A frame-type security resource pool management method and device based on lightweight virtualization
By abstracting the resources of the business board into virtual resources and building a secure resource pool, and combining lightweight virtual technology to schedule resources to run virtual security service components, the high cost problem caused by cloud computing platform relying on a large number of servers is solved, and flexible, scalable and highly available security resource pool management is achieved.
Patent Information
- Application Number
- CN202510242196.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-28
AI Technical Summary
In the prior art, cloud computing platforms rely on a large number of servers to build a security resource pool, resulting in high deployment and maintenance costs and difficult to meet users' security service needs.
The box-based security resource pool management method based on lightweight virtualization is adopted to abstract the resources of the business board into virtual resources, build a security resource pool, and use lightweight virtual technology to schedule independent resources to run the target virtual security service components when receiving user security service requests.
The composition of the security resource pool is simplified, the construction cost of the security resource pool is saved, the flexibility and strong scalability of the security resource pool is improved, the reliability of high availability and security services is enhanced, and the security isolation between users is achieved.
Smart Images

Figure CN119718694B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computers, and in particular to a frame-type security resource pool management method and device based on lightweight virtualization. Background Art
[0002] With the advancement of computer technology, data security has become a critical task that cannot be ignored. However, due to the increasing complexity of network security challenges, the cost of security services for users is also increasing. Therefore, to reduce security service costs, especially in scenarios such as private clouds, dedicated clouds, edge sites, IDCs, and dedicated lines, users often rent security services from the security resource pools provided by cloud computing platforms to protect cloud data security.
[0003] In existing technologies, security resource pools primarily rely on cloud computing platform servers. Cloud computing platform operators abstract the servers into multiple logical virtual machines (VMs), deploying the corresponding operating system and security services on each VM. Once a user subscribes to security services, the cloud computing platform allocates the corresponding VM to the user, providing security services.
[0004] However, with the increasing number of users, in order to meet the security service needs of users, the operators of cloud computing platforms need to continuously increase the number of servers, and the deployment and maintenance costs are getting higher and higher. Based on this, the present application provides a frame-type security resource pool management method and device based on lightweight virtualization. Summary of the Invention
[0005] This specification provides a frame-type security resource pool management method and device based on lightweight virtualization to partially solve the above-mentioned problems existing in the prior art.
[0006] This manual adopts the following technical solutions:
[0007] A lightweight virtualization-based frame-type security resource pool management method is applied to a main control board of a frame-type device, wherein the frame-type device includes at least a main control board and a service board, wherein:
[0008] Determine the type and resources of each service board, abstract the resources of each service board into virtual resources, and construct a security resource pool based on the type of each service board and the virtual resources, wherein the type of each service board includes a processor architecture type;
[0009] Determine a virtual security service component running on each of the service boards, wherein the virtual security service component is determined by dividing the security function module running on each of the service boards into multiple logical units and virtualizing each logical unit using lightweight virtualization technology;
[0010] Upon receiving a security service request from a user, determining at least one target virtual security service component based on the security service request and determining independent resources from the security resource pool for running the target virtual security service component. Determining the type and resources of each service board, abstracting the resources of each service board into virtual resources, and constructing a security resource pool based on the type of each service board and the virtual resources, wherein the type of each service board includes a processor architecture type.
[0011] Determine a virtual security service component running on each of the service boards, wherein the virtual security service component is determined by dividing the security function module running on each of the service boards into multiple logical units and virtualizing each logical unit using lightweight virtualization technology;
[0012] When a security service request from a user is received, at least one target virtual security service component is determined according to the security service request, and independent resources are determined from the security resource pool for running the target virtual security service component.
[0013] Optionally, the service boards are connected via a high-speed binding interface;
[0014] Determine the type and resources of each service board and abstract the resources of each service board into virtual resources, specifically including:
[0015] Virtualizing each of the service boards into a cloud board, and determining the type and resources of the cloud board;
[0016] The cloud board resources are abstracted into virtual resources.
[0017] Optionally, building a security resource pool according to the type of each service board and the virtual resources specifically includes:
[0018] For each type of service board, a security resource pool of that type is constructed according to the virtual resources of that type of service board.
[0019] Optionally, before receiving the user's security service request, the method further includes:
[0020] Pre-storing various types of service software for each service board;
[0021] When the frame device is started, it accepts the service software acquisition request sent by each service board, and sends the corresponding service software to the corresponding service board according to the service software acquisition request, so that the corresponding service board runs the software corresponding to the service.
