Cloud service system, virtual machine creation method, device, medium and program product
By grouping management of virtual CCPs of physical CCPs and selecting idle groups to allocate resources for virtual machines, the problem of unbalanced resource allocation in virtualized environments is solved, and the efficiency of virtual machine creation and load balancing of physical CCPs is improved.
Patent Information
- Application Number
- CN202411642452.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-15
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2044-11-15
AI Technical Summary
How to reasonably manage and allocate virtualized password coprocessor resources to improve the efficiency of virtual machine creation, especially on service devices with multiple physical CCPs, to avoid resource load imbalance and processing bottlenecks.
The virtual CCP corresponding to the physical CCP is grouped and the virtual CCP corresponding to the multiple physical CCPs is divided into multiple virtual CCP groups. Each virtual CCP group includes a different physical CCP. When the virtual machine is created, the target group is selected from the currently idle virtual CCP group to allocate resources for the virtual machine to be created.
It improves the efficiency of virtual CCP resource allocation, reduces resource conflicts, improves the efficiency of virtual machine creation, and ensures load balancing of physical CCP.
Smart Images

Figure CN119127408B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a cloud service system, a virtual machine creation method, a device, a medium, and a program product. Background Art
[0002] A cryptographic coprocessor (CCP) is a hardware module integrated into the central processing unit (CPU) to accelerate encryption and decryption operations. CCP enables servers based on this CPU to efficiently and securely process encryption tasks locally, reducing reliance on external dedicated devices, reducing network latency and hardware costs, and improving the overall efficiency and security of data processing.
[0003] In order to improve the utilization rate of server hardware, multiple virtual machines (VMs) can be virtualized on the service device through virtualization technology, so as to efficiently utilize the computer's hardware resources. In order to enable the virtual machine to have CCP functions, a hardware CCP can be virtualized into multiple virtual CCPs (vCCPs) and allocated to multiple virtual machines for use, so that the virtual machine has CCP functions. Therefore, it is necessary to allocate a suitable vCCP to the virtual machine during the virtual machine creation process. However, for a service device with multiple physical CCPs, each physical CCP can be virtualized into multiple vCCPs. How to reasonably manage and allocate these vCCP resources has become a technical problem that needs to be solved in this field. Summary of the invention
[0004] Multiple aspects of the present application provide a cloud service system, a virtual machine creation method, a device, a medium, and a program product to implement management of virtual CCP resources.
[0005] The embodiment of the present application provides a cloud service system, including: at least one service device; a processor of the service device is integrated with a plurality of physical cryptographic coprocessors CCP; each physical CCP is virtualized into a plurality of virtual CCPs;
[0006] The virtual CCPs corresponding to the multiple physical CCPs are divided into multiple virtual CCP groups, and each virtual CCP group includes virtual CCPs corresponding to different physical CCPs;
[0007] The service device is further used to respond to a virtual machine creation request, determine a target virtual CCP group for the virtual machine to be created from currently idle virtual CCP groups; generate configuration information of the virtual machine to be created according to the target virtual CCP group; and create a virtual machine with a CCP function according to the configuration information of the virtual machine to be created.
[0008] The embodiment of the present application also provides a virtual machine creation method, which is applicable to a service device, wherein a processor of the service device is integrated with multiple physical cryptographic coprocessors CCP; each physical CCP is virtualized into multiple virtual CCPs; the virtual CCPs corresponding to the multiple physical CCPs are divided into multiple virtual CCP groups, and the virtual CCPs included in each virtual CCP group correspond to different physical CCPs;
[0009] The method comprises:
[0010] In response to a virtual machine creation request, determining a target virtual CCP group for the virtual machine to be created from currently idle virtual CCP groups;
[0011] Generating configuration information of the virtual machine to be created according to the target virtual CCP group;
[0012] A virtual machine with a CCP function is created according to the configuration information of the virtual machine to be created.
[0013] The embodiment of the present application further provides an electronic device, comprising: a memory and a processor; wherein the memory is used to store a computer program; a plurality of physical CCPs are integrated in the processor, each physical CCP is virtualized into a plurality of virtual CCPs; the virtual CCPs corresponding to the plurality of physical CCPs are divided into a plurality of virtual CCP groups, and the virtual CCPs included in each virtual CCP group correspond to different physical CCPs;
[0014] The processor is coupled to the memory and is configured to execute the computer program to perform the steps in the aforementioned virtual machine creation method.
[0015] An embodiment of the present application also provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed by one or more processors, the one or more processors are caused to execute the steps in the aforementioned virtual machine creation method.
[0016] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by one or more processors, causes the one or more processors to execute the steps in the aforementioned virtual machine creation method.
[0017] In an embodiment of the present application, multiple vCCP groups are obtained by grouping and managing the vCCPs corresponding to the physical CCPs. When a virtual machine creation request arrives, a target vCCP group is selected for the virtual machine to be created from the currently idle vCCP group. Afterwards, the configuration information of the virtual machine to be created can be generated according to the target vCCP group, thereby realizing the management of vCCP resources. Since the target vCCP group is selected from the currently idle vCCP group, the target vCCP group must be an idle vCCP group, and there is no need to traverse and query whether all vCCPs are occupied before allocating them, which can improve the efficiency of vCCP resource allocation and thus help improve the efficiency of virtual machine creation. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0019] Figure 1 A schematic diagram of the architecture of the cloud service system provided in the embodiment of the present application;
[0020] Figure 2 A schematic diagram of the process of creating a traditional virtual machine;
[0021] Figure 3 A schematic diagram of a virtual machine creation process provided in an embodiment of the present application;
[0022] Figure 4 and Figure 5 A schematic diagram of the correspondence between the physical CCP and the vCCP provided in the embodiment of the present application;
[0023] Figure 6 A flowchart of a method for creating a virtual machine provided in an embodiment of the present application;
[0024] Figure 7 A detailed diagram of the virtual machine creation process provided in the embodiment of the present application;
[0025] Figure 8 A two-dimensional scatter plot of the probability of L,c and vCCP resource conflicts when concurrently creating a 32-core virtual machine provided in an embodiment of the present application;
[0026] Fig. 9 A two-dimensional scatter plot of the probability of L,c and vCCP resource conflicts when concurrently creating a 64-core virtual machine provided in an embodiment of the present application;
[0027] Fig.10 A two-dimensional scatter plot of the probability of L,c and vCCP resource conflicts when concurrently creating a 128-core virtual machine provided in an embodiment of the present application;
[0028] Fig.11 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0029] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.
[0030] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0031] The concepts or terms involved in the embodiments of the present application are first explained below.
[0032] Crypto Co-Processor (CCP): A physical CCP is an encryption and decryption co-processor embedded in a processor (such as a CPU). It is a hardware module used for encryption and decryption processing and can improve the encryption and decryption processing speed.
[0033] Virtual CCP (vCCP): A virtual encryption and decryption coprocessor that is transparently transmitted to a virtual machine through virtualization technology, giving the virtual machine the functionality of a physical CCP.
[0034] Mediated Device (MDEV device): MDEV device refers to Virtual Function Input / Output (VFIO) mediator device (VFIO-MDEV device), which is a framework in the Linux kernel (an operating system) for managing virtualized devices. MDEV device is a virtualized device managed by the MDEV framework, allowing user space applications to interact with IO devices through the VFIO interface. Using MDEV devices can achieve virtualization acceleration, device isolation, and device function customization.
[0035] Virtual machine configuration component (prepareVM): prepareVM is a component used to generate a virtual machine configuration file during the virtual machine creation process. It is integrated into the resource management configuration and virtual machine creation management tools. The virtual machine configuration file can be an Extensible Markup Language (XML) file.
[0036] Resource management configuration and virtual machine creation management tool: A scripting tool used in cloud service virtualization to set virtual machine environment information, assemble virtual machine configuration files, and perform other operations to support virtualization functions.
[0037] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.
[0038] It should be noted that the same reference numerals represent the same object or the same step in the following drawings and embodiments, and therefore, once an object or a step is defined in one drawing or embodiment, there is no need to further discuss it in the subsequent drawings and embodiments.
