Network security service function chain arrangement method and device of data processing unit, computer equipment, storage medium and program product

By designing a functional chain to deploy and optimize the objective function and genetic algorithm in the data processing unit, the problem of low utilization of acceleration sub-units in traditional methods is solved, achieving balanced resource consumption and efficient network security service orchestration, thus meeting the flexibility requirements of cloud-edge-device architecture.

CN121750461APending Publication Date: 2026-03-27SOUTHERN POWER GRID DIGITAL GRID RESEARCH INSTITUTE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-28
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Traditional virtualization-based network security service function chain orchestration methods have failed to effectively improve the utilization rate of acceleration sub-units, resulting in wasted resources and power consumption, and making it difficult to meet the needs of efficient and flexible network security services in cloud-edge-device architecture.

Method used

By designing and optimizing the objective function of the functional chain deployment, and combining it with a genetic algorithm, the resource load of the data processing unit is optimized and the utilization rate of the sub-unit is accelerated. This enables the orchestration of a software and hardware collaborative network security service functional chain, ensuring balanced resource consumption and reducing waste.

Benefits of technology

This improved the utilization rate of the acceleration subunit, reduced resource and power consumption waste, achieved balanced consumption of the network security service function chain among data processing units, and enhanced the efficiency and flexibility of network security services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121750461A_ABST
    Figure CN121750461A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of cloud computing security services, and provides a network security service function chain arrangement method and device of a data processing unit, computer equipment, a storage medium and a program product. The method comprises the steps of obtaining a security service request of a to-be-deployed network security service function chain of a target service flow according to a network security demand of a type to which the target service flow belongs and a security service function of a data processing unit; obtaining a function chain deployment optimization objective function according to the multi-class resource load degree for arranging a to-be-deployed network security service function chain in the security service request at the deployment completion moment and the average utilization rate of acceleration subunits in the data processing unit at the deployment completion moment; and under the constraint of the multi-constraint condition, according to the to-be-deployed network security service function chain, obtaining a network security service function chain target arrangement scheme which enables the function chain deployment optimization target function to reach a preset optimization condition. By adopting the method, waste of resources and power consumption can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of cloud computing security service, and particularly relates to a network security service function chain arrangement method and device of a data processing unit, computer equipment, a computer readable storage medium and a computer program product. BACKGROUND

[0002] With the explosive growth of cloud computing, big data and mobile Internet, the physical binding and static deployment mode of hardware devices in the traditional network security architecture seriously restrict the compatibility, flexibility and scalability of network security protection. In order to solve the compatibility, flexibility and scalability of network security protection in cloud edge architecture, network security service function chain based on virtualization technology emerges as the times require, realizing the paradigm shift from static hardware stacking to software-defined security.

[0003] The traditional network security service function chain arrangement method based on virtualization technology only optimizes and solves the resource utilization rate, deployment success rate and bandwidth consumption of the arrangement scheme, and does not consider improving the utilization rate of the acceleration subunit in the deployable data processing unit, resulting in waste of acceleration subunit resources and power consumption. SUMMARY

[0004] Therefore, it is necessary to provide a network security service function chain arrangement method, device, computer equipment, computer readable storage medium and computer program product of a data processing unit in view of the above technical problems.

[0005] In a first aspect, the present application provides a network security service function chain arrangement method of a data processing unit, comprising:

[0006] According to the network security requirement of the type to which the target business traffic belongs and the security service function of the data processing unit, the security service request of the to-be-deployed network security service function chain of the target business traffic is obtained;

[0007] According to the multi-type resource requirement corresponding to each security service function in the security service request, the average load degree of the deployed node and the average usage rate of the deployed physical link at the deployment completion time are obtained, so as to obtain the multi-type resource load degree of the to-be-deployed network security service function chain in the security service request at the deployment completion time;

[0008] According to the multi-type resource load degree of the to-be-deployed network security service function chain in the security service request at the deployment completion time, and the average usage rate of the acceleration subunit in the data processing unit at the deployment completion time, a function chain deployment optimization objective function is obtained;

[0009] Under the constraint conditions that the consumption amount of the multiple types of resources is lower than the total amount of the respective resources, the amount of incoming traffic and outgoing traffic of the deployed node is equal, the processing capability occupied by the acceleration subunit does not exceed the processing capability possessed by the acceleration subunit, and the delay time of the deployed security service function chain is less than a delay threshold, a network security service function chain target arrangement scheme is obtained according to the to-be-deployed network security service function chain, so that the function chain deployment optimization objective function reaches a preset optimization condition.

[0010] In a second aspect, the present application further provides a network security service function chain arrangement device of a data processing unit, comprising:

[0011] A security service request acquisition module is configured to obtain a security service request of a to-be-deployed network security service function chain of target business traffic according to network security requirements of a type to which the target business traffic belongs and security service functions of the data processing unit.

[0012] A multiple resource load degree acquisition module is configured to obtain an average load degree of a deployed node and an average usage rate of a deployed physical link at a deployment completion moment according to multiple resource requirements corresponding to each security service function in the security service request, so as to obtain a multiple resource load degree for arranging the to-be-deployed network security service function chain in the security service request at the deployment completion moment.

[0013] An objective function acquisition module is configured to obtain a function chain deployment optimization objective function according to the multiple resource load degree for arranging the to-be-deployed network security service function chain in the security service request at the deployment completion moment and an average usage rate of an acceleration subunit of the data processing unit at the deployment completion moment.

[0014] A target arrangement scheme acquisition module is configured to obtain a network security service function chain target arrangement scheme that makes the function chain deployment optimization objective function reach a preset optimization condition according to the to-be-deployed network security service function chain under the constraint conditions that the consumption amount of the multiple types of resources is lower than the total amount of the respective resources, the amount of incoming traffic and outgoing traffic of the deployed node is equal, the processing capability occupied by the acceleration subunit does not exceed the processing capability possessed by the acceleration subunit, and the delay time of the deployed security service function chain is less than a delay threshold.

[0015] In a third aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, the memory stores a computer program, and the processor executes the above method.

[0016] In a fourth aspect, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program is executed by a processor to execute the above method.

[0017] In a fifth aspect, the present application also provides a computer program product. The computer program product comprises a computer program, which is executed by a processor to perform the above method.

[0018] The network security service function chain arrangement method, device, computer equipment, computer readable storage medium and computer program product of the data processing unit can obtain a security service request of a to-be-deployed network security service function chain of target business traffic according to the network security requirement of the type to which the target business traffic belongs and the security service function of the data processing unit; obtain the average load degree of the deployed node and the average usage rate of the deployed physical link at the deployment completion time according to the multi-type resource requirement corresponding to each security service function in the security service request, so as to obtain the multi-type resource load degree of the to-be-deployed network security service function chain in the security service request at the deployment completion time; obtain a function chain deployment optimization objective function according to the multi-type resource load degree of the to-be-deployed network security service function chain in the security service request at the deployment completion time and the average usage rate of the acceleration subunit in the data processing unit at the deployment completion time; and obtain a network security service function chain target arrangement scheme that makes the function chain deployment optimization objective function reach a preset optimization condition according to the to-be-deployed network security service function chain under the constraint of the constraint condition that the consumption amount of the multi-type resource is lower than the total amount of the respective resource, the number of the incoming traffic and the outgoing traffic of the deployed node is equal, the processing capacity occupied by the acceleration subunit does not exceed the processing capacity possessed by the acceleration subunit, and the delay time of the security service function chain after deployment is less than a delay threshold. The present application obtains the network security service function chain target arrangement scheme that makes the function chain deployment optimization objective function reach the preset optimization condition according to the to-be-deployed network security service function chain under the constraint of the constraint condition; and the function chain deployment optimization objective function comprehensively considers the balance of the resource consumption of all data processing units in the physical network and the usage rate of the acceleration subunit, so that the resource consumption of the network security service function chain target arrangement scheme is more balanced among the data processing units, the resource of a small number of data processing units is prevented from being rapidly consumed, the usage rate of the acceleration subunit is improved, and the waste of resources and power consumption is reduced. BRIEF DESCRIPTION OF DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the present application or the related art. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other related drawings can also be obtained without creative labor.

