Resource allocation method, device and system, electronic equipment and storage medium

By dynamically adjusting resource quotas based on account information, the problems of resource waste and security risks in existing technologies are solved, achieving secure and rational resource allocation and improving resource utilization and cloud platform stability.

CN121077992APending Publication Date: 2025-12-05ALIBABA CLOUD COMPUTING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410726810.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-06-05
Publication Date
2025-12-05

AI Technical Summary

Technical Problem

The fixed resource quota design in existing technologies leads to resource waste and security risks, cannot adapt to different user and network security needs, and poses risks of malicious inventory detection and resource theft.

Method used

The target security level is determined based on the account information. The resource quota is dynamically adjusted based on the security level and the resource allocation rules. The resource allocation rules are also dynamically adjusted by combining account location information and historical operation data to ensure security and rationality.

Benefits of technology

This improves the security and rationality of resource allocation, avoids resource waste, ensures that each account receives an appropriate resource quota, and enhances resource utilization and cloud platform stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077992A_ABST
    Figure CN121077992A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a resource allocation method, device and system, electronic equipment and a storage medium. The resource allocation method comprises the steps of determining a target security level of an account number based on information of the account number in response to receiving the account number of a to-be-allocated resource, compared with the prior art, the security level of the account number is considered in the embodiment of the invention, and the security during resource allocation is ensured; on this basis, according to a resource quota rule corresponding to the target security level, a rated resource quota corresponding to the target security level is determined, so that the rationality of the resource quota is ensured, the resource quota conforms to a security standard, each account can obtain a proper resource quota, and meanwhile, the resource quota conforms to a security requirement; and finally, based on the relationship between the rated resource quota and the to-be-allocated resource quota of the account, determining a resource allocation rule of the account, adjusting the resource quota, ensuring resource allocation flexibility and effectiveness, and ensuring full utilization of resources.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of resource allocation, and in particular to a resource allocation method, device, system, electronic device and storage medium. BACKGROUND

[0002] Resource quota refers to allocating resources to an application end according to quantity in order to ensure balanced use of resources and meet the needs of the application end. The allocated resources are usually related to the permissions, region and network security needs of the account (hereinafter referred to as account) of the application end.

[0003] At present, the quota rules and amounts in the related art are generally fixed, which is prone to cause security risks such as AccessKey (AK) leakage and malicious inventory detection. Once a security risk event occurs, a large amount of resources will be wasted. Therefore, the fixed quota mechanism has a large security risk. SUMMARY

[0004] To overcome the problems in the related art, embodiments of the present application provide a resource allocation method, device, system, electronic device and storage medium.

[0005] According to a first aspect of embodiments of the present application, a resource allocation method is provided, the method comprising:

[0006] In response to receiving an account of a resource to be allocated, determining a target security level of the account based on information of the account;

[0007] According to a resource quota rule corresponding to the target security level, determining a rated resource amount corresponding to the target security level;

[0008] Based on the relationship between the rated resource amount and the to-be-allocated resource amount of the account, determining a resource allocation rule of the account.

[0009] According to a second aspect of embodiments of the present application, a resource allocation device is provided, the device comprising:

[0010] A determination level module configured to, in response to receiving an account of a resource to be allocated, determine a target security level of the account based on information of the account;

[0011] A determination amount module configured to, according to a resource quota rule corresponding to the target security level, determine a rated resource amount corresponding to the target security level;

[0012] An allocation resource module configured to, based on the relationship between the rated resource amount and the to-be-allocated resource amount of the account, determine a resource allocation rule of the account.

[0013] According to a third aspect of the embodiments of the present application, a resource allocation system is provided, comprising a cloud platform and at least one client, any of the at least one client is configured to receive a user inputted account number and send the account number to the cloud platform; and the cloud platform is configured to determine a resource allocation rule of the account number according to the method of the first aspect.

[0014] According to a fourth aspect of the embodiments of the present application, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the computer program is executed by the processor to enable the electronic device to perform the method of the first aspect.

[0015] According to a fifth aspect of the embodiments of the present application, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the method of the first aspect.

[0016] According to a sixth aspect of the embodiments of the present application, a computer program product is provided, and the computer program product comprises instructions, and when the instructions are executed on a computer, the computer is enabled to perform the method of the first aspect.

[0017] The technical solutions provided by the embodiments of the present application can include the following beneficial effects:

[0018] In the embodiments of the present application, in response to receiving an account number of a to-be-allocated resource, a target security level of the account number is determined based on information of the account number, compared with the prior art, the security level of the account number is considered in the embodiments of the present application, and the security during resource allocation is ensured; on this basis, a rated resource quota corresponding to the target security level is determined according to a resource quota rule corresponding to the target security level, the rationality of the resource quota is ensured, the security standard is met, and it can be ensured that each account number can obtain a proper resource quota while meeting the security requirements; finally, a resource allocation rule of the account number is determined based on a relationship between the rated resource quota and a to-be-allocated resource quota of the account number, the resource quota is dynamically adjusted, the flexibility and effectiveness of resource allocation are ensured, and the full use of resources is ensured while avoiding resource waste.

[0019] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced. It should be understood that other drawings can also be obtained by those of ordinary skill in the art without creative labor based on these drawings.

