Services communication method among multiple clusters
By setting up gateway modules within the cluster and implementing security policies, the problems of untimely service discovery and insufficient interface compatibility and security in inter-cluster communication methods are solved, and efficient and secure communication between clusters are achieved.
Patent Information
- Application Number
- CN202510608050.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-06-10
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, the communication methods between clusters have problems such as timely service discovery, interface compatibility issues, and insufficient communication security, making it difficult to effectively expand and control information density and security between clusters.
By setting up a gateway module within each cluster, publishing and obtaining service lists of service devices, and achieving secure communication between clusters through security policies and authentication mechanisms, ensuring that only clusters with corresponding service permissions can connect and communicate.
It realizes the comprehensiveness and real-time nature of inter-cluster service discovery, enhances communication compatibility and security, and ensures security and effective communication between clusters.
Smart Images

Figure CN120128627A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of communication between embedded device clusters, and in particular to a service-oriented communication method between multiple clusters. Background Art
[0002] With the development of electronic information technology, embedded devices are becoming more and more clustered, and the computing and communication capabilities of embedded devices are leaping upward exponentially. With the emergence of various clusters built with different purposes or tasks, in order to better play their value internally, most clusters will adopt a service-oriented architecture to solve internal device management and communication problems, reduce the complexity of cluster services, and improve the utilization efficiency of cluster devices.
[0003] However, the data within a single cluster can no longer meet the needs, and the value of the cluster can be better exerted through the interconnection between different clusters. Although there are many ways and channels for clusters to connect with the outside world, the density, security and effectiveness of information cannot be effectively expanded and controlled.
[0004] The communication method between clusters in the existing technology has the following defects and shortcomings: 1) Service discovery and response are not timely, resulting in incomplete and untimely service acquisition; 2) Although there are multiple connection methods between clusters, there is a lack of effective organization and management of communication methods, and there are interface compatibility issues in business data communication.
[0005] 3) There are security issues in inter-cluster communication information, which can easily lead to the spread of inter-cluster failures.
[0006] Therefore, it is urgent to provide a new solution to solve the defects and shortcomings in the above-mentioned prior art. Summary of the invention
[0007] In order to solve the defects and shortcomings in the prior art, the present invention provides a service-oriented communication method among multiple clusters.
[0008] The specific scheme provided by the present invention is: A multi-cluster service-oriented communication method, characterized in that it includes the following steps: S1: The first cluster publishes the current service list of the first business device connected to it through the first gateway module built inside; S2: The second cluster obtains a service list provided by the first service device connected to the first gateway module through an active mode or a passive mode; S3: Only external clusters with corresponding service permissions are allowed to connect to services provided in the service list; S4: Manage the service link of the first cluster through the first gateway module and control the service parameters provided by the first cluster to the outside world; S5: Implement secure communication between the first cluster and the second cluster through security policies and authentication mechanisms.
[0009] As a further preferred embodiment of the present invention, a first service device is provided inside the first cluster. The first service device can provide the services corresponding to its current service list inside. The first service device is signal-connected to the first gateway module through a local area network, and the first gateway module can be signal-connected to the second cluster through a communication link.
[0010] As a further preferred embodiment of the present invention, a second service device is provided inside the second cluster. The second service device can provide the services corresponding to its current service list inside. The second service device is signal-connected to the second gateway module through a local area network, and the second gateway module can be signal-connected to the first cluster through a communication link; As a further preferred embodiment of the present invention, the communication link method is selected from at least one or a combination of multiple of Ethernet, WIFI, and SDR radio frequency.
[0011] As a further preferred embodiment of the present invention, in step S2, the active method includes: The second cluster actively searches for the first service device connected to the first gateway module, and then obtains the service list provided by the first service device.
[0012] As a further preferred embodiment of the present invention, in step S2, the passive method includes: When the first service device actively reports the service list it provides to the first gateway module, when the second cluster discovers the service list, it makes a quick response and simultaneously updates the service list that the second cluster can obtain.
[0013] As a further preferred embodiment of the present invention, in step S3, a unique digital certificate corresponding to each cluster is assigned, and by verifying the validity of the corresponding digital certificate, it is determined whether the cluster has the corresponding service permission.
