Resource exclusion and security isolation guarantee method for elastic bare metal server

By constructing a distributed coupled and associated mapping chain through elastically coupled blockchain and smart contracts, and combining the PoS+QoS consensus algorithm and the three-layer dynamic protection algorithm, the shortcomings of bare metal server resource dynamic scheduling and security protection are solved, realizing hardware-level exclusive access and real-time response, and improving resource utilization and security.

CN121037089AActive Publication Date: 2025-11-28NEWLIXON TECH CO LTD

Patent Information

Application Number
CN202511298328.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-11
Publication Date
2025-11-28
Estimated Expiration
2045-09-11

AI Technical Summary

Technical Problem

Existing bare metal servers have shortcomings in dynamic resource scheduling, fine-grained security protection, and intelligent operation and maintenance. They cannot improve resource utilization and are difficult to deal with new types of network attacks. Hardware-level isolation lacks flexibility and fine-grained control.

Method used

By pre-setting a flexible coupled blockchain and smart contracts, and combining the PoS+QoS consensus algorithm, a distributed coupled and associated mapping chain is constructed to monitor and adjust resource configuration in real time. A three-layer dynamic protection algorithm is used to realize hardware fingerprint verification, VLAN binding and storage hash synchronization to form a closed-loop protection. Combined with predictive analysis models and the principle of shortest latency, overload response is performed.

Benefits of technology

It achieves hardware-level exclusivity and real-time response for bare metal servers, breaking through the limitations of static resource configuration, compressing the response time to milliseconds when the load exceeds the limit, ensuring improved resource utilization and security, and blocking side-channel attack paths.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037089A_ABST
    Figure CN121037089A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of server security, and particularly relates to an elastic bare metal server resource exclusion and security isolation guarantee method and system.The method comprises the steps that an elastic coupling block chain is preset, an intelligent contract on the chain is utilized, resources are allocated from a server group according to user requirements in combination with a PoS + QoS consensus algorithm, and a distributed coupling association mapping chain is constructed; each block chain node configures a unique identity fingerprint and a configuration parameter of a resource according to a demand, deploys and starts the service chain, then applies a preset three-layer dynamic protection algorithm, monitors internal and external running states in real time according to a demand completion progress, and feeds back a judgment result to the resource configuration adjustment model and the combined security adjustment strategy library; performing exception repair and resource uplink and downlink adjustment on the service chain; according to the method, resource configuration-release traceability is guaranteed through the non-tampering property of the block chain, and safe closed loop, exclusive use and isolation of fingerprint anchoring-on-chain configuration-dynamic protection are realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the field of server security, and particularly relates to a method and system for guaranteeing resource sharing and security isolation of elastic bare metal servers. BACKGROUND

[0002] Bare metal servers have the advantages of physical resource sharing, high performance and strong isolation. Although traditional bare metal servers achieve a certain degree of security guarantee through physical isolation technology and basic network protection, they still have significant defects in terms of resource dynamic scheduling, security protection granularity and intelligent operation and maintenance. In the prior art, resource configuration relies on static strategies, which cannot be adjusted in real time according to business load, resulting in low resource utilization. The security protection mechanism is loosely coupled and lacks integration of advanced technologies such as zero-trust architecture and homomorphic encryption, making it difficult to respond to new network attacks. In addition, hardware-level isolation relies on fixed configurations and lacks flexible control over programmable hardware such as FPGA, making it difficult to achieve fine-grained resource dynamic division. Although some solutions attempt to introduce automated scripts or basic monitoring tools, their anomaly detection is still based on threshold alarms, which cannot predict potential faults through machine learning models, and the emergency response process relies on manual intervention, resulting in risks to business continuity.

[0003] A full-stack high-performance computing bare metal management service system and method are disclosed in Chinese Patent No. CN115442316B, which includes a user end electrically connected to the bare metal management service system through an input port, the bare metal management service system is communicatively connected to a network service system, and the network service system is communicatively connected to a cloud server. The method of the full-stack high-performance computing bare metal management service system includes: connecting the bare metal management service system; communicatively connecting the bare metal management service system to the cloud server; deploying the bare metal management service system through DHCP service and FTP service; providing a subnet on the bare metal management service system; processing data by the cloud server; and protecting system security by security isolation and firewall. SUMMARY

[0004] In view of the deficiencies of the prior art, the present application provides an elastic bare metal server resource exclusive and secure isolation protection method and system, which uses a preset elastic coupling blockchain, uses a smart contract on the chain, allocates resources from a server group according to user demand and in combination with a PoS+QoS consensus algorithm, constructs a distributed coupling correlation mapping chain, each blockchain node configures a unique identity fingerprint and configuration parameters of the demand configured resource, after deploying and starting the service chain, uses a preset three-layer dynamic protection algorithm, monitors the internal and external running state in real time according to the demand completion progress, feeds back the judgment result to the resource configuration adjustment model, jointly adjusts the security strategy library, and performs abnormal repair and resource uplink / downlink adjustment on the service chain; the present application realizes the security closed loop and exclusive and isolation of "fingerprint anchoring-chain configuration-dynamic protection" through the non-tamperable nature of the blockchain to ensure the traceability of resource configuration-release.

[0005] To achieve the above object, the present application provides the following technical scheme:

[0006] The elastic bare metal server resource exclusive and secure isolation protection method comprises:

[0007] A preset elastic coupling blockchain is used to configure resources according to user demand based on the smart contract configured on the elastic coupling blockchain, and a distributed coupling correlation mapping chain is obtained in combination with a preset resource configuration adjustment model, a PoS+QoS consensus algorithm and a server group.

[0008] The distributed coupling correlation mapping chain is constructed by each blockchain node on the elastic coupling blockchain in combination with the unique identity fingerprint and configuration parameters of the demand configured resource.

[0009] The distributed coupling correlation mapping chain is deployed and started, and a three-layer dynamic protection algorithm and a demand completion progress are used to detect and judge the internal and external running state of the distributed coupling correlation mapping chain in real time, and the judgment result is fed back to the resource configuration adjustment model in combination with a preset security adjustment strategy library to perform real-time abnormal repair and resource uplink / downlink adjustment on the distributed coupling correlation mapping chain.

[0010] Specifically, the distributed coupling correlation mapping chain is configured with a resource exchange pool; the resource exchange pool is configured with a resource interaction verification network.

[0011] The resource exchange pool is used for storing the configuration, performance, identity fingerprint, historical configuration running state and function of the server group, and the resource interaction verification network is used for real-time resource uplink / downlink verification interaction with the distributed coupling correlation mapping chain through the parameter-resource one-to-one correlation mapping configured.

[0012] The construction steps of the resource interaction verification network comprise:

[0013] The monitoring obtains the configuration, performance, identity fingerprint, historical configuration running state and function and current idle running state data of all server groups at the current time, and constructs a comprehensive state sequence set of real-time idle elastic bare metal servers;

[0014] Based on the performance, historical configuration running state and current idle running state data in the comprehensive state sequence set, the health state score corresponding to each idle elastic bare metal server is obtained through an evaluation algorithm, and the business running risk value after the corresponding configuration resource is chained is obtained in combination with the Bayesian probability model built in the evaluation algorithm.

[0015] Specifically, the construction steps of the resource interaction verification network further include:

[0016] The function attribute, identity fingerprint, health state score and configuration state corresponding to the server group are stored in each parameter node in the metadata subnet in the resource interaction verification network, and the corresponding verification key-public key pair is generated based on the identity fingerprint and location information of each parameter node;

[0017] Based on the server group, a physical resource subnet is constructed, and the public key of the corresponding server in each parameter node is associated and mapped to the physical resource node corresponding to the physical resource subnet, establishing a parameter-resource one-to-one association mapping; each physical resource node represents a server;

[0018] Based on the parameter-resource one-to-one association mapping, the metadata subnet and the physical resource subnet, the resource interaction verification network is obtained through a topological space algorithm, and the initial state of the corresponding server in each parameter node is set to idle.

[0019] Specifically, the construction process of the distributed coupling association mapping chain includes:

[0020] The user resource demand sequence is obtained, triggering the demand analysis model in the smart contract in the elastic coupling block chain to obtain the user resource demand space;

[0021] Based on the user resource demand space and the resource interaction verification network, the server resources and the number of servers meeting the user demand are obtained through a matching algorithm combined with a PoS+QoS consensus algorithm, and the initial state of the corresponding parameter node of the server obtained from the resource exchange pool is converted to the current occupied state, and the occupied state time stamp interval is marked;

[0022] Based on the number of servers, the distributed coupling association mapping chain is constructed based on the block chain and the smart contract.

[0023] Specifically, the distributed coupling association mapping chain includes an isolation block subchain and a business processing subchain.

[0024] The isolation block subchain includes M isolation block subnodes and one extended isolation block subnode; and the business processing subchain includes M business processing subnodes;

[0025] The isolation block subnode is used for saving a hash table of a key-public key, an identity fingerprint, a running result of a corresponding business processing subnode, and verification and uplink and downlink adjustment of a secure isolation interaction strategy; the business processing subchain is used for performing load adjustment and user demand business operation based on real-time load data, and each business processing subnode in the business processing subchain is allowed to interact only with the business processing subnodes in the chain.

[0026] Specifically, the construction process of the distributed coupling association mapping chain further includes:

[0027] The identity fingerprint, the parameter-resource one-to-one association mapping, the key-public key pair, and the marked occupation state time stamp interval of each server corresponding parameter node in the server resource meeting the user demand are associated and mapped from the corresponding parameter node in the metadata subnetwork to the corresponding isolation block subnode in the isolation block subchain through the smart contract, and the three-layer dynamic protection algorithm is configured on the corresponding interface of each isolation block subnode after the resource is chained;

[0028] Meanwhile, the business processing subchain is constructed based on the selected server corresponding physical resource node in the physical resource subnetwork, and a dedicated virtual local area network identifier, VLAN identifier, is configured, and the business processing subnodes in the business processing subchain are one-to-one associated and mapped with the corresponding isolation block subnodes by using the parameter-resource one-to-one association mapping;

[0029] The public key stored in the corresponding isolation block subnode of the isolation block subchain is associated and mapped to the corresponding business processing subnode, and the virtual local area network identifier, VLAN identifier, configured in the business processing subchain and the storage hash of each business processing subnode are associated and mapped to the corresponding isolation block subnode.

[0030] Specifically, the construction process of the distributed coupling association mapping chain further includes:

[0031] A load running upper limit threshold is set in each node in the business processing subchain, an extended association mapping between each business processing subnode and the extended isolation block subnode is established based on the set load running upper limit threshold, and the extended association mapping is built into the uplink extension contract between the isolation block subchain and the prepared resource subpool configured in the resource exchange pool;

[0032] When the predicted load obtained by each business processing subnode configured with a prediction analysis model in combination with real-time running load data is greater than the set load running upper limit threshold corresponding to a probability greater than a preset load overrun probability threshold in the next moment, the uplink extension contract is triggered;

[0033] According to the information stored by the over-limit corresponding business processing sub-node and the isolation block sub-node, combined with the information saved by the idle parameter node corresponding to the current state of the resource exchange pool and the distance between the physical resource node corresponding to each parameter node and the current predicted over-limit business processing sub-node, the matching algorithm is matched and selected by combining the delay shortest principle, and the matched parameter node is stored in the preliminary resource sub-pool;

[0034] At the same time, the public key corresponding to the predicted over-limit corresponding business processing sub-node is associated and mapped into the corresponding parameter node matched from the preliminary resource sub-pool, and the extension chain association mapping is carried out.

