Data processing method and device, equipment and storage medium
By determining the number of PVS servers and implementing isolation zone sinking in multi-tenant scenarios, and combining service node characteristic information authentication, the problems of inflexible desktop cloud virtual machine creation and data leakage in multi-tenant scenarios are solved, realizing the creation of personalized desktop cloud virtual machines and data security.
Patent Information
- Application Number
- CN202211413831.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-11
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2042-11-11
AI Technical Summary
Existing technologies cannot flexibly prepare personalized desktop cloud virtual machines for each tenant in a multi-tenant scenario, and there is a risk of data resource leakage.
By determining the ratio of the number of concurrent desktop cloud users to the number of PVS servers for each tenant, corresponding PVS servers are allocated, and desktop cloud virtual machines are created in the isolated area. The characteristic information of the service nodes is used for authentication and data acquisition to achieve resource isolation.
It enables flexible creation of desktop cloud virtual machines for each tenant, ensuring the security of data resources and reducing the risk of data leakage.
Smart Images

Figure CN115827127B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of desktop cloud management, and particularly relates to a data processing method and device, equipment and a storage medium. BACKGROUND
[0002] The desktop cloud is a security management system integrating users and computers, and is increasingly widely concerned.
[0003] At present, in the preparation process of the desktop cloud, each tenant is prepared for the desktop cloud based on the centralized preparation of the desktop cloud operating system. However, such a preparation method cannot meet the personalized preparation of the desktop cloud of each tenant, and since the data resources of the multi-tenant are centrally stored, there is a risk of data resource leakage in the process of data acquisition of the tenant.
[0004] In order to solve the above problems, the preparation method of the multi-tenant desktop cloud needs to be improved. SUMMARY
[0005] The present application provides a data processing method, device, equipment and storage medium to flexibly create a desktop cloud virtual machine for each tenant and ensure the effect of the tenant acquiring data resources based on the security of the desktop cloud virtual machine.
[0006] In a first aspect, the present application provides a data processing method, comprising: determining, for each tenant, the desktop cloud concurrency number of a current tenant and the server number of a PVS server corresponding to the current tenant; allocating a corresponding PVS server to the current tenant based on the server number; and creating a desktop cloud virtual machine based on the PVS server corresponding to each tenant, so that when the desktop cloud virtual machine is started, the corresponding PVS server is logged in based on the feature information of the service node to which the desktop cloud virtual machine belongs, and the access of the desktop cloud virtual machine is controlled based on the PVS server to acquire corresponding data.
[0007] In a second aspect, the present application provides a data processing device, comprising: a server number determination module configured to determine, for each tenant, the desktop cloud concurrency number of a current tenant and the server number of a PVS server corresponding to the current tenant; a server allocation module configured to allocate a corresponding PVS server to the current tenant based on the server number; and a desktop cloud creation module configured to create a desktop cloud virtual machine based on the PVS server corresponding to each tenant, so that when the desktop cloud virtual machine is started, the corresponding PVS server is logged in based on the feature information of the service node to which the desktop cloud virtual machine belongs, and the access of the desktop cloud virtual machine is controlled based on the PVS server to acquire corresponding data.
[0008] In a third aspect, an embodiment of the present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the data processing method according to any one of the embodiments of the present application when executing the program.
[0009] In a fourth aspect, an embodiment of the present application also provides a computer-readable storage medium, having stored thereon a computer program, which, when executed by a processor, implements the data processing method according to any one of the embodiments of the present application.
[0010] In a fifth aspect, an embodiment of the present application also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the data processing method according to any one of the embodiments of the present application.
[0011] The data processing method, device, equipment and storage medium provided by the present application, for each tenant, determine the desktop cloud concurrency number of the current tenant, determine the server number of the PVS server corresponding to the current tenant, by determining the ratio of the desktop cloud concurrency number and the desktop cloud client number corresponding to each tenant, obtain a first value, further, according to the first value and the server number of the standby PVS server (i.e. the preset value), the server number of the PVS server corresponding to each tenant can be obtained. Based on the server number, the corresponding PVS server is allocated to the current tenant, and according to the server number, a corresponding number of PVS servers are sunk in the isolation area corresponding to each tenant, so as to prepare desktop cloud virtual machines for each tenant based on the PVS server corresponding to each tenant. Based on the PVS server corresponding to each tenant, a desktop cloud virtual machine is created, so as to log in to the corresponding PVS server based on the feature information of the service node to which the desktop cloud virtual machine belongs when the desktop cloud virtual machine starts, so as to control the access of the desktop cloud virtual machine based on the PVS server, so as to obtain corresponding data. In the technical solution provided in the embodiments of the present application, the PVS server corresponding to each tenant can create a desktop cloud virtual machine for the corresponding tenant, and when it is detected that the desktop cloud virtual machine starts, the PVS server performs information authentication on the desktop cloud virtual machine, so as to determine whether the desktop cloud virtual machine can access the PVS server, so as to obtain data resources from the corresponding PVS server. The problem that in a multi-tenant scenario, it is not possible to flexibly prepare a corresponding desktop cloud virtual machine for each tenant, and the resources of each tenant are not isolated, which may cause a data leakage risk, is solved, and the effects of flexibly creating a desktop cloud virtual machine for each tenant and ensuring that the tenant can safely obtain data resources based on the desktop cloud virtual machine are achieved. BRIEF DESCRIPTION OF DRAWINGS
[0012] The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.
[0013] Figure 1 Flow of the data processing method provided for the embodiments of the present application Figure 1 ;
[0014] Figure 2 Flow of the data processing method provided for the embodiments of the present application Figure 2 ;
[0015] Figure 3 Flow of the data processing method provided for the embodiments of the present application Figure 3 ;
[0016] Figure 4 Example diagram of the data processing method provided for the embodiments of the present application;
[0017] Figure 5 Structural schematic diagram of the data processing apparatus provided for the embodiments of the present application;
[0018] Figure 6 Structural schematic diagram of the electronic device provided for the embodiments of the present application.
