Secure communication method and device, electronic equipment and nonvolatile storage medium

By obtaining unit information of the computing unit in the large model platform and determining the target key, and combining the Internet protocol security equipment for encrypted communication, the problems of inefficient encryption and decryption and inflexible key management in the prior art are solved, and efficient and secure container communication is achieved.

CN119996006AActive Publication Date: 2025-05-13CHINA TELECOM ARTIFICIAL INTELLIGENCE TECHNOLOGY (BEIJING) CO LTD

Patent Information

Application Number
CN202510162103.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-05-13
Estimated Expiration
2045-02-13

AI Technical Summary

Technical Problem

When dealing with container communication on large-model platform, the prior art has problems such as low encryption and decryption efficiency, inflexible key management, and difficulty in adapting to the dynamic environment of the container.

Method used

By obtaining unit information of the computing unit in the node of the target cluster, determining the target key corresponding to the computing unit, and when the computing unit communicates across the host, it uses Internet protocol security equipment to encrypt it to realize secure communication between computing units in different nodes.

Benefits of technology

It provides an efficient encrypted communication architecture, improves the security and efficiency of cross-host communication of applications on the large-model platform, solves the problems of inefficient encryption and decryption and inflexible key management, and adapts to the dynamic environment of containers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996006A_ABST
    Figure CN119996006A_ABST
Patent Text Reader

Abstract

The invention discloses a secure communication method and device, electronic equipment and a nonvolatile storage medium. The method comprises the steps that unit information corresponding to computing units in nodes of a target cluster is obtained, the target cluster comprises a cluster corresponding to a large model platform, the target cluster comprises a plurality of nodes, and each node comprises a plurality of computing units; target secret keys corresponding to the calculation units are determined according to the unit information of the calculation units, and each calculation unit corresponds to one target secret key; and under the condition that the computing units carry out cross-host communication, encrypting data transmitted by the computing units according to the target secret key by adopting internet protocol security equipment so as to realize secure communication between the computing units in different nodes. According to the method and the device, the technical problems of low encryption and decryption efficiency and inflexible key management when an encryption communication technology in related technologies is used for coping with large model platform container communication are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud computing communication security technology, and more specifically, to a secure communication method, device, electronic device, and non-volatile storage medium. Background Art

[0002] Currently, many AI large-model platforms and big data platforms are based on Kubernetes technology, so their communication security and privacy issues are extremely critical. In Kubernetes, Pod (computing unit) is the smallest deployable unit, and cross-host communication between Pods often involves important tasks such as application interaction and private data transmission. If these communication data lack protection, it may cause serious security incidents such as sensitive data leakage, unauthorized access, and data tampering. Therefore, ensuring the communication security of Pod is of great significance to the overall security and stability of large-model platforms built on Kubernetes technology.

[0003] However, when dealing with large-model platform container communications, the encryption communication technology in related technologies has technical problems such as low encryption and decryption efficiency, inflexible key management, and difficulty in adapting to the dynamic environment of containers.

[0004] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention

[0005] The embodiments of the present application provide a secure communication method, device, electronic device and non-volatile storage medium to at least solve the technical problems of low encryption and decryption efficiency and inflexible key management in the encryption communication technology in the related art when dealing with large model platform container communications.

[0006] According to one aspect of an embodiment of the present application, a secure communication method is provided, including: obtaining unit information corresponding to a computing unit in a node of a target cluster, wherein the target cluster includes a cluster corresponding to a large model platform, the target cluster includes multiple nodes, and each node includes multiple computing units; determining a target key corresponding to the computing unit based on the unit information of the computing unit, wherein each computing unit corresponds to a target key; in the case where the computing unit communicates across hosts, using an Internet Protocol security device to encrypt data transmitted by the computing unit based on the target key to achieve secure communication between computing units in different nodes, wherein each node corresponds to an Internet Protocol security device.

[0007] Optionally, the method also includes: when a change event is detected in a computing unit in a node, updating a target key corresponding to the computing unit based on unit information corresponding to the changed computing unit, wherein the change event includes at least one of the following: destroying the computing unit, creating the computing unit, and updating the computing unit.

[0008] Optionally, before obtaining the unit information corresponding to the computing unit in the node of the target cluster, the method also includes: installing the target cluster and setting a container network interface plug-in for the target cluster, wherein the type of the target cluster includes: a kubernetes cluster, and the container network interface plug-in is used to allocate Internet Protocol addresses to the computing units in the target cluster and manage network communications between the computing units; determining the operating system type corresponding to each node in the target cluster, and configuring a software package corresponding to the operating system type for the node, wherein the software package is used to install an Internet Protocol security device on the operating system corresponding to the node.

