Method, device and equipment for expanding capacity based on key authorization and storage medium

By introducing a key authorization mechanism during the service expansion process, the legality of expansion tasks is generated and verified, which solves the problems of insufficient security and compliance in existing technologies, realizes secure and controllable expansion operations, and ensures system stability and transparency.

CN119276616BActive Publication Date: 2026-01-16AISINO CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411659207.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2026-01-16
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

Existing service expansion technologies are inadequate in terms of security and compliance, lacking effective access control, which leads to unauthorized operations and resource abuse.

Method used

A key authorization mechanism is introduced, which generates and distributes a unique key for each expansion task, verifies the legitimacy of the expansion task, and then executes the expansion operation to ensure that only authorized tasks can perform expansion.

Benefits of technology

It improves the transparency and controllability of expansion operations, prevents unauthorized access, protects the security of sensitive data, avoids resource abuse, and ensures the efficient and stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276616B_ABST
    Figure CN119276616B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a capacity expansion method and device based on key authorization, equipment and a storage medium. The method comprises: generating and distributing a key for a capacity expansion task, the key being used to prove the legality of the capacity expansion task; obtaining a service group to be expanded corresponding to the capacity expansion task; and after the key passes the legality verification, executing the capacity expansion task and expanding the services in the service group to be expanded. This way of introducing an authorization verification mechanism ensures the security and legality of the capacity expansion operation and prevents unauthorized capacity expansion operations.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of service expansion, and in particular to a key authorization-based expansion method, device, equipment and storage medium. BACKGROUND

[0002] With the popularity of cloud computing, service expansion technology has emerged to cope with the growing user demand and data traffic.

[0003] Service expansion technology is mainly used to dynamically adjust computing resources according to actual needs. Service expansion technology usually relies on pre-set performance indicators to automatically adjust computing resources. For example, automatic service expansion can be achieved according to the number of service nodes and the version information of the application.

[0004] Service expansion technology can improve the responsiveness and availability of the system by automatically adjusting resources, but there are obvious deficiencies in security and compliance during the service expansion process. SUMMARY

[0005] Therefore, the embodiments of the present application provide a key authorization-based expansion method, device, equipment and storage medium to at least solve or alleviate the above problems.

[0006] According to an aspect of the embodiments of the present application, a key authorization-based expansion method is provided, which comprises:

[0007] generating and distributing a key for an expansion task, the key being used to prove the legality of the expansion task;

[0008] obtaining a service group to be expanded corresponding to the expansion task;

[0009] after the key passes the legality verification, executing the expansion task and expanding the services in the service group to be expanded.

[0010] According to another aspect of the embodiments of the present application, a key authorization-based expansion device is provided, which comprises a key management module, an expansion management module and a service node management module.

[0011] The key management module is configured to generate and distribute a key for an expansion task, the key being used to prove the legality of the expansion task;

[0012] The expansion management module is configured to obtain a service group to be expanded corresponding to the expansion task, and control the service node management module to execute the expansion task and expand the services in the service group to be expanded after the key passes the legality verification.

[0013] According to another aspect of the embodiments of the present application, a server is provided, which comprises a processor, a memory, a communication interface and a communication bus, the processor, the memory and the communication interface communicate with each other through the communication bus; the memory is used to store at least one executable instruction, which causes the processor to perform the operation corresponding to the key-based authorization expansion method provided in the above-mentioned aspect.

[0014] According to another aspect of the embodiments of the present application, a computer storage medium is provided, which stores a computer program, and the computer program is executed by a processor to implement the key-based authorization expansion method provided in the above-mentioned aspect.

[0015] According to another aspect of the embodiments of the present application, a computer program product is provided, which comprises computer instructions, and the computer instructions instruct a computer device to execute the key-based authorization expansion method provided in the above-mentioned aspect.

[0016] According to the key-based authorization expansion method provided in the embodiments of the present application, before the expansion task is executed, the key is generated and distributed for the expansion task, after the service group to be expanded is obtained and the expansion target that executes the expansion task is confirmed, the legality of executing the expansion task of expanding the service in the service group to be expanded is verified through the key, and after the legality verification of the key, the expansion task is executed to complete the expansion of the service in the service group to be expanded, which prevents the unauthorized expansion operation, avoids the unauthorized access, and protects the security of the sensitive data. The expansion mode with the authorization verification mechanism introduced can also improve the transparency and controllability of the expansion operation, avoid the abuse or configuration error of the resource, and ensure the efficient and stable operation of the service system in the expansion process. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art based on these drawings.

