High-availability implementation method, system and device of cloud security resource pool and storage medium

CN116455731BActive Publication Date: 2026-09-22BEIJING SHANGYUAN XINAN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310498117.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-05
Publication Date
2026-09-22
Estimated Expiration
2043-05-05

AI Technical Summary

Technical Problem

现有的技术方案具有控制粒度粗,切换影响范围广的问题

Benefits of technology

[0042]本申请通过获取相关资源服务器功能单元的相关运行状态;利用所述相关资源服务器功能单元的相关运行状态,通过心跳机制进行检测;若所述检测的结果不符合第一预设规则,则执行流量切换模式;基于所述流量切换模式的执行结果,得到云安全资源池的高可用实现结果。本申请在出现单点故障后,通过执行流量切换模式,实现在不影响云安全资源池网络安全功能的前提下,细粒度的控制,极大的减小网络切换的影响范围。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455731B_ABST
    Figure CN116455731B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network information security, in particular to a high-availability implementation method, system and device of a cloud security resource pool and a storage medium. The application obtains the relevant running states of relevant resource server function units, detects the relevant running states of the relevant resource server function units through a heartbeat mechanism, executes a traffic switching mode if the detection result does not conform to a first preset rule, and obtains a high-availability implementation result of the cloud security resource pool based on the execution result of the traffic switching mode. After a single-point fault occurs, the traffic switching mode is executed, fine-grained control is realized under the premise that the network security function of the cloud security resource pool is not affected, and the influence range of network switching is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network information security technology, and in particular to high availability implementation methods, systems, devices and storage media for cloud security resource pools. Background Technology

[0002] Traditional security gateway devices are broadly categorized into firewall systems, internet access management systems, intrusion prevention systems, and virus protection management systems. Their high availability (HA) often relies on physical heartbeat lines and support for traditional network protocols (such as ARP).

[0003] Existing high availability (HA) implementations for gateway devices are primarily designed for traditional networking models and are not suitable for cloud security resource pool scenarios. In cloud security resource pool scenarios, traffic is typically diverted to the security capability units of the resource pool via policy routing or OpenFlow flow tables using referral switches. The granularity of HA implementation is based on the resource pool server. That is, in the event of a single point of failure, all traffic is switched from the resource server functional unit to the backup resource pool server. Existing technical solutions suffer from coarse control granularity and a wide-ranging impact during switching.

[0004] In other words, existing high availability implementation methods for cloud security resource pools, when a single point of failure occurs, switch all traffic from the resource server functional unit to the backup resource pool server. This has the problems of coarse control granularity and wide impact of the switch. Summary of the Invention

[0005] To at least partially overcome the problems of coarse control granularity and wide impact of switching all traffic from the resource server functional unit to the backup resource pool server after a single point of failure in related technologies, this application provides a high availability implementation method, system, device and storage medium for cloud security resource pools.

[0006] The proposed solution is as follows:

[0007] Firstly, this application provides a method for implementing high availability of cloud security resource pools, the method comprising:

[0008] Obtain the relevant operational status of the functional units of the relevant resource server;

[0009] The relevant operational status of the associated resource server functional units is used for detection via a heartbeat mechanism;

[0010] If the detection result does not meet the first preset rule, then the traffic switching mode is executed;

[0011] Based on the execution results of the traffic switching mode, the high availability of the cloud security resource pool is achieved.

[0012] Furthermore, the detection of the relevant operating status of the related resource server functional unit through a heartbeat mechanism includes:

[0013] The relevant operating status of the resource server functional units is detected by periodically sending heartbeat packets between the primary and backup functional units, utilizing the relevant operating status of the resource server functional units.

[0014] If a response is received from the resource server functional unit within a preset time, it indicates that the current status of the resource server functional unit is online.

[0015] Otherwise, the current state of the resource server functional unit is abnormal.

[0016] Furthermore, the first preset rule includes:

[0017] The resource server functional unit is currently online.

[0018] Furthermore, if the detection result does not conform to the first preset rule, the corresponding traffic switching mode is executed, including:

[0019] If the detection result does not conform to the first preset rule, the pre-acquired mode selection information will be further judged.

[0020] If the obtained mode selection information is the first traffic switching mode, then the status of the relevant resource server functional unit is reported through the traffic scheduling capability of the cloud security management platform, and the relevant traffic switching request is executed.

[0021] If the obtained mode selection information is the second traffic switching mode, then the relevant traffic switching request is executed by adding a preset communication plugin to the virtual switch.