[0022] A lightweight virtualization-based frame-type security resource pool management method, the method is applied to the service board of a frame-type device, the frame-type device including at least a main control board and a service board, specifically comprising:
[0023] determining a security function module running on itself, and dividing the security function module into at least one logical unit;
[0024] The logic unit is virtualized into a virtual security service component by using lightweight virtualization technology, so that when the main control board receives a security service request from a user, it determines at least one target virtual security service component according to the security service request and determines an independent resource from a security resource pool;
[0025] A virtual device is created and configured according to the independent resources, so that the virtual device runs the target virtual security service component based on the independent resources.
[0026] Optionally, the independent resources include at least independent protocol process management resources and an independent forwarding resource pool.
[0027] This specification provides a lightweight virtualization-based frame-type security resource pool management device, which is applied to a main control board of a frame-type device. The frame-type device includes at least a main control board and several service boards, specifically including:
[0028] A pooling module is used to determine the type and resources of each business board, abstract the resources of each business board into virtual resources, and build a security resource pool based on the type of each business board and the virtual resources, wherein the type of each business board includes a processor architecture type;
[0029] A determination module, configured to determine a virtual security service component running on each of the service boards, wherein the virtual security service component is determined by dividing the security function module running on each of the service boards into a plurality of logical units and virtualizing each logical unit using lightweight virtualization technology;
[0030] The resource management module is used to determine at least one target virtual security service component according to the security service request when receiving a user's security service request, and determine independent resources from the security resource pool for running the target virtual security service component.
[0031] This specification provides a lightweight virtualization-based frame-type security resource pool management device, which is applied to a service board of a frame-type device. The frame-type device includes at least a main control board and several service boards, specifically including:
[0032] a partitioning module, configured to determine a security function module running on itself and to partition the security function module into at least one logical unit;
[0033] a virtualization module, configured to virtualize the logical unit into a virtual security service component using lightweight virtualization technology, so that when the main control board receives a security service request from a user, it determines at least one target virtual security service component according to the security service request and determines independent resources from a security resource pool;
[0034] The running module is used to create and configure a virtual device according to the independent resources, so that the virtual device runs the target virtual security service component based on the independent resources.
[0035] This specification provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned secure resource pool management method is implemented.
[0036] At least one of the above technical solutions adopted in this specification can achieve the following beneficial effects:
[0037] This specification provides a frame-type security resource pool management method based on lightweight virtualization. The method is applied to the main control board of the frame-type device. By abstracting the resources of the business board into virtual resources, a security resource pool is constructed. After receiving the user's security service request, independent resources are dispatched from the security resource pool to run the target virtual security service components divided from the security function modules running by each business board through lightweight virtualization technology to provide security services for the user.
[0038] In the above method, through the combination of software and hardware, frame devices are used to replace the traditional security resource pool built through servers, and through lightweight virtual technology, in the one-cloud-multiple-core scenario, the composition of the security resource pool is simplified, the construction cost of the security resource pool is saved, the flexibility and strong scalability of the construction of the security resource pool are improved, and the high availability of the security resource pool is improved. While improving the reliability of security services, security isolation between users is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The drawings described herein are used to provide a further understanding of this specification and constitute a part of this specification. The exemplary embodiments and descriptions of this specification are used to explain this specification and do not constitute an improper limitation of this specification. In the drawings:
[0040] Figure 1 A schematic diagram of the secure resource pool architecture in a server-based, one-cloud, multi-core scenario provided in this specification;
[0041] Figure 2 A schematic diagram of the process of a frame-type secure resource pool management method based on lightweight virtualization provided in this specification;
[0042] Figure 3 A schematic diagram of the process of a frame-type secure resource pool management method based on lightweight virtualization provided in this specification;
[0043] Figure 4 A schematic diagram of a lightweight virtualization technology provided in this manual;
[0044] Figure 5 This is a schematic diagram of the interaction process between the main control board and the business board provided in this manual;
[0045] Figure 6 This is a schematic diagram of a lightweight virtualization-based frame-type security resource pool management device provided in this specification;
[0046] Figure 7 This is a schematic diagram of a lightweight virtualization-based frame-type security resource pool management device provided in this specification;
[0047] Figure 8 This manual provides a corresponding Figure 2 or Figure 3 Schematic diagram of the structure of the electronic equipment. DETAILED DESCRIPTION
[0048] To make the purpose, technical solutions, and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in conjunction with the specific embodiments of this specification and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.
