Container virtualization-based cloud password service resource pool construction method and system
Through the cloud password service resource pool construction method based on container virtualization, the problem of difficult to dynamically adjust the resource scheduling of traditional cloud password service is solved, and the efficiency of reasonable decomposition and scheduling of resources is improved, and the massive, diverse and dynamically changing user needs are met.
Patent Information
- Application Number
- CN202510328282.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, traditional cloud password service resource scheduling is difficult to dynamically adjust according to real-time user needs and resource load conditions, resulting in low resource utilization, slow response speed, poor scalability, and inability to meet the massive, diverse and dynamically changing user needs, resulting in poor data transmission storage security in the cloud computing environment and poor encryption scheduling and management efficiency of cloud password service resource pool.
By providing a cloud password service resource pool construction method based on container virtualization, it includes creating encryption tasks in response to user access data of the user access layer, decomposition of tasks based on password computing graph, performing four-dimensional scheduling strategy analysis of sub-task sets, activating the task scheduling engine for cloud password scheduling updates, and using the update cloud password scheduling scheme to perform encryption scheduling management of cloud password service resource pool.
It realizes reasonable decomposition and scheduling of resources, improves data security and encryption scheduling management efficiency, can dynamically adjust resource configuration to meet the needs of different tenants, and improves the response speed and scalability of cloud password services.
Smart Images

Figure CN120197193A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of encrypted data transmission, and specifically relates to a method and system for constructing a cloud password service resource pool based on container virtualization. Background Art
[0002] In today's digital age, cloud computing technology has developed rapidly, and more and more enterprises and organizations have migrated their businesses to the cloud. However, with the large-scale storage and processing of data in the cloud, data security issues have become increasingly prominent. Among them, password services are crucial. In the face of the massive, diverse, and dynamically changing user demands in the cloud computing environment, traditional cloud password service resource scheduling mostly relies on static policies and is difficult to dynamically adjust according to real-time user demands and resource load conditions, exposing many deficiencies, such as low resource utilization, slow response speed, poor scalability, etc. For example, when the demand for a certain type of encryption task surges during a certain period, idle resources cannot be allocated in time, resulting in task queuing and backlog, and serious response delays. When the business volume of an enterprise suddenly increases and password services need to be expanded, the traditional mode not only requires reconfiguring the network and installing software but may also face compatibility problems, with severely limited scalability. In addition, in a multi-tenant environment, the demand characteristics of different tenants for password services vary greatly. Some tenants may frequently perform rapid encryption operations on small amounts of data and have extremely high requirements for response speed; while some tenants need to process the encrypted storage of large-scale data and have specific requirements for the security and resource occupancy of storage encryption. The traditional cloud password service mode cannot allocate resources and schedule tasks customized for different tenants and is difficult to provide high-quality services.
[0003] Therefore, in the current related technologies, there are technical problems that the password service mode is difficult to meet the massive, diverse, and dynamically changing user demands, resulting in poor data transmission and storage security in the cloud computing environment and poor encryption scheduling management efficiency of the cloud password service resource pool. Summary of the Invention
[0004] By providing a method and system for constructing a cloud password service resource pool based on container virtualization, this application solves the technical problems in the prior art that the password service mode is difficult to meet the massive, diverse, and dynamically changing user demands, resulting in poor data transmission and storage security in the cloud computing environment and poor encryption scheduling management efficiency of the cloud password service resource pool, realizes reasonable resource decomposition and scheduling, and achieves the technical effect of improving data security and encryption scheduling management efficiency.
[0005] The present application provides a method for constructing a cloud password service resource pool based on container virtualization. The method includes: creating an encryption task in response to user access data at the user access layer, where the user access data is tenant access data after information authentication; performing task decomposition of the encryption task based on a password computation graph to establish a subtask set, where the subtask set is provided with task association identifiers; performing four-dimensional scheduling policy analysis on the subtask set to establish an initial cloud password scheduling plan; activating a task scheduling engine, and after inputting the task association identifier and the initial cloud password scheduling plan as input data into the task scheduling engine, performing cloud password scheduling update to establish an updated cloud password scheduling plan; and using the updated cloud password scheduling plan for encryption scheduling management of the cloud password service resource pool.
[0006] In a possible implementation manner, the method for constructing a cloud password service resource pool based on container virtualization further performs the following processing: configuring a four-dimensional scheduling loss function as follows: ; where represents the four-dimensional scheduling loss function of subtask on computing resource , represents the dynamic priority weight of subtask , , represents the time deadline urgency of subtask , represents the computing resource requirement of subtask , is the subtask index in the subtask set, represents the time deadline urgency of subtask , represents the computing resource requirement of subtask , , are respectively the weight factors of the time deadline urgency and the computing resource requirement, represents the computing complexity of subtask , represents the computing power of computing resource , represents the current load of computing resource , represents the security matching penalty, , represents the required security level of subtask , represents the security level provided by computing resource , is the security weight coefficient, Characterize the SLA default penalty, Characterize the competition game factor, , is the SLA requirement of the subtask , Characterize the SLA requirement of the subtask , Characterize the SLA requirement of the subtask , Characterize the balance parameter, , , , are the weight of computing complexity impact, the weight of load balancing impact, the weight of security impact, and the weight of SLA impact respectively, is the weight of the task game factor.
[0007] In a possible implementation, the method for constructing a cloud password service resource pool based on container virtualization further performs the following processing: obtaining a unique identifier of each subtask in the subtask set; calling a parsing layer to perform task association identification parsing based on the unique identifier, and establishing subtask dependency associations and subtask conflict associations, where the parsing layer is the data calculation layer of the task scheduling engine; generating a first updated scheduling constraint based on the subtask dependency associations and the subtask conflict associations, and performing scheduling update of the cloud password based on the first updated scheduling constraint.
[0008] In a possible implementation, the method for constructing a cloud password service resource pool based on container virtualization further performs the following processing: calling a load prediction layer to perform load prediction of computing resources by using the load prediction layer, generating a load prediction result, where the load prediction layer is the data calculation layer of the task scheduling engine; establishing a second updated scheduling constraint according to the load prediction result; and performing scheduling update of the cloud password by using the first updated scheduling constraint and the second updated scheduling constraint.
[0009] In a possible implementation, the method for constructing a cloud password service resource pool based on container virtualization further performs the following processing: configuring the minimum splitting granularity of task splitting; and performing task decomposition of the encryption task based on the password calculation graph with the minimum splitting granularity as a constraint, and establishing a subtask set.
