Secret marking method, device and equipment for high-performance computing management platform
By receiving resource access requests in the high-performance computing management platform, obtaining the confidentiality of users and resources and matching them, the shortcomings of information resource access security are solved, and the system's security and permission verification efficiency are improved.
Patent Information
- Application Number
- CN202510435788.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-22
AI Technical Summary
The existing high-performance computing management platform has shortcomings in the security of information resource access, which has affected the system security.
By receiving resource access requests, obtain the confidentiality of users and resources, and allow access in the case of matching. Otherwise, access is denied, combined with the confidentiality of jobs and files, dynamically adjust user permissions to ensure the legitimacy of access permissions.
It improves the security of high-performance computing systems, reduces the risk of information resource leakage, and improves the efficiency and security of access permission verification.
Smart Images

Figure CN120354431A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a classified encryption method, device, and equipment for a high-performance computing management platform. Background Art
[0002] In existing HPC (High Performance Computing) management platforms, job schedulers are usually used to manage the submission, scheduling, and execution of jobs in a high-performance computing system. At the same time, the file system can be used to manage the storage and access of data in the high-performance computing system.
[0003] However, although high-performance computing management platforms perform well in resource allocation and task scheduling, they have obvious deficiencies in the access security of information resources (such as data, files, and jobs), thus affecting the security of high-performance computing systems. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a classified encryption method, device, computer equipment, computer-readable storage medium, and computer program product for a high-performance computing management platform that can improve the security of high-performance computing systems.
[0005] On the one hand, this application provides a classified encryption method for a high-performance computing management platform, including: receiving a resource access request for a target information resource, where the target user account is carried in the resource access request; the target information resource is an information resource in a high-performance computing system; obtaining the target user classification level set for the target user account, and obtaining the target resource classification level set for the target information resource; returning the access result of the target information resource when the target user classification level matches the target resource classification level; where the matching of the target user classification level and the target resource classification level is a condition that the target user account needs to meet to access the target information resource; returning a denied access prompt message when the target user classification level does not match the target resource classification level, and the denied access prompt message is used to prompt that the access permission for the target information resource is not available.
[0006] In this embodiment, a resource access request for a target information resource is received. The resource access request carries a target user account. The target information resource is an information resource in a high-performance computing system. The target user level set for the target user account is obtained, and the target resource level set for the target information resource is obtained. The matching of the target user level and the target resource level is a condition required for the target user account to access the target resource. When the target user level matches the target resource level, the access result of the target information resource is returned. When the target user level does not match the target resource level, a denied access prompt message is returned, which is used to prompt that the access permission for the target information resource is not available. Thus, when the target user account has the permission to access the target information resource, the access result of the target information resource is returned, which can reduce the risk of information resource leakage in the high-performance computing system and improve the security of the high-performance computing system.
[0007] In some embodiments, the returning the access result of the target information resource when the target user level matches the target resource level includes: determining a resource level set corresponding to the target user level, where a user account with the target user level has the permission to access information resources with resource levels in the resource level set; when the resource level set includes the target resource level, returning the access result of the target information resource.
[0008] In this embodiment, since the target user level corresponds to a resource level set, and a user account with the target user level has the permission to access information resources with resource levels in the resource level set, it is possible to conveniently and quickly verify whether the target user account has the permission to access the target resource through the resource level set, improving the efficiency of verifying access permissions.
[0009] In some embodiments, the target user account belongs to a general account, and the method further includes: when the target user level is downgraded from a first user level to a second user level, determining the file levels of the files owned by the target user account; when the second user level does not match the file level, updating the owner of the text from the target user account to a management account and modifying the access permission of the file to be accessible only by the management account.
[0010] In this embodiment, when the user level is downgraded so that the user has no right to access the file, the owner of the file is updated to the management account and the access permission of the file is modified to be accessible only by the management account, achieving the effect of dynamically adjusting the user access permission, thereby protecting the security of the file.
[0011] In some embodiments, the method further includes: receiving a job submission script submitted by a user terminal, where the job submission script includes a first job; querying a job classification field from the job submission script, and a value of the job classification field is used to determine a job classification of the first job; in case of querying, verifying the value of the job classification field, and in case of successful verification, notifying the user terminal that the submission is successful; in case of not querying or the verification of the value of the job classification field fails, notifying the user terminal that the submission fails.
[0012] In this embodiment, the job classification set for the job can be obtained through the job classification field, and in case of the job classification being valid (i.e., successful verification), the user is notified that the submission is successful, otherwise, the submission failure is notified, so that it can be ensured that the job is successfully submitted only when the job classification is correctly set.
[0013] In some embodiments, the querying and verification are implemented by a scheduling service by executing a job classification detection script. Before receiving the job submission script submitted by the user terminal, the method further includes: receiving a configuration item addition request for a configuration file of the scheduling service sent by an administrator terminal, where the configuration item addition request includes a path configuration item, and the path configuration item is used to set a storage path of the job classification detection script; in response to the configuration item addition request, adding the path configuration item to the configuration file.
[0014] In this embodiment, by adding a path configuration item to the configuration file of the scheduling service, the storage path of the job classification detection script can be set in the configuration file, so that the scheduling service can access the job classification detection script according to the storage path and execute the job classification detection script, improving the convenience and efficiency of the scheduling service in executing the job classification detection script.
[0015] In some embodiments, the method further includes: receiving a job submission request triggered through a job submission page, where the job submission request carries a second job, a preset field, and a value of the preset field, and the value of the preset field represents a job classification set for the second job through the job submission page; finding the preset field from the job submission request, and obtaining the value of the preset field, and generating job description information of the second job based on the job classification represented by the value of the preset field; storing the job description information of the second job in a database, and the job description information includes the job classification represented by the value of the preset field.
[0016] In this embodiment, in the scenario of submitting jobs through a page, a preset field is used to record the job confidentiality level set for the job through the page. By reading the value of this preset field in the job submission request, the job confidentiality level can be determined, which improves the efficiency of obtaining the job confidentiality level. Storing the job description information containing the job confidentiality level in the database helps to read the job confidentiality level from the database.