[0035] Specifically, the steps of real-time exception repair and resource uplink and downlink adjustment of the distributed coupling association mapping chain include:

[0036] The running state information of the distributed coupling association mapping chain corresponding to the chain and the chain is monitored in real time, and the real-time exception discrimination is carried out through the configured exception discrimination model. When it is found through monitoring discrimination that there is at least one business processing sub-node load exception, the uplink expansion contract is triggered, the physical resource node quantity of the load exception business processing sub-node is obtained according to the predicted migration load quantity corresponding to the load exception and the maximum load quantity of the physical resource node corresponding to the preliminary resource sub-pool;

[0037] According to the physical resource node quantity of the load exception business processing sub-node, the corresponding number of isolation block sub-nodes and business processing sub-nodes are expanded in the distributed coupling association mapping chain through the uplink expansion contract, and the public key-private key saved in the public key corresponding to the parameter node in the preliminary resource sub-pool and the load exception business processing sub-node are associated and mapped, and the uplink verification is carried out through the intelligent contract combined with the resource configuration adjustment model. When the verification is passed, the corresponding uplink parameter node and physical resource node are associated and mapped to the corresponding isolation block sub-node and business processing sub-node;

[0038] When the association mapping is completed, the new isolation block sub-node is verified through the three-layer dynamic protection algorithm configured by the load exception business processing sub-node corresponding to the isolation block sub-node, and when the verification is passed, the abnormal load is migrated to the new business processing sub-node verified, and the corresponding result hash is synchronized to the corresponding isolation block sub-node, and the demand business operation is carried out;

[0039] When the parameter node corresponding to the current physical resource node is not verified, the current physical resource node and the corresponding parameter node are directly refused to be uplinked, and the remaining parameter nodes and physical resource nodes in the preliminary resource sub-pool are continuously verified until the load exception business processing sub-node load migration demand is met.

[0040] Specifically, the step of performing real-time exception repair and resource uplink / downlink adjustment on the distributed coupling correlation mapping chain further comprises:

[0041] When at least one node in the distributed coupling correlation mapping chain receives a cross-chain resource request, the corresponding request is directly rejected and added to a blacklist. When the distributed coupling correlation mapping chain completes the operation of the corresponding business processing subnode, the corresponding business processing subnode is directly downlinked, the business information stored in the business processing subnode and the uplink correlation mapping parameter information corresponding to the corresponding isolated block subnode are cleared, and the operation result is saved in the corresponding isolated block subnode;

[0042] When the corresponding cross-chain resource request still exists after the operation is completed, the parameter information saved in the downlinked physical resource node and the corresponding parameter node is associated and mapped to the distributed coupling correlation mapping chain corresponding to the cross-chain resource request according to the cross-chain resource request;

[0043] When the business operation risk value of at least one node in the distributed coupling correlation mapping chain is greater than a preset abnormal probability threshold, the uplink process of the repeatedly loaded abnormal physical resource node is repeated, a new physical resource node is obtained from a prepared resource subpool, and three-layer verification of uplink verification and resource interaction is performed. When all verifications are passed, the corresponding abnormal isolated block subnode and business processing subnode information are migrated to a new uplink isolated block subnode and business processing subnode to continue operation until the operation is completed, the business processing subchain in the distributed coupling correlation mapping chain is directly dissolved, and all business and configuration information is cleared. At the same time, the uplink correlation mapping information corresponding to the business processing subnode in the business processing subchain is all cleared, and only the operation result is retained in the isolated block subchain.

[0044] The elastic bare metal server resource exclusive and secure isolation guarantee system comprises a coupling service chain module, an isolation verification module, and a repair module.

[0045] The coupling service chain module obtains a distributed coupling correlation mapping chain based on a configured smart contract on an elastic coupling blockchain, responds to user demand configuration information, and combines a preset resource configuration adjustment model and a PoS+QoS consensus algorithm.

[0046] The distributed coupling correlation mapping chain is constructed by each block node on the elastic coupling blockchain in combination with corresponding configured demand resources and corresponding unique identity fingerprints.

[0047] The isolation verification module is used to deploy and start the distributed coupling correlation mapping chain, and simultaneously performs real-time detection and discrimination on the internal and external operation states of the distributed coupling correlation mapping chain through a preset three-dimensional dynamic protection algorithm and demand completion progress to obtain a discrimination result.

[0048] The repair module is used for feeding back the discrimination result to the resource configuration adjustment model and combining the preset security adjustment strategy library to perform real-time exception repair and resource uplink / downlink adjustment on the distributed coupling correlation mapping chain.

[0049] Compared with the prior art, the present application has the following advantages:

[0050] The present application is aimed at the deficiencies of the prior art, and realizes real-time correlation mapping of the hardware fingerprint-configuration parameter-load state of the bare metal server by the smart contract of the elastic coupling blockchain and the PoS+QoS consensus, breaks through the limitation of static resource configuration; the resource interaction verification network integrates three layers of dynamic protection algorithms, completes the full-link verification of hardware fingerprint verification-VLAN binding-storage hash synchronization on the chain, and blocks the side channel attack path; the prediction analysis model combines the extended correlation mapping of the shortest delay principle, compresses the load overrun response from the minute level to the millisecond level, and ensures that the extended node is physically credible through the hardware fingerprint ZKP pre-verification, avoiding the on-chain of the sick node; the three-layer protection algorithm is injected into the isolated block sub-node interface in real time, and the health state score-exception probability-hardware state is checked in three dimensions during the resource uplink / downlink stage, forming a closed-loop protection of "prediction-verification-isolation", solving the problems of resource rigidity, isolation failure and expansion delay in the traditional scheme, and realizing the hardware-level exclusive use and real-time response of the elastic bare metal server. BRIEF DESCRIPTION OF DRAWINGS

[0051] Figure 1 Figure 1 is a logic diagram of the elastic bare metal server resource exclusive use and security isolation guarantee method of embodiment 1 of the present application;

[0052] Figure 2 Figure 1 is a logic diagram of the elastic bare metal server resource exclusive use and security isolation guarantee method of embodiment 1 of the present application;

[0053] Figure 3 Figure 2 is a system module diagram of the elastic bare metal server resource exclusive use and security isolation guarantee system of embodiment 2 of the present application. DETAILED DESCRIPTION

[0054] Embodiment 1:

[0055] Please refer to Figure 1 and Figure 2 An embodiment provided by the present application: an elastic bare metal server resource exclusive use and security isolation guarantee method, comprising the following steps:

[0056] S1, preset an elastic coupling blockchain, configure a smart contract on the elastic coupling blockchain, configure resources in response to user demand and combine a preset resource configuration adjustment model, a PoS+QoS consensus algorithm and a server group to obtain a distributed coupling correlation mapping chain;

[0057] The distributed coupling correlation mapping chain is constructed by each blockchain node of the elastic coupling blockchain in combination with the unique identity fingerprints and configuration parameters of the demand configuration resources.

[0058] It should be further explained that the construction and training process of the resource configuration adjustment model in the embodiment includes:

[0059] Based on the distributed monitoring agent cluster, the server group historical running data is collected, the historical running data covers CPU utilization curve, memory occupancy waveform, disk IO throughput sequence, network bandwidth usage time sequence, service response delay log and resource request rejection rate statistics, data collection is completed through the data collection mechanism, and the server group historical running original data set is obtained;

[0060] Based on the server group historical running original data set, the historical running original data is processed through data cleaning, wherein the data breakpoints in the historical running original data are repaired through a missing value filling algorithm, and the outlier data points in the historical running original data are removed through an abnormal value filtering mechanism, and a regular server group historical running data set is obtained;

[0061] Based on the regular server group historical running data set, a multi-dimensional feature extraction is performed on the regular server group historical running data set through a sliding time window mechanism, the extracted features include resource utilization mean, resource load variance, resource demand peak value, resource conflict frequency and service level agreement violation times, and a multi-dimensional initial feature vector is obtained;

[0062] Based on the multi-dimensional initial feature vector, the influence weight of each feature dimension in the multi-dimensional initial feature vector on the resource adjustment decision is calculated through a feature importance evaluation algorithm, and then a key feature subset is selected according to the influence weight through a recursive feature elimination method, and an optimized multi-dimensional feature vector is obtained;

[0063] Based on the regular server group historical running data set, the regular server group historical running data set is divided into a training data set, a validation data set and a test data set through a time series segmentation method, wherein the training data set accounts for seventy percent of the total amount of the regular server group historical running data set, the validation data set accounts for fifteen percent of the total amount of the regular server group historical running data set, and the test data set accounts for fifteen percent of the total amount of the regular server group historical running data set, and the divided training data set, validation data set and test data set are obtained;

[0064] The resource configuration adjustment model is constructed based on a deep reinforcement learning framework. The main body of the resource configuration adjustment model adopts an Actor-Critic network architecture, in which an Actor network is responsible for generating a resource adjustment strategy, and a Critic network is responsible for evaluating the value of the resource adjustment strategy. The model main body is constructed through a network architecture building mechanism to obtain an initial resource configuration adjustment model.

[0065] Based on the divided training data set and the optimized multi-dimensional feature vector, the initial resource configuration adjustment model is trained through a proximal policy optimization algorithm. The optimized multi-dimensional feature vector is used as the input of the initial resource configuration adjustment model. Through model training iteration, the initial resource configuration adjustment model outputs operation instructions of resource expansion, resource contraction, resource migration or maintaining the status quo. A trained resource configuration adjustment model is obtained.

[0066] Based on the trained resource configuration adjustment model, the pros and cons of the resource adjustment strategy output by the trained resource configuration adjustment model are evaluated through a reward function design mechanism. The calculation factors of the reward function in the reward function design mechanism include the resource utilization rate improvement amplitude, the service level agreement compliance degree, the resource adjustment cost coefficient and the system stability index. A resource adjustment strategy reward function for model training evaluation is obtained.

[0067] Based on the trained resource configuration adjustment model and the resource adjustment strategy reward function for model training evaluation, the training process of the trained resource configuration adjustment model is accelerated through a distributed parallel training framework. The model parameter consistency of each training node is ensured through a gradient synchronization algorithm. The training convergence speed of the trained resource configuration adjustment model is optimized through an adaptive learning rate adjustment strategy. An accelerated training resource configuration adjustment model is obtained.

[0068] Based on the accelerated training resource configuration adjustment model and the divided verification data set, the overfitting of the accelerated training resource configuration adjustment model is prevented through an early stopping mechanism. When the reward value of the accelerated training resource configuration adjustment model on the verification data set no longer improves for a plurality of consecutive training periods, the model training process is automatically terminated. A preliminary trained resource configuration adjustment model is obtained.

[0069] Based on the preliminary trained resource configuration adjustment model and the divided test data set, the performance of the preliminary trained resource configuration adjustment model is evaluated through a test evaluation mechanism using the divided test data set. The evaluation indexes include the strategy accuracy, the decision delay time, the resource utilization rate improvement percentage and the service level agreement violation reduction rate. The resource configuration adjustment model with performance up to standard is selected.

[0070] The performance standard-based resource configuration adjustment model is converted into a lightweight inference engine through a model compression technique, the lightweight inference engine is deployed into an intelligent contract execution environment of the elastic coupling blockchain through a deployment mechanism, and a resource configuration adjustment inference engine deployable in an intelligent contract is obtained;

[0071] Based on the resource configuration adjustment inference engine deployable in the intelligent contract, an online model optimization system is constructed through an online learning mechanism, system running data is collected through a real-time data collection module, model parameters of the resource configuration adjustment inference engine are continuously optimized, historical decision records of the resource configuration adjustment inference engine are stored through an experience replay buffer, model parameter updating is started through a regular incremental training process, and a resource configuration adjustment inference engine with online optimization capability is obtained;

[0072] Based on the resource configuration adjustment inference engine with online optimization capability, the effectiveness and security of the resource adjustment strategy output by the resource configuration adjustment inference engine are ensured through a PoS+QoS consensus algorithm, the resource configuration adjustment inference engine with online optimization capability is integrated in the intelligent contract of the elastic coupling blockchain through an integration mechanism, and a resource configuration adjustment model integrable in the intelligent contract of the elastic coupling blockchain is obtained, which can automatically generate an optimal resource adjustment strategy according to real-time system states.

