Edge security management and control method based on Internet of Things technology and related equipment

By transmitting business models and security policies between cloud platforms and edge computing systems, business-oriented edge security control is achieved, solving the problem of single and high cost of edge security defense strategies in the existing technology, and improving security defense effect and flexibility.

CN120166136APending Publication Date: 2025-06-17HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410178072.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-14
Filing Date
2024-02-08
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The existing edge security defense strategy is single-point defense and cannot flexibly respond to different business scenarios, resulting in poor security defense effects and relying on multiple defense methods to lead to excessive security costs.

Method used

By establishing a communication connection between the cloud platform and the edge computing system, the cloud platform acquires business models and security policies and distributes them to the edge computing system, so that it can execute services in accordance with the business model and security policies, thereby achieving business-oriented edge security control.

Benefits of technology

Improves edge security defense effects, flexibly responds to different business needs, reduces security costs, and ensures the security of business execution and data security in the event of disconnection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120166136A_ABST
    Figure CN120166136A_ABST
Patent Text Reader

Abstract

The invention provides an edge security management and control method based on the Internet of Things technology and related equipment, and the method comprises the steps that a cloud platform firstly obtains a first service model and a first security policy of a first service, the first service model comprises a first service process, and the first service process is used for indicating a process of processing the first service by an edge computing system; the first security policy comprises a corresponding relationship between the first application module and a first sub-business process in the first business process, a corresponding relationship between the second application module and a second sub-business process in the first business process, and a data flow direction between the first application module and the second application module; the plurality of application modules includes a first application module and a second application module, and then the cloud platform sends the first service model and the first security policy to the edge computing system. According to the scheme of the invention, business-oriented edge security management and control are realized, and the edge security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of edge computing, and particularly to an edge security control method and related devices based on Internet of Things technology. Background Art

[0002] With the rapid development of edge computing, edge security issues have attracted increasing attention in the industry, and various edge security defense means have emerged, such as application access verification, interface security management, vulnerability detection, data encrypted transmission, data secure storage, sensitive data processing, etc.

[0003] However, the existing edge security defense strategies focus on single-point defense and are irrelevant to specific business scenarios: using a single fixed security defense strategy to deal with different services is not flexible enough, and it is impossible to achieve differentiated security defenses for the security requirements of different services, resulting in poor security defense effects. And simply relying on superimposing multiple edge security defense means to improve the security defense level will lead to continuous increase in security costs, which is not equivalent to the actual business value. Summary of the Invention

[0004] This application provides an edge security control method and related devices based on Internet of Things technology, which realizes edge security control oriented to services and has better security defense effects.

[0005] In a first aspect, this application provides an edge security control method, which is applied to a cloud platform. The cloud platform is used to manage infrastructure, and multiple application modules are stored in the infrastructure. The cloud platform has a communication connection with an edge computing system, and the edge computing system is used to manage at least one edge device. Specifically, the cloud platform first obtains a first service model and a first security policy of a first service. Among them, the first service model includes a first service process, and the first service process is used to indicate the process of the edge computing system processing the first service. The first security policy includes the correspondence between a first application module and a first sub-service process in the first service process, the correspondence between a second application module and a second sub-service process in the first service process, and the data flow direction between the first application module and the second application module. The multiple application modules include the first application module and the second application module. Then, the cloud platform sends the first service model and the first security policy to the edge computing system.

[0006] Optionally, the above-mentioned first application module and second application module can be any two application modules among the above-mentioned multiple application modules, or specific two application modules among the above-mentioned multiple application modules, which are not specifically limited here. The above-mentioned first service process includes multiple sub-service processes (including the first sub-service process and the second sub-service process). The fact that a certain sub-service process has a correspondence with a certain application module means that the application module is responsible for / designated to execute the sub-service process.

[0007] In this solution, the cloud platform sends the service model and security policy corresponding to the service to the edge computing system, enabling the edge computing system to execute the corresponding service according to the service model and security policy, thereby ensuring that there are no deviations in the execution of the service by the edge computing system and reducing edge security risks. Even in the case of disconnection between the cloud platform and the edge computing system, the edge computing system can still execute the service according to the service model and security policy previously issued by the cloud platform, ensuring that the service execution is not affected, thereby enhancing edge security. When the edge computing system is disconnected from the network and cannot be connected to the cloud platform, even if the first service process on the edge computing system is maliciously tampered with / incorrectly modified, according to the data flow specified in the first security policy, the relevant data of the first service can be locked, preventing the data from being exported, thus ensuring data security.

[0008] Moreover, since the first service model set in this application does not involve application modules and only simply indicates the implementation process of the first service (i.e., the first service process), the decoupling between the service process and the application module is achieved, thereby enhancing the reusability of the service model. Different users can formulate different security policies according to actual application requirements and match them with this service model to achieve the corresponding edge security protection effect.

[0009] Based on the first aspect, in a possible implementation, the first security policy further includes a prohibition policy corresponding to the first service and the corresponding relationship between the prohibition policy and the third application module. The third application module is an application module other than the first application module and the second application module among the above-mentioned multiple application modules, and the edge computing system has the third application module. That is to say, the first security policy also stipulates the prohibition policy related to the first service to meet the security requirements of the first service, and specifically indicates in the first security policy which application module(s) is / are subject to this prohibition logic, enabling the edge security policy to restrict the actions / behaviors of the corresponding application module according to this prohibition logic, thereby enhancing edge security.

[0010] Based on the first aspect, in a possible implementation, the first security policy further includes an encryption policy corresponding to the first service, and the encryption policy includes at least one of hardware encryption, software encryption, and communication encryption. That is to say, one or more encryption methods can be flexibly selected according to the actual security requirements of the first service.

[0011] Based on the first aspect, in a possible implementation, the first business model is input by the user into the cloud platform, or the first business model is selected by the user from multiple business models provided by the cloud platform. Among them, the above-mentioned multiple business models correspond to multiple services one by one, and each business model in the multiple business models includes the business process of the corresponding service. That is to say, the user can edit and upload the business model to the cloud platform by himself, and then the cloud platform distributes the business model to the edge computing system. The user can also directly select a suitable (meeting his own business needs) business model from the multiple business models provided by the cloud platform, so that there is no need for the user to edit the business model by himself and upload it to the cloud platform, which is more convenient and fast. Then the user instructs the cloud platform to distribute the selected business model to the edge computing system.

[0012] Based on the first aspect, in a possible implementation, the cloud platform receives the business data of the first service sent by the edge computing system, and then displays the business data or the business data processed by the cloud platform to the user. That is to say, the cloud platform can directly display the business data uploaded by the edge computing system to the user, or can first process the business data and then display it to the user after processing. In this way, some data processing functions are placed on the cloud platform for execution, thereby reducing the data processing pressure on the edge computing system.

[0013] Based on the first aspect, in a possible implementation, the cloud platform receives the monitoring information sent by the edge computing system, where the monitoring information indicates whether the edge computing system conforms to the first business model and the first security policy during the execution of the first service. That is to say, when the edge computing system detects that there are actions that do not conform to the first business model and the first security policy during the execution of the first service, the edge computing system can send the monitoring information to the cloud platform, so that the user can understand the business execution situation of the edge computing system on the cloud platform, and then the user can respond and process the business anomalies on the edge computing system in a timely manner.

[0014] Based on the first aspect, in a possible implementation, the cloud platform obtains the second business model and the second security policy of the second service, where the second business model includes a second business process, and the second business process is used to indicate the process of the edge computing system processing the second service. The second security policy includes the corresponding relationship between the fourth application module and the first sub-business process in the second business process, the corresponding relationship between the fifth application module and the second sub-business process in the second business process, and the data flow between the fourth application module and the fifth application module. The multiple application modules include the fourth application module and the fifth application module. Then, the cloud platform sends the second business model and the second security policy to the edge computing system.

[0015] It can be seen that this solution supports dynamic service adjustment. When a user needs to adjust the services executed on the edge computing system, the user can adjust the corresponding service models and security policies of the services on the cloud platform. Then, the cloud platform sends the new service models and new security policies to the edge computing system, enabling the edge computing system to execute the adjusted services according to the new service models and new security policies, thereby realizing the dynamic service adjustment of the cloud platform to the edge computing system. Moreover, this adjustment method is very flexible and efficient, without the need to shut down the edge devices in the edge computing system to perform service adjustment. Therefore, it can avoid the interruption of the service on the edge computing system and also avoid affecting other services on the edge computing system.

[0016] In a second aspect, the present application also provides an edge security control method, which is applied to an edge computing system. The edge computing system is used to manage at least one edge device, and the edge computing system has a communication connection with a cloud platform. The cloud platform is used to manage the infrastructure, and the infrastructure stores service applications, and the service applications include multiple application modules. Specifically, the edge computing system receives the first service model and the first security policy of the first service sent by the cloud platform. Among them, the first service model includes a first service process, and the first service process is used to indicate the process for the edge computing system to process the first service. The first security policy includes the correspondence between the first application module and the first sub-service process in the first service process, the correspondence between the second application module and the second sub-service process in the first service process, and the data flow direction between the first application module and the second application module. The multiple application modules include the first application module and the second application module. Then, the edge computing system configures the first application module and the second application module on the edge computing system according to the first service model and the first security policy, so that the first application module and the second application module execute the first service according to the first service process and the data flow direction between the first application module and the second application module.

[0017] That is to say, the user can formulate the service models and security policies corresponding to the services on the cloud platform. Then, the cloud platform sends the service models, security policies, and service applications to the edge computing system, enabling the edge computing system to execute the corresponding services according to the service models and security policies, thereby realizing the security control of the edge computing system and improving the edge security.

[0018] Based on the second aspect, in a possible implementation manner, the first security policy also defines an encryption policy corresponding to the first service, and the encryption policy includes at least one of hardware encryption, software encryption, and communication encryption.

[0019] Based on the second aspect, in a possible implementation, when the encryption policy corresponding to the first service includes hardware encryption, the first service model and the first security policy are stored in the hardware security chip of the edge device, and the hardware security chip is used to perform hardware encryption on the first service model and the first security policy. That is to say, the edge computing system can perform hardware encryption on the service model and the security policy sent by the cloud platform through the hardware security chip to provide hardware-level security protection, thereby effectively preventing the service model and the security policy on the edge computing system from being maliciously tampered with, so that the service execution on the edge computing system will not deviate. Even when the cloud platform and the edge computing system are disconnected, the edge computing system can still execute services according to the service model and the security policy previously sent by the cloud platform, ensuring that the service execution is not affected, thereby enhancing the edge security.