[0019] The specific embodiments of the present application have been shown through the above-described drawings, and will be described in more detail hereinafter. These drawings and the written description are not intended to restrict the scope of the present application concept in any way, but to illustrate the present application concept to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0020] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The same numbers are used in different drawings to represent the same or similar elements. The following detailed description is not intended to restrict the all embodiments consistent with the present application. Rather, it is only an example of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0021] The technical solutions of the present application and how the technical solutions of the present application solve the above-mentioned technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments. The embodiments of the present application will be described below with reference to the drawings. The acquisition, storage, use, processing, etc. of data in the technical solutions of the present application all comply with the relevant provisions of national laws and regulations.
[0022] Before the embodiments of the present application are described in detail, the application scenarios of the present application are briefly introduced so as to more clearly understand the technical solutions provided by the embodiments of the present application. In the process of preparing a desktop cloud, the desktop cloud used by a tenant can usually be prepared based on a PVS server (Citrix Provisioning Services, PVS). In the prior art, a method of centrally preparing a desktop cloud virtual machine is usually adopted, that is, even when multiple tenants exist, the PVS server performs unified preparation and deployment of the desktop cloud virtual machines corresponding to the multiple tenants based on the same PVS server when preparing the desktop cloud. However, such a desktop cloud preparation manner cannot meet the desktop cloud preparation requirements of each tenant in a multi-tenant application scenario, that is, in a multi-tenant scenario, the prior art cannot prepare personalized desktop cloud virtual machines for each tenant to meet the needs of each tenant for personalized customization of the desktop cloud virtual machines. Based on this, the technical solutions provided by the embodiments of the present application propose, based on a multi-tenant scenario, preparation of corresponding desktop cloud virtual machines for each tenant to enable isolation between template resources and template management permissions among the desktop cloud virtual machines of each tenant, and thus more flexibly meet the needs of each tenant for personalized desktop cloud virtual machines.
[0023] The embodiments of the present application provide a data processing method. Figure 1 The flow of the data processing method provided by the embodiments of the present application Figure 1 . As Figure 1 shown, the data processing method comprises:
[0024] To more clearly introduce the technical solutions provided by the embodiments of the present application, the prior art for preparing a desktop cloud virtual machine for each tenant in a multi-tenant scenario is briefly introduced. In the prior art, a virtual desktop controller (Citrix Delivery Controller, CDC) is usually used to centrally control and manage the desktop cloud virtual machines of each tenant in a multi-tenant scenario, that is, multiple tenants share the same CDC controller to control the resource visibility and load balancing control among the tenants based on the CDC controller; wherein the CDC controller is the multi-tenant shared controller mentioned in the technical solutions provided by the embodiments of the present application. When it is necessary to prepare the desktop cloud virtual machines for each tenant, the PVS server in the CDC controller can be used to prepare the desktop cloud virtual machines for each tenant. However, such an operation manner cannot meet the personalized customization of the tenants for the desktop cloud virtual machines, and therefore, in the technical solutions provided by the embodiments of the present application, the PVS server is sunk to the isolated area of each tenant so that the corresponding PVS server of the isolated area can be used to prepare the corresponding desktop cloud virtual machine when preparing the desktop cloud virtual machine for each tenant.
[0025] In order to more clearly understand the technical solutions provided by the embodiments of the present application, the PVS server mentioned in the technical solutions provided by the embodiments of the present application is briefly introduced first. The PVS server is to create a standard virtual machine image, which is similar to a virtual disk and is equivalent to the desktop cloud virtual machine mentioned in the technical solutions provided by the embodiments of the present application. In the virtual machine image, the operating system, application program and configuration information of the desktop cloud virtual machine are included and stored in the PVS server. At the same time, the virtual disk can also be managed based on the PVS server and sent to the corresponding tenant's desktop cloud client for use. More specifically, when the tenant uses the desktop cloud client, the PVS server can stream the virtual machine image to the corresponding desktop cloud client. The advantage of such a setup is that the PVS server can prepare or re-prepare the virtual machine image in real time for each desktop cloud client.
[0026] S101, for each tenant, determine the current tenant's desktop cloud concurrency number, and determine the number of PVS servers corresponding to the current tenant.
[0027] It should be noted that the technical solutions provided by the embodiments of the present application are based on the application scenario of multi-tenancy, and flexibly prepare desktop cloud virtual machines for each tenant. The current tenant can be understood as any user in the multi-tenant who needs to prepare a desktop cloud virtual machine. It can be understood that when the current tenant uses the desktop cloud system, each desktop cloud system corresponds to a corresponding desktop cloud virtual machine, that is, the number of desktop cloud virtual machines matches the number of desktop cloud clients of the current tenant. The so-called desktop cloud concurrency number is the sum of all desktop cloud clients of the current tenant and the maximum number of user accounts provided by each desktop cloud client.
[0028] Exemplarily, if the PVS server prepares the corresponding desktop cloud virtual machine for the current tenant to meet the use of the corresponding desktop cloud virtual machine by each desktop cloud client, the number of the desktop cloud clients is 100, and the number of the user accounts provided in each desktop cloud client is 2, then the desktop cloud concurrency is the number of all the user accounts associated with the desktop cloud client, that is, 200. In a popular way, taking the current tenant, company A, as an example, if company A is equipped with 100 desktop cloud clients, then the employees of company A can use up to 100 desktop cloud clients at the same time when using the desktop cloud clients. If company A is divided into day shift and night shift in the actual work process, that is, the maximum desktop concurrency of company A in the day shift is 100, and the maximum desktop concurrency of company A in the night shift is also 100. Based on this, it can be known that the actual desktop concurrency of company A is the sum of the maximum concurrency of the desktop concurrency in the day shift and the night shift, that is, 200.
