Information processing method and device of computing node
By adding an access module to the computing power nodes to perform dual scanning, the problem of malicious reporting of false service capabilities by computing power nodes is solved, realizing low-cost, real-time verification and security classification, and ensuring the accuracy and security of resource scheduling.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2022-04-18
- Publication Date
- 2026-08-04
AI Technical Summary
In existing technologies, there is a problem that malicious nodes may report false service capabilities, which may affect subsequent tasks. At the same time, existing verification methods add extra operating costs before each execution and are not timely enough.
An access module is added to the computing power node. This module scans the computing power resource information and security configuration information and reports the scan results to the computing power security authentication service entity. The access module is configured by the computing power security authentication service entity to prevent malicious nodes from reporting false service capabilities. A double scan is performed before and after task allocation to ensure consistency of results.
It achieves low-cost real-time verification, avoids the false service capabilities of malicious nodes, ensures the real-time and accuracy of scan results, and supports subsequent security classification and resource scheduling.
Smart Images

Figure CN116961944B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to an information processing method and apparatus for computing power nodes. Background Technology
[0002] In related technologies, the authentication of computing power nodes is divided into identity authentication and computing power service capability authentication.
[0003] Among them, identity authentication follows the traditional authentication scheme, while computing power service capability authentication mainly relies on nodes to independently report the computing power capabilities they can provide, obtain the resource information reported by the nodes, and allocate subsequent tasks accordingly.
[0004] From a security perspective, if malicious computing nodes report false service capabilities, it could seriously impact subsequent tasks of the computing power. Therefore, it is necessary to verify the information reported by the nodes.
[0005] The existing solution verifies the correctness of the resource information reported by the nodes by sending corresponding test tasks to verify the task results. However, verifying the nodes through test tasks before each execution of a computing power task will incur additional operating costs; at the same time, if verification is not performed before each execution, it is difficult to guarantee the timeliness of the previous verification results. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to provide an information processing method and apparatus for computing power nodes, which can prevent malicious nodes from reporting false service capabilities.
[0007] To address the aforementioned technical problems, embodiments of the present invention provide the following technical solutions:
[0008] On one hand, embodiments of the present invention provide an information processing method for computing power nodes, applied to the access module of computing power nodes, the method comprising:
[0009] Scan the computing power resource information and security configuration information of the computing power nodes;
[0010] The first scan result obtained from the scan is reported to the computing power security authentication service entity.
[0011] In some embodiments, after reporting the first scan result obtained from the scan to the computing power security authentication service entity, the method further includes:
[0012] Receive orchestration tasks assigned by the computing power network;
[0013] The computing power resource information and security configuration information of the computing power nodes are scanned again;
[0014] The second scan result obtained from the scan is reported to the computing power security authentication service entity.
[0015] In some embodiments, the computing resource information includes at least one of the following:
[0016] Operating system information and operating system version;
[0017] Computing power component version and computing power component permissions;
[0018] Computing resource catalog and computing resource permissions;
[0019] Storage resource directory and storage resource permissions.
[0020] In some embodiments, the security configuration information includes at least one of the following:
[0021] Whether the component has authentication and authorization enabled;
[0022] Is it in safe mode?
[0023] Enable audit logging;
[0024] Log level;
[0025] Log path.
[0026] In some embodiments, before scanning the computing power resource information and security configuration information of the computing power nodes, the method further includes:
[0027] Receive the access module issued by the computing power security authentication service entity.
[0028] This invention also provides an information processing method for computing power nodes, applied to a computing power security authentication service entity, the method comprising:
[0029] The system receives the first scan result reported by the access module of the computing power node, the first scan result including computing power resource information and security configuration information;
[0030] The first scan result is stored in the resource directory corresponding to the computing power node;
[0031] The computing power resource information of the computing power node is reported to the computing power network.
[0032] In some embodiments, after reporting the computing power resource information of the computing power node to the computing power network, the method further includes:
[0033] The system receives the second scan result reported by the access module of the computing power node. The second scan result includes computing power resource information and security configuration information.
[0034] The first scan result is compared with the second scan result. If the first scan result is consistent with the second scan result, the computing power node is notified to execute the orchestration task issued by the computing power network. If the first scan result is inconsistent with the second scan result, an alarm message is sent to the computing power network.
[0035] In some embodiments, after sending alarm information to the computing power network, the method further includes:
[0036] The second scan result is stored in the resource directory corresponding to the computing power node;
[0037] The computing power resource information of the computing power node in the second scan result is reported to the computing power network.