[0010] In a possible implementation, the method for constructing a cloud password service resource pool based on container virtualization further performs the following processing: performing execution monitoring on the cloud password service resource pool, and establishing an execution monitoring result; performing execution consistency verification based on the execution monitoring result and the updated cloud password scheduling scheme, generating a consistency verification exception; reporting an exception warning according to the consistency verification exception, and reporting an exception of the cloud password service resource pool according to the exception warning.
[0011] In a possible implementation, the method for constructing a cloud password service resource pool based on container virtualization further performs the following processing: under the authorization of a tenant, create a tenant profile for the tenant, and record in the tenant profile the tenant response mapped to the updated cloud password scheduling scheme; perform subsequent optimization of the construction of the cloud password service resource pool for the tenant according to the tenant profile.
[0012] This application also provides a system for constructing a cloud password service resource pool based on container virtualization, including: an encryption task creation module, configured to create an encryption task in response to user access data of the user access layer, where the user access data is tenant access data after information authentication; a task decomposition module, configured to perform task decomposition of the encryption task based on a password computation graph to establish a subtask set, where the subtask set is provided with a task association identifier; a four-dimensional scheduling policy analysis module, configured to perform four-dimensional scheduling policy analysis of the subtask set to establish an initial cloud password scheduling scheme; a cloud password scheduling update module, configured to activate a task scheduling engine, and after inputting the task association identifier and the initial cloud password scheduling scheme as input data into the task scheduling engine, perform cloud password scheduling update to establish an updated cloud password scheduling scheme; an encryption scheduling management module, configured to perform encryption scheduling management of the cloud password service resource pool by using the updated cloud password scheduling scheme.
[0013] It is intended to respond to user access data of the user access layer to create an encryption task through the method and system for constructing a cloud password service resource pool based on container virtualization proposed in this application; perform task decomposition of the encryption task based on a password computation graph; perform four-dimensional scheduling policy analysis of the subtask set to establish an initial cloud password scheduling scheme; activate the task scheduling engine, perform cloud password scheduling update to establish an updated cloud password scheduling scheme; and perform encryption scheduling management of the cloud password service resource pool by using the updated cloud password scheduling scheme. This solves the technical problems in the prior art that the password service mode is difficult to meet the massive, diverse, and dynamically changing user requirements, resulting in poor data transmission and storage security in the cloud computing environment and poor encryption scheduling management efficiency of the cloud password service resource pool, realizes reasonable decomposition and scheduling of resources, and achieves the technical effect of improving data security and encryption scheduling management efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings of the embodiments of the present disclosure will be briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the operations before or below do not necessarily need to be executed precisely in sequence. On the contrary, according to needs, they can be executed in reverse order or simultaneously. At the same time, other operations can also be added to these processes, or one or several operations can be removed from these processes.
[0015] Figure 1 This is a schematic flowchart of the method for constructing a cloud password service resource pool based on container virtualization provided by the embodiments of the present application.
[0016] Figure 2 This is a schematic flowchart of executing cloud password scheduling update in the method for constructing a cloud password service resource pool based on container virtualization provided by the embodiments of the present application.
[0017] Figure 3 This is a schematic structural diagram of the system for constructing a cloud password service resource pool based on container virtualization provided by the embodiments of the present application.
[0018] Explanation of reference numerals: Encryption task creation module 10, task decomposition module 20, four-dimensional scheduling strategy analysis module 30, cloud password scheduling update module 40, encryption scheduling management module 50. Detailed implementation manners
[0019] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically gives the detailed implementation manners of the present application.
[0020] In order to make the purpose, technical solution and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations of the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present application.
[0021] In the following description, "some embodiments" are involved, which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict. The terms "first\second" involved are only used to distinguish similar objects and do not represent a specific order for the objects. The terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or modules not clearly listed or inherent to these processes, methods, products or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application.
[0022] The embodiments of the present application provide a method for constructing a cloud password service resource pool based on container virtualization, asFigure 1 As shown, the method includes: Step S100, creating an encryption task in response to user access data at the user access layer, where the user access data is tenant access data after information authentication.
[0023] Preferably, when a tenant requests a password from the cloud password service system through the user access layer, information authentication is performed on the access data submitted by the tenant to ensure the legality of the tenant's identity and the authenticity and integrity of the submitted data, preventing illegal users or malicious data from entering. Specifically, there are various authentication methods for tenant access data. For example, username and password authentication, that is, when a tenant accesses the system, they need to enter a pre-registered username and password, and compare the entered information with the user information stored in the database. If the two match, the authentication passes; for example, digital certificate authentication, that is, the system issues a digital certificate to the tenant, which contains the tenant's identity information, public key, etc., and is digitally signed by an authoritative certificate issuing authority (CA). When the tenant accesses, the digital certificate is sent to the system, and the legality of the tenant's identity is determined by verifying the validity, integrity of the certificate, and the identity information in the certificate.
[0024] Preferably, tenant access data may include tenant identity information, business data, service request information, and resource configuration information. Among them, identity information includes the tenant's name, identifier (such as the unified social credit code of an enterprise, the ID number of an individual, etc.), account information (username, password, etc.), contact information (such as phone number, email address), etc., which is used to confirm the tenant's identity and perform identity verification; business data is the data that the tenant hopes to encrypt and protect through the cloud password service, and its type can be various formats of files, such as documents (Word, PDF, etc.), database files, images, videos, etc.; service request information describes in what scenario the data will be used, whether it is for data storage encryption, network transmission encryption, or other security application scenarios such as digital signature; resource configuration information includes computing resource requirements (such as how many CPU cores are needed, the memory size, etc., so that the cloud password service resource pool can reasonably allocate resources to ensure the efficient execution of the encryption task), storage resource requirements (including storage capacity, storage type, such as block storage, object storage, etc., and requirements for storage performance, such as read and write speed), and network resource requirements (if the encryption task involves data transmission in the network, the tenant may have certain requirements for network bandwidth, network latency, etc., to ensure that the encrypted data can be quickly and stably transmitted to the specified location).
