Routing method and apparatus for edge node in server cluster, and device and medium
By deploying a trusted execution environment on edge nodes and combining network status and policy adjustment models, the security and integrity issues of edge node routing policies are resolved, and the reliability and security of network services are improved.
Patent Information
- Application Number
- PCT/CN2025/077106
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-21
- Filing Date
- 2025-02-13
- Publication Date
- 2025-09-25
AI Technical Summary
The routing strategy of edge nodes has security and integrity issues in cloud computing architecture. It is especially vulnerable to attacks in untrusted environments, resulting in unstable network services and increased latency.
A trusted execution environment (TEE) is deployed on the edge node to select and adjust the routing policy in this environment, combining the current network status and policy adjustment model to ensure the integrity and correctness of the routing policy.
It improves the reliability and security of network services, prevents potential risks caused by security vulnerabilities in edge nodes, dynamically adjusts routing strategies to adapt to changes in network status, and ensures the accuracy and security of routing strategies.
Smart Images

Figure CN2025077106_25092025_PF_FP_ABST
Abstract
Description
Routing method, device, equipment and medium for edge nodes in server cluster
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on March 21, 2024, with application number 202410330061.8 and invention name “Routing method, device, equipment and medium for edge nodes in a server cluster”, the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present disclosure relates to the field of computer technology, and in particular to a routing method, apparatus, device, and medium for edge nodes in a server cluster. Background Art
[0004] Edge computing is becoming increasingly important in cloud computing architectures, especially in the Internet of Things (IoT) and widespread network coverage applications. These applications rely on edge nodes, typically points of presence (POPs) located at the edge of user access networks, to perform critical data processing and routing decisions to reduce latency and improve user experience. Summary of the Invention
[0005] In a first aspect, the present disclosure provides a routing method for edge nodes in a server cluster, the method comprising:
[0006] Get the data to be processed and the current network status;
[0007] In a trusted execution environment, adjusting a configured routing policy based on the current network state and a policy adjustment model to determine a routing policy corresponding to the data to be processed, wherein the policy adjustment model is trained based on a sample network state and a sample routing policy;
[0008] The routing policy is executed on the data to be processed in the trusted execution environment.
[0009] In a second aspect, the present disclosure provides a routing device for an edge node in a server cluster, the device comprising:
[0010] Data acquisition module, used to obtain data to be processed and current network status;
[0011] a routing policy adjustment module, configured to adjust the configured routing policy in a trusted execution environment based on the current network state and a policy adjustment model, and determine the routing policy corresponding to the data to be processed, wherein the policy adjustment model is trained based on the sample network state and the sample routing policy;
[0012] A routing policy execution module is used to execute the routing policy on the data to be processed in the trusted execution environment.
[0013] In a third aspect, the present disclosure provides an electronic device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to execute the routing method of edge nodes in a server cluster of the above-mentioned first aspect or any corresponding embodiment thereof.
[0014] In a fourth aspect, the present disclosure provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the routing method for edge nodes in a server cluster of the above-mentioned first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0016] FIG1 is a schematic diagram of data transmission of a routing method for edge nodes in a server cluster according to an embodiment of the present disclosure;
[0017] FIG2 is a flow chart of a routing method for edge nodes in a server cluster according to an embodiment of the present disclosure;
[0018] FIG3 is a flow chart of a routing method for edge nodes in another server cluster according to an embodiment of the present disclosure;
[0019] FIG4 is a structural block diagram of a routing device of an edge node in a server cluster according to an embodiment of the present disclosure;
[0020] FIG5 is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0021] To make the purpose, technical solutions, and advantages of the embodiments of the present disclosure more clear, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present disclosure.
[0022] It is understandable that before using the technical solutions disclosed in the various embodiments of this disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0023] For example, in response to a user's active request, a prompt message is sent to the user to clearly inform the user that the operation requested will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the electronic device, application, server, storage medium, or other software or hardware that performs the operations of the disclosed technical solution based on the prompt message.
[0024] As an optional but non-limiting implementation, in response to receiving a user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. Furthermore, the pop-up window may also contain a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0025] It is understandable that the above notification and user authorization process are merely illustrative and do not limit the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0026] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) must comply with the requirements of relevant laws, regulations and relevant provisions.
