Enhanced local security information model construction method

By building a local security information model of the BCube network, evaluating the security status of the server and proposing a routing algorithm, the reliability problem of the data center network in failure scenarios is solved, a higher transmission success rate and shorter path length are achieved, and the stability and security of the network are enhanced.

CN120639729APending Publication Date: 2025-09-12QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510901011.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-01
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

How to improve security, stability, and reliability in data center networks, especially maintaining the reliability and stability of network communications when both servers and links fail simultaneously.

Method used

An enhanced local security information model is constructed. By defining the BCube network structure, a set of neighbor servers of fault-free servers is created. Based on these sets, a local security information model is constructed to evaluate the security level of the server. The security status of the server is determined using predefined evaluation criteria, and a routing algorithm based on this model is proposed to deal with fault scenarios.

Benefits of technology

In the event of failed servers and links, the transmission success rate is improved, the average path length is reduced, the shortest path rate is increased, and the security and reliability of the network are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639729A_ABST
    Figure CN120639729A_ABST
Patent Text Reader

Abstract

The invention discloses an enhanced local security information model construction method, belongs to the technical field of data centers, and aims to solve the technical problem of how to improve the security, stability and reliability of a data center network. Comprising the following steps: defining a BCube network structure, creating a neighbor server set of a fault-free server based on a security state of a neighbor server corresponding to the fault-free server, and constructing a local security information model, the local security information model analyzes the state of the fault-free server in a neighbor server in the minimum sub-L-BC of the fault-free server, performs security assessment on the fault-free server, and performs security assessment on the fault-free server when performing security assessment on the fault-free server; and according to the relationship between the minimum sub-L-BC between the source server and the target server and a predefined maximum sub-L-BC network, performing evaluation through a predefined evaluation criterion, and determining the security level of the server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data centers, and in particular to an enhanced local security information model construction method. Background Art

[0002] Data centers are hubs for data transmission, computing, and storage, and they also house a variety of software and hardware resources and critical business systems. A data center network (DCN) is a network within a data center that connects a large number of servers through links and switches. Currently, DCN architectures are primarily categorized into two types: switch-centric and server-centric. Switch-centric DCNs typically employ a tree topology, but the total bandwidth of the DCN is limited by the available bandwidth of the root node, which can easily lead to system performance bottlenecks. Furthermore, as the scale of DCNs increases, the tree topology becomes increasingly dependent on high-performance switches, significantly increasing costs. To address these issues, a server-centric DCN architecture has emerged. This architecture offloads compute-intensive tasks, such as routing, from switches to servers, leaving switches solely responsible for basic connectivity. This significantly reduces deployment costs while improving network scalability and fault tolerance.

[0003] BCube is a typical server-centric data center network architecture. Built on a hypercube topology using multi-port servers and inexpensive commodity switches, BCube ensures high network connectivity, low network diameter, and exceptional reliability. This architecture supports multipath data transmission and load balancing, effectively avoiding link bottlenecks and improving overall data center network reliability. In the event of server or link failures, BCube mitigates performance degradation, maintaining service availability. With its excellent fault tolerance, high load balancing capabilities, and low network diameter, BCube has become one of the preferred infrastructures for building large-scale data center networks.

[0004] However, as networks continue to expand, server and link failures have become commonplace. Maintaining the reliability and stability of network communications in the face of simultaneous server and link failures is a key challenge. The design of fault-tolerant mechanisms is directly related to the reliability, security, and service continuity of data center networks. Therefore, research on fault-tolerant routing strategies for complex failure scenarios has both theoretical and practical significance.

[0005] How to improve the security, stability and reliability of data center networks is a technical problem that needs to be solved. Summary of the Invention

[0006] The technical task of the present invention is to address the above shortcomings and provide an enhanced local security information model construction method to solve the technical problem of how to improve the security, stability and reliability of data center networks.

[0007] The present invention provides an enhanced local security information model construction method for performing security assessment on servers in a BCube network, comprising the following steps:

[0008] Define the BCube network structure. The BCube network is a server-centric data center network, including servers, switches, and links between servers and switches. By making all switches in the BCube transparent, the logical structure is derived and represented as L-BC. The local network structure in the L-BC is defined as a sub-L-BC. The sub-L-BC is a subgraph of the L-BC. The minimum local network structure that contains a specific set of servers in the sub-L-BC is defined as the minimum sub-L-BC, and the minimum sub-L-BC is represented as MinS.