[0073] S2, deploy and start the distributed coupling correlation mapping chain, simultaneously detect and distinguish the running states inside and outside the distributed coupling correlation mapping chain through a preset three-layer dynamic protection algorithm and demand completion progress, feed back the distinguishing results to the resource configuration adjustment model, combine a preset security adjustment strategy library, and perform real-time exception repair and resource uplink / downlink adjustment on the distributed coupling correlation mapping chain.

[0074] It should be further explained that the construction process of the security adjustment strategy library in the embodiment includes:

[0075] Based on the historical security event data of the distributed coupling correlation mapping chain and the historical exception distinguishing results of the three-layer dynamic protection algorithm, security event records, exception repair action records, resource uplink / downlink adjustment records, and demand completion progress deviation data are obtained through a multi-source data collection interface, and an initial security adjustment strategy data set is obtained.

[0076] It should be further explained that the security event records include network layer intrusion events, node layer abnormal behaviors, and data layer leakage events.

[0077] Based on the initial security adjustment policy dataset, data preprocessing algorithms are used for cleaning and regularization. Redundant records are removed by a repeated data elimination algorithm, event types are classified by an abnormal event classification algorithm, and indicators such as repair time and business scope are converted to a unified dimension by a data standardization algorithm. A regularized security policy training dataset is obtained.

[0078] It should be further explained that the abnormal event classification algorithm classifies event types according to "network layer anomaly, node layer anomaly, data layer anomaly, resource load anomaly, demand progress deviation".

[0079] Based on the regularized security policy training dataset and domain expert knowledge, the core elements of the security adjustment policy are determined by a policy framework definition algorithm, including policy trigger conditions, policy execution actions, and policy execution priority rules. An initial security adjustment policy framework is obtained.

[0080] It should be further explained that domain expert knowledge includes security risk level classification standards and business priority rules. Policy trigger conditions include abnormal probability thresholds output by a three-layer dynamic protection algorithm and demand completion progress deviation thresholds. Policy execution actions include network connection blocking, node isolation, data encryption repair, resource expansion uplink, and redundant resource downlink. Policy execution priority rules include that data leakage events have higher priority than light load anomalies.

[0081] Based on the initial security adjustment policy framework and the regularized security policy training dataset, the association between abnormal types and adjustment actions is mined by an association rule mining algorithm, and the quantitative decision rules of trigger conditions are generated by a decision tree algorithm. An initial security adjustment rule set is obtained.

[0082] It should be further explained that the association rule mining algorithm uses the Apriori algorithm. The association between abnormal types and adjustment actions is exemplified as follows: when the network layer detects an anomaly through deep packet inspection, the flow table blocking operation and temporary isolation measures for abnormal nodes are executed; when the node trust value is lower than the set threshold, the node offline operation and resource migration measures are executed; in terms of trigger condition determination, if the abnormal probability output by the three-layer dynamic protection algorithm exceeds the preset abnormal probability value, the emergency repair strategy is triggered; if the demand completion progress deviation exceeds the preset deviation range and the resource load rate exceeds the high load limit, the resource emergency uplink strategy is triggered.

[0083] Based on the initial security adjustment rule set and the business impact evaluation indicators of the distributed coupling association mapping chain, the weights of each evaluation indicator are determined by the analytic hierarchy process, and the priority score of each security adjustment rule is calculated by the weighted scoring algorithm. The ordered security adjustment policy set is obtained by sorting from high to low according to the score.

[0084] It needs to be further explained that the business impact assessment index contains security risk level, business interruption loss, repair resource cost, and user demand satisfaction.

[0085] Based on the output instructions of the ordered security adjustment strategy set and the resource configuration adjustment model, the association relationship between the security adjustment strategy execution action and the resource configuration adjustment instruction is established through a strategy-model mapping algorithm, the resource adjustment parameters required for strategy execution are determined, and the associated resource configuration security adjustment strategy set is obtained;

[0086] It needs to be further explained that the output instructions of the resource configuration adjustment model include resource expansion instructions, resource contraction instructions, and resource migration instructions; the association relationship between the security adjustment strategy execution action and the resource configuration adjustment instruction, such as the association relationship between the node layer abnormal repair strategy and the associated resource migration instruction, and the association relationship between the resource load abnormal strategy and the associated resource expansion / contraction instruction; the resource adjustment parameters required for strategy execution, such as resource expansion quantity and migration node range.

[0087] Based on the associated resource configuration security adjustment strategy set and the real-time running data of the distributed coupling association mapping chain, new data is continuously integrated to update the strategy rules through an incremental learning algorithm, and invalid strategies are filtered out through a strategy effectiveness evaluation algorithm, to obtain a dynamically updated security adjustment strategy set;

[0088] It needs to be further explained that the real-time running data of the distributed coupling association mapping chain includes newly generated security events, real-time discrimination results of the three-layer dynamic protection algorithm, and real-time data of demand completion progress; an example of updating strategy rules through an incremental learning algorithm is to generate new blocking strategies for new network intrusion modes; the strategy effectiveness evaluation algorithm evaluates by calculating the abnormal repair success rate, business recovery time, and resource utilization rate change after strategy execution; invalid strategies refer to strategies with effectiveness lower than a preset effective threshold.

[0089] Based on the dynamically updated security adjustment strategy set and historical abnormal scenario simulation data, simulation testing is performed through a strategy verification algorithm, the strategy verification pass rate is calculated, and the parameters of strategies that do not pass the verification are modified to obtain a verified security adjustment strategy set;

[0090] It needs to be further explained that the historical abnormal scenario simulation data includes historical abnormal events such as network DDoS attacks and node key leaks; the simulation testing of the strategy verification algorithm verifies the accuracy of policy triggering, the rationality of execution action, and the linkage coordination with the resource configuration adjustment model by replaying historical abnormal events; the strategy verification pass rate is required to be ≥95%; the parameter modification of strategies that do not pass the verification includes adjusting the trigger threshold and optimizing the execution action.

[0091] Based on the security adjustment policy set passed through the verification and the business scene characteristics of the distributed coupling association mapping chain, the strategy parameter is adjusted through the strategy adaptation algorithm to adapt to different scene requirements, the adapted strategy is stored in the database through the strategy deployment algorithm Chain contract callable, establish strategy retrieval index, obtain the security adjustment policy library that can be linked with three-layer dynamic protection algorithm, resource configuration adjustment model;

[0092] It should be further pointed out that the business scene characteristics of the distributed coupling association mapping chain include financial transaction scene, ordinary data processing scene; The strategy adaptation algorithm adjusts the strategy parameter, such as reducing the trigger threshold of the data layer security strategy in the financial transaction scene to a%, and improving the priority by b%; The strategy retrieval index is established according to the type of abnormality and trigger condition.

[0093] Based on the linkable security adjustment policy library, the interaction interface between the three-layer dynamic protection algorithm and the resource configuration adjustment model is established through the strategy call adaptation algorithm, which ensures that the discrimination result output by the three-layer dynamic protection algorithm can match the trigger condition in the security adjustment policy library in real time, and the resource configuration adjustment model can directly call the associated adjustment action in the security adjustment policy library, so as to obtain the security adjustment policy library that can support real-time exception repair and resource uplink / downlink adjustment of the distributed coupling association mapping chain.

[0094] It should be further pointed out that the establishment of the interaction interface needs to realize the bidirectional data transmission and instruction call between the three-layer dynamic protection algorithm and the security adjustment policy library, and the resource configuration adjustment model and the security adjustment policy library, so as to ensure the real-time of the linkage response.

[0095] Further, an implementation process of the three-layer dynamic protection algorithm of the embodiment includes:

[0096] Based on the network layer security protection requirement of the distributed coupling correlation mapping chain, a network layer protection system is deployed through software defined network technology. The network flow table information of all nodes of the distributed coupling correlation mapping chain is obtained in real time by the SDN controller, and the network flow table dataset of the distributed coupling correlation mapping chain nodes is obtained. It needs to be further explained that the network flow table information in the embodiment is the core basis for the decision-making data forwarding behavior of the switch under the SDN architecture, and is also the key data for the SDN controller to master the network running state of each node of the distributed coupling correlation mapping chain. It mainly includes the matching rules of data traffic, such as source IP address, destination IP address, transport layer protocol type, source port number, destination port number, etc., and the processing actions corresponding to the matching rules, such as forwarding traffic to a specified port, discarding abnormal traffic, guiding traffic to a monitoring module for further checking, etc., and may also cover the effective priority of the flow table item, the life cycle length, the traffic statistical data (including but not limited to the number of data packets and the number of bytes) and the like. Through the SDN controller, the network flow table information from all nodes of the distributed coupling correlation mapping chain is collected, which can be integrated to form a dataset that fully reflects the network communication of each node, and provides basic data support for subsequent identification of network anomalies, judgment of security threats, execution of flow table blocking or abnormal node isolation and the like.

[0097] Based on the network flow table dataset of the distributed coupling correlation mapping chain nodes, the characteristics of the network data packet are analyzed through the deep packet inspection algorithm, and the abnormal access mode is identified through the feature matching algorithm, and the network abnormal access mode identification result is obtained.

[0098] Based on the normal network running data of the distributed coupling correlation mapping chain, the normal network behavior baseline is established through the hidden Markov model, and the abnormal probability of the real-time network session is calculated through the state transition probability calculation method, and the real-time network session abnormal probability value is obtained.

[0099] Based on the network abnormal access mode identification result and the real-time network session abnormal probability value, the access control basis is constructed by deploying the distributed firewall rule, and the access control strategy is automatically generated through the smart contract, and then the access control strategy is distributed to each node through the flow table distribution mechanism to block the abnormal network connection in real time, and the abnormal network connection blocking result is obtained.

[0100] Based on the communication data between the nodes of the distributed coupling correlation mapping chain, the communication state within the chain is monitored in real time through the network traffic visualization technology, and the network structure atlas is dynamically updated through the topology discovery algorithm, and the communication state within the chain is monitored in real time and the dynamic network structure atlas is obtained.

