Intelligent management scheduling method and system for virtual cipher machine

By combining SVM and moving average calculation, a smart management and scheduling method for virtual cryptographic machines was developed, which enabled accurate anomaly detection and rapid fault repair of virtual cryptographic machines. This optimized resource scheduling, ensured the continuity of high-concurrency services and the efficiency of resource utilization, and solved the problems of stability and insufficient resource utilization of virtual cryptographic machine clusters in existing technologies.

CN120825328APending Publication Date: 2025-10-21山东三未信安信息科技有限公司 +1
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202511120973.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-10-21

AI Technical Summary

Technical Problem

Existing technologies cannot accurately detect anomalies, cannot quickly self-heal from faults, and lack elastic resource scheduling, resulting in insufficient stability and resource utilization efficiency of virtual cryptographic machine clusters in high-concurrency, low-latency business scenarios.

Method used

A dynamic scaling mechanism based on multi-dimensional anomaly detection and moving average calculation using support vector machine (SVM) is adopted. Combined with image management, it realizes fault self-healing and resource scheduling. An anomaly detection model is built through soft-interval SVM, and image files are used to realize automatic fault repair. Based on moving average calculation, virtual machine scaling or node expansion is triggered on demand.

Benefits of technology

It enables accurate anomaly detection and rapid fault repair of virtual cryptographic machines, ensuring business continuity, optimizing resource utilization efficiency, avoiding resource waste and interruptions, and improving system stability and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120825328A_ABST
    Figure CN120825328A_ABST
Patent Text Reader

Abstract

The invention discloses a virtual cipher machine intelligent management scheduling method and system. The method comprises the steps that a cipher service platform calls a cloud cipher machine to create virtual machines, establishes a device group, and binds the device group with a plurality of created virtual machines; and virtual machine images are created and stored in an HDFS cluster. And the password service platform creates a password service, binds the password service and the device group, and issues virtual machine information in the device group to the password service, so that the password service can normally use the virtual machine function. And the monitoring component regularly acquires a plurality of core monitoring indexes of the virtual machine and starts a management detection task of the state of the virtual cipher machine based on the SVM and a service detection task of dynamic expansion based on moving average calculation. When the virtual machine is judged to be in the abnormal state, triggering a recovery step; or the resource pressure level is judged according to the trend change of the moving average calculation result, and the resource adjustment step is triggered when the preset pressure level is reached. The problems of accurate anomaly detection, rapid fault self-healing and elastic resource scheduling in the cloud password service can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of cloud computing and information security technology, and more specifically, to a method and system for intelligent management and scheduling of virtual cryptographic machines. In particular, it relates to a virtual cryptographic machine cluster management solution that combines support vector machine (SVM) state detection, dynamic capacity expansion through moving average calculation, and virtual machine image recovery technology to improve the stability, reliability, and resource utilization efficiency of cryptographic services. Background Art

[0002] The cryptographic service platform is a system that centrally manages and controls cryptographic devices and services. It integrates multiple cryptographic service components and provides security services such as data encryption and decryption, digital signatures, identity authentication, and key management.

[0003] Cloud cryptographic machine is a new type of cryptographic device developed based on physical cryptographic machine using virtualization technology. It can generate multiple virtual cryptographic machines on a single physical device. Each virtual cryptographic machine is isolated and independent from each other, and can provide services such as data encryption and decryption, signature verification, key generation and management.

[0004] The virtual cryptographic machine (VM) relies on the virtualization technology of the cloud cryptographic machine. It is an independent cryptographic machine instance built on a single physical cryptographic device through resource isolation and environment simulation, which can provide complete cryptographic service capabilities.

[0005] In terms of importance, these technologies must address high concurrency, low latency, and zero-interruption business demands in areas such as financial transactions, e-government, and healthcare. For example, banks must handle tens of thousands of transactions per second, requiring real-time signature verification; government cloud platforms require continuous encrypted transmission of official documents across regions; and medical big data platforms must ensure 24 / 7 encryption of patient privacy data.

[0006] Through in-depth research on mainstream technologies, the following common bottlenecks were discovered:

[0007] Patent document publication number CN119473497A, published on February 18, 2025, is titled "A Cloud Cryptographic Machine Cluster Management Method and Apparatus." The method includes receiving and analyzing cluster management requests; parsing the cluster management requests and, according to cluster management instructions, invoking a cluster management command line tool to complete cluster management tasks; obtaining cluster node status in response to cluster status monitoring requests and, according to cluster monitoring instructions, invoking a cluster monitoring command line tool to obtain the current virtual machine status; and implementing appropriate handling strategies based on the virtual machine status. The method supports automatic migration of faulty nodes, enabling automatic fault repair, shortening downtime, reducing operation and maintenance costs, and improving the availability and reliability of the cloud cryptographic machine cluster. However, this method primarily relies on invoking monitoring tools to complete cluster status monitoring. This method, which only monitors the entire virtual machine, suffers from a single detection dimension and coarse granularity, as well as insufficient generalization capabilities, which can easily lead to false alarms and erroneous operations. Furthermore, the solution lacks the ability to dynamically schedule virtual machine capacity expansion.

