Resource processing method and apparatus, and electronic device
By acquiring and verifying the target computing power usage behavior and credentials in computing power resource requests in a multi-cluster environment, the problem of computing power resource abuse is solved, and resource management and task execution efficiency are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING BAIDU NETCOM SCI & TECH CO LTD
- Filing Date
- 2026-03-19
- Publication Date
- 2026-07-31
AI Technical Summary
In multi-cluster environments, the scheduling and access control schemes for computing resources suffer from the problem of computing resource abuse, which affects management and task execution efficiency.
By obtaining the target computing power usage behavior and computing power usage credentials in the computing power resource request, and performing verification processing, the trusted computing power usage behavior in the task running environment is ensured, and resource abuse is avoided.
It improves the efficiency of computing resource management and task execution, prevents resource abuse, and ensures the legal and compliant use of computing resources in the task execution environment.
Smart Images

Figure CN122489253A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of artificial intelligence technology, particularly to the fields of deep learning, cloud computing, and large models, and especially to a resource processing method, apparatus, and electronic device. Background Technology
[0002] Currently, in multi-cluster environments, the main scheme for scheduling and access control of computing resources is to allocate computing resources to specific tasks. During the task startup phase, the task undergoes identity verification and computing resource permission checks; during the task execution phase, the computing resources allocated to the task are used directly.
[0003] In the above scheme, during the task execution process, there may be situations where the computing resources of other tasks are encroached upon, or the computing resources are encroached upon by other tasks, which leads to the abuse of computing resources, affects the efficiency of computing resource management, and affects the efficiency of task execution. Summary of the Invention
[0004] This disclosure provides a resource processing method, apparatus, and electronic device.
[0005] According to one aspect of this disclosure, a resource processing method is provided, the method comprising: obtaining a computing power resource request; the computing power resource request comprising: a target computing power usage behavior and a computing power usage credential; the computing power usage credential being a computing power usage credential of a task runtime environment to which the target computing power usage behavior belongs, used to indicate a trusted computing power usage behavior in the task runtime environment; verifying the target computing power usage behavior based on the computing power usage credential to obtain a request verification result; and responding to the computing power resource request based on the request verification result.
[0006] According to another aspect of this disclosure, a resource processing apparatus is provided, the apparatus comprising: a first acquisition module, configured to acquire a computing power resource request; the computing power resource request including: a target computing power usage behavior and a computing power usage credential; the computing power usage credential is a computing power usage credential of a task runtime environment to which the target computing power usage behavior belongs, used to indicate a trusted computing power usage behavior in the task runtime environment; a first verification module, configured to verify the target computing power usage behavior based on the computing power usage credential, and acquire a request verification result; and a response processing module, configured to respond to the computing power resource request based on the request verification result.
[0007] According to another aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the resource processing method proposed above in this disclosure.
[0008] According to another aspect of this disclosure, a non-transitory computer-readable storage medium is provided that stores computer instructions for causing a computer to perform the resource processing methods proposed in this disclosure above.
[0009] According to another aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the resource processing method described above.
[0010] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0011] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:
[0012] Figure 1 This is a schematic diagram based on the first embodiment of the present disclosure; Figure 2 This is a schematic diagram according to the second embodiment of the present disclosure; Figure 3 This is a schematic diagram according to the third embodiment of the present disclosure; Figure 4 This is a schematic diagram according to the fourth embodiment of the present disclosure; Figure 5 This is a schematic diagram according to the fifth embodiment of the present disclosure; Figure 6 This is a block diagram of an electronic device used to implement the resource processing method of the embodiments of this disclosure. Detailed Implementation
[0013] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0014] Currently, in multi-cluster environments, the main scheme for scheduling and access control of computing resources is to allocate computing resources to specific tasks. During the task startup phase, the task undergoes identity verification and computing resource permission checks; during the task execution phase, the computing resources allocated to the task are used directly.
[0015] In the above scheme, during the task execution process, there may be situations where the computing resources of other tasks are encroached upon, or the computing resources are encroached upon by other tasks, which leads to the abuse of computing resources, affects the efficiency of computing resource management, and affects the efficiency of task execution.
[0016] To address the aforementioned problems, this disclosure proposes a resource processing method, apparatus, and electronic device.
[0017] Figure 1 This is a schematic diagram based on the first embodiment of the present disclosure. It should be noted that the resource processing method of the present disclosure can be applied to a resource processing device, which can be configured in an electronic device so that the electronic device can perform resource processing functions.
[0018] Among them, electronic devices can be any device with computing capabilities, such as personal computers (PCs), mobile terminals, servers, clusters, multi-cluster computing environments, etc. Mobile terminals can be, for example, in-vehicle devices, mobile phones, tablets, personal digital assistants, wearable devices, smart speakers, and other hardware devices with various operating systems.
[0019] The resource processing device can also be software within an electronic device, such as resource processing software. In the following embodiments, an electronic device is used as an example for illustration.
[0020] like Figure 1 As shown, the resource processing method may include the following steps: Step 101: Obtain a computing power resource request; the computing power resource request includes: the target computing power usage behavior and the computing power usage certificate; the computing power usage certificate is the computing power usage certificate of the task running environment to which the target computing power usage behavior belongs, and is used to indicate the trusted computing power usage behavior in the task running environment.
[0021] In this embodiment of the disclosure, the process of the electronic device performing step 101 can be, for example, obtaining a computing resource request at at least one set verification trigger point. The electronic device may be located in a multi-cluster, multi-tenant, or heterogeneous computing environment. In one example, at least one node in the computing environment may be equipped with a request monitoring module. This request monitoring module is used to monitor computing resource requests at at least one verification trigger point and provide the monitored computing resource requests to the electronic device. In another example, at least one node in the computing environment, upon receiving a computing resource request at at least one verification trigger point, provides the received computing resource request to the electronic device.
[0022] The verification trigger point can be understood as the timing that triggers the provision of the acquired computing resource request to the electronic device. The verification trigger point may include at least one of the following: during computing resource initialization, during task scheduling, when the heartbeat cycle for computing resource invocation arrives, or when the specified resource invocation interface is invoked.