[0039] Figure 1 This is a schematic diagram of the architecture of the cloud service system provided in the embodiment of the present application. Figure 1 As shown, the cloud service system includes at least one service device 10. Generally, the cloud service system includes multiple service devices 10. Multiple refers to more than 2 (including 2).
[0040] A physical cryptographic coprocessor (CCP) 102 is integrated in the processor 101 of the service device 10. The number of physical CCPs 102 integrated in the processor 101 may be one or more. Multiple means more than two (including two). Generally, the number of physical CCPs 102 integrated in the processor 101 is multiple.
[0041] The physical CCP 102 implements cryptographic processing through hardware, and can implement cryptographic functions of security protection, integrity, authenticity, and non-repudiation. The physical CCP 102 can improve the cryptographic processing speed compared with software for cryptographic processing. Cryptographic processing includes but is not limited to data encryption and decryption, digital signature, hash function, and / or key negotiation, etc. The hash function can also be called a hash function or a Hash function, which is a function that compresses an input of any length (referred to as a message or a message) into an output of a fixed length. The encryption and decryption algorithms that the physical CCP 102 can implement include but are not limited to: elliptic curve public key cryptography algorithms (such as the commercial cryptography SM2 in the national cryptography algorithm), message digest algorithms (such as SM3), and / or symmetric encryption algorithms (such as SM4), etc. SM is the commercial cryptography in the national cryptography algorithm, and SM is the pinyin abbreviation of "commercial" and "cryptography" in "commercial cryptography". SM2 is a commercial cryptography in the national cryptography algorithm, which is a public key encryption algorithm based on elliptic curve encryption and is an asymmetric encryption algorithm. SM3 is a message digest algorithm, and SM4 is a symmetric encryption algorithm.
[0042] As Figure 1 shown, the service device 10 may include: hardware and a host operating system (Operating System, OS). The hardware includes a processor 101. The basic input / output system (Basic Input Output System, BIOS) of the service device 10 meets the relevant security requirements and can enable the security capabilities of the processor 101. The host operating system has module capabilities such as CCP drivers, virtual function input / output (Virtual Function I / O, VFIO), MDEV, etc., as well as security certificates required for the corresponding security hardware and suites of the processor.
[0043] The service device can be virtualized into one or more virtual machines. Multiple containers (Container) or container groups (such as Pods, etc.) can run on the virtual machine, and the virtual machine provides the required software and hardware resource environment and the required security capabilities for their operation. The container is managed by Figure 1 the container scheduling and orchestration components in Figure 1The container scheduling and orchestration component is a container scheduling and orchestration engine that supports automated deployment, large-scale scalability, and application container management. Multiple containers or container groups run the customer's own applications or services. The service device 10 can be virtualized into one or more virtual machines through virtualization technology. For example, the service device can be virtualized into one or more virtual machines through Quick Emulator (QEMU) and Kernel-based Virtual Machine (KVM) technology. Therefore, the virtual machine can be represented as a QEMU process. Among them, QEMU provides a user space simulator that can simulate the complete system hardware, including processors (such as CPUs), memory, storage devices (such as disks), etc. KVM: It is a module loaded into the kernel of an operating system (such as a Linux system) that provides hardware-accelerated virtualization capabilities. KVM used in conjunction with QEMU can significantly improve the performance of virtual machines.
[0044] In the embodiment of the present application, the CCP security capability in the virtual machine can be transparently transmitted to the virtual machine in the form of MDEV device by QEMU using the VFIO framework of the host operating system, so that the virtual machine has CCP function, that is, Figure 1 The CPP-VM in the virtual machine is called a virtual CCP (vCCP). The vCCP can also be understood as an MDEV device. Figure 1 In the figure, "ct" is the abbreviation of "Crypto Technology", which is the kernel driver module in the virtual machine operating system.
[0045] Specifically, in the MDEV framework, the real physical device (i.e., physical CCP) is used as the parent device (Parentdevice). The vendor driver (Vendor Driver) registers the physical CCP with the MDEV framework, and then creates an MDEV device under the parent device through the sysfs interface provided by the MDEV framework. MDEV devices are abstract, logical devices. MDEV devices are registered with the VFIO framework by the MDEV driver (such as VFIO-MDEV). From the perspective of the VFIO framework, an MDEV device is a VFIO device. Finally, in QEMU, an MDEV device can be assigned to a virtual machine. The virtual machine's call to the MDEV device-related operation function will be routed to the parent device driver (i.e., the manufacturer driver, that is, the physical CCP driver's related operation function, so that the virtual machine can use the physical CCP's capabilities. Each time QEMU operates on the VFIO group / device, it will go through the QEMUvCCP device-> memory read-> KVM exit-> VFIO-MDEV-> VFIO-> physical CCP address, ensuring that the manufacturer driver can capture the virtual machine's operating system, i.e., the guest operating system (GuestOS)'s access request to the MDEV device, so that the virtual machine can access the physical CCP.
[0046] exist Figure 1 VFIO-PCI is a user space driver framework for the operating system, which aims to provide direct access to Peripheral Component Interconnect (PCI) devices and supports multiple types of devices, including physical CCPs. It is mainly used to implement the pass-through function of the device, allowing the virtual machine to directly access the physical device, thereby obtaining near-native performance.
[0047] .ko is a kernel module of an operating system (such as Linux system). Among them, vfio.ko provides basic device pass-through function and the ability to support user space drivers, supports multiple types of devices, provides core pass-through function and the ability to support user space drivers. vfio-pci.ko is a module designed specifically for PCI devices, which provides registration, mapping and management functions of PCI devices, and mainly supports the pass-through capability of PCI devices. vfio-mdev.ko and mdev.ko are two modules in the Linux kernel, which jointly support device pass-through and device simulation functions. The mdev.ko module is a functional module in the Linux kernel for managing and simulating devices. It allows devices to be created and destroyed dynamically, thereby supporting hot plugging and dynamic configuration of devices. vfio-mdev.ko is a module based on the vfio framework, which is used to support the pass-through function of discrete devices. It allows virtual machines to directly access some functional units of physical devices, thereby achieving higher performance and flexibility. ct.ko is a module related to encryption technology, which is part of a specific system or device driver and is used to implement encryption functions. kvm.ko is a module file in the Linux kernel, representing the core component of KVM. kvm.ko is responsible for providing basic support for hardware virtualization, enabling users to run virtual machines on top of the Linux kernel.
[0048] According to the above process of virtual machines having CCP functions, it is known that vCCP resources need to be allocated to virtual machines during the virtual machine creation process. The following first describes the creation process of traditional virtual machines. Figure 2 The creation process of the traditional virtual machine may include the following steps:
[0049] 1. Users can initiate a virtual machine creation request through the platform-based white screen portal or the background command interface. The virtual machine creation request reaches the management and control component running on the service device.
[0050] 2. The control component generates necessary parameters contained in a virtual machine configuration file (such as an XML file) based on the virtual machine creation request, and passes these necessary parameters to the prepareVM component in the resource management configuration and virtual machine creation management tool.
[0051] The necessary parameters contained in the virtual machine configuration file may include: some hardware configuration parameters of the virtual machine, such as the number of processors and CPU memory size, etc. prepareVM generates basic hardware configuration information of the virtual machine based on the passed parameters to ensure that the virtual machine can be correctly started according to the specified specifications.
[0052] The prepareVM component generates hardware configuration information of the virtual machine based on these parameters. The hardware configuration information can be implemented in the format of an XML file.
[0053] 3. The prepareVM component returns part of the hardware configuration information of the generated virtual machine to the management and control component.
[0054] 4. The control component passes some hardware configuration information to the virtual machine configuration file assembly component (StartVMx).
[0055] The virtual machine configuration file assembly component can assemble part of the virtual machine's hardware configuration information and other configuration information into a complete virtual machine configuration file (such as an XML file). Other configuration information may include: basic attribute information of the virtual machine, security configuration parameters and identity authentication data, etc., but is not limited thereto. The basic attributes of the virtual machine may include: the name of the virtual machine, the image identifier, the instance type of the virtual machine, and the geographical location of the virtual machine. Security configuration parameters may include security group IDs and firewall rules, etc. Identity authentication data may include user names and passwords, etc.
