User-oriented multi-tenant security enhancement service isolation system
By adopting a combination of soft and hard isolation method in the multi-tenant resource management system, combining namespace, firewall and access policies, the security isolation of the multi-tenant environment and dynamic resource adjustment are achieved, solving the problems of isolation policy failure and improper resource allocation in the existing system, and improving the stability and security of the system.
Patent Information
- Application Number
- CN202510386632.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When the existing multi-tenant resource management system realizes security isolation and dynamic resource adjustment, there are problems with isolation policy failure, resource competition and security, which cannot meet the user's security isolation requirements. At the same time, simple physical node isolation will lead to insufficient or excessive resource allocation, affecting the operation of business services.
The user-oriented multi-tenant security enhancement business isolation system is adopted, combining soft isolation and hard isolation, and the security isolation of computing resources, storage resources and network resources is achieved through namespaces, firewalls, access policies and resource controllers, and the automatic dynamic allocation of resources is achieved through resource monitoring modules and dynamic adjustment strategies.
It realizes safe and efficient resource intensive management in a multi-tenant environment, significantly improves cross-resource utilization, improves system stability and security, and meets the needs of tenants' business isolation.
Smart Images

Figure CN120151065A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information processing, and particularly relates to a multi-tenant security-enhanced service isolation system for users. Background Art
[0002] For multi-tenant resource management, a namespace mechanism is usually adopted to achieve dynamic allocation of computing resources and network policy configuration. However, it is prone to isolation policy failure, resulting in resource competition and security issues, and cannot meet the user's security isolation requirements. And the isolation of pure physical nodes usually leads to insufficient resource allocation, affecting the operation of business services, or over-allocation. The requirements for container security have become more complex, especially posing more stringent challenges to the requirements for container cloud security isolation. Summary of the Invention
[0003] The main purpose of the present invention is to provide a multi-tenant security-enhanced service isolation system for users and a method for dynamic resource adjustment to solve the deficiencies in the related technologies.
[0004] To achieve the above object, according to the first aspect of the present invention, there is provided a multi-tenant security-enhanced service isolation system for users, including at least one tenant. Each tenant has an independent namespace, and at least one corresponding service, at least one node, and network storage space; a common node pool including a plurality of common nodes, where a firewall is provided between the common nodes and the nodes corresponding to the tenants; a resource controller for dynamically adjusting the resources of different tenants.
[0005] Optionally, the system further includes a resource monitoring module for managing the resources created by each tenant in its respective independent namespace.
[0006] Optionally, access policies are configured between the services of different tenants, and isolation at the network resource level is achieved through the access policies.
[0007] Optionally, firewalls are provided between the nodes of different tenants.
[0008] Optionally, there is data isolation between the network storage spaces of different tenants.
[0009] Optionally, dynamically adjusting the resources of different tenants includes: determining the resource adjustment method corresponding to each tenant, where the adjustment method includes expanding nodes or shrinking nodes; determining the number of the expanded nodes or shrunk nodes based on the probability of expansion required within the current time interval; and performing expansion or contraction based on the number.
[0010] Optionally, determining the resource adjustment method corresponding to each tenant includes: determining the resource adjustment method based on the total resource size of all node resources allocated to each tenant, the preset resource utilization rate, and the average resource utilization rate.
[0011] Optionally, determining the number of nodes to be scaled out or scaled in includes: determining the number of nodes to be scaled out or scaled in according to the resource size of service requests under each tenant, the total resource size of all node resources allocated to the tenant, and the resource size of the largest node resource among all node resources allocated to the tenant.
[0012] Optionally, determining the probability of needing to scale out within the current time interval includes: calculating the probability of needing to scale out within the current time interval based on the net scale-out times corresponding to a certain time interval in historical data.
[0013] According to a second aspect of the present invention, there is provided a method for dynamically adjusting resources, which determines a resource adjustment method based on the total resource size of all node resources allocated to each tenant, the preset resource utilization rate, and the average resource utilization rate; determines the number of nodes to be scaled out or scaled in according to the resource size of service requests under each tenant, the total resource size of all node resources allocated to the tenant, and the resource size of the largest node resource among all node resources allocated to the tenant; and performs scaling out or scaling in based on the number.