[0008] Patent document publication number CN117527881A, published on February 6, 2024, is titled "A Dynamic Cryptographic Machine Scheduling System and Method." While this solution's evaluation engine enables dynamic scheduling of cryptographic machines, it cannot effectively expand or elastically scale virtual cryptographic machines when high traffic and data volumes lead to performance bottlenecks. Furthermore, this solution lacks a self-repair strategy for cryptographic machines when anomalies occur.

[0009] Patent document publication number CN118900270A, published on November 5, 2024, is titled "A Load Balancing System and Method for Cloud Server Cryptographic Machines." This solution relies on rules to balance load calls across nodes within a cluster. However, this solution typically triggers scheduling based on preset thresholds or rules and lacks time series analysis of historical data, making it impossible to identify cyclical patterns in business load. Consequently, it's impossible to correlate system metrics at different time points, making it difficult to identify the root cause of performance bottlenecks.

[0010] Therefore, those skilled in the art are in urgent need of solving the above technical problems. Summary of the Invention

[0011] In view of this, the present invention provides a method and system for intelligent management and scheduling of virtual cryptographic machines, which can at least partially solve the above-mentioned problems of inability to accurately detect anomalies, inability to quickly self-heal faults, and lack of flexible resource scheduling.

[0012] In order to achieve the above object, the present invention adopts the following technical solutions:

[0013] In a first aspect, the present invention provides a method for intelligent management and scheduling of a virtual cryptographic machine, comprising the following steps:

[0014] Creation and initialization: Calling the cloud cryptographic machine through the cryptographic service platform to create a virtual cryptographic machine, establishing a device group containing multiple virtual cryptographic machines, and binding the virtual cryptographic machine to the device group; creating related image files of the virtual cryptographic machine and storing them in the distributed file system cluster;

[0015] Cryptographic service binding: creating a cryptographic service on the cryptographic service platform, binding the cryptographic service to the device group, and sending access information of the virtual cryptographic machine in the device group to the cryptographic service;

[0016] Status monitoring and detection: The monitoring component regularly collects multi-dimensional monitoring indicator data of the virtual cipher machine, and starts the management detection task of the virtual cipher machine status based on SVM and the business detection task of dynamic expansion based on moving average calculation;

[0017] Scheduling execution: triggering a recovery step when it is determined that the virtual cipher machine is in an abnormal state; and / or judging the resource pressure level according to the trend change of the moving average calculation result, and triggering a resource adjustment step when the preset pressure level is reached.

[0018] Furthermore, in the state monitoring and detection step, when starting the management detection task of the virtual cipher machine state based on the SVM, it includes:

[0019] The monitoring component regularly collects multi-dimensional monitoring indicator data of the virtual cipher machine, including performance indicators, resource indicators, and system indicators;

[0020] The collected indicator data are standardized and input into the abnormal state detection model built based on soft margin support vector machine (SVM) for state classification.

[0021] Furthermore, the construction process of the abnormal state detection model includes:

[0022] The Z-score standardization method was used to process the data of each monitoring indicator;

[0023] Use soft margin SVM to build a classification model, and the optimization objective is:

[0024]

[0025] Among them, w is the SVM hyperplane normal vector, b is the hyperplane intercept, is a slack variable that measures the degree to which the i-th sample violates the classification constraint. =0 means the sample classification is correct, >0 indicates classification error; C is the penalty parameter used to balance the maximization interval and minimization of classification error of SVM, and m is the total number of sample data;

[0026] Use Gaussian kernel function to solve nonlinear classification problems:

[0027]

[0028] Among them, γ is the kernel function bandwidth parameter, k is the index parameter; calculate any two samples through the kernel function The inner product in the high-dimensional feature space transforms the nonlinear classification problem into a linear classification problem in the high-dimensional space;

[0029] The sequential minimum optimization algorithm is used to iteratively update the model parameters, and the penalty parameter C and kernel function bandwidth parameter γ are optimized through cross-validation.

[0030] Furthermore, the decision function of the abnormal state detection model is as follows:

[0031]

[0032] in, For data samples Transformed standardized data; and is the optimal parameter obtained from the previous model training, is the true label value of the i-th sample data; If the final result is -1, it is determined that the device is in an abnormal state. If the final result is 1, it is determined to be in a normal state.

[0033] Furthermore, in the scheduling execution step, when it is determined that the virtual cipher machine is in an abnormal state, a recovery step is triggered, including:

[0034] If the classification result is abnormal, calculate the abnormal score:

[0035]

[0036] When the anomaly score reaches the first preset range, it is a mild anomaly, triggering an alarm and recording the corresponding sample data and virtual cipher machine information;

[0037] When the anomaly score reaches the second preset range, it is a serious anomaly. An available cloud cryptographic machine with the largest resource margin is selected to create a new virtual cryptographic machine. The virtual machine image corresponding to the abnormal virtual cryptographic machine pre-stored in the distributed file system cluster is imported into the new virtual cryptographic machine, and the new virtual cryptographic machine is bound to the device group to which the abnormal virtual cryptographic machine originally belonged; the new virtual cryptographic machine information is updated and sent to the cryptographic service.