[0009] Optionally, the operating system type includes: a target type and a non-target type, wherein the target type includes: an operating system of a Linux distribution; configuring a software package corresponding to the operating system type for the node includes: when the operating system type is the target type, configuring a first software package for the node, wherein the first software package includes at least one of the following: a libreswan software package; when the operating system type is the non-target type, configuring a second software package for the node, wherein the second software package includes at least one of the following: a strongswan software package.

[0010] Optionally, after the node is configured with a software package corresponding to the operating system type, the method further includes: setting the firewall in each node in the target cluster to a closed state to ensure that communication of the Internet Protocol security device in the target cluster is not restricted; or, keeping the firewall open and setting an open User Datagram Protocol port required for the Internet Protocol security device to communicate.

[0011] Optionally, the method also includes: configuring a target encryption algorithm for each node in the target cluster, wherein the target encryption algorithm is used to obtain unit information corresponding to the computing unit in the node through the config configuration of the target cluster, and generate a target key corresponding to the computing unit based on the unit information, wherein the unit information is identification information corresponding to the computing unit, including: Internet Protocol address.

[0012] Optionally, the target key includes: a symmetric key and an asymmetric encryption key; encrypting the data transmitted by the computing unit based on the target key includes: determining the block size based on the data size of the data planned to be transmitted by the computing unit and the system resource load status; dividing the planned transmission data according to the block size to obtain multiple data blocks; using the symmetric key to encrypt the data block to obtain an encrypted data block, wherein each data block corresponds to a symmetric key; using the asymmetric encryption key to encrypt the symmetric key, and sending the encrypted symmetric key and the encrypted data block to the computing unit for calculation and transmission.

[0013] According to another aspect of an embodiment of the present application, a secure communication device is also provided, including: an information acquisition module, used to obtain unit information corresponding to a computing unit in a node of a target cluster, wherein the target cluster includes a cluster corresponding to a large model platform, the target cluster includes multiple nodes, and each node includes multiple computing units; a key determination module, used to determine a target key corresponding to the computing unit based on the unit information of the computing unit, wherein each computing unit corresponds to a target key; an encryption transmission module, used to encrypt data transmitted by the computing unit based on the target key using an Internet Protocol security device when the computing unit communicates across hosts, so as to achieve secure communication between computing units in different nodes, wherein each node corresponds to an Internet Protocol security device.

[0014] According to another aspect of an embodiment of the present application, there is also provided an electronic device, including: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the secure communication method is executed when the program is run.

[0015] According to another aspect of the embodiments of the present application, a non-volatile storage medium is provided, the non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the secure communication method by running the computer program.

[0016] According to another aspect of the embodiments of the present application, a computer program product is provided, including a computer program, which implements the steps of the secure communication method when the computer program is executed by a processor.

[0017] In an embodiment of the present application, the unit information corresponding to the computing unit in the node of the target cluster is obtained, wherein the target cluster includes the cluster corresponding to the large model platform, the target cluster includes multiple nodes, and each node includes multiple computing units; based on the unit information of the computing unit, the target key corresponding to the computing unit is determined, wherein each computing unit corresponds to a target key; in the case where the computing unit communicates across hosts, an Internet Protocol security device is used to encrypt the data transmitted by the computing unit based on the target key to achieve secure communication between computing units in different nodes, wherein each node corresponds to an Internet Protocol security device. Through a simplified and highly universal system architecture and a more secure and efficient target encryption algorithm, an efficient encryption communication architecture is provided, which achieves the purpose of protecting the cross-host communication security of applications on the large model platform based on Kubernetes, thereby solving the technical problems of low encryption and decryption efficiency and inflexible key management in the encryption communication technology in the related technology when dealing with container communication on the large model platform. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0019] Figure 1 It is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a method for secure communication provided in an embodiment of the present application;

[0020] Figure 2 It is a schematic diagram of a method flow of secure communication provided according to an embodiment of the present application;

[0021] Figure 3 It is a schematic diagram of a method flow for encrypting secure communication on a large model platform provided according to an embodiment of the present application;

[0022] Figure 4 is a schematic diagram of a communication architecture in a target cluster provided according to an embodiment of the present application;

[0023] Figure 5 It is a structural diagram of a secure communication device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0026] In order to facilitate those skilled in the art to better understand the embodiments of the present application, some technical terms or nouns involved in the embodiments of the present application are explained as follows:

[0027] Kubernetes: An open source container orchestration engine for automating the deployment, expansion, and management of containerized applications. It can manage containerized applications on multiple hosts and provides functions such as resource scheduling, service discovery, automatic scaling, and rolling updates.

