A network topology architecture construction method and system of an energy data center
By constructing buffer zones and multi-layered protection mechanisms in the energy data center, and utilizing multiple boundary devices to filter information, load balancers to score data, and authentication servers, the single point of failure, load imbalance, and authentication bottleneck issues in the network topology were resolved, resulting in more stable and secure data center operation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUIZHOU POWER GRID CO LTD
- Filing Date
- 2024-12-05
- Publication Date
- 2026-04-17
AI Technical Summary
The existing energy data center network topology is susceptible to single points of failure when faced with large-scale data requests. The lack of multi-layer protection mechanisms leads to slow response times or interruptions. The load balancing mechanism fails to adequately consider network bandwidth and device health status. The authentication server becomes a bottleneck under high load, affecting system performance and stability.
Build a buffer zone and multi-layer protection mechanism, filter information through multiple boundary devices, deploy a load balancer and use scheduling algorithms for load scoring, and combine an authentication server for credential verification and data transmission to ensure that only authorized users can access specific resources.
It enhances network security and stability, optimizes server resource allocation, prevents network attacks, and ensures data transmission security and efficient system operation.
Smart Images

Figure CN119652766B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network topology architecture technology, and in particular to a method and system for constructing a network topology architecture for an energy data center. Background Technology
[0002] With the advancement of informatization, energy data centers have gradually become a crucial infrastructure for the energy industry. Energy data center portals aim to provide governments, enterprises, and the public with comprehensive energy data and related services. By establishing a unified and efficient service window, the portal offers users an intuitive and easy-to-use data display platform, significantly improving the transparency and service efficiency of the energy industry. In recent years, with the rapid development of big data and cloud computing technologies, the sharing and management of energy data is gradually transforming towards intelligence and automation. Energy data center portals, by integrating multiple functional modules such as data resource repositories, demand centers, energy information, and product marketplaces, can provide users with personalized information retrieval and service experiences. Through these modules, the portal not only optimizes the display, application, review, and publication processes of energy data but also promotes the market application and ecosystem cooperation of data products. Simultaneously, with the growth in data service demand, energy data center portals need to handle larger-scale user access requests, thus placing higher demands on the efficiency, security, and reliability of the network architecture. To support the massive flow and processing of energy data, the portal system needs to continuously optimize its network topology and improve the system's scalability and load balancing capabilities.
[0003] While existing energy data center portals have made significant progress in providing comprehensive services, shortcomings remain in the design and implementation of their network topology. Firstly, existing systems are susceptible to single points of failure when handling large-scale data requests, leading to slower response times or service interruptions. This is primarily due to the lack of effective multi-layered protection mechanisms in the network architecture, making rapid recovery difficult when the network is attacked. Secondly, existing load balancing mechanisms often rely solely on basic load metrics for scheduling, failing to adequately consider network bandwidth or device health indicators. This results in inadequate resource allocation under high load conditions, impacting overall system performance and stability. Furthermore, the authentication server's operation has limitations, especially under frequent user requests, where the authentication process can easily become a bottleneck, affecting data transmission efficiency. Therefore, improvements in security, reliability, and system optimization are still needed to better meet the growing demand for energy data services. Summary of the Invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the problem to be solved by this invention is to provide a method for constructing a network topology architecture for energy data centers, which reduces potential network attacks and failure risks by utilizing multiple protections, multi-layer filtering, load balancing and authentication, and provides a more stable and sustainable operating environment for energy data centers.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:
[0007] In a first aspect, embodiments of the present invention provide a method for constructing a network topology architecture for an energy data center, which includes constructing a buffer zone and a multi-layer protection mechanism based on the external environment and the internal core network, performing multiple filtering on request information to obtain multi-filtered request information; deploying a load balancer and using a scheduling algorithm to calculate a load score, allocating the multi-filtered request information based on the load score; and using an authentication server to perform credential verification and data transmission on the allocated multi-filtered request information.