[0038] Furthermore, the available cloud cryptographic machine with the largest resource margin is selected to create a new virtual cryptographic machine, including:

[0039] Prioritize the use of available cloud cryptographic machines with the largest system resource margin in the local area to create new virtual cryptographic machines;

[0040] If the local area resources are insufficient, select the available cloud cryptographic machine with the largest system resource surplus in the remote area.

[0041] Furthermore, in the state monitoring and detection step, when starting the service detection task of dynamic expansion based on moving average calculation, it includes:

[0042] The monitoring component regularly collects multi-dimensional monitoring indicator data of the virtual cipher machine, including performance indicators and resource indicators;

[0043] For the resource and performance indicator data of the virtual cipher machine, a moving average is calculated according to a preset time window:

[0044]

[0045] in, is the throughput value in the lth minute; p is the sliding window for moving average calculation; t is the duration of the detection cycle; and T is the duration of the entire business detection task.

[0046] Furthermore, in the scheduling execution step, the resource pressure level is determined according to the trend change of the moving average calculation result, and the resource adjustment step is triggered when the preset pressure level is reached, including:

[0047] If the moving average value of the indicator exceeding the first ratio threshold value within a continuous preset period shows an upward trend, the resource expansion of the original virtual cipher machine is triggered;

[0048] If the moving average of the indicator exceeding the second ratio threshold value within a continuous preset period shows an upward trend, a new virtual cipher machine is triggered and added to the original device group; the second ratio threshold value is greater than the first ratio threshold value;

[0049] Prioritize expansion or creation of new virtual machines on the local cloud cryptography machine; if local resources are insufficient, perform the operation on a remote available cloud cryptography machine, add the new virtual machine to the device group, and update the cryptography service.

[0050] Furthermore, the related image files of the virtual cryptographic machine include: programs, configuration files, keys and running status data; the running status data includes: disk data, I / O data, network data, process data and task data.

[0051] In a second aspect, an embodiment of the present invention further provides a virtual cryptographic machine intelligent management and scheduling system, which adopts the virtual cryptographic machine intelligent management and scheduling method as described in any one of the first aspects, and the system includes:

[0052] The cryptographic service platform calls the cloud cryptographic machine to create a virtual cryptographic machine, establishes a device group containing multiple virtual cryptographic machines, and binds the virtual cryptographic machines to the device group;

[0053] Cloud cryptography machine, used to create and manage multiple isolated virtual cryptography machines based on virtualization technology;

[0054] Distributed file system cluster, used to store related image files of virtual cipher machines;

[0055] A monitoring component is used to regularly collect multi-dimensional monitoring indicator data of the virtual cipher machine and start the management detection task of the virtual cipher machine status based on SVM and the business detection task of dynamic expansion based on moving average calculation;

[0056] The cryptographic service platform includes:

[0057] The password service module is used to create a password service on the password service platform, bind the password service to the device group, and send access information of the virtual password machine in the device group to the password service;

[0058] Image management module: used to generate image files when the virtual cipher is created and store them in the HDFS cluster. When recovery is triggered, the image files are obtained and imported into the new virtual cipher.

[0059] Scheduling execution module: triggering a recovery step when it is determined that the virtual cipher machine is in an abnormal state; and / or judging the resource pressure level according to the trend change of the moving average calculation result, and triggering a resource adjustment step when the preset pressure level is reached.

[0060] It can be seen from the above technical solutions that compared with the prior art, the present invention has the following technical advantages:

[0061] 1. SVM-based virtual machine status detection: This system uses soft-margin support vector machines (SVMs) based on collected metrics and data to build a virtual machine anomaly detection model. A mechanism for calculating anomaly scores is then established to set different warning levels for the final results and trigger corresponding actions. Compared to traditional rule-based detection, this system can accurately identify anomalies in complex contexts such as VM CPU, memory, and process status. With more dimensions and finer granularity, this system can promptly detect VM anomalies and address them promptly.

[0062] 2. Achieve self-repair of cryptographic machines through image management: Export the cryptographic machine image when the virtual cryptographic machine is operating normally. If an anomaly is detected and the cryptographic machine cannot provide services, create a new virtual cryptographic machine and import the original image. After reissuing the new virtual machine information to the cryptographic service, automatic fault repair is achieved and business continuity is guaranteed.

[0063] 3. Dynamic capacity expansion mechanism based on moving average calculation: Using moving average calculation capabilities to trigger on-demand VM or node expansion. This solves the problem of insufficient resources leading to service degradation or excessive pre-allocation leading to resource redundancy in cryptographic machine clusters when facing sudden business volume and large data volumes. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0065] Figure 1 This is a flow chart of the intelligent management and scheduling method for a virtual cipher machine provided by the present invention.