[0009] For each fault-free server in the smallest sub-L-BC, a neighbor server set of the fault-free server is created based on the security status of the neighbor servers corresponding to the fault-free server. For a fault-free server m, there are three neighbor server sets, namely A(m), T(m) and F(m). A(m) is used to store all neighbor servers of the fault-free server in the smallest sub-L-BC, T(m) is used to store all fault-free neighbor servers of the fault-free server in the smallest sub-L-BC, and F(m) is used to store all faulty neighbor servers of the fault-free server in the smallest sub-L-BC.

[0010] A local security information model is constructed. The local security information model analyzes the status of neighbor servers of the fault-free server in its smallest sub-L-BC and performs a security assessment on the fault-free server. When performing the security assessment on the fault-free server, the model performs an assessment based on the relationship between the smallest sub-L-BC and the predefined largest sub-L-BC between the source server and the target server and predefined assessment criteria, and determines the security level of the server.

[0011] Preferably, for the BCube network, its network dimension is the total recursive level in the construction process;

[0012] BCube c,d The number of ports of each switch in BCube is c, and the dimension of the network is d, where c≥2, d≥0. c,d In the BCube, the dimension of the switch is determined according to its level in the recursive construction process. If a switch is located in the BCube c,d The i-th layer of , then the switch is an i-dimensional switch, i∈[0,d];

[0013] BCube c,0 It consists of a c-port 0-dimensional switch and c servers connected to the switch. For d ≥ 1, BCube c,d By c d A c-port d-dimensional switch and c BCubes connected to the switch c,d-1 Composition, a BCube c,d Including c d+1 servers and (d+1)c d c-port switch.

[0014] As a preference, for a given integer c≥2, d≥0, BCube c,d The definitions of server address, switch address, and link address are as follows:

[0015] Definition 1: The server address is represented by r d r d-1 …r0, where r u ∈[0,c-1],u∈[0,d];

[0016] Definition 2: The address of the switch is expressed as <n;z d-1 z d-2 …z0>, where z v ∈[0,c-1], v∈[0,d-1], n∈[0,d], and n represents the dimension where the switch is located;

[0017] Definition 3: The link directly connecting the switch and the server is represented as follows:

[0018] ( <n;z d-1 z d-2 …z0>,r d r d-1 …r0),

[0019] Among them, z d-1 z d-2 …z0=r d r d-1 …r n+1 r n-1 …r0.

[0020] Preferably, for a given integer c≥2, d≥0, L-BC c,d The server address is defined as follows:

[0021] Definition 1: The server address is represented by r d r d-1 …r0, where r u ∈[0,c-1],u∈[0,d];

[0022] Definition 2: The link between two servers is represented by (r d r d-1 …r0,r′ d r′ d-1 …r′0, where there exists an integer u∈[0,d] such that r u ≠r′ u , and for any v∈[0,d]\{u}, such that r v =r′ v .

[0023] As a preference, for any subgraph If S and L-BC c,d′ If isomorphic and d′≤d, then S is L-BC c,d A sub-L-BC.

[0024] Preferably, for the local security information model, the evaluation criteria include the following:

[0025] Criterion 1: When the minimum sub-L-BC between the source server and the target server is included in a certain maximum safety sub-L-BC, the safety level of the fault-free server is evaluated according to the first concept;

[0026] Criterion 2: When the minimum sub-L-BC between the source server and the target server is not included in a certain maximum safety sub-L-BC, the safety level of the fault-free server is evaluated according to the second concept;

[0027] The first concept is: for a given integer c≥2 and d≥0, L-BC c,d The security level of a fault-free server m in the network within MinS is as follows:

[0028] Case 1: If F(m) in MinS is greater than m in MinS, then m is defined as an enhanced locally completely unsafe server in MinS, abbreviated as ELCUS;

[0029] Case 2: If the neighbor server of m's MinS satisfies any of the following conditions, then m is defined as an enhanced locally unsafe server, or ELUS, in MinS:

[0030] Condition 1: m has at least two neighbor servers in F(m) in MinS;

[0031] Condition 2: There are at least three neighbor servers in the MinS of m, which may all be from F(m), or all are ELUS, or a mixture of these two types of servers.