[0056] 5. The virtual machine configuration file assembly component transfers the complete virtual machine configuration file to the virtual machine management component (such as libvirt). The virtual machine configuration file assembly component can call the libvirt interface and transfer the virtual machine configuration file to libvirt to start the virtual machine.
[0057] Among them, libvirt is a software library and tool collection for managing virtualization functions on machines. It provides a unified application programming interface (API), allowing developers to manage multiple virtualization technologies through the API, including but not limited to KVM and QEMU. Libvirt has virtual machine management functions, such as starting, shutting down, suspending or resuming virtual machines, etc.; it also has storage management functions, such as managing virtual disks and storage pools, and network management functions, such as configuring and managing virtual networks.
[0058] The virtual machine management component (such as libvirt) can convert the virtual machine configuration file into command line parameters suitable for QEMU and perform necessary configuration work at the operating system level. Specifically, the virtual machine management component can parse various parameters in the virtual machine configuration file, such as memory size, number of CPUs, disk information, network interface information, etc. when starting the virtual machine component; further, according to the parsed configuration information, assemble a command line suitable for starting the virtual machine. The command line for starting the virtual machine may include: selecting a suitable virtualization engine (such as QEMU), setting hardware parameters such as processors and memory, specifying the location of the disk image, and configuring network interface parameters.
[0059] 6. Libvirt starts the QEMU process with command line parameters appropriate for QEMU.
[0060] 7. QEMU collaborates with the KVM kernel module to start the virtual machine based on the converted command line parameters.
[0061] The virtual machine runs as a process on the host machine. When executing sensitive operations such as IO, a virtual machine exit (VMexit) event is triggered, causing control to be transferred from the user-mode QEMU to the kernel-mode KVM module.
[0062] 8. After receiving the virtual machine exit message, the KVM module analyzes the reason for the virtual machine exit and performs corresponding processing. Then, it passes the data to QEMU and executes the virtual machine entry (VMentry) operation again, so that the control is transferred to the user state QEMU.
[0063] The interaction between steps 7 and 8 continues, indicating that the virtual machine is running. When this interaction starts running, it means that the virtual machine has been created and is in a running state.
[0064] The above embodiment simply illustrates the creation process of a traditional virtual machine. In the embodiment of the present application, vCCP resources are configured for the virtual machine so that the virtual machine has CCP functions. This requires generating vCCP-related configuration information for the virtual machine during the virtual machine creation process. Figure 3 The figure shows a flow chart of the virtual machine creation process of the embodiment of the present application. Figure 3 The virtual machine creation process shown is similar to Figure 2 The difference between the virtual machine creation process shown is that the Figure 3 Steps 4 and 5 in the above are related contents of generating configuration information of vCCP resources for the virtual machine. Figure 3 For a description of the other steps in Figure 2 The relevant content description is not repeated here.
[0065] according to Figure 3 The creation process of the virtual machine with CCP function shown in the figure shows that: during the virtual machine creation process, it is necessary to allocate appropriate vCCP resources to the virtual machine. However, the number of vCCP resources on a service device is numerous and messy, and there are certain limitations on the allocation of vCCP resources. Specifically, a physical CCP can generate multiple MDEV devices, and multiple refers to 2 or more. For the convenience of subsequent description, the number of MDEV devices is represented by M, M≥2, and is an integer. Each MDEV device corresponds to 1 vCCP, that is, a physical CCP can be virtualized into M vCCPs. There are N physical CCPs on a service device. N≥1, and is an integer.
[0066] N physical CCPs on a service device can be virtualized into N*M vCCPs. In order to prevent the vCCP encryption calculation tasks from being concentrated on one or some physical CCPs, causing uneven load and processing bottlenecks, it is stipulated that the same virtual machine can only use vCCPs virtualized from different physical CCPs. This is mainly because if there are multiple vCCPs corresponding to the same physical CCP in the vCCP used by the virtual machine, it may cause all encryption calculation tasks to be concentrated on the same physical CCP, while other physical CCPs are idle, resulting in an unbalanced load on the physical CCP and prone to processing bottlenecks. Therefore, it is stipulated that the same virtual machine can only use vCCPs virtualized from different physical CCPs, that is, the same virtual machine can only use vCCPs corresponding to different physical CCPs. Therefore, the number of vCCPs that can be used by a virtual machine is [1, N], which means that a service device can support [M, N*M] virtual machines with CCP functions. The number of vCCPs allocated to multiple virtual machines deployed on the service device may be the same or different, depending on the needs of the users corresponding to the virtual machines. In some embodiments, the correspondence between N physical CCPs and vCCPs on the service device is, such as Figure 4 As shown. Figure 4 In the example, the number of physical CCPs on the service device is N, that is, Figure 4 CCP-n is shown, n=1,2,…,N. Each physical CCP can generate M MDEV devices, that is, Figure 4 mdev-uuid-n,m is shown. m=1,2,…,M. uuid is a universally unique identifier (UUID), which represents the unique identifier of the MDEV device. The physical CCP can be transparently transmitted to the virtual machine (VM) in the form of an MDEV device, so that the virtual machine has the CCP capability, that is, the virtual machine has vCCP. One MDEV device corresponds to one vCCP, which can support [M, N*M] virtual machines with CCP functions. Figure 4 In the figure, only M virtual machines (VMs) are used for illustration, that is, Figure 4 VM-m shown in FIG. 1 , m=1, 2, ..., M. The number of vCCPs allocated to the M virtual machines is determined by the needs of the corresponding users. Figure 4 In the figure, only some of the M virtual machines are assigned the same number of vCCPs, such as VM-2 and VM-3 are both assigned 4 vCCPs; while other virtual machines are assigned different numbers of vCCPs, but this does not constitute a limitation.
[0067] Assume that the number of vCCPs a virtual machine needs to use is Q, Q∈[1,N], then the vCCPs allocated to the virtual machine are options. It means that Q physical CCPs are selected from N physical CCPs, and one vCCP is selected from the vCCPs corresponding to each physical CCP in the Q physical CCPs. i represents the i-th physical CCP in the selected Q physical CCPs; represents the number of currently idle vCCPs in the vCCP corresponding to the i-th physical CCP among the selected Q physical CCPs. ∈[1, M]. For example, in some embodiments, the service device has 16 physical CCPs, and one physical CCP can be virtualized into 128 vCCPs. If the number of vCCPs allocated to each virtual machine is 8, and the number of currently idle vCCPs corresponding to each physical CCP is 1, the number of vCCPs allocated to the virtual machine is = 12870 options; if there are multiple currently idle vCCPs corresponding to the physical CCP, there are more options for the vCCPs allocated to the virtual machine. A large number of vCCP resources undoubtedly makes vCCP resource management particularly complex. Therefore, how to efficiently manage vCCP resources is a technical problem that needs to be solved in this field.
[0068] The following is an exemplary description of the vCCP resource management method provided in the embodiment of the present application. Since N=1, that is, when a service device has one physical CCP, the vCCP resources correspond to the same physical CCP, and the allocation and management of vCCP resources are relatively simple, that is, one currently idle vCCP is configured for each virtual machine. Therefore, the embodiment of the present application focuses on N≥2, that is, a service device contains multiple physical CCPs as an example to illustrate the management method of vCCP resources.
[0069] In the embodiment of the present application, in order to facilitate the management of vCCP resources, vCCP resources can be grouped. Specifically, the vCCPs corresponding to multiple physical CCPs can be divided into multiple vCCP groups according to the number K of vCCPs supported by the virtual machine. The vCCPs contained in each vCCP group correspond to different physical CCPs. In this way, it can prevent the vCCPs in the same vCCP group from competing for the same physical CCP, resulting in resource conflicts.
[0070] Assume that the number of vCCPs K supported by the virtual machine satisfies 1≤K≤N. N represents the number of physical CCPs on the service device. In order to facilitate the management of vCCP resources, the CCP capabilities provided by the virtual machines deployed on a service device can be made the same, that is, the virtual machines deployed on the same service device have the same number of vCCPs, that is, they all have K vCCPs. Then, according to the number of vCCPs K supported by the virtual machine, the vCCPs corresponding to the multiple physical CCPs on the service device can be divided into vCCP groups, each vCCP group contains K vCCPs, and these K vCCPs correspond to K different physical CCPs. Specifically, the K vCCPs corresponding to K different physical CCPs can be divided into the same vCCP group to obtain vCCP groups.