[0021] Figure 1 A scenario applicable to the resource allocation method provided in the embodiments of the present application is shown in the figure

[0022] Figure 2 An exemplary method flowchart of the resource allocation method provided in the embodiments of the present application is shown in the figure

[0023] Figure 3 An exemplary method flowchart of the resource allocation method provided in the embodiments of the present application is shown in the figure

[0024] Figure 4 An exemplary schematic diagram of the resource allocation method provided in the embodiments of the present application is shown in the figure

[0025] Figure 5 An exemplary component schematic diagram of the resource allocation apparatus provided in the embodiments of the present application is shown in the figure

[0026] Figure 6 An exemplary structural schematic diagram of the electronic device provided in the embodiments of the present application is shown in the figure DETAILED DESCRIPTION

[0027] The technical solutions of the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.

[0028] The terms used in the following embodiments of the present application are for the purpose of describing specific embodiments, and are not intended to be limiting on the technical solutions of the present application. As used in the specification and the appended claims of the present application, the singular forms "a," "an," and "the" are intended to include plural forms as well, unless the context clearly indicates otherwise.

[0029] It should also be understood that although the terms first, second, etc. can be used in the following embodiments to describe a certain type of object, the object should not be limited to these terms. These terms are used to distinguish between specific implementation objects of the type of object.

[0030] It should be noted that the account and the corresponding information of the account (including but not limited to the security operation information of the account) involved in the embodiments of the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation portal for user to choose authorization or refusal.

[0031] Resource quota is a resource management means in the field of cloud computing, which refers to a technology for cloud platforms to allocate computing resource quota to application terminals requesting the quota. Resource quota is related to the rational allocation of resources, utilization efficiency and security. At present, the related technology adopts a fixed quota design. Although this design simplifies the allocation process of the quota, it exposes some problems in actual application.

[0032] Firstly, the design of fixed quota is usually based on a relatively large amount to meet the normal creation and use needs of most users. However, this "one-size-fits-all" allocation ignores the differences between different users and different accounts. For example, some accounts may not need or be able to fully utilize the allocated resources due to permission restrictions or network security needs, resulting in waste of resources. More seriously, the design of fixed quota also has a high security risk. Some unscrupulous people may exploit system vulnerabilities or weaknesses to obtain access keys and conduct malicious inventory probing or black and gray production activities. For example, some accounts without permission may use malicious means to obtain the resource allocation of the corresponding account, and in addition, some accounts may steal the access keys of other accounts to conduct malicious resource creation. These situations not only cause waste of resources on the corresponding cloud platform, but also affect the task running of normal accounts, and even threaten the stability of the entire cloud computing platform.

[0033] Taking a cloud computer as an example, the resource allocation of the cloud platform for the cloud computer is related to the application scenario. For example, the cloud platform can create multiple cloud computers according to the information of the account and the demand of the account. According to the design of fixed resource quota, the cloud platform will allocate resources that can create 1000 cloud computers to all accounts. However, on the one hand, most accounts only need resources for daily use (for example, three to four cloud computers), and on the other hand, in actual application, there are some accounts with low security permissions. If the access key of such an account is leaked, the account can create a cloud computer and obtain a large amount of computing resources according to the access key, which occupies the computing quota and causes serious waste of resources and a high security risk.

[0034] Therefore, the embodiments of the present application propose a resource allocation method. In the resource allocation process, the rated resource quota corresponding to the account is determined according to the target security level corresponding to the information of the account and the resource quota rule. Compared with the implementation manner in the related art, the security level corresponding to the account is considered, the security of resource allocation is improved, and unnecessary waste of resources is avoided.

[0035] The resource allocation method provided by the embodiments of the present application can be applied to complex resource allocation involving resource classification, highly dynamic resource demand, and scenarios requiring efficient resource management, etc. For example, it can be the resource classification of a cloud computing center, the reasonable allocation of computing resources and storage resources of a big data platform, the allocation of graphics processing units (GPUs), graphics processing units, and memory resources in an artificial intelligence training platform, and the allocation of device resources and network bandwidth in an edge computing environment, etc.

[0036] Specifically, the resource allocation method provided by the embodiments of the present application can be applied to the corresponding cloud computing center in the above-mentioned resource allocation scenarios, embedded application programs in hardware devices, and software programs independent of hardware devices, etc. For example, it can be applied to electronic devices, server devices, edge computing devices, and intelligent terminal devices, etc.

[0037] For example, taking the resource allocation of a cloud platform as an example, as shown in Figure 1 , a system architecture diagram of resource allocation is shown. The system can include a cloud platform 101 and a client 102. The cloud platform 101 can be used to perform resource management and allocation, and the client 102 can be used to receive and deliver the user's instructions.

[0038] The cloud platform 101 can be a service based on hardware resources and software resources, providing computing, network, and storage capabilities. The client 102 can be a terminal device, which can include a mobile phone, a computer, an upper computer, and an embedded device, etc. The terminal device corresponding to the client 102 can be provided with a display screen, and the corresponding display screen includes displayed pictures, texts, buttons, etc. The cloud platform 101 and the client 102 are connected through a network, specifically, it can be wired connection or wireless connection, wherein the wireless connection includes network connection, WI FI connection, and Bluetooth connection, etc.

[0039] The user inputs an account by operating the pictures, texts, buttons, etc. in the display screen of the client 102, and the client 102 sends the account input by the user and the information recorded by the client 102 when the account is logged in (login time, location information, and resource quota to be allocated, etc.) to the cloud platform 101. After receiving the request, the cloud platform 101 will analyze and process according to the resource allocation method disclosed in the embodiments of the present application.

