Server network state evaluation method and system

Through encrypted data transmission and federated learning mechanisms, data security and privacy issues in traditional server network state evaluation methods are solved, and high security and high accuracy server network state evaluation is achieved.

CN120528686AActive Publication Date: 2025-08-22GUANGDONG POLYTECHNIC OF ENVIRONMENTAL PROTECTION ENG
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510851993.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-08-22
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

Traditional server network status evaluation methods rely on manual monitoring and empirical judgment, making it difficult to cover complex network environments in real time and comprehensively, and there are data security and privacy risks.

Method used

The encrypted data transmission and federated learning mechanism are adopted to encrypt the real-time running data through the first server cluster, and the state evaluation model is evaluated in the second server cluster to ensure data security and privacy, while using encrypted gradient information for model training and update.

Benefits of technology

It improves the security of server network status evaluation and the accuracy of evaluation model, protects data privacy, and improves the generalization ability of evaluation model, and is suitable for data privacy-sensitive scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528686A_ABST
    Figure CN120528686A_ABST
Patent Text Reader

Abstract

The invention relates to a server network state evaluation method and system, and relates to the technical field of server operation and maintenance. The method comprises the following steps: enabling at least one first server in a first server cluster to obtain real-time operation data; performing primary encryption on the real-time operation data to generate first encrypted data; transmitting the first encrypted data to a second server in a second server cluster based on a secure communication protocol, so that the second server determines a state evaluation result based on a trained evaluation model after performing integrity verification on the first encrypted data; wherein the training process of the evaluation model comprises the following steps: deploying the evaluation model on at least two first servers, and initializing corresponding network parameters; and carrying out local training on the initialized evaluation model based on a preset training data set, and transmitting encryption gradient information generated in the local training process to a second server, so that the second server globally updates the evaluation model based on an aggregation result of the encryption gradient information. Compared with the prior art, the privacy and security of server network state evaluation can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of server operation and maintenance technology, and in particular to a server network status assessment method and system. Background Art

[0002] With the rapid development of information technology, servers play a core role in modern computing architecture. The stability, performance, and security of their network status directly affect business continuity, user experience, and data security.

[0003] On the one hand, traditional server network status assessment methods usually rely on manual monitoring and empirical judgment, which has many limitations. For example, manual monitoring is difficult to cover complex network environments in real time and comprehensively, and is prone to missing potential problems; and empirical judgment often lacks accuracy, making it difficult to quickly locate and handle complex faults.

[0004] On the other hand, data security and privacy are crucial during server network status assessments. Because network status assessments require processing large amounts of sensitive data, including server hardware configuration information, network traffic data, and user behavior data, data leakage or tampering can pose serious risks. Summary of the Invention

[0005] Based on this, it is necessary to provide a server network status assessment method and system to address the above-mentioned data security issues.

[0006] In order to solve the above technical problems, the technical solutions of the present invention are as follows: In a first aspect, a server network status assessment method includes: Instructing at least one first server in the first server cluster to obtain real-time operation data; Encrypting the real-time operation data once to generate first encrypted data; Transmitting the first encrypted data to a second server in a second server cluster based on a secure communication protocol, so that the second server performs an integrity check on the first encrypted data and then determines a status assessment result of the first server based on a trained assessment model; The training process of the evaluation model includes: Deploying the evaluation model on at least two of the first servers and initializing corresponding network parameters; Based on a preset training data set, the initialized evaluation model is locally trained, and the encrypted gradient information generated during the local training process is transmitted to the second server, so that the second server aggregates the encrypted gradient information from at least two of the first servers and then globally updates the evaluation model based on the aggregation result of the encrypted gradient information; wherein the training data set includes second encrypted data generated based on the historical operation data of the corresponding first server.

