Government affair cloud unified management method, system, device and storage medium

By building a unified access gateway and dynamic routing strategy in the government cloud management system, and combining user permissions and real-time resource status, the problem of low cross-platform collaboration efficiency in the traditional government cloud management system has been solved. This has enabled precise matching of service requests and accurate resource scheduling, ensuring the continuity and security of critical services.

CN122120324APending Publication Date: 2026-05-29SHANXI FANGSHI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANXI FANGSHI TECH CO LTD
Filing Date
2025-09-24
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Traditional government cloud management systems suffer from low cross-platform collaboration efficiency when faced with multi-source heterogeneous service requests. Resource scheduling relies on preset static strategies and fails to dynamically link user permissions with the real-time load status of cloud nodes. The operation and maintenance decision-making process is fragmented, making it difficult to meet the continuity requirements of critical public services.

Method used

By building a unified access gateway to integrate multi-source service requests, generating dynamic routing policies based on user permissions and real-time resource status, and combining response results with infrastructure data aggregation decision-making mechanisms, the system achieves precise matching of service requests with cloud node resources and drives the API scheduling engine to execute resource operations, forming a data-driven closed-loop management mechanism.

Benefits of technology

It improves the cross-platform collaboration efficiency of the government cloud management system, ensures service continuity and accurate resource scheduling, reduces security protection pressure, and improves operation and maintenance response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120324A_ABST
    Figure CN122120324A_ABST
Patent Text Reader

Abstract

The application discloses a government affair cloud unified management method, system, equipment and storage medium, relates to the technical field of data processing, and aims to solve the problem of low cooperation efficiency of traditional cross-platform. The method comprises the following steps: receiving a multi-source service request of a mobile government affair terminal cluster through a unified access gateway, wherein the mobile government affair terminal cluster comprises an instant messaging module, a lightweight service module and an intelligent service module; distributing the multi-source service request to a target cloud node based on a dynamic routing strategy, wherein the dynamic routing strategy is generated according to user permissions and a real-time resource load state, and the multi-source service request is used for instructing the target cloud node to execute corresponding resource operations to generate a response result; aggregating the response result and cloud infrastructure data to generate an operation and maintenance decision instruction, wherein the operation and maintenance decision instruction is used for driving an application program interface (API) scheduling engine to execute corresponding resource operations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to a unified management method, system, device and storage medium for government cloud. Background Technology

[0002] As e-government evolves from single-point applications to integrated and service-oriented approaches, mobile e-government terminals have become a core channel for interaction between the government and the public.

[0003] Currently, government departments at all levels have widely deployed instant messaging applications, mini-programs, and intelligent customer service modules. Due to varying development standards and inconsistent interface protocols, these modules exhibit multi-source and heterogeneous service requests. Traditional distributed access architectures, relying on preset static strategies, may experience node overload and blocking, or low-priority tasks consuming critical resources. Furthermore, traditional distributed access architectures struggle to achieve cross-platform collaboration when dealing with such multi-source and heterogeneous requests, resulting in insufficient accuracy in scheduling multi-dimensional resources and inefficient operational response, thus reducing cross-platform collaboration efficiency. Summary of the Invention

[0004] The purpose of this application is to provide a unified management method, system, device and storage medium for government cloud, which aims to solve the problem of low efficiency in traditional cross-platform collaboration.

[0005] To achieve the above objectives, this application adopts the following technical solution: This application provides a unified management method for government cloud, which includes: receiving multi-source service requests from a mobile government terminal cluster through a unified access gateway, wherein the mobile government terminal cluster includes an instant messaging module, a lightweight service module, and an intelligent service module; distributing the multi-source service requests to target cloud nodes based on a dynamic routing strategy, wherein the dynamic routing strategy is generated according to user permissions and real-time resource load status, and the multi-source service requests are used to instruct the target cloud nodes to perform corresponding resource operations to generate response results; aggregating the response results and cloud infrastructure data to generate operation and maintenance decision instructions, wherein the operation and maintenance decision instructions are used to drive the application programming interface (API) scheduling engine to perform corresponding resource operations.

[0006] The unified management method for government cloud provided in this application integrates multi-source service requests through a unified access gateway, supporting centralized access for instant messaging, lightweight services, and intelligent service modules, thereby improving terminal compatibility and service coverage. Based on user permissions and real-time resource status, a dynamic routing strategy is generated to achieve precise matching of service requests and cloud node resources, ensuring both compliance of operation permissions and avoiding resource overload, thus ensuring service continuity. By aggregating response results and cloud infrastructure data to generate operation and maintenance decision instructions, the API scheduling engine is driven to execute resource operations, forming a data-driven closed-loop management mechanism. This improves the accuracy of resource scheduling and the efficiency of operation and maintenance response, thereby enhancing cross-platform collaboration efficiency.

[0007] In some embodiments, before the above-mentioned service request is distributed to the target cloud node based on the dynamic routing strategy, the unified management method for government cloud provided in this application embodiment further includes: constructing a mapping model based on organizational structure relationship, the mapping model being used to represent the mapping relationship between role identifier and cloud resource operation; inputting the current user's role identifier into the mapping model to generate encrypted access credentials.

[0008] Based on this, this application constructs a precise mapping model of role-resource operations and generates encrypted access credentials to achieve systematic management of government cloud permissions, providing a trusted identity foundation for dynamic routing and avoiding the risk of unauthorized operations.

[0009] In some embodiments, the above-mentioned distribution of multi-source service requests to the target cloud node based on a dynamic routing strategy includes: distributing multi-source service requests to the target cloud node based on a dynamic routing strategy when the scope of the encrypted access credentials includes the resource operations corresponding to the multi-source service requests.

[0010] Based on this, this application moves the security control point to the request entry layer by forcibly verifying the scope of access credentials before routing and distribution, effectively intercepting illegal requests and reducing the internal security protection pressure of the government cloud.

[0011] In some embodiments, the above-mentioned distribution of multi-source service requests to target cloud nodes based on dynamic routing strategies includes: parsing the government affairs scenario identifier in the multi-source service request and matching it with the business rule base to obtain routing strategy parameters, the routing strategy parameters including business priority, data sensitivity level and resource quota requirements; selecting target cloud nodes and generating node routing instructions based on the routing strategy parameters, combined with real-time resource load status and security isolation rules; and executing the node routing instructions through the distributed routing component of the unified access gateway to distribute the multi-source service requests to the target cloud nodes.

