Calculation network arrangement scheduling method and device, storage medium and product
By generating security service identifiers and group behavior descriptions, and identifying target component identifiers for service deployment, the efficiency issues of resource adaptation and policy migration in computing power networks are resolved, achieving rapid response and secure recovery.
Patent Information
- Application Number
- CN202410549938.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-06
- Publication Date
- 2025-11-07
AI Technical Summary
Existing technologies cannot effectively meet the security requirements of computing power networks. Traditional service orchestration suffers from insufficient responsiveness, untimely resource awareness, and complex orchestration in resource adaptation and policy migration, making it difficult to adapt to the dynamic changes of computing power networks.
By generating a security service identifier, the target component identifier is determined based on the description of the population behavior and the device resource information, and the service is deployed in the computing network to be scheduled. The security service identifier is used to ensure that the system can quickly restore services when users are disconnected or nodes are damaged.
It enables rapid response to security service needs in computing power networks, improves the efficiency of resource orchestration and system recovery capabilities, reduces policy migration overhead, and ensures service continuity and security.
Smart Images

Figure CN120915470A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a computing network (algorithm network) orchestration and scheduling method, device, storage medium and product. BACKGROUND
[0002] The computing network (algorithm network) is a new type of information infrastructure that allocates and flexibly schedules computing resources, storage resources and network resources according to business needs among clouds, networks and edges. In the computing network, both network resources and computing resources need to be considered. Due to its dynamic and ubiquitous characteristics, the security requirement is greatly improved. Different security strategies applied to the computing network also need good orchestration and scheduling to adapt to the dynamically changing computing network environment.
[0003] However, traditional service orchestration is mostly for general services in the traditional sense, such as high-bandwidth services and low-latency services. Resource adaptation is mostly limited to related resources in the network. The reaction capability to unexpected situations and the ability to maintain service continuity are poor. The strategy migration overhead is large, the orchestration calculation is complex, the resource perception is not timely and comprehensive, and other defects, which are difficult to meet the needs of the computing network. SUMMARY
[0004] The main purpose of the present application is to provide a computing network (algorithm network) orchestration and scheduling method, device, storage medium and product, which aims to solve the technical problem that the existing service orchestration cannot meet the needs of the computing network.
[0005] To achieve the above purpose, the present application provides a computing network (algorithm network) orchestration and scheduling method, which comprises the following steps:
[0006] In response to the received security service demand, a service behavior description is generated according to the security service demand, and a security service identifier is generated according to the user characteristics corresponding to the security service demand;
[0007] A group behavior description is generated according to the service behavior description and the security service identifier, and device resource information corresponding to each device in the to-be-scheduled computing network is obtained;
[0008] A target component identifier is determined based on the group behavior description and the device resource information, and a corresponding component behavior description is generated;
[0009] Service deployment is performed in the to-be-scheduled computing network according to the target component identifier and the component behavior description.
[0010] In addition, to achieve the above purpose, the present application also provides a computing network (algorithm network) orchestration and scheduling device, which comprises:
[0011] a service resolution module, configured to generate a service behavior description according to the received security service requirement, and generate a security service identifier according to a user feature corresponding to the security service requirement;
[0012] a resource perception module, configured to generate a colony behavior description according to the service behavior description and the security service identifier, and obtain device resource information corresponding to each device in a to-be-scheduled computing network;
[0013] a scheduling module, configured to determine a target component identifier based on the colony behavior description and the device resource information, and generate a corresponding component behavior description;
[0014] a service deployment module, configured to perform service deployment in the to-be-scheduled computing network according to the target component identifier and the component behavior description.
[0015] In addition, to achieve the above-mentioned purpose, the embodiment of the present application also proposes a computing network scheduling device, which comprises a processor, a memory and a computing network scheduling program stored in the memory and executable on the processor. When the computing network scheduling program is executed by the processor, the steps of the computing network scheduling method are implemented.
[0016] In addition, to achieve the above-mentioned purpose, the embodiment of the present application also proposes a computing network scheduling system, which comprises a security service resolution module, a scheduling module, a resource perception deployment module, a computing network security identifier mapping module and an intelligent knowledge storage module. Each functional module in the computing network scheduling system cooperates to execute the steps of the computing network scheduling method.
[0017] In addition, to achieve the above-mentioned purpose, the embodiment of the present application also proposes a computer readable storage medium, which stores a computing network scheduling program. When the computing network scheduling program is executed, the steps of the computing network scheduling method are implemented.
[0018] In addition, to achieve the above-mentioned purpose, the embodiment of the present application also proposes a computer program product, which comprises a computing network scheduling program. When the computing network scheduling program is executed, the steps of the computing network scheduling method are implemented.
[0019] One of the technical solutions in the embodiments of the present application has the following advantages or beneficial effects: by responding to the received security service demand, generating a service behavior description according to the security service demand, and generating a security service identifier according to the user characteristics corresponding to the security service demand; generating a group behavior description according to the service behavior description and the security service identifier, and obtaining device resource information corresponding to each device in the to-be-scheduled computing network; determining a target component identifier based on the group behavior description and the device resource information, and generating a corresponding component behavior description; and performing service deployment in the to-be-scheduled computing network according to the target component identifier and the component behavior description. Since the security service identifier is used, and the identifier is related to the identity of the user and not related to the location of the user, it is ensured that when the user is disconnected and reconnected or part of the nodes in the service function chain are damaged, the computing network security service identifier will not change, and the system can quickly recover the previous service according to the identifier. BRIEF DESCRIPTION OF DRAWINGS
[0020] Figure 1 is a structural schematic diagram of an electronic device of a hardware running environment related to the embodiments of the present application;
[0021] Figure 2 is a flowchart of a first embodiment of the computing network scheduling method of the present application;
[0022] Figure 3 is a structural schematic diagram of a computing network scheduling system of an embodiment of the present application;
[0023] Figure 4 is a flowchart of a computing network scheduling interaction process of an embodiment of the present application;
[0024] Figure 5 is a flowchart of a second embodiment of the computing network scheduling method of the present application;
[0025] Figure 6 is a normal scheduling flowchart of an embodiment of the present application;
[0026] Figure 7 is a service migration flowchart of an embodiment of the present application;
[0027] Figure 8 is a service reconnection flowchart of an embodiment of the present application;
[0028] Figure 9 is a flowchart of a third embodiment of the computing network scheduling method of the present application;
[0029] Figure 10 is a structural block diagram of a first embodiment of the computing network scheduling device of the present application.
[0030] The implementation, functional features and advantages of the present application will be further described with reference to the accompanying drawings in conjunction with the embodiments. DETAILED DESCRIPTION
[0031] It should be understood that the specific embodiments described herein are merely exemplary and do not limit the application.
[0032] Reference Figure 1 , Figure 1 The hardware environment of the electronic device is shown in FIG. 1. The electronic device can include a processor 1001, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to realize the connection and communication between the components. The user interface 1003 can include a display, an input unit such as a keyboard, and can also include a standard wired interface, a wireless interface. The network interface 1004 can optionally include a standard wired interface, a wireless interface (such as a wireless fidelity (WI-FI) interface). The memory 1005 can be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM) such as a disk memory. The memory 1005 can also be a storage device independent of the processor 1001.