[0049] At present, with the development of computer technology, data security has become a critical task that cannot be ignored. However, due to the increasing complexity of network security challenges, the security service costs of users are also getting higher and higher. Therefore, in order to reduce the cost of security services, especially in scenarios such as private clouds, dedicated clouds, edge stations, and dedicated lines, users usually rent security services from the security resource pool provided by cloud computing platforms to protect cloud data security. Among them, in one or more embodiments of this specification, security services include but are not limited to virtual firewalls (Virtual Firewall, vFW), virtual intrusion prevention systems (Virtual Intrusion Prevention System, vIPS), virtual network application firewalls (Virtual Web Application Firewall, vWAF), virtual vulnerability scanning (Virtual Vulnerability Scanning", vScan), etc. The security services in the subsequent content also include but are not limited to the above content, which can be set according to actual needs, and this specification does not impose any restrictions on this.
[0050] In existing technologies, security resource pools primarily rely on cloud computing platform servers. Cloud computing platform operators abstract the servers into multiple logical virtual machines (VMs), deploying the corresponding operating system and security services on each VM. Once a user subscribes to security services, the cloud computing platform allocates the corresponding VM to the user, providing security services.
[0051] In order to enable the cloud computing platform to support multiple different types of processor architectures, namely "one cloud, multiple cores", the software images of different processor architectures will be saved separately through the server virtualization image library. Then, by obtaining the central processing unit (CPU) architecture information of the corresponding server, the virtual machine will identify and schedule the loading of different software images to achieve the purpose of compatibility with one cloud and multiple cores.
[0052] like Figure 1 As shown, Figure 1 This is a schematic diagram of a secure resource pool architecture based on a server-based one-cloud-multi-core scenario provided in the embodiments of this application specification. Each virtual machine includes at least a corresponding operating system and running security services, except Figure 1In addition to the configurations contained in each virtual machine, it also includes CPU, memory, disk and other configurations. The system of the virtual machine itself will also take up a lot of resources. With the increasing number of users, in order to meet the security service needs of users, cloud computing platform operators need to continuously increase the number of servers, which not only takes up physical space, but also consumes huge power and the deployment cost is getting higher and higher. Moreover, with the increase in the number of server deployments, the server system vulnerability patches and feature library upgrades are complex, and the difficulty of operation and maintenance is also increasing exponentially. In addition, since security components of different architectures require different images and corresponding operating systems, for example, Figure 1 As shown in , since the types of server operating systems include at least X86 architecture, Advanced Reduced Instruction Set Computing Machinem (ARM), etc., that is, "one cloud, multiple cores", high requirements are placed on the processor hardware compatibility of the components of the entire virtualized security resource pool, and management difficulty increases.
[0053] Based on the above content, the present application specification provides a frame-type security resource pool management method based on lightweight virtualization. The method is applied to the main control board on the frame-type device, replacing the traditional security resource pool built through the server with the frame-type device, and through lightweight virtualization technology, in the one-cloud-multiple-core scenario, simplifying the composition of the security resource pool, saving the construction cost of the security resource pool, improving the flexibility and strong scalability of the construction of the security resource pool, and also improving the high availability of the security resource pool, and improving the reliability of security services while achieving security isolation between users.
[0054] It should be noted that in one or more embodiments of this specification, the number of main control boards and service boards in the frame device is not limited and can be set according to actual needs. For example, when the depth of the security resource pool needs to be increased, this can be achieved by increasing the number of service boards. Alternatively, the reliability of the frame device can be improved by providing at least two main control boards and using the remaining main control boards as backup boards for a certain main control board. Furthermore, in one or more embodiments of this specification, the model and type of the main control boards and service boards installed in the frame device are not limited. Each service board runs a security function module, and each security function module corresponds to a security service.
[0055] Figure 2 A schematic diagram of a process for a lightweight virtualization-based frame-type secure resource pool management method provided in an embodiment of this specification includes the following steps:
[0056] S200: Determine the type and resources of each business board, abstract the resources of each business board into virtual resources, and build a security resource pool based on the type of each business board and the virtual resources, wherein the type of each business board includes a processor architecture type.