[0040] Under the above-mentioned operating environment, the present application provides a resource allocation method as shown in Figure 2 . The embodiments of the present application take the resource allocation method corresponding to the cloud platform as an example for introduction. The resource allocation method includes the following steps:

[0041] In step S201, in response to receiving an account of a resource to be allocated, the target security level of the account is determined based on the information of the account.

[0042] Wherein, the account of the resource to be allocated can be the account obtained from the sent resource request instruction when the corresponding account needs to be allocated resources, and the corresponding account can be an identifier (ID). The resource to be allocated is the resource quota corresponding to the account that needs to be allocated. The target security level can be the security information corresponding to the account. Specifically, the security information of the account can be identified. The specific implementation manner can be that if it is determined according to the information of the account that the account is a known account, or the information of the account contains historical resource allocation information, and the corresponding information has no record of malicious operation, etc., it can be determined that the target security level corresponding to the account is safe and has no security problem.

[0043] Correspondingly, if there is a record of malicious operation, it is determined that the target security level corresponding to the account is abnormal.

[0044] In step S202, according to the resource quota rule corresponding to the target security level, the rated resource quota corresponding to the target security level is determined.

[0045] Wherein, the resource quota rule is the rule of resource allocation corresponding to the target security level, and different resource quota rules can be matched for different target security levels. The rated resource quota can be the total resource quota of the account within a period of time, or the available resource quota corresponding to the account at the corresponding moment. The specific type of the rated resource quota is not limited in the present application embodiment, and can be determined by the person skilled in the art according to the actual situation.

[0046] Exemplarily, after determining the target security level, the rated resource quota corresponding to the target security level can be determined according to the mapping relationship between the target security level and the corresponding resource quota rule. The specific mapping relationship can be determined according to the total resource allocation capability of the cloud platform.

[0047] In step S203, based on the relationship between the rated resource quota and the resource to be allocated of the account, the resource allocation rule of the account is determined.

[0048] Exemplarily, after determining the rated resource quota, there can be a case that the rated resource quota does not meet the resource to be allocated. Therefore, the resource needs to be allocated according to the relationship between the two.

[0049] It should be pointed out that in the present embodiment, if the rated resource quota does not meet the resource to be allocated, the account will not be allocated resources.

[0050] It can be seen that, by using the embodiment of the application, in response to receiving the account of the to-be-allocated resource, the target security level of the account is determined based on the information of the account. Compared with the prior art, the security level of the account is considered in the embodiment of the application, and the security during resource allocation is ensured. On this basis, according to the resource quota rule corresponding to the target security level, the rated resource quota corresponding to the target security level is determined, the rationality of the resource quota is ensured, the security standard is met, and it can be ensured that each account can obtain appropriate resource quota while meeting the security requirements. Finally, based on the relationship between the rated resource quota and the to-be-allocated resource quota of the account, the resource is allocated to the account according to the to-be-allocated resource quota, the resource quota is dynamically adjusted, the flexibility and effectiveness of resource allocation are ensured, and the full use of resources is ensured while avoiding resource waste.

[0051] In some embodiments, the implementation process of step S201 in the above embodiment can be that the target security level rule of the account is determined based on the mapping relationship between the information type corresponding to the information of the account and the security level rule; and the target security level of the account is calculated according to the information of the account and the target security level rule.

[0052] For example, the information of the account can include account login information (out-of-place login), consumption information (abnormal consumption, large payment, frequent payment, etc.), and whether there is a high-risk / permission sub-account, etc. The target security level rule corresponding to the information type is determined according to the information type of the information, and then the target security level of the information of the corresponding information type is calculated according to the target security level rule.

[0053] In some embodiments, the information of the account includes at least one historical operation information, and the historical operation information corresponding to the information type of the account is screened in a preset security information library; the target security level rule corresponding to each information type is determined according to the corresponding historical operation information; the first target security level of the account is calculated according to the sub-security level corresponding to each historical operation information, and the first target security level represents the security level of the information of the account; and the first target security level is determined as the target security level of the account.

[0054] For example, in determining the target security level of the account, the target account can be further determined according to the historical operation information corresponding to the account.

[0055] Specifically, the historical operation information corresponding to the security operation information included in the account information can be screened in a preset security information library (storing historical security operation information of each account, which can include operation type, operation time, operation result, and detailed information of related parameters). The determination method of the sub-security level corresponding to different types of historical operation information can be different, and the corresponding rules can be calculated according to the historical operation type, operation time, and operation result to obtain the corresponding sub-security level. For each sub-security level, the first target security level can be determined by means of weighted average.

[0056] Specifically, each type of data in the security account information can be compared with the information in the preset security information library one by one, and the target security level is determined according to the comparison result.

[0057] The comparison process can be that, first, the historical login information of the account in the preset security information library is queried according to the account login information (key data such as login location and login time, which are recorded by the client at the time of login) in the security account information this time. The historical login information can include the time, location, Internet Protocol (IP) address, login result (such as success or failure), and other related operation details of each login. Second, the current login information is compared with the historical login information. Specifically, it includes: (1) location comparison: check whether the current login location is consistent or similar to the historical login location. For example, if the historical record shows that the account usually logs in from a certain city, and the geographical location of this login is different, a security alarm is triggered; (2) time comparison: whether the current login time is consistent with the historical login time. For example, if the historical record shows that the account usually logs in during the day, and this login occurs at night, it can also be an abnormal signal; (3) other information comparison: it can also include comparison of login equipment, IP address and other information to confirm whether there is an anomaly. Finally, according to the comparison result, the system determines the security of the current login.