[0023] In multi-tenancy, a tenant refers to a user, team, or application in a shared computing environment. Tenants can be defined using at least one of the following elements: resource quotas, network policies, authentication and authorization policies, etc.
[0024] In this context, heterogeneity in a computing environment refers to different types of devices used for computation. These different types of devices include, for example, a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), and a Neural Processing Unit (NPU).
[0025] In this embodiment of the disclosure, the target computing power usage behavior can be represented by at least one of the following: runtime computing power fingerprint, task identity, and the time point in time of occurrence of the target computing power usage behavior. The runtime computing power fingerprint can be the fingerprint information of the computing power resources involved in the target computing power usage behavior. The runtime computing power fingerprint can be determined based on at least one of the following: the device identifier of the device to which the computing power resource belongs, the cluster identifier of the cluster to which it belongs, and the runtime context information of the computing power resource. The runtime computing power fingerprint can be obtained by concatenating and hashing the above at least one of the following.
[0026] The computing resource runtime context information may include at least one of the following: container identifier, pod identifier, runtime window, resource quota information, etc. There are no specific limitations here, and it can be set according to actual needs.
[0027] The target computing power usage behavior can be shown in the following formula (1).
[0028] (1) in, Indicates the target computing power usage behavior; Represents runtime computing power fingerprint; Indicates the mission identity; This indicates the point in time when the target computing power usage behavior occurs.
[0029] The runtime computing power fingerprint can be, for example, as shown in the following formula (2).
[0030] (2) in, The device identifier that indicates the equipment to which the computing resources belong; The cluster identifier that represents the cluster to which it belongs; This indicates the runtime context information of computing resources; Represents a secure hash function; This indicates a concatenation character.
[0031] In this embodiment of the disclosure, the computing power usage credential may include: credential declaration content and trusted proof. The credential declaration content may include at least one of the following: task identity, a set of computing power fingerprints bound to the task identity, credential effective time point, credential expiration time point, and a computing power usage policy summary.
[0032] The computing power usage policy summary is a summary obtained by generating a summary of the computing power usage policies for the computing power resource set corresponding to the computing power fingerprint set. The computing power usage policy indicates the usage rights of the computing power resources in the computing power resource set.
[0033] The computing power fingerprint set can include the basic computing power fingerprint of each computing power resource in the computing power resource set. The basic computing power fingerprint can be determined based on at least one of the following: the device identifier of the device to which the computing power resource belongs, the cluster identifier of the cluster to which it belongs, the computing power resource type, and the attribute information of the device to which it belongs.
[0034] The device's attribute information, such as the device serial number, the device's universal unique identifier, and the motherboard identifier, is not specifically limited here and can be set according to actual needs.
[0035] The basic computing power fingerprint can be represented by the following formula (3).
[0036] (3) in, Indicates the type of computing resources; This indicates the attribute information of the device to which it belongs.
[0037] One method for obtaining a trusted proof is to perform a hash operation on the credential declaration content to obtain a declaration content digest; and then use the cluster trust root of the cluster to sign the declaration content digest to obtain a trusted proof.
[0038] The content of the certificate declaration can be, for example, as shown in the following formula (4).
[0039] (4) in, This indicates the content of the certificate declaration; This represents a set of computing power fingerprints that are associated with the task identity. Indicates the effective date of the certificate; Indicates the time point when the voucher expires; This represents a summary of the computing power usage strategy.
[0040] The process of determining the credible proof can be shown in the following formula (5).
[0041] (5) in, This indicates a signature operation performed by the cluster's root of trust. This indicates a credible proof.
[0042] Step 102: Verify the target computing power usage behavior based on the computing power usage certificate and obtain the request verification result.
[0043] In this embodiment of the disclosure, the process of the electronic device performing step 102 may be as follows: determining the target parameter content of the parameter item to be verified based on the target computing power usage behavior; determining the reference parameter content of the parameter item to be verified based on the computing power usage certificate; and determining the requested verification result based on the target parameter content and the reference parameter content of the parameter item to be verified.
[0044] The parameters to be verified include at least one of the following: computing power fingerprint, task identity, computing power usage policy, and effective time. Verification processing is performed based on at least one of these parameters, allowing for selection according to actual needs and thus improving verification flexibility.
[0045] Among them, the computing power usage certificate indicates the trusted computing power usage behavior in the task running environment; the reference parameter content on the parameter to be verified is the trusted parameter content; based on the target parameter content and the reference parameter content on the parameter to be verified, the obtained request verification result can indicate whether the target computing power usage behavior is a trusted computing power usage behavior, thereby improving the verification accuracy of the target computing power usage behavior.
[0046] In this embodiment of the disclosure, when the parameters to be verified include a computing power fingerprint and a task identity, the target parameter content of the computing power fingerprint is the runtime computing power fingerprint; the reference parameter content of the computing power fingerprint is at least one reference base computing power fingerprint; the target parameter content of the task identity is the target task identity; and the reference parameter content of the task identity is the reference task identity. Correspondingly, the electronic device can perform step 102 as follows: if the target task identity and the reference task identity are consistent, and at least one reference base computing power fingerprint includes a reference base computing power fingerprint that matches the runtime computing power fingerprint, the verification request result is determined to be successful; if the target task identity and the reference task identity are inconsistent, or if at least one reference base computing power fingerprint does not include a reference base computing power fingerprint that matches the runtime computing power fingerprint, the verification request result is determined to be unsuccessful.
[0047] The matching of runtime computing power fingerprint and reference basic computing power fingerprint can mean that the device identifier determined based on the runtime computing power fingerprint is consistent with the device identifier determined based on the reference basic computing power fingerprint; and / or that the cluster identifier determined based on the runtime computing power fingerprint is consistent with the cluster identifier determined based on the reference basic computing power fingerprint.