[0029] In the technical scheme provided in the embodiment of the application, in order to prepare the corresponding desktop cloud virtual machine for the desktop cloud client of each tenant in the multi-tenant application scenario, taking the current tenant as an example, the desktop cloud concurrency corresponding to the current tenant needs to be determined. The purpose is that when preparing the desktop cloud virtual machine for the current tenant, if only one PVS server is used to prepare the desktop cloud virtual machine, the preparation efficiency is low. However, if a large number of PVS servers are directly prepared for the current tenant to prepare the desktop cloud virtual machine, resource waste will occur. Therefore, in the technical scheme provided in the embodiment of the application, based on the actual situation, the desktop cloud concurrency corresponding to the current tenant is first obtained, and the number of servers of the corresponding PVS server is determined based on the desktop cloud concurrency, so that the preparation efficiency of the desktop cloud virtual machine for the current tenant can be improved without wasting PVS server resources.
[0030] Optionally, the determination of the desktop cloud concurrency of the current tenant and the determination of the number of servers of the PVS server corresponding to the current tenant include: determining a first value based on the desktop cloud concurrency and the polling information; and determining the number of servers of the PVS server corresponding to the current tenant based on the first value and a preset value.
[0031] In the preparation of the desktop cloud virtual machine for the current tenant, the number of desktop cloud clients of the current tenant at the current time is needed to be obtained to determine the corresponding PVS server based on the desktop cloud concurrency and the number of desktop cloud clients. The polling information can be understood as information for obtaining the number of desktop cloud clients of the current tenant. Specifically, the polling information can be a query instruction, and the user obtains the number of desktop cloud clients actually used by the current tenant at the current time. The first value can be understood as a value obtained based on the ratio of the desktop cloud concurrency of the current tenant and the number of desktop cloud clients. The preset value is the number of backup PVS servers pre-set.
[0032] Specifically, in order to determine the number of PVS servers most matched with the current tenant, the number of desktop cloud clients of the current tenant and the number of user accounts used corresponding to each desktop cloud client need to be determined. The number of desktop cloud clients of the current tenant can be pre-obtained information. For example, before the preparation of the desktop cloud virtual machine for the current tenant, the associated information of the current tenant needs to be obtained first, such as the number of desktop cloud clients provided by the current tenant and the maximum number of user accounts that can be associated with each desktop cloud client, to determine the number of PVS servers corresponding to the current tenant. When actually providing PVS servers for the current tenant, polling information can be sent to the desktop cloud clients associated with the current tenant to determine the number of desktop cloud clients actually used at the current time. Further, a first value is obtained according to the ratio of the desktop cloud concurrency and the actual number of desktop cloud clients, and the number of PVS servers needed to be provided for the current tenant is obtained according to the sum of the first value and a preset value.
[0033] It should be noted that in the technical solution provided by the embodiment of the present application, the first value obtained based on the ratio of the desktop cloud concurrency and the number of desktop cloud clients can be used to represent the number of PVS servers needed to be provided when actually providing PVS servers. The purpose of setting the preset value of the backup PVS server is to ensure that at least one backup PVS server can be used for the preparation of the desktop cloud virtual machine of the current tenant, that is, if a PVS server fails in the actual execution process, the backup PVS server can replace the PVS server to prepare the desktop cloud virtual machine, so as to ensure that the corresponding number of desktop cloud virtual machines can be prepared quickly for the current tenant.
[0034] It should be noted that the number of PVS servers in the technical solution provided by the embodiment of the present application can be determined not only according to the number of desktop cloud clients actually used by the current tenant, but also according to the maximum desktop cloud concurrency and the maximum desktop cloud client.
[0035] For example, in actual application, the number of desktop cloud clients corresponding to the current tenant is 100, the number of user accounts available for each client is 2, the maximum desktop cloud concurrency is 200, the maximum number of desktop cloud clients is 100, and the server number of the PVS server is determined based on the maximum desktop cloud concurrency and the maximum number of desktop cloud clients and the preset value corresponding to the number of backup PVS servers.
[0036] Specifically, the server number of the PVS server can be determined by the following formula:
[0037]
[0038] Wherein, P represents the number of PVS servers, A represents the desktop cloud concurrency of the current tenant, B represents the number of desktop cloud clients of the current tenant, and t represents the server number of the backup PVS server.
[0039] S102, allocate the corresponding PVS server to the current tenant based on the server number.
[0040] Specifically, after determining the server number of the PVS server corresponding to the current tenant, the corresponding number of PVS servers can be applied to the multi-tenant multiplexing controller, so that the multi-tenant multiplexing controller can be decoupled by the PVS server sinking, and the corresponding number of PVS servers can be sunk to the isolation area corresponding to the current tenant as the PVS server corresponding to the current tenant.
[0041] S103, create a desktop cloud virtual machine based on the PVS server corresponding to each tenant, so that when the desktop cloud virtual machine is started, the desktop cloud virtual machine can be logged into the corresponding PVS server based on the feature information of the service node to which the desktop cloud virtual machine belongs, and the access of the desktop cloud virtual machine can be controlled based on the PVS server to obtain the corresponding data.
[0042] Wherein, the service node can be understood as the desktop cloud client corresponding to the tenant, and the feature information is specifically the computer feature information to which each desktop cloud client belongs, such as computer authorization code, serial number, authentication code and registration application code and other unique identification information corresponding to the computer.
[0043] In the technical scheme provided in the embodiment of the application, after confirming the server number of the PVS server corresponding to each tenant, the corresponding number of PVS servers is sunk to the isolation area of the corresponding tenant. It can be understood that the PVS server has the ability to prepare a desktop cloud virtual machine, so when a desktop cloud virtual machine associated with the PVS server is detected to start, the feature information of the corresponding service node can be identified first to determine whether the desktop cloud virtual machine can be logged into the PVS server, and further data can be obtained from the PVS server.
