A server monitoring and management method and system

By dividing the server monitoring and management system into passive, active, and security management layers, each with its own independent processor core, the system addresses the limitations of existing technologies in terms of scalability and security, and enables flexible configuration and power consumption management.

CN114968704BActive Publication Date: 2026-03-13SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-29
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing server monitoring and management systems, which use single-core BMC chips, suffer from insufficient scalability, poor configurability, and security vulnerabilities, making it difficult to meet the needs of complex application scenarios.

Method used

The server monitoring and management system is divided into a passive monitoring management layer, an active monitoring management layer, and a security management layer. Each layer has an independent processor core that executes its own functions. The system can selectively enable or disable the functions of the corresponding layer according to the application scenario, thereby achieving independent function upgrades and security separation.

Benefits of technology

It improves the scalability and configurability of the monitoring and management system, reduces the risk of security monitoring programs being tampered with, and adapts to the needs of different application scenarios by dynamically adjusting power consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114968704B_ABST
    Figure CN114968704B_ABST
Patent Text Reader

Abstract

This invention proposes a server monitoring and management method and system. The method includes: layering the server monitoring and management system; configuring multiple independent processor cores to execute the functions of each layer; and selectively enabling or disabling functions in corresponding layers, or shutting down corresponding processor cores, based on the server's application scenario. The beneficial effects of this invention include: by layering the monitoring and management system (including both software-level functional layering and hardware-level device and interface layering), different layer functions are run by different and independent processor cores. This ensures that upgrading functions in different layers does not affect the operation of functions in other layers, significantly reduces the ease with which security monitoring programs can be tampered with, and allows for selective enabling or disabling of corresponding functions or processor cores based on the actual application scenario of the server, thereby achieving adjustable power consumption for the monitoring and management system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of server technology, and in particular to a server monitoring and management method and system. Background Technology

[0002] Servers have extremely high reliability requirements for their own systems and underlying hardware and software, thus necessitating the configuration of an independent monitoring and management subsystem. Most existing server monitoring and management subsystems are implemented using BMC (Board Management Chip) technology. A monitoring and management subsystem implemented using BMC technology has an independent BMC chip, and an independent operating system runs within the BMC chip. To achieve monitoring and management functions independent of the main server system, a separate processor core needs to be integrated into the BMC chip to run an independent monitoring operating system.

[0003] However, as server application scenarios become increasingly complex, the monitoring scenarios of monitoring and management subsystems based on BMC technology are also becoming more complex. The approach of running a separate monitoring operating system on a single-core BMC chip is gradually proving insufficient. Specifically, this inadequacy is mainly reflected in the lack of scalability and sufficient configurability of the overall BMC chip architecture. Different chip products must be built using different processor cores for different application scenarios. For example, in scenarios with low power consumption requirements, the existing BMC monitoring operating system architecture has very little room for optimization; in most cases, a new BMC monitoring operating system that meets power consumption requirements must be developed. Furthermore, running all monitoring functions (including security verification programs for monitoring functions) on a single processor core also poses security risks.

[0004] Therefore, a completely new server monitoring and management method / system architecture is urgently needed in the field of server monitoring. Summary of the Invention

[0005] To address the aforementioned technical issues, Ben Amin proposes a server monitoring and management method, which includes: layering the server monitoring and management system; configuring multiple independent processor cores to execute the functions of each layer; and selectively enabling or disabling the functions in the corresponding layers, or shutting down the corresponding processor cores, based on the server's application scenario.

[0006] In one or more embodiments, the layering of the server monitoring and management system includes: dividing the server monitoring and management system into a passive monitoring management layer, an active monitoring management layer, and a security management layer; configuring the functions in the passive monitoring management layer as functions that are reserved by default; and configuring the functions in the active monitoring management layer and the security management layer as functions that can be selectively enabled or disabled.

[0007] In one or more embodiments, the passive monitoring management layer integrates one or more processor cores, multiple peripheral monitoring interfaces, a server CPU status monitoring interface, a remote monitoring interface, a first data bus, and multiple protocol processing modules mounted on the first data bus. Configuring multiple independent processor cores to execute the functions of each layer includes: configuring the one or more processor cores to perform data monitoring, data preprocessing, and data transmission; and performing corresponding operations on external devices and the server CPU that are communicatively connected to them according to received instructions.