[0018] Figure 1 is a schematic diagram of an exemplary system to which an embodiment of the present application is applied;

[0019] Figure 2 is a flowchart of the key-based authorization expansion method of an embodiment of the present application;

[0020] Figure 3 is a flowchart of the key-based authorization expansion method of an embodiment of the present application;

[0021] Figure 4 is a schematic diagram of the interaction between various modules of an embodiment of the present application;

[0022] Figure 5 is a schematic diagram of a key authorization-based expansion device of an embodiment of the present application;

[0023] Figure 6 is a schematic diagram of an electronic device of an embodiment of the present application. DETAILED DESCRIPTION

[0024] The present application is described in the following based on embodiments, but the present application is not limited to these embodiments only. In the following detailed description of the present application, some specific details are described in detail. The present application can also be completely understood without the description of these details by those skilled in the art. In order to avoid confusion of the essence of the present application, the well-known methods, processes, procedures are not described in detail. In addition, the drawings are not necessarily drawn to scale.

[0025] First, some nouns or terms appearing in the description of the embodiments of the present application are applicable to the following explanations.

[0026] Service expansion refers to the way of increasing resources or cloud services to improve the processing capacity and performance of the system when the existing system resources cannot meet the current use demand. The service expansion scenario targeted by the embodiments provided by the present application includes but is not limited to: maintenance scenario, after the user uses for a period of time, the system finds that the resources are about to be exhausted or the performance cannot meet the demand, and automatically solves it through expansion; Add optional cloud service scenario: when the user needs to use more cloud service functions, the deployment of optional cloud services can be quickly completed through the expansion way.

[0027] Exemplary system

[0028] Figure 1 An exemplary computer system is shown. The computer system includes a terminal device 101, a wired or wireless network 102 and a server 103.

[0029] The terminal device 101 installs and runs an application program. The terminal device 101 can be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers and desktop computers, etc.

[0030] The terminal device 101 is connected to the server 103 through the wired or wireless network 102. The user can use the terminal device 101 to interact with the server 103 through the wired or wireless network 102 to receive or send messages, etc.

[0031] The server 103 comprises at least one of a server, multiple servers, a cloud computing platform, and a virtualization center. The server 103 is configured to support running of an application program or a subprogram in the application program on the terminal device 101, that is, the server 103 provides background service for the application program or the subprogram. Alternatively, the server 103 undertakes main computing work, and the terminal device 101 undertakes secondary computing work; or the server 103 undertakes secondary computing work, and the terminal device 101 undertakes main computing work; or the server 103 and the terminal device 101 perform collaborative computing in a distributed computing architecture.

[0032] The server 103 is provided with a computing system, which comprises a key management module 11, an expansion management module 12, a service node management module 13, and a state feedback and audit module 14, and supports execution of the expansion method based on key authorization provided in the embodiments of the present application. For example, the key management module 11 generates and distributes a key for an expansion task, the expansion management module 12 acquires a to-be-expanded service group corresponding to the expansion task, and then cooperates with the key management module 11 to verify the legality of performing the expansion task on the to-be-expanded service group, and controls the service node management module 13 to perform the expansion task on the to-be-expanded service group after the key passes the legality verification. During execution of the expansion method, the state feedback and audit module 14 tracks and records process information, including generation and distribution of the key, verification of the key, creation of a container, and the like, to provide real-time feedback and audit functions.

[0033] It should be noted that, Figure 1 The terminal device, wired or wireless network, and server shown in the figure are merely illustrative. Any number of terminal devices and servers can be provided according to implementation needs.

[0034] Method for expanding capacity based on key authorization

[0035] Based on the above system, the embodiments of the present application provide an expansion method based on key authorization, which can be executed by the server in the above system embodiments. The method is described in detail through multiple embodiments as follows.

[0036] Figure 2 is a flowchart of the expansion method based on key authorization according to an embodiment of the present application. As shown in the figure, the method comprises the following steps: Figure 2

[0037] Step 201: A key is generated and distributed for an expansion task, and the key is used to prove the legality of the expansion task.

