Computing power network isolation method and device of intelligent computing center cloud platform

By configuring network isolation space according to network boundary information of different granularity in the intelligent computing center cloud platform, the problem of poor flexibility in traditional computing power network isolation methods is solved, and flexible and secure network isolation effect is achieved to adapt to the needs of different business scenarios.

CN120498820APending Publication Date: 2025-08-15DATACANVAS LTD

Patent Information

Application Number
CN202510753124.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, the computing power network isolation method of intelligent computing centers has the problem of poor flexibility. The traditional VLAN logical isolation configuration is complex and has poor scalability, while physical isolation is highly secure but has poor flexibility.

Method used

By obtaining the first network boundary information, the network is configured for the computing power of the intelligent computing center cloud platform, and according to the network boundary information of different granularity, the network isolation objects are separated into multiple network isolation spaces, including tenants, projects, tasks, services, containers, virtual servers, etc., and the corresponding logical network is configured, combining physical and virtual network resources, and an SDN controller and access control list are used for access rights control.

Benefits of technology

It realizes multi-grain network isolation according to different business needs in the intelligent computing center cloud platform, improves the flexibility and security of network isolation, reduces resource waste, and enhances the system's adaptability and operationality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498820A_ABST
    Figure CN120498820A_ABST
Patent Text Reader

Abstract

The invention provides a computing power network isolation method and device for an intelligent computing center cloud platform, and relates to the technical field of intelligent computing centers, intelligent computing centers and computing power infrastructures, and the method comprises the steps: S1, obtaining first network boundary information; s2, configuring a network for the computing power of the intelligent computing center cloud platform based on the first network boundary information; and S3, according to the first network boundary information, the network is divided into at least two network isolation spaces according to network isolation objects, the network isolation objects comprise at least one of tenants, items, tasks, services, containers and virtual servers, and each network isolation space is configured with a corresponding logic network. In the invention, the network isolation space is divided for the computing power configuration logic network, and the first network boundary comprises the network boundary information of different granularities, so that the computing power of the intelligent computing center cloud platform can be subjected to network isolation according to multiple granularities, and the flexibility of network isolation can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent computing centers, smart computing centers and computing power infrastructure, and in particular to a method and device for isolating computing power networks of intelligent computing center cloud platforms. Background Art

[0002] With the rapid development of artificial intelligence technology, "intelligent computing centers" and "intelligent computing centers" have emerged.

[0003] An "Intelligent Computing Center" is a facility that uses large-scale heterogeneous computing resources, including general-purpose and intelligent computing power, to provide the computing power, data, and algorithms required for AI applications (such as AI deep learning model development, model training, and model inference). The Intelligent Computing Center encompasses facilities, hardware, and software, and provides a full stack of capabilities, from bottom-level computing power to top-level application enablement.

[0004] “Intelligent Computing Center” includes but is not limited to “Smart Computing Center”.

[0005] "Intelligent Computing Center" refers to an artificial intelligence computing center. It is a type of computing power infrastructure that is based on artificial intelligence theory, adopts artificial intelligence computing architecture, and provides computing power services, data services, and algorithm services required for artificial intelligence applications.

[0006] "Computing power" is the core of "intelligent computing center" and "intelligent computing center". It is the ability of computer equipment or computing / data center to process information. It is the ability of computer hardware and software to work together to perform certain computing needs. It is the computing power to achieve target result output by processing information data. It is a new type of productivity that integrates information computing power, network carrying capacity, and data storage capacity. It mainly provides services to society through computing power infrastructure.

[0007] Since the emergence of intelligent computing centers, the issue of computing power network isolation has become increasingly prominent. Traditional network isolation methods include logical isolation based on virtual local area networks (VLANs) and isolation based on physical networks. However, while logical VLAN isolation can provide a certain degree of network segmentation, its configuration process is complex and its scalability is poor. Physical isolation, while highly secure, suffers from limited flexibility. Therefore, improving the flexibility of computing power network isolation is an urgent issue. Summary of the Invention

[0008] The present invention provides a computing power network isolation method and device for an intelligent computing center cloud platform, which are used to solve the problem of how to improve the flexibility of computing power network isolation.

[0009] In order to solve the above-mentioned technical problems, the present invention is achieved as follows:

[0010] In a first aspect, the present invention provides a method for isolating computing power networks of an intelligent computing center cloud platform, comprising:

[0011] Step S1: Obtain first network boundary information;

[0012] Step S2: Based on the first network boundary information, configure a network for the computing power of the intelligent computing center cloud platform, where the network includes at least one of a physical network and a virtual network;

[0013] Step S3: Based on the first network boundary information, the network is divided into at least two network isolation spaces according to the network isolation object, wherein the network isolation object includes at least one of a tenant, a project, a task, a service, a container, and a virtual server, and each of the at least two network isolation spaces is configured with a corresponding logical network.