[0017] In some embodiments, the method further includes: receiving a file upload request triggered by a file upload page, where the file upload request carries a file and the file confidentiality level of the file, and the file confidentiality level is set based on the file upload page; in response to the file upload request, recording the file confidentiality level of the file into the extended attributes of the file.
[0018] In this embodiment, since the file confidentiality level can be set through the page, the convenience and efficiency of setting the file confidentiality level are improved. Recording the file confidentiality level into the extended attributes of the file helps to read the file confidentiality level of the file, improving the convenience and efficiency of obtaining the file confidentiality level.
[0019] In some embodiments, the method further includes: periodically detecting the file confidentiality level of a target file under the target user account, where the target file is a file uploaded, created, or modified within a preset duration before the current time; in the case where the file confidentiality level of the target file is not detected, sending a confidentiality level setting notification to the user terminal corresponding to the target user account.
[0020] In this embodiment, by periodically detecting the file confidentiality level of a file and sending a confidentiality level setting notification in the case where the file confidentiality level is not detected, the user can be reminded to set the file confidentiality level in a timely manner, improving the access security of the file.
[0021] On the other hand, the present application also provides a classified secrecy device for a high-performance computing management platform, including: a request receiving module, configured to receive a resource access request for a target information resource, where the resource access request carries a target user account; the target information resource is an information resource in a high-performance computing system; a confidentiality level obtaining module, configured to obtain a target user confidentiality level set for the target user account and obtain a target resource confidentiality level set for the target information resource; an access result returning module, configured to return an access result of the target information resource in the case where the target user confidentiality level matches the target resource confidentiality level; where the matching of the target user confidentiality level and the target resource confidentiality level is a condition required for the target user account to access the target information resource; an access rejection module, configured to return a rejection access prompt message in the case where the target user confidentiality level does not match the target resource confidentiality level, and the rejection access prompt message is used to prompt that the access permission for the target information resource is not available.
[0022] On the other hand, the present application also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps in the above-mentioned classified encryption method for a high-performance computing management platform are implemented.
[0023] On the other hand, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned classified encryption method for a high-performance computing management platform are implemented.
[0024] On the other hand, the present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps in the above-mentioned classified encryption method for a high-performance computing management platform are implemented.
[0025] The above-mentioned classified encryption method, device, computer device, computer-readable storage medium and computer program product for a high-performance computing management platform receive a resource access request for a target information resource. The resource access request carries a target user account. The target information resource is an information resource in a high-performance computing system. Obtain the target user classification level set for the target user account, and obtain the target resource classification level set for the target information resource. The target user classification level matches the target resource classification level, which is a condition required for the target user account to access the target resource. When the target user classification level matches the target resource classification level, return the access result of the target information resource. When the target user classification level does not match the target resource classification level, a denied access prompt message is returned. The denied access prompt message is used to prompt that the access permission for the target information resource is not available. Thus, when the target user account has the permission to access the target information resource, the access result of the target information resource is returned, which can reduce the risk of information resource leakage in the high-performance computing system and improve the security of the high-performance computing system. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0027] Figure 1 It is an application environment diagram of the classified encryption method for a high-performance computing management platform in an embodiment;
[0028] Figure 2 It is a flowchart of the classified encryption method for a high-performance computing management platform in an embodiment;
[0029] Figure 3 Schematic diagram of the process for determining user permissions according to user confidentiality levels in an embodiment
[0030] Figure 4 Schematic diagram of the process for accessing resources in an embodiment
[0031] Figure 5 Schematic diagram of the process for handling after user confidentiality level downgrade in an embodiment
[0032] Figure 6 Schematic diagram of the process from submitting a job to executing a job in an embodiment
[0033] Figure 7 Schematic diagram of the process for handling a job submission request in an embodiment
[0034] Figure 8 Schematic diagram of the process for handling the confidentiality level of an uploaded file in an embodiment
[0035] Figure 9 Schematic diagram of the process for detecting the confidentiality level of a file in an embodiment
[0036] Figure 10 Schematic diagram of the process for handling the confidentiality level of a file in an embodiment
[0037] Figure 11 Schematic diagram of the process for the confidentiality marking method for a high-performance computing management platform in another embodiment
[0038] Figure 12 Structure block diagram of the confidentiality marking device for a high-performance computing management platform in an embodiment
[0039] Figure 13 Internal structure diagram of a computer device in an embodiment Detailed implementation manners
[0040] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0041] The confidentiality marking method for a high-performance computing management platform provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. The application environment includes a user terminal, an administrator terminal, a server, and computing nodes. The user terminal is the terminal of an ordinary user, and the administrator terminal is the terminal of an administrator. Ordinary users are not administrators. The user terminal can communicate with the server through SSH (Secure Shell) or a remote access protocol. The server provides a job submission interface, and the server is the server where the HPC (High Performance Computing) management platform is located. The high-performance computing management platform is a software system for managing and scheduling high-performance computing resources, aiming to optimize the execution efficiency of computing tasks, providing resource monitoring, task scheduling, user management, and data management functions to ensure the efficient utilization of computing resources and the sequential completion of tasks. The computing node is a node of the high-performance computing system.
[0042] The user terminal interacts with the HPC management platform deployed on the server through the client tool of the HPC management platform (such as submitting jobs, querying job status, canceling jobs, creating or uploading files, downloading files). The user terminal can submit jobs to the server through the client tool, and the server can allocate the jobs to the computing nodes for the computing nodes to execute the jobs. The client tool can be but is not limited to the Slurm (Simple Linux Utility for Resource Management) client.
[0043] Among them, a job is a computing task, including the program to be executed and related resource requests. Files are used to store programs, data, etc. The management methods of jobs and files are different. Jobs are managed through a job scheduling system, including submission, queuing, or execution, etc. Files are managed through a file system, including operations such as creation, reading, modification, or deletion.