[0066] Figure 2 This is a diagram of the intelligent management and scheduling technology architecture of the virtual cryptographic machine provided by the present invention. DETAILED DESCRIPTION

[0067] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0068] Example 1:

[0069] The embodiment of the present invention discloses a virtual cipher machine intelligent management and scheduling method, referring to Figure 1 As shown, the following steps S1 to S4 are included. For the convenience of description, the following steps are numbered, but they do not constitute a limitation on the execution order or the scope of protection.

[0070] Specifically include:

[0071] S1. Creation and initialization: Calling the cloud cryptographic machine through the cryptographic service platform to create a virtual cryptographic machine, establishing a device group containing multiple virtual cryptographic machines, and binding the virtual cryptographic machine to the device group; creating the relevant image files of the virtual cryptographic machine and storing them in the distributed file system cluster;

[0072] The cryptographic service platform is a system that centrally manages and controls cryptographic devices and services. It integrates multiple cryptographic service components and provides security services such as data encryption and decryption, digital signatures, identity authentication, and key management.

[0073] Cloud cryptographic machine is a new type of cryptographic device developed based on physical cryptographic machine using virtualization technology. It can generate multiple virtual cryptographic machines on a single physical device. Each virtual cryptographic machine is isolated and independent from each other, and can provide services such as data encryption and decryption, signature verification, key generation and management.

[0074] Virtual cryptographic machine, also known as virtual machine: Relying on the virtualization technology of cloud cryptographic machine, an independent cryptographic machine instance is built on a single physical cryptographic device through resource isolation, environment simulation, etc., which can provide complete cryptographic service capabilities.

[0075] Related image files of the virtual cryptographic machine: including programs, configuration files and keys. The running status includes but is not limited to disk data, I / O data, network data, process data and task data; files used to restore the virtual machine status when the virtual machine status is abnormal.

[0076] A distributed file system cluster, also known as an HDFS cluster, is a distributed file system architecture optimized for large-scale data storage and processing. It can store massive amounts of data across multiple servers, achieving distributed storage, high availability, and high-throughput access through collaborative management at the software layer.

[0077] S2 password service binding: Create a password service in the password service platform, bind the password service to the device group, and send the access information of the virtual password machine within the device group to the password service;

[0078] Among them, cryptographic services focus on cryptographic applications and provide functions such as encryption and decryption, signature verification, key management, and certificate management to ensure data security and identity authentication.

[0079] For example: Key management service is responsible for the management of key generation, storage, distribution, update and synchronization, and is the key support for data encryption and decryption.

[0080] Encryption and decryption service: A service that encrypts and decrypts data. It obtains keys by interacting with the key management service to achieve encoding and decoding conversion of data in a secure state.

[0081] Signature Verification Service: A service that generates and verifies digital signatures for data. Its core purpose is to ensure the integrity, authenticity, and non-repudiation of data, and to provide reliable identity authentication and data tamper-proofing capabilities during data interaction.

[0082] S3 status monitoring and detection: The monitoring component regularly collects multi-dimensional monitoring indicator data of the virtual cipher machine, and opens the management detection task of the virtual cipher machine status based on SVM and the dynamic expansion of the business detection task based on the moving average calculation;

[0083] The monitoring component collects and analyzes monitoring data from cloud cryptographic machines and virtual machines, providing data support for subsequent virtual machine expansion and scheduling. SVM (Support Vector Machine) is a supervised learning model, a classification and regression analysis method widely used in pattern recognition, data classification, and other fields. Its core concept is to find an optimal hyperplane in feature space that maximizes the separation between data points of different categories, achieving efficient classification.

[0084] Moving average calculation is a time series analysis method that uses the average of multiple consecutive data points in a series to generate a new smoothed series to reveal the long-term trend or cyclical characteristics of the data.

[0085] S4. Scheduling and Execution: When the virtual cryptographic machine is determined to be in an abnormal state, a recovery step is triggered; and / or the resource pressure level is determined based on the trend change of the moving average calculation result, and when the pressure level reaches a preset level, a resource adjustment step is triggered. For example, if a virtual machine is detected to be in an abnormal state and unable to provide services normally, the platform calls the cloud cryptographic machine to create a new virtual machine, obtains the original virtual machine image from the HDFS cluster, imports it into the new virtual machine, rebinds the virtual machine to the original device group, and sends the virtual machine information to the cryptographic service.

[0086] For example, when it is detected that the virtual machine status is normal but the concurrency is high or the throughput is low, the platform calls the cloud cryptographic machine to perform capacity expansion operations on the original virtual machine or create a new virtual machine and bind it to the device group to increase throughput and ensure uninterrupted business.

[0087] The virtual cipher machine intelligent management and scheduling method provided by the present invention is based on the technical architecture when implemented, referring to Figure 2 The following figure shows the data and control flows between the cryptographic service platform, monitoring components, cloud cryptographic machine, and HDFS cluster. The main processes involved are as follows:

[0088] 1) The cryptographic service platform calls the cloud cryptographic machine to create a virtual machine. The cryptographic service platform establishes a device group and binds the device group to multiple created virtual machines. The created virtual machine image is stored in the HDFS cluster.