[0071] In some embodiments, considering that the virtual machine needs to provide CCP computing power for the running containers, each container always obtains all CCP resources on the virtual machine, and the competition between containers for CCP resources is essentially the same as the competition between multiple processes for CCP resources. In order to ensure the CCP capability of the container, for a single virtual machine, the virtual machine can be given the maximum number N of vCCPs it can have, that is, the number of physical CCPs available on the service device, and these N vCCPs are used as a vCCP group, with a total of M vCCP groups. Accordingly, according to the number N of vCCPs supported by the virtual machine, the N vCCPs corresponding to N different physical CCPs can be divided into the same vCCP group to obtain M vCCP groups. In this embodiment, the correspondence between the physical CCP and the vCCP can be as follows. Figure 5 As shown in Figure 2. M vCCP groups can be assigned to M virtual machines, that is, Figure 5 VM-m in, m=1,2,…,M. Figure 5 A group of vCCPs in each virtual machine is a vCCP group, and each vCCP group contains N vCCPs.
[0072] After the above grouping, the multiple physical CCPs on the service device 10 are divided into multiple vCCP groups, and the vCCPs included in each vCCP group correspond to different physical CCPs.
[0073] In the embodiment of the present application, the vCCP group is used as the scheduling unit, and an index can be configured for each vCCP group. .in, , Represents a set of integers. i=0,1,…, Accordingly, the set of all vCCP groups available for allocation can be defined as a resource window W, where the length of W is the number of vCCPs. , each vCCP group contains K vCCPs. The resource window W is an index set of available vCCP groups, i.e., multiple vCCP groups, which can be expressed as: . represents the index of a vCCP group, corresponding to the K vCCPs contained in the (i+1)th vCCP group. In some embodiments, K=N, then the length of the resource window W is M, and the resource window W can be expressed as: .in, , , i=0,1,…, .
[0074] After completing the grouping of vCCP resources, vCCP resource management is performed using the vCCP group as the scheduling unit. A user can send a virtual machine creation request to a service device. In response to the virtual machine creation request, the service device can schedule resources for the vCCP group, and use the scheduled vCCP group to create a virtual machine with CCP functionality. It should be noted that the grouping of vCCP resources can be a pre-completed operation, or it can be an operation completed by the service device in response to the virtual machine creation request. Specifically, the service device can group vCCP resources when it first receives a virtual machine creation request, and when it subsequently receives a virtual machine creation request, it does not need to group vCCP resources again, and can directly use the grouped vCCP group to schedule vCCP resources to create a virtual machine with CCP functionality. The following is an illustrative description of the virtual machine creation method provided in an embodiment of the present application from the perspective of a service device.
[0075] Figure 6 The flowchart of the virtual machine creation method provided in the embodiment of the present application is as follows. Figure 6 As shown, the method mainly includes the following steps:
[0076] 601. In response to a virtual machine creation request, determine a target vCCP group for a virtual machine to be created from currently idle vCCP groups.
[0077] 602. Generate configuration information of a virtual machine to be created according to the target vCCP group.
[0078] 604. Create a virtual machine with CCP function according to the configuration information of the virtual machine to be created.
[0079] Based on the aforementioned group management of the vCCP resources of the service device, in step 601 of this embodiment, in response to the virtual machine creation request, a target vCCP group can be determined for the virtual machine to be created from the idle vCCP groups.
[0080] In some embodiments, identifiers may be assigned to the multiple vCCP groups divided, and each identifier represents a vCCP group. Accordingly, a list of identifiers of unused (i.e., idle) vCCP groups may be maintained. Whenever a vCCP group is assigned, the identifier of the vCCP group is deleted from the identifier list. Based on this, step 601 may be implemented as follows: from the identifier list of idle vCCP groups maintained, a target identifier is determined for the virtual machine to be created; and the vCCP group corresponding to the target identifier is used as the target vCCP group.
[0081] In some other embodiments, based on the index of the aforementioned vCCP group, an index set of currently idle vCCP groups may be determined in response to a virtual machine creation request. For ease of description, the index set of currently idle vCCP groups is defined as target index set A.
[0082] Specifically, in response to the virtual machine creation request, the index set of the multiple vCCP groups divided, that is, the aforementioned resource window W, can be obtained, and the index set U of the currently occupied vCCP group can be obtained. In the embodiment of the present application, for the convenience of description and distinction, the index set of the multiple vCCP groups divided, that is, the aforementioned resource window W, is defined as the first index set W; and the index set U of the currently occupied vCCP group is defined as the second index set U.
[0083] After obtaining the full index set of the vCCP group of the service device, that is, the first index set W, and the second index set U of the currently occupied vCCP group; the target index set A of the currently idle vCCP group can be determined according to the first index set W and the second index set U. Where A=WU, that is, for any index in the first index set W ,like exists in the first index collection, but does not exist in the second index set U, then is the index of a currently idle vCCP group. The same method can be used to determine the indexes of all currently idle vCCP groups to obtain the target index set A.
[0084] In the embodiment of the present application, a first index set W of the divided multiple vCCP groups can be maintained, and the first index set W is implemented as a fixed-length list, with very low maintenance cost and occupies very little storage resources. Accordingly, in response to a virtual machine creation request, the maintained first index set W, that is, the index set of all available vCCP groups on the service device, can be read.
[0085] In some embodiments, an index list of used vCCP groups may also be maintained, and the index list is used to store the indexes of used vCCP groups. Accordingly, in response to a virtual machine creation request, an index set of used vCCP groups stored in the index list of used vCCP groups maintained by the service device may be obtained as a second index set U of the currently occupied vCCP group.
[0086] Among them, the index set of used vCCP groups is a dynamically updated index list. Whenever a virtual machine is created, the index of the vCCP group occupied by the currently created virtual machine will be updated to the index set of used vCCP groups. Moreover, whenever a virtual machine is destroyed, the vCCP group occupied by the destroyed virtual machine will be released. Accordingly, it is also necessary to delete the index of the vCCP group occupied by the destroyed virtual machine from the index set of used vCCP groups. In this implementation method, when a new virtual machine requests to be created, the used index set can be quickly checked to determine which vCCP groups are still available without having to scan the usage of the entire system in real time, which can improve the allocation speed of vCCP resources. However, this implementation method requires the storage of the usage of vCCP resources, and the maintenance and update of the usage of vCCP resources, which occupies a large storage space, and there is a certain processing overhead for maintaining and updating the usage of vCCP resources, which will reduce the performance of the virtual machine running applications or services.
[0087] In order to reduce the processing overhead of storing, maintaining and updating the usage of vCCP resources, in other embodiments, the index set of the used vCCP group may not be maintained, and when a virtual machine creation request arrives, the second index set U of the currently occupied vCCP group is obtained in real time. Specifically, in response to the virtual machine creation request, the second index set U of the currently occupied vCCP group can be obtained through a virtualization management command. Among them, the virtualization management command is a naming line used to manage virtual machine resources in a virtualized environment. The resource information occupied by the virtual machine can be obtained through the virtualization management command. In this embodiment, the information of the vCCP group occupied by the virtual machine is mainly obtained through the virtualization management command. The virtualization management command can be a virsh command. Virsh is a command line tool for interacting with libvirt. Libvirt is a software layer for managing virtualization on a machine. Virsh provides a series of commands to manage virtualization resources such as virtual machines, networks, and storage pools. In this embodiment, the second index set U of the currently occupied vCCP group is obtained through a virtualization management command without maintaining and updating the usage of vCCP resources. This can save the processing overhead of maintaining and updating the usage of vCCP resources, has low code complexity, and can also save storage space for storing the usage of vCCP resources.
[0088] In some embodiments, the virtual machines currently running on the service device may be determined by a list command in a virtualization management command (such as a virsh list command). The virsh list command is a command for displaying the status of currently running virtual machines (VMs). It lists all running virtual machines and provides their basic information, such as identification information (ID), name, and current status.