[0044] To protect the security of information resources such as files or jobs, in this application, the user terminal sends a resource access request for a target information resource to the server. The target information resource is an information resource in the high-performance computing system, and the target user account is carried in the resource access request. In response to the resource access request, the server obtains the target user confidentiality level set for the target user account and obtains the target resource confidentiality level set for the target information resource. When the target user confidentiality level matches the target resource confidentiality level, the server returns the access result of the target information resource to the user terminal; the matching of the target user confidentiality level and the target resource confidentiality level is the condition required for the target user account to access the target information resource. When the target user confidentiality level does not match the target resource confidentiality level, the server returns a denied access prompt message to the user terminal. Among them, the denied access prompt message is used to prompt that the access permission for the target information resource is not available.
[0045] Among them, the computing node can be a terminal node or a server node. The terminal can be, but is not limited to, a desktop computer, a laptop computer, a smart phone, a tablet computer, an Internet of Things device, and a portable wearable device. The Internet of Things device can be a smart speaker, a smart TV, a smart air conditioner, a smart vehicle-mounted device, a projection device, etc. The portable wearable device can be a smart watch, a smart bracelet, a head-mounted device, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The server can be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services. The cloud server is used to provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The nodes can be directly or indirectly connected through wired or wireless communication methods, which are not limited in this application.
[0046] In some embodiments, as Figure 2 shown, a classified secrecy method for a high-performance computing management platform is provided. Taking the method applied to the Figure 1 server in it as an example, the following steps 202 to 206 are included. Among them:
[0047] Step 202, receive a resource access request for a target information resource, where the target user account is carried in the resource access request; the target information resource is an information resource in the high-performance computing system.
[0048] Among them, the information resource can be a resource containing any information. The information resource can be, but is not limited to, at least one of a job, a file, or page content, etc. The target information resource can be any information resource. The server can be a Linux server. The resource access request can be triggered and sent through a page or a command line. For example, a shell command line can be used to trigger and send the resource access request. The server can be a Linux server.
[0049] Specifically, when the target information resource is a file, the resource access request can be a request to download the file or open the file. When the target information resource is a job list, the resource access request can be a request to view the job list. When the target information resource is a page resource, the resource access request can be a request to obtain the page resource. The page resource can be, but is not limited to, at least one of a file list or job details, etc.
[0050] Step 204: Obtain the target user security level set for the target user account, and obtain the target resource security level set for the target information resource.
[0051] Among them, the user security level characterizes the information resources that the user account has the right to access. The user security level can be divided into multiple levels, such as core, important, and general, etc. Information resources have a resource security level, and the resource security level can be divided into multiple levels, such as confidential, secret, internal, and public, etc. The user security level determines the scope of permissions of the user account in the system or platform, that is, it is used to determine the information resources that the user account has the right to access. The resource security level is used to clarify the user accounts that can access the resource. For example, if the user security level is core, then access to confidential, secret, internal, and public resources is allowed; if the user security level is important, then access to secret, internal, and public resources is allowed; if the user security level is general, then access to internal and public resources is allowed. The user can be understood as the subject in the HPC management platform, and the information resource can be understood as the object in the HPC management platform.
[0052] In some embodiments, as Figure 3 shown, during the process of registering or creating a user account, the administrator of the system (high-performance computing system) can assign a user security level to the user account according to information such as the user's identity or responsibilities, and determine the user permissions according to the user security level, that is, determine the resource security level of the information resources that the user account has the right to access.
[0053] In some embodiments, the user security level can be stored in the server, or can be stored in the database. The information resource can be stored in the server, or can exist in the database. The server can obtain the target user security level and the target resource security level from the local or the database.
[0054] Step 206: When the target user security level matches the target resource security level, return the access result of the target information resource; among them, the matching of the target user security level and the target resource security level is the condition that the target user account needs to meet to access the target information resource.
[0055] Among them, the access result includes the relevant information of the target information resource.
[0056] Specifically, the server can determine the set of user security levels corresponding to the target resource security level. Among them, the condition for the user account to access the target resource is that the user account has any one of the user security levels in the set of user security levels. When the set of user security levels contains the target user security level, it is determined that the access permission verification is passed, and the access result of the target resource is returned.
[0057] In some embodiments, the target information resource is a target list, which contains multiple list elements. Each list element can represent a file or a job. For example, the target list can be a job list or a file list. The server can obtain the security level corresponding to each list element in the target list. The security level corresponding to a list element is the security level of the file or job represented by that list element. The server can separately match the target user security level with the security level corresponding to each list element. If there is a list element whose security level matches the target user security level, an access result of the target information resource is generated, and the access result contains the list element whose security level matches the target user security level.
[0058] Step 208, in the case where the target user security level does not match the target resource security level, return a denied access prompt message, which is used to prompt that the access permission for the target information resource is not available.
[0059] Specifically, in the case where the resource access request is triggered through a page, the user terminal receives the denied access prompt message returned by the server and can display the denied access prompt message in the form of a pop-up window.
[0060] In some embodiments, in the case where the resource access request is triggered through a command-line interface, the user terminal receives the denied access prompt message returned by the server and can display the denied access prompt message in the command-line interface.
[0061] In the above method for marking security levels for a high-performance computing management platform, a resource access request for a target information resource is received. The resource access request carries a target user account. The target information resource is an information resource in a high-performance computing system. The target user security level set for the target user account is obtained, and the target resource security level set for the target information resource is obtained. The matching of the target user security level and the target resource security level is a condition required for the target user account to access the target resource. In the case where the target user security level matches the target resource security level, the access result of the target information resource is returned. In the case where the target user security level does not match the target resource security level, a denied access prompt message is returned, which is used to prompt that the access permission for the target information resource is not available. Thus, the access result of the target information resource is returned only when the target user account has the permission to access the target information resource, which can reduce the risk of information resource leakage in the high-performance computing system and improve the security of the high-performance computing system.
[0062] In some embodiments, when the target user security level matches the target resource security level, the access result of the target information resource is returned, including: determining the set of resource security levels corresponding to the target user security level, where a user account with the target user security level has the right to access information resources with the resource security levels in the set of resource security levels; when the set of resource security levels includes the target resource security level, the access result of the target information resource is returned.
