mass storage 810 is an example of a tangible storage medium readable by processor 801, in which software 811 is stored as instructions executed by processor 801 to cause computer system 800 to operate as described below in this specification with respect to various figures. Computer program products and examples of the execution of such instructions are described in more detail below. A communication adapter 807 interconnects system bus 802 with network 812, which may be an external network, enabling computer system 800 to communicate with other such systems. In one embodiment, a portion of system memory 803 and mass storage 810 collectively stores an operating system, which may be any suitable operating system, for example, z / OS or AIX operating systems from IBM Corporation, for coordinating the functions of the various components shown in Figure 8.
[0059] Additional input / output devices are shown connected to the system bus 802 via display adapter 815 and interface adapter 816. In one embodiment, adapters 806, 807, 815, and 816 may be connected to one or more I / O buses connected to the system bus 802 via an intermediate bus bridge (not shown). A display 819 (e.g., a screen or display monitor) is connected to the system bus 802 by display adapter 815, which may include a graphics controller to improve the performance of graphics-intensive applications and video controllers. A keyboard 821, mouse 822, speaker 823, etc., may be interconnected to the system bus 802 via interface adapter 816, which may include a Super I / O chip that integrates multiple device adapters into a single integrated circuit. Suitable I / O buses for connecting peripheral devices such as hard disk controllers, network adapters, and graphics adapters typically include common protocols such as Peripheral Component Interconnect (PCI). Therefore, as shown in Figure 8, the computer system 800 includes processing capabilities in the form of a processor 801, storage capabilities including system memory 803 and mass storage 810, input means such as a keyboard 821 and a mouse 822, and output capabilities including a speaker 823 and a display 819.
[0060] In some embodiments, the communication adapter 807 can transmit data using any suitable interface or protocol, such as an Internet Small Computer System interface. The network 812 may be a cellular network, a wireless network, a wide area network (WAN), a local area network (LAN), or the Internet. An external computing device may connect to the computer system 800 through the network 812. In some examples, the external computing device may be an external web server or a cloud computing node.
[0061] It will be understood that the block diagram in Figure 8 is not intended to show that the computer system 800 includes all the components shown in Figure 8. Rather, the computer system 800 may include any suitable fewer components or additional components not shown in Figure 8 (e.g., additional memory components, embedded controllers, modules, additional network interfaces, etc.). Furthermore, embodiments of the computer system 800 described herein may be implemented using any suitable logic, which, when referred to herein, may include any suitable hardware (e.g., in particular, a processor, embedded controller, or application-specific integrated circuit), software (e.g., in particular, an application), firmware, or any suitable combination of hardware, software, and firmware in various embodiments.
[0062] Various embodiments of the present invention are described herein with reference to the relevant drawings. Alternative embodiments of the present invention may be devised without departing from the scope of the invention. Various connections and positional relationships (e.g., above, below, adjacent, etc.) are described between elements in the following description and drawings. These connections and / or positional relationships may be direct or indirect unless otherwise specified, and the present invention is not intended to limit them in this respect. Thus, the joining of entities may refer to either a direct or indirect joining, and the positional relationships between entities may be direct or indirect positional relationships. Furthermore, the steps of the various tasks and processes described herein may be incorporated into more comprehensive procedures or processes having additional steps or functions not described in detail herein.
[0063] One or more of the methods described herein may be implemented using any or a combination of the following technologies: discrete logic circuits having logic gates for implementing logic functions for data signals, application-specific integrated circuits (ASICs) having appropriate combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc., each of which is well known in the art.
[0064] For the sake of brevity, prior art relating to the manufacture and use of aspects of the present invention may or may not be described in detail herein. In particular, various forms of computing systems and specific computer programs for implementing the various technical features described herein are well known. Therefore, for the sake of brevity, many prior art implementation details are only briefly mentioned herein or are omitted entirely without providing details of well known systems and / or processes.
[0065] In some embodiments, various functions or operations may be performed at a given location and / or in connection with the operation of one or more devices or systems. In some embodiments, a portion of a given function or operation may be performed at a first device or location, and the remainder of the function or operation may be performed at one or more additional devices or locations.
[0066] The terms used herein are intended to describe only specific embodiments and are not intended to be limiting. Where used herein, the singular forms “a,” “an,” and “the” are intended to include the plural form unless otherwise explicitly stated in the context. Where used herein, the terms “comprises” and / or “comprising” specify the presence of the described features, integers, steps, actions, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, actions, elements, components, and / or groups thereof.