[0012] Based on this, this application dynamically selects target nodes based on government characteristic parameters such as business priority and data sensitivity, so as to achieve precise matching between business needs and resource status and significantly improve the resource guarantee capability of key government services.

[0013] In some embodiments, the above-mentioned aggregation of response results and cloud infrastructure data through the resource monitoring center to generate operation and maintenance decision instructions includes: extracting a multi-dimensional feature set from the aggregated data, the aggregated data including response results and cloud infrastructure data, the multi-dimensional feature set including resource load trend characteristics, security threat pattern characteristics, and key characteristics of business scenarios; matching the decision vector corresponding to the multi-dimensional feature set from the government cloud operation and maintenance rule base to generate operation and maintenance decision instructions, the operation and maintenance decision instructions including resource operation type and parameters, and security handling level parameters mapped to business continuity assurance identifiers.

[0014] Based on this, this application generates operation and maintenance instructions that balance efficiency and security by extracting three-dimensional features of resources, security, and business and by weighted optimization of the government rule base, thus resolving the decision-making contradiction between resource scheduling and business assurance in traditional solutions.

[0015] In some embodiments, the aforementioned driving API scheduling engine performs corresponding resource operations, including: when the business continuity assurance identifier is in the livelihood assurance mode, initiating a hot standby node switching process and generating a node group identifier; calling the cloud resource API to perform resource operations, injecting security handling level parameters and node group identifiers; capturing the operation status of resource operations in real time, generating traceable execution records, which include resource fingerprints and security audit events.

[0016] Based on this, this application triggers hot standby switching and security parameter injection through the livelihood security model, and with the generation of traceable execution records, forms a complete closed loop of "decision-execution-feedback" to ensure the continuous availability of key livelihood services.

[0017] In some embodiments, the aforementioned cloud infrastructure data includes business service status data. The acquisition of this business service status data includes: receiving cross-platform business data streams at the data exchange layer, extracting government business characteristic tags, and performing data standardization transformation; injecting traceability identifiers into the transformed data to generate a unified data entity, the traceability identifiers including data security level, business source system, and government business characteristic tags, the data security level being used to determine a secure storage strategy, and the business source system being used to associate with a resource allocation strategy; synchronizing the unified data entity to the target business system, and triggering corresponding service status updates based on the government business characteristic tags; capturing the status change event stream generated by the service status update, and extracting key performance indicators as business service status data, the key performance indicators including service response latency, transaction processing success rate, and system backlog.

[0018] Based on this, this application utilizes feature-label-driven status update rules and standardized indicator extraction to achieve accurate perception of government business status, providing real-time and effective business layer data support for operation and maintenance decisions.

[0019] This application provides a unified management system for government cloud, comprising: a receiving unit for receiving multi-source service requests from a mobile government terminal cluster via a unified access gateway, the mobile government terminal cluster including an instant messaging module, a lightweight service module, and an intelligent service module; an output unit for distributing the multi-source service requests to target cloud nodes based on a dynamic routing strategy, the dynamic routing strategy being generated according to user permissions and real-time resource load status, the multi-source service requests being used to instruct the target cloud nodes to perform corresponding resource operations and generate response results; and a generation unit for aggregating the response results and cloud infrastructure data to generate operation and maintenance decision instructions, the operation and maintenance decision instructions being used to drive the API scheduling engine to execute corresponding resource operations.

[0020] In some embodiments, the unified government cloud management system improved in this application further includes: a construction unit, configured to construct a mapping model based on organizational structure relationships before distributing service requests to target cloud nodes based on dynamic routing strategies; the mapping model is used to represent the mapping relationship between role identifiers and cloud resource operations; the aforementioned generation unit is further configured to input the current user's role identifier into the mapping model to generate encrypted access credentials.

[0021] In some embodiments, the above-mentioned output unit is specifically used to: distribute multi-source service requests to the target cloud node based on a dynamic routing strategy when the scope of permissions of the encrypted access credentials includes resource operations corresponding to multi-source service requests.

[0022] In some embodiments, the above-mentioned output unit is specifically used to: parse the government affairs scenario identifier in the multi-source service request and match it with the business rule base to obtain routing policy parameters, the routing policy parameters including business priority, data sensitivity level and resource quota requirements; select the target cloud node and generate node routing instructions according to the routing policy parameters, combined with real-time resource load status and security isolation rules; and execute the node routing instructions through the distributed routing component of the unified access gateway to distribute the multi-source service request to the target cloud node.

[0023] In some embodiments, the above-mentioned generation unit is specifically used to: extract a multi-dimensional feature set from the aggregated data, the aggregated data including response results and cloud infrastructure data, the multi-dimensional feature set including resource load trend features, security threat pattern features and key features of business scenarios; match the decision vector corresponding to the multi-dimensional feature set from the government cloud operation and maintenance rule base, and generate operation and maintenance decision instructions, the operation and maintenance decision instructions including resource operation type and parameters, and security handling level parameters mapped to the business continuity assurance identifier.

[0024] In some embodiments, the unified government cloud management system improved in this application further includes: an execution unit, configured to: initiate a hot standby node switching process and generate a node group identifier when the business continuity assurance identifier is set to the livelihood assurance mode; call the cloud resource API to perform resource operations, injecting security handling level parameters and node group identifiers; the aforementioned generation unit is also configured to capture the operation status of resource operations in real time and generate traceable execution records, the traceable execution records including resource fingerprints and security audit events.

[0025] In some embodiments, the cloud infrastructure data includes business service status data. The receiving unit is further configured to receive cross-platform business data streams at the data exchange layer, extract government business feature tags, and perform data standardization transformation. The execution unit is further configured to inject traceability identifiers into the transformed data to generate a unified data entity. The traceability identifiers include data security level, business source system, and government business feature tags. The data security level is used to determine the secure storage strategy, and the business source system is used to associate resource allocation strategies. The output unit is further configured to synchronize the unified data entity to the target business system and trigger corresponding service status updates based on the government business feature tags. The execution unit is further configured to capture the status change event stream generated by the service status update and extract key performance indicators as business service status data. The key performance indicators include service response latency, transaction processing success rate, and system backlog.

[0026] This application provides an electronic device, including: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to execute instructions to implement the unified management method for government cloud described above.

