Cloud center system based on articulated naturality web
By dividing the cloud center system into video network services, management and storage networks, and using technologies such as video network protocols and firewalls, the security risks of the traditional TCP/IP protocol stack and the challenges of heterogeneous environment collaboration are solved, achieving high security and automated operation and maintenance.
Patent Information
- Application Number
- CN202511230502.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2026-01-06
AI Technical Summary
Traditional cloud data center networks are based on the TCP/IP protocol stack, which poses security risks and is out of step with the needs of modern cloud environments, making it difficult to achieve network security and collaboration with heterogeneous environments.
The cloud center system is divided into physically isolated video network service network, management network and storage network using the video network protocol, which are used for data transmission of computing, security and storage resources respectively, and protocol conversion and security control are achieved through video network firewall and core server.
It improves the network security of the cloud center system, ensures that each module operates independently, solves the security issues of the TCP/IP protocol, and realizes collaborative management and automated operation and maintenance response in heterogeneous environments.
Smart Images

Figure CN121284054A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of visual network technology, and in particular to a cloud center system based on visual network. Background Technology
[0002] Traditional cloud data center networks are built on top of the TCP / IP protocol stack, a design that is severely out of step with the needs of today's cloud environments. Furthermore, cloud data center networks built on the TCP / IP protocol stack present significant security vulnerabilities. Summary of the Invention
[0003] In view of the above problems, a cloud center system based on visual networks is proposed to overcome or at least partially solve the above problems, including:
[0004] A cloud center system based on video network, wherein the network of the cloud center system is divided into a physically isolated video network service network, a video network management network, and a video network storage network, wherein:
[0005] The video network service network is used for data transmission between the computing resource pool and the security resource pool in the cloud center system;
[0006] The video network management network is used for data transmission in the cloud operation and maintenance management center of the cloud center system;
[0007] The visual network storage network is used for data transmission in the storage resource area of the cloud center system.
[0008] Optionally, the video network service network includes a first video network router, a video network firewall, a first video network management system, a first core server, a first video network terminal operating environment, and a first data communication control system. The first video network router is connected to the video network firewall, and the video network firewall is connected to the first core server. The first core server includes hierarchically connected sub-core servers, and the sub-core servers are connected to the first video network management system, the first data communication control system, or the first video network terminal operating environment. The first video network router is used to connect the Internet and the video network and to convert the Internet protocol to the video network protocol. The video network firewall is used for video network access. The first video network terminal operating environment includes the video network terminal operating environments in the computing resource pool and the security resource pool.
[0009] Optionally, the video network management network includes a second core server, a second video network router, a second video network management system, and a second data communication control system, wherein the second core server is connected to the second video network router, the second video network management system, and the second data communication control system.
[0010] Optionally, the video network storage network includes a third core server, a third video network terminal operating environment, a third network management system, and a third data communication control system. The third core server is connected to the third video network terminal operating environment, the third network management system, and the third data communication control system. The third video network terminal operating environment is the video network terminal operating environment of the storage resource area.
[0011] Optionally, the video network management network can access video network scenarios and / or Internet scenarios.
[0012] Optionally, when the video network management network is accessed as a video network scenario, the first user terminal on the video network side installs a second video network terminal operating environment, and the second video network terminal operating environment, the video network converged switch, and the video network converged switch are connected to the video network management network.
[0013] Optionally, when the video network management network is connected to the Internet, the second user terminal on the Internet side is equipped with an Internet terminal operating environment, the Internet terminal operating environment is connected to the target router, and the target router is connected to the video network management network.
[0014] Optionally, the second video network terminal operating environment is used to send the device fingerprint of the first user terminal to the second core server through the video network converged switch for video network access authentication. After successful access authentication, user authentication is performed. After successful user authentication, the user configuration information sent by the second data communication control is received, and the user configuration information is used to establish a point-to-point connection of the video network with the second video network router or to enter the cloud operation and maintenance management center.