[0058] Comparison result determination: if the current login information is highly consistent with the historical login information in key aspects (such as location and time), and there is no other abnormal signal, it is determined that the current login is safe, and the sub-security level is marked as “high security level”; if there is any significant inconsistency or abnormality, the current login is marked as possibly risky.

[0059] In combination with the cloud computer in the embodiments of the present application, the corresponding account security information can be the creation frequency and number of the cloud computer, and whether there is “illegal operation” in the operation process of the account using the created cloud computer. Correspondingly, when determining the target security level of the account security information, the following steps can be implemented.

[0060] First, collect activity data of the account on the cloud computer, including but not limited to cloud computer creation records, usage duration, operation logs, etc. These data can be obtained through monitoring and logging systems, and can reflect the behavior characteristics of the account on the cloud computer.

[0061] Next, preprocess and analyze these activity data. For example, calculate the cloud computer creation frequency and quantity of the account within a certain time period, and analyze whether these data are within the normal range. At the same time, through the analysis of operation logs, it can be identified whether there are illegal operations such as unauthorized access, data tampering or attacks, etc.

[0062] Then, based on the results of preprocessing and analysis, evaluate the security level of the account. If the cloud computer creation frequency and quantity of the account are within the normal range and no illegal operations are found, the security level of the account can be rated as high. Conversely, if the creation frequency is abnormally high, the creation quantity is greater than the preset standard, or there are illegal operations, the security level should be lowered and marked as a high-risk account.

[0063] During the evaluation process, other security information such as the account's historical behavior, login location, access time, etc. can also be combined to further improve the accuracy of security level evaluation. In addition, the cloud platform can also set different security level thresholds and evaluation standards according to actual needs to meet the security needs of different scenarios.

[0064] Finally, according to the evaluation results, the cloud platform can allocate corresponding resources and management strategies to accounts of different security levels. For accounts with high security levels, give resource support; while for accounts with lower security levels, limit their resource use or strengthen security verification to ensure the safe operation of the entire cloud platform.

[0065] In summary, by collecting and analyzing the activity data of the account on the cloud computer, combined with other security information, the security level of the account can be accurately evaluated, and targeted resource allocation and management strategies can be provided for the cloud platform.

[0066] Through the analysis of the security operation information of the account, the target security level of the account can be determined more accurately, and the security in the resource allocation process is improved. With the changes of account behavior and environment, the historical operation information will be updated continuously, so that the target security level can be dynamically adjusted. This helps to update the security level in real time.

[0067] The location information corresponding to the account is a reference factor for cloud platform resource allocation. Since there are differences in population numbers in different regions, adjusting the rated resource quota of the account according to its location information can better utilize resources.

[0068] Specifically, when the location information of an account is in a city with a large population base, these cities usually have higher task requirements and higher requirements for computing, storage, and network resources. Therefore, when allocating resources, the cloud platform will give these accounts more rated resource quotas to meet the actual usage requirements. In this way, not only can the account smoothly run its tasks, but also can avoid performance bottlenecks or task interruptions caused by insufficient resources. Correspondingly, for accounts located in cities with a small population base, their task requirements are not high. Therefore, the cloud platform will allocate appropriate resource quotas to them according to the actual situation to avoid waste and over-allocation of resources. This differentiated resource allocation strategy not only helps to improve resource utilization, but also reduces the operating costs of the cloud platform.

[0069] In this way, the cloud platform can accurately meet the different needs of accounts according to their location information, and realize reasonable allocation and efficient use of resources. This not only improves the user's task experience, but also promotes the sustainable development of the cloud platform.

[0070] According to the location information corresponding to the account, the rated resource quota of the account is flexibly adjusted, which is an important means for the cloud platform to realize the optimized allocation of resources. Through this approach, the cloud platform can more effectively address the different needs of accounts in different regions and improve resource utilization.

[0071] Therefore, based on the above content, in addition to the security operation information in the above embodiments, the information of the account can also include location information, that is, the location information of the account. In actual application, different target security levels or rated resource amounts can be set according to the actual location of the account, which can effectively reduce resource waste.

[0072] In actual application, step S202 in the above embodiments can be implemented in the following manner: determining an initial resource quota corresponding to the target security level, the initial resource quota being a resource quota under the condition that the security of the account is determined; determining the rated resource quota based on the initial resource quota according to the relationship between the target security level and at least two preset security levels, each security level in the at least two security levels representing the degree of existence of a security problem.

[0073] Illustratively, after determining the target security level, the initial resource quota corresponding to the target security level can be determined first. Here, the initial resource quota can be the resource quota corresponding to the account under the condition of security.

[0074] When the target security level corresponds to one of at least two preset security levels, the rated resource quota is determined based on the corresponding security level. These preset security levels can be those where security issues exist. For example, in practical applications, this could be a low security level (account anomaly, second security level) and a high security level (no security risks, first security level). In the case of a low security level, the corresponding rated resource quota can be set to zero; in the case of a high security level, the initial resource quota can be directly used as the rated resource quota. Alternatively, there could be a situation where the security level is in the middle (account may be anomaly, belonging to the second security level), and the corresponding rated resource quota can be determined based on the actual situation.

