A media cloud desktop management method and system based on a bare metal server

CN117290110BActive Publication Date: 2026-08-28ZHEJIANG RADIO AND TELEVISION GROUP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311408283.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-26
Publication Date
2026-08-28
Estimated Expiration
2043-10-26

AI Technical Summary

Technical Problem

而既要把握好云桌面业务应用的高性能用户体验,又要充分发挥云计算的动态弹性的特点,还要保障关键数据的网络安全及信息安全,从而给媒体行业的云计算业务带来了极大的挑战

Benefits of technology

[0029] 1) This invention innovatively proposes a media cloud desktop system based on a virtual laboratory mode of elastic bare metal servers, and builds a complete media cloud desktop management method based on this system, which can effectively handle the operation, maintenance, release and management of media cloud desktops.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117290110B_ABST
    Figure CN117290110B_ABST
Patent Text Reader

Abstract

The application discloses a media cloud desktop management method and system based on a bare metal server. The application comprises the following method: providing the basic resources of the cloud desktop in a bare metal pooling mode, adding instance matching specifications suitable for different vGPU use scenarios in the media cloud desktop system before the cloud desktop is created, creating cloud desktop template kits belonging to different virtual laboratories according to the corresponding specifications, and connecting various tool-type cloud desktops belonging to different laboratories through network access mode of the client. The application provides a media cloud desktop management method and system based on a virtual laboratory mode of an elastic bare metal server, realizes efficient management of the vGPU resources of the bare metal pooling, provides a convenient management mechanism for cloud desktop authorization and recycling, reduces the idle rate of the tool-type desktops, greatly improves the desktop use efficiency of the vGPU, realizes efficient operation and maintenance and elastic publishing and deployment capabilities of the exclusive desktop and a large number of multi-version desktop templates.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of media cloud computing, and in particular to a media cloud desktop management method and system based on bare metal servers. Background Technology

[0002] As media convergence continues to advance, cloud computing has become a major technological support in the media industry. Lighter production processes are shifting to the cloud, and the increasing maturity of technologies such as bare metal and GPU virtualization is driving the adoption of high-performance, high-intensity production on the cloud. However, balancing the high-performance user experience of cloud desktop applications with the dynamic elasticity of cloud computing, while ensuring the network and information security of critical data, presents significant challenges for the media industry's cloud computing operations.

[0003] The collaborative production mindset of cloud-based production and cloud-based office work has presented considerable challenges to the management of media cloud desktops. The media industry generally adopts a channel-based organizational structure, and the independent approach has resulted in the monopolization of a large number of tool-type cloud desktops, causing a significant waste of resources. The inability to share tool-type desktops between channels and the inability to share files and materials have become obstacles to media convergence.

[0004] Therefore, it is necessary to invent a media cloud desktop management method and system based on bare metal servers to solve the above-mentioned technical problems. Summary of the Invention

[0005] This invention addresses the shortcomings of existing technologies by proposing a media cloud desktop management method and system based on bare metal servers, applicable to media cloud environments.

[0006] To achieve the above-mentioned objectives, the technical solution adopted by the present invention is as follows:

[0007] In a first aspect, the present invention provides a media cloud desktop management method based on a bare metal server, which is applied to a cloud desktop system. The specific method is as follows:

[0008] S1. Create a bare metal GPU server cluster, and divide the bare metal GPU server cluster into slices according to the vGPU memory size required by the media tool cloud desktop. Then, combine general server and media storage pool resources to release the underlying basic resources that meet the configuration requirements of the media cloud desktop. The underlying basic resources include the necessary CPU, memory and storage, as well as the optional GPU. The GPU is divided into pass-through GPUs and vGPUs provided by the bare metal GPU server cluster.

[0009] S2. Configure the instance specifications corresponding to the underlying basic resources in the cloud desktop management system. The instance specifications are divided into different instance specifications according to the different underlying physical machines. General servers are one instance specification, and bare metal GPU servers are another instance specification.

[0010] S3. In the cloud desktop management system, various media tool-type virtual labs are divided for different media tool-type cloud desktops. Each media tool-type virtual lab has a corresponding cloud desktop template. The corresponding instance specifications are bound according to the configuration requirements of the cloud desktop to complete the production of the virtual lab cloud desktop template suite. Finally, each virtual lab creates and publishes cloud desktop resources that meet the estimated demand based on the template suite.

