Power Internet of Things gateway management method and device, server and storage medium

Through containerized deployment and trusted platform modules, combined with software-defined networks, the shortcomings of the power IoT gateway in resource utilization, security protection and system flexibility are solved, efficient dynamic management and security protection are achieved, and the security and scalability of the system are improved.

CN120301902APending Publication Date: 2025-07-11GUANGDONG POWER GRID CO LTD CHAOZHOU POWER SUPPLY BUREAU +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510285701.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing power IoT gateways have shortcomings in resource utilization, security protection and system flexibility, and are difficult to meet current needs.

Method used

It adopts containerized deployment technology, combined with trusted platform modules and software-defined networks, to achieve application and service isolation, and dynamic management and security protection are carried out through the container orchestration platform.

Benefits of technology

It improves the security, reliability and stability of the system, improves resource utilization and system scalability, supports dynamic configuration and management in different environments, and reduces the risks of malicious attacks and internal threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301902A_ABST
    Figure CN120301902A_ABST
Patent Text Reader

Abstract

The invention provides a power Internet of Things gateway management method and device, a server and a storage medium, and relates to the technical field of computers. The method is applied to a container arrangement platform, and the container arrangement platform carries out independent containerization deployment on services and / or applications on power internet of things gateway equipment based on a container technology to obtain a plurality of containers. The container arrangement platform monitors the operation states of a plurality of containers; when it is monitored that the target container in the multiple containers is abnormal, credible restarting and / or credible repairing are / is conducted on the target container based on the credible platform module. By means of containerized deployment, application and / or service isolation is achieved, the safety of the system is improved, system modularization is achieved in a containerized mode, and the expansibility of the system and the utilization rate of hardware resources are improved. On the basis of containerized deployment, hardware-level security protection measures are realized by using the trusted platform module, so that the operating environment in the container is strictly controlled, the security is further improved, and the safe and stable operation of the Internet of Things gateway is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular, to a management method, device, server, and storage medium for a power Internet of Things gateway. Background Art

[0002] With the integrated development of information technology and power systems, the power Internet of Things (IoT) has gradually become a core component of intelligent power systems. As a key device for data acquisition, device management, and control, the power Internet of Things gateway plays a pivotal role in connecting power devices, sensors, and cloud platforms. The power Internet of Things gateway not only needs to support remote device monitoring and data transmission but also possess efficient computing and storage capabilities to handle the increasing data processing requirements. However, current power Internet of Things gateways face a series of challenges, especially in terms of resource utilization, security protection, and system flexibility.

[0003] Therefore, there is an urgent need for an effective management method for power Internet of Things gateways to meet the current requirements of power Internet of Things gateways. Summary of the Invention

[0004] The present application provides a management method, device, server, and storage medium for a power Internet of Things gateway to improve the resource utilization rate, security, flexibility, and scalability of the power Internet of Things gateway.

[0005] In a first aspect, the present application provides a management method for a power Internet of Things gateway, which is applied to a container orchestration platform deployed on a server. The server is communicatively connected to a power Internet of Things gateway device. The container orchestration platform performs independent containerization deployment of services and / or applications on the power Internet of Things gateway device based on container technology to obtain a plurality of containers.

[0006] The management method includes:

[0007] Monitoring the running status of a plurality of containers;

[0008] When an abnormal target container is detected among the plurality of containers, a trusted restart and / or trusted repair is performed on the target container based on a trusted platform module integrated on the power Internet of Things gateway device. The trusted platform module is used to provide a trusted execution environment for the container.

[0009] In a possible implementation manner, performing a trusted restart and / or trusted repair on the target container based on the trusted platform module includes:

[0010] Invoking the trusted platform module to verify the trustworthiness of the image corresponding to the target container. The trustworthiness reflects the integrity and non-tampering of the image.

[0011] If the image is not trusted, repair or replace the image to obtain a trusted image; and based on the trusted image, restart the target container; or, based on the trusted image, recreate a new container to complete the trusted repair of the target container.

[0012] If the image is trusted, based on the verified image, restart the target container; or, based on the verified image, recreate a new container to complete the trusted repair of the target container.

[0013] In a possible implementation, a software-defined network is deployed on the power Internet of Things gateway device, and the software-defined network is used to allocate isolated network resources for the container. The management method further includes:

[0014] After creating a new container, call the trusted platform module to verify the trustworthiness of the new container;

[0015] If the new container is trusted, based on the software-defined network, allocate isolated network resources to the new container, so that the new container performs network communication based on the allocated isolated network resources.

[0016] In a possible implementation, the management method of the power Internet of Things gateway further includes:

[0017] By communicating with the power Internet of Things gateway device, monitor the load status information of the power Internet of Things gateway device;

[0018] According to the load status information, schedule the container cluster corresponding to the power Internet of Things gateway device.

[0019] In a possible implementation, according to the load status information, scheduling the container cluster corresponding to the power Internet of Things gateway device includes:

[0020] According to the load status information, expand or reduce the scale of the container cluster;

[0021] And / or, according to the load status information, adjust the resource allocation of each container in the container cluster, and the resource allocation includes computing resource allocation, storage resource allocation, and network bandwidth allocation.

[0022] In a possible implementation, according to the load status information, scheduling the container cluster corresponding to the power Internet of Things gateway device includes:

[0023] Input the load status information into a pre-trained resource scheduling model to obtain a scheduling policy corresponding to the load status information;

[0024] According to the scheduling policy, schedule the container cluster corresponding to the power Internet of Things gateway device.

[0025] In a possible implementation, the management method of the power Internet of Things gateway further includes:

[0026] Monitor the operating status of the power IoT gateway device;

[0027] When a fault of the power IoT gateway device is detected, migrate the container corresponding to the power IoT gateway device to a normal power IoT gateway device.

[0028] In a possible implementation manner, the container orchestration platform is Apache Mesos.

[0029] In a second aspect, the present application provides a management device for a power IoT gateway, which is applied to a container orchestration platform. The container orchestration platform is deployed on a server, and the server is communicatively connected to the power IoT gateway device. The container orchestration platform, based on container technology, performs independent containerized deployment on services and / or applications on the power IoT gateway device to obtain a plurality of containers;

[0030] The management device includes:

[0031] A monitoring module, configured to monitor the operating status of a plurality of containers;

[0032] A processing module, configured to, when an abnormal target container is detected among the plurality of containers, perform a trusted restart and / or trusted repair on the target container based on a trusted platform module. The trusted platform module is integrated on the power IoT gateway device, and the trusted platform module is used to provide a trusted execution environment for the container.