[0101] Based on the node layer security authentication requirements of the distributed coupling correlation mapping chain, a node identity authentication system is constructed through a public key infrastructure, and the node identity authenticity is verified through a digital certificate verification mechanism to obtain a node identity authenticity verification result;

[0102] Based on the node identity authenticity verification result, node access control is strengthened through a multi-factor authentication protocol, and dynamic verification credentials are generated through a time synchronization one-time password algorithm to obtain node access dynamic verification credentials;

[0103] Based on the node running data of the distributed coupling correlation mapping chain, a node trustworthiness evaluation foundation is constructed by deploying a trust evaluation model, and node running indicators are collected through a behavior monitoring algorithm. Then, the node trust value is calculated by combining the Bayesian inference algorithm to obtain the node trustworthiness evaluation result;

[0104] Based on the node trustworthiness evaluation result, an abnormal node disposal foundation is constructed by implementing a node isolation mechanism. When the node behavior is abnormal, the node isolation process is triggered through a consensus algorithm to obtain the abnormal node isolation result;

[0105] Based on the node key security requirements of the distributed coupling correlation mapping chain, the node key is stored and protected through a hardware security module, and the node startup program integrity is verified through a secure startup mechanism to ensure the trustworthiness of the node running environment. The node key security protection result and the node trusted running environment are obtained;

[0106] Based on the data layer encryption protection requirements of the distributed coupling correlation mapping chain, a data encryption foundation is constructed through a national cryptography algorithm system, and business data is encrypted through a symmetric encryption algorithm. Meanwhile, an asymmetric encryption algorithm is used to distribute encryption keys to obtain encrypted business data and key security distribution results;

[0107] Based on the encrypted business data, a data integrity protection foundation is constructed by deploying a data integrity verification mechanism, and a data digest is generated through a secure hash algorithm. Then, the data digest consistency is verified through digital signature technology to confirm the data integrity, and the data integrity verification result is obtained;

[0108] Based on the sensitive data in the distributed coupling correlation mapping chain, a sensitive data protection foundation is constructed by deploying a data leakage protection system, and sensitive data is detected through a content recognition algorithm. Meanwhile, private information is processed through data desensitization technology to obtain sensitive data detection results and desensitized private information;

[0109] Based on the data access behavior of the distributed coupling correlation mapping chain, data access logs are recorded through blockchain technology, and the audit record is trusted through the tamper-proof nature of blockchain to obtain trusted data audit tracking records;

[0110] Based on the data availability requirement of the distributed coupling correlation mapping chain, a data backup and recovery mechanism is deployed to build a data guarantee foundation, and a redundant coding algorithm is used to process the data redundantly to guarantee the data availability, so as to obtain the data backup result and the data recovery guarantee capability;

[0111] Based on the three-layer protection linkage requirement of the distributed coupling correlation mapping chain, the security information and event management system is used to integrate the security event data of the network layer, the node layer and the data layer, and then the correlation analysis algorithm is used to mine the correlation between the security events of each layer, so as to obtain the integrated security event correlation data set;

[0112] Based on the integrated security event correlation data set, a security event automatic disposal foundation is built through security orchestration automation and response technology, and then the security event is automatically disposed through a pre-defined security disposal script, so as to obtain the security event automatic disposal result;

[0113] Based on the security event automatic disposal result, a security management foundation is built through the deployment of a unified security management platform, and then the security situation is displayed through a visual interface, and the historical security data is analyzed through a machine learning algorithm to predict the security risk, so as to obtain the security situation visualization result and the security risk prediction result;

[0114] Based on the security risk prediction result, a security adjustment strategy library is established to store the protection rules, and then the protection strategy is dynamically adjusted according to the real-time security situation through a rule engine, and the protection rules are updated in combination with threat intelligence, so as to obtain the dynamically adjusted security protection strategy;

[0115] Based on the dynamically adjusted security protection strategy, real-time security data is collected through the implementation of a continuous security monitoring mechanism, and then the security event is notified to the management end through a real-time alarm mechanism, and the security threat is disposed through an emergency response process, so as to obtain the security event real-time alarm result and the security threat disposal result;

[0116] Based on the abnormal network connection blocking result, the abnormal node isolation result, the data integrity verification result, the security event automatic disposal result and the security threat disposal result, the protection coverage range and the linkage effect are confirmed through a protection system effectiveness verification mechanism, and a full-range dynamic protection system covering the network layer, the node layer and the data layer is obtained, which can detect and block various security threats in real time, and provides dynamic and active security protection capability for the distributed coupling correlation mapping chain.

[0117] Further, the distributed coupling correlation mapping chain in the embodiment is deployed and implemented based on the function and configuration information of the algorithm bird cloud platform.

[0118] Further, the distributed coupling correlation mapping chain in the embodiment is deployed and implemented based on the function and configuration information of the algorithm bird cloud platform.

[0119] The resource exchange pool is used for storage of configuration, performance, identity fingerprint, historical configuration running state and function of the server group, and the resource interaction verification network performs real-time resource uplink and downlink verification interaction through the configured parameter-resource one-to-one association mapping and the distributed coupling association mapping chain;

[0120] Further, the construction steps of the resource interaction verification network in the embodiment include:

[0121] Monitoring and obtaining configuration, performance, identity fingerprint, historical configuration running state and function of all server groups at the current time and current idle running state data, and constructing a comprehensive state sequence set of real-time idle elastic bare metal servers;

[0122] Further, in the embodiment, the monitoring data is collected from three aspects of hardware layer, service layer and space layer;

[0123] Specifically, the collected data of the hardware layer includes but is not limited to: server configuration, TPM fingerprint, CPU utilization collected by BMC, hard disk SMART, IPMI sensor temperature;

[0124] The collected data of the service layer includes but is not limited to: historical configuration record, current idle state;

[0125] The collected data of the space layer includes but is not limited to: geographic location, latitude and longitude of the out-of-band management IP obtained through the IPMI sensor, rack position read through the SNMP cabinet label;

[0126] Based on the performance, historical configuration running state and current idle running state data in the comprehensive state sequence set, a health state score corresponding to each idle elastic bare metal server is obtained through an evaluation algorithm, and a business running risk value after corresponding configuration resource uplink is obtained in combination with a Bayesian probability model built in the evaluation algorithm.

[0127] It needs to be further explained that the construction process of the Bayesian probability model built in the evaluation algorithm in the embodiment includes:

[0128] Based on historical business running data, server performance monitoring indicators, resource configuration parameter records, business load fluctuation data and fault event logs are obtained through a data collection interface to obtain an initial training data set;

[0129] Based on the initial training data set, the initial training data set is cleaned and converted through a data preprocessing process, wherein the data null value is processed through a missing value filling algorithm, the error record is removed through an abnormal value detection algorithm, and various indicators are converted to a unified dimension through a data standardization method to obtain a preprocessed training data set;

[0130] Based on the pre-processed training data set, key feature vectors are extracted through feature engineering methods, including calculating trend features and periodic features of performance indicators, extracting change pattern features of historical configuration states, quantifying duration features and resource idle rate features of idle running states, to obtain a key feature vector set;

[0131] Based on the key feature vector set and domain expert knowledge, the node variables and their dependencies of the Bayesian network are determined through network structure definition methods, where the parent nodes include performance indicator nodes, historical configuration nodes, and idle state nodes, and the child node is the business running risk level node, to obtain an initial Bayesian network structure;

[0132] Based on the initial Bayesian network structure and the pre-processed training data set, model parameter learning is performed through the expectation maximization algorithm, including E-step to calculate the posterior probability of hidden variables given the observed data, and Q-step to update the model parameter estimates, through an iterative optimization process to calculate the conditional probability distribution table of each node in the network, to obtain a parameterized Bayesian network model; It needs to be further explained that in this embodiment, in the process of learning the parameters of the Bayesian network model based on the expectation maximization algorithm, the core of the E-step (expectation step) is to calculate the posterior probability distribution of all hidden variables (i.e. variables not directly observed) given the observed data based on the current model parameter estimates, in order to quantify the possible states and their likelihoods of the hidden variables; The Q-step (maximization step) is to construct a target function about the model parameters based on the posterior probability of the hidden variables obtained by the E-step, which is usually the expectation of the log-likelihood function, i.e. the Q function, and the estimate value of the model parameters is updated by maximizing the target function, so that the parameters are more consistent with the current data distribution. The two are iteratively alternated, and the model parameters are gradually optimized until convergence.

[0133] Based on the parameterized Bayesian network model and the missing values existing in the pre-processed training data set, the missing values are processed through the Gibbs sampling algorithm, wherein samples are extracted from the conditional probability distribution based on the Markov Chain Monte Carlo method, and the true joint probability distribution is gradually approached, to obtain a Bayesian network model after processing the missing values;

[0134] Based on the Bayesian network model after processing the missing values, the model performance is evaluated through the cross-validation method, the pre-processed training data set is divided into a training set and a test set, the model prediction accuracy, recall rate and F1 score are calculated to evaluate the model discrimination ability, and a performance-evaluated Bayesian network model is obtained;

[0135] Based on the performance-evaluated Bayesian network model, model regularization techniques are used to prevent model overfitting, where the Bayesian information criterion is used to optimize the network structure complexity, and the weight decay method is used to constrain the size of the parameter estimates, to obtain a regularized Bayesian probability model;

[0136] Based on the regularized Bayesian probability model, the model is continuously optimized through the establishment of an online updating mechanism, wherein new monitoring data is continuously integrated through an incremental learning algorithm, a sliding time window mechanism is used to maintain the adaptability of the model to system state changes, and an online updating Bayesian probability model is obtained;

[0137] Based on the online updating Bayesian probability model and the production environment, the model is deployed to the production environment through model deployment technology, the performance data, configuration state and idle state of the current server are received through the real-time monitoring interface and input into the model for inference calculation to obtain real-time inference results;

[0138] Based on the real-time inference results, the posterior probability in the real-time inference results is converted into a business operation risk value through a risk level division algorithm, wherein the risk value interval is calibrated according to historical fault data to obtain a business operation risk value;

[0139] Based on the business operation risk value and the resource scheduling system requirement, the online updating Bayesian probability model is integrated into the resource scheduling system through system integration technology, so that the model can provide risk prediction support for resource allocation decisions, and a Bayesian probability model capable of accurately evaluating the business operation risk after the chain of the elastic bare metal server is obtained.

[0140] The function attributes, identity fingerprints, health state scores and configuration states of the server groups are stored in each parameter node in the metadata subnet in the resource interaction verification network, and based on the identity fingerprints and location information of each parameter node, a corresponding verification key-public key pair is generated;

[0141] Based on the server group, a physical resource subnet is constructed, and the public key of the corresponding server in each parameter node is associated and mapped to the physical resource node corresponding to the physical resource subnet, establishing a parameter-resource one-to-one association mapping; each physical resource node represents a server;

[0142] Based on the parameter-resource one-to-one association mapping, the metadata subnet and the physical resource subnet, the resource interaction verification network is obtained through a topological space algorithm, and the initial state of the corresponding server in each parameter node is set to "idle".

[0143] Further, the process of associating the metadata subnet with the physical resource node in the embodiment includes:

[0144] By collecting the function attributes, health state scores, identity fingerprints and geographic locations of the servers, a multi-dimensional description vector of the physical resource node is constructed to provide basic metadata for key generation and association mapping;

[0145] Based on the server fingerprint and the geographical position, an asymmetric key pair is generated using an elliptic curve algorithm, the private key is stored in a hardware security module, and the public key is used as a node identity, ensuring that the communication link is authenticated and tamper-proof.

[0146] According to the health status score, idle parameter nodes are screened, and a one-to-one binding is established between the public key and the physical resource nodes in the same machine room, thereby preferentially ensuring low latency and high reliability, and isolating the potential risk of cross-machine room communication.

[0147] A plurality of parameter nodes and a plurality of physical machines are respectively formed into a metadata subnet and a physical resource subnet according to a binding relationship, and cross-subnet encrypted communication and resource scheduling permission control are realized through public key association.

[0148] Further, in the embodiment, the geographical position sensitive association mapping, combined with the tamper-proofing of the hardware fingerprint, realizes "location + identity" dual isolation, and the network attack interception rate is greatly improved.

[0149] A user resource demand sequence is obtained, a demand analysis model in a smart contract in an elastic coupling blockchain is triggered, and a user resource demand space is obtained.