[0015] Optionally, the Internet terminal operating environment is used to send the device fingerprint of the second user terminal to the second core server through the target router for video network access authentication. After successful access authentication, user authentication is performed. After successful user authentication, the user configuration information sent by the second data communication control is received, and the user configuration information is used to establish a point-to-point connection of the video network with the second video network router or to enter the cloud operation and maintenance management center.
[0016] Optionally, the user configuration information includes the service IP address of the cloud operation and maintenance management center and / or the video network number of the cloud operation and maintenance management center.
[0017] The embodiments of the present invention have the following advantages:
[0018] In this embodiment of the invention, the network in the cloud center system can be divided into physically isolated video network service networks, video network management networks, and video network storage networks. Each type of network is responsible for the data transmission of each module in the cloud center system, thereby ensuring the network security of the cloud center system. In this embodiment of the invention, the cloud center system adopts the video network protocol instead of the TCP / IP protocol in the existing cloud center system. The video network protocol is more secure than the TCP / IP protocol. Attached Figure Description
[0019] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the description of the present invention will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1a This is a schematic diagram of the structure of a cloud center system based on a video network according to an embodiment of the present invention;
[0021] Figure 1b This is a schematic diagram of the structure of a video networking service network according to an embodiment of the present invention;
[0022] Figure 1c This is a schematic diagram of the structure of a video network management network according to an embodiment of the present invention;
[0023] Figure 1d This is a schematic diagram of the structure of a video network storage network according to an embodiment of the present invention;
[0024] Figure 1e This is a schematic diagram of the structure of a cloud center system for a video network according to an embodiment of the present invention;
[0025] Figure 2a This is a flowchart illustrating the steps of a cloud-based network security operation and maintenance method according to an embodiment of the present invention.
[0026] Figure 2b This is a flowchart illustrating another cloud-based network security operation and maintenance method in this invention.
[0027] Figure 2c This is a schematic diagram of the structure of another cloud center system for a video network in an embodiment of the present invention;
[0028] Figure 2d This is a flowchart illustrating the steps of a network security operation and maintenance method in a video network scenario according to an embodiment of the present invention;
[0029] Figure 2e This is a flowchart illustrating the steps of a network security operation and maintenance method in an Internet scenario, as described in an embodiment of the present invention. Detailed Implementation
[0030] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0031] The Visioncloud platform in this invention embodiment not only provides cloud host and cloud disk resource services based on virtualization technology, but also offers various container-based application services to better match the diversity of enterprise-level businesses. In addition to providing related services, it also provides supporting intelligent monitoring and maintenance, and service governance capabilities to ensure efficient and stable operation of businesses. A unified operation and maintenance portal ensures a consistent user experience. Visioncloud, based in the IaaS+PaaS market, is an industry-leading, deeply optimized, easy-to-use, stable, secure, and fully autonomous and controllable enterprise-level cloud platform, providing users with a one-stop turnkey solution for private cloud construction. The biggest difference from existing cloud platforms is that the underlying network uses the video network protocol.
[0032] Reference Figure 1a This diagram illustrates a structural schematic of a cloud center system based on a video network according to an embodiment of the present invention. The network of the cloud center system is divided into a physically isolated video network service network 101, a video network management network 102, and a video network storage network 103. Specifically, the video network service network can be used for data transmission between the computing resource pool 11 and the security resource pool 12 in the cloud center system; the video network management network can be used for data transmission between the cloud operation and maintenance management center 13 in the cloud center system; and the video network storage network can be used for data transmission between the storage resource area 14 in the cloud center system.
[0033] The computing resource pool is a collection of all physical computing servers and virtualized computing capabilities within the cloud center. Its core function is to abstract physical resources such as CPU and memory through virtualization technologies (such as VMs and containers) to form a unified, on-demand logical resource pool, providing users with elastic cloud host, container instance, and other services.