[0022] Furthermore, if the obtained mode selection information is a first traffic switching mode, then the status of the relevant resource server functional units is reported through the traffic scheduling capability of the cloud security management platform, and relevant traffic switching requests are executed, including:

[0023] If the obtained mode selection information is the first traffic switching mode, the virtual switch will send the relevant message about the offline status of the relevant resource server functional unit interface to the cloud security management platform.

[0024] The cloud security management platform receives the relevant message about the offline status of the relevant resource server functional unit interface and sends a traffic switching request to the virtual switch;

[0025] The virtual switch receives the traffic switching request from the cloud security management platform and switches the traffic to the relevant backup resource pool server.

[0026] Furthermore, if the obtained mode selection information is a second traffic switching mode, then by adding a preset communication plugin to the virtual switch, the relevant traffic switching request is executed, including:

[0027] If the obtained mode selection information is the second traffic switching mode, then the online message of the relevant backup resource pool server is received by adding a preset communication plugin to the virtual switch.

[0028] The determination is made using the first request instruction and the online message of the relevant backup resource pool server;

[0029] If the interface status of the primary and backup walls of the relevant resource server functional unit is closed and the running status of the relevant backup resource pool server is online, the traffic is switched to the relevant backup resource pool server through the virtual switch.

[0030] Wherein, the first request instruction includes:

[0031] The full management platform will switch the traffic that needs to be processed to the corresponding backup resource pool server for the virtual switch based on the relevant interface shutdown message.

[0032] Secondly, this application provides a high-availability implementation system for cloud security resource pools, the system comprising:

[0033] The acquisition module is used to acquire the relevant operating status of the functional units of the relevant resource server;

[0034] The detection module is used to perform detection through a heartbeat mechanism by utilizing the relevant operating status of the related resource server functional units;

[0035] The switching module is used to execute a traffic switching mode if the detection result does not meet the first preset rule;

[0036] The execution module is used to obtain the high availability implementation result of the cloud security resource pool based on the execution result of the traffic switching mode.

[0037] Thirdly, this application provides a high-availability implementation device for cloud security resource pools, the device comprising:

[0038] Memory, on which executable programs are stored;

[0039] A processor for executing the executable program in the memory to implement the steps of any of the methods described above.

[0040] Fourthly, this application provides a computer-readable storage medium storing computer instructions for causing a computer to perform the steps of any of the methods described above.

[0041] The technical solution provided in this application may include the following beneficial effects:

[0042] This application obtains the relevant operational status of the functional units of the relevant resource server; uses the operational status of the relevant resource server functional units to perform detection through a heartbeat mechanism; if the detection result does not meet the first preset rule, a traffic switching mode is executed; based on the execution result of the traffic switching mode, the high availability implementation result of the cloud security resource pool is obtained. In the event of a single point of failure, this application achieves fine-grained control without affecting the network security function of the cloud security resource pool by executing the traffic switching mode, greatly reducing the impact range of network switching.

[0043] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0044] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0045] Figure 1 This is a flowchart illustrating a high availability implementation method for a cloud security resource pool according to one embodiment of this application;

[0046] Figure 2 This is a schematic diagram illustrating a use case of a cloud security resource pool provided in another embodiment of this application;

[0047] Figure 3 This is a schematic diagram of a firewall (FW) provided in another embodiment of this application;

[0048] Figure 4 This is a high-availability networking diagram of a gateway device provided in another embodiment of this application;

[0049] Figure 5 This is a flowchart illustrating the design of a high-availability implementation method for a cloud security resource pool, provided in yet another embodiment of this application.

[0050] Figure 6 This is a flowchart illustrating the design and optimization of a high-availability implementation method for a cloud security resource pool, provided in yet another embodiment of this application.

[0051] Figure 7This is a schematic diagram of the composition process of a high availability implementation system for a cloud security resource pool provided in one embodiment of this application;

[0052] Figure 8 This is a schematic diagram of the device composition process for a high availability implementation of a cloud security resource pool, provided in one embodiment of this application. Detailed Implementation

[0053] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0054] Cloud computing represents a significant revolution in information technology and service models, profoundly impacting traditional software development and deployment methods, network traffic flow, and the structure of the IT industry chain. In a cloud computing ecosystem, storage and computing resources are centrally located in a public cloud resource pool, enabling customers to access them conveniently and on a pay-as-you-go basis via the network. To some extent, the cloud resource pool is the core of cloud services.