[0057] In one or more embodiments of the present specification, in order to improve the resource utilization of the business board, enhance the flexibility of the business board, uniformly manage and monitor the resources of the business board, and achieve resource isolation, thereby improving the high availability of the business board, the main control board may first determine the resources of each business board, and then abstract the hardware resources of each business board into virtual resources.
[0058] Specifically, the main control board can obtain the resource information of each business board, such as hardware specifications, network interfaces, health status, etc., by scanning the business boards. Then, the physical resources on each business board are abstracted into virtual resources, such as abstracting multiple CPU cores into virtual CPUs, dividing the memory into multiple logical memory areas, and abstracting the network interface into a virtual network card. Resource abstraction is achieved based on lightweight one-virtual-many virtualization technology, thereby reducing virtualization overhead and providing performance close to bare metal. Then, since different types of business boards have different processing efficiency when performing security services, in order to improve the security service efficiency of the security resource pool, the main control board can build a security resource pool based on the determined virtual resources and the type of each business board. Among them, the type of business board may depend on the processor architecture type of the business board, such as X86 architecture, ARM architecture, etc.
[0059] It should be noted that in one or more embodiments of this specification, there is no restriction on how the main control board determines the resources of each business board. The resources of each business board can be determined by hardware scanning, or by obtaining resource reports sent by the business board to the main control board. Since there are many ways to determine the resources of each business board, this specification will not go into details here, and can be set according to actual needs. In addition, in one or more embodiments of this specification, there is no restriction on what specific resources each business board has, including but not limited to computing resources, network resources, interface resources, memory resources, etc., which can be set according to actual needs.
[0060] Furthermore, in one or more embodiments of this specification, there is no restriction on the specific method used by the main control board to implement resource abstraction and determine virtual resources, such as using containerization technology, virtual network function (VNF) slicing, etc., and setting it according to actual needs. This specification does not impose any restrictions on this.
[0061] S202: Determine a virtual security service component running on each business board, wherein the virtual security service component is determined by dividing the security function module running on each business board into multiple logical units and virtualizing each logical unit through lightweight virtualization technology.
[0062] In order to further improve resource utilization and flexibility, the security function module running on each business board can be divided into multiple logical units, and then each logical unit can be virtualized through lightweight virtualization technology to determine each virtual security service component.
[0063] Specifically, the business board divides its own security function modules into multiple logical units, implementing security pooling within the business board. Using lightweight virtualization technology, each logical unit is virtualized to identify virtual security service components. In other words, the business board uses lightweight virtualization technology to divide its own security function modules into multiple independent virtual security service components, each of which provides security services to a single user. The main control board then determines the virtualized virtual security service components.
[0064] It should be noted that in one or more embodiments of this specification, there is no limitation on how the main control board determines each virtual security service component. The main control board may determine each virtual security service component by scanning each service board, or each service board may determine the globally unique identifier of each virtual security service component after completing the virtualization of the security function module and send it to the main control board. Since there are many possible methods, they will not be detailed here. You can set it according to your actual needs.
[0065] S204: When a security service request from a user is received, at least one target virtual security service component is determined according to the security service request, and independent resources are determined from the security resource pool for running the target virtual security service component.
[0066] In order to provide security services to users, after receiving a security service request, the main control board determines independent resources from the constructed security resource pool according to the security service request, and uses them to run the security service provided to the user.
[0067] Specifically, the main control board obtains a security service request, and then obtains the user's configuration information and the required security service based on the security service request. Then, based on the configuration information and security service, it determines independent resources from the security resource pool, as well as virtual security service components that can provide the security service to the user, and runs them on the business board to provide security services to the user.
[0068] It should be noted that in one or more embodiments of this specification, the specific form of the security service request is not limited, and it can be a string of code, a string of data streams, etc., and can be set according to actual needs. In addition, in one or more embodiments of this specification, how the main control board determines the target virtual security service component is not limited, and it can be determined according to the content of the security service request. For example, if the security service request includes a globally unique identifier of the virtual security service component, the main control board can directly use the virtual security service component corresponding to the globally unique identifier as the target virtual security service component. If it does not include a globally unique identifier, the main control board can also randomly select a virtual security service component that can be run by the user's configuration from each virtual security service component based on the user's configuration information. It can also select the most efficient virtual security service request from the virtual security service components that can be run by the user's configuration based on the health status of each business board. Since there are many methods that can be used, they will not be repeated here, and can be set according to actual needs.