[0075] Specifically, the initial resource allocation can be of different proportions. The specific proportion can be determined based on the actual situation within the security level. Other parameters can also be used to determine this proportion, and the methods for determining these parameters are not limited to the embodiments described in this application. Of course, those skilled in the art can further divide the security levels according to actual circumstances to meet practical application needs.

[0076] The initial resource allocation is determined based on the actual security level of the account, which improves the security of resource allocation. On this basis, by limiting the rated resource allocation of accounts with lower security levels, the probability of security incidents can be reduced.

[0077] It should be noted that, in determining the initial resource limit during the implementation of the above embodiments, if the target security level is determined solely based on the first target security level, the resource limit corresponding to the first security level can be directly determined as the initial resource limit. However, if the target security level is determined jointly by the first and second target security levels, the initial resource limit needs to be determined based on a first preset ratio corresponding to the resource limit corresponding to the first security level. This first preset ratio is related to the location information corresponding to the second target security level. In practice, a mapping relationship between location information and the first preset ratio can be established to determine the exact value of the first preset ratio.

[0078] In some optional embodiments, step S203 in the above embodiments can be implemented in the following way: when the rated resource quota is greater than or equal to the resource quota to be allocated, the resource quota to be allocated is allocated to the account; when the rated resource quota is less than the resource quota to be allocated, the resource quota to be allocated is re-determined based on the number of times the account exceeds the quota within a preset time period, and the updated resource quota to be allocated is allocated to the account.

[0079] The number of times the resource quota is less than the resource quota to be allocated is defined as the number of times the quota is less than the resource quota to be allocated.

[0080] For example, if the rated resource quota is greater than or equal to the resource quota to be allocated for the account, it means that the account's resource demand is not greater than the rated resource quota. Therefore, the account can be directly allocated the corresponding resource quota.

[0081] In another scenario, if the allocated resource quota is less than the account's required resource quota, it means the account's resource needs exceed the allocated quota. Generally, resources exceeding the allocated quota cannot be directly allocated to the account. However, to flexibly handle special circumstances during resource allocation and improve efficiency, a compensation mechanism can be used to compensate for situations exceeding the allocated quota.

[0082] Specifically, the compensation amount can be determined based on the number of times an account's available resource quota exceeds its rated resource quota within a preset time period. This compensation amount is the amount of resources that can exceed the rated resource quota; in other words, the final allocatable resource quota for the account is the rated resource quota plus the compensation resource quota.

[0083] Determining the compensation amount based on the number of occurrences can effectively prevent situations where the resource limit is frequently exceeded within a certain period of time, and compensation will still be provided. Such frequent over-limit situations may be due to malicious memory probing methods, etc. Therefore, determining the compensation amount based on the number of occurrences can improve the security of resource allocation to a certain extent and avoid resource waste.

[0084] Specifically, the method of determining the compensation resource amount based on the number of times resources are allocated to the account within a preset time period is as follows: when the account exceeds the limit for the first time, the compensation resource amount is determined by a preset multiple of the preset allowed quota limit; when the account exceeds the limit for the i-th time, the compensation resource amount for the i-th time is calculated based on the second preset ratio and the compensation resource amount corresponding to the (i-1)-th time of exceeding the limit; where i is an integer greater than 1.

[0085] For example, the preset time period can be 1 day. When the account's resource allocation quota is greater than the rated resource quota for the first time, the account may be in a special situation and needs to allocate more resources than the corresponding rated resource quota. This situation can be achieved through compensation quota.

[0086] Specifically, the compensation amount can be determined based on the upper limit of the single allowed quota for resource allocation by the cloud platform. In this embodiment, the upper limit of the single allowed quota is set to M, and the preset multiplier can be 1.5, so the compensation amount for the first time is 1.5M. When it is the i-th time, it means that there are i instances of exceeding the limit within one day. To avoid malicious probing, the compensation amount can decrease with the increase of the number of times. Specifically, it can be 70% of the compensation amount corresponding to the (i-1)-th time.

[0087] In practical applications, resource allocation strategies for accounts need to be more flexible. For example, when an account is classified as a high-importance type, its resource needs often have higher priority. In this case, even after compensation, if the allocated resource quota is still insufficient to meet the account's resource needs, special measures are required to ensure timely resource supply.

[0088] Specifically, when an account is identified as belonging to a high-importance category, a resource allocation mechanism for compensation is triggered. The core of this mechanism is determining the importance of an account based on its tags, and adjusting resource allocation strategies accordingly. These tags are pre-defined for each account to identify its corresponding importance type, such as mission-critical accounts, VIP client accounts, etc. Multiple criteria can be referenced when assessing account importance, including but not limited to the account's historical usage records, task scale, contract amount, and partner level. These criteria can be adjusted based on actual circumstances to ensure the accuracy and fairness of the assessment results.

[0089] Based on the above, when determining the resource allocation amount based on the compensated resource amount, if the compensated resource amount is less than the resource allocation amount, the account information is obtained and matched with the target type tag in the preset account information database. Any type tag is used to characterize the importance level of the corresponding account; if the target type tag is a preset importance type tag, then resources are allocated to the account according to the resource allocation amount.

[0090] In this situation, if the compensated resource quota still does not meet the demand for allocated resources, it is necessary to determine whether the account has excess qualifications (whether it belongs to the category of importance). If it has excess qualifications, resources will be allocated directly to the account according to the demand for allocated resources. Excess qualifications indicate the corresponding importance of the account on the cloud platform.