[0048] The authentication process based on task identity and computing power fingerprint can combine the binding relationship between task identity and computing power fingerprint set to ensure that there is a binding relationship between the target task identity involved in the target computing power usage behavior and the runtime computing power fingerprint. This allows for the use of a small number of parameters to be verified while ensuring the accuracy of the verification result, thereby improving the verification speed.
[0049] Step 103: Response processing of computing resource requests based on request verification results.
[0050] In one embodiment of this disclosure, the computing resource request can be a request received by an electronic device. Correspondingly, the electronic device executing step 103 can, for example, involve: if the request verification result is successful, acquiring the computing resources provided by the request; processing the computing resources as a response result; and if the request verification result is unsuccessful, returning an empty response result or a response result including a preset symbol. The preset symbol can indicate that the verification failed.
[0051] In another example, the computing resource request can be a request provided by other nodes to the electronic device. Correspondingly, the electronic device performing step 103 could, for example, return the request verification result to other nodes, allowing them to respond to the computing resource request based on the verification result.
[0052] The resource processing method of this disclosure embodiment obtains a computing power resource request. The computing power resource request includes a target computing power usage behavior and a computing power usage certificate. The computing power usage certificate is a computing power usage certificate of the task execution environment to which the target computing power usage behavior belongs, used to indicate the trusted computing power usage behavior in the task execution environment. The target computing power usage behavior is verified based on the computing power usage certificate to obtain a request verification result. The computing power resource request is responded to based on the request verification result. The method of verifying the target computing power usage behavior in the computing power resource request based on the computing power usage certificate can realize the verification of the computing power resource request obtained in real time during the task execution phase, thereby avoiding the abuse of computing power resources, improving the efficiency of computing power resource management and utilization, and improving the efficiency of task execution.
[0053] To ensure that computing resource requests are accompanied by computing power usage credentials, and to verify these credentials, thereby guaranteeing that all computing resource requests within the task execution environment are validated and processed, and further improving computing resource management efficiency, electronic devices can generate computing power usage credentials for each created model task. For example... Figure 2 As shown, Figure 2 This is a schematic diagram based on the second embodiment of the present disclosure. Figure 2 The illustrated embodiment may include the following steps: Step 201: Obtain the model task and computing resource set; the computing resources in the computing resource set are the computing resources allocated to the model task.
[0054] In this embodiment, the model task and the set of computing resources can be obtained from a server or electronic device responsible for scheduling computing resources in the computing environment. The computing resources can be schedulable resource instances in the computing environment. The computing resources can be represented by the following information: resource type, resource instance identifier, belonging node, resource capacity attribute, etc., without specific limitations, and can be set according to actual needs. Resource types include, for example, CPU, GPU, NPU, etc. The number of computing resources in the set can be one or more.
[0055] Step 202: Determine the task identity and computing power fingerprint set of the model task; the computing power fingerprint set includes the basic computing power fingerprint of the computing power resources in the computing power resource set.
[0056] In this embodiment of the disclosure, the process by which the electronic device determines the task identity of the model task may, for example, involve obtaining at least one of the following elements related to the model task: tenant identifier, model identifier, task instance identifier, time element, and random disturbance element; and determining the task identity of the model task based on the above at least one element.
[0057] The tenant identifier is the identifier of the tenant who rents computing resources in the computing environment to execute model tasks. The task instance identifier is the instance identifier assigned to different model tasks within the same model, used to distinguish different model tasks within the same model. The time element is the time point when the model task is created, or the time point when the task identity generation process is performed. The setting of the time element is to ensure the uniqueness of each task identity in the time dimension and to avoid the reuse of historical task identities.
[0058] The process of determining the identity of the task can be illustrated by formula (6) below.
[0059] (6) in, Indicates the mission identity; Indicates tenant identifier; Indicates model identifier; Indicates the task instance identifier; Indicates the time element; This represents random disturbance elements.
[0060] In this embodiment of the disclosure, the process of determining the computing power fingerprint set by the electronic device may be as follows: for each computing power resource in the computing power resource set, obtain at least one of the following elements of the computing power resource: the device identifier of the device to which the computing power resource belongs, the cluster identifier of the cluster to which it belongs, the type of computing power resource, and the attribute information of the device to which it belongs; perform concatenation and hash operation on the above at least one element to obtain the basic computing power fingerprint of the computing power resource; and combine the basic computing power fingerprints of each computing power resource in the computing power resource set to obtain the computing power fingerprint set.
[0061] Among them, determining the basic computing power fingerprint based on at least one of the following elements—the device identifier of the device to which the computing power resource belongs, the cluster identifier of the cluster to which it belongs, the type of computing power resource, and the attribute information of the device to which it belongs—can ensure the uniqueness of the determined basic computing power fingerprint.
[0062] Step 203: Establish the binding relationship between task identity and computing power fingerprint set.
[0063] In this embodiment of the disclosure, the binding relationship may include task identity, computing power fingerprint set, and binding effective time window. The binding effective time window can be determined based on the establishment time of the binding relationship and a preset binding duration. The start time of the binding effective time window can be the establishment time of the binding relationship.
[0064] The binding relationship can be, for example, as shown in the following formula (7).
[0065] (7) in, Indicates a binding relationship; This represents the nth computing power fingerprint; This indicates the window when the binding takes effect.
[0066] Step 204: Based on the binding relationship, generate the computing power usage certificate for the task execution environment corresponding to the model task.
[0067] In this embodiment of the disclosure, the process of the electronic device performing step 204 may include, for example, obtaining the computing power usage policy corresponding to the computing power resource set; determining the credential effective time window according to the binding effective time window in the binding relationship; and determining the computing power usage credential according to the task identity, computing power fingerprint set, computing power usage policy and credential effective time window in the binding relationship.
[0068] The process of determining the effective time window of the voucher can be shown in formulas (8) and (9) below.
[0069] (8) (9) in, Indicates the start time of the certificate's effective time window; This indicates the point in time when the computing power usage certificate was generated; Indicates the length of time; This indicates the end time of the binding effective time window.