[0069] based on Figure 2 In the illustrated method for managing a frame-type security resource pool based on lightweight virtualization, the method is applied to the main control board of a frame-type device. By abstracting the resources of the business board into virtual resources, a security resource pool is constructed. After receiving a user's security service request, independent resources are dispatched from the security resource pool to run the target virtual security service component divided from the security function module running on each business board through lightweight virtualization technology, thereby providing security services to the user.
[0070] In the above method, through the combination of software and hardware, frame devices are used to replace the traditional security resource pool built through servers, and through lightweight virtual technology, in the scenario of one cloud and multiple cores, the composition of the security resource pool is simplified, saving the cost of building, operating and maintaining the security resource pool, improving the flexibility and strong scalability of the construction of the security resource pool, and also improving the high availability of the security resource pool. While improving the reliability of security services, security isolation between users is achieved. In addition, resource management, resource scheduling and other management operations are performed through the main control board, and each business board and each security service is managed in a unified manner, further simplifying the composition of the security resource pool.
[0071] In addition, when the main control board builds a security resource pool, since the number of business boards is often large, in order to improve the efficiency of building the security resource pool, the business boards of the frame device can also be connected through a high-speed binding interface. Then the main control board can virtualize each business board into a cloud board card. By abstracting the resources of the cloud board card instead of abstracting the resources of each business board, centralized management of each business board is achieved, the composition of the security resource pool is simplified, and the needs of the one-cloud-multiple-core scenario are met while simplifying management.
[0072] Furthermore, since the software between operating systems of different architectures are incompatible with each other, and the types of operating systems of business boards are often diverse, that is, "one cloud, multiple cores", in order to facilitate the subsequent scheduling of resources in the security resource pool, the main control board can also build a security resource pool of this type for each type of business board based on the virtual resources of this type of business board.
[0073] Furthermore, since different types of business boards run different types of software, the versions of software run by business boards of the same type may also be different. Therefore, in order to simplify the management of the security resource pool, the main control board can also pre-store the business software of each type of business board. When the frame device is started, it accepts the business software acquisition request sent by each business board, and sends the corresponding business software to the corresponding business board based on the business software acquisition request, so that the corresponding business board runs the software corresponding to the business.
[0074] like Figure 3 As shown, Figure 3 A schematic diagram of a process for a lightweight virtualization-based frame-type secure resource pool management method provided in an embodiment of this specification includes the following steps:
[0075] S300: Determine a security function module running on the system, and divide the security function module into at least one logical unit.
[0076] S302: Virtualize the logical unit into a virtual security service component using lightweight virtualization technology, so that when the main control board receives a security service request from a user, it determines at least one target virtual security service component according to the security service request and determines independent resources from a security resource pool.
[0077] To further improve resource utilization and flexibility, the security function modules running on each service board can be divided into multiple logical units. These units are then virtualized using lightweight virtualization technology to identify virtual security service components. This allows the main control board to obtain the user's configuration information and the required security service based on the security service request. Based on the configuration information and security service, the main control board then determines independent resources from the security resource pool and the virtual security service component that can provide the security service. These resources are then run on the service board, providing security services to the user.
[0078] Specifically, the business board divides its own security function modules into multiple logical units to achieve business board security pooling. Using lightweight virtualization technology, each logical unit is virtualized to identify virtual security service components. That is, using lightweight virtualization technology, the business board divides its own security function modules into multiple independent virtual security service components, each of which provides security services to a single user. For example, the security admission, access control, behavior modeling, data exchange, and other security services of the virtual device are virtualized, and then different learning processes and security policy entries are assigned to each virtual device, allowing it to independently occupy software and hardware resources for service processing. This is business plane virtualization.
[0079] The steps of determining independent resources and the method of the target virtual security service component are shown in the above step S304 and will not be repeated here. It should be noted that the above independent resources at least include independent protocol process management resources and independent forwarding resource pools.
[0080] S304: Create and configure a virtual device according to the independent resource, so that the virtual device runs the target virtual security service component based on the independent resource.
[0081] In order to improve the reliability of security services and achieve security isolation between users, the business board can create and configure virtual devices for running target virtual security service components based on independent resources, thereby providing security services to users.
