Security Management Method, Device, Equipment and Storage Medium for Back-End Extended Data
By real-time monitoring and optimizing the performance of the back-end expansion cabinet, the storage system reliability problem caused by the lack of management modules in the prior art is solved, and higher system stability and reliability are achieved.
Patent Information
- Application Number
- CN202211362470.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-02
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-11-02
AI Technical Summary
The lack of independent management modules in the prior art monitors, warnings, and adjusts and optimizes the back-end expansion cabinet, resulting in abnormalities in a single expansion cabinet affecting data access to other expansion cabinets and reducing the reliability of the entire storage system.
By obtaining front-end business model information, determining the theoretical performance data of each back-end module, monitoring the actual performance data in real time, determining the working status, and generating warning information based on abnormal status, adjusting the connection method of the back-end expansion cabinet to optimize the system.
Real-time monitoring and optimization of the back-end storage system is realized, the reliability and stability of the system are improved, and the continuous availability of front-end services is ensured.
Smart Images

Figure CN115757018B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the technical field of backend storage, and more particularly, to a method, device, equipment, and storage medium for secure management of backend extended data. Background Art
[0002] With the development of storage technology, array storage, especially high-end array storage, has been more and more widely used, which has the characteristics of large storage capacity and high security. Currently, array storage generally uses an external expansion cabinet to expand data disks, and external data disks are carried on the backend expansion cabinet. Therefore, the reliability of each backend module including the backend expansion cabinet needs to be ensured. In the prior art, there is no independent management module to monitor, give early warnings, and adjust and optimize each backend module including the backend expansion cabinet.
[0003] Since there is no independent management module to monitor, give early warnings, and adjust and optimize each backend module including the backend expansion cabinet, it is easy to cause the abnormality of a single expansion cabinet and affect the data access of other expansion cabinets, thus affecting the reliability of the entire storage system. Summary of the Invention
[0004] The embodiments of the present application provide a method, device, equipment, and storage medium for secure management of backend extended data, aiming to improve the reliability of the backend storage system.
[0005] In the first aspect of the embodiments of the present application, a method for secure management of backend extended data is provided. The method includes:
[0006] Obtain the front-end service model information corresponding to the current front-end service;
[0007] According to the front-end service model information, determine the theoretical performance data of each backend module corresponding to the front-end service model. Each backend module includes: a backend main control module, a backend expansion module, and a backend expansion cabinet;
[0008] Monitor the actual performance data of each backend module;
[0009] According to the magnitude relationship between the theoretical performance data and the actual performance data of each backend module, determine the working state of each backend module;
[0010] When there is a backend module with an abnormal working state among each backend module, generate a corresponding warning message according to the type of the working state of the backend module, and correspondingly adjust the connection mode of the backend expansion cabinet.
[0011] Optionally, the determining the theoretical performance data of each backend module corresponding to the front-end service model according to the front-end service model information includes:
[0012] Determine the parameters of the front-end service model according to the front-end service model information;
[0013] According to the parameters of the front-end service model, search for the theoretical performance data of each back-end module under the front-end service model in the database.
[0014] Optionally, determining the working status of each back-end module according to the theoretical performance data and the actual performance data of each back-end module includes:
[0015] When the current management mode is the normal mode, for each back-end module, when it is monitored that within a first preset time period, the range of the actual performance data of the back-end module exceeding the theoretical performance data is greater than a first preset threshold, enter the first test mode;
[0016] In the first test mode, when it is detected that the service pressure at the front end is less than a first preset pressure threshold, perform a simulation test on the back-end module for a second preset time period to obtain a first simulation test result;
[0017] When the first simulation test result is that the range of the actual performance data exceeding the theoretical performance data is greater than a first preset threshold, determine that the type of the working status of the back-end module is the super-performance status;
[0018] When it is monitored that within a first preset time period, the range of the actual performance data of the back-end module being lower than the theoretical performance data exceeds a second preset threshold, determine that the type of the working status of the back-end module is the suspicious status;
[0019] When the type of the working status of the back-end module is the suspicious status, in response to a mode switching instruction, switch the current management mode to the high-reliability mode;
[0020] In the high-reliability mode, when it is monitored that within a first preset time period, the range of the actual performance data of the back-end module exceeding the theoretical performance data is greater than a first preset threshold, enter the second test mode;
[0021] In the second test mode, when it is detected that the service pressure at the front end is less than a second preset pressure threshold, perform a simulation test on the back-end module for a second preset time period to obtain a second simulation test result;
[0022] When the second simulation test result is that the range of the actual performance data exceeding the theoretical performance data is greater than a first preset threshold, determine that the type of the working status of the back-end module is the super-performance status;
[0023] When it is monitored that within the first preset time period, the actual performance data of the backend module is lower than the range of the theoretical performance data by more than a third preset threshold, it is determined that the working state type of the backend module is a low-performance state.
[0024] Optionally, generating a corresponding warning message according to the type of the working state of the backend module and correspondingly adjusting the connection mode of the backend expansion cabinet includes:
[0025] When the type of the working state of the backend module is a super-performance state, a secondary warning message is generated, and the secondary warning message is used to remind the management personnel that the actual performance of the backend module is higher than the theoretical performance;
[0026] When the type of the working state of the backend module is a suspicious state, a tertiary warning message is generated, and the tertiary warning message is used to remind the management personnel that the backend module may have a fault and needs to be switched to the high-reliability mode for further testing;
[0027] When the type of the working state of the backend module is a low-performance module, a quaternary warning message is generated, and the quaternary warning message is used to remind the management personnel that the backend module has a fault;
[0028] When generating the quaternary warning message, the connection mode of the backend expansion cabinet is switched between the near end and the far end.
[0029] Optionally, the method further includes:
[0030] When sending the secondary warning message, a database update prompt is sent simultaneously;
[0031] When sending the tertiary warning message, an inquiry message is sent simultaneously, and the inquiry message is used to inquire whether to switch the current management mode to the high-reliability mode.
[0032] Optionally, after the connection mode of the backend expansion cabinet is switched between the near end and the far end, the method further includes:
[0033] When it is monitored that within the third preset time period, the range by which the actual performance data of the backend module is lower than the theoretical performance data does not exceed the third preset threshold, the quaternary warning message is cancelled.
[0034] Optionally, the method further includes:
[0035] In response to an operation of creating a disk array, information of the backend expansion cabinet is obtained;
[0036] According to the information of the backend expansion cabinet, a disk distribution list of the disk array in the backend expansion cabinet is generated.