[0020] Figure 1 The application environment diagram of the network security service function chain arrangement method of the data processing unit in an embodiment;

[0021] Figure 2 A schematic diagram of a network security service function chain architecture taking a data processing unit as a running carrier in an embodiment;

[0022] Figure 3 A schematic diagram of a flow of a network security service function chain orchestration method of a data processing unit in an embodiment;

[0023] Figure 4 A schematic diagram of a flow of a verification of a server and a data processing unit in an embodiment;

[0024] Figure 5 A structural block diagram of a network security service function chain orchestration apparatus of a data processing unit in an embodiment;

[0025] Figure 6 An internal structure diagram of a computer device in an embodiment. DETAILED DESCRIPTION

[0026] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application is further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0027] It should be noted that the terms "comprising" and "having" and any variations thereof used in the present application are intended to cover non-exclusive inclusion. The term "multiple" used in the present application refers to two and more than two. The term "and / or" used in the present application refers to one of the solutions or any combination of multiple solutions.

[0028] The network security service function chain orchestration method of the data processing unit provided by the embodiments of the present application can be applied to, for example, Figure 1The application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data required by the server 104 to process. The data storage system can be integrated on the server 104, or placed on the cloud or other network servers. The terminal 102 can obtain the security service request of the target business traffic according to the network security requirement of the type to which the target business traffic belongs and the security service function of the data processing unit; according to the multi-type resource load degree of the security service request in the deployed network security service function chain at the deployment completion time, and the average utilization rate of the acceleration sub-unit in the data processing unit at the deployment completion time, obtain the function chain deployment optimization objective function; under the constraint of multiple constraint conditions, according to the network security service function chain to be deployed, obtain the network security service function chain target arrangement scheme that makes the function chain deployment optimization objective function reach the preset optimization condition. Among them, the terminal 102 can be, but not limited to, various personal computers, notebook computers, smart phones, tablet computers, unmanned aerial vehicles, low-altitude aircraft, Internet of Things devices and portable wearable devices. The server 104 can be a standalone physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0029] The network security service function chain architecture taking the data processing unit (DPU) as the running carrier is as shown in Figure 2

[0030] Taking the cloud-edge-end network scene as an example, the data processing unit is embedded in the edge gateway, switch and server in the physical network, and can provide network security processing for business traffic passing through its location. The embedded data processing unit should contain central processing unit (CPU) resources and field-programmable gate array (FPGA) resources, and support remote programming of hardware acceleration sub-units. The deployed data processing unit security function has a software and hardware collaboration feature, including a software logic part and a hardware logic part.

[0031] When the business traffic from the terminal arrives at the edge gateway, the edge gateway identifies the type to which the business traffic belongs, and generates a network security service function chain to be deployed for the business traffic according to the network security requirement of the type to which the business traffic belongs and the security service function of the schedulable data processing unit. The security service request can be generated according to the network security service function chain to be deployed for the business traffic.

[0032] ​According to the security service request, a network security service function chain orchestration scheme can be determined, and then according to the network security service function chain orchestration scheme, the security service functions on the network security service function chain are mapped to specific data processing units in the physical network, the data processing unit security function software logic is deployed and the hardware acceleration module is burned, the soft and hard cooperative data processing unit security function instance is started, finally the business traffic is guided to pass through the deployed function instance in turn, the security service processing is completed, and finally the business traffic reaches the destination.

[0033] In one exemplary embodiment, as shown in Figure 3 , a network security service function chain orchestration method of a data processing unit is provided, which is applied to Figure 1 terminal 102 as an example, including the following steps S301 to S304. Wherein:

[0034] Step S301, according to the network security requirement of the type to which the target business traffic belongs and the security service function of the data processing unit, the security service request of the target business traffic is obtained.

[0035] The business traffic to be processed by the security service can be referred to as target business traffic.

[0036] According to the network security requirement of the type to which the target business traffic belongs and the security service function of the data processing unit, the target business traffic can be deployed network security service function chain. According to the target business traffic to be deployed network security service function chain, the security service request of the target business traffic to be deployed network security service function chain is generated , as shown in formula (1).

[0037] (1)

[0038] Wherein, the source node of the s-th security service request is represented by the destination node of the s-th security service request is represented by , the ordered security service function of the s-th security service request is represented by the type of the i-th security function is represented by the central processing unit resource requirement corresponding to each security service function on the network security service function chain to be deployed is represented by , the field programmable gate array resource requirement corresponding to each security service function on the network security service chain to be deployed is represented by the hardware acceleration processing capacity occupation is represented by the processing delay of the security service function is represented by denotes an arrival time of the s-th arrived security service request, denotes a link bandwidth requirement of the security service request, denotes a highest delay threshold that the security service request can tolerate, denotes a life cycle of a network security service function chain of the security service request in the network.

[0039] In step S302, according to the multi-type resource requirement corresponding to each security service function in the security service request, the average load degree of the deployed node and the average usage rate of the deployed physical link at the deployment completion time are obtained to obtain the multi-type resource load degree of the arrangement of the network security service function chain to be deployed in the security service request at the deployment completion time.

[0040] The multi-type resource requirement corresponding to each security service function can include a computing resource requirement, a storage resource requirement, and a transmission resource requirement.

[0041] The average load degree of the deployed node at the deployment completion time can be obtained according to the computing resource requirement and the storage resource requirement corresponding to each security service function in the security service request.

[0042] The average usage rate of the deployed physical link at the deployment completion time can be obtained according to the transmission resource requirement corresponding to each security service function in the security service request.

[0043] The multi-type resource load degree of the arrangement of the network security service function chain to be deployed in the security service request at the deployment completion time can be obtained according to the average load degree of the deployed node and the average usage rate of the deployed physical link at the deployment completion time, and the weight coefficients of the deployed node load and the deployed physical link load, as shown in formula (2).

[0044] (2)

[0045] wherein, denotes the average load degree of the deployed node at the deployment completion time the multi-type resource load degree of the arrangement of the network security service function chain to be deployed in the security service request, denotes the average usage rate of the deployed physical link at the deployment completion time the average load degree of the deployed node at the deployment completion time, denotes the average usage rate of the deployed physical link at the deployment completion time the average usage rate of the deployed physical link at the deployment completion time, denotes the weight coefficient of the deployed node load, denotes the weight coefficient of the deployed physical link load, and .

[0046] In step S303, the function chain deployment optimization objective function is obtained according to the load degree of the plurality of types of resources arranged for the network security service function chain to be deployed in the security service request at the deployment completion time, and the average usage rate of the acceleration subunit in the data processing unit at the deployment completion time.

[0047] The function chain deployment optimization objective function can be obtained according to the load degree of the plurality of types of resources arranged for the network security service function chain to be deployed in the security service request at the deployment completion time, the average usage rate of the acceleration subunit in the data processing unit at the deployment completion time, the weight of the load degree of the plurality of types of resources, and the weight of the average usage rate of the acceleration subunit, as shown in formula (3).

[0048] (3)

[0049] wherein s represents the security service function chain to be deployed, t represents the deployment completion time of completing the deployment of the security service function chain, represents the function chain deployment optimization objective function, represents the deployment completion time the load degree of the plurality of types of resources arranged for the network security service function chain to be deployed in the security service request, represents the deployment completion time the average usage rate of the acceleration subunit in the data processing unit, represents the weight of the load degree of the plurality of types of resources, represents the weight of the average usage rate of the acceleration subunit, which is set by the user according to the demand.

[0050] In step S304, under the constraints that the consumption amount of the plurality of types of resources is lower than the total amount of the respective resources, the amount of the incoming traffic and the outgoing traffic of the deployed node is equal, the processing capacity occupied by the acceleration subunit does not exceed the processing capacity possessed by itself, and the delay time of the completed security service function chain is less than the delay threshold, the network security service function chain target arrangement scheme that makes the function chain deployment optimization objective function reach the preset optimization condition is obtained according to the network security service function chain to be deployed.

[0051] In order to ensure the quality of security service and reliable link transmission, it is necessary to ensure that the data processing unit node has sufficient resources to run the security service function, and the link has sufficient bandwidth to transmit traffic. The following constraints are proposed: the consumption amount of the plurality of types of resources is lower than the total amount of the respective resources, the amount of the incoming traffic and the outgoing traffic of the deployed node is equal, the processing capacity occupied by the acceleration subunit does not exceed the processing capacity possessed by itself, and the delay time of the completed security service function chain is less than the delay threshold.