[0014] Optionally, step S1 includes:

[0015] Step S11: obtaining first network boundary information, and creating at least two network isolation spaces based on the first network boundary information, wherein the first network boundary information includes network boundary information with at least one of a tenant, a project, a task, a service, a container, and a virtual server as a network isolation object;

[0016] The step S3 comprises:

[0017] Step S31: Based on the at least two network isolation spaces corresponding to the first network boundary information, logical network configuration is performed on the computing power, and each network isolation space in the at least two network isolation spaces corresponds to each network isolation object.

[0018] Optionally, step S2 includes:

[0019] Step S21: Based on the first network boundary information, configure at least one of a physical network card and a virtual network card for the computing power of the intelligent computing center cloud platform;

[0020] Step S22: Allocate an Internet Protocol IP address, a Media Access Control MAC address and routing rules to the computing power.

[0021] Optionally, the method further comprises at least one of the following:

[0022] Step S4: Setting access rights to the computing power through at least one of a software defined network (SDN) controller, an access control list (ACL), and a flow table;

[0023] Step S5: Control the network traffic of the computing power based on the access permission.

[0024] Optionally, step S1 includes any of the following:

[0025] Step S12: Acquire the first network boundary information input by the user;

[0026] Step S13: When the computing power changes, the second network boundary information is adjusted based on the changed computing power to obtain the first network boundary information.

[0027] Optionally, the network configured for the computing power of the intelligent computing center cloud platform includes an in-band management network and an out-of-band control network that are isolated from each other; and the method further includes:

[0028] Step S6: performing service transmission based on the in-band management network, and performing control instruction transmission based on the out-of-band control network.

[0029] In a second aspect, the present invention provides a computing power network isolation device for an intelligent computing center cloud platform, comprising:

[0030] An acquisition module, configured to acquire first network boundary information;

[0031] a configuration module, configured to configure a network for computing power of the intelligent computing center cloud platform based on the first network boundary information, wherein the network includes at least one of a physical network and a virtual network;

[0032] A separation module is used to separate the network into at least two network isolation spaces according to the network isolation object based on the first network boundary information, wherein the network isolation object includes at least one of a tenant, a project, a task, a service, a container, and a virtual server, and each of the at least two network isolation spaces is configured with a corresponding logical network.

[0033] In the third aspect, the present invention provides a server comprising: a processor, a memory, and a program stored on the memory and runnable on the processor. When the program is executed by the processor, the steps of the computing power network isolation method of the intelligent computing center cloud platform as described in the first aspect above are implemented.

[0034] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the computing power network isolation method of the intelligent computing center cloud platform as described in the first aspect above are implemented.

[0035] In a fifth aspect, the present invention provides a computer program product comprising computer instructions, which, when executed by a processor, implement the steps of the computing power network isolation method of the intelligent computing center cloud platform as described in the first aspect above.

[0036] In the present invention, the network isolation space is divided based on the first network boundary information, and a logical network is configured for the computing power of the intelligent computing center cloud platform to achieve the division of the network isolation space. Since the first network boundary includes network boundary information of different granularities, the computing power of the intelligent computing center cloud platform can be network isolated according to multiple granularities, which can improve the flexibility of network isolation. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:

[0038] Figure 1 This is one of the flow charts of the computing power network isolation method of the intelligent computing center cloud platform provided by the present invention;

[0039] Figure 2 This is the second flow chart of the computing power network isolation method of the intelligent computing center cloud platform provided by the present invention;

[0040] Figure 3 This is the third flow chart of the computing power network isolation method of the intelligent computing center cloud platform provided by the present invention;

[0041] Figure 4 This is a structural diagram of the computing power network isolation device of the intelligent computing center cloud platform provided by the present invention;

[0042] Figure 5 This is a structural diagram of a server provided by the present invention. DETAILED DESCRIPTION

[0043] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the accompanying drawings. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0044] First, the technical terms involved in the present invention are briefly explained below.

[0045] The "computing power" mentioned in the present invention refers to: the ability of computer equipment or computing / data centers to process information, the ability of computer hardware and software to work together to execute certain computing requirements, and the computing power to achieve target result output by processing information data. It is a new type of productivity that integrates information computing power, network carrying capacity, and data storage capacity, and mainly provides services to society through computing power infrastructure.

