Authentication method and device based on data dyeing mechanism
By adding authentication identifiers of device-side feature information in authentication requests, the problem that automated operation and maintenance systems are difficult to uniformly authenticate virtual machines across multiple cloud platforms in hybrid cloud scenarios is solved, and authentication efficiency and configuration simplicity is improved.
Patent Information
- Application Number
- CN202510233968.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-13
AI Technical Summary
In hybrid cloud scenarios, it is difficult for automated operation and maintenance systems to authenticate virtual machines across multiple different cloud platforms in a unified authentication method, resulting in low authentication efficiency.
The authentication method based on the data staining mechanism is adopted, and by adding authentication identifiers to the authentication request, indicating the characteristic information of the device side, so that the server can authenticate the virtual machine client based on the characteristic information of the physical device.
It improves the authentication efficiency of the client, and can uniformly authenticate virtual machine clients across multiple different cloud platforms in a hybrid cloud scenario, reducing the configuration complexity of the virtual machine.
Smart Images

Figure CN120150996A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computers, and in particular, to an authentication method and device based on a data staining mechanism. Background Art
[0002] With the popularization of information technology and the rapid development of the digitalization wave, the scale of enterprises' IT systems has been continuously expanding, and the business complexity has been increasing day by day. The traditional manual operation and maintenance method can no longer meet the requirements of efficient and accurate operation and maintenance. Therefore, the client-based automated operation and maintenance technology has emerged as the times require. The automated operation and maintenance system can deploy clients on target machines to achieve tasks such as remote control and data collection, greatly improving the operation and maintenance efficiency.
[0003] In current automated operation and maintenance, the deployment and authentication of clients are crucial for the automated operation and maintenance system. The automated operation and maintenance system can deploy clients in various ways such as deployment scripts and image templates, and the deployed clients need to be securely authenticated. In the current authentication scheme, in addition to the authentication methods of passing through a third-party system or presetting certificates, the automated operation and maintenance system can also perform authentication through the data sharing between the virtual machine management platform and the automated operation and maintenance system, that is, the client deployed inside the virtual machine reads the identity information of the virtual machine during authentication and reports the information to the automated operation and maintenance system. If the automated operation and maintenance system can find the corresponding identity information in the virtual machine identity information library, it means that the virtual machine is legal, and the authentication passes.
[0004] However, the authentication method based on identity information needs to rely on the virtual machine management platform. And the automated operation and maintenance system is often a heterogeneous multi-cloud hybrid cloud scenario. In the hybrid cloud scenario, users often use more than one cloud platform, and there will be virtual machines from various different cloud platforms. At this time, there is no unified identity data for different virtual machines, resulting in that the automated operation and maintenance system cannot authenticate virtual machines across multiple different cloud platforms in a unified authentication manner, leading to low authentication efficiency. Summary of the Invention
[0005] The embodiments of the present application provide an authentication method based on a data staining mechanism for improving the authentication efficiency of clients. The embodiments of the present application also provide an authentication device based on a data staining mechanism, a computing device, a computing device cluster, a computer-readable storage medium, and a computer program product.
[0006] In a first aspect, an embodiment of the present application provides an authentication method based on a data coloring mechanism. This method can be executed by a computing device, or by components of a computing device, such as a processor, chip, or chip system of the computing device, or can also be implemented by a logic module or software that can implement all or part of the functions of the computing device. The method provided in the first aspect includes: the device side sends an authentication request to the server side. The authentication request is used to request the server side to authenticate the client side. The client side includes a proxy program deployed on the device side. The device side can deploy various types of computing resources, such as virtual machines and bare-metal servers. The client side can be a client in a virtual machine or a bare-metal server. The device side adds an authentication identifier to the authentication request based on the data coloring mechanism. The authentication identifier is used to indicate the characteristic information of the device side, and the characteristic information is used by the server side to authenticate the client side. The device side receives the authentication response sent by the server side. The authentication response includes the authentication result of the server side on the client side.
[0007] In the embodiment of the present application, the device side can add an authentication identifier to the authentication request based on the data coloring mechanism, and thus can indicate the characteristic information of the terminal device. The server side can authenticate the client side in the device side based on the characteristic information of the device side. Compared with the prior art where the automated operation and maintenance system cannot authenticate the virtual machine clients across multiple different cloud platforms in a unified authentication manner, since the physical device where the virtual machine client is located is determined, and the network communication of the virtual machine client also belongs to the determined physical device, therefore, the server side can authenticate the virtual machine client according to the characteristic information of the physical device, thereby improving the authentication efficiency of the client side in the device side.
[0008] In a possible implementation manner, before the device side adds an authentication identifier to the authentication request based on the data coloring mechanism, the device side intercepts the authentication request based on a network identifier. The network identifier is used to identify the server side corresponding to the authentication request. The network identifier includes an IP address, a domain name, a virtual IP address, or a virtual domain name.
[0009] In the embodiment of the present application, the device side can identify the authentication request to be intercepted based on the network identifier, thereby improving the feasibility of adding an authentication identifier by the device side based on the data coloring mechanism.
[0010] In a possible implementation manner, when the network identifier is a virtual IP or a virtual domain name, the virtual IP address corresponds to one or more server sides, and the virtual domain name corresponds to one or more server sides. After the user newly creates a virtual machine or a bare-metal server, the client side in the virtual machine or the bare-metal server can be configured based on the virtual IP or the virtual domain name, so that the client side is not aware of the server side. After the server side changes, there is no need to re-
[0011] In the embodiments of the present application, a virtual IP address and a virtual domain name can correspond to one or more servers. The virtual machines in the device end can send authentication requests based on the virtual IP address or the virtual domain name without being aware of the real IP address of the server. Therefore, when creating a new virtual machine, there is no need to configure the real IP address of the server, reducing the configuration complexity of the virtual machine.