[0027] This application provides a computer-readable storage medium storing instructions that, when executed on a terminal, cause the terminal to perform the unified management method for government cloud described above.

[0028] This application provides a computer program product containing instructions that, when executed by a computer, cause the computer to perform the unified management method for government cloud described above.

[0029] This application provides a chip including a processor and a communication interface, the communication interface and the processor being coupled together. The processor is used to run computer programs or instructions to implement the unified management method for government cloud described above.

[0030] Specifically, the chip provided in this application embodiment also includes a memory for storing computer programs or instructions. Attached Figure Description

[0031] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0032] Figure 1 A flowchart illustrating a unified management method for government cloud services provided in this application embodiment; Figure 2 A structural diagram of a unified government cloud management system provided in this application embodiment; Figure 3 This is a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0033] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0034] In the description of this application, it should be understood that the terms "upper," "lower," "left," "right," "front," "rear," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or relative positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this application and for simplification, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application. Unless otherwise specified, the above-mentioned orientational descriptions can be flexibly set in practical applications, provided that the relative positional relationships shown in the accompanying drawings are satisfied.

[0035] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0036] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," "linking," and "communication" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection. They can refer to a direct connection or an indirect connection through an intermediate medium, or a connection within two components. Those skilled in the art can understand the specific meaning of the above terms in this application according to the specific circumstances.

[0037] In some embodiments, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, article, or apparatus that includes that element.

[0038] In some embodiments, the words "exemplary" or "for example" are used to indicate that something is an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0039] In the description of this specification, specific features, structures, materials, or characteristics may be combined in any suitable manner in one or more embodiments or examples.

[0040] Existing government cloud management technologies suffer from two major contradictions: First, resource scheduling relies on preset static strategies and fails to dynamically link user permission verification with the real-time load status of cloud nodes. This often results in high-privilege operations being blocked due to node overload, or low-priority tasks occupying critical resources.

[0041] Secondly, the operation and maintenance decision-making process is fragmented, relying solely on infrastructure monitoring data or service response results, lacking analysis of the correlation between the two. This leads to delays in fault location and resource optimization, making it difficult to meet the stringent continuity requirements of public services.

[0042] Therefore, existing government cloud management systems suffer from low collaboration efficiency when facing cross-platform collaboration scenarios.

[0043] Against this backdrop, to address the low efficiency of traditional cross-platform collaboration in related technologies, this application provides a unified management method, system, device, and storage medium for government cloud. By constructing a unified access gateway to integrate multi-source requests, combining user permissions and real-time resource status to generate dynamic routing strategies, and introducing an aggregation decision-making mechanism for response results and infrastructure data, this aims to solve the collaborative challenges of compatibility, scheduling efficiency, and intelligent operation and maintenance in government cloud management.

[0044] The following is a reference. Figure 1 The unified management method for government cloud provided in the embodiments of this application is described.

[0045] Figure 1 The flowchart of the unified management method for government cloud provided in this application embodiment is shown. The subject executing the method can be an electronic device or various devices / modules in the electronic device, such as integrated circuits or chips. This application embodiment does not specifically limit this.

[0046] For example, such as Figure 1 As shown, the unified management method for government cloud provided in this application embodiment may include the following S101 to S103: S101. Receive multi-source service requests from the mobile government terminal cluster through the unified access gateway.

[0047] In this embodiment, the mobile government affairs terminal cluster includes an instant messaging module, a lightweight service module, and an intelligent service module.

[0048] For example, the instant messaging module is used for real-time collaborative communication among staff within the government system. For instance, if staff from the provincial finance department and the municipal finance bureau are exchanging messages in real-time regarding the allocation of provincial special funds, they would send a request containing information such as the allocation amount, arrival time, and purpose description.

[0049] For example, the lightweight service module is a government service portal that can be accessed directly through a browser or mini-program without downloading and installing a client. For instance, individual business owners can submit their "Annual Business License Report" through the lightweight service module, which requires them to fill in information such as "changes in business address, number of employees, and scope of business revenue"; citizens can make "real estate registration appointments" through the lightweight service module, selecting the appointment date, time slot, and service location, and the system will automatically provide an appointment number.

[0050] For example, the intelligent service module is an intelligent customer service system that integrates natural language processing capabilities to receive government inquiries from the public and provide immediate responses. For instance, if a member of the public inquires about "what materials are needed for transferring social security to another location," the system will automatically identify the keywords "transfer of social security to another location" and "materials," and return a reply containing information such as "original ID card, social security payment certificate, and social security account information of the destination location."

[0051] In addition, if the inquiry is complex, such as "how can flexible workers make up for the missed pension insurance payments", it will be automatically transferred to a human operator and the identified inquiry points will be synchronized to improve the efficiency of human service.

[0052] S102. Distribute multi-source service requests to target cloud nodes based on dynamic routing strategies.

[0053] In this embodiment, the dynamic routing policy is generated based on user permissions and real-time resource load status.

[0054] For example, user permissions can be divided into multiple levels according to the administrative management level.

[0055] For example, national-level administrators can operate government cloud resources nationwide, including resource allocation adjustments and cross-regional node monitoring; provincial-level administrators can only manage cloud resources within their own province, such as expanding the capacity of provincial government systems and data backup.

[0056] For example, city-level administrators may have limited authority to their own city, such as the routine maintenance of city-level government service nodes.

[0057] For example, district-level administrators are mainly responsible for the basic operations of government applications in their respective districts.

[0058] For example, real-time resource load status can be generated by continuously collecting performance metrics from each cloud node and updating the performance metrics periodically (e.g., every 30 seconds) to form a real-time load curve.

[0059] For example, performance metrics may include central processing unit (CPU) utilization (e.g., node A's current CPU utilization is 65%, and node B's is 85%), memory usage (e.g., node C's memory usage is 50% of the total capacity, and node D's is 70%), network bandwidth utilization (e.g., node E's upload bandwidth utilization is 30%, and node F's download bandwidth utilization is 60%), and disk input / output speed (e.g., node G's disk write speed is 80MB / s, and node H's is 40MB / s).

[0060] In this embodiment, the multi-source service request is used to instruct the target cloud node to perform the corresponding resource operation to generate a response result.