[0020] Based on the second aspect, in a possible implementation, the first security policy further includes a prohibition policy corresponding to the first service and the corresponding relationship between the prohibition policy and the third application module. The third application module is an application module other than the first application module and the second application module among the multiple application modules. The edge computing system can configure the third application module on the edge computing system according to the prohibition policy, so that the third application module follows the prohibition policy during the execution of the first service by the first application module and the second application module.

[0021] Based on the second aspect, in a possible implementation, the edge computing system sends monitoring information to the cloud platform, and the monitoring information indicates whether the edge computing system complies with the first service model and the first security policy during the execution of the first service. That is to say, the edge computing system can monitor the local service execution based on the service model and the security policy sent by the cloud platform. In the case of service execution deviation, corresponding monitoring information is sent to the cloud platform, and then remote monitoring of the edge computing system is realized on the cloud platform. Users on the cloud platform can quickly understand the service execution situation on the edge computing system in order to make timely responses.

[0022] Based on the second aspect, in a possible implementation, the prohibition policy corresponding to the first service includes prohibiting local storage, and the third application module corresponding to this prohibition policy is the data storage module. When the data transfer module on the edge computing system performs local data transfer, the edge computing system can send monitoring information to the cloud platform, and the monitoring information indicates that the data storage module on the edge computing system violates the prohibition of local storage in this prohibition policy.

[0023] Based on the second aspect, in a possible implementation, the prohibition policy corresponding to the first service includes prohibiting local data transfer. The third application module corresponding to this prohibition policy is the data transfer module. When the data transfer module on the edge computing system performs local data transfer, the edge computing system sends monitoring information to the cloud platform. Here, local data transfer is an operation of data transmission between different edge devices in the edge computing system, and this monitoring information indicates that the data transfer module on the edge computing system violates the prohibition of local data transfer in the above-mentioned prohibition policy.

[0024] Based on the second aspect, in a possible implementation, the first application module and the second application module on the edge computing system execute the first service according to the above data flow direction to obtain the service data of the first service, and then the edge computing system sends the service data to the cloud platform.

[0025] Based on the second aspect, in a possible implementation, the edge computing system receives the second service model and the second security policy of the second service sent by the cloud platform. Here, the second service model includes a second service process, and the second service process is used to indicate the process for the edge computing system to process the second service. The second security policy includes the correspondence between the fourth application module and the first sub-service process in the second service process, the correspondence between the fifth application module and the second sub-service process in the second service process, and the data flow direction between the fourth application module and the fifth application module. The multiple application modules include the fourth application module and the fifth application module. Then, the edge computing system configures the fourth application module and the fifth application module on the edge computing system according to the second service model and the second security policy, so that the fourth application module and the fifth application module execute the second service according to the second service process and the data flow direction between the fourth application module and the fifth application module.

[0026] In a third aspect, the present application further provides a cloud platform, including an acquisition module and a sending module. The acquisition module is used to acquire the first service model of the first service, where the first service model includes a first service process, and the first service process is used to indicate the process for the edge computing system to process the first service. The acquisition module is further used to acquire the first security policy of the first service, where the first security policy includes the correspondence between the first application module and the first sub-service process in the first service process, the correspondence between the second application module and the second sub-service process in the first service process, and the data flow direction between the first application module and the second application module. The multiple application modules include the first application module and the second application module. The sending module is used to send the first service model and the first security policy to the edge computing system.

[0027] The above cloud platform may also include more or fewer units / modules, which are not specifically defined here. The cloud platform in the third aspect is specifically used to execute the method of any implementation scheme in the first aspect. For details, please refer to the foregoing introduction and will not be elaborated here.

[0028] In a fourth aspect, the present application further provides an edge computing system, including a receiving module and a control module. The receiving module is configured to receive a first service model and a first security policy of a first service sent by a cloud platform. The first service model includes a first service process, and the first service process is used to indicate the process for the edge computing system to process the first service. The first security policy includes the correspondence between a first application module and a first sub-service process in the first service process, the correspondence between a second application module and a second sub-service process in the first service process, and the data flow direction between the first application module and the second application module. The multiple application modules include the first application module and the second application module. The control module is configured to configure the first application module and the second application module on the edge computing system according to the first service model and the first security policy, so that the first application module and the second application module execute the first service according to the data flow direction.

[0029] The above edge computing system may also include more or fewer units / modules, which are not specifically defined here. The edge computing system in the fourth aspect is specifically used to execute the method of any implementation scheme in the second aspect. For details, please refer to the foregoing introduction and will not be elaborated here.

[0030] In a fifth aspect, the present application further provides an edge security control method, which is applied to a cloud-edge collaboration system. The cloud-edge collaboration system includes a cloud platform and an edge computing system. The cloud platform is used to manage infrastructure, and the infrastructure stores business applications. The business applications include multiple application modules. The cloud platform has a communication connection with the edge computing system, and the edge computing system is used to manage at least one edge device. Specifically, the cloud platform obtains a first service model of a first service, where the first service model includes a first service process, and the first service process is used to indicate the process for the edge computing system to process the first service; the cloud platform obtains a first security policy of the first service, where the first security policy includes the correspondence between a first application module and a first sub-service process in the first service process, the correspondence between a second application module and a second sub-service process in the first service process, and the data flow direction between the first application module and the second application module. The multiple application modules include the first application module and the second application module; the cloud platform sends the first service model and the first security policy to the edge computing system; the edge computing system configures the first application module and the second application module on the edge computing system according to the first service model and the first security policy, so that the first application module and the second application module execute the first service according to the data flow direction.

[0031] The cloud platform in the above fifth aspect is specifically used to execute the method of any implementation in the first aspect, and the edge computing system in the fifth aspect is specifically used to execute the method of any implementation in the second aspect. For details, please refer to the previous introduction and will not be elaborated here.

[0032] In a sixth aspect, the present application further provides a cloud-edge collaboration system, including a cloud platform and an edge computing system. The cloud platform is used to execute the method of any implementation in the first aspect, and the edge computing system is specifically used to execute the method of any implementation in the second aspect. For details, please refer to the full text explanation and will not be elaborated here.

[0033] In a seventh aspect, the present application further provides a computing device cluster, including at least one computing device, and each computing device includes a processor and a memory. The processor of the at least one computing device is used to execute the instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method of any implementation in the first aspect or the second aspect.

[0034] In an eighth aspect, the present application further provides a computer-readable storage medium, including computer program instructions. When the computer program instructions are executed by a computing device cluster (including at least one computing device), the computing device cluster executes the method of any implementation in the first aspect or the second aspect.

[0035] In a ninth aspect, the present application further provides a computer program product including instructions. When the instructions are run by a computing device cluster (including at least one computing device), the computing device cluster is caused to execute the method of any implementation in the first aspect or the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for description in the embodiments.

[0037] Figure 1 is an architecture diagram of a cloud-edge collaboration system provided by an embodiment of the present application;

[0038] Figure 2 is a schematic diagram of docking edge base software and a data bus provided by an embodiment of the present application;

[0039] Figure 3 is a flowchart of an edge security control method based on the Internet of Things technology provided by an embodiment of the present application;

[0040] Figure 4 is a schematic diagram of executing a first service based on a first service model and a first security policy provided by an embodiment of the present application;

[0041] Figure 5It is a schematic diagram of executing a second service based on a second service model and a second security policy provided by an embodiment of the present application;

[0042] Figure 6 It is a schematic structural diagram of a computing device provided by an embodiment of the present application;

[0043] Figure 7 It is a schematic diagram of a computing device cluster provided by an embodiment of the present application;

[0044] Figure 8 It is a schematic diagram of two computing devices interacting through a network provided by an embodiment of the present application. Detailed implementation manners

[0045] Next, the technical solutions of the embodiments of the present application will be described in conjunction with the specification drawings in the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0046] To improve the edge security protection effect, the present application provides a cloud-edge collaboration system, including a cloud platform and an edge computing system. The cloud platform issues the service model and security policy corresponding to the service to the edge computing system, so that the edge computing system strictly executes the service according to the service model and security policy, which can avoid deviations when the edge computing system executes the service and reduce the edge security risk. The cloud-edge collaboration system will be introduced in detail below.

[0047] Please refer to Figure 1 , Figure 1 It is an architecture diagram of a cloud-edge collaboration system provided by an embodiment of the present application, including a cloud platform 100 and an edge computing system 200. The cloud platform 100 and the edge computing system 200 have a communication connection, which can be a wired connection or a wireless connection, and the embodiments of the present application do not make specific limitations. The cloud platform 100 and the edge computing system 200 will be specifically introduced below.

[0048] 1. Cloud platform 100: It is used to manage the infrastructure of cloud service providers, where the infrastructure is used to provide cloud computing resources (such as computing, storage, network and other resources).

[0049] Specifically, the cloud platform 100 and the basic resources constitute a cloud environment, which is an entity that uses basic resources to provide cloud services to users under the cloud computing model. Among them, the cloud platform 100 can provide access interfaces (such as an interactive interface or an application programming interface (API)) to interact with users of cloud service providers (or called tenants / customers), and then users can choose to deploy and run their own applications / businesses / services on the infrastructure.

[0050] Optionally, one or more business applications can be stored on the infrastructure. Users can log in to the cloud platform 100 through the access interface, and then upload their own business applications on the interactive interface of the cloud platform 100. Then, the cloud platform 100 stores the user's business applications in the infrastructure. Subsequently, users can deploy the business applications to corresponding locations according to actual business needs (such as deploying in the cloud data center or the edge computing system 200 in the cloud environment). Cloud service providers can also provide one or more business applications for users to choose from. These one or more business applications are stored in the infrastructure, and users interact with the cloud platform 100 to select appropriate business applications for deployment and use.

[0051] Optionally, a business application can be used to implement one or more businesses, or multiple business applications can jointly implement a business. Each business application contains one or more application modules (which are software modules), and each application module is used to implement part or all of the functions of the business application. By combining different application modules, a complete business application can be constructed, and thus the corresponding business can be implemented based on the business application. There can be the same or different application modules between different business applications. The relationships between application modules can be different, depending on business requirements and designs. A common relationship is the collaborative cooperation between application modules.

