Hyper-converged platform based on hardware isolation of multiple systems and method for forming same

Through hardware isolation and hyperconvergence technology, multi-core server nodes are isolated into multiple system domains, solving the flexible recovery and resource chaos of the hyperconvergence platform in the event of abnormality, and achieving efficient resource management and security improvement.

CN120090920BActive Publication Date: 2025-07-08KYLIN CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510527619.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-07-08
Estimated Expiration
2045-04-25

AI Technical Summary

Technical Problem

The existing hyperconvergence technology cannot be flexibly restored when server nodes are abnormal, resource usage is chaotic, operating systems cannot fully perform their performance in multi-GPU environments, and software complexity is high.

Method used

The hyperconverged platform that is hardware isolated from multiple systems is used to isolate multi-core server nodes into multiple isolated service system domains through hardware isolation virtualization technology. Each domain runs a different operating system. It uses hyperconverged management components to manage resources uniformly, and connects to various domains through a shared network to achieve flexible scheduling and abnormal recovery of resources.

Benefits of technology

It improves the server node's ability to manage service resources, reduces the difficulty of resource use and deployment complexity, improves the security of hardware resources and data, and enhances the diversity and stability of server deployment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090920B_ABST
    Figure CN120090920B_ABST
Patent Text Reader

Abstract

The present invention relates to a hyper-converged platform based on hardware isolation of multiple systems and a formation method. Among them, the hyper-converged platform includes multiple hyper-converged isolated multi-core server nodes, and the multiple hyper-converged isolated multi-core server nodes form a hyper-converged platform through a network switch; each hyper-converged isolated multi-core server node includes a multi-core server and multiple isolated service system domains; the multiple isolated service system domains are formed by the multi-core server through hardware isolation virtualization technology, different operating systems are run on each isolated service system domain, and each isolated service system domain is interconnected through a shared network. The present invention greatly improves the management ability of the server node for service resources, reduces the difficulty of using service resources, reduces the complexity of service deployment, improves the diversity and flexibility of server deployment, and saves hardware resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of virtualization technology, and in particular to a hyper-converged platform based on hardware isolation of multiple systems and a method for forming the same. Background Art

[0002] Servers usually use multi-core, high computing performance, high network bandwidth, and high storage. Hyperconvergence is an IT infrastructure architecture that integrates multiple components such as computing, storage, network, and virtualization into a single, easy-to-manage system, and adds more applications and services on this basis. The hyper-converged infrastructure consists of multiple nodes, each node having computing, storage, and network functions. These nodes form a cluster through software-defined virtualization technology and can be scaled to hundreds of nodes. Harvester is a modern, open, and interoperable hyper-converged infrastructure (HCI) solution based on Kubernetes.

[0003] Hardware isolation methods such as jailhouse can isolate multiple system domains on a multi-core SOC through virtualized hardware isolation methods to run different systems. At the same time, different system domain network communications can be achieved through network sharing technology.

[0004] Hyperconvergence technology can connect different server nodes together through a network and uniformly use resources such as computing units, storage, network, and virtualization. However, when a server node fails, it is not possible to flexibly recover the corresponding abnormal node. At the same time, the resources such as computing units, storage, network, and virtualization corresponding to a service node may need to be used by multiple users, and the hyperconvergence method will cause chaos in resource usage. Hardware isolation of multiple system domains runs multiple isolated operating systems, and the coordination and use of resources between each operating system lack unified scheduling. A server node can access multiple GPUs to improve computing performance. However, when the number of GPUs is too large, the operating system cannot fully utilize the performance of the corresponding multiple GPUs, and the complexity of GPU-related hyperconvergence software increases significantly. Summary of the Invention

[0005] To solve the deficiencies of the existing technology, the present invention provides a hyper-converged platform based on hardware isolation of multiple systems, including multiple hyper-converged isolated multi-core server nodes, and the multiple hyper-converged isolated multi-core server nodes form a hyper-converged platform through a network switch;