[0046] The "computing power" (CP) mentioned in the present invention refers to: the ability of a data center server to process data and output results. It is a comprehensive indicator to measure the computing power of a data center, including general computing power, super computing power and intelligent computing power. The commonly used unit of measurement is the number of floating-point operations performed per second (FLOPS, 1EFLOPS=10^18FLOPS). The larger the value, the stronger the comprehensive computing power. According to calculations, 1EFLOPS is approximately the computing power output of 5 Tianhe-2A or 500,000 mainstream server CPUs or 2 million mainstream notebooks. The calculation formula is: CP=CP 通用 +CP 智能 +CP 超级 .

[0047] The "carrying capacity" (Network Power, NP) mentioned in the present invention refers to: it is the performance of the data transmission capability of the computing power facility, which includes comprehensive capabilities such as network architecture, network bandwidth, transmission latency, intelligent management and scheduling, etc. It involves network transmission within and between data centers, and is a comprehensive indicator for measuring network transmission scheduling capabilities.

[0048] The "Storage Power" (SP) described in this invention refers to the comprehensive capabilities of a data center in terms of data storage capacity, performance, security and reliability, and environmental friendliness. It is a comprehensive indicator for measuring a data center's data storage capacity, encompassing both external storage devices such as storage arrays and internal server storage. Storage capacity is commonly measured in exabytes (EB, 1EB = 2^60 bytes), while performance is commonly measured in IOPS / TB (Input / Output Operations Per Second / TB). Disaster recovery ratio is a key indicator of security and reliability.

[0049] The "computing power infrastructure" mentioned in the present invention refers to a new type of information infrastructure that integrates information computing power, network carrying capacity, and data storage capacity, and can realize the centralized calculation, storage, transmission and application of information.

[0050] The "new information infrastructure" mentioned in the present invention refers to: mainly including network infrastructure such as 5G networks, fiber-optic broadband networks, backbone networks, international communication networks, satellite Internet, computing power infrastructure such as data centers, general computing power centers, intelligent computing centers, supercomputing centers, and new technology facilities such as artificial intelligence, blockchain, and quantum computing.

[0051] The "computing power" mentioned in the present invention includes: general computing power, intelligent computing power and super computing power.

[0052] The "general computing power" mentioned in the present invention refers to the computing power provided by servers based on CPU (Central Processing Unit) chips, which is used to support basic general computing such as cloud computing and edge computing.

[0053] The "intelligent computing power" mentioned in this invention refers to: a computing platform based on specialized chips such as GPU (Graphics Processing Unit), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit) for various innovative artificial intelligence applications, such as natural language processing (NLP) and machine vision.

[0054] The "supercomputing power" mentioned in the present invention refers to the computing power provided by high-performance computing clusters such as supercomputers. It utilizes the centralized computing resources of multiple computer systems working in parallel and uses a dedicated operating system to handle extremely complex or data-intensive problems. It is mainly used for calculations in cutting-edge scientific fields, such as planetary simulation, drug molecule design, genetic analysis, etc.

[0055] The "intelligent computing center" described in this article refers to a facility that provides the computing power, data, and algorithms required for artificial intelligence applications (such as AI deep learning model development, model training, and model inference) by utilizing large-scale heterogeneous computing resources, including general-purpose computing power (CPU) and intelligent computing power (GPU, FPGA, ASIC, etc.). The intelligent computing center encompasses facilities, hardware, and software, and can provide a full stack of capabilities, from bottom-level computing power to top-level application enablement.

[0056] The "intelligent computing center cloud platform" mentioned in the present invention refers to: a cloud computing platform that provides comprehensive services based on the hardware resources and software resources of the intelligent computing center.

[0057] The "intelligent computing center" mentioned in the present invention includes but is not limited to the "intelligent computing center".

[0058] The "intelligent computing center" mentioned in the present invention is an artificial intelligence computing center, which is a type of computing power infrastructure based on artificial intelligence theory, adopts artificial intelligence computing architecture, and provides computing power services, data services and algorithm services required for artificial intelligence applications.

[0059] The "computing power center" mentioned in the present invention refers to: a facility that is mainly composed of infrastructure such as wind, fire, water, electricity, and IT hardware and software equipment, and has computing power, transportation capacity, and storage capacity, including general data centers, intelligent computing centers, supercomputing centers, etc.

[0060] The "supercomputing center" mentioned in the present invention refers to: a supercomputing data center, which is a data center based on a supercomputer or a large-scale computing cluster, which can provide large-scale computing, storage and network services and other functions, and is widely used in application scenarios such as aerospace, national defense, oil exploration, climate modeling and genome sequencing.