[0052] Taking an e-commerce business as an example, this business includes functions such as order management, inventory management, and payment management. These functions can be implemented by different business applications respectively, and each business application contains corresponding application modules. The business application for implementing order management may include application modules such as order creation, order query, and order cancellation; the business application for implementing inventory management may include application modules such as inventory query, inventory update, and inventory warning; the business application for implementing payment management may include application modules such as payment interface, payment verification, and refund processing. These application modules need to cooperate with each other to complete the entire business process of the e-commerce business. For example, when an order is created, the order management application module needs to interact with the inventory management application module to update inventory information; the payment management application module needs to interact with the order management application module to verify payment information and complete the payment operation.

[0053] Optionally, in addition to the above forms of business applications, multiple application modules can also be directly stored on the infrastructure, and each application module is used to implement certain functions.

[0054] Optionally, the infrastructure may include one or more cloud data centers, and each cloud data center includes one or more types of servers. There are certain differences in the hardware and / or software configurations of different types of servers. For example, the servers can be of types such as general-purpose servers, computing servers, and storage servers. For servers in high-performance computing (HPC) scenarios, multiple central processing units (CPUs) are generally configured; for servers in scenarios such as artificial intelligence (AI) or heterogeneous computing power, they are not only configured with CPUs but may also be configured with coprocessors such as graphics processing units (GPUs), neural network processing units (NPUs), and data processing units (DPUs). In addition to the above server types, there can be other ways to divide server types, and the embodiments of the present application do not make specific limitations.

[0055] 2. Edge computing system 200: used to manage at least one edge device (a cluster of multiple edge devices), where the edge device is used to provide edge computing resources (such as computing, storage, communication, etc. resources). The edge computing system 200 can be a management software and can be deployed on one or more edge devices ( Figure 1 the edge devices are not directly drawn), or can be deployed on other devices. Without special instructions, the former will be mainly used as an example for description hereinafter.

[0056] It should be understood that compared with the infrastructure managed by the above cloud platform 100, the edge devices managed by the edge computing system 200 refer to terminal devices that are geographically closer to the data source / user and have characteristics such as low latency and high bandwidth. Therefore, the user can log in to the cloud platform 100 to operate and instruct the cloud platform 100 to deploy the business application corresponding to a certain business to the edge devices managed by the edge computing system 200 (closer to the user / terminal device, near the customer site), so as to achieve lower latency and more efficient business functions. Regarding the types of edge devices, the embodiments of the present application do not make specific limitations. For example, the edge devices can be edge gateways, edge servers, intelligent cameras, and other devices.

[0057] Optionally, as Figure 1As shown, one or more hardware security chips 300 can be equipped on the edge devices managed by the edge computing system 200. The hardware security chip 300 is a dedicated chip for implementing hardware encryption. Regarding the type of the hardware security chip 300, the embodiments of the present application do not make specific limitations. For example, the hardware security chip 300 can be a trusted platform module (TPM), a trusted computing module (TPCM), etc. chips, all of which can be used to implement security functions and protections at the hardware level. It should be noted that the hardware security chip 300 can be integrated inside the edge devices managed by the edge computing system 200, or can be additionally installed on the edge devices (such as plugged on the edge devices), and the embodiments of the present application do not make specific limitations.

[0058] Optionally, as Figure 1 shown, the edge computing system 200 / edge device can be connected to one or more terminal devices 400 (which can be wired or wireless connections) to obtain data of the corresponding terminal devices 400. Among them, the terminal device 400 can be an industrial production device, a smart home device, a sensor, an instrument, etc., and the embodiments of the present application do not make specific limitations. It should be understood that the type of data obtained by the edge computing system 200 / edge device from the terminal device is related to the specific services to be executed on the edge computing system 200 / edge device, and the embodiments of the present application also do not make specific limitations. For example, in the business scenario of numerically controlled machine tool control based on the Internet of Things (IoT) technology, the edge computing system 200 can have a communication connection with a numerically controlled machine tool (a type of terminal device 400). The edge computing system 200 obtains the production data of the numerically controlled machine tool according to the requirements of the data machine tool control service, and then reports the production data to the cloud platform 100. For another example, in the remote monitoring business scenario, the edge computing system 200 can be connected to one or more cameras (a type of terminal device 400). The edge computing system 200 obtains the video data / image data collected by these cameras according to the requirements of the remote monitoring service, and then preprocesses the obtained video data / image data (such as data cleaning, data format conversion, data aggregation, etc. operations), and then sends the preprocessed video data / image data to the cloud platform 100.

[0059] Furthermore, both the above cloud platform 100 and the edge computing system 200 can be divided into multiple unit modules according to functions. Figure 1An exemplary division method of the cloud platform 100 and the edge computing system 200 is given. Among them, the cloud platform 100 includes an acquisition module 101, a sending module 102, a receiving module 103, and an interaction module 104, and the edge computing system 200 includes a receiving module 201, a management and control module 202, and a sending module 203. It should be noted that Figure 1 The given division method is only for example and does not constitute a specific limitation on the embodiments of the present application. The cloud platform 100 and the edge computing system 200 may both include more or fewer unit modules. For example, Figure 1 the sending module 102 and the receiving module 103 in may be combined into one unit module, and the management and control module 202 may also be split into an execution module (for instructing various application modules in the edge computing system 200 to perform corresponding operations / functions) and a monitoring module (for monitoring the service execution status of the edge computing system 200). Additionally, a processing module may be added to the cloud platform 100 for subsequent processing of the service data sent by the edge computing system 200.

[0060] Next, the functions of each unit module in the cloud platform 100 and the edge computing system 200 will be specifically described.

[0061] (1) Acquisition module 101: It is used to acquire the first service model of the first service and is also used to acquire the first security policy of the first service.

[0062] Among them, the first service model is used to indicate the process of the edge computing system 200 for processing the first service. The first service model includes a first service process, and the first service process may include multiple sub-service processes. Regarding the service type of the first service, the embodiments of the present application do not make specific limitations. For example, the first service may be a service of types such as home remote monitoring, traffic management, production control, intelligent healthcare, environmental protection detection, etc.

[0063] Correspondingly, the first security policy defines the correspondence between the first application module and the first sub-business process in the first business process of the first business model, the correspondence between the second application module and the second sub-business process in the first business process, and the data flow direction between the first application module and the second application module. Here, it is assumed that there are N application modules stored in the infrastructure managed by the cloud platform 100, where N is a positive integer greater than 1, and different application modules have different functions. The above-mentioned first application module and second application module belong to the N application modules, and can be any two or specific two of the N application modules; the above-mentioned first sub-business process and second sub-business process can be any two sub-business processes in the first business process, or any two sub-business processes. It should be understood that the fact that an application module has a correspondence with a sub-business process in the first business process means that the application module is designated to execute the actions of the sub-business process. Optionally, in addition to the above-mentioned first sub-business process and second sub-business process, the first business process may further include other sub-business processes, and the first security policy indicates the correspondence between other application modules except the first application module and the second application module and the other sub-business processes.

[0064] For example, assume that the first business is a production equipment control business, and there are 5 application modules stored in the infrastructure, denoted as application modules A, B, C, D, and E for ease of description. The first business model of the first business includes a first business process, and the first business process includes the following three sub-business processes: collecting production data, preprocessing the production data, and sending the preprocessed production data to the cloud platform 100. Correspondingly, the first security policy of the first business includes: the correspondence between application module A and the sub-business process of collecting production data, the correspondence between application module B and the sub-business process of preprocessing the production data, and the correspondence between application module D and the sub-business process of sending the preprocessed production data to the cloud platform 100. In addition, the first security policy further includes: application module A sends the collected production data to application module B, and application module B sends the preprocessed production data to application module D, that is, the data flow direction is application module A → application module B → application module D.

[0065] It can be seen that the first business model actually defines (or describes) a set of business processes for the first business according to the business scenario. However, the first business model does not specify the execution objects of each sub-business process in the business process. The first security policy defines the functional roles of some / all application modules in the business application (that is, describes what sub-business processes of the first business each application module is designated to execute), that is, specifies the execution objects of each sub-business process in the business process. The first security policy also defines the association relationships (i.e., data flow directions) between application modules. The functional roles and association relationships of application modules depend on the actual business requirements of the first business, and the business functions of the first business are realized through the collaborative cooperation between application modules.

[0066] Optionally, the first security policy further includes a prohibition policy corresponding to the first business and the corresponding relationship between the third application module and the prohibition policy, that is, the third application module is subject to the prohibition policy, and the third application module is prohibited from performing the operations / actions described in the prohibition policy. The third application module is other application modules among the above N application modules except the first application module and the second application module.

[0067] For example, assume that the third application module includes a data storage module (one of the application modules), and the data storage module has the function of local storage. The first security policy includes a prohibition policy corresponding to the first business: local storage is not allowed to prevent data leakage locally. Correspondingly, the first security policy also includes the corresponding relationship between the data storage module and the prohibition policy, which means that the data storage module is prohibited from performing local storage operations.

[0068] Optionally, the first security policy further includes an encryption policy corresponding to the first service. The encryption policy may include at least one of hardware encryption, software encryption, and communication encryption. Among them, hardware encryption refers to an encryption method that uses dedicated hardware components (such as hardware security chips / smart cards / encryption modules) to perform encryption and decryption operations, usually featuring high security, high speed, and low power consumption. Software encryption refers to an encryption method that uses software algorithms to implement data encryption and decryption. Software encryption usually has the advantages of high flexibility, easy implementation, and maintenance. Software encryption algorithms can be symmetric encryption algorithms, asymmetric encryption algorithms, hash algorithms, national encryption algorithms (i.e., a series of data encryption processing algorithms developed and formulated by the National Cryptography Administration), etc. This application embodiment does not make specific limitations. Through software encryption, security protection at the software level can be achieved to prevent data leakage / malicious instruction issuance caused by hacker attacks. Communication encryption refers to using encryption technology in network communication to protect the security and privacy of communication data. Communication encryption can be implemented using encryption algorithms such as symmetric encryption, asymmetric encryption, and hybrid encryption. This application embodiment does not make specific limitations. It should be understood that one or more of the above encryption methods can be flexibly selected according to the security requirements of the first service as the encryption policy corresponding to the first service in the first security policy, thereby realizing the association between the encryption method and the service.