[0033] In a possible implementation manner, the processing module is specifically configured to: call the trusted platform module to verify the trustworthiness of the image corresponding to the target container, where the trustworthiness reflects the integrity and non-tampering of the image; if the image is untrusted, repair or replace the image to obtain a trusted image; and based on the trusted image, restart the target container; or, based on the trusted image, recreate a new container to complete the trusted repair of the target container; if the image is trusted, based on the verified image, restart the target container; or, based on the verified image, recreate a new container to complete the trusted repair of the target container.

[0034] In a possible implementation manner, a software-defined network is deployed on the power IoT gateway device. The software-defined network is used to allocate isolated network resources for the container. The processing module is further configured to: after creating a new container, call the trusted platform module to verify the trustworthiness of the new container; if the new container is trusted, based on the software-defined network, allocate isolated network resources to the new container, so that the new container performs network communication based on the allocated isolated network resources.

[0035] In a possible implementation manner, the monitoring module is further configured to: monitor the load status information of the power IoT gateway device by communicating with the power IoT gateway device; and schedule the container cluster corresponding to the power IoT gateway device according to the load status information.

[0036] In a possible implementation manner, the monitoring module is specifically configured to: expand or reduce the scale of the container cluster according to the load status information; and / or adjust the resource allocation of each container in the container cluster according to the load status information, where the resource allocation includes computing resource allocation, storage resource allocation, and network bandwidth allocation.

[0037] In a possible implementation manner, the monitoring module is further configured to: input the load status information into a pre-trained resource scheduling model to obtain a scheduling policy corresponding to the load status information; and schedule the container cluster corresponding to the power Internet of Things gateway device according to the scheduling policy.

[0038] In a possible implementation manner, the monitoring module is further configured to: monitor the operating status of the power Internet of Things gateway device; and when a failure of the power Internet of Things gateway device is detected, migrate the container corresponding to the power Internet of Things gateway device to a normal power Internet of Things gateway device.

[0039] In a possible implementation manner, the container orchestration platform is Apache Mesos.

[0040] In a third aspect, the present application provides a server, including: a memory, a processor;

[0041] The memory stores computer-executable instructions;

[0042] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementation manners of the first aspect.

[0043] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed, they are used to implement the above first aspect and / or various possible implementation manners of the first aspect.

[0044] In a fifth aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed, it implements the above first aspect and / or various possible implementation manners of the first aspect.

[0045] The management method, device, server, and storage medium of the power IoT gateway provided by this application are applied to a container orchestration platform. The container orchestration platform is deployed on a server, and the server is communicatively connected to the power IoT gateway device. Based on container technology, the container orchestration platform performs independent containerized deployment on services and / or applications on the power IoT gateway device to obtain multiple containers. Through containerized deployment, application and / or service isolation is achieved, the risk of being attacked maliciously or threatened internally is reduced, and the security, reliability, and stability of the system are improved. Containerization can also improve system scalability and hardware resource utilization rate, and support dynamic configuration and management of the power IoT gateway in different environments. When the container orchestration platform detects an abnormality in a target container among multiple containers, based on the trusted platform module, it performs a trusted restart and / or trusted repair on the target container, realizing hardware-level security protection measures using the trusted platform module on the basis of containerized deployment, ensuring that the operating environment inside the container is strictly controlled, further improving security, and guaranteeing the safe and stable operation of the IoT gateway. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0047] Figure 1 It is a schematic diagram of the scenario of the management method of the power IoT gateway provided by an embodiment of this application;

[0048] Figure 2 It is a schematic flowchart of the management method of the power IoT gateway provided by an embodiment of this application;

[0049] Figure 3 It is a principle block diagram of the intelligent security management and energy-saving technology of the power IoT gateway provided by an embodiment of this application;

[0050] Figure 4 It is a schematic structural diagram of the management device of the power IoT gateway provided by an embodiment of this application;

[0051] Figure 5 It is a schematic structural diagram of the server provided by an embodiment of this application.

[0052] Through the above-mentioned drawings, the clear embodiments of this application have been shown, and there will be more detailed descriptions later. These drawings and text descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of apparatuses and methods consistent with some aspects of the present application as detailed in the appended claims.

[0054] In related technologies, the management of power IoT gateways generally includes the following methods: First, an embedded system is used for the tight integration of hardware and software. This method usually has a relatively fixed hardware configuration and operating system and is suitable for applications in specific scenarios. Although the embedded system has low power consumption and strong real-time performance and can operate stably on devices with limited resources. However, due to the lack of sufficient modularity and flexibility in the embedded system, when the system needs to be functionally extended, relatively complex hardware upgrades or firmware updates are usually required, which not only increases the maintenance cost but also may lead to system instability and unavailability. Moreover, since the computing resources, memory, and storage capabilities of the device are mostly statically configured, the resource utilization efficiency is low during actual operation. In addition, the isolation of the embedded system is relatively limited. Second, virtualization technology is used to partition hardware resources into multiple virtual machines to achieve resource isolation and management. The virtualization technology in power IoT gateways enables different services and applications to run in independent virtual environments, improving the isolation and security of the system. For example, virtual machine technology can provide support for different operating systems for power IoT gateways and improve the scalability of the system through resource allocation strategies. However, virtualization technology usually requires a large computing overhead, resulting in low resource utilization, long startup time, and insufficient flexibility. Third, rely on traditional security protection means, such as encryption protocols (such as Transport Layer Security / Secure Sockets Layer protocol (TLS / SSL)), firewalls, Intrusion Detection System (IDS), etc., to ensure the security and integrity of data. These technologies can effectively prevent external attacks and data tampering. However, in the face of a large-scale, distributed power IoT environment or complex and changing attack scenarios, there are certain limitations in security. For example, the trust chain and identity authentication mechanism between devices are relatively weak and are easily exploited by attackers.

[0055] In summary, related technologies have deficiencies in aspects such as resource utilization, security protection, and system flexibility, and still cannot meet the current requirements of power IoT gateways.

[0056] The inventors' research found that power Internet of Things gateways are generally deployed between power equipment and monitoring terminals and are required to operate efficiently in different environments. As a lightweight virtualization technology, container technology can be an ideal choice for improving the performance of power Internet of Things gateways due to its high efficiency, flexibility, and energy-saving characteristics.