[0008] In one or more embodiments, the active monitoring management layer integrates one or more processor cores, a storage module, and corresponding storage interfaces. Configuring multiple independent processor cores to execute the functions of each layer includes: configuring the one or more processor cores to obtain and execute corresponding operating system programs and applications through the storage interfaces; and calling the corresponding interfaces of the passive monitoring management layer according to the instructions of the applications to obtain the corresponding device status, and performing corresponding operation management based on the corresponding device status.

[0009] In one or more embodiments, the operating system of the active monitoring management layer is configured to allow the configuration of customized monitoring applications into the storage module via the storage interface.

[0010] In one or more embodiments, the operating system is further configured to allow the startup or shutdown of corresponding monitoring applications via operation commands.

[0011] In one or more embodiments, the security management layer integrates one or more processor cores, multiple security verification programs, multiple data encryption and decryption algorithms, and multiple extension interfaces. The configuration of multiple independent processor cores to execute the functions of each layer includes: configuring the one or more processors to perform trust measurement on the corresponding devices through the corresponding interfaces of the passive monitoring management layer and to perform encryption and decryption operations on the corresponding device data; and performing secure boot detection on the operating system program and monitoring application through the storage interface of the active management layer.

[0012] In one or more embodiments, multiple extension interfaces of the security management layer are configured to extend external algorithm modules or security detection modules.

[0013] In one or more embodiments, the operating system of the security management layer is configured to allow the acquisition of algorithms and security detection programs in the extension module to perform corresponding device-measurable or program-secure boot detection.

[0014] In a second aspect of the invention, a server monitoring and management system is provided, comprising: a passive monitoring and management subsystem, wherein the passive monitoring and management subsystem integrates one or more processor cores, multiple peripheral monitoring interfaces, a server CPU status monitoring interface, a remote monitoring interface, a first data bus, and multiple protocol processing modules mounted on the first data bus; wherein the one or more processor cores are configured to perform data monitoring, data preprocessing, data transmission, and corresponding operations on external devices and the server CPU connected to them according to received instructions; and an active monitoring and management subsystem, wherein the active monitoring and management subsystem integrates one or more processor cores, a storage module, and a corresponding storage interface; wherein the passive ... One or more processor cores obtain and execute corresponding operating system programs and applications through the storage interface; and call the corresponding interface of the passive monitoring management layer according to the instructions of the application to obtain the corresponding device status, and perform corresponding operation management according to the corresponding device status; a security management subsystem, the security management subsystem integrating one or more processor cores, multiple security verification programs, multiple data encryption and decryption algorithms, and multiple expansion interfaces; wherein, the one or more processors are configured to perform trust measurement on the corresponding devices through the corresponding interface of the passive monitoring management layer, and perform encryption and decryption operations on the corresponding device data; and perform secure boot detection on the operating system program and monitoring application through the storage interface of the active management layer.

[0015] The beneficial effects of this invention include: by layering the monitoring and management system (including functional layering at the software level and device / interface layering at the hardware level), different layer functions are run by different and independent processor cores, thus ensuring that upgrading functions in different layers does not affect the operation of functions in other layers; furthermore, by having the programs for software / hardware monitoring and the security monitoring programs for software / hardware (used for security detection of software / hardware) run on processor cores in different layers, the ease with which the security monitoring programs can be tampered with can be greatly reduced; and during server monitoring, corresponding functions can be selectively enabled or disabled, or corresponding processor cores can be turned off, based on the actual application scenario of the server, thereby achieving adjustable power consumption of the monitoring and management system. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other embodiments can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart of a server monitoring and management method according to the present invention.

[0018] Figure 2 This is a schematic diagram of the structure of a server monitoring and management system according to the present invention. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to specific examples and the accompanying drawings.

[0020] It should be noted that all uses of "first" and "second" in the embodiments of the present invention are for the purpose of distinguishing two entities or parameters with the same name but different names. It is clear that "first" and "second" are only for the convenience of expression and should not be construed as limiting the embodiments of the present invention. Subsequent embodiments will not explain this in detail.

[0021] To address the shortcomings of existing server monitoring and management systems, this invention proposes a novel server monitoring and management system architecture, aiming to improve its scalability, configurability, and dynamic energy consumption adjustment. To more clearly illustrate the technical solution of this invention, the following description will be provided in conjunction with specific accompanying drawings.