[0150] Further, in the embodiment, the construction and training process of the demand analysis model includes:

[0151] Based on historical user resource demand data, resource specification description text, performance index requirements, service level agreement terms, business type labels, and resource usage mode records are obtained through a multi-source data acquisition interface to obtain an original training corpus;

[0152] Based on the original training corpus, the original training corpus is preprocessed through natural language processing technology, wherein irrelevant characters and stop words are removed through a text cleaning algorithm, vocabulary standardization is realized through stem extraction and lemmatization technology, and resource-related entities are extracted through a named entity recognition algorithm to obtain preprocessed training data;

[0153] Based on the preprocessed training data, a multi-modal feature vector is constructed through a feature engineering method, wherein text descriptions are converted into numerical vectors through word embedding technology, classification features are processed through one-hot encoding, and numerical features are processed through a normalization algorithm to obtain a unified dimension multi-modal feature vector;

[0154] Based on the multi-modal feature vector, a deep demand analysis model is constructed through a Transformer architecture, wherein a multi-head self-attention mechanism is used to capture long-distance dependency relationships in demand text, position encoding is used to maintain sequence order information, and a feedforward neural network is used to realize feature nonlinear transformation to obtain an initial deep demand analysis model structure.

[0155] Based on the initial depth requirement analysis model structure and large-scale unlabeled resource requirement text, the model parameters are initialized through the mask language model pre-training strategy, the model is trained through self-supervised learning, and the semantic understanding ability of the model is enhanced through the next sentence prediction task to obtain a pre-trained requirement analysis base model;

[0156] Based on the pre-trained requirement analysis base model and the annotated resource requirement-configuration mapping data, the pre-trained requirement analysis base model is fine-tuned through domain adaptation technology, and the model is optimized through supervised training, wherein the cross-entropy loss function is used to calculate the loss value, the model weight is updated through the gradient descent algorithm, and the fine-tuned requirement analysis model is obtained.

[0157] Based on the fine-tuned requirement analysis model, the model robustness is improved through the deployment of the adversarial training mechanism, wherein the adversarial samples are generated through the generative adversarial network, the model anti-interference ability is enhanced through the gradient penalty method, and the model calibration performance is improved through the label smoothing technology, and the requirement analysis model with enhanced robustness is obtained.

[0158] Based on the requirement analysis model with enhanced robustness and the domain knowledge graph, the model inference ability is enhanced through the integration of the knowledge graph, wherein the domain knowledge entity relationship is fused through the graph neural network, and the important knowledge nodes are dynamically weighted through the attention mechanism, the model's ability to infer implicit requirements is enhanced, and the requirement analysis model with enhanced inference ability is obtained.

[0159] Based on the requirement analysis model with enhanced inference ability, the model performance is optimized through the multi-task learning framework, including jointly training the requirement classification task and the resource configuration generation task, maintaining the independence of each task through the task-specific adapter network, and coordinating the multi-task learning process through the gradient balancing algorithm, and the requirement analysis model with optimized performance is obtained.

[0160] Based on the requirement analysis model with optimized performance, the hyperparameter tuning is performed through the Bayesian optimization algorithm, wherein the relationship between the hyperparameters and the model performance is modeled through the Gaussian process, and the optimal hyperparameter combination is selected through the expected improvement acquisition function, and the requirement analysis model with the best hyperparameter configuration is obtained.

[0161] Based on the requirement analysis model with the best hyperparameter configuration, the inference efficiency is improved through the model compression technology, the lightweight student model is trained through the knowledge distillation method, the redundant parameters are removed through the model pruning algorithm, and the model storage requirement is reduced through the quantization technology, and the lightweight and efficient requirement analysis model is obtained.

[0162] Based on a lightweight and efficient demand analysis model and a smart contract environment, the model service is deployed to the smart contract environment through model deployment technology, wherein the model is cross-platform deployed through ONNX format, the inference speed is improved through hardware acceleration technology, and online hot update is supported through model version management, so as to obtain the demand analysis model service deployed in the smart contract environment;

[0163] Based on the demand analysis model service deployed in the smart contract environment, the model adaptability is optimized through the establishment of a continuous learning mechanism, wherein the new demand mode is adapted through an online learning algorithm, the old knowledge is maintained through a catastrophic forgetting prevention technology, and valuable samples are selected for labeling through an active learning strategy, so as to obtain a demand analysis model with continuous learning ability;

[0164] Based on the demand analysis model with continuous learning ability, the understanding accuracy of the model for user resource demand and the reliability of the output structured demand space are confirmed through a function verification mechanism, so as to obtain a high-performance demand analysis model, which can output a structured user resource demand space description and provide reliable input for subsequent resource scheduling and allocation.

[0165] Further, the demand analysis model in the smart contract in the embodiment is constructed by LSTM to identify the business type and extract key parameters, for example, the financial demand requires "exclusive VLAN + hardware encryption".

[0166] Based on the user resource demand space and the resource interaction verification network, the server resources and the number of servers that meet the user demand are obtained through a matching algorithm combined with a PoS+QoS consensus algorithm, and the initial state of the parameter nodes of the servers obtained from the resource exchange pool is converted into a "current occupation state", and the occupation state timestamp interval is marked;

[0167] It should be further explained that the implementation process of the state conversion in the embodiment includes:

[0168] Based on the task state of the business processing sub-chain, the smart contract listens to the task completion event of the business processing sub-chain, and when detecting a business execution completion signal or a lease expiration signal, the resource state conversion process is automatically triggered, and the event-driven architecture is adopted to ensure the timeliness of the state conversion, so as to obtain a resource state conversion trigger instruction;

[0169] Based on the resource state conversion trigger instruction, a resource cleaning task is created through a resource release instruction generation algorithm, and the resource release instruction generation algorithm generates differentiated cleaning strategies based on the characteristics of the resource types, wherein a memory zeroing operation is performed on the computing resources, a data erasing operation is performed on the storage resources, and a rule recycling operation is performed on the network resources, so as to obtain a resource cleaning task set;

[0170] Based on the storage resource cleaning task in the resource cleaning task set, the storage resource is cleaned multiple times by a secure data erasure algorithm, and the data unrecoverability is ensured by an erasure specification to obtain a storage resource cleaning result;

[0171] Based on the computing resource cleaning task in the resource cleaning task set, the memory resource is initialized by a physical memory zeroing instruction, and the cleaning integrity is ensured by a hardware-assisted memory protection mechanism to obtain a memory resource initialization result;

[0172] Based on the security key processing task in the resource cleaning task set, the security key material is processed by a key destruction protocol, wherein a key derivation tree management mechanism is used to trace all derived keys, an cryptographic secure random number generator is used to cover the original key storage area to ensure complete elimination of key information, and a key information cleaning result is obtained;

[0173] Based on the storage resource cleaning result, the memory resource initialization result and the key information cleaning result, a resource cleaning verification mechanism is deployed to verify the cleaning effect, wherein a resource state snapshot is obtained by a digital fingerprint collection algorithm, a resource state digest value is generated by a hash operation, and the resource state digest value is compared with an initial state reference value to obtain a resource cleaning effect verification result;

[0174] Based on the resource cleaning effect verification result, a smart contract is executed to verify the cleaning proof, wherein the correctness of the resource cleaning process is verified by zero-knowledge proof technology without revealing specific cleaning details, a Merkle tree structure is used to build a cleaning operation proof to ensure the efficiency of the verification process, and a cleaning process correctness verification result is obtained;

[0175] Based on the full-process operation of resource state conversion, an audit log is recorded to record the complete resource release process, wherein a blockchain technology is used to ensure the non-tamperability of the log, a timestamp service is used to record the time node of each operation, and a digital signature is used to ensure the traceability of the operation responsibility, and a non-tamperable resource release audit log is obtained;

[0176] Based on the integrity and quality of the resource release process, a health state score updating mechanism is implemented to dynamically adjust the node score, wherein a weighted scoring algorithm is used to consider multiple factors such as cleaning time, resource consumption and verification result, and an updated node health state score is obtained;

[0177] Based on the fault monitoring in the resource release process, an exception handling process is established to deal with release failures, when a resource release process failure is detected, a backup cleaning solution is automatically triggered, and a redundant cleaning mechanism is used to ensure that the resource release task can be completed under various abnormal conditions, and a resource release completion result under abnormal conditions is obtained;

[0178] Based on the resource release completion result, the node state in the resource interaction verification network is updated through a state synchronization protocol, wherein a consensus algorithm is adopted to ensure the consistency of the resource state cognition of all nodes, a distributed transaction is adopted to ensure the atomicity of the state update, and a consistent update result of the node state in the resource interaction verification network is obtained;

[0179] Based on the consistent update result of the node state, the safe conversion of the resource from the occupied state to the idle state is completed through a state conversion confirmation mechanism, the resource is ensured to be completely cleaned up and can be allocated to a new user task again, the safety and reliability of the system are maintained, and a safe and available resource that can be allocated again is obtained.

[0180] Exemplarily, in order to better illustrate the process of obtaining server resources and the number of servers that meet the user demand through the matching algorithm combined with the PoS+QoS consensus algorithm, the following exemplary steps are given in the financial transaction scenario, specifically as follows:

[0181] The user submits a JSON format request containing his own demand, and the request contains user information, business type, hardware specification, required server quantity, network requirement, use time window and service level agreement and the like.

[0182] The smart contract in the embodiment parses the request and completes the following operations:

[0183] The business type is identified as finance, so that the financial exclusive rules are triggered, and these rules usually require that the server is located in the same machine room, has a hardware encryption function and a TPM (trusted platform module) verification capability.

[0184] The occupation state time stamp interval of each server in the resource interaction verification network is queried, and those servers that have been preoccupied within the user specified time window are excluded.

[0185] The hardware specification of the user demand is associated and mapped to a hardware fingerprint prefix, so as to facilitate matching according to the "configuration fingerprint" field in the resource interaction verification network, and finally the user request is converted into a structured demand object.

[0186] Related data is extracted from the metadata subnet and the physical resource subnet of the resource interaction verification network, including the configuration fingerprint, the health state score, the geographical position, the financial label, the latest use time, the pledge state and the QoS score of the server. Then the data is filtered according to some basic conditions:

[0187] The servers with a health state score lower than a preset score are excluded, because the servers with a low health state score may have a hardware failure risk, which will affect the stable operation of the business;

[0188] Only servers with financial tags are selected to ensure that the servers meet the special requirements of financial services;

[0189] Servers available within the user-specified time window are screened to avoid time conflicts.

[0190] Furthermore, in this embodiment, the PoS (Proof of Stake) consensus mechanism is used to screen the nodes providing server resources, and the specific steps are as follows:

[0191] Through the smart contract, the resource interaction verification network is traversed to check whether the number of resources in the provider node's pledge pool meets the demand, and the nodes with sufficient pledge amount and locked resources within the limit are screened to provide a trusted resource pool for subsequent priority sorting;

[0192] In this embodiment, the proportion of the pledge amount will affect the priority of the node. The higher the pledge amount, the greater the weight. The weight of the node that pledges 100% of the resources will be doubled, which encourages providers to provide more resources and ensure their availability. Finally, the provider nodes with sufficient pledges are screened.

[0193] Based on the proportion of the pledge amount and the QoS score, the nodes are sorted in descending order. If the scores are the same, they are arranged in ascending order of pledge weight. If the pledge weight is also the same, they are arranged in ascending order of geographic location, which encourages high-pledge nodes and guarantees the service quality baseline.

[0194] Through three-level filtering, servers are screened to ensure low latency, high security, and resource polling balance, and the available candidate list is intercepted into the atomic lock machine process. Further, in this embodiment, the three-level filtering includes the same machine room financial tag, hardware encryption support, and recent non-use priority.

[0195] Further, the implementation process of the PoS+QoS consensus algorithm in this embodiment includes:

[0196] Based on the node participation basis of distributed coupling correlation mapping chain, a node pledge system is established through the proof of stake mechanism, and a digital asset pledge algorithm is used to require server resource providers to pledge digital assets of corresponding value. Then, the smart contract automatically records the pledge amount and timestamp, and uses the on-chain ledger to ensure the transparency and non-tamperability of the pledge record, obtaining the node pledge record dataset;

[0197] Based on the server nodes in the node pledge record dataset, real-time server performance data is collected through the service quality measurement system. Network probe technology is used to measure node response delay, bandwidth monitoring tools are used to obtain node throughput data, and resource monitoring agents are used to collect node CPU utilization and memory usage indicators, obtaining the node real-time service quality dataset.