[0008] As a preferred embodiment of the network topology architecture construction method for the energy data center described in this invention, the construction of the buffer area includes: setting up an Internet exit area and a buffer area as a buffer area between the network data cloud platform and the Internet; using a third-party access area as a buffer area between external terminals and the network data cloud platform to isolate the external environment from the internal core network; and constructing the multi-layer protection mechanism refers to setting up multiple boundary devices to block multiple times, forming a multi-layer protection mechanism.
[0009] As a preferred embodiment of the network topology architecture construction method for the energy data center described in this invention, the multi-boundary devices include a first boundary device, a second boundary device, and an isolation boundary device; the multi-filtering of request information includes: a client sending internet request information to the second boundary device via the internet; the second boundary device filtering the internet request information according to a second preset rule; if the internet request information conforms to the second preset rule, the internet request information conforming to the second preset rule is allowed to pass through the second boundary device; the second boundary device forwards the internet request information conforming to the second preset rule to a load balancer; the load balancer selects a front-end server according to a scheduling algorithm and checks the front-end server; when the selected front-end server is working normally, the first boundary device again filters the internet request information conforming to the second preset rule according to the first preset rule; if the internet request information conforms to the first preset rule, the internet request information conforming to the first preset rule is allowed to pass through the first boundary device; the first boundary device sends the internet request information conforming to the first preset rule to the isolation boundary device in the buffer; the isolation boundary device filters the internet request information conforming to the first preset rule according to the isolation preset rule; if the internet request information conforms to the isolation preset rule, the internet request information conforming to the isolation preset rule is sent to the selected front-end server.
[0010] As a preferred embodiment of the network topology architecture construction method for the energy data center described in this invention, the load balancer is used to distribute request information from the Internet to multiple front-end servers according to the actual load status of the front-end servers; the load balancer is set between the buffer boundary device and the Internet egress boundary device.
[0011] In a preferred embodiment of the network topology architecture construction method for the energy data center described in this invention, the calculation of the load score using a scheduling algorithm refers to the load balancer's scheduling algorithm calculating the load content and related weights of the front-end servers. The formula for calculating the load score of the front-end servers using the scheduling algorithm is as follows:
[0012] Load score = CPU utilization × CPU weight + Memory utilization × Memory weight
[0013] +Network bandwidth utilization × bandwidth weight +Distance × distance weight
[0014] Among them, CPU utilization, memory utilization, and network bandwidth utilization are all state characteristics of the corresponding front-end server; distance is the distance between the terminal that sends the Internet request information and the corresponding front-end server; CPU weight, memory weight, bandwidth weight, and distance weight are determined by manual setting or other preset algorithms.
[0015] As a preferred embodiment of the network topology architecture construction method for the energy data center described in this invention, the authentication server is set in the portal internet domain of the buffer, which is closer to the internet than the internal and external network exchange platform, and has an equal number of front-end boundary devices; the authentication server is used to import existing user information into the central user directory, and the authentication server is integrated with the central user directory and set in the internal and external network exchange platform or the buffer, wherein the authentication server and the front-end server can be the same device, so that the authentication function is allocated by the load balancer.
[0016] As a preferred embodiment of the network topology architecture construction method for the energy data center described in this invention, the credential verification includes the following steps: A request message is sent over the Internet, reaching the internal and external network exchange platform. The authentication server on the internal and external network exchange platform receives the request message and prompts the user to enter access credentials. The authentication server obtains the access credentials and queries user information from the central user directory to verify the validity of the access credentials. If the authentication server determines that the access credentials are valid, it obtains the user permission information corresponding to the access credentials from the central user directory. After determining that the access credentials are valid, the authentication server obtains the corresponding user permission information based on the contents of the central user directory, and encapsulates the request message, access credentials, and user permission information into a data packet and generates an encrypted packet using an encryption algorithm. The authentication server transmits the encrypted packet to the data main domain through the network connected to the data main domain. After receiving the encrypted packet, the data main domain decrypts the encrypted packet according to a pre-set decryption method, recovers the data packet, and extracts the request message, access credentials, and user permission information from the data packet.