[0063] Among them, the set of resource security levels corresponding to the target user security level can be pre-stored in a database or a server. The correspondence between user security levels and sets of resource security levels can be pre-stored in the database or the server, and different user security levels correspond to different sets of resource security levels. The server can query the set of resource security levels corresponding to the target user security level from local or the database.
[0064] Specifically, a user account with the target user security level has no right to access information resources with other resource security levels outside the set of resource security levels. Other resource security levels refer to resource security levels not included in the set of resource security levels corresponding to the target user security level. When the set of resource security levels corresponding to the target user account includes the target resource security level, it indicates that the target user account has the right to access the target resource. Since the target user account may need to meet other conditions to access the target resource, it can be understood that: the set of resource security levels including the target resource security level is one of the conditions that the target user account needs to meet to access the target resource.
[0065] In some embodiments, if the target information resource is a file and the resource access request is a file download request, the access result may include the file to be downloaded. If the target information resource is job details and the resource access request is a view request, the access result may include the job details to be queried. If the target information resource is a file list or a job list and the resource access request is a view request, the access result may include the list elements in the file list or the job list that the target user account has the right to access.
[0066] For example, Figure 4 in (a) of, the server receives a file download request for a text sent by the user terminal, determines whether the file security level of the file matches the user security level of the target user account (i.e., the target user security level). If it matches, the server allows the file to be downloaded. If it does not match, the server refuses to download and returns a prompt message for indicating insufficient permissions to the user terminal. Among them, the file download request can be triggered and sent through a page displayed on the user terminal (such as a page provided by the high-performance management system).
[0067] For another example, Figure 4In (b), the server receives a page resource viewing request sent by the user terminal for a page resource, and determines whether the resource confidentiality level of the page resource matches the user confidentiality level of the target user account (i.e., the target user confidentiality level). If they match, the server allows viewing of the page resource; if not, the server refuses to view and returns a prompt message for insufficient permissions to the user terminal. Among them, the page resource viewing request can be triggered and sent through a page displayed on the user terminal (such as a page provided by the high-performance management system), and the page resource is a resource in the page provided by the high-performance management system.
[0068] For another example, Figure 4 In (c), the server receives a job list viewing request sent by the user terminal for a job list. The server queries for jobs that meet the requirements based on the target user confidentiality level and returns the job list, so that the user can conveniently view the jobs to which they have access permissions. Among them, the "jobs that meet the requirements" refer to jobs whose job confidentiality level matches the target user confidentiality level.
[0069] In this embodiment, since the target user confidentiality level corresponds to a set of resource confidentiality levels, and a user account with the target user confidentiality level has the right to access information resources with the resource confidentiality levels in the set of resource confidentiality levels, it is possible to conveniently and quickly verify whether the target user account has the right to access the target resource through the set of resource confidentiality levels, improving the efficiency of verifying access permissions.
[0070] In some embodiments, the target user account belongs to a common account, and the method further includes: when the target user confidentiality level is lowered from the first user confidentiality level to the second user confidentiality level, determining the file confidentiality level of the files owned by the target user account; when the second user confidentiality level does not match the file confidentiality level, updating the owner of the text from the target user account to the management account and modifying the access permission of the file to be accessible only by the management account.
[0071] Among them, the common account and the management account are two accounts with different permissions in the Linux system. The permission of the management account is higher than that of the common account. The management account is, for example, the superuser account, i.e., the root account. The level of the first user confidentiality level is higher than that of the second user confidentiality level. For example, the first user confidentiality level is "core" and the second user confidentiality level is "important". The management account has the permission to access information resources with any resource confidentiality level.
[0072] Specifically, the server can determine the set of user security levels corresponding to the file security level, and the set of user security levels contains at least one user security level. Only when the user account has any one of the user security levels in the set of user security levels does it have the permission to access the file. The server can determine whether there is a second user security level in the set of user security levels. If the set of user security levels contains the second user security level, it is determined that the second user security level matches the file security level; otherwise, it is determined that the second user security level does not match the file security level.
[0073] In some embodiments, when the target user security level is upgraded from the first user security level to the third user security level, there is no need to change the file security level and the owner of the files owned by the target user account. Among them, the level of the first user security level is lower than that of the third user security level. For example, the first user security level is "general", and the third user security level is "core" or "important".
[0074] As Figure 5 shown, in the case of downgrading the user security level, the server can scan all the files under the user account. For the files whose file security levels do not match the user security level, the owners of the non-matching files are changed to the management account to prohibit the user from accessing.
[0075] In this embodiment, when the downgrading of the user security level results in the user losing the right to access the file, the owner of the file is updated to the management account and the access permission of the file is modified to be accessible only by the management account, achieving the effect of dynamically adjusting the user access permission, thereby protecting the security of the file.
[0076] In some embodiments, the method further includes: receiving a job submission script submitted by the user terminal, where the job submission script contains a first job; querying a job security level field from the job submission script, and the value of the job security level field is used to determine the job security level of the first job; in the case of querying, verifying the value of the job security level field, and in the case of successful verification, notifying the user terminal that the submission is successful; in the case of not querying or the verification of the value of the job security level field fails, notifying the user terminal that the submission fails.
[0077] Among them, the job submission script is a script used to submit jobs. In the job submission script, the job is the content that needs to be executed, and the job can include a series of instructions. The job confidentiality level field can be a pre-set field. For example, it can be the SECURITY_LEVEL field. By writing the job confidentiality level field in the job submission script and setting the value of the job confidentiality level field, the confidentiality level of the job can be set. The job is pre-set with multiple different confidentiality levels, and "multiple" means at least two. The confidentiality level refers to the level of confidentiality, and different confidentiality levels represent different confidentiality levels. For example, the confidentiality levels of jobs are divided into public, internal, secret, and confidential. Different confidentiality levels correspond to different values. For example, the value corresponding to public is 1, the value corresponding to internal is 2, the value corresponding to secret is 3, and the value corresponding to confidential is 4. The value of the job confidentiality level field can be set to the value corresponding to any confidentiality level of the job, so that the value of the job confidentiality level field represents the confidentiality level of the job.