[0034] A security resource pool virtualizes the functions of traditional hardware security devices (such as firewalls, WAFs, and intrusion detection systems, IDS) using Network Functions Virtualization (NFV), forming a series of elastically scalable security service chains. It decouples security capabilities from fixed hardware, transforming them into cloud services that can be requested on demand and billed based on traffic.
[0035] The cloud operations and maintenance management center is the "brain" of the cloud center. It is a unified management platform that integrates a full range of functions such as monitoring, operations and maintenance, automation, and service delivery, enabling unified management, scheduling, and service of all resource pools, including computing, storage, security, and network.
[0036] The storage resource zone is a collection of all storage resources in the cloud center, providing persistent data storage capabilities for the computing resource pool. Based on performance and application scenarios, it is typically divided into block storage (such as cloud disks), file storage (such as NAS), and object storage (such as OSS / S3).
[0037] In this embodiment of the invention, a physically isolated network is used in the video network cloud center, which allows each part to operate safely under its corresponding network. When one network fails, it will not affect the network status of other areas. Furthermore, corresponding networks can be set up according to the characteristics of different areas, enabling refined network management.
[0038] In this embodiment of the invention, data transmission within each region can be accomplished through the corresponding module structure within each part of the network.
[0039] In one embodiment of the present invention, the video network service network includes a first video network router, a video network firewall, a first video network management system, a first core server, a first video network terminal operating environment, and a first data communication control system. The first video network router is connected to the video network firewall, the video network firewall is connected to the first core server, and the first core server includes hierarchically connected sub-core servers. The sub-core servers are connected to the first video network management system, the first data communication control system, or the first video network terminal operating environment.
[0040] The first video network router can connect the Internet and the video network, and convert the Internet protocol to the video network protocol. After Internet data enters the video network service network, it can be converted from Internet protocol data to video network protocol data that can be transmitted within the video network. The converted video network protocol data can then be transmitted in the video network cloud center, specifically from the first video network router to the video network firewall, and then to the video network core server. In this embodiment, the first video network router can be a 301B router.
[0041] The video network firewall in this embodiment of the invention can be used for video network access. The video network firewall is an intelligent security gateway capable of understanding the "language" (dedicated protocol) and "behavior" (video services) of the video network, and performing access control and security protection accordingly. In practical applications, the video network firewall can receive video network protocol data transmitted via the video network or video network protocol data after protocol conversion by the first video network router. The use of a video network firewall in this embodiment of the invention enables fine-grained access control (authorization management), thereby ensuring network data access security.
[0042] The primary core server is a core forwarding device within a video network, serving as the "brain" and "central dispatch center" of the video network system. It is not a single server, but rather a software system integrating core functions such as signaling control, media switching, resource management, user authentication, and service scheduling.
[0043] The core server is defined by its centralized scheduling role. Completely different from the peer-to-peer, decentralized communication models of IP networks (such as IP telephony and P2P video conferencing), all communication in the video network must be established, controlled, and managed through the core server. Terminal devices (cameras, conferencing terminals, displays) do not communicate directly with each other; instead, they all interact with the core server.
[0044] In the video network service network, the first core server may include hierarchically connected sub-core servers. The top-level core server can connect to the first video network management system and the first data communication management system. Each level of core server can connect to the first video network terminal operating environment. The first video network terminal operating environment is a deeply customized and highly optimized lightweight software operating environment that can be directly embedded into the internal firmware of video network terminal devices (such as video conferencing terminals, high-definition cameras, decoders, professional displays, etc.). In this embodiment of the invention, the first video network terminal operating environment may include video network terminal operating environments within a computing resource pool and a security resource pool.
[0045] In this embodiment of the invention, the first video network management system is a central controller for network management within the video network. For example, the V20 management system.
[0046] In one embodiment of the present invention, the first data communication control is a router or VVoE controller within a video network, and the first data communication control can be used to configure security policies during data transmission.
[0047] like Figure 1b The diagram shown is a structural schematic of a video networking service network according to an embodiment of the present invention.