[0061] In one example, the "Business License Annual Report" request is used to instruct the target cloud node to perform operations such as "data format verification (e.g., checking whether the filled fields are complete and whether the format meets the requirements), information storage (e.g., storing the report content in the enterprise credit information database), and status marking (e.g., updating the annual report status of the enterprise to completed)", and finally returns the response result: annual report submitted successfully, report number XXX.

[0062] In another example, the "XX test data report" request is used to instruct the target cloud node to perform operations such as "data decryption (such as decrypting the encrypted reported data), integrity verification (such as checking whether it includes test data from all districts and counties), and summary statistics (such as calculating the total number of tests and the number of positive cases in the province on that day)". The response result is: data report successful, and the summary results have been synchronized to the provincial CDC system.

[0063] Optionally, before sending a service request to the target cloud node, a mapping model can be built based on the organizational structure relationship, and then the current user's role identifier can be input into the mapping model to generate encrypted access credentials.

[0064] In this embodiment of the application, the organizational structure can be constructed according to a four-level government system of "province-city-county-township", with each level containing multiple departments.

[0065] For example, the provincial-level architecture includes the Department of Finance, the Department of Education, and the Health Commission; the municipal-level architecture includes the Municipal Finance Bureau and the Municipal Education Bureau.

[0066] In this embodiment of the application, the mapping model is used to represent the mapping relationship between role identifiers and cloud resource operations.

[0067] For example, the mapping model can bind corresponding cloud resource operation permissions to each role identifier. For instance, the role identifier of the budget department of the provincial finance department can operate permissions such as "expanding resources and backing up budget data in the provincial budget management system"; the role identifier of the information center of the municipal education bureau can perform operations such as "querying logs and making minor resource adjustments on the municipal education resource platform".

[0068] In this embodiment, the encrypted access credential can be generated using an asymmetric encryption algorithm and includes role identity verification (identifier, ID) (e.g., “Provincial Finance Department - Budget Department - 001”), scope of permissions (e.g., “Provincial Budget System Resource Operation”), validity period (e.g., 24 hours) and system signature. The private key is stored by the government cloud management platform, and the public key is used for encryption on the user end.

[0069] Thus, this application achieves systematic management of government cloud permissions by constructing a precise mapping model of role-resource operations and generating encrypted access credentials, providing a trusted identity foundation for dynamic routing and avoiding the risk of unauthorized operations.

[0070] Furthermore, when the scope of permissions for the encrypted access credentials includes resource operations corresponding to multi-source service requests, multi-source service requests are distributed to the target cloud node based on a dynamic routing strategy.

[0071] For example, consider a municipal health commission staff member whose encrypted access credentials are limited to "operations on cloud resources within the municipal health system". If the staff member initiates a "provincial CDC data query" request, the system will detect that the resource operation corresponding to the request exceeds the credential's access permissions, directly intercept it, and return a "insufficient permissions, unable to execute this operation" message. If the staff member initiates a "statistics on XX testing data in this city" request, since the operation is within the access permissions, the system will distribute the request to the target cloud node based on a dynamic routing strategy.

[0072] Thus, by forcibly verifying the scope of access credentials before routing and distribution, this application moves the security control point forward to the request entry layer, effectively intercepting illegal requests and reducing the internal security protection pressure of the government cloud.

[0073] In some embodiments, the government service scenario identifier in the multi-source service request can be parsed first, and the routing strategy parameters can be obtained by matching the business rule base.

[0074] The routing policy parameters include business priority, data sensitivity level, and resource quota requirements.

[0075] For example, business priority refers to the urgency of government services. For instance, business priorities can be divided into multiple levels according to their importance: P0 is the highest priority, involving major livelihood security or urgent government tasks (such as "College Entrance Examination Score Inquiry System" and "Flood Control Command and Communication System"); P1 is the regular priority (such as "Enterprise Social Security Payment Declaration" and "Citizen Housing Provident Fund Inquiry" and other routine services); P2 is the low priority (such as "Government System User Guide Inquiry" and "Historical Policy Document Browsing" and other non-urgent services).

[0076] For example, data sensitivity level refers to the degree of confidentiality of business data. For instance, data sensitivity levels can be divided into multiple levels: S3 is the highest sensitivity level, containing data involving personal privacy or state secrets (such as "details of individual income tax payment" and "draft provincial fiscal budget"); S2 is the medium sensitivity level (such as "enterprise registration information" and "list of social security participants"); and S1 is the low sensitivity level (such as publicly available information such as "address of government service outlets" and "service procedure guide").

[0077] For example, resource quota requirements refer to the minimum resource allocation required to complete a business task.

[0078] For example, the "large-scale vaccination appointment" service requires cloud nodes with at least 8 CPU cores, 16GB of memory, and 100Mbps network bandwidth due to the large number of users online at the same time and frequent data interaction.

[0079] For example, the "Personal Social Security Payment Record Inquiry" service requires a cloud node with 2 CPU cores, 4GB of memory, and 10Mbps network bandwidth because the amount of data requested in a single request is small.

[0080] Furthermore, based on routing policy parameters, combined with real-time resource load status and security isolation rules, target cloud nodes can be selected and node routing instructions can be generated. Then, the distributed routing components of the unified access gateway can execute the node routing instructions to distribute multi-source service requests to the target cloud nodes.

[0081] For example, consider a "college entrance examination results query" request with multi-source service requests classified as "P0 level, S3 level". The corresponding routing strategy parameters require that the node's CPU utilization is below 70%, memory usage is below 60%, and it must comply with the dedicated isolation rules for education data (i.e., physical isolation from other government data nodes). In this case, nodes that meet the conditions can be filtered out using real-time load curves (such as node J, with a CPU utilization of 60% and memory usage of 55%). Then, a routing instruction to "forward the request to the port of node J" is generated. After receiving the instruction, the distributed routing component establishes a data transmission channel and accurately distributes the request to node J.

[0082] Thus, this application dynamically selects target nodes based on government characteristics parameters such as business priority and data sensitivity, achieving precise matching between business needs and resource status, and significantly improving the resource guarantee capability of critical government services.

[0083] S103 aggregates response results and cloud infrastructure data to generate operation and maintenance decision instructions.

[0084] In this embodiment, the operation and maintenance decision instructions are used to drive the API scheduling engine to execute corresponding resource operations.

[0085] In this embodiment of the application, the response results and cloud infrastructure data can be aggregated into aggregated data.