[0033] As shown in FIG. 1, the electronic device can include a processor 1001, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to realize the connection and communication between the components. The user interface 1003 can include a display, an input unit such as a keyboard, and can also include a standard wired interface, a wireless interface. The network interface 1004 can optionally include a standard wired interface, a wireless interface (such as a wireless fidelity (WI-FI) interface). The memory 1005 can be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM) such as a disk memory. The memory 1005 can also be a storage device independent of the processor 1001. Figure 1 The skilled in the art can understand that the structure shown in FIG. 1 does not constitute a limitation on the electronic device, and can include more or fewer components than shown, or combine certain components, or different component arrangements.
[0034] Figure 1 The structure shown in FIG. 1 does not constitute a limitation on the electronic device, and can include more or fewer components than shown, or combine certain components, or different component arrangements.
[0035] As shown in FIG. 1, the electronic device can include a processor 1001, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to realize the connection and communication between the components. The user interface 1003 can include a display, an input unit such as a keyboard, and can also include a standard wired interface, a wireless interface. The network interface 1004 can optionally include a standard wired interface, a wireless interface (such as a wireless fidelity (WI-FI) interface). The memory 1005 can be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM) such as a disk memory. The memory 1005 can also be a storage device independent of the processor 1001. Figure 1 In the electronic device shown in FIG. 1, the network interface 1004 is mainly used for data communication with a network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the electronic device can be arranged in the algorithm network arrangement and scheduling device, and the electronic device calls the algorithm network arrangement and scheduling program stored in the memory 1005 through the processor 1001, and executes the algorithm network arrangement and scheduling method provided in the embodiments of the application.
[0036] Figure 1
[0037] The embodiment of the application provides a kind of algorithm network arrangement scheduling method, refer to Figure 2 , Figure 2 It is the flowchart of the first embodiment of the algorithm network arrangement scheduling method of the application.
[0038] In the embodiment, the algorithm network arrangement scheduling method includes the following steps:
[0039] Step S10: in response to the received security service demand, generate service behavior description according to the security service demand, and generate security service identification according to the user characteristics corresponding to the security service demand.
[0040] It should be noted that the execution subject of the embodiment can be the algorithm network arrangement scheduling device, or the algorithm network arrangement scheduling system combined in a cluster manner by multiple algorithm network arrangement scheduling devices, and the algorithm network arrangement scheduling device can be a personal computer, a server or other electronic devices, and can also be other devices that can realize the same or similar functions, which are not limited in the embodiment. In the embodiment and the following embodiments, the algorithm network arrangement scheduling device is taken as an example to describe the algorithm network arrangement scheduling method of the application.
[0041] It should be noted that the security service demand can be the demand of a user using the computing power network, wherein the user can describe the security service demand in the form of natural language, for example: need to use the computing power network to run model algorithm A.
[0042] In actual use, when the algorithm network arrangement scheduling device receives the security service demand, the security service demand is parsed to determine the specific functions required when the service satisfies the security service demand, so as to generate the service behavior description, wherein the service behavior description can include the description information of the specific execution behavior of each function when completing the demand.
[0043] Then, in order to ensure that a unique identification of the security service demand can be formed, the user characteristics corresponding to the security service demand can also be obtained at this time, and the security service identification is generated according to the user characteristics and the related information of the specific functions required when the service satisfies the security service demand.
[0044] In actual use, the security service identification marks the detailed attributes of a service execution, which can include user identity, service name, service type and other information, wherein the user identity can be generated according to the user characteristics, and can include various attributes such as user identity and user source, such as user name, user type (such as ordinary user, senior user and other types), user belonging to operator, etc.
[0045] Step S20: generate group behavior description according to the service behavior description and the security service identification, and obtain device resource information corresponding to each device in the to-be-scheduled algorithm network.
[0046] It should be noted that, depending on the different functions of the devices joining the computing network, a clustering mechanism will be used after the devices join the computing network to divide devices with the same or similar functions into a cluster. However, since different devices may have different functions, the same device may be in different functional clusters at the same time.
[0047] In practical use, after obtaining the service behavior description and security service identifier, they can be further transformed into behavior descriptions related to various types of functional clusters in the computing power network, thereby obtaining the group behavior description. The group behavior description (i.e., the service function chain, which is a function chain composed of functions provided by multiple functional clusters in sequence) can include the execution order of each functional cluster during service execution, as well as the description information of the execution behavior of each functional group.
[0048] For example, network orchestration and scheduling can parse service behavior descriptions and security service identifiers to obtain the service requirements: the destination node is a node with a certain computing power, the user requires a medium level of security, the user needs a large computing service, and the user needs low-latency transmission.
[0049] The generated population behavior description at this time can be as follows: the destination node is a node with a certain computing power; the user requires a medium level of security, so firewall and intrusion detection functions are deployed for the user; the user needs a large computing service, so a function with high computing power is required; furthermore, the user needs low-latency transmission, so a low-latency link needs to be found.
[0050] In practical applications, after determining the description of population behavior, it is also necessary to obtain the device resource information corresponding to each device in the computing network to be scheduled, in order to facilitate resource orchestration and scheduling. The computing network to be scheduled can be a computing power network managed by computing power orchestration and scheduling equipment. Device resource information can include the device's computing power resources, security resources, network resources, and other resource information.
[0051] Step S30: Determine the target component identifier based on the group behavior description and the device resource information, and generate the corresponding component behavior description.
[0052] In practical use, after determining the behavior description of the population and the device resource information of each device in the network to be scheduled, further matching can be performed to select the components that can execute the service in each functional cluster, thereby determining the target component identifier and the behavior that each component needs to perform during service execution, thus generating a component behavior description.
[0053] In a specific implementation, in order to reasonably determine the target component identifier, step S30 in this embodiment may include:
[0054] generate a security service policy based on the group behavior description and the device resource information;
[0055] generate a security group identification according to the security service policy;
[0056] find a corresponding security component through the security group identification to obtain a target component identification;
[0057] generate a component behavior description according to the security service policy and the target component identification.
[0058] It should be noted that after the algorithm network arrangement and scheduling device determines the group behavior description and the device resource information corresponding to each device in the to-be-scheduled algorithm network, it can consider the user demand and the resource situation in the algorithm power network, generate a security service policy that can meet the actual demand of the user and the current best security service policy in the current algorithm power network, and then extract the group identification of the functional group involved in the security service policy as the security group identification.
[0059] For example: assuming that the group behavior description is: the destination node is a node with certain computing power; the user required security level is medium, the firewall function and intrusion detection function are deployed for the user, and the user needs a large calculation service at one time, so a function with large computing power is needed, and in addition, the user needs low-latency transmission, so a low-latency link needs to be found;
[0060] At this time, the generated security service policy is: the firewall and intrusion detection function are deployed in the high-security group 1, the computing function is deployed in the high-computing-power group 2, and the low-latency function is deployed in the low-latency group 3.
[0061] At this time, the security group identification can be extracted from the security service policy, which is high-security group 1, high-computing-power group 2, and low-latency group 3, respectively.
[0062] In actual use, after the security group identification is determined, a security component with sufficient device resources can also be selected as a target component in the functional group corresponding to the security group identification, and the unique identification of the target component is taken as the target component identification, and then a component behavior description can be generated according to the security service policy and the target component identification.