[0012] In a possible implementation manner, before the device end intercepts the authentication request based on the network identifier, the device end configures the mapping relationship between the network identifier and the server. The mapping relationship is used for the client to identify the authentication request to be intercepted. The mapping relationship includes the mapping relationship between the virtual IP address and one or more servers or the mapping relationship between the virtual domain name and one or more servers.
[0013] In the embodiments of the present application, the device end can configure the mapping relationship between the network identifier and the server, so that the device end can determine the network identifier corresponding to the server by querying the mapping relationship and intercept the authentication request to be dyed based on the network identifier, thereby improving the feasibility of intercepting the authentication request based on the network identifier.
[0014] In a possible implementation manner, when the device end adds an authentication identifier to the authentication request based on the data dyeing mechanism, the device end adds the authentication identifier to the authentication request based on the extended packet filter eBPF program. Subsequently, data dyeing based on the extended packet filter eBPF is a technical means for marking and tracking data. Using eBPF, user-defined programs can run in the kernel. At a specific stage when data flows through the kernel, specific marks are attached to the data for data identification, classification, and tracking.
[0015] In the embodiments of the present application, the device end adds an authentication identifier to the authentication request based on the extended packet filter eBPF program, thereby improving the feasibility of the device end adding an authentication identifier to the authentication request.
[0016] In a possible implementation manner, the authentication request includes resource data encrypted based on the server public key certificate. The resource data includes one or more of the following: hostname, operating system version, IP address. The version number is used to identify the software version of the client, and the version number can be a group of numbers or an alphanumeric combination. The device end information length refers to the number of bytes occupied by the device end information data and is used to indicate the size of the subsequent device end information data to the server. The device end information data carries characteristic information and other device end information, such as hardware information and system information, etc.
[0017] In the embodiments of the present application, the authentication request sent by the client to the server further includes resource data encrypted by the server public key certificate, so that the server can determine the running status of the virtual machine based on these resource data and perform operation and maintenance operations, thereby improving the feasibility of the device side to execute operation and maintenance tasks.
[0018] In a possible implementation manner, the authentication identifier includes one or more of the following: version number, device-side information length, device-side information data, and the device-side information data is used to carry feature information, and the feature information includes one or more of the following: device serial number, central processing unit (CPU) motherboard serial number, device-side MAC address. The device serial number is the unique identifier of the device side and can be used to identify, track, manage, and maintain the device side. The CPU motherboard serial number is the unique number of the motherboard in the device side. The device-side MAC address is the unique identifier of the device side in the network and is also called the physical address.
[0019] In the embodiments of the present application, the authentication identifier added by the device side based on the data staining mechanism includes content such as version number, device-side information length, device-side information data, etc., where the device-side information data is used to carry the feature information of the device side, thereby improving the feasibility of the device side to perform client authentication based on the data staining mechanism.
[0020] In a second aspect, the embodiments of the present application provide an authentication method based on a data staining mechanism. This method can be executed by a computing device, or by components of a computing device, such as a processor, a chip, or a chip system of the computing device, etc., and can also be implemented by a logic module or software that can implement all or part of the functions of the computing device. The method provided in the second aspect includes: the server receives an authentication request sent by the device side, the authentication request is used to request the server to authenticate the client, the client includes a proxy program deployed on the device side, the authentication request includes an authentication identifier added based on the data staining mechanism, and the authentication identifier is used to indicate the feature information of the device side. The server parses the authentication request and generates an authentication response based on the authentication identifier in the authentication request. The server sends the authentication response to the client, and the authentication response includes the authentication result of the server for the client, and the authentication result includes that the client authentication is successful and the client authentication fails.
[0021] In the embodiments of the present application, the server can authenticate the client in the device side based on the feature information of the device side. Since the physical device where the virtual machine client is located is determined, and the network communication of the virtual machine client also belongs to the determined physical device, the server can authenticate the virtual machine client according to the feature information of the physical device, thereby improving the authentication efficiency of the server for the client.
[0022] In a possible implementation manner, when the server generates an authentication response based on the authentication identifier in the authentication request, if the feature information of the device end indicated by the authentication identifier conforms to the feature information of the legitimate device list, it is determined that the client identity authentication corresponding to the authentication request is successful. If the feature information of the device end indicated by the authentication identifier does not conform to the feature information of the legitimate device list, it is determined that the client identity authentication corresponding to the authentication request fails.
[0023] In the embodiment of the present application, the server can compare the feature information of the device end with the feature information of the legitimate device list to determine the authentication result of the client, which improves the feasibility of the server to authenticate the client.
[0024] In a third aspect, the embodiment of the present application provides an authentication device based on a data coloring mechanism. The device includes a transceiver unit and a processing unit. Among them, the transceiver unit is used to send an authentication request to the server. The authentication request is used to request the server to authenticate the client. The client includes a proxy program deployed on the device end. The processing unit is used to add an authentication identifier to the authentication request based on the data coloring mechanism. The authentication identifier is used to indicate the feature information of the device end, and the feature information is used by the server to authenticate the client. The transceiver unit is also used to receive the authentication response sent by the server. The authentication response includes the authentication result of the server for the client.
[0025] In a possible implementation manner, the processing unit is further used to intercept the authentication request based on the network identifier. The network identifier is used to identify the server corresponding to the authentication request. The network identifier includes an IP address, a domain name, a virtual IP address, or a virtual domain name.
[0026] In a possible implementation manner, a virtual IP address corresponds to one or more servers, and a virtual domain name corresponds to one or more servers.
[0027] In a possible implementation manner, the processing unit is further used to configure the mapping relationship between the network identifier and the server. The mapping relationship is used by the client to identify the authentication request to be intercepted.
[0028] In a possible implementation manner, the processing unit is specifically used to add an authentication identifier to the authentication request based on an eBPF (Extended Berkeley Packet Filter) program.