[0025] Preferably, after completing information authentication, an encryption task is created based on the data accessed by the authenticated tenant to ensure that the tenant's data can be securely and reliably encrypted in the cloud. For example, the tenant may request to encrypt some sensitive data stored in the cloud or encrypt the data in transit, etc. Specifically, first, key information related to the encryption task is extracted from the data accessed by the authenticated tenant, including the data to be encrypted, encryption algorithm requirements, encryption mode requirements, application scenario information, etc. The extracted information is checked for completeness and consistency to ensure that there is no missing key data or conflicting instructions; then different encryption strategies are selected according to the application scenario, such as choosing an appropriate key length, whether to use encryption authentication, etc., and the priority of the encryption task is set according to the tenant's level, the urgency of the business, etc. For example, for high-priority tenants or urgent business requirements, the corresponding encryption tasks should be processed first to ensure that the service level agreement (SLA) requirements of the tenant are met; then the various parsed and determined information is encapsulated into an encryption task object, which usually contains attributes such as a reference or pointer to the data to be encrypted, specific parameters of the encryption algorithm and mode, encryption strategy, task priority, etc., and a unique task association identifier is assigned to the encryption task for tracking and managing the task throughout the system; finally, the created encryption task is added to the corresponding task queue according to its priority, and the task scheduler will take out the tasks in turn according to the priority order of the queue for processing, and at the same time, according to the current system resource status and task resource requirements, allocate corresponding computing, storage, and network resources to the encryption task. Finally, the creation of the encryption task based on the tenant-accessed data is completed to achieve secure encryption processing of the tenant's data.
[0026] Step S200: Decompose the encryption task based on a cryptographic computation graph to establish a subtask set, where the subtask set is set with a task association identifier.
[0027] Preferably, a cryptographic computation graph is a directed graph structure used to describe the cryptographic computation process. Various operations in an encryption task (such as key generation, different steps of encryption algorithms, data processing, etc.) are represented as nodes in the graph, and the edges between nodes represent the dependency relationships and data flows between operations. For example, in a task using the AES encryption algorithm, the cryptographic computation graph may include a key expansion node, an initial round key generation node, an encryption round function node, and a final ciphertext generation node, etc., which are connected to each other according to the execution order and data dependency relationships of the AES algorithm; based on the cryptographic computation graph, the encryption task is decomposed into sub-tasks, that is, according to the cryptographic computation graph, the entire encryption task is decomposed into multiple sub-tasks, and each sub-task corresponds to one or more nodes and their related edges in the computation graph. For example, decomposing the AES encryption task into a key generation sub-task, an encryption round function execution sub-task, etc., helps to refine the complex encryption task into smaller tasks that are easier to manage and execute, while clarifying the logical relationships and data flows between the sub-tasks, facilitating parallel processing or distributed execution on different computing resources, and improving the execution efficiency and scalability of the encryption task.
[0028] Preferably, the decomposed sub-tasks are managed in a centralized manner to form a sub-task set, which contains all the sub-tasks required to complete the entire encryption task and is organized according to a certain order or logical relationship. For example, in a complete encryption task, it may include multiple sub-tasks such as key generation, data chunking, encryption processing, and ciphertext splicing, which together constitute the sub-task set; then a unique task association identifier is assigned to each sub-task set for tracking and managing the entire encryption task and its sub-tasks. Among them, the task association identifier may be a randomly generated string or a sequence of numbers. Through the task association identifier, it is convenient to identify the sub-task sets of different encryption tasks, and perform operations such as scheduling, monitoring, status query, and result aggregation on them. For example, when multiple encryption tasks are carried out simultaneously, the sub-tasks can be accurately assigned to the corresponding computing resources for execution according to the task association identifier, and the results can be correctly aggregated and returned to the corresponding tenant after the tasks are completed, thereby enhancing data security and scheduling management efficiency.
[0029] Furthermore, step S200 further includes step S210 of configuring the minimum splitting granularity for task splitting; step S220 of decomposing the encryption task based on the cryptographic computation graph with the minimum splitting granularity as a constraint, and establishing a sub-task set.
[0030] Preferably, the minimum splitting granularity refers to the minimum scale or complexity of the subtasks allowed when decomposing an encryption task. It is a configurable parameter used to control the level of detail in task decomposition. For example, the minimum splitting granularity can be defined as performing a specific encryption algorithm operation (such as one round function operation of AES encryption), processing a data block of a fixed size (such as a 128-byte data block), or completing a simple key generation step, etc. Configuring the minimum splitting granularity of task splitting can balance the fineness of task decomposition and the execution efficiency of the system. If the minimum splitting granularity is set too small, although tasks can be scheduled and resources can be allocated more flexibly, it will increase the complexity of task management and the system overhead (such as the time cost of task scheduling, the overhead of data transmission, etc.). If it is set too large, the parallel processing ability of computing resources may not be fully utilized, resulting in low resource utilization rate.
[0031] Preferably, with the configured minimum splitting granularity as a constraint condition, the encryption task based on the cryptographic computation graph is decomposed. Specifically, during the decomposition process, the entire encryption task is divided into multiple subtasks, and the scale or complexity of each subtask is not less than the minimum splitting granularity. For example, if the minimum splitting granularity is defined as processing a 128-byte data block, then during task decomposition, the original encrypted data will be divided into units of 128 bytes, and the encryption operation of each data block will be used as a subtask. At the same time, operations such as key processing related to the encryption of this data block will also be reasonably combined into the corresponding subtasks according to the requirements of the minimum splitting granularity. Finally, all the decomposed subtasks are managed in a centralized manner to form a subtask set, which contains all the subtasks required to complete the entire encryption task, and each subtask has a clear function and boundary. The subtasks are interconnected through the dependency relationships in the cryptographic computation graph. The task scheduling engine can perform reasonable scheduling and resource allocation on the tasks according to the subtask set and the dependency relationships between the subtasks to achieve efficient encryption task processing. Exemplarily, the data on the impact of the minimum splitting granularity configuration on the performance of cloud cryptographic services is shown in Table 1: Table 1 Comparison table of data on the impact of minimum splitting granularity configuration on the performance of cloud cryptographic services Comparison items Larger minimum splitting granularity Smaller minimum splitting granularity Impact on results Task scheduling time cost When processing 1KB data blocks, the scheduler processes 1000 tasks per second on average When processing 128-byte data blocks, the scheduler processes 800 tasks per second on average The task scheduling time cost increases by about 25% Data transmission overhead When splitting in units of 1MB, the average data transmission time per time is 80ms When splitting in units of 128KB, the average data transmission time per time is 10ms, but the number of transmissions increases, and the total transmission time increases by about 30% The total data transmission time increases, and the network overhead and latency jitter may increase Computing resource parallel processing ability When performing a complex encryption algorithm operation (processing larger data blocks) once, the resource utilization rate is about 60% When performing a simple encryption round function operation (processing smaller data blocks) once, the resource utilization rate increases to over 85% The resource utilization rate is significantly improved, and the parallel processing ability can be better exerted Resource idle and waste Taking 10MB as the subtask unit, the resource idle time accounts for 30% - 40% of the total task processing time After reasonably reducing the minimum splitting granularity, the resource idle time is reduced to 10% - 15% The resource idle time is reduced, and the resource utilization rate is increased Step S300, perform a four-dimensional scheduling strategy analysis of the subtask set to establish an initial cloud cryptographic scheduling scheme.