[0063] For example, assuming security group identifiers are group A, group B, and group C, the unique identifier of the target component determined in the functional group corresponding to group A is R3, the unique identifier of the target component determined in the functional group corresponding to group B is R4, and the unique identifier of the target component determined in the functional group corresponding to group C is R5. Then, the generated component behavior description can be: deploy firewall functionality on node R3 to provide security protection; deploy intrusion detection functionality on node R4 to provide intrusion detection; and send computing tasks to the data center connected to R5 for implementation, with R5 providing low-latency transmission and the data center providing high-performance computing.
[0064] Step S40: Deploy services in the scheduling network according to the target component identifier and the component behavior description.
[0065] It should be noted that after determining the target component identifier and component behavior description, the corresponding component (which can be a physical device or functional node in the computing network to be scheduled) can be found in the computing network to be scheduled based on the target component identifier. Based on the component behavior description, the functions and software required for service execution can be deployed in the component, and the deployed functions or software can be configured accordingly (including software configuration, data flow settings, etc.) to ensure that the service can be executed smoothly.
[0066] To facilitate understanding, we will now combine... Figure 3 and 4 Please provide an explanation. Figure 3 This is a schematic diagram of the computer network orchestration and scheduling system structure in this embodiment. Figure 4 This is a schematic diagram of the computer network orchestration and scheduling interaction process in this embodiment.
[0067] like Figure 3 As shown, the computing network orchestration and scheduling system consists of a cluster of multiple computing network orchestration and scheduling devices. Based on functional differences, it can be mainly divided into five functional modules: a security service parsing module, an orchestration and scheduling module, a resource awareness deployment module, a computing network security identifier mapping module, and an intelligent knowledge storage module. Each functional module works together to execute the computing network orchestration and scheduling method provided in this embodiment. The functions of each module in this process are as follows:
[0068] The main function of the security service parsing module is to sense and collect user service requirements from the upper-layer computing network service operation layer, and parse out the specific functions required for the service. This functional module is divided into a security service perception submodule and a security service analysis submodule. The security service perception submodule receives the computing network security service identifier (CSID) and service description (CSBD) sent from the upper layer and sends them to the security service analysis submodule.
[0069] The security service analysis submodule analyzes the content of the algorithm network security service identifier, analyzes the actual required function of the service, generates the input parameters corresponding to the CSID and CSBD, and then sends them to the algorithm network security identifier mapping module. Generally speaking, in the traditional orchestration and scheduling framework, there will also be a similar process of analyzing user service demand, but most of these schemes do not mark the service or only give a simple number as a mark for a service. The service identifier added in the security service analysis module in this scheme describes a service in more detail and accurately, and can still identify the original service after the service is temporarily interrupted.
[0070] The algorithm network security identifier mapping module saves the entire content of the algorithm network security service identifier, the algorithm network security group identifier, and the algorithm network security component identity identifier, as well as the mapping table therebetween. Its main function is to complete the mutual mapping of the algorithm network security service identifier, the algorithm network security group identifier, and the algorithm network security component identity identifier. The algorithm network security service identifier mainly serves as a unique mark for a service, and also contains a user identity identifier as a record of the service initiator. The user identity identifier records various attributes of the user identity and source of the service, such as user name, user type, and user's operator, etc. The algorithm network security service identifier marks the detailed attributes of a service, such as the service publisher (i.e. the user identity identifier), the service name, the service type, etc.
[0071] After the device joins the network, it will be joined into different groups by the clustering mechanism according to its main function. A group refers to a collection of devices with the same or similar function. A device may have different functions, so a device may be in different groups at the same time. The algorithm network security group identifier is used to mark the attributes of a group, such as the group name and the group type (computing function group, storage function group, transmission function group, security function group), etc. The algorithm network security component identity identifier uniquely marks the attributes of a network device, such as the component name and the component type (router, switch, server), etc. After the security service analysis module completes the service analysis, the algorithm network security identifier mapping module receives the input parameters generated thereby, matches the service demand represented by the parameters, generates a group function behavior description CFBD, which is a service function chain SFC, and then sends it to the orchestration and scheduling module for service policy orchestration. After the orchestration and scheduling module completes the service policy orchestration, the algorithm network security identifier mapping module needs to receive the service policy generated by the orchestration and scheduling module, i.e. the algorithm network security group identifier CFID of the selected groups by the algorithm, matches the corresponding network components and their corresponding algorithm network security component identity identifier CNID according to the CFID, generates the corresponding component behavior description CNBD, and sends the result to the resource perception deployment module for deployment of the network components of the underlying algorithm network infrastructure layer.
[0072] The orchestration scheduling module fuses the algorithm network security group identification on the basis of the traditional orchestration scheduling function, and the main function is to calculate, generate and issue the service strategy. The module includes a service orchestration submodule and a routing control submodule. The service orchestration submodule calculates the best service deployment strategy and the corresponding container deployment strategy according to the family function behavior description CFBD sent by the algorithm network security identification mapping module and the whole network resource situation sent by the resource perception deployment module, selects the group to be used, and generates the corresponding algorithm network security group identification CFID. The routing control submodule generates the corresponding routing strategy and flow table according to the service strategy. Then the orchestration scheduling module sends the service strategy and the flow table to the resource perception deployment module to control the network equipment of the underlying network infrastructure layer. In the traditional orchestration scheduling framework, the orchestration function part is calculated by the service function chain SFC to obtain the service deployment strategy corresponding to each device. In this step, other schemes do not make the two-step operation of first finding the corresponding group and then finding the corresponding network equipment. The present application introduces the algorithm network security group identification on the basis of the traditional orchestration scheduling process, so that the orchestration efficiency of the present application is improved compared with the traditional framework, and the system overhead during orchestration is reduced.
[0073] The resource perception deployment module is mainly responsible for perceiving the computing power resources, security resources and network resources of the underlying algorithm network infrastructure layer. The computing power resources include the types and sizes of the computing power of each node; the security resources include the security level and security capability of each node; the network resources include the network topology, the data processing of each node, the bandwidth and throughput of each link, etc. The resource perception deployment module periodically detects and collects the above-mentioned resource situations and sends them to the orchestration scheduling module when the orchestration scheduling algorithm is executed to query the resource situations, so as to serve as the basis for orchestration scheduling. In addition, when the resource state of the underlying algorithm network infrastructure changes, the underlying device will immediately report it to the resource perception deployment module to ensure its real-time update.
[0074] After the orchestration scheduling is completed, the resource perception deployment module also needs to receive the strategy results generated by the orchestration scheduling module, issue the strategy and flow table to the corresponding network equipment, and control the equipment to perform the corresponding operation. The resource perception of the traditional orchestration scheduling framework is mostly one-way, while the resource perception deployment module of the present application has both the "reporting" type resource perception from the lower layer to the upper layer and the "detection" type resource perception from the upper layer to the lower layer. The mixed perception mode makes the orchestration scheduling framework of the present application have more accurate and real-time resource perception ability compared with the traditional framework.
[0075] The main function of the intelligent knowledge storage module is to save the historical services and their corresponding policy solutions for a period of time to reduce the computing pressure of the system. The intelligent knowledge storage module mainly includes three parts: service demand, service policy and routing policy. The service demand part stores the service content generated in a period of time; the service policy part stores the service policy corresponding to the service; and the routing policy part stores the routing policy corresponding to the service. When a new service arrives, the intelligent knowledge storage module is first queried to determine whether the same service has been generated in a period of time. If there is a matching search result, the corresponding service policy and routing policy are directly deployed without the need for policy calculation of the arrangement and scheduling module, thereby relieving the computing pressure of the system.
