Cloud service data information security management system suitable for mobile equipment

By designing a cloud service data information security management system suitable for mobile devices, the risk of company data leakage caused by mobile phone attacks is solved, and efficient data security management and resource optimization are achieved.

CN120201433APending Publication Date: 2025-06-24ZHENGZHOU UNIVERSITY OF LIGHT INDUSTRY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510410921.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the prior art, when company employees use their mobile phones to access company data, the risk of mobile phones being attacked by malware is high, resulting in the risk of company data being leaked.

Method used

A cloud service data information security management system suitable for mobile devices is designed, including data storage authentication module, data backup module, capacity adjustment module, intelligent resource scheduling module, central control module, VPN and data isolation module and cloud server. The system ensures data security and recoverability through encrypted storage, blockchain ledger, intelligent resource scheduling, VPN connection and data isolation strategies.

Benefits of technology

By establishing a secure VPN connection between the company and mobile devices and implementing data isolation policies within the VPN, the confidentiality and integrity of data is significantly enhanced and the risk of data breaches is reduced. At the same time, the intelligent resource scheduling and capacity adjustment modules improve resource utilization and operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201433A_ABST
    Figure CN120201433A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud service data information security management system suitable for mobile equipment. A data storage authentication module is responsible for providing and obtaining data; the data backup module is used for performing data backup operation; the capacity adjusting module is used for dynamically adjusting the capacity of the cloud server to adapt to data storage requirements in different time periods; and the VPN and data isolation module is used for establishing secure VPN connection between the company and the mobile equipment, the VPN provides an additional security layer, a data isolation strategy is implemented in the VPN, and the flow of data among different applications is limited. In the invention, when an employee uses a mobile device to access company data, the employee needs to establish a secure connection with the data isolation module through the VPN to ensure confidentiality and integrity in a data transmission process, and meanwhile, the VPN provides an additional security layer and is combined with a data isolation strategy for use, so that the security of the data can be further enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security management, and particularly to a cloud service data information security management system applicable to mobile devices. Background Art

[0002] With the rapid development of information technology, remote work has become an indispensable part of modern enterprises. The emergence of cloud services provides a new solution for remote work, enabling employees to collaborate anytime and anywhere through the network and access various applications and data provided by the enterprise. The cloud service data information security management system can ensure the security of data during transmission and storage, preventing data from being illegally leaked, tampered with, or lost. This is of great significance for protecting sensitive information such as the business secrets and customer privacy of enterprises. Through cloud services, employees can share, edit, and discuss files in real time, achieving efficient teamwork. The data information security management system can ensure the security of these collaboration processes and avoid the risks brought by information leakage and misoperation.

[0003] However, during the above use process, company employees use their own mobile phones to access company data. However, due to the poor security performance of mobile phones, there is a risk of being attacked by malicious software. Once the mobile phone is attacked, the company's data will face the risk of leakage. Therefore, a cloud service data information security management system applicable to mobile devices is proposed. Summary of the Invention

[0004] The purpose of the present invention is to solve the drawback that when using a mobile phone to access company data in the prior art, once the mobile phone is attacked, the company's data will face the risk of leakage, and a cloud service data information security management system applicable to mobile devices is proposed.