[0089] 2) The password service platform creates a password service and binds the password service to the device group, and sends the virtual machine information in the device group to the password service so that the password service can use the virtual machine functions normally.

[0090] 3) The monitoring component regularly obtains multiple core monitoring indicators of the virtual machine and starts the management detection task of the virtual cipher machine status based on SVM and the business detection task of dynamic expansion based on moving average calculation.

[0091] 4) Create keys, import certificates, and other operations through the cryptographic service platform and provide external cryptographic service capabilities.

[0092] The core of the intelligent management and scheduling method for virtual cryptographic machines provided by the present invention lies in the above-mentioned steps S3 and S4, which involve implementing fine-grained anomaly detection and hierarchical warning based on a multi-dimensional SVM model, implementing minute-level self-healing of faulty virtual machines based on an image recovery mechanism, and implementing precise resource scheduling driven by business load based on moving average prediction.

[0093] The following is a detailed explanation from three aspects:

[0094] 1. Manage testing tasks:

[0095] The management detection task is implemented based on the soft margin SVM and is mainly used to detect the status of the virtual machine. Based on the characteristics of the virtual machine, the monitoring component regularly collects data from multiple dimensions, including:

[0096] Performance indicator data: CPU usage, memory usage, disk usage, system throughput, etc.;

[0097] Resource indicator data: disk IO rate, network traffic bandwidth, remaining storage resources, etc.

[0098] System indicator data: process status, service status, error log generation frequency, etc.

[0099] Take each piece of data as a data sample ,in It represents the value of the jth indicator in the i-th sample data, and n represents the total number of indicators.

[0100] Use Z-score to standardize the collected indicator data to ensure that each indicator contributes to the model consistently:

[0101]

[0102] in, is the mean value of the jth indicator on all sample data, is the standard deviation, The data is normalized so that all indicators obey the standard normal distribution.

[0103] Use soft margin SVM to build a classification model, and the optimization objective is:

[0104]

[0105] Among them, w is the SVM hyperplane normal vector, b is the hyperplane intercept, is a slack variable that measures the degree to which the i-th sample violates the classification constraint ( =0 means the sample classification is correct, >0 indicates classification error); C is the penalty parameter used to balance the maximization of SVM margin and minimization of classification error, and m is the total number of sample data;

[0106] Use Gaussian kernel function to solve the problem of nonlinear separability of data:

[0107]

[0108] Among them, γ is the kernel function bandwidth parameter, k is the index parameter; calculate any two samples through the kernel function The inner product in the high-dimensional feature space transforms the nonlinear classification problem into a linear classification problem in the high-dimensional space;

[0109] Then, randomly initialize the parameters and , use the sequential minimum optimization algorithm to iteratively update the parameters. Use 5-fold cross validation to update the parameters and Preset parameter search range, such as ,The F1 score is used as the evaluation metric to evaluate the model performance.

[0110] In this embodiment, a classification model is constructed using a soft-margin SVM combined with multi-dimensional indicators. The Gaussian kernel function addresses nonlinear separability issues, while the z-score is used to normalize and balance indicator contributions. Compared to traditional threshold detection, this approach offers more dimensions and finer granularity, enabling early and accurate identification of anomalies in complex contexts such as VM CPU, memory, and process status. This improves anomaly detection accuracy and reduces the risk of false positives and missed negatives. Furthermore, this approach can be combined with quantitative and graded warnings using anomaly scores (described in detail in Part 2 below) to provide reliable status awareness for the stable operation of cryptographic services.

[0111] 2. Abnormal state of virtual machine and decision-making:

[0112] For the virtual machine data collected by the monitoring component, the same data preprocessing process as the model training phase is performed to convert the newly collected data samples Convert to standardized data , input it into the trained SVM model and judge the state through the decision function. The decision function is as follows:

[0113]

[0114] in, and is the optimal parameter obtained from the previous model training, is the true label value of the i-th sample data. If the final result is -1, it is determined that the device is in an abnormal state. If the final result is 1, it is determined to be in a normal state.

[0115] In order to further quantify the severity of the anomaly, anomaly score calculation is introduced:

[0116]

[0117] According to the preset threshold, for example, in this embodiment, 0.7 is considered a mild abnormality ( , for example, as the first preset range), 0.9 is a serious abnormality ( , for example as a second preset range).

[0118] If a minor anomaly is triggered, the sample data and virtual machine information at that time will be recorded, triggering the password service platform to generate an alarm event to remind the system administrator and help the system administrator intervene in advance.

[0119] If a serious exception is triggered, the virtual machine will be triggered to attempt automatic repair. The process is as follows:

[0120] 1) Detect the available cloud cryptographic machines in the local area and select the cloud cryptographic machine with the largest system resource reserve to generate a new virtual machine.

[0121] 2) Obtain the image data of the original abnormal virtual machine and import it into the new virtual machine, bind the new virtual machine to the original device group, and re-issue the relevant information of the new virtual machine to the password service bound to the device group.