[0052] The network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization condition can be obtained according to the network security service function chain to be deployed under the constraint of the constraint condition based on a genetic algorithm. The preset optimization condition can be set according to actual conditions.

[0053] In the network security service function chain orchestration method of the data processing unit, the network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization condition can be obtained according to the network security service function chain to be deployed under the constraint of the constraint condition. The function chain deployment optimization objective function comprehensively considers the balance of resource consumption of all data processing units in the physical network and the usage rate of the acceleration subunit, so that the resource consumption of the network security service function chain target orchestration scheme is more balanced among the data processing units, preventing a few data processing units from being quickly exhausted, while improving the usage rate of the acceleration subunit and reducing the waste of resources and power consumption.

[0054] In one embodiment, according to the multi-type resource demand of each security service function in the security service request, the average load degree of the deployed node at the deployment completion time and the average usage rate of the deployed physical link are obtained. The specific steps are as follows: according to the central processing unit resource requirement, memory resource requirement and field programmable gate array resource requirement of each security service function in the security service request, the average load degree of the deployed node at the deployment completion time is obtained; according to the link bandwidth demand of each security service function in the security service request and the maximum data transmission bandwidth of each physical link, the average usage rate of the deployed physical link at the deployment completion time is obtained.

[0055] The multi-type resource demand of each security service function can include operation resource demand, storage resource demand and transmission resource demand. The operation resource demand can include central processing unit resource requirement and field programmable gate array resource requirement, the storage resource demand can include memory resource requirement, and the transmission resource demand can include link bandwidth demand.

[0056] According to the central processing unit resource requirement, memory resource requirement and field programmable gate array resource requirement of each security service function in the security service request, and the security service function corresponding to each deployed node, the central processing unit resource consumption, memory resource consumption and field programmable gate array resource consumption of each deployed node at the deployment completion time can be obtained to obtain the central processing unit resource load degree, memory resource load degree and field programmable gate array resource load degree of each deployed node.

[0057] The load level of each deployed node can be obtained based on the CPU resource load level, memory resource load level, and FPGA resource load level of each deployed node, as well as the respective weight coefficients of CPU resources, memory resources, and FPGA resources, so as to obtain the average load level of the deployed nodes at the time of deployment completion.

[0058] The utilization rate of each deployed physical link at the time of deployment completion can be obtained based on the link bandwidth requirement corresponding to each security service function in the security service request, the maximum data transmission bandwidth of each physical link, and the security service function mapped to each deployed physical link, as shown in Equation (4).

[0059] (4)

[0060] in, Node t represents the deployment completion time. and nodes The utilization rate of the deployed physical links between them Indicates a security service request. Indicates the first The link bandwidth requirement for each security service request. This indicates the virtual link when the s-th security service request is made. At deployment completion time t, it is mapped to the physical link. hour, ;otherwise , Represents node t and nodes The maximum data transmission bandwidth of the deployed physical links between them.

[0061] The average utilization rate of the deployed physical links at the moment of deployment completion can be calculated based on the ratio between the utilization rate of each deployed physical link and the number of deployed physical links, as shown in Equation (5).

[0062] (5)

[0063] in, This represents the average utilization of the deployed physical links at deployment completion time t. Node t represents the deployment completion time. and nodes The utilization rate of the deployed physical links between them This indicates the number of physical links deployed.

[0064] In this embodiment, according to the central processor resource requirement, the memory resource requirement and the field programmable gate array resource requirement corresponding to each security service function in the security service request, the average load degree of the deployed node at the deployment completion time is obtained; according to the link bandwidth demand corresponding to each security service function in the security service request and the maximum data transmission bandwidth of each physical link, the average usage rate of the deployed physical link at the deployment completion time is obtained, which makes data preparation for subsequent calculation of the multi-type resource load degree of the security service request for the to-be-deployed network security service function chain at the deployment completion time.

[0065] In one of the embodiments, according to the central processor resource requirement, the memory resource requirement and the field programmable gate array resource requirement corresponding to each security service function in the security service request, the average load degree of the deployed node at the deployment completion time is obtained, and the specific steps are as follows: according to the central processor resource requirement, the memory resource requirement and the field programmable gate array resource requirement corresponding to each security service function in the security service request, the central processor resource consumption, the memory resource consumption and the field programmable gate array resource consumption of each deployed node at the deployment completion time are obtained; according to the central processor resource consumption, the memory resource consumption and the field programmable gate array resource consumption of each deployed node at the deployment completion time, and the total amount of central processor resource, the total amount of memory resource and the total amount of field programmable gate array resource of each deployed node, the central processor resource load degree, the memory resource load degree and the field programmable gate array resource load degree of each deployed node are obtained; according to the central processor resource load degree, the memory resource load degree and the field programmable gate array resource load degree of each deployed node, and the weight coefficient of the central processor resource, the memory resource and the field programmable gate array resource respectively, the load degree of each deployed node is obtained; according to the load degree of each deployed node and the number of deployed nodes, the average load degree of the deployed node at the deployment completion time is obtained.

[0066] According to the central processor resource requirement, the memory resource requirement and the field programmable gate array resource requirement corresponding to each security service function in the security service request, and the security service function corresponding to each deployed node, the central processor resource consumption, the memory resource consumption and the field programmable gate array resource consumption of each deployed node at the deployment completion time can be obtained.

[0067] The CPU resource load of each deployed node can be determined by the ratio of its CPU resource consumption to the total CPU resources at the time of deployment completion. Similarly, the memory resource load of each deployed node can be determined by the ratio of its memory resource consumption to the total memory resources at the time of deployment completion. Finally, the field-programmable gate array (FPGA) resource load of each deployed node can be determined by the ratio of its FPGA resource consumption to the total FPGA resources at the time of deployment completion.

[0068] The load level of each deployed node can be obtained based on the CPU resource load level, memory resource load level and field-programmable gate array resource load level of each deployed node, as well as the respective weight coefficients of CPU resources, memory resources and field-programmable gate array resources, as shown in Equation (6).

[0069] (6)

[0070] in, This indicates the load level of each deployed node v at deployment completion time t; Indicates a security service request; This represents the ordered security service function for the s-th security service request; This indicates the security service function in the s-th security service request. When deployment is completed at time t and mapped to the deployed node v, ,otherwise ; Indicates the s-th security service request. CPU resource consumption corresponding to each security service function; This indicates the total amount of central processing unit resources; Indicates the s-th security service request. The memory resource consumption corresponding to each security service function; Indicates the total amount of memory resources. This represents the number of acceleration sub-units deployed in the physical network at deployment completion time t. Indicates when the acceleration subunit When deployment is completed at time t and mapped to the deployed node v, ;otherwise , This indicates the field-programmable gate array (FPGA) resource consumption of the acceleration subunit for security service functions. This indicates the type of security service function corresponding to the m-th hardware acceleration subunit. This indicates the total amount of field-programmable gate array resources. a weight coefficient representing a central processing unit resource, a weight coefficient representing a memory resource, a weight coefficient representing a field programmable gate array resource, which is pre-set by a user according to a requirement, and .

[0071] The average load degree of the deployed nodes at the deployment completion time can be obtained according to the load degree of each deployed node and the ratio between the number of the deployed nodes, as shown in equation (7).

[0072] (7)

[0073] wherein, the average load degree of the deployed nodes at the deployment completion time t, the load degree of the deployed nodes at the deployment completion time t, the number of the deployed nodes.

[0074] In the embodiment, the central processing unit resource consumption, the memory resource consumption and the field programmable gate array resource consumption of each deployed node at the deployment completion time are obtained according to the central processing unit resource requirement, the memory resource requirement and the field programmable gate array resource requirement corresponding to each security service function in the security service request; and the average load degree of the deployed nodes at the deployment completion time is obtained according to the central processing unit resource consumption, the memory resource consumption and the field programmable gate array resource consumption of each deployed node at the deployment completion time, which can prepare data for the subsequent calculation of the multi-type resource load degree of the arrangement of the to-be-deployed network security service function chain in the security service request at the deployment completion time.