[0005] In order to achieve the above purpose, the present invention adopts the following technical solutions: A cloud service data information security management system applicable to mobile devices, comprising: A data storage and authentication module: responsible for providing and obtaining data, ensuring the legality and security of data, generating a unique identifier, public key, and private key for each data terminal, and maintaining a blockchain ledger to achieve encrypted storage and identity authentication of data. The data storage and authentication module stores the encrypted data in a cloud server and records the correspondence between the data terminal identifier and the cloud server address in the blockchain ledger; A data backup module: performing data backup operations according to the capacity adjustment result of the cloud server to prevent data loss, and adopting different backup strategies according to the predicted capacity to ensure the persistence and recoverability of data; Capacity adjustment module: Dynamically adjusts the capacity of the cloud server to adapt to the data storage requirements at different time periods. It realizes the intelligent adjustment of capacity by collecting time series data, building and training a prediction model, and predicting future capacity requirements. Intelligent resource scheduling module: Builds a resource prediction model and automatically adjusts the allocation and scheduling of resources such as CPU, memory, and storage according to the real-time load situation, resource utilization rate, and business priorities. It improves resource utilization rate and response speed through intelligent means. Central control module: The central control module connects to and manages the data storage authentication module, data backup module, capacity adjustment module, and intelligent resource scheduling module. At the same time, the central control module communicates with the cloud server to coordinate data interaction and work processes among modules. VPN and data isolation module: Establishes a secure VPN connection between the company and mobile devices to ensure the confidentiality and integrity of data during transmission. At the same time, it implements data isolation policies within the VPN to restrict the flow of data between different applications, protecting data privacy and security. When employees access company data, they need to first establish a secure connection through the VPN and data isolation module. The VPN and data isolation module implements data isolation policies internally to restrict the flow of data between different applications. At the same time, the VPN and data isolation module ensures the confidentiality and integrity of data during transmission, protecting data privacy and security. The cloud server conducts data interaction with employee devices through the VPN and data isolation module. Cloud server: The cloud server is responsible for storing encrypted data and providing data access services according to data requests. The capacity of the cloud server is dynamically adjusted by the capacity adjustment module, and the cloud server adjusts and optimizes resources according to the instructions of the intelligent resource scheduling module.

[0006] The above technical solution further includes: Furthermore, the capacity adjustment module includes a time series data collection unit, a prediction model building and training unit, a future capacity requirement prediction unit, and a capacity adjustment execution unit. The time series data collection unit is responsible for collecting time series data of the cloud server capacity load, including historical data of key performance indicators such as CPU usage rate, memory occupancy rate, and disk I / O, and transfers the collected time series data to the prediction model building and training unit. The prediction model building and training unit builds a prediction model based on the time series data and conducts training. After training the model, it transfers the prediction model to the future capacity requirement prediction unit. The future capacity requirement prediction unit uses the trained prediction model to predict future capacity requirements based on current and past time series data and transfers the prediction results to the capacity adjustment execution unit. The capacity adjustment execution unit dynamically adjusts the capacity of the cloud server according to the prediction results of future capacity requirements.

[0007] Further, the prediction model building and training unit combines LSTM and ARIMA to build a prediction model, including the following steps: Data preprocessing: Collect time series data from the cloud service system, such as historical records of key performance indicators such as CPU usage, memory occupancy, and disk I / O. Preprocess the time series data, including steps such as denoising and normalization, to improve data quality; ARIMA model training: Determine the ARIMA model parameters according to the autocorrelation function (ACF) and partial autocorrelation function (PACF) plots of the time series data , where p is the autoregressive order, d is the differencing order, and q is the moving average order. Train the ARIMA model to capture the linear trends and seasonal variations in the data; LSTM model training: Use the residual sequence of the ARIMA model as the input of the LSTM model, and at the same time construct the corresponding label data, that is, the future capacity demand value. Train the LSTM model to capture the non-linear relationships and long-term dependence problems in the data; Combined prediction: Combine the prediction results of the ARIMA model and the prediction results of the LSTM model to obtain the final prediction result.

[0008] Further, the intelligent resource scheduling module includes a data collection unit, a data analysis unit, a decision-making unit, a resource scheduling execution unit, and a monitoring and feedback unit. The data collection unit is responsible for collecting data related to the load situation, resource utilization, and business priorities on the cloud server in real time. The data analysis unit constructs a resource prediction model, processes and analyzes the collected data, and identifies the resource demand trends and bottlenecks. The decision-making unit formulates resource scheduling decisions based on the analysis results of the resource prediction model, including the allocation and scheduling of resources such as CPU, memory, and storage. The resource scheduling execution unit executes the resource allocation and scheduling operations according to the instructions of the decision-making unit. The monitoring and feedback unit monitors the execution of the resource scheduling, collects feedback information, and is used to evaluate the scheduling effect and optimize the scheduling strategy.