[0067] In the following claims, the corresponding structures, materials, actions, and equivalents of any means-plus-function element or step-plus-function element are intended to include any structures, materials, or actions for performing a function in combination with any other claimed element specifically claimed. This disclosure is presented for illustrative and explanatory purposes and is not intended to be exhaustive or to be limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing the scope of this disclosure. The embodiments have been selected and described to best illustrate the principles and practical applications of this disclosure and so that others skilled in the art may understand that the various embodiments with various modifications are suitable for the particular use to which this disclosure is intended.
[0068] The figures shown herein are illustrative. Many variations may exist to the figures or steps (or actions) described herein without departing from the scope of this disclosure. For example, actions may be performed in a different order, or actions may be added, deleted, or modified. Furthermore, the term “joining” describes the existence of a signal path between two elements, and does not imply that there are no intervening elements / connections between them or that the elements are directly connected. All such variations are considered part of this disclosure.
[0069] The following definitions and abbreviations may be used for interpretation of the claims and specification. Where used herein, the terms “comprises,” “comprising,” “includes,” “including,” “has,” “having,” “contains,” or “containing,” or any other variation thereof, are intended to cover non-exclusive inclusion. For example, a composition, mixture, process, method, article, or apparatus containing a list of elements is not necessarily limited to those elements alone, but may include other elements not expressly listed, or other elements specific to such composition, mixture, process, method, article, or apparatus.
[0070] Furthermore, the term “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any embodiment or design described herein as “exemplary” is not necessarily construed to be preferable or advantageous to other embodiments or designs. The terms “at least one” and “one or more” may be understood to include any integer one or more, i.e., 1, 2, 3, 4, etc. The term “more” is understood to include any integer two or more, i.e., 2, 3, 4, 5, etc. The term “connection” may include both indirect “connection” and direct “connection.”
[0071] The terms “about,” “substantially,” and “approximately,” and their variations, are intended to include the degree of error associated with measurements of a particular quantity based on equipment available at the time of filing this application. For example, “about” may include a range of ±8%, 5%, or 2% of a given value.
[0072] The present invention may be a system, method, and / or computer program product integrated at any possible level of technical detail. The computer program product may include a computer-readable storage medium (or a plurality of computer-readable storage media) having computer-readable program instructions for causing a processor to perform aspects of the present invention.
[0073] A computer-readable storage medium can be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer-readable storage medium may, but is not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any preferred combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media is below: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory sticks, floppy disks, mechanically encoded devices such as punch cards or grooved structures on which instructions are recorded, and any preferred combination thereof. As used herein, a computer-readable storage medium itself is not considered to be a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (for example, an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through a wire, or any other transient signal.
[0074] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device, or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface within each computing / processing device receives computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within each computing / processing device.
[0075] The computer-readable program instructions for performing the operation of the present invention may be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, including Smalltalk®, C++ or similar object-oriented programming languages, and procedural programming languages or similar programming languages such as the "C" programming language. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or wide area network (WAN), or the connection may be made to an external computer (for example, via the Internet using an Internet service provider). In some embodiments, for example, an electronic circuit including a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer-readable program instructions by personalizing the electronic circuit using state information of computer-readable program instructions in order to perform aspects of the present invention.
[0076] Aspects of the present invention are described herein with reference to flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It will be understood that each block in the flowcharts and / or block diagrams, and combinations of blocks within the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0077] These computer-readable program instructions may be provided to the processor of a general-purpose computer, a dedicated computer, or other programmable data processing device to generate a machine, and the instructions executed via the processor of the computer or other programmable data processing device will create means for implementing functions / operations specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can instruct a computer, a programmable data processing device, and / or other device to function in a particular manner, and the computer-readable storage medium having instructions stored therein will comprise a product containing instructions that implement modes of functions / operations specified in one or more blocks of a flowchart and / or block diagram.
[0078] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing device, or other device to perform a series of operational steps on the computer, other programmable device, or other device, thereby creating a computer implementation process in which the instructions executed on the computer, other programmable device, or other device implement the functions / operations specified in one or more blocks of a flowchart and / or block diagram.
[0079] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of the system, method, and computer program product according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions described within a block may occur in an order different from the order shown in the drawings. For example, two consecutively shown blocks may actually be executed substantially simultaneously, or the blocks may be executed in reverse order depending on the related functions. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs a specified function or operation or a combination of dedicated hardware and computer instructions.