[0028] Cni: A standard network plugin interface that defines a common specification between container runtimes (such as Docker, rkt, etc.) and network plugins. It enables different network solutions (such as Flannel, Calico, etc.) to be easily integrated with container orchestration systems (such as Kubernetes).

[0029] IPsec (Internet Protocol Security): A set of protocol suites used to provide secure IP communications at the network layer. It can encrypt, authenticate, and protect the integrity of IP packets.

[0030] Pod: The smallest deployable and manageable computing unit in Kubernetes.

[0031] In actual operation, after the large model platform creates a Vcjob (Virtual Cluster Job), it will schedule multiple training Pods on the Node nodes in the Kubernetes cluster. During training, a large amount of training data needs to be exchanged when multiple Pods communicate across hosts. In related technologies, for the encryption of cross-host communication between Pods, a service grid method is used to inject a SideCar container into each training Pod, and establish a two-way TLS (Transport Layer Security) configuration between the two services to achieve encrypted communication between services. However, the encryption algorithms in related technologies have many shortcomings in large model scenarios.

[0032] First, from a performance perspective, traditional encryption algorithms have low computational efficiency when processing the encryption and decryption of large amounts of training data. For example, when multiple Pods are exchanging data at the same time, encryption and decryption operations will take up a lot of CPU (Central Processing Unit) resources, resulting in a decrease in the performance of the Pod in processing training tasks. Secondly, key management is not flexible enough. For a dynamically changing Pod environment, key updates and distribution are difficult to be timely and efficient, which can easily lead to security risks, thus affecting overall communication efficiency and security.

[0033] At the same time, the service grid approach also has many disadvantages. Its high degree of autonomy, system complexity, and high system performance overhead have largely limited its widespread application, and its high degree of autonomy has also largely restricted security. For example, the complex architecture of the service grid will have performance bottlenecks when dealing with specific scenarios such as large-model container platforms with tight resources, and due to its complex autonomous logic, once a security vulnerability occurs, it may be difficult to quickly locate and repair it.

[0034] In order to solve the above problems, relevant solutions are provided in the embodiments of the present application, aiming to solve the problems of complexity of the service grid system, high performance overhead and high autonomy limiting security, as well as the encryption algorithms in related technologies having low encryption and decryption efficiency, inflexible key management and difficulty in adapting to the dynamic environment of containers when dealing with large model platform container communications. A detailed explanation is given below.

[0035] According to an embodiment of the present application, an embodiment of a method for secure communication is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0036] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 FIG. 1 shows a hardware structure block diagram of a computer terminal (or electronic device) for implementing a secure communication method. Figure 1 As shown, the computer terminal 10 (or electronic device) may include one or more (102a, 102b, ..., 102n are used to illustrate) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations shown.

[0037] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuits". The data processing circuits may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any of the other components in the computer terminal 10 (or electronic device). As described in the embodiments of the present application, the data processing circuit acts as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0038] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the secure communication method in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, realizing the above-mentioned secure communication method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0039] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0040] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 (or electronic device).

[0041] In the above operating environment, the embodiment of the present application provides a secure communication method. Figure 2 is a schematic diagram of a secure communication method flow according to an embodiment of the present application, such as Figure 2 As shown, the method comprises the following steps:

[0042] Step S202, obtaining unit information corresponding to a computing unit in a node of a target cluster, wherein the target cluster includes a cluster corresponding to a large model platform, the target cluster includes multiple nodes, and each node includes multiple computing units;

[0043] Step S204, determining a target key corresponding to the computing unit according to the unit information of the computing unit, wherein each computing unit corresponds to one target key;

[0044] Step S206, when the computing unit communicates across hosts, an Internet Protocol security device is used to encrypt data transmitted by the computing unit according to a target key to achieve secure communication between computing units in different nodes, wherein each node corresponds to an Internet Protocol security device.

[0045] Through the above steps, through a simplified and highly universal system architecture and a more secure and efficient target encryption algorithm, an efficient encryption communication architecture is provided, which achieves the purpose of protecting the cross-host communication security of applications on a large model platform based on Kubernetes, and further solves the technical problems of low encryption and decryption efficiency and inflexible key management in the encryption communication technology in related technologies when dealing with large model platform container communications.

[0046] The following is a further introduction to the secure communication method in steps S202 to S206 of the embodiment of the present application.