[0044] For example, taking tenant A as an example, if the isolation area where tenant A is located includes 10 PVS servers, it means that tenant A exclusively uses the 10 PVS servers, in other words, the 10 PVS servers are only used to create the desktop cloud virtual machines corresponding to tenant A. Meanwhile, the PVS servers also save the computer feature information of all the desktop cloud virtual machines corresponding to tenant A in the storage area in the isolation area where tenant A is located. When the desktop cloud virtual machine associated with tenant A needs to be used, the pre-stored computer feature information can be called to perform login authentication on the corresponding desktop cloud virtual machine, to determine whether the desktop cloud virtual machine can access the PVS server and can obtain data resources from the PVS server.
[0045] For example, when a user logs in to the system of server A, server A needs to identify the identity information of the user, specifically, whether the user has the permission to log in to server A can be determined according to the feature information of the computer used by the user. If yes, it means that the computer can log in to server A and can obtain corresponding data from server A.
[0046] The data processing method, device, equipment and storage medium provided by the application, for each tenant, determine the desktop cloud concurrency number of the current tenant, determine the server number of the PVS server corresponding to the current tenant, determine the ratio of the desktop cloud concurrency number and the desktop cloud client number corresponding to each tenant, obtain a first value, further, according to the first value and the server number of the standby PVS server (i.e. the preset value), the server number of the PVS server corresponding to each tenant can be obtained. Based on the server number, the corresponding PVS server is allocated to the current tenant, and a corresponding number of PVS servers is sunk in the isolation area corresponding to each tenant according to the server number, so as to prepare desktop cloud virtual machines for each tenant based on the PVS server corresponding to each tenant. Based on the PVS server corresponding to each tenant, the desktop cloud virtual machine is created, so as to log in to the corresponding PVS server based on the feature information of the service node to which the desktop cloud virtual machine belongs when the desktop cloud virtual machine starts, so as to control the access of the desktop cloud virtual machine based on the PVS server, so as to obtain corresponding data. In the technical scheme provided in the embodiment of the application, the PVS server corresponding to each tenant can create a desktop cloud virtual machine for the corresponding tenant, and when it is detected that the desktop cloud virtual machine starts, the PVS server performs information authentication on the desktop cloud virtual machine, so as to determine whether the desktop cloud virtual machine can access the PVS server, so as to obtain data resources from the corresponding PVS server. The problem that in a multi-tenant scenario, it is not possible to flexibly prepare a corresponding desktop cloud virtual machine for each tenant, and the resource data of each tenant is not isolated, which may cause a data leakage risk, is solved, and the effects of flexibly creating a desktop cloud virtual machine for each tenant and ensuring that the tenant can safely obtain data resources based on the desktop cloud virtual machine are achieved.
[0047] On the basis of the above-mentioned embodiments, after the corresponding PVS server is allocated to the current tenant, the method further comprises creating a desktop cloud virtual machine for the current tenant based on the PVS server, and binding the PVS server and the desktop cloud virtual machine; and / or, saving the feature information corresponding to the desktop cloud virtual machine, so as to log in to the corresponding PVS server based on the feature information. Correspondingly, the application provides the following embodiments:
[0048] Figure 2 The flow of the data processing method provided in the embodiments of the application Figure 2 As shown in Figure 2 , the data processing method comprises the following steps:
[0049] S201, creating a desktop cloud virtual machine for the current tenant based on the PVS server, and binding the PVS server and the desktop cloud virtual machine.
[0050] In actual application, the server quantity of the PVS server corresponding to the current tenant is determined, and the corresponding quantity of PVS servers can be sunk into the isolation area corresponding to the current tenant based on the multi-tenant multiplexing controller, based on which, each PVS server can create a desktop cloud virtual machine for the current tenant. It should be noted that in the subsequent use process, the desktop cloud virtual machine corresponding to the current tenant needs to be authenticated by the information of the PVS server at each start, so that the data resources can be obtained from the PVS server corresponding to the current tenant after the information authentication.
[0051] Therefore, after creating the desktop cloud virtual machine corresponding to the current tenant based on the PVS server corresponding to the current tenant, each PVS server needs to be bound with the created desktop cloud virtual machine. Based on this, the PVS server of the current tenant can detect the bound desktop cloud virtual machine in real time to obtain the computer information of the desktop cloud client of the desktop cloud virtual machine when starting the desktop cloud virtual machine, and perform information authentication.
[0052] S202, save the feature information corresponding to the desktop cloud virtual machine, and log in to the corresponding PVS server based on the feature information.
[0053] It can be understood that the PVS server corresponding to the current tenant will also store the feature information of the computer corresponding to each desktop cloud virtual machine in the corresponding PVS server when binding the desktop cloud virtual machine corresponding to the current tenant. On this basis, the PVS server will obtain the corresponding computer feature information from the corresponding PVS server each time the bound desktop cloud virtual machine is detected, so as to perform information authentication on the corresponding desktop cloud virtual machine based on the computer feature information.
[0054] For example, when the PVS server binds the desktop cloud virtual machine 1, the computer information of the desktop cloud client to which the desktop cloud virtual machine 1 belongs is obtained, and the obtained computer information corresponding to the desktop cloud virtual machine 1 is stored in the PVS server. When the desktop cloud virtual machine is detected to start, the PVS server will call the pre-stored computer information corresponding to the desktop cloud virtual machine 1, and perform information authentication on the computer information to determine whether the desktop cloud virtual machine 1 is the virtual machine bound with the PVS server. If yes, the desktop cloud virtual machine 1 can be allowed to obtain data resources from the PVS server; otherwise, the desktop cloud virtual machine 1 is not allowed to obtain data resources from the PVS server.
[0055] The advantage of such setting is that each tenant can obtain data resources from the corresponding PVS server after information authentication, avoiding other tenants to obtain data resources that do not belong to them, and improving the security of the data resources of the tenants.