[0078] For example, the job submission script can include the following content:
[0079] #! / bin / bash
[0080] #SBATCH --job-name=test_job
[0081] #SECURITY_LEVEL=2
[0082] Among them, the format of the job confidentiality level field is: #SECURITY_LEVEL=x, where the value range of x is 1, 2, 3, 4. #! / bin / bash is used to specify that the script is executed using the Bash interpreter. #SBATCH --job-name=test_job is used to set the name of the job to test_job, and the name of the job can be displayed in the job queue (viewed through the squeue command), which is convenient for users to identify their own jobs.
[0083] Specifically, the job submission script can be generated and submitted through the command line. For example, the user terminal can display a command line interface, through which the job submission script can be written and submitted, and the value of the job confidentiality level field can be set during the process of writing the job submission script.
[0084] In some embodiments, when the server queries the job confidentiality level field, it can obtain the value of the job confidentiality level field from the job submission script, and compare the value of the job confidentiality level field with the value corresponding to the confidentiality level of the job. When it is determined that the value of the job confidentiality level field is consistent with the value corresponding to any confidentiality level of the job, it is determined that the verification is successful. When it is determined that the value of the job confidentiality level field is not consistent with the value corresponding to each confidentiality level of the job, it is determined that the verification fails.
[0085] In some embodiments, when the verification is successful, the server may return a prompt message indicating successful submission to the user terminal.
[0086] In some embodiments, when the job security level field is not found, the server may return an error message indicating the lack of the job security level field to the user terminal.
[0087] In some embodiments, when the value verification of the job security level field fails, the server may return an error message to the user terminal indicating that the job security level field is invalid. Here, the invalidity of the job security level field means that the value set for the job security level field is inconsistent with each value corresponding to the security level of the job.
[0088] In some embodiments, a job security level detection script may be pre - deployed in the server, and the server may execute the job security level detection script to query and verify the job security level field from the job submission script through the job security level detection script.
[0089] Among them, the job security level detection script may be, but is not limited to, a Lua script. Lua is a lightweight, multi - paradigm programming language designed to be embedded in other applications to provide flexible extension and customization functions for these applications. For example, if the job security level detection script is the job_submit.lua script and the job security level field is SECURITY_LEVEL, the job_submit.lua script may include the following content:
[0090] {function job_submit(job_desc, part_list, submit_uid)
[0091] -- Get the path of the submitted script
[0092] local script_path = job_desc.script
[0093] -- Open and read the script content
[0094] local file = io.open(script_path, "r")
[0095] if not file then
[0096] slurm.log_user("Unable to read script: %s", script_path)
[0097] return slurm.ERROR
[0098] end
[0099] local content = file:read("*all")
[0100] file:close()
[0101] -- Find the security level field (e.g., #SECURITY_LEVEL=1)
[0102] local security_level = content:match("#SECURITY_LEVEL=(%d)")
[0103] if security_level then
[0104] -- Convert to numeric type
[0105] security_level = tonumber(security_level)
[0106] -- Check if it is 1, 2, 3, or 4
[0107] if security_level == 1 or security_level == 2 or security_level == 3 or security_level == 4 then
[0108] -- Additional processing can be done according to requirements
[0109] slurm.log_user("Security level field check passed: %d", security_level)
[0110] else
[0111] slurm.log_user("Invalid security level field: %d", security_level)
[0112] return slurm.ERROR
[0113] end
[0114] else
[0115] slurm.log_user("Security level field (#SECURITY_LEVEL=1|2|3|4) is missing in the script")
[0116] return slurm.ERROR
[0117] end
[0118] -- Normal job submission
[0119] return slurm.SUCCESS
[0120] end}。
[0121] In some embodiments, after successful verification, the first job is scheduled and executed on a compute node. Specifically, the server can add the first job to the job queue, select a target compute node from multiple compute nodes; and allocate the first job to the target compute node so that the target compute node executes the first job.
[0122] In some embodiments, when the execution of the first job is completed, the server can record the job status of the first job in the database. For example, the job status can be recorded in the database in the form of a log.
[0123] As Figure 6 shown, a schematic diagram of the process from job submission to job execution completion is provided. The server obtains the submitted job submission script, determines whether the job submission script contains a job classification field. If so, it determines whether the job classification field is valid (i.e., determines whether the verification is successful). If not, it returns an error message indicating the lack of a job classification field. If the job classification field is valid, it notifies the user terminal that the job submission is successful and performs job scheduling and execution. After the job execution is completed, a log is recorded in the database, and the job status is recorded in the log. If the job classification field is invalid, it returns an error message indicating that the job classification field is invalid.
[0124] In this embodiment, the job classification set for the job can be obtained through the job classification field, and when the job classification is valid (i.e., the verification is successful), the user is notified of successful submission. Otherwise, the user is notified of failed submission, thereby ensuring that the job is successfully submitted only when the job classification is correctly set.
[0125] In some embodiments, the query and verification are implemented by the scheduling service by executing a job classification detection script. Before receiving the job submission script submitted by the user terminal, the method further includes: receiving a configuration item addition request for the configuration file of the scheduling service sent by the administrator terminal, where the configuration item addition request includes a path configuration item, and the path configuration item is used to set the storage path of the job classification detection script; and in response to the configuration item addition request, adding the path configuration item to the configuration file.
[0126] Among them, a scheduling service is deployed in the server. The scheduling service is an open-source job scheduling system for high-performance computing. The scheduling service can be, but is not limited to, the SLURM service. The SLURM service is an open-source, fault-tolerant, and highly scalable Linux cluster supercomputing system resource management and job scheduling system. The configuration file can be the configuration file of the SLURM service, such as slurm.conf.
