Micro-service intrusion tolerance scheduling method and system for cloud edge collaborative network
By adopting multi-agent reinforcement learning and cooperative game theory in the cloud-edge collaborative network and dynamically adjusting the scheduling strategy of microservices, the shortcomings of microservice scheduling technology in the cloud-edge collaborative network in the face of dynamic threats and complex resource management have been solved, and security and performance have been improved.
Patent Information
- Application Number
- CN202510604426.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-08-15
AI Technical Summary
The existing microservice scheduling technology in the cloud-edge collaborative network is difficult to effectively deal with dynamically changing security threats and complex resource management needs, resulting in the system lacking defense capabilities when facing attacks, and the scale of resource allocation strategy solving is constantly expanding, making it difficult to achieve the best security protection effect.
The multi-agent reinforcement learning algorithm and cooperative game theory are adopted, and the Markov decision-making process model combined with resources and secure joint state space is used to dynamically adjust the redundant deployment, migration path and cleaning strategy of microservice instances to optimize resource allocation and scheduling decisions.
It improves the security and reliability of microservices in the cloud-edge collaborative network, reduces the risk of system attacks, and optimizes resource utilization efficiency and service performance to ensure that the system operates efficiently in complex environments.
Smart Images

Figure CN120499271A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure relate to the field of computer networks, and more particularly to a method and system for intrusion tolerance scheduling of microservices in a cloud-edge collaborative network. Background Art
[0002] With the advent of the digital age, the growth of massive amounts of data has driven a significant increase in demand for computing resources. The combination of cloud computing and edge computing technologies, by distributing computing power across a wide range of devices, improves data processing efficiency, reduces latency, and provides more personalized and localized services. However, traditional scheduling technologies are often targeted at specific scenarios and needs and cannot meet diverse and dynamically changing computing demands. Furthermore, the heterogeneity of resources in the cloud and edge, their widespread geographical distribution, and the complexity of the network environment make resource management and scheduling more difficult.
[0003] In cloud-edge collaborative networks, the complexity and dynamism of microservices architectures pose new challenges to system security, performance, and resource management. By breaking down applications into multiple small services, microservices architectures improve system flexibility and scalability, but this also increases system complexity. Each microservice may face different security threats. For example, attackers may target vulnerable nodes for lateral penetration, expanding the attack surface and causing severe damage.
[0004] Existing cloud-edge collaborative scheduling technologies primarily focus on unified resource management and dynamic scheduling to maximize resource utilization and ensure user quality of service. However, these technologies have limitations when addressing the intrusion-tolerant scheduling of microservices. For example, traditional scheduling technologies often fail to effectively address the dynamic changes in microservices under attack, resulting in a system lacking sufficient defense capabilities against complex security threats.
[0005] Furthermore, security policy solutions in cloud-edge collaborative networks require robust scalability to effectively coordinate resource allocation between the cloud and edge. However, as the number and types of microservices continue to increase, the scale of configuration policy solutions also continues to expand, making it increasingly difficult to achieve optimal security protection with limited resources. Therefore, a system and method that can adapt to intrusion tolerance scheduling of microservices in cloud-edge collaborative networks is needed to address the shortcomings of existing technologies. Summary of the Invention
[0006] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0007] Some embodiments of the present disclosure propose microservice intrusion tolerance scheduling methods, systems, devices, electronic devices and computer-readable media for cloud-edge collaborative networks to solve the technical problems mentioned in the above background technology section.
[0008] In the first aspect, some embodiments of the present disclosure provide a microservice intrusion tolerance scheduling method for a cloud-edge collaborative network, the method comprising: collecting operating information of cloud data centers, edge nodes, and microservice instances, wherein the operating information includes: resource usage, service request type, and network topology; constructing a Markov decision process model of the resource and security joint state space based on the collected operating information, and analyzing the scheduling requirements and security risks of the microservice instances; based on cooperative game theory, calculating the resource allocation strategy of each node according to the total amount of resources, the minimum demand for microservice resources in the cloud-edge collaborative network, and the bargaining weight to perform resource allocation; adopting a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path, and cleaning strategy of the microservice instances; sending the optimized scheduling plan to the cloud data center and edge nodes for configuration and deployment of the microservice instances, wherein the scheduling plan includes: redundant deployment, migration path, and cleaning strategy; real-time monitoring of the operating status and security status of the microservice instances, and dynamic adjustment of the scheduling strategy.