[0038] ​The server monitors service load in real time, and generates a capacity expansion task according to the service load. For example, a capacity expansion management module is arranged in the server to manage various operations related to capacity expansion in the server. The capacity expansion management module monitors service load in real time; when the server cannot support the operation of the current service load, the execution of the capacity expansion task is triggered; or when the server cannot support the operation of the newly added load, the execution of the capacity expansion task is triggered.

[0039] A key management module is also arranged in the server to manage the authorization of various operations in the server, including the authorization of the capacity expansion task. In the process of capacity expansion, the server generates and distributes a key for the capacity expansion task through the key management module, and each capacity expansion task has a unique key. The key possessed by the capacity expansion task can be requested by the capacity expansion management module from the key management module.

[0040] The key is generated before the start of the capacity expansion task, and is used to verify the legality of the capacity expansion task. For example, the key possessed by the capacity expansion task can be generated and distributed to the capacity expansion management module by the key management module before the generation of the capacity expansion task, and the capacity expansion management module subsequently generates the capacity expansion task with the key. Alternatively, the key can be generated and distributed by the key management module for the capacity expansion task after the generation of the capacity expansion task and before the start of the capacity expansion task.

[0041] An authorization interface is arranged between the capacity expansion management module and the key management module, and the key management module sends the key to the capacity expansion management module through the authorization interface after generating the key.

[0042] Step 202, obtaining a to-be-expanded service group corresponding to the capacity expansion task.

[0043] The to-be-expanded service group in the server includes one or more (i.e. at least one). Each to-be-expanded service group contains one or more services, and each service corresponds to one or more service nodes. Wherein, "multiple" means two or more. The server obtains the to-be-expanded service group to be executed in this capacity expansion task through the capacity expansion management module, and clearly defines the target and scope of the capacity expansion task, laying a foundation for subsequent service capacity expansion operations.

[0044] The to-be-expanded service group can be part or all of the service groups deployed in the server.

[0045] Step 203, after the key passes the legality verification, executing the capacity expansion task to expand the services in the to-be-expanded service group.

[0046] The server performs legality verification of the capacity expansion task through the interaction between the capacity expansion management module and the key management module, and executes the capacity expansion task to expand the services in the to-be-expanded service group after the key passes the legality verification.

[0047] The server further comprises a service node management module, configured to manage the operation of each service node, including managing the expansion operation of each service node. Optionally, the server sends a verification request to the key management module through the expansion management module, the verification request carrying a key; the key management module receives the verification request and verifies the legality of the expansion task according to the key carried by the verification request; after the key passes the legality verification, the key management module sends an authorization credential to the expansion management module; after the expansion management module receives the authorization credential, the expansion strategy of the service group to be expanded is determined, and the service node management module is controlled to perform the expansion task according to the expansion strategy.

[0048] After receiving the authorization credential fed back by the key management module, the expansion management module can control the service node management module to perform the expansion task by generating and sending an instruction. For example, the server generates an expansion instruction according to the authorization credential and the expansion strategy through the expansion management module, and sends the expansion instruction to the service node management module; after the service node management module receives the expansion instruction, the expansion task is performed according to the expansion strategy.

[0049] The authorization credential is used to authorize the expansion management module to generate the expansion instruction, and the expansion management module generates the expansion instruction only after receiving the authorization credential; or the authorization instruction is used to authorize the service node management module to perform the expansion task, and the service node management module performs the expansion task according to the indication of the expansion instruction only after detecting the authorization credential in the received expansion instruction; or the authorization credential is used to authorize both the expansion management module to generate the expansion instruction and the service node management module to perform the expansion task, the expansion management module generates the expansion instruction carrying the authorization credential after receiving the authorization credential, and the service node management module performs the expansion task according to the indication of the expansion instruction after detecting the authorization credential in the received expansion instruction.

[0050] For the generation of the expansion strategy, the server polls the service group to be expanded through the expansion management module to obtain the number of service nodes of each service in the service group to be expanded; and determines the expansion strategy according to the number of service nodes of each service. The service node can be understood as a service instance (Service). Whenever a service is polled, the number of service nodes currently included in the service is automatically obtained, and finally the number of service nodes corresponding to each service in the service group to be expanded is obtained; and the expansion strategy is generated according to the number of service nodes corresponding to each service in the service group to be expanded.