[0017] Secondly, to further address security issues in network topology architecture, this invention provides a network topology architecture construction system for an energy data center, comprising: an information filtering module, used to construct buffer zones and multi-layer protection mechanisms based on the external environment and internal core network, acquire request information and perform multiple filtering to obtain multi-filtered request information; an information allocation module, used to calculate a load score based on the load content and related weights of the front-end server using a scheduling algorithm, and allocate the multi-filtered request information based on the load score; and a verification and transmission module, used to verify the allocated multi-filtered request information using an authentication server, and transmit data according to the verification result.
[0018] Thirdly, embodiments of the present invention provide a computer device, including a memory and a processor, wherein the memory stores a computer program, and the computer program, when executed by the processor, implements any step of the network topology architecture construction method for energy data centers as described in the first aspect of the present invention.
[0019] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the network topology architecture construction method for energy data centers as described in the first aspect of the present invention.
[0020] The beneficial effects of this invention are as follows: By establishing a buffer zone and constructing a multi-layered protection mechanism, this invention enhances data security and network stability through effective isolation between the external environment and the internal network. By filtering request information multiple times, it reduces the inflow of malicious or unnecessary data into the internal network, thereby effectively preventing potential network attacks. By deploying a load balancer and combining it with scheduling algorithms to perform load scoring on request information, it can optimize server resource allocation, ensure the efficient operation of the data center, and rationally schedule server load, avoiding the risk of performance degradation or downtime caused by overload of a single server. By using an authentication server for credential verification, it can effectively ensure that only authorized users can access specific resources, guaranteeing the security of data transmission. Attached Figure Description
[0021] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:
[0022] Figure 1 This is an overall flowchart of the network topology architecture construction method for the energy data center in Example 1.
[0023] Figure 2 This is a schematic diagram of the computer device in Example 3.
[0024] Figure 3 This is a schematic diagram of the network topology architecture of the energy data center in Example 4. Detailed Implementation
[0025] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0026] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0027] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0028] Example 1
[0029] Reference Figure 1 This is the first embodiment of the present invention, which provides a method for constructing a network topology architecture for an energy data center.
[0030] Existing network topology construction methods suffer from the following main problems: First, existing systems are susceptible to single points of failure when dealing with large-scale data requests, leading to slower system response or service interruptions. This is primarily due to the lack of effective multi-layered protection mechanisms in the network architecture, making rapid recovery difficult when the network is attacked. Second, existing load balancing mechanisms often rely solely on basic load metrics for scheduling, failing to adequately consider network bandwidth or device health indicators. This results in the system being unable to allocate resources reasonably under high load conditions, impacting the overall system performance and stability. Furthermore, the operation of authentication servers has limitations, especially when user requests are frequent, where the authentication process can easily become a bottleneck, affecting data transmission efficiency.
[0031] This application provides a method that can effectively solve the problems mentioned above. The following will describe in detail how to implement the network topology architecture construction method of the energy data center with multiple embodiments.
[0032] Figure 1 The flowchart illustrates the overall process for constructing the network topology architecture of an energy data center, including:
[0033] S1: Based on the external environment and internal core network, a buffer zone and multi-layer protection mechanism are constructed to perform multiple filtering on request information, resulting in multi-filtered request information.
[0034] Preferably, constructing a buffer zone includes setting up an Internet exit zone and a buffer zone as a buffer zone between the network data cloud platform and the Internet.
[0035] The third-party access area serves as a buffer zone between external terminals and the network data cloud platform, isolating the external environment from the internal core network.
[0036] Preferably, building a multi-layered protection mechanism means setting up multiple boundary devices to block multiple times, forming a multi-layered protection mechanism that effectively prevents external attackers from intruding into the internal network.
[0037] Specifically, the multi-border device includes a first border device, a second border device, and an isolation border device.
[0038] Furthermore, the multiple filtering of request information includes: the client sending Internet request information to the second boundary device via the Internet; the second boundary device filtering the Internet request information according to a second preset rule; and if the Internet request information conforms to the second preset rule, then the Internet request information conforming to the second preset rule is allowed to pass through the second boundary device.