[0006] Each hyper-converged isolated multi-core server node includes a multi-core server and multiple isolated service system domains; wherein, the multiple isolated service system domains are isolated by the multi-core server through hardware isolation virtualization technology, different operating systems are run on each isolated service system domain, and each isolated service system domain is interconnected through a shared network;

[0007] Each isolated service system domain includes a hyper-converged isolation management component, service resources, and hyper-converged components. The hyper-converged management component collects and prepares the service resources of this isolated service system domain and starts the hyper-converged components of this isolated service system domain; the hyper-converged components connect the isolated service system domains to each other through a shared network;

[0008] The multiple isolated service system domains include an isolated primary service system domain and isolated secondary service system domains, and the isolated secondary service system domains are created by the isolated primary service system domain.

[0009] Among them, the service resources of each isolated service system domain include computing unit resources, storage resources, network resources, and virtualization resources. The service resources are managed by the hyper-converged isolation management component, and at the same time, the use of service resources by the isolated service system domain is monitored.

[0010] Among them, the hyper-converged isolation management component of the isolated primary service system domain can manage the hyper-converged isolation management components of each isolated secondary service system domain. At the same time, each hyper-converged isolation management component of the isolated primary service system domain has a priority, and the hyper-converged isolation management component with a higher priority can manage the hyper-converged isolation management component with a lower priority.

[0011] Among them, the hyper-converged isolation management component manages and controls whether the isolated service system domain accesses the hyper-converged platform, and the isolated service system domain that has not accessed the hyper-converged platform has an independent operation function.

[0012] Among them, the isolated service system domain corresponding to each hyper-converged isolated multi-core server node can access multiple hyper-converged platforms, and the hyper-converged isolation management component of the isolated service system domain controls its isolated service system domain to access different hyper-converged platforms.

[0013] Among them, the hyper-converged isolation management component of each isolated service system domain can virtualize the service resources of other hyper-converged isolated multi-core server nodes into virtual devices through virtualization technology and make them available for other isolated service system domains of this hyper-converged isolated multi-core server node through sharing technology.

[0014] Among them, each isolated secondary service system domain determines whether it can be managed by the hyper-converged isolation management component of other isolated service system domains through the configuration file of the hyper-converged isolation management component within this system domain.

[0015] Among them, when the hyper-converged isolation management component detects an abnormality in other isolated service system domains, it can choose to recover the corresponding abnormal isolated service system domain.

[0016] Among them, each hyper-converged isolation management component can manage the hyper-converged components of this isolated service system domain to control the service resource permissions of this isolated service system domain, and the permissions include read-only, write-only, invisible, and readable and writable.

[0017] The present invention further provides a method for forming a hyper-converged platform based on hardware isolation of multiple systems, comprising the following steps:

[0018] Step S1: Isolate the hardware resources of a multi-core server into multiple different isolated service system domains through hardware isolation technology, and run different operating systems on each isolated service system domain;

[0019] Step S2: The operating system running on each isolated service system domain loads the hyper-converged isolation management component of this isolated service system domain. The hyper-converged isolation management component collects and prepares the service resources of this isolated service system domain, and starts the hyper-converged component of this isolated service system domain;

[0020] Step S3: The hyper-converged components of each isolated service system domain are interconnected through a shared network to form a hyper-converged isolated multi-core server node, and multiple hyper-converged isolated multi-core server nodes form a hyper-converged platform through a network switch.

[0021] The hyper-converged platform based on hardware isolation of multiple systems and the method for forming the same provided by the present invention integrate the resources of different server nodes by uniformly managing the computing, storage, communication, etc. of the isolated service system domains, greatly improving the management ability of server nodes for service resources, reducing the difficulty of resource use, lowering the complexity of service deployment, enhancing the diversity of server deployment, and saving hardware resources; at the same time, the isolation method provides the security of the hardware devices and data of the server nodes, enhances the protection ability for hardware resources and data, and further decouples the corresponding service resources. Description of the Drawings

[0022] Figure 1 It is a logical architecture diagram of a hyper-converged isolated multi-core server node of a hyper-converged platform based on hardware isolation of multiple systems according to the present invention.