[0070] The computing power usage credential may include: credential declaration content and a trusted proof. The credential declaration content may include at least one of the following: task identity, a set of computing power fingerprints bound to the task identity, the credential's effective date, the credential's expiration date, and a digest of the computing power usage policy. The trusted proof can be obtained, for example, by hashing the credential declaration content to obtain a declaration content digest; and by signing the declaration content digest using the cluster's root of trust to obtain the trusted proof.
[0071] Specifically, the computing power usage certificate is determined based on the task identity, computing power fingerprint set, and binding effective time window in the binding relationship. This allows the computing power usage certificate to be used to verify the target computing power usage behavior, thereby further preventing the abuse of computing power resources and improving the efficiency of computing power resource management.
[0072] In this embodiment of the disclosure, the computing power usage certificate is set with a certificate effective time window. After the computing power usage certificate is provided to the task execution environment, a certificate generation request sent by the task execution environment when the certificate expires can be received to regenerate the computing power usage certificate.
[0073] The computing power usage certificate can be determined to be invalid when it meets at least one of the following conditions: the current time is outside the certificate's effective time window; the model task corresponding to the computing power usage certificate is terminated or suspended; or the binding relationship used to generate the computing power usage certificate is revoked or updated.
[0074] Step 205: Obtain a computing power resource request; the computing power resource request includes: the target computing power usage behavior and the computing power usage certificate; the computing power usage certificate is the computing power usage certificate of the task running environment to which the target computing power usage behavior belongs, and is used to indicate the trusted computing power usage behavior in the task running environment.
[0075] Step 206: Verify the target computing power usage behavior based on the computing power usage certificate and obtain the request verification result.
[0076] Step 207: Response processing of computing resource requests based on request verification results.
[0077] It should be noted that for details of steps 205 to 207, please refer to [link / reference needed]. Figure 1 Steps 101 to 103 in the illustrated embodiment will not be described in detail here.
[0078] The resource processing method of this disclosure includes: acquiring a model task and a set of computing resources; the computing resources in the set of computing resources are those allocated to the model task; determining the task identity and a set of computing fingerprints for the model task; the set of computing fingerprints includes the basic computing fingerprints of the computing resources in the set of computing resources; establishing a binding relationship between the task identity and the set of computing fingerprints; generating a computing power usage certificate for the task runtime environment corresponding to the model task based on the binding relationship; acquiring a computing power resource request; the computing power resource request includes: a target computing power usage behavior and a computing power usage certificate; the computing power usage certificate is the computing power usage certificate of the task runtime environment to which the target computing power usage behavior belongs, used to indicate the trusted computing power usage behavior in the task runtime environment; verifying the target computing power usage behavior based on the computing power usage certificate and obtaining a request verification result; and responding to the computing power resource request based on the request verification result. The generation of computing power usage certificates for each created model task allows each computing power resource request to carry a computing power usage certificate in the request, enabling verification processing of the computing power resource request based on the computing power usage certificate, thereby further improving the efficiency of computing power resource management.
[0079] In order to verify and process cross-cluster computing resource requests, thereby ensuring that all computing resource requests in the task execution environment can be verified and processed, and further improving the efficiency of computing resource management, electronic devices can perform cluster-level verification processing for cross-cluster computing resource requests. For example... Figure 3 As shown, Figure 3 This is a schematic diagram based on the third embodiment of the present disclosure. Figure 3 The illustrated embodiment may include the following steps: Step 301: Obtain a computing power resource request; the computing power resource request includes: target computing power usage behavior and computing power usage certificate; the computing power usage certificate is the computing power usage certificate of the task running environment to which the target computing power usage behavior belongs, and is used to indicate the trusted computing power usage behavior in the task running environment.
[0080] Step 302: Determine whether the computing resource request is a cross-cluster computing resource request.
[0081] In this embodiment of the disclosure, the computing resource request may carry the cluster identifier of the cluster to which it belongs. Correspondingly, the electronic device can compare the cluster identifier carried in the computing resource request with the cluster identifier of the cluster to which it belongs, and obtain the comparison result; if the comparison result indicates that they are consistent, it is determined that the computing resource request is not a cross-cluster computing resource request, but an intra-cluster computing resource request; if the comparison result indicates that they are inconsistent, it is determined that the computing resource request is a cross-cluster computing resource request.
[0082] In cases where the computing power resource request is not a cross-cluster computing power resource request, the verification process for the target computing power usage behavior can be directly executed based on the computing power usage credentials in the computing power resource request, and the request verification result can be obtained.
[0083] Step 303: In the case of a cross-cluster computing resource request, obtain the trust statement list maintained by the first cluster to which it belongs; the trust statement list includes the trust statement of the second cluster; the trust statement indicates that the computing power usage credentials of the task running environment where the second cluster is located can be verified by the first cluster.
[0084] In this embodiment of the disclosure, the trust statement may include a cluster identifier, a cluster trust root, and a trust validity time window. Additionally, the trust statement may also include a trust scope, such as a specific type of computing resource.
[0085] In this embodiment of the disclosure, the cluster identifier can be determined based on at least one of the following elements: the identifier of the organization or management domain to which the cluster belongs; the identifier of the region where the cluster is deployed; the logical name of the cluster; a random perturbation value, etc. The cluster identifier can be determined, for example, by concatenating and hashing the above at least one element to obtain the cluster identifier.
[0086] The formula for determining the cluster identifier can be, for example, as shown in formula (10).
[0087] (10) in, Indicates the cluster identifier; An identifier representing the organization or management domain to which the cluster belongs; Indicates the identifier of the region where the cluster is deployed; The logical name representing the cluster; This represents the random perturbation value.
[0088] In this embodiment of the disclosure, the cluster trust root may include a cluster identifier and a public key. The public key may be pre-set. For a specific cluster, such as a first cluster, a cluster trust root and a trust statement may be determined; the first cluster may store the cluster trust root; the first cluster may identify other clusters that allow verification of its computing power usage credentials, and then provide its trust statement to those other clusters.
