Secure cloud platform deployment method, system, device and equipment and storage medium
By constructing a hot-standby redundant virtual machine set and deploying it to a server set, the problem of the inability to deploy rail transit signaling systems in the cloud was solved, realizing the sharing of computing resources and the reduction of hardware costs, and improving resource utilization and scalability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-27
- Publication Date
- 2026-03-31
AI Technical Summary
The safety systems of existing rail transit signaling systems cannot be truly deployed in the cloud, and computing resources cannot be shared, resulting in high hardware procurement costs.
Construct a hot standby redundant virtual machine set, including at least two virtual machine groups. The virtual machine groups implement hot standby redundancy functions. Each virtual machine group includes a first virtual machine, a second virtual machine, and a third virtual machine. The first and second virtual machines are used for 2-out-of-2 secure operations, and the third virtual machine is used for communication functions. Deploy them to a server set to achieve multi-station sharing.
While ensuring that the security level is not reduced, it has achieved a leap from dedicated hardware to general cloud computing, reducing hardware procurement costs, improving resource utilization, and simplifying the cabling and expansion process.
Smart Images

Figure CN121764590A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of rail transit technology, and in particular to a method, system, device, equipment and storage medium for deploying a secure cloud platform. Background Technology
[0002] Traditionally, rail transit signaling systems employ embedded dedicated hardware to implement their safety architecture. However, this approach requires the independent deployment of dedicated hardware for each system, preventing the sharing of computing resources. While non-safety systems have gradually migrated to the cloud with the development of cloud computing technology, truly cloud-based deployment has not yet been achieved for the highest level of safety integrity systems, which must meet safety standards such as EN50716 / 50129. Summary of the Invention
[0003] This invention provides a secure cloud platform deployment method, system, device, equipment, and storage medium to address the deficiencies in the prior art.
[0004] This invention provides a method for deploying a secure cloud platform, comprising: Obtain the security computing deployment requirements of each station; Based on the aforementioned security operation deployment requirements, a set of hot standby redundant virtual machines corresponding to each of the stations is constructed; wherein, the set of hot standby redundant virtual machines includes at least two groups of virtual machines, and the virtual machines implement hot standby redundancy functions among the virtual machine groups. Each group of virtual machines includes a first virtual machine, a second virtual machine, and a third virtual machine. The first virtual machine and the second virtual machine are used to implement 2-out-of-2 secure operations, and the third virtual machine is used to implement communication functions. Deploy each of the aforementioned hot standby redundant virtual machine sets to the server set.
[0005] According to a secure cloud platform deployment method provided by the present invention, the server set includes at least two server groups, each server group corresponding to a virtual machine group, and each server group includes a first server and a second server. The step of deploying each of the hot standby redundant virtual machine sets to the server set includes: The first virtual machine and the third virtual machine in each virtual machine group are deployed on the first server of the corresponding server group; Deploy the second virtual machine in each virtual machine group on the second server of the corresponding server group; The virtual machines are connected to each other via Ethernet.
[0006] According to a secure cloud platform deployment method provided by the present invention, the step of constructing a set of hot standby redundant virtual machines corresponding to each of the stations based on the secure computing deployment requirements includes: Based on the aforementioned security computing deployment requirements, computing resources are allocated to each of the stations from a general server resource pool, and the hot standby redundant virtual machine set is constructed based on the computing resources; wherein, the computing resources include vCPU, memory, storage, and network.
[0007] According to a secure cloud platform deployment method provided by the present invention, after deploying each of the hot-standby redundant virtual machine sets to the server set, the method further includes: Obtain the service load of each of the aforementioned stations; Based on the aforementioned workload, the computing resources allocated to each virtual machine are dynamically adjusted.
[0008] According to a secure cloud platform deployment method provided by the present invention, after deploying each of the hot-standby redundant virtual machine sets to the server set, the method further includes: If a server failure is detected in the server set, the virtual machine group deployed on the failed server will be migrated to a normal server.
[0009] According to a secure cloud platform deployment method provided by the present invention, after deploying each of the hot-standby redundant virtual machine sets to the server set, the method further includes: If a station to be deployed is detected, the corresponding hot standby redundant virtual machine set is deployed for the station in the server set using the clone virtual machine image function.