[0080] The descriptions of various embodiments of the present invention are presented for illustrative purposes only and are not intended to be exhaustive or to limit oneself to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the described embodiments. The terms used herein have been selected to best describe the principles, practical applications, or technical improvements to the technologies available on the market of the embodiments, or to enable other those skilled in the art to understand the embodiments described herein. (Other possible items) [Item 1] The stage where the first object is received from the first client; A step of determining a first file format relating to the first object, wherein the first file format is operable to run on a first platform; A step of generating a catalog relating to the first object, wherein the catalog comprises data associated with the first object, and wherein the catalog relating to the first object is stored on a first server; The step of receiving a request from a second client to access the data associated with the first object; A step of determining the second platform operated by the second client; On a second server, the first file format relating to the first object is converted to a second file format, where the second file format is operable to run on the second platform; The step of sending the first object to the second client in the second file format. A computer implementation method comprising the following: [Item 2] The step of determining the first file format for the first object is: The step of decrypting the first object using the public key on the second server; and The step of identifying the first platform associated with the first object by the platform service module on the second server. A computer implementation method as described in item 1, comprising: [Item 3] The step of generating the catalog relating to the first object is: A step of determining the first platform for the first object; The step of operating the first platform and accessing the first object on the second server; The steps of analyzing the first object via the first platform and determining the data associated with the first object; and Steps to store the data associated with the first object in the catalog on the first server. A computer implementation method as described in item 1, comprising: [Item 4] In response to receiving the request to access the data associated with the first object: The step of determining the access rights of the first object, wherein the first object comprises an access control list; and The step of determining whether the second client can access the first object based on the access control list. A computer implementation method as described in item 1, further comprising the features described above. [Item 5] The step of converting the first file format for the first object to the second file format is: The step of identifying the first platform associated with the first object using a platform service module on the second server; The step of operating the first platform and accessing the first object on the second server; A step of converting the first file format of the first object to a common file format; The steps include: operating the second platform on the second server and accessing the common file format; and The step of converting the common file format to the second file format using the second platform. A computer implementation method as described in item 1, comprising: [Item 6] The computer implementation method described in item 1, wherein the first server has a public cloud environment. [Item 7] The aforementioned second server is a computer implementation method described in item 1, which includes a private cloud environment. [Item 8] Memory with computer-readable instructions; and One or more processors for executing the aforementioned computer-readable instructions The computer-readable instructions are provided by the one or more processors: The stage where the first object is received from the first client; A step of determining a first file format relating to the first object, wherein the first file format is operable to run on a first platform; A step of generating a catalog relating to the first object, wherein the catalog comprises data associated with the first object, and wherein the catalog relating to the first object is stored on a first server; The step of receiving a request from a second client to access the data associated with the first object; A step of determining the second platform operated by the second client; On a second server, the first file format relating to the first object is converted to a second file format, where the second file format is operable to run on the second platform; The step of sending the first object to the second client in the second file format. Control to perform an action that includes the following: system. [Item 9] The step of determining the first file format for the first object is: The step of decrypting the first object using the public key on the second server; and The step of identifying the first platform associated with the first object by the platform service module on the second server. The system described in item 8, which has the following features. [Item 10] The step of generating the catalog relating to the first object is: A step of determining the first platform for the first object; The step of operating the first platform and accessing the first object on the second server; The steps of analyzing the first object via the first platform and determining the data associated with the first object; and Steps to store the data associated with the first object in the catalog on the first server. The system described in item 8, which has the following features. [Item 11] The aforementioned operation is: In response to receiving the request to access the data associated with the first object: The step of determining the access rights of the first object, wherein the first object comprises an access control list; and The step of determining whether the second client can access the first object based on the access control list. The system described in item 8, further comprising the features described above. [Item 12] The step of converting the first file format for the first object to the second file format is: The step of identifying the first platform associated with the first object using a platform service module on the second server; The step of operating the first platform and accessing the first object on the second server; A step of converting the first file format of the first object to a common file format; The steps include: operating the second platform on the second server and accessing the common file format; and The step of converting the common file format to the second file format using the second platform. The system described in item 8, which has the following features. [Item 13] The aforementioned first server is the system described in item 8, which has a public cloud environment. [Item 14] The second server mentioned above is the system described in item 8, which has a private cloud environment. [Item 15] A computer-readable storage medium on which program instructions are embodied, wherein the program instructions are transmitted to one or more processors: The stage where the first object is received from the first client; A step of determining a first file format relating to the first object, wherein the first file format is operable to run on a first platform; A step of generating a catalog relating to the first object, wherein the catalog comprises data associated with the first object, and wherein the catalog relating to the first object is stored on a first server; The step of receiving a request from a second client