[0127] Specifically, before receiving the configuration item addition request for the configuration file of the scheduling service sent by the administrator terminal, it also includes: receiving the storage request for the job confidentiality level detection script sent by the administrator terminal, and in response to the storage request, storing the job confidentiality level detection script. Among them, the storage request can carry the job confidentiality level detection script and the specified path. The server stores the job confidentiality level detection script under the specified path on the server in response to the storage request.
[0128] In some embodiments, the administrator terminal can provide a text editor for adding configuration items to the configuration file slurm.conf of the SLURM service. Through the text editor, plugin configuration items and path configuration items can be added to the configuration file. For example, add the plugin configuration item JobSubmitPlugins=lua and the path configuration item JobSubmitLua= / path / to / job_submit.lua. The plugin configuration item JobSubmitPlugins=lua is used to enable the Lua plugin as the plugin used for job submission. The path configuration item JobSubmitLua= / path / to / job_submit.lua is used to set the storage path of the Lua script (i.e., job_submit.lua) on the server. Then, the administrator terminal can send a restart request for the scheduling service to the server, and the server restarts the scheduling service in response to the restart request. By restarting the scheduling service, such as the SLURM service, the added configuration items can take effect. The instruction to restart the SLURM service can be, for example: sudo systemctl restart slurmctld.
[0129] In this embodiment, by adding a path configuration item to the configuration file of the scheduling service, the storage path of the job confidentiality level detection script can be set in the configuration file, so that the scheduling service can access the job confidentiality level detection script according to the storage path and execute the job confidentiality level detection script, improving the convenience and efficiency of the scheduling service in executing the job confidentiality level detection script.
[0130] In some embodiments, the method further includes: receiving a job submission request triggered by a job submission page, where the job submission request carries a second job, a preset field, and a value of the preset field, and the value of the preset field represents the job confidentiality level set for the second job through the job submission page; searching for the preset field in the job submission request, obtaining the value of the preset field, and generating job description information for the second job based on the job confidentiality level represented by the value of the preset field; storing the job description information of the second job in a database, where the job description information includes the job confidentiality level represented by the value of the preset field.
[0131] Among them, the preset field can be the comment field of the SLURM service. The job submission request may further include resource requirement information of the second job, such as the number of CPU cores, memory size, or running time, etc., and the job description information may include resource requirement information and job confidentiality level, etc. The job submission page can be a page provided by a high-performance computing management platform.
[0132] Such as Figure 7 As shown, the server receives a job submission request triggered by a page, determines the job confidentiality level according to the value of the preset field in the job submission request, sets the job confidentiality level for the second job, and records the job description information (including the job confidentiality level) in the database.
[0133] Specifically, the server can parse the job information related to the second job in the job submission request. For example, it can parse the job information through a Java program and record the job confidentiality level parsed from the job information in the database for subsequent access control and management.
[0134] In this embodiment, in the scenario of submitting a job through a page, a preset field is used to record the job confidentiality level set for the job through the page, and by reading the value of this preset field in the job submission request, the job confidentiality level can be determined, which improves the efficiency of obtaining the job confidentiality level. And storing the job description information including the job confidentiality level in the database helps to read the job confidentiality level of the job from the database.
[0135] In some embodiments, the method further includes: receiving a file upload request triggered by a file upload page, where the file upload request carries a file and the file confidentiality level of the file, and the file confidentiality level is set based on the file upload page; in response to the file upload request, recording the file confidentiality level of the file in the extended attributes of the file.
[0136] Among them, the file upload page is a page provided by a high-performance computing management platform. The server can store the file and its extended attributes in the file system. Extended Attributes (xattr) are used to store additional metadata in the file system.
[0137] Specifically, the user terminal can display a file upload page. When the file to be uploaded is determined through the file upload page, the user terminal can display a classification setting prompt box, which is used to prompt the user to set the file classification for the file to be uploaded. When the file classification is set through the classification setting prompt box, the user terminal can send a file upload request to the server.
[0138] As Figure 8 shown, when the general situation of the file to be uploaded is determined, the user terminal pops up a classification setting prompt box. After setting the file classification through the classification setting prompt box, a file upload request is sent to the server. The server responds to the file upload request, sets the classification of the file according to the file classification in the file upload request, and stores the file classification as the extended attribute of the file.
[0139] In some embodiments, the server can set a scheduled task, which is used to scan newly created (or uploaded) files and detect the extended attributes of the newly created (or uploaded) files. The newly created files can be files created within a preset duration before the current time, for example, files created in the most recent 24 hours or files created in the most recent 2 days. Among them, the created (or uploaded) files can be created or uploaded through a page or a shell command line. For newly created files, if no extended attribute is detected or the detected extended attribute does not contain the file classification, the server sends a classification notification to the user terminal, and the classification notification is used to remind the user to classify the newly created file as soon as possible. Classifying means setting the file classification. The classification notification can be, but is not limited to, sent by means such as email, system message, or text message.
[0140] As Figure 9 shown, when a newly created file is determined, for example, when a file creation request is received, in the case of file classification, the file classification can be recorded in the extended attribute of the file; in the case of unclassified files, the newly created files can be scanned regularly through a scheduled task, and it is judged whether the file already has a file classification. If not, a notification is sent to remind the user to classify as soon as possible.
[0141] In this embodiment, since the file classification can be set through a page, the convenience and efficiency of setting the file classification are improved, and recording the file classification in the extended attribute of the file helps to read the file classification and improves the convenience and efficiency of obtaining the file classification.
[0142] In some embodiments, the method further includes: regularly detecting the file classification of the target file under the target user account, where the target file is a file uploaded, created, or modified within a preset duration before the current time; and when the file classification of the target file is not detected, sending a classification setting notification to the user terminal corresponding to the target user account.
[0143] Among them, the file confidentiality level can be set through a command. For example, the command for a user to set the file confidentiality level can be: setfattr -n user:security_level -v "Confidential" filename. During the process of creating or modifying a file, the file confidentiality level can be set using a command.
[0144] In some embodiments, the server receives a file creation request sent by a user terminal corresponding to a target user account, determines the file to be created and the set file confidentiality level according to the file creation request, and returns a prompt message indicating an error in setting the file confidentiality level when the set file confidentiality level does not match the target user confidentiality level. Thus, it can be ensured that the file confidentiality level matches the user confidentiality level.