[0009] In the second aspect, some embodiments of the present disclosure provide a microservice intrusion tolerance scheduling system for a cloud-edge collaborative network, the system including: a cloud-edge collaborative network controller collects operating information of cloud data centers, edge nodes and microservice instances, wherein the operating information includes: resource usage, service request type, and network topology; the cloud-edge collaborative network controller constructs a Markov decision process model of the resource and security joint state space based on the collected operating information, and analyzes the scheduling requirements and security risks of the microservice instances; the cloud-edge collaborative network controller calculates the resource allocation strategy of each node based on the total amount of resources, the minimum demand for microservice resources in the cloud-edge collaborative network and the bargaining weight based on cooperative game theory to perform resource allocation; the cloud-edge collaborative network controller adopts a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path and cleaning strategy of the microservice instances; the cloud-edge collaborative network controller sends the optimized scheduling plan to the cloud data center and edge nodes to configure and deploy the microservice instances, wherein the scheduling plan includes: redundant deployment, migration path and cleaning strategy; the cloud-edge collaborative network controller monitors the operating status and security status of the microservice instances in real time, and dynamically adjusts the scheduling strategy.
[0010] On the third aspect, some embodiments of the present disclosure provide a microservice intrusion tolerance scheduling device for a cloud-edge collaborative network, the device comprising: a collection unit, configured to collect operating information of cloud data centers, edge nodes and microservice instances, wherein the operating information includes: resource usage, service request type, and network topology; a construction unit, configured to construct a Markov decision process model of the resource and security joint state space based on the collected operating information, and analyze the scheduling requirements and security risks of the microservice instances; a computing unit, configured to calculate the resource allocation strategy of each node based on the cooperative game theory, according to the total amount of resources, the minimum demand for microservice resources in the cloud-edge collaborative network and the bargaining weight, so as to perform resource allocation; an adjustment unit, configured to adopt a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path and cleaning strategy of the microservice instance; a sending unit, configured to send the optimized scheduling plan to the cloud data center and edge node for configuration and deployment of the microservice instance, wherein the scheduling plan includes: redundant deployment, migration path and cleaning strategy; a monitoring unit, configured to monitor the operating status and security status of the microservice instance in real time, and dynamically adjust the scheduling strategy.
[0011] In a fourth aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation manner of the above-mentioned first aspect.
[0012] In a fifth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation of the first aspect above is implemented.
[0013] The above-mentioned embodiments of the present disclosure have the following beneficial effects: through the microservice intrusion tolerance scheduling method for cloud-edge collaborative networks of some embodiments of the present disclosure, the data transmission control architecture of the cloud-edge collaborative network environment constructed provides environmental support for the secure operation of microservices; the designed microservice intrusion tolerance scheduling method can adaptively judge and dynamically adjust the scheduling strategy of microservices based on the operating characteristics and security requirements of microservices, giving priority to ensuring the security and continuity of key microservices. The present invention can not only effectively improve the security and reliability of microservices in cloud-edge collaborative networks and reduce the risk of system attacks, but also optimize resource utilization efficiency and service performance, so that the system can still maintain efficient operation in the face of complex security threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.
[0015] Figure 1 is a flowchart of some embodiments of the microservice intrusion tolerance scheduling method for cloud-edge collaborative networks according to the present disclosure;
[0016] Figure 2 This is an exemplary architecture diagram of a microservice intrusion tolerance scheduling system for a cloud-edge collaborative network according to some embodiments of the present disclosure;
[0017] Figure 3 This is a flow chart of a microservice intrusion tolerance scheduling system for cloud-edge collaborative networks according to some embodiments of the present disclosure;
[0018] Figure 4 1 is a schematic diagram of the structure of some embodiments of a microservice intrusion tolerance scheduling device for a cloud-edge collaborative network according to the present disclosure;
[0019] Figure 5 It is a structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION
[0020] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0021] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.
[0022] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0023] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0024] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0025] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0026] Figure 1 This is a process 100 of some embodiments of a microservice intrusion tolerance scheduling method for a cloud-edge collaborative network according to some embodiments of the present disclosure. The microservice intrusion tolerance scheduling method for a cloud-edge collaborative network includes the following steps:
[0027] Step 101: Collect operating information of cloud data centers, edge nodes, and microservice instances.