[0082] Specifically, based on the determined independent resources, a virtual device is created, and independently running protocol process management resources are configured for the virtual device. The configuration files, log processes and files corresponding to the virtual device can also be stored independently to achieve independent process restart, configuration recovery, local log storage and external sending functions, which is management plane virtualization.
[0083] It should be noted that the business board can also store file data in a unified manner, and at the same time assign an independent administrator account to the virtual device to independently access and manage the corresponding data. The data files between the virtual devices are not visible.
[0084] In addition, the service board can also allocate an independent forwarding resource pool for the virtual device, where the forwarding resource pool includes resources such as interfaces and addresses. That is, the forwarding control of each virtual device is divided into routing table entries, Layer 2 table entries, sessions, fast forwarding tables, etc., and resources are allocated according to the actual networking, business logic, etc., and is unrelated to other virtual machines, that is, control plane virtualization.
[0085] based on Figure 3In the frame-type security resource pool management method based on lightweight virtualization shown, the method is applied to the business board of the frame-type device. The target virtual security service component divided from the security function module running itself is used to provide security services for the user through lightweight virtualization technology, so that the main control board schedules independent resources from the security resource pool constructed by abstracting the resources of the business board into virtual resources, and is used to create and configure virtual devices based on the independent resources, so that the virtual devices run the target virtual security service components based on the independent resources.
[0086] In the above method, through the combination of software and hardware, frame devices are used to replace the traditional security resource pool built through servers, and through lightweight virtual technology, in the one-cloud-multiple-core scenario, the composition of the security resource pool is simplified, the construction cost of the security resource pool is saved, the flexibility and strong scalability of the construction of the security resource pool are improved, and the high availability of the security resource pool is improved. While improving the reliability of security services, security isolation between users is achieved.
[0087] like Figure 4 As shown, Figure 4 A schematic diagram of a lightweight virtualization technology provided in an embodiment of this specification, that is, after receiving a user's security service request, management plane virtualization, control plane virtualization and service plane virtualization are implemented.
[0088] Based on the above content, this application specification also provides a frame device, which includes at least a main control board and a business board. The frame device is used to deploy and manage a frame security resource pool based on lightweight virtualization, such as Figure 5 As shown, Figure 5 A schematic diagram of the interaction process between the main control board and the service board provided in the embodiment of this application specification is as follows:
[0089] S500: The main control board determines the type and resources of each business board, and abstracts the resources of each business board into virtual resources, and builds a security resource pool according to the type of each business board and the virtual resources, wherein the type of each business board includes the processor architecture type.
[0090] S501: The service board determines a security function module running on the service board, divides the security function module into at least one logical unit, and virtualizes the logical unit into a virtual security service component using lightweight virtualization technology.
[0091] S502: When receiving a security service request from a user, the main control board determines at least one target virtual security service component according to the security service request, and determines an independent resource from the security resource pool.
[0092] S503: The service board virtualizes the logical unit into a virtual security service component using lightweight virtualization technology; creates and configures a virtual device based on the independent resources, so that the virtual device runs the target virtual security service component based on the independent resources.
[0093] In addition, to improve the performance of security services provided to users, the service board of the device can also include at least one hardware accelerator, such as an encryption and decryption chip or a field-programmable gate array (FPGA). This improves the performance of the service board and reduces the relative latency of security services.
[0094] Based on the same idea as the lightweight virtualization-based frame-type security resource pool management method provided in one or more embodiments of this specification, this specification also provides a corresponding lightweight virtualization-based frame-type security resource pool management device, such as Figure 6 shown.
[0095] Figure 6 A schematic diagram of a lightweight virtualization-based frame-type secure resource pool management device provided in this specification specifically includes:
[0096] A pooling module 600 is configured to determine the type and resources of each service board, abstract the resources of each service board into virtual resources, and construct a secure resource pool based on the type of each service board and the virtual resources, wherein the type of each service board includes a processor architecture type;
[0097] Determining module 601, configured to determine a virtual security service component running on each service board, wherein the virtual security service component is determined by dividing the security function module running on each service board into multiple logical units and virtualizing each logical unit using lightweight virtualization technology;
[0098] The resource management module 602 is used to determine at least one target virtual security service component according to the security service request when receiving a user's security service request, and determine independent resources from the security resource pool for running the target virtual security service component.