[0011] S4. User group creation steps: All users are pre-divided into several user groups. The cloud desktop management system pre-configures the cloud desktop quota that each user group can use in different media tool virtual labs. Users can access the cloud desktop resources within the quota range of their own user group through the client access portal, but different user groups share the cloud desktop resources of the same media tool virtual lab.

[0012] Furthermore, in the cloud desktop management system, the rules for media material data storage and personal user data storage when users access and use the cloud desktop are set as follows: the media materials required by the cloud desktop are connected to the media storage NAS via CIFS to achieve shared storage data mounting. When different user groups authenticate as domain users upon their first login, a shared folder for the corresponding user group will be created on the media storage NAS. Personal user data will be created in an encrypted folder within the user group's shared folder, thus completing the sharing of media material data and the storage of personal user data.

[0013] As a preferred option in the first aspect mentioned above, when binding instance specifications, if the actual business running on the cloud desktop is a high-performance resource exclusive usage scenario, then the instance specification it is bound to is provided with pass-through GPU resources by the bare metal GPU server; otherwise, the bare metal GPU server provides vGPU slice resources with the required video memory specifications.

[0014] As a preferred option for the first aspect mentioned above, each media tool category virtual lab includes a number of cloud desktops that are actually created and published. After the quotas are allocated to each user group, the total quota actually allocated to the same media tool category virtual lab must be greater than the number of cloud desktops that are actually created and published in each media tool category virtual lab.

[0015] As a preferred option in the first aspect mentioned above, each media tool virtual lab's cloud desktop is an exclusive cloud desktop. If all published desktops in a virtual lab are occupied by users, when a new user connects to the virtual lab's desktop, the cloud desktop dynamic scaling rules will be triggered. The virtual lab will then call the corresponding virtual lab cloud desktop template suite to dynamically publish and provide a cloud desktop for the new user. If the new user is disconnected for a period of time that reaches the preset dynamic scaling lifespan, the virtual lab will call the cloud desktop recycling mechanism to restore the number of cloud desktops in the virtual lab to the initial set.

[0016] As a preferred option in the first aspect mentioned above, when slicing a bare metal GPU server cluster, all slices on the same physical machine are divided into vGPU slices of the same size to maximize resource utilization.

[0017] As a preferred embodiment of the first aspect above, the number of users in the user group is not strongly correlated with the number of cloud desktops actually created and published in the virtual laboratory, and the quota of the user group in the virtual laboratory is not strongly correlated with the number of cloud desktops actually created and published in the virtual laboratory.

[0018] Secondly, the present invention provides a media cloud desktop system based on a bare metal server, the system comprising:

[0019] The cloud desktop basic resource module is used to support the underlying basic resources of cloud desktops through bare metal GPU servers, general-purpose servers and media storage pooling resources, providing CPU, memory, storage and GPU computing power resources for cloud desktops;

[0020] The cloud desktop operation and maintenance management module is used to realize the operation and maintenance release and management before the user logs in to the cloud desktop system, according to any of the media cloud desktop management methods described in the first aspect above.

[0021] The cloud desktop distributed portal module is used to provide users with a unified portal to access the cloud desktop system through a client. Through the portal, users can select different availability zones. When the underlying infrastructure resources or network leased line of an availability zone fail, users are allowed to switch to another availability zone to access the cloud desktop.

[0022] The cloud desktop control and authentication module is used to provide one-to-one or one-to-many user allocation and management for cloud desktops according to different usage scenarios. It realizes user metadata recording and login-related log recording. The user client logs in by calling the authentication server and clicks on the virtual desktop. The user client transmits the user identity credentials to the authentication server through the ADC's encrypted channel. The authentication server transmits the user identity credentials to the application delivery controller. The application delivery controller verifies the account's legitimacy with the AD domain controller and returns the verification information to the application delivery controller. The application delivery controller queries the virtual machine list based on the account information and returns the information to the authentication server. The authentication server then provides the corresponding cloud desktop to the user terminal.

[0023] The cloud desktop network connection optimization module is used to detect the dynamic fluctuations of data center network equipment and the elasticity data of hardware infrastructure resources in real time after the user connects to the cloud desktop. It dynamically utilizes the CPU and GPU resources of the cloud desktop and optimizes the transmission link through the HDX transmission protocol. When the user and the cloud desktop transmit data, it determines whether the network bandwidth is approaching and causing congestion based on the detected elasticity data. If so, it uses a data compression algorithm to reduce the display frame rate of the cloud desktop and adopts smooth display. If not, it maintains the current display frame rate of the cloud desktop.