[0056] The data processing method, device, equipment and storage medium provided by the present application create a desktop cloud virtual machine for the current tenant based on the PVS server, and bind the PVS server and the desktop cloud virtual machine, by binding the PVS server corresponding to the current tenant and the desktop cloud virtual machine of the current tenant, the start of the desktop cloud virtual machine can be detected based on the PVS server to verify the information of the desktop cloud virtual machine. Save the feature information corresponding to the desktop cloud virtual machine, and log in to the corresponding PVS server based on the feature information. The computer feature information corresponding to the desktop cloud virtual machine is stored in the corresponding PVS server, so that the corresponding authentication information can be retrieved from the PVS server when the desktop cloud virtual machine is detected to start, to determine whether the desktop cloud virtual machine being started is the bound desktop cloud virtual machine. If so, the desktop cloud virtual machine can obtain data resources from the PVS server. By authenticating the information of the desktop cloud virtual machine, the security of the data resources of the tenant can be improved. The problem of information leakage in the process of obtaining resources in the multi-tenant application scenario is solved, and the security of the data resources of each tenant is improved, and the risk of data leakage is reduced.
[0057] On the basis of the above-mentioned embodiments, in the process of creating a desktop cloud virtual machine based on the PVS server corresponding to each tenant, the method further comprises: for each tenant, allocating a corresponding network segment to the desktop cloud virtual machine of the current tenant, so that when the desktop cloud virtual machine starts, it logs in to the corresponding PVS server based on the network segment and feature information corresponding to the desktop cloud virtual machine. Correspondingly, the present application provides the following embodiments:
[0058] Figure 3 The flow of the data processing method provided by the present application Figure 3 As shown in Figure 4 , the data processing method comprises the following steps:
[0059] S301, for each tenant, determine the number of desktop cloud concurrent sessions of the current tenant, and determine the number of PVS servers corresponding to the current tenant.
[0060] S302, allocate a corresponding PVS server to the current tenant based on the number of servers.
[0061] S303, for each tenant, allocate a corresponding network segment to the desktop cloud virtual machine of the current tenant, so that when the desktop cloud virtual machine starts, it logs in to the corresponding PVS server based on the network segment and feature information corresponding to the desktop cloud virtual machine.
[0062] Specifically, when creating a desktop cloud virtual machine for each tenant, a corresponding network segment can be allocated to the desktop cloud virtual machine of each tenant.
[0063] Exemplarily, for different tenants, each tenant corresponds to a unique network segment, taking the current tenant as an example, the network segment corresponding to the current tenant can include multiple network segment addresses, such as IP addresses. According to the number of PVS servers of the current tenant, a corresponding network segment address can be created for each PVS server in the network segment of the current tenant. Further, each PVS server can correspond to one or more desktop cloud virtual machines, and a corresponding network segment address is also allocated for each desktop cloud virtual machine. For example, the network segment corresponding to the current tenant is network segment 1, and the number of PVS servers corresponding to the current tenant is 3, then a corresponding network segment is allocated for each PVS server in the network segment 1, which are network segment a, network segment b and network segment c respectively. Further, each PVS server corresponds to 10 desktop cloud virtual machines respectively, and the network segment addresses of the desktop clouds in the corresponding network segment are determined respectively. Taking network segment a as an example, a corresponding network segment address is allocated for each desktop cloud virtual machine bound to the PVS server in the network segment a, which are a1-a10 respectively. When detecting the start of the desktop cloud virtual machine, first, the network segment address corresponding to the desktop cloud virtual machine is determined, such as the network segment address a1, then the PVS server corresponding to the desktop cloud virtual machine can be determined, and the network segment corresponding to the PVS server is network segment a. Further, the network segment corresponding to the tenant corresponding to the desktop cloud virtual machine is network segment 1.
[0064] That is, by allocating a corresponding network segment to each desktop cloud virtual machine, the PVS server corresponding to each desktop cloud virtual machine and the information such as the network segment to which it belongs can be determined, so as to determine the PVS server for information authentication of the desktop cloud virtual machine when detecting the start of the desktop cloud virtual machine, and log in to the corresponding PVS server based on the network segment and feature information corresponding to the desktop cloud virtual machine.
[0065] Optionally, a server address corresponding to the network segment is configured; wherein the server address corresponds to a load balancing address of the PVS server.
[0066] In the technical scheme provided in the embodiment of the application, each PVS server can correspond to a unique load balancing server, and based on this, when allocating a server address to the PVS server, the load balancing address of the corresponding load balancing server can be taken as the server address corresponding to the PVS server.
[0067] The advantage of the arrangement is that when a user logs in through the desktop cloud virtual machine, if corresponding request information is sent through the desktop cloud virtual machine, the request information can be sent to the corresponding PVS server. Further, the PVS server determines the load balancing server that can be used based on the corresponding configuration network segment, and sends the request information to the load balancing server, so as to determine the request processing server that can process the request information based on the load balancing server. When the request processing server obtains corresponding data resources according to the request information, the data resources can be fed back to the desktop cloud virtual machine sending the request information through the load balancer.
[0068] Optionally, the server address corresponding to the configuration network segment comprises: configuring the server address for the network segment based on at least two dynamic host configuration protocols, and setting the at least two dynamic host configuration protocols as a fault detection module to detect the conflict of the server address.
[0069] In the technical scheme provided by the embodiment of the application, when the server address corresponding to the configuration network segment of the PVS server is configured, in order to ensure the high availability of the server address, the network segment addresses of at least two load balancing servers can be set as the server address, that is, at least two load balancing servers are deployed, and fault detection modules are set respectively, so that when the number of request information sent by the PVS server is large, the conflict of the server address is avoided, the sending of the request information is not failed, and the data resources that the desktop cloud virtual machine sending the request information can be fed back are ensured.