[0198] Based on the node real-time service quality dataset, the real-time QoS score of each node is calculated by a multi-dimensional scoring algorithm, wherein the weighted moving average method is used to process the historical performance data of the node to smooth fluctuations, the coefficient of variation method is used to dynamically adjust the weights of CPU utilization, memory usage, response delay and throughput, the normalized processing is used to convert the index values of different dimensions into scores in a unified interval, and the node real-time QoS standardized score is obtained;

[0199] It should be further explained that the process of dynamically adjusting the weights of CPU utilization, memory usage, response delay and throughput of each index by the coefficient of variation method in the embodiment includes:

[0200] Firstly, a sliding time window containing the last N fixed collection periods is set, N is a preset positive integer, and the CPU utilization, memory usage, response delay and throughput of the node are extracted from the window as the basic data source for weight calculation. Then, for the historical performance data of each index, the arithmetic mean is calculated, and the sample standard deviation is calculated by Bessel correction to ensure that the standard deviation can more accurately reflect the data fluctuation. On this basis, the coefficient of variation CV of each index is calculated by the formula CV=σ / μ, σ is the variance of the index, and μ is the mean of the index. If the mean μ of an index is 0, to avoid calculation anomalies, a preset maximum value is set for the coefficient of variation of the index. Then, the coefficients of variation CV of the four indexes are normalized, and the coefficient of variation of each index is divided by the sum of the coefficients of variation of the four indexes to obtain the weight ω corresponding to each index, and the sum of the weights of the four indexes is always 1. At the same time, the regular update period of the weight is set to P collection periods, P is a preset positive integer and P≤N, and the whole process from data extraction to weight calculation is repeated every P collection periods to realize periodic dynamic update of the weight. In addition, when the absolute value of the change of the coefficient of variation of an index in two consecutive update periods exceeds a preset threshold, the regular update period is broken, and the weight update process is triggered immediately to perform data extraction, coefficient of variation calculation and normalization operation again to quickly adapt to the abnormal change of the index fluctuation.

[0201] Based on the node pledge record dataset and the node reputation historical data, the PoS weight factor is determined by the equity weight calculation algorithm, wherein the logarithmic function is used to smooth the difference in the number of pledges of different nodes to avoid excessive concentration of equity, the time decay factor is used to quantify the influence of pledge duration on equity (the longer the pledge time, the smaller the decay coefficient), the maximum equity proof score is calculated by combining the historical non-violation operation records of the node, and the node equity proof score is obtained;

[0202] Based on the node proof-of-stake score and the node real-time QoS standardized score, the scores of both are combined through a linear weighted fusion algorithm, wherein the importance of proof-of-stake and service quality is balanced through a dynamic weight adjustment mechanism, the weight distribution ratio is automatically adjusted according to the business type using a fuzzy logic control algorithm, and the QoS index weight is increased by 30%-50% in a financial transaction scenario, for example, to obtain a node comprehensive consensus score;

[0203] Based on the node comprehensive consensus score, a candidate node pool of resource allocation scheme is created through a consensus proposal generation mechanism, wherein a polling selection algorithm is used to preliminarily screen candidate nodes from all nodes that meet the comprehensive consensus score, a cryptographic secure random number generator is used to introduce selection uncertainty, and a verifiable random function is used to ensure the fairness and unpredictability of the candidate node selection process, to obtain a consensus candidate node list;

[0204] Based on the consensus candidate node list and resource scheduling requirements (cost, performance, risk constraints), the optimal resource allocation scheme is solved through a multi-objective optimization algorithm, wherein a non-dominated sorting genetic algorithm is used to handle the multi-constraint conditions of "cost minimization, performance maximization, and risk minimization", a Pareto optimal solution selection mechanism is used to screen the optimal scheme considering each target from multiple feasible solutions, and an optimal node resource allocation scheme is obtained;

[0205] Based on the node optimal resource allocation scheme, the final consensus verification is executed through a smart contract, wherein a multi-signature mechanism is used to require at least two-thirds of the verification nodes (verification nodes are selected from the top 30% nodes in the comprehensive consensus score) to collectively confirm the allocation scheme, a Byzantine fault tolerance algorithm is used to resist malicious behavior of no more than one-third of the nodes to ensure consensus security, a threshold signature technology is used to combine multiple node signatures into a single signature to improve verification efficiency, and a resource allocation scheme consensus verification pass result is obtained;

[0206] Based on the resource allocation scheme consensus verification pass result, the consensus execution effect is tracked through a real-time monitoring system, wherein a feedback control algorithm is used to dynamically adjust consensus parameters such as QoS index weight and candidate node screening threshold according to the actual executed service quality deviation, a reinforcement learning mechanism is used to optimize the weight distribution strategy with the reward target of improving consensus efficiency and service quality compliance rate, an online learning algorithm is used to incorporate new network environment data such as node failure rate and business load changes in real time to adapt to demand changes, and dynamically optimized consensus parameter configurations are obtained;

[0207] Based on the consensus full-process data, including candidate node selection records, voting data, verification results, a traceable and auditable system is constructed through a consensus result tracing mechanism, wherein a blockchain technology is used to record the complete consensus process to the chain ledger, a Merkle tree structure is used to store the voting data of each node to realize fast hash verification, a zero-knowledge proof technology is used to verify the correctness of the consensus process without revealing the specific voting details, and a complete record of the traceable and auditable consensus process is obtained;

[0208] Based on the consensus verification result of the resource allocation scheme, the dynamically optimized consensus parameter configuration, and the traceable and auditable consensus process complete record, the algorithm integrity verification mechanism confirms that the consensus algorithm meets the "Proof of Stake (PoS)" and "Quality of Service (QoS)" requirements at the same time, and can adapt to the safe and reliable scheduling requirements of high-demand scenarios such as financial transactions, and obtains a complete PoS+QoS consensus algorithm. This algorithm can provide consensus support for resource scheduling of distributed coupling and associated mapping chains.

[0209] Further, in the embodiment, the server is filtered through three levels of filtering, specifically:

[0210] First-level filtering, specifically, according to user IP positioning, servers with financial labels and health state scores greater than 90 points located in the same machine room as the user are screened out. Servers in the same machine room can reduce network delay and meet the low delay requirements of financial businesses;

[0211] Second-level filtering, specifically, the SecureBoot state of the server BMC (Baseboard Management Controller) is queried through IPMI (Intelligent Platform Management Interface) to confirm whether the server supports hardware encryption. Servers that do not support hardware encryption are excluded to ensure the security of financial business data;

[0212] Third-level filtering, specifically, the remaining servers are sorted in ascending order according to the "last use time", and the servers that have not been used recently are selected first. The first few servers in the sorted order are intercepted, and it is verified whether they are available within the user-specified time window.

[0213] The selected server state is locked by calling the smart contract, the CAS mechanism handles concurrent conflicts, failed requests enter the retry queue, ensuring the uniqueness of resource configuration, and at the same time deducting the number of pledge pools to trigger state changes;

[0214] Based on user IP and SDN path detection to calculate delay, nodes in the same machine room with delay < SLA requirement are forced to be selected, and cross-regional servers are excluded. If resources are insufficient, the delay is relaxed to 15 ms and IPsec tunnel encryption is enabled to balance performance and security;

[0215] Get the server real-time health score through the HealthOracle predictor, automatically release and replace the abnormal node with the alternative to prevent business interruption caused by state mutation after locking the machine;

[0216] Synchronize the metadata subnet and the physical resource subnet using the Paxos algorithm, deduct the pledge pool resources and record the timestamp, roll back if not confirmed within the timeout period, and ensure distributed consistency;

[0217] When the resources in the same room are insufficient, dynamically relax the delay limit, increase the cross-regional node pledge weight, and force encryption, record the configuration audit trail on the chain to ensure compliance while maximizing resource utilization;

[0218] Return the server details in JSON and notify the user, trigger the SDN controller to pre-bind the VLAN, reduce user-side configuration delay, and improve end-to-end readiness speed; the server has selected IP, VLAN, fingerprint, and algorithm parameters;

[0219] Record the configuration ID, user ID, server fingerprint, and algorithm parameters on the chain throughout the process, generate a quarterly compliance report, support regulatory traceability and audit, and form a closed-loop trusted proof.

[0220] Based on the number of servers, blockchain, and smart contracts, a distributed coupling correlation mapping chain is constructed.

[0221] Further, the distributed coupling correlation mapping chain in the embodiment includes an isolated block subchain and a business processing subchain;

[0222] The isolated block subchain includes M isolated block subnodes and an extended isolated block subnode; the business processing subchain includes M business processing subnodes.

[0223] The isolated block subnode is used to save the key-public key, identity fingerprint, hash table of running results of the corresponding business processing subnode, and verification and on-chain adjustment of the security isolation interaction strategy; the business processing subchain is used to perform load adjustment and user demand business operation based on real-time load data, and each business processing subnode in the business processing subchain is only allowed to interact with the business processing subnodes in the chain.

[0224] The identity fingerprint, parameter-resource one-to-one correlation mapping, key-public key pair, and marked occupancy state timestamp interval of each server corresponding parameter node that meets the user's demand are associated and mapped from the corresponding parameter node in the metadata subnet to the corresponding isolated block subnode in the isolated block subchain through the smart contract, and the three-layer dynamic protection algorithm is configured on the interface of each isolated block subnode after resource on-chain;

[0225] Meanwhile, based on the physical resource nodes corresponding to the selected server of the physical resource subnet, a service processing sub-chain is constructed, and a dedicated VLAN identifier is configured, and the service processing sub-nodes in the service processing sub-chain are one-to-one associated and mapped with the corresponding isolated block sub-nodes by using the parameter-resource one-to-one association mapping;

[0226] Further, in the embodiment, the VLAN is a technology for logically dividing devices in a local area network into different network segments. By using the VLAN, a physical local area network can be divided into multiple logically isolated networks. By default, devices in different VLANs cannot directly communicate with each other, thereby improving the security, flexibility, and manageability of the network.

[0227] The public key stored in the isolated block sub-node corresponding to the isolated block sub-chain is associated and mapped to the corresponding service processing sub-node, and the VLAN identifier configured in the service processing sub-chain and the hash corresponding to each service processing sub-node are associated and mapped to the corresponding isolated block sub-node.

[0228] A load running upper limit threshold is set for each node in the service processing sub-chain, and an extension association mapping is established between each service processing sub-node and the extended isolated block sub-node based on the set load running upper limit threshold, and the extension association mapping is built into the upper chain extension contract between the isolated block sub-chain and the prepared resource sub-pool configured in the resource exchange pool;

[0229] When the predicted load obtained by each service processing sub-node configured with a prediction analysis model in combination with real-time running load data is greater than the load running upper limit threshold corresponding to a probability greater than a preset load overrun probability threshold in the next moment, the upper chain extension contract is triggered;

[0230] According to the information stored in the corresponding service processing sub-node and isolated block sub-node, in combination with the information saved in the idle parameter node corresponding to the current state of the resource exchange pool and the distance between each parameter node and the current predicted overrun service processing sub-node, a matching algorithm is used in combination with the shortest delay principle to select and match, and the matched parameter node is stored in the prepared resource sub-pool.

[0231] Meanwhile, the public key corresponding to the predicted overrun service processing sub-node is associated and mapped to the corresponding parameter node matched in the prepared resource sub-pool, and an extension upper chain association mapping is performed.