[0037] Optionally, the method further includes:
[0038] When the number of the backend expansion cabinets does not meet the distribution of the disk array, a first-level warning message is generated, and the first-level warning message is used to remind the management personnel that the number of the backend expansion cabinets is insufficient;
[0039] Determine the required quantity ratio of the backend expansion cabinets according to the distribution of the disk array.
[0040] The second aspect of the embodiments of the present application provides a security management device for backend expansion data, and the device includes:
[0041] A model information acquisition module, configured to acquire the front-end service model information corresponding to the current front-end service;
[0042] A theoretical performance data acquisition module, configured to determine the theoretical performance data of each backend module corresponding to the front-end service model according to the front-end service model information, and each backend module includes: a backend main control module, a backend expansion module, and a backend expansion cabinet;
[0043] An actual performance data monitoring module, configured to monitor the actual performance data of each backend module;
[0044] A working state determination module, configured to determine the working state of each backend module according to the magnitude relationship between the theoretical performance data and the actual performance data of each backend module;
[0045] A backend warning adjustment module, configured to generate a corresponding warning message according to the type of the working state of the backend module and correspondingly adjust the connection mode of the backend expansion cabinet when there is a backend module with an abnormal working state among each backend module.
[0046] Optionally, the theoretical performance data acquisition module includes:
[0047] A model parameter acquisition sub-module, configured to determine the parameters of the front-end service model according to the front-end service model information;
[0048] A theoretical performance acquisition sub-module, configured to search for the theoretical performance data of each backend module under the front-end service model in the database according to the parameters of the front-end service model.
[0049] Optionally, the working state determination module includes:
[0050] A first test mode start sub-module, configured to, when the current management mode is the normal mode, for each backend module, when it is monitored that within a first preset time period, the actual performance data of the backend module exceeds the range of the theoretical performance data by more than a first preset threshold, enter the first test mode;
[0051] The first simulation test result acquisition sub-module is used to, in the first test mode, when it is detected that the business pressure at the front end is less than the first preset pressure threshold, perform a simulation test on the back-end module for a duration of the second preset time period to obtain the first simulation test result;
[0052] The first status determination sub-module is used to, when the first simulation test result shows that the range where the actual performance data exceeds the theoretical performance data is greater than the first preset threshold, determine that the type of the working status of the back-end module is the super-performance status;
[0053] The second status determination sub-module is used to, when it is monitored that within the first preset time period, the range where the actual performance data of the back-end module is lower than the theoretical performance data exceeds the second preset threshold, determine that the type of the working status of the back-end module is the suspicious status;
[0054] The management mode switching sub-module is used to, when the type of the working status of the back-end module is the suspicious status, in response to a mode switching instruction, switch the current management mode to the high-reliability mode;
[0055] The second test mode startup sub-module is used to, in the high-reliability mode, when it is monitored that within the first preset time period, the range where the actual performance data of the back-end module exceeds the theoretical performance data is greater than the first preset threshold, enter the second test mode;
[0056] The second simulation test result acquisition sub-module is used to, in the second test mode, when it is detected that the business pressure at the front end is less than the second preset pressure threshold, perform a simulation test on the back-end module for a duration of the second preset time period to obtain the second simulation test result;
[0057] The third status determination sub-module is used to, when the second simulation test result shows that the range where the actual performance data exceeds the theoretical performance data is greater than the first preset threshold, determine that the type of the working status of the back-end module is the super-performance status;
[0058] The fourth status determination sub-module is used to, when it is monitored that within the first preset time period, the range where the actual performance data of the back-end module is lower than the theoretical performance data exceeds the third preset threshold, determine that the type of the working status of the back-end module is the low-performance status.
[0059] Optionally, the back-end early warning adjustment module includes:
[0060] The first warning message generation sub-module is used to, when the type of the working status of the back-end module is the super-performance status, generate a secondary warning message, and the secondary warning message is used to remind the management personnel that the actual performance of the back-end module is higher than the theoretical performance;
[0061] A second warning information generating submodule is used to generate a third-level warning message when the working state of the back-end module is a suspicious state, and the third-level warning message is used to remind the management personnel that the back-end module may have a fault and needs to be switched to a high-reliability mode for further testing;
[0062] A third warning information generating submodule is used to generate a level 4 warning information when the working state of the backend module is a low-performance module, and the level 4 warning information is used to remind the management personnel that the backend module has a fault;
[0063] The connection mode switching submodule is used to switch the connection mode of the rear-end expansion cabinet between the far end and the near end when the fourth-level warning information is generated.
[0064] Optionally, the device further comprises:
[0065] A database update prompt submodule, used to send a database update prompt at the same time as sending the secondary warning information;
[0066] The inquiry information sending submodule is used to send inquiry information at the same time as sending the third-level warning information, and the inquiry information is used to inquire whether to switch the current management mode to the high-reliability mode.
[0067] Optionally, the device further comprises:
[0068] The warning information cancellation submodule is used to cancel the fourth-level warning information when it is monitored that the actual performance data of the back-end module is lower than the theoretical performance data within a third preset time period by no more than a third preset threshold.
[0069] Optionally, the device further comprises:
[0070] A back-end expansion cabinet information obtaining submodule, used for obtaining the information of the back-end expansion cabinet in response to the operation of creating a disk array;
[0071] The disk distribution list generating submodule is used to generate a disk distribution list of the disk array in the back-end expansion cabinet according to the information of the back-end expansion cabinet.
[0072] Optionally, the device further comprises:
[0073] A first-level warning information generating module, used for generating a first-level warning information when the number of the back-end expansion cabinets does not meet the distribution of the disk array, wherein the first-level warning information is used to remind the management personnel that the number of the back-end expansion cabinets is insufficient;
[0074] The quantity ratio determination module is used to determine the quantity ratio of the required back-end expansion cabinets according to the distribution of the disk array.
[0075] In the third aspect of the embodiments of the present application, a readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the method described in the first aspect of the present application are implemented.
[0076] In the fourth aspect of the embodiments of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the method described in the first aspect of the present application are implemented.
