Multi-virtual machine isolation operation system based on security level automatic scheduling

By constructing a security-aware scheduling system, the problems of insufficient security isolation, inefficient manual scheduling, and weak cross-domain data management in the virtual machine management system have been solved, achieving efficient and secure virtual machine resource management and data exchange control.

CN120930132APending Publication Date: 2025-11-11XIAN LEIFENG ELECTRONIC TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511072589.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing virtual machine management systems suffer from insufficient security isolation, inefficient manual scheduling, poor dynamic adaptability, and weak cross-domain data management.

Method used

A security-aware scheduling system was constructed, including an intelligent security level assessment mechanism, a security-layered virtual machine resource pool, a two-stage scheduling decision algorithm, and fine-grained cross-level data management and control, which realizes automated management and fine-grained data exchange control based on security levels.

Benefits of technology

It reduces the risk of cross-level attacks, improves scheduling efficiency, optimizes resource utilization, and enhances system resilience, ensuring efficient and secure virtual machine resource management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120930132A_ABST
    Figure CN120930132A_ABST
Patent Text Reader

Abstract

The invention provides a multi-virtual machine isolation operation system based on security level automatic scheduling, and relates to the technical field of cloud computing and virtualization. According to the system, an intelligent security level evaluation module is combined with multi-dimensional analysis to generate a task security level, a security-layered virtual machine resource pool realizes hierarchical cluster management and elastic scaling, an intelligent scheduling engine realizes task allocation based on security level matching and resource optimization, and a cross-level data exchange control module realizes fine-grained data management and control. The system solves the problems that an existing virtual machine management system is insufficient in security isolation, low in manual scheduling efficiency, poor in dynamic adaptability and weak in cross-domain data management and control, deep binding of the security level and resource allocation is achieved, and the resource utilization rate and the system robustness are improved. Performing subject term cloud computing; a virtualization technology; a security level; isolating the virtual machine; and automatic scheduling.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of cloud computing and virtualization technology, and specifically to a system and method that can automatically assign software or tasks to virtual machines of corresponding security levels. Background Technology

[0002] Existing virtual machine management systems have the following problems:

[0003] 1. Insufficient security isolation: Applications with different security requirements are deployed in a mixed manner, lacking an automatic isolation mechanism based on security levels;

[0004] 2. Inefficient manual scheduling: It relies on administrators to manually assess and allocate security levels, which is prone to errors and difficult to handle large-scale clusters;

[0005] 3. Poor dynamic adaptability: Unable to detect changes in application security status in real time and adjust deployment strategies accordingly;

[0006] 4. Weak cross-domain data management: There is a lack of fine-grained control over data interaction between virtual machines with different security levels. Summary of the Invention

[0007] The core innovation of this invention lies in the construction of a complete security-aware scheduling system, which mainly includes:

[0008] 1. Intelligent security level assessment mechanism

[0009] Multi-dimensional assessment model: Combining static code analysis, external threat intelligence correlation, and runtime behavior monitoring to generate a comprehensive security score;

[0010] Dynamic adjustment capability: Based on real-time threat intelligence and behavioral analysis, dynamically update the security level of the mission;

[0011] Standardized scoring: Mapping security indicators from different sources to a standardized security level system.

[0012] 2. Security-layered virtual machine resource pools

[0013] Tiered cluster architecture: The resource pools are divided according to security levels, and each sub-pool is configured with a dedicated security policy;

[0014] Elastic scaling mechanism: Supports dynamically adjusting the number of virtual machines at each level based on load and security requirements;

[0015] Security Status Monitoring: Monitors the security compliance of virtual machines in real time to ensure that they always meet the preset level requirements.

[0016] 3. Two-phase scheduling decision algorithm

[0017] Security filtering phase: Based on the principle of security level matching, candidate virtual machines that meet the security requirements of the task are selected;

[0018] Resource optimization phase: From the security compliance candidate set, resource utilization and load balancing algorithms are used to select the optimal deployment node;

[0019] Elastic creation strategy: When no existing virtual machine meets the requirements, a new instance matching the security level is automatically created.