[0029] In a possible implementation manner, the authentication request includes resource data encrypted based on the server public key certificate. The resource data includes one or more of the following: hostname, operating system version, IP address.
[0030] In a possible implementation, the authentication identifier includes one or more of the following: version number, device-side information length, device-side information data, and the device-side information data is used to carry feature information, and the feature information includes one or more of the following: device serial number, central processing unit (CPU) motherboard serial number, device-side MAC address.
[0031] In a fourth aspect, an embodiment of the present application provides an authentication device based on a data coloring mechanism. The device includes a transceiver unit and a processing unit. Among them, the transceiver unit is configured to receive an authentication request sent by a device side. The authentication request is used to request the server to authenticate the client. The client includes a proxy program deployed on the device side. The authentication request includes adding an authentication identifier based on the data coloring mechanism, and the authentication identifier is used to indicate the feature information of the device side. The processing unit is configured to parse the authentication request and generate an authentication response based on the authentication identifier in the authentication request. The transceiver unit is further configured to send the authentication response to the client, and the authentication response includes the authentication result of the server on the client, and the authentication result includes that the client authentication is successful and the client authentication is failed.
[0032] In a possible implementation, the processing unit is specifically configured to determine that the client authentication corresponding to the authentication request is successful when the feature information of the device side indicated by the authentication identifier conforms to the feature information of the legitimate device list. When the feature information of the device side indicated by the authentication identifier does not conform to the feature information of the legitimate device list, it is determined that the client authentication corresponding to the authentication request fails.
[0033] In a fifth aspect, an embodiment of the present application provides a computing device. The computing device includes a processor, and the processor is coupled to a memory. The processor is configured to store instructions. When the instructions are executed by the processor, the computing device is caused to execute the method described in the first aspect or any possible implementation manner of the first aspect, or the computing device is caused to execute the method described in the second aspect or any possible implementation manner of the second aspect.
[0034] In a sixth aspect, an embodiment of the present application provides a computing device cluster. The computing device cluster includes one or more computing devices. The computing device includes a processor, and the processor is coupled to a memory. The processor is configured to store instructions. When the instructions are executed by the processor, the computing device cluster is caused to execute the method described in the first aspect or any possible implementation manner of the first aspect, or the computing device cluster is caused to execute the method described in the second aspect or any possible implementation manner of the second aspect.
[0035] In a seventh aspect, an embodiment of the present application provides a computer-readable storage medium, on which instructions are stored. When the instructions are executed, the computer is caused to execute the method described in the first aspect or any possible implementation manner of the first aspect, or the computer is caused to execute the method described in the second aspect or any possible implementation manner of the second aspect.
[0036] In an eighth aspect, an embodiment of the present application provides a computer program product. The computer program product includes instructions that, when executed, cause a computer to implement the method described in the first aspect or any possible implementation manner of the first aspect, or cause a computer to implement the method described in the second aspect or any possible implementation manner of the second aspect.
[0037] It can be understood that the beneficial effects that can be achieved by any of the above-provided authentication devices, computing devices, computing device clusters, computer-readable media, or computer program products based on the data coloring mechanism can refer to the beneficial effects in the corresponding methods, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 It is a schematic diagram of the system architecture of an automated operation and maintenance system provided by an embodiment of the present application;
[0039] Figure 2 It is a schematic flowchart of an authentication method based on a coloring mechanism provided by an embodiment of the present application;
[0040] Figure 3 It is a schematic flowchart of another authentication method based on a data coloring mechanism provided by an embodiment of the present application;
[0041] Figure 4 It is a schematic diagram of the data structure of an authentication request provided by an embodiment of the present application;
[0042] Figure 5 It is a schematic diagram of client authentication based on a virtual IP address provided by an embodiment of the present application;
[0043] Figure 6 It is a schematic diagram of the structure of an authentication device based on a data coloring mechanism provided by an embodiment of the present application;
[0044] Figure 7 It is a schematic diagram of the structure of a computing device provided by an embodiment of the present application;
[0045] Figure 8 It is a schematic diagram of the structure of a computing device cluster provided by an embodiment of the present application;
[0046] Figure 9 It is a schematic diagram of computer devices in a computer cluster connected through a network provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] An embodiment of the present application provides an authentication method and device based on a data coloring mechanism for improving the authentication efficiency of a client.
[0048] In the description and claims of this application and the above-mentioned drawings, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0049] In the embodiments of this application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0050] First, some terms involved in the embodiments of this application are introduced to facilitate those skilled in the art to understand the technical solutions.
[0051] Extended Berkeley Packet Filter (eBPF) is a technology in the Linux kernel that allows developers to dynamically load custom programs into the kernel to run without modifying the kernel code.
[0052] Data staining is a technology for dynamically attaching metadata to data, used to identify data sources, types, security levels, or processing rules, etc.
[0053] Data staining based on extended Berkeley packet filter is a technology that uses eBPF technology to mark and track data. It attaches eBPF programs on the critical path where data flows, and stains and marks data that meets specific conditions, so as to trace and monitor the source, flow, and processing process of the data.
[0054] In order to make the technical solutions of this application clearer and easier to understand, the system architecture of this application is introduced below with reference to the drawings.
[0055] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the system architecture of an automated operation and maintenance system provided by the embodiments of this application. In Figure 1In the illustrated example, the automated operation and maintenance system 10 includes a device side 101 and a server side 102. Among them, the device side 101 includes a client 1011 and a data coloring subsystem 1012. The functions of each part of the system will be specifically introduced below.
[0056] The device side 101 can also be referred to as a physical machine or a physical device. One or more virtual machines can be created in the device side 101, or a bare metal server (BMS) can be run. Among them, a virtual machine is a virtual computer environment created in the device side 101 through virtualization technology, and multiple virtual machines can share the hardware resources of a physical device. The bare metal server BMS can run directly on the device side 101 without passing through the virtualization layer, that is, the bare metal server BMS can provide the same performance as the physical device.