[0070] The data processing method, device, equipment and storage medium provided by the application can allocate a corresponding network segment to the desktop cloud virtual machine of the current tenant for each tenant, so that when the desktop cloud virtual machine starts, the desktop cloud virtual machine logs in to the corresponding PVS server based on the network segment and the feature information corresponding to the desktop cloud virtual machine. The PVS server corresponding to the desktop cloud virtual machine can be determined when the desktop cloud virtual machine starts, and whether the desktop cloud virtual machine can log in to the corresponding PVS server can be determined, so that data resources can be obtained from the corresponding PVS server. The problem of possible data leakage in the multi-tenant scenario is solved, and the security of the data resources of each tenant is improved.
[0071] On the basis of the above-mentioned embodiments, in order to make the person skilled in the art further clear the technical scheme of the embodiments of the application, the data processing method is introduced in detail through specific examples as follows:
[0072] In one specific example, as Figure 5As shown, based on the network area isolation of each tenant by the multi-tenant multiplexing controller, the corresponding isolated area is allocated to each tenant, and the multi-tenant multiplexing control is multiplexed to sink the preparation component (i.e., the PVS server) to the isolated area where each tenant is located. For example, tenant A, tenant B and tenant C are located in different isolated areas, and in each isolated area, the preparation component (i.e., the PVS server) corresponding to each tenant is set, and the desktop cloud virtual machine corresponding to each tenant is created based on each preparation component. In the technical solution provided in the embodiment of the present application, three multi-tenant multiplexing controllers are deployed to ensure that the desktop cloud virtual machine can normally run when one of the multi-tenant multiplexing controllers fails.
[0073] Specifically, when the PVS server is sunk to the isolated area of each tenant, the number of PVS servers corresponding to each tenant needs to be determined first. Taking the current tenant as an example, the number of desktop cloud concurrency and the number of desktop cloud clients of the current tenant are determined, and a first value is obtained based on the ratio of the number of desktop cloud concurrency and the number of desktop cloud clients. Further, the number of standby PVS servers (i.e., the preset value) is determined, and the server number of the PVS server corresponding to the current tenant is obtained based on the sum of the first value and the preset value. Then, the corresponding number of PVS servers is sunk to the isolated area where the current tenant is located, and these PVS servers are limited to create desktop cloud virtual machines for the current tenant.
[0074] After allocating the corresponding number of PVS servers to the current tenant, the PVS server can be bound to the desktop cloud virtual machine of the current tenant, so as to perform information authentication on the desktop cloud virtual machine based on the corresponding PVS server when the desktop cloud virtual machine is detected to start.
[0075] In addition, in the process of creating the desktop cloud virtual machine, the PVS server also stores the computer feature information corresponding to the computer to which the desktop cloud virtual machine belongs, so as to log in to the corresponding PVS server based on the feature information of the corresponding computer when the desktop cloud virtual machine is detected to start.
[0076] Further, the technical scheme provided by the embodiment of the present application further configures a corresponding network segment for the desktop cloud virtual machine of each tenant, so that when the desktop cloud virtual machine is started, the desktop cloud virtual machine is authenticated according to the network segment corresponding to the desktop cloud virtual machine and the characteristic information of the computer to which the desktop cloud virtual machine belongs, and it is determined whether the corresponding PVS server can be logged in. It should be noted that in the technical scheme provided by the embodiment of the present application, a corresponding network segment is configured for each PVS server, and each PVS server corresponds to a unique load balancing server, so that when the PVS server receives the request information sent by the desktop cloud virtual machine, the request information is processed based on the corresponding load balancing server, and the data resources corresponding to the request information are fed back to the desktop cloud virtual machine sending the request information.
[0077] It should be noted that in the technical scheme provided by the embodiment of the present application, because there is isolation between each tenant, each tenant can personalize the corresponding desktop cloud virtual machine template. For example, after a tenant exclusively occupies a PVS preparation server, this set of PVS server will only deliver the template of the tenant, and in the template, the software license purchased by the tenant can be included, and a BYOL (customer carries a purchased license, reduces the overhead of repeated software purchase) service similar to the public cloud service can be provided. In addition, the template can also provide different basic software configurations, such as different JAVA Runtime versions and different IE browser versions than the basic template, so as to realize the isolation between tenants based on template resources and template management permissions.
[0078] The data processing method, device, equipment and storage medium provided by the application determine the desktop cloud concurrency of a current tenant and the number of PVS servers corresponding to the current tenant for each tenant, obtain a first value by determining the ratio of the desktop cloud concurrency and the number of desktop cloud clients corresponding to each tenant, further obtain the number of PVS servers corresponding to each tenant according to the first value and the number of standby PVS servers (i.e. a preset value). The corresponding PVS server is allocated to the current tenant based on the number of servers, and a corresponding number of PVS servers are sunk in the isolation area corresponding to each tenant according to the number of servers, so as to prepare desktop cloud virtual machines for each tenant based on the PVS servers corresponding to each tenant. The desktop cloud virtual machine is created based on the PVS server corresponding to each tenant, so as to log in to the corresponding PVS server based on the feature information of the service node to which the desktop cloud virtual machine belongs when the desktop cloud virtual machine starts, control the access of the desktop cloud virtual machine based on the PVS server, and obtain corresponding data. In the technical solution provided in the embodiment of the application, the PVS server corresponding to each tenant can create a desktop cloud virtual machine for the corresponding tenant, and when it is detected that the desktop cloud virtual machine starts, the PVS server performs information authentication on the desktop cloud virtual machine to determine whether the desktop cloud virtual machine can access the PVS server to obtain data resources from the PVS server. The problem that the desktop cloud virtual machine cannot be prepared for each tenant flexibly in a multi-tenant scenario, and the resource data of each tenant is not isolated, which may cause a data leakage risk, is solved, and the effects of flexibly creating a desktop cloud virtual machine for each tenant and ensuring that the tenant can safely obtain data resources based on the desktop cloud virtual machine are achieved.