[0089] The cluster trust root can be, for example, as shown in formula (11). The trust declaration can be, for example, as shown in formula (12).
[0090] (11) (12) in, Indicates the cluster's root of trust; Represents the public key; Indicates a statement of trust; This indicates the cluster identifier of other clusters that allow this cluster to verify the credentials used to access computing power; Indicates the scope of trust; This indicates the effective time window for trust.
[0091] Step 304: Obtain the cluster identifier from the cross-cluster computing resource request.
[0092] Step 305: If the cluster identifier is included in the first trust statement in the trust statement list, verify the computing power usage credentials in the cross-cluster computing power resource request according to the cluster trust root in the first trust statement, and obtain the credentials verification result.
[0093] In this embodiment of the disclosure, the electronic device may perform step 305 as follows: hash the credential declaration content in the computing power usage credential to obtain a digest of the credential declaration content; sign the digest according to the cluster trust root in the first trust declaration to obtain a signature result; compare the signature result with the trusted proof in the computing power usage credential to obtain a comparison result; if the comparison result is consistent, determine that the credential verification result is verified successfully; if the comparison result is inconsistent, determine that the credential verification result is verified unsuccessfully.
[0094] The verification process for the computing power usage certificate can be shown in the following formula (13).
[0095] (13) in, This indicates the verification of the computing power usage certificate; This represents the cluster trust root in the first trust declaration; A summary of the certificate statement content; This indicates the verification result of a successfully verified credential.
[0096] In this embodiment of the disclosure, the electronic device may also perform the following process: if the cluster identifier is not included in any trust statement in the trust statement list, determine that the verification request result is verification failure.
[0097] In cases where the cluster identifier is not included in any trust statement in the trust statement list, it indicates that the cluster corresponding to the cluster identifier is an untrusted cluster. There is no need to process cross-cluster computing resource requests, and the request verification result can be directly determined as verification failure, thereby reducing the amount of computation when processing computing resource requests and improving the efficiency of computing resource request processing.
[0098] Step 306: If the credential verification result is "verification failed", determine that the request verification result is "verification failed".
[0099] Step 307: If the credential verification result is successful, verify the target computing power usage behavior based on the computing power usage credential and obtain the request verification result.
[0100] Step 308: Response processing of computing resource requests based on request verification results.
[0101] It should be noted that for details regarding steps 301, 307, and 308, please refer to [the relevant documentation / reference]. Figure 1 Steps 101 to 103 in the illustrated embodiment will not be described in detail here.
[0102] The resource processing method of this disclosure embodiment obtains a computing power resource request; the computing power resource request includes: a target computing power usage behavior and a computing power usage certificate; the computing power usage certificate is the computing power usage certificate of the task runtime environment to which the target computing power usage behavior belongs, used to indicate a trusted computing power usage behavior in the task runtime environment; determines whether the computing power resource request is a cross-cluster computing power resource request; if the computing power resource request is a cross-cluster computing power resource request, obtains a trust statement list maintained by the first cluster to which it belongs; the trust statement list includes a trust statement of the second cluster; the trust statement indicates that the computing power usage certificate of the task runtime environment where the second cluster is located allows verification by the first cluster; obtains the cluster identifier in the cross-cluster computing power resource request; and in the case that the cluster identifier is included in the trust statement list of the first cluster, the method further determines whether the computing power resource request is a cross-cluster computing power resource request. In the case of a trust declaration, the computing power usage credentials in the cross-cluster computing power resource request are verified based on the cluster trust root in the first trust declaration, and the credential verification result is obtained. If the credential verification result is that the verification fails, the request verification result is determined to be that the verification fails. If the credential verification result is that the verification passes, the target computing power usage behavior is verified based on the computing power usage credentials, and the request verification result is obtained. The computing power resource request is responded to based on the request verification result. Among these, performing cluster-level verification processing for cross-cluster computing power resource requests can realize the verification processing of cross-cluster computing power resource requests, thereby further ensuring that each computing power resource request in the task running environment can be verified and processed, and thus further improving the efficiency of computing power resource management.
[0103] To reduce the number of computing resource requests that fail subsequent verification, thereby further improving the processing efficiency of computing resource requests and reducing the computational load during processing, electronic devices can generate abnormal events and perform abnormal handling for computing resource requests that fail verification. For example... Figure 4 As shown, Figure 4 This is a schematic diagram based on the fourth embodiment of the present disclosure. Figure 4 The illustrated embodiment may include the following steps: Step 401: Obtain a computing power resource request; the computing power resource request includes: target computing power usage behavior and computing power usage certificate; the computing power usage certificate is the computing power usage certificate of the task running environment to which the target computing power usage behavior belongs, and is used to indicate the trusted computing power usage behavior in the task running environment.
[0104] Step 402: Verify the target computing power usage behavior based on the computing power usage certificate and obtain the request verification result.
[0105] Step 403: Response processing of computing resource requests based on request verification results.
[0106] Step 404: If the verification result is that the verification failed, obtain the reason for the failure.
[0107] Reasons for rejection include, for example, the target computing power usage behavior is not trusted computing power usage behavior, or the computing power usage certificate is invalid.
[0108] Step 405: Generate an exception event based on the target computing power usage behavior, computing power usage credentials, and reasons for failure.
[0109] In this embodiment of the disclosure, an abnormal event can be represented by at least one of the following elements: target computing power usage behavior, computing power usage certificate, reason for failure, time of occurrence of abnormal event, etc.
[0110] Among them, abnormal events can be represented by the following formula (14).
[0111] (14) in, Indicates an abnormal event; Indicates the target computing power usage behavior; This refers to the content of the certificate declaration in the computing power usage certificate; Indicates the time when the abnormal event occurred.
[0112] Step 406: Determine the exception handling strategy based on the exception event; the exception handling strategy includes: the object to be handled and the handling operation for the object to be handled.