[0014] The multi-tenant security enhanced service isolation system and the method for dynamically adjusting resources according to the present embodiment are directed to users. The system includes: at least one tenant, where each tenant has an independent namespace, as well as corresponding at least one service, at least one node, and network storage space; a common node pool, including a plurality of common nodes, where a firewall is provided between the common nodes and the nodes corresponding to the tenants; and a resource controller for dynamically adjusting the resources of different tenants. A secure isolation environment for computing resources, storage resources, and network resources is constructed by combining soft isolation and hard isolation, realizing safe and efficient resource intensive management in a multi-tenant environment, and determining the resource adjustment method for each tenant according to the index data of each tenant, realizing automatic dynamic allocation of tenant resources, and meeting the tenant service isolation requirements on the premise of ensuring system stability and security. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1It is a schematic architecture diagram of a multi-tenant security enhanced service isolation system for users according to an embodiment of the present invention;
[0017] Figure 2 It is an application schematic diagram of a resource dynamic adjustment method according to an embodiment of the present invention;
[0018] Figure 3 It is a logical schematic diagram of a resource dynamic adjustment method according to an embodiment of the present invention. Detailed implementation manners
[0019] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0020] It should be noted that the terms "first", "second", etc. in the specification of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances for the embodiments of the present invention described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0021] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the drawings and in combination with the embodiments.
[0022] According to an embodiment of the present invention, there is provided a multi-tenant security enhanced service isolation system for users, including at least one tenant. Among them, each tenant has an independent namespace, as well as at least one corresponding service, at least one node, and network storage space; a common node pool, including a plurality of common nodes, wherein a firewall is provided between the common nodes and the nodes corresponding to the tenants; a resource controller for dynamically adjusting the resources of different tenants.
[0023] In this embodiment, referring to Figure 1, in order to achieve safe and efficient resource intensive management in a multi-tenant environment, a method of combining soft isolation and hard isolation is proposed to build a multi-tenant environment. A firewall is configured between tenant physical nodes, network policies are configured between namespaces, and access policies are configured between namespaces and the services under them to achieve security isolation at the network resource level; independent network storage is used to achieve data isolation; dynamic adjustment of tenant resource policies and dynamic prediction means are adopted to achieve intensive use of system computing resources. To solve the resource competition problem that may occur in a single soft isolation strategy, hard isolation means are combined. At the physical level, independent servers, storage devices, etc. are used to provide resources for different tenants.
[0024] As an optional implementation manner of this embodiment, the system further includes a resource monitoring module to manage the resources created by each tenant in their respective independent namespaces.
[0025] In this optional implementation manner, a tenant soft isolation strategy is adopted to achieve isolation of computing resources and network resources between tenants through software-level control and management. Namespaces are used as a soft isolation mechanism. Each tenant can create and manage resources in its own namespace, and resource quotas can be used to ensure that tenants do not exceed their allocated resources. At the same time, it supports configuring network policies between tenant namespaces and the services under them to achieve in and out stack traffic control.
[0026] As an optional implementation manner of this embodiment, access policies are configured between the services of different tenants to achieve isolation at the network resource level through the access policies.
[0027] As an optional implementation manner of this embodiment, a firewall is set between the nodes of different tenants.
[0028] As an optional implementation manner of this embodiment, there is data isolation between the network storage spaces of different tenants.
[0029] In this optional implementation manner, when building a hard isolation environment, configuring the network and providing independent tenant network storage can ensure the security of network traffic and user data at the same time.
[0030] As an optional implementation manner of this embodiment, dynamically adjusting the resources of different tenants includes: determining the resource adjustment methods corresponding to each tenant, where the adjustment methods include expanding nodes or shrinking nodes; determining the number of the expanding nodes or shrinking nodes based on the probability of expansion required within the determined current time interval; performing expansion or shrinking based on the number.
[0031] As an alternative implementation of this embodiment, determining the resource adjustment method corresponding to each tenant includes: determining the resource adjustment method based on the total resource size of all node resources allocated to each tenant, a preset resource utilization rate, and an average resource utilization rate.
[0032] As an alternative implementation of this embodiment, determining the number of nodes to be scaled out or scaled in includes: determining the number of nodes to be scaled out or scaled in according to the resource size of service requests under each tenant, the total resource size of all node resources allocated to the tenant, and the resource size of the largest node resource among all node resources allocated to the tenant.