[0048] In one embodiment of the present invention, the video network management network may include a second core server, a second video network router, a second video network management system, and a second data communication control system, wherein the second core server is connected to the second video network router, the second video network management system, and the second data communication control system.
[0049] In this embodiment of the invention, data interaction between various structures in the video network management network enables the cloud operation and maintenance management center to achieve secure operation and maintenance of the video network cloud center system.
[0050] like Figure 1c The diagram shown is a structural schematic of a video network management network according to an embodiment of the present invention.
[0051] In one embodiment of the present invention, the video network storage network includes a third core server, a third video network terminal operating environment, a third network management system, and a third data communication control system. The third core server is connected to the third video network terminal operating environment, the third network management system, and the third data communication control system. The third video network terminal operating environment is the video network terminal operating environment of the storage resource area.
[0052] like Figure 1d The diagram shown is a structural schematic of a video network storage network according to an embodiment of the present invention.
[0053] In this embodiment of the invention, the video network management network can access video network scenarios and / or internet scenarios. Compared to directly connecting to the cloud operation and maintenance management center via the internet, this further ensures the security of data transmission. Furthermore, considering different network scenarios, it has a wide range of applications.
[0054] Reference Figure 1e This diagram illustrates the structure of another cloud center system for video networking according to an embodiment of the present invention. The video networking cloud center system may include a computing resource pool, a security resource pool, a storage resource pool, and a cloud operation and maintenance management center. The computing resource pool and the security resource pool transmit data within a V2V service network; the storage resource pool transmits data within a V2V storage network; and the cloud operation and maintenance management center transmits data within a V2V management network.
[0055] The V2V service network includes a 301B router, a V2V firewall, a core server for hierarchical connections, a V20 network management system, data communication control, and a VVOE for the computing resource pool and a VVOE for the security resource pool.
[0056] V2V storage networks include core servers, v20 network management, data communication control, and VVoE.
[0057] The V2V management network includes a core server, a v20 network management system, data communication control, and a video link router.
[0058] The internet can be accessed through an IP router to the cloud operations and maintenance management center.
[0059] The Visioncloud platform in this invention embodiment not only provides cloud host and cloud disk resource services based on virtualization technology, but also offers various container-based application services to better match the diversity of enterprise-level businesses. In addition to providing related services, it also provides supporting intelligent monitoring and maintenance, and service governance capabilities to ensure efficient and stable operation of businesses. A unified operation and maintenance portal ensures a consistent user experience. Visioncloud, based in the IaaS+PaaS market, is an industry-leading, deeply optimized, easy-to-use, stable, secure, and fully autonomous and controllable enterprise-level cloud platform, providing users with a one-stop turnkey solution for private cloud construction. The biggest difference from existing cloud platforms is that the underlying network uses the video network protocol.
[0060] Reference Figure 2a This document illustrates a flowchart of a cloud-based network security operation and maintenance method according to an embodiment of the present invention. Applied to a cloud center system, the cloud center system includes a cloud operation and maintenance management center that uses a video network management network for data transmission. The cloud operation and maintenance management center is the "brain" of the cloud center. The cloud operation and maintenance management center is a unified management platform integrating comprehensive functions such as monitoring, operation and maintenance, automation, and service delivery, enabling unified management, scheduling, and service of all resource pools, including computing, storage, security, and network resources. The video network management network accesses the video network terminal operating environment in the video network scenario, specifically including the following steps:
[0061] Step S201: The operating environment of the video network terminal obtains the device fingerprint of the user terminal;
[0062] In practical applications, the video network terminal operating environment (VLOOMO) is the core software system residing within the terminal device in the video network architecture. The VLOOMO is a dedicated operating environment tailored for video network communication. It can obtain the device fingerprint of the user terminal, which serves as a unique identifier to distinguish the device.
[0063] Prior to step S201, the VVoE of the user's terminal PC can be configured in the data communication management of the video network. The device identifier of the user's terminal PC can be generated by the device fingerprint. The terminal identifier can be used for subsequent terminal data transmission.