[0032] Furthermore, step S300 also includes configuring a four-dimensional scheduling loss function as follows: ; where represents the four-dimensional scheduling loss function of subtask on computing resource , Characterization subtask of the dynamic priority weight, , Characterization subtask of the time deadline urgency, Characterization subtask of the computing resource requirement, is the subtask index in the subtask set, Characterization subtask of the time deadline urgency, Characterization subtask of the computing resource requirement, , are the weight factors of the time deadline urgency and the computing resource requirement respectively, Characterization subtask of the computing complexity, Characterizes the computing power of the computing resource, Characterizes the computing resource of the current load, Characterizes the security matching penalty, , Characterization subtask of the required security level, Characterizes the computing resource of the provided security level, is the security weight coefficient, Characterizes the SLA default penalty, Characterizes the competition game factor, , is the SLA requirement of the subtask, Characterization subtask of the SLA requirement, Characterization subtask of the computing complexity, Characterizes the balance parameter, , , , are the computing complexity impact weight, the load balancing impact weight, the security impact weight, and the SLA impact weight respectively, is the task game factor weight.
[0033] Preferably, a four-dimensional scheduling strategy analysis is performed on the sub-task set, that is, comprehensively considering four key dimensions such as computational complexity (high computational volume tasks are prioritized, HSM), security level (sensitive operations are prioritized in a confidential computing environment), current load (automatically switch to software-simulated HSM when HSM is overloaded), and tenant SLA requirements (VIP users can preferentially use HSM), etc., to formulate an initial cloud password scheduling plan for the sub-task set. Among them, the four-dimensional scheduling loss function , which is used to measure the loss situation of sub-tasks during scheduling on computing resources. The lower the loss function value, the more reasonable the scheduling of the sub-task on this computing resource. Specifically, in cloud password services, different encryption sub-tasks have different computational complexities. The Hardware Security Module (HSM) has powerful computing capabilities and is particularly suitable for processing tasks with high computational volumes. Computational complexity analysis is to identify tasks with high computational complexity in the sub-task set. For example, some complex asymmetric encryption algorithms (such as RSA algorithm when dealing with large key lengths), high-intensity hash operations, etc., have extremely high requirements for computing resources. In the scheduling strategy, such high-computational-volume tasks are preferentially assigned to HSM for execution, which can give full play to the performance advantages of HSM and improve the execution efficiency of the entire encryption task. By preferentially processing high-computational-volume tasks, it is possible to avoid their long queuing waiting on ordinary computing resources and reduce the overall task execution time.
[0034] Preferably, the encryption task involves multiple operations with different security levels. Some operations are related to the generation and processing of core keys or the encryption of extremely sensitive data, with extremely high security risks. The confidential computing environment provides additional hardware and software protection mechanisms, which can greatly enhance the security of operations. When analyzing the security level dimension, it is necessary to clarify which operations in the sub-task set are sensitive operations. For example, operations such as generating the main key for financial transaction encryption and encrypting medical sensitive data. And the scheduling strategy stipulates that these sensitive operations should be preferentially arranged for execution in the confidential computing environment to ensure that key cryptographic operations are carried out in the safest environment, reduce the risks caused by security vulnerabilities, and meet application scenarios with extremely high requirements for data security. Although HSM has powerful performance, its resources are limited and it may become overloaded. The current load analysis aims to monitor the workload status of HSM in real time. When the load of HSM reaches a certain threshold, that is, when it is in an overloaded state, continuing to allocate tasks to it will lead to task processing delays or even system crashes. The scheduling strategy will start an automatic switching mechanism to switch tasks that were originally planned to be assigned to HSM, especially tasks with relatively low computational complexity and less dependence on hardware acceleration, to be executed on software-simulated HSM. Among them, software-simulated HSM simulates the functions of HSM through software algorithms. Although its performance is not as good as that of hardware HSM, it can be used as a backup solution when HSM is overloaded to maintain the normal operation of the system, ensure the continuity of encryption tasks, and avoid service interruptions caused by HSM overload.
[0035] Preferably, there are differences in the service level agreements (SLAs) signed between different tenants and cloud service providers. VIP users usually pay higher fees or have stricter requirements for service quality. In the tenant SLA requirements, it may be clearly stipulated that they have the right to preferentially use certain key resources (such as HSM). Tenant SLA requirement analysis is to identify the subtasks of VIP users according to the tenant's identity and the corresponding SLA terms; and during the scheduling process, for the encryption subtasks of VIP users, HSM resources are preferentially allocated to ensure that VIP users obtain high-quality and low-latency cloud password services, meet their SLA requirements, improve the satisfaction and loyalty of VIP users, and at the same time maintain the business reputation of cloud service providers. Through the comprehensive analysis of the above four dimensions (computational complexity, security level, current load, tenant SLA requirements), weighing various factors, an initial cloud password scheduling scheme is formulated, which details which computing resources (such as HSM, software-simulated HSM, ordinary computing resources, or confidential computing environments, etc.) each subtask should be allocated to, as well as the order of task execution, so as to achieve reasonable utilization of resources, ensure data security, meet tenant service requirements, and ensure the efficient and stable operation of the entire cloud password service system.
[0036] Step S400, activate the task scheduling engine. After inputting the task association identifier and the initial cloud password scheduling scheme as input data into the task scheduling engine, perform cloud password scheduling update to establish an updated cloud password scheduling scheme.