[0022] Figure 1 This is a flowchart of a server monitoring and management method according to the present invention. To address the problems of existing server monitoring and management system architectures being unable to be easily expanded, configured, or have their power consumption adjusted, the method proposed in this invention includes: Step S1, layering the server monitoring and management system; Step S2, configuring multiple independent processor cores to execute the functions of each layer; Step S3, selectively enabling or disabling the functions in the corresponding layers, or shutting down the corresponding processor cores, based on the server's application scenario.

[0023] Specifically, because the existing server monitoring and management system architecture integrates software / hardware monitoring and security monitoring into a single program, upgrading any one of these components requires modifying the entire program. Furthermore, the upgrade process necessitates halting server monitoring, rendering the server unmanageable. Additionally, since all programs run on a single processor core, especially since running software / hardware monitoring and security monitoring programs on the same core, the security monitoring program is susceptible to tampering, thus posing a security vulnerability.

[0024] To overcome the aforementioned problems, this invention employs a layered approach to the monitoring and management system (including functional layering at the software level and device / interface layering at the hardware level). This allows different layer functions to run on different and independent processor cores, ensuring that upgrades to functions in different layers do not affect the operation of functions in other layers. Furthermore, by having the software / hardware monitoring program and the software / hardware security monitoring program (used for security detection) run on different layer processor cores, the ease with which the security monitoring program can be tampered with is significantly reduced. Moreover, during server monitoring, corresponding functions can be selectively enabled or disabled, or specific processor cores can be shut down, based on the actual application scenario of the server, thereby achieving adjustable power consumption for the monitoring and management system.

[0025] Furthermore, by leveraging this layered approach, the present invention can also configure operating systems with corresponding permissions for the functions of different layers to better support the scalability and configurability of different layers (mainly reflected in the proactive monitoring management layer and security management, the specific analysis of which will be explained later).

[0026] In a preferred embodiment, the present invention performs functional layering of the server monitoring and management system, including: step S11, dividing the server monitoring and management system into a passive monitoring management layer, an active monitoring management layer, and a security management layer; step S12, configuring the functions in the passive monitoring management layer as functions to be reserved by default; and step S13, configuring the functions in the active monitoring management layer and the security management layer as functions that can be selectively enabled or disabled.

[0027] Specifically, in this embodiment, the invention is layered according to whether a function can be disabled and its functional characteristics; it separates the status monitoring of software / hardware from the security monitoring of software / hardware, and further divides status monitoring into passive monitoring management and active monitoring management. Functions in the passive monitoring management layer are reserved by default, meaning that during normal operation, monitoring functions set to be reserved by default cannot be easily disabled or turned off, thus avoiding the loss of control of important monitoring functions due to misoperation. Active monitoring and security monitoring are less important than passive monitoring; therefore, functions in the active monitoring management layer and the security management layer are configured to be selectively enabled or disabled. For example, when the server is in a trusted environment, relevant functions in the active monitoring management layer can be selectively disabled to reduce monitoring complexity. Another example is when the server in the trusted environment needs to reduce power consumption; one or more processor cores of the main control monitoring management layer can be directly shut down to achieve the purpose of reducing power consumption. Yet another example is in a server cluster, the active monitoring management layer and the security management layer, as well as the applications managed by them, are selectively enabled according to the importance of different servers.

[0028] In a preferred embodiment, the hardware devices and interfaces in the passive monitoring management layer include one or more processor cores, multiple peripheral monitoring interfaces, a server CPU status monitoring interface, a remote monitoring interface, and / or a first data bus, as well as multiple protocol processing modules mounted on the first data bus. Correspondingly, the functional layering in the passive monitoring management layer includes configuring one or more processor cores to perform tasks including data monitoring, data preprocessing, data transmission, and executing corresponding operations on external devices and the server's CPU according to received instructions. In this approach, multiple applications can run on the same processor core or on multiple processor cores respectively; wherein, the remote monitoring interface is a network interface used to monitor remote devices.

[0029] In an optional embodiment, the operating system in the passive monitoring management layer is configured to disallow modification of monitoring applications running in its environment to prevent malicious tampering.