[0057] The device side 101 includes a client 1011 and a data coloring subsystem 1012. Among them, the client 1011 is an agent program deployed in a virtual machine or a bare metal server BMS, and can also be referred to as an agent node. As a software entity in the device side 101, the client 1011 can automatically execute a series of operation and maintenance tasks, including collecting and reporting data such as performance indicators and log information of the device side 101, and receiving and executing task instructions issued by the server side 102, etc.
[0058] The client 1011 needs to be authenticated before executing the operation and maintenance tasks. The client 1011 sends an authentication request to the server side 102, and the server side 102 authenticates the client 1011 based on the authentication request sent by the client 1011. The authenticated client 1011 can be assigned corresponding access and operation permissions.
[0059] The data coloring subsystem 1012 is used to color the data sent by the device side 101 based on the extended Berkeley packet filter eBPF technology, so as to identify the identification data of the device side 101 that sends the data. The colored data carries the identification data of the device side 101, enabling the server side 102 to authenticate the client 1011 through the identification data of the device side 101.
[0060] The data coloring subsystem 1012 can complete the marking of the physical device at an early stage of the data life cycle through the eBPF program, realizing fine-grained data tracking and control. Among them, data coloring based on the extended packet filter eBPF is a technical means of marking and tracking data. Using eBPF, user-defined programs can run in the kernel, and specific marks can be attached to the data when the data flows through the kernel, so as to identify, classify, and track the data.
[0061] The server 102 is used for centralized management of the client 1011, including registration, authentication, status monitoring, etc. of the client 1011. The server 102 can also receive the collected data uploaded by the client 1011, analyze the collected data to obtain an operation and maintenance strategy, and send various operation and maintenance tasks and instructions to the client 1011 according to the operation and maintenance strategy. The server 102 is also used for receiving the alarm information from the client 1011, and centrally managing and processing the alarms, including classification, filtering, priority setting, etc. of the alarms.
[0062] It should be noted that both the client 1011 and the server 102 in the above-mentioned automated operation and maintenance system 10 can be deployed on a computing device or a computing device cluster. Therefore, in the embodiments of the present application, the computing device or the computing device cluster can also be used to refer to the automated operation and maintenance system 10 and each module therein.
[0063] Based on Figure 1 the automated operation and maintenance system 10 shown, the present application also provides an authentication method based on a coloring mechanism. The following introduces the authentication method based on the coloring mechanism provided by the embodiments of the present application in combination with the embodiments.
[0064] Please refer to Figure 2 , Figure 2 which is a schematic flowchart of an authentication method based on a coloring mechanism provided by the embodiments of the present application. In Figure 2 the example shown, the method includes the following steps:
[0065] 201. The device side sends an authentication request to the server, and the authentication request is used to request the server to authenticate the client. The client includes a proxy program deployed on the device side.
[0066] In the embodiments of the present application, before the server 102 performs operation and maintenance operations on the device side 101 by using the remote control capability, it is necessary to install the client 1011 on the device side 101 and authenticate the client 1011. The client 1011 can also be called a proxy (agent) program or a proxy node, and is deployed in the virtual machine VM or the bare metal server BMS of the device side 101.
[0067] During the authentication process of the client 101, the device side 101 sends an authentication request to the server 102, and the authentication request is used to request the server 102 to authenticate the client 1011. Among them, the authentication request includes resource data encrypted based on the server public key certificate, and the resource data includes one or more of the following: host name, operating system version, IP address.
[0068] Among them, the host name is the identification name of the virtual machine or bare-metal server where the client 1011 is located in the network, which is used to uniquely identify the virtual machine or bare-metal server in the automated operation and maintenance system. The host name is usually specified by the user when creating the virtual machine or bare-metal server or automatically generated according to certain naming rules. The operating system version refers to the specific version information of the operating system running on the virtual machine or bare-metal server where the client 1011 is located. The IP address includes the logical address of the virtual machine or bare-metal server where the client 1011 is located in the network, which is used for data communication between the client 1011 and the server 102.
[0069] Please refer to Figure 3 , Figure 3 which is a schematic flowchart of another authentication method based on the data coloring mechanism provided by the embodiments of this application. In Figure 3 Step 1 of the example shown, after the virtual machine VM1 of the device side 101 is started, the agent in the virtual machine VM1 initiates an authentication request to the server side 102. The authentication request includes resource data such as the host name, operating system version, and IP address.
[0070] In Figure 3 the example shown, before the agent in the virtual machine VM1 initiates an authentication request, it needs to obtain the public key certificate of the server side. Specifically, the agent in the virtual machine VM1 is pre-configured with the relevant connection information of the server side 102, such as the network identification of the server side 102, and the network identification includes the IP address, port number, etc. These information are used to establish a communication connection with the server side. The agent in the virtual machine VM1 uses a specific network protocol to initiate a connection request to the server side according to the configured server side information. This connection is used to request to obtain the public key certificate of the server side. After the agent in the virtual machine VM1 obtains the public key certificate of the server side, it uses this public key certificate to encrypt the above resource data in the virtual machine VM1. The resource data in the authentication request is the encrypted resource data.
[0071] 202. The device side adds an authentication identifier to the authentication request based on the data coloring mechanism. The authentication identifier is used to indicate the characteristic information of the device side, and the characteristic information is used for the server side to authenticate the client.
[0072] After the client 1011 sends an authentication request to the server side 102, the device side 101 performs data coloring on the authentication request based on the data coloring mechanism, that is, the device side 101 adds an authentication identifier to the authentication request based on the data coloring mechanism. The authentication identifier is used to indicate the characteristic information of the device side 101, and the characteristic information is used for the server side 102 to authenticate the client 1011.