[0057] To solve the above problems, this application provides a management method for power Internet of Things gateways. By containerizing the deployment of power Internet of Things gateways, application and / or service isolation is achieved, reducing the risk of being attacked maliciously or threatened internally, and improving the security, reliability, and stability of the system. Containerization is used to improve system scalability and hardware resource utilization. On the basis of containerized deployment, a trusted platform module is used for hardware-level security protection measures to ensure that the operating environment within the container is strictly controlled, further enhancing security and guaranteeing the safe and stable operation of the power Internet of Things gateway.

[0058] The following uses specific embodiments to elaborate in detail on the technical solutions of this application and how the technical solutions of this application solve the above technical problems. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0059] Figure 1 It is a schematic diagram of the scenario of the management method for the power Internet of Things gateway provided by the embodiments of this application. As Figure 1 shown, the management method for the power Internet of Things gateway provided by the embodiments of this application is applied to a container orchestration platform. The container orchestration platform is deployed on a server, and the server is communicatively connected to the power Internet of Things gateway device. Among them, the number of servers and power Internet of Things gateway devices can both be at least one. In practical applications, for example, relevant technical personnel such as operation and maintenance personnel perform independent containerized deployment of services and / or applications on the power Internet of Things gateway device through the container orchestration platform to obtain multiple containers. After the deployment is completed, the management method for the power Internet of Things gateway provided by this application is executed to complete the effective management of each power Internet of Things gateway device.

[0060] It should be noted that the server can also be replaced by a server cluster or other computing devices with a certain computing power. The container orchestration platform is generally deployed on a server with a certain computing power, and can also be a computer, a laptop, a virtual machine, etc.

[0061] The following combines Figure 1 the application scenario of Figure 2 to describe the management method for the power Internet of Things gateway provided by the embodiments of this application. It should be noted that the above application scenario is only shown for the convenience of understanding the spirit and principle of this application, and the implementation manner of this application is not limited by Figure 1 the shown application scenario.

[0062] Figure 2 It is a schematic flowchart of the management method of the power IoT gateway provided by the embodiments of the present application.

[0063] The management method of the power IoT gateway provided by the embodiments of the present application is applied to a container orchestration platform. The container orchestration platform is deployed on a server, and the server is communicatively connected to the power IoT gateway device. Based on container technology, the container orchestration platform performs independent containerization deployment on services and / or applications on the power IoT gateway device to obtain multiple containers.

[0064] Among them, the power IoT gateway device is used to connect sensors, control devices, and other intelligent terminals to the central system or cloud platform, and is mainly responsible for data forwarding and communication. Through the container orchestration platform, operation and maintenance personnel perform automated container deployment on various applications and services on the power IoT gateway device. After containerization deployment, each application and service can run independently in a standardized container environment, and the containers are isolated from each other and managed independently, avoiding resource conflicts and mutual interference between different services or applications.

[0065] The containerized deployment method can not only achieve more efficient resource utilization, but also greatly improve the flexibility and scalability of the system, supporting the dynamic configuration and management of the power IoT gateway in different environments. In addition, through the container orchestration platform to achieve automated deployment and management of large-scale systems, it can also quickly respond to changes in business requirements, reduce the complexity of system upgrades and maintenance, and at the same time reduce development and operation and maintenance costs.

[0066] Compared with the traditional monolithic architecture, all functions on the power IoT gateway device are integrated into the same application, and the deployment and management are relatively simple. However, with the increase in business scale and functional requirements, the monolithic architecture may encounter performance bottlenecks, resulting in increased system complexity, poor scalability, and difficult maintenance, making it difficult to meet the requirements of high concurrency and high availability. The embodiments of the present application adopt a containerized modular architecture, enabling each functional module of the system to be independently deployed, managed, and extended, which is more suitable for large-scale and dynamically changing power IoT gateway application scenarios.

[0067] As Figure 2 shown, the management method of the power IoT gateway provided by the embodiments of the present application includes the following steps:

[0068] S201. Monitor the running status of multiple containers.

[0069] Among them, the running status can be regarded as different stages or states that a container is in during its life cycle, not limited to including running, stopped, paused, suspended, failed, container environment, etc. With the continuous deployment of the power IoT gateway device, the network environment is complex and changeable, and the container system may be affected by various external attacks or internal failures.

[0070] The container orchestration platform can integrate powerful tools to monitor the running status of containers. For example, probes, log collection tools, event monitoring tools, resource monitoring tools, setting alarm rules, etc.

[0071] S202. When it is detected that the target container among multiple containers is abnormal, based on the trusted platform module, perform a trusted restart and / or trusted repair on the target container. The trusted platform module is integrated on the power Internet of Things gateway device, and the trusted platform module is used to provide a trusted execution environment for the container.

[0072] Exemplarily, integrate a trusted platform module (Trusted Platform Module, TPM) module in each power Internet of Things gateway device. TPM is a dedicated hardware chip that can be used to ensure the integrity of the startup and running environment of the power Internet of Things gateway device.

[0073] When the container orchestration platform detects that the target container fails to run, the process hangs, the container environment is damaged, it is under a malicious attack, the application or service in the container is tampered with, or shows abnormal behavior, etc., the running status of the target container is identified as abnormal. Once the abnormal running status of the container is detected, the target container is automatically triggered to be restarted and / or repaired, and the TPM is called for full-process trusted verification during the restart and repair process. In practical applications, if the target container is abnormal and the running status of the target container cannot be restored through a trusted restart, or the abnormality of the target container is related to data integrity and security, then the target container needs to be further subjected to a trusted repair. Through trusted restart or trusted repair, ensure the integrity and security of the target container to prevent malware or unauthorized modifications from affecting the running of the container.

[0074] In the embodiments of this application, through containerized deployment, application and / or service isolation is achieved. Even if a certain container is attacked or damaged, the attack will not spread to other containers or affect the entire power Internet of Things gateway system, reducing the risk of being subjected to malicious attacks or internal threats, and improving the security, reliability and stability of the system. Containerization can also improve the system scalability and hardware resource utilization rate, and support the dynamic configuration and management of the power Internet of Things gateway in different environments. Based on the security isolation ability of container technology, the container orchestration platform monitors the running status of containers. When a container is abnormal, based on the TPM, perform automated security responses, trusted container restart and / or trusted repair, quickly restore the trusted state of the container, and realize hardware-level security protection measures using the TPM on the basis of containerized deployment, ensure that the running environment in the container is strictly controlled, further improve the security of the power Internet of Things gateway system, significantly enhance the anti-attack ability of the system, and ensure the safe and stable operation of the Internet of Things gateway, especially suitable for environments with high reliability and high security requirements such as power Internet of Things gateways.