[0007] In a second aspect, a server network status assessment system is provided, applying the method described in the first aspect, comprising: A data acquisition module, configured to enable at least one first server in the first server cluster to obtain real-time operation data; A data encryption module, configured to encrypt the real-time operation data once to generate first encrypted data; a status assessment module, configured to transmit the first encrypted data to a second server in a second server cluster based on a secure communication protocol, so that the second server performs an integrity check on the first encrypted data and then determines a status assessment result of the first server based on a trained assessment model; The training process of the evaluation model includes: Deploying the evaluation model on at least two of the first servers and initializing corresponding network parameters; Based on a preset training data set, the initialized evaluation model is locally trained, and the encrypted gradient information generated during the local training process is transmitted to the second server, so that the second server aggregates the encrypted gradient information from at least two of the first servers and then globally updates the evaluation model based on the aggregation result of the encrypted gradient information; wherein the training data set includes second encrypted data generated based on the historical operation data of the corresponding first server.

[0008] According to a third aspect, an electronic device includes: a memory for storing computer-executable instructions or computer programs; The processor is configured to implement the method of the first aspect when executing the computer-executable instructions or computer program stored in the memory.

[0009] In a fourth aspect, a computer-readable storage medium is provided, on which is stored at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by a processor to implement the method described in the first aspect.

[0010] In a fifth aspect, a computer program product comprises a computer program or computer executable instructions, wherein when the computer program or computer executable instructions are executed by a processor, the method described in the first aspect is implemented.

[0011] Compared with the prior art, the beneficial effects of the technical solution of the present invention are: The present application discloses a server network status assessment method, which encrypts the real-time running data of a first server and transmits it to a second server based on a secure communication protocol, so that a trained assessment model performs status assessment based on the first encrypted data, ensuring the security and privacy of the original data, thereby improving the security of the server network status online assessment method; at the same time, the present application applies a federated learning mechanism to the training of the evaluation model. During the training process, the first server only shares encrypted gradient information with the second server. The second server does not contact the original data during the training process of the evaluation model, and ensures that the trained evaluation model can effectively capture the data features in the first encrypted data, thereby improving the generalization ability and evaluation accuracy of the model. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 This is a flowchart of a server network status evaluation method in some embodiments of the present application.

[0013] Figure 2 This is a flowchart of the training process of the evaluation model in some embodiments of the present application.

[0014] Figure 3 This is a structural diagram of a server network status evaluation system in some embodiments of the present application.

[0015] Figure 4 This is a schematic diagram of the hardware entity of an electronic device in some embodiments of the present application. DETAILED DESCRIPTION

[0016] The terms "first", "second" etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable in appropriate circumstances, and this is merely a way of distinguishing the objects of the same attribute when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment. The term "determine" widely covers various actions, may include obtaining, calculating, computing, processing, deriving, investigating, searching (for example, searching in a table, a database or other data structure), ascertaining and similar actions, may also include receiving (for example, receiving information), accessing (for example, accessing data in a memory) and similar actions, may also include generating, creating, establishing and similar actions, and parsing, selecting, selecting and similar actions etc. The relevant definitions of other terms will be provided in the following description.

[0017] It should be noted that when an element is considered to be "connected" to another element, it can be directly connected to the other element or connected to the other element through an intervening element. In addition, the "connection" in the following embodiments should be understood as "electrical connection", "communication connection", etc., if there is transmission of electrical signals or data between the connected objects.

[0018] It should be emphasized that the acquisition, transmission, storage, use, and processing of data in the technical solutions of the embodiments of this application comply with the relevant provisions of national laws and regulations.

[0019] In the embodiments of the present application, certain software, components, models and other existing solutions in the industry may be mentioned. They should be regarded as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of the present application, but it does not mean that the applicant has or will necessarily use the solution.

[0020] The accompanying drawings are for illustrative purposes only and are not to be construed as limiting this patent; In order to better illustrate this embodiment, some parts in the drawings may be omitted, enlarged, or reduced, and do not represent the actual product size; It is understandable to those skilled in the art that some well-known structures and descriptions thereof may be omitted in the drawings.

[0021] The technical solution of the present invention is further described below with reference to the accompanying drawings and embodiments.

[0022] FIG1 shows a flow chart of a server network status assessment method provided by some embodiments of the present application, including: S110, instructing at least one first server in the first server cluster to obtain real-time operation data; S120, encrypting the real-time operation data once to generate first encrypted data; S130. Based on a secure communication protocol, transmit the first encrypted data to a second server in a second server cluster, so that the second server determines a status evaluation result of the first server based on a trained evaluation model after performing an integrity check on the first encrypted data.