[0030] In one optional embodiment, when the passive monitoring management layer has multiple processor cores, the multiple processor cores monitor each other's heartbeats; when any one of the multiple processor cores fails, the normal processor core sends a task request to the active management layer, requesting to load the corresponding function in the active management layer to replace the failed processor core in performing the corresponding monitoring function, or the active monitoring management layer directly takes over the corresponding monitoring function temporarily.

[0031] In a preferred embodiment, the hardware devices and interfaces in the active monitoring management layer include one or more processor cores, a storage module, and corresponding storage interfaces. Accordingly, the functional layering in the active monitoring management layer includes configuring one or more processor cores to obtain and execute corresponding operating system programs and applications through the storage interfaces; and invoking the corresponding interfaces of the passive monitoring management layer according to the instructions of the applications to obtain the corresponding device status, and performing corresponding operation management based on the corresponding device status.

[0032] In an optional embodiment, the operating system in the active monitoring management layer is configured to allow users to configure monitoring functions themselves and to selectively start or disable corresponding monitoring programs. Based on this, the active monitoring management layer can set up some backup monitoring functions. These backup monitoring programs are not run under normal circumstances, but are only invoked or run when a corresponding instruction is received from the passive monitoring management layer, thereby replacing the corresponding monitoring functions in the passive monitoring management layer.

[0033] In a preferred embodiment, the hardware devices and interfaces in the security management layer include one or more processor cores and multiple expansion interfaces; the functional layering of the security management layer includes configuring one or more processors to perform trust measurement on the corresponding devices through the corresponding interfaces of the passive monitoring management layer, and to perform encryption and decryption operations on the corresponding device data; and to perform secure boot detection on the operating system program and monitoring application through the storage interface of the active management layer.

[0034] In an optional embodiment, the operating system of the security management layer is configured to allow the acquisition of algorithms and security detection programs in the extension module through an extension interface to perform corresponding device-measurable or program security boot detection, thereby enabling customization of monitoring functions.

[0035] In an optional embodiment, to verify the security of the extension module, the security management layer will have a preset naming method for the extension module and encrypt it; when the extension module joins the security management layer through the extension interface, the name of the extension module will be obtained and compared with the pre-saved name of the extension module to determine the reliability of the extension module.

[0036] Through the methods proposed in the above embodiments, this invention proposes a hierarchical multi-core chip architecture that separates and implements functions originally integrated onto a single processor core. This includes independent security management layer, active control management layer, and passive monitoring management layer. By configuring different permissions for the operating systems of different layers, each layer can perform monitoring and management functions while also achieving different combinations of power consumption, performance, and security through configuration. This allows the chip to meet the needs of more application scenarios and expand its applicability without requiring frequent modifications to the chip design.

[0037] In a second aspect of the invention, a server monitoring and management system is proposed, which consists of an integrated chip. Figure 2 This is a structural view of a server monitoring and management system according to the present invention. Figure 2 As shown, the server monitoring and management system of the present invention includes: a passive monitoring and management subsystem 100, an active monitoring and management subsystem 200, and a security management subsystem 300, which are interconnected via a second on-chip bus; wherein, the passive monitoring and management subsystem 100 integrates one or more processor cores, multiple peripheral monitoring interfaces, a server CPU status monitoring interface, a remote monitoring interface, a first data bus, and multiple protocol processing modules mounted on the first data bus; it configures one or more processor cores to perform data monitoring, data preprocessing, data transmission, and to perform corresponding operations on external devices and the server CPU that are connected to it according to received instructions; wherein, the remote monitoring interface is a network interface used to monitor remote devices.

[0038] The active monitoring and management subsystem 200 integrates one or more processor cores, storage modules, and corresponding storage interfaces. It is configured to obtain and execute the corresponding operating system programs and applications through the storage interfaces, and to call the corresponding interfaces of the passive monitoring management layer according to the instructions of the application programs to obtain the corresponding device status, and to perform corresponding operation management according to the corresponding device status.

[0039] The 300 Security Management Subsystem integrates one or more processor cores, multiple security verification programs, multiple data encryption and decryption algorithms, and multiple expansion interfaces. Among them, one or more processors are configured to perform trust measurement on the corresponding devices through the corresponding interfaces of the passive monitoring management layer, and to perform encryption and decryption operations on the corresponding device data; and to perform secure boot detection on the operating system program and monitoring application through the storage interface of the active management layer.