[0076] As shown in Figure 4 The algorithm network arrangement and scheduling interaction process of the embodiment includes the following steps:
[0077] 1. The user sends the user's own security service demand in the form of natural language to the algorithm network service operation layer. The algorithm network service operation layer analyzes the security service demand from the natural language form into the algorithm network security service behavior description CSBD, and generates the corresponding algorithm network security service identifier CSID according to the user characteristics. Then, the algorithm network service operation layer sends the generated CSID and CSBD to the security service analysis module for further analysis and processing of the security service.
[0078] 2. After receiving the CSID and CSBD, the security service analysis module first sends the CSID to the intelligent knowledge storage module to query whether the same service has been generated in a period of time in the intelligent knowledge storage module, and whether there is a corresponding arrangement and deployment policy solution for the service.
[0079] 3. The intelligent knowledge storage module queries its own database. If the same historical service as the service is found, the service policy and path policy corresponding to the historical service are directly found, the corresponding service function and flow table are deployed to the corresponding network components in the algorithm network infrastructure layer, and the arrangement and deployment are completed. If the same historical service is not found, the result is returned to the security service analysis module.
[0080] 4. After receiving the message that the historical service is not found, the security service analysis module starts to analyze the service by itself. The CSID and CSBD are converted and sent to the algorithm network security identifier mapping module as input parameters.
[0081] 5. The algorithm network security identifier mapping module queries the identifier mapping table maintained by itself according to the received service parameters, and maps the corresponding parameters to generate the group function behavior description CFBD. The group function behavior description is used to identify the behaviors that the group needs to perform to complete the service, that is, the service function chain SFC. Then, the CFBD is sent to the arrangement and scheduling module.
[0082] 6、The orchestration scheduling module receives the CFBD and sends a query message to the resource perception deployment module to query the resource status of each device in the current network.
[0083] 7、The resource perception deployment module periodically runs according to the process in Section 7.3.1 in normal state, sends a probe message to the devices in the network infrastructure layer, and real-time perceives the computing power resources, security resources, and network resources of the devices in the network infrastructure layer, and stores them in its own database. Therefore, when the resource perception deployment module receives the query message from the orchestration scheduling module, it sends the current network device resource status stored in itself to the orchestration scheduling module.
[0084] 8、The orchestration scheduling module receives the information, inputs the current computing power resources, security resources, and network resources of the network devices and the CFBD of the population function behavior description into its own orchestration scheduling algorithm, which comprehensively considers user demand and network resource status, calculates the best security service orchestration scheduling strategy that meets user demand and the current network state, generates the corresponding CFID of the network security population, and sends the matched CFID to the network security identification mapping module, and stores the corresponding strategy in the intelligent knowledge storage module.
[0085] 9、The network security identification mapping module matches the components involved in the security service strategy according to the received strategy scheme, the CNID of the corresponding bottom layer device stored in the identification mapping table, and generates the CNBD of the behavior of each bottom layer device according to the security service strategy, and sends the selected components to the orchestration scheduling module.
[0086] 10、The orchestration scheduling module receives the selected components, generates the route and corresponding flow table of the selected components, and sends them to the resource perception deployment module together with the CNID and CNBD of the network identification mapping module.
[0087] 11、The resource perception deployment module receives the required deployment function CNID and CNBD and the corresponding flow table, sends the current security service and the corresponding security service strategy scheme, component behavior description, and routing forwarding flow table to the knowledge base module for a period of time, and uses it to deal with the same service that may come later. Then deploy the corresponding service function to the corresponding bottom layer device, and send the flow table to the devices required by the current security service to control their execution of related operations.
[0088] 12、Algorithm network infrastructure layer device receives the instruction, if the current resource is sufficient, then complete the deployment of the relevant function, if the resource is insufficient, then deployment failure, the deployment result is returned to the resource-aware deployment module.
[0089] 13、Resource-aware deployment module further returns the deployment result to the algorithm network service operation layer, thereby returning to the user. If the deployment is successful, the user can send data to the corresponding device in the network at this time, and the network completes the service to the user. If the deployment fails, the user is informed of the result of the deployment failure.
[0090] The embodiment generates a service behavior description according to the received security service demand, and generates a security service identifier according to the user characteristics corresponding to the security service demand; generates a group behavior description according to the service behavior description and the security service identifier, and obtains device resource information corresponding to each device in the to-be-scheduled algorithm network; determines a target component identifier based on the group behavior description and the device resource information, and generates a corresponding component behavior description; and performs service deployment in the to-be-scheduled algorithm network according to the target component identifier and the component behavior description. Since the security service identifier is used, which is irrelevant to the user's location and only related to the user's identity, it is ensured that the algorithm network security service identifier will not change when the user disconnects and reconnects or part of the nodes in the service function chain are damaged, and the system can quickly recover the previous service according to the identifier.
[0091] Reference Figure 5 , Figure 5 The flowchart of the second embodiment of the algorithm network arrangement and scheduling method is shown in the figure.
[0092] Based on the first embodiment, the step S40 of the algorithm network arrangement and scheduling method comprises:
[0093] Step S401: generating a routing strategy according to the target component identifier and the component behavior description.
[0094] Step S402: searching for a target component corresponding to the target component identifier in the to-be-scheduled algorithm network.
[0095] Step S403: performing service deployment in the target component based on the component behavior description, and issuing the routing strategy to the target component.
[0096] In a specific implementation, after the target component identifier and the component behavior description are determined, a complete service execution link, i.e., a routing strategy, can also be constructed according to the target component identifier and the component behavior description, and then service deployment is performed in the to-be-scheduled algorithm network according to the component behavior description, and finally the routing strategy is issued to the target component, so that the target component controls function execution and data flow direction according to the routing strategy, thereby completing service execution.
[0097] The service execution link can include functions that should be executed by each component and specific flow of data, and can be represented in the form of a routing flow table.
[0098] For example, assuming that the target component identifier includes R3, R4, and R5, the component behavior is described as follows: deploying a firewall function at node R3; deploying an intrusion detection function at node R4; and sending a computing task to a data center connected to R5 for implementation, and R1 is a data entry of the user in the computing network, and R2 is a link that must be passed between R1 and R3, the service execution link can be user→R1→R2→R3→R4→R5→data center. At this time, the computing network arrangement and scheduling device can first control the firewall function to be deployed to component R3, and the intrusion detection function to be deployed to component R4, and then send the service execution link to R1, R2, R3, R4, and R5. At this time, R1 receives data from the user, and transmits the data to R3 through R2, R3 transmits the data to R4 after filtering by the firewall, R4 transmits the data to R5 after passing the intrusion detection, and R5 forwards the data to the data center connected thereto, which is implemented by the data center. At this time, one service execution is completed.
[0099] In a possible implementation manner of the embodiment, in order to avoid unnecessary resource consumption, the step S20 can include the following steps.
[0100] Searching for a historical arrangement and scheduling record corresponding to the security service identifier in the intelligent knowledge storage table;
[0101] If the search result is empty, generating a group behavior description according to the service behavior description and the security service identifier, and obtaining device resource information corresponding to each device in the to-be-scheduled computing network.