[0091] In practical applications, for example, a cloud platform system might have a specific account belonging to a core VIP customer. This VIP customer is not only a long-term partner of the cloud platform, but also ranks among the top in terms of investment and resource purchases in the actual operation of the cloud platform, playing a crucial role in its operation. Therefore, this account is marked as "extremely important."

[0092] When the required resource allocation for this VIP account exceeds its purchased limit during actual operation, the cloud platform will still meet the VIP customer account's resource needs. In other words, the cloud platform may reserve more resources for this VIP customer account to ensure it can handle special circumstances during actual use.

[0093] This example demonstrates the crucial role account importance plays in resource allocation. By supporting higher-importance accounts, the system ensures a better task experience and satisfaction for these accounts, thereby contributing to maintaining a long-term partnership with the cloud platform and ensuring task stability.

[0094] If the target type tag is not a preset important type tag, meaning the account does not have excess qualifications, then resource allocation to the account will be stopped, or the corresponding resource allocation request will be canceled. Determining the target type tag improves the flexibility of account allocation and enhances the user experience.

[0095] The implementation method in the above embodiments will be further explained and illustrated with a specific example below. Figure 3 As shown.

[0096] After receiving a request to create cloud resources for an account, the target security level for that account is determined based on the account's security operation information. If the target security level is Level 1 (low security level), resource allocation to the account is stopped. If the target security level is Level 2, the system continues to compare the allocated resource quota and the resource quota to be allocated based on the target security level. If the allocated resource quota for the target security level meets the resource quota to be allocated, resources are allocated directly. If the allocated resource quota for the target security level does not meet the resource quota to be allocated, the system continues to determine the compensation amount. Here, when determining the allocated resource quota for the target security level, the location information of the account needs to be considered.

[0097] It should be understood that the above description illustrates the implementation of the embodiments of this application using two security levels as an example, and does not constitute a limitation on the technical solutions of the embodiments of this application. In other implementations, the technical solutions of the embodiments of this application may set more or fewer security levels based on the actual implementation scenario. Regardless of the number of full levels, the implementation of resource quotas for accounts based on security levels in the embodiments of this application can be referred to the above description, and will not be repeated here.

[0098] After compensating the rated resource quota according to the compensation amount, if the compensated rated resource quota meets the resource quota to be allocated, then resources are allocated to the account; if the compensated rated resource quota does not meet the resource quota to be allocated, then the target type tag corresponding to the account (such as the aforementioned dynamic tag strategy) is determined to determine the importance type of the account. If the importance type is an important account, then resources are allocated; if the importance type is not an important account, then the account is blocked.

[0099] The determination of the compensation amount, such as Figure 4 As shown, when the compensated rated resource quota corresponding to the target security level does not meet the resource quota to be allocated, the compensation mechanism is triggered. When determining the compensation amount, firstly, the maximum single creation quantity M (i.e., the allowed quota limit) of the corresponding cloud platform needs to be determined; secondly, it needs to be determined how many times the compensation mechanism has been triggered within a day (i.e., the number of times the account has exceeded its limit within a preset time period). If it is the first time, the compensation amount can be set to 1.5M. If it is not the first time, for example, the second time, the compensation amount is 1.5M × 70%. In other words, if the compensation mechanism is not triggered for the first time, the corresponding compensation amount for this instance is 70% of the previous compensation amount.

[0100] For example, if the above implementation steps can be implemented by software modules, corresponding to the above resource allocation method, this application embodiment can also provide a resource allocation device.

[0101] like Figure 5 As shown, a resource allocation device is provided, which may include a level determination module 51, a quota determination module 52, and a resource allocation module 53. This resource allocation device can be used to perform the above-described... Figure 2 Some or all of the operations of the resource allocation method in China.

[0102] For example: the level determination module 51 is used to determine the target security level of the account based on the information of the account in response to receiving an account for which resources are to be allocated; the quota determination module 52 is used to determine the rated resource quota corresponding to the target security level according to the resource quota rules corresponding to the target security level; and the resource allocation module 53 is used to determine the resource allocation rules of the account based on the relationship between the rated resource quota and the resource quota to be allocated to the account.

[0103] Therefore, the resource allocation device provided in this application embodiment, in response to receiving an account for which resources are to be allocated, determines the target security level of the account based on the account information. Compared with the prior art, this application embodiment considers the security level of the account, ensuring the security of resource allocation. Based on this, according to the resource quota rules corresponding to the target security level, a rated resource quota corresponding to the target security level is determined, ensuring the rationality of the resource quota and compliance with security standards. This ensures that each account can obtain an appropriate resource quota while meeting security requirements. Finally, based on the relationship between the rated resource quota and the account's resource quota to be allocated, the resource allocation rules for the account are determined, and the resource quota is dynamically adjusted to ensure the flexibility and effectiveness of resource allocation, ensuring full utilization of resources while avoiding resource waste.

[0104] Optionally, the level determination module 51 includes: a first level determination submodule, used to determine the target security level rule of the account based on the mapping relationship between the information type corresponding to the account information and the security level rule; and a second level determination submodule, used to calculate the target security level of the account according to the account information and the target security level rule.

[0105] Optionally, the account information includes at least one piece of historical operation information, and the level determination module 51 is further configured to: filter historical operation information corresponding to the information type of the account in a preset security information database; determine the sub-security level matching the corresponding historical operation information according to the target security level rules corresponding to each information type; calculate the first target security level of the account based on the sub-security level corresponding to each historical operation information, wherein the first target security level represents the security level of the account information; and determine the first target security level as the target security level of the account.