[0047] In the embodiment of the present application, the above-mentioned target cluster is illustrated by taking the Kubernetes cluster corresponding to the large model platform as an example, then the above-mentioned node refers to the Node node in the Kubernetes cluster, and the above-mentioned computing unit refers to the Pod on the Node node; the embodiment of the present application creates an Ipsec device at each Node node, adopts Ipsec tunnel technology and configures a self-developed encryption algorithm to encrypt cross-host container traffic, and transmits it through a physical network; compared with the solution of injecting companion containers and combining traditional encryption algorithms in related technologies, the embodiment of the present application completes communication encryption through a self-developed algorithm at the system network layer, has higher encryption and decryption efficiency and a dynamic key management mechanism, and has zero intrusion on the business, thereby improving communication security while not affecting system performance, which is described in detail below.

[0048] Figure 3 is a schematic diagram of a method flow for encrypting secure communication on a large model platform provided in an embodiment of the present application, such as Figure 3 shown.

[0049] First, install the Kubernetes cluster and deploy related plug-ins. The specific steps are as follows.

[0050] In some embodiments of the present application, before obtaining the unit information corresponding to the computing unit in the node of the target cluster, the method also includes the following steps: installing the target cluster and setting a container network interface plug-in for the target cluster, wherein the type of the target cluster includes: a kubernetes cluster, and the container network interface plug-in is used to assign Internet Protocol addresses to the computing units in the target cluster and manage network communications between the computing units; determining the operating system type corresponding to each node in the target cluster, and configuring a software package corresponding to the operating system type for the node, wherein the software package is used to install an Internet Protocol security device on the operating system corresponding to the node.

[0051] Specifically, you can pre-install the official standard version of the Kubernetes cluster, deploy relevant CNI (Container Network Interface) plug-ins, and do not deploy third-party network components.

[0052] For example, you can use the official tools (such as kubeadm) to install the standard Kubernetes cluster, which includes control plane components (API Server, Controller Manager, Scheduler, etc.) and worker node components (Kubelet, Kube-proxy, etc.); then, deploy a CNI plug-in that supports Kubernetes to ensure that the Pods in the cluster can communicate with each other. The CNI plug-in is responsible for assigning IP addresses to Pods and managing network communications between Pods. At the same time, in this step, no additional third-party network components (such as Istio, Linkerd, and other service meshes) are used. This helps simplify the network architecture and avoid performance or compatibility issues caused by complex network configurations.

[0053] By building the above infrastructure, we can ensure that the Kubernetes cluster can run normally and provide a basic environment for subsequent network configuration. In addition, through the CNI plug-in, we can provide network isolation and communication capabilities for Pods while maintaining the simplicity of the network architecture.

[0054] After that, you can configure the software package corresponding to the operating system type for each node according to the different operating systems of each node in the cluster. The specific steps are as follows.

[0055] In some embodiments of the present application, the operating system type includes: a target type and a non-target type, wherein the target type includes: an operating system of a Linux distribution; configuring a software package corresponding to the operating system type for a node includes: when the operating system type is a target type, configuring a first software package for the node, wherein the first software package includes at least one of the following: a libreswan software package; when the operating system type is a non-target type, configuring a second software package for the node, wherein the second software package includes at least one of the following: a strongswan software package.

[0056] Specifically, depending on the different operating systems corresponding to the nodes in the cluster, in this embodiment, the libreswan software package can be installed on the nodes of RedHat's Linux distribution (ie, the above-mentioned target type), and the strongswan software package can be installed on the nodes running other operating systems (ie, the above-mentioned non-target type).

[0057] Among them, libreswan and strongswan are IPsec implementation software packages optimized for different operating systems. The embodiment of the present application ensures that all nodes in the cluster can stably run IPsec devices by selecting IPsec implementations suitable for different operating systems, thereby supporting encrypted communications across hosts.

[0058] To further ensure smooth communication of IPsec devices, after configuring the software package corresponding to the operating system type on the node, you also need to set up the firewall in the system. The specific steps are as follows.

[0059] In some embodiments of the present application, after the node is configured with a software package corresponding to the operating system type, the method further includes the following steps: setting the firewall in each node in the target cluster to a closed state to ensure that the communication of the Internet Protocol security device in the target cluster is not restricted; or, keeping the firewall open and setting an open User Datagram Protocol port required for the Internet Protocol security device to communicate.

[0060] Specifically, in this embodiment, if the cluster environment permits, the firewall can be completely closed to ensure that IPsec communication is not restricted; alternatively, if the firewall needs to be kept open, the specified UDP (User Datagram Protocol Port) ports required by IPsec need to be opened to ensure that these ports are open on all nodes so that IPsec devices can communicate normally.

[0061] This step ensures smooth communication between IPsec devices and avoids encrypted communication failures caused by firewall restrictions. In addition, while ensuring communication security, you can choose whether to close the firewall according to actual needs to improve the flexibility of the system.

[0062] After that, you can target the encryption algorithm for each node in the cluster as follows.