[0086] In one example, when aggregated data shows that the CPU utilization of the node where the "Enterprise Tax Refund Application" service is located exceeds 90% and the memory utilization exceeds 85% for 10 consecutive minutes, and the service is a P1 level business, the operation and maintenance decision instruction will drive the API scheduling engine to perform the operation of "temporarily expanding the CPU of the node to 16 cores and the memory to 32GB".

[0087] In another example, when the aggregated data shows that the node where the "Enterprise Tax Refund Application" service is located has a security log of "5 consecutive invalid login attempts" and that the node stores S3 level data, the decision instruction will drive the API scheduling engine to execute the operation of "banning the login account for 24 hours".

[0088] In some embodiments, a multidimensional feature set of the aggregated data can be extracted first.

[0089] The aggregated data includes response results and cloud infrastructure data.

[0090] In this embodiment of the application, the multidimensional feature set includes resource load trend features, security threat pattern features, and key features of business scenarios.

[0091] For example, resource load trend characteristics are obtained by analyzing the changing patterns of resource indicators over a continuous time period.

[0092] For example, if the CPU utilization of node K gradually increases from 40% an hour ago to 70% currently, it can be determined that the load on this node is showing a continuous upward trend and may reach full load in the next hour.

[0093] For example, the memory usage of node L suddenly dropped from 60% to 30% within 30 minutes. According to the business logs, this was caused by the execution of a "temporary data cleanup task", which is a normal fluctuation.

[0094] For example, security threat pattern features are features obtained by pattern recognition of abnormal behavior in system logs.

[0095] For example, between 1 a.m. and 3 a.m., node M received 15 "database administrator account login" requests from the same Internet Protocol (IP) address, and each time a different password was used, which is consistent with the behavior pattern of brute-force attack.

[0096] For example, if the outbound traffic of node N surges in a short period of time and the target IP is an unknown overseas address that does not match the IP range of the node's daily business interactions, there may be a risk of data leakage.

[0097] For example, key features of a business scenario refer to features determined based on the importance of the business within the government service system.

[0098] For example, the "data synchronization service of the flood control command system" is of utmost importance during the flood season. If it is interrupted, it may lead to delays in flood control decision-making and affect the safety of people's lives and property.

[0099] For example, the "housing provident fund loan calculator" is a routine service, and even if it is interrupted for a short period of time, it will have a small impact on the overall government services and is of low importance.

[0100] Furthermore, decision vectors corresponding to multi-dimensional feature sets can be matched from the government cloud operation and maintenance rule base to generate operation and maintenance decision instructions.

[0101] In this embodiment, the operation and maintenance decision instructions include resource operation types and parameters, as well as security handling level parameters mapped to the business continuity assurance identifier.

[0102] For example, resource operation type and parameters refer to specific resource adjustment actions and corresponding configuration requirements.

[0103] For example, node expansion operation: upgrade the CPU of node O from 8 cores to 16 cores and expand the memory from 16GB to 32GB. After expansion, it is necessary to maintain the synchronization frequency with the original data (such as once every 5 minutes).

[0104] For example, in a node migration operation: the "pension insurance inquiry" service is migrated from node P to node Q. During the migration process, the service needs to be suspended for 30 minutes, and a "system maintenance notice" is pushed to users in advance.

[0105] For example, a business continuity assurance identifier is an identifier used to mark the importance of a business service. For instance, "flood control command is marked as a core service," "medical insurance settlement is marked as a critical service," and "housing provident fund inquiry is marked as a routine service," with different identifiers corresponding to different resource assurance priorities.

[0106] For example, the security handling level parameter is the strength of security measures determined based on the business continuity assurance identifier.

[0107] For example, the core services corresponding to "Level 1 Security Response" require enabling real-time intrusion detection, performing log audits every 5 minutes, and enabling data transmission encryption.

[0108] For example, "Level 2 security measures" correspond to critical services, which require enabling regular access control and performing log audits every hour.

[0109] For example, "Level 3 security response" corresponds to regular services and requires the activation of basic security protection.

[0110] Thus, this application generates operation and maintenance instructions that balance efficiency and security by extracting three-dimensional features of resources, security, and business and by weighted optimization of the government rule base, thereby resolving the decision-making contradiction between resource scheduling and business assurance in traditional solutions.

[0111] In the unified management method for government cloud provided in this application embodiment, a unified access gateway integrates multi-source service requests, supports centralized access for instant messaging, lightweight services, and intelligent service modules, and improves terminal compatibility and service coverage. A dynamic routing strategy generated based on user permissions and real-time resource status enables precise matching of service requests and cloud node resources, ensuring both compliance of operation permissions and avoiding resource overload, thus ensuring service continuity. By aggregating response results and cloud infrastructure data to generate operation and maintenance decision instructions, the API scheduling engine is driven to execute resource operations, forming a data-driven closed-loop management mechanism. This improves the accuracy of resource scheduling and the efficiency of operation and maintenance response, thereby enhancing cross-platform collaboration efficiency.

[0112] Optionally, the above-mentioned driver API scheduling engine performs the corresponding resource operations, including the following steps P1 to P3: Step P1: When the business continuity assurance identifier is set to the livelihood assurance mode, initiate the hot standby node switching process and generate a node group identifier.

[0113] In this application's embodiments, the livelihood security model covers key services closely related to people's daily lives. Examples include "the disbursement of urban and rural residents' old-age insurance benefits" and "the public announcement of the allocation results for compulsory education school places."

[0114] For example, when the primary node response delay is detected to be more than 1.5 seconds, the hot standby node switching process is immediately initiated. First, the status of the hot standby node (such as CPU utilization, memory usage, and data synchronization with the primary node) is checked. After confirming that the hot standby node is available, a node group identifier is generated.

[0115] The node identifier includes the service type, date, and primary / backup identifier, and is used to uniquely identify the group of primary and backup nodes.

[0116] Step P2: Call the cloud resource API to perform resource operations, injecting security handling level parameters and node group identifiers.

[0117] In one example, when calling the "Cloud Server Expansion API", the parameter node group identifier (such as business type, date and primary / backup identifier, security handling level (such as level three), and the number of CPU cores after expansion) needs to be passed in. After receiving the parameters, the API will automatically locate the primary and backup nodes of the node group, perform the expansion operation, and enable level one security handling measures (such as real-time encrypted data transmission and restriction of abnormal IP access).