[0064] Step S202: Use device fingerprinting for video network access authentication;
[0065] After obtaining the device fingerprint, it can be used for video network access authentication. Video network access authentication is used to verify whether the device is a secure device that is allowed to access the video network.
[0066] In one embodiment of the present invention, user authentication of a user terminal may include: the operating environment of the video network terminal can obtain first user authentication information input by the user terminal; then obtain second user authentication information stored in the user terminal; and the user terminal performs user authentication in accordance with the first user authentication information and the second user authentication information.
[0067] The first user authentication information can be the user's login account and password when logging into the device, and the second user authentication information is the pre-registration step S203, which performs user authentication on the user terminal after successful network access authentication.
[0068] When the device fingerprint determines that the user terminal is a device already registered with the video network, the network access authentication is successful. When the device fingerprint determines that the user terminal is not a device registered with the video network, the network access authentication is deemed to have failed.
[0069] If the network access authentication is completed and successful, further user authentication will be performed on the user. This user authentication is used to determine whether the logged-in user is a registered user.
[0070] In this embodiment of the invention, network access authentication and user authentication can effectively ensure the security of the video network cloud center system.
[0071] Step S204: After successful user authentication, receive user configuration information sent by the data communication control in the video network management network;
[0072] After successful user authentication, the video network terminal operating environment can receive user configuration information sent by the data communication control system in the video network management network. This user configuration information is used by the user terminal to transmit data with the cloud operations and maintenance management center. Specifically, the user configuration information includes the service IP address of the cloud operations and maintenance management center and / or the video network number of the cloud operations and maintenance management center.
[0073] Step S205: Use user configuration information to establish a point-to-point connection of the video network with the video network router in the video network management network or access the cloud operation and maintenance management center.
[0074] In this embodiment of the invention, after obtaining the user configuration information, the user configuration information can be used to establish a point-to-point connection between the video network and the video network router in the video network management network or the cloud operation and maintenance management center. Specifically, the video network number of the cloud operation and maintenance center can enable the video network terminal operating environment to establish a point-to-point connection between the video network and the video network router, and the IP address of the cloud operation and maintenance center can enable the video network terminal operating environment to enter the cloud operation and maintenance center (Internet side).
[0075] Reference Figure 2b This diagram illustrates a flowchart of another cloud-based network security operation and maintenance method according to an embodiment of the present invention. The method is applied to a cloud center system, which includes a cloud operation and maintenance management center that uses a video network management network for data transmission. The video network management network accesses the internet terminal operating environment in an internet-connected scenario. Specifically, the method may include the following steps:
[0076] Step S301: The Internet terminal operating environment obtains the device fingerprint of the user terminal;
[0077] In practical applications, the Internet terminal operating environment refers to the basic software platform and its ecosystem provided for running Internet applications on general-purpose smart terminal devices (such as PCs, mobile phones, tablets, smart TVs, etc.). Its core characteristics are openness, universality, and standardization.
[0078] In this embodiment of the invention, the Internet terminal operating environment can obtain the device fingerprint of the user terminal, wherein the device fingerprint is a unique identifier used to distinguish the device.
[0079] Step S302: Use device fingerprint for video network access authentication;
[0080] After obtaining the device fingerprint, it can be used for video network access authentication. Video network access authentication is used to verify whether the device is a secure device that is allowed to access the video network.
[0081] In one embodiment of the present invention, the Internet terminal operating environment is connected to a target router for converting between the video network protocol and the Internet protocol. Before using the device fingerprint for video network access authentication, the Internet terminal operating environment configures the IP address of the target router. Then, it can use the IP address to establish a TCP connection with the target router. Thus, the Internet terminal operating environment sends the device fingerprint to the target router based on the TCP connection, so that the target router forwards the device fingerprint to the core server in the cloud operation and maintenance management center for video network access authentication.