[0040] In this embodiment, the present invention not only layers the existing monitoring and management system at the hardware level, but also layers it according to whether functions can be disabled and their characteristics. It separates the status monitoring of software / hardware from the security monitoring of software / hardware, further dividing status monitoring into passive monitoring management and active monitoring management. Functions in the passive monitoring management subsystem 100 are reserved by default; that is, during normal operation, monitoring functions set to be reserved by default cannot be easily disabled or turned off, thus avoiding the loss of control of important monitoring functions due to misoperation. Active monitoring and security monitoring are less important than passive monitoring; therefore, functions in the active monitoring management subsystem and security management subsystem are configured to be selectively enabled or disabled. For example, when the server is in a trusted environment, relevant functions in the active monitoring management subsystem 200 can be selectively disabled to reduce monitoring complexity. As another example, when the server in the trusted environment also needs to reduce power consumption, one or more processor cores of the main control monitoring management subsystem 200 can be directly shut down to achieve the purpose of reducing power consumption. For example, in a server cluster, applications managed by the proactive monitoring and management subsystem 200 and the security management subsystem 300, or both, can be selectively enabled based on the importance of different servers.

[0041] In an optional embodiment, the operating system in the passive monitoring management subsystem is configured to disallow modification of monitoring applications running in its environment to prevent malicious tampering.

[0042] In one optional embodiment, when the passive monitoring and management subsystem has multiple processor cores, the multiple processor cores monitor each other's heartbeats; when any one of the multiple processor cores fails, the normal processor core sends a task request to the active management subsystem, requesting to load the corresponding function in the active management subsystem to replace the failed processor core in performing the corresponding monitoring function, or the active monitoring and management subsystem directly takes over the corresponding monitoring function temporarily.

[0043] In an optional embodiment, the operating system in the active monitoring and management subsystem is configured to allow users to configure monitoring functions themselves and to selectively start or disable corresponding monitoring programs. Based on this, the active monitoring and management subsystem can set up some backup monitoring functions. These backup monitoring programs are not run under normal circumstances, but are only invoked or run when a corresponding instruction is received from the passive monitoring and management subsystem, thereby replacing the corresponding monitoring functions in the passive monitoring and management subsystem.

[0044] In an optional embodiment, the operating system of the security management subsystem is configured to allow the acquisition of algorithms and security detection programs in the extension module via an extension interface to perform corresponding device measurability or program security boot detection.

[0045] In an optional embodiment, to verify the security of the extension module, the security management subsystem will preset and encrypt the naming method of the extension module; when the extension module is added to the security management subsystem through the extension interface, the name of the extension module will be obtained and compared with the pre-saved name of the extension module to determine the reliability of the extension module.

[0046] Through the server monitoring and management system proposed in the above embodiments, this invention proposes a hierarchical multi-core chip architecture. The functions originally integrated on a single processor core are layered and implemented separately, including an independent security management subsystem, an active control management subsystem, and a passive monitoring management subsystem. By configuring different permissions for the operating systems of different layers, each layer can complete the monitoring and management functions while also achieving different combinations of power consumption, performance, and security through configuration. This allows the chip to meet the needs of more application scenarios without frequent changes to the chip design, thus expanding its applicability.

[0047] The above are exemplary embodiments disclosed in this invention. However, it should be noted that various changes and modifications can be made without departing from the scope of the embodiments of this invention as defined by the claims. The functions, steps, and / or actions of the methods according to the disclosed embodiments described herein do not need to be performed in any particular order. Furthermore, although the elements disclosed in the embodiments of this invention may be described or claimed individually, they may be understood as multiple unless explicitly limited to a singular number.

[0048] It should be understood that, as used herein, the singular form “a” is intended to include the plural form as well, unless the context clearly supports an exception. It should also be understood that, as used herein, “and / or” refers to any and all possible combinations of one or more of the associated listed items.

[0049] The embodiment numbers disclosed in the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0050] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention (including the claims) is limited to these examples. Within the framework of the invention, technical features of the above embodiments or different embodiments can be combined, and many other variations of different aspects of the invention exist, which are not provided in the details for the sake of brevity. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the invention should be included within the protection scope of the invention.