[0077] By using the security management method for backend extended data provided in the present application, obtain the front-end service model information corresponding to the current front-end service; according to the front-end service model information, determine the theoretical performance data of each backend module corresponding to the front-end service model, and the backend modules include: a backend main control module, a backend extension module, and a backend extension cabinet; monitor the actual performance data of each backend module; according to the magnitude relationship between the theoretical performance data and the actual performance data of each backend module, determine the working state of each backend module; when there is a backend module with an abnormal working state among the backend modules, generate a corresponding warning message according to the type of the working state of the backend module, and correspondingly adjust the connection mode of the backend extension cabinet. In the present application, by obtaining the current front-end service model information, determining the theoretical performance data of each backend module corresponding to the front-end service model, and then real-time monitoring the actual performance data of each backend module under the current service, the working state and performance of each backend module are monitored in real time. According to the working state of each backend module, for each backend module, compare its actual performance data with the theoretical performance data to determine the working state of each backend module, realizing real-time monitoring of the working state of the backend module, generating corresponding warning messages according to the working state of each backend module, realizing warning of problems occurring in each backend module, and at the same time correspondingly adjusting the connection mode of the backend extension cabinet, realizing real-time adjustment and optimization of the extension cabinet. Through real-time monitoring, warning, and adjustment and optimization of each backend module, it is ensured that the backend storage system can always provide highly reliable services for the front-end service, and the security and stability of backend data storage are ensured. Description of the Drawings
[0078] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0079] Figure 1It is a schematic structural diagram of a backend storage system proposed in an embodiment of the present application;
[0080] Figure 2 It is a flowchart of a method for secure management of backend extended data proposed in an embodiment of the present application;
[0081] Figure 3 It is a schematic connection diagram of a backend expansion cabinet proposed in an embodiment of the present application;
[0082] Figure 4 It is a schematic diagram of a device for secure management of backend extended data proposed in an embodiment of the present application. Detailed implementation manners
[0083] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0084] The method in the embodiments of the present application is to improve the reliability of the backend storage system. Refer to Figure 1 , Figure 1 It is a schematic structural diagram of a backend storage system proposed in an embodiment of the present application, as Figure 1As shown in the figure, the backend storage system includes: a CPU module, a backend main control module, a backend expansion module, a backend expansion cabinet, a Backend Extended Data Security (BEDS) module, an indication module, a serial port module, and a wireless module. The backend extended data security management module is used to manage the working states of the CPU module, the backend main control module, the backend expansion module, and the backend expansion cabinet in real time, and programmable logic devices such as ARM can be used. The CPU module is used to store the main control unit, carry the storage system, and send the current service model to the backend extended data security management module. The backend main control module is used to implement various functions of the backend storage and control the backend storage. Generally, it is a control chip such as a SAS controller or a PCIE switch or an external plug-in IO card according to different backend expansion cabinets. The backend expansion module is used for the expansion of backend functions and backend storage. Generally, it is a SAS expander expansion chip or an external plug-in IO card according to different backend expansion cabinets. The backend expansion cabinet is used to store data, generally used to carry hard disks or memories, and generally carries dual-port hard disks or SSDs with SAS interfaces or NVME interfaces. The serial port module is used for information interaction between the outside world and the backend extended data security management module. The wireless module is used to convert the signal of the serial port module into wireless signals such as WIFI, so that the outside world can interact with the backend data security management module without using a physical serial cable. The indication module is used to indicate the status of the current backend data security management module to the outside, and is directly controlled by the serial port module.
[0085] Reference Figure 2 , Figure 2 is a flowchart of a method for securing management of backend extended data proposed in an embodiment of this application. As Figure 2 shown, the method includes the following steps:
[0086] S11: Obtain the front-end service model information corresponding to the current front-end service.
[0087] In this embodiment, the front-end business model refers to the relevant parameters of the data generated by the business being carried out by the front-end server. The business model information includes the size of the data block that needs to be stored for this business. The data storage can be random access or sequential access, and the operations can be read operations or write operations, etc. A data block is a group or several groups of records arranged continuously in sequence, and it is the data unit for transmission between the main memory and the input device, output device, or external memory. Random storage of data is direct storage, where the position of an element can be directly accessed through a subscript, regardless of the storage position. For example, in an array, when accessing the Nth data, it is not necessary to access the first N - 1 data, and the Nth data can be directly accessed and stored. Sequential access, also called non-random access, cannot be accessed through a subscript. When accessing the Nth data, it is necessary to first access the first N - 1 data. For example, in a linked list.
[0088] In this embodiment, when the front-end server executes a business, the back-end data security management module obtains the model information of the business model corresponding to the current business from the CPU module. The CPU module stores the business model of the business being executed by the front-end server, and the CPU module transmits the stored model information of the business model to the back-end data security management module through the data transmission interface.
[0089] Exemplarily, the model information of the front-end business model is large data blocks, random data, read operations, or it can also be small data blocks, sequential data, write operations, etc.
[0090] S12: Determine the theoretical performance data of each back-end module corresponding to the front-end business model according to the front-end business model information. The back-end modules include: CPU module, back-end main control module, back-end expansion module, and back-end expansion cabinet.
[0091] In this embodiment, the back-end modules include the CPU module, back-end main control module, back-end expansion module, and back-end expansion cabinet. The performance data of each back-end module corresponding to the front-end business model is the storage performance-related data of the CPU module, back-end main control module, back-end expansion module, and back-end expansion cabinet when the front-end server executes a business, including IOPS (read / write speed), bandwidth, latency, etc. Among them, IOPS includes... The theoretical performance data is the theoretical performance data of each back-end module when running under the front-end business model with a certain configuration. IOPS will vary greatly under different system configurations and can represent the data read / write speed per second in storage. Bandwidth can represent the amount of data passing through the link per unit time, and latency represents the data transmission time.
[0092] In this embodiment, after obtaining the front-end business model, the back-end extended data security management module respectively obtains the theoretical performance data of each back-end module corresponding to the front-end business model. The specific steps include:
[0093] S12-1: Determine the parameters of the front-end service model according to the front-end service model information.
[0094] In this embodiment, the current service model information includes the size of the data block, whether the data is stored sequentially or randomly, read operations or write operations. The parameters of the service model include the size parameters of specific data blocks, the data storage method, etc.
[0095] In this embodiment, after the back-end data security management module obtains the front-end service model information from the CPU module, it determines the specific parameters of the front-end service model according to the front-end service model information.
[0096] Exemplarily, after the back-end data security and management module obtains the model information of the front-end service model, it determines that the specific parameters of the model are data blocks with a size of 1GB, obtains the storage address of the data block, and the storage operation of the data block is a write operation.
[0097] S12-2: According to the parameters of the front-end service model, search in the database for the theoretical performance data of each back-end module under the front-end service model.
[0098] In this embodiment, the database is a database embedded in the back-end extended data security management module. This database stores the theoretical performance data of each back-end module under different configurations and different front-end service models, including the size data of IOPS, the size data of bandwidth, and the length data of latency.