[0023] Figure 2 It is a logical architecture diagram of a hyper-converged platform based on hardware isolation of multiple systems according to the present invention. Detailed Embodiments

[0024] In order to have a further understanding of the technical solutions and beneficial effects of the present invention, the technical solutions of the present invention and the beneficial effects produced thereby will be described in detail below with reference to the accompanying drawings.

[0025] Figure 1 It is a logical architecture diagram of a hyper-converged isolated multi-core server node of a hyper-converged platform based on hardware isolation of multiple systems provided by the present invention, Figure 2 It is a logical architecture diagram of a hyper-converged platform based on hardware isolation of multiple systems provided by the present invention. Please refer to Figure 1 andFigure 2 As shown, a hyper-converged platform based on hardware isolation of multiple systems provided by the present invention includes multiple hyper-converged isolated multi-core server nodes (the hyper-converged isolated multi-core server nodes are server nodes with hyper-converged functions, corresponding to Figure 2 the hyper-converged isolated multi-core server node 0, hyper-converged isolated multi-core server node 1, hyper-converged isolated multi-core server node n, and non-isolated hyper-converged server node n in Figure 2 ). Each hyper-converged isolated multi-core server node includes a multi-core server and multiple isolated service system domains (corresponding to Figure 2 the isolated service system domain 0, isolated service system domain 1, and isolated service system domain n in

[0026] ). At the same time, the isolated service system domain with hyper-converged function can be used as a hyper-converged server node (corresponding to

[0027] the hyper-converged server node 0, hyper-converged server node 1, and hyper-converged server node n in

[0028] ). Among them, multiple isolated service system domains are isolated by the multi-core server through hardware isolation virtualization technology. Different operating systems are run on each isolated service system domain, and each isolated service system domain is interconnected through a shared network; each isolated service system domain includes a hyper-converged isolation management component, service resources, and hyper-converged components. The hyper-converged isolation management component collects and prepares the service resources of the isolated service system domain where it is located, and starts the hyper-converged components of the isolated service system domain where it is located; the hyper-converged components connect each isolated service system domain to each other through a shared network; multiple isolated service system domains include an isolated primary service system domain and an isolated secondary service system domain, and the isolated secondary service system domain is created by the isolated primary service system domain.

[0029] The corresponding isolated service system domain can be connected to the hyper-converged platform through a network (including physical resources and shared networks). By means of hardware isolation, a hyper-converged isolated multi-core server node is isolated into multiple isolated service system domains, as opposed to dividing a hyper-converged isolated multi-core server node into multiple hyper-converged server nodes by software means. That is, an isolated service system domain is a hyper-converged server node and can be flexibly connected to the hyper-converged platform.

[0030] In the present invention, hardware isolation technology can adopt virtualization technologies such as jailhouse. Through hardware isolation technology, resources such as server kernels, GPUs, memory, disks, and hardware peripherals are isolated into different isolated service system domains, so that different isolated service system domains provide different service resources, specifically involving computing unit resources, storage resources, network resources, and virtualization resources, etc.

[0031] In the present invention, different isolated service system domains can run different operating systems. As Figure 1 shown, operating systems such as centos, ubuntu, kylin, and Windows can run on different isolated service system domains to provide isolated ubuntu service systems, isolated kylin service systems, and isolated windows service systems respectively, giving full play to the server hardware functions according to the characteristics of different operating systems.

[0032] In the present invention, the multiple isolated service system domains isolated include an isolated main service system domain and an isolated slave service system domain, and the isolated slave service system domain is created by the isolated main service system domain.

[0033] 2. The operating systems running on each isolated service system domain load and run the hyper-converged isolation management component on this isolated service system domain. The hyper-converged isolation management component collects and prepares the service resources (including computing unit resources, storage resources, network, and virtualization resources, etc.) on this isolated service system domain, and starts the hyper-converged component of this isolated service system domain.