[0020] 4. Fine-grained cross-level data management

[0021] One-way flow principle: Strictly restrict data to flow only from low security level to high security level;

[0022] Data processing pipeline: Includes security enhancement processes such as encryption, de-identification, and integrity verification;

[0023] Audit trail system: Fully records detailed information on all cross-level data exchanges.

[0024] Beneficial effects

[0025] 1. Enhanced security isolation: Resource pools are divided according to security level, and network segmentation and hardware isolation are combined to reduce the risk of cross-level attacks by more than 92%, and the unidirectional flow control of data meets the requirements of information security protection.

[0026] 2. Improve scheduling efficiency: Intelligent assessment replaces manual operation, reducing the deployment time of large-scale cluster tasks from hours to minutes, and elastic creation responds to insufficient resources within 15 seconds.

[0027] 3. Optimize resource utilization: Dynamic scaling improves resource utilization by 35%, hybrid cloud expansion reduces hardware costs by 40%, and real-time monitoring maintains system compliance of over 99.5%.

[0028] 4. Enhanced system resilience: Sub-resource pools are independently fault-tolerant, and hot migration ensures service interruption of less than 100ms when security level changes, and is compatible with multiple hardware architectures and virtualization platforms. Detailed Implementation

[0029] 1. System Overall Architecture

[0030] The system of this invention consists of four core modules:

[0031] Security Level Assessment Module: Determines the security level of software or tasks through multi-dimensional analysis;

[0032] Virtual machine resource pool management module: Maintains virtual machine clusters with different security levels and supports dynamic resource allocation;

[0033] Intelligent scheduling engine: Assigns tasks based on security level matching and resource optimization principles;

[0034] Cross-security level data exchange control module: manages data interaction between virtual machines with different security levels.

[0035] The overall system architecture described above can be found in the attached diagram of the instruction manual. Figure 1 .

[0036] 2. Implementation of the security level assessment module

[0037] This module assesses the security level of a task through the following steps:

[0038] Static code analysis: Checking for known vulnerabilities in dependent components, analyzing code permission request levels and scope, and assessing code quality and compliance with security coding standards;

[0039] Threat intelligence correlation: query external threat intelligence systems to obtain component vulnerability information, check mission-related attack activity reports, and assess the credibility of mission sources;

[0040] Runtime behavior analysis (for running tasks): Monitor network connection patterns to identify abnormal communication, analyze resource usage patterns to detect abnormal resource consumption, and monitor system call behavior to identify permission overreach attempts;

[0041] Comprehensive score calculation: The scores from the above three aspects are combined according to preset weights to generate the final security level. The weight coefficients can be dynamically adjusted according to the system security policy.

[0042] The above safety level assessment process can be found in the accompanying diagram of the instruction manual. Figure 2 .

[0043] 3. Implementation of Virtual Machine Resource Pool Management Module

[0044] Hierarchical cluster architecture design: Physical resources are divided into N security level sub-resource pools, each sub-resource pool corresponds to a specific security policy, and isolation is achieved through virtual network segmentation, hardware partitioning or enhanced virtualization isolation technology;

[0045] Elastic scaling mechanism: Automatic scaling up and down is triggered based on load thresholds (such as CPU / memory utilization) and security events; virtual machines are quickly created based on templated images; hybrid cloud expansion is supported.

[0046] Security status monitoring and compliance management: Real-time monitoring of security configuration, operational status, performance indicators and compliance audits, and automatic response to configuration deviations or violations;

[0047] Resource scheduling collaboration interface: It works in conjunction with the intelligent scheduling engine and security level assessment module to provide a list of available resources and perform resource creation / release and security level migration operations;

[0048] Management console features: Provides a visual interface for configuring resource quotas, threshold parameters, and custom policies, and supports historical data queries.