[0099] In this embodiment, after the back-end extended data security management module obtains the parameters of the front-end service model, it searches in the embedded database for the theoretical performance data of each back-end module corresponding to the parameters of this service model according to the obtained parameters.
[0100] Exemplarily, the model parameters obtained by the back-end data security management module are data blocks with a size of 1GB, randomly stored, and the storage operation is a read operation. By searching in the embedded database, the IOPS of the back-end main control module is 5000 IOPS, that is, an average of 5000 reads per second, the bandwidth is 3M / s, and the latency is 10ms. The theoretical performance data of each back-end module, such as the back-end extended module and the back-end extended cabinet module, can also be searched according to this parameter.
[0101] S13: Monitor the actual performance data of each back-end module.
[0102] In this embodiment, the actual performance data of each back-end module is the actual performance data of the back-end main control module, the back-end extended module, and the back-end extended cabinet during storage under the current model, that is, the actual IOPS, the actual bandwidth, and the actual latency.
[0103] In this embodiment, the backend data security control module and each backend module transmit data through a data transmission interface. When the current service is running, the backend data security control module monitors the actual performance data of each backend module in real time.
[0104] Exemplarily, the backend security control module monitors that under the current front-end model, the actual IOPS of the backend expansion cabinet is 3000, the bandwidth is 1M / s, and the latency is 15ms.
[0105] S14: Determine the working status of each backend module according to the magnitude relationship between the theoretical performance data and the actual performance data of each backend module.
[0106] In this embodiment, the working status of each backend module is the current working status of the backend main control module, the backend expansion module, and the backend expansion cabinet. The working status is divided into a normal status and an abnormal status. The abnormal status includes: a super-performance status, that is, the actual performance data of the backend module exceeds the theoretical performance data of the backend module under this front-end model; a low-performance status, that is, the actual performance data of the backend module does not reach the theoretical performance data of the backend module under this front-end model; a suspicious status, that is, the actual performance data of the backend module is lower than the theoretical performance data of the backend module under this front-end model for a period of time, and it may be in a state of failure.
[0107] In this embodiment, after the backend data security control module obtains the theoretical performance data and the actual performance data of each backend module, it compares the theoretical performance data and the actual performance data. According to the magnitude relationship between the theoretical performance data and the actual performance data, it determines the working status of the backend module. The comparison is not simply a comparison of magnitudes, but a certain threshold is set. When the difference between the theoretical performance data and the actual performance data within a certain period of time is greater than a certain threshold, it is determined that the backend module is in the corresponding state.
[0108] Exemplarily, when the backend data security control module monitors that within a period of time, the actual performance data of the backend data cabinet exceeds the theoretical performance data, and the difference between the theoretical performance data and the actual performance data exceeds the preset threshold, it is determined that the backend expansion cabinet is in a super-performance status.
[0109] S15: When there is a backend module with an abnormal working status among each backend module, generate a corresponding warning message according to the working status of the backend module, and correspondingly adjust the connection mode of the backend expansion cabinet.
[0110] In this embodiment, the warning information is used to prompt the working status of each backend module to the outside world. The connection methods of the backend expansion cabinets are divided into remote connection and proximal connection. The proximal connection means that the host and multiple backend expansion cabinets are connected in sequence from near to far, and the remote connection means that the host and multiple backend expansion cabinets are connected in sequence from far to near.
[0111] In this embodiment, when there is a backend module with an abnormal working status among the backend modules, the backend data security management module generates corresponding warning information according to the type of the working status of the backend module, and adjusts the connection method of the backend expansion cabinet according to the type of the working status of the backend module, and performs a near / far end switch on the connection method of the backend expansion cabinet. When the proximal expansion cabinet is damaged, the host can still control the remaining expansion cabinets through the remote expansion cabinet to make the entire system resume normal operation.
[0112] For example, when the backend connection cabinet is in an abnormal state and the working status type is a low performance state, corresponding warning information is generated, and the connection method of the backend expansion cabinet is switched from proximal connection (the original connection method) to remote connection.
[0113] In this embodiment, the actual performance data of each backend module is obtained in real time through the backend expansion data security management module, the actual performance data is compared with the theoretical performance data to determine the working status of each backend module. When an abnormal backend module is detected among the backend modules, corresponding warning information is generated according to the type of the working status of the backend module, and the connection method of the backend expansion cabinet is adjusted accordingly, and the entire backend storage system is monitored, alarmed and adjusted and optimized in real time, which is beneficial to improving the stability of the entire backend storage system.
[0114] In another embodiment of the present application, determining the working status of each backend module according to the theoretical performance data and the actual performance data of each backend module includes:
[0115] S21: When the current management mode is the normal mode, for each backend module, when it is monitored that within a first preset time period, the actual performance data of the backend module exceeds the range of the theoretical performance data by more than a first preset threshold, enter the first test mode.
[0116] In this embodiment, the backend expansion data security management mode is divided into a normal mode and a high reliability mode. The first preset time period is a preset time period, and the first preset threshold is a threshold at which the actual performance data can exceed the theoretical performance data. The test mode is to use the storage system to continue to simulate the front-end tasks executed in the previous time period and obtain the data of each backend module when executing the front-end tasks.
[0117] In this embodiment, when the back-end extended data security management module detects that the actual performance data of any back-end module exceeds the range of the theoretical performance data by more than a first preset threshold within a first preset time period, it enters the first test mode.
[0118] Exemplarily, if within 30 consecutive minutes, the actual performance data B of the IOPS of the back-end expansion cabinet is greater than 125% of the theoretical performance data A, then it enters the first test mode.
[0119] S22: In the first test mode, when it is detected that the business pressure at the front end is less than a first preset pressure threshold, a simulation test with a duration of a second preset time period is performed on the back-end module to obtain a first simulation test result.
[0120] In this embodiment, the front-end business pressure refers to the amount of the entire system resources occupied by the data generated by the front-end business, and the first preset pressure threshold is a preset threshold for the front-end business pressure. The second preset time period is a preset duration for performing the simulation test, and the simulation test result is the actual performance data of each back-end module obtained in the simulation test.
[0121] In this embodiment, when the back-end extended data security management module enters the first test mode and it is detected that the front-end business pressure is less than the first preset pressure threshold, it indicates that the business pressure of the entire storage system is relatively low, and the idle resources can be used for the simulation test. At this time, the simulation test starts, the front-end business model parameters in the previous first preset time period are brought into the entire storage system, the simulation time lasts for the second preset time period, and the actual performance data of each back-end module within the second preset time period is obtained. The obtained actual performance data is compared with the theoretical performance data to obtain a first simulation test result.