[0122] 3) If the local cloud cipher machine resources are insufficient and a new virtual machine cannot be created, the system will trigger a check for available cloud cipher machines in remote areas.

[0123] 4) Select the cloud cryptographic machine with the largest system resource reserve to generate a new virtual machine and repeat step 2) in the above process.

[0124] That is, the available cloud cryptographic machine with the largest system resource margin in the local area is given priority to create a new virtual cryptographic machine; if the local area resources are insufficient, the available cloud cryptographic machine with the largest system resource margin in the remote area is selected.

[0125] In this embodiment, VMs are managed through the cryptographic service platform, enabling VM status detection and decoupling between VMs. When a VM experiences a serious anomaly, it supports linkage with local and remote cloud cryptographic machine resources, automatically completing the closed loop of "new VM creation - image restoration - device group rebinding - information distribution." This effectively avoids cryptographic service interruptions and ensures the continued availability of core services such as key creation, certificate management, and data encryption and decryption. It also enables self-healing and rapid recovery, ensuring the continuity of cryptographic services.

[0126] 3. Business detection tasks:

[0127] After the management detection task completes the VM status detection, the business detection task is executed to determine the current resource usage of the VM. If the VM is running low on resources or has reduced throughput, capacity expansion or node expansion is performed in a timely manner.

[0128] The service detection task is implemented based on the use of moving average calculation. In this embodiment, judgment is made based on resource indicator data and performance indicator data.

[0129] First, the resource indicator data and the performance indicator data are aggregated according to a certain time frequency. In this embodiment, one minute is taken as an example, that is, the data is aggregated and stored once every minute.

[0130] Set the moving average calculation sliding window p, taking 5 minutes as an example. Then calculate each indicator in The moving average value of one minute, taking throughput as an example:

[0131]

[0132] in, is the throughput value in the first minute. t is the duration of the detection cycle; T is the duration of the entire service detection task.

[0133] Then, the moving average of each indicator among other resource indicators and performance indicators is calculated.

[0134] Based on preset thresholds, in this embodiment, exceeding a first ratio threshold (e.g., 50%) indicates mild performance pressure, while exceeding a second ratio threshold (e.g., 80%) indicates severe performance pressure, triggering different levels of operations. For example, if an upward trend of more than 50% of the moving average values ​​of an indicator is detected over two consecutive detection cycles, a capacity expansion operation is triggered. If an upward trend of more than 80% of the moving average values ​​of an indicator is detected over two consecutive detection cycles, a node expansion operation is triggered.

[0135] The expansion process is as follows:

[0136] 1) Locate the cloud cryptographic machine corresponding to the VM generating performance pressure and trigger capacity expansion of the VM, for example, from 8 cores and 16GB to 16 cores and 32GB.

[0137] 2) Check the remaining resources of the cloud cryptographic machine. If the remaining resources meet the expansion requirements, the expansion operation is triggered.

[0138] 3) If the resource margin does not meet the expansion requirements, a cloud cryptographic machine with sufficient resource margin is detected in the local area, a new virtual machine is created, and added to the device group where the original virtual machine is located. The new virtual machine information is then sent to the cryptographic service.

[0139] 4) If the local cloud cipher machine resources are insufficient and a new virtual machine cannot be created, the system will trigger a check for available cloud cipher machines in remote areas.

[0140] 5) Select the cloud cryptographic machine with the largest system resource margin to generate a new virtual machine, add it to the device group, and send the virtual machine information to the cryptographic service.

[0141] In this embodiment, a service detection task based on moving average calculation monitors resource metrics such as VM concurrency and throughput in real time, triggering capacity expansion or node expansion as needed. When VM performance pressure increases, resource adaptation is automatically completed, from local capacity expansion to local new capacity creation to remote new capacity creation. This also avoids excessive resource pre-allocation, reducing O&M costs and resource waste. Ultimately, this achieves dynamic resource adaptation and optimization, improving platform operational efficiency.

[0142] In the financial industry, high-frequency trading systems are typical scenarios that require extremely high real-time performance. This virtual cryptographic machine intelligent management and scheduling method can play a key role in this scenario. Specific examples are as follows:

[0143] High-frequency trading systems must complete a large number of trade orders within milliseconds or even microseconds, including operations such as order encryption, decryption, and digital signature verification. These operations rely on cryptographic services. Delays or interruptions in cryptographic services can lead to trade failures, missed trading opportunities, and significant financial losses for financial institutions.

[0144] The overall process is as follows:

[0145] 1. Initialization and service binding: The cryptographic service platform calls the cloud cryptographic machine to create multiple virtual cryptographic machines and form a device group. At the same time, it generates an image file containing programs, keys, etc. and stores it in the HDFS cluster. It then binds the device group to the corresponding cryptographic service to ensure that the business can call the cryptographic service normally.

[0146] 2. Real-time monitoring and detection: The monitoring component regularly collects multi-dimensional indicators such as the performance, resources, and system of the virtual cipher machine, detects whether the virtual machine is abnormal through an SVM-based model, and uses moving average calculation to analyze resource pressure trends.