[0063] In some embodiments of the present application, the method also includes the following steps: configuring a target encryption algorithm for each node in the target cluster, wherein the target encryption algorithm is used to obtain unit information corresponding to the computing unit in the node through the config configuration of the target cluster, and based on the unit information, generate a target key corresponding to the computing unit, wherein the unit information is identification information corresponding to the computing unit, including: Internet Protocol address.

[0064] In this embodiment, the above-mentioned target encryption algorithm can be a self-developed encryption algorithm, which can obtain the Pod information (i.e., the above-mentioned unit information) on the current node through the Kubernetes config configuration, and generate a dynamic key (i.e., the target key) based on the Pod unique identifier.

[0065] Afterwards, the IPsec device can use the dynamic key to authenticate each other between the two nodes in the cluster. When the computing unit communicates across hosts, the data transmitted by the computing unit is encrypted according to the target key to achieve secure communication between computing units in different nodes, ensure the legitimacy of both parties in communication, and prevent illegal nodes from accessing the communication. For example, after the above series of configurations, the communication architecture in the target cluster is as follows: Figure 4 shown.

[0066] The self-developed encryption algorithm in this embodiment is based on the analysis of existing encryption algorithms and is designed in combination with the special needs of large model platform container communication.

[0067] In terms of algorithm structure, the self-developed encryption algorithm in this embodiment is connected to the kubernetes cluster by configuring authentication information, and can monitor the destruction, creation, update and other events of the Pod on the current node in real time to dynamically change the key, which can greatly improve the security of key exchange. The specific steps are as follows.

[0068] In some embodiments of the present application, the method also includes the following steps: when a change event is detected in a computing unit in a node, updating the target key corresponding to the computing unit based on the unit information corresponding to the changed computing unit, wherein the change event includes at least one of the following: destroying the computing unit, creating the computing unit, and updating the computing unit.

[0069] Specifically, in a Kubernetes environment, the life cycle of a Pod is dynamic and may be frequently created, updated, or destroyed. The self-developed encryption algorithm in the embodiment of the present application can monitor these changes in real time, and generate and update keys in a timely manner according to the current state of the Pod. This mechanism ensures that each Pod uses the latest key during operation, thereby reducing the risk of key leakage or cracking. Moreover, by dynamically generating keys, even if a key is leaked at a certain moment, an attacker cannot use the key for illegal access for a long time, because the key will be updated in a short time. This short-life key management strategy greatly improves the security of the key and reduces potential security risks.

[0070] In addition, container communications in large model platforms involve a large amount of highly sensitive data, such as model training data, user privacy data, etc. Although the general encryption algorithms in related technologies can provide certain security guarantees, they may be inefficient or inflexible in key management when faced with the special needs of large model platforms. The encryption algorithm in this embodiment fully considers the usage characteristics of the large model platform when designing. For the common large data block transmission in large model platforms, special block encryption and merged decryption technologies can be used to increase the speed of encryption and decryption. By reducing memory usage and reducing the encryption header information in network transmission, system overhead can be reduced. The details are as follows.

[0071] In some embodiments of the present application, the target key includes: a symmetric key and an asymmetric encryption key; encrypting the data transmitted by the computing unit based on the target key includes the following steps: determining the block size based on the data size of the data planned to be transmitted by the computing unit and the system resource load status; dividing the planned transmission data according to the block size to obtain multiple data blocks; using a symmetric key to encrypt the data block to obtain an encrypted data block, wherein each data block corresponds to a symmetric key; using an asymmetric encryption key to encrypt the symmetric key, and sending the encrypted symmetric key and the encrypted data block to the computing unit for calculation and transmission.

[0072] Specifically, the large data block can be divided into multiple small blocks according to the size of the data to be transmitted and the system resources. For example, each data block can be set to 4MB; a symmetric key (such as an AES key) is generated for each data block. Symmetric encryption algorithms (such as AES) have high encryption and decryption speeds. Each data block is encrypted using the generated symmetric key. The encryption process can be processed in parallel to further improve efficiency; then, the symmetric key is encrypted using an asymmetric encryption algorithm (such as RSA) to ensure secure transmission of the key.

[0073] During data transmission, the encrypted symmetric key can be transmitted together with the encrypted data block and transmitted to the target node through the network to ensure that the receiver can correctly decrypt and merge the data blocks. After receiving the data, the receiver uses the asymmetrically encrypted private key to decrypt the symmetric key, thereby ensuring that only the legitimate receiver can decrypt the symmetric key. The decrypted symmetric key is then used to decrypt each data block. The decryption process can also be processed in parallel to improve efficiency. Finally, the decrypted data blocks are merged in sequence to restore the original data.