[0069] This application embodiment does not limit the specific manner in which the obtaining module 101 obtains the first service model and the first security policy.

[0070] For example, the user can log in to the cloud platform 100 through the access interface and input the first service model and the first security policy corresponding to the first service on the interaction interface of the cloud platform 100. Correspondingly, the obtaining module 101 in the cloud platform 100 obtains the first service model and the first security policy input by the user, and then sends the first service model and the first security policy to the sending module 102 in the cloud platform 100. Furthermore, the sending module 102 sends the first service model and the first security policy to the edge computing system 200.

[0071] For another example, the cloud service provider can also provide one or more service models for the user to choose from, and these one or more service models are stored in the infrastructure managed by the cloud platform 100. The user can interact with the cloud platform 100 to select one of these one or more service models as the first service model of the first service, and then the user can also formulate the first security policy corresponding to the first service model on the cloud platform 100. Correspondingly, the obtaining module 101 in the cloud platform 100 obtains the first service model selected by the user and the first security policy formulated by the user, and then sends the first service model and the first security policy to the sending module 102 in the cloud platform 100. Furthermore, the sending module 102 sends the first service model and the first security policy to the edge computing system 200.

[0072] Optionally, the first security policy further includes a reporting address corresponding to the service data of the first service, that is, the edge computing system 200 can only send the service data of the first service to the cloud platform 100 through this reporting address, and cannot send the service data of the first service to other addresses, so as to ensure the data security of the first service.

[0073] It should be noted that since the first service model set in the embodiment of the present application does not involve application modules, but only simply points out the implementation process of the first service (that is, the first service process), the decoupling between the service process and the application module is realized, thereby improving the reusability of the service model. Different users can formulate different security policies according to actual application requirements and match them with this service model, so as to achieve the corresponding edge security protection effect. For example, on the basis of selecting the first service model, the user formulates a corresponding first security policy according to its actual application requirements, so as to control the process of the edge computing system 200 executing the first service with the first service model and the first security policy.

[0074] It should also be noted that the first service model and the first security policy were described separately above. In fact, the first service model and the first security policy can also be regarded as an information whole. This information whole includes both the first service process (including multiple sub-service processes) of the first service, and the corresponding relationship between multiple application modules and multiple sub-service processes in the first service process, and also includes the data flow between the above multiple application modules. Correspondingly, the sending module 102 can send this information whole to the edge computing system 200, so as to realize edge security control for the first service at the edge computing system 200. Unless otherwise specified, the first service model and the first security policy will be described as two parts of information in the following text.

[0075] (2) Sending module 102: It is used to send the first service model and the first security policy corresponding to the first service to the edge computing system 200, and is also used to send multiple application modules (or the entire service application) to the edge computing system 200. Optionally, the first service model, the first security policy, and multiple application modules can be sent to the edge computing system 200 together, or can be sent to the edge computing system 200 separately.

[0076] (3) Receiving module 201: It is used to receive the first service model and the first security policy sent by the cloud platform 100, and is also used to receive multiple application modules sent by the cloud platform 100.

[0077] (4) Management and control module 202: It is used to configure the corresponding application modules on the edge computing system 200 to execute the first service according to the data flow specified in the first security policy according to the first service model and the first security policy.

[0078] Specifically, the management and control module 202 can install and deploy the business applications (i.e., multiple application modules) sent by the cloud platform 100 on the edge computing system 200. Optionally, the business applications can be deployed on one or more edge devices managed by the edge computing system 200. For example, the business application can be deployed on each edge device, or different application modules in the business application can be deployed on different edge devices. The embodiments of the present application do not make specific limitations in this regard.

[0079] The management and control module 202 can also control the relevant application modules (including the first application module and the second application module) on the edge devices managed by the edge computing system 200 to execute the first service based on the first service model and the first security policy sent by the cloud platform 100. That is, it controls the relevant application modules on the edge devices managed by the edge computing system 200 to follow the first service model and the first security policy, and restricts the function execution of the relevant application modules and the data flow between the application modules, and so on.

[0080] Optionally, when the encryption policy corresponding to the first service includes hardware encryption, the receiving module 201 can store the first service model and the first security policy sent by the cloud platform 100 into the hardware security chip 300 of the edge computing system 200 to implement hardware encryption of the first service model and the first security policy. It should be understood that the first service model and the first security policy are actually a set of execution policies used to control and restrict the process of the edge computing system 200 executing the first service. By using the hardware security chip 300 to perform hardware encryption on the first service model and the first security policy on the edge computing system 200 side, hardware-level security protection for the first service model and the first security policy can be achieved, preventing the first service model and the first security policy on the edge computing system 200 side from being cracked and changed, that is, locking the execution policy of the first service on the edge computing system 200 side. Even in the case of a disconnection between the cloud platform 100 and the edge computing system 200 (due to network failures or other reasons), it can still ensure that the edge computing system 200 side executes the first service according to the first service model and the first security policy previously issued by the cloud platform 100. The cloud platform 100 has a high degree of security control over the edge computing system 200 side, and can avoid business execution deviations (i.e., the situation of not executing the first service according to the first service model and the first security policy).

[0081] Optionally, in addition to performing hardware encryption on the first service model and the first security policy, the hardware security chip 300 can also perform hardware encryption on the communication authentication credentials (such as keys, tokens, certificates, etc.) between the cloud platform 100 and the edge computing system 200 to prevent being cracked and reduce the risk of spoofing attacks (a form of attack that attempts to obtain access to the system by pretending to be an authorized user).

[0082] Optionally, when the encryption policy corresponding to the first service does not include hardware encryption, the receiving module 201 in the edge computing system 200 may store the first service model and the first security policy received from the cloud platform 100 at other locations (such as memory / disk, etc.) on the edge computing system 200 except for the hardware security chip 300. Then, by parsing the first service model and the first security policy, the management and control module 202 can determine information such as the correspondence between the corresponding application modules and each sub-service process in the first service process, and the data flow between relevant application modules, and then control the relevant application modules on the edge computing system 200 to execute the first service according to the above-parsed information.

[0083] Optionally, the management and control module 202 may also monitor the process of the edge computing system 200 executing the first service based on the first service model and the first security policy. If it is detected that the edge computing system 200 does not execute the first service in accordance with the provisions of the first service model and the first security policy, the management and control module 202 may control the edge computing system 200 to stop executing the first service, or send monitoring information to the cloud platform 100, and the monitoring information indicates that the edge computing system 200 does not conform to the first service model and the first security policy during the execution of the first service. If it is detected that the edge computing system 200 executes the first service in accordance with the provisions of the first service model and the first security policy, the management and control module 202 may also send monitoring information to the cloud platform 100, and the monitoring information indicates that the edge computing system 200 conforms to the first service model and the first security policy during the execution of the first service. It should be noted that the management and control module 202 may send the monitoring information to the cloud platform 100, or the management and control module 202 may hand the monitoring information to the sending module 203, and then the sending module 203 sends the monitoring information to the cloud platform 100. The embodiments of the present application do not make specific limitations.

[0084] For example, assume that the prohibition policy corresponding to the first service in the first security policy includes "prohibiting local storage", and the first security policy includes the correspondence between the data storage module (one of the application modules with local storage function) and this "prohibiting local storage", which indicates that the first service prohibits the data storage module from performing local storage. When the data storage module on the edge device managed by the edge computing system 200 performs local storage, the edge computing system 200 may send monitoring information to the cloud platform 100, and the monitoring information indicates that the data storage module on the edge device managed by the edge computing system 200 violates the "prohibiting local storage" in the prohibition policy.

[0085] For another example, assume that the prohibition policy corresponding to the first service in the first security policy includes "prohibiting local data transfer", and the first security policy includes the correspondence between the data transfer module (one of the application modules with data transfer function) and "prohibiting local data transfer" defined in the first service model. This indicates that the first service prohibits the data storage module from performing local data transfer. Here, local data transfer refers to the operation of data transmission between different edge devices managed by the edge computing system 200. When the data storage module on the edge device managed by the edge computing system 200 performs local data transfer, the edge computing system 200 can send monitoring information to the cloud platform 100, and this monitoring information indicates that the data storage module on the edge device managed by the edge computing system 200 violates the "prohibiting local data transfer" in the prohibition policy.

[0086] The embodiments of the present application do not specifically limit the specific manner in which the control module 202 monitors the application modules on the edge devices managed by the edge computing system 200.

[0087] For example, as Figure 2 shown, the control module 202 can achieve the above monitoring function by docking with the data bus and the edge base software (or called the edge application operation base) in the edge devices managed by the edge computing system 200. Here, the edge base software refers to the software platform installed on the edge device, which is used to manage and coordinate edge computing resources, provide edge computing services and functions. By running the edge base software on the edge device, various application programs (such as business applications) can be supported, and synchronization and collaboration with the cloud can be achieved. The edge base software can be pre-installed when the edge device is first shipped from the factory to ensure communication security during cloud-edge collaborative connection. The data bus is usually a logical bus used to control the data flow between application modules to achieve data interaction and collaboration between application modules. For example, the business application corresponding to an e-commerce service includes application modules such as an order management module, an inventory management module, and a payment management module. When an order is created, the order management module needs to interact with the inventory management module to update the inventory information. At this time, the order management module can send the order information to the data bus, and the inventory management module can receive the order information from the data bus and perform the corresponding inventory update operation. Similarly, when the payment information is verified, the payment management module can send the payment result to the data bus, and the order management module can receive the payment result from the data bus and complete the update of the order status.

[0088] (5) Sending module 203: used to send the service data of the first service to the cloud platform 100.

[0089] Specifically, the control module 202 can control relevant application modules (including the first application module and the second application module) on the edge devices managed by the edge computing system 200 to execute the first service according to the data flow based on the first service model and the first security policy sent by the cloud platform 100, so as to obtain the service data of the first service. Then, the sending module 203 sends the service data to the cloud platform 100.