[0028] In some embodiments, the execution subject (e.g., computing device) of the microservice intrusion tolerance scheduling method for cloud-edge collaborative network collects the operation information of cloud data center, edge node and microservice instance. The operation information includes: resource usage, service request type, network topology. The execution subject of the microservice intrusion tolerance scheduling method for cloud-edge collaborative network can be a microservice intrusion tolerance scheduling system. The location of cloud data center and edge node is as follows: Figure 2 For example, the cloud layer can represent cloud data centers, and the edge layer can represent edge nodes. Specifically, the cloud-edge collaborative network controller communicates with cloud data centers and edge nodes to collect information about each node's resource usage, including CPU utilization, memory usage, and storage capacity. The controller also collects operational information about microservice instances, including service request types, response times, and error rates. Furthermore, the controller obtains network topology information to facilitate scheduling decisions.
[0029] The microservice intrusion tolerance scheduling system includes a cloud-edge collaborative network controller, cloud data centers, edge nodes, microservice instances, and various computing, storage, and connection / exchange resources.
[0030] The aforementioned cloud-edge collaborative network controller has the ability to discover network topology and the resource processing and computing capabilities of network nodes. When diverse business demands arise within the network, the cloud-edge collaborative network controller analyzes the collected microservice operation information and calculates scheduling configurations. It then deploys the new scheduling solutions to cloud data centers and edge nodes, ensuring that network microservices meet their scheduling requirements.
[0031] The above-mentioned cloud data center, as the core computing resource in the system, is responsible for processing large-scale data and complex computing tasks, and provides powerful computing and storage resources.
[0032] The above-mentioned edge nodes are deployed close to the user end, responsible for processing tasks with high real-time and low latency requirements, and providing limited computing and storage resources.
[0033] The aforementioned microservice instances, as the basic service units in the system, are responsible for specific business processing. Microservice instances can be migrated and redundantly deployed between cloud data centers and edge nodes.
[0034] The above-mentioned computing and storage resources, including CPU, memory, storage and other hardware resources, are available for on-demand acquisition and use by the cloud-edge collaborative network controller.
[0035] The above connection / exchange resources are used to connect different network device nodes to realize data transmission and exchange.
[0036] Furthermore, these microservice instances are redundantly deployed and migrated within the cloud-edge collaborative network to improve the system's intrusion tolerance. The cloud-edge collaborative network controller dynamically adjusts the redundant deployment and migration strategies for microservice instances based on network resource availability and security requirements.
[0037] Step 102: Based on the collected operation information, a Markov decision process model of the resource and security joint state space is constructed, and the scheduling requirements and security risks of the microservice instance are analyzed.
[0038] In some embodiments, the aforementioned execution entity can construct a Markov decision process model of the joint resource and security state space based on the collected operational information, and analyze the scheduling requirements and security risks of the microservice instances. Specifically, the controller uses collected information such as resource usage, service request type, and network topology as input to the state space, and combines it with a security risk assessment model to construct a Markov decision process model of the joint resource-security state space. Using this model, the controller can analyze the scheduling requirements and security risks of microservices, providing a basis for subsequent scheduling decisions.
[0039] Construct a Markov decision process model of the resource-security joint state space, represented as a tuple <S,O,A,P,R,γ>, where s t ∈S is the environment state space, O={O e ,O c} is the observation space set of the two agents in the cloud data center; A={A e ,A c} is the set of agent action spaces, and are the actions taken by the cloud data center and edge node agents at the current time step t, respectively. t is the joint action of all agents at the current time step t. P:(s t+1 |s t,a t ):S×A→S is the transition from the current state s t Perform joint action a t Transition to the next state s t+1 The state transition probability. R(r t |s t ,a t ):S×A→R is the reward function, and r t is the agent in state s t Next take action a t The instant reward obtained. γ∈[0,1) is the cumulative reward discount factor. The state space validity test confirms the model's ability to represent the actual network environment and the currently observed security risks.
[0040] Step 103, based on cooperative game theory, according to the total amount of resources, the minimum demand for microservice resources in the cloud-edge collaborative network and the bargaining weight, calculate the resource allocation strategy of each node to perform resource allocation.