[0024] The cloud desktop security protection module is used to force users' client devices to interact with the security protection module for security access matching when they connect to the cloud desktop via remote desktop. It determines whether the security access standards are met. If yes, remote connection is allowed; otherwise, the connection is automatically disconnected. The cloud desktop is included in the physical host security protection scope from the moment it is published and created. The security protection module collects cloud desktop operating system information, monitors real-time intrusion events, collects port process data, and forms baseline rectification suggestions.

[0025] As a preferred embodiment of the second aspect above, the cloud desktop distributed portal module is associated and bound with the cloud desktop basic resource module. The basic resources of different distributed availability zones are different, but the cloud desktops of the tool-type virtual laboratories to be connected are all the same, and the backend media storage and metadata of different distributed availability zones are kept synchronized in real time.

[0026] As a preferred embodiment of the second aspect above, the cloud desktop network connection optimization module detects seven features in the elastic data, namely network bandwidth, network congestion index, number of network packet losses, number of cloud desktop latency, CPU utilization, memory utilization, and number of CIFS connections. The detected elastic data is used to determine whether it approaches the network bandwidth and causes congestion through preset judgment rules or pre-trained neural networks.

[0027] As a preferred embodiment of the second aspect above, in the cloud desktop security protection module, when a user transmits a suspicious virus or Trojan file to the cloud desktop that matches the virus database and rule database of the security protection module, the file extension is modified and the corresponding file is removed to the security protection isolation folder.

[0028] Compared with the prior art, the beneficial effects of the present invention are:

[0029] 1) This invention innovatively proposes a media cloud desktop system based on a virtual laboratory mode of elastic bare metal servers, and builds a complete media cloud desktop management method based on this system, which can effectively handle the operation, maintenance, release and management of media cloud desktops.

[0030] 2) This invention optimizes the entire media cloud desktop publishing and creation process. Based on the slice management method of elastic bare metal GPU cluster, it provides differentiated deployment and publishing capabilities for vGPU and pass-through GPU services, thereby improving the system's adaptability.

[0031] 3) The cloud desktop system based on the virtual laboratory of this invention improves the efficiency of media practitioners in using various tool-type cloud desktops and increases the utilization rate of underlying resources; moreover, the distributed portal module and network connection optimization module can improve the smoothness of users' use of cloud desktops and enhance the user experience by improving high availability and dynamically adjusting the real-time interaction of the desktop according to network fluctuations. Attached Figure Description

[0032] Figure 1 A flowchart illustrating the steps of a media cloud desktop management method based on a virtual laboratory mode using elastic bare metal servers;

[0033] Figure 2 This is a modular composition diagram of a media cloud desktop system based on a virtual laboratory mode using elastic bare metal servers.

[0034] Figure 3 This is an architectural flowchart of a media cloud desktop system based on a virtual laboratory mode using elastic bare metal servers. Detailed Implementation

[0035] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Many specific details are set forth in the following description to provide a thorough understanding of the present invention. However, the present invention can be practiced in many other ways different from those described herein, and those skilled in the art can make similar modifications without departing from the spirit of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below. Technical features in the various embodiments of the present invention can be combined accordingly without mutual conflict.

[0036] like Figure 1 The diagram shown is a flowchart of a media cloud desktop management method based on a bare metal server, provided in a preferred embodiment of the present invention. This method can be applied to the operation, maintenance, deployment, and management of cloud desktop systems. The method specifically includes the following steps:

[0037] S1. Create a bare-metal GPU server cluster and slice the cluster according to the vGPU memory required by media tool-type cloud desktops. Then, combine general-purpose server and media storage pooled resources to release the underlying infrastructure resources that meet the configuration requirements of media cloud desktops. The aforementioned underlying infrastructure resources include the necessary CPU, memory, and storage, as well as optional GPUs. It is particularly important to note that the GPUs are divided into pass-through GPUs and vGPUs, which are provided by the bare-metal GPU server cluster.