[0090] For example, assume that the first service process includes the following three sub-service processes: collecting production data, preprocessing the production data, and encrypting the preprocessed production data to send it to the cloud platform 100. Correspondingly, the first security policy includes the following corresponding relationships: the correspondence between application module 1 in the service application and the sub-service process of collecting production data, the correspondence between application module 2 and the sub-service process of preprocessing the production data, and the correspondence between application module N and the sub-service process of data encryption, that is, application module 1 is designated to execute collecting production data, application module 2 is designated to execute preprocessing the production data, and application module N is designated to execute data encryption. The first security policy also includes the following data flow between application modules: application module 1 → application module 2 → application module N.

[0091] The control module 202 parses the above first service model and the first security policy, and then configures application module 1 on the edge device managed by the edge computing system 200 to collect production data (raw data) from a production device (a terminal device 400 connected to the edge computing system 200) and send the production data to application module 2. Then, the control module 202 also instructs application module 2 to preprocess the production data and send the preprocessed production data to application module N. The control module 202 also configures application module N to perform software encryption on the preprocessed production data to obtain service data, and send the service data to the sending module 203. Subsequently, the sending module 203 sends the above service data to the cloud platform 100, thereby realizing the cloudification of the service data of the first service.

[0092] (6) Receiving module 103: Used to receive the service data sent by the edge computing system 200.

[0093] (7) Interaction module 104: Used to display the service data sent by the edge computing system 200 to the cloud platform 100 to the user.

[0094] Optionally, the interaction module 104 can directly perform visual display on the service data uploaded by the edge computing system 200, such as visual display in the form of graphics, tables, texts, etc., which is not specifically limited in the embodiments of the present application. Or, the interaction module 104 can first process the service data uploaded by the edge computing system 200, the processing method is not specifically limited, and then perform visual display on the processed service data.

[0095] It should be understood that the cloud platform 100 can also refer to the deployment method of the above-mentioned first service, and send the service models, security policies, and related application modules corresponding to other services to the edge computing system 200 side. That is, one or more services can be deployed on the edge computing system 200 side. Then, the edge computing system 200 controls the execution process of the corresponding service according to the service model and security policy corresponding to each service, so as to ensure the correctness of the execution of each service, and can also effectively prevent local risks on the edge computing system 200 side (such as malicious operations / misoperations of local personnel, etc.), and improve edge security. Moreover, since different services are executed based on different service models and different security policies, the security defense means on the edge computing system 200 side are no longer single and fixed, but are scenario-based for services. Therefore, the differential of service security defense is realized, the service security defense effect is improved, and the edge security prevention and control cost can be reduced to a certain extent.

[0096] Optionally, assume that after the cloud platform 100 sends the first service model and the first security policy corresponding to the first service to the edge computing system 200, the user has a service adjustment requirement and expects to adjust the first service executed on the edge computing system 200 side to the second service. Then, the cloud platform 100 can refer to the method of obtaining the first service model and the first security policy in the previous text to obtain the second service model and the second security policy corresponding to the second service. Among them, the second service model is used to indicate the process of the edge computing system 200 processing the second service. The second service model includes a second service process, and the second service process includes multiple sub-service processes. The second security policy includes the correspondence between the fourth application module and the first sub-service process in the second service process, the correspondence between the fifth application module and the second sub-service process in the second service process, and the data flow direction between the fourth application module and the fifth application module. Among them, both the fourth application module and the fifth application module belong to the N application modules stored in the infrastructure, and the cloud platform 100 can send the fourth application module and the fifth application module to the edge computing system 200.

[0097] It can be understood that due to certain differences between the first service and the second service (reflected in the differences in service models and security policies), it is impossible to use the first service model and the first security policy previously issued by the cloud platform 100 to implement the second service. Therefore, the cloud platform 100 needs to send new service models and security policies (i.e., the second service model and the second security policy) to the edge computing system 200 so that the edge computing system 200 side executes the second service based on the second service model and the second security policy. It can be seen that by sending new service models and new security policies to the edge computing system 200, the cloud platform 100 can flexibly adjust the services on the edge computing system 200 side, so as to be able to well respond to the development and changes of services.

[0098] It should be noted that the above-mentioned acquisition module 101, sending module 102, receiving module 103, interaction module 104, receiving module 201, management and control module 202, and sending module 203 can all be implemented by software or by hardware. Exemplarily, next, taking the acquisition module 101 as an example, the implementation manner of the acquisition module 101 will be introduced. Similarly, the implementation manners of the above-mentioned other modules can refer to the implementation manner of the acquisition module 101.

[0099] As an example of a software functional unit, the acquisition module 101 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the acquisition module 101 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code may be distributed in the same region, or may be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running this code may be distributed in the same availability zone (AZ), or may be distributed in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally one region may include multiple AZs.

[0100] Similarly, the multiple hosts / virtual machines / containers for running this code may be distributed in the same virtual private cloud (VPC), or may be distributed in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is realized through the communication gateway.

[0101] As an example of a hardware functional unit, the obtaining module 101 may include at least one computing device, such as a server. Alternatively, the obtaining module 101 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0102] The multiple computing devices included in the obtaining module 101 may be distributed in the same region or in different regions. The multiple computing devices included in the obtaining module 101 may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the obtaining module 101 may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0103] Based on the cloud-edge collaboration system introduced above ( Figure 1 and Figure 2 ), the embodiments of the edge security control method based on the Internet of Things technology provided in this application are introduced below.

[0104] Please refer to Figure 3 , Figure 3 which is a flowchart of an edge security control method based on the Internet of Things technology provided in an embodiment of this application, including steps S301 to S304.

[0105] S301. The cloud platform 100 obtains the first service model of the first service.

[0106] Among them, the cloud platform 100 is used to manage the infrastructure, and N application modules are stored in the infrastructure, where N is a positive integer greater than 1. The first service model includes a first service process, and the first service process includes a first sub-service process and a second sub-service process.

[0107] For other content about the first service and the first service model, please refer to Figure 1 for the relevant introduction, which will not be elaborated here.

[0108] S302. The cloud platform 100 obtains the first security policy of the first service.

[0109] Among them, the first security policy includes the correspondence between the first application module and the first sub-business process in the first business process, the correspondence between the second application module and the second sub-business process in the first business process, and the data flow direction between the first application module and the second application module. The first application module and the second application module belong to the above N application modules.

[0110] Optionally, the first security policy further includes a prohibition policy corresponding to the first business and the correspondence between the prohibition policy and the third application module. The third application module is other application modules among the above N application modules except the first application module and the second application module.

[0111] Optionally, the first security policy further includes an encryption policy corresponding to the first business. The encryption policy includes at least one of hardware encryption, software encryption, and communication encryption.

[0112] Optionally, the first business model can be input by the user to the cloud platform 100 or selected by the user from multiple business models provided by the cloud platform 100. Among them, the above multiple business models correspond to multiple businesses one by one, and each business model in the multiple business models includes different business processes.

[0113] For other content about the first security policy, please also refer to Figure 1 the relevant introduction, which will not be elaborated here.

[0114] S303. The cloud platform 100 sends the first business model and the first security policy to the edge computing system 200. Correspondingly, the edge computing system 200 receives the first business model and the first security policy sent by the cloud platform 100.

[0115] Optionally, the first application module and the second application module can be sent to the edge computing system 200 together with the first business model and the first security policy, or can be sent to the edge computing system 200 earlier than / later than the first business model and the first security policy. The embodiments of the present application do not make specific limitations. The time for sending other application modules to the edge computing system 200 is not specifically limited either. The entire business application (including N application modules) can be sent, or only the application modules related to the first business module and the first security policy (including the first application module and the second application module) can be sent to the edge computing system 200.

[0116] S304. The edge computing system 200 configures the first application module and the second application module on the edge computing system 200 according to the first business model and the first security policy, so that the first application module and the second application module execute the first business according to the data flow direction between the first application module and the second application module.

[0117] Optionally, based on the first service model and the first security policy, the edge computing system 200 controls the first application module and the second application module on the edge devices managed by the edge computing system 200 to execute the first service, thereby obtaining the service data of the first service, and then sending the service data of the first service to the cloud platform 100. Correspondingly, the cloud platform 100 can further process and / or visually display the service data uploaded by the edge computing system 200, and the processing method and the visualization method are not specifically limited.

[0118] Optionally, the edge computing system 200 can send monitoring information to the cloud platform 100, where the monitoring information indicates whether the edge computing system 200 complies with the first service model and the first security policy during the execution of the first service. When the edge computing system 200 detects an abnormal operation that does not conform to the first service model and the first security policy, the edge computing system 200 can send the specific information of the abnormal operation (such as the abnormal type, the time when the abnormality occurs, the application module corresponding to the abnormal operation, etc.) to the cloud platform 100 as the monitoring information, so that the user can understand the abnormal operations that occur in the edge computing system 200 on the cloud platform 100, and then take corresponding countermeasures, such as sending a new service model and a new security policy to the edge computing system 200, or instructing the edge computing system 200 to stop executing the first service, and so on.

[0119] Regarding the above abnormal operations, it may include one or more of the following: the sub-service processes executed by the service applications on the edge computing system 200 do not conform to the first service model (such as executing one or more sub-service processes more or less), the actual data flow between the application modules on the edge computing system 200 does not conform to the data flow specified in the first security policy, the application modules on the edge computing system 200 violate the prohibited policy defined in the first security policy, the encryption method adopted by the edge computing system 200 for the first service does not conform to the encryption policy defined in the first security policy (such as executing one or more encryption methods more or less), and so on.

[0120] Next, in combination with Figure 4 , for Figure 3 's method, a specific example will be given.