[0089] Furthermore, the configuration information of the currently running virtual machine can be obtained through the configuration file export command in the virtualization management command (such as the virsh dumpxml command). The virsh dumpxml command is a command for exporting the configuration file of the virtual machine. This command can view and back up the detailed configuration information of the virtual machine, including hardware specifications, network settings, disk information, etc. In the embodiment of the present application, since the virtual machine is configured with vCCP resources, the virsh dumpxml command can also view the vCCP resource information of the virtual machine.
[0090] Further, the index set of the vCCP group used by the currently running virtual machine can be obtained from the configuration information of the currently running virtual machine as the second index set U. Specifically, the MDEV path pattern related to the currently running virtual machine can be obtained from the configuration information of the currently running virtual machine through the virsh dumpxml command; further, the MDEV path pattern is parsed to obtain the specific vCCP resource path. After that, the vendor index (vendor / idx) file under the vCCP resource path is read, and the index number idx is read from the vendor index file, which is the index of the vCCP group occupied by the currently running virtual machine. In this embodiment, the second index set U of the currently occupied vCCP group is obtained through virtualization management commands (such as the virsh list command and the virshdumpxml command), without the need to maintain and update the usage of vCCP resources, which can save the processing overhead of maintaining and updating the usage of vCCP resources, and can also save the storage space for storing the usage of vCCP resources.
[0091] After determining the second index set U of the currently occupied vCCP group, the target index set A of the currently idle vCCP group can be determined according to the first index set W and the second index set U. Since the target index set A stores the index of the currently idle vCCP group, the target index can be determined for the virtual machine to be created from the target index set A. Since the target index set A stores the index of the currently idle vCCP group, the target index is directly selected from the target index set A for the virtual machine to be created. The vCCP group corresponding to the target index must be an idle vCCP group, and there is no need to traverse and query whether all vCCPs are occupied before allocation, which can improve the efficiency of vCCP resource allocation, thereby helping to improve the efficiency of virtual machine creation.
[0092] In the embodiments of the present application, the specific implementation method of determining the target index for the virtual machine to be created from the target index set A is not limited. In some embodiments, the target index set can be sorted, and the maximum index or the minimum index can be selected from the sorted target index set as the target index. Among them, the target index set can be sorted in ascending order, or the target index set can be sorted in descending order. Alternatively, an index at a set position can be selected from the target index set as the target index. For example, an index at the first or last position can be selected as the target index. Alternatively, an index at other set positions can be selected as the target index, etc.
[0093] The aforementioned method of selecting indexes in sequence or selecting indexes with set positions has simple logic and simplifies the allocation logic. Since the index itself is an ordered identifier, selecting the minimum index, the maximum index, or the index at a set position means that an unused vCCP group can be quickly located without the need for a complex algorithm to determine which vCCP group is suitable for allocation. However, the method of selecting indexes in sequence requires sorting the indexes of the target index set, which has a certain processing overhead. On the other hand, when multiple concurrent virtual machine creation requests arrive, there is a conflict in vCCP resources.
[0094] Specifically, suppose that two concurrent virtual machine creation requests (i.e., virtual machine creation requests 1 and 2) arrive at the same time, and the service device responds to virtual machine creation request 1 and assigns the smallest index in the target index set (assuming that ) corresponding vCCP group; for virtual machine creation request 2, the minimum index of the target index set obtained by the service device is also , the virtual machines corresponding to virtual machine creation requests 1 and 2 will be assigned to the same vCCP group, causing the two to compete for the same vCCP group, resulting in vCCP resource conflicts, and then causing virtual machine creation failure.
[0095] Similarly, when multiple concurrent virtual machine creation requests are received, there will also be vCCP resource conflicts when selecting the index at the set position. Assume that two concurrent virtual machine creation requests (i.e., virtual machine creation requests 1 and 2) arrive at the same time, and the service device responds to virtual machine creation request 1 and allocates the first index in the target index set (assuming that ) corresponding vCCP group; for virtual machine creation request 2, the first index of the target index set obtained by the service device is also , the virtual machines corresponding to virtual machine creation requests 1 and 2 will be assigned to the same vCCP group, causing the two to compete for the same vCCP group, resulting in vCCP resource conflicts, and then causing virtual machine creation failure.
[0096] In order to solve the vCPP resource conflict problem caused by sequentially selecting indexes and selecting indexes with set positions, in some embodiments, the vCCP resource conflict problem can be solved by locking. Specifically, for any virtual machine creation request X among multiple concurrent virtual machine creation requests, before responding to the virtual machine creation request X, the index list of the used vCCP group maintained by the aforementioned service device is locked; then, in response to the virtual machine creation request X, the second index set U of the currently occupied vCCP group is obtained from the index list of the used vCCP group maintained by the service device; then, according to the first index set W and the second index set U, the target index set A of the currently idle vCCP group is determined, and the minimum index, the maximum index or the index at the set position is selected from the target index set A as the target index. Then, the vCCP group corresponding to the target index is allocated to the virtual machine requested to be created by the virtual machine creation request X. After the virtual machine request requested to be created by the virtual machine creation request X is completed, the aforementioned target index (the minimum index, the maximum index or the index at the set position) is deleted from the index list, and the lock of the index list is released. Afterwards, the index list of used vCCP groups maintained can be locked again for another virtual machine creation request among the multiple concurrent virtual machine creation requests, and the execution is repeated in sequence until the creation of the virtual machines requested by the multiple concurrent virtual machine creation requests is completed. This method of locking the index list of used vCCP groups maintained by the service device can avoid vCCP resource conflicts caused by multiple concurrent virtual machine creation requests competing for vCCP resources. However, this method converts the parallel allocation of vCCP resources for multiple concurrent virtual machine creation requests into serial execution, which has low vCCP resource allocation efficiency and increases the virtual machine creation time. On the other hand, the locking and releasing logic is complex, the code complexity is high, and the computing resource overhead of the service device is large.
[0097] In order to solve the above problems caused by locking and releasing locks, in other embodiments, a random number selection mechanism is introduced. Specifically, a random number Index greater than or equal to 0 and less than or equal to the length of the target index set A can be generated. That is, Index∈[0,len(A)]. Len(A) represents the length of the target index set A, that is, the number of indexes in the target index set A.
[0098] In some embodiments, the internal system variables of the operating system can be obtained in the operating system of the service device as random seeds, and the length of the target index set A is used as a parameter to generate a random number greater than or equal to 0 and less than or equal to the length of the target index set A. Using the internal variables of the operating system as random number seeds does not require additional library support, and the random number generation speed is faster. However, due to the low randomness of the internal variables of the operating system, the randomness of the generated random numbers will also be low.
[0099] In other embodiments, a system random number may be obtained as a random seed, and a random number greater than or equal to 0 and less than or equal to the length of the target index set A may be generated using the length of the target index set A as a parameter. Since the system random number is a random number based on the system entropy pool, it has a higher randomness. The system entropy pool refers to a mechanism for generating random numbers in an operating system. The entropy pool collects data (i.e., "entropy") from various uncertain sources and uses the data to generate high-quality random numbers. Therefore, the random number generated by the system random number as a random seed has a stronger randomness. However, this random number generation method requires access to the system entropy pool, and the generation speed is relatively slow.
[0100] In some other embodiments, the current timestamp can be used as a random seed, and the length of the target index set A can be used as a parameter to generate a random number greater than or equal to 0 and less than or equal to the length of the target index set A. Since the current timestamp is unique, using the current timestamp as a random seed can ensure that the random number generated each time is different, that is, the generated random number has a strong randomness. On the other hand, the current timestamp is the system timestamp of the service device, and the system timestamp can be obtained conveniently and quickly, thereby generating random numbers faster.
[0101] The random number generation method shown in the above embodiment is only an exemplary description and does not constitute a limitation. After generating a random number Index that is greater than or equal to 0 and less than or equal to the length of the target index set, the target index corresponding to the random number Index in the target index set A can be determined. Specifically, the index of the position corresponding to the random number Index in the target index set A can be used as the target index. Assuming that the random number Index is equal to 2, the second index in the target index set A is used as the target index. Further, the vCCP group corresponding to the target index can be determined as the target vCCP group.