[0041] In some embodiments, the aforementioned execution entities can calculate resource allocation strategies for each node based on cooperative game theory, based on the total resource volume, the minimum resource requirements of microservices in the cloud-edge collaborative network, and bargaining weights, to perform resource allocation. State space validity testing is used to confirm the model's ability to represent the actual network environment and currently observed security risks. Based on cooperative game theory, the cloud-edge collaborative network controller coordinates resource allocation on the cloud and edge sides. Based on the total resource volume, the minimum resource requirements of microservices in the cloud-edge collaborative network, and bargaining weights, it calculates resource allocation strategies for each node, dynamically adjusting resource allocation to maximize the overall security benefits of the system. Specifically, the controller utilizes cooperative game theory to consider resource allocation issues on both the cloud and edge sides. By constructing a cooperative game model, the controller calculates resource allocation strategies for each node to maximize the overall security benefits of the system. During the resource allocation process, the controller comprehensively considers factors such as each node's resource usage, service request type, and security risk to ensure the rationality and effectiveness of resource allocation.
[0042] Step 104: Use a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path, and cleaning strategy of the microservice instance.
[0043] In some embodiments, the aforementioned execution entities can employ multi-agent reinforcement learning algorithms to dynamically adjust the redundant deployment, migration paths, and cleaning strategies of microservice instances. When node resources are sufficient, multiple copies of key microservices can be deployed. When a microservice instance is compromised, it can quickly switch to other healthy copies to ensure service continuity. If current node resources are limited and cannot meet the microservice redundant deployment requirements, the remaining global nodes are considered and key microservices are migrated to nodes with sufficient defense resources to cope with complex network environments and security threats. Regularly cleaning redundant copies of microservices can effectively remove copies that could be exploited by attackers.
[0044] Specifically, the controller uses a multi-agent reinforcement learning algorithm to train two agents, one on the cloud and one on the edge, to learn the optimal actions under different states. The states, actions, and rewards can be described as follows:
[0045] (1) Status: Indicates the current operation status and environmental information of microservices in the cloud-edge collaborative network, including resource usage, service request type, security risk assessment results (including security risk assessment results of each microservice instance and node, such as attack detection status, vulnerability information, etc.), microservice operation status (including the operation status of microservice instances, such as normal operation, abnormality, attack, etc.)
[0046] (2) Action: Indicates the operations that the cloud-edge collaborative network controller can perform in a specific state, including specifying nodes for microservice redundant deployment or microservice migration, microservice replica cleaning, and resource allocation adjustment.
[0047] (3) Reward: refers to the feedback signal given by the system after performing a certain action, specifically including service response delay (the reward value is inversely proportional to the service response delay, the lower the response delay, the higher the reward value), resource utilization efficiency, system risk, and task completion.
[0048] In this way, the controller can dynamically adjust the redundant deployment, migration paths, and cleaning strategies of microservices to cope with complex network environments and security threats. During this adjustment process, the controller monitors the operating status and security status of microservices in real time and dynamically adjusts the scheduling strategy as needed to ensure system security and performance.
[0049] Step 105: Send the optimized scheduling plan to the cloud data center and edge nodes to configure and deploy the microservice instances.
[0050] In some embodiments, the above-mentioned execution entity can send the optimized scheduling plan to the cloud data center and edge nodes to configure and deploy the microservice instances. The scheduling plan includes: redundant deployment, migration path, and cleaning strategy. Specifically, the controller sends the optimized scheduling plan to the cloud data center and edge nodes to guide the configuration and deployment of the microservice instances. During the sending process, the controller will ensure the accuracy and timeliness of the scheduling plan so that the microservice instances can quickly respond to scheduling instructions and achieve reasonable resource allocation and security protection.
[0051] Step 106: Monitor the operating status and security status of the microservice instance in real time, and dynamically adjust the scheduling strategy.
[0052] In some embodiments, the aforementioned execution entities can monitor the operating status and security status of microservice instances in real time and dynamically adjust scheduling policies. Specifically, the system collects relevant data by monitoring the operating status and security status of microservices in real time and feeds it back to the cloud-edge collaborative network controller. Based on this data, the controller dynamically adjusts scheduling policies to respond to changes in the network environment and evolving security threats. In this way, the system can always maintain optimal operating status, ensuring the security and performance of microservices.