[0023] Referring to FIG2 , the training process of the evaluation model includes: S210: deploy the evaluation model (referred to as a “local model”) on at least two of the first servers and initialize corresponding network parameters; S220: Locally train the initialized evaluation model based on a preset training data set, and transmit encrypted gradient information generated during the local training process to the second server; wherein the training data set includes second encrypted data generated based on historical operating data of the corresponding first server; S230: After aggregating the encrypted gradient information from at least two of the first servers, the second server globally updates the evaluation model based on the aggregation result of the encrypted gradient information.

[0024] Therefore, by applying the federated learning mechanism to the server network status evaluation, combined with data encryption methods and secure communication protocols, each first server only shares encrypted data (first encrypted data and encrypted gradient information) to the second server, which can fully utilize the advantages of distributed data while protecting data privacy, effectively protecting the security and privacy of the server network status data. During the training and application of the evaluation model, the second server side will not touch the original operation data throughout the process, and the original data remains invisible to the second server, thereby improving the security of the server network status online evaluation method. At the same time, it can also improve the generalization ability and accuracy of the evaluation model, which is particularly suitable for scenarios with sensitive data privacy, such as medical data, financial data or user personal information.

[0025] Federated learning is a distributed learning method that aims to train a shared machine learning model or neural network model on multiple clients (i.e., the first server in this application). In an embodiment of the present application, each client only uses local data for model training, and does not share the data with other clients or a central server (i.e., the second server in this application). It should be emphasized that in traditional centralized learning, all data is usually concentrated on a central server, and then model training is performed on that server. However, in federated learning, the data is retained on each client, and each client only calculates update information related to model training, rather than directly sharing data.

[0026] First, regarding step S110, the real-time operating data may include hardware performance data (such as CPU utilization and memory usage), energy consumption and temperature data (such as core temperature and overall power consumption), network load data (such as packet throughput, network latency, and transmission error rate), or task load data collected in real time from the first server. It may also be a combination of these types of data, so that the evaluation model can evaluate the current status and future trends of the first server based on multi-dimensional information. Exemplarily, the hardware performance data includes CPU utilization and memory usage.

[0027] For example, a real-time monitoring service, such as Prometheus or Nagios, may be deployed to continuously monitor the operating status of the first server and collect the latest data in real time.

[0028] In some specific implementation processes, the collected real-time operation data needs to be preprocessed, including removing invalid / abnormal data, data standardization, statistical feature extraction, etc.

[0029] For example, the operation of removing invalid / abnormal data may include filtering out data with CPU utilization exceeding 100% or below 0%, and data with negative network latency. If some data points are missing, they can be filled using interpolation or the average value of adjacent data points.

[0030] For data normalization operations, for example, normalizing data such as CPU utilization and memory usage to the range [0, 1], the process can be expressed as:

[0031] For the operation of statistical feature extraction, for example, it is achieved by extracting statistical features such as the average value, standard deviation, maximum value and minimum value of the sliding window from the time series data.

[0032] Furthermore, the preprocessed data is converted into a consistency feature matrix for evaluating the training of the model.

[0033] Next, in step S130, the status assessment results can include not only current performance indicators such as CPU utilization, memory usage, and network latency, but also failure risk predictions and resource demand forecasts, providing comprehensive and accurate decision-making for operations personnel. The assessment model is implemented using a neural network model, particularly one that can capture time series features.

[0034] Exemplarily, the status assessment results may include performance indicators, such as CPU utilization, memory occupancy, network latency, etc.; they may also include fault risk prediction results, such as hardware failure probability, network anomaly risk, etc.; they may also include resource demand prediction results, such as resource demand predictions for CPU, memory, network bandwidth, etc. in the future.

[0035] For example, an LSTM (Long Short-Term Memory) model can be used to evaluate the first server. LSTM is a special type of recurrent neural network (RNN) that effectively processes long-term dependencies in time series data and is well-suited for evaluating server network status. The output layer is used to output evaluation results, such as a server's performance score or failure probability.

[0036] Next, the above LSTM model is explained.

[0037] An LSTM model typically consists of an input layer, an LSTM layer, a fully connected layer, and an output layer.