[0121] For example, assume that a certain business application includes application modules such as a data collection module, a data preprocessing module, a physical model conversion module, a data cloud encryption module, a data storage module, and a data transfer module. The first business is a production equipment monitoring business, and the first business model of the first business includes a first business process. The first business process includes the following four sub-business processes: collecting production data, preprocessing the production data, mapping the preprocessed production data to a physical model, and encrypting the physical model to send it to the cloud platform 100. Among them, the physical model refers to abstracting entities, attributes, and relationships in the physical world into a model that can be understood and processed by a computer. It describes the structure, behavior, and interaction between physical entities for easy management, monitoring, and control. Correspondingly, the first security policy of the first business includes the following corresponding relationships: the corresponding relationship between the data collection module and the sub-business process of collecting production data, the corresponding relationship between the data preprocessing module and the sub-business process of preprocessing production data, the corresponding relationship between the physical model conversion module and the sub-business process of mapping the preprocessed production data to a physical model, and the corresponding relationship between the data cloud encryption module and the sub-business process of encrypting the physical model. The first security policy also includes the following data flow between application modules: data collection module → data preprocessing module → physical model conversion module → data cloud encryption module (these four application modules are Figure 4 shown in gray fill in

[0122] ). Further, the first security policy also includes a prohibition policy corresponding to the first business: neither local storage nor local data transfer is allowed to prevent data leakage locally. The first security policy also includes the corresponding relationship between the data storage module and "no local storage" in the above prohibition policy, indicating that the data storage module is prohibited from performing local storage operations. The first security policy also includes the corresponding relationship between the data transfer module and "no local data transfer open" in the above prohibition policy, indicating that the data transfer module is prohibited from transmitting relevant data of the first business between different edge devices in the edge computing system 200 to avoid data being stolen, tampered with, or lost during the transmission between edge devices, thereby avoiding data transfer from affecting the security and reliability of the data.

[0123] Further, the first security policy also includes an encryption policy corresponding to the first business. This encryption policy includes hardware encryption (implemented by the hardware security chip 300 in the edge computing system 200) and software encryption (implemented by the above data cloud encryption module).

[0124] Such as Figure 4As shown in the figure, the cloud platform 100 sends the above-mentioned first service model, first security policy, and service application to the edge computing system 200. Then, the receiving module 201 in the edge computing system 200 receives the first service model, first security policy, and service application sent by the cloud platform 100, and sends them to the management and control module 202. The management and control module 202 installs and deploys the service application sent by the cloud platform 100 on the side of the edge computing system 200, which can be deployed on one or more edge devices managed by the edge computing system 200. For example, the service application is deployed on each edge device, or different application modules in the service application are deployed on different edge devices. The embodiments of the present application do not make specific limitations. The management and control module 202 parses the first security policy and finds that the encryption policy corresponding to the first service includes hardware encryption. Therefore, the management and control module 202 stores the first service model and the first security policy in the hardware security chip 300, so as to implement hardware encryption of the first service model and the first security policy through the hardware security chip 300, prevent them from being maliciously tampered with, ensure that the edge computing system 200 side always executes the first service according to the first service model and the first security policy, avoid service execution deviation, and reduce the local security risk of the edge.

[0125] By parsing the first service model and the first security policy, the management and control module 202 can also determine the first service process of the first service, the correspondence between the application modules in the service application and the sub-service processes in the first service process, and determine the data flow between these application modules. The management and control module 202 can also determine which application modules the prohibition policy of the first service corresponds to. Then, based on the above-mentioned content parsed by the management and control module 202, the data acquisition module on the edge device managed by the edge computing system 200 is configured to collect production data (raw data) from the production device (a terminal device 400 connected to the edge computing system 200), and send the production data to the data preprocessing module. The management and control module 202 also configures the data preprocessing module to preprocess the above-mentioned production data, and send the preprocessed production data to the physical model conversion module. The management and control module 202 also configures the physical model conversion module to map the above-mentioned preprocessed production data to the physical model, and then send the physical model to the data cloud encryption module. The management and control module 202 also configures the data cloud encryption module to perform software encryption on the above-mentioned physical model, so as to obtain the service data of the first service, and then send the service data to the sending module 203. The sending module 203 sends the service data to the cloud platform 100, so as to realize the cloudification of the service data of the first service.

[0126] The control module 202 also monitors the process of the edge computing system 200 executing the first service based on the first service model and the first security policy, and determines whether there are operations that do not conform to the first service model and the first security policy (i.e., abnormal operations) on the edge computing system 200 side. If it is detected that the data storage module attempts to perform a local storage operation on the relevant data of the first service (such as the original data of the first service or the processed original data), the control module 202 can prohibit the data storage module from performing the local storage operation by docking with the edge base software, thereby avoiding data leakage locally. If it is detected that the data transfer module has performed a data transfer operation, the actual data flow between application modules does not conform to the data flow defined in the first security policy, or one or more abnormal operations such as missing execution / less execution of the sub-service processes defined in the first service model occur, the control module 202 can also perform corresponding stopping operations to ensure the accuracy of service execution and edge security. In addition to promptly stopping abnormal operations that do not conform to the first service model and the first security policy by docking with the edge base software, the control module can also send monitoring information to the cloud platform 100, and the monitoring information indicates that the edge computing system 200 side does not conform to the first service model and the first security policy during the process of executing the first service. Optionally, the monitoring information can further include specific information about the abnormal operation, such as indicating the application module where the abnormal operation occurs, the time when the abnormality appears, etc.

[0127] It should be noted that the data transmission between the above application modules is realized through a data bus. For example, Figure 4 the data acquisition module in [[]] sends the acquired production data to the data preprocessing module. Actually, the data acquisition module first sends the production data to the data bus, and then the data preprocessing module can obtain the production data from the data bus. The data transmission between other application modules is the same, and will not be introduced in detail here.

[0128] Optionally, Figure 3 the method of [[]] may further include the following steps S305 to S308.

[0129] S305. Obtain the second service model of the second service.

[0130] Among them, the second service model includes a second service process, the second service process is different from the first service process, and the second service process may include multiple sub-service processes.

[0131] Optionally, the above first service and second service may be the same type of service or different types of services. The second service may be a service after business adjustment (update) based on the first service.

[0132] S306. Obtain the second security policy of the second service.

[0133] Among them, the second security policy includes the correspondence between the fourth application module and the first sub-business process in the second business process, the correspondence between the fifth application module and the second sub-business process in the second business process, and the data flow direction between the fourth application module and the fifth application module. The fourth application module and the fifth application module belong to the N application modules described above.

[0134] Optionally, the fourth application module and the fifth application module here may be the same as or different from the first application module and the second application module described in step S302, that is, the second business and the first business may involve the same or different application modules.

[0135] It should be noted that the embodiments of the present application do not specifically limit the execution order of steps S305 and S306. For example, the cloud platform 100 may first execute step S305 and then execute S306, or may execute steps S305 and S306 in parallel. It should also be noted that steps S305 and S306 may be executed after step S304, and steps S305 and S306 may also be executed between steps S303 and S304.

[0136] S307. The cloud platform 100 sends the second service model and the second security policy to the edge computing system 200. Correspondingly, the edge computing system 200 receives the second service model and the second security policy sent by the cloud platform 100.

[0137] S308. The edge computing system 200 configures the fourth application module and the fifth application module on the edge computing system 200 according to the second service model and the second security policy, so that the fourth application module and the fifth application module execute the second service according to the data flow direction between the fourth application module and the fifth application module.

[0138] Optionally, based on the second service model and the second security policy, the edge computing system 200 controls the relevant application modules (including the fourth application module and the fifth application module) on the edge devices managed by the edge computing system 200 to execute the second service, obtains the service data of the second service, and then sends the service data of the second service to the cloud platform 100. Correspondingly, the cloud platform 100 may further process and / or visually display the service data uploaded by the edge computing system 200, and the processing method and the visualization method are not specifically limited.

[0139] Optionally, the edge computing system 200 may send monitoring information to the cloud platform 100, where the monitoring information indicates whether the edge computing system 200 complies with the second service model and the second security policy during the execution of the second service.

[0140] Next, in combination with Figure 4 and Figure 5 , forFigure 3 Specific examples will be given by the method of

[0141] Continuing from the above Figure 4 In the example, after the user formulates the first service model and the first security policy corresponding to the first service on the cloud platform 100, the cloud platform 100 sends the first service model, the first security policy, and related application modules (including the first application module and the second application module) to the edge computing system 200. Furthermore, the edge computing system 200 controls the related application modules on the edge devices managed by the edge computing system 200 to execute the first service based on the first service model and the first security policy.

[0142] Subsequently, assuming that the user has a service adjustment requirement, the user formulates the second service model and the second security policy corresponding to the second service on the cloud platform 100. Among them, the second service model includes a second service process, and the second service process includes the following three sub-service processes: collecting production data, preprocessing the production data, and encrypting the preprocessed data to send it to the cloud platform 100. It can be seen that compared with the first service model in the Figure 4 example, Figure 5 the service process defined in the second service model in Figure 5 has reduced the sub-service process of "mapping the preprocessed production data to the physical model". Therefore, adjusting the first service executed on the edge computing system 200 to the second service can reduce the computing pressure on the edge computing system 200. Correspondingly, the second security policy of the second service includes the following corresponding relationships: the corresponding relationship between the data collection module and the sub-service process of collecting production data, the corresponding relationship between the data preprocessing module and the sub-service process of preprocessing production data, and the corresponding relationship between the data cloud encryption module and the sub-service process of encrypting the preprocessed data. The second security policy also includes the following data flow between application modules: data collection module → data preprocessing module → data cloud encryption module (these three application modules are all represented by gray filling in Figure 4 the example). The second security policy defines the same prohibited policy and encryption policy as the first security policy in the

[0143] Then, the cloud platform 100 sends the second service model and the second security policy to the edge computing system 200. Correspondingly, the receiving module 201 in the edge computing system 200 receives the second service model and the second security policy sent by the cloud platform 100 and sends them to the management and control module 202. The management and control module 202 analyzes the second security policy and finds that the encryption policy corresponding to the second service includes hardware encryption. Therefore, the management and control module 202 stores the second service model and the second security policy in the hardware security chip 300, so as to implement hardware encryption of the second service model and the second security policy through the hardware security chip 300, prevent them from being maliciously tampered with, ensure that the edge computing system 200 can always execute the second service according to the second service model and the second security policy, avoid service execution deviation and reduce the local security risk of the edge. By analyzing the second service model and the second security policy, the management and control module 202 can also determine the second service process of the second service, the corresponding relationship between the relevant application modules and the sub-service processes in this service process, and determine the data flow direction between these application modules, and can also determine which application modules the prohibition policy of the second service corresponds to. Then, based on the above content analyzed by the management and control module 202, the data collection module on the edge device managed by the edge computing system 200 is configured to collect production data (raw data) from the production device (a terminal device 400 connected to the edge computing system 200) and send the production data to the data preprocessing module. The management and control module 202 also configures the data preprocessing module to preprocess the above production data and send the preprocessed production data to the data encryption module for uploading to the cloud. The management and control module 202 also configures the data encryption module for uploading to the cloud to perform software encryption on the above preprocessed production data, so as to obtain the service data of the second service, and then send the service data to the sending module 203, and the sending module 203 sends the service data to the cloud platform 100.