[0055] The cloud security resource pool is a subset of the cloud resource pool. It typically interfaces with the cloud platform in a loosely coupled manner, directing traffic requiring protection into the security pool for security protection. It provides cloud tenants with personalized security capability packages, primarily addressing the following issues:

[0056] 1. Solved the problem of elastic scaling of security capabilities.

[0057] 2. Solved the problem of combining security capabilities on demand and providing them to cloud tenants.

[0058] 3. Solves the problem that traditional security hardware cannot be deployed in the cloud.

[0059] The use cases for cloud security resource pools are as follows: Figure 2 As shown:

[0060] The cloud security resource pool is a one-stop, elastic, flexible, and highly reliable security solution designed to address the north-south and east-west traffic security protection and security auditing needs of cloud-based businesses. The cloud security resource pool realizes the service-oriented and pooled nature of security capabilities, providing multi-tenant access to a rich set of virtualized security components, including next-generation firewalls, virus protection, intrusion prevention, and web application firewalls. Users can perform automated security service chain orchestration to provide comprehensive L2-L7 layer security protection for business traffic according to their needs, effectively ensuring that cloud-based businesses meet the security compliance requirements of cloud-based information security standards.

[0061] Traditional security gateway devices are broadly categorized into firewall systems, internet access management systems, intrusion prevention systems, and virus protection management systems. Their high availability (HA) often relies on physical heartbeat lines and support for traditional network protocols (such as ARP), as follows: Figure 3 As shown (using a firewall as an example).

[0062] Existing high availability (HA) implementations for gateway devices are primarily designed for traditional networking models and are not suitable for cloud security resource pool scenarios. In cloud security resource pool scenarios, traffic is typically diverted to the security capability units of the resource pool via policy routing or OpenFlow flow tables using referral switches. The high availability network topology is as follows: Figure 4 As shown, its high availability (HA) implementation granularity is based on resource pool servers. That is, in the event of a single point of failure, all traffic is switched from the resource server functional unit to the backup resource pool server. This approach has the problem of coarse control granularity and a wide range of impact from the switchover.

[0063] This application provides a method, system, device, and storage medium for achieving high availability of a cloud security resource pool. It obtains the relevant operational status of the functional units of the resource servers; utilizes the operational status of these functional units through a heartbeat mechanism for detection; if the detection result does not conform to a first preset rule, a traffic switching mode is executed; based on the execution result of the traffic switching mode, the high availability achievement result of the cloud security resource pool is obtained. In the event of a single point of failure, this application achieves fine-grained control by executing a traffic switching mode, without affecting the network security function of the cloud security resource pool, thus greatly reducing the impact range of network switching.

[0064] Example 1

[0065] Please see Figure 1 , Figure 1 This is a flowchart illustrating a high availability implementation method for a cloud security resource pool according to an embodiment of this application. The method includes:

[0066] S1. Obtain the relevant operating status of the relevant resource server functional units;

[0067] S2. Detect the relevant operating status of the related resource server functional units through a heartbeat mechanism;

[0068] S3. If the detection result does not meet the first preset rule, then execute the traffic switching mode;

[0069] S4. Based on the execution result of the traffic switching mode, the high availability implementation result of the cloud security resource pool is obtained.

[0070] In one embodiment, as described in step S2, the detection via a heartbeat mechanism using the relevant operating status of the relevant resource server functional unit includes:

[0071] The relevant operating status of the resource server functional units is detected by periodically sending heartbeat packets between the primary and backup functional units, utilizing the relevant operating status of the resource server functional units.

[0072] If a response is received from the resource server functional unit within a preset time, it indicates that the current status of the resource server functional unit is online.

[0073] Otherwise, the current state of the resource server functional unit is abnormal.

[0074] It should be noted that, in the embodiments of this application, the abnormal status includes, but is not limited to, a machine down.

[0075] Furthermore, the first preset rule includes:

[0076] The resource server functional unit is currently online.

[0077] Furthermore, if the detection result does not conform to the first preset rule, the corresponding traffic switching mode is executed, including:

[0078] If the detection result does not conform to the first preset rule, the pre-acquired mode selection information will be further judged.

[0079] If the obtained mode selection information is the first traffic switching mode, then the status of the relevant resource server functional unit is reported through the traffic scheduling capability of the cloud security management platform, and the relevant traffic switching request is executed.

[0080] If the obtained mode selection information is the second traffic switching mode, then the relevant traffic switching request is executed by adding a preset communication plugin to the virtual switch.

[0081] Furthermore, if the obtained mode selection information is a first traffic switching mode, then the status of the relevant resource server functional units is reported through the traffic scheduling capability of the cloud security management platform, and relevant traffic switching requests are executed, including:

[0082] If the obtained mode selection information is the first traffic switching mode, the virtual switch will send the relevant message about the offline status of the relevant resource server functional unit interface to the cloud security management platform.