[0038] In some embodiments, the inconsistency between the first scan result and the second scan result includes at least one of the following:
[0039] The operating system information has changed;
[0040] Reduced computing resources;
[0041] Reduced storage resources;
[0042] The security configuration level has been reduced.
[0043] In some embodiments, the computing resource information includes at least one of the following:
[0044] Operating system information and operating system version;
[0045] Computing power component version and computing power component permissions;
[0046] Computing resource catalog and computing resource permissions;
[0047] Storage resource directory and storage resource permissions.
[0048] In some embodiments, the security configuration information includes at least one of the following:
[0049] Whether the component has authentication and authorization enabled;
[0050] Is it in safe mode?
[0051] Enable audit logging;
[0052] Log level;
[0053] Log path.
[0054] In some embodiments, before receiving the first scan result reported by the access module of the computing power node, the method further includes:
[0055] The access module is sent to the computing power node.
[0056] This invention also provides an information processing device for computing power nodes, applied to the access module of computing power nodes. The device includes a processor and a transceiver.
[0057] The processor is used to scan the computing power resource information and security configuration information of the computing power nodes;
[0058] The transceiver is used to report the first scan result obtained from the scan to the computing power security authentication service entity.
[0059] In some embodiments, the transceiver is also used to receive orchestration tasks allocated by the computing power network;
[0060] The processor is also used to scan the computing power resource information and security configuration information of the computing power nodes again;
[0061] The transceiver is also used to report the second scan result obtained from the scan to the computing power security authentication service entity.
[0062] In some embodiments, the computing resource information includes at least one of the following:
[0063] Operating system information and operating system version;
[0064] Computing power component version and computing power component permissions;
[0065] Computing resource catalog and computing resource permissions;
[0066] Storage resource directory and storage resource permissions.
[0067] In some embodiments, the security configuration information includes at least one of the following:
[0068] Whether the component has authentication and authorization enabled;
[0069] Is it in safe mode?
[0070] Enable audit logging;
[0071] Log level;
[0072] Log path.
[0073] In some embodiments, the transceiver is also used to receive the access module issued by the computing power security authentication service entity.
[0074] This invention also provides an information processing device for computing power nodes, applied to a computing power security authentication service entity. The device includes a processor and a transceiver.
[0075] The transceiver is used to receive the first scan result reported by the access module of the computing power node. The first scan result includes computing power resource information and security configuration information.
[0076] The processor is used to store the first scan result in a resource directory corresponding to the computing power node;
[0077] The transceiver is also used to report the computing power resource information of the computing power node to the computing power network.
[0078] In some embodiments, the transceiver is further configured to receive a second scan result reported by the access module of the computing power node, the second scan result including computing power resource information and security configuration information;
[0079] The processor is further configured to compare the first scan result with the second scan result; if the first scan result is consistent with the second scan result, the processor notifies the computing power node to execute the orchestration task issued by the computing power network; if the first scan result is inconsistent with the second scan result, the processor sends an alarm message to the computing power network.
[0080] In some embodiments, the processor is further configured to store the second scan result in a resource directory corresponding to the computing node;
[0081] The transceiver is also used to report the computing power resource information of the computing power node in the second scan result to the computing power network.
[0082] In some embodiments, the inconsistency between the first scan result and the second scan result includes at least one of the following:
[0083] The operating system information has changed;
[0084] Reduced computing resources;
[0085] Reduced storage resources;
[0086] The security configuration level has been reduced.
[0087] In some embodiments, the computing resource information includes at least one of the following:
[0088] Operating system information and operating system version;
[0089] Computing power component version and computing power component permissions;
[0090] Computing resource catalog and computing resource permissions;
[0091] Storage resource directory and storage resource permissions.
[0092] In some embodiments, the security configuration information includes at least one of the following:
[0093] Whether the component has authentication and authorization enabled;
[0094] Is it in safe mode?
[0095] Enable audit logging;
[0096] Log level;
[0097] Log path.
[0098] In some embodiments, the transceiver is also used to send the access module to the computing node.
[0099] This invention also provides an information processing device for a computing power node, including a memory, a processor, and a computer program stored in the memory and executable on the processor; when the processor executes the program, it implements the information processing method for the computing power node as described above.
[0100] In some embodiments, the processor is used to scan the computing power resource information and security configuration information of the computing power node; and to report the first scan result obtained from the scan to the computing power security authentication service entity.
[0101] In some embodiments, the processor is used to receive orchestration tasks allocated by the computing power network; scan the computing power resource information and security configuration information of the computing power nodes again; and report the second scan result obtained from the scan to the computing power security authentication service entity.