[0049] 4. Implementation of the intelligent scheduling engine

[0050] Get Task Security Level: Call the security level assessment module to obtain the security level value of the task to be scheduled;

[0051] Filter candidate virtual machines: Filter virtual machines from the resource pool that meet the requirements of virtual machine security level being greater than or equal to task security level and resource utilization being lower than a preset threshold;

[0052] Select the optimal deployment node: Apply resource optimization algorithms (considering resource utilization, load balancing, task affinity, etc.) to select the optimal node;

[0053] Elastic resource expansion: When there are no candidate virtual machines available, dynamically create new virtual machines that meet the security level requirements.

[0054] The above intelligent scheduling algorithm can be found in the accompanying diagram of the instruction manual. Figure 3 .

[0055] 5. Cross-level data exchange control implementation

[0056] Security level verification: Check whether the data exchange request conforms to the flow rule of "low security level to high security level", and reject it if it violates the rule;

[0057] Data processing pipeline: performs encryption, desensitization, and integrity verification on data;

[0058] Audit logs record information such as the source and target virtual machine identifiers, data digests, operation timestamps, and processing result status of data exchanges.

[0059] Data transfer execution: The processed data is transferred to the target virtual machine through a secure channel.

[0060] The above-mentioned cross-level data exchange control can be referred to the attached diagram in the instruction manual. Figure 4 .

[0061] Example Description

[0062] In a financial industry implementation scenario, the system of this invention is deployed on a bank's cloud computing platform:

[0063] The core transaction system runs in a high-security cluster, configured with network isolation, intrusion detection, and advanced encryption.

[0064] Medium-security cluster processing manages customer information, implementing data masking and access control;

[0065] Low-security clusters run public information display applications.

[0066] When a new business task is submitted, the system automatically assesses its security level and schedules it to a matching cluster. For example, a transfer transaction involving sensitive customer information is assessed as a high-security task and automatically scheduled to run on a virtual machine with the highest security level to ensure business security. Simultaneously, the system continuously monitors task behavior; if abnormal activity is detected, its security level can be dynamically adjusted and the task migrated to a more secure environment.

Claims

1. A multi-virtual machine isolation operation system based on automatic scheduling of security levels, characterized in that, include: o Intelligent security level assessment module: It is used to combine static code analysis, external threat intelligence correlation and runtime behavior monitoring to generate a comprehensive security score for the task, and dynamically update the security level of the task based on real-time threat intelligence and behavior analysis, and uniformly map security indicators from different sources to a standardized security level system. o Security-layered virtual machine resource pool management module: Divides the virtual machine into sub-resource pools according to security level, each sub-pool is configured with a dedicated security policy, supports dynamic adjustment of the number of virtual machines at each level according to load and security requirements, and monitors the security compliance of virtual machines in real time; o Intelligent scheduling engine module: Based on the security level matching principle, it filters candidate virtual machines that meet the task security requirements, applies resource utilization and load balancing algorithms to select the optimal deployment node in the security compliance candidate set, and automatically creates a new instance that matches the security level when there are no existing virtual machines that meet the conditions. o Cross-security level data exchange control module: manages data interaction between virtual machines of different security levels, restricts data to flow only from low security level to high security level, performs data encryption, desensitization, integrity verification and other processing on data, and fully records detailed information of all cross-security level data exchanges.

2. The system according to claim 1, characterized in that, The static code analysis of the intelligent security level assessment module includes checking whether there are known vulnerabilities in dependent components, analyzing the code permission request level and scope, and evaluating the code quality and compliance with security coding standards.

3. The system according to claim 1, characterized in that, The isolation mechanism of the security-layered virtual machine resource pool management module includes network layer isolation through virtual network segmentation, and improved isolation at the physical resource level through hardware partitioning or enhanced virtualization isolation technology.

4. The system according to claim 1, characterized in that, The intelligent scheduling engine module filters candidate virtual machines based on the following criteria: the virtual machine's security level is greater than or equal to the task's security level, and the virtual machine's current resource utilization rate is lower than a preset threshold.

5. The system according to claim 1, characterized in that, The data processing pipeline of the cross-level data exchange control module includes encryption processing, desensitization filtering, and integrity verification.

Citation Information

Cited By

  • AI safe operation situation scheduling method and system for LNG receiving station

    CN122414739A