[0075] In one of the embodiments, under the constraint conditions that the consumption amount of each of the multiple types of resources is lower than the total amount of the respective resource, the amount of the traffic entering and the amount of the traffic flowing out of the deployed node are equal, the processing capability occupied by the acceleration sub-unit does not exceed the processing capability possessed by the acceleration sub-unit, and the delay time of the completed deployed security service function chain is less than the delay threshold, according to the network security service function chain to be deployed, a network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization condition is obtained, and the specific steps are as follows: obtaining an initial population; each individual in the initial population is a potential orchestration scheme of the network security service function chain to be deployed that satisfies the constraint condition; when the initial population is iterated, the fitness function value of each individual in the initial population is obtained according to the function chain deployment optimization objective function value of each individual in the initial population; the high-quality individual set of the current iteration is selected from the initial population according to the fitness function value of each individual in the initial population; the crossover operation and the mutation operation are performed on the high-quality individual set of the current iteration to obtain a new population of the current iteration; whether the maximum iteration number is reached is judged, if yes, the best individual in the new population of the current iteration is output as the network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization condition, and if not, the next round of iteration is performed on the new population of the current iteration.

[0076] The initial population can be obtained based on the initial population generation algorithm of the greedy strategy, wherein each individual in the initial population is a potential orchestration scheme of the network security service function chain to be deployed that satisfies the constraint condition.

[0077] When the initial population is iterated, the fitness function value of each individual in the initial population is obtained according to the function chain deployment optimization objective function value of each individual in the initial population, as shown in formula (8).

[0078] (8)

[0079] wherein, indicates the fitness function value of the individual , and indicates the function chain deployment optimization objective function value. When the F(s, t) value of the individual is lower, the individual is better, and the fitness value should be the highest.

[0080] The high-quality individual set of the current iteration can be selected from the initial population according to the fitness function value of each individual in the initial population. Specifically, the roulette mechanism can be adopted, and the probability that the individual is selected is as shown in formula (9).

[0081] (9)

[0082] wherein, indicates the probability that the individual The probability of being selected, Indicates the population size. This indicates that the individual with higher fitness The possibility of being eliminated is small, but other individuals still have opportunities.

[0083] The crossover operation and mutation operation can be performed on the set of high-quality individuals of this iteration to obtain the new population of this iteration. Specifically, after selecting the high-quality individuals of this iteration, the crossover operation and mutation operation are performed to generate new individuals of this iteration. The crossover operation can adopt uniform crossover operation, which can ensure that the new individuals of this iteration generated are feasible.

[0084] It is judged whether the maximum iteration number is reached , if the maximum iteration number is reached, the best individual in the new population of this iteration is output as the network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization condition, and if the maximum iteration number is not reached, the next round of iteration is performed on the new population of this iteration. The maximum iteration number can be set according to actual conditions.

[0085] In this embodiment, when the initial population is iterated, the fitness function value of each individual in the initial population is obtained according to the function chain deployment optimization objective function value of each individual in the initial population, to filter out the set of high-quality individuals of this iteration from the initial population, and obtain the new population of this iteration; it is judged whether the maximum iteration number is reached, if the maximum iteration number is reached, the best individual in the new population of this iteration is output as the network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization condition, and if the maximum iteration number is not reached, the next round of iteration is performed on the new population of this iteration, which can quickly solve the network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization condition.

[0086] In one of the embodiments, the initial population is obtained, and the specific steps are as follows: according to the principle of selecting the node with the least resource consumption to deploy the network security function, each network security service function corresponding to the deployed node in the target node list is selected to obtain the potential orchestration scheme of the to-be-deployed network security service function chain that satisfies the constraint condition; the target node list includes the nodes allowed to be used by the to-be-deployed network security service function chain; each potential orchestration scheme is regarded as a single individual to obtain the initial population.

[0087] The target node list includes the nodes allowed to be used by the to-be-deployed network security service function chain, and can record all the nodes used by the to-be-deployed network security service function chain.

[0088] The initial population can be obtained based on a greedy strategy initial population generation algorithm. One network function without deployed security service can be selected from the network security service function chain to be deployed, and deployed to the target node list The node in which the corresponding hardware acceleration subunit is deployed.

[0089] Specifically, if There are multiple nodes in which the corresponding hardware acceleration subunit is deployed, the node to be deployed corresponding to each network security service function in the network security service function chain to be deployed is selected from the target node list according to the principle of selecting the node with the least resource consumption to deploy the network security function, and the link capacity is further checked to ensure the feasibility of the selected node, so as to obtain a potential arrangement scheme of the network security service function chain to be deployed that satisfies the constraint condition.

[0090] The process described above can be performed pSize times to obtain pSize potential arrangement schemes of the network security service function chain to be deployed that satisfy the constraint condition, and each potential arrangement scheme is regarded as a single individual to obtain the initial population.

[0091] In this embodiment, the node to be deployed corresponding to each network security service function in the network security service function chain to be deployed is selected from the target node list according to the principle of selecting the node with the least resource consumption to deploy the network security function, so as to obtain a potential arrangement scheme of the network security service function chain to be deployed that satisfies the constraint condition, to obtain the initial population. The initial population with higher fitness can be generated, so as to further improve the convergence efficiency of obtaining the target arrangement scheme of the network security service function chain.

[0092] In one of the embodiments, the method provided in the present application further includes: if the node resource state of the target node list does not satisfy the deployment condition of the network security service function chain to be deployed, selecting a node with a resource state satisfying a preset resource condition from the physical network and adding the node to the target node list.

[0093] If there is no feasible node in the target node list , i.e., the node resource state of the target node list does not satisfy the deployment condition of the network security service function chain to be deployed, a node with a resource state satisfying a preset resource condition can be selected from the physical network and added to the target node list . The preset resource condition can be set according to actual conditions.

[0094] In this embodiment, if the node resource state of the target node list does not satisfy the deployment condition of the network security service function chain to be deployed, a node with a resource state satisfying a preset resource condition is selected from the physical network and added to the target node list, so as to ensure that the node resource state of the target node list satisfies the deployment condition of the network security service function chain to be deployed.

[0095] In order to better understand the above method, the following detailed application embodiment of a network security service function chain orchestration method of the data processing unit of the present application is described.

[0096] The cloud-edge-end network architecture is a system architecture combining cloud servers, edge devices and terminal devices. Compared with traditional cloud computing systems, it has advantages in privacy protection, bandwidth pressure, business latency, resource utilization, etc., and has been increasingly applied in smart cities, industrial control, smart grids and other fields. The cloud-edge-end architecture has brought great changes to the network and information system, and its security protection also faces new challenges. The types of services carried in the cloud-edge-end architecture network tend to be diversified and intelligent, cross-subject interactions become more frequent, the degree of infrastructure opening to the outside world continues to improve, and the number of intelligent terminals accessing the network has surged, making the complexity and dynamics of the network system increase, and the security boundary of the network gradually blurred. On the one hand, traditional network security services based on border protection are mostly carried in dedicated hardware devices, such as firewalls, one-way isolation, intrusion detection, etc. These dedicated hardware devices have high processing efficiency, but the security functions are coupled with specific hardware platforms, which may come from multiple different manufacturers, resulting in high maintenance costs, low compatibility, poor flexibility, low scalability, and difficulty in responding to sudden situations, dynamically changing network topology and rapidly changing business security needs. Special security devices also do not support end-to-end security orchestration capabilities by nature, and if middleware is not introduced, they cannot provide differentiated security protection for businesses in different network environments. On the other hand, network security service chains based on virtualization technology can be flexibly deployed according to the needs of service tenants, solving compatibility, flexibility, scalability and other problems, but still face two problems: first, due to the gradual failure of Moore's Law, the performance improvement of general-purpose central processors cannot keep up with the increasing speed of data center traffic, making it difficult to match low-latency line-speed security processing needs. Second, edge devices have limited computing resources, and providing both business computing services and security processing services will easily lead to resource competition and affect business stability. The above two technical routes are difficult to meet the efficient, flexible and variable network security service needs under the cloud-edge-end architecture network, so there is an urgent need for a network security service providing method that has both the efficient processing characteristics of dedicated security hardware devices and the flexible and scalable characteristics of virtualized network security services.