[0102] It should be noted that the intelligent knowledge storage table can have a historical arrangement and scheduling record. The historical arrangement and scheduling record can be a record generated according to a security service demand of a user when previously performing computing network arrangement and scheduling. The historical arrangement and scheduling record can at least include a security service identifier, a routing strategy, and a security service strategy.
[0103] In actual use, searching for a historical arrangement and scheduling record corresponding to the security service identifier in the intelligent knowledge storage table can be searching for whether there is a historical arrangement and scheduling record containing a security service identifier consistent with the currently generated security service identifier.
[0104] It can be understood that if the search result is empty, it indicates that the security service demand corresponding to the currently generated security service identifier has not been arranged and scheduled by the computing network before. Therefore, a group behavior description can be generated according to the service behavior description and the security service identifier, and device resource information corresponding to each device in the to-be-scheduled computing network can be obtained, so as to continue to execute subsequent steps.
[0105] Since a large amount of resources needs to be consumed each time the network arrangement scheduling is performed, and if the network arrangement scheduling has been performed previously, the service deployment can be directly performed according to the routing strategy and the security service strategy generated previously, without re-performing the network arrangement scheduling, so as to reduce unnecessary resource consumption as much as possible. Therefore, after the step of searching, in the intelligent knowledge storage table, for the historical arrangement scheduling record corresponding to the security service identifier, the embodiment can further include:
[0106] If the historical arrangement scheduling record corresponding to the security service identifier is found, the routing strategy and the security service strategy are read from the historical arrangement scheduling record.
[0107] The service deployment is performed according to the routing strategy and the security service strategy.
[0108] It should be noted that if the historical arrangement scheduling record corresponding to the security service identifier is found, it indicates that the security service demand corresponding to the security service identifier has been subjected to the network arrangement scheduling previously, and at this time, the routing strategy and the security service strategy generated previously can be reused to reduce resource consumption. Therefore, the routing strategy and the security service strategy can be read from the historical arrangement scheduling record, and the service deployment is performed according to the routing strategy and the security service strategy.
[0109] The specific implementation manner of performing the service deployment according to the routing strategy and the security service strategy is consistent with the implementation manners of the above embodiment and the present embodiment, and can be referred to the above explanation. Here, no longer be described in detail.
[0110] In actual use, since the device resources in the computing power network also change over time, the routing strategy and the security service strategy contained in the historical arrangement scheduling record can also have a certain valid time. Therefore, the historical arrangement scheduling record stored in the intelligent knowledge storage table for a storage time longer than a preset time threshold can be cleared periodically. The preset time threshold can be set by the manager of the network arrangement scheduling device in advance, and the storage time corresponding to the historical arrangement scheduling record can be the difference between the time when the historical arrangement scheduling record is stored in the intelligent knowledge storage table and the current time.
[0111] In a possible implementation manner of the present embodiment, in order to ensure that the record subjected to the network arrangement scheduling previously can be found subsequently, the step S403 can further include, before the step S403:
[0112] The historical arrangement scheduling record is generated according to the security service identifier, the routing strategy and the security service strategy.
[0113] The historical arrangement scheduling record is stored in the intelligent knowledge storage table.
[0114] It should be noted that generating historical orchestration and scheduling records based on security service identifiers, routing policies, and security service policies can be achieved by assembling these elements in a preset format. Furthermore, when storing historical orchestration and scheduling records in the intelligent knowledge storage table, the exact moment of storage can also be recorded.
[0115] In its specific implementation, the network orchestration and scheduling provided in this embodiment is also applicable to security policy migration scenarios. For ease of understanding, it is now combined with... Figure 6 , 7 The following points are provided for explanation, but do not limit the scope of this scheme. Figure 6 This is a schematic diagram of the normal orchestration process in this embodiment. Figure 7 This is a schematic diagram of the service migration process in this embodiment. Figure 8 This is a schematic diagram of the service reconnection process in this embodiment.
[0116] Consider as Figure 6 The scenario shown has three distinct computing domains. The nodes in the network are controlled by a network orchestration and scheduling system consisting of five servers in the control plane. Each server represents one of the five functional modules of the network orchestration and scheduling. The computing network includes one access user (node R1) and one data center (node R5).
[0117] Before a user initiates a service request, the resource-aware deployment server is already working normally, that is, periodically sending probe messages to the nodes of its three subordinate computing power domains. After receiving the probe messages, each computing power domain node returns its own security resources, computing power resources, and network resources to the resource-aware deployment server.
[0118] At a certain moment, a user initiates a service request on the network. Assuming the user has passed pre-process security authentication such as identity authentication and access control, and the service has been authorized, the following process can be executed to complete the network orchestration and scheduling:
[0119] 1. A user initiates a service request to the network through node R1, requesting a computational task with a medium security level. This request is sent to the computing domain control server, and further to the top-level controller. The controller generates a Security Service Identifier (CFID) and a Service Behavior Description (CFBD) for this service based on the user's service request, and sends the CFID and CFBD to the security service resolution server.
[0120] 2. The network security service resolution server first sends the network security service identifier to the intelligent knowledge storage server to check if there is a similar historical service.
[0121] 3、The intelligent knowledge storage server queries its own library, if a match is successful, the corresponding service strategy and routing strategy are directly found and issued to the resource-aware deployment server. Step 13) is executed. Otherwise, the query failure result is returned to the security service analysis server, and step 4) is executed.
[0122] 4、The security service analysis server analyzes the CSID and CSBD to obtain the user's service input parameters this time.
[0123] 5、The security service analysis server sends the service-related input parameters to the algorithm network security identifier mapping server.
[0124] 6、The algorithm network security identifier mapping server learns the user's service requirements this time according to the parameters: the destination node is a node with certain computing power; the user's required security level is medium, so the user is deployed with firewall function and intrusion detection function, and the user needs a large computing service, so a function with large computing power is needed, and the user needs low-latency transmission, so a low-latency link needs to be found. According to the above requirements, the colony behavior description CFBD, i.e., the service function chain SFC, is generated.
[0125] 7、The security service analysis server sends the colony function behavior description CFBD to the orchestration and scheduling server.
[0126] 8、The orchestration and scheduling server learns from the colony function behavior description that the target colony for function deployment is a colony that meets the above requirements, and needs to deploy functions such as firewall function and intrusion detection function, and needs to allocate computing tasks. Then the orchestration and scheduling module sends a call command to the resource-aware deployment server to retrieve the network resource information.
[0127] 9、The resource-aware deployment server sends the network resource information stored in itself to the orchestration and scheduling module.
[0128] 10、After receiving the network resource information, the orchestration and scheduling server inputs it together with the information obtained in step 6) into the orchestration algorithm. After calculation by the orchestration algorithm, the service strategy scheme this time is obtained: the firewall and intrusion detection function are deployed in the high-security colony 1, the computing function is deployed in the high-computing-power colony 2, and the low-latency function is deployed in the low-latency colony 3, the security colony identifier CFID is matched to the three colonies, and the CFID is sent to the algorithm network security identifier mapping server.
[0129] 11、The algorithm network security identifier mapping server further processes the CFID, and matches to specific components R3, R4, and R5, specifically: deploying a firewall function at node R3; deploying an intrusion detection function at node R4; and sending a calculation task to a data center connected to R5 for implementation, matching to the component identity identifier CNID of the corresponding algorithm network security component of each node, and generating the corresponding component behavior description CNBD, and then sending the result to the arrangement and scheduling module to calculate the routing strategy.