[0037] Preferably, the task scheduling engine is a core component in the cloud password service system, responsible for coordinating and managing the execution order and resource allocation of tasks. Activating the task scheduling engine to make it in a working state enables it to receive input data and perform corresponding processing. Specifically, input the task association identifier as input data into the task scheduling engine, and also input the initial cloud password scheduling scheme as input data into the task scheduling engine to provide the preliminary guiding principles and resource allocation framework for task scheduling. After receiving the input data, the task scheduling engine performs cloud password scheduling update, that is, dynamically adjusts and optimizes the initial cloud password scheduling scheme according to the real-time state of the system (such as the load change of current computing resources, newly emerged high-priority tasks, security events, etc.), similar to a traffic control center adjusting the traffic routes and time arrangements of vehicles according to real-time road condition information to ensure smooth traffic, thereby making the execution of encryption tasks safer and more efficient and meeting the requirements of the tenant's service level agreement; finally, an updated cloud password scheduling scheme is generated, which re-plans the resource allocation and execution order of tasks, and is used as a specific scheme to guide the cloud password service system to execute encryption tasks, can better adapt to the changes during the system operation, improve the overall quality and efficiency of the cloud password service, and ensure the secure encryption processing of tenant data.
[0038] Furthermore, as Figure 2As shown, step S400 further includes step S410 of obtaining the unique identifier of each subtask in the subtask set; step S420 of calling the parsing layer to perform task association identifier parsing based on the unique identifier, and establishing subtask dependency associations and subtask conflict associations, where the parsing layer is the data calculation layer of the task scheduling engine; step S430 of generating a first updated scheduling constraint based on the subtask dependency associations and the subtask conflict associations, and performing scheduling update of the cloud password based on the first updated scheduling constraint.
[0039] Preferably, during the cloud password scheduling update process, the task association relationship is processed and a scheduling constraint is generated. Among them, each subtask is assigned a unique identifier, similar to everyone's ID card number, which is used to uniquely determine the corresponding subtask in the system. Obtaining the unique identifier of each subtask in the subtask set facilitates accurately identifying and managing each subtask; then the parsing layer is called to perform task association identifier parsing based on the unique identifier. Among them, the parsing layer, as the data calculation layer of the task scheduling engine, is used to analyze and process information related to encryption tasks. Specifically, based on the unique identifier, the parsing layer analyzes and establishes two important association relationships, including subtask dependency associations and subtask conflict associations. Subtask dependency associations indicate that there is a sequential or data-dependent relationship between subtasks. For example, subtask A must be executed after subtask B is completed because subtask A requires the output data of subtask B as input; subtask conflict associations refer to the fact that some subtasks cannot be executed simultaneously, possibly because they compete for the same resources (such as computing resources, storage resources, or keys, etc.). For example, if two subtasks both need to exclusively use the same hardware security module (HSM) for encryption calculation, there is a conflict association between them.
[0040] Preferably, based on the established subtask dependency associations and subtask conflict associations, a first updated scheduling constraint is generated. Specifically, it is clarified whether the dependency between subtasks is a data dependency (the input data of one subtask comes from the output of another subtask) or a logical dependency (the sequential order based on business logic), and then the execution sequence of subtasks is determined according to the dependency type. For a pair of subtasks with a dependency relationship (A and B), a constraint condition is added, requiring subtask A to be executed before subtask B. When there are multiple subtasks forming a dependency chain, sequential constraints between adjacent subtasks are established in turn to ensure that the subtasks on the entire dependency chain are executed in the correct order. At the same time, considering the situation of dependency chain branches, the execution logic and sequence of different branches are reasonably planned; then the specific resources that cause subtask conflicts are determined, such as the hardware security module (HSM), a specific storage area, or network bandwidth, etc. For the conflicting resources, mutual exclusion rules between subtasks are formulated, that is, it is stipulated that at the same time, only one subtask can occupy the conflicting resource.
[0041] Preferably, the constraint conditions generated based on subtask dependency association and subtask conflict association are merged to form a complete constraint set, that is, the first updated scheduling constraint. For example, which subtasks must be executed in a specific order, which subtasks cannot run simultaneously, etc., to ensure that the constraints are mutually compatible and there are no contradictions or conflicts. Finally, according to the generated first updated scheduling constraint, the scheduling of the cloud password is updated, that is, the task scheduling engine adjusts the resource allocation and execution order of the subtasks again according to the first updated scheduling constraint to ensure that the cloud password scheduling scheme conforms to the association relationship between the subtasks and avoid errors or inefficiencies caused by task conflicts or unreasonable execution orders, thereby improving the operation efficiency and stability of the entire cloud password scheduling system.
[0042] Further, step S430 further includes step S431 of calling the load prediction layer to perform load prediction of computing resources by using the load prediction layer to generate a load prediction result, where the load prediction layer is the data calculation layer of the task scheduling engine; step S432 of establishing a second updated scheduling constraint according to the load prediction result; and step S433 of using the first updated scheduling constraint and the second updated scheduling constraint to perform scheduling update of the cloud password.
[0043] Preferably, the load prediction layer is the data calculation layer of the task scheduling engine. The load prediction layer is used to analyze and predict the load conditions of computing resources (such as hardware security modules HSM, servers, etc.). It can collect historical load data, current resource usage status, and other relevant information (such as task submission frequency, resource performance metrics, etc.). By calling the load prediction layer to perform load prediction of computing resources, that is, using its internal analysis and prediction mechanism to estimate the load conditions of computing resources in the next period of time. For example, according to the number and time-consuming of HSM processing encryption tasks in the past few hours, combined with the upcoming task queue information, based on a time series analysis model (such as the ARIMA model), capture the long-term trend and periodic changes of the data, and predict whether the load of HSM in the next half hour is light load, normal load or overloaded state, and finally generate a load prediction result.
[0044] Preferably, a detailed analysis is performed on the load prediction results generated by the load prediction layer. If it is predicted that a certain computing resource will be overloaded, it means that allocating too many tasks during this time period may lead to task processing delays or even system failures. If it is predicted to be lightly loaded, the task allocation can be appropriately increased to improve resource utilization. Then, corresponding scheduling constraints, that is, the second updated scheduling constraints, are established based on the analysis results. For example, when it is predicted that the HSM will be overloaded, the constraint condition can be to limit the allocation of new high-computational-complexity tasks to the HSM, or to set that only the tasks with the highest priority are allowed to be executed during the overload time period. If it is predicted to be lightly loaded, the restrictions on task allocation can be relaxed to allow more subtasks to use this resource. Finally, the first updated scheduling constraints generated based on subtask dependency association and subtask conflict association are combined with the second updated scheduling constraints generated according to the load prediction results to update the original cloud password scheduling scheme, and re-adjust the resource allocation and execution order of subtasks to ensure that the scheduling scheme not only meets the dependency and conflict requirements between tasks, but also can adapt to the load changes of computing resources, thereby improving the efficiency of cloud password scheduling and the stability of the system, and ensuring that encryption tasks can be executed smoothly and efficiently.