[0075] Compared with the traditional containerized environment, container restart and repair often lack effective security guarantees, which may lead to the introduction of potential vulnerabilities or the destruction of the trust in the container running environment. The embodiments of the present application introduce the TPM technology, combine dynamic container repair and trusted restart mechanisms to achieve the trusted restart and / or trusted repair of containers, and improve security and stability.

[0076] In some embodiments, based on the trusted platform module, perform trusted restart and / or trusted repair on the target container, including:

[0077] Step 1.1: Invoke the trusted platform module to verify the trustworthiness of the image corresponding to the target container. The trustworthiness reflects the integrity and non-tampering of the image.

[0078] TPM can provide a hardware-level trust foundation for the integrity and source of the container image, preventing the image from being tampered with or maliciously replaced. The container orchestration platform supports image signing and verification, and combined with the security functions provided by TPM, enhances the credibility of the image.

[0079] Exemplarily, when building the image of the target container, use the private key to digitally sign the image. The signature can ensure the integrity and trustworthiness of the source of the image. Store the private key used for signing in the TPM to protect it from being leaked or tampered with. When pulling and running the container image, use the public key to verify the signature of the image. The public key can be used in combination with the TPM to ensure that it has not been tampered with. The verification process includes calculating the hash value of the image and comparing it with the hash value in the signature. Only when they match is the running allowed. The signature usually includes the hash value of the image and other metadata.

[0080] Step 1.2: If the image is untrusted, repair or replace the image to obtain a trusted image; and based on the trusted image, restart the target container; or, based on the trusted image, recreate a new container to complete the trusted repair of the target container.

[0081] A trusted image can be regarded as an image that has been verified and signed, ensuring that it has not been tampered with and its source is trusted.

[0082] Exemplarily, configure security policies in the container orchestration platform to ensure that only signed and verified images can be deployed. When the container orchestration platform receives the message that the image is untrusted verified by the TPM, it stops the target container from starting, issues a security alert, and at the same time records the details of the untrusted image in the security log and isolates the untrusted image from the production environment. Relevant technical personnel conduct in-depth analysis to determine how the image was tampered with. Once the reasons and scope of the tampering are determined, based on the discovered security vulnerabilities and tampering methods, update the system's security policies and defense measures, and repair or completely replace the untrusted image. The entire process of obtaining a trusted image is carried out under the protection of the TPM to prevent the introduction of malicious software or tampered updates.

[0083] Furthermore, restart the target container using a verified trusted image. For cases where the running state of the target container cannot be restored through trusted restart, or the abnormal state of the target container is related to security or data integrity, a new container needs to be recreated based on the verified trusted image to thoroughly eliminate potential security threats. Moreover, when the container is created, it will undergo TPM verification of the startup environment to ensure that it has not been tampered with or injected with malware during startup.

[0084] Verify the credibility of the image of the target container through TPM to ensure that the version of the newly started target container has not been tampered with, thus maintaining the security and stability of the system.

[0085] Optionally, if the security vulnerabilities that occur do not involve underlying system or middleware vulnerabilities, hotfixes can be performed. Based on the rolling update function of the container orchestration platform, the old containers can be gradually replaced to avoid service interruption caused by a full restart of the containers.

[0086] Step 1.3: If the image is trusted, restart the target container based on the verified image; or, recreate a new container based on the verified image to complete the trusted repair of the target container.

[0087] See the relevant description in Step 1.2 and will not be elaborated here.

[0088] In the embodiments of the present application, by invoking the hardware security function of TPM to verify the integrity of the image, trusted automatic restart and trusted automatic repair of abnormal containers are performed to ensure that the image, container, and applications in the container during the repair process are verified as trusted, preventing the introduction of malware or tampered updates. It not only protects the integrity and source of the image but also provides a higher level of trust for the entire container ecosystem, significantly improving the security of containerized applications.

[0089] Compared with the related art that uses software-based Secure Boot technology and Trusted Execution Environment (TEE) to protect the integrity of the system on the power IoT gateway device, the embodiments of the present application have higher security through the hardware-level security protection of TPM, which is not limited by the vulnerabilities and security of the software itself.

[0090] In the containerized environment of the power Internet of Things gateway, each container often needs to perform network communication and access other services. To prevent potential cross-container attacks, in some embodiments, a software-defined network is deployed on the power Internet of Things gateway device. The software-defined network is used to allocate isolated network resources for the containers. The management method further includes: after creating a new container, invoking the trusted platform module to verify the trustworthiness of the new container; if the new container is trustworthy, based on the software-defined network, allocate isolated network resources to the new container, so that the new container performs network communication based on the allocated isolated network resources.

[0091] Among them, the software-defined network (Software Defined Network, abbreviated as SDN) can be used by the container orchestration platform to automatically optimize the network configuration between containers, dynamically create and manage isolated networks for containers, provide independent network environments for different services or applications in the power Internet of Things gateway system, and thus provide network-level security protection measures for the power Internet of Things gateway system.

[0092] After the container orchestration platform automatically creates a new container instance, first invoke the TPM to perform a trust verification on the new container instance to ensure the trustworthiness of the running environment and status of the new container. For example, through the remote attestation function of the TPM, verify the integrity and trustworthiness of the running environment of the new container. Protect the data and communication inside the container through the key storage and management function provided by the TPM.

[0093] Exemplarily, after the trustworthiness of the new container is verified, communicate with the SDN controller through the network plugin in the containerized orchestration platform, and invoke the SDN to achieve automated allocation of network resources, improving the manageability of the network. For example, dynamically allocate an IP address, configure routing, and set firewall rules, etc. for the new container.

[0094] Furthermore, to improve security, the SDN can be invoked to define and implement fine-grained network policies to control the communication between containers. The network policies can prevent unauthorized access and ensure the security of communication between containers. For example, it includes access control based on IP, port, protocol, etc.

[0095] Alternatively, network micro-segmentation can also be implemented. After dividing the network into smaller isolated units, then allocate them to the new containers. The new containers communicate based on the isolated network resources. The network micro-segmentation implemented by the SDN can limit the attack surface, prevent potential security vulnerabilities from spreading horizontally in the network, and reduce the impact range.