[0039] The second boundary device forwards Internet request information that conforms to the second preset rule to the load balancer. The load balancer selects a front-end server according to the scheduling algorithm and checks the front-end server.
[0040] When the selected front-end server is working normally, the first boundary device filters the Internet request information that conforms to the second preset rule again according to the first preset rule. If the Internet request information conforms to the first preset rule, the Internet request information that conforms to the first preset rule is allowed to pass through the first boundary device.
[0041] The first boundary device sends Internet request information that conforms to the first preset rule to the isolation boundary device in the buffer. The isolation boundary device filters the Internet request information that conforms to the first preset rule according to the isolation preset rule. If the Internet request information conforms to the isolation preset rule, it sends the Internet request information that conforms to the isolation preset rule to the selected front-end server.
[0042] S2: Deploy a load balancer and use a scheduling algorithm to calculate the load score, and then allocate the multi-filtered request information based on the load score.
[0043] Preferably, the load balancer is used to reasonably distribute various request information from the Internet to multiple front-end servers according to the actual load status of each front-end server, reduce the burden on a single front-end server, avoid service interruption due to the failure of a certain front-end server, and improve the overall processing capacity and response speed of the system by processing requests in parallel.
[0044] Specifically, the load balancer is positioned between the buffer boundary device and the internet egress boundary device, avoiding direct exposure to the internet and becoming a target of attacks. It also allows the load balancer sufficient time to analyze, process, and distribute the received request information, preventing the load balancer from being too slow to respond and fully utilizing the load balancer's effectiveness.
[0045] Furthermore, the load score is calculated using a scheduling algorithm. This load balancer's scheduling algorithm calculates the load score for each front-end server based on its load content and relevant weights. The formula for calculating the load score for each front-end server using the scheduling algorithm is as follows:
[0046] Load score = CPU utilization × CPU weight + Memory utilization × Memory weight
[0047] +Network bandwidth utilization × bandwidth weight +Distance × distance weight
[0048] Among them, CPU utilization, memory utilization, and network bandwidth utilization are all state characteristics of the corresponding front-end server; distance is the distance between the terminal that sends the Internet request information and the corresponding front-end server; CPU weight, memory weight, bandwidth weight, and distance weight are determined by manual setting or other preset algorithms.
[0049] S3: Utilize the authentication server to perform credential verification and data transmission on the multi-filtered request information.
[0050] Preferably, the authentication server is located in the portal internet domain of the buffer zone. Compared with the internal and external network exchange platform, it is closer to the internet and has an equal number of front-end boundary devices, which ensures both response speed and sufficient security.
[0051] Preferably, the authentication server is used to import existing user information into the central user directory. The authentication server is integrated with the central user directory and set up in the internal and external network exchange platform or buffer. The authentication server and the front-end server can be the same device, so that the authentication function is allocated by the load balancer, which is more conducive to resource allocation and improves the response rate.
[0052] Specifically, credential verification includes the following steps: the Internet sends a request message, the request message reaches the internal and external network exchange platform, the identity verification server on the internal and external network exchange platform receives the request message, and prompts the user to enter access credentials.
[0053] The authentication server obtains access credentials and queries user information from the central user directory to verify the validity of the access credentials. If the authentication server determines that the access credentials are valid, it then retrieves the user permission information corresponding to the access credentials from the central user directory.
[0054] After verifying the validity of the access credentials, the authentication server obtains the corresponding user permission information based on the contents of the central user directory, and encapsulates the request information, access credentials, and user permission information into a data packet and generates an encrypted packet using an encryption algorithm.
[0055] The authentication server transmits encrypted packets to the data master domain via a network connected to the data master domain.
[0056] After receiving the encrypted packet, the data master domain decrypts the encrypted packet according to the pre-set decryption method, recovers the data packet, and extracts the request information, access credentials, and user permission information from the data packet to complete the entire transmission process.
[0057] It should be noted that in the network topology, multiple paths are designed to connect different network areas, ensuring that if one path fails, data can be automatically switched to other paths for transmission. Between the buffer zone and the data center, two or more border firewall and border switch paths can be designed to ensure that if one path fails, data can be transmitted through other paths.