[0102] This implementation method generates a random number Index greater than or equal to 0 and less than or equal to the length of the target index set to select vCCP resources, and probabilistically disperses the vCCP resource conflicts of multiple virtual machine creation requests, which can reduce the vCCP resource conflicts of multiple virtual machine creation requests. Moreover, this implementation method randomly selects a value within the length interval of the available resource window A (i.e., the target index set A of the idle vCCP group). As long as the randomly selected values are different, the corresponding vCCP resources must be unoccupied and allocable, and no other data structures and overheads are required to maintain the context state of the vCCP resources to be allocated before and after the allocation, avoiding the locking and releasing operations of maintaining atomic operations, which can reduce the complexity of code logic, improve the efficiency of vCCP resource allocation, and thus help improve the efficiency of virtual machine creation.
[0103] After determining the target index, the vCCP group corresponding to the target index can be used as the target vCCP group. Accordingly, in step 602, configuration information of the virtual machine to be created can be generated according to the target vCCP group. Specifically, the resource path of the target vCCP group is converted into a format of a virtual machine configuration file, such as XML format, to obtain a vCCP resource configuration file of the virtual machine to be created; then, the vCCP resource configuration file of the virtual machine to be created is added to the initial configuration file of the virtual machine to be created, to obtain a configuration file of the virtual machine to be created.
[0104] Specifically, the resource path of the target vCCP group is converted into the format of the virtual machine configuration file (such as XML format) to obtain the vCCP resource configuration file of the virtual machine to be created, such as a vCCPXML file. Furthermore, the vCCP resource configuration file of the virtual machine to be created can be added to the initial configuration file of the virtual machine to be created through the prepareVM component to obtain the configuration file of the virtual machine to be created. Among them, the initial configuration file of the virtual machine to be created can be a domain configuration file obtained by the prepareVM component from the parameters sent from the control component to the prepareVM component, such as a domain XML (DomainXML) file. The initial configuration file contains the configuration information of the virtual machine, including but not limited to hardware configuration information such as processor, memory, disk, network interface, drive, and startup parameters. The prepareVM component adds the vCCP resource configuration file of the virtual machine to be created to the initial configuration file of the virtual machine to be created to obtain a DomainXML file, which is the configuration file of the virtual machine to be created. The configuration file contains the vCCP resource configuration information of the virtual machine and other resource configuration information. Other resource configuration information refers to the configuration information of other resources required by the virtual machine except the virtual CCP, including but not limited to: hardware configuration information such as processor, memory, disk, network interface, driver, and startup parameters.
[0105] Furthermore, since the configuration information of the virtual machine to be created includes the resource information of the vCCP to which the virtual machine to be created is allocated, in step 603, a virtual machine with a CCP function may be created according to the configuration information of the virtual machine to be created.
[0106] Specifically, the Virtual Machine Manager (VMM) can be used to determine the target physical CCP corresponding to the target vCCP group according to the resource path of the target vCCP group; then, the VMM can be used to create a virtual machine with CCP function according to the target physical CCP and other resource configuration information. Among them, other resource configuration information includes but is not limited to: hardware configuration information such as processor, memory, disk, network interface, driver, and startup parameters.
[0107] Among them, the VMM may include: a QEMU module and a KVM module. Accordingly, a virtual machine instance can be created through the QEMU module, and the information in the virtual machine configuration file to be created can be loaded; the QEMU module can use the interface provided by the KVM module to initialize the resources of the virtual machine, such as the processor, memory, storage and target physical CCP, according to the target physical CCP and other resource configuration information, to obtain a virtual machine with CCP functions.
[0108] In an embodiment of the present application, multiple vCCP groups are obtained by grouping and managing the vCCPs corresponding to the physical CCPs. When a virtual machine creation request arrives, a target vCCP group is determined for the virtual machine to be created from the currently idle vCCP group. Afterwards, the configuration information of the virtual machine to be created can be generated according to the target vCCP group, thereby realizing the management of vCCP resources. Since the target vCCP group is selected from the currently idle vCCP group, the target vCCP group must be an idle vCCP group, and there is no need to traverse and query whether all vCCPs are occupied before allocating them, which can improve the efficiency of vCCP resource allocation and thus help improve the efficiency of virtual machine creation.
[0109] Since each time a request is made to create a virtual machine with CCP function, the currently occupied vCCP resources will be updated with the startup and destruction of the previous virtual machine, but the available resource window (i.e. the target index set A of the currently idle vCCP mentioned above) is always a subset of the full resource window W (i.e. the index set W of all vCCP groups available on the service device), the available resource window (i.e. the target index set A of the currently idle vCCP mentioned above) is like sliding in a bar with a length of W, so this available resource window (i.e. the target index set A of the currently idle vCCP mentioned above) is a sliding window in a broad sense. The aforementioned random selection of available target vCCP groups in the available resource window by random numbers can ensure that there is no conflict with the used vCCP resources. Therefore, this vCCP resource management and allocation mechanism can be called a sliding window random selection mechanism (Slide Window Random Selection, SWRS).
[0110] Combine the following Figure 7 The internal software architecture of the service device shown in the figure specifically illustrates the method of implementing virtual machine creation using the SWRS mechanism. Figure 7 The control component, prepareVM component, virtualization management component, QEMU, KVM and vCCP resource management component are all deployed on the service device, and the service device can schedule the corresponding component to execute the method logic of the component. Figure 7 As shown, the virtual machine creation method mainly includes the following steps:
[0111] 1. Users can initiate a virtual machine creation request through the platform-based white screen portal or the background command interface. The virtual machine creation request reaches the management and control component running on the service device.
[0112] 2. The control component obtains the necessary parameters contained in the virtual machine configuration file (such as an XML file) based on the virtual machine creation request, and passes these necessary parameters to the prepareVM component in the resource management configuration and virtual machine creation management tool.
[0113] For a description of steps 1 and 2, see the previous Figure 2 The relevant content will not be repeated here.
[0114] The prepareVM component generates the initial configuration file of the virtual machine to be created based on these parameters.
[0115] 3. The prepareVM component calls the vCCP resource management component. The vCCP resource management component uses the SWRS mechanism to determine the target vCCP group for the virtual machine to be created and generates a CCP resource configuration file for the virtual machine to be created.
[0116] 4. The vCCP resource management component passes the CCP resource configuration file to the prepareVM component. The prepareVM component adds the CCP resource configuration file of the virtual machine to be created to the initial configuration file of the virtual machine to be created, so as to obtain the configuration file of the virtual machine to be created.
[0117] 5. The prepareVM component sends the configuration file of the virtual machine to be created to the management and control component.
[0118] 6. The control component passes the virtual machine configuration file to the virtual machine configuration file assembly component (such as StartVMx) in the control component.
[0119] The virtual machine configuration file assembly component combines the virtual machine configuration file and other configuration information into a complete virtual machine configuration file.
[0120] 7. The virtual machine configuration file assembly component sends the complete virtual machine configuration file to the virtualization management component (such as libvirt).
[0121] 8. Libvirt can convert the virtual machine configuration file into command line parameters suitable for QEMU, perform the necessary operating system-level configuration work, and start the QEMU process using command line parameters suitable for QEMU.
[0122] 9. QEMU cooperates with the KVM kernel module to start the virtual machine according to the converted command line parameters to obtain a virtual machine with CCP function.
[0123] 10. After receiving the virtual machine exit message, the KVM module analyzes the reason for the virtual machine exit and performs corresponding processing. Then, it passes the data to QEMU and executes the virtual machine entry (VMentry) operation again, so that the control is transferred to the user state QEMU.
[0124] The interaction between steps 9 and 10 continues, indicating that the virtual machine is running. When this interaction starts running, it means that the virtual machine has been created and is in a running state.
[0125] The inventor of the present application has theoretically analyzed and verified the process of allocating vCCP resources to virtual machines by taking the above-mentioned method of using the current timestamp as a random seed and the length of the target index set A of the currently idle vCCP group as a parameter to generate a random number; and using the random number to select the target index from the target index set A as an example. Although the random number cannot guarantee that there will be no vCCP resource conflict 100%, the probability of conflict is within a tolerable range. The theoretical analysis process of the above-mentioned SWRS scheme is explained below.
[0126] Assume that the concurrent number c of virtual machines created in the time period [t, t+t0], that is, the number c of concurrent virtual machine creation requests, follows a Poisson distribution, that is, c satisfies the following distribution:
[0127] (1).