[0032] Case 3: If m does not satisfy the above two conditions, then m is considered as an enhanced local security server in MinS, referred to as ELSS;

[0033] Case 4: If m is an ELUS, it can be further classified according to the situation of its neighbor servers in MinS. When further classified, if m has at least one neighbor server in MinS that is an ELSS, it is called an enhanced local low-insecurity server, abbreviated as ELLUS; otherwise, it is called an enhanced local high-insecurity server, abbreviated as ELHUS;

[0034] The second concept is: for a given integer c≥2 and d≥0, L-BC c,d The security level of a fault-free server m in MinS is as follows:

[0035] If T(m) in MinS is empty, the server is a completely insecure server;

[0036] If F(m) in MinS is not empty, the server is a level 1 unsafe server;

[0037] If there are at least two level 1 unsafe neighbor servers in m's MinS, then the server is a level 2 unsafe server; if there are at least three level 1 and level 2 unsafe neighbor servers in m's MinS, then the server is also a level 2 unsafe server;

[0038] Otherwise, m is safe;

[0039] In the first concept, if a sub-L-BC contains at least one ELSS, the sub-L-BC is called a safe sub-L-BC, otherwise, the sub-L-BC is called a completely unsafe sub-L-BC;

[0040] Among them, a d-dimensional L-BC c,d It is called the maximum security sub-L-BC, represented by the symbol MSSL, and meets the following two conditions at the same time:

[0041] Condition 1: L-BC c,d It is a safe sub-L-BC;

[0042] Condition 2: Any L-BC that correctly contains it c,d′ are all completely unsafe, where d′>d.

[0043] An enhanced local security information model construction method of the present invention has the following advantages: it can solve the situation where both faulty servers and faulty links exist in BCube, overcoming the shortcomings of security information models that can only solve faulty servers or only solve faulty links. The routing algorithm proposed based on the enhanced local security information model has good performance in terms of transmission success rate, average path length and shortest path rate. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0045] The present invention will be further described below with reference to the accompanying drawings.

[0046] Figure 1 This is a flowchart of an enhanced local security information model construction method according to Example 1;

[0047] Figure 2 BCube in an enhanced local security information model construction method in Example 1 3,2 Schematic diagram of the structure;

[0048] Figure 3 The network model L-BC required in the enhanced local security information model construction method of Example 1 3,2 The structural diagram of

[0049] Figure 4 The network model required in the enhanced local security information model construction method of Example 1 has 10 faulty servers and 10 faulty links L-BC 3,2 The structural diagram of

[0050] Figure 5 The L-BC of the faulty device in the enhanced local security information model construction method of Example 1 is c,d Schematic diagram of experimental results of transmission success rate;

[0051] Figure 6 In the embodiment 1, an enhanced local security information model construction method is used in the L-BC of the faulty device. c,d Schematic diagram of experimental results of average path length in ;

[0052] Figure 7 In the embodiment 1, an enhanced local security information model construction method is used in the L-BC of the faulty device. c,dSchematic diagram of experimental data of the shortest path rate in . DETAILED DESCRIPTION

[0053] The present invention will be further described below with reference to the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it. However, the embodiments given are not intended to limit the present invention. Unless there is a conflict, the embodiments of the present invention and the technical features in the embodiments may be combined with each other.

[0054] The embodiment of the present invention provides an enhanced local security information model construction method for solving the technical problem of how to improve the security, stability and reliability of a data center network.

[0055] Example 1:

[0056] The present invention provides an enhanced local security information model construction method for performing security assessment on servers in a BCube network, comprising three steps: defining a BCube network structure, defining a set of neighboring servers, and constructing a local security information model.

[0057] Step S100: Define the BCube network structure. The BCube network is a server-centric data center network, including servers, switches, and links between servers and switches. The logical structure is derived by making all switches in the BCube transparent. The logical structure is represented as L-BC. The local network structure in the L-BC is defined as a sub-L-BC. The sub-L-BC is a subgraph of the L-BC. The minimum local network structure that contains a specific set of servers in the sub-L-BC is defined as a minimum sub-L-BC, and the minimum sub-L-BC is represented as MinS.