to access the data associated with the first object; A step of determining the second platform operated by the second client; On a second server, the first file format relating to the first object is converted to a second file format, where the second file format is operable to run on the second platform; The step of sending the first object to the second client in the second file format. A computer program product that can be executed by one or more processors to perform an operation comprising the following: [Item 16] The step of determining the first file format for the first object is: The step of decrypting the first object using the public key on the second server; and The step of identifying the first platform associated with the first object by the platform service module on the second server. A computer program product as described in item 15, which has the following characteristics. [Item 17] The step of generating the catalog relating to the first object is: A step of determining the first platform for the first object; The step of operating the first platform and accessing the first object on the second server; The steps of analyzing the first object via the first platform and determining the data associated with the first object; and Steps to store the data associated with the first object in the catalog on the first server. A computer program product as described in item 15, which has the following characteristics. [Item 18] The aforementioned operation is: In response to receiving the request to access the data associated with the first object: The step of determining the access rights of the first object, wherein the first object comprises an access control list; and The step of determining whether the second client can access the first object based on the access control list. A computer program product as described in item 15, further comprising the features described therein. [Item 19] The step of converting the first file format for the first object to the second file format is: The step of identifying the first platform associated with the first object using a platform service module on the second server; The step of operating the first platform and accessing the first object on the second server; A step of converting the first file format of the first object to a common file format; The steps include: operating the second platform on the second server and accessing the common file format; and The step of converting the common file format to the second file format using the second platform. A computer program product as described in item 15, which has the following characteristics. [Item 20] The computer program product described in item 15, wherein the first server has a public cloud environment and the second server has a private cloud environment.
Claims
1. The stage in which the first server receives the first object from the first client; In the step where the second server determines a first file format relating to the first object, the first file format is operable to run on a first platform, and the first platform is implemented on the first client; In the first step, the first server generates a catalog relating to the first object, wherein the catalog comprises data associated with the first object, and wherein the catalog relating to the first object is stored on the first server; The first server receives a request from a second client to access the data associated with the first object; In the stage where the first server determines the second platform to be operated by the second client, the second platform is implemented on the second client; On the second server, the first file format relating to the first object is converted to a second file format, wherein the second file format is operable to run on the second platform; The first server sends the first object to the second client in the second file format. A computer implementation method comprising the following:
2. The step of determining the first file format for the first object is: The step of decrypting the first object using the public key on the second server; and The step of identifying the first platform associated with the first object by the platform service module on the second server. A computer implementation method according to claim 1, comprising:
3. The step of generating the catalog relating to the first object is: The first server determines the first platform for the first object; The step of operating the first platform on the second server and accessing the first object; The steps include: the second server analyzing the first object via the first platform and determining the data associated with the first object; and Step 1: The first server stores the data associated with the first object in the catalog on the first server. A computer implementation method according to claim 1, comprising:
4. In response to receiving the request to access the data associated with the first object: In the step where the second server determines the access rights of the first object, the first object comprises an access control list; and The second server determines, based on the access control list, that the second client can access the first object. A computer implementation method according to any one of claims 1 to 3, further comprising the above.
5. The step of converting the first file format for the first object to the second file format is: The step of identifying the first platform associated with the first object using a platform service module on the second server; The step of operating the first platform on the second server and accessing the first object; The step in which the second server converts the first file format of the first object to a common file format; The steps include: operating the second platform on the second server and accessing the common file format; and The second server converts the common file format to the second file format using the second platform. A computer implementation method according to any one of claims 1 to 3, comprising:
6. The computer implementation method according to any one of claims 1 to 3, wherein the first server comprises a public cloud environment.
7. The computer implementation method according to any one of claims 1 to 3, wherein the second server comprises a private cloud environment.
8. Memory with computer-readable instructions; and Multiple processors for executing the aforementioned computer-readable instructions The computer-readable instructions are: The first step is for the processor of the first server to receive a first object from the first client; In the step of determining a first file format relating to the first object by the processor of the second server, wherein the first file format is operable to run on a first platform, and the first platform is implemented on the first client; A step in which a catalog relating to the first object is generated by the processor of the first server, wherein the catalog comprises data associated with the first object, and wherein the catalog relating to the first object is stored on the first server; The first step is for the processor of the first server to receive a request from a second client to access the data associated with the first object; In the step of determining the second platform operated by the second client using the processor of the first server, the second platform is implemented on the second client; The processor of the second server converts the first file format relating to the first object to a second file format, wherein the second file format is operable to run on the second platform; Steps to send the first object to the second client in the second file format by the processor of the first server. Control to perform an action that includes the following: system.