[0083] The cloud security management platform receives the relevant message about the offline status of the relevant resource server functional unit interface and sends a traffic switching request to the virtual switch;

[0084] The virtual switch receives the traffic switching request from the cloud security management platform and switches the traffic to the relevant backup resource pool server.

[0085] Furthermore, if the obtained mode selection information is a second traffic switching mode, then by adding a preset communication plugin to the virtual switch, the relevant traffic switching request is executed, including:

[0086] If the obtained mode selection information is the second traffic switching mode, then the online message of the relevant backup resource pool server is received by adding a preset communication plugin to the virtual switch.

[0087] The determination is made using the first request instruction and the online message of the relevant backup resource pool server;

[0088] If the interface status of the primary and backup walls of the relevant resource server functional unit is closed and the running status of the relevant backup resource pool server is online, the traffic is switched to the relevant backup resource pool server through the virtual switch.

[0089] Wherein, the first request instruction includes:

[0090] The full management platform will switch the traffic that needs to be processed to the corresponding backup resource pool server for the virtual switch based on the relevant interface shutdown message.

[0091] In one embodiment, the specific implementation steps are as follows, and the schematic diagram of the scheme is as follows. Figure 5 As shown, taking a firewall (FW Firewall) as an example, (M represents Master, the primary firewall, and B represents Backup, the backup firewall).

[0092] 1. Reuse the heartbeat mechanism from the traditional solution;

[0093] 2. After the primary device fails (e.g., the primary device goes down), the backup device cannot detect the primary device's heartbeat, and a high-availability (HA) switchover occurs;

[0094] 3. If the main device fails, the main device's connection to the vswitch interface will also go down synchronously.

[0095] 4. vswitch sends a down message from the main device interface to the cloud security management platform;

[0096] 5. The cloud security management platform sends a message to vswitch to switch traffic to the backup machine based on the interface down message;

[0097] 6. Vswitch switches traffic to the backup machine.

[0098] It should be noted that HA stands for High Availability, which means that when the heartbeat detection fails, that is, when a connectivity problem is detected between them, a switchover will occur.

[0099] To further optimize the solution and address the potential switching latency issue caused by network interaction with the "cloud security management platform" in steps 3-5 of the above approach, a plugin for communication with the firewall is added to vswitch. The solution is as follows: Figure 6 As shown.

[0100] The optimized process is as follows:

[0101] 1. Reuse the heartbeat mechanism from the traditional solution;

[0102] 2. When the main equipment fails (e.g., the main equipment goes down), the backup equipment cannot detect the heartbeat of the main equipment, and a high-availability (HA) switchover occurs.

[0103] 3. If the main device fails, the main device's connection to the vswitch interface will also go down.

[0104] 4. vswitch receives the backup wall online message through the plugin;

[0105] 5. Use vswitch to determine the interface status between the standby server online message and the primary / standby firewall.

[0106] 6. Vswitch switches traffic to the backup machine.

[0107] In practice, the current mainstream cloud security resource pool architecture has a coarse-grained implementation of high availability. When a single point of failure occurs, the entire system needs to be switched over, which has a significant impact on the user's network.

[0108] Specifically, this application addresses the above issues by proposing an approach that leverages the high availability implementation of traditional gateway devices within the resource pool. By combining vswitch interface status judgment and dynamic traffic switching, it achieves the function of switching only the faulty network processing unit after a single point of failure. The specific implementation process involves adding a plugin to vswitch to communicate with the firewall, thereby achieving fine-grained control without affecting the network security function of the cloud security resource pool. This greatly reduces the impact of network switching and enables rapid switching.

[0109] Example 2

[0110] Please see Figure 7 , Figure 7 This is a schematic diagram of the composition process of a high availability implementation system for a cloud security resource pool according to an embodiment of this application. The system includes:

[0111] The acquisition module 701 is used to acquire the relevant operating status of the relevant resource server functional units;

[0112] The detection module 702 is used to perform detection through a heartbeat mechanism by utilizing the relevant operating status of the relevant resource server functional unit;

[0113] The switching module 703 is used to execute a traffic switching mode if the detection result does not meet the first preset rule;

[0114] The execution module 704 is used to obtain the high availability implementation result of the cloud security resource pool based on the execution result of the traffic switching mode.