[0145] In some embodiments, the server receives a file confidentiality level modification request sent by a user terminal corresponding to a target user account, determines the modified file confidentiality level, and returns a prompt message indicating an error in setting the file confidentiality level when the modified file confidentiality level does not match the target user confidentiality level. Thus, it can be ensured that the file confidentiality level matches the user confidentiality level. Among them, the server can record the change operation of the file confidentiality level in the audit log for subsequent auditing.
[0146] As Figure 10 shown in (a) below, during the process of creating or modifying a file, the file confidentiality level can be set using a command, and the change operation of the file confidentiality level can be recorded. As Figure 10 shown in (b) below, the files under the user account can be periodically detected to determine that the file confidentiality level matches the user confidentiality level, and the change information of the file confidentiality level can be recorded in the audit log.
[0147] In this embodiment, by periodically detecting the file confidentiality level of a file and sending a confidentiality level setting notice when the file confidentiality level is not detected, the user can be reminded to set the file confidentiality level for the file in a timely manner, improving the access security of the file.
[0148] In some embodiments, as Figure 11 shown below, a method for classifying confidential information for a high-performance computing management platform is provided. Taking the application of this method to a server as an example, it includes the following steps 1102 to step 1114. Among them:
[0149] Step 1102, receive a resource access request for a target information resource, where the target user account is carried in the resource access request; the target information resource is an information resource in a high-performance computing system.
[0150] Step 1104, obtain the target user confidentiality level set for the target user account.
[0151] Step 1106, obtain the target resource confidentiality level set for the target information resource.
[0152] Step 1108, determine the set of resource confidentiality levels corresponding to the target user confidentiality level. Among them, a user account with the target user confidentiality level has the right to access the information resources with the resource confidentiality levels in the set of resource confidentiality levels.
[0153] Step 1110, determine whether the set of resource confidentiality levels contains the target resource confidentiality level. If so, execute Step 1112; if not, execute Step 1114.
[0154] Step 1112, return the access result of the target information resource.
[0155] Step 1114, return a denied access prompt message, which is used to prompt that the user does not have the access right to the target information resource.
[0156] For the specific processes of the above Steps 1102 - 1114, reference can be made to the descriptions of the method embodiments above. Their implementation principles and technical effects are similar, and will not be elaborated here.
[0157] Traditional high-performance computing management platforms generally lack mechanisms for classifying and controlling the confidentiality levels of jobs and files. This results in users being unable to effectively set or identify the security levels when submitting jobs or uploading files, thereby affecting the overall security of the system. Especially in a classified environment, the main confidentiality level of the user does not match the object confidentiality level of the job or file, presenting potential security risks. The solution provided in this application overcomes this problem and improves security.
[0158] It should be understood that although the steps in the flowcharts involved in the above-mentioned embodiments are shown in sequence according to the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0159] Based on the same inventive concept, an embodiment of the present application further provides a classified secrecy device for a high-performance computing management platform for implementing the classified secrecy method for the high-performance computing management platform involved above. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the classified secrecy device for the high-performance computing management platform provided below can refer to the limitations on the classified secrecy method for the high-performance computing management platform in the above text, and will not be repeated here.
[0160] In some embodiments, as Figure 12 shown, a classified secrecy device for a high-performance computing management platform is provided, including: a request receiving module 1202, a classification level obtaining module 1204, an access result returning module 1206, and an access rejection module 1208, where:
[0161] The request receiving module 1202 is configured to receive a resource access request for a target information resource, and the resource access request carries a target user account; the target information resource is an information resource in a high-performance computing system.
[0162] The classification level obtaining module 1204 is configured to obtain a target user classification level set for the target user account, and obtain a target resource classification level set for the target information resource.
[0163] The access result returning module 1206 is configured to return an access result of the target information resource when the target user classification level matches the target resource classification level; where the matching of the target user classification level and the target resource classification level is a condition that the target user account needs to meet for accessing the target information resource.
[0164] The access rejection module 1208 is configured to return a rejection access prompt message when the target user classification level does not match the target resource classification level, and the rejection access prompt message is used to prompt that the access permission for the target information resource is not available.
[0165] In some embodiments, the access result returning module 1206 is further configured to determine a resource classification level set corresponding to the target user classification level, where a user account with the target user classification level has the permission to access information resources with the resource classification levels in the resource classification level set; when the resource classification level set contains the target resource classification level, the access result of the target information resource is returned.
[0166] In some embodiments, the target user account belongs to a general account, and the device further includes a file update module. The file update module is configured to determine the file confidentiality level of the files owned by the target user account when the target user confidentiality level is downgraded from the first user confidentiality level to the second user confidentiality level; and when the second user confidentiality level does not match the file confidentiality level, update the owner of the file from the target user account to the management account and modify the access permission of the file to be accessible only by the management account.
[0167] In some embodiments, the device further includes a job submission detection module. The job submission detection module is configured to receive a job submission script submitted by a user terminal, where the job submission script includes a first job; query a job confidentiality level field from the job submission script, and the value of the job confidentiality level field is used to determine the job confidentiality level of the first job; in the case of querying, verify the value of the job confidentiality level field, and in the case of successful verification, notify the user terminal that the submission is successful; in the case of not querying or the verification of the value of the job confidentiality level field fails, notify the user terminal that the submission fails.
[0168] In some embodiments, the query and verification are implemented by the scheduling service by executing a job confidentiality level detection script. Before receiving the job submission script submitted by the user terminal, the device further includes a configuration module. The configuration module is configured to receive a configuration item addition request for the configuration file of the scheduling service sent by an administrator terminal, where the configuration item addition request includes a path configuration item, and the path configuration item is used to set the storage path of the job confidentiality level detection script; in response to the configuration item addition request, add the path configuration item to the configuration file.