[0099] Optionally, the business boards are connected via a high-speed binding interface, and the pooling module 600 is used to virtualize the business boards into cloud boards, determine the type and resources of the cloud boards, and abstract the cloud board resources into virtual resources.
[0100] Optionally, the pooling module 600 is configured to construct a security resource pool of each type of service board according to the virtual resources of the service board of that type.
[0101] Optionally, before receiving the user's security service request, the device also includes a storage module 603, which is used to pre-store business software of each type of business board; when the frame device is started, it accepts the business software acquisition request sent by each business board, and sends the corresponding business software to the corresponding business board according to the business software acquisition request, so that the corresponding business board runs the software corresponding to the business.
[0102] Based on the same idea as the lightweight virtualization-based frame-type security resource pool management method provided in one or more embodiments of this specification, this specification also provides a corresponding lightweight virtualization-based frame-type security resource pool management device, such as Figure 7 shown.
[0103] Figure 7 A schematic diagram of a lightweight virtualization-based frame-type secure resource pool management device provided in this specification specifically includes:
[0104] A division module 700 is configured to determine a security function module running on itself and divide the security function module into at least one logical unit;
[0105] a virtualization module 701 configured to virtualize the logical unit into a virtual security service component using lightweight virtualization technology, so that when the main control board receives a security service request from a user, it determines at least one target virtual security service component based on the security service request and determines independent resources from a security resource pool;
[0106] The running module 702 is configured to create and configure a virtual device according to the independent resources, so that the virtual device runs the target virtual security service component based on the independent resources.
[0107] This specification also provides a computer-readable storage medium, which stores a computer program that can be used to execute the above Figure 2 or Figure 3 Provides a positioning method.
[0108] This manual also provides Figure 8 The one shown corresponds to Figure 2 or Figure 3 Schematic diagram of the structure of the electronic equipment. Figure 8 As shown, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include other hardware required for the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to achieve the above Figure 2 or Figure 3 The method for managing a frame-type security resource pool based on lightweight virtualization.
[0109] Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0110] In the 1990s, technological improvements could be clearly distinguished as either hardware improvements (for example, improvements to circuit structures like diodes, transistors, and switches) or software improvements (improvements to process flows). However, with the advancement of technology, many process flow improvements can now be considered direct improvements to hardware circuit structures. Designers almost always create the corresponding hardware circuit structure by programming the improved process flow into the hardware circuit. Therefore, it cannot be said that a process flow improvement cannot be implemented using physical hardware modules. For example, a programmable logic device (PLD), such as a field programmable gate array (FPGA), is an integrated circuit whose logical function is determined by user programming. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to hire a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly performed using software called a "logic compiler." This is similar to the software compilers used during program development. Before compilation, the original code must be written in a specific programming language, called a Hardware Description Language (HDL). There are many types of HDL, including ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art will also understand that simply by programming a method flow in one of these hardware description languages and then programming it into an integrated circuit, a hardware circuit that implements the logic method flow can be easily obtained.
[0111] The controller can be implemented in any suitable manner. For example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the memory control logic. Those skilled in the art will also appreciate that, in addition to implementing the controller purely in computer-readable program code, the controller can also be implemented in the form of logic gates, switches, an application-specific integrated circuit, a programmable logic controller, an embedded microcontroller, etc. by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the means for implementing the various functions included therein can also be considered as structures within the hardware component. Alternatively, the means for implementing the various functions can be considered both a software module implementing the method and a structure within the hardware component.
[0112] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0113] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0114] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, this specification may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0115] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0116] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0117] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0118] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0119] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0120] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0121] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0122] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0123] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.
[0124] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0125] The foregoing is merely an example of the present invention and is not intended to limit the present invention. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be included within the scope of the claims of the present invention.
Claims
1. A frame-type security resource pool management method based on lightweight virtualization, characterized in that: The method is applied to a main control board of a frame-type device, wherein the frame-type device includes at least a main control board and a service board, and specifically includes: Determine the type and resources of each business board, and abstract the resources of each business board into virtual resources, and build a security resource pool according to the type of each business board and the virtual resources, wherein the type of each business board includes a processor architecture type; Determine a virtual security service component running on each of the service boards, wherein the virtual security service component is determined by dividing the security function module running on each of the service boards into a plurality of logical units, and virtualizing each logical unit through a lightweight virtualization technology; When a security service request from a user is received, at least one target virtual security service component is determined according to the security service request, and an independent resource is determined from the security resource pool for running the target virtual security service component.