[0010] The present invention also provides a secure cloud platform system, comprising: A set of servers, wherein a set of hot-standby redundant virtual machines is deployed in the set of servers based on any of the above-described secure cloud platform deployment methods.
[0011] The present invention also provides a secure cloud platform deployment device, characterized in that it comprises: The first acquisition module is configured to acquire the security computing deployment requirements of each station; The construction module is configured to construct a set of hot standby redundant virtual machines corresponding to each station based on the security operation deployment requirements; wherein, the set of hot standby redundant virtual machines includes at least two groups of virtual machines, and the virtual machines implement hot standby redundancy functions between the virtual machine groups. Each group of virtual machines includes a first virtual machine, a second virtual machine, and a third virtual machine. The first virtual machine and the second virtual machine are used to implement 2-out-of-2 security operations, and the third virtual machine is used to implement communication functions. The first deployment module is configured to deploy each of the hot standby redundant virtual machine sets to the server set.
[0012] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the secure cloud platform deployment method described above.
[0013] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the secure cloud platform deployment method as described above.
[0014] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the secure cloud platform deployment method as described above.
[0015] This invention provides a secure cloud platform deployment method, system, device, equipment, and storage medium. Based on the secure computing deployment requirements of each station, it constructs a set of hot-standby redundant virtual machines corresponding to each station. Each set includes at least two virtual machine groups, which implement hot-standby redundancy. Each virtual machine group includes a first virtual machine, a second virtual machine, and a third virtual machine. The first and second virtual machines are used to implement a 2-out-of-2 secure computation, while the third virtual machine is used for communication. The constructed set of hot-standby redundant virtual machines is deployed to a server set, enabling multiple stations to share servers without requiring dedicated hardware for each station, significantly reducing hardware procurement costs. This invention improves resource utilization through virtual machines, and the third virtual machine's communication function allows for resource sharing among virtual machines. This invention achieves a leap from dedicated hardware to general-purpose cloud computing without compromising security levels, demonstrating significant economic efficiency and technological advancement. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0017] Figure 1 This is a flowchart illustrating the secure cloud platform deployment method provided by the present invention.
[0018] Figure 2 This is an application diagram of the secure cloud platform deployment method provided by the present invention.
[0019] Figure 3 This is a schematic diagram of the structure of the secure cloud platform system provided by the present invention.
[0020] Figure 4This is a schematic diagram of the structure of the secure cloud platform deployment device provided by the present invention.
[0021] Figure 5 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0022] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0023] Figure 1 This is a flowchart illustrating a method for deploying a secure cloud platform according to an exemplary embodiment. For example... Figure 1 As shown in an exemplary embodiment, the method for deploying a secure cloud platform includes steps 110 to 130, which are described in detail below.
[0024] Step 110: Obtain the security computing deployment requirements for each station.
[0025] In this embodiment of the invention, the security computing deployment requirements of the entire line or multiple stations are obtained.
[0026] Step 120: Based on the security operation deployment requirements, construct a hot standby redundant virtual machine set corresponding to each station; wherein, the hot standby redundant virtual machine set includes at least two virtual machine groups, and the virtual machine groups implement hot standby redundancy functions. Each virtual machine group includes a first virtual machine, a second virtual machine, and a third virtual machine. The first virtual machine and the second virtual machine are used to implement 2-out-of-2 secure operations, and the third virtual machine is used to implement communication functions.
[0027] In this embodiment of the invention, based on the security computing deployment requirements of each station, a hot standby redundant virtual machine set corresponding to each station is constructed. The hot standby redundant virtual machine set includes at least two virtual machine groups, and the virtual machine groups implement hot standby redundancy functions, that is, the virtual machine groups are in a powered-on running state, and the two virtual machine groups maintain real-time data synchronization. One virtual machine group serves as a backup for the other virtual machine group, but the virtual machine group does not undertake actual control output (it is in a "standby" state). When the working virtual machine group fails for any reason (such as hardware failure, power outage, software crash), the backup virtual machine group can take over all work without interruption in a very short time, showing a seamless switch to the outside world and ensuring uninterrupted service.