[0038] It should be noted that among the aforementioned underlying infrastructure resources, GPUs are optional resources, and are divided into pass-through GPUs and vGPUs. This is to meet the GPU computing power requirements of different cloud desktop application scenarios. If the cloud desktop application scenario does not require GPUs, general-purpose servers can directly provide underlying infrastructure resources without GPUs. If the cloud desktop application scenario requires GPUs, GPU resources need to be provided by a bare-metal GPU server cluster. For applications with high GPU performance requirements, GPU pass-through needs to be provided separately, while for applications with low GPU performance requirements, vGPU slicing resources are sufficient. The advantage of the above bare-metal GPU pool creation steps is that GPU memory can be pre-allocated according to actual business needs, ensuring that when slicing the bare-metal GPU server cluster, vGPU slices of the same specification are divided on the same physical machine, maximizing resource utilization.

[0039] S2. Instance Specification Creation Steps: Configure the instance specification corresponding to the underlying basic resources in the cloud desktop management system. The instance specification is divided into different instance specifications according to the different underlying physical machines. General server is one instance specification, and bare metal GPU server is another instance specification.

[0040] Additionally, it's important to note that while instance specifications are categorized by server type, different resource configuration options can be set within the same instance specification. Different configurations correspond to different CPU and GPU computing power, as well as memory and storage space. Ultimately, the specific instance specification and configuration chosen for each cloud desktop can be determined based on the actual business requirements.

[0041] In the above instance specification creation steps, the advantage of instance specifications corresponding to underlying basic resources is that device instance specifications can be divided according to the underlying physical host. On the one hand, it can differentiate and provide bare metal GPU passthrough or vGPU instances for different cloud desktops. On the other hand, when the underlying physical host needs to be iterated and updated, it can be replaced as a whole through instance specifications to ensure the iterative scalability of resources.

[0042] S3. Virtual Lab Creation Steps: In the cloud desktop management system, various media tool-type cloud desktops are divided into multiple media tool-type virtual labs. Each media tool-type virtual lab has a corresponding cloud desktop template. The instance specifications are bound according to the configuration requirements of the cloud desktop to complete the creation of the virtual lab cloud desktop template suite. Finally, each virtual lab creates and publishes cloud desktop resources that meet the estimated demand based on the template suite.

[0043] It should be noted that the media tools mentioned in this invention refer to the types of tools used in the media industry. For example, the media industry has a large amount of non-linear editing work, and different work uses different non-linear editing software, such as the common Adobe, Dayang, Sobe, and Eduis software for video editing and production. Different media tools require different underlying resources, so virtual labs can be built for different media tools, and corresponding cloud desktops can be published.

[0044] In embodiments of the present invention, when binding instance specifications, if the actual business running on the cloud desktop is a resource-exclusive usage scenario with high GPU performance requirements, then the bound instance specification provides pass-through GPU resources from a bare-metal GPU server. The characteristics of bare metal eliminate the CPU and memory overhead and performance loss associated with virtualization. Otherwise, the bare-metal GPU server provides vGPU slice resources with the required video memory specifications. The specific specifications of the provided vGPU slice resources can be determined according to the required video memory specifications. For example, taking a single physical GPU with 16GB of actual video memory as an example, it can actually be divided into 2GB, 4GB, or 8GB vGPU video memory specifications to provide different services externally.

[0045] In addition, the creation of the virtual laboratory cloud desktop template kit in the above-mentioned virtual laboratory creation steps involves the creation of an operating system template. After the virtual laboratory cloud desktop template kit is created and published as a cloud desktop, if there are iterative updates at the operating system level, the operating system template needs to be updated to the virtual laboratory cloud desktop template kit.

[0046] S4. User Group Creation Steps: All users are pre-divided into several user groups. The cloud desktop management system pre-configures the cloud desktop quotas that each user group can use in different media tool virtual labs. Users can access the cloud desktop resources within their own user group's quota range through the client access portal, but different user groups share the same cloud desktop resources in the same media tool virtual lab.

[0047] Because the media industry commonly adopts a channel-based organizational structure, the media tools and cloud desktops used by different channels often overlap. However, if resources are not shared between channels, a large number of cloud desktop tools will be wasted. Therefore, the inability to share resources and files between channels has become an obstacle to media convergence. In contrast, the user groups of this invention can be divided according to the channel to which the user belongs. Although cloud desktop quotas are configured, different user groups still share cloud desktop resources, reducing resource idleness.