[0058] Furthermore, the internal and external network switching platform is the boundary between the internal and external networks. From the perspective of the Internet access party, the internal and external network switching platform is relatively close and usually has high-performance network equipment that can handle a large number of concurrent requests, resulting in a very fast response time for user requests. In addition, the internal and external network switching platform of this invention is located between the Internet exit zone, the buffer zone, and the network data cloud platform. It is isolated by multiple boundary devices in the Internet exit zone and the buffer zone, which greatly improves security.
[0059] In summary, this invention enhances data security and network stability by establishing a buffer zone and constructing a multi-layered protection mechanism, effectively isolating the external environment from the internal network. Multiple filtering of request information reduces the inflow of malicious or unnecessary data into the internal network, effectively preventing potential network attacks. Deploying a load balancer and combining it with scheduling algorithms to perform load scoring on request information optimizes server resource allocation, ensuring efficient data center operation and rationally scheduling server load, avoiding performance degradation or downtime risks caused by overload of a single server. Using an authentication server for credential verification effectively ensures that only authorized users can access specific resources, guaranteeing data transmission security.
[0060] Example 2, an embodiment of the present invention, provides a network topology architecture construction system for an energy data center, comprising: an information filtering module, used to construct a buffer zone and multi-layer protection mechanism based on the external environment and the internal core network, acquire request information and perform multiple filtering to obtain multi-filtered request information; an information allocation module, used to calculate a load score based on the load content and related weights of the front-end server, and allocate the multi-filtered request information based on the load score; and a verification and transmission module, used to verify the allocated multi-filtered request information using an authentication server and transmit data according to the verification result.
[0061] Example 3 is an embodiment of the present invention, which differs from the previous embodiment in that:
[0062] like Figure 2 As shown, if the function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0063] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0064] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0065] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0066] Example 4 is an embodiment of the present invention, which provides a method for constructing a network topology architecture for an energy data center. To verify the beneficial effects of the present invention, a simulation experiment is conducted for scientific demonstration.
[0067] This example simulates the network topology of a real-world energy data center, constructing buffer zones and multi-layered protection mechanisms. It performs multiple filtering of request information, deploys a load balancer and uses scheduling algorithms for calculation, allocates the filtered request information based on load scores, and then uses an authentication server to verify credentials and transmit data for the allocated, multi-filtered request information. Specifically... Figure 3 As shown.
[0068] First, the internet sends a request to the internet egress zone. After processing by the internet egress-border device, it is transmitted to the DMZ zone. After processing by the DMZ-border device and the portal internet domain in resource pool 1, it is transmitted to the Southern Power Grid Cloud via the internal and external network exchange platform. In the Southern Power Grid Cloud, it is processed by the Southern Power Grid Cloud Zone IV-border device and finally transmitted to the third-party access zone. After processing by the third-party access zone-border device, it enters the government network and performs credential verification and data transmission with government units, including the Energy Bureau PC, the Development and Reform Commission PC, the Industry and Information Technology Bureau PC, and other bureau PCs. Data transmission is carried out through a dedicated government network line, thereby ensuring that only authorized users can access specific resources, guaranteeing data transmission security, and effectively preventing potential network attacks.