[0169] In some embodiments, the device further includes a job processing module. The job processing module is configured to receive a job submission request triggered through a job submission page. The job submission request carries a second job, a preset field, and the value of the preset field. The value of the preset field represents the job confidentiality level set for the second job through the job submission page; find the preset field from the job submission request and obtain the value of the preset field, and generate job description information for the second job based on the job confidentiality level represented by the value of the preset field; store the job description information of the second job in a database, and the job description information includes the job confidentiality level represented by the value of the preset field.
[0170] In some embodiments, the method further includes a file processing module. The file processing module is configured to receive a file upload request triggered through a file upload page. The file upload request carries a file and the file confidentiality level of the file, and the file confidentiality level is set based on the file upload page; in response to the file upload request, record the file confidentiality level of the file in the extended attributes of the file.
[0171] In some embodiments, the file processing module is further configured to periodically detect the file classification of the target file under the target user account, where the target file is a file uploaded, created, or modified within a preset duration before the current time; in the case where the file classification of the target file is not detected, a classification setting notification is sent to the user terminal corresponding to the target user account.
[0172] Each module in the above-mentioned classification marking device for a high-performance computing management platform can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor in the computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above-mentioned modules.
[0173] In some embodiments, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 13 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the data involved in the classification marking method for a high-performance computing management platform. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a classification marking method for a high-performance computing management platform.
[0174] Those skilled in the art can understand that Figure 13 the structure shown in
[0175] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0176] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned classified encryption method for a high-performance computing management platform are implemented.
[0177] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above-mentioned classified encryption method for a high-performance computing management platform are implemented.
[0178] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned method embodiments. Among them, any reference to a memory, database, or other medium used in the various embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the various embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the various embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0179] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.
[0180] The above-described embodiments merely represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application shall be subject to the appended claims.
Claims
1. A classified secret method for a high-performance computing management platform, characterized in that, The method includes: Receiving a resource access request for a target information resource, where the target user account is carried in the resource access request; the target information resource is an information resource in a high-performance computing system; Obtaining the target user confidentiality level set for the target user account, and obtaining the target resource confidentiality level set for the target information resource; Returning an access result of the target information resource when the target user confidentiality level matches the target resource confidentiality level; wherein, the matching of the target user confidentiality level and the target resource confidentiality level is a condition required for the target user account to access the target information resource; Returning a denied access prompt message when the target user confidentiality level does not match the target resource confidentiality level, and the denied access prompt message is used to prompt that the access permission for the target information resource is not available.
2. The method according to claim 1, wherein The returning the access result of the target information resource when the target user confidentiality level matches the target resource confidentiality level includes: Determining a set of resource confidentiality levels corresponding to the target user confidentiality level, where a user account with the target user confidentiality level has the right to access information resources with the resource confidentiality levels in the set of resource confidentiality levels; Returning the access result of the target information resource when the set of resource confidentiality levels includes the target resource confidentiality level.
3. The method according to claim 1, characterized in that, The target user account belongs to a general account, and the method further includes: Determining the file confidentiality level of the files owned by the target user account when the target user confidentiality level is downgraded from a first user confidentiality level to a second user confidentiality level; When the second user confidentiality level does not match the file confidentiality level, updating the owner of the text from the target user account to the management account, and modifying the access permission of the file to be accessible only by the management account.
4. The method according to any one of claims 1 to 3, characterized in that The method further includes: Receiving a job submission script submitted by a user terminal, where the job submission script includes a first job; Querying a job confidentiality level field from the job submission script, and the value of the job confidentiality level field is used to determine the job confidentiality level of the first job; When the query is successful, verifying the value of the job confidentiality level field, and notifying the user terminal that the submission is successful when the verification is successful; Notifying the user terminal that the submission fails when the query fails or the value of the job confidentiality level field fails the verification.
5. The method according to claim 4, characterized in that, The query and verification are implemented by the scheduling service by executing a job confidentiality level detection script. Before receiving the job submission script submitted by the user terminal, the method further includes: Receiving a configuration item addition request for a configuration file of the scheduling service sent by an administrator terminal, where the configuration item addition request includes a path configuration item, and the path configuration item is used to set the storage path of the job confidentiality level detection script; Responding to the configuration item addition request, adding the path configuration item to the configuration file.
6. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Receiving a job submission request triggered through a job submission page, where the job submission request carries a second job, a preset field, and the value of the preset field, and the value of the preset field represents the job confidentiality level set for the second job through the job submission page; Find the preset field from the job submission request, obtain the value of the preset field, and generate the job description information of the second job based on the job confidentiality level represented by the value of the preset field; Store the job description information of the second job in a database, where the job description information includes the job confidentiality level represented by the value of the preset field.
7. The method according to any one of claims 1 to 3, characterized in that The method further includes: Receive a file upload request triggered through a file upload page, where the file upload request carries a file and the file confidentiality level of the file, and the file confidentiality level is set based on the file upload page; In response to the file upload request, record the file confidentiality level of the file in the extended attributes of the file.
8. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Regularly detect the file confidentiality level of a target file under the target user account, where the target file is a file uploaded, created, or modified within a preset duration before the current time; In the case where the file confidentiality level of the target file is not detected, send a confidentiality level setting notification to the user terminal corresponding to the target user account.
9. A classified device for a high-performance computing management platform, characterized in that, The device includes: A request receiving module, configured to receive a resource access request for a target information resource, where the resource access request carries a target user account; the target information resource is an information resource in a high-performance computing system; A confidentiality level obtaining module, configured to obtain the target user confidentiality level set for the target user account and obtain the target resource confidentiality level set for the target information resource; An access result returning module, configured to return the access result of the target information resource when the target user confidentiality level matches the target resource confidentiality level; where the matching of the target user confidentiality level and the target resource confidentiality level is a condition required for the target user account to access the target information resource; An access rejection module, configured to return a rejection access prompt message when the target user confidentiality level does not match the target resource confidentiality level, and the rejection access prompt message is used to prompt that the access right to the target information resource is not available.
10. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Account authentication method and device, computer equipment and storage medium
CN110620782A
Resource access method and device
CN115459943A
Data access control method and device
CN119324788A