[0051] In summary, the method for capacity expansion based on key authorization provided in the embodiment generates and distributes a key for a capacity expansion task before the execution of the capacity expansion task, verifies the legality of the execution of the capacity expansion task on the services in the service group to be expanded through the key after the service group to be expanded is obtained and the capacity expansion target executing the capacity expansion task is confirmed, executes the capacity expansion task after the key passes the legality verification, completes the capacity expansion on the services in the service group to be expanded, ensures that only the authorized capacity expansion task can execute the capacity expansion operation, prevents unauthorized capacity expansion operations, avoids unauthorized access, and protects the security of sensitive data. The capacity expansion method with the authorization verification mechanism can manage and control the use of the key by the administrator, improve the transparency and controllability of the capacity expansion operation, avoid misuse or configuration errors of resources, and ensure the efficient and stable operation of the service system during the capacity expansion process.

[0052] In some embodiments, in Figure 2 Based on the embodiment shown, the capacity expansion strategy can implement dynamic allocation of containers. As described below, the capacity expansion task is executed according to the capacity expansion strategy, including:

[0053] First, according to the indication of the capacity expansion strategy, service containers are created for the multiple service nodes of each service in the service group to be expanded.

[0054] The server can execute the capacity expansion task through the service node management module according to the indication of the capacity expansion strategy. First, the service node management module generates a capacity expansion task table according to the indication of the capacity expansion strategy, and the capacity expansion task table records the service containers to be created and the creation status of each service container. The service containers to be created include the service containers corresponding to the multiple service nodes of each service. According to the capacity expansion task table, service containers are created for the multiple service nodes of each service.

[0055] The service containers not created in the capacity expansion task table are marked as a creation status of "to be created", and the service containers already created are marked as a creation status of "creation completed". The server scans the capacity expansion task table every set time length, such as 3 seconds, or 4 seconds, or 5 seconds, until the creation status of each service container in the capacity expansion task table is "creation completed".

[0056] The capacity expansion strategy includes creating service containers consistent with the number of service nodes. For example, the service node management module uses a container management tool (such as Kubernetes, an open source tool for managing containerized applications on multiple hosts in a cloud platform) to create service containers consistent with the number of service nodes.

[0057] Secondly, the following publishing process is performed for each service in the service group to be scaled: version information of each service node in the plurality of service nodes of the service is obtained, the number of service nodes corresponding to each version information is counted, and the version information corresponding to the maximum number of service nodes is determined as target version information; the service container corresponding to the service is published according to the target version information, the application program corresponding to the target version information is loaded into the service container corresponding to the service, and the service container corresponding to the service is started.

[0058] After the creation of the service container is completed, a publishing operation on the service container is performed. For each service in the service group to be scaled, if there is one or more service nodes under the service, there is a master service node in the one or more service nodes, and a monitoring table is set in the master service node, the monitoring table is used for real-time monitoring and management of the service container corresponding to the service node under the service; the service node management module can obtain version information of each service node under the service through the monitoring table, and the application version used by the service node under the service can exist in one or more, if there are multiple, the number of service nodes corresponding to each version information under the service is counted, and the version information corresponding to the maximum number of service nodes is determined as target version information; then, the publishing operation is performed on the service container corresponding to the plurality of service nodes under the service according to the target version information.

[0059] The version information of the service node refers to the software version number of the service node, which is used to identify different versions of software. The version number of server software is usually composed of multiple parts, including major version number, minor version number, revision number and build number, etc.

[0060] The plurality of service nodes corresponding to each service include a master service node, and the following registration process is performed for each service before the publishing process is performed: the service container corresponding to the plurality of service nodes of the service is registered in the monitoring table of the master service node, so as to perform real-time monitoring and management on the service container corresponding to the plurality of service nodes of the service. That is, after the container is created, the target version information is determined first, then the service node management module registers the newly created service container to the master service node, and then the publishing operation is performed.

[0061] The method can perform the scaling operation of the service according to the actual load condition in the server, and realize dynamic container allocation.