[0082] Step S303: After successful network access authentication, perform user authentication on the user terminal;
[0083] When the device fingerprint determines that the user terminal is a device already registered with the video network, the network access authentication is successful. When the device fingerprint determines that the user terminal is not a device registered with the video network, the network access authentication is deemed to have failed.
[0084] If the network access authentication is completed and successful, further user authentication will be performed on the user. This user authentication is used to determine whether the logged-in user is a registered user.
[0085] In this embodiment of the invention, network access authentication and user authentication can effectively ensure the security of the video network cloud center system.
[0086] Step S304: After successful user authentication, receive user configuration information sent by the data communication control in the video network management network;
[0087] After successful user authentication, the internet terminal's operating environment can receive user configuration information sent by the data communication control system in the video network management network. This user configuration information is used by the user terminal to transmit data with the cloud operations and maintenance management center. Specifically, the user configuration information includes the service IP address of the cloud operations and maintenance management center and / or the video network number of the cloud operations and maintenance management center.
[0088] Step S305: Use user configuration information to establish a point-to-point connection of the video network with the video network router in the video network management network or access the cloud operation and maintenance management center.
[0089] In this embodiment of the invention, after obtaining the user configuration information, a point-to-point connection of the video network or the cloud operation and maintenance management center can be established with the video network router in the video network management network using the user configuration information. Specifically, the video network number of the cloud operation and maintenance center can enable the Internet terminal operating environment to establish a point-to-point connection of the video network with the video network router, and the IP address of the cloud operation and maintenance center can enable the Internet terminal operating environment to enter the cloud operation and maintenance center (Internet side).
[0090] Reference Figure 2c This is a schematic diagram of another video network cloud center system structure in an embodiment of the present invention.
[0091] The video network cloud center system can include a computing resource pool, a security resource pool, a storage resource pool, and a cloud operation and maintenance management center. The computing resource pool and the security resource pool transmit data in the v2v service network; the storage resource pool transmits data in the v2v storage network; and the cloud operation and maintenance management center transmits data in the v2v management network.
[0092] Among them, the user's IP0E in the Internet can access the core server through the 301B router, and then obtain the user configuration information returned by the data communication management system after the video network access authentication and user authentication to conduct video network point-to-point connection or cloud operation and maintenance management center.
[0093] In the video network, the VV0E at the user end can access the core server through the video network converged switch, and then obtain the user configuration information returned by the data communication management system after the video network access authentication and user authentication to conduct video network point-to-point connection or cloud operation and maintenance management center.
[0094] The network security operation and maintenance method in this embodiment of the invention can solve the following problems faced by existing cloud center network security:
[0095] (1) Inherent defects of TCP / IP protocol: lack of native security mechanisms, vulnerable to threats such as IP spoofing and man-in-the-middle attacks.
[0096] In this embodiment of the invention, the video network protocol is used instead of the TCP / IP protocol.
[0097] (2) Difficulty in collaboration in heterogeneous environments: Differences in protocols across cloud platforms make it difficult to uniformly implement security strategies.
[0098] In this embodiment of the invention, the cloud operation and maintenance management center can simultaneously access user terminals on both the video network and the internet. This effectively solves the problem of coordination difficulties in heterogeneous environments.
[0099] (3) Delayed operation and maintenance response: Traditional operation and maintenance relies on manual analysis, which makes it difficult to deal with new types of attacks (such as DDoS and APT).
[0100] The embodiments of this invention enable automated operation and maintenance responses, effectively addressing new types of attacks.
[0101] (4) Urgent need for localization: Key areas need to replace TCP / IP with independent and controllable protocols to avoid supply chain risks.
[0102] This invention uses a domestically developed video network protocol instead of the TCP / IP protocol to achieve independent supply.
[0103] In this embodiment of the invention, the Internet terminal operating environment obtains the device fingerprint of the user terminal; uses the device fingerprint for video network access authentication; after successful access authentication, performs user authentication on the user terminal; after successful user authentication, receives user configuration information sent by the data communication control in the video network management network; uses the user configuration information to establish a point-to-point connection of the video network with the video network router in the video network management network or enters the cloud operation and maintenance management center, thereby realizing secure access to the cloud operation and maintenance management center in the video network cloud center system by replacing the TCP / IP protocol with the video network protocol.