[0009] Further, the data analysis unit constructs a resource prediction model. First, use the support vector machine model for preliminary training to obtain a preliminary estimate of the resource demand. Then, use the random forest model to correct and optimize the preliminary estimate to identify the resource demand trends and bottlenecks, including the following steps: Data preprocessing: Collect data related to the real-time load situation, resource utilization, and business priorities from the cloud data center, remove invalid, missing, or abnormal data records, and extract feature variables related to resource demand, such as CPU usage, memory occupancy, and disk I / O; Initial training of support vector machine: Use the collected historical data to train the support vector machine model to obtain a preliminary estimate of resource requirements; Correction and optimization of random forest model: On the basis of the preliminary training of SVM, construct a random forest model. The random forest consists of multiple decision trees. Each decision tree randomly selects a part of the features from the original features for splitting during training. Use the preliminary estimation result of SVM as the input of the random forest to train the random forest model. By synthesizing the output results of multiple decision trees, a more accurate resource requirement prediction can be obtained; Identify resource requirement trends and bottlenecks: According to the prediction results of the random forest model, analyze the change trends of resource requirements, and combine business priorities and resource utilization rates to identify the bottleneck links of resource requirements. The bottleneck is manifested as a situation where the resource utilization rate is high, the business demand is large and difficult to meet.

[0010] Furthermore, the specific steps for identifying the bottleneck links of resource requirements by combining business priorities and resource utilization rates are as follows: Resource utilization rate: Calculate the utilization rates of various resources, such as CPU utilization rate, memory utilization rate, etc. The resource utilization rate formula is expressed as , where represents the utilization rate of the i-th resource, represents the current resource usage, represents the total amount of resources; Business priority: Use the weighted summation method to calculate the business priority and assign priorities to different businesses, which is expressed as , where represents the priority of the j-th business, represents the weight of the k-th evaluation factor, represents the score of the j-th business on the k-th evaluation factor; Identify bottleneck links: Set thresholds for resource utilization rate and business priority. For example, CPU utilization rate exceeding 80% or memory utilization rate exceeding 90% may be regarded as resource tension; business priority higher than a certain specific value may be regarded as a high-priority business. Match and analyze the resource utilization rate and business priority to find out the links with high resource utilization rate and high business priority. The said links are where the bottlenecks are located.

[0011] Furthermore, the VPN and data isolation module includes a VPN connection unit, a data isolation unit, an authentication and authorization unit, a logging and auditing unit, and a cloud server interaction unit. The VPN connection unit is responsible for establishing and maintaining a secure VPN connection between the company and mobile devices, ensuring the confidentiality and integrity of data during the data transmission process through encryption technology. The data isolation unit implements data isolation policies within the VPN, restricting the flow of data between different applications to prevent data leakage and abuse. The authentication and authorization unit authenticates the identities of employees accessing company data and authorizes their permissions, ensuring that only legitimate users can access sensitive data. The logging and auditing unit records all data access and operation logs passing through the VPN, providing an auditing function for traceability and analysis in the event of security incidents. The cloud server interaction unit is responsible for data interaction with the cloud server, transmitting data through the secure VPN channel to ensure the confidentiality and integrity of the data.

[0012] Furthermore, the data isolation unit implements data isolation policies within the VPN, restricting the flow of data between different applications, including the following steps: Policy definition: According to business requirements and security requirements, define data isolation policies, which include data access permissions and data flow rules; Policy implementation: Within the VPN, implement the defined data isolation policies through technical means (such as firewalls, access control lists, etc.); Monitoring and auditing: After implementing the data isolation policies, continuously monitor the data flow and record all access and operation logs for traceability and analysis in the event of security incidents.

[0013] The present invention has the following beneficial effects: 1. In the present invention, by establishing a secure VPN connection between the company and mobile devices, the confidentiality and integrity of data during the transmission process are ensured. At the same time, data isolation policies are implemented within the VPN to restrict the flow of data between different applications. The VPN provides an additional security layer, which, when combined with data isolation policies, can further enhance data security.