[0038] The input dimension of the input layer is the dimension of the first encrypted data. The LSTM layer contains multiple LSTM units to capture dynamic changes in time series data. The fully connected layer is used to map the output of the LSTM layer to the dimensions of evaluation indicators (such as performance indicators and failure risks). The output layer is used to output status evaluation results, such as the performance score or failure probability of the first server.

[0039] As a non-limiting example, taking LSTM as the evaluation model, its local training process is as follows: Initialize model parameters: Randomly initialize the weights and biases of the LSTM layer. Forward propagation: Pass the first encrypted data through the LSTM layer and the fully connected layer to calculate the output. Loss calculation: Use the mean squared error (MSE) or cross-entropy loss function to calculate the difference between the model output and the true label. Backward propagation: Calculate the gradient through the backpropagation algorithm and use an optimizer (such as Adam) to update the model parameters. Cross-validation: Use cross-validation to evaluate model performance and avoid overfitting.

[0040] In addition, in the embodiments of the present application, the secure communication protocol adopted refers to the protocol used to ensure the security of network communications, which is intended to prevent unauthorized access, eavesdropping, tampering and data leakage, and is used to provide data integrity protection to ensure that data is not tampered with during transmission, such as the TLS / SSL protocol.

[0041] Furthermore, regarding step S220, the second encrypted data should be encrypted in the same manner as the first encrypted data, so that the evaluation model can learn effective data features.

[0042] In some embodiments of the present application, step S120 may include steps S1201 to S1202.

[0043] S1201. Instruct the first server to obtain a symmetric encryption key from a trusted HSM (Hardware Security Module); wherein the symmetric encryption key is generated by a KMS (Key Management Service).

[0044] S1202: Based on a symmetric encryption algorithm, the first server uses the symmetric encryption key to encrypt the real-time operation data to generate the first encrypted data.

[0045] For example, AES-256 is used to encrypt the real-time operation data to ensure confidentiality during transmission. AES-256 is a symmetric encryption algorithm that uses a 256-bit key length, and the same key is used for both encryption and decryption processes.

[0046] It is understood that in the embodiments of the present application, the symmetric encryption algorithm may also use any one of DES, 3DES, TDEA, Blowfish, RC2, RC4, and RC5. In the embodiments of this application, a KMS is a service used to manage and protect encryption keys. It is typically an independent security service that provides key generation, storage, distribution, rotation, and destruction, ensuring key security and availability for protecting data and applications. A KMS can use an HSM to store keys, thereby ensuring key security. An HSM is a physical device that provides high-strength encryption and key management capabilities.

[0047] In some embodiments of the present application, a first digital certificate is deployed on the first server, and a second digital certificate is deployed on the second server; in step S130, transmitting the first encrypted data to the second server in the second server cluster includes steps S1311 to S1313.

[0048] S1311. Based on a two-way authentication mechanism, when the first server verifies and passes the second digital certificate of the second server, and the second server verifies and passes the first digital certificate of the first server, a session key is generated.

[0049] For example, the verification process includes checking the validity period of the certificate, the signature of the certificate authority, and whether the server identity information in the certificate matches the target server. Certificate verification ensures the legitimacy of the identities of both communicating parties and prevents man-in-the-middle attacks.

[0050] S1312. Use the session key to re-encrypt the first encrypted data on the first server to generate second encrypted data.

[0051] S1313. Transmit the second encrypted data to the second server based on a secure communication protocol, so that the second server decrypts the second encrypted data based on the session key to obtain the first encrypted data.

[0052] In some specific implementations, the first server, acting as a client, initiates a TLS / SSL connection request to the second server. After receiving the connection request, the second server sends its second digital certificate to the client. The first server uses the CA's public key to verify the authenticity of the second server's second digital certificate. After verification, the first server sends its first digital certificate to the second server. The second server uses the CA's public key to verify the authenticity of the first server's first digital certificate, ensuring the legitimacy of the client's identity. After the certificates of both parties are verified, the first and second servers negotiate a session key using the TLS / SSL protocol to encrypt and decrypt data in this connection. The session key negotiation process is based on an asymmetric encryption algorithm to ensure the security of the key exchange. The first server uses the negotiated session key to re-encrypt the encrypted data (i.e., the first encrypted data) and transmits it to the second server via the TLS / SSL channel. The second server uses the same session key to decrypt the received data, restoring the original first encrypted data.