[0048] Furthermore, in the embodiments of the present invention, each media tool-type virtual lab includes an actual number n of cloud desktops created and published. After quota allocation for each user group, the total quota actually allocated to the same media tool-type virtual lab must be greater than the actual number n of cloud desktops created and published by each media tool-type virtual lab. This ensures that the cloud desktop resources actually created and published by the media tool-type virtual lab can be maximized, avoiding resource waste of tool-type cloud desktops.

[0049] Correspondingly, in order to ensure that cloud desktop resources can be maximized, when performing the user group creation step, the number of users in the user group is not strongly correlated with the number of cloud desktops actually created and published in the virtual lab, and the user group's quota in the virtual lab is not strongly correlated with the number of cloud desktops actually created and published in the virtual lab. This solves the problem of user groups sharing cloud desktops in the virtual lab and further enhances the utilization rate of underlying basic resources.

[0050] However, it should be noted that since the total quota of a media tool-type virtual lab is greater than the actual number of cloud desktops (n) created and published by each media tool-type virtual lab, the number of cloud desktops may not be able to meet user demand during peak usage periods. In this case, a dynamic scaling rule for cloud desktops needs to be introduced. In the embodiments of this invention, especially for the case where each media tool-type virtual lab's cloud desktops are exclusive cloud desktops, if all published desktops of a virtual lab are occupied by users, a new user connecting to the virtual lab's desktops will trigger the dynamic scaling rule for cloud desktops. The virtual lab will then call the corresponding virtual lab cloud desktop template suite to dynamically publish and provide cloud desktops for the new user. If the new user is disconnected for a period of time that reaches the preset dynamic scaling lifespan, the virtual lab will invoke the cloud desktop recycling mechanism to restore the initial number of cloud desktops for the virtual lab.

[0051] In addition, in the above-mentioned media cloud desktop management method based on bare metal servers, since user groups share cloud desktop resources, it is also necessary to set media material data storage and personal user data storage rules in the cloud desktop management system when users access and use the cloud desktop. These rules are specifically set as follows: the media materials required by the cloud desktop are connected to the media storage NAS via CIFS to achieve shared storage data mounting; different user groups will create a shared folder for the corresponding user group on the media storage NAS when they log in to the domain user authentication for the first time; personal user data will be created in an encrypted folder in the user group's shared folder, thus completing the sharing of media material data and the storage of personal user data.

[0052] The aforementioned media cloud desktop management method based on bare metal servers is mainly used in the operation and maintenance management phase of the media cloud desktop system to manage the underlying resources, instance specifications, virtual labs, and user groups required by the system in real time.

[0053] In another embodiment of the present invention, a media cloud desktop system based on a virtual laboratory mode using an elastic bare metal server can be further provided, based on the aforementioned media cloud desktop management method using a bare metal server. For example... Figure 2 As shown, the system includes a cloud desktop basic resource module, a cloud desktop operation and maintenance management module, a cloud desktop distributed portal module, a cloud desktop control and authentication module, a cloud desktop network connection optimization module, and a cloud desktop security protection module. The specific functional implementation of each module is described in detail below.

[0054] The cloud desktop basic resource module is used to support the underlying basic resources of cloud desktops through bare metal GPU servers, general-purpose servers and media storage pooling resources, providing cloud desktops with related computing power resources such as CPU, memory, storage, and GPU.

[0055] The cloud desktop operation and maintenance management module is used to implement operation and maintenance deployment and management before users log in to the cloud desktop system, based on the aforementioned media cloud desktop management method.

[0056] The cloud desktop distributed portal module is used to provide users with a unified portal to access the cloud desktop system through a client. Through the portal, users can select different availability zones. When the underlying infrastructure resources or network leased line of an availability zone fail, users are allowed to switch to another availability zone to access the cloud desktop.

[0057] The cloud desktop control and authentication module is used to provide one-to-one or one-to-many user allocation and management for cloud desktops according to different usage scenarios. It realizes user metadata recording and login-related log recording. The user client logs in by calling the authentication server. When the user client clicks on the virtual desktop, the user client transmits the user identity credentials to the authentication server through the ADC's encrypted channel. The authentication server transmits the user identity credentials to the application delivery controller. The application delivery controller verifies the account's legitimacy with the AD domain controller and returns the verification information to the application delivery controller. The application delivery controller queries the virtual machine list based on the account information and returns the information to the authentication server. The authentication server then provides the corresponding cloud desktop to the user terminal.