[0073] In a hybrid cloud scenario, the lifecycle of virtual machines is often uncertain and can come from different cloud platforms. However, the physical devices where the virtual machines and bare metal servers are located are often determined. Compared with virtual machines, the management of physical devices is a definite process. The server 102 has a list of legitimate physical devices. Therefore, the characteristic information of the physical device where the virtual machine is located can be used as the authentication identifier for the client in the virtual machine. That is, the characteristic information of the device end 101 where the client 1011 is located is attached to the authentication request, indicating that the authentication request has a binding relationship with the device end 101. The client 1011 can be authenticated based on the characteristic information of the device end 101.
[0074] In a possible implementation, when the device end 101 performs data coloring on the authentication request based on the data coloring mechanism, the device end 101 intercepts the authentication request based on the network identifier and adds an authentication identifier to the intercepted authentication request based on the data coloring mechanism. The network identifier is used to identify the authentication request to be intercepted, and the network identifier includes an IP address, a domain name, a virtual IP address, or a virtual domain name.
[0075] Specifically, the device end 101 intercepts the authentication request sent to the specified network identifier based on the extended packet filter eBPF program and completes the coloring process by adding a prefix to the authentication request. The prefix added to the authentication request includes the characteristic information of the device end 101. Then, the device end 101 sends the authentication request with the added prefix to the server 102 corresponding to the specified network identifier.
[0076] It should be noted that data coloring based on the extended packet filter eBPF is a technical means for marking and tracking data. By using eBPF, user-defined programs can run in the kernel. At a specific stage when data flows through the kernel, specific marks are attached to the data for data identification, classification, and tracking.
[0077] In the embodiment of the present application, the extended packet filter eBPF program is deployed when the device end 101 is managed. During the running stage, the eBPF program is deployed and the device end 101 works in the direct-action mode. The direct-action mode allows users to directly modify the content of the data packet, redirect the data packet path, or perform custom operations.
[0078] Please continue to refer to Figure 3 In Figure 3In steps 2 to 3 of the illustrated example, when the virtual machine VM1 in the client 101 sends an authentication request to the server 102, the device side 101 intercepts the authentication request sent to the client 102 based on the extended packet filter eBPF and adds an authentication identifier to the authentication request, and this authentication identifier is used to indicate the characteristic information of the device side 101. For example, the eBPF program of the device side 101 monitors and filters TCP packets sent to the specified server 102, modifies the packets by adding a prefix, and then sends the modified packets to the specified server 102.
[0079] In Figure 3 In the illustrated example, during the process that the device side 101 sends the modified packets to the specified server 102, the device side 101 establishes a Transmission Control Protocol (TCP) connection with the server 102. For example, the device side 101 and the server 102 confirm their connection status through a three-way handshake to ensure that both sides can perform data transmission. After the TCP connection is established, the device side 101 and the server 102 start a Transport Layer Security (TLS) handshake to negotiate relevant TLS parameters, such as encryption algorithms, key lengths, authentication methods, etc. During the TLS handshake, the server 102 can send a digital certificate to the device side 101, and the device side 101 verifies the validity of the certificate to confirm the identity of the server 102. After the authentication passes, the device side 101 encrypts the resource data to be sent and then sends it to the server 102 through the TCP connection.
[0080] In a possible implementation manner, the authentication identifier includes one or more of the following: version number, device side information length, device side information data, and the device side information data is used to carry characteristic information. The version number is used to identify the software version of the client 1011, and the version number can be a group of numbers or an alphanumeric combination. The device side information length refers to the number of bytes occupied by the device side information data and is used to indicate the size of the subsequent device side information data to the server 102. In addition to carrying characteristic information, the device side information data can also include other device side information, such as hardware information and system information, etc.
[0081] In a possible implementation manner, the characteristic information in the embodiments of the present application includes one or more of the following: device serial number, central processing unit (CPU) motherboard serial number, device side MAC address. The device serial number is the unique identifier of the device side 101 and can be used to identify, track, manage, and maintain the device side 101. The CPU motherboard serial number is the unique number of the motherboard in the device side 101. The device side MAC address is the unique identifier of the device side 101 in the network and is also called the physical address.
[0082] Please refer to Figure 4 , Figure 4Schematic diagram of the data structure of an authentication request provided by an embodiment of this application. In Figure 4 In the example shown, the authentication request includes multiple data segments, including a version field, a device-side information length field, a device-side information data field, and a client-side information data field. Among them, the version field, the device-side information length field, and the device-side information data field are the authentication identifiers added by the device side 101 based on the data coloring mechanism.
[0083] In Figure 4 In the example shown, the client-side information data field in the authentication request includes resource data encrypted based on the server public key certificate. Encrypting this data is to prevent the information of the client 1011 from being leaked on the device side 1011. Among them, the resource data encrypted based on the server public key certificate is, for example, the hostname of the virtual machine where the client is located, the operating system version, the IP address, etc.
[0084] In a possible implementation manner, before the device side 101 intercepts the authentication request based on the network identifier, the device side 101 configures the mapping relationship between the network identifier and the server. The mapping relationship is used to identify the authentication request to be intercepted. Specifically, the device side 101 can determine the network identifier corresponding to the server 102 based on this mapping relationship, and identify the authentication request to be intercepted based on the network identifier.
[0085] It should be noted that when the network identifier of the server 102 in the embodiment of this application is a virtual IP or a virtual domain name, a virtual IP address can correspond to one or more servers 102, and a virtual domain name can also correspond to one or more servers 102. Since both the virtual IP address and the virtual domain name can correspond to multiple servers 102, after the user creates a new virtual machine in the form of an image, there is no need to reconfigure the server 102 corresponding to the virtual machine. Even if the server 102 corresponding to the authentication request changes, the client in the virtual machine can still send an authentication request based on the virtual IP address of the server 102.