[0062] In some other embodiments, on the basis of the above-mentioned embodiments, a state feedback and auditing module is further arranged in the server to record the process information of the expansion task execution. The server records the process information of the expansion task execution of the expansion management module and the service node management module through the state feedback and auditing module. The process information of the expansion task execution includes the process information of the generation, distribution and verification of the key, and the state information of the container creation and release. The state feedback and auditing module stores the above-mentioned process information in the log for the administrator to conduct auditing and problem troubleshooting. In addition, the information recorded in the log can also help to optimize the expansion strategy and provide effective support for the security management of the system.

[0063] For example, as Figure 3 The implementation process of the expansion method based on the key authorization is schematically illustrated. The implementation process of the method by the server is as follows:

[0064] Step 301: generating and distributing the key for the expansion task.

[0065] Step 302: obtaining the to-be-expanded service group corresponding to the expansion task.

[0066] Step 303: verifying the key to confirm the legality of the expansion task.

[0067] Step 304: polling the to-be-expanded service group to obtain the service node quantity corresponding to each service in the to-be-expanded service group after the key verification is passed.

[0068] Step 305: creating the service container according to the service node quantity corresponding to each service.

[0069] Step 306: determining the target version information corresponding to each service according to the version information corresponding to the service node of each service.

[0070] Step 307: registering the newly created service container to the main service node for each service.

[0071] Step 308: performing the release operation on the service container registered under each service according to the target version information corresponding to each service.

[0072] Step 309: performing the state feedback and auditing according to the log information of the expansion task.

[0073] For example, as Figure 4 The interaction of each module in the execution process of the above-mentioned process is schematically illustrated. The server includes a key management module 11, an expansion management module 12, a service node management module 13 and a state feedback and auditing module 14.

[0074] The key management module 11 generates and distributes the key to the capacity expansion management module 12, and the capacity expansion management module 12 verifies the legitimacy of the capacity expansion task by the key to the key management module 11 before starting the capacity expansion task; after the key verification, the capacity expansion management module 12 requests the service node management module 13 to manage the service node, and the service node management module 13 cooperates with the capacity expansion management module 12 to create and register the container.

[0075] The capacity expansion management module 12 feeds back the log information generated in the process of interacting with the key management module 11 and the service node management module 13, such as the state update information of container creation and registration, to the state feedback and audit module 14 for recording. The service node management module 13 feeds back the log information generated in the process of interacting with the capacity expansion management module 12, such as the state information of the service node, to the state feedback and audit module 14 for recording.

[0076] In summary, the capacity expansion method based on key authorization provided by the embodiments of the present application introduces a key management and authorization verification mechanism, so that the capacity expansion operation can be scaled while maintaining strict access control, significantly improving the security and legality of the operation in the process of dynamic capacity expansion. This mechanism ensures that all capacity expansion operations must undergo strict key generation and authorization verification before execution, and only authorized tasks can be allowed to carry out, fundamentally eliminating the security threat that may be caused by unauthorized capacity expansion operations.

[0077] This is different from the traditional dynamic capacity expansion method, which often lacks effective control of capacity expansion operations and is prone to malicious or erroneous operations. The present application provides a unique authorization key for each capacity expansion operation through the key management function, and verifies the legality of the operation in real time through the key management module of the system, ensuring that the capacity expansion task is executed in a safe and controlled environment. In addition, the generation, distribution, verification and other processes of the key are recorded in detail, supporting subsequent audit and problem troubleshooting, thereby further improving the transparency and security of the system and ensuring the safe and stable operation of the system in a large-scale capacity expansion scenario.

[0078] Device for expanding capacity based on key authorization

[0079] Corresponding to the method embodiment, Figure 5 A schematic diagram of a capacity expansion device based on key authorization is shown. As Figure 5 shown, the capacity expansion device based on key authorization includes a key management module 501, a capacity expansion management module 502, and a service node management module 503.

[0080] The key management module 501 is configured to generate and distribute a key for a capacity expansion task, and the key is used to prove the legitimacy of the capacity expansion task.

[0081] The expansion management module 502 is configured to obtain a service group to be expanded corresponding to an expansion task; and control the service node management module 503 to execute the expansion task to expand the services in the service group to be expanded after the key is verified as legitimate.

[0082] In some embodiments, the expansion management module 502 is configured to send a verification request to the key management module 501, and the verification request carries the key.

[0083] The key management module 501 is configured to receive the verification request, verify the legitimacy of the expansion task according to the key carried in the verification request, and send an authorization credential to the expansion management module 502 after the key is verified as legitimate.