[0014] 2. In the present invention, a resource prediction model is constructed to automatically adjust the allocation and scheduling of resources according to real-time load conditions, resource utilization rates, and business priorities, ensuring the effective utilization of resources and the continuous operation of the business, reducing resource waste, improving resource utilization rates, and at the same time reducing operation and maintenance costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a system block diagram of a cloud service data information security management system for mobile devices proposed by the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0016] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0017] Please refer to Figure 1 As shown, the present invention is a cloud service data information security management system applicable to mobile devices, including: Data storage and authentication module: responsible for providing and obtaining data, ensuring the legality and security of data, generating a unique identifier, public key, and private key for each data terminal, and maintaining a blockchain ledger to achieve encrypted storage and identity authentication of data. The data storage and authentication module stores the encrypted data in the cloud server and records the correspondence between the data terminal identifier and the cloud server address in the blockchain ledger; Data backup module: performs data backup operations according to the capacity adjustment result of the cloud server to prevent data loss, and adopts different backup strategies according to the predicted capacity to ensure the persistence and recoverability of data; Capacity adjustment module: dynamically adjusts the capacity of the cloud server to adapt to the data storage requirements in different time periods. By collecting time series data, building and training a prediction model, and predicting future capacity requirements, intelligent adjustment of capacity is achieved; Intelligent resource scheduling module: constructs a resource prediction model, and automatically adjusts the allocation and scheduling of resources such as CPU, memory, and storage according to the real-time load situation, resource utilization rate, and business priority, and improves resource utilization rate and response speed through intelligent means; Central control module: The central control module connects to and manages the data storage and authentication module, data backup module, capacity adjustment module, and intelligent resource scheduling module. At the same time, the central control module communicates with the cloud server to coordinate data interaction and work processes between modules; VPN and data isolation module: ensures the confidentiality and integrity of data transmission by establishing a secure VPN connection between the company and the mobile device. At the same time, data isolation policies are implemented within the VPN to restrict the flow of data between different applications and protect the privacy and security of data. When employees access company data, they need to first establish a secure connection through the VPN and data isolation module. The VPN and data isolation module implements data isolation policies internally to restrict the flow of data between different applications. At the same time, the VPN and data isolation module ensures the confidentiality and integrity of data transmission and protects the privacy and security of data. The cloud server conducts data interaction with employee devices through the VPN and data isolation module; Cloud server: The cloud server is responsible for storing the encrypted data and providing data access services according to data requests. The capacity of the cloud server is dynamically adjusted by the capacity adjustment module, and the cloud server adjusts and optimizes resources according to the instructions of the intelligent resource scheduling module.

[0018] In one embodiment, the capacity adjustment module includes a time series data collection unit, a prediction model construction and training unit, a future capacity demand prediction unit, and a capacity adjustment execution unit. The time series data collection unit is responsible for collecting the time series data of the cloud server capacity load, including historical data of key performance indicators such as CPU usage rate, memory occupancy rate, disk I / O, etc., and transmitting the collected time series data to the prediction model construction and training unit. The prediction model construction and training unit constructs a prediction model based on the time series data and conducts training. After training the model, it transmits the prediction model to the future capacity demand prediction unit. The future capacity demand prediction unit uses the trained prediction model to predict the future capacity demand according to the current and past time series data, and transmits the prediction result to the capacity adjustment execution unit. The capacity adjustment execution unit dynamically adjusts the capacity of the cloud server according to the prediction result of the future capacity demand.

[0019] In one embodiment, the prediction model construction and training unit combines LSTM and ARIMA to construct a prediction model, including the following steps: Data preprocessing: Collect time series data from the cloud service system, such as historical records of key performance indicators such as CPU usage rate, memory occupancy rate, disk I / O, etc., and preprocess the time series data, including steps such as denoising and normalization, to improve data quality; ARIMA model training: Determine the ARIMA model parameters according to the autocorrelation function (ACF) and partial autocorrelation function (PACF) graphs of the time series data , where p is the autoregressive order, d is the differencing order, and q is the moving average order, and train the ARIMA model to capture the linear trend and seasonal changes in the data; LSTM model training: Use the residual sequence of the ARIMA model as the input of the LSTM model, and at the same time construct the corresponding label data, that is, the future capacity demand value, and train the LSTM model to capture the non-linear relationship and long-term dependence problems in the data; Combined prediction: Combine the prediction results of the ARIMA model and the LSTM model to obtain the final prediction result.