[0147] 3. Dynamic scheduling and recovery: If a virtual machine anomaly is detected, an alarm will be issued for a minor anomaly. For a serious anomaly, local or remote resources will be quickly called to create a new virtual machine and import the image file to restore the service. If the moving average calculation shows that the resource pressure has reached the preset level, it will trigger the expansion of local or remote resources or the addition of new virtual machines to ensure that the cryptographic service continues to respond efficiently, thereby ensuring the real-time nature of the business.

[0148] Example 2:

[0149] Based on the same inventive concept, the present invention also provides a virtual cipher machine intelligent management and scheduling system, which adopts the virtual cipher machine intelligent management and scheduling method of embodiment 1, and the system includes:

[0150] The cryptographic service platform calls the cloud cryptographic machine to create a virtual cryptographic machine, establishes a device group containing multiple virtual cryptographic machines, and binds the virtual cryptographic machines to the device group;

[0151] Cloud cryptography machine, used to create and manage multiple isolated virtual cryptography machines based on virtualization technology;

[0152] Distributed file system cluster, used to store related image files of virtual cipher machines;

[0153] A monitoring component is used to regularly collect multi-dimensional monitoring indicator data of the virtual cipher machine and start the management detection task of the virtual cipher machine status based on SVM and the business detection task of dynamic expansion based on moving average calculation;

[0154] The cryptographic service platform includes:

[0155] The password service module is used to create a password service on the password service platform, bind the password service to the device group, and send access information of the virtual password machine in the device group to the password service;

[0156] Image management module: used to generate image files when the virtual cipher is created and store them in the HDFS cluster. When recovery is triggered, the image files are obtained and imported into the new virtual cipher.

[0157] Scheduling execution module: triggering a recovery step when it is determined that the virtual cipher machine is in an abnormal state; and / or judging the resource pressure level according to the trend change of the moving average calculation result, and triggering a resource adjustment step when the preset pressure level is reached.

[0158] Through the three core mechanisms of intelligent detection (SVM+moving average), image hot migration, and elastic resource scheduling, the system has built a virtual cryptographic machine management architecture that integrates "self-warning-self-decision-making-self-repair-self-optimization", achieving zero interruption of cryptographic services, zero waste of resources, and zero blind spots in operation and maintenance in high-pressure scenarios such as finance and government affairs.

[0159] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.

[0160] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A virtual cipher machine intelligent management and scheduling method, characterized in that: The following steps are involved: Creation and initialization: Calling the cloud cryptographic machine through the cryptographic service platform to create a virtual cryptographic machine, establishing a device group containing multiple virtual cryptographic machines, and binding the virtual cryptographic machine to the device group; creating related image files of the virtual cryptographic machine and storing them in the distributed file system cluster; Cryptographic service binding: creating a cryptographic service on the cryptographic service platform, binding the cryptographic service to the device group, and sending access information of the virtual cryptographic machine in the device group to the cryptographic service; Status monitoring and detection: The monitoring component regularly collects multi-dimensional monitoring indicator data of the virtual cipher machine, and starts the management detection task of the virtual cipher machine status based on SVM and the business detection task of dynamic expansion based on moving average calculation; Scheduling execution: triggering a recovery step when it is determined that the virtual cipher machine is in an abnormal state; and / or judging the resource pressure level according to the trend change of the moving average calculation result, and triggering a resource adjustment step when the preset pressure level is reached.

2. A virtual cipher machine intelligent management and scheduling method according to claim 1, characterized in that: In the state monitoring and detection step, when starting the management detection task of the virtual cipher machine state based on the SVM, it includes: The monitoring component regularly collects multi-dimensional monitoring indicator data of the virtual cipher machine, including performance indicators, resource indicators, and system indicators; The collected indicator data are standardized and input into the abnormal state detection model built based on soft margin support vector machine (SVM) for state classification.

3. A virtual cipher machine intelligent management and scheduling method according to claim 2, characterized in that: The construction process of the abnormal state detection model includes: The Z-score standardization method was used to process the data of each monitoring indicator; Use soft margin SVM to build a classification model, and the optimization objective is: ; Among them, w is the SVM hyperplane normal vector, b is the hyperplane intercept, is a slack variable that measures the degree to which the i-th sample violates the classification constraint. =0 means the sample classification is correct, >0 indicates classification error; C is the penalty parameter used to balance the maximization interval and minimization of classification error of SVM, and m is the total number of sample data; Use Gaussian kernel function to solve nonlinear classification problems: ; Among them, γ is the kernel function bandwidth parameter, k is the index parameter; calculate any two samples through the kernel function The inner product in the high-dimensional feature space transforms the nonlinear classification problem into a linear classification problem in the high-dimensional space; The sequential minimum optimization algorithm is used to iteratively update the model parameters, and the penalty parameter C and kernel function bandwidth parameter γ are optimized through cross-validation.