[0053] Figure 3 This is a process 300 of some embodiments of a microservice intrusion tolerance scheduling system for a cloud-edge collaborative network according to some embodiments of the present disclosure. The microservice intrusion tolerance scheduling system for a cloud-edge collaborative network includes the following steps:
[0054] In step 301, the cloud-edge collaborative network controller collects operating information of cloud data centers, edge nodes, and microservice instances.
[0055] In some embodiments, the cloud-edge collaborative network controller collects operating information of cloud data centers, edge nodes, and microservice instances. Among them, the operating information includes: resource usage, service request type, and network topology. Specifically, the cloud-edge collaborative network controller collects the resource usage of each node, including CPU usage, memory occupancy, storage capacity, etc., through communication with the cloud data center and edge nodes. At the same time, the controller also collects operating information of microservice instances, including service request type, response time, error rate, etc. In addition, the controller also obtains network topology information to better make scheduling decisions. The microservice intrusion tolerance scheduling system includes a cloud-edge collaborative network controller, a cloud data center, edge nodes, microservice instances, and various computing storage resources and connection / switching resources.
[0056] The above-mentioned microservice intrusion tolerance scheduling system includes: a cloud-edge collaborative network controller, a cloud data center, an edge node, and a microservice instance.
[0057] The above-mentioned cloud-edge collaborative network controller is used to discover the network topology and the resource processing and computing capabilities of nodes in the network.
[0058] The above-mentioned cloud data center serves as the core computing resource in the system, responsible for processing data and complex computing tasks.
[0059] The above-mentioned edge nodes are deployed close to the user end and are responsible for processing tasks with high real-time and low latency requirements.
[0060] The above microservice instances serve as the basic service units in the microservice intrusion tolerance scheduling system, responsible for business processing, as well as migration and redundant deployment between cloud data centers and edge nodes.
[0061] The above-mentioned computing and storage resources, including CPU, memory, storage and other hardware resources, are available for on-demand acquisition and use by the cloud-edge collaborative network controller.
[0062] The above connection / exchange resources are used to connect different network device nodes to realize data transmission and exchange.
[0063] In step 302 , the cloud-edge collaborative network controller builds a Markov decision process model of the resource and security joint state space based on the collected operation information, and analyzes the scheduling requirements and security risks of the microservice instances.
[0064] In some embodiments, the cloud-edge collaborative network controller constructs a Markov decision process model of the resource and security joint state space based on the collected operational information, and analyzes the scheduling requirements and security risks of the microservice instances. Specifically, the controller uses the collected information such as resource usage, service request type, network topology, etc. as the input of the state space, and combines it with the security risk assessment model to construct a Markov decision process model of the resource-security joint state space. Through this model, the controller can analyze the scheduling requirements and security risks of microservices, providing a basis for subsequent scheduling decisions.
[0065] Construct a Markov decision process model of the resource-security joint state space, represented as a tuple <S,O,A,P,R,γ>, where s t ∈S is the environment state space, O={O e ,O c} is the observation space set of the two agents in the cloud data center; A={A e ,A c} is the set of agent action spaces, and are the actions taken by the cloud data center and edge node agents at the current time step t, respectively. t is the joint action of all agents at the current time step t. P:(s t+1 |st ,a t ):S×A→S is the transition from the current state s t Perform joint action a t Transition to the next state s t+1 The state transition probability. R(r t |s t ,a t ):S×A→R is the reward function, and r t is the agent in state s t Next take action a t The instant reward obtained. γ∈[0,1) is the cumulative reward discount factor. The state space validity test confirms the model's ability to represent the actual network environment and the currently observed security risks.
[0066] In step 303, the cloud-edge collaborative network controller calculates the resource allocation strategy of each node based on cooperative game theory, the total amount of resources, the minimum demand for microservice resources in the cloud-edge collaborative network, and the bargaining weight to perform resource allocation.