[0014] As a further preferred embodiment of the present invention, in step S4, the service parameters at least include the number of communication links provided by the first cluster to the outside world, the priority of the communication links, and the network quality of the communication links, and at the same time include the permission for the first cluster to access the services of other clusters outside.
[0015] As a further preferred embodiment of the present invention, in step S5, the security policy includes: 1) Adopt encryption algorithms and encryption protocols for the communication data between the first cluster and the second cluster 2) Set an external access control list for each cluster, and add the clusters with access permissions to the external access control list.
[0016] As a further preferred embodiment of the present invention, in step S5, the authentication mechanism includes: assigning a unique digital certificate corresponding to each cluster, and verifying the signature of the digital certificate corresponding thereto by sending a message to determine whether the cluster has the corresponding service permissions.
[0017] Compared with the prior art, the technical effects that the present invention can achieve include: 1) The present invention provides a method for service-oriented communication between multiple clusters. By setting a gateway module inside each cluster, and obtaining the services in the service list of the business devices connected thereto through the gateway module, other clusters can obtain the services provided by the service list of the business devices inside the cluster in an active or passive manner, thereby realizing service-oriented communication between clusters. The comprehensiveness and real-time nature of service discovery are ensured through a dual-mode, enabling the system to always master the latest and most complete service information.
[0018] 2) The present invention provides a method for service-oriented communication between multiple clusters. The communication link mode can be selected from at least one or a combination of multiple of Ethernet, WIFI, and SDR radio frequency to meet the communication requirements of different data between clusters, increase the communication compatibility between clusters, and ensure the interface compatibility problem between clusters. 3) The present invention provides a method for service-oriented communication between multiple clusters. By setting that only external clusters with corresponding service permissions are allowed to connect to the services provided in the service list, and assigning a unique digital certificate corresponding to each cluster, and verifying the digital certificate corresponding thereto to determine whether the cluster has the corresponding service permissions, to ensure the security and confidentiality of the communication data between clusters.
[0019] 4) The present invention provides a method for service-oriented communication between multiple clusters. Secure communication between the first cluster and the second cluster is achieved through a security policy and an authentication mechanism. Thus, the security and confidentiality of the communication data are ensured by adopting an encryption algorithm and an encryption protocol for the communication data between the first cluster and the second cluster respectively. At the same time, an external access control list is set for each cluster, and the clusters with access permissions are added to the external access control list, thereby further ensuring the permissions and security of the external access of the clusters. In addition, by assigning a unique digital certificate corresponding to each cluster, and verifying the signature of the digital certificate corresponding thereto by sending a message to determine whether the cluster has the corresponding service permissions, the security of the communication data between clusters is further ensured through message verification. Description of the Drawings
[0020] Figure 1 The figure shows the logical structure diagram between clusters provided by the present invention. Detailed implementation mode
[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0022] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "upper", "lower", "inner", "outer", "front end", "rear end", "both ends", "one end", "the other end", etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0023] In the description of the present invention, it should be noted that unless otherwise clearly specified and limited, the terms "installed", "provided with", "connected", etc. should be understood in a broad sense. For example, "connected" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0024] First embodiment The cluster structure mentioned in this embodiment is as Figure 1 shown. Taking the first cluster and the second cluster as examples (those skilled in the art know that the clusters communicating with each other can be one-to-one communication, or many-to-one or one-to-many communication methods. In this embodiment, the one-to-one communication method is taken as an example for elaboration).
[0025] As Figure 1 shown:[[]]END]] A first service device is arranged inside the first cluster. The first service device can provide the services corresponding to its current service list inside. The first service device is signal-connected to the first gateway module through a local area network LAN, and the first gateway module can be signal-connected to the second cluster through a communication link.
[0026] The second cluster is internally provided with a second service device, which can provide services corresponding to its current service list. The second service device is signal-connected to the second gateway module via the local area network LAN, and the second gateway module can be signal-connected to the first cluster via a communication link.