[0118] In another example, when calling the "Database Backup API", the node group identifier, security level (such as level 2), and backup frequency are injected. After receiving the parameters, the API performs the backup according to the parameters and stores the backup file in an encrypted storage space.

[0119] Step P3: Capture the operation status of resource operations in real time and generate traceable execution records.

[0120] The traceable execution records include resource fingerprints and security audit events.

[0121] For example, a resource fingerprint is a feature information used to uniquely identify the state of a resource, including the node's unique hardware identifier, the hash value of the current configuration, and a comparison of the configuration before and after the operation.

[0122] For example, unique hardware identifiers: server serial number, motherboard model; hash value of current configuration: a string calculated from configuration information such as CPU core count, memory capacity, disk size; configuration comparison before and after operation: 8 CPU cores before expansion, 16 CPU cores after expansion.

[0123] For example, a security audit event is log information that records the entire process of a resource operation, including the operation time, operator identification, operation type, operation result, and the scope of sensitive data involved in the operation.

[0124] For example, the operation time is: 08:30:25 on XX / XX / XXXX; the operator is identified as either an automatic system operation or a manual operation; the operation type is: node expansion, data backup, or IP blocking; the operation result is: success or failure; the scope of sensitive data involved in the operation is: XXXX medical insurance settlement records.

[0125] In this way, this application triggers hot standby switching and security parameter injection through the livelihood security model, and with the generation of traceable execution records, forms a complete closed loop of "decision-execution-feedback" to ensure the continuous availability of key livelihood services.

[0126] Optionally, the aforementioned cloud infrastructure data includes business service status data. Obtaining the aforementioned business service status data may include the following steps Q1 to Q4: Step Q1: Receive cross-platform business data streams at the data exchange layer, extract government business feature tags, and perform data standardization transformation.

[0127] In this embodiment of the application, the cross-platform business data flow can come from multiple government systems.

[0128] For example, the "pension insurance payment record" in the human resources and social security system (such as "insured person ID, payment month, payment amount, payment method"); the "outpatient reimbursement details" in the medical insurance system (such as "reimbursement ID, hospital visited, reimbursement amount, reimbursement item"); and the "individual income tax declaration data" in the tax system (such as "taxpayer ID, declaration period, taxable income, tax paid").

[0129] In this embodiment of the application, government service feature tags are used to reflect the service type and attributes. For example, “pension-payment-monthly-individual”; “medical insurance-reimbursement-outpatient-urban employee”; “individual income tax-declaration-annual-flexible employment”.

[0130] In the embodiments of this application, data standardization conversion refers to converting data into a unified format. For example, the date format is unified to "YYYY-MM-DD" (e.g., "2024 / 03 / 05" is converted to "2024-03-05"); the monetary unit is unified to "yuan" (e.g., "3000 jiao" is converted to "300 yuan").

[0131] Step Q2: Inject traceability identifiers into the transformed data to generate a unified data entity.

[0132] In this embodiment of the application, the traceability identifier includes data security level, business source system, and government business characteristic label.

[0133] For example, data security classification is used to determine secure storage strategies. Data security classification can be divided into multiple levels: "Top Secret" data includes unpublished social security fund adjustment plans, draft major tax policies, etc., which are accessible to personnel with level 3 or higher access; "Confidential" data includes individual social security payment details, original data of enterprise value-added tax declarations, etc., which are accessible to personnel with level 2 or higher access; "Secret" data includes basic information on enterprise business registration, types of real estate registration for citizens, etc., which are accessible to personnel with level 1 or higher access; "Public" data includes government service guides, ranges of social security payment bases, etc., which are accessible anonymously.

[0134] For example, the business source system is used to associate resource allocation strategies. The business source system refers to the source system that generates business data, such as the "Provincial Human Resources and Social Security Department Core Business System" or the "Municipal Tax Bureau Collection and Management System".

[0135] In this application embodiment, different source systems correspond to different resource allocation weights. Provincial systems have a wide business coverage and large data volume, so the resource allocation weight can be 0.6, municipal systems can be 0.3, and district systems can be 0.1.

[0136] Step Q3: Synchronize the unified data entity to the target business system and trigger the corresponding service status update based on the government business characteristic tags.

[0137] In one example, a unified data entity labeled “pension-contribution-year-individual” can be synchronized to the “social security benefits calculation system”. Then, based on this label, the status update of the “individual pension insurance contribution years statistics” service can be triggered to calculate whether each insured person’s cumulative contribution years have reached 15 years and mark those who have not met the standard.

[0138] In another example, a unified data entity labeled "medical insurance-reimbursement-hospitalization-urban and rural residents" can be synchronized to the "medical insurance fund monitoring system". Then, the status update of the "hospitalization reimbursement ratio compliance check" service can be triggered based on the label to check whether the reimbursement ratio complies with the urban and rural residents' medical insurance policy and mark abnormal reimbursement records.

[0139] Step Q4: Capture the state change event stream generated by the service state update and extract key performance indicators as business service state data.

[0140] In this application embodiment, key performance indicators include service response latency, transaction processing success rate, and system backlog.

[0141] For example, service response latency refers to the complete time interval from when a user initiates a business request to when the system returns a processing result.

[0142] For example, if an insured person queries their "cumulative years of contribution" in the "Social Security Benefits Calculation System", and the time interval from clicking the "Query" button to the page displaying "cumulative years and months of contribution" is 180 milliseconds, then the service response delay is 180 milliseconds.

[0143] For example, if a company submits a "hospitalization reimbursement review" request in the "medical insurance fund monitoring system" and the time interval between submission and receiving the "review approved" feedback is 3 seconds, then the service response delay is 3 seconds.

[0144] For example, transaction success rate refers to the proportion of successfully completed business requests out of the total number of requests.

[0145] For example, if the "Social Security Benefits Calculation System" receives 10,000 "Cumulative Contribution Years Inquiry" requests in a day, of which 9,980 successfully return results and 20 fail due to "Insured Person ID does not exist", the transaction processing success rate is 99.8%.

[0146] For example, if the "Medical Insurance Fund Monitoring System" receives 5,000 "Inpatient Reimbursement Review" requests, 4,900 will be approved or rejected, and 100 will fail due to "unclear uploaded inpatient medical records", then the transaction processing success rate is 98%.