[0096] In the embodiments of the present application, TPM is used to verify whether each new container is a trusted container at startup. Meanwhile, combined with SDN, isolated network resources are dynamically allocated to provide trusted network layer support for communication between containers, ensuring that the communication between containers is not subject to external attacks and tampering, significantly improving the security and performance of containerized applications and services, and thus enhancing the security of the entire power IoT gateway. In addition, by using SDN to allocate isolated network resources for containers, not only is network management simplified, but also higher network control capabilities are provided.

[0097] Considering that traditional power IoT gateway systems lack an intelligent adjustment mechanism in resource management and energy conservation, most systems cannot dynamically adjust resource allocation according to the actual load, resulting in resource waste and excessive energy consumption.

[0098] In view of this, in some embodiments, the management method of the power IoT gateway further includes: monitoring the load status information of the power IoT gateway device by communicating with the power IoT gateway device; scheduling the container cluster corresponding to the power IoT gateway device according to the load status information.

[0099] Among them, the load status information is not limited to including CPU usage rate, memory usage rate, disk usage rate, network bandwidth, and I / O.

[0100] Exemplarily, the container orchestration platform communicates with the IoT gateway device through protocols such as Message Queuing Telemetry Transport (MQTT), CoAP (The Constrained Application Protocol), LoRa, Zigbee, Distributed Network Protocol 3 (DNP3), etc. A monitoring agent is deployed on the power IoT gateway device to collect load status information such as CPU, memory, network bandwidth, and I / O. The collected data is sent to the container orchestration platform through the above communication protocols. The container orchestration platform receives the load status information from each power IoT gateway device to achieve real-time monitoring on the container orchestration platform.

[0101] Furthermore, the container orchestration platform analyzes the received load data and dynamically manages and schedules the container cluster on the power IoT gateway device according to the analysis results. In some embodiments, scheduling the container cluster corresponding to the power IoT gateway device according to the load status information includes the following implementation methods:

[0102] One implementation method is to expand or reduce the scale of the container cluster according to the load status information.

[0103] For example, an Auto-scaling policy is set. For instance, thresholds are set based on predefined performance metrics (such as CPU utilization, memory usage, network traffic, etc.). When the metrics reach or exceed these thresholds, the auto-scaling mechanism triggers scaling operations (increasing or decreasing the number of container instances); or, machine learning and historical data analysis are used to predict future load changes, so as to perform resource scaling or reduction in advance. This method can better handle sudden traffic and reduce response time; or, an auto-expansion policy based on a hybrid strategy (for example, using a threshold-based policy for real-time adjustment, and at the same time using scheduled expansion to handle known peak periods).

[0104] Optionally, in practical applications, the step size and frequency of expansion and reduction can be defined, or a cooling time can be set to prevent frequent triggering of expansion or reduction operations in a short period of time.

[0105] In another implementation method, according to the load status information, the resource allocation of each container in the container cluster is adjusted. The resource allocation includes computing resource allocation, storage resource allocation, and network bandwidth allocation.

[0106] Among them, computing resources mainly include CPU and memory, storage resources mainly include storage volumes, network storage, temporary file systems, etc., and network bandwidth resources mainly include network bandwidth and traffic.

[0107] For example, appropriate resource requests and limits are set for each container, and the settings are dynamically adjusted in response to load changes. For example, when resources are scarce, the needs of the containers where critical applications or services are located are preferentially met. Or, to improve the response speed of applications on the power IoT gateway device (for example, application A includes services a, b, and c, service a is deployed on container a, service b is deployed on container b, and service c is deployed on container c), based on the idea of load balancing, network traffic is distributed to service instances a, b, and c to improve the availability and response speed of application A.

[0108] In yet another implementation method, according to the load status information, the scale of the container cluster is expanded or reduced, and the resource allocation of each container in the container cluster is adjusted. The resource allocation includes computing resource allocation, storage resource allocation, and network bandwidth allocation.

[0109] For example, when the load is low or idle, unnecessary containers can be shut down to reduce energy consumption, thereby extending the working life of the power IoT gateway device and reducing energy consumption. When the load is high, the expansion function is automatically triggered to deploy new containers to ensure that the number of containers adapts to the load and avoid over-allocation or waste of resources. After expanding or reducing the scale of the container cluster, in order to improve the availability and response speed of a certain application, the resource allocation of the containers corresponding to the application can be further adjusted.

[0110] Optionally, a feedback loop can also be established to continuously optimize the resource scheduling strategy based on the resource scheduling results and the performance feedback of the power IoT gateway system, regularly evaluate the effectiveness of the resource scheduling strategy, and adjust parameters to improve efficiency.

[0111] In the embodiments of this application, according to the load status information of the power IoT gateway device, the resource allocation is dynamically and automatically optimized, enabling the optimal allocation of resources, realizing intelligent resource management, while avoiding over-allocation or waste of resources, and achieving lower energy consumption. Additionally, the resource usage is optimized according to the workload to ensure high efficiency and energy conservation under different operating states, improve the energy efficiency of the power IoT gateway system, and reduce the long-term operating costs. Moreover, it ensures that the system can smoothly cope with the challenges of high concurrency and large data volumes.

[0112] Compared with the resource scheduling mechanism using a fixed strategy, that is, adjusting the resource allocation regularly according to the preset configuration instead of dynamically adjusting according to the real-time load (for example, a certain number of containers can be set to start fixedly during certain periods without considering the actual load situation), the resource scheduling mechanism with a fixed strategy is relatively simple but does not have the ability of intelligent and dynamic adjustment, cannot optimize the resource utilization rate according to the real-time load, may cause resource waste when the load is low, and cannot be expanded in time when the load is high. In the embodiments of this application, through the intelligent resource scheduling and energy-saving mechanism, the high-efficiency operation and energy-saving goals of the power IoT gateway can be better achieved.

[0113] In some embodiments, according to the load status information, scheduling the container cluster corresponding to the power IoT gateway device may further include: inputting the load status information into a pre-trained resource scheduling model to obtain a scheduling strategy corresponding to the load status information; and scheduling the container cluster corresponding to the power IoT gateway device according to the scheduling strategy.