[0097] The traditional network security service function chain orchestration method based on virtualization technology either ignores the limitations of the data processing unit itself resources, and all hardware acceleration modules of all security processing functions of a request are deployed in a data processing unit embedded in an edge device, which may encounter insufficient programmable hardware resources. Or the virtual security function chain constructed must run in a virtualization platform, which requires high central processing unit and memory resources and is difficult to implement on a resource-limited edge device. Or the service function chain orchestration and deployment method only optimizes the resource utilization rate, deployment success rate, bandwidth consumption, etc. of the deployment scheme, and does not consider improving the utilization rate of the acceleration subunit (which can be referred to as a hardware acceleration subunit) in the deployable data processing unit, resulting in waste of acceleration subunit resources and power consumption.

[0098] In order to overcome the defects of the above-mentioned traditional technology, the embodiment proposes a network security service function chain orchestration method of a data processing unit, which aims to utilize the soft and hard collaboration and programmable characteristics of the data processing unit as a deployment platform for the service function chain, ensuring the flexibility of network security service provision while ensuring the efficiency of network security service processing. At the same time, for the service function chain deployment problem of the data processing unit, a function chain deployment optimization objective function is designed, an optimization deployment strategy solving algorithm based on genetic algorithm is proposed, and an initial population generation algorithm of the genetic algorithm under this problem is proposed to quickly solve the optimization deployment strategy. The specific technical scheme includes the following steps:

[0099] I. Network security service function chain architecture of data processing unit

[0100] The network security service function chain architecture taking the data processing unit (DPU) as the running carrier is shown in Figure 2 .

[0101] Taking a cloud-edge-end network scenario as an example, the data processing unit is embedded in an edge gateway, a switch and a server in the physical network, and can provide network security processing for business traffic passing through its location. The embedded data processing unit should contain central processing unit (CPU) resources and field-programmable gate array (FPGA) resources, and support remote programming of hardware acceleration subunits. The deployed data processing unit security function has soft and hard collaboration characteristics, including software logic and hardware logic.

[0102] When service traffic from a terminal arrives at an edge gateway, the edge gateway identifies the type to which the service traffic belongs, and generates a to-be-deployed network security service function chain for the service traffic according to a network security requirement of the type to which the service traffic belongs and a security service function of a programmable data processing unit.

[0103] According to the to-be-deployed network security service function chain for the service traffic, a security service request can be generated.

[0104] According to the security service request, a network security service function chain orchestration scheme can be determined, and then according to the network security service function chain orchestration scheme, a security service function on the network security service function chain is mapped to a specific data processing unit in a physical network, data processing unit security function software logic is deployed and a hardware acceleration module is burned, a soft-hard collaborative data processing unit security function instance is started, and finally the service traffic is guided to pass through the deployed function instance in sequence to complete security service processing and finally arrive at a destination of the service traffic.

[0105] In this embodiment, on the basis of the following mathematical modeling of the function chain deployment optimization problem of the data processing unit, a function chain deployment optimization objective function of the data processing unit is designed. The objective function comprehensively considers the balance of resource consumption of all data processing unit devices in the physical network and the utilization rate of the hardware acceleration subunit, can make the resource consumption more balanced among the data processing units, prevent a small number of data processing units from being quickly exhausted, and at the same time improve the utilization rate of each deployed hardware acceleration subunit, and reduce the waste of resources and power consumption.

[0106] (1) Network and service function model:

[0107] The physical network can be represented by an undirected graph , where V represents a device node, and L represents a physical link. The data processing unit node v contains three attributes, which are the total amount of central processor resources , the total amount of memory resources , and the total amount of field programmable gate array resources . The physical link between node u and node v is represented by Luv, the maximum data transmission bandwidth of which is defined as , and the link delay at the deployment completion time t is defined as .

[0108] The N kinds of security service functions available for orchestration in the network are defined as a set . The field programmable gate array resource occupation of the hardware acceleration subunit of the nth security service function is , and the processing capacity of the hardware acceleration subunit is At the deployment completion time t, the hardware acceleration sub-units deployed in the network are defined as where the m-th hardware acceleration sub-unit corresponds to the security service function category .

[0109] The s-th dynamically arrived security service request in the network is represented by a 12-tuple as shown in equation (1).

[0110] (1)

[0111] where, denotes the source node of the s-th security service request, denotes the destination node of the s-th security service request, , denotes the ordered security service functions of the s-th security service request, denotes the category of the i-th security function. denotes the central processing unit resource requirement of each security service function on the network security service function chain to be deployed, and the memory resource requirement is represented as , denotes the field programmable gate array resource requirement of each security service function on the network security service function chain to be deployed, denotes the hardware acceleration processing capability occupation, denotes the processing delay of the security service function. denotes the arrival time of the s-th arrived security service request, denotes the link bandwidth requirement of the security service request, denotes the highest delay threshold that the security service request can tolerate, denotes the life cycle of the network security service function chain of the security service request in the network.

[0112] (2) Service function deployment model:

[0113] The mapping between the security service function, hardware acceleration sub-unit and data processing unit node and the mapping between the virtual link and physical link are defined as binary variables: , , and .

[0114] where, denotes that when the security service function in the s-th security service request is mapped to node v at the deployment completion time t, ; otherwise .

[0115] denotes that the security service function in the s-th security service request is mapped to the hardware acceleration sub-unit at the deployment completion moment t , ; otherwise .

[0116] denotes that the hardware acceleration sub-unit is mapped to the node v at the deployment completion moment t ; otherwise .

[0117] denotes that the virtual link in the s-th security service request is mapped to the physical link at the deployment completion moment t ; otherwise .

[0118] (3) Resource consumption rate and hardware acceleration module usage rate model:

[0119] The load degree (resource usage rate) of each deployed node can be obtained according to the central processing unit resource load degree, the memory resource load degree, and the field programmable gate array resource load degree of each deployed node, and the weight coefficients of the central processing unit resource, the memory resource, and the field programmable gate array resource.

[0120] The average load degree of the deployed nodes at the deployment completion moment can be obtained according to the ratio between the load degree of each deployed node and the number of deployed nodes.

[0121] The usage rate of each deployed physical link at the deployment completion moment can be obtained according to the link bandwidth demand corresponding to each security service function in the security service request, the maximum data transmission bandwidth of each physical link, and the security service function corresponding to the mapping of each deployed physical link.

[0122] The average usage rate of the deployed physical links at the deployment completion moment can be obtained according to the ratio between the usage rate of each deployed physical link and the number of deployed physical links.

[0123] The multi-class resource load degree for arranging the to-be-deployed network security service function chain in the security service request at the deployment completion moment can be obtained according to the average load degree of the deployed nodes and the average usage rate of the deployed physical links at the deployment completion moment, and the weight coefficients of the deployed node load and the deployed physical link load.

[0124] In addition, the usage rate of the hardware acceleration sub-module m at the deployment completion moment t is shown as formula (10).

[0125] (10)

[0126] wherein, denotes the usage rate of the hardware acceleration sub-module m at the deployment completion time t; denotes a security service request; denotes an ordered security service function of the s-th security service request; denotes that the security service function of the s-th security service request is mapped to the hardware acceleration sub-unit at the deployment completion time t, ; otherwise ; denotes the hardware acceleration processing capacity occupation; denotes the processing capacity of the hardware acceleration sub-unit; denotes the security service function type corresponding to the m-th hardware acceleration sub-unit.

[0127] The average usage rate of all hardware acceleration sub-modules at the deployment completion time t is shown in equation (11).

[0128] (11)

[0129] wherein, denotes the average usage rate of all hardware acceleration sub-modules at the deployment completion time t, and denotes denotes the usage rate of the hardware acceleration sub-module m at the deployment completion time t, denotes the number of hardware acceleration sub-modules.

[0130] (4) Constraint condition:

[0131] In order to ensure the quality of security services and reliable link transmission, it is necessary to ensure that the data processing unit node has sufficient resources to run security service functions, and the link has sufficient bandwidth to transmit traffic. The following constraint conditions are proposed: the consumption of multi-type resources is lower than the total amount of each resource, the number of incoming and outgoing traffic of the deployed node is equal, the processing capacity occupied by the acceleration sub-unit does not exceed the processing capacity it possesses, and the delay time of the completed security service function chain is less than the delay threshold.