[0058] Step S200: Define a neighbor server set. For each fault-free server in the smallest sub-L-BC, create a neighbor server set of the fault-free server based on the security status of the neighbor servers corresponding to the fault-free server. For a fault-free server m, there are three neighbor server sets, namely A(m), T(m), and F(m). A(m) is used to store all neighbor servers of the fault-free server in the smallest sub-L-BC, T(m) is used to store all fault-free neighbor servers of the fault-free server in the smallest sub-L-BC (the link between the fault-free neighbor server and m must also be fault-free), and F(m) is used to store all faulty neighbor servers of the fault-free server in the smallest sub-L-BC (the neighbor server fails, the link between the neighbor server and m fails, or both fail).

[0059] Step S300: Construct a local security information model. The local security information model analyzes the status of the neighboring servers of the fault-free server in its smallest sub-L-BC and performs a security assessment on the fault-free server. When performing the security assessment on the fault-free server, the model performs an assessment based on the relationship between the smallest sub-L-BC and the predefined largest sub-L-BC between the source server and the target server and the predefined assessment criteria, and determines the security level of the server.

[0060] In this embodiment, for the BCube network, its network dimension is the total recursive level in the construction process. BCubec,d means that the number of ports of each switch in the BCube is c and the dimension of the network is d, where c≥2 and d≥0. c,d In the BCube, the dimension of the switch is determined according to its level in the recursive construction process. If a switch is located in the BCube c,d The i-th layer of , then the switch is an i-dimensional switch, i∈[0,d].

[0061] BCube c,0 It consists of a c-port 0-dimensional switch and c servers connected to the switch. For d ≥ 1, BCube c,d By c d A c-port d-dimensional switch and c BCubes connected to the switch c,d-1 Composition, a BCube c,d Including c d+1 servers and (d+1)c d c-port switch.

[0062] For a given integer c ≥ 2, d ≥ 0, BCube c,d The definitions of server address, switch address, and link address are as follows:

[0063] Definition 1: The server address is represented by r d r d-1 …r0, where r u ∈[0,c-1],u∈[0,d];

[0064] Definition 2: The address of the switch is expressed as <n;z d-1 z d-2 …z0>, where z v ∈[0,c-1], v∈[0,d-1], n∈[0,d], and n represents the dimension where the switch is located;

[0065] Definition 3: The link directly connecting the switch and the server is represented as follows:

[0066] ( <n;z d-1z d-2 …z0>,r d r d-1 …r0),

[0067] Among them, z d-1 z d-2 …z0=r d r d-1 …r n+1 r n-1 …r0.

[0068] Among them, for a given integer c ≥ 2, d ≥ 0, L-BC c,d The server address is defined as follows:

[0069] Definition 1: The server address is represented by r d r d-1 …r0, where r u ∈[0,c-1],u∈[0,d];

[0070] Definition 2: The link between two servers is represented by (r d r d-1 …r0,r′ d r′ d-1 …r′0, where there exists an integer u∈[0,d] such that r u ≠r′ u , and for any v∈[0,d]\{u}, such that r v =r′ v .

[0071] Among them, for any subgraph If S and L-BC c,d′ If isomorphic and d′≤d, then S is L-BC c,d A sub-L-BC.

[0072] In this embodiment, the evaluation criteria for the local security information model include the following:

[0073] Criterion 1: When the smallest sub-L-BC between the source server and the target server is included in a certain maximum security sub-L-BC network, the security level of the fault-free server is evaluated according to the first concept;

[0074] Criterion 2: When the minimum sub-L-BC between the source server and the target server is not included in a certain maximum safety sub-L-BC, the safety level of the fault-free server is evaluated based on the second concept.

[0075] The first concept is: for a given integer c≥2 and d≥0, L-BC c,d The security level of a fault-free server m in MinS is as follows:

[0076] Case 1: If F(m) in MinS is greater than m in MinS, then m is defined as an enhanced locally completely unsafe server in MinS, abbreviated as ELCUS;

[0077] Case 2: If the neighbor server of m's MinS satisfies any of the following conditions, then m is defined as an enhanced locally unsafe server, or ELUS, in MinS:

[0078] Condition 1: m has at least two neighbor servers in F(m) in MinS;

[0079] Condition 2: There are at least three neighbor servers in the MinS of m, which may all be from F(m), or all are ELUS, or a mixture of these two types of servers.