[0061] The "computing resources" mentioned in the present invention refer to: technologies and facilities with information calculation, transmission, storage and application capabilities required for the development of a digital society, including but not limited to computing resources such as CPUs and GPUs, network resources such as switches and routers, storage resources such as storage arrays and distributed storage, security resources such as firewalls and intrusion detection systems, and supporting and guarantee resources such as wind, fire, water, and electricity.

[0062] The "computing power node" mentioned in the present invention refers to the computing resources of the server / container that can process computing tasks.

[0063] The "computing power operation task" mentioned in the present invention refers to: a specific workload or job executed on computing power resources that requires a certain amount of computing power support, usually involving complex data processing, numerical calculations, model training or simulation scenarios.

[0064] The "network boundary information" mentioned in the present invention refers to: after the computing power is network isolated, the boundary information of each network isolation space is used to represent the scope of each network isolation space.

[0065] The "network isolation space" mentioned in the present invention refers to the network space range of each network isolation object obtained after network isolation of computing power.

[0066] The "network isolation object" mentioned in the present invention refers to: an object that needs to be network isolated, such as a tenant, project, task, service, container, virtual server, etc. Each network isolation object corresponds to an independent network isolation space.

[0067] See also Figure 1 , Figure 1 This is a computing power network isolation method for an intelligent computing center cloud platform provided by an embodiment of the present application, such as Figure 1 As shown, the method includes:

[0068] Step S1: Obtain first network boundary information;

[0069] Step S2: Based on the first network boundary information, configure a network for the computing power of the intelligent computing center cloud platform, where the network includes at least one of a physical network and a virtual network;

[0070] Step S3: Based on the first network boundary information, the network is divided into at least two network isolation spaces according to the network isolation object, wherein the network isolation object includes at least one of a tenant, a project, a task, a service, a container, and a virtual server, and each of the at least two network isolation spaces is configured with a corresponding logical network.

[0071] The first network boundary information may include network boundary information of one or more network isolation objects.

[0072] In some implementations, network isolation boundary information, ie, network boundary information, may be defined through user input or preset rules.

[0073] In some implementations, the network boundary information can be dynamically adjusted based on existing network boundary information according to changes in computing power (eg, addition or deletion).

[0074] In some implementations, the computing power of the intelligent computing center cloud platform can be used to define network boundaries according to the granularity of tenants, projects, tasks, services, containers, virtual servers, etc., to achieve network isolation between network isolation objects. For example, tenant-level isolation: allocate independent network resources to each tenant to limit communication between tenants. Task-level isolation: configure an independent logical network for task A to ensure that the data of task A is only transmitted within the resources of task A. Container-level isolation: allocate an independent logical network for container B to achieve fine-grained network isolation. The boundary information of network isolation can be defined according to one or more of the above granularities. For example, configure an independent logical network for tenant A, and configure an independent logical network for task B within tenant A to achieve double network isolation and improve network security.

[0075] This multi-granularity definition method can meet the personalized needs of network isolation in different business scenarios, whether it is the overall network isolation of large enterprise tenants or the fine-grained isolation at the level of individual projects, tasks, or even containers, which can improve the flexibility of network isolation.

[0076] Based on the first network boundary information, at least one of a physical network and a virtual network is allocated to the computing power. The physical network can be understood as a network configured by network hardware resources; the virtual network can be understood as a network configured by virtualization technology.

[0077] In some implementations, dedicated virtual network interfaces (NICs) or physical NICs are bound to the computing resources of the intelligent computing center cloud platform, and Internet Protocol (IP) and Media Access Control (MAC) routing rules are configured. This network configuration approach allows for flexible selection of virtual or physical network interfaces based on business needs and security levels, ensuring the uniqueness and security of computing resources within the network. Furthermore, by configuring IP and MAC routing rules, the accuracy and efficiency of network communications are improved.

[0078] In some embodiments, when the computing resources of the intelligent computing center cloud platform include multiple computing resources, at least one of a physical network or a virtual network is allocated to each computing resource.

[0079] After configuring the network for the computing power of the intelligent computing center cloud platform, the computing power of the intelligent computing center cloud platform is isolated according to the network isolation object based on the first network boundary information to obtain at least two network isolation spaces, each network isolation space including a corresponding network isolation object.

[0080] For example, tenant isolation: Tenant A's network isolation space and tenant B's network isolation space cannot communicate with each other.

[0081] Task isolation: The network isolation space of Task C only allows access by specific computing power.

[0082] In some implementations, an independent logical network space is allocated to each network isolation object through overlay networking, such as Virtual Extensible LAN (VxLAN) and Generic Network Virtualization Encapsulation (Geneve), to isolate different network isolation objects from each other. Overlay networking technology can build multiple independent virtual network spaces based on the physical network. In this way, network traffic from different network isolation objects can only be transmitted within their respective virtual network isolation spaces without interfering with each other, greatly improving the strength and security of network isolation.