[0067] In some embodiments, the cloud-edge collaborative network controller, based on cooperative game theory, calculates resource allocation strategies for each node based on the total resource volume, the minimum resource requirements of microservices in the cloud-edge collaborative network, and bargaining weights to allocate resources. State space validity testing confirms the model's ability to represent the actual network environment and currently observed security risks. Based on cooperative game theory, the cloud-edge collaborative network controller coordinates resource allocation on the cloud and edge sides. Based on the total resource volume, the minimum resource requirements of microservices in the cloud-edge collaborative network, and bargaining weights, it calculates resource allocation strategies for each node. It dynamically adjusts resource allocation to maximize the overall security benefits of the system. Specifically, the controller utilizes cooperative game theory to consider resource allocation issues on both the cloud and edge sides. By constructing a cooperative game model, the controller calculates resource allocation strategies for each node to maximize the overall security benefits of the system. During the resource allocation process, the controller comprehensively considers factors such as each node's resource usage, service request type, and security risk to ensure the rationality and effectiveness of resource allocation.
[0068] In step 304, the cloud-edge collaborative network controller uses a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path, and cleaning strategy of the microservice instances.
[0069] In some embodiments, the cloud-edge collaborative network controller uses a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path, and cleaning strategy of microservice instances. When node resources are sufficient, multiple copies of key microservices can be deployed. When a microservice instance is attacked, it can quickly switch to other normal copies to ensure service continuity. If the current node resources are limited and cannot meet the microservice redundant deployment requirements, the remaining nodes will be considered globally and the key microservices will be migrated to nodes with sufficient defense resources to cope with complex network environments and security threats. By regularly cleaning redundant copies of microservices, copies that can be exploited by attackers can be effectively removed.
[0070] Specifically, the controller uses a multi-agent reinforcement learning algorithm to train two agents, one on the cloud and one on the edge, to learn the optimal actions under different states. The states, actions, and rewards can be described as follows:
[0071] (1) Status: Indicates the current operation status and environmental information of microservices in the cloud-edge collaborative network, including resource usage, service request type, security risk assessment results (including security risk assessment results of each microservice instance and node, such as attack detection status, vulnerability information, etc.), microservice operation status (including the operation status of microservice instances, such as normal operation, abnormality, attack, etc.)
[0072] (2) Action: Indicates the operations that the cloud-edge collaborative network controller can perform in a specific state, including specifying nodes for microservice redundant deployment or microservice migration, microservice replica cleaning, and resource allocation adjustment.
[0073] (3) Reward: refers to the feedback signal given by the system after performing a certain action, specifically including service response delay (the reward value is inversely proportional to the service response delay, the lower the response delay, the higher the reward value), resource utilization efficiency, system risk, and task completion.
[0074] In this way, the controller can dynamically adjust the redundant deployment, migration paths, and cleaning strategies of microservices to cope with complex network environments and security threats. During this adjustment process, the controller monitors the operating status and security status of microservices in real time and dynamically adjusts the scheduling strategy as needed to ensure system security and performance.
[0075] In step 305 , the cloud-edge collaborative network controller sends the optimized scheduling plan to the cloud data center and edge nodes for configuration and deployment of microservice instances.
[0076] In some embodiments, the cloud-edge collaborative network controller sends the optimized scheduling plan to the cloud data center and edge nodes to configure and deploy microservice instances, where the scheduling plan includes: redundant deployment, migration path, and cleaning strategy. Specifically, the controller sends the optimized scheduling plan to the cloud data center and edge nodes to guide the configuration and deployment of microservice instances. During the sending process, the controller will ensure the accuracy and timeliness of the scheduling plan so that the microservice instances can quickly respond to scheduling instructions and achieve reasonable resource allocation and security protection.
[0077] In step 306, the cloud-edge collaborative network controller monitors the operating status and security status of the microservice instance in real time, and dynamically adjusts the scheduling strategy.
[0078] In some embodiments, the cloud-edge collaborative network controller monitors the operating status and security status of microservice instances in real time and dynamically adjusts scheduling policies. Specifically, the system collects relevant data by monitoring the operating status and security status of microservices in real time and feeds it back to the cloud-edge collaborative network controller. Based on this data, the controller dynamically adjusts scheduling policies to respond to changes in the network environment and evolving security threats. In this way, the system can always maintain optimal operating status, ensuring the security and performance of microservices.
[0079] Further references Figure 4 As an implementation of the systems shown in the above figures, the present disclosure provides some embodiments of a microservice intrusion tolerance scheduling device for a cloud-edge collaborative network. These device embodiments are similar to Figure 1 Corresponding to the system embodiments shown, the microservice intrusion tolerance scheduling device for cloud-edge collaborative networks can be specifically applied to various electronic devices.