Claims

1. A method of server monitoring management, characterized by, The method comprises: Layering the server monitoring management system; Configuring multiple independent processor cores to execute the functions of each layer respectively; According to the application scenario of the server, selectively enable or shield the functions in the corresponding layer, or close the corresponding processor core; Wherein, the layering of the server monitoring management system comprises: dividing the server monitoring management system into passive monitoring management layer, active monitoring management layer and security management layer; configuring the functions in the passive monitoring management layer as default reserved functions; configuring the functions in the active monitoring management layer and the security management layer as selectable enabled or shielded functions; The passive monitoring management layer integrates one or more processor cores, multiple peripheral monitoring interfaces, CPU state monitoring interfaces of the server, remote monitoring interfaces, a first data bus and multiple protocol processing modules mounted on the first data bus, and the configuration of multiple independent processor cores to execute the functions of each layer respectively comprises: configuring the one or more processor cores to execute data monitoring, data preprocessing and data transmission; and performing corresponding operations on the external devices and the CPU of the server in communication connection according to the received instructions; The active monitoring management layer integrates one or more processor cores, a storage module and a corresponding storage interface, and the configuration of multiple independent processor cores to execute the functions of each layer respectively comprises: configuring the one or more processor cores to obtain corresponding operating system programs and application programs through the storage interface and execute them; and calling the corresponding interfaces of the passive monitoring management layer according to the instructions of the application program to obtain the corresponding device state, and performing corresponding operation management according to the corresponding device state; The security management layer integrates one or more processor cores, multiple security verification programs, multiple data encryption and decryption algorithms, and multiple expansion interfaces, and the configuration of multiple independent processor cores to execute the functions of each layer respectively comprises: configuring the one or more processors to perform trust measurement on the corresponding devices through the corresponding interfaces of the passive monitoring management layer, and perform encryption and decryption operations on the corresponding device data; and performing security startup detection on the operating system program and monitoring application program through the storage interface of the active monitoring management layer.

2. The server monitoring management method of claim 1, wherein, The operating system of the active monitoring management layer is configured to allow the configuration of customized monitoring application programs in the storage module through the storage interface.

3. The server monitoring management method of claim 2, wherein, The operating system is also configured to allow the control of starting or shielding the corresponding monitoring application program through operation instructions.

4. The server monitoring management method of claim 1, wherein, The multiple expansion interfaces of the security management layer are configured to expand external algorithm modules or security detection modules.

5. The method of claim 4, wherein, The operating system of the security management layer is configured to allow the acquisition of algorithms and security detection programs in the expansion module to perform corresponding device measurement or program security startup detection.

6. A server monitoring management system for executing the server monitoring management method according to any one of claims 1 to 5, characterized by Comprise: The passive monitoring management subsystem is integrated with one or more processor cores, a plurality of peripheral monitoring interfaces, a CPU state monitoring interface of a server, a remote monitoring interface, a first data bus, and a plurality of protocol processing modules mounted on the first data bus; wherein the one or more processor cores are configured to perform data monitoring, data preprocessing, and data transmission; and perform corresponding operations on external devices and the CPU of the server in communication connection therewith according to received instructions, and functions in the passive monitoring management layer are configured as default reserved functions; The active monitoring management subsystem is integrated with one or more processor cores, a storage module, and a corresponding storage interface; wherein the one or more processor cores are configured to obtain corresponding operating system programs and application programs through the storage interface and execute them; and call corresponding interfaces of the passive monitoring management layer to obtain corresponding device states according to instructions of the application programs, and perform corresponding operation management according to the corresponding device states, and functions in the active monitoring management layer are configured as selectable enabled or shielded functions; The security management subsystem is integrated with one or more processor cores, a plurality of security verification programs, a plurality of data encryption and decryption algorithms, and a plurality of extension interfaces; wherein the one or more processor cores are configured to perform trust measurement on corresponding devices through corresponding interfaces of the passive monitoring management layer, and perform encryption and decryption operations on corresponding device data; and perform security startup detection on the operating system programs and monitoring application programs through the storage interface of the active monitoring management layer, and functions in the security management layer are configured as selectable enabled or shielded functions.

Citation Information

Patent Citations

  • Hierarchical data monitoring system and monitoring method

    CN103365756A

  • Video surveillance network intelligent information security integrated management system

    CN108600236A

  • Layered and segmented monitoring and intervention method for large-scale parallel test tasks

    CN113326209A