[0020] In one embodiment, the intelligent resource scheduling module includes a data collection unit, a data analysis unit, a decision-making unit, a resource scheduling execution unit, and a monitoring and feedback unit. The data collection unit is responsible for collecting data related to the load situation, resource utilization rate, and business priority on the cloud server in real time. The data analysis unit constructs a resource prediction model, processes and analyzes the collected data, and identifies the demand trend and bottleneck of resources. The decision-making unit formulates resource scheduling decisions based on the analysis results of the resource prediction model, including the allocation and scheduling of resources such as CPU, memory, and storage. The resource scheduling execution unit executes the resource allocation and scheduling operations according to the instructions of the decision-making unit. The monitoring and feedback unit monitors the execution of resource scheduling, collects feedback information, and is used to evaluate the scheduling effect and optimize the scheduling strategy.

[0021] In one embodiment, the data analysis unit constructs a resource prediction model. First, it uses a support vector machine model for preliminary training to obtain a preliminary estimate of resource requirements. Then, it uses a random forest model to correct and optimize the preliminary estimate, and identifies the demand trend and bottleneck of resources, including the following steps: Data preprocessing: Collect data related to the real-time load situation, resource utilization rate, and business priority from the cloud data center, remove invalid, missing, or abnormal data records, and extract feature variables related to resource requirements, such as CPU usage rate, memory occupancy rate, disk I / O, etc.; Support vector machine preliminary training: Use the collected historical data to train the support vector machine model to obtain a preliminary estimate of resource requirements; Random forest model correction and optimization: On the basis of SVM preliminary training, construct a random forest model. The random forest consists of multiple decision trees. Each decision tree randomly selects a part of the features from the original features for splitting during training. Use the preliminary estimation result of SVM as the input of the random forest model to train the random forest model, and obtain a more accurate resource demand prediction by synthesizing the output results of multiple decision trees; Identify resource demand trends and bottlenecks: According to the prediction results of the random forest model, analyze the change trend of resource demand, and combine business priority and resource utilization rate to identify the bottleneck links of resource demand. The bottleneck is manifested as a situation where the resource utilization rate is high, the business demand is large, and it is difficult to meet.

[0022] In one embodiment, the specific steps for identifying the bottleneck links of resource demand by combining business priority and resource utilization rate when identifying resource demand trends and bottlenecks are as follows: Resource utilization rate: Calculate the utilization rate of various resources, such as CPU utilization rate, memory utilization rate, etc. The resource utilization rate formula is expressed as , where represents the utilization rate of the \(i\)-th type of resource, represents the current resource usage, represents the total amount of resources; Business priority: The weighted summation method is used to calculate the business priority, and priorities are assigned to different services, expressed as , where represents the priority of the \(j\)-th service, represents the weight of the \(k\)-th evaluation factor, represents the score of the \(j\)-th service on the \(k\)-th evaluation factor; Identifying bottleneck links: Set thresholds for resource utilization and business priority. For example, a CPU utilization rate exceeding 80% or a memory utilization rate exceeding 90% may be regarded as resource stress; a business priority higher than a certain specific value may be regarded as a high-priority service. Perform a matching analysis of resource utilization and business priority to find the links with high resource utilization and high business priority, and the said links are where the bottlenecks are located.

[0023] In one embodiment, the VPN and data isolation module includes a VPN connection unit, a data isolation unit, an authentication and authorization unit, a logging and auditing unit, and a cloud server interaction unit. The VPN connection unit is responsible for establishing and maintaining a secure VPN connection between the company and the mobile device, ensuring the confidentiality and integrity of the data transmission process through encryption technology. The data isolation unit implements data isolation policies within the VPN, restricting the flow of data between different applications to prevent data leakage and abuse. The authentication and authorization unit authenticates the identity and authorizes the permissions of employees accessing company data to ensure that only legitimate users can access sensitive data. The logging and auditing unit records all data access and operation logs passing through the VPN, providing an auditing function for traceability and analysis in case of security incidents. The cloud server interaction unit is responsible for data interaction with the cloud server, transmitting data through the secure VPN channel to ensure the confidentiality and integrity of the data.