[0034] In the present invention, the hyper-converged component is a service component required to run the hyper-converged platform, such as Harvester, qemu, Kvm, etc.

[0035] In the present invention, each hyper-converged isolation management component can manage the hyper-converged component of this isolated service system domain to control the service resource permissions of this isolated service system domain, and the permissions include read-only, write-only, invisible, and readable and writable. The service resources are managed by the hyper-converged isolation management component, and at the same time, the use of service resources by the isolated service system domain is monitored.

[0036] Furthermore, the hyper-converged isolation management component calls the hyper-converged component to set the corresponding isolated service system domain as a hyper-converged server node with hyper-converged functions.

[0037] Furthermore, each hyper-converged isolation management component isolating the main service system domain has a priority. The hyper-converged isolation management component with a higher priority can manage the hyper-converged isolation management component with a lower priority.

[0038] The hyper-converged isolation management component manages and controls whether the isolated service system domain accesses the hyper-converged platform. The isolated service system domain that has not accessed the hyper-converged platform has an independent operation function. If the corresponding isolated service system domain has hardware network resources, it can access the hyper-converged platform through the corresponding network resources or the shared network via a switch. If the corresponding isolated service system domain does not have hardware network resources, it can access the hyper-converged platform through the shared network. After the corresponding isolated service system domain accesses the hyper-converged platform, it can be interconnected with all isolated multi-core server nodes and other isolated service system domains of the hyper-converged platform.

[0039] Furthermore, the isolated service system domain corresponding to a hyper-converged isolated multi-core server node can access multiple hyper-converged platforms, that is, the hyper-converged isolation management component of the isolated service system domain controls the hyper-converged components to access different hyper-converged platforms.

[0040] Still further, the hyper-converged isolation management component of the isolated service system domain that accesses the hyper-converged platform can virtualize the service resources of other isolated multi-core server nodes into virtual devices through virtualization technology and make them available for other isolated service system domains of this isolated multi-core server node that have not accessed the hyper-converged platform through sharing technology, so that the isolated service system domains that have not accessed the hyper-converged platform can use the service resources in other isolated multi-core server nodes.

[0041] The method of virtualizing the service resources of other isolated multi-core server nodes of the hyper-converged platform into virtual devices for other isolated service system domains of this isolated multi-core server node includes:

[0042] (1) The hyper-converged isolation management component of a certain isolated service system domain (which needs to be an isolated service system domain that accesses the hyper-converged platform) of this isolated multi-core server node applies for the service resources of other isolated multi-core server nodes and virtualizes the corresponding service resources into virtual devices through virtualization technology;

[0043] (2) A certain isolated service system domain of this isolated multi-core server node shares the virtual device to other isolated service system domains of this isolated multi-core server node through device sharing technology, that is, it can conveniently virtualize the service hardware resources of other isolated multi-core server nodes into hardware resources and share them to other isolated service system domains in this isolated multi-core server node that have not accessed the hyper-converged platform for other isolated service system domains in this isolated multi-core server node that have not accessed the hyper-converged platform to process desktop displays, real-time tasks, etc.

[0044] Specifically, the steps for virtualizing and sharing the GPU devices of other isolated multi-core server nodes through hyper-convergence technology include:

[0045] (1) The hyper-convergence isolation management component of a certain isolation service system domain (which needs to be an isolation service system domain connected to the hyper-convergence platform) in this isolated multi-core server node applies for the GPU computing unit resources of other isolated multi-core server nodes, and virtualizes the corresponding GPU computing resources into GPU virtual devices through GPU virtualization technology;

[0046] (2) A certain isolation service system domain in this isolated multi-core server node shares the GPU virtual device to the desktop operating systems of other isolation service system domains in this isolated multi-core server node that are not connected to the hyper-convergence platform through GPU device sharing technology. The desktop operating systems of other isolation service system domains in this isolated multi-core server node that are not connected to the hyper-convergence platform use the GPU hardware resources of other isolated multi-core server nodes by using the GPU virtual device.