[0045] Step S500, use the updated cloud password scheduling scheme to perform encryption scheduling management on the cloud password service resource pool.
[0046] Preferably, using the updated cloud password scheduling scheme to perform encryption scheduling management on the cloud password service resource pool mainly includes resource allocation, task execution order control, real-time monitoring and adjustment, and resource recycling and reallocation. Specifically, according to the planning of each subtask in the updated cloud password scheduling scheme, the computing resources (such as CPU, memory, GPU, etc.), storage resources (such as hard disk, solid-state drive, etc.), and password-related resources (such as hardware security module HSM, key management system, etc.) in the cloud password service resource pool are reasonably allocated to each subtask. For example, for subtasks with high computational complexity and high security level requirements, high-performance HSM devices and sufficient computing resources are preferentially allocated to ensure the efficient and secure execution of tasks. According to the subtask dependency relationship and priority determined in the scheduling scheme, strictly control the execution order of tasks. For subtasks with a dependency relationship, ensure that the subsequent subtasks are started only after the preceding subtasks are completed. For example, first complete the key generation subtask and then perform the encryption operation subtask. At the same time, according to factors such as the service level agreement (SLA) requirements of tenants and the urgency of tasks, determine the priorities of different tasks, and give priority to executing high-priority tasks to ensure that important or urgent encryption tasks can be processed in a timely manner.
[0047] Preferably, during the execution of the encryption task, continuously monitor the status of the cloud password service resource pool and the execution of the task. By collecting information such as the usage of resources (such as CPU utilization rate, memory occupancy rate, etc.), the execution progress and completion time of the task, judge whether the current scheduling scheme is still effective and reasonable. If it is found that there are resource overloads, task execution delays or other abnormal situations, according to the real-time monitoring data, adjust the scheduling scheme in a timely manner. For example, when the load of a certain HSM device is too high, transfer some tasks to other idle HSM devices or software-simulated HSMs for execution to balance the resource load and ensure the stable operation of the entire system. When a subtask completes execution, promptly recycle the resources it occupies so that these resources can be reallocated to other tasks. For computing resources, storage resources or password resources that are no longer in use, release and mark them to make them return to the available state; at the same time, according to the new task requirements and the available situation of the resources, reasonably reallocate the recycled resources to improve the resource utilization rate and avoid resource waste. By using the updated cloud password scheduling scheme to perform encryption scheduling management on the cloud password service resource pool, it is possible to achieve efficient utilization of resources, orderly execution of tasks, and security guarantee of data, providing high-quality cloud password services for tenants.
[0048] Further, step S500 further includes step S510 of performing execution monitoring on the cloud password service resource pool and establishing an execution monitoring result; step S520 of performing execution consistency verification based on the execution monitoring result and the updated cloud password scheduling scheme to generate a consistency verification exception; step S530 of reporting an exception warning according to the consistency verification exception and reporting an exception of the cloud password service resource pool according to the exception warning.
[0049] Preferably, use the monitoring tools in the cloud password service system to comprehensively monitor the usage of various resources and the execution status of encryption tasks in the cloud password service resource pool, specifically including computing resources (such as CPU usage rate, memory occupancy), storage resources (such as hard disk read and write speed, remaining storage space), password resources (such as the usage frequency of hardware security modules, the number of key generations and uses), and task execution conditions (such as the execution progress of tasks, whether they are completed on time, whether the dependencies between tasks are normal, etc.). Organize and analyze the collected monitoring data to form an execution monitoring result to intuitively reflect the operating status of the cloud password service resource pool. For example, generate a report showing that in the past hour, the average usage rate of each hardware security module is 80%, the average execution time of a certain type of encryption task is 10 seconds, and 5 tasks have experienced slight delays.
[0050] Preferably, compare and verify the execution monitoring results with the updated cloud password scheduling scheme, and check whether the actual resource usage and task execution meet the expectations of the scheduling scheme. For example, if the scheduling scheme stipulates that a certain encryption task should be executed on a specific hardware security module and completed within a certain time, while using a specific amount of computing resources, it is necessary to check whether the task in the monitoring results is indeed executed on the specified hardware security module, whether it is completed within the specified time, and whether the actual computing resources used are consistent with those specified in the scheme; if it is found that the actual execution situation is inconsistent with the scheduling scheme, a consistency verification exception will be generated, which may include task execution timeout, unreasonable resource allocation (such as excessive use of one resource while other resources are idle), incorrect task execution order (violating the dependencies between tasks), etc. For example, if it is monitored that a certain encryption task should have been completed within 10 seconds but actually took 15 seconds, or the specific memory space allocated to a certain task is occupied by other tasks, resulting in the abnormal operation of this task, these all belong to consistency verification exceptions.
[0051] Preferably, according to the generated consistency verification exception, the system immediately issues an exception warning, such as sending an email to notify the administrator, displaying a red warning sign on the system interface, issuing a sound alarm, etc. The content of the exception warning usually details the specific situation of the exception, such as which task has a problem, which resources are involved, the type and severity of the exception, etc., so that the administrator can quickly understand the key information of the problem; then, according to the exception warning, further report and record the overall exception situation of the cloud password service resource pool, which may include recording the exception information in the system log for subsequent troubleshooting and analysis; at the same time, send an exception report to the relevant management system or monitoring platform to comprehensively track and manage the operation status of the entire cloud password service; it may also classify and grade the exception situations to take corresponding measures according to different severity levels. For example, for severe exceptions, it may be necessary to immediately stop the execution of relevant tasks and perform emergency repairs; thus improving the efficiency of cloud password service scheduling management.
[0052] Further, step S500 further includes step S540, under the authorization of the tenant, create a tenant profile for the tenant and record the tenant response mapped to the updated cloud password scheduling scheme in the tenant profile; step S550, perform subsequent construction and optimization of the cloud password service resource pool for the tenant according to the tenant profile.