[0083] In some embodiments, a network isolation space is created based on the first network boundary information, computing power resources of the intelligent computing center cloud platform are enabled in multiple isolated networks, computing power resources are bound to network resources (virtual network or physical network), and then a logical network (Overlay network) is configured through a switch to achieve isolation of computing power in the virtual network space.

[0084] In some embodiments, a network (virtual network or physical network) is configured for the computing power of the intelligent computing center cloud platform based on the first network boundary information, and a network isolation space is created based on the first network boundary information, and then a logical network (Overlay network) is configured through a switch to achieve isolation of computing power in the virtual network space.

[0085] Through the above method, multi-level isolation can be supported to meet the flexibility requirements of different business scenarios.

[0086] Optionally, step S1 includes:

[0087] Step S11: obtaining first network boundary information, and creating at least two network isolation spaces based on the first network boundary information, wherein the first network boundary information includes network boundary information with at least one of a tenant, a project, a task, a service, a container, and a virtual server as a network isolation object;

[0088] The step S3 comprises:

[0089] Step S31: Based on the at least two network isolation spaces corresponding to the first network boundary information, logical network configuration is performed on the computing power, and each network isolation space in the at least two network isolation spaces corresponds to each network isolation object.

[0090] Among them, network boundary information can be based on user operations or preset network isolation rules, and can include network isolation objects (such as tenants, projects, tasks, services, containers, virtual servers, etc.) and resource allocation requirements.

[0091] Among them, tenants can be users or groups that use cloud platform services, such as an enterprise, department, etc.

[0092] A project can be a business unit under a tenant.

[0093] A task can be a specific computing power operation task, such as a data analysis task, a large model calculation task, etc.

[0094] Services can be used to implement specific functions.

[0095] A container can be a unit of virtualization.

[0096] The network isolation based on the above different granularities can be adapted to different user needs and improve the flexibility of network isolation.

[0097] In some embodiments, as Figure 2As shown in the figure, at least two virtual network spaces (i.e., network isolation spaces) are created based on user-defined network boundaries. After the user activates computing resources, the computing resources are configured with a physical network or virtual network, and the IP, MAC, and routing rules are configured. By controlling the switch, a logical network (overlay network) is configured for the computing resources, thus achieving network isolation between different network isolation objects.

[0098] Taking the network isolation object including the first isolation object as an example, when it is determined based on the first network boundary information that the network isolation object includes the first isolation object, the computing power is used to create a logical network based on the first isolation object, and the logical network is used to separate the network isolation space.

[0099] The first isolation object may be any object among tenants, projects, tasks, services, containers, and virtual servers.

[0100] Taking the first isolation object as a tenant as an example, when it is determined based on the first network boundary information that the isolation object includes tenant A, a logical network is configured based on the computing power corresponding to tenant A, thereby configuring an independent network isolation space for tenant A.

[0101] When the first network boundary information includes information of multiple network isolation objects, the process of creating a network isolation space for each network isolation object can be the same as that for the first isolation object.

[0102] Through the above methods, flexible and secure isolation of computing power at multiple granularities is achieved.

[0103] Optionally, step S2 includes:

[0104] Step S21: Based on the first network boundary information, configure at least one of a physical network card and a virtual network card for the computing power of the intelligent computing center cloud platform;

[0105] Step S22: Allocate an Internet Protocol IP address, a Media Access Control MAC address and routing rules to the computing power.

[0106] In some embodiments, physical network cards and virtual network cards are allocated to the computing power of the intelligent computing center cloud platform based on the first network boundary information (such as isolated objects such as tenants, tasks, and containers).

[0107] In some implementations, a physical network card is allocated to the computing power of the intelligent computing center cloud platform, and an independent physical network interface is allocated.

[0108] In some implementations, a virtual network card is allocated to the computing power of the intelligent computing center cloud platform, and an independent virtual network interface is allocated.

[0109] According to the first network boundary information, an IP address, a MAC address and a routing rule are allocated to the physical network card or the virtual network card of the computing power.

[0110] For example, assign an IP address and MAC address to the physical network card of tenant A and configure routing rules.

[0111] By allocating the computing power of the intelligent computing center cloud platform to the network in the above manner, virtual networks or physical network interfaces can be flexibly selected according to business needs and security levels to ensure that the computing power remains unique in the network, improve security, and enhance the accuracy and efficiency of network communications.

[0112] Optionally, the method further includes:

[0113] Step S4: Setting access rights to the computing power through at least one of a software-defined network (SDN) controller, an access control list (ACL), and a flow table;

[0114] Step S5: Control the network traffic of the computing power based on the access permission.