[0053] Furthermore, the transmission of the encrypted gradient information in step S220 can also adopt a similar method, where the first server uses the session key to encrypt the encrypted gradient information (recorded as "second encrypted gradient information") and then transmits it to the second server. The second server then uses the session key to decrypt the second encrypted gradient information and restore the original encrypted gradient information.

[0054] In some embodiments of the present application, in order to ensure the reliability and integrity of the first encrypted data received by the second server, in step S130, the integrity verification process may include steps S1321 to S1323.

[0055] S1321. Generate a first digest value for the received first encrypted data on the second server based on a hash algorithm.

[0056] Among them, the hash algorithm (Hash), also known as the digest algorithm (Digest), can perform a hash operation on any set of input data to obtain an output digest of a fixed length. For the hash algorithm, the same input will definitely produce the same output, and different inputs will most likely produce different outputs.

[0057] As a non-limiting example, SHA-256 is used in step S1321 to generate a first digest value based on the first encrypted data. SHA-256 is a one-way encryption algorithm that can convert data of any length into a fixed-length (256-bit) digest value. The generated digest value is highly unique. Even a single byte change in the data will result in a completely different digest value.

[0058] S1322. Compare the first digest value with a second digest value received from the first server to generate a comparison result; wherein the second digest value is generated by the first server based on a hash operation on the first encrypted data.

[0059] In some specific implementations, the first server divides the first encrypted data to be sent into data blocks of a fixed size (such as 512). ; Use the SHA-256 algorithm to generate the second digest value for each data block After the data block Send to the second server together.

[0060] S1323. When the comparison result shows that the first digest value is consistent with the second digest value, it is deemed that the first encrypted data received by the second server passes the integrity check.

[0061] Specifically, the digest values ​​(256-bit binary numbers) generated using the SHA-256 algorithm are compared bit by bit. If the two digest values ​​match, we can be highly confident that the data has not been tampered with during transmission. If the digest values ​​do not match, the second server discards the data and sends an error notification to the first server, requesting recollection and retransmission of the data. By comparing the digest values ​​bit by bit, the reliability of the comparison results is guaranteed.

[0062] Therefore, by comparing the first digest value with the second digest value received from the first server, if the two digest values ​​match, it indicates that the data has not been tampered with during transmission, and the data integrity is guaranteed. If the digests do not match, an error handling mechanism can be triggered, such as discarding the data and re-requesting data transmission, thus ensuring data reliability, security, and integrity. With data integrity and security guaranteed, the assessment model determines the status assessment result of the first server based on the verified data, which is more accurate.

[0063] In some embodiments of the present application, step S230 may include steps S2310 to S2330.

[0064] S2310. The second server receives the encrypted gradient information and decrypts it using KMS to obtain decrypted first gradient information. The encrypted gradient information is obtained by the first server encrypting the first gradient information calculated during the local training process.

[0065] It should be understood that gradient information is the derivative of the model parameters, indicating the direction and magnitude in which the model parameters need to be adjusted during the training process.

[0066] S2320: Aggregate the first gradient information from at least two of the first servers to generate an aggregation result.

[0067] For example, the aggregation process may adopt weighted averaging or other optimization algorithms to ensure that the global model can integrate the training results of each local model.

[0068] S2330. Globally update the evaluation model according to the aggregation result, and transmit the global network parameters of the evaluation model to the first server in the next round of local training to initialize the evaluation model deployed on the first server.

[0069] For example, the second server receives the gradient information (denoted as and ) is weighted averaged to generate the aggregated result. The update process of the global network parameters can be expressed as:

[0070] Where, Represents the learning rate. Indicates the global network parameters before update. Calculated by the first server A based on its local data, Calculated by the first server B based on its local data.

[0071] It should be noted that raw data often contains sensitive information, and directly sharing this data may lead to privacy leakage. By sharing only the gradient information, the direct transmission of raw data can be avoided, thereby protecting data privacy.