[0027] In this embodiment, the communication link mode can select at least one or more combinations of Ethernet, WIFI, and SDR radio frequency to meet the communication requirements of different data between clusters, increase the communication compatibility between clusters, and ensure the interface compatibility between clusters.
[0028] A first embodiment of the present invention provides a multi-cluster service-oriented communication method, comprising the following steps: S1: The first cluster publishes the current service list of the first business device connected to it through the first gateway module built inside; S2: The second cluster obtains the service list provided by the first service device connected to the first gateway module in an active or passive mode; in this step, the second cluster can obtain the service list provided by the first service device in an active or passive dual mode: The active mode is: the second cluster actively searches for the first service device connected to the first gateway module, and then obtains the service list provided by the first service device; The passive mode is: when the first service device actively reports the service list it provides to the first gateway module, the second cluster discovers the service list, responds quickly and updates the service list that the second cluster can obtain at the same time; The dual modes of active and passive acquisition ensure the comprehensiveness and real-time nature of service discovery, allowing the system to grasp the latest and most complete service information at any time.
[0029] S3: Only external clusters with corresponding service permissions are allowed to connect to services provided in the service list; for example, in this embodiment, a unique digital certificate corresponding to each cluster can be assigned, and by verifying the validity of the corresponding digital certificate, it is determined whether the cluster has the corresponding service permission.
[0030] Whether clusters can connect to each other requires verification of certificate validity before subsequent service communication can be carried out. Certificates are issued by management agencies and contain the issuing authority, validity period, cluster set, service permissions, types of services provided to the outside world, serial number, certificate algorithm, etc. Verification of certificate validity is verification of service permissions in the certificate, thereby determining whether the cluster has the corresponding service permissions. The significance of a certificate is to serve as an external identification of a cluster and is a prerequisite for interconnection between clusters.
[0031] S4: Manage the service link of the first cluster through the first gateway module and control the service parameters provided by the first cluster externally; in this embodiment, the service parameters at least include the number of communication links provided by the first cluster externally, the priority of the communication links, and the network quality of the communication links, and at the same time include the permission for the first cluster to access the services of other external clusters.
[0032] The basic product parameters of each cluster have been determined at the time of factory, such as parameters like the maximum number of external communication links it can provide and the maximum communication bandwidth, etc. In actual usage scenarios, the number of actual external communication links can be set as needed within the range of the maximum number of external communication links it can provide; Regarding the priority of the communication links, since the radio frequency communication links are serial queued for transceiver, a mechanism of rotating for the same priority and preempting for different priorities is adopted, which is supported by the corresponding algorithm. Among them, The mechanism of rotating for the same priority means that when the priorities are the same, each radio frequency communication link conducts data communication transmission in sequence; The mechanism of preempting for different priorities means that when the priorities are different, the service with a higher priority passes through the radio frequency communication link for data communication transmission first, while the service with a lower priority delays passing through the radio frequency communication link for data communication transmission; The external communication service priority can be set in advance and can be adjusted as needed during subsequent use. The basis for priority adjustment includes but is not limited to: the importance and urgency of the transmission service, the network communication quality of the radio frequency communication link, the adaptability of the service permission, and the size of the service permission, etc.
[0033] The adjustment of the network quality of the communication links is achieved by pre-setting and adjusting parameters such as the power and waveform of the hardware link radio frequency as needed. The pre-setting and actual adjustment of the hardware parameters of different radio frequency links are different.
[0034] S5: Implement secure communication between the first cluster and the second cluster through the security policy and authentication mechanism.
[0035] In this embodiment, the security policy includes: 1) Adopt encryption algorithms and encryption protocols for the communication data between the first cluster and the second cluster; The specific steps of encryption include: The first step: Establish a radio frequency link; The second step: Certificate authentication; The third step: Achieve information synchronization between clusters.
[0036] Subsequently, encrypted communication between clusters can be achieved according to the service.
[0037] Communication data encryption algorithms and encryption protocols include communication content encryption and hardware modulation and demodulation. Specific encryption algorithms and types are pre-loaded by cluster manufacturers, which may include common symmetric encryption and asymmetric encryption methods, etc. User units can select corresponding encryption algorithms and encryption protocols according to the requirements of system design.