[0106] Optionally, the account information also includes the account's location information, and the level determination module 51 is further configured to: determine a second target security level for the account based on the location information, wherein the second security level represents the security level of the location information to which the account belongs; and determine a target security level for the account based on the first target security level and the second target security level.

[0107] Optionally, the quota determination module 52 is further configured to: determine the initial resource quota corresponding to the target security level, wherein the initial resource quota is the resource quota under the condition that the account is secure; and determine the rated resource quota based on the initial resource quota according to the relationship between the target security level and at least two preset security levels, wherein each of the at least two security levels represents the degree of security problem.

[0108] Optionally, the quota determination module 52 is further configured to: determine the resource quota corresponding to the first security level as the initial resource quota when the target security level is determined according to the first target security level, wherein the first security level is any one of the at least two security levels; and determine a first preset ratio of the resource quota corresponding to the first security level as the initial resource quota when the target security level is determined according to the first target security level and the second target security level, wherein the first preset ratio is related to the location information.

[0109] Optionally, the quota determination module 52 is further configured to: if the target security level is a first security level, determine the initial resource quota as the rated resource quota, wherein the initial resource quota is the resource quota corresponding to the first security level, and the first security level is a security level in the target security level that indicates that the account does not have security problems; if the target security level is a second security level, adjust the initial resource quota according to the weight corresponding to the second security level, wherein the adjusted resource quota is the rated resource quota, and the second security level is any security level other than the first security level in the target security level that indicates that the account has security problems.

[0110] Optionally, the resource allocation module 53 is further configured to: allocate resources of the resource quota to the account when the rated resource quota is greater than or equal to the resource quota to be allocated; and when the rated resource quota is less than the resource quota to be allocated, re-determine the resource quota to be allocated based on the number of times the account exceeds the quota within a preset time period, and allocate resources of the updated resource quota to the account, wherein the number of times the rated resource quota is less than the resource quota to be allocated.

[0111] Optionally, the resource allocation module 53 is further configured to: determine a compensation resource amount based on the number of times the account exceeds its limit within a preset time period; use the compensation resource amount to compensate the rated resource amount; and redetermine the resource amount to be allocated based on the compensated resource amount.

[0112] Optionally, the resource allocation module 53 is further configured to: determine a preset multiple of the preset allowed quota limit as the compensation resource amount when the account exceeds the limit for the first time; and calculate the compensation resource amount for the i-th time based on the second preset ratio and the compensation resource amount corresponding to the (i-1)-th time the account exceeds the limit; where i is an integer greater than 1.

[0113] Optionally, the resource allocation module 53 is further configured to: if the compensated resource amount is less than the resource amount to be allocated, obtain the target type tag matching the account information in a preset account information database, where any type tag is used to characterize the importance level of the corresponding account; if the target type tag is a preset importance type tag, then allocate resources to the account according to the resource amount to be allocated.

[0114] Optionally, the device is also configured to: stop allocating resources to the account if the target type tag is not a tag of a preset important type.

[0115] Understandable, Figure 5 The division of the various modules is merely a logical functional division. In actual implementation, the functions of these modules can be integrated into the hardware entity of the electronic device.

[0116] Please refer to Figure 6 , Figure 6 An electronic device is provided, and this disclosure also provides an electronic device for performing the above-described resource allocation method. Please refer to... Figure 6 This illustrates a schematic diagram of an electronic device provided by some embodiments of the present disclosure. For example... Figure 6 As shown, the electronic device includes: a processor 600, a memory 601, a bus 602, and a communication interface 603. The processor 600, the communication interface 603, and the memory 601 are connected via the bus 602. The memory 601 stores a computer program that can run on the processor 600. When the processor 600 runs the computer program, it executes the aforementioned provisions of this disclosure. Figure 2 The resource allocation method provided by any of the illustrated embodiments.

[0117] The memory 601 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 603 (which can be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc.

[0118] Bus 602 can be an ISA bus, PCI bus, or EIS bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. Memory 601 is used to store programs, and the processor 600 executes the programs after receiving execution instructions. Figure 2 The illustrated embodiments reveal that the resource allocation method can be applied to, or implemented by, the processor 600.

[0119] The processor 600 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 600 or by instructions in software form. The processor 600 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this disclosure can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory 601, and processor 600 reads the information in memory 601 and, in conjunction with its hardware, completes the steps of the above method.

[0120] The electronic device provided in this disclosure and the resource allocation method provided in this disclosure are based on the same inventive concept and have the same beneficial effects as the methods they adopt, operate or implement.

[0121] This application also provides a computer-readable storage medium storing resource allocation instructions that, when executed on a computer, cause the computer to perform some or all of the steps in the methods described in the foregoing embodiments.

[0122] This application also provides a computer program product including instructions for resource allocation, which, when run on a computer, causes the computer to perform some or all of the steps in the methods described in the foregoing embodiments.

[0123] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0124] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.

[0125] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0126] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0127] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, smartphone, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0128] Although alternative embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make further changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0129] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of this application should be included within the scope of protection of this invention.

Claims

1. A resource allocation method, characterized by, The method comprises: in response to receiving an account of a resource to be allocated, determining a target security level of the account based on information of the account; determining a rated resource quota corresponding to the target security level according to a resource quota rule corresponding to the target security level; determining a resource allocation rule of the account based on a relationship between the rated resource quota and a to-be-allocated resource quota of the account.