[0132] Wherein, the multi-type resource requirement corresponding to each security service function can include operation resource requirement, storage resource requirement and transmission resource requirement. The operation resource requirement can include central processing unit resource requirement and field programmable gate array resource requirement, the storage resource requirement can include memory resource requirement, and the transmission resource requirement can include link bandwidth requirement. The constraint conditions are specifically shown in equations (12)-(18).

[0133] (12)

[0134] (13)

[0135] (14)

[0136] (15)

[0137] (16)

[0138] (17)

[0139] (18)

[0140] wherein, constraint represents that the central processing unit resource consumption of a node must be lower than the total amount of corresponding central processing unit resources possessed by the node , represents that the memory resource consumption of a node must be lower than the total amount of corresponding memory resources possessed by the node , represents that the field programmable gate array resource consumption of a node must be lower than the total amount of corresponding field programmable gate array resources possessed by the node . Constraint represents that the consumption of link bandwidth must be lower than the maximum link bandwidth possessed by the link. In terms of flow conservation constraints, constraint represents that the amount of incoming flow and outgoing flow of each node is equal, unless the node is the start node or the destination node of the service function chain. In terms of processing capacity occupation of hardware acceleration sub-units, constraint represents that the occupied processing capacity of each acceleration sub-unit cannot exceed the processing capacity possessed by the acceleration sub-unit. Constraint represents the delay time of the completed deployed security service function chain is less than the delay threshold , so as to guarantee the quality of service.

[0141] When the above constraint conditions cannot be met, the security service function chain deployment will be rejected, and the corresponding security service cannot be provided.

[0142] (5) Function chain deployment optimization objective function:

[0143] In summary, the embodiment provides the function chain deployment optimization objective function shown in formula (3):

[0144]

[0145] (3)

[0146] wherein s represents a to-be-deployed security service function chain, and t represents a deployment completion time instant at which the deployment of the security service function chain is completed, denotes a function chain deployment optimization objective function, denotes a deployment completion time instant a multi-class resource load degree of a to-be-deployed network security service function chain in a security service request, denotes a deployment completion time instant an average usage rate of an acceleration subunit in a data processing unit, denotes a weight of a multi-class resource load degree, denotes a weight of an acceleration subunit average usage rate, which is set by a user according to a demand of the user.

[0147] The function chain deployment optimization objective function comprehensively considers the balance of device resource consumption of all data processing units in the network and the usage rate of the hardware acceleration subunit, can make the resource consumption more balanced among the data processing units, prevent a few data processing units from being quickly exhausted in resources, and at the same time improve the usage rate of each deployed hardware acceleration subunit, and reduce the waste of resources and power consumption.

[0148] III. Solution of the optimization deployment problem based on a genetic algorithm:

[0149] Secondly, the embodiment provides an optimization deployment problem solving algorithm based on a genetic algorithm, which is used to obtain a network security service function chain target arrangement scheme of a data processing unit. Specifically, the algorithm is improved in population initialization.

[0150] In the algorithm, the deployed data processing units and the nodes that are not deployed are regarded as ordinary network nodes, and the difference between them mainly lies in the amount of available resources. A potential arrangement scheme of a service function chain (which can be called a possible deployment scheme) is regarded as an individual, denoted as wherein denotes a population size. In each individual, an integer array is used to represent the correspondence between the deployed nodes and the network functions on the chain. The length of each array is the number of service functions on the service chain. For , the subscript denotes the identifier of the to-be-deployed network function. The array value represents the index of the network node that deploys this network function.

[0151] After obtaining the initial population, when iterating the initial population, the fitness function value of each individual in the initial population is obtained according to the function chain deployment optimization objective function value of each individual in the initial population, as shown in equation (8).

[0152] (8)

[0153] wherein, represents the fitness function value of the individual , represents the function chain deployment optimization objective function value. When the F(s, t) value of the individual is lower, the individual is better, and the fitness value should be the highest.

[0154] The high-quality individual set of the current iteration can be selected from the initial population according to the fitness function value of each individual in the initial population. Specifically, the roulette mechanism can be used, and the probability of selection of the individual is shown in equation (9).

[0155] (9)

[0156] wherein, represents the probability of selection of the individual , represents the population size. This indicates that the individual with a higher fitness value has a smaller chance of being eliminated, but other individuals still have a chance.

[0157] The crossover operation and the mutation operation can be performed on the high-quality individual set of the current iteration to obtain the new population of the current iteration. Specifically, after selecting the high-quality individual of the current iteration, the crossover operation and the mutation operation are performed to generate the new individual of the current iteration. The crossover operation can use the uniform crossover operation, which can ensure that the generated new individual of the current iteration is feasible.

[0158] It is determined whether the maximum iteration number is reached. If the maximum iteration number is reached, the best individual in the new population of the current iteration is output as the network security service function chain target arrangement scheme that makes the function chain deployment optimization objective function reach the preset optimization condition, and if the maximum iteration number is not reached, the next round of iteration is performed on the new population of the current iteration. The maximum iteration number

[0159] can be set according to actual conditions. The complete process of the optimization deployment problem solving algorithm (algorithm 1) based on the genetic algorithm is shown in Table 1, which takes the service function chain to be deployed and the network resource state as input and tries to find the optimal solution of deployment. First, set the required parameters (row 1); then initialize the population by the initial population generation algorithm based on the greedy strategy (row 2). Each individual can be evaluated according to the fitness function. In each iteration, the crossover operation and the mutation operation are performed with a random probability to generate the new individual of the current iteration (rows 4-18). To ensure that a local optimal solution can be found, is usually greater than If the iteration process is terminated, the optimal individual in the newly generated population in this iteration is output as the network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization condition, and if the maximum number of iterations is not reached the next iteration of the newly generated population in this iteration is performed. The maximum number of iterations may be set according to actual conditions.

[0160] Table 1

[0161]

[0162] Four, initial population generation algorithm based on greedy strategy:

[0163] To further improve the possibility of obtaining the optimal solution of the optimization deployment problem solving algorithm based on the genetic algorithm, the embodiment provides a population initialization algorithm based on the greedy strategy. The initial population can be obtained based on the initial population generation algorithm based on the greedy strategy. One network function in the to-be-deployed network security service function chain that has not been deployed can be selected and deployed to a node in the target node list that has deployed the corresponding hardware acceleration subunit. The target node list includes nodes allowed to be used by the to-be-deployed network security service function chain, and can record all nodes used by the to-be-deployed network security service function chain.

[0164] Specifically, if contains multiple nodes that have deployed the corresponding hardware acceleration subunit, the node that has deployed the corresponding hardware acceleration subunit is selected as the deployed node corresponding to each network security service function in the to-be-deployed network security service function chain from the target node list according to the principle of selecting the node with the least resource consumption to deploy the network security function, and the link capacity is checked to ensure the feasibility of the selected node, thereby obtaining a potential orchestration scheme of the to-be-deployed network security service function chain that satisfies the constraint condition.

[0165] The above process can be performed pSize times to obtain pSize potential orchestration schemes of the to-be-deployed network security service function chain that satisfy the constraint condition, and each potential orchestration scheme is regarded as a single individual to obtain the initial population.

[0166] If there is no feasible node in the target node list , i.e., the node resource state of the target node list does not satisfy the deployment condition of the to-be-deployed network security service function chain, a node with a resource state satisfying the preset resource condition can be selected from the physical network and added to the target node list . The preset resource condition can be set according to actual conditions.

[0167] The main steps of the initial population generation algorithm based on the greedy algorithm (algorithm 2) are shown in Table 2. Compared with the random method, the initial population generation algorithm based on the greedy algorithm can generate an initial population with higher fitness, thereby further improving the convergence efficiency of the deployment solution algorithm.