[0027] As mentioned above, edge computing is becoming increasingly important within cloud computing architectures, particularly in the Internet of Things (IoT) and other applications with widespread network coverage. These applications rely on edge nodes, typically located at the edge of user access networks, to perform critical data processing and routing decisions to reduce latency and improve user experience. However, as edge nodes become increasingly ubiquitous and important, attackers may attempt to disrupt or tamper with the routing policies executed on them through various means, resulting in routing insecurity.
[0028] In view of this, the present disclosure provides a routing method, apparatus, device and medium for edge nodes in a server cluster to solve the routing security problem of edge nodes. The routing method for edge nodes in a server cluster provided by the embodiment of the present disclosure deploys a trusted execution environment on the edge node, and selects a routing strategy in the trusted execution environment. At the same time, when selecting the routing strategy, the configured routing strategy is adjusted in combination with the current network status to obtain a routing strategy corresponding to the data to be processed. This method ensures that the integrity of the routing strategy and the correctness of the execution are not threatened even in an untrusted environment by implementing and executing the routing strategy in a trusted execution environment. This method can not only significantly improve the reliability and security of network services, but also dynamically adjust the routing strategy under different current network states, thereby preventing potential risks and attacks caused by security vulnerabilities of the edge node, thereby ensuring the routing security of the edge node and improving the accuracy of routing strategy selection through the policy adjustment model.
[0029] A Trusted Execution Environment (TEE) is a hardware-based security mechanism that loads the code and data involved in computing into a trusted environment protected by the central processing unit, providing confidentiality and integrity protection. Edge nodes are used to represent access points, network nodes, or the point where a network intersects with other networks in service provisioning. Edge nodes are typically located at the edge of the user access network. Because they are closer to end users, they can provide lower latency network services.
[0030] The routing method for edge nodes in a server cluster, provided in embodiments of the present disclosure, introduces a trusted execution environment (TEE) as a technical solution for enhancing edge node security. The TEE provides an isolated execution environment in which code and data processing can be securely executed, ensuring they are immune to malware at the operating system level or higher. Applying the TEE to routing policy execution ensures that even if edge nodes are attacked, routing policies are reliably protected and correctly executed.
[0031] In some optional embodiments, FIG1 shows a data transmission diagram of the routing method of the edge node, and the devices involved in the data transmission include a client, a network device, an edge node, and an application server. Among them, the edge node can be in a server cluster, and communication with the application server is carried out through the edge node. The client initiates an access service to the application service, and the access service forwards the traffic value to the edge node via the network device, filters the routing strategy in the edge node and forwards the traffic to the application server by executing the filtered routing strategy. Correspondingly, the application server feeds back the response data corresponding to the access service to the client. Among them, the routing method of the edge node in the server cluster provided by the embodiment of the present disclosure can be applied to the edge node shown in FIG1, and the routing strategy is filtered by the edge node to obtain the routing strategy corresponding to each data to be processed, and the forwarding of the data to be processed is realized by executing the routing strategy.
[0032] According to an embodiment of the present disclosure, an embodiment of a routing method for edge nodes in a server cluster is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0033] In this embodiment, a routing method for edge nodes in a server cluster is provided, which can be used in the above-mentioned edge nodes. FIG2 is a flow chart of the routing method for edge nodes in a server cluster according to an embodiment of the present disclosure. As shown in FIG2 , the flow includes the following steps:
[0034] Step S201: Obtain data to be processed and current network status.
[0035] The data to be processed is data received by the edge node. Its source can be a client connected to the edge node or a server connected to the edge node. There are no restrictions on the source of the data to be processed and it should be set based on actual needs. The data to be processed can be encapsulated in data packets or other forms, and the specific encapsulation method is not limited.
[0036] The current network status is the state of the network to which the edge node is connected, as detected by the edge node. For example, a network performance monitoring device can be deployed in the edge node to monitor the uplink or downlink data rates, etc. to obtain the current network status. The current network status includes, but is not limited to, network speed, network packet loss rate, network congestion, etc. The specific performance indicators of the network status are not limited here.
[0037] Step S202: In the trusted execution environment, the configured routing policy is adjusted based on the current network status and the policy adjustment model to determine the routing policy corresponding to the data to be processed.
[0038] A trusted execution environment (TEE) is deployed in edge nodes, and a configured routing policy is defined within the TEE. This configured routing policy includes routing rules, access control lists, and traffic management policies. Because the configured routing policy is defined within the TEE, it is isolated from the outside world. Even if the edge node is in an untrusted environment, the TEE ensures the security of the configured routing policy.