[0128] The variable I corresponding to the random number used by each concurrent thread (i.e., each thread that executes the concurrent virtual machine creation process) to take the target index obeys a discrete uniform distribution and is independent, then:
[0129] (2).
[0130] Wherein, L represents the length of the available resource window A within the time period, that is, the length of the target index set A of the aforementioned currently idle vCCP group.
[0131] Then, the probability that multiple concurrent virtual machine creation workflows do not conflict with each other within the time period satisfies the following relationship with the concurrent number c:
[0132] (3).
[0133] From equations (1), (2) and (3), we can get the probability of vCCP resource conflict occurring in this time period:
[0134] (4).
[0135] Define the maximum possible concurrency on the service device as C, C ≤ M, M is the number of vCCPs virtualized from the aforementioned physical CCP, then L and c in formula (4) satisfy the following constraints:
[0136] (5).
[0137] In some actual application scenarios, for a service device with 128 processor cores and 16 physical CCPs, one physical CCP can be virtualized into 128 vCCPs. If the number of vCCPs supported by each virtual machine is 16, the number of vCCP groups available to the service device is 128. Assuming that the number of cores that can be sold by the service device is 118 cores, according to the overselling ratio of 1:4, 472 processor cores can be sold. Since containers need to run in virtual machines, only the cases of virtual machines with 32 cores, 64 cores, 128 cores and 256 cores are considered. At this time, the number of fully loaded virtual machines on the physical machine (that is, the maximum number of virtual machines that can be deployed on the physical machine) is shown in Table 1 below:
[0138] Table 1 Number of fully loaded virtual machines on a physical machine
[0139]
[0140] Considering the above specifications, M=128, according to the above constraint condition (5) and the vCCP resource conflict probability (4), the two-dimensional scatter plot of L,c and vCCP resource conflict probability can be obtained as follows: Figure 8 , Fig. 9 and Fig.10 As shown. Figure 8 A two-dimensional scatter plot of the probability of L,c and vCCP resource conflicts when creating a 32-core virtual machine concurrently. Figure 8 It can be obtained that when the number of concurrent requests is 0 and 1 in the time period [t, t+t0], the conflict probability is zero, which is consistent with the actual situation. In the L dimension (i.e., the length dimension of the target index set A of the idle vCCP group), the probability of vCCP resource conflict P decreases with the increase of the available resource window length L (i.e., the length L of the target index set A of the idle vCCP group). When the number of concurrent requests is greater than 1, that is, in the c dimension (i.e., the dimension of the number of concurrent requests, which can also be called the dimension of the number of concurrent virtual machine creation requests), the probability of vCCP resource conflict decreases with the increase of the number of concurrent requests c. The main reason is that although a vCCP group can only be used by one virtual machine, the more virtual machines are created concurrently, the more difficult it is to select different vCCP groups. However, according to the definition of Poisson distribution, formula (1) represents the probability of c concurrent events occurring in a very short time period t0. Obviously, in a short time, the larger the number of concurrent events c, the smaller the probability. Therefore, considering the above factors, the probability of vCCP resource conflict decreases with the increase of the number of concurrent requests c. From a theoretical analysis, the scenario most likely to cause conflicts occurs when the available resource window length (that is, the length L of the target index set A of the idle vCCP group) is minimum and the number of concurrent connections is 2. At this time, the probability of vCCP resource conflict is 0.159%. Therefore, when creating 32-core virtual machines concurrently, a service device can deploy up to 14 32-core virtual machines, and the maximum failure probability of concurrently creating 32-core virtual machines is 0.159%.
[0141] Fig. 9 A 2D scatter plot of L,c and the probability of vCCP resource conflicts when concurrently creating 64-core virtual machines. A service device can deploy up to 7 64-core virtual machines. Fig. 9 It can be obtained that when a virtual machine with 64 cores is created concurrently, the maximum failure probability of concurrently creating a virtual machine with 64 cores is 0.150%.
[0142] Fig.10 A 2D scatter plot of L,c and the probability of vCCP resource conflicts when concurrently creating 128-core virtual machines. A service device can deploy up to three 64-core virtual machines. Fig.10 It can be seen that when a virtual machine with 128 cores is created concurrently, the maximum failure probability of concurrently creating a virtual machine with 64 cores is 0.145%.
[0143] Because a service device can deploy at most one 256-core virtual machine, there is no concurrent creation of virtual machines in the scenario of creating a 256-core virtual machine. Therefore, in this case, the probability of vCCP resource conflict is 0.
[0144] Through the above theoretical analysis, it can be concluded that the SWRS solution provided in the embodiment of the present application allocates vCCP resources to virtual machines. The probability of vCCP resource conflicts in the scenario of concurrent virtual machine creation is very low, and the probability of virtual machine creation failure is acceptable in actual application scenarios.
[0145] It should be noted that the execution subject of each step of the method provided in the above embodiment can be the same device, or the method can be executed by different devices. For example, the execution subject of steps 601 and 602 can be device A; for another example, the execution subject of step 601 can be device A, and the execution subject of step 602 can be device B; and so on.
[0146] In addition, in some of the processes described in the above embodiments and the accompanying drawings, multiple operations appearing in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel, and the sequence numbers of the operations, such as 601, 602, etc., are only used to distinguish between different operations, and the sequence numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel.
[0147] Accordingly, an embodiment of the present application also provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed by one or more processors, the one or more processors are caused to execute the steps in the above-mentioned virtual machine creation method.
[0148] The embodiment of the present application also provides a computer program product, including a computer program, which, when executed by one or more processors, causes the one or more processors to execute the steps in the above-mentioned virtual machine creation method. In the embodiment of the present application, the specific implementation form of the computer program product is not limited. In some embodiments, the computer program product can be implemented as an application (Application, APP), a mini-program, a computer-side client, a program module, a plug-in, an installation package, a software development kit (Software Development Kit, SDK), an image file of a CD (such as an ISO file), a plug-in or software in the form of software as a service (Software as a Service, SaaS), etc., but is not limited to this.
[0149] Fig.11 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Fig.11 As shown, the electronic device includes: a memory 11a and a processor 11b. The memory 11a is used to store computer programs. The processor integrates multiple physical CCPs 11b1, each of which is virtualized into multiple virtual CCPs; the multiple physical CCPs 11b1 and the corresponding virtual CCPs are divided into multiple virtual CCP groups, and the virtual CCPs included in each virtual CCP group correspond to different physical CCPs.
[0150] The processor 11b is coupled to the memory 11a and is used to execute a computer program to execute the steps in the virtual machine creation method provided in the above embodiments. The specific implementation of each step can be found in the related description of the above embodiments, which will not be repeated here.
[0151] In some optional embodiments, such as Fig.11 As shown, the electronic device may also include optional components such as a communication component 11c, a power component 11d, a display component 11e and an audio component 11f. Fig.11 The components are shown schematically only, and do not mean that the electronic device must include Fig.11 The components shown do not necessarily mean that the electronic device can only include Fig.11 Components shown.
[0152] in addition, Fig.11 The components in the dashed box are optional components, not mandatory components, and may depend on the product form of the electronic device. The electronic device of this embodiment may be implemented as a terminal device such as a desktop computer, a laptop computer, a mobile phone, or an IoT device; or it may be various server devices such as a traditional server, a cloud server, or a server cluster.
[0153] In an embodiment of the present application, the memory is used to store a computer program and can be configured to store various other data to support operations on the device where it is located. Among them, the processor can execute the computer program stored in the memory to implement the corresponding control logic. The memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random-Access Memory, SRAM), electrically erasable programmable read only memory (Electrically Erasable Programmable Read Only Memory, EEPROM), erasable programmable read only memory (Electrical Programmable Read Only Memory, EPROM), programmable read only memory (Programmable Read Only Memory, PROM), read only memory (Read Only Memory, ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0154] In the embodiment of the present application, the processor may be any hardware processing device that can execute the logic of the above method. Optionally, the processor may be a central processing unit (CPU), a graphics processing unit (GPU) or a microcontroller unit (MCU); it may also be a field programmable gate array (FPGA), a programmable array logic device (PAL), a general array logic device (GAL), a complex programmable logic device (CPLD) or other programmable devices; or it may be an advanced reduced instruction set (RISC) processor (Advanced RISC Machines, ARM) or a system on chip (System on Chip, SoC), etc., but not limited thereto.