2. The method according to claim 1, characterized in that The service boards are connected via high-speed binding interfaces; the types and resources of the service boards are determined, and the resources of the service boards are abstracted into virtual resources, specifically including: Virtualizing each of the service boards into a cloud board, and determining the type and resources of the cloud board; The cloud board resources are abstracted into virtual resources.
3. The method according to claim 1, characterized in that According to the types of the service boards and the virtual resources, a security resource pool is constructed, specifically including: For each type of service board, a security resource pool of this type is constructed according to the virtual resources of this type of service board.
4. The method according to claim 1, characterized in that Before receiving the security service request from the user, the method further includes: Pre-storing various types of service software for each service board; When the frame device is started, it accepts the service software acquisition request sent by each service board, and sends the corresponding service software to the corresponding service board according to the service software acquisition request, so that the corresponding service board runs the software corresponding to the service.
5. A frame-type security resource pool management method based on lightweight virtualization, characterized in that: The method is applied to a service board of a frame-type device, wherein the frame-type device includes at least a main control board and a service board, and specifically includes: Determine a security function module running on itself, and divide the security function module into at least one logical unit; The logic unit is virtualized into a virtual security service component through lightweight virtual technology, so that when the main control board receives a security service request from a user, at least one target virtual security service component is determined according to the security service request, and independent resources are determined from a security resource pool, wherein the security resource pool is constructed by the main control board according to the types and virtual resources of each business board, and the virtual resources are obtained by the main control board by abstracting the resources of each business board; A virtual device is created and configured according to the independent resource, so that the virtual device runs the target virtual security service component based on the independent resource.
6. The method according to claim 5, characterized in that The independent resources at least include independent protocol process management resources and an independent forwarding resource pool.
7. A frame-type security resource pool management device based on lightweight virtualization, characterized in that: The device is applied to a main control board of a frame-type device, and the frame-type device at least includes a main control board and several service boards, specifically including: A pooling module, used to determine the type and resources of each business board, and abstract the resources of each business board into virtual resources, and build a security resource pool according to the type of each business board and the virtual resources, wherein the type of each business board includes a processor architecture type; A determination module, used to determine the virtual security service components running on each business board, wherein the virtual security service components are determined by dividing the security function modules running on each business board into multiple logical units and virtualizing each logical unit through lightweight virtualization technology; The resource management module is used to determine at least one target virtual security service component according to the security service request when receiving a security service request from a user, and to determine an independent resource from the security resource pool for running the target virtual security service component.
8. A frame-type security resource pool management device based on lightweight virtualization, characterized in that: The device is applied to a service board of a frame-type device, and the frame-type device includes at least a main control board and several service boards, specifically including: A division module, used for determining a security function module running on itself, and dividing the security function module into at least one logical unit; A virtualization module, used to virtualize the logic unit into a virtual security service component through lightweight virtualization technology, so that when the main control board receives a security service request from a user, it determines at least one target virtual security service component according to the security service request, and determines independent resources from a security resource pool, wherein the security resource pool is constructed by the main control board according to the types and virtual resources of each business board, and the virtual resources are obtained by the main control board by abstracting the resources of each business board; The running module is used to create and configure a virtual device according to the independent resources, so that the virtual device runs the target virtual security service component based on the independent resources.
9. A frame-type device, characterized in that: The frame device includes at least a main control board and a service board, and the frame device is used to deploy and manage a frame security resource pool based on lightweight virtualization, wherein: The main control board is used to determine the type and resources of each business board, and abstract the resources of each business board into virtual resources, and build a security resource pool according to the type of each business board and the virtual resources, wherein the type of each business board includes a processor architecture type; when receiving a user's security service request, determine at least one target virtual security service component according to the security service request, and determine an independent resource from the security resource pool; The business board is used to determine the security function module running on itself, divide the security function module into at least one logical unit, and virtualize the logical unit into a virtual security service component through lightweight virtualization technology; based on the independent resources, create and configure a virtual device so that the virtual device runs the target virtual security service component based on the independent resources.
10. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Method and platform for carrying out service in cloud system of base station
CN104429121A
Network security service system and method
CN112671772A