[0147] For example, the system backlog refers to the number of business requests that are waiting to be processed, reflecting the real-time processing pressure of the system. The number of requests waiting to be processed in the request queue can be counted periodically (e.g., every 5 seconds) to generate a backlog curve.

[0148] For example, the peak backlog of requests in the "Social Security Benefits Calculation System" is 200 from the 1st to the 5th of each month, and 50 on weekdays; the peak backlog of requests in the "Medical Insurance Fund Monitoring System" is 150 from 9:00 to 11:00 am on weekdays, and 30 in the afternoon.

[0149] Thus, this application utilizes feature-label-driven status update rules and standardized indicator extraction to achieve accurate perception of government business status, providing real-time and effective business layer data support for operation and maintenance decisions.

[0150] The above primarily describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, the government cloud unified management system or electronic device includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0151] This application embodiment can, based on the above method, exemplarily divide a unified government cloud management system or electronic device into functional modules. For example, the unified government cloud management system or electronic device may include functional modules corresponding to each functional division, or two or more functions may be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division; in actual implementation, there may be other division methods.

[0152] Figure 2 This is a structural diagram of a unified government cloud management system provided in an embodiment of this application. The unified government cloud management system 200 includes: a receiving unit 201, an output unit 202, and a generating unit 203.

[0153] The system comprises: a receiving unit 201, used to receive multi-source service requests from a mobile government terminal cluster via a unified access gateway; the mobile government terminal cluster includes an instant messaging module, a lightweight service module, and an intelligent service module; an output unit 202, used to distribute multi-source service requests to target cloud nodes based on a dynamic routing strategy; the dynamic routing strategy is generated according to user permissions and real-time resource load status; the multi-source service requests are used to instruct the target cloud nodes to perform corresponding resource operations and generate response results; and a generation unit 203, used to aggregate response results and cloud infrastructure data to generate operation and maintenance decision instructions; these instructions drive the API scheduling engine to perform corresponding resource operations.

[0154] In some embodiments, the unified government cloud management system improved by this application further includes: a construction unit, used to construct a mapping model based on organizational structure relationships before distributing service requests to target cloud nodes based on dynamic routing strategies, the mapping model being used to represent the mapping relationship between role identifiers and cloud resource operations; the aforementioned generation unit 203 is also used to input the current user's role identifier into the mapping model to generate encrypted access credentials.

[0155] In some embodiments, the output unit 202 is specifically used to: distribute multi-source service requests to the target cloud node based on a dynamic routing strategy when the scope of the encrypted access credentials includes resource operations corresponding to multi-source service requests.

[0156] In some embodiments, the output unit 202 is specifically used to: parse the government affairs scenario identifier in the multi-source service request and match it with the business rule base to obtain routing policy parameters, the routing policy parameters including business priority, data sensitivity level and resource quota requirements; select the target cloud node and generate node routing instructions according to the routing policy parameters, combined with real-time resource load status and security isolation rules; and execute the node routing instructions through the distributed routing component of the unified access gateway to distribute the multi-source service request to the target cloud node.

[0157] In some embodiments, the generation unit 203 is specifically used to: extract a multi-dimensional feature set from aggregated data, the aggregated data including response results and cloud infrastructure data, the multi-dimensional feature set including resource load trend features, security threat pattern features and key features of business scenarios; match the decision vector corresponding to the multi-dimensional feature set from the government cloud operation and maintenance rule base, and generate operation and maintenance decision instructions, the operation and maintenance decision instructions including resource operation type and parameters, and security handling level parameters mapped to the business continuity assurance identifier.

[0158] In some embodiments, the unified government cloud management system improved in this application further includes: an execution unit, configured to: initiate a hot standby node switching process and generate a node group identifier when the business continuity assurance identifier is in the livelihood assurance mode; call the cloud resource API to perform resource operations, and inject security handling level parameters and node group identifiers; the above-mentioned generation unit 203 is also configured to capture the operation status of resource operations in real time and generate traceable execution records, the traceable execution records including resource fingerprints and security audit events.

[0159] In some embodiments, the cloud infrastructure data includes business service status data. The receiving unit 201 is further configured to receive cross-platform business data streams at the data exchange layer, extract government business feature tags, and perform data standardization transformation. The execution unit is further configured to inject traceability identifiers into the transformed data to generate a unified data entity. The traceability identifiers include data security level, business source system, and government business feature tags. The data security level is used to determine the secure storage strategy, and the business source system is used to associate resource allocation strategies. The output unit 202 is further configured to synchronize the unified data entity to the target business system and trigger corresponding service status updates based on the government business feature tags. The execution unit is further configured to capture the status change event stream generated by the service status update and extract key performance indicators as business service status data. The key performance indicators include service response latency, transaction processing success rate, and system backlog.

[0160] In the unified government cloud management system provided in this application embodiment, multi-source service requests are integrated through a unified access gateway, supporting centralized access for instant messaging, lightweight services, and intelligent service modules, thereby improving terminal compatibility and service coverage. Dynamic routing strategies generated based on user permissions and real-time resource status enable precise matching of service requests with cloud node resources, ensuring compliance of operational permissions while avoiding resource overload and ensuring service continuity. By aggregating response results and cloud infrastructure data to generate operation and maintenance decision instructions, the API scheduling engine is driven to execute resource operations, forming a data-driven closed-loop management mechanism. This improves the accuracy of resource scheduling and the efficiency of operation and maintenance response, thereby enhancing cross-platform collaboration efficiency.

[0161] Regarding the system in the above embodiments, the specific manner in which each unit performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.

[0162] Figure 3 This is a structural diagram of an electronic device provided in an embodiment of this application. Figure 3 As shown, the electronic device 300 includes, but is not limited to, a processor 301 and a memory 302.

[0163] The aforementioned memory 302 is used to store the executable instructions of the aforementioned processor 301. It is understood that the aforementioned processor 301 is configured to execute instructions to implement the unified management method for government cloud in the above embodiments.

[0164] It should be noted that those skilled in the art will understand that Figure 3 The electronic device structure shown does not constitute a limitation on the electronic device; the electronic device may include, but is not limited to, other electronic devices. Figure 3 This may indicate more or fewer components, or combinations of certain components, or different component arrangements.