[0115] By configuring any one or more of the SDN controller, ACL, and flow table, you can set access permissions for the computing power. For example, you can allow devices within a specific IP range to access the computing power; deny traffic from unknown or unauthorized IP addresses; or allow traffic from specific IP addresses to access the computing power.

[0116] For example, you can set computing power B to be able to access computing power A, but computing power C cannot access computing power A.

[0117] With these access permissions, computing power network traffic can be filtered, forwarded, or discarded, enabling east-west (between isolated objects) and north-south (external access) traffic filtering and control. Comprehensive monitoring and precise control of network traffic effectively prevents unauthorized access and data leaks, ensuring network security and stability. Furthermore, auditing network traffic facilitates the timely identification and resolution of network security issues.

[0118] Optionally, step S1 includes any of the following:

[0119] Step S11: Acquire the first network boundary information input by the user;

[0120] Step S12: When the computing power changes, the second network boundary information is adjusted based on the changed computing power to obtain the first network boundary information.

[0121] The first network boundary information may be defined based on user input or dynamically adjusted based on computing power changes.

[0122] In one embodiment, first network boundary information defined and input by a user is obtained.

[0123] In one embodiment, the network is configured based on the second network boundary information input by the user. When a computing power change is detected, the current second network boundary information is adjusted based on the changed computing power to obtain the first network boundary information.

[0124] For example, when computing power changes, including adding new computing resource nodes or migrating computing resources, the network isolation strategy is adjusted based on the changed computing power, that is, the current second network boundary information is adjusted to the first network boundary information. The adjusted first network boundary information can perform network isolation for the changed computing power, thereby improving the effectiveness and continuity of network isolation.

[0125] Optionally, the network configured for the computing power of the intelligent computing center cloud platform includes an in-band management network and an out-of-band control network that are isolated from each other; and the method further includes:

[0126] Step S6: performing service transmission based on the in-band management network, and performing control instruction transmission based on the out-of-band control network.

[0127] By isolating the computing power configuration network of the intelligent computing center cloud platform into an in-band management network and an out-of-band control network, the in-band management network is responsible for the transmission and scheduling of business data, while the out-of-band control channel is used for the management and transmission of control instructions for the platform. The two are independent and do not affect each other. This approach achieves isolation of north-south traffic (external access traffic), further improving system security and reliability.

[0128] As a specific embodiment of the present invention, Figure 2 As shown in the figure, the computing power network isolation method of the intelligent computing center cloud platform includes the following steps:

[0129] Step 1: The user defines the network boundary information.

[0130] Step 2: Transmit the network boundary information to the resource management system.

[0131] Step 3: Divide the virtual network space, that is, temporarily store the network boundary information in the distributed key-value storage (etcd), and apply the network to specific devices after the user opens the resources.

[0132] Step 4: The user turns on computing resources.

[0133] Step 5: Transmit the computing resource information enabled by the user to the resource manager, including resource scheduling information.

[0134] Step 6: Send the network information required for the computing power resources to the network resource binding module, and at the same time send a signal to the virtual network space division module.

[0135] Step 7: The network resource binding module configures IP / MAC / routing rules for the physical network or virtual network to implement the network configuration of computing power, where computing power resources can include GPUs, containers (PODs), etc.

[0136] Step 8: Use the virtual network space partitioning module to control the switch to configure the Overlay network to achieve network space partitioning.

[0137] Step 9: The border control and audit module monitors resource and traffic usage in real time.

[0138] Step 10: The monitored resources and traffic status are transmitted to the resource management system, and the isolation strategy is adjusted in real time through the resource management system, that is, the network boundary information is adjusted.

[0139] Through this approach, the automated configuration system can pre-set policy generation templates, application programming interfaces (APIs), and dynamic change mechanisms. When computing resources or computing power changes, policies are generated based on the changed computing power or computing power resources and automatically sent to the resource manager or cloud platform. This reduces the workload of manual configuration and improves configuration efficiency and accuracy. Furthermore, the dynamic change mechanism enables network isolation policies to be adjusted promptly based on changing business needs, enhancing the system's adaptability and flexibility.

[0140] The process of the above scheme can be found in Figure 3 shown.

[0141] The above process may be performed by a network isolation device, which may include the following core units:

[0142] Policy Controller: Used to generate and distribute network isolation policies. As the core of the entire device, the policy controller generates reasonable network isolation policies based on the requirements of the resource management system and business needs, and accurately distributes them to each relevant module to ensure the effective implementation of the network isolation policy.