[0024] In one embodiment, the data isolation unit implements data isolation policies within the VPN, restricting the flow of data between different applications, including the following steps: Policy definition: Define data isolation policies according to business requirements and security requirements. The data isolation policies include access permissions for data and rules for data flow; Policy implementation: Implement the defined data isolation policies within the VPN through technical means (such as firewalls, access control lists, etc.); Monitoring and auditing: After implementing the data isolation policies, continuously monitor the data flow and record all access and operation logs for traceability and analysis in case of security incidents; Suppose in a telecommuting environment, there are two applications, Application A and Application B, which process sensitive data and ordinary data respectively. To prevent the leakage of sensitive data into the ordinary data application, the following data isolation policies are defined:

[0025] Policy 1: The data generated by Application A can only be accessed by Application A itself or administrators with specific permissions.

[0026] Policy 2: Application B cannot access the data generated by Application A.

[0027] In the implementation phase, these policies are implemented through the firewall rules within the VPN. For example, we set firewall rules to prohibit any data flow from the IP address range of Application B to the data storage area of Application A.

[0028] In the monitoring and auditing phase, a log collection and analysis system is deployed to record all data access and operation logs passing through the VPN. If any data flow violating the policy is detected, the system will immediately issue an alarm and generate a detailed audit report.

[0029] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A cloud service data information security management system suitable for mobile devices, characterized in that: include: Data storage authentication module: responsible for providing and acquiring data, generating a unique identifier, public key and private key for each data terminal, and maintaining the blockchain account book. The data storage authentication module stores the encrypted data in the cloud server and records the correspondence between the data terminal identifier and the cloud server address in the blockchain account book; Data backup module: performs data backup operations based on the capacity adjustment results of the cloud server and adopts different backup strategies based on the predicted capacity; Capacity adjustment module: dynamically adjusts the capacity of cloud servers to meet data storage requirements in different time periods by collecting time series data, building prediction models, and training and predicting future capacity requirements; Intelligent resource scheduling module: builds a resource prediction model to automatically adjust resource allocation and scheduling based on real-time load conditions, resource utilization, and business priorities; Central control module: The central control module connects and manages the data storage authentication module, the data backup module, the capacity adjustment module and the intelligent resource scheduling module. At the same time, the central control module communicates with the cloud server; VPN and data isolation module: By establishing a secure VPN connection between the company and the mobile device, and implementing a data isolation policy within the VPN to limit the flow of data between different applications, when employees access company data, they need to first establish a secure connection through the VPN and data isolation module. The VPN and data isolation module implements a data isolation policy internally to limit the flow of data between different applications. The cloud server interacts with the employee's device through the VPN and data isolation module; Cloud server: The cloud server is responsible for storing encrypted data and providing data access services based on data requests. The capacity of the cloud server is dynamically adjusted by the capacity adjustment module. The cloud server adjusts and optimizes resources according to the instructions of the intelligent resource scheduling module.

2. A cloud service data information security management system suitable for mobile devices according to claim 1, characterized in that: The capacity adjustment module includes a time series data collection unit, a prediction model building and training unit, a future capacity demand prediction unit and a capacity adjustment execution unit. The time series data collection unit is responsible for collecting the time series data of the cloud server capacity load, and passing the collected time series data to the prediction model building and training unit. The prediction model building and training unit builds a prediction model based on the time series data and performs training. After the model is trained, the prediction model is passed to the future capacity demand prediction unit. The future capacity demand prediction unit uses the trained prediction model to predict future capacity demand based on current and past time series data, and passes the prediction result to the capacity adjustment execution unit. The capacity adjustment execution unit dynamically adjusts the capacity of the cloud server according to the prediction result of future capacity demand.

3. A cloud service data information security management system suitable for mobile devices according to claim 2, characterized in that: The prediction model building and training unit combines LSTM and ARIMA to build a prediction model, including the following steps: Data preprocessing: Collect time series data from the cloud service system and preprocess the time series data; ARIMA model training: Determine the ARIMA model parameters based on the autocorrelation function and partial autocorrelation function graph of the time series data , where p is the autoregressive order, d is the difference order, and q is the moving average order. Train the ARIMA model to capture the linear trend and seasonal changes in the data; LSTM model training: The residual sequence of the ARIMA model is used as the input of the LSTM model. At the same time, the corresponding label data, that is, the future capacity demand value, is constructed. The LSTM model is trained to capture the nonlinear relationship and long-term dependency problems in the data. Combined prediction: The prediction results of the ARIMA model and the LSTM model are combined to obtain the final prediction results.