[0047] 3. The hyper-convergence components on each isolation service system domain in each isolated multi-core server node establish connections through a shared network, so that the isolation service system domains in multiple isolated multi-core server nodes form a hyper-convergence platform. Thus, the service resources on each isolation service system domain can be uniformly scheduled and used by using the hyper-convergence method.

[0048] Furthermore, the hyper-convergence components form a hyper-convergence platform for each isolation service system domain in each isolated multi-core server node through a shared network. The hyper-convergence platform of the present invention can achieve the following technical functions:

[0049] (1) The hyper-convergence isolation management components of each isolation service system domain can communicate through a shared network. The hyper-convergence isolation management component of the isolation main service system domain can manage the hyper-convergence isolation management components of each isolation slave service system domain; whether each isolation slave service system domain can be managed by the hyper-convergence isolation management components of other isolation service system domains is determined by the configuration file of the hyper-convergence isolation management component within this system domain;

[0050] (2) In addition to being able to collect the service resources of the operating systems running in this isolation service system domain, each hyper-convergence isolation management component can also conveniently use the special service resources (including but not limited to computing unit resources, storage resources, network resources, virtualization resources, hardware device resources, etc.) of other different isolation service system domains through hyper-convergence technology;

[0051] (3) Each hyper-convergence isolation management component can detect the running status of each isolation service system domain. When an abnormality is detected in an isolation service system domain other than this isolation service system domain, it can choose to restore the running state of the abnormal isolation service system domain;

[0052] Specifically, the method for abnormal recovery of the hyper-converged isolation service system domain is as follows:

[0053] a: The hyper-converged isolation management components of each isolation service system domain regularly send operation status data packets to the hyper-converged isolation management components of other isolation service system domains with higher priorities through the network;

[0054] b: The hyper-converged isolation management components of the isolation service system domain with a higher priority can actively query or receive the operation status data packets of the hyper-converged isolation management components of other isolation service system domains;

[0055] c: The hyper-converged isolation management components of the isolation service system domain with a higher priority rotate to recover the operation status of the abnormal isolation service system domain through the operation status data packets. For example, when detecting or not receiving the operation status data packets of the hyper-converged isolation management components of the corresponding isolation service system domain with a lower priority for a long time, the operation of the corresponding abnormal isolation service system domain can be recovered by restarting the isolation service system domain with a lower priority;

[0056] d: The operation status includes that a certain system service running on the operating system in the corresponding isolation service system domain is abnormal, or the operating system freezes or crashes.

[0057] (4) Each hyper-converged isolation management component can transmit the corresponding hardware resources to different isolation service system domains through virtualization and passthrough technologies. That is, the hyper-converged platform can be used to passthrough different hardware resources between different isolation service system domains to increase the flexibility, real-time performance, and sharing of hardware resource usage between different isolation service system domains.

[0058] Furthermore, service resources can be transmitted to different isolation service system domains and different hyper-converged platforms through virtualization and passthrough technologies. For example, multiple GPUs can be isolated to different isolation service system domains through virtualization and hardware isolation methods, and each isolation service system domain uses the appropriate corresponding GPU device, which greatly improves the utilization of multi-GPU performance by the hyper-converged platform for isolating multi-core server nodes and reduces the difficulty of using the hyper-converged platform to access multi-GPUs for multi-core server nodes; at the same time, multiple hyper-converged platforms can flexibly use the idle GPU resources.

[0059] Furthermore, a hyper-converged isolated multi-core server node can form a hyper-converged platform alone. For example, the corresponding hyper-converged isolated multi-core server node is isolated into multiple isolation service system domains and multiple hyper-converged server nodes, and each hyper-converged server node runs the hyper-converged component and the hyper-converged isolation management component, and forms a hyper-converged platform alone through the shared network.