[0072] It should also be noted that, similar to the transmission process of encrypted gradient information, the network parameters after the global update in step S2303 are transmitted to the first server participating in the next round of local training by the second server using a two-way authentication mechanism and negotiating to establish a session key at the beginning of the next round of local training.

[0073] Therefore, even if the encrypted gradient information or parameter information is intercepted during transmission, it is difficult for an attacker to restore the original data from this information because the encrypted gradient information or updated parameter information is calculated and encrypted.

[0074] It should be noted that in step S2330, by transmitting the globally updated network parameters to the first server for initializing the network parameters of the evaluation model deployed on the first server, the convergence speed of the local model during local training can be improved.

[0075] In some implementations, the performance of the evaluation model is regularly evaluated to check the accuracy and reliability of the status evaluation results. If model performance deteriorates, retraining or optimization of the model is triggered. Automatic hyperparameter tuning techniques (such as Bayesian optimization) are used to dynamically adjust hyperparameters based on model performance to improve model performance and generalization.

[0076] In some embodiments of the present application, the method may further include the following steps: S140. Adjust the resource allocation strategy of the first server according to the status evaluation result; wherein the resource allocation strategy includes adjusting at least one of the CPU, GPU, memory, storage, network and task load of the first server.

[0077] For example, when the status assessment results indicate that a first server has an excessively high task load, such as a CPU-intensive task (which may be manifested by a CPU utilization rate consistently exceeding 80%), some of the CPU-intensive tasks are migrated to other servers with lower CPU utilization. For example, a load balancing algorithm is used to allocate tasks to servers with a CPU utilization rate below 50%. If the task is memory-intensive (which may be manifested by a memory usage rate consistently exceeding 90%), the memory allocation strategy is adjusted, for example, by migrating some memory-intensive tasks to the first server with lower memory utilization, or by using memory compression technology to free up some memory.

[0078] Exemplarily, when the status assessment result shows that the storage capacity of a certain first server is insufficient, an elastic scaling strategy is executed on the first server to improve server performance.

[0079] For example, if the status assessment results indicate that a particular first server is at risk of hardware failure (e.g., a hard drive failure probability exceeding 10%), critical tasks on that first server will be preemptively migrated to other healthy first servers within the cluster to prevent data loss or service interruption. If the status assessment results indicate that a particular server has excessively high network latency or a risk of network anomalies (e.g., a packet loss rate exceeding 5%), network configuration adjustments will be made, such as reallocating network bandwidth or switching to an alternate network path.

[0080] For example, if the status assessment results indicate that a server will face high load in the near future, the system will allocate more CPU and memory resources to it in advance to ensure stable service operation. If the status assessment results indicate that the load on a first server is low (e.g., CPU utilization is less than 20%), the system will automatically reduce its resource allocation, such as reducing the number of CPU cores or memory allocation, to save energy.

[0081] Some embodiments of the present application further provide a server network status evaluation system, referring to FIG3 , including: The data acquisition module 601 is configured to enable at least one first server in the first server cluster to obtain real-time operation data; The data encryption module 602 is used to encrypt the real-time operation data once to generate first encrypted data; a status assessment module 603 configured to transmit the first encrypted data to a second server in a second server cluster based on a secure communication protocol, so that the second server performs an integrity check on the first encrypted data and then determines a status assessment result of the first server based on a trained assessment model; The training process of the evaluation model includes: Deploying the evaluation model on at least two of the first servers and initializing corresponding network parameters; Based on a preset training data set, the initialized evaluation model is locally trained, and the encrypted gradient information generated during the local training process is transmitted to the second server, so that the second server aggregates the encrypted gradient information from at least two of the first servers and then globally updates the evaluation model based on the aggregation result of the encrypted gradient information; wherein the training data set includes second encrypted data generated based on the historical operation data of the corresponding first server.

[0082] Some embodiments of the present application also provide a computer-readable storage medium, on which is stored at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by a processor, so that the processor performs some or all steps of the method provided in other embodiments of the present application.

[0083] It is understood that the storage medium may be transient or non-transient. Exemplarily, the storage medium includes, but is not limited to, a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, among other media capable of storing program code.

[0084] Exemplarily, the processor may be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP), an application specific integrated circuit (ASIC), or a field programmable gate array (FPGA).