[0102] In some embodiments, the computing resource information includes at least one of the following:
[0103] Operating system information and operating system version;
[0104] Computing power component version and computing power component permissions;
[0105] Computing resource catalog and computing resource permissions;
[0106] Storage resource directory and storage resource permissions.
[0107] In some embodiments, the security configuration information includes at least one of the following:
[0108] Whether the component has authentication and authorization enabled;
[0109] Is it in safe mode?
[0110] Enable audit logging;
[0111] Log level;
[0112] Log path.
[0113] In some embodiments, the processor is used to receive the access module issued by the computing power security authentication service entity.
[0114] In some embodiments, the processor is configured to receive a first scan result reported by the access module of the computing power node, the first scan result including computing power resource information and security configuration information; store the first scan result in a resource directory corresponding to the computing power node; and report the computing power resource information of the computing power node to the computing power network.
[0115] In some embodiments, the processor is configured to receive a second scan result reported by the access module of the computing power node, the second scan result including computing power resource information and security configuration information; compare the first scan result with the second scan result; if the first scan result is consistent with the second scan result, notify the computing power node to execute the orchestration task issued by the computing power network; if the first scan result is inconsistent with the second scan result, send an alarm message to the computing power network.
[0116] In some embodiments, the processor is used to store the second scan result in a resource directory corresponding to the computing power node; and to report the computing power resource information of the computing power node in the second scan result to the computing power network.
[0117] In some embodiments, the inconsistency between the first scan result and the second scan result includes at least one of the following:
[0118] The operating system information has changed;
[0119] Reduced computing resources;
[0120] Reduced storage resources;
[0121] The security configuration level has been reduced.
[0122] In some embodiments, the computing resource information includes at least one of the following:
[0123] Operating system information and operating system version;
[0124] Computing power component version and computing power component permissions;
[0125] Computing resource catalog and computing resource permissions;
[0126] Storage resource directory and storage resource permissions.
[0127] In some embodiments, the security configuration information includes at least one of the following:
[0128] Whether the component has authentication and authorization enabled;
[0129] Is it in safe mode?
[0130] Enable audit logging;
[0131] Log level;
[0132] Log path.
[0133] In some embodiments, the processor is used to distribute the access module to the computing node.
[0134] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps in the information processing method for computing power nodes as described above.
[0135] The embodiments of the present invention have the following beneficial effects:
[0136] In the above scheme, an access module is added to the computing power node. This access module scans the computing power node's computing resource information and security configuration information, and reports the scan results to the computing power security authentication service entity. The access module can be configured by the computing power security authentication service entity to the computing power node. Compared to the computing power node actively reporting, this avoids the problem of malicious nodes reporting false service capabilities. Compared to task testing to verify the node's reported information, this embodiment only requires adding an access module to the computing power node, resulting in low implementation cost and ensuring the real-time nature of the scan results. Furthermore, adding the scanning and registration of the computing power node's security configuration information ensures that subsequent node security classification can be implemented, enabling hierarchical allocation and scheduling of computing power resources. Attached Figure Description
[0137] Figure 1 This is a schematic diagram showing the location of computing nodes in a computing network.
[0138] Figure 2 This is a schematic diagram illustrating the identity registration of computing power nodes according to an embodiment of the present invention;
[0139] Figure 3 This is a schematic diagram illustrating the capability scanning and reporting of computing nodes according to an embodiment of the present invention;
[0140] Figure 4 This is a schematic diagram illustrating how the computing power nodes maintain the node resource catalog and report their computing power resource information to the computing power network, as per an embodiment of the present invention.
[0141] Figure 5 This is a schematic diagram illustrating the trigger scan for the distribution of computing power tasks according to an embodiment of the present invention;
[0142] Figure 6 This is a schematic diagram of the information processing device of the computing node according to an embodiment of the present invention;
[0143] Figure 7This is a schematic diagram of the composition of the information processing device for the computing power node in an embodiment of the present invention. Detailed Implementation
[0144] To make the technical problems, technical solutions and advantages of the embodiments of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0145] Multiple computing nodes are deployed in a computing network. Figure 1 This diagram illustrates the location of computing nodes within a computing network. The computing network schedules all computing nodes to participate in computing tasks; these nodes provide computing services. The providers of computing nodes can be telecom operators, third-party companies, universities, or even individuals. The types of computing nodes can be cloud platforms, servers, or even personal terminals. Based on their location, computing nodes can be broadly categorized into central nodes, end nodes, and edge nodes.