[0069] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A method for constructing a network topology architecture for an energy data center, characterized in that: include: Based on the external environment and the internal core network, a buffer zone and a multi-layer protection mechanism are constructed to perform multiple filtering on the request information, resulting in multi-filtered request information. Deploy a load balancer and use a scheduling algorithm to calculate the load score, and allocate the multi-filtered request information based on the load score; The authentication server is used to verify credentials and transmit data for the multi-filtered request information. The construction buffer region includes: Set up an internet exit zone and a buffer zone as a buffer area between the network data cloud platform and the internet; The third-party access area serves as a buffer zone between external terminals and the network data cloud platform, isolating the external environment from the internal core network. Constructing the aforementioned multi-layered protection mechanism refers to setting up multiple boundary devices to perform multiple blocking operations, thereby forming a multi-layered protection mechanism; The multi-boundary device includes a first boundary device, a second boundary device, and an isolation boundary device; The multiple filtering of the request information includes: The client sends an Internet request to the second boundary device via the Internet. The second boundary device filters the Internet request according to a second preset rule. If the Internet request conforms to the second preset rule, the Internet request that conforms to the second preset rule is allowed to pass through the second boundary device. The second boundary device forwards Internet request information that conforms to the second preset rule to the load balancer. The load balancer selects a front-end server according to the scheduling algorithm and checks the front-end server. When the selected front-end server is working normally, the first boundary device filters the Internet request information that conforms to the second preset rule again according to the first preset rule. If the Internet request information conforms to the first preset rule, the Internet request information that conforms to the first preset rule is allowed to pass through the first boundary device. The first boundary device sends Internet request information that conforms to the first preset rule to the isolation boundary device in the buffer. The isolation boundary device filters the Internet request information that conforms to the first preset rule according to the isolation preset rule. If the Internet request information conforms to the isolation preset rule, it sends the Internet request information that conforms to the isolation preset rule to the selected front-end server.
2. The method of claim 1, wherein: The load balancer is used to distribute request information from the Internet to multiple front-end servers according to the actual load status of the front-end servers. The load balancer is positioned between the buffer boundary device and the Internet egress boundary device.
3. The method for constructing the network topology architecture of an energy data center as described in claim 2, characterized in that: The calculation of the load score using the scheduling algorithm refers to the load balancer's scheduling algorithm calculating the load score of the front-end servers based on their load content and relevant weights. The formula for calculating the load score of the front-end servers using the scheduling algorithm is as follows: ; Wherein, the CPU utilization, memory utilization and network bandwidth utilization are all corresponding to the state characteristics of the front-end server itself; the distance is the distance between the terminal sending the Internet request information and the corresponding front-end server; , , and determined by manual setting or other preset algorithms.
4. The method of claim 3, wherein: The authentication server is located in the portal internet domain of the buffer zone. Compared with the internal and external network exchange platform, it is closer to the internet and has an equal number of front-end boundary devices. The authentication server is used to import existing user information into the central user directory. The authentication server is integrated with the central user directory and set up in the internal and external network exchange platform or buffer. The authentication server and the front-end server can be the same device, so that the authentication function is allocated by the load balancer.
5. The method of claim 4, wherein: The credential verification includes the following steps: The Internet sends a request message, which reaches the internal and external network exchange platform. The authentication server on the internal and external network exchange platform receives the request message and prompts the user to enter access credentials. The authentication server obtains access credentials and queries user information from the central user directory to verify the validity of the access credentials. If the authentication server determines that the access credentials are valid, it then obtains the user permission information corresponding to the access credentials from the central user directory. After verifying the validity of the access credentials, the authentication server obtains the corresponding user permission information based on the contents of the central user directory, and encapsulates the request information, access credentials, and user permission information into a data packet and generates an encrypted packet using an encryption algorithm. The authentication server transmits encrypted packets to the data master domain via a network connected to the data master domain. After receiving the encrypted packet, the data master domain decrypts the encrypted packet according to the pre-set decryption method, recovers the data packet, and extracts request information, access credentials, and user permission information from the data packet.
6. A network topology architecture construction system for an energy data center, based on the network topology architecture construction method for an energy data center according to any one of claims 1 to 5, characterized in that: include, The information filtering module is used to build a buffer zone and multi-layer protection mechanism based on the external environment and the internal core network, obtain request information and perform multiple filtering to obtain the request information after multiple filtering. The information allocation module is used to calculate the load score based on the load content and related weights of the front-end server, and then allocate the request information after multiple filtering based on the load score. The verification and transmission module is used to verify the credentials of the multi-filtered request information assigned by the authentication server, and to transmit the data according to the credential verification result.
7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the network topology architecture construction method for the energy data center as described in any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the network topology architecture construction method for the energy data center as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Network data processing method, device and system
CN106713332A
Network security architecture, network security implementation method and system, and medium
CN117155605A