[0074] Through this block encryption and combined decryption technology, the encrypted transmission of large data blocks can be efficiently processed while ensuring the security of communication and the integrity of data.

[0075] The following is an example of the process of cross-host container secure communication in the target cluster configured as above.

[0076] Assume that Pod A runs on Node 1 and needs to communicate with Pod B running on Node 2. Pod A can send the request to the network interface of Node 1 through the Kubernetes network plug-in. The IPsec device on Node 1 is configured to intercept all cross-host network traffic. When Pod A's data packets arrive at the network interface of Node 1, the IPsec device captures these data packets. The IPsec device calls the self-developed encryption algorithm to encrypt the data packet. The self-developed encryption algorithm generates a dynamic key based on the unique identifier of Pod A (such as the IP address) and uses the key to encrypt the data packet. The encrypted data packet can contain an additional IPsec header to identify the encrypted information.

[0077] After that, the encrypted data packet is sent from Node 1 to Node 2 through a physical network (such as Ethernet, optical fiber, etc.). After the IPsec device on Node 2 receives the encrypted data packet, it will recognize that this is an IPsec data packet that needs to be decrypted. The IPsec device uses a self-developed encryption algorithm and dynamic key to decrypt the data packet. During the decryption process, the IPsec device verifies the source and integrity of the data packet. This is done by using a dynamic key for authentication to ensure that the data packet does come from a legitimate Node 1. If the authentication fails (for example, the key does not match or the data packet has been tampered with), the data packet will be discarded and the communication will be interrupted. The decrypted data packet is passed to Pod B through the network interface of Node 2. After receiving the data, Pod B can process the request normally, just as it receives any other unencrypted network traffic.

[0078] Through the above process, container communications across hosts are encrypted and authenticated during transmission, ensuring the confidentiality, integrity, and legitimacy of the data. Self-developed encryption algorithms and dynamic key management mechanisms further improve the security of communications, while the interception and processing of IPsec devices at the network layer ensure the transparency and efficiency of the entire process. This design not only protects sensitive data, but also ensures the overall security of container communications on large model platforms.

[0079] This application solution is based on the CNI interface open to Kubernetes, and uses Linux IPsec technology to implement a cross-host communication solution in Kubernetes, and implements a pod encrypted communication solution. Compared to the method of injecting companion containers for encrypted communication in related technologies, this method directly uses existing technical interfaces and protocols at the network layer, avoiding intrusion into the business, and has zero intrusion into the business. While ensuring the security of communications, it will not affect the normal operation of the business, and avoids the problem of interference with business logic or performance due to security measures, greatly improving the overall stability and resource utilization of the large model platform, while improving the security and efficiency of communications;

[0080] In addition, this application scheme is aimed at the common large data block transmission of large model platforms. Based on the self-developed encryption algorithm, it adopts special block encryption and merge decryption technology to improve the efficiency of the encryption algorithm. By configuring the authentication information to connect to the Kubernetes cluster, the destruction, creation, and update of the Pod on the current node are monitored in real time to dynamically change the key and realize the dynamic key management mechanism.

[0081] Among them, the dynamic key management mechanism in the self-developed encryption algorithm can update the key in time according to the dynamic changes of the Pod, prevent the key from being leaked or cracked, and greatly improve the security of key exchange. At the same time, the dynamic key generated based on the Pod information is used for mutual authentication between nodes to ensure the legitimacy of both communicating parties and effectively prevent illegal nodes from accessing the communication. In addition, the use of IPsec equipment combined with the self-developed encryption algorithm at the network layer to encrypt container traffic can provide comprehensive protection against security issues such as data leakage and tampering during network transmission, ensuring the security of container communications on large model platforms.

[0082] The block encryption and combined decryption technology in the self-developed encryption algorithm improves the speed of encryption and decryption, reduces data processing time, and thus improves the performance of container processing training tasks and other services. At the same time, by reducing memory usage and reducing encryption header information in network transmission, the system overhead is reduced, allowing the system to use resources more efficiently and avoid system performance degradation caused by encryption operations.

[0083] According to an embodiment of the present application, an embodiment of a secure communication device is also provided. Figure 5Schematic diagram of a secure communication device provided according to an embodiment of the present application. Figure 5 As shown, the device comprises:

[0084] An information acquisition module 50 is used to acquire unit information corresponding to a computing unit in a node of a target cluster, wherein the target cluster includes a cluster corresponding to a large model platform, the target cluster includes multiple nodes, and each node includes multiple computing units;

[0085] A key determination module 52, configured to determine a target key corresponding to a computing unit according to unit information of the computing unit, wherein each computing unit corresponds to one target key;

[0086] The encryption transmission module 54 is used to use an Internet Protocol security device to encrypt data transmitted by the computing unit according to a target key when the computing unit communicates across hosts, so as to achieve secure communication between computing units in different nodes, wherein each node corresponds to an Internet Protocol security device.