[0080] Case 3: If m does not meet the above two conditions, then m is considered as an enhanced local security server in MinS, referred to as ELSS;

[0081] Case 4: If m is ELUS, it can be further classified according to the situation of its neighbor servers in MinS. When further classified, if m has at least one neighbor server in MinS that is ELSS, it is called an enhanced local low-insecurity server, abbreviated as ELLUS; otherwise, it is called an enhanced local high-insecurity server, abbreviated as ELHUS.

[0082] The second concept is: for a given integer c≥2 and d≥0, L-BC c,d The security level of a fault-free server m in MinS is as follows:

[0083] Case 1: If T(m) in MinS is empty, the server is a completely insecure server;

[0084] Case 2: If F(m) in MinS is not empty, the server is a level 1 unsafe server;

[0085] Case 3: If there are at least two level 1 unsafe neighbor servers in m's MinS, then the server is a level 2 unsafe server; if there are at least three level 1 and level 2 unsafe neighbor servers in m's MinS, then the server is also a level 2 unsafe server;

[0086] Case 4: Otherwise, m is safe.

[0087] In the first concept, if a sub-L-BC contains at least one ELSS, the sub-L-BC is called a safe sub-L-BC; otherwise, the sub-L-BC is called a completely unsafe sub-L-BC.

[0088] Among them, a d-dimensional L-BC c,d It is called the maximum security sub-L-BC, represented by the symbol MSSL, and meets the following two conditions at the same time:

[0089] Condition 1: L-BC c,d It is a safe sub-L-BC;

[0090] Condition 2: Any L-BC that correctly contains it c,d′ are all completely unsafe, where d′>d.

[0091] The network model used in the method disclosed in this embodiment is as follows Figure 2 BCube shown 3,2 According to the definition of BCube in step S100, we know that BCube 3,2 Composed of three BCubes 3,1 And nine 3-port 2D switches. 3,2 Each BCube in 3,1 There are three BCubes 3,0 and three 3-port 1-dimensional switches. Therefore, a BCube 3,2 There are twenty-seven servers and twenty-seven 3-port switches.

[0092] The logical structure of the network model used in the method disclosed in this embodiment is as follows: Figure 3 L-BC shown 3,2 According to the definition of L-BC in step S100, it can be seen that L-BC 3,2 By three L-BC 3,1 Composition, while L-BC 3,1 There are three L-BC 3,0 Therefore, an L-BC 3,2 There are 27 servers in the L-BC. According to the definition of the sub-L-BC in step S100, the L-BC 3,2 In this example, *2* is a sub-L-BC, where *∈{0,1,2}. According to the definition of the minimum sub-L-BC, MinS(022,012,020) is the minimum sub-L-BC that contains servers 022, 012, and 020. Therefore, MinS(022,012,020) is 0**.

[0093] The network model used in the method disclosed in this embodiment has 10 faulty servers and 10 faulty links L-BC 3,2 like Figure 4 As shown, according to the definition in step S100, L-BC 3,2It is completely unsafe because it does not contain any ELSS. For ease of understanding, this embodiment uses **0 to represent L-BC 3,2 In a sub-L-BC, the addresses of all servers in sub-L-BC**0 are ##0, *∈{0,1,2} and #∈{0,1,2}. Server 122 is an ELUS in sub-L-BC**2. Server 002 is an ELSS in sub-L-BC**0.

[0094] In order to evaluate the performance of the ELSIM-based routing algorithm, this embodiment conducted a comprehensive simulation experiment and compared it with the existing technology.

[0095] In L-BC with failed server and failed link c,d In the present invention, the ELSIM-based routing algorithm aims to establish a reliable fault-tolerant path between any two fault-free servers in the network. However, in some cases, the algorithm may not be able to successfully find a valid path due to network conditions. To this end, this embodiment introduces the transmission success rate as a key indicator to measure the performance of the algorithm. It is defined as the ratio of the number of times the algorithm successfully transmits to the target server to the total number of transmissions. In network performance evaluation, the average path length and the shortest path rate are also two crucial parameters that directly affect the transmission efficiency of the network. A shorter average path length means a faster transmission speed, while a higher shortest path rate indicates that the optimal path can be found more frequently in the network. We evaluate the average path length by calculating the ratio of the sum of the path lengths between all server pairs that successfully transmit to the target server to the total number of successful transmissions. In addition, this embodiment evaluates the shortest path rate by the ratio of the number of shortest path lengths successfully transmitted by the algorithm to the total number of successful transmissions.