[0113] In this embodiment of the disclosure, the process of the electronic device performing step 406 may, for example, be as follows: based on the abnormal event, determine the dimension value of at least one of the following scoring dimensions: abnormality type, resource scale of computing resources involved, and abnormality duration; determine the severity of the abnormality based on the dimension value of at least one scoring dimension; and determine the abnormality handling strategy based on the severity of the abnormality and the abnormal event.
[0114] The electronic device can determine the anomaly type based on the reason given in the abnormal event. The anomaly type can include at least one of the following: no computing power usage certificate, expired computing power usage certificate, mismatched computing power fingerprint, inconsistent task identity, unauthorized cross-cluster use, etc. No specific limitations are set here; the configuration can be tailored to actual needs.
[0115] The process of determining the severity of the abnormality can be illustrated by formula (15) below.
[0116] (15) in, Indicates the severity of the abnormality; Indicates the exception type; This indicates the scale of computing resources involved; Indicates the duration of the anomaly; , , This represents the weighting coefficient.
[0117] In this embodiment of the disclosure, the anomaly handling strategy may include at least one of the following: blocking access to computing resources, isolating computing resources, pausing model tasks, reclaiming computing resources, and issuing tenant-level or task-level alarms. The objects of handling include, for example, computing resources and model tasks. The handling operations include, for example, blocking, isolating, pausing, reclaiming, and issuing alarms.
[0118] The process by which electronic devices determine anomaly handling strategies can be, for example, as follows: obtaining computing resource operating context information; inputting the computing resource operating context information, anomaly severity, and anomaly event into the handling decision model; and obtaining the anomaly handling strategy output by the handling decision model.
[0119] The process of determining the abnormal handling strategy can be shown in the following formula (16).
[0120] (16) in, Indicates the abnormal handling strategy; This indicates the runtime context information of computing resources.
[0121] The input to the decision-making model may also include safety principles. These safety principles are the guidelines that must be followed in determining the anomaly handling strategy. Safety principles may include, for example, at least one of the following: the principle of minimum impact; the principle of rollback; and the principle of evidence priority. The principle of minimum impact, for example, affects only the anomalous entity. The principle of rollback, for example, supports the recovery of misjudgment scenarios. The principle of evidence priority, for example, secures evidence before performing destructive operations.
[0122] In this embodiment of the disclosure, to further improve the accuracy of determining the anomaly handling strategy, the electronic device can maintain an anomaly state for each model task. The anomaly state may include: the currently effective computing power usage certificate, the result of the most recent request verification, and the cumulative count of verification failures. The anomaly state can be used as input to the handling decision model to further improve the accuracy of the determined anomaly handling strategy.
[0123] Among them, the severity of an anomaly can be determined based on at least one of the following: anomaly type, the scale of computing resources involved, and anomaly duration. The severity of anomalies can be determined by combining the impact of the anomaly event, thereby improving the accuracy of the determination of the severity of anomalies and further improving the accuracy of the determination of anomaly handling strategies.
[0124] Step 407: Perform exception handling according to the exception handling strategy.
[0125] In this embodiment of the disclosure, in order to facilitate subsequent auditing and training of the handling decision model, the electronic device may also perform the following process: acquiring at least one abnormal event, as well as an abnormal handling strategy and handling time point for the abnormal event; generating an audit evidence chain based on at least one abnormal event, as well as an abnormal handling strategy and handling time point for the abnormal event, for subsequent audit processing.
[0126] Among them, the audit evidence in the audit evidence chain can be, for example, as shown in the following formula (17).
[0127] (17) in, Indicates audit evidence; Indicates an abnormal event; Indicates the abnormal handling strategy; Indicates the time point of the action.
[0128] The resource processing method of this disclosure embodiment obtains a computing power resource request. The computing power resource request includes a target computing power usage behavior and a computing power usage certificate. The computing power usage certificate is a computing power usage certificate of the task execution environment to which the target computing power usage behavior belongs, used to indicate the trusted computing power usage behavior in the task execution environment. The target computing power usage behavior is verified based on the computing power usage certificate to obtain a request verification result. The computing power resource request is responded to based on the request verification result. If the request verification result is that the verification fails, the reason for the failure is obtained. An abnormal event is generated based on the target computing power usage behavior, the computing power usage certificate, and the reason for the failure. An abnormal handling strategy is determined based on the abnormal event. The abnormal handling strategy includes a handling object and a handling operation for the handling object. An abnormal handling is performed according to the abnormal handling strategy. In this way, generating an abnormal event and performing abnormal handling for computing power resource requests that fail verification can reduce the number of subsequent computing power resource requests that fail verification, thereby further improving the processing efficiency of computing power resource requests and reducing the amount of computation when processing computing power resource requests.
[0129] To implement the above embodiments, this disclosure also provides a resource processing apparatus. For example... Figure 5 As shown, Figure 5 This is a schematic diagram according to the fifth embodiment of the present disclosure. The resource processing device 50 may include: a first acquisition module 501, a first verification module 502, and a response processing module 503.
[0130] The first acquisition module 501 is used to acquire a computing power resource request; the computing power resource request includes: a target computing power usage behavior and a computing power usage certificate; the computing power usage certificate is a computing power usage certificate of the task running environment to which the target computing power usage behavior belongs, used to indicate the trusted computing power usage behavior in the task running environment; the first verification module 502 is used to verify the target computing power usage behavior according to the computing power usage certificate and obtain a request verification result; the response processing module 503 is used to respond to the computing power resource request according to the request verification result.
[0131] As a possible implementation of this disclosure, the apparatus further includes: a second acquisition module, a first determination module, an establishment module, and a first generation module; the second acquisition module is used to acquire a model task and a set of computing power resources; the computing power resources in the set of computing power resources are computing power resources allocated to the model task; the first determination module is used to determine the task identity and a set of computing power fingerprints of the model task; the set of computing power fingerprints includes the basic computing power fingerprints of the computing power resources in the set of computing power resources; the establishment module is used to establish a binding relationship between the task identity and the set of computing power fingerprints; the first generation module is used to generate a computing power usage certificate for the task running environment corresponding to the model task based on the binding relationship.