[0122] S23: When the first simulation test result shows that the range by which the actual performance data exceeds the theoretical performance data is greater than the first preset threshold, it is determined that the type of the working state of the back-end module is a super-performance state.
[0123] In this embodiment, when the first simulation test result shows that the range by which the actual performance data exceeds the theoretical performance data is greater than the first preset threshold, it means that the first simulation test result is the same as the previously detected actual performance data, indicating that the actual performance of the back-end module under this front-end model is greater than the theoretical performance, and it is determined that the type of the working state of the back-end module is a super-performance state.
[0124] Exemplarily, when the simulation test is performed when the front-end pressure is lower than 30%, the test time of the first simulation test is 50 minutes. Within 50 minutes, the actual performance data B of the IOPS of the back-end expansion cabinet is greater than 125% of the theoretical performance data A, which is consistent with the previously monitored data, then it is determined that the back-end expansion cabinet is in a super-performance state.
[0125] S24: When it is monitored that within a first preset time period, the actual performance data of the backend module is lower than the range of the theoretical performance data by more than a second preset threshold, determine that the type of the working state of the backend module is a suspicious state.
[0126] In this embodiment, the suspicious state represents that the backend module may be in a low-performance state and there may be a fault. The second preset threshold is the preset threshold for the range where the actual performance data is lower than the theoretical performance data.
[0127] In this embodiment, when the backend extended data security management module monitors that the actual performance of the backend module is lower than the range of the theoretical performance data by more than the second preset threshold, determine that the type of the working state of the backend module is a suspicious state.
[0128] Exemplarily, it is monitored that the actual performance data B of the backend expansion cabinet within 30 consecutive minutes is less than 70% of the theoretical performance data A, then determine that the type of the working state of the backend expansion cabinet is a suspicious state.
[0129] S25: When the type of the working state of the backend module is a suspicious state, in response to a mode switching instruction, switch the current management mode to the high-reliability mode.
[0130] In this embodiment, the high-reliability mode is a more refined management mode, which can increase the refined management of the entire storage system and improve the reliability of the entire storage system.
[0131] In this embodiment, when the type of the working state of the backend module is a suspicious state, the management personnel will issue a mode switching instruction through the CPU, the CPU will send the mode switching instruction to the backend extended data security management module, and the backend extended data security management module will switch the management mode from the normal mode to the high-reliability mode.
[0132] S26: In the high-reliability mode, when it is monitored that within a first preset time period, the actual performance data of the backend module exceeds the range of the theoretical performance data by more than a first preset threshold, enter the second test mode.
[0133] In this embodiment, the second test mode is a test mode carried out in the high-reliability mode.
[0134] In this embodiment, when the management mode of the backend extended data security management module is the high-reliability mode, and it is monitored that within a first preset time period, the actual performance data of the backend module exceeds the range of the theoretical performance data by more than the first preset threshold, enter the second test mode.
[0135] For example, in the high-reliability mode, if within 30 consecutive minutes, the actual performance data B of the IOPS of the backend expansion cabinet is greater than 125% of the theoretical performance data A, then enter the second test mode.
[0136] S27: In the second test mode, when it is detected that the service pressure at the front end is less than the second preset pressure threshold, a simulation test with a duration of the second preset time period is performed on the backend module to obtain a second simulation test result.
[0137] In this embodiment, the second preset pressure threshold is a preset front-end pressure threshold, which is different from the first preset threshold.
[0138] In this embodiment, when the backend expansion data security management module enters the second test mode and it is detected that the front-end service pressure is less than the second preset pressure threshold, it indicates that the service pressure of the entire storage system is relatively low, and the idle resources can be used for simulation testing. At this time, the simulation test starts. The front-end service model parameters within the previous first preset time period are brought into the entire storage system, and the simulation time lasts for the second preset time period to obtain the actual performance data of each backend module within the second preset time period. The obtained actual performance data is compared with the theoretical performance data to obtain a second simulation test result.
[0139] S28: When the second simulation test result shows that the range where the actual performance data exceeds the theoretical performance data is greater than the first preset threshold, determine that the working state type of the backend module is the super-performance state.
[0140] In this embodiment, when the second simulation test result shows that the range where the actual performance data exceeds the theoretical performance data is greater than the first preset threshold, it means that the second simulation test result is the same as the actual performance data detected in the previous high-reliability mode, indicating that the actual performance of the backend module under this front-end model is greater than the theoretical performance. Determine that the working state type of this backend module is the super-performance state.
[0141] For example, when the front-end pressure is lower than 20%, a simulation test is performed. The test time of the second simulation test is 45 minutes. Within 45 minutes, the actual performance data B of the IOPS of the backend expansion cabinet is greater than 125% of the theoretical performance data A, which is consistent with the previously monitored data. Then it is determined that the backend expansion cabinet is in the super-performance state.
[0142] S29: When it is monitored that within the first preset time period, the range where the actual performance data of the backend module is lower than the theoretical performance data exceeds the third preset threshold, determine that the working state type of the backend module is the low-performance state.
[0143] In this embodiment, when it is monitored that the third preset threshold is the range threshold at which the actual performance data of the backend module is lower than the theoretical performance data in the high-reliability mode, the low-performance state is the state where the actual performance data of the backend module is lower than the theoretical performance data.
[0144] In this embodiment, when the backend extended data security management module monitors in the high-reliability mode that the range by which the actual performance data of the backend module is lower than the theoretical performance data within the first preset time period exceeds the third preset threshold, it is determined that the working state type of the backend module is the low-performance state.
[0145] Exemplarily, within a duration of 30 minutes, it is monitored that the theoretical performance data B of the backend expansion cabinet is less than 80% of the actual performance data A, and it is determined that the working state type of the backend expansion cabinet is the low-performance state.
[0146] In this embodiment, when the actual performance data of the storage system is lower than the theoretical performance data, it enters the high-reliability mode to manage the working states of each backend module, determines the working states of each backend module, monitors the working states of each backend module in real time, and further determines the working states of the backend modules through the high-reliability mode, improving the reliability of the storage system.
[0147] In another embodiment of the present application, generating corresponding warning information according to the type of the working state of the backend module and correspondingly adjusting the connection mode of the backend expansion cabinet includes:
[0148] S31: When the type of the working state of the backend module is the super-performance state, generate a secondary warning information, and the secondary warning information is used to remind the management personnel that the actual performance of the backend module is higher than the theoretical performance.
[0149] In this embodiment, when the backend extended data security management module determines that the type of the working state of any one of the backend modules among each backend module is the super-performance state, generate a secondary warning information, and the secondary warning information is used to remind the management personnel that the actual performance of the backend module is higher than the theoretical performance.