[0096] In order to facilitate comparative analysis, the routing algorithm based on ELSIM is compared with the routing algorithm proposed in the prior art. There are three existing technologies adopted in this embodiment, namely Document 1, Document 2 and Document 3. Document 1 is titled: The Adaptive Fault-tolerant Routing Based on an Improved Local Security Information Model of the Exchanged Hypercube, with the original title: The Adaptive Fault-tolerant Routing Based on an Improved Local Security Information Model of the Exchanged Hypercube, the publication date is April 11, 2024, and the conference is: 2023 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA / BDCloud / SocialCom / SustainCom); Document 2 is titled: Fault-tolerant Routing in Hypercube Multicomputers using Local Safety Information, with the original title: Fault-tolerant Routing in Hypercube Multicomputers using Local Safety Information Information, publication date: June 30, 2001, published in the journal: IEEE Transactions on Parallel and Distributed Systems, the original title of the journal is: IEEE Transactions on Parallel and Distributed Systems; the third article is called: Fault-tolerant Unicast using Conditional Local Safe Model in the Data Center Network BCube, the original title is: Fault-tolerant Unicast using Conditional Local Safe Model in the Data Center Network BCube, publication date: November 2023, published in the journal: Journal of Parallel and Distributed Computing, the original title of the journal is: Journal of Parallel and Distributed Computing.

[0097] In the specific comparison process, TSR_M, APL_M, and SPR_M are used to represent the transmission success rate, average path length, and shortest path rate corresponding to the routing algorithm based on ELSIM in this embodiment; TSR_Z, APL_Z, and SPR_Z are used to represent the transmission success rate, average path length, and shortest path rate corresponding to the routing algorithm in Document 1; TSR_X, APL_X, and SPR_X are used to represent the transmission success rate, average path length, and shortest path rate corresponding to the routing algorithm in Document 2; and TSR_D, APL_D, and SPR_D are used to represent the transmission success rate, average path length, and shortest path rate corresponding to the routing algorithm in Document 3. In order to ensure the accuracy of the experimental results, the L-BC c,d 1000 experiments were conducted under different conditions with different ratios of faulty devices (faulty servers and faulty links), and the average of these experimental results was calculated. When the number of faulty servers accounts for a certain percentage of the total number of servers in the network, and the number of faulty links also accounts for the same percentage of the total number of links in the network, this situation is called a specific percentage failure situation of faulty servers and faulty links in the network. In the experimental configuration of this embodiment, the L-BC c,d We set up different failure scenarios, with the specific percentages of failed servers and failed links set to 5%, 10%, 15%, 20%, 25%, and 30%, respectively. In each experiment, we randomly selected the corresponding percentages of failed servers and failed links. Based on the experimental design, we conducted simulations under the following two parameter configurations:

[0098] (1) c = 3, d ∈ {1, 2, 3, 4};

[0099] (2) d = 2, c ∈ {3, 4, 5, 6};

[0100] First, this embodiment studies the transmission success rate of the routing algorithm. Figure 5 Demonstrates L-BC in the presence of faulty equipment c,d The experimental results of the transmission success rate in Figure 5 In (c), L-BC is compared 3,3 When the specific percentage of failed servers and failed links is 20%, the specific data of the transmission success rate of different routing algorithms are as follows: TSR_M = 98.93%, TSR_Z = 96.73%, TSR_X = 53.37% and TSR_D = 51.63%. Figure 5In (f), the transmission success rate data for the case where the specific percentage of failed servers and failed links in L-BC4,2 is 15% is also shown: TSR_M = 99.83%, TSR_Z = 98.15%, TSR_X = 36.91%, and TSR_D = 37.16%. These data clearly show that among the four algorithms, our ELSIM-based routing algorithm has the highest transmission success rate, while TSR_X and TSR_D have the lowest transmission success rates. Notably, when the number of failed servers and failed links in BCube accounts for 20% of the total servers and total links, respectively, the transmission success rate of our ELSIM-based routing algorithm can still remain above 90%.