[0058] The cloud desktop network connection optimization module is used to detect the dynamic fluctuations of data center network equipment and the elasticity data of hardware infrastructure resources in real time after a user connects to the cloud desktop. It dynamically utilizes the CPU and GPU resources of the cloud desktop and optimizes the transmission link through the HDX transmission protocol. When the user and the cloud desktop transmit data, it determines whether the network bandwidth is approaching and causing congestion based on the detected elasticity data. If so, it uses a data compression algorithm to reduce the cloud desktop display frame rate and adopts smooth display. If not, it maintains the current high display frame rate of the cloud desktop.

[0059] The cloud desktop security protection module is used to force users' client devices to interact with the security protection module for security access matching when they connect to the cloud desktop via remote desktop. It determines whether the security access standards are met. If yes, remote connection is allowed; otherwise, the connection is automatically disconnected. The cloud desktop is included in the physical host security protection scope from the moment it is published and created. The security protection module collects cloud desktop operating system information, monitors real-time intrusion events, collects port process data, and forms baseline rectification suggestions.

[0060] In embodiments of the present invention, the aforementioned cloud desktop distributed portal module is associated and bound to the cloud desktop basic resource module. While the basic resources differ across distributed availability zones, the cloud desktops of the tool-type virtual laboratories to be connected are identical. Backend media storage and metadata across different distributed availability zones are synchronized in real time. In the cloud desktop distributed portal module, when an availability zone fails and a switch occurs, the tool-type cloud desktops connected by the user in different availability zones can access the real-time synchronized media material storage and personal data storage, ensuring that the cloud desktop accessed by the user meets usage requirements and further enhancing business continuity.

[0061] In the embodiments of the present invention, the elastic data detected in the cloud desktop network connection optimization module includes seven features, namely network bandwidth, network congestion index, number of network packet loss, number of cloud desktop latency, CPU utilization, memory utilization and CIFS connection number. The detected elastic data is used to determine whether it approaches the network bandwidth and causes congestion through preset judgment rules or pre-trained neural networks.

[0062] In addition, in the embodiments of the present invention, in the cloud desktop security protection module, when a user transmits a suspicious virus or Trojan file to the cloud desktop that matches the virus database and rule database of the security protection module, the file extension can be modified and the corresponding file can be removed to the security protection isolation folder to ensure the implementation of the security protection function.

[0063] Furthermore, in the embodiments of the present invention, the cloud desktop control and authentication module described above can have one-to-one or one-to-many authentication control methods depending on the type of service. Specifically, one cloud desktop can be used by multiple users (multiple users logging into the same cloud desktop through different sessions) or by a single user (a single user exclusively using the cloud desktop). By differentiating authentication access methods based on service type, the management of user desktops is further strengthened and resource utilization is enhanced.

[0064] In addition, in the embodiments of the present invention, if the computing power and basic resources occupied by the cloud desktop in the above-mentioned cloud desktop basic resource module experience host failure, the cluster high availability mechanism will be triggered to perform fault switching to avoid affecting the normal operation of the business.

[0065] In addition, in the embodiments of the present invention, in the cloud desktop security protection module, the uplink and downlink access of the cloud desktop is restricted by the host proxy to avoid sensitive ports, and the information collected from the security protection module is used for active defense to further improve system security.

[0066] In another preferred embodiment of the present invention, the steps of a user connecting to a cloud desktop are used to describe how the various modules of the present invention cooperate and operate in the following manner.

[0067] Step 1: Following the media cloud desktop management method based on bare metal servers described in S1~S4 above, complete the operation and maintenance deployment and management in advance during the operation and maintenance phase.

[0068] Step Two: The complete process of a user obtaining a cloud desktop after logging into the media cloud desktop system, such as... Figure 3 As shown, the specific steps include the following:

[0069] (1) When users in user group A log in to the distributed portal module and complete the selection of availability zone.

[0070] (2) When the user clicks on the virtual desktop, the authentication server of the control and authentication module is invoked to log in. The user terminal transmits the user identity credentials to the authentication delivery controller group through the encrypted channel of the authentication delivery controller group.

[0071] (3) The authentication delivery controller group transmits the user identity credentials to the application delivery controller group.

[0072] (4) The Application Delivery Controller verifies the validity of the account with the AD Domain Controller Group and returns it to the Application Delivery Controller Group. The Application Delivery Controller Group queries the list of virtual machines using the account information and returns the authentication delivery controller group information.

[0073] (5) The authentication delivery controller provides the published cloud desktop to the end user through the basic resource module.