[0039] The adjustment and execution of routing policies are all performed in the trusted execution environment. Specifically, in the trusted execution environment, the configured routing policies are adjusted based on the current network status to determine the routing policy corresponding to the data to be processed.
[0040] When adjusting routing policies, you can consider both routing selection and optimization, as well as traffic load balancing. For example, routing selection and optimization include shortest path priority and fault avoidance. Shortest path priority is to improve network efficiency and reduce latency by sending data packets along the shortest or fastest path. Fault avoidance automatically reroutes traffic to bypass the fault point when a routing node or link failure is detected. Load balancing includes traffic distribution and dynamic adjustment. Traffic distribution refers to distributing traffic across multiple paths to prevent any single path from being overloaded, thereby improving the overall network throughput and reliability. Dynamic adjustment is to dynamically adjust the traffic distribution policy based on real-time network load conditions.
[0041] In some optional implementations, security and access control can also be configured within the routing policy. For example, firewall rules and intrusion detection and prevention can be configured. Firewall rules define rules that allow or deny specific types of traffic, such as those based on Internet Protocol (IP) addresses, port numbers, or protocol types. Intrusion detection and prevention implements policies to detect and respond to potential network attacks, such as denial of service attacks.
[0042] In some optional implementations, quality of service (QoS) can also be configured within the routing policy, including priority rules and bandwidth management. Priority rules are used to set different priorities for different types of network traffic, and bandwidth management is used to allocate bandwidth based on traffic type and priority to ensure the performance of critical applications.
[0043] One or more of the above-mentioned configurations may be configured in the configured routing policy, and the specific contents are not limited here. The current network status characterizes the network quality, and the network quality provides the basis for selecting the routing policy. The configured routing policy is adjusted in combination with the destination information corresponding to the data to be processed to obtain the routing policy corresponding to the data to be processed. The adjustment of the routing policy can be carried out in combination with a trained policy adjustment model, the input of which includes the current network status, and the output is the corresponding routing policy. Alternatively, the current network status can be analyzed to determine the changes in the network status, and then the configured routing policy can be adjusted according to the changes, thereby obtaining the routing policy corresponding to the data to be processed.
[0044] It should be noted that the adjustment of the configured routing policy in step S202 can be performed before, after, or simultaneously with the acquisition of the data to be processed. There is no limitation on the timing of the two processes, and they can be set according to actual needs. Alternatively, the adjustment of the configured routing policy and the acquisition of the data to be processed can be performed in different processes, and there is no conflict between the two. After the data to be processed is acquired, the latest routing policy can be used to route and forward the data to be processed.
[0045] Step S203: executing the routing policy on the data to be processed in the trusted execution environment.
[0046] After determining the routing strategy, the routing strategy is executed on the data to be processed in the trusted execution environment. Wherein, the routing strategy includes multiple strategies, and the data to be processed are processed in sequence, so as to forward the data to be processed to the corresponding destination.
[0047] The routing method for edge nodes in a server cluster provided in this embodiment implements and executes routing policies in a trusted execution environment, ensuring the integrity and correctness of routing policies, even in untrusted environments. This method not only significantly improves the reliability and security of network services, but also dynamically adjusts routing policies based on different current network states, preventing potential risks and attacks caused by security vulnerabilities in edge nodes, thereby ensuring routing security for edge nodes.
[0048] In this embodiment, a routing method for edge nodes in a server cluster is provided, which can be used in the above-mentioned edge nodes. FIG3 is a flow chart of the routing method for edge nodes in a server cluster according to an embodiment of the present disclosure. As shown in FIG3 , the flow chart includes the following steps:
[0049] Step S301: Obtain the data to be processed and the current network status. Please refer to step S201 of the embodiment shown in FIG2 for details, which will not be repeated here.
[0050] Step S302: In the trusted execution environment, the configured routing policy is adjusted based on the current network state and the policy adjustment model to determine the routing policy corresponding to the data to be processed. The policy adjustment model is trained based on the sample network state and the sample routing policy.
[0051] Specifically, the above step S302 includes:
[0052] Step S3021: pre-process the data to be processed to determine whether the data to be processed needs to be processed in a trusted execution environment.