[0150] S32: When the type of the working state of the backend module is the suspicious state, generate a tertiary warning information, and the tertiary warning information is used to remind the management personnel that the backend module may have a fault and needs to be switched to the high-reliability mode for further testing.
[0151] In this embodiment, when the backend extended data security management module determines that the type of the working state of any one of the backend modules among each backend module is the suspicious state, generate a tertiary warning information, and the tertiary warning information is used to remind the management personnel that the backend module may have a fault and needs to be switched to the high-reliability mode for further testing.
[0152] S33: When the type of the working state of the backend module is a low-performance module, generate a level-four warning message, which is used to remind the management staff that there is a fault in the backend module.
[0153] In this embodiment, when the backend extension data security management module determines that the type of the working state of any one of the backend modules is a low-performance state, it generates a level-four warning message, which is used to remind the management staff that there is a fault in the backend module. This fault may be caused by the module itself, or may be caused by the connection problem between the module and other modules, or may be caused by a fault in a certain node in the entire link.
[0154] S34: When generating the level-four warning message, perform a near / far-end switch on the connection mode of the backend extension cabinet.
[0155] In this embodiment, when generating a level-four warning message, the backend extension data security management module controls the backend extension chips in the backend extension cabinet, such as FW extension chips, to perform a near / far-end switch on the connection mode of the backend extension cabinet.
[0156] In this embodiment, as Figure 3 shown, Figure 3 is a schematic diagram of the connection of the backend extension cabinet proposed in an embodiment of the present application. In the figure, the backend extension cabinet has two connection modes. The left side in the figure is the near-end connection mode, and the right side is the far-end connection mode. The connection sequence of the near-end connection mode is host - extension cabinet 1 - extension cabinet 2 - extension cabinet 3, and the far-end connection mode is host - extension cabinet 3 - extension cabinet 2 - extension cabinet 1. Each node of each extension cabinet can use these two connection modes, but only one connection mode can exist at the same time. The backend extension data security management module realizes the switching of the input port and the output port by controlling the backend extension chips in the extension cabinet, and realizes the near / far-end switch of the extension cabinet connection by switching the input port and the output port. When performing a far-end connection, the interface of the host with the far-end extension cabinet is changed to the output port, and the other interface is changed to the input port, and the remaining extension cabinets are switched in turn.
[0157] In this embodiment, when the backend module is in the low-performance mode, a level-four warning message is issued and the connection mode of the extension cabinet is switched, ensuring that when the front-end extension cabinet is damaged, storage can still be performed through the backend extension cabinet, improving the reliability of the system.
[0158] In another embodiment of the present application, the method further includes:
[0159] S41: When sending the level-two warning message, send a database update prompt at the same time;
[0160] In this embodiment, when the back-end extended data security management module sends a secondary warning message to the outside world, it simultaneously sends a database update prompt to remind the personnel to update the database and update the monitored actual performance data to the database.
[0161] S42: When sending the tertiary warning message, an inquiry message is simultaneously sent, and the inquiry message is used to inquire whether to switch the current management mode to the high-reliability mode.
[0162] In this embodiment, when the back-end extended data security management module sends a tertiary warning message to the outside world, an inquiry message is simultaneously sent, which is used to inquire whether to switch the current management mode to the high-reliability mode. After receiving the inquiry message, the management personnel switch the current management mode to the high-reliability mode through the back-end extended data security management module.
[0163] In another embodiment of the present application, after the connection mode of the back-end extended cabinet is switched between the near end and the far end, the method further includes:
[0164] S51: When it is monitored that within a third preset time period, the range of the actual performance data of the back-end module being lower than the theoretical performance data does not exceed a third preset threshold, the quaternary warning message is cancelled.
[0165] In this embodiment, the third preset time period is a time period preset for monitoring the actual performance data of the back-end module in the high-performance mode.
[0166] In this embodiment, when the back-end extended data security management module monitors in the high-reliability mode that the range of the actual performance data of the back-end module being lower than the theoretical performance data within the third preset time period is lower than the third preset threshold, it indicates that the gap between the actual performance data and the theoretical performance data of the back-end module is not large, and the quaternary warning message is cancelled.
[0167] Exemplarily, within a duration of 60 minutes, if it is monitored that the theoretical performance data B of the back-end extended cabinet is less than 80% of the actual performance data A, the quaternary warning message is cancelled.
[0168] In another embodiment of the present application, the method further includes:
[0169] S61: In response to an operation of creating a disk array, obtain the information of the back-end extended cabinet.
[0170] In this embodiment, the disk array is a plurality of storage hard disks placed in the back-end extended cabinet and arranged in a certain array order. The information of the back-end extended cabinet includes the number of back-end extended cabinets, the internal capacity size of the back-end extended cabinet, etc.
[0171] Exemplarily, the information of the back-end extended cabinet is that the number of back-end extended cabinets is 3, and the capacity of each back-end extended cabinet can be expanded to 10×10 disks.
[0172] S62: Generate a disk distribution list of the disk array in the backend expansion cabinet according to the information of the backend expansion cabinet.
[0173] In this embodiment, the disk distribution list is the positions of each disk in the disk array in each expansion cabinet.
[0174] In this embodiment, the backend expansion data security management module generates a disk distribution list of the disk array in the backend expansion cabinet according to the information of the backend expansion cabinet.
[0175] Exemplarily, to create a 4×4 disk array, the disk distribution list shows that the disks of the disk array are respectively placed in expansion cabinets 1 - 4, with 4 disks placed in each expansion cabinet. Then the array distribution list is sent to the CPU module, and the CPU module can display this list at the front end for management personnel to view.
[0176] In another embodiment of the present application, the method further includes:
[0177] S71: When the number of the backend expansion cabinets does not meet the distribution of the disk array, generate a first-level warning message for reminding the management personnel that the number of the backend expansion cabinets is insufficient.
[0178] S72: Determine the required quantity ratio of the backend expansion cabinets according to the distribution of the disk array.
[0179] In this embodiment, when the number of the backend expansion cabinets does not meet the distribution of the disk array, a first-level warning message is generated, which is used to remind the management personnel that the data volume of the backend expansion cabinets is insufficient. When the number of the backend expansion cabinets does not meet the distribution of the disk array, the disk array cannot be arranged in the backend expansion cabinets according to the arrangement method in the disk distribution list, which may affect the security of data storage. At this time, a first-level warning message needs to be issued, and the required quantity ratio of the backend expansion cabinets is determined according to the distribution of the disk array. This quantity ratio is sent to the CPU module, and the CPU module restricts this quantity ratio at the front end for management personnel to view.