[0085] Exemplarily, the read-only memory includes but is not limited to MASK ROM, PROM (Programmable ROM), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), Flash, etc.

[0086] Exemplarily, the random access memory includes but is not limited to DRAM (Dynamic Random Access Memory), SRAM (Static Random Access Memory), SDRAM (Synchronous Dynamic Random Access Memory), DDR SDRAM (Double Data Rate Synchronous Dynamic Random Access Memory), ESDRAM (Enhanced SDRAM), SLDRAM (Synchronous-Link DRAM), RDRAM (Rambus Dynamic Random Access Memory), etc.

[0087] In some examples, a computer program product is provided, which can be implemented in hardware, software, or a combination thereof. As a non-limiting example, the computer program product can be embodied as the storage medium, or as a software product, such as an SDK (Software Development Kit).

[0088] As a non-limiting example, a computer program product is provided, comprising a computer program or computer-executable instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer program or computer-executable instructions from the computer-readable storage medium and executes the computer-executable instructions, causing the electronic device to perform some or all of the steps of the method described in the embodiments of the present application.

[0089] In some examples, a computer program is provided, comprising a computer-readable code. When the computer-readable code is run in a computer device, a processor in the computer device executes the code to implement part or all of the steps in the method.

[0090] In some embodiments of the present application, an electronic device is also proposed, including a memory and a processor, wherein the memory stores at least one instruction, at least one program, code set or instruction set, and when the processor executes the at least one instruction, at least one program, code set or instruction set, it implements part or all of the steps of the method described in other embodiments of the present application.

[0091] In some examples, a hardware entity of the electronic device is provided, see Figure 4, including: a processor, a memory and a communication interface; wherein the processor generally controls the overall operation of the electronic device; the communication interface is used to enable the electronic device to communicate with other terminals or servers through a network; the memory is configured to store instructions and applications executable by the processor, and can also cache data to be processed or processed by the processor and various modules in the electronic device (including but not limited to image data, audio data, voice communication data and video communication data), and can be implemented by flash memory (FLASH), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM) or random access memory (RAM).

[0092] A processor may include one or more processing elements. Thus, a processor may include one or more integrated circuits (ICs) configured to perform the functions of the processor. Furthermore, each integrated circuit may include circuits (e.g., a first circuit, a second circuit, and other circuits) configured to perform the functions of the processor.

[0093] Furthermore, data may be transmitted between the processor, the communication interface and the memory via a bus, which may include any number of interconnected buses and bridges, connecting various circuits of one or more processors and memories.

[0094] The same or similar reference numerals correspond to the same or similar components; The terms used in the drawings to describe positional relationships are for illustrative purposes only and are not to be construed as limiting the present application. It should be noted that, unless there is any conflict, the embodiments and features in the embodiments of this application can be combined with each other.

[0095] In different specific implementations, the method or system described in this application can be implemented in software, hardware or a combination thereof. In addition, the order of the steps of the method can be changed, and various elements can be added, reordered, combined, omitted, modified, etc.

[0096] Obviously, the above embodiments of the present application are merely examples for clearly illustrating the present application, and are not intended to limit the implementation methods of the present application, and are not intended to limit the present application. For those skilled in the art, other different forms of changes or modifications can be made based on the above description. Each discrete structural / functional module or unit can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part, and the structure and function of the discrete components can be implemented as a combined structure or component. It is not necessary and impossible to enumerate all the implementation methods here. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present application should be included in the scope of protection of the claims of the present application.

Claims

1. A server network status evaluation method, characterized in that: include: Instructing at least one first server in the first server cluster to obtain real-time operation data; Encrypting the real-time operation data once to generate first encrypted data; Transmitting the first encrypted data to a second server in a second server cluster based on a secure communication protocol, so that the second server performs an integrity check on the first encrypted data and then determines a status assessment result of the first server based on a trained assessment model; The training process of the evaluation model includes: Deploying the evaluation model on at least two of the first servers and initializing corresponding network parameters; Based on a preset training data set, the initialized evaluation model is locally trained, and the encrypted gradient information generated during the local training process is transmitted to the second server, so that the second server aggregates the encrypted gradient information from at least two of the first servers and then globally updates the evaluation model based on the aggregation result of the encrypted gradient information; wherein the training data set includes second encrypted data generated based on the historical operation data of the corresponding first server.