[0130] 12、The arrangement and scheduling server generates a route for the user -> R1 -> R2 -> R3 -> R4 -> R5 -> data center, and then sends the result together with the CNID and CNBD selected by the algorithm network security identifier mapping server to the resource-aware deployment server.
[0131] 13、The resource-aware deployment server receives the deployment strategy, first makes a copy and sends it to the intelligent knowledge storage server for saving. Then, according to the function deployment strategy and the routing strategy content, the firewall function is deployed to node R3, the intrusion detection function is deployed to node R4, and the routing flow table is sent to R1, R2, R3, R4, and R5. Then the execution result is returned to the user.
[0132] 14、The user receives the deployment success result and starts to send calculation tasks to the network.
[0133] As shown in Figure 7 , if at a certain moment, due to a large-scale power outage in the right lower corner of the computing power domain, the original data center can no longer be used, the user service needs to be migrated to the middle computing power domain at this time, the following steps can be performed:
[0134] 1、At a certain moment, a large-scale power outage occurs in the computing power domain, and the original data center is offline.
[0135] 2、Due to changes in the underlying link, the remaining nodes report the change to the resource-aware deployment server, and the resource-aware deployment server also detects that the original data center has become unusable by issuing a detection packet, at which time the security service must be migrated to a new computing power domain.
[0136] 3、The resource-aware deployment server reports to the arrangement and scheduling server and initiates a service strategy migration request.
[0137] 4、After receiving the request, the arrangement and scheduling server does not need to perform service analysis again since the algorithm network security service identifier of this service does not change, and directly looks up the corresponding family behavior description CFBD and security family identifier CFID of this service from the intelligent knowledge storage module.
[0138] 5. The intelligent knowledge storage server retrieves the corresponding group function behavior description and the algorithm network security group identifier that match its record according to the algorithm network security service identifier, and returns them to the arrangement and scheduling server.
[0139] 6. The arrangement and scheduling module sends the corresponding CFID and CFBD to the algorithm network security identifier mapping server.
[0140] 7. After receiving the CFID and CFBD, the algorithm network security identifier mapping server calculates the new deployment strategy with the minimum migration cost and does not affect the original service of the new computing power domain according to the service strategy migration algorithm, which takes the minimum migration time delay and cost as the optimization target, further matches to nodes R6 and R7, deploys firewall function in node R6, and deploys intrusion detection function in node R7, queries the component identity identifier CNID of the corresponding algorithm network security component R6 and R7, and generates a new component behavior description CNBD for it, sends the matching situation to the arrangement and scheduling server, and generates a new route.
[0141] 8. The route generated by the arrangement and scheduling server for communication with the new data center changes to R1→R2→R8→R7→R6→data center, and then the result is sent to the resource-aware deployment server together with the CNID and CNBD selected by the algorithm network security identifier mapping server.
[0142] 9. The resource-aware deployment server receives the deployment strategy, first copies a copy, and sends it to the knowledge base server for saving. Then, according to the content of the component behavior description, the firewall function is migrated from node R3 to node R6, and the intrusion detection function is migrated from node R4 to node R7, and the new routing flow table is downloaded to R6, R7 and R8. The security policy migration is completed.
[0143] Obviously, during the security policy migration, since the user's security requirements do not change and the required functions do not change, the group identifier does not change, and the migration algorithm can directly calculate and find suitable new function deployment devices in the original corresponding group without calculating all network devices. Compared with the existing scheme of calculating the security policy migration strategy according to all network devices, the application can further reduce the cost and time delay of security policy migration, and realize efficient and lossless migration.
[0144] In addition, based on the scenario shown in Figure 6 , another situation needs to be considered, such as Figure 8 , at a certain moment, the user disconnects and reconnects, and node R4 is damaged, and a new node needs to be selected to undertake the function deployed by node R4. The following steps can be performed for reconnection:
[0145] 1. At a certain moment, the user disconnects and reconnects, and node R4 is disconnected.
[0146] 2, The infrastructure layer senses the change and reports the state to the resource-aware deployment server.
[0147] 3, The resource-aware deployment server sends the situation and the current network-wide resource situation to the orchestration deployment server.
[0148] 4, Since the user algorithm network security service identifier has not changed, the orchestration deployment server queries the intelligent knowledge storage server for the deployment strategy corresponding to the service.
[0149] 5, The intelligent knowledge storage server queries its own library and returns the strategy corresponding to the service to the orchestration deployment server.
[0150] 6, Since the user algorithm network security service identifier has not changed, the user can continue the service that was not completed before the disconnection. For the disconnection of node R4, the orchestration deployment server selects a temporary deployment node R9 nearby, deploys the function of R4 to R9, generates the corresponding routing flow table, and sends the strategy to the algorithm network identifier mapping server.
[0151] 7, The algorithm network identifier mapping server receives the change of the strategy, matches the component identity identifier CNID of the algorithm network security component corresponding to node R9 and generates the corresponding component behavior description CNBD, and sends the new strategy to the resource-aware deployment server.
[0152] 8, The resource-aware deployment server receives the new strategy, issues the new flow table and execution instruction to R9, and then the original service can continue.
[0153] In the algorithm network orchestration scheduling process of the embodiment, the security group identifier is used to well and smoothly connect the security service identifier of the upper layer and the component identity identifier of the algorithm network security component of the lower layer. Through the two-step mapping scheme of first mapping the security service identifier to the security group identifier to obtain a type of device with the required function, and then further mapping to the component identity identifier to obtain the target component identifier and a few specific devices, the computing amount required for mapping the user service demand to the specific execution device is greatly reduced compared with the prior art, the data amount stored by the controller is reduced, the storage pressure is reduced, the running time required for calculation is greatly reduced, the overhead of the orchestration scheduling process is reduced, and the flexibility is higher.
[0154] Reference Figure 9 , Figure 9 The flowchart of the third embodiment of the algorithm network orchestration scheduling method of the application is shown.
[0155] Based on the first embodiment, the step S20 of the algorithm network orchestration scheduling method of the embodiment comprises:
[0156] Step S201: generating a group behavior description according to the service behavior description and the security service identifier.
[0157] Step S202: obtaining a device resource information table.
[0158] Step S203: reading device resource information corresponding to each device in the to-be-scheduled computing network from the device resource information table.
[0159] It should be noted that the device resource information table can be a data table recording device resource information of each device in the to-be-scheduled computing network. After obtaining the device resource information table, the device resource information corresponding to each device in the to-be-scheduled computing network can be read by parsing the device resource information table.
[0160] In a possible implementation manner of the embodiment, since the device resource information of each device in the computing network changes over time, the data in the device resource information table can have a part of lag. In order to ensure that the current obtained device resource information corresponding to each device in the to-be-scheduled computing network, the step S201 of the embodiment can further include, before the step S201:
[0161] sending a probe packet to each device in the to-be-scheduled computing network, and each device in the to-be-scheduled computing network feeds back real-time resource information when receiving the probe packet;
[0162] updating the device resource information table according to the real-time resource information when receiving the real-time resource information fed back by each device in the to-be-scheduled computing network.