[0132] As one possible implementation of this disclosure, the basic computing power fingerprint of the computing power resource is determined based on at least one of the following: the device identifier of the device to which it belongs, the type of computing power resource, the cluster identifier of the cluster to which it belongs, and the attribute information of the device to which it belongs.
[0133] As one possible implementation of this disclosure, the first generation module is specifically used to: obtain the computing power usage policy corresponding to the computing power resource set; determine the credential effective time window according to the binding effective time window in the binding relationship; and determine the computing power usage credential according to the task identity, computing power fingerprint set, computing power usage policy and credential effective time window in the binding relationship.
[0134] As one possible implementation of this disclosure, the first verification module 502 is specifically configured to: determine the target parameter content of the parameter item to be verified based on the target computing power usage behavior; determine the reference parameter content of the parameter item to be verified based on the computing power usage certificate; and determine the request verification result based on the target parameter content and the reference parameter content of the parameter item to be verified.
[0135] As one possible implementation of this disclosure, the parameter item to be verified includes at least one of the following: computing power fingerprint item, task identity item, computing power usage strategy item, and effective time item.
[0136] As one possible implementation of this disclosure, the parameter item to be verified includes a computing power fingerprint item and a task identity item; the target parameter content on the computing power fingerprint item is a runtime computing power fingerprint; the reference parameter content on the computing power fingerprint item is at least one reference basic computing power fingerprint; the target parameter content on the task identity item is a target task identity; the reference parameter content on the task identity item is a reference task identity; the first verification module 502 is further configured to, when the target task identity is consistent with the reference task identity and the at least one reference basic computing power fingerprint includes a reference basic computing power fingerprint that matches the runtime computing power fingerprint, determine that the request verification result is verification passed; when the target task identity is inconsistent with the reference task identity, or when the at least one reference basic computing power fingerprint does not include a reference basic computing power fingerprint that matches the runtime computing power fingerprint, determine that the request verification result is verification failed.
[0137] As a possible implementation of this disclosure, the apparatus further includes: a second determining module, a third acquiring module, a fourth acquiring module, a second verifying module, and a third determining module; the second determining module is used to determine whether the computing power resource request is a cross-cluster computing power resource request; the third acquiring module is used to acquire a trust statement list maintained by the first cluster to which the request belongs when the computing power resource request is a cross-cluster computing power resource request; the trust statement list includes a trust statement of the second cluster; the trust statement indicates that the computing power usage credentials of the task runtime environment where the second cluster is located are allowed to be verified by the first cluster; the fourth acquiring module is used to acquire the cluster identifier in the cross-cluster computing power resource request; the second verifying module is used to verify the computing power usage credentials in the cross-cluster computing power resource request according to the cluster trust root in the first trust statement when the cluster identifier is included in the first trust statement in the trust statement list, and acquire the credentials verification result; the third determining module is used to determine that the request verification result is verification failure when the credentials verification result is verification failure.
[0138] As one possible implementation of this disclosure, the apparatus further includes: a fourth determining module, configured to determine that the verification request result is verification failure if the cluster identifier is not included in any trust statement in the trust statement list.
[0139] As one possible implementation of this disclosure, the apparatus further includes: a fifth acquisition module, a second generation module, a fifth determination module, and an exception handling module; the fifth acquisition module is used to acquire a reason for failure when the request verification result is verification failure; the second generation module is used to generate an exception event based on the target computing power usage behavior, the computing power usage certificate, and the reason for failure; the fifth determination module is used to determine an exception handling strategy based on the exception event; the exception handling strategy includes: a handling object and a handling operation for the handling object; the exception handling module is used to perform exception handling according to the exception handling strategy.
[0140] As one possible implementation of this disclosure, the fifth determining module is specifically used to: determine the dimension value of at least one of the following scoring dimensions based on the abnormal event: abnormality type, resource scale of computing resources involved, and abnormality duration; determine the severity of the abnormality based on the dimension value of the at least one scoring dimension; and determine the abnormality handling strategy based on the severity of the abnormality and the abnormal event.
[0141] As one possible implementation of this disclosure, the apparatus further includes: a sixth acquisition module and a third generation module; the sixth acquisition module is configured to acquire at least one abnormal event, as well as an abnormal handling strategy and a handling time point for the abnormal event; the third generation module is configured to generate an audit evidence chain based on the at least one abnormal event, as well as the abnormal handling strategy and the handling time point for the abnormal event, for subsequent audit processing.
[0142] The resource processing apparatus of this disclosure acquires a computing power resource request. The computing power resource request includes a target computing power usage behavior and a computing power usage certificate. The computing power usage certificate is a computing power usage certificate of the task execution environment to which the target computing power usage behavior belongs, used to indicate a trusted computing power usage behavior in the task execution environment. The target computing power usage behavior is verified based on the computing power usage certificate to obtain a request verification result. The computing power resource request is responded to based on the request verification result. The verification of the target computing power usage behavior in the computing power resource request based on the computing power usage certificate enables verification of the computing power resource request acquired in real time during the task execution phase, thereby preventing the abuse of computing power resources and improving the efficiency of computing power resource management and utilization, as well as the efficiency of task execution.
[0143] In the technical solutions disclosed herein, the collection, storage, use, processing, transmission, provision, and disclosure of users' personal information are all carried out with the consent of the users, and all comply with the provisions of relevant laws and regulations, and do not violate public order and good morals.
[0144] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0145] Figure 6 A schematic block diagram of an example electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0146] like Figure 6 As shown, device 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 602 or a computer program loaded into random access memory (RAM) 603 from storage unit 608. RAM 603 may also store various programs and data required for the operation of device 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.
[0147] Multiple components in device 600 are connected to I / O interface 605, including: input unit 606, such as keyboard, mouse, etc.; output unit 607, such as various types of monitors, speakers, etc.; storage unit 608, such as disk, optical disk, etc.; and communication unit 609, such as network card, modem, wireless transceiver, etc. Communication unit 609 allows device 600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0148] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above, such as resource processing methods. For example, in some embodiments, the resource processing method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed on device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by the computing unit 601, one or more steps of the resource processing method described above may be performed. Alternatively, in other embodiments, the computing unit 601 may be configured to perform resource processing methods by any other suitable means (e.g., by means of firmware).