[0084] The expansion management module 502 is configured to determine an expansion strategy for the service group to be expanded after receiving the authorization credential, and control the service node management module 503 to execute the expansion task according to the expansion strategy.

[0085] In some embodiments, the expansion management module 502 is configured to poll the service group to be expanded to obtain the number of service nodes of each service in the service group to be expanded, and determine the expansion strategy according to the number of service nodes of each service.

[0086] In some embodiments, the expansion management module 502 is configured to generate an expansion instruction according to the authorization credential and the expansion strategy, and send the expansion instruction to the service node management module 503.

[0087] The service node management module 503 is configured to execute the expansion task according to the expansion strategy after receiving the expansion instruction.

[0088] In some embodiments, the service node management module 503 is configured to create service containers for a plurality of service nodes of each service in the service group to be expanded according to the indication of the expansion strategy; and perform the following release processing on each service in the service group to be expanded: obtain version information of each service node in the plurality of service nodes of the service, count the number of service nodes corresponding to each version information, determine the version information corresponding to the maximum number of service nodes as target version information; release the service container corresponding to the service according to the target version information, load an application corresponding to the target version information into the service container corresponding to the service, and start the service container corresponding to the service.

[0089] In some embodiments, the service node management module 503 is configured to generate an expansion task table according to the indication of the expansion strategy, the expansion task table records the service containers to be created and the creation status of each service container, and the service containers to be created include the service containers corresponding to the plurality of service nodes of each service; and create the service containers for the plurality of service nodes of each service according to the expansion task table.

[0090] In some embodiments, the plurality of service nodes corresponding to the service comprises a primary service node;

[0091] The service node management module 503 is configured to perform the following registration process on each service before performing the release processing: register the service containers corresponding to the plurality of service nodes of the service into a monitoring table of the primary service node, so as to perform real-time monitoring and management on the service containers corresponding to the plurality of service nodes of the service.

[0092] In some embodiments, the server further comprises a state feedback and audit module 504;

[0093] The state feedback and audit module 504 is configured to record the process information of the expansion task performed by the expansion management module 502 and the service node management module 503.

[0094] In some embodiments, the key management module 501 is configured to generate and distribute the key for the expansion task;

[0095] The expansion management module 502 is configured to obtain the to-be-expanded service group corresponding to the expansion task.

[0096] It should be noted that the key-authorized expansion apparatus in the embodiment is used to implement the corresponding key-authorized expansion method in the foregoing method embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be described herein.

[0097] Electronic device

[0098] Figure 6 is a schematic block diagram of an electronic device provided by an embodiment of the present application. Embodiments of the present application do not limit the specific implementation of the electronic device. The electronic device can be a server. As shown in Figure 6 The electronic device can include a processor 602, a communications interface 604, a memory 606, and a communications bus 608. Among them:

[0099] The processor 602, the communications interface 604, and the memory 606 complete mutual communication through the communications bus 608.

[0100] The communications interface 604 is configured to communicate with other electronic devices or servers.

[0101] The processor 602 is configured to execute the program 610, and specifically can execute the related steps in any one of the foregoing key-authorized expansion method embodiments.

[0102] Specifically, the program 610 can include program code, and the program code includes computer operation instructions.

[0103] The processor 602 can be a CPU, or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement one or more embodiments of the present application. The one or more processors included in the smart device can be the same type of processor, such as one or more CPUs; or different types of processors, such as one or more CPUs and one or more ASICs.

[0104] RISC-V is an open-source instruction set architecture based on the principle of reduced instruction set (RISC), which can be applied to various aspects such as single-chip microcomputers and FPGA chips. Specifically, it can be applied in the fields of Internet of Things security, industrial control, mobile phones, personal computers, etc. Due to its consideration of small size, speed, and low power consumption in design, it is particularly suitable for modern computing devices such as warehouse-scale computers, high-end mobile phones, and small embedded systems. With the rise of artificial intelligence Internet of Things (AIoT), the RISC-V instruction set architecture has received more and more attention and support, and is expected to become the next generation of widely used CPU architecture.