[0155] In an embodiment of the present application, the communication component is configured to facilitate wired or wireless communication between the device in which it is located and other devices. The device in which the communication component is located can access a wireless network based on a communication standard, such as Wireless Fidelity (WiFi), 2G or 3G, 4G, 5G or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component can also be implemented based on Near Field Communication (NFC) technology, Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wide Band (UWB) technology, Bluetooth (BT) technology or other technologies.
[0156] In an embodiment of the present application, the display component may include a liquid crystal display (LCD) and a touch panel (TP). If the display component includes a touch panel, the display component may be implemented as a touch screen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense the boundaries of a touch or slide action, but also detect the duration and pressure associated with the touch or slide operation.
[0157] In an embodiment of the present application, a power supply component is configured to provide power to various components of the device in which it is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device in which the power supply component is located.
[0158] In an embodiment of the present application, the audio component may be configured to output and / or input audio signals. For example, the audio component includes a microphone (Microphone, MIC), and when the device where the audio component is located is in an operating mode, such as a call mode, a recording mode, and a speech recognition mode, the microphone is configured to receive an external audio signal. The received audio signal may be further stored in a memory or sent via a communication component. In some embodiments, the audio component also includes a speaker for outputting an audio signal. For example, for a device with a language interaction function, voice interaction with a user may be achieved through an audio component.
[0159] It should be noted that the descriptions such as “first” and “second” in this article are used to distinguish different messages, devices, modules, etc., and do not represent the order of precedence, nor do they limit “first” and “second” to different types.
[0160] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, compact disc read-only memory (CD-ROM), optical storage, etc.) containing computer-usable program codes.
[0161] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0162] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0163] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0164] In a typical configuration, a computing device includes one or more processors (CPU, etc.), input / output interfaces, network interfaces, and memory.
[0165] Memory may include non-permanent storage in a computer-readable medium, in the form of random-access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0166] Computer storage media is readable storage media, also known as readable media. Readable storage media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. Information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disc (DVD) or other optical storage, magnetic cassettes, disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0167] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of further restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the above elements.
[0168] The above contents are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A cloud service system, characterized in that: include: At least one service device; a processor of the service device is integrated with a plurality of physical cryptographic coprocessors CCP; each physical CCP is virtualized into a plurality of virtual CCPs; The virtual CCPs corresponding to the multiple physical CCPs are divided into multiple virtual CCP groups, and each virtual CCP group includes virtual CCPs corresponding to different physical CCPs; The service device is further used to determine, in response to a virtual machine creation request, a target index set of a currently idle virtual CCP group; determine a target index for the virtual machine to be created from the target index set; generate configuration information of the virtual machine to be created according to the target virtual CCP group corresponding to the target index; and create a virtual machine with a CCP function according to the configuration information of the virtual machine to be created.
2. A method for creating a virtual machine, applicable to a service device, characterized in that: The processor of the service device is integrated with a plurality of physical cryptographic coprocessors CCP; each physical CCP is virtualized into a plurality of virtual CCPs; the virtual CCPs corresponding to the plurality of physical CCPs are divided into a plurality of virtual CCP groups, and the virtual CCPs included in each virtual CCP group correspond to different physical CCPs; The method comprises: In response to the virtual machine creation request, determining a target index set of currently idle virtual CCP groups; Determining a target index for the virtual machine to be created from the target index set; Generate configuration information of the virtual machine to be created according to the target virtual CCP group corresponding to the target index; A virtual machine with a CCP function is created according to the configuration information of the virtual machine to be created.
3. The method according to claim 2, characterized in that The step of determining, in response to the virtual machine creation request, a target index set of a currently idle virtual CCP group includes: In response to a virtual machine creation request, obtaining a first index set of the plurality of virtual CCP groups and a second index set of a currently occupied virtual CCP group; The target index set is determined according to the first index set and the second index set.
4. The method according to claim 3, characterized in that Obtain the second index set of the currently occupied virtual CCP group, including: The second index set is obtained by using a virtualization management command; or the second index set is obtained from an index list of used virtual CCP groups maintained by the service device.
5. The method according to claim 4, characterized in that The obtaining the second index set by using a virtualization management command includes: Determine the virtual machine currently running on the service device through a list command in a virtualization management command; Obtaining configuration information of the currently running virtual machine through a configuration file export command in a virtualization management command; An index set of a virtual CCP group used by the currently running virtual machine is obtained from the configuration information of the currently running virtual machine as the second index set.
6. The method according to claim 3, characterized in that Determining a target index for the virtual machine to be created from the target index set includes: Generate a random number that is greater than or equal to 0 and less than or equal to the length of the target index set; Determine the index corresponding to the random number in the target index set as the target index.
7. The method according to claim 6, characterized in that The generating a random number greater than or equal to 0 and less than or equal to the length of the target index set includes: The random number is generated by taking the current timestamp as a random seed and the length of the target index set as a parameter.
8. The method according to claim 2, characterized in that: Determining a target index for the virtual machine to be created from the target index set includes: Sorting the indexes in the target index set, and selecting a maximum index or a minimum index from the sorted target index set as the target index; or, From the target index set, an index at a set position is selected as the target index.
9. The method according to claim 4, characterized in that Also includes: After the virtual machine to be created is created, the index of the target virtual CCP group is added to the index list of used virtual CCP groups maintained by the service device.
10. The method according to claim 7, characterized in that The virtual machine creation request is a concurrent multiple virtual machine creation request; the method further includes: For any virtual machine creation request among the multiple virtual machine creation requests, before responding to the any virtual machine creation request, locking an index list of used virtual CCP groups maintained by the service device; After the creation of the virtual machine requested by any virtual machine creation request is completed, the target index is deleted from the index list, and the lock of the index list is released.
11. The method according to any one of claims 2 to 10, characterized in that: The method further comprises: According to the number of virtual CCPs supported by the virtual machine, the virtual CCPs corresponding to the multiple physical CCPs are divided into the multiple virtual CCP groups.
12. The method according to any one of claims 2 to 10, characterized in that: The generating, according to the target virtual CCP group, configuration information of the virtual machine to be created includes: Convert the resource path of the target virtual CCP group into a format of a virtual machine configuration file to obtain a virtual CCP resource configuration file of the virtual machine to be created; The virtual CCP resource configuration file of the virtual machine to be created is added to the initial configuration file of the virtual machine to be created to obtain configuration information of the virtual machine to be created.
13. The method according to claim 12, characterized in that The configuration information of the virtual machine to be created includes: the resource path of the target virtual CCP group and other resource configuration information; the other resource configuration information refers to the configuration information of other resources required by the virtual machine except the virtual CCP; the step of creating a virtual machine with the CCP function according to the configuration information of the virtual machine to be created includes: Determine, by using the virtual machine manager according to the resource path of the target virtual CCP group, a target physical CCP corresponding to the target virtual CCP group; The virtual machine with CCP function is created by using the virtual machine manager according to the target physical CCP and other resource configuration information.
14. An electronic device, characterized in that: include: A memory and a processor; wherein the memory is used to store computer programs; a plurality of physical CCPs are integrated in the processor, each physical CCP is virtualized into a plurality of virtual CCPs; the virtual CCPs corresponding to the plurality of physical CCPs are divided into a plurality of virtual CCP groups, and the virtual CCPs included in each virtual CCP group correspond to different physical CCPs; The processor is coupled to the memory and is configured to execute the computer program to perform the steps of the method according to any one of claims 2 to 13.
15. A computer-readable storage medium storing computer instructions, characterized in that: When the computer instructions are executed by one or more processors, the one or more processors are caused to execute the steps in the method according to any one of claims 2 to 13.
16. A computer program product, characterized in that The method comprises a computer program which, when executed by one or more processors, causes the one or more processors to execute the steps of the method according to any one of claims 2 to 13.
Citation Information
Patent Citations
Physical GPU virtualization management method, system, device and product
CN112463294A
Virtual resource allocation method and device, equipment, storage medium and program product
CN118502936A