[0080] like Figure 4As shown, a microservice intrusion tolerance scheduling device 400 for a cloud-edge collaborative network in some embodiments includes: a collection unit 401, a construction unit 402, a calculation unit 403, an adjustment unit 404, a sending unit 405 and a monitoring unit 406. Among them, the collection unit is configured to collect the operation information of the cloud data center, edge nodes and microservice instances, wherein the operation information includes: resource usage, service request type, and network topology; the construction unit is configured to construct a Markov decision process model of the resource and security joint state space based on the collected operation information, and analyze the scheduling requirements and security risks of the microservice instances; the calculation unit is configured to calculate the resource allocation strategy of each node based on the cooperative game theory, according to the total amount of resources, the minimum demand for microservice resources in the cloud-edge collaborative network and the bargaining weight, so as to perform resource allocation; the adjustment unit is configured to adopt a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path and cleaning strategy of the microservice instance; the sending unit is configured to send the optimized scheduling plan to the cloud data center and edge node for configuration and deployment of the microservice instance, wherein the scheduling plan includes: redundant deployment, migration path and cleaning strategy; the monitoring unit is configured to monitor the operation status and security status of the microservice instance in real time, and dynamically adjust the scheduling strategy.
[0081] It is understandable that the units recorded in the microservice intrusion tolerance scheduling device 400 for cloud-edge collaborative network are similar to those in the reference Figure 1 Therefore, the operations, features, and beneficial effects described above for the system are also applicable to the microservice intrusion tolerance scheduling device 400 for cloud-edge collaborative network and the units contained therein, and will not be repeated here.
[0082] Reference below Figure 5 , which shows a schematic structural diagram of an electronic device (such as a computing device) suitable for implementing some embodiments of the present disclosure. Figure 5 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure. Figure 5As shown, the computer device includes a processor, a memory and a network interface connected via a system bus, wherein the memory may include a non-volatile storage medium and an internal memory. The non-volatile storage medium can store an operating system and a computer program. The computer program includes program instructions, which, when executed, can enable the processor to execute any microservice intrusion tolerance scheduling method for a cloud-edge collaborative network. The processor is used to provide computing and control capabilities to support the operation of the entire computer device. The internal memory provides an environment for the operation of the computer program in the non-volatile storage medium, which, when executed by the processor, can enable the processor to execute any microservice intrusion tolerance scheduling method for a cloud-edge collaborative network. The network interface is used for network communication, such as sending assigned tasks, etc. Those skilled in the art will understand that Figure 5 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present disclosure, and does not constitute a limitation on the computer device to which the solution of the present disclosure is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0083] It should be understood that the processor may be a central processing unit (CPU), or other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0084] In one embodiment, the processor is used to run a computer program stored in a memory to implement the following steps: collecting operating information of cloud data centers, edge nodes, and microservice instances, wherein the operating information includes: resource usage, service request type, and network topology; constructing a Markov decision process model of the resource and security joint state space based on the collected operating information, and analyzing the scheduling requirements and security risks of the microservice instances; based on cooperative game theory, calculating the resource allocation strategy of each node according to the total amount of resources, the minimum demand for microservice resources in the cloud-edge collaborative network, and the bargaining weight to perform resource allocation; using a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path, and cleaning strategy of the microservice instances; sending the optimized scheduling plan to the cloud data center and edge nodes for configuration and deployment of the microservice instances, wherein the scheduling plan includes: redundant deployment, migration path, and cleaning strategy; real-time monitoring of the operating status and security status of the microservice instances, and dynamic adjustment of the scheduling strategy.
[0085] An embodiment of the present disclosure also provides a computer-readable storage medium, on which a computer program is stored. The computer program includes program instructions. The system implemented when the program instructions are executed can refer to the various embodiments of the microservice intrusion tolerance scheduling method for cloud-edge collaborative networks disclosed in the present disclosure.
[0086] The computer-readable storage medium may be an internal storage unit of the computer device described in the aforementioned embodiment, such as a hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a SmartMedia Card (SMC), a Secure Digital (SD) card, a flash memory card, etc., provided on the computer device.
[0087] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, system, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, system, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, system, article, or system comprising the element.