[0028] Each virtual machine group includes a first virtual machine, a second virtual machine, and a third virtual machine. The first and second virtual machines are used to implement a 2-out-of-2 safe computation; that is, the first and second virtual machines handle the safety functions and simultaneously and synchronously execute the exact same safety-critical computational tasks. After each step of the computation, they compare their intermediate and final results with each other. Only when the computation results of the first and second virtual machines are completely identical is the result considered correct and safe, and allowed to be output. If any inconsistency occurs in the computation results of the first and second virtual machines, a fault is immediately considered to have occurred, and safety measures are taken (e.g., stopping output, triggering a brake, alarm, etc.). The third virtual machine acts as a communication mechanism, enabling communication between the virtual machines. The third virtual machine does not handle safety functions.
[0029] Step 130: Deploy each of the hot standby redundant virtual machine sets to the server set.
[0030] In this embodiment of the invention, the constructed hot standby redundant virtual machine set is deployed to a server set, which consists of multiple physical servers.
[0031] In this embodiment of the invention, a set of hot-standby redundant virtual machines is constructed for each station based on the security computing deployment requirements of each station. The set of hot-standby redundant virtual machines includes at least two virtual machine groups, which implement hot-standby redundancy functionality. Each virtual machine group includes a first virtual machine, a second virtual machine, and a third virtual machine. The first and second virtual machines are used to implement a 2-out-of-2 secure computation, and the third virtual machine is used for communication functionality. The constructed set of hot-standby redundant virtual machines is deployed to a server set, enabling multiple stations to share a server without requiring dedicated hardware for each station, significantly reducing hardware procurement costs. This invention improves resource utilization through virtual machines, and the third virtual machine's communication functionality allows for resource sharing among virtual machines. This invention achieves cloud deployment while meeting the SIL4 security standard. This invention achieves a leap from dedicated hardware to general-purpose cloud computing without compromising security levels, demonstrating significant economic efficiency and technological advancement.
[0032] In an exemplary embodiment of the present invention, the server set includes at least two server groups, each server group corresponding to a virtual machine group, and each server group includes a first server and a second server. The step of deploying each of the hot standby redundant virtual machine sets to the server set includes: The first virtual machine and the third virtual machine in each virtual machine group are deployed on the first server of the corresponding server group; Deploy the second virtual machine in each virtual machine group on the second server of the corresponding server group; The virtual machines are connected to each other via Ethernet.
[0033] In this embodiment of the invention, the secure cloud platform system consists of at least two sets of six virtual machines, with each set comprising at least three virtual machines, defined as a first virtual machine, a second virtual machine, and a third virtual machine, forming two completely independent sets of hot-standby redundant virtual machines with identical hardware and software configurations and full secure computing capabilities. The two sets implement a 2-times hot-standby redundancy function. Within the same set, the first and second virtual machines perform a 2-out-of-2 secure operation, undertaking the security function; the third virtual machine serves as a communication device and does not undertake any security function. Within the same hot-standby redundant virtual machine set, the first and second virtual machines, which undertake the security function, are located on different hardware devices to achieve physical independence, i.e., they are respectively located on the first and second servers, while the third virtual machine can be located on either the first or second server. The three virtual machines within each hot-standby redundant virtual machine set, and the virtual machines between different hot-standby redundant virtual machine sets, are connected via shared memory or Ethernet. All communication interfaces of external devices are connected to the C machines of the two sets via Ethernet.
[0034] like Figure 2 As shown, two server groups are set up, each consisting of two high-performance general-purpose servers to form the first server and the second server, respectively. Figure 2 S5000C server 1 and S5000C server 2 form one server group, and S5000C server 3 and S5000C server 4 form another server group. The hot standby redundant virtual machine set includes two virtual machine groups. Figure 2 In this context, "user virtual machine" refers to the virtual machine of a station, which in practice corresponds to multiple users (stations). S5000C server 1, as the first server, can simultaneously run the first virtual machine (user virtual machine IA) and the third virtual machine (user virtual machine IC) of the station. S5000C server 2, as the second server, runs the second virtual machine (user virtual machine IB). S5000C server 3, as the first server in another server group, can simultaneously run the first virtual machine (user virtual machine II-A) and the third virtual machine (user virtual machine II-C) of the station as backups. S5000C server 4, as the second server in another server group, runs the second virtual machine (user virtual machine II-B) as a backup.