[0060] It should be noted that the Figure 1 and Figure 2In this case, only one hyper-converged platform is shown. In fact, each isolated service system domain of each isolated multi-core server node can be used by multiple hyper-converged platforms. In other words, multiple isolated service system domains formed through hardware isolation can not only be arranged and combined into different isolated multi-core server nodes with each other, but also be arranged and formed into different hyper-converged platforms.

[0061] In summary, the present invention forms the decoupling of the hardware resources of the isolated multi-core server node and the coupling of the service resources of each isolated service system domain through hardware isolation and hyper-convergence technology. In specific application scenarios, the following technical effects can be achieved:

[0062] 1. Since a server node may have hundreds, thousands or even tens of thousands of processor cores, and at the same time, a server node not only needs hyper-convergence but also needs to process other tasks. By using the hardware isolation method to isolate multiple isolated service system domains and enabling different isolated service system domains to flexibly access each hyper-converged platform or detach from each hyper-converged platform to process other tasks, the multi-core hardware resources of the server node are flexibly and fully utilized, greatly improving the richness and diversity of the server node deployment and reducing the deployment difficulty of different functional system domains. For example, a server node isolates multiple isolated service system domains through the hardware isolation method. Some of the isolated service system domains process desktop display, real-time tasks, etc., and some of the isolated service system domains use hyper-convergence technology and flexibly access the hyper-converged platform. At the same time, the corresponding server node is not limited to accessing one hyper-converged platform.

[0063] 2. When a certain isolated service system domain does not use computing resources, the corresponding computing resources can be released or passed through virtualization and passthrough technology to other isolated service system domains. For example, when it is detected that the computing resources corresponding to the hyper-converged isolated service system domain are not in use, the corresponding computing resources are released or passed through to other isolated service system domains that process desktop display or real-time tasks, solving the difficulty that the server node cannot process real-time tasks through hybrid deployment; when the hyper-converged isolated service system domain needs to use the corresponding computing resources, the corresponding computing resources are recycled for the corresponding isolated service system domain to use, greatly improving the utilization rate and management ability of the computing resources.

[0064] 3. When a certain isolated service system domain runs abnormally or crashes abnormally, other isolated service system domains can recover the abnormally crashed isolated service system domain, avoiding the situation that the server node can only be restored physically after only one operating system runs abnormally and crashes, greatly improving the stability of the isolated hyper-converged operating system;

[0065] 4. Through hyper-convergence technology, virtualization technology, and device sharing technology, the service hardware resources of other server nodes can be easily virtualized into hardware resources and shared to the isolated service system domain that is not connected to the hyper-convergence platform for other hyper-convergence platforms or the isolated service system domain that is not connected to the hyper-convergence platform to process desktop displays, real-time tasks, etc.

[0066] That is, a hyper-convergence platform based on hardware isolation of multiple systems provided by the present invention isolates the hardware resources of server nodes into different systems through hardware isolation technology, and at the same time uniformly manages the computing, storage, communication, etc. of the isolated service system domain through hyper-convergence technology, integrating the resources of different server nodes, greatly improving the management ability of server nodes for service resources, reducing the difficulty of resource use, reducing the complexity of service deployment, enhancing the diversity of server deployment, and saving hardware resources; at the same time, through the isolation method, the security of the hardware devices and data of the server nodes is provided, enhancing the protection ability for hardware resources and data, and further decoupling the corresponding service resources.

[0067] A hyper-convergence method and system based on hardware isolation of multiple systems of the present invention are as Figure 1 The construction method of a specific embodiment can include the following steps.

[0068] 1. The isolated ubuntu service system in the isolated main service system domain isolates resources such as the server kernel, GPU, memory, disk, and hardware peripherals into different isolated service system domains through the hardware isolation method according to requirements, and runs different operating systems such as the windows system and the kylin system in different isolated service system domains.

[0069] 2. The isolated operating systems running in each isolated service system domain load and run the hyper-convergence isolation management components. Each hyper-convergence isolation management component collects and prepares resources such as computing units, storage, networks, and virtualization, and starts the hyper-convergence components. For example, the isolated ubuntu service system, the isolated kylin service system, and the isolated windows service system run their respective hyper-convergence isolation management components, collect the service resource information corresponding to the operating systems running in this isolated system domain, and hand over the resources such as computing units, storage, networks, and virtualization to the hyper-convergence components according to the set permissions.