[0143] The interface binding module is used to bind independent network interfaces to computing nodes (i.e., computing resources) based on policies. The interface binding module strictly follows the policies issued by the policy controller and selects the appropriate virtual or physical network interface for each computing node to bind, ensuring the independence and security of the computing node in the network.

[0144] Virtual Network Generation Module: This module is used to automatically create an isolated virtual network environment. Leveraging overlay network technology, the module quickly and efficiently creates an independent virtual network space for each tenant, ensuring network isolation between different tenants.

[0145] Audit and Monitoring Module: This module provides real-time auditing and alerting of network isolation status. The module continuously monitors network isolation status and issues alerts if any anomalies are detected, allowing operations personnel to quickly take action and ensure the network's secure and stable operation.

[0146] Dynamic Scheduling Interface: This interface automatically adapts policies to dynamic changes in computing power or computing resources. Specifically, when computing power or computing resources change dynamically, such as when new computing nodes are added or resources are migrated, the dynamic scheduling interface automatically adjusts network isolation policies to ensure the effectiveness and continuity of network isolation.

[0147] Traditional network isolation methods include VLAN-based logical isolation. This approach assigns different tenants or services to their own broadcast domains by configuring different VLAN IDs, and then uses ACLs for access control. This approach offers flexibility but suffers from complex configuration and poor scalability, leading to high management costs, especially in large-scale data centers.

[0148] Physical network isolation achieves physical isolation and ensures security by assigning independent physical network ports and switches to different tenants. However, this approach wastes resources, is costly, and is not suitable for scenarios requiring flexible resource scheduling.

[0149] Isolation based on virtual private clouds (VPCs) and SDNs achieves tenant-level virtual network isolation by flexibly scheduling network traffic through network virtualization and SDN controllers. This approach is flexible, but relies on the capabilities of the SDN controller, is complex to configure, can easily bypass security policies, and suffers from consistency and response delay issues.

[0150] The proposed method for isolating computing power networks in intelligent computing centers achieves network security isolation through physical and logical isolation. It also supports automatic adjustment and rollback of network isolation policies during task execution, improving the system's adaptability. Automated configuration and reuse mechanisms reduce waste of network equipment and bandwidth resources, while network status auditing and visualization modules enhance maintainability and compliance.

[0151] See also Figure 4 , Figure 4 This invention provides a computing power network isolation device for an intelligent computing center cloud platform. Figure 4 As shown, the device includes:

[0152] An acquisition module 401 is configured to acquire first network boundary information;

[0153] A configuration module 402 is configured to configure a network for computing power of the intelligent computing center cloud platform based on the first network boundary information, wherein the network includes at least one of a physical network and a virtual network;

[0154] The separation module 403 is used to separate the network into at least two network isolation spaces according to the network isolation object based on the first network boundary information, wherein the network isolation object includes at least one of a tenant, a project, a task, a service, a container, and a virtual server, and each of the at least two network isolation spaces is configured with a corresponding logical network.

[0155] Optionally, the acquisition module 401 is specifically configured to: acquire first network boundary information, and create at least two network isolation spaces based on the first network boundary information, wherein the first network boundary information includes network boundary information with at least one of a tenant, a project, a task, a service, a container, and a virtual server as a network isolation object;

[0156] The separation module 403 is specifically used to: perform logical network configuration on the computing power based on the at least two network isolation spaces corresponding to the first network boundary information, and each network isolation space in the at least two network isolation spaces corresponds to each network isolation object.

[0157] Optionally, the configuration module 402 includes:

[0158] A configuration submodule, configured to configure at least one of a physical network card and a virtual network card for the computing power of the intelligent computing center cloud platform based on the first network boundary information;

[0159] The allocation submodule is used to allocate Internet Protocol IP addresses, Media Access Control MAC addresses and routing rules to the computing power.

[0160] Optionally, the device further comprises:

[0161] A setting module is used to set the access rights of the computing power through at least one of a software defined network SDN controller, an access control list ACL, and a flow table;

[0162] A control module is used to control the network traffic of the computing power based on the access permission.

[0163] Optionally, the acquisition module is specifically configured to perform any of the following:

[0164] Acquire the first network boundary information input by a user;

[0165] In the case of a change in computing power, the second network boundary information is adjusted based on the changed computing power to obtain the first network boundary information.

[0166] Optionally, the network configured for the computing power of the intelligent computing center cloud platform includes an in-band management network and an out-of-band control network that are isolated from each other; the device further includes:

[0167] A transmission module is used to transmit services based on the in-band management network and to transmit control instructions based on the out-of-band control network.