[0144] The management and control module 202 will also monitor the process of the edge computing system 200 executing the second service based on the second service model and the second security policy, and determine whether there are operations that do not conform to the second service model and the second security policy (i.e., abnormal operations) on the edge computing system 200 side. In the case of abnormal operations, the management and control module can also send monitoring information to the cloud platform 100, and the monitoring information indicates that the edge computing system 200 side does not conform to the second service model and the second security policy during the execution of the second service. This will not be introduced in detail here.

[0145] That is to say, when the edge computing system 200 receives the second service model and the second security policy sent by the cloud platform 100, it will execute the second service according to the second service model and the second security policy, rather than executing the first service according to the previous first service model and the first security policy, so as to realize the adjustment of the service executed on the edge computing system 200 side.

[0146] In summary, in the edge security control method provided in the embodiments of the present application, a user can formulate / select a first service model and a first security policy on the cloud platform 100, and then let the cloud platform 100 send the service model and security policy corresponding to the service to the edge computing system 200, so that the edge computing system 200 executes the corresponding service according to the service model and security policy, thereby ensuring that there is no deviation when the edge computing system 200 executes the service. Even when the cloud platform 100 and the edge computing system 200 are disconnected, the edge computing system 200 can still execute the service according to the service model and security policy previously issued by the cloud platform 100, ensuring that the service execution is not affected and there is no deviation in service execution, thereby improving edge security. When the edge computing system 200 is disconnected from the network and cannot be connected to the cloud platform 100, even if the first service model on the edge computing system 200 side is maliciously tampered with / incorrectly modified, according to the data flow specified in the first security policy, the relevant data of the first service can be locked, preventing the data from being exported, thereby ensuring data security.

[0147] The method of the embodiments of the present application also supports dynamic service adjustment. When a user needs to adjust the service executed on the edge computing system 200 side, the user can adjust the service model and security policy corresponding to the service on the cloud platform 100, and then let the cloud platform 100 send the new service model and new security policy to the edge computing system 200, so that the edge computing system 200 executes the adjusted service according to the new service model and new security policy, thereby realizing the dynamic service adjustment of the cloud platform 100 to the edge computing system 200. Moreover, this adjustment method is very flexible and efficient, and there is no need to stop the edge device on the edge computing system 200 side for service adjustment. Therefore, it is possible to avoid the interruption of the service on the edge computing system 200 side and also avoid affecting other services on the edge computing system 200 side.

[0148] Based on the above content, the following introduces a computing device for executing Figure 3 the method.

[0149] Please refer to Figure 6 , the present application also provides a computing device 600, including a bus 602, a processor 604, a memory 606, and a communication interface 608. The processor 604, the memory 606, and the communication interface 608 communicate with each other through the bus 602. The computing device 600 can be a server, a laptop computer, a desktop computer, an edge device, etc., which are not specifically limited in the embodiments of the present application, and the number of processors and memories in the computing device 600 is also not limited in the embodiments of the present application.

[0150] The bus 602 can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 6 only one line is used to represent it in Figure 6 , but it does not mean that there is only one bus or one type of bus. The bus 602 can include a path for transmitting information between various components of the computing device 600 (for example, the memory 606, the processor 604, the communication interface 608).

[0151] The processor 604 can include any one or more of processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0152] The memory 606 can include volatile memory, such as random access memory (RAM). The processor 604 can also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0153] Executable program code is stored in the memory 606. The processor 604 executes the executable program code to respectively implement the functions of the acquisition module 101, the sending module 102, the receiving module 103, and the interaction module 104 in Figure 1 , so as to implement the steps on the cloud platform 100 side of this application. Or, the processor 604 executes the executable program code to respectively implement the functions of the receiving module 201, the management and control module 202, and the sending module 203 in Figure 3 , so as to implement the steps on the edge computing system 200 side of this application. Figure 1 Figure 3 Figure 3

[0154] The communication interface 608 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement the communication between the computing device 600 and other devices or a communication network.

[0155] The embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.

[0156] As Figure 7 shown, the computing device cluster includes at least one computing device 600. Instructions for executing the Figure 3 method of the embodiment may be stored in the memories 606 of one or more of the computing devices 600 in the computing device cluster.

[0157] In some possible implementation manners, instructions for executing the Figure 3 method of the foregoing embodiment may also be stored separately in the memories 606 of one or more of the computing devices 600 in the computing device cluster. In other words, a combination of one or more computing devices 600 may jointly execute the instructions for the Figure 3 method of the embodiment.

[0158] It should be noted that the memories 606 in different computing devices 600 in the computing device cluster may store different instructions, which are respectively used to execute Figure 1 part of the functions of the cloud platform 100 in , that is, the instructions stored in the memories 606 in different computing devices 600 may implement Figure 1 the functions of one or more of the acquisition module 101, the sending module 102, the receiving module 103, and the interaction module 104 in . Or, the memories 606 in different computing devices 600 in the computing device cluster may store different instructions, which are respectively used to execute Figure 1 part of the functions of the edge computing system 200 in , that is, the instructions stored in the memories 606 in different computing devices 600 may implement Figure 1 the functions of one or more of the receiving module 201, the management and control module 202, and the sending module 203 in .

[0159] In some possible implementation manners, one or more of the computing devices in the computing device cluster may be connected through a network. Wherein, the network may be a wide area network or a local area network, etc. Figure 8 shows a possible implementation manner. As Figure 8As shown, two computing devices 600A and 600B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation, the memory 606 in computing device 600A stores instructions for executing the functions of the acquisition module 101 and the sending module 102. At the same time, the memory 606 in computing device 600B stores instructions for executing the functions of the receiving module 103 and the interaction module 104.

[0160] It should be understood that Figure 8 the functions of computing device 600A shown in can also be completed by multiple computing devices 600 together. Similarly, the functions of computing device 600B can also be completed by multiple computing devices 600 together.

[0161] The embodiments of the present application also provide another computing device cluster. The connection relationship between the computing devices in this computing device cluster can be similarly referred to Figure 8 the connection method of the described computing device cluster. The difference is that the memory 606 in one or more computing devices 600 in this computing device cluster may store the same instructions for executing the Figure 3 preceding method.

[0162] In some possible implementation manners, the memory 606 in one or more computing devices 600 in this computing device cluster may also separately store partial instructions for executing the Figure 3 implementable method. In other words, a combination of one or more computing devices 600 can jointly execute the instructions for implementing the Figure 3 implementable method.

[0163] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc. This computer-readable storage medium includes instructions that direct a computing device cluster (including at least one computing device) to execute Figure 3 the method on the cloud platform 100 / edge computing system 200 side in the embodiment.

[0164] The embodiments of the present application also provide a computer program product containing instructions. The computer program product can be software or a program product that contains instructions and can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute Figure 3 the method on the cloud platform 100 / edge computing system 200 side in.

[0165] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the various embodiments of the present invention.

Claims

1. An edge security management and control method based on Internet of Things technology, characterized in that: The method is applied to an edge computing system, the edge computing system is used to manage at least one edge device, the edge computing system is in communication connection with a cloud platform, the cloud platform is used to manage infrastructure, the infrastructure stores multiple application modules, and the method includes: Receive a first business model and a first security policy of a first business sent by the cloud platform, wherein the first business model includes a first business process, the first business process is used to indicate a process for the edge computing system to process the first business, the first security policy includes a correspondence between a first application module and a first sub-business process in the first business process, a correspondence between a second application module and a second sub-business process in the first business process, and a data flow between the first application module and the second application module, and the multiple application modules include the first application module and the second application module; The first application module and the second application module on the edge computing system are configured according to the first business model and the first security policy, so that the first application module and the second application module execute the first business according to the data flow between the first application module and the second application module.

2. The method according to claim 1, characterized in that After receiving the first business model and the first security policy of the first business sent by the cloud platform, the method further includes: Monitoring information is sent to the cloud platform, wherein the monitoring information indicates whether the edge computing system complies with the first business model and the first security policy during execution of the first business.

3. The method according to claim 1 or 2, characterized in that: The first security policy also includes a prohibition policy corresponding to the first service and a corresponding relationship between the prohibition policy and a third application module, the third application module being an application module other than the first application module and the second application module among the multiple application modules, and the method further includes: The third application module on the edge computing system is configured according to the prohibition policy, so that during the process in which the first application module and the second application module execute the first service, the third application module complies with the prohibition policy.

4. The method according to claim 3, characterized in that The prohibition strategy includes prohibiting local storage, the third application module includes a data storage module, and the method further includes: First monitoring information is sent to the cloud platform, wherein the first monitoring information indicates that the data storage module on the edge computing system violates the prohibition of local storage.

5. The method according to claim 3, characterized in that: The prohibition strategy includes prohibiting local data flow, wherein prohibiting local data flow means prohibiting data transmission between different edge devices in the edge computing system, the third application module includes a data flow module, and the method further includes: Sending second monitoring information to the cloud platform, wherein the second monitoring information indicates that the data flow module on the edge computing system violates the prohibition of local data flow.

6. The method according to any one of claims 1 to 5, characterized in that The first security policy also includes an encryption policy corresponding to the first service, and the encryption policy includes at least one of hardware encryption, software encryption, and communication encryption.

7. The method according to claim 6, characterized in that The edge computing system has a hardware security chip. After receiving the first business model and the first security policy of the first business sent by the cloud platform, the method further includes: In a case where the encryption policy corresponding to the first service includes the hardware encryption, the first service model and the first security policy are stored in the hardware security chip.

8. The method according to any one of claims 1 to 7, characterized in that The first application module and the second application module execute the first service according to the data flow direction, including: The first application module and the second application module execute the first service according to the data flow, obtain service data of the first service, and send the service data to the cloud platform.