[0104] Reference Figure 2d As shown, this is a network security operation and maintenance method in a video network scenario according to an embodiment of the present invention, which includes the following steps:
[0105] Step S11: Configure the VVoE of the user's terminal PC in the data communication management of the video network. The device identifier of the user's terminal PC is generated by the device fingerprint.
[0106] Step S12: The VVoE carries the device fingerprint for video network access authentication;
[0107] Step S13: Determine whether the network access authentication is successful. If successful, proceed to step S14.
[0108] In step S14, VVoE performs user authentication, and the user enters their username and password.
[0109] Step S15: Determine whether the user login was successful. If successful, proceed to step S15.
[0110] Step S16: Data communication control sends user configuration information to the PC, mainly including IP address, service IP address of cloud operation and maintenance center and video network number of cloud operation and maintenance center;
[0111] Step S17: VVOE establishes a point-to-point connection with the VisionNet router for the VisionNet network;
[0112] In step S18, VVoE accesses the cloud operations and maintenance management application via the IP address of the cloud operations and maintenance center.
[0113] Reference Figure 2e As shown in the figure, a network security operation and maintenance method in an Internet scenario according to an embodiment of the present invention includes the following steps:
[0114] Step S21: Configure the IPoE of the user's terminal PC in the data communication management of the video network. The device identifier of the user's network PC is generated by the device fingerprint.
[0115] Step S22: Configure the IP address of the 301B router in IPoE, and establish a TCP connection between IPoE and the 301B router;
[0116] Step S23: The IPoE carries the device fingerprint for video network access authentication;
[0117] Step S24: Determine whether the network access authentication is successful. If the network access is successful, proceed to step S25.
[0118] In step S25, IPoE performs user authentication, and the user enters their username and password.
[0119] Step S26: Determine whether the user login was successful. If the user login was successful, execute step S26.
[0120] Step S27: Data communication control sends user configuration information to the PC, mainly including the service IP address of the cloud operation and maintenance center and the video network number of the cloud operation and maintenance center;
[0121] Step S28: IPoE establishes a point-to-point connection between the video network and the video network router;
[0122] Step S29: IPoE accesses the cloud operations and maintenance management application via the IP address of the cloud operations and maintenance center.
[0123] In one embodiment of the present invention, when the video network management network is accessed as a video network scenario, the first user terminal on the video network side installs a second video network terminal operating environment, and the second video network terminal operating environment, the video network converged switch, and the video network converged switch are connected to the video network management network.
[0124] Based on the video network scenario structure of this embodiment, the second video network terminal operating environment is used to send the device fingerprint of the first user terminal to the second core server through the video network converged switch for video network access authentication. After successful access authentication, user authentication is performed. After successful user authentication, the user configuration information sent by the second data communication control is received, and the user configuration information is used to establish a point-to-point connection of the video network with the second video network router or to enter the cloud operation and maintenance management center.
[0125] The user configuration information includes the service IP address of the cloud operation and maintenance management center and / or the video network number of the cloud operation and maintenance management center.
[0126] In another embodiment of the present invention, when the video network management network accesses the Internet, the second user terminal on the Internet side installs an Internet terminal operating environment, the Internet terminal operating environment is connected to the target router, and the target router accesses the video network management network.
[0127] Based on the Internet terminal architecture in this embodiment of the invention, the Internet terminal operating environment can be used to send the device fingerprint of the second user terminal to the second core server through the target router for video network access authentication. After successful access authentication, user authentication is performed. After successful user authentication, the user configuration information sent by the second data communication control is received, and the user configuration information is used to establish a point-to-point connection of the video network with the second video network router or to enter the cloud operation and maintenance management center.
[0128] The user configuration information includes the service IP address of the cloud operation and maintenance management center and / or the video network number of the cloud operation and maintenance management center.