[0114] Exemplarily, the resource scheduling model can be trained in the following way: select a suitable machine learning or deep learning model, such as decision tree, random forest, support vector machine (SVM), neural network, etc., collect historical load data and the corresponding resource usage as training samples, clean and extract features from the training samples for resource scheduling model training. The training samples can also be divided into a test set and a validation set, use the test set to train the resource scheduling model so that it can predict the best resource scheduling strategy under a given load status, use the validation set to evaluate the performance of the resource scheduling model, and adjust the model parameters to improve the accuracy.

[0115] Input the load status information collected in real time into the trained resource scheduling model, and the resource scheduling model outputs the corresponding resource scheduling strategy, including the number of containers to be scaled up or down, priority, computing resource allocation, storage resource allocation, network bandwidth allocation, etc. Based on the predicted resource scheduling strategy, the container orchestration platform performs automated scheduling on the container cluster corresponding to the power IoT gateway device.

[0116] In the embodiments of the present application, through the intelligent resource scheduling model, the accuracy of the scheduling strategy is improved, thereby enhancing the resource scheduling effect and being more adaptable to the large-scale and dynamically changing power IoT gateway application scenarios.

[0117] In some embodiments, the management method of the power IoT gateway further includes: monitoring the operating status of the power IoT gateway device; when a failure of the power IoT gateway device is detected, migrating the container corresponding to the power IoT gateway device to a normal power IoT gateway device.

[0118] Exemplarily, monitoring tools such as Prometheus, Zabbix, or Nagios are pre-deployed on the container orchestration platform to collect the operating status data of the power IoT gateway device in real time. Monitor key performance indicators such as CPU usage, memory usage, network latency, device temperature, and error logs, and determine whether the power IoT gateway device is faulty by monitoring the key performance indicators. When it is determined that the power IoT gateway device is faulty, based on the scheduling function of the container orchestration platform (such as Kubernetes, Apache Mesos), reschedule the containers on the faulty power IoT gateway device to the nodes (referring to the power IoT gateway devices) that are running normally.

[0119] Compared with the traditional power IoT gateway, its maintenance and update usually require manual intervention and often rely on relatively complex hardware and software system upgrade processes, lacking automation and remote management capabilities, resulting in high equipment maintenance and management costs. In the embodiments of the present application, the container orchestration platform automatically manages the monitoring of the power IoT gateway device, and can automatically migrate the containers on the power IoT gateway device to other nodes when a failure is detected, improving the availability of the system, reducing manual intervention, reducing the workload of operation and maintenance personnel, and improving the operation and maintenance efficiency.

[0120] In some embodiments, the container orchestration platform is Apache Mesos.

[0121] Apache Mesos is a powerful cluster manager that provides resource abstraction and isolation mechanisms, making it highly suitable for running distributed systems in large-scale clusters such as data centers or large-scale cloud environments. Compared to Kubernetes, Apache Mesos is designed to run various types of distributed systems, not just containers. The architecture of Apache Mesos allows users to run various applications including Hadoop, Spark, and Elasticsearch on the same physical resource pool. This ability makes Mesos particularly suitable for environments that need to manage multiple types of loads simultaneously. Apache Mesos also provides more fine-grained resource management capabilities. It can precisely allocate the number of CPU cores, memory, disk space, and other resources according to application requirements. This resource management makes Apache Mesos generally more efficient in resource utilization than Kubernetes. In addition, the architecture of Apache Mesos is highly modular, allowing developers to customize resource scheduling policies or extend existing functions. For scenarios that need to run multiple types of loads on the same platform and have more refined requirements for resource management, Apache Mesos provides unique advantages. The following are the steps for containerizing the power IoT gateway through Apache Mesos. It should be noted that for the sake of understanding, the following steps are only taken as an example:

[0122] 1. Environment Preparation

[0123] Ensure that Apache Mesos and Marathon are installed in the environment. There needs to be a running Mesos cluster, and Marathon also needs to be set as a framework for this cluster.

[0124] 2. Create Container Image

[0125] Write a Dockerfile to containerize the application on the gateway device. The Dockerfile should include the base image, dependency installation, environment variable setting, and startup command:

[0126] FROM ubuntu:20.04

[0127] RUN apt-get update && apt-get install -y nginx

[0128] COPY. / gateway-config / etc / nginx / sites-enabled / default

[0129] EXPOSE 80

[0130] CMD ["nginx", "-g", "daemon off;"]

[0131] Use the Docker build tool to create the gateway container image:

[0132] docker build -t yourregistry / gateway:latest.

[0133] Push the built image to the Docker image repository:

[0134] docker push yourregistry / gateway:latest

[0135] 3. Configure Marathon

[0136] Create a JSON file to define the configuration of the gateway service on Marathon:

[0137] {

[0138] "id": "gateway",

[0139] "container": {

[0140] "type": "DOCKER",

[0141] "docker": {

[0142] "image": "yourregistry / gateway:latest",

[0143] "network": "BRIDGE",

[0144] "portMappings": [{

[0145] "containerPort": 80,

[0146] "hostPort": 0,

[0147] "servicePort": 10000,

[0148] "protocol": "tcp"

[0149] }]

[0150] }

[0151] },

[0152] "instances": 3,

[0153] "cpus": 1,

[0154] "mem": 512,

[0155] "healthChecks": [{

[0156] "protocol": "HTTP",

[0157] "path": " / ",

[0158] "portIndex": 0,

[0159] "timeoutSeconds": 10,

[0160] "intervalSeconds": 10,

[0161] "maxConsecutiveFailures": 3

[0162] }]

[0163] }

[0164] This configuration file defines the service ID, the container image used, network settings, port mapping, number of instances, resource allocation, and health checks.

[0165] 4. Deploy to Marathon

[0166] Use Marathon's API or interface to deploy the gateway service:

[0167] curl -X POST -H "Content-Type: application / json" http: / / yourmarathonhost:8080 / v2 / apps -d@your_config_file.json

[0168] 5. Verify the deployment

[0169] Log in to Marathon's user interface, check the application status and health, and use the service address provided by the Marathon UI to access the gateway to ensure it is running properly.

[0170] Figure 3 This is the schematic diagram of the intelligent security management and energy-saving technology principle of the power IoT gateway provided by the embodiment of this application.