[0168] The computing power network isolation device for the intelligent computing center cloud platform provided by the present invention is capable of realizing the various processes of each embodiment of the computing power network isolation method for the above-mentioned intelligent computing center cloud platform. The technical features correspond one to one and can achieve the same technical effects. To avoid repetition, they will not be described here.

[0169] It should be noted that the computing power network isolation device of the intelligent computing center cloud platform in the present invention can be a device, or it can be a component, integrated circuit, or chip in an electronic device.

[0170] Please refer to Figure 5 The present invention also provides a server 110, including a processor 111, a memory 112, and a computer program stored in the memory 112 and executable on the processor 111. When the computer program is executed by the processor 111, the various processes of the embodiment of the computing power network isolation method of the above-mentioned intelligent computing center cloud platform are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0171] The present invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the various processes of the embodiment of the computing power network isolation method of the intelligent computing center cloud platform, and can achieve the same technical effect. To avoid repetition, it is not described here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0172] The present application also provides a computer program product, including computer instructions, which, when executed by a processor, implement the above Figure 1 The various processes of the embodiment of the computing power network isolation method of the intelligent computing center cloud platform shown can achieve the same technical effect. To avoid repetition, they will not be repeated here.

[0173] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0174] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0175] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the present invention and the claims, all of which are protected by the present invention.

Claims

1. A computing power network isolation method for an intelligent computing center cloud platform, characterized in that: include: Step S1: Obtain first network boundary information; Step S2: Based on the first network boundary information, configure a network for the computing power of the intelligent computing center cloud platform, where the network includes at least one of a physical network and a virtual network; Step S3: Based on the first network boundary information, the network is divided into at least two network isolation spaces according to the network isolation object, wherein the network isolation object includes at least one of a tenant, a project, a task, a service, a container, and a virtual server, and each of the at least two network isolation spaces is configured with a corresponding logical network.

2. The method according to claim 1, characterized in that The step S1 comprises: Step S11: obtaining first network boundary information, and creating at least two network isolation spaces based on the first network boundary information, wherein the first network boundary information includes network boundary information with at least one of a tenant, a project, a task, a service, a container, and a virtual server as a network isolation object; The step S3 comprises: Step S31: Based on the at least two network isolation spaces corresponding to the first network boundary information, logical network configuration is performed on the computing power, and each network isolation space in the at least two network isolation spaces corresponds to each network isolation object.

3. The method according to claim 1, characterized in that The step S2 comprises: Step S21: Based on the first network boundary information, configure at least one of a physical network card and a virtual network card for the computing power of the intelligent computing center cloud platform; Step S22: Allocate an Internet Protocol IP address, a Media Access Control MAC address and routing rules to the computing power.

4. The method according to claim 1, wherein The method further comprises: Step S4: Setting access rights to the computing power through at least one of a software defined network (SDN) controller, an access control list (ACL), and a flow table; Step S5: Control the network traffic of the computing power based on the access permission.

5. The method according to any one of claims 1 to 4, characterized in that The step S1 includes any one of the following: Step S12: Acquire the first network boundary information input by the user; Step S13: When the computing power changes, the second network boundary information is adjusted based on the changed computing power to obtain the first network boundary information.

6. The method according to claim 1, characterized in that The network configured for the computing power of the intelligent computing center cloud platform includes an in-band management network and an out-of-band control network that are isolated from each other; the method further includes: Step S6: performing service transmission based on the in-band management network, and performing control instruction transmission based on the out-of-band control network.

7. A computing power network isolation device for an intelligent computing center cloud platform, characterized in that: include: An acquisition module, configured to acquire first network boundary information; a configuration module, configured to configure a network for computing power of the intelligent computing center cloud platform based on the first network boundary information, wherein the network includes at least one of a physical network and a virtual network; A separation module is used to separate the network into at least two network isolation spaces according to the network isolation object based on the first network boundary information, wherein the network isolation object includes at least one of a tenant, a project, a task, a service, a container, and a virtual server, and each of the at least two network isolation spaces is configured with a corresponding logical network.

8. A server, characterized in that: include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, the steps of the computing power network isolation method of the intelligent computing center cloud platform as described in any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the computing power network isolation method of the intelligent computing center cloud platform as described in any one of claims 1 to 6.

10. A computer program product, characterized in that It includes computer instructions, which, when executed by a processor, implement the steps of the computing power network isolation method of the intelligent computing center cloud platform as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • SDN-based virtual network isolation method and SDN controller

    CN108512811A

  • Method for realizing Overlay multi-tenant CNI container network based on Open vSwitch

    CN111049796A

  • Computing power task network isolation method of intelligent computing center and related equipment

    CN119210807A

Cited By

  • Parameter plane network configuration method, device, equipment, medium and product

    CN120880912A