[0053] Preprocessing can be a preliminary security check on the data to be processed, for example, determining whether the data to be processed is lost, or whether the data to be processed is sent incorrectly, etc. Among them, the data to be processed after passing the security check can be considered to need to be processed in a trusted execution environment.
[0054] In some optional implementations, the preprocessing of the data to be processed can also be combined with the processing performance of the edge node itself. If the processing performance of the edge node itself is good, all the data to be processed that have passed the preliminary security check can be processed in the trusted execution environment; if the processing performance of the edge node itself is low, the data to be processed can be further screened to determine the importance of the data to be processed, and the most important data to be processed can be placed in the trusted execution environment for processing, and the rest can be processed in the non-trusted execution environment of the edge node.
[0055] By setting a performance threshold, the edge node's processing performance is compared with the performance threshold. If the performance threshold is greater than the performance threshold, the edge node's processing performance is good; otherwise, the edge node's processing performance is low. For example, if the edge node is a vending machine, the edge node's processing performance is considered high; if the edge node is a patrol point, the edge node's processing performance is considered low.
[0056] Step S3022: If the data to be processed needs to be processed in a trusted execution environment, the data to be processed is transferred to the trusted execution environment.
[0057] If it is determined that the data to be processed needs to be processed in the trusted execution environment, the data to be processed is transmitted to the trusted execution environment so that a routing policy corresponding to the data to be processed can be adjusted in the trusted execution environment later.
[0058] In some optional implementations, the trusted execution environment is determined by:
[0059] Step a1: Configure the initial trusted execution environment.
[0060] Step a2: start the initial trusted execution environment and verify the firmware or software corresponding to the initial trusted execution environment.
[0061] Step a3: If the firmware or software corresponding to the initial trusted execution environment passes verification, the initial trusted execution environment is determined to be a trusted execution environment.
[0062] A trusted execution module is integrated into the hardware of the edge node, wherein the trusted execution module can be a security chip or a preset secure hardware area. The trusted execution module is initialized, that is, the initial trusted execution environment is configured, the necessary security protocols and encryption suites are loaded into the trusted execution module, and the routing policy is defined in the trusted execution module to obtain the configured routing policy. After the trusted execution module is configured as described above, an initial trusted execution environment is formed. The initial trusted execution environment is started, and the firmware or software corresponding to the initial trusted execution environment is verified to determine whether the firmware or software can be verified. During the verification, the firmware or software corresponding to the initial trusted execution environment can be verified in sequence by executing a script to obtain a verification result. If the verification result indicates that the verification failed, a prompt message is issued to check the initial trusted execution environment; if the verification result indicates that the verification passed, the initial trusted execution environment is determined to be a trusted execution environment.
[0063] For the initial trusted execution environment, by verifying its corresponding firmware or software, it is determined as a trusted execution environment only after the verification passes, thereby ensuring that the trusted execution environment itself is verified and secure.
[0064] Step S3023: In the trusted execution environment, based on the current network status and the policy adjustment model, the configured routing policy is adjusted to determine the routing policy corresponding to the data to be processed.
[0065] The policy adjustment model takes as input the current network state and configured routing policies, and outputs the parameters of the algorithms in the routing policy corresponding to the data to be processed. The policy adjustment model adjusts the parameters of each algorithm in the routing policy. For example, the current network state is input into the policy adjustment model, and the output is the parameters of each algorithm. Different algorithm parameters correspond to different routing policies.
[0066] In some optional implementations, the method for determining the policy adjustment model in step S3023 includes:
[0067] Step b1: Obtain sample routing information, where the sample routing information includes a sample network state and a sample routing strategy.
[0068] Step b2: training an initial policy adjustment model based on the sample routing information to obtain a policy adjustment model. The structural complexity of the initial policy adjustment model corresponds to the computing resources of the trusted execution environment.
[0069] The policy adjustment model can be a machine learning module, including but not limited to a decision tree, neural network model, or reinforcement learning model. The specific structure of the policy adjustment model can be set based on actual needs and is not limited here. The initial policy adjustment model and the policy adjustment model have the same structure, differing in the model parameters. The model parameters of the initial policy adjustment model can be set based on empirical values or randomly, while the model parameters of the policy adjustment model are obtained through multiple rounds of iterative training of the initial routing model.