2. A server network status evaluation method according to claim 1, characterized in that: The encrypting the real-time operation data once includes: Instructing the first server to obtain a symmetric encryption key from a trusted HSM, wherein the symmetric encryption key is generated by a KMS; Based on a symmetric encryption algorithm, the first server uses the symmetric encryption key to encrypt the real-time operation data to generate the first encrypted data.

3. A server network status evaluation method according to claim 2, characterized in that: The globally updating the evaluation model based on the aggregated encrypted gradient information includes: The second server receives the encrypted gradient information and decrypts it using the KMS to obtain decrypted first gradient information; the encrypted gradient information is obtained by the first server encrypting the first gradient information calculated during the local training process; aggregating the first gradient information from at least two of the first servers to generate an aggregation result; The evaluation model is globally updated according to the aggregation result, and the global network parameters of the evaluation model are transmitted to the first server in the next round of local training to initialize the evaluation model deployed on the first server.

4. A server network status evaluation method according to claim 2, characterized in that: The integrity verification process of the first encrypted data by the second server includes: generating, at the second server, a first digest value for the received first encrypted data based on a hash algorithm; Comparing the first digest value with a second digest value received from the first server to generate a comparison result; wherein the second digest value is generated by the first server based on a hash operation on the first encrypted data; When the comparison result shows that the first digest value is consistent with the second digest value, it is deemed that the first encrypted data received by the second server passes the integrity check.

5. A server network status evaluation method according to any one of claims 1 to 4, characterized in that: A first digital certificate is deployed on the first server, and a second digital certificate is deployed on the second server; The transmitting the first encrypted data to the second server in the second server cluster includes: Based on a two-way authentication mechanism, when the first server verifies and passes the second digital certificate of the second server, and the second server verifies and passes the first digital certificate of the first server, generating a session key; performing secondary encryption on the first encrypted data using the session key at the first server to generate second encrypted data; The second encrypted data is transmitted to the second server based on a secure communication protocol, so that the second server decrypts the second encrypted data based on the session key to obtain the first encrypted data.

6. A server network status evaluation method according to claim 1, characterized in that: Also includes: Adjusting the resource allocation strategy of the first server according to the status assessment result; wherein the resource allocation strategy includes adjusting at least one of the CPU, GPU, memory, storage, network and task load of the first server.

7. A server network status assessment system, applying the method according to any one of claims 1 to 6, characterized in that: include: A data acquisition module, configured to enable at least one first server in the first server cluster to obtain real-time operation data; A data encryption module, configured to encrypt the real-time operation data once to generate first encrypted data; a status assessment module, configured to transmit the first encrypted data to a second server in a second server cluster based on a secure communication protocol, so that the second server performs an integrity check on the first encrypted data and then determines a status assessment result of the first server based on a trained assessment model; The training process of the evaluation model includes: Deploying the evaluation model on at least two of the first servers and initializing corresponding network parameters; Based on a preset training data set, the initialized evaluation model is locally trained, and the encrypted gradient information generated during the local training process is transmitted to the second server, so that the second server aggregates the encrypted gradient information from at least two of the first servers and then globally updates the evaluation model based on the aggregation result of the encrypted gradient information; wherein the training data set includes second encrypted data generated based on the historical operation data of the corresponding first server.

8. An electronic device, characterized in that: include: a memory for storing computer-executable instructions or computer programs; The processor is configured to implement the method according to any one of claims 1 to 6 when executing the computer-executable instructions or computer program stored in the memory.

9. A computer-readable storage medium, characterized in that The storage medium stores at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by the processor to implement the method according to any one of claims 1 to 6.

10. A computer program product comprising a computer program or computer executable instructions, characterized in that When the computer program or computer executable instructions are executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Federal learning method for privacy protection based on SM9 algorithm

    CN115442050A

  • Performance evaluation method and device, server and storage medium

    CN117472719A

  • Data processing method and device, computer equipment and storage medium

    CN118468353A

  • Server parameter optimization method and device

    CN119135533A

  • Server health state diagnosis method based on GAT-LP algorithm

    CN120086105A