[0168] Table 2

[0169]

[0170] The network security service function chain arrangement method of the data processing unit provided in the embodiment is applicable to a software defined network, and can be deployed on a data processing unit node containing heterogeneous computing resources (CPU, FPGA) in the network to provide the target business traffic with flexible deployment and high processing speed of network security services. In the embodiment, the server and the data processing unit are verified in a cluster composed of 3 servers, 1 software defined network (Software-Defined Networking, SDN) switch and 3 data processing unit nodes, and the software defined network switch is taken as the center to form a star type topology. The specific implementation process is shown in Figure 4

[0171] ​Firstly, when the target traffic enters the forwarding plane of the network from the traffic source end, the software-defined network switch determines whether the target traffic has been provided with the corresponding security service by the system according to whether the message header of the target traffic contains a security service chain identifier. If there is a security service chain identifier, the target traffic is forwarded to the next destination according to the forwarding flow table strategy configured by the software-defined network switch; if there is no security service chain identifier, the target traffic is forwarded to the traffic service classifier. Then, the traffic service classifier determines the service type of the target traffic according to the pre-configured rules by containing the source Internet Protocol (IP) address, the destination IP address, the source port, the destination port and the protocol number, and generates a corresponding security service request, which is sent to the service chain composer for subsequent processing. Next, the service chain composer obtains a list of security services required and available for the security service request from the security service manager according to the received security service request and the service type, and then collects the information of the security service function, the data processing unit resource and the network resource of the current network from the resource manager, generates a network security service function chain target arrangement scheme for the target traffic by using the network security service function chain arrangement method of the data processing unit provided in the embodiment, including the security service chain, the security service chain identifier, the security service deployment location mapping scheme and the network forwarding configuration information. Then, the service chain composer controls the data processing unit in the corresponding physical location to start the corresponding network security service function through the Network Functions Virtualization (NFV) controller according to the security service deployment mapping scheme; the network forwarding configuration information is sent to the forwarding plane through the network controller to issue the flow table information; after completion, the security service function chain identifier is sent to the traffic service classifier, and the traffic service classifier writes the security service chain identifier into the message header of the target traffic. Next, the traffic service classifier sends the target traffic with the security service chain identifier back to the forwarding plane, and the software-defined network switch forwards the target traffic to the corresponding security service function in the service chain in sequence, and completes the security processing. Finally, the target traffic that has completed all security processing is sent back to the forwarding plane, and the forwarding plane forwards the traffic to the destination of the target traffic.

[0172] The network security service function chain arrangement method of the data processing unit provided in the embodiment has the following beneficial effects:

[0173] (1) High flexibility and high efficiency of network security service processing: the network security service is provided in the form of a service function chain, and the data processing unit is used as the running carrier of each security service function, and the soft and hard cooperation and the field programmable gate array remote configuration are used to realize the flexible deployment of the network security service function with high processing efficiency.

[0174] (2) The function chain deployment optimization objective function construction: According to the characteristics of the scene, a function chain deployment optimization objective function is designed, which comprehensively considers the balance of resource consumption of all data processing unit devices in the network and the utilization rate of hardware acceleration subunits. The function chain deployment optimization objective function can make the resource consumption more balanced among data processing units, prevent a small number of data processing units from being quickly exhausted, and at the same time, improve the utilization rate of each deployed hardware acceleration subunit, and reduce the waste of resources and power consumption.

[0175] (3) The optimization deployment strategy solving algorithm based on the genetic algorithm: The algorithm has stronger adaptability, universality and search efficiency. Compared with the exact algorithm and the general linear optimization solver, the algorithm can find the approximate optimal solution in a faster time under a larger problem size, and is suitable for larger scale network environment.

[0176] (4) The initial population generation algorithm based on the greedy strategy: In the initial population generation process of the genetic algorithm, the greedy strategy is to try to use the deployed hardware acceleration subunits as much as possible to generate the initial population of the deployment strategy solution, which can improve the possibility of obtaining the optimal solution, improve the convergence efficiency of the genetic algorithm, and speed up the calculation speed of the optimization deployment strategy solution.

[0177] It should be understood that, although each step in the flowchart involved in each embodiment as described above is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other orders. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps. It can be understood that the steps in different embodiments can be freely combined as needed, and various non-contradictory schemes formed by the combination are within the scope of protection of the present application.

[0178] Based on the same inventive concept, the embodiments of the present application also provide a network security service function chain orchestration apparatus of a data processing unit for implementing the network security service function chain orchestration method of the data processing unit as described above. The implementation scheme for solving the problem provided by the apparatus is similar to the implementation scheme described in the above method, so the specific limitations in one or more data processing unit network security service function chain orchestration apparatus embodiments provided below can be referred to the limitations of the data processing unit network security service function chain orchestration method described above, which will not be repeated here.

[0179] In one example embodiment, as shown in Figure 5 a network security service function chain arrangement apparatus of a data processing unit is provided, wherein:

[0180] The security service request obtaining module 501 is configured to obtain a security service request of a to-be-deployed network security service function chain of the target service traffic according to network security requirements of a type to which the target service traffic belongs and security service functions of the data processing unit.

[0181] The multi-type resource load degree obtaining module 502 is configured to obtain an average load degree of a deployed node and an average usage rate of a deployed physical link at a deployment completion time according to multi-type resource requirements corresponding to each security service function in the security service request, so as to obtain a multi-type resource load degree of the to-be-deployed network security service function chain in the security service request at the deployment completion time.

[0182] The objective function obtaining module 503 is configured to obtain a function chain deployment optimization objective function according to the multi-type resource load degree of the to-be-deployed network security service function chain in the security service request at the deployment completion time and an average usage rate of an acceleration subunit in the data processing unit at the deployment completion time.

[0183] The target arrangement scheme obtaining module 504 is configured to obtain a network security service function chain target arrangement scheme that makes the function chain deployment optimization objective function reach a preset optimization condition according to the to-be-deployed network security service function chain under constraint conditions that a consumption amount of multi-type resources is lower than a total amount of each resource, an amount of traffic entering and flowing out of a deployed node is equal, processing capacity occupied by an acceleration subunit does not exceed processing capacity possessed by itself, and a delay time of a completed security service function chain is less than a delay threshold.

[0184] In one example embodiment, the multi-type resource load degree obtaining module 502 is further configured to obtain an average load degree of a deployed node at a deployment completion time according to central processing unit resource requirements, memory resource requirements, and field programmable gate array resource requirements corresponding to each security service function in the security service request, and obtain an average usage rate of a deployed physical link at the deployment completion time according to link bandwidth requirements of each security service function in the security service request and a maximum data transmission bandwidth of each physical link.

[0185] In one of the embodiments, the multi-type resource load degree obtaining module 502 is further configured to: obtain, according to the central processing unit resource requirement, the memory resource requirement and the field programmable gate array resource requirement of each security service function in the security service request, the central processing unit resource consumption, the memory resource consumption and the field programmable gate array resource consumption of each deployed node at the deployment completion moment; obtain, according to the central processing unit resource consumption, the memory resource consumption and the field programmable gate array resource consumption of each deployed node at the deployment completion moment and the total amount of central processing unit resource, the total amount of memory resource and the total amount of field programmable gate array resource of each deployed node, the central processing unit resource load degree, the memory resource load degree and the field programmable gate array resource load degree of each deployed node; obtain, according to the central processing unit resource load degree, the memory resource load degree and the field programmable gate array resource load degree of each deployed node and the weight coefficients of the central processing unit resource, the memory resource and the field programmable gate array resource respectively, the load degree of each deployed node; and obtain, according to the load degree of each deployed node and the number of deployed nodes, the average load degree of the deployed nodes at the deployment completion moment.

[0186] In one of the embodiments, the target arrangement scheme obtaining module 504 is further configured to: obtain an initial population; each individual in the initial population is a potential arrangement scheme of the security service function chain to be deployed that satisfies the constraint condition; when the initial population is iterated, obtain the fitness function value of each individual in the initial population according to the function chain deployment optimization objective function value of each individual in the initial population; select, from the initial population, a high-quality individual set of the current iteration according to the fitness function value of each individual in the initial population; perform a crossover operation and a mutation operation on the high-quality individual set of the current iteration to obtain a newly-born population of the current iteration; and determine whether the maximum number of iterations is reached, if yes, output the best individual in the newly-born population of the current iteration as the target arrangement scheme of the security service function chain that makes the function chain deployment optimization objective function reach the preset optimization condition, and if not, perform the next round of iteration on the newly-born population of the current iteration.