[0035] based on Figure 2It can be seen that the virtual machines IA and IC for multiple stations are deployed on physical server 1, and the virtual machines IB for multiple stations are deployed on physical server 2, thus forming a multi-station interlocking system 1; the virtual machines II-A and II-C for multiple stations are deployed on physical server 3, and the virtual machines II-B for multiple stations are deployed on physical server 4, thus forming a multi-station interlocking system 2. Therefore, four servers are sufficient to meet the deployment requirements of multi-station interlocking applications.
[0036] In this embodiment of the invention, by setting up a server cluster, only bulk-purchased commercial servers (COTS) are needed during deployment. Their cost is far lower than dedicated embedded hardware, thus reducing procurement costs. Simultaneously, the number of servers is significantly reduced, directly lowering power consumption and the required data center area and cooling load. Furthermore, the standardization of hardware types for secure computing simplifies spare parts inventory and personnel skill requirements, while automated operation and maintenance reduces manual intervention. Moreover, only standard high-speed Ethernet connections are needed between virtual machines, simplifying cabling and achieving complete decoupling of computing and communication. When expansion is required, any virtual machine can be included in the resource pool as long as it is network accessible.
[0037] In an exemplary embodiment of the present invention, constructing a set of hot standby redundant virtual machines corresponding to each of the stations based on the security computing deployment requirements includes: Based on the aforementioned security computing deployment requirements, computing resources are allocated to each of the stations from a general server resource pool, and the hot standby redundant virtual machine set is constructed based on the computing resources; wherein, the computing resources include vCPU, memory, storage, and network.
[0038] In this embodiment of the invention, the computing resources required by the entire line or multiple stations are integrated into a unified general-purpose server resource pool. Instead of configuring dedicated hardware for each station, computing resources are dynamically allocated from the general-purpose server resource pool to create multiple virtual machines based on security computing deployment requirements, thus supporting security systems such as interlocking and area controllers at different stations. Theoretically, if there is no upper limit to the performance of a single server, virtual machines for all stations along the entire line can be deployed on a single server; that is, four servers are sufficient to meet the 2x2 safety function of the interlocking equipment across the entire line. Computing resources include vCPU, memory, storage, and network.
[0039] In an exemplary embodiment of the present invention, after deploying each of the hot-standby redundant virtual machine sets to the server set, the method further includes: Obtain the service load of each of the aforementioned stations; Based on the aforementioned workload, the computing resources allocated to each virtual machine are dynamically adjusted.
[0040] In this embodiment of the invention, the service load of each station is obtained, and the computing resources allocated to each virtual machine can be dynamically adjusted according to the service load, or new virtual machine instances can be deployed to achieve on-demand allocation and smooth expansion of resources.
[0041] In an exemplary embodiment of the present invention, after deploying each of the hot-standby redundant virtual machine sets to the server set, the method further includes: If a server failure is detected in the server set, the virtual machine group deployed on the failed server will be migrated to a normal server.
[0042] In this embodiment of the invention, if any physical server hosting a virtual machine fails, it can be automatically migrated in real-time to another normal server in the resource pool to resume operation. The service interruption time is extremely short, far exceeding the recovery efficiency of traditional manual board replacement. Through the real-time migration of virtual machines, fault switching and recovery can be completed in a short time.
[0043] In this embodiment of the invention, when a server in the server set or a virtual machine deployed on the server fails, another set of virtual machines, which serves as a backup, takes over all the work.
[0044] When online upgrades or patching of the server are required, the virtual machine can be migrated to another server first, the server can be maintained or upgraded, and then the virtual machine can be migrated back, achieving "zero downtime" maintenance of software and hardware and having good horizontal scalability.
[0045] In an exemplary embodiment of the present invention, after deploying each of the hot-standby redundant virtual machine sets to the server set, the method further includes: If a station to be deployed is detected, the corresponding hot standby redundant virtual machine set is deployed for the station in the server set using the clone virtual machine image function.