4. A cloud service data information security management system suitable for mobile devices according to claim 1, characterized in that: The intelligent resource scheduling module includes a data collection unit, a data analysis unit, a decision-making unit, a resource scheduling execution unit and a monitoring and feedback unit. The data collection unit is responsible for collecting real-time load conditions, resource utilization and business priority related data on the cloud server. The data analysis unit builds a resource prediction model, processes and analyzes the collected data, and identifies resource demand trends and bottlenecks. The decision-making unit makes resource scheduling decisions based on the analysis results of the resource prediction model. The resource scheduling execution unit executes resource allocation and scheduling operations according to the instructions of the decision-making unit. The monitoring and feedback unit monitors the execution of resource scheduling and collects feedback information for evaluating scheduling effects and optimizing scheduling strategies.

5. A cloud service data information security management system suitable for mobile devices according to claim 4, characterized in that: The data analysis unit constructs a resource prediction model, firstly performs preliminary training using a support vector machine model to obtain a preliminary estimate of resource demand, and then uses a random forest model to correct and optimize the preliminary estimate to identify resource demand trends and bottlenecks, including the following steps: Data preprocessing: Collect real-time load conditions, resource utilization, and business priority data from cloud data centers, remove invalid, missing, or abnormal data records, and extract characteristic variables related to resource requirements; Initial training of support vector machine: Use the collected historical data to train the support vector machine model to obtain a preliminary estimate of resource requirements; Modification and optimization of random forest model: Based on the initial training of SVM, a random forest model is constructed. The initial estimation results of SVM are used as the input of random forest to train the random forest model. By integrating the output results of multiple decision trees, resource demand forecasts are obtained. Identify resource demand trends and bottlenecks: Based on the prediction results of the random forest model, analyze the changing trend of resource demand, combine business priorities and resource utilization, and identify the bottleneck links of resource demand. The bottleneck is manifested as high resource utilization and large and difficult to meet business demand.

6. A cloud service data information security management system suitable for mobile devices according to claim 5, characterized in that: When identifying resource demand trends and bottlenecks, the specific steps to identify the bottleneck of resource demand are as follows, combining business priorities and resource utilization: Resource utilization: Calculate the utilization of various resources. The resource utilization formula is: ,in, represents the utilization rate of the i-th resource, Indicates the current resource usage. Indicates the total amount of resources; Business priority: Use the weighted sum method to calculate business priority and assign priorities to different businesses, expressed as ,in, represents the priority of the jth service, represents the weight of the kth evaluation factor, represents the score of the j-th business on the k-th evaluation factor; Identify bottleneck links: set thresholds for resource utilization and business priority, match and analyze resource utilization and business priority, and find links with high resource utilization and high business priority, which are bottlenecks.

7. A cloud service data information security management system suitable for mobile devices according to claim 1, characterized in that: The VPN and data isolation module includes a VPN connection unit, a data isolation unit, an authentication and authorization unit, a logging and auditing unit, and a cloud server interaction unit. The VPN connection unit is responsible for establishing and maintaining a secure VPN connection between the company and the mobile device. The data isolation unit implements a data isolation policy within the VPN to limit the flow of data between different applications. The authentication and authorization unit performs identity authentication and permission authorization on employees who access company data. The logging and auditing unit records all data access and operation logs through the VPN. The cloud server interaction unit is responsible for data interaction with the cloud server and transmitting data through a VPN secure channel.

8. A cloud service data information security management system suitable for mobile devices according to claim 7, characterized in that: The data isolation unit implements a data isolation strategy within the VPN to limit the flow of data between different applications, including the following steps: Policy definition: Define data isolation policies based on business needs and security requirements. The data isolation policies include data access permissions and data flow rules. Policy implementation: Implement defined data isolation policies within the VPN through technical means; Monitoring and auditing: After implementing the data isolation strategy, data flow is continuously monitored and all access and operation logs are recorded.