[0101] Then, this embodiment studies the average path length of the routing algorithm. Figure 6 The L-BC in the presence of faulty equipment is shown c,d Experimental results of the average path length in . Figure 6 (c) When L-BC 3,3 When the specific percentage of failed servers and failed links is 20%, the average path length data of different routing algorithms are as follows: APL_M = 7.84, APL_Z = 11.49, APL_X = 2.59 and APL_D = 2.39. Figure 6 In (f), the average path length data for the case where the specific percentage of failed servers and failed links in L-BC4,2 is 15% are also compared: APL_M = 5.83, APL_Z = 7.82, APL_X = 1.95 and APL_D = 2. These data clearly show that among the four algorithms, APL_X and APL_D perform the best, while APL_Z performs the worst.

[0102] Finally, this embodiment studies the shortest path rate of the routing algorithm. Figure 7 It further demonstrates the L-BC in the presence of faulty equipment c,d The experimental data of the shortest path rate in . Figure 7 (c) When L-BC 3,3 When the specific percentage of failed servers and failed links is 20%, the shortest path rate data of different routing algorithms are as follows: SPR_M = 53.36%, SPR_Z = 19.32%, SPR_X = 95.02%, and SPR_D = 95.63%. Figure 7In (f), the shortest path rates for L-BC4,2 with a specific percentage of failed servers and failed links of 15% are: SPR_M = 53.26%, SPR_Z = 25.11%, SPR_X = 97.81%, and SPR_D = 98.91%. These data show that among the four algorithms, SPR_X and SPR_D perform the best, while SPR_Z performs the worst.

[0103] In summary, compared with the routing algorithms in the three references, the ELSIM-based routing algorithm in this embodiment still has the highest transmission success rate, shorter average path length, and higher shortest path rate even under a higher device failure rate.

[0104] The above is a detailed introduction to an enhanced local security information model construction method provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for general technical personnel in this field, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. An enhanced local security information model construction method, characterized in that: Used to perform security assessment on servers in the BCube network, including the following steps: Define the BCube network structure. The BCube network is a server-centric data center network, including servers, switches, and links between servers and switches. By making all switches in the BCube transparent, the logical structure is derived and represented as L-BC. The local network structure in the L-BC is defined as a sub-L-BC. The sub-L-BC is a subgraph of the L-BC. The minimum local network structure that contains a specific set of servers in the sub-L-BC is defined as the minimum sub-L-BC, and the minimum sub-L-BC is represented as MinS. For each fault-free server in the smallest sub-L-BC, a neighbor server set of the fault-free server is created based on the security status of the neighbor servers corresponding to the fault-free server. For a fault-free server m, there are three neighbor server sets, namely A(m), T(m) and F(m). A(m) is used to store all neighbor servers of the fault-free server in the smallest sub-L-BC, T(m) is used to store all fault-free neighbor servers of the fault-free server in the smallest sub-L-BC, and F(m) is used to store all faulty neighbor servers of the fault-free server in the smallest sub-L-BC. A local security information model is constructed. The local security information model analyzes the status of neighbor servers of the fault-free server in its smallest sub-L-BC and performs a security assessment on the fault-free server. When performing the security assessment on the fault-free server, the model performs an assessment based on the relationship between the smallest sub-L-BC and the predefined largest sub-L-BC between the source server and the target server and predefined assessment criteria, and determines the security level of the server.

2. The enhanced local security information model construction method according to claim 1, characterized in that: For the BCube network, its network dimension is the total recursive level in the construction process; BCube c,d The number of ports of each switch in BCube is c, and the dimension of the network is d, where c≥2, d≥0. c,d In the BCube, the dimension of the switch is determined by its level in the recursive construction process. If a switch is located in the BCube c,d The i-th layer of , then the switch is an i-dimensional switch, i∈[0,d]; BCube c,0 It consists of a c-port 0-dimensional switch and c servers connected to the switch. For d ≥ 1, BCube c,d By c d A c-port d-dimensional switch and c BCubes connected to the switch c,d-1 Composition, a BCube c,d Including c d+1 servers and (d+1)c d c-port switch.