[0046] In this embodiment of the invention, when a new station needs to deploy secure computing, rapid deployment can be achieved through the cloning virtual machine image function, greatly shortening the project delivery and expansion cycle.
[0047] Figure 3 This is a schematic diagram illustrating the structure of a secure cloud platform system according to an exemplary embodiment. For example... Figure 3 As shown, in an exemplary embodiment, the secure cloud platform system includes: A set of servers, wherein a set of hot-standby redundant virtual machines is deployed in the server set based on any of the aforementioned secure cloud platform deployment methods.
[0048] In this embodiment of the invention, the secure cloud platform system consists of at least two sets of six virtual machines, with each set comprising at least three virtual machines, defined as a first virtual machine, a second virtual machine, and a third virtual machine, forming two completely independent sets of hot-standby redundant virtual machines with identical hardware and software configurations and full secure computing capabilities. The two sets implement a 2-times hot-standby redundancy function. Within the same set, the first and second virtual machines perform a 2-out-of-2 secure operation, undertaking the security function; the third virtual machine serves as a communication device and does not undertake any security function. Within the same hot-standby redundant virtual machine set, the first and second virtual machines, which undertake the security function, are located on different hardware devices to achieve physical independence, i.e., they are respectively located on the first and second servers, while the third virtual machine can be located on either the first or second server. The three virtual machines within each hot-standby redundant virtual machine set, and the virtual machines between different hot-standby redundant virtual machine sets, are connected via shared memory or Ethernet. All communication interfaces of external devices are connected to the C machines of the two sets via Ethernet.
[0049] like Figure 2 As shown, two server groups are set up, each consisting of two high-performance general-purpose servers to form the first server and the second server, respectively. Figure 2 S5000C server 1 and S5000C server 2 form one server group, and S5000C server 3 and S5000C server 4 form another server group. The hot standby redundant virtual machine set includes two virtual machine groups. Figure 2 In this context, "user virtual machine" refers to the virtual machine at the station, which in practice corresponds to multiple users (stations). S5000C server 1, as the first server, can simultaneously run the station's first virtual machine (user virtual machine IA) and third virtual machine (user virtual machine IC). S5000C server 2, as the second server, runs the second virtual machine (user virtual machine IB). S5000C server 3, as the first server in another server group, can simultaneously run the station's backup first virtual machine (user virtual machine II-A) and third virtual machine (user virtual machine II-C). S5000C server 4, as the second server in another server group, runs the backup second virtual machine (user virtual machine II-B). Simultaneously, maintenance and diagnostic virtual machines run on each server. This cross-system, cross-functional hybrid deployment mode greatly improves resource utilization and fundamentally reduces the number of physical devices.
[0050] like Figure 2 As shown, the physical network interface cards (NICs) on each server are connected to enable communication between virtual machines, facilitating the sharing of computing resources.
[0051] based on Figure 2It can be seen that the virtual machines IA and IC for multiple stations are deployed on physical server 1, and the virtual machines IB for multiple stations are deployed on physical server 2, thus forming a multi-station interlocking system 1; the virtual machines II-A and II-C for multiple stations are deployed on physical server 3, and the virtual machines II-B for multiple stations are deployed on physical server 4, thus forming a multi-station interlocking system 2. Therefore, four servers are sufficient to meet the deployment requirements of multi-station interlocking applications.
[0052] In this embodiment of the invention, the secure cloud platform system runs on top of the virtualization layer, decoupled from the underlying hardware details. It can support x86 servers from different manufacturers and generations, protecting investment and avoiding technology lock-in.
[0053] The technical solution provided by this invention enables cloud deployment while meeting the SIL4 security standard. Through the Hypervisor collaborative scheduling and memory self-checking mechanism, the real-time performance and security of the secure cloud platform system in the virtualization environment are guaranteed, filling the technical gap of existing general cloud platforms in security-critical systems.
[0054] The following describes the secure cloud platform deployment apparatus provided by the present invention. The secure cloud platform deployment apparatus described below can be referred to in correspondence with the secure cloud platform deployment method described above. It should be noted that the apparatus provided in the following embodiments and the method provided in the above embodiments belong to the same concept, and the specific way in which each module and unit performs operations has been described in detail in the method embodiments, and will not be repeated here.