[0074] (6) When a user connects to the cloud desktop, the security protection module access mechanism is triggered to intercept dangerous interactive data between the user's host and the cloud desktop. The host security agent in the cloud desktop will collect operating system data information, uplink and downlink port data and judge intrusion events in real time.

[0075] (7) The network connection optimization module will record the entire process link data of the user's connection to the cloud desktop. A total of 7 elastic data are collected, namely network bandwidth, network congestion index, number of network packet loss, number of cloud desktop latency, CPU utilization, memory utilization, and number of CIFS connections. These data will serve as the basis for dynamically adjusting the desktop display frame rate to ensure the user's desktop connection experience and optimize image quality.

[0076] It should also be noted that, in the systems provided by the above embodiments, the modules other than the cloud desktop basic resource module are executed sequentially as program modules, thus essentially performing a data processing flow. Those skilled in the art will understand that, for ease of description and brevity, the specific working process of the system described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here. In the embodiments provided in this application, the division of steps or modules in the methods and systems is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple modules or steps may be combined or integrated together, and a module or step may also be split.

[0077] The embodiments described above are merely preferred embodiments of the present invention and are not intended to limit the invention. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the invention. Therefore, all technical solutions obtained through equivalent substitution or transformation fall within the protection scope of the present invention.

Claims

1. A media cloud desktop management method based on bare metal servers, applied to a cloud desktop system, characterized in that: S1. Create a bare metal GPU server cluster, and divide the bare metal GPU server cluster into slices according to the vGPU memory size required by the media tool cloud desktop. Then, combine general server and media storage pool resources to release the underlying basic resources that meet the configuration requirements of the media cloud desktop. The underlying basic resources include the necessary CPU, memory and storage, as well as the optional GPU. The GPU is divided into pass-through GPUs and vGPUs provided by the bare metal GPU server cluster. S2. Configure the instance specifications corresponding to the underlying basic resources in the cloud desktop management system. The instance specifications are divided into different instance specifications according to the different underlying physical machines. General servers are one instance specification, and bare metal GPU servers are another instance specification. S3. In the cloud desktop management system, various media tool-type virtual labs are divided for different media tool-type cloud desktops. Each media tool-type virtual lab has a corresponding cloud desktop template. The corresponding instance specifications are bound according to the configuration requirements of the cloud desktop to complete the production of the virtual lab cloud desktop template suite. Finally, each virtual lab creates and publishes cloud desktop resources that meet the estimated demand based on the template suite. S4. User group creation steps: All users are pre-divided into several user groups. The cloud desktop management system pre-configures the cloud desktop quota that each user group can use in different media tool virtual labs. Users can access the cloud desktop resources within the quota range of their own user group through the client access portal, but different user groups share the cloud desktop resources of the same media tool virtual lab. Furthermore, in the cloud desktop management system, the rules for media material data storage and personal user data storage when users access and use the cloud desktop are set as follows: the media materials required by the cloud desktop are connected to the media storage NAS via CIFS to achieve shared storage data mounting. When different user groups authenticate as domain users upon their first login, a shared folder for the corresponding user group will be created on the media storage NAS. Personal user data will be created in an encrypted folder within the user group's shared folder, thus completing the sharing of media material data and the storage of personal user data.

2. The media cloud desktop management method based on bare metal servers as described in claim 1, characterized in that, When binding instance specifications, if the actual business running on the cloud desktop is a high-performance resource exclusive usage scenario, the instance specification it is bound to will be provided with pass-through GPU resources by the bare metal GPU server; otherwise, the bare metal GPU server will provide vGPU slice resources with the required video memory specifications.

3. The media cloud desktop management method based on bare metal servers as described in claim 1, characterized in that, Each media tools virtual lab contains a number of cloud desktops that have actually been created and published. After quotas are allocated to each user group, the total quota actually allocated to the same media tools virtual lab must be greater than the number of cloud desktops that have actually been created and published in each media tools virtual lab.

4. The media cloud desktop management method based on bare metal servers as described in claim 1, characterized in that, Each media tool virtual lab's cloud desktop is an exclusive cloud desktop. If all published desktops in a virtual lab are occupied by users, when a new user connects to the virtual lab's desktop, it will trigger the cloud desktop dynamic scaling rules. The virtual lab will call the corresponding virtual lab cloud desktop template suite to dynamically publish and provide cloud desktops for the new user. If the new user is disconnected for a period of time that reaches the preset dynamic scaling lifespan, the virtual lab will call the cloud desktop recycling mechanism to restore the number of cloud desktops in the virtual lab to the initial setting.