[0105] The computer operation instructions in the embodiments of the present application can be computer operation instructions based on the RISC-V instruction set architecture, and correspondingly, the processor 602 can be designed based on the RISC-V instruction set. Specifically, the chip of the processor in the electronic device provided by the embodiments of the present application can be a chip designed based on the RISC-V instruction set, which can execute executable code based on the configured instructions, and thus implement the key-authorized expansion method in the above embodiments.

[0106] The memory 606 is used to store programs 610. The memory 606 can include a high-speed RAM memory, and can also include a non-volatile memory such as at least one disk memory.

[0107] The programs 610 can be specifically used to make the processor 602 execute the key-authorized expansion method in any of the preceding embodiments.

[0108] The specific implementation of each step in the programs 610 can refer to the corresponding description in the corresponding steps and units of any of the key-authorized expansion method embodiments described above, and will not be described here. Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the devices and modules described above can refer to the corresponding process description in the preceding method embodiments, which will not be described here.

[0109] Computer storage medium

[0110] The present application also provides a computer-readable storage medium storing instructions for causing a machine to perform the method of key-based authorization for capacity expansion as described herein. Specifically, a system or apparatus equipped with a storage medium on which a software program code for realizing the functions of any of the above-described embodiments is stored, and causing a computer (or CPU or MPU) of the system or apparatus to read out and execute the program code stored in the storage medium can be provided.

[0111] In this case, the program code read from the storage medium itself can realize the functions of any of the above-described embodiments, and thus the program code and the storage medium storing the program code constitute a part of the present application.

[0112] Embodiments of the storage medium for providing the program code include a floppy disk, a hard disk, a magneto-optical disk, an optical disk (such as a CD-ROM, a CD-R, a CD-RW, a DVD-ROM, a DVD-RAM, a DVD-RW, a DVD+RW), a magnetic tape, a non-volatile memory card, and a ROM. Alternatively, the program code can be downloaded from a server computer via a communication network.

[0113] Computer program product

[0114] The embodiments of the present application also provide a computer program product including computer instructions instructing a computing device to perform any corresponding operation in the above-described method embodiments.

[0115] It should be noted that, according to the needs of implementation, each component / step described in the embodiments of the present application can be split into more components / steps, or two or more components / steps or partial operations of components / steps can be combined into new components / steps, to achieve the purpose of the embodiments of the present application.

[0116] The methods according to the embodiments of the present application described above can be implemented in hardware, firmware, or software, or a combination of them, and can be stored in a recording medium such as a CD ROM, RAM, floppy disk, hard disk, or magneto-optical disk, or be downloaded from a network originally stored in a remote recording medium or a non-transitory machine-readable medium and stored in a local recording medium, so that the methods described herein can be processed by such software on a recording medium using a general-purpose computer, a special-purpose processor, or programmable or special-purpose hardware such as an ASIC or an FPGA. It can be understood that the computer, processor, microprocessor controller, or programmable hardware includes a storage component (for example, RAM, ROM, flash memory, etc.) that can store or receive software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods described herein. Furthermore, when a general-purpose computer accesses code for implementing the methods shown herein, the execution of the code will convert the general-purpose computer into a special-purpose computer for executing the methods shown herein.

[0117] Those skilled in the art can realize that the units and method steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of the present application.

[0118] The above embodiments are only used to illustrate but not limit the embodiments of the present application, and those skilled in the art can make various changes and modifications without departing from the spirit and scope of the embodiments of the present application, therefore all equivalent technical solutions belong to the scope of the embodiments of the present application, and the patent protection scope of the embodiments of the present application should be defined by the claims.

Claims

1. A method for capacity expansion based on key authorization, characterized in that, Applied to a server, the method comprises: generating and distributing a key for a capacity expansion task, the key being used to prove the legality of the capacity expansion task; obtaining a service group to be expanded corresponding to the capacity expansion task; after the key is verified for legality, executing the capacity expansion task to expand the service group to be expanded; wherein the server comprises a capacity expansion management module, a key management module and a service node management module; the generating and distributing of the key for the capacity expansion task comprises generating the key for the capacity expansion task by the key management module and sending the key to the capacity expansion management module; the obtaining of the service group to be expanded corresponding to the capacity expansion task comprises obtaining the service group to be expanded corresponding to the capacity expansion task by the capacity expansion management module; the executing of the capacity expansion task after the key is verified for legality comprises sending a verification request to the key management module by the capacity expansion management module based on the key distributed for the capacity expansion task by the key management module, the verification request carrying the key; receiving the verification request by the key management module and verifying the legality of the capacity expansion task according to the key carried by the verification request; sending an authorization credential to the capacity expansion management module after the key is verified for legality; determining an expansion strategy of the service group to be expanded by the capacity expansion management module after receiving the authorization credential, and controlling the service node management module to execute the capacity expansion task according to the expansion strategy.