[0055] In one exemplary embodiment of the present invention, please refer to Figure 4 , Figure 4 This is a secure cloud platform deployment apparatus according to an exemplary embodiment, comprising the following modules.
[0056] The first acquisition module 410 is configured to acquire the security computing deployment requirements of each station; The construction module 420 is configured to construct a set of hot standby redundant virtual machines corresponding to each station based on the security operation deployment requirements; wherein, the set of hot standby redundant virtual machines includes at least two groups of virtual machines, and the virtual machines implement hot standby redundancy functions between the virtual machine groups. Each group of virtual machines includes a first virtual machine, a second virtual machine, and a third virtual machine. The first virtual machine and the second virtual machine are used to implement 2-out-of-2 security operations, and the third virtual machine is used to implement communication functions. The first deployment module 430 is configured to deploy each of the hot standby redundant virtual machine sets to the server set.
[0057] In an exemplary embodiment of the present invention, the server set includes at least two server groups, each server group corresponding to a virtual machine group, and each server group includes a first server and a second server. The first deployment module 430 includes: The first deployment submodule is configured to deploy the first virtual machine and the third virtual machine in each virtual machine group on the first server of the corresponding server group; The second deployment submodule is configured to deploy the second virtual machine in each virtual machine group on the second server of the corresponding server group; The third deployment submodule is configured to establish communication connections between the virtual machines via Ethernet.
[0058] In an exemplary embodiment of the present invention, the construction module 420 includes: A submodule is configured to allocate computing resources to each station from a general server resource pool based on the security computing deployment requirements, and to build the hot standby redundant virtual machine set based on the computing resources; wherein, the computing resources include vCPU, memory, storage, and network.
[0059] In an exemplary embodiment of the present invention, the secure cloud platform deployment apparatus further includes: The second acquisition module is configured to acquire the service load of each of the stations; The adjustment module is configured to dynamically adjust the computing resources allocated to each virtual machine based on the business load.
[0060] In an exemplary embodiment of the present invention, the secure cloud platform deployment apparatus further includes: The migration module is configured to migrate the virtual machine group deployed on the failed server to a normal server if a server failure is detected in the server set.
[0061] In an exemplary embodiment of the present invention, the secure cloud platform deployment apparatus further includes: The second deployment module is configured to, if a station to be deployed is detected, deploy a corresponding hot standby redundant virtual machine set for the station to be deployed in the server set through the virtual machine image cloning function.
[0062] Figure 5 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 5As shown, the electronic device may include: a processor 510, a communications interface 520, a memory 530, and a communication bus 540, wherein the processor 510, the communications interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call logical instructions in the memory 530 to execute a secure cloud platform deployment method, which includes: obtaining the secure computing deployment requirements of each station; Based on the aforementioned security operation deployment requirements, a set of hot standby redundant virtual machines corresponding to each of the stations is constructed; wherein, the set of hot standby redundant virtual machines includes at least two groups of virtual machines, and the virtual machines implement hot standby redundancy functions among the virtual machine groups. Each group of virtual machines includes a first virtual machine, a second virtual machine, and a third virtual machine. The first virtual machine and the second virtual machine are used to implement 2-out-of-2 secure operations, and the third virtual machine is used to implement communication functions. Deploy each of the aforementioned hot standby redundant virtual machine sets to the server set.
[0063] Furthermore, the logical instructions in the aforementioned memory 530 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0064] On the other hand, the present invention also provides a computer program product, the computer program product including a computer program, the computer program being able to be stored on a non-transitory computer-readable storage medium, and when the computer program is executed by a processor, the computer is able to execute the secure cloud platform deployment method provided by the above methods, the method including: obtaining the secure computing deployment requirements of each station; Based on the aforementioned security operation deployment requirements, a set of hot standby redundant virtual machines corresponding to each of the stations is constructed; wherein, the set of hot standby redundant virtual machines includes at least two groups of virtual machines, and the virtual machines implement hot standby redundancy functions among the virtual machine groups. Each group of virtual machines includes a first virtual machine, a second virtual machine, and a third virtual machine. The first virtual machine and the second virtual machine are used to implement 2-out-of-2 secure operations, and the third virtual machine is used to implement communication functions. Deploy each of the aforementioned hot standby redundant virtual machine sets to the server set.