[0070] 3. The hyper-convergence components corresponding to the isolated service system domains set permissions and priorities and use a shared network to connect different isolated service system domains to establish connections between the isolated service system domains. For example, the hyper-convergence components of the isolated ubuntu service system, the isolated kylin service system, and the isolated windows service system communicate with each other using the shared network, and connections are established between the isolated service systems.

[0071] 4. The isolated Ubuntu service system, the isolated Kylin service system, and the isolated Windows service system form an isolated multi-core server node (multiple isolated multi-core server nodes form a hyper-converged platform) through a shared network with the help of hyper-converged components. They can organize the resources such as computing units, storage, network, and virtualization obtained from their respective system domain hyper-converged isolation management components, and can uniformly schedule and use service resources with the help of a hyper-converged terminal. For example, the corresponding computing resources are allocated to the three isolated systems, namely the isolated Ubuntu service system, the isolated Kylin service system, and the isolated Windows service system, using the hyper-converged method. The relevant data of the corresponding hyper-converged platform can also be stored in different isolated service systems.

[0072] 5. The hyper-converged isolation management component can manage the disconnection of the hyper-convergence of the corresponding isolated service system domain. For example, the isolated Windows service system running in the isolated slave service system domain disconnects the hyper-convergence connection and only provides Windows office functions. The isolated Kylin service system running in the isolated slave service system domain disconnects the hyper-convergence and uses isolated peripherals to only provide the corresponding industrial control functions. When the isolated Kylin service system and the isolated Windows service system in the isolated slave service system domain need to access the hyper-converged platform again, the corresponding hyper-converged isolation management components of the isolated Kylin service system and the isolated Windows service system call the hyper-converged components to set the isolated Kylin service system and the isolated Windows service system as hyper-converged server nodes with the function of accessing the hyper-converged platform, and control the corresponding hyper-converged server nodes to reconnect to the hyper-converged platform.

[0073] 6. Through the hyper-converged isolation management component, the service resources in the isolated service system domain can be selectively accessed to the hyper-converged platform. For example, through the jailhouse isolation recipe, the corresponding shared resources of the isolated Kylin service system and the isolated Windows service system are shared out, and the corresponding isolated resources are hidden. It provides a method for organizing service resources between isolated multi-systems through the hyper-converged method, getting rid of the bondage of the isolation recipe.

[0074] 7. The isolated Ubuntu service system, the isolated Kylin service system, and the isolated Windows service system are independent operating systems. Each operating system can form different isolated multi-core server nodes and hyper-converged platforms through the network. For example, the isolated Ubuntu service system and the isolated Kylin service system form an isolated multi-core server node, or each system in the isolated Ubuntu service system and the isolated Kylin service system can be networked with other isolated multi-core server nodes to form 3 hyper-converged platforms.

[0075] 8. Give full play to the functions of different systems through the isolated multi-system method and make full use of the hardware functions. For example, the use of the N card GPU in Windows, the secure network function of Kylin, and the computing function of Ubuntu.

[0076] Although the present invention has been described by using the above preferred embodiments, it is not intended to limit the protection scope of the present invention. Any person skilled in the art can make various changes and modifications to the above embodiments without departing from the spirit and scope of the present invention, and these still fall within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be defined by the claims.