4. A virtual cipher machine intelligent management and scheduling method according to claim 3, characterized in that: The decision function of the abnormal state detection model is as follows: ; in, For data samples Transformed standardized data; and is the optimal parameter obtained from the previous model training, is the true label value of the i-th sample data; If the final result is -1, it is determined that the device is in an abnormal state. If the final result is 1, it is determined to be in a normal state.

5. A virtual cipher machine intelligent management and scheduling method according to claim 4, characterized in that: In the scheduling execution step, when it is determined that the virtual cipher machine is in an abnormal state, triggering a recovery step includes: If the classification result is abnormal, calculate the abnormal score: ; When the anomaly score reaches the first preset range, it is a mild anomaly, triggering an alarm and recording the corresponding sample data and virtual cipher machine information; When the anomaly score reaches the second preset range, it is a serious anomaly. An available cloud cryptographic machine with the largest resource margin is selected to create a new virtual cryptographic machine. The virtual machine image corresponding to the abnormal virtual cryptographic machine pre-stored in the distributed file system cluster is imported into the new virtual cryptographic machine, and the new virtual cryptographic machine is bound to the device group to which the abnormal virtual cryptographic machine originally belonged; the new virtual cryptographic machine information is updated and sent to the cryptographic service.

6. A virtual cipher machine intelligent management and scheduling method according to claim 5, characterized in that: Select the available cloud cryptographic machine with the largest resource margin to create a new virtual cryptographic machine, including: Prioritize the use of available cloud cryptographic machines with the largest system resource margin in the local area to create new virtual cryptographic machines; If the local area resources are insufficient, select the available cloud cryptographic machine with the largest system resource surplus in the remote area.

7. A virtual cipher machine intelligent management and scheduling method according to claim 1, characterized in that: In the state monitoring and detection step, when starting the service detection task of dynamic expansion based on moving average calculation, it includes: The monitoring component regularly collects multi-dimensional monitoring indicator data of the virtual cipher machine, including performance indicators and resource indicators; For the resource and performance indicator data of the virtual cipher machine, a moving average is calculated according to a preset time window: ; in, is the throughput value in the lth minute; p is the sliding window for moving average calculation; t is the duration of the detection cycle; and T is the duration of the entire business detection task.

8. A virtual cipher machine intelligent management and scheduling method according to claim 7, characterized in that: In the scheduling execution step, judging the resource pressure level according to the trend change of the moving average calculation result, and triggering the resource adjustment step when the preset pressure level is reached, includes: If the moving average value of the indicator exceeding the first ratio threshold value within a continuous preset period shows an upward trend, the resource expansion of the original virtual cipher machine is triggered; If the moving average of the indicator exceeding the second ratio threshold value within a continuous preset period shows an upward trend, a new virtual cipher machine is triggered and added to the original device group; the second ratio threshold value is greater than the first ratio threshold value; Prioritize expansion or creation of new virtual machines on the local cloud cryptography machine; if local resources are insufficient, perform the operation on a remote available cloud cryptography machine, add the new virtual machine to the device group, and update the cryptography service.

9. A virtual cipher machine intelligent management and scheduling method according to claim 1, characterized in that: The related image files of the virtual cipher machine include: programs, configuration files, keys and running status data; the running status data include: disk data, I / O data, network data, process data and task data.

10. A virtual cryptographic machine intelligent management and scheduling system, characterized in that: The method for intelligent management and scheduling of a virtual cryptographic machine according to any one of claims 1 to 9 is adopted, and the system comprises: The cryptographic service platform calls the cloud cryptographic machine to create a virtual cryptographic machine, establishes a device group containing multiple virtual cryptographic machines, and binds the virtual cryptographic machines to the device group; Cloud cryptography machine, used to create and manage multiple isolated virtual cryptography machines based on virtualization technology; Distributed file system cluster, used to store related image files of virtual cipher machines; A monitoring component is used to regularly collect multi-dimensional monitoring indicator data of the virtual cipher machine and start the management detection task of the virtual cipher machine status based on SVM and the business detection task of dynamic expansion based on moving average calculation; The cryptographic service platform includes: The password service module is used to create a password service on the password service platform, bind the password service to the device group, and send access information of the virtual password machine in the device group to the password service; Image management module: used to generate image files when the virtual cipher is created and store them in the HDFS cluster. When recovery is triggered, the image files are obtained and imported into the new virtual cipher. Scheduling execution module: triggering a recovery step when it is determined that the virtual cipher machine is in an abnormal state; and / or judging the resource pressure level according to the trend change of the moving average calculation result, and triggering a resource adjustment step when the preset pressure level is reached.

Citation Information

Patent Citations

  • Dynamic cipher machine scheduling system and scheduling method

    CN117527881A

  • Docker-based cloud password service calling method and middleware system

    CN113821305A

  • Virtual machine live migration method for cloud cipher machine

    CN115576647A

  • Multivariate computing power comprehensive management scheduling method and system for intelligent computing center

    CN117950868A

  • Degradation fault detection method of electromagnetic relay contact system

    CN118194148A