[0065] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the secure cloud platform deployment method provided by the above methods, the method comprising: obtaining the secure computing deployment requirements of each station; Based on the aforementioned security operation deployment requirements, a set of hot standby redundant virtual machines corresponding to each of the stations is constructed; wherein, the set of hot standby redundant virtual machines includes at least two groups of virtual machines, and the virtual machines implement hot standby redundancy functions among the virtual machine groups. Each group of virtual machines includes a first virtual machine, a second virtual machine, and a third virtual machine. The first virtual machine and the second virtual machine are used to implement 2-out-of-2 secure operations, and the third virtual machine is used to implement communication functions. Deploy each of the aforementioned hot standby redundant virtual machine sets to the server set.
[0066] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0067] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0068] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A secure cloud platform deployment method, characterized by, The method comprises the following steps: acquiring the safety operation deployment requirements of each station; based on the safety operation deployment requirements, constructing a hot standby redundant virtual machine set corresponding to each station; wherein the hot standby redundant virtual machine set comprises at least two virtual machine groups, the virtual machine groups realize hot standby function, each virtual machine group comprises a first virtual machine, a second virtual machine and a third virtual machine, the first virtual machine and the second virtual machine are used to realize 2 out of 2 safety operation, and the third virtual machine is used to realize communication function; deploying each hot standby redundant virtual machine set to a server set.
2. The secure cloud platform deployment method of claim 1, wherein, The server set comprises at least two server groups, each server group corresponds to a virtual machine group, and each server group comprises a first server and a second server; The method of deploying each hot standby redundant virtual machine set to a server set comprises: deploying the first virtual machine and the third virtual machine in each virtual machine group on the first server of the corresponding server group; deploying the second virtual machine in each virtual machine group on the second server of the corresponding server group; Each virtual machine is connected through Ethernet.
3. The secure cloud platform deployment method of claim 1, wherein, The method of constructing a hot standby redundant virtual machine set corresponding to each station based on the safety operation deployment requirements comprises: based on the safety operation deployment requirements, allocating computing resources to each station from a general server resource pool, and constructing the hot standby redundant virtual machine set based on the computing resources; wherein the computing resources include vCPU, memory, storage and network.
4. The secure cloud platform deployment method of claim 1, wherein, After deploying each hot standby redundant virtual machine set to a server set, the method further comprises: acquiring the business load of each station; based on the business load, dynamically adjusting the computing resources allocated to each virtual machine.
5. The secure cloud platform deployment method of claim 1, wherein, After deploying each hot standby redundant virtual machine set to a server set, the method further comprises: if it is detected that a server in the server set fails, migrating the virtual machine group deployed on the failed server to a normal server.
6. The secure cloud platform deployment method of any one of claims 1 to 5, wherein, After deploying each hot standby redundant virtual machine set to a server set, the method further comprises: if a to-be-deployed station is detected, deploying a corresponding hot standby redundant virtual machine set for the to-be-deployed station in the server set through the cloning virtual machine image function.
7. A secure cloud platform system, characterized by The method comprises the following steps: a server set, wherein the server set is deployed with a hot standby redundant virtual machine set generated based on the safety cloud platform deployment method according to any one of claims 1 to 6.
8. A secure cloud platform deployment apparatus, characterized by, The method comprises the following steps: a first acquisition module configured to acquire the safety operation deployment requirements of each station; a construction module configured to construct a hot standby redundant virtual machine set corresponding to each station based on the safety operation deployment requirements; wherein the hot standby redundant virtual machine set comprises at least two virtual machine groups, the virtual machine groups realize hot standby function, each virtual machine group comprises a first virtual machine, a second virtual machine and a third virtual machine, the first virtual machine and the second virtual machine are used to realize 2 out of 2 safety operation, and the third virtual machine is used to realize communication function; A first deploying module, configured to deploy each of the sets of hot-standby redundant virtual machines to a set of servers.
9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, The processor executes the computer program to implement the method for deploying a secure cloud platform according to any one of claims 1 to 6. 10.A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method for deploying a secure cloud platform according to any one of claims 1 to 6.