[0087] Optionally, the key determination module 52 is also used to: when a change event is detected in a computing unit in a node, update the target key corresponding to the computing unit based on the unit information corresponding to the changed computing unit, wherein the change event includes at least one of the following: destroying the computing unit, creating the computing unit, and updating the computing unit.

[0088] Optionally, before obtaining the unit information corresponding to the computing unit in the node of the target cluster, the security communication device is also used to: install the target cluster and set a container network interface plug-in for the target cluster, wherein the type of the target cluster includes: a kubernetes cluster, and the container network interface plug-in is used to allocate Internet Protocol addresses to the computing units in the target cluster and manage network communications between the computing units; determine the operating system type corresponding to each node in the target cluster, and configure the software package corresponding to the operating system type for the node, wherein the software package is used to install the Internet Protocol security device on the operating system corresponding to the node.

[0089] Optionally, the operating system type includes: a target type and a non-target type, wherein the target type includes: an operating system of a Linux distribution; configuring a software package corresponding to the operating system type for the node includes: when the operating system type is the target type, configuring a first software package for the node, wherein the first software package includes at least one of the following: a libreswan software package; when the operating system type is the non-target type, configuring a second software package for the node, wherein the second software package includes at least one of the following: a strongswan software package.

[0090] Optionally, after the node is configured with a software package corresponding to the operating system type, the security communication device is also used to: set the firewall in each node in the target cluster to a closed state to ensure that the communication of the Internet Protocol security device in the target cluster is not restricted; or, keep the firewall open and set the User Datagram Protocol port required for the Internet Protocol security device to communicate.

[0091] Optionally, the secure communication device is also used to: configure a target encryption algorithm for each node in the target cluster, wherein the target encryption algorithm is used to obtain unit information corresponding to the computing unit in the node through the config configuration of the target cluster, and generate a target key corresponding to the computing unit based on the unit information, wherein the unit information is identification information corresponding to the computing unit, including: Internet Protocol address.

[0092] Optionally, the target key includes: a symmetric key and an asymmetric encryption key; encrypting the data transmitted by the computing unit based on the target key includes: determining the block size based on the data size of the data planned to be transmitted by the computing unit and the system resource load status; dividing the planned transmission data according to the block size to obtain multiple data blocks; using the symmetric key to encrypt the data block to obtain an encrypted data block, wherein each data block corresponds to a symmetric key; using the asymmetric encryption key to encrypt the symmetric key, and sending the encrypted symmetric key and the encrypted data block to the computing unit for calculation and transmission.

[0093] It should be noted that the various modules in the above-mentioned security communication device can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.

[0094] It should be noted that the secure communication device provided in this embodiment can be used to perform Figure 2 The secure communication method shown, therefore, the relevant explanations and descriptions of the above secure communication method are also applicable to the embodiments of the present application and will not be repeated here.

[0095] An embodiment of the present application also provides a non-volatile storage medium, the non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the following secure communication method by running the computer program: obtaining unit information corresponding to the computing unit in the node of the target cluster, wherein the target cluster includes a cluster corresponding to the large model platform, the target cluster includes multiple nodes, and each node includes multiple computing units; based on the unit information of the computing unit, determining the target key corresponding to the computing unit, wherein each computing unit corresponds to a target key; when the computing unit communicates across hosts, using an Internet Protocol security device, according to the target key, encrypting the data transmitted by the computing unit to achieve secure communication between computing units in different nodes, wherein each node corresponds to an Internet Protocol security device.

[0096] The embodiments of the present application also provide a computer program product, including a computer program, which, when executed by a processor, implements the steps of the secure communication method described in each embodiment of the present application: obtaining unit information corresponding to a computing unit in a node of a target cluster, wherein the target cluster includes a cluster corresponding to a large model platform, the target cluster includes multiple nodes, and each node includes multiple computing units; determining a target key corresponding to the computing unit based on the unit information of the computing unit, wherein each computing unit corresponds to a target key; in the case where the computing unit communicates across hosts, using an Internet Protocol security device to encrypt data transmitted by the computing unit based on the target key to achieve secure communication between computing units in different nodes, wherein each node corresponds to an Internet Protocol security device.

[0097] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0098] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0099] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units can be a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0100] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0101] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0102] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.