[0115] Example 3

[0116] Please see Figure 8 , Figure 8 This is a schematic diagram illustrating the composition process of a high-availability cloud security resource pool according to an embodiment of this application. The device includes:

[0117] Memory 81, on which an executable program is stored;

[0118] Processor 82 is configured to execute the executable program in the memory to implement the steps of any of the methods described above.

[0119] Furthermore, this application provides a computer-readable storage medium storing computer instructions for causing a computer to perform the steps of any of the methods described above.

[0120] It is understood that the same or similar parts in the above embodiments can be referred to each other, and the contents not described in detail in some embodiments can be referred to the same or similar contents in other embodiments.

[0121] It should be noted that in the description of this application, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this application, unless otherwise stated, "a plurality of" means at least two.

[0122] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this application pertain.

[0123] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0124] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0125] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0126] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.

[0127] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0128] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.

Claims

1. A method for achieving high availability of cloud security resource pools, characterized in that, The method includes: Obtain the relevant operational status of the functional units of the relevant resource server; The relevant operational status of the associated resource server functional units is used for detection via a heartbeat mechanism; If the detection result does not meet the first preset rule, then the traffic switching mode is executed; Based on the execution results of the traffic switching mode, the high availability of the cloud security resource pool is achieved. The first preset rule includes: The current status of the resource server functional unit is online; If the detection result does not meet the first preset rule, the corresponding traffic switching mode is executed, including: If the detection result does not conform to the first preset rule, the pre-acquired mode selection information will be further judged. If the obtained mode selection information is the first traffic switching mode, then the status of the relevant resource server functional unit is reported through the traffic scheduling capability of the cloud security management platform, and the relevant traffic switching request is executed. If the obtained mode selection information is the second traffic switching mode, then the relevant traffic switching request is executed by adding a preset communication plugin to the virtual switch; If the obtained mode selection information is the first traffic switching mode, then the status of the relevant resource server functional units is reported through the traffic scheduling capability of the cloud security management platform, and the relevant traffic switching request is executed, including: If the obtained mode selection information is the first traffic switching mode, the virtual switch will send the relevant message about the offline status of the relevant resource server functional unit interface to the cloud security management platform. The cloud security management platform receives the relevant message about the offline status of the relevant resource server functional unit interface and sends a traffic switching request to the virtual switch; The virtual switch receives the traffic switching request from the cloud security management platform and switches the traffic to the relevant backup resource pool server.

2. The method according to claim 1, characterized in that, The step of utilizing the relevant operational status of the related resource server functional units and detecting it through a heartbeat mechanism includes: The relevant operating status of the resource server functional units is detected by periodically sending heartbeat packets between the primary and backup functional units, utilizing the relevant operating status of the resource server functional units. If a response is received from the resource server functional unit within a preset time, it indicates that the current status of the resource server functional unit is online. Otherwise, the current state of the resource server functional unit is abnormal.

3. The method according to claim 1, characterized in that, If the obtained mode selection information is the second traffic switching mode, then by adding a preset communication plugin to the virtual switch, the relevant traffic switching request is executed, including: If the obtained mode selection information is the second traffic switching mode, then the online message of the relevant backup resource pool server is received by adding a preset communication plugin to the virtual switch. Make a judgment based on the first request command and the online message of the relevant backup resource pool server; If the interface status of the primary and backup walls of the relevant resource server functional unit is closed and the running status of the relevant backup resource pool server is online, the traffic is switched to the relevant backup resource pool server through the virtual switch. Wherein, the first request instruction includes: The cloud security management platform will switch the traffic that needs to be processed to the corresponding backup resource pool server for the virtual switch based on the relevant interface closure message.

4. A high-availability implementation system for a cloud security resource pool, applied to the high-availability implementation method for a cloud security resource pool as described in any one of claims 1-3, characterized in that, The system includes: The acquisition module is used to acquire the relevant operating status of the functional units of the relevant resource server; The detection module is used to perform detection through a heartbeat mechanism by utilizing the relevant operating status of the related resource server functional units; The switching module is used to execute a traffic switching mode if the detection result does not meet the first preset rule; The execution module is used to obtain the high availability implementation result of the cloud security resource pool based on the execution result of the traffic switching mode.

5. A high-availability implementation device for cloud security resource pools, characterized in that: The device includes: Memory, on which executable programs are stored; A processor for executing the executable program in the memory to implement the steps of the method according to any one of claims 1-3.

6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to perform the functions of claim 1.

3. The steps of any of the methods described.

Citation Information

Patent Citations

  • Distributed drainage system and method based on cloud security resource pool

    CN115484208A