[0232] The process realizes the full life cycle security management of the elastic bare metal server through the chain trust architecture. Specifically, the hardware layer realizes accurate state perception through multi-dimensional data collection and health state scoring evaluation; the resource scheduling layer ensures node optimization and exclusive configuration based on a dynamic consensus algorithm and a smart contract lock; the security protection layer establishes a three-level in-depth defense relying on network isolation, hardware trust verification, and business compliance verification; and the elastic expansion layer realizes dynamic optimization of resources through a load prediction analysis model and a hot migration technology. The architecture supports efficient elastic expansion of high-sensitivity businesses while ensuring the tamper resistance of physical devices, and provides full-stack trusted infrastructure support for financial-grade applications.

[0233] Further, the step of real-time exception repair and resource uplink and downlink adjustment of the distributed coupling correlation mapping chain in the embodiment includes:

[0234] The running state information of the distributed coupling correlation mapping chain is monitored in real time, and an exception discrimination model is configured to perform real-time exception discrimination. When it is determined through monitoring and discrimination that there is at least one load exception of a business processing subnode, an uplink expansion contract is triggered, and the maximum load of the corresponding physical resource node of the predicted migration load and the prepared resource subpool is obtained according to the load exception of the business processing subnode.

[0235] It should be further pointed out that the construction and training process of the exception discrimination model in the embodiment includes:

[0236] Based on the business processing subnode, a data collection agent is deployed on the business processing subnode to collect running state index data of the business processing subnode in real time. The running state index data includes CPU usage rate time series data, memory occupancy rate change curve, disk IO throughput statistical value, network bandwidth usage rate waveform, and service response delay log, and the real-time running state original data of the business processing subnode is obtained.

[0237] Based on the real-time running state original data of the business processing subnode, the real-time running state original data is received through a distributed message queue, and the real-time running state original data is subjected to a missing value filling operation and an abnormal value filtering operation through data preprocessing. Subsequently, the continuous data stream subjected to preprocessing is converted into a fixed-length time series data segment through a sliding time window mechanism, and the time series data segment of the business processing subnode is obtained.

[0238] Based on the business processing sub-node time series data segment, multi-dimensional feature extraction is performed on the time series data segment through feature engineering technology. The extracted feature types include statistical features, time domain features, and frequency domain features. The statistical features include mean, variance, and extreme value. The time domain features include autocorrelation function value and partial autocorrelation function value. The frequency domain features include fast Fourier transform coefficient and wavelet transform coefficient. A multi-dimensional feature vector of the business processing sub-node is obtained.

[0239] Based on the historical abnormal event annotation data and the business processing sub-node time series data segment, the time series data associated with the historical abnormal event annotation data is preliminarily annotated through an expert rule system. Then, a clustering analysis algorithm is used to supplement the annotation of the time series data that is not associated with the historical annotation. The samples annotated as abnormal state are set as positive samples, and the samples annotated as normal state are set as negative samples. An annotated abnormal detection training sample set is obtained.

[0240] Based on the annotated abnormal detection training sample set and the multi-dimensional feature vector of the business processing sub-node, an initial abnormal detection model is constructed through an isolation forest algorithm. The isolation forest algorithm constructs multiple isolation trees by randomly selecting features in the multi-dimensional feature vector and randomly selecting partition points corresponding to the features. Then, the abnormal scores of the samples in the multiple isolation trees are calculated to determine the abnormal scores of the samples. A baseline abnormality discrimination model is obtained.

[0241] Based on the annotated abnormal detection training sample set and the multi-dimensional feature vector of the business processing sub-node, a time series anomaly detection neural network is constructed through a deep learning method. The time series anomaly detection neural network adopts an encoder-decoder architecture. The encoder part uses a one-dimensional convolutional neural network to extract local features in the multi-dimensional feature vector, and the decoder part uses a long short-term memory network to capture long-term dependencies in the multi-dimensional feature vector. An initial time series anomaly detection neural network model is obtained.

[0242] Based on the initial time series anomaly detection neural network model and the annotated abnormal detection training sample set, the initial time series anomaly detection neural network model is trained through a contrastive learning mechanism. The contrastive learning mechanism uses a triplet loss function to pull the feature distances between normal samples closer and push the feature distances between normal samples and abnormal samples farther apart, thereby enhancing the model's ability to discriminate abnormal patterns. A trained time series anomaly detection neural network model is obtained.

[0243] The output results of the two models are fused through an ensemble learning framework based on the baseline anomaly discrimination model, the trained time series anomaly detection neural network model, and the verification set in the labeled anomaly detection training sample set, the ensemble learning framework adopts a weighted voting mechanism to calculate the final anomaly probability value, wherein the voting weight is dynamically adjusted according to the accuracy of the two models on the verification set, and an integrated anomaly discrimination model is obtained;

[0244] Based on the integrated anomaly discrimination model and the newly generated monitoring data of the business processing subnode, the parameters of the integrated anomaly discrimination model are continuously optimized through an online learning mechanism, the online learning mechanism uses an incremental learning algorithm to process the newly generated monitoring data to update the model parameters, and uses a model distillation technology to keep the model lightweight to adapt to real-time inference requirements, and an anomaly discrimination model with online optimization capability is obtained;

[0245] Based on the anomaly discrimination model with online optimization capability and the edge computing node, the anomaly discrimination model with online optimization capability is deployed to the edge computing node through model deployment technology to form a model service, wherein the inference speed of the model service is improved through hardware acceleration technology, and the hot update operation and rollback operation of the model service are supported through the model version management mechanism to ensure service continuity, and an anomaly discrimination model service deployed on the edge computing node is obtained.

[0246] Based on the anomaly discrimination model service deployed on the edge computing node, the running effect of the model service is evaluated and monitored through a model performance monitoring system, the model performance monitoring system evaluates the discrimination effect of the model service through accuracy, recall rate, F1 score and response delay index, regularly tests the robustness of the model service using adversarial samples to find and repair model defects in time, and an anomaly discrimination model service with controllable performance is obtained.

[0247] Based on the performance controllable anomaly discrimination model service and the stable operation requirement of the distributed coupling association mapping chain, the performance controllable anomaly discrimination model service is confirmed to be able to accurately identify various load anomaly patterns of the business processing subnode through a function verification mechanism, and can trigger the on-chain expansion contract in time when detecting an anomaly, and an anomaly discrimination model capable of real-time discrimination of load anomalies of the business processing subnode is obtained.

[0248] According to the amount of physical resource nodes of the load abnormal service processing subnode, the corresponding number of isolated block subnodes and service processing subnodes are expanded in the distributed coupling association mapping chain through the uplink expansion contract, and the public key-private key saved in the corresponding parameter nodes of the uplink physical resource nodes in the prepared resource subpool is associated and mapped to the public key of the load abnormal service processing subnode. Through the smart contract combined with the resource configuration adjustment model, the uplink verification is carried out. When the verification is passed, the corresponding uplink parameter nodes and physical resource nodes are associated and mapped to the corresponding isolated block subnodes and service processing subnodes;

[0249] When the association mapping is completed, the three-layer dynamic protection algorithm configured by the load abnormal service processing subnode corresponding to the isolated block subnode is used to interactively verify the new isolated block subnode uploaded to the chain. When the verification is passed, the abnormal load is migrated to the new service processing subnode that passes the verification, and the corresponding result hash is synchronized to the corresponding isolated block subnode for demand business operation;

[0250] When the corresponding parameter nodes of the current physical resource nodes are not verified, the current physical resource nodes and the corresponding parameter nodes are directly rejected from being uploaded to the chain, and the remaining parameter nodes and physical resource nodes in the prepared resource subpool are continuously verified until the load abnormal service processing subnode meets the load migration requirements.

[0251] When at least one node in the distributed coupling association mapping chain receives a cross-chain resource request, the corresponding request is directly rejected and added to the blacklist. When the corresponding business processing subnode of the distributed coupling association mapping chain finishes the business operation, the corresponding business processing subnode that finishes the operation is directly off-chained, the business information stored in the business processing subnode and the corresponding uplink association mapping parameter information of the corresponding isolated block subnode are cleared, and the operation result is saved in the corresponding isolated block subnode;

[0252] When the corresponding cross-chain resource request still exists after the operation is completed, the parameter information saved in the off-chained physical resource nodes and the corresponding parameter nodes is associated and mapped to the corresponding distributed coupling association mapping chain of the cross-chain resource request according to the cross-chain resource request;

[0253] When the risk value of at least one node business operation in the distributed coupling correlation mapping chain is greater than the preset abnormal probability threshold, the uplink process of the abnormal load physical resource node is repeated, a new physical resource node is obtained from the preparation resource sub-pool, and three-layer verification of uplink verification and resource interaction is performed. When all verifications are passed, the corresponding abnormal isolation block sub-node and business processing sub-node information are migrated to the new uplink isolation block sub-node and business processing sub-node to continue operation, until the operation is completed, the business processing sub-chain in the distributed coupling correlation mapping chain is directly dissolved and all business and configuration information is cleared, and the uplink correlation mapping information corresponding to the business processing sub-node in the business processing sub-chain is all cleared, only the operation result is retained in the isolation block sub-chain.

[0254] The self-closed loop control system of the elastic bare metal service chain constructed in this embodiment realizes fusion analysis of real-time monitoring of hardware health characteristics and business load, dynamically triggers resource expansion decision in combination with a prediction analysis model. In the node migration process, a stereoscopic protection mechanism of network layer flow table comparison, hardware layer TPM verification and business layer encryption processing is adopted to block counterfeit attacks and ensure data integrity; based on the zero trust mechanism, abnormal requests are intercepted and attack fingerprints are recorded in the cross-chain scenario, and security cleaning and compliance storage are performed after the business ends. For the problem of exceeding the node abnormal probability, the system automatically schedules the replacement of the front resource pool node, synchronously migrates the business state and isolates the old node, forming a closed-loop security system covering the whole process of perception, decision, migration and protection.

[0255] Embodiment 2:

[0256] Please refer to Figure 3 The present application provides another embodiment: an elastic bare metal server resource exclusive and secure isolation guarantee system, comprising: a coupling service chain module, an isolation verification module and a repair module;

[0257] The coupling service chain module, based on the configured smart contract on the elastic coupling blockchain, responds to user demand configuration information and combines a preset resource configuration adjustment model and a PoS+QoS consensus algorithm to obtain a distributed coupling correlation mapping chain.

[0258] The distributed coupling correlation mapping chain is constructed by each block node on the elastic coupling blockchain in combination with the corresponding configured demand resource and the corresponding unique identity fingerprint.

[0259] The isolation verification module is used to deploy and start the distributed coupling correlation mapping chain, and simultaneously performs real-time detection and discrimination on the internal and external operation states of the distributed coupling correlation mapping chain through a preset three-dimensional dynamic protection algorithm and demand completion progress to obtain a discrimination result.

[0260] The repair module is used for feeding back the discrimination result to the resource configuration adjustment model, combining a preset security adjustment strategy library, and performing real-time exception repair and resource uplink / downlink adjustment on the distributed coupling correlation mapping chain.

[0261] The embodiments of the present application are described above with reference to the drawings; however, the present application is not limited to the specific embodiments described above, which are only illustrative rather than restrictive, and any person skilled in the art can make changes, modifications, replacements and variations to the above-described embodiments without departing from the purpose of the present application and the scope protected by the claims, and these are all within the protection of the present application.