[0070] The sample routing information includes sample network states and sample routing policies. These correspond to each other and are used as training labels. An initial policy adjustment model is trained based on the sample routing information. After a model iteration cutoff condition is met, the model parameters of the initial policy adjustment model are fixed to obtain a policy adjustment model. The model iteration cutoff condition includes, but is not limited to, a maximum number of iterations or an iteration loss less than a preset value.
[0071] It should be noted that the structural complexity of the initial policy adjustment model corresponds to the computing resources of the Trusted Execution Environment (TEE). Due to the limited computing resources of the TEE, the initial policy adjustment model is lightweight to reduce memory and processor requirements. Lightweight processing includes but is not limited to simplifying the algorithm model, such as reducing the number of parameters or using a simpler decision tree structure, to adapt to the computing resource constraints of the TEE.
[0072] An initial policy adjustment model is trained through sample routing information to obtain a policy adjustment model, and an initial policy adjustment model of corresponding structural complexity is selected according to the computing resources of the trusted execution environment, thereby reducing memory and processor requirements.
[0073] The trained policy adjustment model is deployed to the trusted execution environment of the edge node. The model parameters of the policy adjustment model in the trusted execution environment can still be updated. The update method can be a third-party device sending update information to the trusted execution environment of the edge node through a secure transmission channel, or the edge node can collect historical network status and corresponding historical routing policies and adaptively update the policy adjustment model locally to obtain the updated policy adjustment model.
[0074] In some optional implementations, the method for determining the policy adjustment model in step S2023 includes:
[0075] Step c1: Acquire update information of the policy adjustment model from a secure transmission channel.
[0076] Step c2: updating the policy adjustment model in the trusted execution environment based on the update information to obtain an updated policy adjustment model.
[0077] The secure transmission channel includes, but is not limited to, an encrypted channel, such as Transport Layer Security (TLS) or Secure Sockets Layer (SSL) for data transmission. The third-party device periodically or on demand sends updated information about the policy adjustment model to the edge node via the secure transmission channel. Accordingly, the policy adjustment model is updated within the trusted execution environment of the edge node based on the updated information to obtain an updated policy adjustment model.
[0078] The update information may be an updated policy adjustment model, or parameters of the updated policy adjustment model, etc. The specific form of the update information is not limited here and is set according to actual needs.
[0079] The update of the policy adjustment model is performed by obtaining the update information through a secure transmission channel. The setting of the secure transmission channel ensures that the update process is not subject to external interference.
[0080] In some optional implementations, the method for determining the policy adjustment model in step S2023 includes:
[0081] Step d1: Obtain the processing performance of the trusted execution environment.
[0082] In step d2, if the processing performance characterization requires updating the policy adjustment model, historical routing information corresponding to the policy adjustment model is obtained in the trusted execution environment. The historical routing information includes historical network status and historical routing policies.
[0083] Step d3: In the trusted execution environment, the policy adjustment model is updated based on the historical routing information to obtain an updated policy adjustment model.
[0084] The TEE's processing performance includes metrics such as processing time, resource usage, network latency, and throughput. Resource usage includes, but is not limited to, CPU and memory utilization. A monitoring system is deployed within the TEE to collect real-time data on the algorithms running within the TEE and their impact on performance, thereby providing insights into the TEE's processing performance.
[0085] After obtaining the processing performance, it is analyzed to identify potential performance bottlenecks or optimization opportunities. Based on the analysis results, which are representative of the processing performance, it is determined whether the policy adjustment model needs to be updated. If an update is required, historical routing information corresponding to the local policy adjustment model is obtained. In the trusted execution environment, the policy adjustment model is updated based on the historical routing information to obtain an updated policy adjustment model.
[0086] The timing of updating the policy adjustment model is determined by the processing performance of the trusted execution environment. That is, the update of the policy adjustment model can be adaptively updated locally based on the actual usage scenario of the trusted execution environment to better adapt to the current network environment.
[0087] Based on the analysis results, it is determined whether to trigger an update of the policy adjustment model, which can be done by setting a performance threshold condition or predicting the update timing through a performance prediction model.
[0088] In some optional implementations, the method for determining the policy adjustment model in the above step S2023 further includes: if the processing performance meets the performance threshold condition, determining that the processing performance representation requires updating the policy adjustment model.