[0079] Figure 5 The structure diagram of the data processing device provided in the embodiment of the application is shown in FIG. 1. Figure 6 As shown in the figure, the data processing device comprises a server number determination module 401, a server allocation module 402 and a desktop cloud creation module 403.
[0080] The server number determination module 401 is configured to determine the desktop cloud concurrency of a current tenant and the number of PVS servers corresponding to the current tenant for each tenant. The server allocation module 402 is configured to allocate the corresponding PVS server to the current tenant based on the number of servers. The desktop cloud creation module 403 is configured to create a desktop cloud virtual machine based on the PVS server corresponding to each tenant, log in to the corresponding PVS server based on the feature information of the service node to which the desktop cloud virtual machine belongs when the desktop cloud virtual machine starts, control the access of the desktop cloud virtual machine based on the PVS server, and obtain corresponding data.
[0081] The data processing method, device, equipment and storage medium provided in the application, for each tenant, determine the desktop cloud concurrency number of the current tenant, determine the server number of the PVS server corresponding to the current tenant, determine the ratio of the desktop cloud concurrency number and the desktop cloud client number corresponding to each tenant to obtain a first value, further, according to the first value and the server number of the standby PVS server (i.e., a preset value), the server number of the PVS server corresponding to each tenant can be obtained. Based on the server number, the corresponding PVS server is allocated to the current tenant, and a corresponding number of PVS servers are sunken in the isolation area corresponding to each tenant according to the server number, so as to prepare the desktop cloud virtual machine for each tenant based on the PVS server corresponding to each tenant. The desktop cloud virtual machine is created based on the PVS server corresponding to each tenant, so that when the desktop cloud virtual machine starts, the corresponding PVS server is logged in based on the feature information of the service node to which the desktop cloud virtual machine belongs, and the access of the desktop cloud virtual machine is controlled based on the PVS server to obtain corresponding data. In the technical scheme provided in the embodiment of the application, the PVS server corresponding to each tenant can create the desktop cloud virtual machine for the corresponding tenant, and when it is detected that the desktop cloud virtual machine starts, the information of the desktop cloud virtual machine is authenticated based on the corresponding PVS server to determine whether the desktop cloud virtual machine can access the PVS server to obtain data resources from the corresponding PVS server. The problem that in the multi-tenant scenario, the desktop cloud virtual machine cannot be prepared for each tenant flexibly, and the resource data of each tenant is not isolated, which may cause a data leakage risk, is solved, and the effects of flexibly creating the desktop cloud virtual machine for each tenant and ensuring that the tenant can safely obtain data resources based on the desktop cloud virtual machine are achieved.
[0082] In some embodiments, optionally, the server number determination module 401 comprises a first value determination submodule for determining a first value based on the desktop cloud concurrency number and the polling information.
[0083] The server number determination submodule is configured to determine the server number of the PVS server corresponding to the current tenant based on the first value and the preset value.
[0084] In some embodiments, optionally, the data processing device further comprises a server binding module configured to create a desktop cloud virtual machine for the current tenant based on the PVS server after the corresponding PVS server is allocated to the current tenant, and bind the PVS server and the desktop cloud virtual machine.
[0085] In some embodiments, optionally, the data processing device comprises a feature information saving module configured to save the feature information corresponding to the desktop cloud virtual machine after the corresponding PVS server is allocated to the current tenant, and log in to the corresponding PVS server based on the feature information.
[0086] In some embodiments, the desktop cloud creating module 403, optionally, comprises a network segment allocating sub-module, configured to allocate a corresponding network segment to the desktop cloud virtual machine of the current tenant for each tenant, so as to log in to the corresponding PVS server based on the network segment and the feature information corresponding to the desktop cloud virtual machine when the desktop cloud virtual machine is started.
[0087] In some embodiments, the desktop cloud creating module 403, optionally, further comprises a server address configuring sub-module, configured to configure the server address corresponding to the network segment; wherein the server address corresponds to the load balancing address of the PVS server.
[0088] In some embodiments, the server address configuring sub-module, optionally, comprises a fault detecting sub-module, configured to configure the server address for the network segment based on at least two dynamic host configuration protocols, and set the at least two dynamic host configuration protocols as the fault detecting module to detect the conflict of the server address.
[0089] The data processing apparatus provided by the embodiments of the present application can be used to execute the technical solutions of the data processing method in the above embodiments, and has similar implementation principles and technical effects, which will not be described here.
[0090] It should be noted that the division of each module of the above apparatus should be understood as a logical function division, and all or part of the modules can be integrated into one physical entity, or can be physically separated. Moreover, all the modules can be implemented in the form of software invoked by a processing element; all the modules can also be implemented in the form of hardware; or part of the modules can be implemented in the form of software invoked by a processing element, and part of the modules can be implemented in the form of hardware. For example, the server quantity determining module 401 can be a separately established processing element, or can be integrated into a chip of the above apparatus, and in addition, the server quantity determining module 401 can also be stored in the form of program code in the memory of the above apparatus, and the functions of the server quantity determining module 401 can be invoked and executed by a processing element of the above apparatus. The implementation of other modules is similar. Moreover, all or part of the modules can be integrated together, or can be independently implemented. The processing element herein can be an integrated circuit having a signal processing capability. In the implementation process, each step of the above method or each module can be completed by the integrated logic circuit of hardware or the instruction of software in the processing element.
[0091] Figure 6 The structure schematic diagram of the electronic device provided by the embodiments of the present application is shown in FIG. 1. As shown in FIG. 1, the electronic device can include a transceiver 121, a processor 122, and a memory 123.
[0092] The processor 122 executes computer-executed instructions stored in the memory to cause the processor 122 to perform the solutions in the above-described embodiments. The processor 122 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; and can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.