[0180] Exemplarily, the number of the backend expansion cabinets is 2, while the disk array is a 4×4 disk array. It is determined that the existing number of expansion cabinets does not meet the distribution of the disk array, and the required number of the backend expansion cabinets is determined to be 4, and this quantity ratio is sent to the CPU module.
[0181] Based on the same inventive concept, an embodiment of the present application provides a security management device for backend expansion data. Refer to Figure 4 , Figure 4 is a schematic diagram of a security management device 400 for backend expansion data proposed in an embodiment of the present application. AsFigure 4 As shown in the figure, the device includes:
[0182] A model information acquisition module 401, configured to acquire the front-end service model information corresponding to the current front-end service;
[0183] A theoretical performance data acquisition module 402, configured to determine the theoretical performance data of each backend module corresponding to the front-end service model according to the front-end service model information, where the backend modules include: a backend main control module, a backend expansion module, and a backend expansion cabinet;
[0184] An actual performance data monitoring module 403, configured to monitor the actual performance data of each backend module;
[0185] A working state determination module 404, configured to determine the working state of each backend module according to the magnitude relationship between the theoretical performance data and the actual performance data of each backend module;
[0186] A backend warning adjustment module 405, configured to generate a corresponding warning message according to the type of the working state of the backend module and correspondingly adjust the connection mode of the backend expansion cabinet when there is a backend module with an abnormal working state among the backend modules.
[0187] Optionally, the theoretical performance data acquisition module includes:
[0188] A model parameter acquisition sub-module, configured to determine the parameters of the front-end service model according to the front-end service model information;
[0189] A theoretical performance acquisition sub-module, configured to search for the theoretical performance data of each backend module under the front-end service model in the database according to the parameters of the front-end service model.
[0190] Optionally, the working state determination module includes:
[0191] A first test mode start sub-module, configured to, when the current management mode is the normal mode, for each backend module, when it is detected that within a first preset time period, the actual performance data of the backend module exceeds the range of the theoretical performance data by more than a first preset threshold, enter the first test mode;
[0192] A first simulation test result acquisition sub-module, configured to, in the first test mode, when it is detected that the business pressure at the front end is less than a first preset pressure threshold, perform a simulation test on the backend module for a second preset time period to obtain a first simulation test result;
[0193] The first status determination sub-module is used to determine that the type of the working status of the backend module is the super-performance status when the first simulation test result shows that the range of the actual performance data exceeding the theoretical performance data is greater than the first preset threshold;
[0194] The second status determination sub-module is used to determine that the type of the working status of the backend module is the suspicious status when it is monitored that within the first preset time period, the range of the actual performance data of the backend module being lower than the theoretical performance data exceeds the second preset threshold;
[0195] The management mode switching sub-module is used to switch the current management mode to the high-reliability mode in response to a mode switching instruction when the type of the working status of the backend module is the suspicious status;
[0196] The second test mode start sub-module is used to enter the second test mode when it is monitored that within the first preset time period in the high-reliability mode, the range of the actual performance data of the backend module exceeding the theoretical performance data is greater than the first preset threshold;
[0197] The second simulation test result obtaining sub-module is used to perform a simulation test on the backend module for a duration of the second preset time period to obtain a second simulation test result when it is detected in the second test mode that the service pressure of the front end is less than the second preset pressure threshold;
[0198] The third status determination sub-module is used to determine that the type of the working status of the backend module is the super-performance status when the second simulation test result shows that the range of the actual performance data exceeding the theoretical performance data is greater than the first preset threshold;
[0199] The fourth status determination sub-module is used to determine that the type of the working status of the backend module is the low-performance status when it is monitored that within the first preset time period, the range of the actual performance data of the backend module being lower than the theoretical performance data exceeds the third preset threshold.
[0200] Optionally, the backend warning and adjustment module includes:
[0201] The first warning message generation sub-module is used to generate a secondary warning message when the type of the working status of the backend module is the super-performance status, and the secondary warning message is used to remind the management personnel that the actual performance of the backend module is higher than the theoretical performance;
[0202] The second warning message generation sub-module is used to generate a tertiary warning message when the type of the working status of the backend module is the suspicious status, and the tertiary warning message is used to remind the management personnel that there may be a fault in the backend module and it is necessary to switch to the high-reliability mode for further testing;
[0203] A third warning information generating submodule is used to generate a level 4 warning information when the working state of the backend module is a low-performance module, and the level 4 warning information is used to remind the management personnel that the backend module has a fault;
[0204] The connection mode switching submodule is used to switch the connection mode of the rear-end expansion cabinet between the far end and the near end when the fourth-level warning information is generated.
[0205] Optionally, the device further comprises:
[0206] A database update prompt submodule, used to send a database update prompt at the same time as sending the secondary warning information;
[0207] The inquiry information sending submodule is used to send inquiry information at the same time as sending the third-level warning information, and the inquiry information is used to inquire whether to switch the current management mode to the high-reliability mode.
[0208] Optionally, the device further comprises:
[0209] The warning information cancellation submodule is used to cancel the fourth-level warning information when it is monitored that the actual performance data of the back-end module is lower than the theoretical performance data within a third preset time period by no more than a third preset threshold.
[0210] Optionally, the device further comprises:
[0211] A back-end expansion cabinet information obtaining submodule, used for obtaining the information of the back-end expansion cabinet in response to the operation of creating a disk array;
[0212] The disk distribution list generating submodule is used to generate a disk distribution list of the disk array in the back-end expansion cabinet according to the information of the back-end expansion cabinet.
[0213] Optionally, the device further comprises:
[0214] A first-level warning information generating module, used for generating a first-level warning information when the number of the back-end expansion cabinets does not meet the distribution of the disk array, wherein the first-level warning information is used to remind the management personnel that the number of the back-end expansion cabinets is insufficient;
[0215] The quantity ratio determination module is used to determine the quantity ratio of the required back-end expansion cabinets according to the distribution of the disk array.
[0216] Based on the same inventive concept, another embodiment of the present application provides a readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps in the method for secure management of backend extended data as described in any of the above embodiments of the present application are implemented.
[0217] Based on the same inventive concept, another embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes, it implements the steps in the security management method for backend extended data described in any one of the above embodiments of the present application.
[0218] For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, please refer to the partial description of the method embodiments.
[0219] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0220] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0221] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0222] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0223] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process or multiple processes and / or blocks. Figure 1 one process or multiple processes and / or blocks Figure 1 steps for implementing the functions specified in one block or multiple blocks.