9. The step of determining the first file format for the first object is: The step of decrypting the first object using the public key on the second server; and The step of identifying the first platform associated with the first object by the platform service module on the second server. The system according to claim 8, having the following features.
10. The step of generating the catalog relating to the first object is: A step in which the processor of the first server determines the first platform for the first object; The step of operating the first platform on the second server and accessing the first object; The steps include: the processor of the second server analyzing the first object via the first platform and determining the data associated with the first object; and Steps include storing the data associated with the first object in the catalog on the first server using the processor of the first server. The system according to claim 8, having the following features.
11. The aforementioned operation is: In response to receiving the request to access the data associated with the first object: The step of determining the access rights of the first object by the processor of the second server, wherein the first object includes an access control list; and The second step involves the processor of the second server determining, based on the access control list, that the second client can access the first object. The system according to any one of claims 8 to 10, further comprising:
12. The step of converting the first file format for the first object to the second file format is: The step of identifying the first platform associated with the first object using a platform service module on the second server; The step of operating the first platform on the second server and accessing the first object; A step in which the processor of the second server converts the first file format of the first object to a common file format; The steps include: operating the second platform on the second server and accessing the common file format; and The step of using the second platform to convert the common file format to the second file format using the processor of the second server. The system according to any one of claims 8 to 10, having
13. The system according to any one of claims 8 to 10, wherein the first server comprises a public cloud environment.
14. The system according to any one of claims 8 to 10, wherein the second server comprises a private cloud environment.
15. When a program instruction is provided and executed by multiple processors, the program instruction is: The first step is for the processor of the first server to receive a first object from the first client; In the step of determining a first file format relating to the first object by the processor of the second server, wherein the first file format is operable to run on a first platform, and the first platform is implemented on the first client; A step in which a catalog relating to the first object is generated by the processor of the first server, wherein the catalog comprises data associated with the first object, and wherein the catalog relating to the first object is stored on the first server; The first step is for the processor of the first server to receive a request from a second client to access the data associated with the first object; In the step of determining the second platform operated by the second client using the processor of the first server, the second platform is implemented on the second client; The processor of the second server converts the first file format relating to the first object to a second file format, wherein the second file format is operable to run on the second platform; Steps to send the first object to the second client in the second file format by the processor of the first server. A computer program that causes an action to be performed.
16. The step of determining the first file format for the first object is: The step of decrypting the first object using the public key on the second server; and The step of identifying the first platform associated with the first object by the platform service module on the second server. A computer program according to claim 15, having the following:
17. The step of generating the catalog relating to the first object is: A step in which the processor of the first server determines the first platform for the first object; The step of operating the first platform on the second server and accessing the first object; The steps include: the processor of the second server analyzing the first object via the first platform and determining the data associated with the first object; and Steps include storing the data associated with the first object in the catalog on the first server using the processor of the first server. A computer program according to claim 15, having the following:
18. The aforementioned operation is: In response to receiving the request to access the data associated with the first object: The step of determining the access rights of the first object by the processor of the second server, wherein the first object includes an access control list; and The second step involves the processor of the second server determining, based on the access control list, that the second client can access the first object. A computer program according to any one of claims 15 to 17, further comprising:
19. The step of converting the first file format for the first object to the second file format is: The step of identifying the first platform associated with the first object using a platform service module on the second server; The step of operating the first platform on the second server and accessing the first object; A step in which the processor of the second server converts the first file format of the first object to a common file format; The steps include: operating the second platform on the second server and accessing the common file format; and The step of using the second platform to convert the common file format to the second file format using the processor of the second server. A computer program according to any one of claims 15 to 17, having the following:
20. The computer program according to any one of claims 15 to 17, wherein the first server has a public cloud environment and the second server has a private cloud environment.
Citation Information
Patent Citations
Proxy server device
JP2006163694A
Security printing system and method for outputting data
JP2006318245A
Content asset management system, method and control program
JP2009175790A
Data relay device, terminal device, data processing system, and program
JP2015082177A
Image file conversion method and apparatus
US20180203719A1