[0103] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A secure communication method, characterized in that: include: Obtain unit information corresponding to a computing unit in a node of a target cluster, wherein the target cluster includes a cluster corresponding to a large model platform, the target cluster includes a plurality of the nodes, and each of the nodes includes a plurality of the computing units; Determining a target key corresponding to the computing unit according to the unit information of the computing unit, wherein each computing unit corresponds to one target key; When the computing unit communicates across hosts, an Internet Protocol security device is used to encrypt data transmitted by the computing unit based on the target key to achieve secure communication between the computing units in different nodes, wherein each node corresponds to one Internet Protocol security device.

2. The secure communication method according to claim 1, characterized in that: The method further comprises: When a change event is detected in the computing unit in the node, the target key corresponding to the computing unit is updated based on the unit information corresponding to the changed computing unit, wherein the change event includes at least one of the following: destroying the computing unit, creating the computing unit, and updating the computing unit.

3. The secure communication method according to claim 1, characterized in that: Before obtaining unit information corresponding to the computing unit in the node of the target cluster, the method further includes: Install the target cluster and set a container network interface plug-in for the target cluster, wherein the type of the target cluster includes: a Kubernetes cluster, and the container network interface plug-in is used to allocate Internet Protocol addresses to the computing units in the target cluster and manage network communications between the computing units; Determine the operating system type corresponding to each of the nodes in the target cluster, and configure a software package corresponding to the operating system type for the node, wherein the software package is used to install the Internet Protocol security device on the operating system corresponding to the node.

4. The secure communication method according to claim 3, characterized in that: The operating system type includes: a target type and a non-target type, wherein the target type includes: an operating system of a Linux distribution; and configuring a software package corresponding to the operating system type for the node includes: In the case where the operating system type is the target type, configuring a first software package for the node, wherein the first software package includes at least one of the following: a libreswan software package; In a case where the operating system type is the non-target type, a second software package is configured for the node, wherein the second software package includes at least one of the following: a strongswan software package.

5. The secure communication method according to claim 3, characterized in that: After the node is configured with a software package corresponding to the operating system type, the method further includes: Setting the firewall in each of the nodes in the target cluster to a closed state to ensure that the communication of the Internet Protocol security device in the target cluster is not restricted; Alternatively, the firewall is kept turned on, and a user datagram protocol port required for the Internet Protocol security device to communicate is set to be opened.

6. The secure communication method according to claim 1, characterized in that: The method further comprises: Configure a target encryption algorithm for each of the nodes in the target cluster, wherein the target encryption algorithm is used to obtain the unit information corresponding to the computing unit in the node through the config configuration of the target cluster, and generate the target key corresponding to the computing unit based on the unit information, wherein the unit information is identification information corresponding to the computing unit, including: Internet Protocol address.

7. The secure communication method according to claim 1, characterized in that: The target key includes: a symmetric key and an asymmetric encryption key; encrypting the data transmitted by the computing unit according to the target key includes: Determining a block size according to the data size of the data planned to be transmitted by the computing unit and a system resource load status; Dividing the data to be transmitted according to the block size to obtain multiple data blocks; Using the symmetric key, encrypt the data block to obtain an encrypted data block, wherein each data block corresponds to one symmetric key; The asymmetric encryption key is used to encrypt the symmetric key, and the encrypted symmetric key and the encrypted data block are sent to the computing unit for computing transmission.

8. A secure communication device, characterized in that: include: An information acquisition module, used to acquire unit information corresponding to a computing unit in a node of a target cluster, wherein the target cluster includes a cluster corresponding to a large model platform, the target cluster includes a plurality of the nodes, and each of the nodes includes a plurality of the computing units; A key determination module, configured to determine a target key corresponding to the computing unit according to the unit information of the computing unit, wherein each computing unit corresponds to one target key; An encryption transmission module is used to use an Internet Protocol security device to encrypt data transmitted by the computing unit according to the target key when the computing unit communicates across hosts, so as to achieve secure communication between the computing units in different nodes, wherein each node corresponds to an Internet Protocol security device.

9. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the program executes the secure communication method according to any one of claims 1 to 7 when running.

10. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the secure communication method according to any one of claims 1 to 7 by running the computer program.

11. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the secure communication method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Automatic encryption system for data in container

    CN115935380A

  • Key management method and device, storage medium and computer equipment

    CN117081839A

  • Multi-layer data privacy protection method based on hybrid chain encryption protocol

    CN117527233A

  • Real-time communication application-oriented dynamic management firewall policy system and method

    CN117614733A

  • Automatic encryption for cloud native workloads

    CN118176699A

Cited By

  • Method and device for encrypting and decrypting integrated hardware of DPU (Data Processing Unit) centralized sunken service grid and electronic equipment

    CN120561978A

  • Secure communication method and apparatus, electronic device and non-volatile storage medium

    WO2026170758A1