[0086] Please refer to Figure 5 , Figure 5 Schematic diagram of client authentication based on a virtual IP address provided by an embodiment of this application. In Figure 5 In the example shown, when the virtual IP address of the server can correspond to one or more real IP addresses of the server. For example, the virtual IP address of the server is "111.222.123.124", and the real IP addresses of the server corresponding to this virtual IP address include the IP address "1.2.3.4" of server 1 and the IP address "1.2.3.5" of server 2.
[0087] In Figure 5In the example shown, when virtual machine 1 accesses the virtual IP "111.222.123.124" of the server, device side 101 queries the virtual IP mapping system based on the virtual IP address "111.222.123.124" to determine the real IP address of the server. During the process of virtual machine 1 sending an authentication request to the server, even if the real IP address of the server changes, virtual machine 1 does not perceive the change in the server IP address when sending the authentication request based on the virtual IP address.
[0088] In Figure 5 the example shown, when a user creates virtual machine 2 based on virtual machine 1 in mirror mode, the newly created virtual machine 2 does not need to configure the real IP address of the server, and can directly send an authentication request to the server based on the virtual IP address "111.222.123.124" configured for virtual 1.
[0089] The authentication method provided by the embodiments of this application supports the client to use the virtual IP or virtual domain name of the server. By configuring the mapping relationship of the virtual IP or virtual domain name of the server on the device side, the communication process between the device side and the server can be automatically completed without additional IP forwarding and domain name mapping.
[0090] 203. The device side receives the authentication response sent by the server, and the authentication response includes the authentication result of the server for the client.
[0091] After device side 101 sends an authentication request to server 102, server 102 parses the authentication identifier in the authentication request to determine the device side feature information in the authentication identifier. Server 102 verifies whether the device side is a legal device based on the feature information of the device side. If it is a legal device, then server 102 determines that client 1011 authentication is passed and sends an authentication response to device side 101. Specifically, when the feature information of device side 101 indicated by the authentication identifier conforms to the feature information of the legal device list, it is determined that the identity authentication of client 1011 corresponding to the authentication request is successful. When the feature information of device side 101 indicated by the authentication identifier does not conform to the feature information of the legal device list, it is determined that the identity authentication of client 1011 corresponding to the authentication request fails.
[0092] After device side 101 receives the authentication response sent by server 102, the authentication response includes the authentication result of server 102 for client 1011. When the authentication result indicates that client 1011 authentication is successful, then client 1011 continues to execute the operation and maintenance tasks, for example, executing scripts, collecting data, or uploading files. When the authentication result indicates that client 1011 authentication fails, then client 1011 exits the operation and maintenance tasks.
[0093] Please continue to refer to Figure 3 In Figure 3In steps 4 to 6 of the illustrated example, after the server 102 authenticates the client 1011 based on the authentication identifier, it sends an authentication response to the client 1011. After receiving the authentication response, the client 1011 first performs integrity verification and signature verification on the data to ensure that the data has not been tampered with or damaged during transmission. Then the client 1011 parses the authentication response and extracts the authentication result.
[0094] In Figure 3 the illustrated example, the client 1011 performs corresponding processing according to the parsed authentication result. If the authentication is successful, the client 1011 updates the local authentication status information and saves the relevant authorization information for subsequent other interaction operations with the server 102. If the authentication fails, the client 1011 makes corresponding prompts or records on the device side 101 according to the error code and error information, such as recording the reason for the authentication failure in the device log or sending a notification message to the device administrator.
[0095] In the embodiment of the present application, after the client 1011 of the device side 101 passes the authentication, it can specify various types of operation and maintenance tasks. For example, the client 1011 collects various running data of virtual machines or bare-metal servers at preset time intervals, such as system metrics such as CPU usage, memory usage, network traffic, and logs and performance data of application programs. For another example, the operation and maintenance tasks executed by the client 1011 can be software upgrades, configuration modifications, service restarts, etc. for virtual machines or bare-metal servers.
[0096] It can be seen from the above embodiments that in the embodiment of the present application, the device side can add an authentication identifier to the authentication request based on the data staining mechanism, which can indicate the characteristic information of the terminal device, so that the server can authenticate the client in the device side based on the characteristic information of the device side. Since the network communication of the virtual machine client belongs to a definite physical device, the server can authenticate the virtual machine client based on the characteristic information of the physical device, and there is no need to pre-set additional data on the virtual machine. Virtual machines created in various ways can be accessed into the cluster without intervention when installing the client, thereby improving the authentication efficiency of the client in the device side.
[0097] Based on the above method embodiments, the embodiment of the present application further provides an authentication device based on the data staining mechanism. The following specifically introduces the authentication device based on the data staining mechanism provided by the embodiment of the present application.
[0098] Please refer to Figure 6 , Figure 6 which is a schematic structural diagram of an authentication device based on the data staining mechanism provided by the embodiment of the present application. In Figure 6In the illustrated example, the authentication device 600 based on the data coloring mechanism is used to implement each of the steps performed by the device side 101 or the service side 102 in the automated operation and maintenance system 10 in the above embodiments. The authentication device 600 based on the data coloring mechanism includes a transceiver unit 601 and a processing unit 602.
[0099] In an alternative embodiment, the authentication device 600 based on the data coloring mechanism is used to implement each of the steps performed by the device side 101 of the automated operation and maintenance system 10 in the above embodiments.
[0100] Among them, the transceiver unit 601 is used to send an authentication request to the service side. The authentication request is used to request the service side to authenticate the client. The client includes a proxy program deployed on the device side. The processing unit 602 is used to add an authentication identifier to the authentication request based on the data coloring mechanism. The authentication identifier is used to indicate the characteristic information of the device side. The characteristic information is used by the service side to authenticate the client. The transceiver unit 601 is further used to receive the authentication response sent by the service side. The authentication response includes the authentication result of the service side on the client.