[0146] like Figure 1 As shown, the relevant technology performs the following steps when scheduling computing nodes:
[0147] Step 1: Tenants connect to the network through the operations service entity;
[0148] Step 2: The operations service entity distributes the tenant's computing power requirements to the orchestration management entity;
[0149] Step 3: The computing nodes report computing network information;
[0150] Step 4: The orchestration management entity performs orchestration and scheduling;
[0151] Step 5: The orchestration management entity distributes the scheduling strategy to the computing power nodes;
[0152] Step 6: Deploy applications on computing nodes and prepare the environment;
[0153] Step 7: The tenant sends the computing task to the computing node;
[0154] Step 8: The computing nodes execute computing tasks;
[0155] Step 9: The computing node returns the calculation results to the tenant.
[0156] The variety of computing power nodes and providers provides greater resource security for computing power networks, but also brings greater security risks.
[0157] Existing solutions, while considering node "computing power capability authentication," generally neglect the requirement for node "security capability authentication." The tasks processed by computing networks vary in sensitivity and security requirements. Tasks with different security requirements necessitate the allocation of computing nodes with different security levels to ensure computational and data security. This necessitates that computing network service providers not only authenticate the identity and service capabilities of computing nodes, but also authenticate their security capabilities or confirm their security levels.
[0158] This invention provides a method and apparatus for processing information of computing nodes, which can prevent malicious nodes from reporting false service capabilities.
[0159] Embodiments of the present invention provide an information processing method for computing power nodes, applied to the access module of computing power nodes, the method comprising:
[0160] Scan the computing power resource information and security configuration information of the computing power nodes;
[0161] The first scan result obtained from the scan is reported to the computing power security authentication service entity.
[0162] The access module can be a secure access program issued by the computing power security authentication service entity to the computing power node.
[0163] In this embodiment, an access module is added to the computing power node. This access module scans the computing power node's computing power resource information and security configuration information, and reports the scan results to the computing power security authentication service entity. The access module can be configured by the computing power security authentication service entity to the computing power node. Compared to the computing power node actively reporting, this avoids the problem of malicious nodes reporting false service capabilities. Compared to verifying the node's reported information through task testing, this embodiment only requires adding an access module to the computing power node, resulting in low implementation cost and ensuring the real-time nature of the scan results. Furthermore, adding the scanning and registration of the computing power node's security configuration information ensures that subsequent node security classification can be implemented, enabling hierarchical allocation and scheduling of computing power resources.
[0164] In some embodiments, after reporting the first scan result obtained from the scan to the computing power security authentication service entity, the method further includes:
[0165] Receive orchestration tasks assigned by the computing power network;
[0166] The computing power resource information and security configuration information of the computing power nodes are scanned again;
[0167] The second scan result obtained from the scan is reported to the computing power security authentication service entity.
[0168] In some embodiments, the computing resource information includes at least one of the following:
[0169] Operating system information and operating system version;
[0170] Computing power component version and computing power component permissions;
[0171] Computing resource catalog and computing resource permissions;
[0172] Storage resource directory and storage resource permissions.
[0173] In some embodiments, the security configuration information includes at least one of the following:
[0174] Whether the component has authentication and authorization enabled;
[0175] Is it in safe mode?
[0176] Enable audit logging;
[0177] Log level;
[0178] Log path.
[0179] In some embodiments, before scanning the computing power resource information and security configuration information of the computing power nodes, the method further includes:
[0180] Receive the access module issued by the computing power security authentication service entity.
[0181] This invention also provides an information processing method for computing power nodes, applied to a computing power security authentication service entity, the method comprising:
[0182] The system receives the first scan result reported by the access module of the computing power node, the first scan result including computing power resource information and security configuration information;
[0183] The first scan result is stored in the resource directory corresponding to the computing power node;
[0184] The computing power resource information of the computing power node is reported to the computing power network.
[0185] The access module can be a secure access program issued by the computing power security authentication service entity to the computing power node.
[0186] In some embodiments, after reporting the computing power resource information of the computing power node to the computing power network, the method further includes:
[0187] The system receives the second scan result reported by the access module of the computing power node. The second scan result includes computing power resource information and security configuration information.
[0188] The first scan result is compared with the second scan result. If the first scan result is consistent with the second scan result, the computing power node is notified to execute the orchestration task issued by the computing power network. If the first scan result is inconsistent with the second scan result, an alarm message is sent to the computing power network.
[0189] In some embodiments, after sending alarm information to the computing power network, the method further includes:
[0190] The second scan result is stored in the resource directory corresponding to the computing power node;
[0191] The computing power resource information of the computing power node in the second scan result is reported to the computing power network.