2. The method of claim 1, wherein, the determining of the expansion strategy of the service group to be expanded by the capacity expansion management module comprises: polling the service group to be expanded by the capacity expansion management module to obtain the number of service nodes of each service in the service group to be expanded; and determining the expansion strategy according to the number of service nodes of each service.

3. The method of claim 1, wherein, the controlling of the service node management module to execute the capacity expansion task according to the expansion strategy by the capacity expansion management module comprises: generating an expansion instruction according to the authorization credential and the expansion strategy by the capacity expansion management module, and sending the expansion instruction to the service node management module; executing the capacity expansion task according to the expansion strategy by the service node management module after receiving the expansion instruction.

4. The method according to any one of claims 1 to 3, characterized in that, the executing of the capacity expansion task according to the expansion strategy comprises: creating a service container for a plurality of service nodes of each service in the service group to be expanded according to the indication of the expansion strategy; performing the following release processing on each service in the service group to be expanded respectively: obtaining version information of each service node of the plurality of service nodes of the service, counting the number of service nodes corresponding to each version information, determining the version information corresponding to the maximum number of service nodes as target version information; releasing the service container corresponding to the service according to the target version information, loading an application corresponding to the target version information into the service container corresponding to the service, and starting the service container corresponding to the service.

5. The method of claim 4, wherein, the creating of the service container for the plurality of service nodes of each service in the service group to be expanded according to the indication of the expansion strategy comprises: According to the indication of the capacity expansion strategy, a capacity expansion task table is generated, and the capacity expansion task table records service containers to be created and creation statuses of the service containers, and the service containers to be created include service containers corresponding to the service nodes of the services; According to the capacity expansion task table, the service containers are created for the service nodes of the services.

6. The method of claim 4, wherein, The service nodes corresponding to the services include a master service node, and the method further includes: Before performing the release processing, the following registration processing is performed on the services respectively: The service containers corresponding to the service nodes of the services are registered in a monitoring table of the master service node, so as to perform real-time monitoring and management on the service containers corresponding to the service nodes of the services.

7. The method according to any one of claims 1 to 3, characterized in that, The server includes a state feedback and audit module; The method further includes: Process information of the capacity expansion management module and the service node management module performing the capacity expansion task is recorded by the state feedback and audit module.

8. A key authorization-based capacity expansion apparatus, characterized by comprising: The device includes a key management module, a capacity expansion management module, and a service node management module; The key management module is configured to generate a key for a capacity expansion task and send the key to the capacity expansion management module, and the key is used to prove the legality of the capacity expansion task; The capacity expansion management module is configured to obtain a service group to be expanded corresponding to the capacity expansion task, send a verification request to the key management module based on the key distributed by the key management module for the capacity expansion task, and the verification request carries the key; The key management module is configured to receive the verification request, verify the legality of the capacity expansion task according to the key carried by the verification request, and send an authorization credential to the capacity expansion management module after the key passes the legality verification; The capacity expansion management module is configured to determine a capacity expansion strategy of the service group to be expanded after receiving the authorization credential, control the service node management module to perform the capacity expansion task, and expand the services in the service group to be expanded.

9. A server, characterized by The server includes a processor, a memory, a communication interface, and a communication bus, and the processor, the memory, and the communication interface complete communication with each other through the communication bus; The memory is configured to store at least one executable instruction, and the executable instruction causes the processor to perform operations corresponding to the capacity expansion method based on key authorization in any one of claims 1-7.

10. A computer storage medium, characterized in that, The computer storage medium stores a computer program, and the computer program is executed by the processor to implement the capacity expansion method based on key authorization in any one of claims 1-7.

Citation Information

Patent Citations

  • Alliance chain-oriented large-scale node capacity expansion method

    CN111769946A

  • Software authorization control method and device, electronic equipment and storage medium

    CN115495713A