[0053] Preferably, in the cloud password service system, the tenant has certain control over the management and use of its own data. With the explicit authorization of the tenant, the cloud service provider creates a tenant profile for it. Among them, the tenant profile is a collection for storing tenant-related information, similar to a "dedicated folder", which contains the tenant's basic information (such as name, contact information, enterprise scale, etc.), service requirements (such as the type of encryption task, data volume size, security level requirements, etc.), and historical service records, etc.; and records and updates the tenant response mapped to the cloud password scheduling scheme in the tenant profile, that is, the feedback and performance of the tenant to the updated cloud password scheduling scheme. For example, the tenant may have its own evaluations and opinions on aspects such as the rationality of resource allocation, the efficiency of task execution, and the guarantee of data security in the scheme. Recording these tenant responses mapped to the updated cloud password scheduling scheme in the tenant profile can enable the cloud service provider to track the satisfaction of the tenant with different scheduling schemes and the changes in requirements, thereby improving the execution efficiency of encryption tasks.
[0054] Preferably, the cloud service provider deeply analyzes the tenant profile to explore the characteristics and requirements of the tenant. For example, by viewing the tenant's historical encryption task records, understanding the peak and trough periods of its tasks, and analyzing the tenant's preferences for different security levels and service qualities. Through these analyses, the rules and potential requirements of the tenant in the process of using cloud password services can be discovered. For example, it is found that a certain tenant will have a large number of high-priority encryption tasks during a specific period of each month and has extremely high requirements for data security; then, based on the analysis results of the tenant profile, the subsequent cloud password service resource pool is constructed and optimized in a targeted manner. If it is found that a certain tenant has a large demand for computing resources and is sudden, appropriately increase the dynamically allocable computing resources in the resource pool to meet the tenant's needs; according to the tenant's requirements for service quality, adjust the resource allocation strategy and task scheduling priority to ensure that cloud password services that meet the needs of different tenants are provided. For example, for tenants with high requirements for service quality, allocate high-performance resources first to ensure that their encryption tasks can be executed quickly and stably. Through the construction and optimization of the cloud password service resource pool, the cloud service provider can better meet the needs of tenants, improve tenant satisfaction, and at the same time optimize the configuration and management of the cloud password service resource pool, improving the utilization efficiency of resources and the overall quality of services.
[0055] In the above text, reference is made to Figure 1 which describes in detail the method for constructing a cloud password service resource pool based on container virtualization according to an embodiment of the present invention. Next, reference will be made to Figure 3 to describe a cloud password service resource pool construction system based on container virtualization according to an embodiment of the present invention.
[0056] The cloud password service resource pool construction system based on container virtualization according to an embodiment of the present invention is used to solve the technical problems existing in the prior art that the password service mode is difficult to meet the massive, diverse and dynamically changing user needs, resulting in poor data transmission and storage security in the cloud computing environment and poor encryption scheduling management efficiency of the cloud password service resource pool, realizing reasonable resource decomposition and scheduling, and achieving the technical effect of improving data security and encryption scheduling management efficiency. As Figure 3 shown, the cloud password service resource pool construction system based on container virtualization includes: an encryption task creation module 10, a task decomposition module 20, a four-dimensional scheduling strategy analysis module 30, a cloud password scheduling update module 40, and an encryption scheduling management module 50.
[0057] The encryption task creation module 10 is used to create an encryption task in response to user access data from the user access layer, and the user access data is tenant access data after information authentication; the task decomposition module 20 is used to perform task decomposition on the encryption task based on a password calculation graph to establish a subtask set, wherein the subtask set is provided with a task association identifier; the four-dimensional scheduling strategy analysis module 30 is used to perform four-dimensional scheduling strategy analysis on the subtask set to establish an initial cloud password scheduling plan; the cloud password scheduling update module 40 is used to activate a task scheduling engine, and after inputting the task association identifier and the initial cloud password scheduling plan as input data into the task scheduling engine, perform cloud password scheduling update to establish an updated cloud password scheduling plan; the encryption scheduling management module 50 is used to perform encryption scheduling management of the cloud password service resource pool by using the updated cloud password scheduling plan.
[0058] Next, the specific configuration of the four-dimensional scheduling strategy analysis module 30 will be described in detail. The four-dimensional scheduling strategy analysis module 30 further includes: configuring a four-dimensional scheduling loss function as follows: ; wherein, represents the four-dimensional scheduling loss function of the subtask on the computing resource , represents the dynamic priority weight of the subtask , , represents the time deadline urgency of the subtask , represents the computing resource requirement of the subtask , is the subtask index in the subtask set, represents the time deadline urgency of the subtask , represents the computing resource requirement of the subtask , , are the weight factors for the time deadline urgency and the computing resource requirement respectively, representing the subtask computing complexity, representing the computing resource computing power, representing the current load of the computing resource , representing the security matching penalty, , representing the required security level of the subtask , representing the security level provided by the computing resource , being the security weight coefficient, representing the SLA default penalty, representing the competition game factor, , being the SLA requirement of the subtask , representing the SLA requirement of the subtask , representing the computing complexity of the subtask , representing the balance parameter, , , , are the computing complexity impact weight, the load balancing impact weight, the security impact weight, and the SLA impact weight respectively, being the task game factor weight.
[0059] Next, the specific configuration of the cloud password scheduling update module 40 will be described in detail. The cloud password scheduling update module 40 further includes: obtaining the unique identifier of each subtask in the subtask set; calling the parsing layer to perform task association identification parsing based on the unique identifier, establishing subtask dependency associations and subtask conflict associations, where the parsing layer is the data calculation layer of the task scheduling engine; generating a first update scheduling constraint based on the subtask dependency associations and the subtask conflict associations, and performing scheduling update of the cloud password based on the first update scheduling constraint.
[0060] Next, the specific configuration of the cloud password scheduling update module 40 will be further described in detail. The cloud password scheduling update module 40 further includes: calling the load prediction layer, using the load prediction layer to perform load prediction of the computing resource, generating a load prediction result, where the load prediction layer is the data calculation layer of the task scheduling engine; establishing a second update scheduling constraint according to the load prediction result; using the first update scheduling constraint and the second update scheduling constraint to perform scheduling update of the cloud password.
[0061] Next, the specific configuration of the task decomposition module 20 will be described in detail. The task decomposition module 20 further includes: configuring the minimum splitting granularity of task splitting; based on the minimum splitting granularity as a constraint, performing task decomposition of the encryption task based on the password calculation graph, and establishing a subtask set.