[0165] Processor 301 is the control center of the electronic device. It connects various parts of the electronic device via various interfaces and lines. By running or executing software programs and / or modules stored in memory 302, and by calling data stored in memory 302, it performs various functions and processes data, thereby providing overall monitoring of the electronic device. Processor 301 may include one or more processing units. Optionally, processor 301 may integrate an application processor and a modem processor. The application processor mainly handles the operating system, user interface, and applications, while the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into processor 301.

[0166] The memory 302 can be used to store software programs and various data. The memory 302 may mainly include a program storage area and a data storage area, wherein the program storage area may store the operating system, application programs required by at least one functional module (such as a determination unit, a processing unit, etc.), etc. In addition, the memory 302 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0167] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory 302 including instructions, which can be executed by a processor 301 of an electronic device 300 to implement the unified management method for government cloud in the above embodiments.

[0168] In actual implementation, Figure 2 The steps performed by the receiving unit 201, the output unit 202, and the generating unit 203 can all be performed by... Figure 3 The processor 301 calls the computer program stored in the memory 302 to implement the process. The specific execution process can be found in the method section of the previous embodiment, and will not be repeated here.

[0169] Optionally, the computer-readable storage medium may be a non-transitory computer-readable storage medium, such as a read-only memory (ROM), random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device.

[0170] In an exemplary embodiment, this application also provides a computer program product including one or more instructions, which can be executed by the processor 301 of an electronic device to complete the unified management method of government cloud in the above embodiments.

[0171] It should be noted that when one or more instructions in the computer-readable storage medium or computer program product are executed by the processor of an electronic device, they implement the various processes of the above method embodiments and achieve the same technical effect as the above method. To avoid repetition, they will not be described again here.

[0172] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0173] In the embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection of systems or units may be electrical, mechanical, or other forms.

[0174] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the classified units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0175] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0176] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, essentially, or the part that contributes to the prior art, or a complete or partial classification of the technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0177] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A unified management method for government cloud platforms, characterized in that, include: The system receives multi-source service requests from a mobile government affairs terminal cluster via a unified access gateway. The mobile government affairs terminal cluster includes an instant messaging module, a lightweight service module, and an intelligent service module. The multi-source service requests are distributed to the target cloud node based on a dynamic routing strategy. The dynamic routing strategy is generated according to user permissions and real-time resource load status. The multi-source service requests are used to instruct the target cloud node to perform corresponding resource operations and generate response results. The response results and cloud infrastructure data are aggregated to generate operation and maintenance decision instructions, which are used to drive the application programming interface (API) scheduling engine to execute corresponding resource operations.

2. The unified management method for government cloud as described in claim 1, characterized in that, Before distributing the service request to the target cloud node based on the dynamic routing strategy, the method further includes: A mapping model is constructed based on organizational structure relationships. This mapping model is used to represent the mapping relationship between role identification and cloud resource operations. Input the current user's role identifier into the mapping model to generate encrypted access credentials.

3. The unified management method for government cloud as described in claim 2, characterized in that, The distribution of the multi-source service requests to the target cloud node based on the dynamic routing strategy includes: When the scope of the encrypted access credentials includes the resource operations corresponding to the multi-source service request, the multi-source service request is distributed to the target cloud node based on a dynamic routing strategy.

4. The unified management method for government cloud as described in claim 1 or 3, characterized in that, The distribution of the multi-source service requests to the target cloud node based on the dynamic routing strategy includes: The government affairs scenario identifier in the multi-source service request is parsed and matched with the business rule base to obtain routing strategy parameters, which include business priority, data sensitivity level and resource quota requirements; Based on the routing policy parameters, combined with the real-time resource load status and security isolation rules, the target cloud node is selected and a node routing instruction is generated; The node routing instructions are executed by the distributed routing component of the unified access gateway to distribute the multi-source service request to the target cloud node.

5. The unified management method for government cloud as described in claim 1, characterized in that, The aggregation of the response results and cloud infrastructure data generates operation and maintenance decision instructions, including: Extract a multidimensional feature set from the aggregated data, which includes the response results and the cloud infrastructure data. The multidimensional feature set includes resource load trend features, security threat pattern features, and key features of business scenarios. The decision vector corresponding to the multi-dimensional feature set is matched from the government cloud operation and maintenance rule base to generate the operation and maintenance decision instruction. The operation and maintenance decision instruction includes resource operation type and parameters, as well as security handling level parameters mapped to the business continuity assurance identifier.

6. The unified management method for government cloud as described in claim 5, characterized in that, The driver API scheduling engine executes the corresponding resource operations, including: When the business continuity assurance identifier is set to the livelihood assurance mode, the hot standby node switching process is initiated and a node group identifier is generated. Call the cloud resource API to perform resource operations, injecting the security handling level parameters and the node group identifier; The operation status of the resource operation is captured in real time, and a traceable execution record is generated, which includes resource fingerprints and security audit events.

7. The unified management method for government cloud as described in claim 1, characterized in that, The cloud infrastructure data includes business service status data, and the acquisition of the business service status data includes: The data exchange layer receives cross-platform business data streams, extracts government business feature tags, and performs data standardization transformation. A traceability identifier is injected into the transformed data to generate a unified data entity. The traceability identifier includes a data security level, a business source system, and a government business characteristic tag. The data security level is used to determine the secure storage strategy, and the business source system is used to associate resource allocation strategy. The unified data entity is synchronized to the target business system, and the corresponding service status update is triggered based on the government business feature tags. The state change event stream generated by the service state update is captured, and key performance indicators are extracted as the business service state data. The key performance indicators include service response latency, transaction processing success rate, and system backlog.

8. A unified management system for government cloud, characterized in that, The system includes: The receiving unit is used to receive multi-source service requests from a mobile government terminal cluster through a unified access gateway. The mobile government terminal cluster includes an instant messaging module, a lightweight service module, and an intelligent service module. The output unit is used to distribute the multi-source service request to the target cloud node based on a dynamic routing strategy. The dynamic routing strategy is generated according to user permissions and real-time resource load status. The multi-source service request is used to instruct the target cloud node to perform corresponding resource operations to generate a response result. The generation unit is used to aggregate the response results and cloud infrastructure data to generate operation and maintenance decision instructions, which are used to drive the application programming interface (API) scheduling engine to execute corresponding resource operations.

9. An electronic device, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the unified management method for government cloud as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing instructions, characterized in that, When the computer executes the instruction, the computer performs the unified management method for government cloud as described in any one of claims 1 to 7.