[0192] In some embodiments, the inconsistency between the first scan result and the second scan result includes at least one of the following:
[0193] The operating system information has changed;
[0194] Reduced computing resources;
[0195] Reduced storage resources;
[0196] The security configuration level has been reduced.
[0197] In some embodiments, the computing resource information includes at least one of the following:
[0198] Operating system information and operating system version;
[0199] Computing power component version and computing power component permissions;
[0200] Computing resource catalog and computing resource permissions;
[0201] Storage resource directory and storage resource permissions.
[0202] In some embodiments, the security configuration information includes at least one of the following:
[0203] Whether the component has authentication and authorization enabled;
[0204] Is it in safe mode?
[0205] Enable audit logging;
[0206] Log level;
[0207] Log path.
[0208] In some embodiments, before receiving the first scan result reported by the access module of the computing power node, the method further includes:
[0209] The access module is sent to the computing power node.
[0210] The technical solutions of the embodiments of this application will be further described below with reference to the accompanying drawings. Figure 2 As shown, to ensure the security of access for multiple computing power nodes, this embodiment of the application adds a computing power security authentication service entity and a secure access procedure to the computing power network.
[0211] The functions of the computing power security authentication service entity include computing power node identity authentication, secure access program download, computing power resource registration and verification, security capability registration and verification, node alarms, and information reporting to the computing power network orchestration and management entity. The functions of the secure access program include program status feedback, computing power node scanning, scan task triggering, and information reporting to the computing power security authentication service entity.
[0212] like Figure 2 As shown, computing power nodes must first register their identity. When a computing power node applies to join the computing power network, it can download the secure access program from the computing power security authentication service entity after passing identity authentication.
[0213] Once the computing power node installs the secure access program, and the program is successfully installed, a "successful installation" status is reported to the computing power security authentication service entity. If the computing power security authentication service entity receives the feedback result, the computing power node's identity registration is successful.
[0214] After installing the secure access program, the computing nodes need to perform capability scanning and reporting. For example... Figure 3 As shown, after the computing node successfully installs the secure access program, grant the program the appropriate permissions to ensure that it can read the following information:
[0215] (1) Basic computing power information, including operating system information, version, and information and version of the components providing services;
[0216] (2) Computing resources, including the file directories and program functions required to provide computing power;
[0217] (3) Storage resources, including storage resources needed to provide computing power, file system directories, and databases;
[0218] (4) Security configuration information, including security configuration files that can provide computing power design function components.
[0219] After the secure access program is successfully installed, the first scan function is triggered to perform the following scan:
[0220] (1) Computing resource scanning: Based on the basic computing information (such as different operating systems), scan the computing resources and storage resources of each computing node. Obtain the resource information of the computing nodes, including the operating system and version, the version and permissions of computing components, the computing resource directory and permissions, and the storage resource directory and permissions.
[0221] (2) Security configuration scan: Scan the security configuration files of the computing power nodes to obtain the component security configuration. For example: whether the component has authentication and authorization enabled, whether it is in security mode, whether audit logs are enabled, log level, log path, etc.
[0222] Afterwards, the secure access program reports the scanned content to the computing power security authentication service entity. The computing power security authentication service entity obtains the first scan result reported by the secure access program and completes the authentication of the computing power node.
[0223] Afterwards, the computing nodes are registered as optional resources for computing power services, such as... Figure 4 As shown, the computing power security authentication service entity maintains the resource catalog of computing power nodes, stores the first scan result reported by the security access program in the catalog under the node identifier (ID), and reports the resource information of computing power nodes to the computing power network (including the orchestration management entity, or other similar entities), so that the computing power nodes become available computing power service resources of the computing power network.
[0224] like Figure 5 As shown, when a new computing task is available in the computing power network, the orchestration and management entity distributes the computing task, triggering the secure access program of the computing power node to scan again. When the computing power network orchestrates tasks based on the information of the computing power nodes and assigns a task to a certain computing power node, the secure access program of that computing power node is triggered again to scan. The secure access program reports the scan result, i.e., the second scan result, to the computing power security authentication service entity. The computing power security authentication service entity compares the current scan result with the node information in the computing power node resource directory, that is, compares the second scan result with the first scan result. If the comparison result is the same, the computing power node executes the computing task; if the comparison result is different, an alarm is triggered, and the computing power security authentication service entity records the new scan result in the computing power node resource directory and updates the resource information of that computing power node. In addition, if an alarm occurs, the computing power security authentication service entity reports the updated resource information of the computing power node to the computing power network (orchestration and management entity, etc.) to update the schedulable computing resources, confirm whether the computing power node still meets the task requirements, and whether the computing power node needs to be reallocated.