[0101] In a possible implementation manner, the processing unit 602 is further used to intercept the authentication request based on the network identifier. The network identifier is used to identify the service side corresponding to the authentication request. The network identifier includes an IP address, a domain name, a virtual IP address, or a virtual domain name.
[0102] In a possible implementation manner, a virtual IP address corresponds to one or more service sides, and a virtual domain name corresponds to one or more service sides.
[0103] In a possible implementation manner, the processing unit 602 is further used to configure the mapping relationship between the network identifier and the service side. The mapping relationship is used by the client to identify the authentication request to be intercepted.
[0104] In a possible implementation manner, the processing unit 602 is specifically used to add an authentication identifier to the authentication request based on the extensible packet filter eBPF program.
[0105] In a possible implementation manner, the authentication request includes resource data encrypted based on the public key certificate of the service side. The resource data includes one or more of the following: hostname, operating system version, IP address.
[0106] In a possible implementation manner, the authentication identifier includes one or more of the following: version number, device side information length, device side information data. The device side information data is used to carry the characteristic information. The characteristic information includes one or more of the following: device serial number, central processing unit CPU motherboard serial number, device side MAC address.
[0107] In another alternative embodiment, the authentication device 600 based on the data staining mechanism is used to implement each step executed by the server 102 of the automated operation and maintenance system 10 in the above embodiments.
[0108] Among them, the transceiver unit 601 is used to receive an authentication request sent by the device side. The authentication request is used to request the server to authenticate the client. The client includes an agent program deployed on the device side. The authentication request includes adding an authentication identifier based on the data staining mechanism. The authentication identifier is used to indicate the feature information of the device side. The processing unit 602 is used to parse the authentication request and generate an authentication response based on the authentication identifier in the authentication request. The transceiver unit 601 is also used to send the authentication response to the client. The authentication response includes the authentication result of the server for the client. The authentication result includes that the client authentication is successful or the client authentication fails.
[0109] In a possible implementation manner, the processing unit 602 is specifically configured to determine that the client authentication corresponding to the authentication request is successful when the feature information of the device side indicated by the authentication identifier conforms to the feature information of the legal device list. When the feature information of the device side indicated by the authentication identifier does not conform to the feature information of the legal device list, it is determined that the client authentication corresponding to the authentication request fails.
[0110] It can be understood that the transceiver unit 601 and the processing unit 602 in the authentication device 600 based on the data staining mechanism can exist as functional modules and Figure 1 each module in the automated operation and maintenance system 10 has a mapping, so as to implement the functions of each module in the automated operation and maintenance system 10.
[0111] It should be understood that the division of units in the above device is only a logical function division. In actual implementation, it can be fully or partially integrated into a physical entity, or physically separated. And the units in the device can all be implemented in the form of software called by processing elements; they can also all be implemented in the form of hardware; or some units can be implemented in the form of software called by processing elements, and some units can be implemented in the form of hardware. For example, each unit can be a separately established processing element, or can be integrated in a certain chip of the device. In addition, it can also be stored in the memory in the form of a program, and the function of the unit is called and executed by a certain processing element of the device. In addition, all or part of these units can be integrated together or can be independently implemented. The processing element mentioned here can also be called a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above units can be implemented by the integrated logic circuit of the hardware in the processor element or in the form of software called by the processing element.
[0112] It should be noted that, for the above method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by this application.
[0113] Other reasonable combinations of steps that those skilled in the art can think of based on the above description also fall within the protection scope of this application. Secondly, those skilled in the art should also be familiar that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by this application.
[0114] Please refer to Figure 7 , Figure 7 which is a schematic structural diagram of a computing device provided by an embodiment of this application. As Figure 7 shown, the computing device 700 includes: a processor 701, a memory 702, a communication interface 703, and a bus 704. The processor 701, the memory 702, and the communication interface 703 are coupled through a bus (not labeled in the figure). The memory 702 stores instructions. When the execution instructions in the memory 702 are executed, the computing device 700 executes the methods executed by the automated operation and maintenance system in the above method embodiments.
[0115] The computing device 700 can be one or more integrated circuits configured to implement the above methods. For example: one or more application specific integrated circuits (ASICs), or, one or more digital signal processors (DSPs), or, one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. Again, when the units in the device can be implemented in the form of a processing element scheduler, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call programs. Again, these units can be integrated together to be implemented in the form of a system-on-a-chip (SOC).
[0116] The processor 701 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0117] The memory 702 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0118] The memory 702 stores executable program code, and the processor 701 executes the executable program code to implement the functions of the foregoing units or modules respectively, thereby implementing the foregoing authentication method based on the data coloring mechanism. That is to say, the memory 702 stores instructions for executing the foregoing authentication method based on the data coloring mechanism.
[0119] The communication interface 703 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 700 and other devices or communication networks.
[0120] In addition to the data bus, the bus 704 may also include a power bus, a control bus, a status signal bus, etc. The bus can be a Peripheral Component Interconnect Express (PCIe) bus, or an Extended Industry Standard Architecture (EISA) bus, a Unified Bus (Ubus or UB), a Compute Express Link (CXL), a Cache Coherent Interconnect for Accelerators (CCIX), etc. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0121] Please refer to Figure 8 , Figure 8 for a schematic diagram of a computing device cluster provided by an embodiment of this application. As Figure 8 shown, the computing device cluster 800 includes at least one computing device 700.
[0122] As Figure 8 shown, the computing device cluster 800 includes at least one computing device 700. Instructions for executing the above authentication method based on the data coloring mechanism may be stored in the memories 702 of one or more of the computing devices 700 in the computing device cluster 800.
[0123] In some possible implementation manners, partial instructions for executing the above authentication method based on the data coloring mechanism may also be stored separately in the memories 702 of one or more of the computing devices 700 in the computing device cluster 800. In other words, a combination of one or more computing devices 700 may jointly execute the instructions for executing the above authentication method based on the data coloring mechanism.