[0129] In this embodiment of the invention, the network in the cloud center system can be divided into physically isolated video network service networks, video network management networks, and video network storage networks. Each type of network is responsible for the data transmission of each module in the cloud center system, thereby ensuring the network security of the cloud center system. In this embodiment of the invention, the cloud center system adopts the video network protocol instead of the TCP / IP protocol in the existing cloud center system. The video network protocol is more secure than the TCP / IP protocol.
[0130] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0131] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0132] Embodiments of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0133] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0134] These computer program instructions may also be loaded onto a computer or other programmable data processing terminal equipment to cause a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable terminal equipment, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0135] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.
[0136] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0137] The above provides a detailed description of a cloud center system based on video networking. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A cloud-centric system based on a video network, characterized in that, The network of the cloud center system is divided into a physically isolated vision network service network, a vision network management network and a vision network storage network, wherein: The vision network service network is used for data transmission of the computing resource pool and the security resource pool in the cloud center system; The vision network management network is used for data transmission of the cloud operation and maintenance center in the cloud center system; The vision network storage network is used for data transmission of the storage resource area in the cloud center system.
2. The system of claim 1, wherein, The vision network service network comprises a first vision network router, a vision network firewall, a first vision network network management, a first core server, a first vision network terminal running environment and a first number communication management and control, the first vision network router is connected with the vision network firewall, the vision network firewall is connected with the first core server, the first core server comprises a hierarchically connected sub-core server, the sub-core server is connected with the first vision network network management, the first number communication management and control or the first vision network terminal running environment, wherein the first vision network router is used for connecting the Internet and the vision network, and performing protocol conversion between the Internet protocol and the vision network protocol; the vision network firewall is used for vision network access, and the first vision network terminal running environment comprises a vision network terminal running environment in the computing resource pool and the security resource pool.
3. The system of claim 1, wherein, The vision network management network comprises a second core server, a second vision network router, a second vision network network management and a second number communication management and control, the second core server is connected with the second vision network router, the second vision network network management and the second number communication management and control.
4. The system of claim 1, wherein, The vision network storage network comprises a third core server, a third vision network terminal running environment, a third network management and a third number communication management and control, the third core server is connected with the third vision network terminal running environment, the third network management and the third number communication management and control, wherein the third vision network terminal running environment is a vision network terminal running environment of the storage resource area.
5. The system of claim 3, wherein, The vision network management network accesses a vision network scene and / or an Internet scene.
6. The system of claim 5, wherein, When the vision network management network accesses the vision network scene, a first user terminal on the vision network side installs a second vision network terminal running environment, the second vision network terminal running environment is connected with a vision network converged switch and the vision network converged switch accesses the vision network management network.
7. The system of claim 5, wherein, When the vision network management network accesses the Internet scene, a second user terminal on the Internet side installs an Internet terminal running environment, the Internet terminal running environment is connected with a target router and the target router accesses the vision network management network.
8. The system of claim 6, wherein, The second vision network terminal running environment is used for sending a device fingerprint of the first user terminal to the second core server through the vision network converged switch for vision network access authentication, after successful access authentication, user authentication is performed, after successful user authentication, user configuration information sent by the second number communication management and control is received, the point-to-point connection of the vision network is established with the second vision network router or the cloud operation and maintenance center is entered by using the user configuration information.
9. The system of claim 7, wherein, The internet terminal running environment is configured to send a device fingerprint of the second user terminal to the second core server through the target router for a vision Internet access authentication, after the access authentication succeeds, perform user authentication, after the user authentication succeeds, receive user configuration information sent by the second number management and control, and use the user configuration information to establish a point-to-point connection of the vision Internet with the second vision Internet router or enter the cloud operation and maintenance center.
10. The system of claim 8 or 9, characterized in that, The user configuration information includes a service IP address of the cloud operation and maintenance center and / or a vision Internet number of the cloud operation and maintenance center.