[0225] The differences in the comparison results include changes in basic computing power information, computing power resources, storage resources, and security configuration information. For example, changes in operating system information, reductions in computing power resources, reductions in storage resources, and reductions in security configuration levels may occur.
[0226] This embodiment of the application implements the registration and authentication of the identity, resources, and security configuration of computing power nodes through a computing power security authentication service entity on the computing power network side and a secure access program on the computing power node side. Specifically, the secure access program scans computing power node information and reports it to the computing power security authentication service entity, which then completes the resource registration process for the computing power nodes. This embodiment, by scanning and reporting information through a secure access program, avoids malicious nodes reporting false information compared to computing power nodes actively reporting. Compared to verifying node-reported information through task testing, this embodiment has lower implementation costs and ensures real-time verification results. Furthermore, adding the scanning and registration of the security configuration information of computing power nodes ensures that node security classification can be implemented subsequently, enabling hierarchical allocation and scheduling of computing power resources.
[0227] This invention also provides an information processing device for computing power nodes, such as... Figure 6 As shown, the access module is applied to computing nodes. The device includes a processor 22 and a transceiver 21.
[0228] The processor 22 is used to scan the computing power resource information and security configuration information of the computing power nodes;
[0229] The transceiver 21 is used to report the first scan result obtained from the scan to the computing power security authentication service entity.
[0230] In this embodiment, an access module is added to the computing power node. This access module scans the computing power node's computing power resource information and security configuration information, and reports the scan results to the computing power security authentication service entity. The access module can be configured by the computing power security authentication service entity to the computing power node. Compared to the computing power node actively reporting, this avoids the problem of malicious nodes reporting false service capabilities. Compared to verifying the node's reported information through task testing, this embodiment only requires adding an access module to the computing power node, resulting in low implementation cost and ensuring the real-time nature of the scan results. Furthermore, adding the scanning and registration of the computing power node's security configuration information ensures that subsequent node security classification can be implemented, enabling hierarchical allocation and scheduling of computing power resources.
[0231] In some embodiments, the transceiver 21 is also used to receive orchestration tasks allocated by the computing power network;
[0232] The processor 22 is also used to scan the computing power resource information and security configuration information of the computing power node again;
[0233] The transceiver 21 is also used to report the second scan result obtained from the scan to the computing power security authentication service entity.
[0234] In some embodiments, the computing resource information includes at least one of the following:
[0235] Operating system information and operating system version;
[0236] Computing power component version and computing power component permissions;
[0237] Computing resource catalog and computing resource permissions;
[0238] Storage resource directory and storage resource permissions.
[0239] In some embodiments, the security configuration information includes at least one of the following:
[0240] Whether the component has authentication and authorization enabled;
[0241] Is it in safe mode?
[0242] Enable audit logging;
[0243] Log level;
[0244] Log path.
[0245] In some embodiments, the transceiver 21 is also used to receive the access module issued by the computing power security authentication service entity.
[0246] This invention also provides an information processing device for computing power nodes, applied to computing power security authentication service entities, such as... Figure 6 As shown, the device includes a processor 22 and a transceiver 21.
[0247] The transceiver 21 is used to receive the first scan result reported by the access module of the computing power node. The first scan result includes computing power resource information and security configuration information.
[0248] The processor 22 is used to store the first scan result in a resource directory corresponding to the computing power node;
[0249] The transceiver 21 is also used to report the computing power resource information of the computing power node to the computing power network.
[0250] In some embodiments, the transceiver 21 is further configured to receive a second scan result reported by the access module of the computing power node, the second scan result including computing power resource information and security configuration information;
[0251] The processor 22 is further configured to compare the first scan result with the second scan result; if the first scan result is consistent with the second scan result, notify the computing power node to execute the orchestration task issued by the computing power network; if the first scan result is inconsistent with the second scan result, send an alarm message to the computing power network.
[0252] In some embodiments, the processor 22 is further configured to store the second scan result in a resource directory corresponding to the computing power node;
[0253] The transceiver 21 is also used to report the computing power resource information of the computing power node in the second scan result to the computing power network.
[0254] In some embodiments, the inconsistency between the first scan result and the second scan result includes at least one of the following:
[0255] The operating system information has changed;
[0256] Reduced computing resources;
[0257] Reduced storage resources;
[0258] The security configuration level has been reduced.
[0259] In some embodiments, the computing resource information includes at least one of the following:
[0260] Operating system information and operating system version;
[0261] Computing power component version and computing power component permissions;
[0262] Computing resource catalog and computing resource permissions;
[0263] Storage resource directory and storage resource permissions.