[0062] Next, the specific configuration of the encryption scheduling management module 50 will be described in detail. The encryption scheduling management module 50 further includes: performing execution monitoring on the cloud password service resource pool, and establishing an execution monitoring result; based on the execution monitoring result and the updated cloud password scheduling scheme, performing execution consistency verification to generate a consistency verification exception; reporting an exception warning according to the consistency verification exception, and reporting an exception of the cloud password service resource pool according to the exception warning.
[0063] Next, the specific configuration of the encryption scheduling management module 50 will be further described in detail. The encryption scheduling management module 50 further includes: under the condition of tenant authorization, creating a tenant profile for the tenant, and recording the tenant response mapped to the updated cloud password scheduling scheme in the tenant profile; performing subsequent construction optimization of the cloud password service resource pool for the tenant according to the tenant profile.
[0064] The system for constructing a cloud password service resource pool based on container virtualization provided by the embodiments of the present invention can execute the method for constructing a cloud password service resource pool based on container virtualization provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0065] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, however, any number of different modules can be used and run on the user terminal and / or the server. The included individual units and modules are only divided according to the functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present invention.
[0066] The above specific embodiments do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A method for constructing a cloud cryptographic service resource pool based on container virtualization, characterized in that: The method comprises: In response to user access data of the user access layer, an encryption task is created, wherein the user access data is tenant access data after information authentication; Decomposing the encryption task based on the cryptographic computation graph to establish a subtask set, wherein the subtask set is provided with a task association identifier; Performing a four-dimensional scheduling strategy analysis of the subtask set and establishing an initial cloud cryptography scheduling scheme; Activate the task scheduling engine, input the task association identifier and the initial cloud password scheduling scheme into the task scheduling engine as input data, execute cloud password scheduling update, and establish an updated cloud password scheduling scheme; The updated cloud cryptographic scheduling scheme is used to perform encryption scheduling management of the cloud cryptographic service resource pool.
2. The method for constructing a cloud cryptographic service resource pool based on container virtualization according to claim 1, characterized in that: The four-dimensional scheduling strategy analysis for executing the subtask set includes: Configure the four-dimensional scheduling loss function as follows: ; in, Representation subtask In computing resources The four-dimensional scheduling loss function on Representation subtask The dynamic priority weight of , Representation subtask The urgency of the deadline, Representation subtask The computing resource requirements, is the subtask index in the subtask set, Representation subtask The urgency of the deadline, Representation subtask The computing resource requirements, , are the weight factors of deadline urgency and computing resource requirements, respectively. Representation subtask The computational complexity of Characterizing Computational Resources The computing power of Characterizing Computational Resources The current load, Characterizes the security matching penalty, , Representation subtask The required safety level, Characterizing Computational Resources The level of security provided, is the safety weight coefficient, Characterizes the SLA breach penalty, Characterize the competitive game factors, , For subtask SLA requirements, Representation subtask SLA requirements, Representation subtask The computational complexity of Characterize the equilibrium parameters, , , , They are the weights of computational complexity, load balancing, security, and SLA. is the task game factor weight.
3. The method for constructing a cloud cryptographic service resource pool based on container virtualization according to claim 2, characterized in that: The executing cloud password scheduling update comprises: Obtain a unique identifier for each subtask in the subtask set; Calling a parsing layer to perform task association identification parsing based on the unique identifier, and establishing subtask dependency associations and subtask conflict associations, the parsing layer being the data calculation layer of the task scheduling engine; A first update scheduling constraint is generated based on the subtask dependency association and the subtask conflict association, and a scheduling update of the cloud password is performed based on the first update scheduling constraint.
4. The method for constructing a cloud cryptographic service resource pool based on container virtualization according to claim 3, characterized in that: The executing the scheduling update of the cloud password based on the first update scheduling constraint includes: Calling a load prediction layer, using the load prediction layer to perform load prediction of computing resources, and generating a load prediction result, the load prediction layer being the data calculation layer of the task scheduling engine; Establishing a second updated scheduling constraint according to the load prediction result; The first update scheduling constraint and the second update scheduling constraint are used to perform a scheduling update of the cloud password.
5. The method for constructing a cloud cryptographic service resource pool based on container virtualization according to claim 1, characterized in that: The step of performing task decomposition on the encryption task based on a cryptographic computation graph includes: Configure the minimum splitting granularity of task splitting; Taking the minimum split granularity as a constraint, the encryption task is decomposed based on the cryptographic calculation graph to establish a subtask set.
6. The method for constructing a cloud cryptographic service resource pool based on container virtualization according to claim 1, characterized in that: The method of using the updated cloud cryptographic scheduling scheme to perform encryption scheduling management of a cloud cryptographic service resource pool includes: Performing execution monitoring on the cloud cryptographic service resource pool and establishing execution monitoring results; Performing execution consistency verification based on the execution monitoring result and the updated cloud password scheduling scheme, and generating a consistency verification exception; An abnormal warning is issued based on the consistency verification abnormality, and an abnormality of the cloud cryptographic service resource pool is reported based on the abnormal warning.
7. The method for constructing a cloud cryptographic service resource pool based on container virtualization according to claim 1, characterized in that: The method further comprises: With the authorization of the tenant, create a tenant profile for the tenant, and record the tenant response mapped with the updated cloud password scheduling scheme in the tenant profile; The subsequent cloud cryptographic service resource pool construction of the tenant is optimized based on the tenant profile.
8. A cloud cryptographic service resource pool construction system based on container virtualization, characterized in that: The system is used to implement the method for building a cloud cryptographic service resource pool based on container virtualization according to any one of claims 1 to 7, and the system includes: An encryption task creation module, used to create an encryption task in response to user access data of the user access layer, wherein the user access data is tenant access data after information authentication; A task decomposition module, used to decompose the encryption task based on the cryptographic calculation graph and establish a subtask set, wherein the subtask set is provided with a task association identifier; A four-dimensional scheduling strategy analysis module, used to perform a four-dimensional scheduling strategy analysis of the subtask set and establish an initial cloud cryptography scheduling plan; A cloud password scheduling update module is used to activate the task scheduling engine, input the task association identifier and the initial cloud password scheduling scheme as input data into the task scheduling engine, execute the cloud password scheduling update, and establish an updated cloud password scheduling scheme; The encryption scheduling management module is used to perform encryption scheduling management of the cloud cryptographic service resource pool by using the updated cloud cryptographic scheduling scheme.
Citation Information
Cited By
Cloud task scheduling method based on security grading rule
CN120872583A