[0224] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present application.
[0225] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or terminal device comprising the said element.
[0226] The above has introduced in detail the security management method, device, equipment and storage medium of the backend extended data provided by the present application. Specific examples are used in this text to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A security management method for backend extended data, characterized in that, The method includes: Obtaining the front-end service model information corresponding to the current front-end service; the front-end service model is the parameter of the data generated by the business being carried out by the front-end server, and the front-end service model information at least includes: the size of the data block that needs to be stored for this service, whether the data storage is random access or sequential access, and the operation is a read operation or a write operation; Determining the theoretical performance data of each backend module corresponding to the front-end service model according to the front-end service model information, and the backend modules include: a backend main control module, a backend expansion module, and a backend expansion cabinet; Monitoring the actual performance data of each backend module; Determining the working state of each backend module according to the magnitude relationship between the theoretical performance data and the actual performance data of each backend module; When there is a backend module with an abnormal working state among each backend module, generating a corresponding warning message according to the type of the working state of the backend module, and correspondingly adjusting the connection mode of the backend expansion cabinet; The determining the theoretical performance data of each backend module corresponding to the front-end service model according to the front-end service model information includes: Determining the parameters of the front-end service model according to the front-end service model information; Searching in the database for the theoretical performance data of each backend module under the front-end service model according to the parameters of the front-end service model.
2. The method according to claim 1, wherein the determining the working state of each backend module according to the theoretical performance data and the actual performance data of each backend module includes: When the current management mode is the normal mode, for each backend module, when it is monitored that within a first preset time period, the range of the actual performance data of the backend module exceeds the range of the theoretical performance data by more than a first preset threshold, enter the first test mode; In the first test mode, when it is detected that the business pressure at the front end is less than a first preset pressure threshold, performing a simulation test on the backend module for a second preset time period to obtain a first simulation test result; When the first simulation test result is that the range of the actual performance data exceeds the range of the theoretical performance data by more than a first preset threshold, determining that the type of the working state of the backend module is a super-performance state; When it is monitored that within a first preset time period, the range by which the actual performance data of the backend module is lower than the theoretical performance data exceeds a second preset threshold, determining that the type of the working state of the backend module is a suspicious state; When the type of the working state of the backend module is a suspicious state, in response to a mode switching instruction, switching the current management mode to the high-reliability mode; In the high-reliability mode, when it is monitored that within a first preset time period, the range of the actual performance data of the backend module exceeds the range of the theoretical performance data by more than a first preset threshold, enter the second test mode; In the second test mode, when it is detected that the business pressure at the front end is less than a second preset pressure threshold, performing a simulation test on the backend module for a second preset time period to obtain a second simulation test result; When the range where the actual performance data exceeds the theoretical performance data in the second simulation test result is greater than the first preset threshold, determine that the working state type of the backend module is the super-performance state; When it is monitored that within the first preset time period, the range where the actual performance data of the backend module is lower than the theoretical performance data exceeds the third preset threshold, determine that the working state type of the backend module is the low-performance state.
3. The method according to claim 1, wherein Generating corresponding warning information according to the type of the working state of the backend module and correspondingly adjusting the connection mode of the backend expansion cabinet includes: When the type of the working state of the backend module is the super-performance state, generate a secondary warning information, and the secondary warning information is used to remind the management personnel that the actual performance of the backend module is higher than the theoretical performance; When the type of the working state of the backend module is the suspicious state, generate a tertiary warning information, and the tertiary warning information is used to remind the management personnel that there may be a fault in the backend module and it is necessary to switch to the high-reliability mode for further testing; When the type of the working state of the backend module is the low-performance module, generate a quaternary warning information, and the quaternary warning information is used to remind the management personnel that there is a fault in the backend module; When generating the quaternary warning information, perform a near-far end switch on the connection mode of the backend expansion cabinet.
4. The method according to claim 3, wherein The method further includes: When sending the secondary warning information, send a database update prompt at the same time; When sending the tertiary warning information, send an inquiry message at the same time, and the inquiry message is used to inquire whether to switch the current management mode to the high-reliability mode.
5. The method according to claim 3, wherein After the connection mode of the backend expansion cabinet performs a near-far end switch, the method further includes: When it is monitored that within the third preset time period, the range where the actual performance data of the backend module is lower than the theoretical performance data does not exceed the third preset threshold, cancel the quaternary warning information.
6. The method according to claim 1, wherein The method further includes: In response to an operation of creating a disk array, obtain information of the backend expansion cabinet; Generate a disk distribution list of the disk array in the backend expansion cabinet according to the information of the backend expansion cabinet.
7. The method according to claim 6, wherein The method further includes: When the number of the backend expansion cabinets does not meet the distribution of the disk array, generate a primary warning information, and the primary warning information is used to remind the management personnel that the number of the backend expansion cabinets is insufficient; Determine the required quantity ratio of the backend expansion cabinets according to the distribution of the disk array.
8. A security management device for backend extended data, characterized in that, The device includes: A model information acquisition module, configured to acquire the front-end service model information corresponding to the current front-end service; the front-end service model is the parameters of the data generated by the service being performed by the front-end server, and the front-end service model information at least includes: the size of the data block that needs to be stored for this service, whether the data storage is random access or sequential access, and the operation is a read operation or a write operation; A theoretical performance data acquisition module, configured to determine the theoretical performance data of each backend module corresponding to the front-end service model according to the front-end service model information, and the backend modules include: a backend main control module, a backend expansion module, and a backend expansion cabinet; An actual performance data monitoring module, configured to monitor the actual performance data of each of the backend modules; A working state determination module, configured to determine the working state of each of the backend modules according to the magnitude relationship between the theoretical performance data and the actual performance data of each of the backend modules; A backend warning and adjustment module, configured to generate corresponding warning information according to the type of the working state of the backend module and correspondingly adjust the connection mode of the backend expansion cabinet when there is a backend module with an abnormal working state among the backend modules; The theoretical performance data acquisition module includes: A model parameter acquisition sub-module, configured to determine the parameters of the front-end service model according to the front-end service model information; A theoretical performance acquisition sub-module, configured to search for the theoretical performance data of each of the backend modules under the front-end service model in the database according to the parameters of the front-end service model.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps in the method according to any one of claims 1 to 7 are implemented.
10. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Server fault positioning method and device, electronic equipment and storage medium
CN113568798A
Methods, apparatus and computer programs for managing performance and resource utilization within cluster-based systems
US20050088976A1