[0264] In some embodiments, the security configuration information includes at least one of the following:
[0265] Whether the component has authentication and authorization enabled;
[0266] Is it in safe mode?
[0267] Enable audit logging;
[0268] Log level;
[0269] Log path.
[0270] In some embodiments, the transceiver 21 is also used to send the access module to the computing node.
[0271] This invention also provides an information processing device for computing power nodes, such as... Figure 7 As shown, it includes a memory 31, a processor 32, and a computer program stored in the memory 31 and executable on the processor 32; when the processor 32 executes the program, it implements the information processing method of the computing node as described above.
[0272] In some embodiments, the processor 32 is used to scan the computing power resource information and security configuration information of the computing power node; and to report the first scan result obtained from the scan to the computing power security authentication service entity.
[0273] In some embodiments, the processor 32 is used to receive the orchestration task allocated by the computing power network; scan the computing power resource information and security configuration information of the computing power nodes again; and report the second scan result obtained from the scan to the computing power security authentication service entity.
[0274] In some embodiments, the computing resource information includes at least one of the following:
[0275] Operating system information and operating system version;
[0276] Computing power component version and computing power component permissions;
[0277] Computing resource catalog and computing resource permissions;
[0278] Storage resource directory and storage resource permissions.
[0279] In some embodiments, the security configuration information includes at least one of the following:
[0280] Whether the component has authentication and authorization enabled;
[0281] Is it in safe mode?
[0282] Enable audit logging;
[0283] Log level;
[0284] Log path.
[0285] In some embodiments, the processor 32 is used to receive the access module issued by the computing power security authentication service entity.
[0286] In some embodiments, the processor 32 is configured to receive a first scan result reported by the access module of the computing power node, the first scan result including computing power resource information and security configuration information; store the first scan result in a resource directory corresponding to the computing power node; and report the computing power resource information of the computing power node to the computing power network.
[0287] In some embodiments, the processor 32 is used to receive a second scan result reported by the access module of the computing power node, the second scan result including computing power resource information and security configuration information; compare the first scan result with the second scan result; if the first scan result is consistent with the second scan result, notify the computing power node to execute the orchestration task issued by the computing power network; if the first scan result is inconsistent with the second scan result, send alarm information to the computing power network.
[0288] In some embodiments, the processor 32 is used to store the second scan result in a resource directory corresponding to the computing power node; and to report the computing power resource information of the computing power node in the second scan result to the computing power network.
[0289] In some embodiments, the inconsistency between the first scan result and the second scan result includes at least one of the following:
[0290] The operating system information has changed;
[0291] Reduced computing resources;
[0292] Reduced storage resources;
[0293] The security configuration level has been reduced.
[0294] In some embodiments, the computing resource information includes at least one of the following:
[0295] Operating system information and operating system version;
[0296] Computing power component version and computing power component permissions;
[0297] Computing resource catalog and computing resource permissions;
[0298] Storage resource directory and storage resource permissions.
[0299] In some embodiments, the security configuration information includes at least one of the following:
[0300] Whether the component has authentication and authorization enabled;
[0301] Is it in safe mode?
[0302] Enable audit logging;
[0303] Log level;
[0304] Log path.
[0305] In some embodiments, the processor 32 is used to send the access module to the computing node.
[0306] In this embodiment, an access module is added to the computing power node. This access module scans the computing power node's computing power resource information and security configuration information, and reports the scan results to the computing power security authentication service entity. The access module can be configured by the computing power security authentication service entity to the computing power node. Compared to the computing power node actively reporting, this avoids the problem of malicious nodes reporting false service capabilities. Compared to verifying the node's reported information through task testing, this embodiment only requires adding an access module to the computing power node, resulting in low implementation cost and ensuring the real-time nature of the scan results. Furthermore, adding the scanning and registration of the computing power node's security configuration information ensures that subsequent node security classification can be implemented, enabling hierarchical allocation and scheduling of computing power resources.
[0307] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps in the information processing method for computing power nodes as described above.