[0163] It should be noted that, since the device resource information of each device in the computing network changes over time, when the device resource information corresponding to each device in the to-be-scheduled computing network is needed to be obtained, a probe packet can be first sent to each device in the to-be-scheduled computing network, and each device in the to-be-scheduled computing network feeds back real-time resource information when receiving the probe packet. Then, the computing network scheduling device can update the device resource information table according to the real-time resource information fed back by each device in the to-be-scheduled computing network. Thereafter, the information in the device resource information table is read, and the latest device resource information of each device in the to-be-scheduled computing network at the current time can be obtained.
[0164] In a possible implementation manner of the embodiment, the device in the to-be-scheduled computing network can also actively apply to update the device resource information table. In this case, the step S201 of the embodiment can further include, before the step S201:
[0165] extracting a component identifier from the notification packet when receiving the notification packet;
[0166] parsing the component identifier to obtain device resource information;
[0167] Update the device resource information table according to the device resource information.
[0168] It should be noted that the notification message can be sent to the algorithm network scheduling device when the device successfully registers in the to-be-scheduled algorithm network (i.e., sent by the device that has just successfully joined the to-be-scheduled algorithm network), or sent to the algorithm network scheduling device when any device in the to-be-scheduled algorithm network detects a change in its own device resources.
[0169] The component identity can be assembled according to real-time resource information of the device, and can specifically include: computing power resource situation of the device, security resource situation of the device, network resource situation of the device, and the like. The computing power resource situation of the device can include the type of computing power (CPU, GPU, FPGA, etc.) currently available to the device, the size of the computing power (unit FLOPS) currently available to the device, and the like. The security resource situation of the device can include the security level of the computing power domain in which the device is located, the security level of the device itself (low, medium, and high levels), and the security functions (firewall, intrusion detection, etc.) possessed by the device. The network resource situation of the device can include the neighbor nodes of the device, the link state (delay, bandwidth, throughput, etc.) of the link connected by the device, and the like.
[0170] It can be understood that after the notification message is obtained, the component identity can be extracted from the notification message, and then the component identity is parsed in a preset format, so that the device resource information is read. At this time, the algorithm network scheduling device can update the device resource information table according to the device resource information.
[0171] For ease of understanding, examples will now be provided, but the present scheme is not limited thereto:
[0172] In a specific implementation, in order to ensure that the algorithm network scheduling of the present embodiment can achieve the goal of high resource utilization and strong real-time performance, the resources of each device in the to-be-scheduled algorithm network need to be systematically and real-time perceived. The resource perception process can include the following steps:
[0173] 1. After the bottom layer device completes registration, the management node of each computing power domain of the bottom layer generates the algorithm network security component identity of the corresponding device, and sends the identity to the resource perception deployment module of the algorithm network scheduling control layer.
[0174] 2. After receiving the algorithm network security component identity, the resource perception deployment module analyzes the content of the identity to obtain the resource situation related to the device. Specifically, it includes:
[0175] Computing power resource situation of the device: type of computing power (CPU, GPU, FPGA, etc.) currently available to the device, size of computing power (unit FLOPS) currently available to the device, and the like.
[0176] Security resource of the device: security level of the computing power domain where the device is located, security level of the device itself (low, medium, and high), and security functions (firewall, intrusion detection, etc.) possessed by the device.
[0177] Network resource of the device: neighbor nodes of the device, and link state (delay, bandwidth, throughput, etc.) of the link connected by the device.
[0178] After the resource perception deployment module analyzes the resource situation of the device, it organizes the data into a tabular form and stores it in its own database, waiting for the orchestration and scheduling module to query.
[0179] 3. The database of the resource perception deployment module needs to be updated every small time T to ensure the real-time nature of the stored data. At this time, the resource perception deployment module sends a probe packet to the underlying device.
[0180] 4. After receiving the probe packet, the underlying device sends its current resource data situation to the resource perception deployment module. The resource perception deployment module updates its database after receiving it.
[0181] Or,
[0182] When the resource state of the underlying device changes, such as temporary local occupation of computing power, changes in link state, and adjustment of security resources, a notification packet is sent to the resource perception deployment module, which updates its database after receiving it.
[0183] The embodiment combines the reporting from the underlying device to the controller and the probing from the controller to the underlying device for the perception of the device resources in the computing network to be scheduled. Compared with the resource perception scheme of only the underlying device actively reporting or only the controller actively probing, the hybrid scheme of the embodiment can solve the problems of missing report or malicious false report of the underlying device when reporting and the problem of excessive overhead caused by frequent probing of the controller.
[0184] In addition, the embodiment of the present application also proposes a storage medium, which stores a computing network orchestration and scheduling program. When the computing network orchestration and scheduling program is executed by a processor, the steps of the computing network orchestration and scheduling method as described above are implemented.
[0185] In addition, the embodiment of the present application also proposes a computer program product, which includes a computing network orchestration and scheduling program. When the computing network orchestration and scheduling program is executed by a processor, the steps of the computing network orchestration and scheduling method as described above are implemented.
[0186] Reference Figure 10 , Figure 10 The structure block diagram of the first embodiment of the computing network orchestration and scheduling device of the present application is shown in the figure.
[0187] AsFigure 10 As shown, the algorithm network arrangement and scheduling device provided by the embodiment of the application comprises:
[0188] The service analysis module 10 is configured to generate a service behavior description according to the received security service requirement, and generate a security service identifier according to the user characteristics corresponding to the security service requirement;
[0189] The resource perception module 20 is configured to generate a group behavior description according to the service behavior description and the security service identifier, and obtain device resource information corresponding to each device in the algorithm network to be scheduled;
[0190] The arrangement and scheduling module 30 is configured to determine a target component identifier based on the group behavior description and the device resource information, and generate a corresponding component behavior description;
[0191] The service deployment module 40 is configured to perform service deployment in the algorithm network to be scheduled according to the target component identifier and the component behavior description.
[0192] According to the embodiment, the security service requirement is responded to, the service behavior description is generated according to the security service requirement, and the security service identifier is generated according to the user characteristics corresponding to the security service requirement; the group behavior description is generated according to the service behavior description and the security service identifier, and the device resource information corresponding to each device in the algorithm network to be scheduled is obtained; the target component identifier is determined based on the group behavior description and the device resource information, and the corresponding component behavior description is generated; and the service deployment is performed in the algorithm network to be scheduled according to the target component identifier and the component behavior description. Since the security service identifier is used, which is irrelevant to the user location and only related to the identity of the user, it is ensured that the algorithm network security service identifier will not change when the user is disconnected and reconnected or part of the nodes in the service function chain are damaged, and the system can quickly restore the previous service according to the identifier.
[0193] In a possible implementation manner of the embodiment, the service analysis module 10 is further configured to generate a security service strategy based on the group behavior description and the device resource information; generate a security group identifier according to the security service strategy; find the corresponding security component through the security group identifier to obtain the target component identifier; and generate the component behavior description according to the security service strategy and the target component identifier.
[0194] In a possible implementation manner of the embodiment, the service deployment module 40 is further configured to generate a routing strategy according to the target component identifier and the component behavior description in a possible implementation manner of the embodiment; find the target component corresponding to the target component identifier in the algorithm network to be scheduled; perform service deployment in the target component based on the component behavior description, and issue the routing strategy to the target component.
[0195] In a possible implementation of the present embodiment, the service deployment module 40 is further configured to generate a historical orchestration scheduling record according to the security service identifier, the routing policy and the security service policy; and store the historical orchestration scheduling record into the intelligent knowledge storage table.