[0149] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0150] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0151] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0152] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0153] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0154] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.
[0155] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0156] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A resource processing method, the method comprising: Request computing resources; The computing power resource request includes: target computing power usage behavior and computing power usage certificate; the computing power usage certificate is the computing power usage certificate of the task running environment to which the target computing power usage behavior belongs, and is used to indicate the trusted computing power usage behavior in the task running environment; The target computing power usage behavior is verified based on the computing power usage certificate, and the verification result is obtained. The request for computing resources is processed in response to the verification result of the request.
2. The method according to claim 1, wherein, The method further includes: Obtain the model task and computing resource set; the computing resources in the computing resource set are the computing resources allocated to the model task; Determine the task identity and computing power fingerprint set of the model task; the computing power fingerprint set includes the basic computing power fingerprint of the computing power resources in the computing power resource set. Establish a binding relationship between the task identity and the computing power fingerprint set; Based on the binding relationship, a computing power usage certificate for the task execution environment corresponding to the model task is generated.
3. The method according to claim 2, wherein, The basic computing power fingerprint of the computing power resource is determined based on at least one of the following: the device identifier of the device to which it belongs, the type of computing power resource, the cluster identifier of the cluster to which it belongs, and the attribute information of the device to which it belongs.
4. The method according to claim 2, wherein, The step of generating a computing power usage certificate for the task execution environment corresponding to the target model task based on the binding relationship includes: Obtain the computing power utilization strategy corresponding to the set of computing power resources; The credential activation time window is determined based on the binding activation time window in the binding relationship; The computing power usage credential is determined based on the task identity, computing power fingerprint set, computing power usage policy, and credential effective time window in the binding relationship.
5. The method according to claim 1, wherein, The step of verifying the target computing power usage behavior based on the computing power usage certificate and obtaining the verification result includes: Based on the target computing power usage behavior, determine the target parameter content of the parameter item to be verified; Based on the computing power usage certificate, determine the reference parameter content on the parameter item to be verified; The verification result is determined based on the target parameter content and the reference parameter content of the parameter item to be verified.
6. The method according to claim 5, wherein, The parameters to be verified include at least one of the following: computing power fingerprint, task identity, computing power usage strategy, and effective time.
7. The method according to claim 5, wherein, The parameters to be verified include a computing power fingerprint and a task identity; the target parameter content of the computing power fingerprint is the runtime computing power fingerprint; the reference parameter content of the computing power fingerprint is at least one reference base computing power fingerprint. The target parameter content of the task identity item is the target task identity; The reference parameter content on the task identity item is the reference task identity; Determining the verification result based on the target parameter content and the reference parameter content of the parameter item to be verified includes: If the target task identity is consistent with the reference task identity, and the at least one reference basic computing power fingerprint includes a reference basic computing power fingerprint that matches the runtime computing power fingerprint, then the request verification result is determined to be verification passed. If the target task identity is inconsistent with the reference task identity, or if the at least one reference basic computing power fingerprint does not include a reference basic computing power fingerprint that matches the runtime computing power fingerprint, the request verification result is determined to be verification failure.
8. The method according to claim 1 or 5, wherein, Before verifying the target computing power usage behavior based on the computing power usage certificate and obtaining the request verification result, the method further includes: Determine whether the computing resource request is a cross-cluster computing resource request; When the computing power resource request is a cross-cluster computing power resource request, obtain the trust statement list maintained by the first cluster to which it belongs; the trust statement list includes the trust statement of the second cluster; the trust statement indicates that the computing power usage credentials of the task running environment where the second cluster is located can be verified by the first cluster; Obtain the cluster identifier from the cross-cluster computing resource request; If the cluster identifier is included in the first trust statement in the trust statement list, the computing power usage credentials in the cross-cluster computing power resource request are verified according to the cluster trust root in the first trust statement, and the credentials verification result is obtained. If the verification result of the credential is unsuccessful, it is determined that the verification result of the request is unsuccessful.
9. The method according to claim 8, wherein, The method further includes: If the cluster identifier is not included in any of the trust statements in the trust statement list, the verification result of the request is determined to be verification failure.
10. The method according to claim 1, wherein, The method further includes: If the verification result of the request is that the verification fails, obtain the reason for the failure; An exception event is generated based on the target computing power usage behavior, the computing power usage certificate, and the reason for failure; An anomaly handling strategy is determined based on the anomaly event; the anomaly handling strategy includes: the object to be handled and the handling operation for the object to be handled. Perform exception handling according to the aforementioned exception handling strategy.
11. The method according to claim 10, wherein, The step of determining the exception handling strategy based on the exception event includes: Based on the abnormal event, determine the dimensional values of at least one of the following scoring dimensions: abnormality type, resource scale of computing power resources involved, and duration of abnormality; The severity of the anomaly is determined based on the dimensional values of at least one of the rating dimensions; The anomaly handling strategy is determined based on the severity of the anomaly and the anomaly event.
12. The method according to claim 10, wherein, The method further includes: Acquire at least one abnormal event, as well as the abnormal handling strategy and handling time point for the abnormal event; Based on the at least one abnormal event, the abnormal handling strategy for the abnormal event, and the handling time point, an audit evidence chain is generated for subsequent audit processing.
13. A resource processing apparatus, the apparatus comprising: The first acquisition module is used to acquire computing resource requests; The computing power resource request includes: target computing power usage behavior and computing power usage certificate; the computing power usage certificate is the computing power usage certificate of the task running environment to which the target computing power usage behavior belongs, and is used to indicate the trusted computing power usage behavior in the task running environment; The first verification module is used to verify the target computing power usage behavior based on the computing power usage certificate and obtain the request verification result; The response processing module is used to process the computing resource request in response to the request verification result.
14. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1 to 12.
15. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1 to 12.
16. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 12.