[0033] As an alternative implementation of this embodiment, determining the probability of needing to scale out within the current time interval includes: calculating the probability of needing to scale out within the current time interval based on the net scale-out times corresponding to a certain time interval in historical data.
[0034] In the above alternative implementation, a resource dynamic adjustment strategy is adopted to effectively manage tenant resources and ensure that the service performance of tenant services is not affected. According to the metric data of each cluster namespace corresponding to each tenant, calculate the total resource size of all nodes allocated to the tenant, a preset resource utilization rate, and an average resource utilization rate, and determine that the resource adjustment method for the tenant is to scale out or scale in nodes P1. Then, according to the resource size of service requests under the tenant, the total resource size of all nodes allocated to the tenant, and the resource size of the largest node among all nodes allocated to the tenant, determine the number of nodes to be scaled out or scaled in P2. At the same time, combine the net scale-out times corresponding to each time interval that is consistent with a certain time interval in historical data, calculate the probability of needing to scale out within the current time interval, and perform a scale-out operation through prediction. Refer to Figure 2 , which shows the resource dynamic adjustment algorithm. The total resource size n of all node resources allocated to the tenant; the preset resource utilization rate S; the average resource utilization rate U; the resource size R of service requests under the tenant; the resource size c of the largest node resource among all node resources allocated to the tenant.
[0035] This embodiment innovates a software-hardware combined isolation method to achieve dynamic allocation of computing resources and dynamic allocation of network policy configuration, meeting both the requirements of security isolation and resource intensive use. This method not only significantly improves cross-resource utilization, but also greatly enhances system stability and security, while increasing the flexibility of the system. It is particularly suitable for vertical industry fields where the system has a deep penetration level and many using units, and there are interaction requirements among them, but there are also high requirements for security isolation in the business field.
[0036] Further, on the above basis, in order to further enhance security isolation, the technology of endogeneous security strong isolation containers can be further adopted to improve the isolation level of containers, reduce the probability and severity of container compromise, prevent the further spread of risks, improve the security of services on the cloud platform, achieve the goal of improving container security, and enhance the security protection ability. The information processing steps to ensure the security of the running container environment can include:
[0037] Step 201: After determining to expand resources for the current service in the enabled monitoring environment, the resource scheduling service. When the enabled monitoring environment determines whether to expand resources for a certain service, it obtains the real-time status information of different sub-resource pools of the cloud platform server and the real-time running status information of each service deployed and running on the cloud platform; and judges whether to expand resources for a certain service based on the real-time status information of the different sub-resource pools and the real-time running status information of each service.
[0038] In this step, the running monitoring environment collects two types of status data in real time: the usage status of the current resources in the cloud platform server resource pool and the real-time running status of the service cluster. It judges whether to expand service resources according to the running status, and at the same time checks whether there are expandable resources according to the resource usage situation. If both conditions are met, the resource scheduling service allocates new resources for the service.
[0039] As an optional implementation manner of this embodiment, before the enabled monitoring environment obtains the real-time status information of different sub-resource pools of the cloud platform server and the real-time running status information of each service deployed and running on the cloud platform, different servers are divided into the same resource sub-pool; traffic control is performed on different resource sub-pools; wherein, the basis for the division is to divide the security levels of the servers based on a hierarchical division strategy; the services deployed and running on the cloud platform are divided into service confidentiality levels; each service is determined to have a corresponding core degree; different core degree services are sorted in descending order, wherein the level of the core degree is used as the basis for the resource allocation order.
[0040] In this optional implementation, when performing physical isolation based on the security level of tenant devices, the security levels of servers are divided. The security levels of servers are divided by using security policies and their own performance, etc., and different security level tags are added to the servers. The servers are divided into different security levels according to the added security level tags. Thus, the unified resource pool is divided into resource sub-pools of different levels. When performing traffic control on different resource sub-pools, network tools such as iptables are used to perform traffic control on resource sub-pools of different security levels, enabling services within the same security level sub-pool to access each other and ensuring that servers within the same security level can communicate and cooperate normally. Servers in the resource sub-pool with a high security level are allowed to access servers in the resource sub-pool with a low security level. This type of access is usually one-way to meet requirements such as management and monitoring. Servers in the resource sub-pool with a low security level are prohibited from accessing servers in the resource sub-pool with a high security level to further prevent potential security threats such as malicious attacks and data theft.