3. The enhanced local security information model construction method according to claim 2, characterized in that: For a given integer c ≥ 2, d ≥ 0, BCube c,d The definitions of server address, switch address, and link address are as follows: Definition 1: The server address is represented by r d r d-1 …r0, where r u ∈[0,c-1],u∈[0,d]; Definition 2: The address of the switch is expressed as <n;z d-1 z d-2 …z0>, where z v ∈[0,c-1], v∈[0,d-1], n∈[0,d], and n represents the dimension where the switch is located; Definition 3: The link directly connecting the switch and the server is represented as follows: ( <n;z d-1 With d-2 …z0>,r d r d-1 …r0), Among them, z d-1 z d-2 …z v …z0=r d r d-1 …r n+1 r n-1 …r0.

4. The enhanced local security information model construction method according to claim 3, characterized in that: For a given integer c ≥ 2, d ≥ 0, L-BC c,d The server address is defined as follows: Definition 1: The server address is represented by r d r d-1 …r0, where r u ∈[0,c-1],u∈[0,d]; Definition 2: The link between two servers is represented by (r d r d-1 …r0,r′ d r′ d-1 …r′0, where there exists an integer u∈[0,d] such that r u ≠r′ u , and for any v∈[0,d]\{u}, such that r v =r′ v .

5. The enhanced local security information model construction method according to claim 4, characterized in that: For any subgraph If S and L-BC c,d′ If isomorphic and d′≤d, then S is L-BC c,d A sub-L-BC.

6. The enhanced local security information model construction method according to any one of claims 1 to 5, characterized in that: For local security information models, the evaluation criteria include the following: Criterion 1: When the smallest sub-L-BC between the source server and the target server is included in a certain maximum security sub-L-BC network, the security level of the fault-free server is evaluated according to the first concept; Criterion 2: When the minimum sub-L-BC between the source server and the target server is not included in a certain maximum safety sub-L-BC, the safety level of the fault-free server is evaluated according to the second concept; The first concept is: for a given integer c≥2 and d≥0, L-BC c,d The security level of a fault-free server m in MinS is as follows: Case 1: If F(m) in MinS is greater than m in MinS, then m is defined as an enhanced locally completely unsafe server in MinS, abbreviated as ELCUS; Case 2: If the neighbor server of m's MinS satisfies any of the following conditions, then m is defined as an enhanced locally unsafe server, or ELUS, in MinS: Condition 1: m has at least two neighbor servers in F(m) in MinS; Condition 2: There are at least three neighbor servers in the MinS of m, which may all be from F(m), or all are ELUS, or a mixture of these two types of servers. Case 3: If m does not satisfy the above two conditions, then m is considered as an enhanced local security server in MinS, referred to as ELSS; Case 4: If m is an ELUS, it can be further classified according to the situation of its neighbor servers in MinS. When further classified, if m has at least one neighbor server in MinS that is an ELSS, it is called an enhanced local low-insecurity server, abbreviated as ELLUS; otherwise, it is called an enhanced local high-insecurity server, abbreviated as ELHUS; The second concept is: for a given integer c≥2 and d≥0, L-BC c,d The security level of a fault-free server m in MinS is as follows: Case 1: If T(m) in MinS is empty, the server is a completely insecure server; Case 2: If F(m) in MinS is not empty, the server is a level 1 unsafe server; Case 3: If there are at least two level 1 unsafe neighbor servers in m's MinS, then the server is a level 2 unsafe server; if there are at least three level 1 and level 2 unsafe neighbor servers in m's MinS, then the server is also a level 2 unsafe server; Case 4: Otherwise, m is safe; In the first concept, if a sub-L-BC contains at least one ELSS, the sub-L-BC is called a safe sub-L-BC, otherwise, the sub-L-BC is called a completely unsafe sub-L-BC; Among them, a d-dimensional L-BC c,d It is called the maximum security sub-L-BC, represented by the symbol MSSL, and meets the following two conditions at the same time: Condition 1: L-BC c,d It is a safe sub-L-BC; Condition 2: Any L-BC that correctly contains it c,d′ are all completely unsafe, where d′>d.