[0171] As Figure 3As shown in the figure, the intelligent security management and energy-saving technology solution of the power Internet of Things gateway includes a power Internet of Things gateway and a container orchestration platform. The power Internet of Things gateway and the container orchestration platform are communicatively connected. Among them, the power Internet of Things gateway (specifically referring to the power Internet of Things gateway device) integrates a trusted platform module TPM and deploys a software-defined network SDN. The trusted platform module is used to verify the trustworthiness and integrity of the environment (including containers and / or images). The software-defined network is used to control network traffic and isolate network intervals, allocate isolated network resources for containers, and ensure the security of communication between containers.

[0172] The container orchestration platform is used to execute the management method of the power Internet of Things gateway described in the above embodiments. The container orchestration platform includes a containerization module, an intelligent scheduling module, and a security control module. Among them:

[0173] The containerization module is used to perform containerized deployment of the power Internet of Things gateway based on containerization technology. Moreover, the containerization module can manage multiple independent containers, and different containers represent different functional services (such as data collection, device management, data processing, control, etc.). These containers are independent of each other and isolated from each other, but are uniformly managed through the container orchestration platform.

[0174] The intelligent scheduling module is used to allocate resources, adjust loads, and optimize energy conservation for the power Internet of Things gateway device. It mainly includes automatic scheduling of containers, monitoring, and managing the life cycle of containers, dynamically increasing or decreasing container instances, and adjusting resources according to system loads. Through the intelligent scheduling module, resources can be flexibly configured among containers, loads can be optimized, and power consumption can be dynamically adjusted.

[0175] The security control module is used to perform anomaly detection and security log recording on the power Internet of Things gateway device and the containers thereon, and perform trusted restart on the containers.

[0176] In summary, the present application has at least the following beneficial effects:

[0177] 1. Through containerized deployment, application and / or service isolation is achieved. Even if a certain container is attacked or damaged, the attack will not spread to other containers or affect the entire power IoT gateway system, reducing the risk of being attacked maliciously or threatened internally, and enhancing the security, reliability, and stability of the system. Containerization can also improve system scalability and hardware resource utilization, supporting the dynamic configuration and management of the power IoT gateway in different environments. Based on the security isolation capabilities of container technology, the container orchestration platform monitors the running status of containers. When a container is abnormal, automated security responses, trusted container restarts, and / or trusted repairs are performed based on TPM to quickly restore the trusted state of the container. On the basis of containerized deployment, hardware-level security protection measures are implemented using TPM to ensure that the running environment within the container is strictly controlled, further enhancing the security of the power IoT gateway system, significantly improving the system's anti-attack capabilities, and ensuring the secure and stable operation of the IoT gateway, especially suitable for environments with high reliability and high security requirements such as power IoT gateways.

[0178] 2. Use TPM to verify whether each new container is a trusted container at startup. At the same time, in combination with SDN, isolated network resources are dynamically allocated to provide trusted network layer support for communication between containers, ensuring that communication between containers is not subject to external attacks and tampering, significantly improving the security and performance of containerized applications and services, and thus enhancing the security of the entire power IoT gateway. In addition, by using SDN to allocate isolated network resources for containers, not only is network management simplified, but also higher network control capabilities are provided.

[0179] 3. Through the container orchestration platform, automated deployment and management of large-scale systems can be achieved, enabling rapid response to changes in business requirements, enhancing flexibility, reducing the complexity of system upgrades and maintenance, and at the same time reducing development and operation and maintenance costs. In addition, through the container orchestration platform, automated monitoring of power IoT gateway devices is managed, and when a fault is detected, the containers on the power IoT gateway device can be automatically migrated to other nodes, improving the availability of the system, reducing manual intervention, further reducing the workload of operation and maintenance personnel, and improving operation and maintenance efficiency.

[0180] 4. Dynamically and automatically optimize resource allocation to achieve optimal resource allocation, realize intelligent resource management, and at the same time avoid over-allocation or waste of resources, achieving lower energy consumption. In addition, optimize resource usage according to the workload to ensure high efficiency and energy conservation in different operating states, improve the energy efficiency of the power IoT gateway system, and reduce long-term operating costs. Also, ensure that the system can smoothly handle challenges of high concurrency and large data volumes.

[0181] Figure 4 This is the structural schematic diagram of the management device for the power IoT gateway provided by the embodiment of this application. As Figure 4As shown in the figure, the management device of the power Internet of Things gateway provided in this embodiment is applied to a container orchestration platform. The container orchestration platform is deployed on a server, and the server is communicatively connected to the power Internet of Things gateway device. Based on container technology, the container orchestration platform performs independent containerized deployment on services and / or applications on the power Internet of Things gateway device to obtain multiple containers;

[0182] The management device 40 of the power Internet of Things gateway includes a monitoring module 41 and a processing module 42. Among them:

[0183] The monitoring module 41 is used to monitor the running status of multiple containers;

[0184] The processing module 42 is used to, when it is detected that a target container among multiple containers is abnormal, based on a trusted platform module, perform a trusted restart and / or trusted repair on the target container. The trusted platform module is integrated on the power Internet of Things gateway device, and the trusted platform module is used to provide a trusted execution environment for the container.

[0185] In a possible implementation manner, the processing module 42 is specifically used to: call the trusted platform module to verify the trustworthiness of the image corresponding to the target container, where the trustworthiness reflects the integrity and non-tampering of the image; if the image is untrusted, repair or replace the image to obtain a trusted image; and based on the trusted image, restart the target container; or, based on the trusted image, recreate a new container to complete the trusted repair of the target container; if the image is trusted, based on the verified image, restart the target container; or, based on the verified image, recreate a new container to complete the trusted repair of the target container.

[0186] In a possible implementation manner, a software-defined network is deployed on the power Internet of Things gateway device. The software-defined network is used to allocate isolated network resources for the container. The processing module 42 is further used to: after creating a new container, call the trusted platform module to verify the trustworthiness of the new container; if the new container is trusted, based on the software-defined network, allocate isolated network resources to the new container, so that the new container performs network communication based on the allocated isolated network resources.

[0187] In a possible implementation manner, the monitoring module 41 is further used to: monitor the load status information of the power Internet of Things gateway device by communicating with the power Internet of Things gateway device; and schedule the container cluster corresponding to the power Internet of Things gateway device according to the load status information.

[0188] In a possible implementation manner, the monitoring module 41 is specifically used to: expand or reduce the scale of the container cluster according to the load status information; and / or adjust the resource allocation of each container in the container cluster according to the load status information, where the resource allocation includes computing resource allocation, storage resource allocation, and network bandwidth allocation.