[0041] When performing classification of security levels, when describing the resources required by a service, service security level information can be added, and the service security level is divided based on the sensitivity of the data, the importance of the business, and potential security risks. The service security level information mainly provides a scheduling basis for container orchestration and scheduling. During container orchestration, the scheduler will match the corresponding level of resource sub-pool according to the service security level information.
[0042] When performing classification of core degrees, when describing the resources required by a service, core degree information can be added. The classification of core degrees can be determined according to factors such as the business importance of the service, the degree of dependence on system functions, and the correlation between services.
[0043] It should be understood that the above classifications can all be obtained by the user through configuration based on the management terminal.
[0044] Step 202: The resource scheduling service invokes the service task scheduler plugin, so that the service task scheduler plugin generates pending task information for the newly allocated resources and sends the pending task information to the resource scheduling service, enabling the resource scheduling service to invoke the deployment and upgrade service. The deployment and upgrade service creates a container for a certain service through the server indicated by the newly allocated resources and creates a service instance in the container.
[0045] In this step, based on the current available resources, the resource scheduling service uses a scheduling algorithm to newly allocate resources for the service and submits the newly allocated resources to the task scheduler plugin of the service. The task scheduler of the service is ready to process tasks based on the allocated resources, and hands over the resources and tasks to the resource scheduling service; the resource scheduling service hands over the resources and tasks to the deployment and upgrade service; the deployment and upgrade service, according to the resource information, finds the server providing the resource, and based on the microservice operation management agent of the server and the task executor of the service, obtains the container image according to the service information, creates a Docker container, and updates and improves the service configuration information; assuming that service A needs to be scaled out, the task executor of the service starts service A in the container, creates service instance A3, and service instance A3 registers the service in the service A cluster, realizing the expansion of the service A cluster.
[0046] As an optional implementation manner of this embodiment, when the resource scheduling service determines newly allocated resources for a certain service, the method includes: determining the corresponding resource requirement data for the certain service; determining the service confidentiality level and the security level of the server to determine the target resource sub-pool matching the certain service; determining the remaining resource information of each server in the target resource sub-pool; and determining the server corresponding to the certain service based on the remaining resource information and the resource requirement data.
[0047] In this optional implementation manner, assuming that the software service set is A = {a 1 , a 2 , …, a m}, and the server set is S = {s 1 , s 2 , …, s n}, sort the services in descending order according to the core degree core(a i ), calculate the resource requirement resource(a i ) = (r i1 , r i2 , r i3 ) for each software service ai, which respectively represent CPU, memory, and disk resources, and the remaining resources remaining(s j ) = (rr j1 , rr j2 , rr j3 ) of server sj. Let the confidentiality level of software service a i be sec(a i ), and the confidentiality level of server s j be sec(s j ), then find that while satisfying sec(a i ) <= sec(s j ) and The smallest server s j Deployment a i .
[0048] In this embodiment, by clarifying the service confidentiality level and service core degree to match the corresponding level of resource sub-pool and implementing a cross-level deployment strategy, a two-level scheduling mechanism for service confidentiality level and service core degree is introduced, which supports the dynamic expansion and contraction of the service cluster, ensures that the security and performance requirements of the service are met, improves the overall resource utilization rate, and can further improve the security and stability of the platform.
[0049] As an optional implementation manner of this embodiment, the method further includes determining container risks by using a container monitoring module: the container monitoring module obtains real-time container security metric information in the running container environment from a container anomaly monitoring tool; based on the security metric information and the security level of the server corresponding to the container, determines the risk scores of multiple preset metric items, and determines the target risk score based on the scores under each of the preset metric items; based on the risk level to which the target risk score belongs, executes different risk handling processes.
[0050] In this optional implementation manner, container security isolation can be further achieved through container threat automated flow control processing. Commonly used image scanning tools such as Trivy and Clair, as well as container anomaly behavior monitoring tools such as Falco, can be used for real-time container security monitoring. The risks are comprehensively rated according to the monitoring results in combination with the server security level, and the weighted impact of high-security-level servers on the risk rating is increased to further improve the risk level of high-security-level servers. The risk levels are generally divided into high, medium, and low, and are comprehensively evaluated by a risk rating algorithm.