9. The method according to any one of claims 1 to 8, characterized in that After receiving the first business model and the first security policy of the first business sent by the cloud platform, the method further includes: Receive a second business model and a second security policy of a second business sent by the cloud platform, wherein the second business model includes a second business process, the second business process is used to indicate a process for the edge computing system to process the second business, the second security policy includes a correspondence between a fourth application module and a first sub-business process in the second business process, a correspondence between a fifth application module and a second sub-business process in the second business process, and a data flow between the fourth application module and the fifth application module, and the multiple application modules include the fourth application module and the fifth application module; The fourth application module and the fifth application module on the edge computing system are configured according to the second business model and the second security policy, so that the fourth application module and the fifth application module execute the second business according to the second business process and the data flow between the fourth application module and the fifth application module.

10. An edge security management and control method based on Internet of Things technology, characterized in that: The method is applied to a cloud platform, the cloud platform is used to manage infrastructure, the infrastructure stores multiple application modules, the cloud platform has a communication connection with an edge computing system, the edge computing system is used to manage at least one edge device, and the method includes: Acquire a first business model of a first business, wherein the first business model includes a first business process, and the first business process is used to indicate a process of the edge computing system processing the first business; Obtaining a first security policy for the first business, wherein the first security policy includes a correspondence between a first application module and a first sub-business process in the first business process, a correspondence between a second application module and a second sub-business process in the first business process, and a data flow between the first application module and the second application module, and the multiple application modules include the first application module and the second application module; Send the first business model and the first security policy to the edge computing system.

11. The method according to claim 10, characterized in that The first security policy also includes a prohibition policy corresponding to the first business and a corresponding relationship between the prohibition policy and a third application module. The third application module is an application module among the multiple application modules except the first application module and the second application module. The edge computing system has the third application module.

12. The method according to claim 10 or 11, characterized in that: After sending the first business model and the first security policy to the edge computing system, the method further includes: Receiving business data of the first business sent by the edge computing system; Display the business data or the business data processed by the cloud platform to the user.

13. The method according to any one of claims 10 to 12, characterized in that After sending the first business model and the first security policy to the edge computing system, the method further includes: Receive monitoring information sent by the edge computing system, wherein the monitoring information indicates whether the edge computing system complies with the first business model and the first security policy during execution of the first business.

14. The method according to any one of claims 10 to 13, characterized in that The first security policy also includes an encryption policy corresponding to the first service, and the encryption policy includes at least one of hardware encryption, software encryption, and communication encryption.

15. The method according to any one of claims 10 to 14, characterized in that After sending the first business model and the first security policy to the edge computing system, the method further includes: Acquire a second business model for a second business, wherein the second business model includes a second business process, and the second business process is used to indicate a process for the edge computing system to process the second business; Obtaining a second security policy for the second business, wherein the second security policy includes a correspondence between a fourth application module and a first sub-business process in the second business process, a correspondence between a fifth application module and a second sub-business process in the second business process, and a data flow direction between the fourth application module and the fifth application module, and the multiple application modules include the fourth application module and the fifth application module; Send the second business model and the second security policy to the edge computing system.

16. An edge security management method, characterized in that: Applied to a cloud-edge collaborative system, the cloud-edge collaborative system includes a cloud platform and an edge computing system, the cloud platform is used to manage infrastructure, the infrastructure stores multiple application modules, the cloud platform has a communication connection with the edge computing system, the edge computing system is used to manage at least one edge device, the method includes: The cloud platform acquires a first business model of a first business, wherein the first business model includes a first business process, and the first business process is used to indicate a process of the edge computing system processing the first business; The cloud platform obtains a first security policy for the first business, wherein the first security policy includes a correspondence between a first application module and a first sub-business process in the first business process, a correspondence between a second application module and a second sub-business process in the first business process, and a data flow between the first application module and the second application module, and the multiple application modules include the first application module and the second application module; The cloud platform sends the first business model and the first security policy to the edge computing system; The edge computing system configures the first application module and the second application module on the edge computing system according to the first business model and the first security policy, so that the first application module and the second application module execute the first business according to the data flow direction.

17. A cloud-edge collaborative system, characterized in that: The cloud-edge collaborative system includes a cloud platform and an edge computing system. The cloud platform is used to execute the method as described in any one of claims 10-15, and the edge computing system is used to execute the method as described in any one of claims 1-9.

18. An edge computing system, characterized in that: The edge computing system is used to manage at least one edge device, the edge computing system is in communication connection with a cloud platform, the cloud platform is used to manage infrastructure, the infrastructure stores multiple application modules, and the edge computing system includes: A receiving module, used to receive a first business model and a first security policy of a first business sent by the cloud platform, wherein the first business model includes a first business process, the first business process is used to indicate a process for the edge computing system to process the first business, the first security policy includes a correspondence between a first application module and a first sub-business process in the first business process, a correspondence between a second application module and a second sub-business process in the first business process, and a data flow between the first application module and the second application module, and the multiple application modules include the first application module and the second application module; A management and control module is used to configure the first application module and the second application module on the edge computing system according to the first business model and the first security policy, so that the first application module and the second application module execute the first business according to the data flow.

19. The edge computing system according to claim 18, characterized in that: The edge computing system further includes a sending module, which is used to: Monitoring information is sent to the cloud platform, wherein the monitoring information indicates whether the edge computing system complies with the first business model and the first security policy during execution of the first business.

20. The edge computing system according to claim 18 or 19, characterized in that: The first security policy also includes a prohibition policy corresponding to the first service and a corresponding relationship between the prohibition policy and a third application module, the third application module is an application module other than the first application module and the second application module among the multiple application modules, and the control module is further used to: The third application module on the edge computing system is configured according to the prohibition policy, so that during the process in which the first application module and the second application module execute the first service, the third application module complies with the prohibition policy.

21. The edge computing system according to claim 20, characterized in that: The prohibition strategy includes prohibiting local storage, the third application module includes a data storage module, and the edge computing system further includes a sending module, and the sending module is used to: First monitoring information is sent to the cloud platform, wherein the first monitoring information indicates that the data storage module on the edge computing system violates the prohibition of local storage.

22. The edge computing system according to claim 20, characterized in that: The prohibition strategy includes prohibiting local data flow, wherein prohibiting local data flow means prohibiting data transmission between different edge devices in the edge computing system, the third application module includes a data flow module, and the edge computing system further includes a sending module, wherein the sending module is used to: Sending second monitoring information to the cloud platform, wherein the second monitoring information indicates that the data flow module on the edge computing system violates the prohibition of local data flow.

23. The edge computing system according to any one of claims 18 to 22, characterized in that: The first security policy also includes an encryption policy corresponding to the first service, and the encryption policy includes at least one of hardware encryption, software encryption, and communication encryption.

24. The edge computing system according to claim 23, characterized in that: The edge computing system has a hardware security chip, and the control module is also used for: In a case where the encryption policy corresponding to the first service includes the hardware encryption, the first service model and the first security policy are stored in the hardware security chip.

25. The edge computing system according to any one of claims 18 to 24, characterized in that: The control module is specifically used for: configuring the first application module and the second application module to execute the first service according to the data flow direction, and obtaining service data of the first service; The sending module is also used to send the business data to the cloud platform.

26. The edge computing system according to any one of claims 18 to 15, characterized in that: The receiving module is further used to: receive a second business model and a second security policy of a second business sent by the cloud platform, wherein the second business model includes a second business process, the second business process is used to indicate a process of the edge computing system processing the second business, the second security policy includes a correspondence between a fourth application module and a first sub-business process in the second business process, a correspondence between a fifth application module and a second sub-business process in the second business process, and a data flow direction between the fourth application module and the fifth application module, and the multiple application modules include the fourth application module and the fifth application module; The management and control module is also used to configure the fourth application module and the fifth application module on the edge computing system according to the second business model and the second security policy, so that the fourth application module and the fifth application module execute the second business according to the second business process and the data flow between the fourth application module and the fifth application module.

27. A cloud platform, characterized in that: The cloud platform is used to manage infrastructure, the infrastructure stores multiple application modules, the cloud platform has a communication connection with the edge computing system, the edge computing system is used to manage at least one edge device, and the cloud platform includes: An acquisition module, configured to acquire a first business model of a first business, wherein the first business model includes a first business process, and the first business process is used to indicate a process for the edge computing system to process the first business; The acquisition module is further used to acquire a first security policy for the first business, wherein the first security policy includes a correspondence between a first application module and a first sub-business process in the first business process, a correspondence between a second application module and a second sub-business process in the first business process, and a data flow direction between the first application module and the second application module, and the multiple application modules include the first application module and the second application module; A sending module is used to send the first business model and the first security policy to the edge computing system.

28. The cloud platform according to claim 27, characterized in that: The first security policy also includes a prohibition policy corresponding to the first business and a corresponding relationship between the prohibition policy and a third application module. The third application module is an application module among the multiple application modules except the first application module and the second application module. The edge computing system has the third application module.

29. The cloud platform according to claim 27 or 28, characterized in that: The cloud platform also includes a receiving module and an interaction module. The receiving module is used to receive the business data of the first business sent by the edge computing system, and the interaction module is used to display the business data or the business data processed by the cloud platform to the user.

30. The cloud platform according to any one of claims 27 to 29, characterized in that: The cloud platform further includes a receiving module, which is used to: Receive monitoring information sent by the edge computing system, wherein the monitoring information indicates whether the edge computing system complies with the first business model and the first security policy during execution of the first business.

31. The cloud platform according to any one of claims 27 to 30, characterized in that: The first security policy also includes an encryption policy corresponding to the first service, and the encryption policy includes at least one of hardware encryption, software encryption, and communication encryption.

32. The cloud platform according to any one of claims 27 to 31, characterized in that: The acquisition module is also used for: Acquire a second business model for a second business, wherein the second business model includes a second business process, and the second business process is used to indicate a process for the edge computing system to process the second business; Obtaining a second security policy for the second business, wherein the second security policy includes a correspondence between a fourth application module and a first sub-business process in the second business process, a correspondence between a fifth application module and a second sub-business process in the second business process, and a data flow direction between the fourth application module and the fifth application module, and the multiple application modules include the fourth application module and the fifth application module; The sending module is also used to: send the second business model and the second security policy to the edge computing system.

33. A computing device cluster, characterized in that: It includes at least one computing device, each computing device includes a processor and a memory, and the processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method as described in any one of claims 1-9 or 10-15.

34. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method as claimed in any one of claims 1-9 or 10-15.

35. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster executes the method as claimed in any one of claims 1-9 or 10-15.