[0189] In a possible implementation, the monitoring module 41 is further configured to: input the load status information into a pre-trained resource scheduling model to obtain a scheduling policy corresponding to the load status information; and schedule the container cluster corresponding to the power Internet of Things gateway device according to the scheduling policy.

[0190] In a possible implementation, the monitoring module 41 is further configured to: monitor the operating status of the power Internet of Things gateway device; and when a failure of the power Internet of Things gateway device is detected, migrate the container corresponding to the power Internet of Things gateway device to a normal power Internet of Things gateway device.

[0191] In a possible implementation, the container orchestration platform is Apache Mesos.

[0192] The management device of the power Internet of Things gateway provided in this embodiment can execute the method provided in the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0193] Figure 5 The following is a schematic structural diagram of the server provided in the embodiment of the present application. As Figure 5 shown, the server 50 provided in this embodiment includes: at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. Among them, the processor 501, the memory 502, and the communication component 503 are connected through a bus 504.

[0194] In a specific implementation process, at least one processor 501 executes the computer execution instructions stored in the memory 502, so that at least one processor 501 executes the above method.

[0195] The specific implementation process of the processor 501 can be referred to in the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0196] In the above embodiment, it should be understood that the processor may be a central processing unit (English: Central Processing Unit, abbreviated as: CPU), and may also be other general-purpose processors, digital signal processors (English: Digital Signal Processor, abbreviated as: DSP), application specific integrated circuits (English: Application Specific Integrated Circuit, abbreviated as: ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly embodied as being executed and completed by a hardware processor, or executed and completed by a combination of hardware and software modules in the processor.

[0197] The memory may include a random access memory (RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.

[0198] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.

[0199] The embodiments of the present application also provide a computer program product, including a computer program, which implements the above method when executed by a processor.

[0200] The embodiments of the present application also provide a computer-readable storage medium, in which computer-executable instructions are stored, and when the processor executes the computer-executable instructions, the above method is implemented.

[0201] The above-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.

[0202] An exemplary readable storage medium is coupled to the processor, so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.

[0203] The division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed among each other can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0204] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0205] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0206] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. And the aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks or optical disks and other various media that can store program codes.

[0207] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When this program is executed, it executes the steps including the above method embodiments; and the aforementioned storage medium includes: ROM, RAM, magnetic disks or optical disks and other various media that can store program codes.

[0208] Finally, it should be noted that those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention, which follow the general principles of the present invention and include known common knowledge or conventional technical means in the technical field not disclosed in the present invention. It is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.

Claims

1. A management method for an electric power Internet of Things gateway, characterized in that Applied to a container orchestration platform, which is deployed on a server. The server is communicatively connected to a power Internet of Things gateway device. The container orchestration platform, based on container technology, independently performs containerized deployment on services and / or applications on the power Internet of Things gateway device to obtain multiple containers; The management method includes: Monitoring the running status of the multiple containers; When it is detected that a target container among the multiple containers is abnormal, based on a trusted platform module integrated on the power Internet of Things gateway device, which is used to provide a trusted execution environment for the container, perform trusted restart and / or trusted repair on the target container; 2. The management method of the power Internet of Things gateway according to claim 1, characterized in that The performing trusted restart and / or trusted repair on the target container based on the trusted platform module includes: Invoking the trusted platform module to verify the trustworthiness of the image corresponding to the target container, where the trustworthiness reflects the integrity and non-tampering of the image; If the image is untrusted, repair or replace the image to obtain a trusted image; and based on the trusted image, restart the target container; or, based on the trusted image, recreate a new container to complete the trusted repair of the target container; If the image is trusted, based on the verified image, restart the target container; or, based on the verified image, recreate a new container to complete the trusted repair of the target container; 3. The management method of the power Internet of Things gateway according to claim 2, characterized in that, A software-defined network is deployed on the power Internet of Things gateway device, which is used to allocate isolated network resources for the containers. The management method further includes: After creating a new container, invoking the trusted platform module to verify the trustworthiness of the new container; If the new container is trusted, based on the software-defined network, allocate isolated network resources to the new container, so that the new container performs network communication based on the allocated isolated network resources.

4. The management method of the power Internet of Things gateway according to any one of claims 1 to 3, characterized in that It further includes: Monitoring the load status information of the power Internet of Things gateway device by communicating with the power Internet of Things gateway device; Scheduling the container cluster corresponding to the power Internet of Things gateway device according to the load status information.

5. The management method of the power Internet of Things gateway according to claim 4, characterized in that The scheduling the container cluster corresponding to the power Internet of Things gateway device according to the load status information includes: Expanding or reducing the scale of the container cluster according to the load status information; And / or, adjusting the resource allocation of each container in the container cluster according to the load status information, where the resource allocation includes computing resource allocation, storage resource allocation, and network bandwidth allocation.

6. The management method of the power IoT gateway according to claim 4, characterized in that The scheduling the container cluster corresponding to the power Internet of Things gateway device according to the load status information includes: Inputting the load status information into a pre-trained resource scheduling model to obtain a scheduling policy corresponding to the load status information; Scheduling the container cluster corresponding to the power Internet of Things gateway device according to the scheduling policy.

7. The management method of the power Internet of Things gateway according to any one of claims 1 to 3, characterized in that, It further includes: Monitoring the running status of the power Internet of Things gateway device; When it is detected that the power Internet of Things gateway device fails, migrating the containers corresponding to the power Internet of Things gateway device to a normal power Internet of Things gateway device.

8. The management method of the power Internet of Things gateway according to any one of claims 1 to 3, characterized in that, The container orchestration platform is Apache Mesos.

9. A management device for an electric power Internet of Things gateway, characterized in that, Applied to a container orchestration platform, the container orchestration platform is deployed on a server, the server is communicatively connected to a power Internet of Things gateway device, and the container orchestration platform, based on container technology, performs independent containerized deployment on services and / or applications on the power Internet of Things gateway device to obtain a plurality of containers; The management device includes: A monitoring module, configured to monitor the running status of the plurality of containers; A processing module, configured to, when an abnormal target container is detected among the plurality of containers, perform a trusted restart and / or trusted repair on the target container based on a trusted platform module, the trusted platform module being integrated on the power Internet of Things gateway device, and the trusted platform module being used to provide a trusted execution environment for the containers.

10. A server, characterized in that, Comprising: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed, they are used to implement the method according to any one of claims 1 to 8.