2. The method of claim 1, wherein, The determination of the target security level of the account based on the information of the account comprises: determining a target security level rule of the account based on a mapping relationship between an information type corresponding to the information of the account and a security level rule; calculating the target security level of the account according to the information of the account and the target security level rule.

3. The method of claim 2, wherein, The information of the account comprises at least one item of historical operation information, and the calculation of the target security level of the account according to the information of the account and the target security level rule comprises: screening historical operation information corresponding to the information type of the account in a preset security information library; determining a sub-security level matched by corresponding historical operation information according to a target security level rule corresponding to each information type; calculating a first target security level of the account according to the sub-security level corresponding to each historical operation information, the first target security level representing the security level of the information of the account; determining the first target security level as the target security level of the account.

4. The method of claim 3, wherein, The information of the account further comprises location information of the account, and the calculation of the target security level of the account according to the information of the account and the target security level rule further comprises: determining a second target security level of the account according to the location information, the second security level representing the security level of the location information to which the account belongs; determining the target security level of the account according to the first target security level and the second target security level.

5. The method of claim 4, wherein, The determination of the rated resource quota corresponding to the target security level comprises: determining an initial resource quota corresponding to the target security level, the initial resource quota being a resource quota in a case where the security of the account is determined; determining the rated resource quota based on the initial resource quota according to a relationship between the target security level and at least two preset security levels, each security level in the at least two security levels representing a degree of existence of a security problem.

6. The method of claim 5, wherein, The determination of the initial resource quota corresponding to the target security level comprises: when the target security level is determined according to the first target security level, determining a resource quota corresponding to the first security level as the initial resource quota, the first security level being any one of the at least two security levels; when the target security level is determined according to the first target security level and the second target security level, determining a first preset proportion of the resource quota corresponding to the first security level as the initial resource quota, the first preset proportion being related to the location information.

7. The method of claim 6, wherein, The determining the rated resource quota based on a relationship between the target security level and preset security levels comprises: if the target security level is a first security level, determining the initial resource quota as the rated resource quota, the initial resource quota being a resource quota corresponding to the first security level, the first security level being a security level representing that the account has no security problem in the target security levels; if the target security level is a second security level, adjusting the initial resource quota according to a weight corresponding to the second security level, the adjusted resource quota being the rated resource quota, the second security level being any security level other than the first security level in the target security levels, the second security level representing that the account has a security problem.

8. The method of claim 1, wherein, The determining the resource allocation rule of the account based on a relationship between the rated resource quota and a to-be-allocated resource quota of the account comprises: allocating resources of the to-be-allocated resource quota to the account when the rated resource quota is greater than or equal to the to-be-allocated resource quota; re-determining the to-be-allocated resource quota based on an overage number of the account in a preset period of time, and allocating resources of the updated to-be-allocated resource quota to the account when the rated resource quota is less than the to-be-allocated resource quota, the overage number being a number of times that the rated resource quota is less than the to-be-allocated resource quota.

9. The method of claim 8, wherein, The re-determining the to-be-allocated resource quota based on the overage number of the account in the preset period of time comprises: determining a compensation resource quota based on the overage number of the account in the preset period of time; compensating the rated resource quota using the compensation resource quota; and re-determining the to-be-allocated resource quota based on the compensated resource quota.

10. The method of claim 9, wherein, The determining the compensation resource quota based on the overage number of the account in the preset period of time comprises: determining a preset multiple of a preset upper limit of an allowed quota as the compensation resource quota when the account overages for the first time; calculating the compensation resource quota for the i-th time according to a second preset proportion and the compensation resource quota corresponding to the (i-1)-th time overage when the account overages for the i-th time, the i being an integer greater than 1.

11. The method according to claim 9 or 10, characterized in that, The determining the to-be-allocated resource quota based on the compensated resource quota comprises: if the compensated resource quota is less than the to-be-allocated resource quota, obtaining a target type label matched with information of the account in a preset account information library, any type label being used to represent an importance type of a corresponding account; if the target type label is a label of a preset important type, allocating resources to the account according to the to-be-allocated resource quota.

12. The method of claim 11, wherein, The method further comprises: if the target type label is not a label of a preset important type, stopping allocating resources to the account.

13. A resource allocation apparatus, characterized by comprising: The device comprises: a determination level module configured to determine a target security level of an account to be allocated resources based on information of the account in response to receiving the account to be allocated resources; a determination quota module configured to determine a rated resource quota corresponding to the target security level according to a resource quota rule corresponding to the target security level; and a resource allocation module configured to allocate resources to the account according to a resource allocation rule of the account determined based on a relationship between the rated resource quota and a to-be-allocated resource quota of the account. The allocation resource module is configured to determine a resource allocation rule of the account based on a relationship between the quota and a to-be-allocated resource quota of the account.

14. A resource allocation system characterized by The system comprises a cloud platform and at least one client, Any of the at least one client is configured to receive an account input by a user and send the account to the cloud platform. The cloud platform is configured to determine a resource allocation rule of the account according to the method in any of claims 1-12.

15. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The computer program is run by the processor to enable the electronic device to perform the method in any of claims 1-12.

16. A computer readable storage medium having stored thereon a computer program, characterized in that, The program is run by the processor to implement the method in any of claims 1-12.

17. A computer program product, characterised in that, The program is run by the processor to implement the method in any of claims 1-12. The program is run by the processor to implement the method in any of claims 1-12.