[0038] 2) Set up an external access control list for each cluster and add the clusters with access permissions to this external access control list; thus, by adopting encryption algorithms and encryption protocols for the communication data between the first cluster and the second cluster respectively, the security and confidentiality of the communication data are ensured. At the same time, set up an external access control list for each cluster and add the clusters with access permissions to this external access control list, thereby further ensuring the access rights and security of the clusters' external access.
[0039] The authentication mechanism includes: allocating a unique digital certificate corresponding to each cluster and verifying the signature of the digital certificate corresponding thereto by sending a message to determine whether the cluster has the corresponding service permissions, and further ensuring the security of the communication data between clusters through the method of message verification.
[0040] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced within the present invention. Any reference signs in the claims should not be regarded as limiting the claimed rights.
Claims
1. A multi-cluster service-oriented communication method, characterized in that: The following steps are involved: S1: The first cluster publishes the current service list of the first business device connected to it through the first gateway module built inside; S2: The second cluster obtains a service list provided by the first service device connected to the first gateway module through an active mode or a passive mode; S3: Only external clusters with corresponding service permissions are allowed to connect to services provided in the service list; S4: managing the service link of the first cluster through the first gateway module, and controlling the service parameters provided by the first cluster to the outside; S5: Implement secure communication between the first cluster and the second cluster through security policies and authentication mechanisms.
2. A multi-cluster service-based communication method according to claim 1, characterized in that: The first cluster is internally provided with a first service device, which can provide services corresponding to its current service list. The first service device is signal-connected to a first gateway module via a local area network, and the first gateway module can be signal-connected to a second cluster via a communication link.
3. A multi-cluster service-oriented communication method according to claim 2, characterized in that: The second cluster is internally provided with a second service device, which can provide services corresponding to its current service list. The second service device is signal-connected to a second gateway module via a local area network, and the second gateway module can be signal-connected to the first cluster via a communication link.
4. The method for service-oriented communication among multiple clusters according to claim 3, characterized in that: The communication link mode is selected from at least one or more combinations of Ethernet, WIFI, and SDR radio frequency.
5. The method for service-based communication among multiple clusters according to claim 1, characterized in that: In the step S2, the active method includes: the second cluster actively searches for the first service device connected to the first gateway module, and then obtains the service list provided by the first service device.
6. The method for service-based communication among multiple clusters according to claim 1, characterized in that: In step S2, the passive method includes: when the first service device actively reports the service list it provides to the first gateway module, the second cluster discovers the service list, responds quickly and updates the service list that the second cluster can obtain.
7. The method for service-oriented communication among multiple clusters according to claim 1, characterized in that: In step S3, a unique digital certificate corresponding to each cluster is allocated, and by verifying the validity of the digital certificate corresponding to each cluster, it is determined whether the cluster has the corresponding service authority.
8. The method for service-based communication among multiple clusters according to claim 1, characterized in that: In step S4, the service parameters include at least the number of communication links provided by the first cluster, the priority of the communication links and the network quality of the communication links, and also include the authority of the first cluster to access services of other external clusters.
9. The method for service-based communication among multiple clusters according to claim 1, characterized in that: In step S5, the security policy includes: 1) Use encryption algorithms and encryption protocols for communication data between the first cluster and the second cluster 2) Set up an external access control list for each cluster and add clusters with access rights to the external access control list.
10. The method for service-based communication among multiple clusters according to claim 1, characterized in that: In step S5, the authentication mechanism includes: allocating a unique digital certificate corresponding to each cluster, and verifying the signature of the digital certificate corresponding to each cluster by sending a message to determine whether the cluster has the corresponding service authority.
Citation Information
Patent Citations
Cross-cluster data transmission method and device, computer equipment and storage medium
CN110519217A
All-domain multi-level unified safe data transmission method and server cluster
CN114143039A
Request response method and device, electronic equipment and computer readable storage medium
CN114760360A
Heterogeneous multi-container cluster scheduling method, system and device and storage medium
CN117978406A
Kubernetes-based service container scheduling method and system under cloud edge collaboration
CN118337786A