[0051] As an optional implementation manner of this embodiment, executing different risk handling processes based on the risk level to which the target risk score belongs includes: if the risk level is medium, cutting off the inbound and outbound traffic of the server node where the risk container is located; if the risk level is high, cutting off the inbound and outbound traffic of the server node where the risk container is located and outputting an alarm message.
[0052] In this optional implementation manner, for different risk ratings, in addition to the regular danger alarms, for medium-level risks, an automatic defense mechanism needs to be started to isolate the risk scope. With the help of iptables rules, a two-way blocking method at the container level and the server level is completed, that is, in addition to cutting off the inbound and outbound traffic of the risk container / the server node where the risk container is located, other normal containers / the server nodes where the normal containers are located are also made to reject the access of the risk container / the containers on the server node where the risk container is located, preventing the risk from further expanding. For high-level risks, in addition to taking medium-risk isolation measures, an alarm is used to prompt the user to manually intervene as soon as possible to block the risk source and confirm whether to stop the service.
[0053] As an optional implementation of this embodiment, when determining the scores under each of the preset metrics, the method includes: a first score determined based on whether it is deployed to different cloud computing nodes according to different service security levels; a second score determined based on whether the network security service and the business service are isolatedly deployed; a third score determined based on whether the container image source is trustworthy, whether there are vulnerabilities in the image, and the vulnerability level; a fourth score determined based on whether the image is minimized and whether the proportion of non-essential components is the lowest; a fifth score determined based on whether there is an image signature and integrity check; a sixth score determined based on detecting abnormal behaviors of processes, file systems, and networks; a seventh score determined based on monitoring resource abuse; an eighth score determined based on container escape defense configuration; a ninth score determined based on regular abnormal traffic, software vulnerabilities or configuration errors, data security, and malware scanning.
[0054] In this optional implementation, there are 9 monitoring metrics. Assuming the rating factors are F i (i = 1 to 9), and the corresponding weights are w j (j = 1 to 9), and The scores of each metric factor are shown in Table 1. The score range is from 0 to 10 points, where 0 represents the safest and 10 represents the most dangerous. For risk assessment, first score each security rating factor according to Table 1 to obtain the score S i (i = 1 to 9), and 0 ≤ S i ≤ 10. The comprehensive risk score is R, and the calculation formula is . When 0 ≤ R < 3, it indicates that the system risk is relatively low. When 3 ≤ R < 7, it indicates that the risk is relatively high, and the risk level is medium risk. When 7 ≤ R < 10, it indicates that the risk is very high, and the level is high risk. The specific items and calculation rules of each metric refer to Table 1:
[0055] Table 1
[0056]
[0057] This embodiment adopts the above-mentioned endogenous security strong isolation container technical solution, and uses the physical isolation technology based on the security level of tenant devices and the container threat automatic flow control technology to achieve the isolation of the user perception layer of the container, improve the isolation level of the container, reduce the probability and severity of the container being compromised, prevent the further spread of risks, improve the security of services on the cloud platform, achieve the purpose of improving container security, and the security protection ability is improved by 20%.
[0058] According to the embodiments of the present invention, there is also provided a method for dynamically adjusting resources, refer to Figure 3, including step 101: determining a resource adjustment method based on the total resource size of all node resources allocated to each tenant, a preset resource utilization rate, and an average resource utilization rate; step 102: determining the number of the nodes for expansion or contraction according to the resource size of the service requests under each tenant, the total resource size of all node resources allocated to the tenant, and the resource size of the largest node resource among all node resources allocated to the tenant; step 103: performing expansion or contraction based on the number.
[0059] As an optional implementation manner of this embodiment, the system includes at least one tenant, where each tenant has an independent namespace, and a corresponding at least one service, at least one node, and network storage space; a common node pool, including a plurality of common nodes, where a firewall is provided between the common nodes and the nodes corresponding to the tenants; and a resource controller for dynamically adjusting the resources of different tenants.
[0060] As an optional implementation manner of this embodiment, the system further includes a resource monitoring module for managing the resources created by each tenant in its respective independent namespace.
[0061] As an optional implementation manner of this embodiment, access policies are configured between the services of different tenants, and isolation at the network resource level is achieved through the access policies.