Claims

1. A method for ensuring dedicated resource access and security isolation on elastic bare metal servers, characterized in that: include: A pre-defined elastically coupled blockchain is used. Based on the smart contracts configured on the elastically coupled blockchain, resources are configured in response to user needs. Combined with a pre-defined resource configuration adjustment model, PoS+QoS consensus algorithm and server group, a distributed coupled association mapping chain is obtained. The distributed coupled association mapping chain is constructed by each blockchain node on the elastic coupled blockchain, combining the unique identity fingerprint and configuration parameters of the corresponding configuration requirements and configuration resources. Deploy and start the distributed coupled-associated mapping chain. At the same time, through the preset three-layer dynamic protection algorithm and the required completion progress, the internal and external operating status of the distributed coupled-associated mapping chain is detected and judged in real time. The judgment results are fed back to the resource configuration adjustment model and combined with the preset security adjustment strategy library to perform real-time anomaly repair and resource on-chain and off-chain adjustment of the distributed coupled-associated mapping chain.

2. The method for ensuring exclusive resource access and security isolation of elastic bare metal servers as described in claim 1, characterized in that, The distributed coupled association mapping chain is configured with a resource exchange pool; the resource exchange pool is configured with a resource interaction verification network; The resource exchange pool is used to store the configuration, performance, identity fingerprint, historical configuration running status and functions of the server group, and the resource interaction verification network performs real-time resource uplink and downlink verification interaction through the configured parameter-resource one-to-one association mapping and the distributed coupled association mapping chain. The construction steps of the resource interaction verification network include: The system monitors and acquires the configuration, performance, identity fingerprint, historical configuration running status and functions, and current idle running status data of all server groups at the current moment, and constructs a comprehensive status sequence set of real-time idle elastic bare metal servers. Based on the performance, historical configuration operation status, and current idle operation status data in the comprehensive state sequence set, an evaluation algorithm is used to obtain the health status score corresponding to each idle elastic bare metal server. Combined with the Bayesian probability model built into the evaluation algorithm, the business operation risk value after the corresponding configuration resources are put on the blockchain is obtained.

3. The method for ensuring exclusive resource access and security isolation of elastic bare metal servers as described in claim 2, characterized in that, The construction steps of the resource interaction verification network also include: The functional attributes, identity fingerprints, health status scores, and configuration status of the server group are stored in each parameter node of the metadata subnet within the resource interaction verification network, and a corresponding verification key-public key pair is generated based on the identity fingerprint and location information of each parameter node. A physical resource subnet is constructed based on the server group, and the public key of the server corresponding to each parameter node is associated and mapped to the physical resource node corresponding to the physical resource subnet, establishing a parameter-resource one-to-one association mapping; each physical resource node represents a server. Based on parameter-resource one-to-one association mapping, metadata subnet and physical resource subnet, a resource interaction verification network is obtained through topology space algorithm, and the initial state of the corresponding server in each parameter node is set to idle.

4. The method for ensuring exclusive resource access and security isolation of elastic bare metal servers as described in claim 3, characterized in that, The construction process of the distributed coupled association mapping chain includes: Obtain the user resource demand sequence, trigger the demand parsing model in the smart contract of the elastically coupled blockchain, and obtain the user resource demand space; Based on the user resource demand space and resource interaction verification network, the matching algorithm combined with the PoS+QoS consensus algorithm is used to obtain the server resources and number of servers that meet the user's needs. The initial state of the corresponding parameter node of the server obtained from the resource exchange pool is converted into the current occupied state, and the occupied state timestamp interval is marked. Based on the number of servers, combined with blockchain and smart contracts, a distributed coupled and related mapping chain is constructed.

5. The method for ensuring exclusive resource access and security isolation of elastic bare metal servers as described in claim 4, characterized in that, The distributed coupled association mapping chain includes an isolated block sub-chain and a business processing sub-chain; The isolated block subchain contains M isolated block sub-nodes and one extended isolated block sub-node; the service processing subchain contains M service processing sub-nodes; The isolated block sub-nodes are used to store the key-public key, identity fingerprint, hash table of the running results, and verification and on / off chain adjustment of the security isolation interaction strategy for the corresponding business processing sub-nodes; the business processing sub-chain is used to perform load adjustment and calculation of user demand business based on real-time load data, and each business processing sub-node in the business processing sub-chain is only allowed to interact with business processing sub-nodes within the chain.

6. The method for ensuring exclusive resource access and security isolation of elastic bare metal servers as described in claim 5, characterized in that, The construction process of the distributed coupled association mapping chain also includes: The identity fingerprint, parameter-resource one-to-one association mapping, key-public key pair, and marked occupation status timestamp interval of each server corresponding parameter node in the server resources that meet user needs are associated and mapped from the parameter node in the metadata subnet to the corresponding isolated block sub-node in the isolated block sub-chain through smart contracts for resource on-chaining, and a three-layer dynamic protection algorithm is configured on the interface corresponding to each isolated block sub-node after the resources are on-chain. Simultaneously, based on the physical resource subnet, select the physical resource node corresponding to the server, construct the service processing subchain and configure the exclusive virtual LAN identifier and VLAN identifier, and use parameter-resource one-to-one association mapping to connect the service processing sub-nodes in the service processing subchain with the corresponding isolation block sub-nodes. The public key stored in the isolation block sub-nodes corresponding to the isolation block sub-chain is associated and mapped to the corresponding service processing sub-nodes. At the same time, the virtual LAN identifier, VLAN identifier, and storage hash corresponding to each service processing sub-node configured in the service processing sub-chain are associated and mapped to the corresponding isolation block sub-nodes.

7. The method for ensuring exclusive resource access and security isolation of elastic bare metal servers as described in claim 6, characterized in that, The construction process of the distributed coupled association mapping chain also includes: In the business processing sub-chain, a load operation limit threshold is set for each node, and an extended association mapping between each business processing sub-node and the extended isolation block sub-node is established based on the set load operation limit threshold. The extended association mapping is then embedded into the on-chain extended contract between the isolation block sub-chain and the preparatory resource sub-pool configured by the resource exchange pool. When the probability that the predicted load obtained by each business processing sub-node, configured with a predictive analysis model and combined with real-time running load data, is greater than the preset load over-limit probability threshold, the on-chain extended contract is triggered. Based on the information stored in the over-limit corresponding business processing sub-node and the isolation block sub-node, combined with the information saved in the resource exchange pool corresponding to the idle parameter node and the distance between the physical resource node corresponding to each parameter node and the currently predicted over-limit business processing sub-node, a matching algorithm is used to select the parameter node by combining the principle of shortest delay, and the matched parameter node is stored in the reserve resource sub-pool. Simultaneously, the public key associated with the business processing sub-node corresponding to the predicted over-limit is mapped to the corresponding parameter node obtained by matching the reserve resource sub-pool, and the extended on-chain association mapping is performed.

8. The method for ensuring exclusive resource access and security isolation of elastic bare metal servers as described in claim 7, characterized in that, The steps for real-time anomaly repair and resource on / off chain adjustment of the distributed coupled association mapping chain include: The system monitors the running status information of the distributed coupled association mapping chain within and between the chains in real time, and performs real-time anomaly detection through the configured anomaly detection model. When it is detected that there is at least one business processing sub-node with abnormal load, the on-chain extension contract is triggered. Based on the expected migration load corresponding to the load abnormality and the maximum load of the physical resource node corresponding to the prepared resource sub-pool, the physical resource node quantity of the business processing sub-node with abnormal load is obtained. Based on the physical resource node quantity of the load anomaly business processing sub-node, the corresponding number of isolated block sub-nodes and business processing sub-nodes are extended in the distributed coupled association mapping chain through the on-chain extension contract. The public-private key stored in the parameter node corresponding to the on-chain physical resource node in the prepared resource sub-pool is associated and mapped to the public key of the load anomaly business processing sub-node. On-chain verification is performed through smart contract combined with resource configuration adjustment model. When the verification is successful, the corresponding on-chain parameter node and physical resource node are associated and mapped to the corresponding isolated block sub-node and business processing sub-node. Once the association mapping is complete, the new isolated block sub-nodes on the chain are interactively verified using the three-layer dynamic protection algorithm configured in the isolated block sub-nodes corresponding to the load anomaly business processing sub-nodes. If the verification is successful, the abnormal load is migrated to the new business processing sub-nodes that have passed the verification, and the corresponding result hash is synchronously migrated to the corresponding isolated block sub-nodes for the required business calculations. If the parameter node corresponding to the current physical resource node fails the verification, the current physical resource node and its corresponding parameter node will be rejected from being put on the chain. The remaining parameter nodes and physical resource nodes in the reserve resource sub-pool will continue to be verified until the load migration requirements of the load anomaly business processing sub-node are met.

9. The method for ensuring exclusive resource access and security isolation of a flexible bare metal server as described in claim 8, characterized in that, The steps of real-time anomaly repair and resource on / off chain adjustment of the distributed coupled association mapping chain also include: When at least one node in the distributed coupled association mapping chain receives a cross-chain resource request, it directly rejects the corresponding request and adds it to the blacklist. When the business processing sub-node of the distributed coupled association mapping chain completes its business operation, it directly removes the completed business processing sub-node from the chain, clears the business information stored in the business processing sub-node and the on-chain association mapping parameter information corresponding to the corresponding isolated block sub-node, and saves the operation result in the corresponding isolated block sub-node. If the corresponding cross-chain resource request still exists after the calculation is completed, then according to the cross-chain resource request, the physical resource node of the next chain and the parameter information stored in the corresponding parameter node are associated and mapped to the distributed coupled association mapping chain corresponding to the cross-chain resource request. When the risk value of the business operation of at least one node in the distributed coupled association mapping chain exceeds the preset abnormal probability threshold, the process of loading the abnormal physical resource node onto the chain is repeated. A new physical resource node is obtained from the reserve resource sub-pool, and on-chain verification and resource interaction three-layer verification are performed. When all verifications pass, the information of the corresponding abnormal isolation block sub-node and business processing sub-node is migrated to the new on-chain isolation block sub-node and business processing sub-node to continue the operation until the operation ends. The business processing sub-chain in the distributed coupled association mapping chain is directly disbanded and all business and configuration information is cleared. At the same time, the on-chain association mapping information corresponding to the business processing sub-node in the business processing sub-chain is cleared, and only the operation result is retained in the isolation block sub-chain.

10. A system for ensuring dedicated and secure access to resources on an elastic bare metal server, used to implement the method for ensuring dedicated and secure access to resources on an elastic bare metal server as described in any one of claims 1-9, characterized in that, include: The service chain module, isolation verification module, and repair module are coupled. The coupled service chain module, based on the smart contract configuration information configured on the elastically coupled blockchain, responds to user demand configuration information and combines a preset resource configuration adjustment model with the PoS+QoS consensus algorithm to obtain a distributed coupled association mapping chain. The distributed coupled association mapping chain is constructed by each block node on the elastic coupled blockchain, combining the corresponding configured resource requirements and the corresponding unique identity fingerprint. The isolation verification module is used to deploy and start the distributed coupled association mapping chain. At the same time, it uses a preset three-dimensional dynamic protection algorithm and the required completion progress to detect and judge the internal and external operating status of the distributed coupled association mapping chain in real time and obtain the judgment result. The repair module is used to feed back the judgment result to the resource configuration adjustment model and combine it with the preset security adjustment strategy library to perform real-time anomaly repair and resource uplink / downlink adjustment on the distributed coupled association mapping chain.

Citation Information

Patent Citations

  • Full-stack high-performance computing bare metal management service system and method

    CN115442316B

  • Bare metal server computing power scheduling platform

    CN119088575A

  • Intelligent contract driven workflow engine automatic execution method and system based on block chain

    CN120179419A

  • Method and system for releasing acceleration capability of physical GPU (Graphic Processing Unit) of cloud server

    CN120448133A

  • Communication scheduling network management intelligent optimization system and method based on AI dynamic decision

    CN120547039A

Cited By

  • Cloud security multi-level depth defense system construction method and system

    CN121396667A