[0088] The above description is only an illustration of some preferred embodiments of the present disclosure and the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A microservice intrusion tolerance scheduling method for cloud-edge collaborative networks, characterized by: include: Collect operational information of cloud data centers, edge nodes, and microservice instances, including resource usage, service request types, and network topology. Based on the collected operational information, a Markov decision process model of the resource and security joint state space is constructed, and the scheduling requirements and security risks of microservice instances are analyzed. Based on cooperative game theory, the resource allocation strategy of each node is calculated according to the total amount of resources, the minimum resource requirements of microservices in the cloud-edge collaborative network, and the bargaining weight to allocate resources; Adopting multi-agent reinforcement learning algorithms to dynamically adjust the redundant deployment, migration paths, and cleaning strategies of microservice instances; Distribute the optimized scheduling plan to the cloud data center and edge nodes for configuration and deployment of microservice instances. The scheduling plan includes redundant deployment, migration paths, and cleaning strategies. Monitor the operating status and security status of microservice instances in real time, and dynamically adjust scheduling strategies.
2. A microservice intrusion tolerance scheduling system for cloud-edge collaborative networks, characterized by: include: The cloud-edge collaborative network controller collects operational information from cloud data centers, edge nodes, and microservice instances. This operational information includes resource usage, service request types, and network topology. The cloud-edge collaborative network controller builds a Markov decision process model of the resource and security joint state space based on the collected operational information, and analyzes the scheduling requirements and security risks of microservice instances. Based on cooperative game theory, the cloud-edge collaborative network controller calculates the resource allocation strategy of each node according to the total amount of resources, the minimum resource requirements of microservices in the cloud-edge collaborative network, and the bargaining weight to allocate resources. The cloud-edge collaborative network controller uses a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path, and cleaning strategy of microservice instances; The cloud-edge collaborative network controller sends the optimized scheduling plan to the cloud data center and edge nodes for configuration and deployment of microservice instances. The scheduling plan includes redundant deployment, migration path, and cleaning strategy. The cloud-edge collaborative network controller monitors the operating status and security status of microservice instances in real time, and dynamically adjusts the scheduling strategy.
3. The microservice intrusion tolerance scheduling system according to claim 2, characterized in that: The microservice intrusion tolerance scheduling system includes: a cloud-edge collaborative network controller, a cloud data center, an edge node, and a microservice instance; The cloud-edge collaborative network controller is used to discover the network topology and the resource processing and computing capabilities of the nodes in the network; The cloud data center serves as the core computing resource in the system, responsible for processing data and complex computing tasks; The edge nodes are deployed close to the user end and are responsible for processing tasks with high real-time and low latency requirements; The microservice instance serves as the basic service unit in the microservice intrusion tolerance scheduling system, responsible for business processing, as well as migration and redundant deployment between the cloud data center and edge nodes.
4. A microservice intrusion tolerance scheduling device for cloud-edge collaborative networks, characterized in that: include: A collection unit is configured to collect operation information of cloud data centers, edge nodes, and microservice instances, wherein the operation information includes: resource usage, service request type, and network topology; The construction unit is configured to build a Markov decision process model of the resource and security joint state space based on the collected operation information, and analyze the scheduling requirements and security risks of the microservice instances; The computing unit is configured to calculate the resource allocation strategy of each node based on the total amount of resources, the minimum resource requirements of microservices in the cloud-edge collaborative network, and the bargaining weight to perform resource allocation; The adjustment unit is configured to use a multi-agent reinforcement learning algorithm to dynamically adjust the redundant deployment, migration path, and cleaning strategy of microservice instances; The delivery unit is configured to deliver the optimized scheduling plan to the cloud data center and edge nodes for configuration and deployment of microservice instances, wherein the scheduling plan includes redundant deployment, migration path, and cleaning strategy; The monitoring unit is configured to monitor the operating status and security status of the microservice instances in real time and dynamically adjust the scheduling strategy.
5. An electronic device, characterized in that: include: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the microservice intrusion tolerance scheduling method for cloud-edge collaborative networks as described in claim 1.
6. A computer-readable medium, characterized in that A computer program is stored thereon, wherein when the computer program is executed by a processor, the microservice intrusion tolerance scheduling method for a cloud-edge collaborative network as claimed in claim 1 is implemented.
Citation Information
Cited By
Collaborative data copy control method and system for cloud real-time machine learning
CN120980078A
Collaborative data replica control method and system for real-time machine learning on cloud
CN120980078B