[0124] It should be noted that the memories 702 in different computing devices 700 in the computing device cluster 800 may store different instructions, respectively for executing partial functions of the above node load control device. That is, the instructions stored in the memories 702 of different computing devices 700 may implement the functions of one or more modules in the transceiver unit and the processing unit.
[0125] In some possible implementations, one or more computing devices 700 in the computing device cluster 800 can be connected via a network. Among them, the network can be a wide area network or a local area network, etc.
[0126] Please refer to Figure 9 , Figure 9 which is a schematic diagram of a computer device in a computer cluster being connected via a network provided by an embodiment of the present application. As Figure 9 shown, two computing devices 700A and 700B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device.
[0127] In a possible implementation, the memory in computing device 700A stores instructions for executing the functions of the transceiver unit. At the same time, the memory in computing device 700B stores instructions for executing the functions of the processing unit.
[0128] It should be understood that Figure 9 the functions of computing device 700A shown in
[0129] can also be completed by multiple computing devices. Similarly, the functions of computing device 700B can also be completed by multiple computing devices.
[0130] In another embodiment of the present application, a computer-readable storage medium is further provided. The computer-readable storage medium stores computer-executable instructions. When the processor of the device executes the computer-executable instructions, the device executes the method performed by the automated operation and maintenance system 10 in the above method embodiment.
[0131] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0132] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.
[0133] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0134] In addition, in each embodiment of this application, the functional units can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0135] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, read-only memory), random access memories (RAM, random access memory), magnetic disks, or optical disks and other various media that can store program codes.
Claims
1. An authentication method based on data coloring mechanism, characterized in that: include: The device sends an authentication request to the server, wherein the authentication request is used to request the server to perform identity authentication on the client, wherein the client includes an agent program deployed on the device; The device adds an authentication identifier to the authentication request based on a data coloring mechanism, where the authentication identifier is used to indicate feature information of the device, and the feature information is used by the server to authenticate the client; The device receives an authentication response sent by the server, where the authentication response includes an authentication result of the server on the client.
2. The method according to claim 1, characterized in that Before the device adds the authentication identifier to the authentication request based on the data coloring mechanism, the method further includes: The device intercepts the authentication request based on a network identifier, where the network identifier is used to identify a server corresponding to the authentication request, and the network identifier includes an IP address, a domain name, a virtual IP address, or a virtual domain name.
3. The method according to claim 2, characterized in that The virtual IP address corresponds to one or more of the servers, and the virtual domain name corresponds to one or more of the servers.
4. The method according to claim 2, characterized in that: Before the device intercepts the authentication request based on the network identifier, the method further includes: The device side configures a mapping relationship between the network identifier and the server side, and the mapping relationship is used by the client to identify the authentication request to be intercepted.
5. The method according to any one of claims 1 to 4, characterized in that The device side adds the authentication identifier in the authentication request based on the data coloring mechanism, including: The device adds the authentication identifier in the authentication request based on the extensible packet filter eBPF program.
6. The method according to any one of claims 1 to 4, characterized in that The authentication request includes resource data encrypted based on the server public key certificate, and the resource data includes one or more of the following: host name, operating system version, and IP address.
7. The method according to any one of claims 1 to 4, characterized in that The authentication identifier includes one or more of the following: version number, device-side information length, and device-side information data. The device-side information data is used to carry the characteristic information. The characteristic information includes one or more of the following: device serial number, central processing unit CPU motherboard serial number, and device-side MAC address.
8. An authentication device based on a data coloring mechanism, characterized in that: include: A transceiver unit, used to send an authentication request to a server, wherein the authentication request is used to request the server to perform identity authentication on a client, wherein the client includes an agent program deployed on the device; A processing unit, configured to add an authentication identifier to the authentication request based on a data coloring mechanism, wherein the authentication identifier is used to indicate feature information of the device end, and the feature information is used by the server end to authenticate the client end; The transceiver unit is further configured to receive an authentication response sent by the server, wherein the authentication response includes an authentication result of the server on the client.
9. The device according to claim 8, characterized in that The processing unit is also used for: The authentication request is intercepted based on a network identifier, where the network identifier is used to identify a server corresponding to the authentication request, and the network identifier includes an IP address, a domain name, a virtual IP address, or a virtual domain name.
10. The device according to claim 9, characterized in that The virtual IP address corresponds to one or more of the servers, and the virtual domain name corresponds to one or more of the servers.
11. The device according to claim 9, characterized in that The processing unit is also used for: A mapping relationship between the network identifier and the server is configured, wherein the mapping relationship is used by the client to identify the authentication request to be intercepted.
12. The device according to any one of claims 8 to 11, characterized in that The processing unit is specifically used for: The authentication identifier is added to the authentication request based on an extensible packet filter eBPF program.
13. The device according to any one of claims 8 to 11, characterized in that The authentication request includes resource data encrypted based on the server public key certificate, and the resource data includes one or more of the following: host name, operating system version, and IP address.
14. The device according to any one of claims 8 to 11, characterized in that The authentication identifier includes one or more of the following: version number, device-side information length, and device-side information data. The device-side information data is used to carry the characteristic information. The characteristic information includes one or more of the following: device serial number, central processing unit CPU motherboard serial number, and device-side MAC address.
15. A computing device cluster, characterized in that: The method comprises at least one computing device, wherein the computing device comprises a processor, wherein the processor is coupled to a memory, and wherein the processor is used to store instructions. When the instructions are executed by the processor, the computing device cluster performs the method according to any one of claims 1 to 7.
16. A computer-readable storage medium having instructions stored thereon, characterized in that: When the instructions are executed, the computer is caused to perform the method according to any one of claims 1 to 7.
17. A computer program product, comprising instructions, characterized in that: When the instructions are executed, the computer implements the method according to any one of claims 1 to 7.