[0308] Computer-readable media, including both permanent and non-permanent, removable and non-removable media, can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage, or any other non-transferable medium that can be used to store information accessible to the computer-readable terminal device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0309] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. An information processing method of a computing power node, characterized by, An access module applied to computing power nodes, the method comprising: Receive the access module issued by the computing power security authentication service entity; Scan the computing power resource information and security configuration information of the computing power nodes; The first scan result obtained from the scan is reported to the computing power security authentication service entity; Receive orchestration tasks assigned by the computing power network; The computing power resource information and security configuration information of the computing power nodes are scanned again; The second scan result obtained from the scan is reported to the computing power security authentication service entity, so that the computing power security authentication service entity compares the first scan result with the second scan result. If the first scan result is consistent with the second scan result, the computing power node is notified to execute the orchestration task issued by the computing power network; if the first scan result is inconsistent with the second scan result, an alarm message is sent to the computing power network. 2.The information processing method of the computing node according to claim 1, wherein, The computing resource information includes at least one of the following: Operating system information; Computing power component version and computing power component permissions; Computing resource catalog and computing resource permissions; Storage resource directory and storage resource permissions.
3. The information processing method for computing nodes according to claim 1, characterized in that, The security configuration information includes at least one of the following: Whether the component has authentication and authorization enabled; Is it in safe mode? Enable audit logging; Log level; Log path.
4. An information processing method of a computing power node, characterized by, The method, applied to computing power security authentication service entities, includes: Distribute the access module for the computing power nodes to the computing power nodes; The system receives the first scan result reported by the access module of the computing power node, the first scan result including computing power resource information and security configuration information; The first scan result is stored in the resource directory corresponding to the computing power node; The computing power resource information of the computing power nodes is reported to the computing power network; The system receives the second scan result reported by the access module of the computing power node. The second scan result includes computing power resource information and security configuration information. The first scan result is compared with the second scan result. If the first scan result is consistent with the second scan result, the computing power node is notified to execute the orchestration task issued by the computing power network. If the first scan result is inconsistent with the second scan result, an alarm message is sent to the computing power network.
5. The information processing method for computing nodes according to claim 4, characterized in that, After sending alarm information to the computing power network, the method further includes: The second scan result is stored in the resource directory corresponding to the computing power node; The computing power resource information of the computing power node in the second scan result is reported to the computing power network.
6. The information processing method of the computing node according to claim 4, characterized in that, The inconsistency between the first scan result and the second scan result includes at least one of the following: The operating system information has changed; Reduced computing resources; Reduced storage resources; The security configuration level has been reduced.
7. The information processing method for computing nodes according to claim 4, characterized in that, The computing resource information includes at least one of the following: Operating system information; Computing power component version and computing power component permissions; Computing resource catalog and computing resource permissions; Storage resource directory and storage resource permissions. 8.The information processing method of the computing node according to claim 4, characterized in that, The security configuration information includes at least one of the following: Whether the component has authentication and authorization enabled; Is it in safe mode? Enable audit logging; Log level; Log path. 9.The information processing method of the computing node according to claim 4, characterized in that, Before receiving the first scan result reported by the access module of the computing power node, the method further includes: The access module is sent to the computing power node.
10. An information processing device for a computing node, characterized in that, An access module for computing nodes, the device including a processor and a transceiver, The transceiver is used to receive the access module issued by the computing power security authentication service entity; The processor is used to scan the computing power resource information and security configuration information of the computing power nodes; The transceiver is used to report the first scan result obtained from the scan to the computing power security authentication service entity; and to receive the orchestration tasks assigned by the computing power network; The processor is also used to scan the computing power resource information and security configuration information of the computing power nodes again; The transceiver is also used to report the second scan result obtained by scanning to the computing power security authentication service entity, so that the computing power security authentication service entity compares the first scan result with the second scan result. If the first scan result is consistent with the second scan result, the computing power node is notified to execute the orchestration task issued by the computing power network. If the first scan result is inconsistent with the second scan result, an alarm message is sent to the computing power network.
11. An information processing apparatus of a computing power node, comprising: The device, used in computing power security authentication service entities, includes a processor and a transceiver. The transceiver is used to send the access module of the computing power node to the computing power node; and to receive the first scan result reported by the access module of the computing power node, the first scan result including computing power resource information and security configuration information; The processor is used to store the first scan result in a resource directory corresponding to the computing power node; The transceiver is also used to report the computing power resource information of the computing power node to the computing power network; The transceiver is also used to receive the second scan result reported by the access module of the computing power node, the second scan result including computing power resource information and security configuration information; The processor is further configured to compare the first scan result with the second scan result, and if the first scan result is consistent with the second scan result, notify the computing power node to execute the orchestration task issued by the computing power network; If the first scan result is inconsistent with the second scan result, an alarm message is sent to the computing power network.
12. An information processing device for a computing node, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor; characterized in that, When the processor executes the program, it implements the information processing method for the computing node as described in any one of claims 1-8.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps in the information processing method for computing nodes as described in any one of claims 1-8.