[0187] In one of the embodiments, the target arrangement scheme obtaining module 504 is further configured to: select, according to the principle of deploying the security function on the node with the least resource consumption, the deployed node corresponding to each security service function in the security service function chain to be deployed from a target node list to obtain a potential arrangement scheme of the security service function chain to be deployed that satisfies the constraint condition; the target node list includes the nodes allowed to be used by the security service function chain to be deployed; and regard each potential arrangement scheme as a single individual to obtain an initial population.

[0188] In one of the embodiments, the target orchestration scheme acquisition module 504 is further configured to: if the node resource state of the target node list does not satisfy the deployment condition of the to-be-deployed network security service function chain, select a node with a resource state satisfying a preset resource condition from the physical network and add the node to the target node list.

[0189] The modules in the network security service function chain orchestration apparatus of the data processing unit can be implemented by software, hardware or a combination thereof. The modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a memory in the computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to the modules.

[0190] In one of the embodiments, a computer device is provided, which can be a server. An internal structure diagram of the computer device can be as shown in FIG. 8. Figure 6 The computer device includes a processor, a memory, an input / output interface and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The database of the computer device is configured to store data of the embodiments of the network security service function chain orchestration method of the data processing unit. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to communicate with external terminals through a network connection. The computer program is executed by the processor to implement the network security service function chain orchestration method of the data processing unit.

[0191] Those skilled in the art can understand that Figure 6 The structure shown in FIG. 8 is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. Specifically, the computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0192] In one of the embodiments, a computer device is provided, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps in the above-mentioned method embodiments.

[0193] In an embodiment, a computer readable storage medium is provided, having stored thereon a computer program which, when executed by a processor, implements the steps of any of the method embodiments described above.

[0194] In an embodiment, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the steps of any of the method embodiments described above.

[0195] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.

[0196] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.

[0197] The technical features of the above embodiments can be combined in any manner. To make the description concise, all possible combinations of the technical features in the above embodiments are not described, but as long as the combinations of the technical features do not exist, they should be considered as the scope of the present application.

[0198] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.

Claims

1. A method for orchestrating a network security service function chain in a data processing unit, characterized in that, The method includes: Based on the network security requirements of the target business traffic type and the security service functions of the data processing unit, the security service request of the network security service function chain to be deployed for the target business traffic is obtained. Based on the multiple resource requirements corresponding to each security service function in the security service request, the average load level of the deployed node and the average utilization rate of the deployed physical link at the time of deployment completion are obtained, so as to obtain the multiple resource load levels for orchestrating the chain of network security service functions to be deployed in the security service request at the time of deployment completion. Based on the multi-resource load levels of the network security service function chain to be deployed in the security service request at the time of deployment completion, and the average utilization rate of the acceleration sub-unit in the data processing unit at the time of deployment completion, the objective function for function chain deployment optimization is obtained. Under the constraints that the consumption of multiple types of resources is lower than their respective total resources, the amount of traffic entering and leaving the deployed nodes is equal, the processing capacity occupied by the acceleration subunit does not exceed its own processing capacity, and the latency of the completed security service function chain is less than the latency threshold, a network security service function chain objective orchestration scheme is obtained based on the network security service function chain to be deployed, which makes the objective function of the function chain deployment optimization reach the preset optimization conditions.

2. The method according to claim 1, characterized in that, The step of obtaining the average load level of the deployed nodes and the average utilization rate of the deployed physical links at the time of deployment completion based on the multiple resource requirements corresponding to each security service function in the security service request includes: Based on the CPU resource requirements, memory resource requirements, and field-programmable gate array resource requirements corresponding to each security service function in the security service request, the average load level of the deployed node at the time of deployment completion is obtained. Based on the link bandwidth requirement corresponding to each security service function in the security service request and the maximum data transmission bandwidth of each physical link, the average utilization rate of the deployed physical links at the time of deployment completion is obtained.

3. The method according to claim 2, characterized in that, The step of obtaining the average load level of the deployed node at the time of deployment completion based on the CPU resource requirements, memory resource requirements, and FPGA resource requirements corresponding to each security service function in the security service request includes: Based on the CPU resource requirements, memory resource requirements, and FPGA resource requirements corresponding to each security service function in the security service request, the CPU resource consumption, memory resource consumption, and FPGA resource consumption of each deployed node at the deployment completion time are obtained. Based on the CPU resource consumption, memory resource consumption, and FPGA resource consumption of each deployed node at the time of deployment completion, as well as the total CPU resource, total memory resource, and total FPGA resource of each deployed node, the CPU resource load, memory resource load, and FPGA resource load of each deployed node are obtained. The load level of each deployed node is obtained based on the CPU resource load level, memory resource load level, and field-programmable gate array resource load level of each deployed node, as well as the respective weight coefficients of CPU resources, memory resources, and field-programmable gate array resources. Based on the load level of each deployed node and the number of deployed nodes, the average load level of the deployed nodes at the time of deployment completion is obtained.

4. The method according to claim 1, characterized in that, Under the constraints of the following conditions—that the consumption of multiple types of resources is lower than their respective total resources, the amount of traffic entering and leaving the deployed nodes is equal, the processing capacity occupied by the acceleration subunit does not exceed its own processing capacity, and the latency of the completed security service function chain is less than the latency threshold—a network security service function chain objective orchestration scheme is obtained based on the network security service function chain to be deployed, which makes the objective function of the function chain deployment optimization meet the preset optimization conditions. This scheme includes: Obtain an initial population; each individual in the initial population is a potential orchestration scheme that satisfies the constraints of the network security service function chain to be deployed. When iterating over the initial population, the fitness function value of each individual in the initial population is obtained by optimizing the objective function value based on the functional chain deployment of each individual in the initial population. Based on the fitness function value of each individual in the initial population, a set of high-quality individuals for this iteration is selected from the initial population. Perform crossover and mutation operations on the set of high-quality individuals in this iteration to obtain the new population in this iteration; Determine whether the maximum number of iterations has been reached. If it has, output the best individual in the new population of this iteration as the network security service function chain objective orchestration scheme that enables the function chain deployment optimization objective function to reach the preset optimization conditions. If it has not been reached, proceed to the next round of iteration for the new population of this iteration.

5. The method according to claim 4, characterized in that, The process of obtaining the initial population includes: Following the principle of selecting the node with the least resource consumption to deploy network security functions, the deployment node corresponding to each network security service function in the chain of network security service functions to be deployed is selected from the target node list, resulting in a potential orchestration scheme that satisfies the constraints of the chain of network security service functions to be deployed; the target node list includes nodes that are allowed to be used by the chain of network security service functions to be deployed. Each potential arrangement is treated as a single individual, resulting in an initial population.

6. The method according to claim 5, characterized in that, The method further includes: If the resource status of the nodes in the target node list does not meet the deployment conditions of the network security service function chain to be deployed, then nodes whose resource status meets the preset resource conditions are selected from the physical network and added to the target node list.

7. A network security service function chain orchestration device for a data processing unit, characterized in that, The device includes: The security service request acquisition module is used to obtain the security service request of the network security service function chain to be deployed for the target business traffic based on the network security requirements of the target business traffic type and the security service functions of the data processing unit. The multi-resource load level acquisition module is used to obtain the average load level of the deployed node and the average utilization rate of the deployed physical link at the time of deployment completion based on the multi-resource requirements corresponding to each security service function in the security service request, so as to obtain the multi-resource load level of the network security service function chain to be deployed in the security service request at the time of deployment completion. The objective function acquisition module is used to obtain the objective function for optimizing the deployment of the function chain based on the multi-resource load levels of the network security service function chain to be deployed in the security service request at the time of deployment completion, and the average utilization rate of the acceleration sub-unit in the data processing unit at the time of deployment completion. The target orchestration scheme acquisition module is used to obtain a network security service function chain target orchestration scheme that makes the function chain deployment optimization objective function reach the preset optimization conditions, under the constraints that the consumption of multiple types of resources is lower than their respective total resources, the amount of traffic entering and leaving the deployed nodes is equal, the processing capacity occupied by the acceleration subunit does not exceed its own processing capacity, and the latency of the completed deployment security service function chain is less than the latency threshold.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.