Claims

1. A hyper-converged platform based on hardware isolation for multiple systems, characterized in that: It includes multiple hyper-converged isolated multi-core server nodes, and the multiple hyper-converged isolated multi-core server nodes form a hyper-converged platform through a network switch; Each hyper-converged isolated multi-core server node includes a multi-core server and multiple isolated service system domains; among them, the multiple isolated service system domains are isolated by the multi-core server through hardware isolation virtualization technology, and different operating systems are run on each isolated service system domain, and each isolated service system domain is interconnected through a shared network; Each isolated service system domain includes a hyper-converged isolation management component, service resources, and hyper-converged components. The hyper-converged management component collects and prepares the service resources of this isolated service system domain and starts the hyper-converged components of this isolated service system domain; the hyper-converged components connect each isolated service system domain to each other through a shared network; The multiple isolated service system domains include an isolated main service system domain and an isolated slave service system domain, and the isolated slave service system domain is created by the isolated main service system domain; The hyper-converged isolation management components of each isolated service system domain virtualize the service resources of other hyper-converged isolated multi-core server nodes into virtual devices through virtualization technology and make them available for other isolated service system domains of this hyper-converged isolated multi-core server node through sharing technology; When the hyper-converged isolation management component detects an abnormality in other isolated service system domains, it selects to recover the corresponding abnormal isolated service system domain.

2. The hyper-converged platform based on hardware isolation of multiple systems according to claim 1, wherein: The service resources of each isolated service system domain include computing unit resources, storage resources, network resources, and virtualization resources. The service resources are managed by the hyper-converged isolation management component, and at the same time, the use of service resources by the isolated service system domain is monitored.

3. The hyper-converged platform based on hardware isolation of multiple systems according to claim 1, wherein: The hyper-converged isolation management component of the isolated main service system domain can manage the hyper-converged isolation management components of each isolated slave service system domain. At the same time, each hyper-converged isolation management component of the isolated main service system domain has a priority, and the hyper-converged isolation management component with a higher priority manages the hyper-converged isolation management component with a lower priority.

4. The hyper-converged platform based on hardware isolation of multiple systems according to claim 1, wherein: The hyper-converged isolation management component manages and controls whether the isolated service system domain accesses the hyper-converged platform, and the isolated service system domain that does not access the hyper-converged platform has an independent operation function.

5. The hyper-converged platform based on hardware isolation of multiple systems according to claim 1, characterized in that: The isolated service system domains corresponding to each hyper-converged isolated multi-core server node access multiple hyper-converged platforms, and the hyper-converged isolation management component of the isolated service system domain controls its isolated service system domain to access different hyper-converged platforms.

6. The hyper-converged platform based on hardware isolation of multiple systems according to claim 3, characterized in that: Each isolated slave service system domain determines whether it is managed by the hyper-converged isolation management component of other isolated service system domains through the configuration file of the hyper-converged isolation management component within this system domain.

7. The hyper-converged platform based on hardware isolation of multiple systems according to claim 1, characterized in that: Each hyper-converged isolation management component can manage the hyper-converged components of this isolated service system domain to control the service resource permissions of this isolated service system domain, and the permissions include read-only, write-only, invisible, and readable and writable.

8. A method for forming a hyper-converged platform based on hardware-isolated multi-systems, characterized in that, It includes the following steps: Step S1: Isolate the hardware resources of the multi-core server into multiple different isolated service system domains through hardware isolation technology, and different operating systems are run on each isolated service system domain; Step S2: The hyper-converged isolation management component of each isolated service system domain is loaded by the operating system running on the isolated service system domain. The hyper-converged isolation management component collects and prepares the service resources of the isolated service system domain, and starts the hyper-converged component of the isolated service system domain; Step S3: The hyper-converged components of each isolated service system domain are interconnected through a shared network to form a hyper-converged isolated multi-core server node. Multiple hyper-converged isolated multi-core server nodes form a hyper-converged platform through a network switch; The hyper-converged isolation management component of each isolated service system domain virtualizes the service resources of other hyper-converged isolated multi-core server nodes into virtual devices through virtualization technology, and makes them available for other isolated service system domains of the hyper-converged isolated multi-core server node through sharing technology; When the hyper-converged isolation management component detects an abnormality in other isolated service system domains, it selects to recover the corresponding abnormal isolated service system domain.

Citation Information

Patent Citations

  • Distributed computing and storage system capable of being assembled and construction method thereof

    CN112804297A

  • Network system and access method

    CN118433053A