[0093] The memory 123 is connected with the processor 122 through the system bus and completes mutual communication, and the memory 123 is used for storing computer program instructions.
[0094] The transceiver 121 can be used to send a target processing result corresponding to a service request.
[0095] The system bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The system bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or only one type of bus. The transceiver is used to realize the communication between the database access device and other computers (for example, a client, a read-write library and a read-only library). The memory can include a random access memory (RAM), and can also include a non-volatile memory.
[0096] The electronic device provided by the embodiments of the present application can be the terminal device of the above-described embodiments.
[0097] The embodiments of the present application further provide a chip for running instructions, which is used to execute the technical solutions of the data processing method in the above-described embodiments.
[0098] The embodiments of the present application further provide a computer readable storage medium, which stores computer instructions, and when the computer instructions are run on a computer, the computer executes the technical solutions of the data processing method in the above-described embodiments.
[0099] The embodiments of the present application further provide a computer program product, which includes a computer program stored in a computer readable storage medium, at least one processor can read the computer program from the computer readable storage medium, and when the at least one processor executes the computer program, the technical solutions of the data processing method in the above-described embodiments can be implemented.
[0100] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the specification and examples be considered as exemplary only, with the true scope and spirit of the application being indicated by the following claims.
[0101] It is to be understood that the application is not limited to the precise construction herein disclosed and shown in the drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application is limited only by the claims that follow.
Claims
1. A data processing method, characterized by, The method comprises the following steps: For each tenant, determine the number of concurrent desktop clouds of the current tenant; Send polling information to the desktop cloud client associated with the current tenant to determine the number of desktop cloud clients actually used at the current time; Obtain a first value according to the ratio of the number of concurrent desktop clouds to the number of desktop cloud clients actually used; Determine the number of PVS servers corresponding to the current tenant according to the sum of the first value and a preset value, wherein the preset value is the number of standby PVS servers; Isolate the network area of each tenant based on a multi-tenant multiplexing controller, and allocate a corresponding isolated area to each tenant; Sink the PVS servers with the number of servers to the isolated area corresponding to the current tenant as the PVS servers corresponding to the current tenant; Create a desktop cloud virtual machine for the current tenant based on the PVS servers, and bind the PVS servers and the desktop cloud virtual machine, and allocate a corresponding network segment to the desktop cloud virtual machine of the current tenant; Store the feature information of the computer corresponding to each desktop cloud virtual machine in the corresponding PVS server; When it is detected that the desktop cloud virtual machine is started, authenticate the desktop cloud virtual machine according to the network segment corresponding to the desktop cloud virtual machine and the feature information of the computer, and determine whether the desktop cloud virtual machine can log in to the corresponding PVS server; If yes, control the access of the desktop cloud virtual machine based on the PVS server to obtain corresponding data.
2. The method of claim 1, wherein, Further comprising: Configure the server address corresponding to the network segment; The server address corresponds to the load balancing address of the PVS server.
3. The method of claim 2, wherein, The configuration of the server address corresponding to the network segment comprises: Configure the server address for the network segment based on at least two dynamic host configuration protocols, and set the at least two dynamic host configuration protocols as a fault detection module to detect the conflict of the server address.
4. A data processing apparatus, characterized by, The method comprises the following steps: A server number determination module is configured to determine the number of concurrent desktop clouds of the current tenant for each tenant, and determine the number of PVS servers corresponding to the current tenant; A server allocation module is configured to allocate a corresponding PVS server to the current tenant based on the number of servers; A desktop cloud creation module is configured to create a desktop cloud virtual machine based on the PVS server corresponding to each tenant, log in to the corresponding PVS server based on the feature information of the service node to which the desktop cloud virtual machine belongs when the desktop cloud virtual machine is started, control the access of the desktop cloud virtual machine based on the PVS server to obtain corresponding data; The server number determination module comprises: A first value determination submodule is configured to send polling information to the desktop cloud client associated with the current tenant to determine the number of desktop cloud clients actually used at the current time, and obtain a first value according to the ratio of the number of concurrent desktop clouds to the number of desktop cloud clients actually used. The server quantity determination sub-module is configured to determine the server quantity of the PVS server corresponding to the current tenant according to the sum of the first value and a preset value, wherein the preset value is the quantity of the backup PVS server which is preset in advance. The server allocation module is configured to isolate the network area of each tenant based on the multi-tenant multiplexing controller, allocate an isolated area to each tenant, and sink the PVS server of the server quantity to the isolated area corresponding to the current tenant as the PVS server corresponding to the current tenant. The desktop cloud creation module is configured to create a desktop cloud virtual machine for the current tenant based on the PVS server, bind the PVS server and the desktop cloud virtual machine, and allocate a corresponding network segment to the desktop cloud virtual machine of the current tenant, store the feature information of the computer corresponding to each desktop cloud virtual machine in the corresponding PVS server, and when detecting that the desktop cloud virtual machine is started, authenticate the desktop cloud virtual machine according to the network segment corresponding to the desktop cloud virtual machine and the feature information of the computer, determine whether the corresponding PVS server can be logged in, and if so, control the access of the desktop cloud virtual machine based on the PVS server to obtain corresponding data.
5. The apparatus of claim 4, wherein, The network segment allocation module comprises: The fault detection sub-module is configured to configure a server address for the network segment based on at least two dynamic host configuration protocols, and set the at least two dynamic host configuration protocols as a fault detection module to detect the conflict of the server address.
6. An electronic device, comprising: It comprises: A processor and a memory connected in communication with the processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to implement the data processing method of any one of claims 1-3.
7. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method of any one of claims 1-3.
8. A computer program product, characterised in that, It comprises a computer program which, when executed by the processor, implements the data processing method of any one of claims 1-3.
Citation Information
Patent Citations
Multi-tenant multi-session catalogs with machine-level isolation
CN108139944A