[0062] As an optional implementation manner of this embodiment, firewalls are provided between the nodes of different tenants.
[0063] As an optional implementation manner of this embodiment, there is data isolation between the network storage spaces of different tenants.
[0064] According to an embodiment of the present invention, the present invention further provides a readable storage medium storing computer instructions for enabling a computer to execute the method described in any of the above embodiments when executed.
[0065] According to an embodiment of the present invention, the present invention further provides a computer program product that can implement the method described in any of the above embodiments when executed by a processor.
[0066] Those skilled in the art can understand that to implement all or part of the processes in the above method embodiments, a program can be used to instruct relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the method embodiments as described above. Among them, the storage medium can be a magnetic disk, an optical disc, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD), etc.; the storage medium can also include a combination of the above types of memories.
[0067] Although the embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present disclosure. Such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A user-oriented multi-tenant security enhanced service isolation system, characterized in that: include: At least one tenant, wherein each tenant has an independent namespace, and corresponding at least one service, at least one node, and network storage space; A public node pool, including multiple public nodes, wherein a firewall is set between the public nodes and the nodes corresponding to the tenants; Resource controller, dynamically adjusts resources for different tenants.
2. The user-oriented multi-tenant security enhanced service isolation system according to claim 1 is characterized in that: The system also includes a resource monitoring module to manage the resources created by each tenant in their own independent namespace.
3. The user-oriented multi-tenant security enhanced service isolation system according to claim 2 is characterized in that: Access policies are configured between services of different tenants, and isolation at the network resource level is achieved through the access policies.
4. The user-oriented multi-tenant security enhanced service isolation system according to claim 3 is characterized in that: Firewalls are set up between nodes of different tenants.
5. The user-oriented multi-tenant security enhanced service isolation system according to claim 4 is characterized in that: There is data isolation between network storage spaces of different tenants.
6. The user-oriented multi-tenant security enhanced service isolation system according to claim 1, characterized in that: Dynamic adjustment of resources for different tenants includes: Determine a resource adjustment method corresponding to each tenant, wherein the adjustment method includes expanding or reducing the capacity of a node; Determine the number of the expansion nodes or the reduction nodes; Capacity expansion or reduction is performed based on the quantity.
7. The user-oriented multi-tenant security enhanced service isolation system according to claim 6, characterized in that: Determine the resource adjustment methods corresponding to each tenant, including: The resource adjustment method is determined based on the total resource size of all node resources allocated to each tenant, the preset resource utilization rate and the average resource utilization rate.
8. The user-oriented multi-tenant security enhanced service isolation system according to claim 6, characterized in that: Determining the number of the expansion nodes or the reduction nodes includes: The number of nodes to be expanded or reduced is determined according to the resource size of the service request belonging to each tenant, the total resource size of all node resources allocated to the tenant, and the resource size of the largest node resource among all node resources allocated to the tenant.
9. The user-oriented multi-tenant security enhanced service isolation system according to claim 6, characterized in that: Before determining the number of nodes to be expanded or reduced, the probability of requiring expansion within the current time interval is also determined, including: Based on the number of net capacity expansions corresponding to a certain time interval in historical data, calculate the probability of needing capacity expansion in the current time interval.
10. A method for dynamically adjusting tenant resources based on the system of claim 1, characterized in that: include: Determine the resource adjustment method based on the total resource size of all node resources allocated to each tenant, the preset resource utilization rate and the average resource utilization rate; Determine the number of nodes to be expanded or reduced according to the resource size of the service request belonging to each tenant, the total resource size of all node resources allocated to the tenant, and the resource size of the largest node resource among all node resources allocated to the tenant; Capacity expansion or reduction is performed based on the quantity.
Citation Information
Patent Citations
Management network and method for multi-tenant container cloud computing system
CN105554015A
SaaS product multi-tenant environment and equipment isolation method
CN117527373A
Tenant resource allocation method and device, equipment and storage medium
CN117687803A
Power distribution network information infrastructure high-elasticity cloud security service method
CN117873639A
Multi-tenant management method and device of intelligent internet-of-things system, medium and equipment
CN117992181A
Cited By
Server leasing data maintenance method and application system
CN120415926A
A data maintenance method and application system for server leasing
CN120415926B
Data physical node isolation scheduling method and system
CN121396606A