[0196] In a possible implementation of the present embodiment, the resource perception module 20 is further configured to search for the historical orchestration scheduling record corresponding to the security service identifier in the intelligent knowledge storage table; if the search result is empty, generate a group behavior description according to the service behavior description and the security service identifier, and obtain the device resource information corresponding to each device in the to-be-scheduled algorithm network.
[0197] In a possible implementation of the present embodiment, the resource perception module 20 is further configured to, if the historical orchestration scheduling record corresponding to the security service identifier is found, read the routing policy and the security service policy from the historical orchestration scheduling record; and perform service deployment according to the routing policy and the security service policy.
[0198] In a possible implementation of the present embodiment, the resource perception module 20 is further configured to obtain a device resource information table; and read the device resource information corresponding to each device in the to-be-scheduled algorithm network from the device resource information table.
[0199] In a possible implementation of the present embodiment, the resource perception module 20 is further configured to send a probe packet to each device in the to-be-scheduled algorithm network, each device in the to-be-scheduled algorithm network feeds back real-time resource information upon receiving the probe packet; and update the device resource information table according to the real-time resource information upon receiving the real-time resource information fed back by each device in the to-be-scheduled algorithm network.
[0200] In a possible implementation of the present embodiment, the resource perception module 20 is further configured to, upon receiving a notification packet, extract a component identity identifier from the notification packet, the notification packet being sent by a device in the to-be-scheduled algorithm network upon successful registration, or being sent by a device in the to-be-scheduled algorithm network upon a change in device resource; analyze the component identity identifier to obtain device resource information; and update the device resource information table according to the device resource information.
[0201] It should be understood that the above is only for illustration, and does not limit the technical solutions of the present application. In specific applications, those skilled in the art can set them up according to needs, and the present application does not limit this.
[0202] It should be noted that the above-described workflow is merely illustrative and does not limit the scope of protection of the present application. In actual applications, a person skilled in the art can select part or all of the above-described workflow to achieve the purpose of the present embodiment according to actual needs, which is not limited herein.
[0203] In addition, technical details not described in detail in the present embodiment can be found in the network arrangement scheduling method provided by any embodiment of the present application, which will not be described here.
[0204] In addition, it should be noted that in this document, the terms "comprise", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or system comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or system. Without more limitations, the element defined by the statement "comprises a" does not exclude the presence of another identical element in the process, method, article or system comprising the element.
[0205] The above-mentioned serial numbers of the embodiments of the present application are only for description, not representing the advantages or disadvantages of the embodiments.
[0206] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk), and includes a plurality of instructions for making a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) execute the methods described in various embodiments of the present application.
[0207] The above is only the preferred embodiment of the present application, and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation, or direct or indirect application in other related technical fields, is also included in the patent protection scope of the present application.
Claims
1. A method for scheduling a network arrangement, characterized by The algorithm network arrangement scheduling method comprises: In response to the received security service requirement, a service behavior description is generated according to the security service requirement, and a security service identifier is generated according to the user characteristics corresponding to the security service requirement; A group behavior description is generated according to the service behavior description and the security service identifier, and device resource information corresponding to each device in a to-be-scheduled algorithm network is obtained; A target component identifier is determined based on the group behavior description and the device resource information, and a corresponding component behavior description is generated; Service deployment is performed in the to-be-scheduled algorithm network according to the target component identifier and the component behavior description.
2. The network orchestration scheduling method of claim 1, wherein, The determination of the target component identifier based on the group behavior description and the device resource information, and the generation of the corresponding component behavior description, comprise: A security service strategy is generated based on the group behavior description and the device resource information; A security group identifier is generated according to the security service strategy; The target component identifier is obtained by searching for the corresponding security component through the security group identifier; A component behavior description is generated according to the security service strategy and the target component identifier.
3. The grid orchestration scheduling method of claim 1, wherein, The service deployment in the to-be-scheduled algorithm network according to the target component identifier and the component behavior description, comprise: A routing strategy is generated according to the target component identifier and the component behavior description; The target component corresponding to the target component identifier is searched for in the to-be-scheduled algorithm network; Service deployment is performed in the target component based on the component behavior description, and the routing strategy is pushed to the target component.
4. The network orchestration scheduling method of claim 3, wherein, Before the service deployment in the target component based on the component behavior description, and the pushing of the routing strategy to the target component, it further comprises: A historical arrangement scheduling record is generated according to the security service identifier, the routing strategy and the security service strategy; The historical arrangement scheduling record is stored in an intelligent knowledge storage table.
5. The grid orchestration scheduling method of claim 1, wherein, The generation of the group behavior description according to the service behavior description and the security service identifier, and the obtaining of the device resource information corresponding to each device in the to-be-scheduled algorithm network, comprise: The historical arrangement scheduling record corresponding to the security service identifier is searched for in the intelligent knowledge storage table; If the search result is empty, the group behavior description is generated according to the service behavior description and the security service identifier, and the device resource information corresponding to each device in the to-be-scheduled algorithm network is obtained.
6. The network orchestration scheduling method of claim 5, wherein, After the search for the historical arrangement scheduling record corresponding to the security service identifier in the intelligent knowledge storage table, it further comprises: If the historical arrangement scheduling record corresponding to the security service identifier is found, the routing strategy and the security service strategy are read from the historical arrangement scheduling record; Service deployment is performed according to the routing strategy and the security service strategy.
7. The grid orchestration scheduling method of claim 1, wherein, The obtaining of the device resource information corresponding to each device in the to-be-scheduled algorithm network, comprises: An equipment resource information table is obtained; The device resource information corresponding to each device in the to-be-scheduled algorithm network is read from the equipment resource information table.
8. The network arrangement scheduling method according to claim 7, wherein, Before the obtaining of the equipment resource information table, it further comprises: A probe packet is sent to each device in the to-be-scheduled algorithm network, and real-time resource information is fed back by each device in the to-be-scheduled algorithm network upon receiving the probe packet; When receiving the real-time resource information fed back by each device in the to-be-scheduled algorithm network, the device resource information table is updated according to the real-time resource information.
9. The network arrangement scheduling method according to claim 7, wherein, Before the device resource information table is acquired, the method further includes: When receiving the notification message, extracting the component identity from the notification message, the notification message being sent by a device in the to-be-scheduled algorithm network when the device registers successfully or when the device resource changes; Analyzing the component identity to obtain device resource information; Updating the device resource information table according to the device resource information.
10. A network orchestration and scheduling device, comprising: The algorithm network scheduling device includes a processor, a memory, and an algorithm network scheduling program stored in the memory and executable on the processor, and the algorithm network scheduling program, when executed by the processor, implements the steps of the algorithm network scheduling method according to any one of claims 1-9.
11. A network orchestration scheduling system, comprising: The algorithm network scheduling system includes a security service analysis module, a scheduling module, a resource perception deployment module, an algorithm network security identifier mapping module, and an intelligent knowledge storage module, and each functional module in the algorithm network scheduling system cooperates to execute the steps of the algorithm network scheduling method according to any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores an algorithm network scheduling program, and the algorithm network scheduling program, when executed, implements the steps of the algorithm network scheduling method according to any one of claims 1-9.
13. A computer program product, characterised in that, The computer program product includes an algorithm network scheduling program, and the algorithm network scheduling program, when executed, implements the steps of the algorithm network scheduling method according to any one of claims 1-9.