5. The media cloud desktop management method based on bare metal servers as described in claim 1, characterized in that, When slicing bare metal GPU server clusters, all vGPU slices of the same size are divided on the same physical machine to maximize resource utilization.

6. The media cloud desktop management method based on bare metal servers as described in claim 1, characterized in that, The number of users in the user group is not strongly correlated with the number of cloud desktops actually created and published in the virtual lab, and the user group's quota in the virtual lab is not strongly correlated with the number of cloud desktops actually created and published in the virtual lab.

7. A media cloud desktop system based on bare metal servers, characterized in that, The system includes: The cloud desktop basic resource module is used to support the underlying basic resources of cloud desktops through bare metal GPU servers, general-purpose servers and media storage pooling resources, providing CPU, memory, storage and GPU computing power resources for cloud desktops; The cloud desktop operation and maintenance management module is used to realize the operation and maintenance release and management before the user logs in to the cloud desktop system according to any one of the media cloud desktop management methods according to claims 1 to 6; The cloud desktop distributed portal module is used to provide users with a unified portal to access the cloud desktop system through a client. Through the portal, users can select different availability zones. When the underlying infrastructure resources or network leased line of an availability zone fail, users are allowed to switch to another availability zone to access the cloud desktop. The cloud desktop control and authentication module is used to provide one-to-one or one-to-many user allocation and management for cloud desktops according to different usage scenarios. It realizes user metadata recording and login-related log recording. The user client logs in by calling the authentication server and clicks on the virtual desktop. The user client transmits the user identity credentials to the authentication server through the ADC's encrypted channel. The authentication server transmits the user identity credentials to the application delivery controller. The application delivery controller verifies the account's legitimacy with the AD domain controller and returns the verification information to the application delivery controller. The application delivery controller queries the virtual machine list based on the account information and returns the information to the authentication server. The authentication server then provides the corresponding cloud desktop to the user terminal. The cloud desktop network connection optimization module is used to detect the dynamic fluctuations of data center network equipment and the elasticity data of hardware infrastructure resources in real time after the user connects to the cloud desktop. It dynamically utilizes the CPU and GPU resources of the cloud desktop and optimizes the transmission link through the HDX transmission protocol. When the user and the cloud desktop transmit data, it determines whether the network bandwidth is approaching and causing congestion based on the detected elasticity data. If so, it uses a data compression algorithm to reduce the display frame rate of the cloud desktop and adopts smooth display. If not, it maintains the current display frame rate of the cloud desktop. The cloud desktop security protection module is used to force users' client devices to interact with the security protection module for security access matching when they connect to the cloud desktop via remote desktop. It determines whether the security access standards are met. If yes, remote connection is allowed; otherwise, the connection is automatically disconnected. The cloud desktop is included in the physical host security protection scope from the moment it is published and created. The security protection module collects cloud desktop operating system information, monitors real-time intrusion events, collects port process data, and forms baseline rectification suggestions.

8. The media cloud desktop system based on a bare metal server as described in claim 7, characterized in that, The cloud desktop distributed portal module is associated and bound with the cloud desktop basic resource module. The basic resources of different distributed availability zones are different, but the cloud desktops of the tool-type virtual laboratories to be connected are consistent. The backend media storage and metadata of different distributed availability zones are kept synchronized in real time.

9. The media cloud desktop system based on a bare metal server as described in claim 7, characterized in that, The cloud desktop network connection optimization module detects seven features in its elastic data: network bandwidth, network congestion index, number of network packet losses, number of cloud desktops with latency, CPU utilization, memory utilization, and number of CIFS connections. The detected elastic data is used to determine whether it is approaching network bandwidth and causing congestion through preset judgment rules or pre-trained neural networks.

10. The media cloud desktop system based on a bare metal server as described in claim 7, characterized in that, In the cloud desktop security protection module, when a user transmits a suspicious virus or Trojan file to the cloud desktop that matches the virus database and rule database of the security protection module, the file extension is modified and the corresponding file is removed to the security protection isolation folder.

Citation Information

Patent Citations

  • A virtual cloud desktop security access method based on deep protection

    CN109472136A

  • Research and development resource cloud platform and resource sharing method

    CN110138855A