[0089] Performance threshold conditions include CPU usage exceeding a first preset threshold, memory usage exceeding a second preset threshold, and so on. When processing performance meets a performance threshold, it indicates that the policy adjustment model needs to be updated. For example, if CPU usage exceeds 80%, the system may reduce the resource requirements of the policy adjustment model; if memory usage is high, the system may reduce the cache size or adjust the data storage method. In this case, it indicates that route filtering may not be able to adapt to the current network environment, thus triggering an adaptive update of the policy adjustment model.
[0090] Since the performance threshold condition can intuitively and simply characterize the performance of the trusted execution environment, the update timing of the policy adjustment model is determined by the performance threshold condition, thereby improving the accuracy of the update timing of the policy adjustment model.
[0091] In some optional implementations, the method for determining the policy adjustment model in the above step S2023 further includes: predicting the update timing of the policy adjustment model based on the processing performance and the performance prediction model.
[0092] The performance prediction model is used to predict the resource demand of the policy adjustment model over a preset time period. Its input is processing performance, and its output is resource demand. If the resource demand trend is significantly increasing, it indicates that the policy adjustment model needs to be updated.
[0093] The update timing of the policy adjustment model is predicted by the performance prediction model, which improves the accuracy of the prediction timing and further improves the accuracy of the update results of the policy adjustment model.
[0094] In some optional implementations, the timing for triggering local updating of the policy adjustment model is not limited to the two methods shown above. The updating of the policy adjustment model may also be triggered when the processing performance of the trusted execution environment suddenly deteriorates.
[0095] It should be noted that the update of the policy adjustment model is based on the continuous monitoring of the trusted execution environment. By continuously collecting the processing performance of the trusted execution environment, the update of the policy adjustment model can be triggered in a timely manner.
[0096] For example, based on real-time network traffic and server load data, combined with the policy adjustment model, the parameters of the load balancing algorithm can be dynamically adjusted to update the configured routing policy; or, based on the access pattern and cache hit rate, the policy adjustment model can be used to automatically adjust the cache size and replacement strategy in the routing policy, etc.
[0097] Step S303: Execute the routing policy on the data to be processed in the trusted execution environment. Please refer to the description of step S203 in the embodiment shown in FIG2 for details, which will not be repeated here.
[0098] The routing method for edge nodes in a server cluster provided in this embodiment pre-processes data that does not need to be processed in the trusted execution environment, thereby reducing the data processing pressure on the trusted execution environment. Furthermore, in the trusted execution environment, routing policy selection is based on the current network status and the policy adjustment model, making it adaptable to network fluctuations. The policy adjustment model improves the accuracy of routing policy selection.
[0099] In some optional embodiments, the routing method of the edge node in the above-mentioned server cluster also includes: if the data to be processed meets the encryption requirements, the encryption suite is used to encrypt the data to be processed in the trusted execution environment to obtain the encrypted data to be processed, and the encryption suite is generated in the trusted execution environment.
[0100] For the data to be processed, a preset field in the data to be processed includes the method for processing the data to be processed, such as encryption. Of course, to ensure secure transmission of the data to be processed, the data to be processed can also be encrypted. For example, if the data to be processed involves high security, the data to be processed that meets the encryption requirements is encrypted using an encryption suite in the trusted execution environment to obtain the encrypted data to be processed.
[0101] The encryption suite includes, but is not limited to, encryption keys and digital certificates, and is configured based on actual needs. The encryption suite is generated within a trusted execution environment. For example, symmetric or asymmetric encryption can be used for encryption, and the specific encryption method is not limited herein. Generating the encryption suite within a trusted execution environment improves the security of the encryption keys.
[0102] In some optional embodiments, the aforementioned routing method for edge nodes in a server cluster further includes: if it is detected that a suite update condition is currently met, updating the encryption suite in a trusted execution environment. For the encryption suite, the update improves its reliability. The method detects whether the suite update condition is currently met, and if so, updates the encryption suite in the trusted execution environment. If not, the detection continues.
[0103] The conditions for suite update include, but are not limited to, reaching the scheduled update time, receiving an update instruction, or detecting a change in the location information of an edge node, etc. The conditions for suite update are not limited here and can be set according to actual needs.
[0104] In some optional embodiments, the aforementioned method for routing edge nodes in a server cluster further includes obtaining encryption suite update information and updating the encryption suite within a trusted execution environment using the encryption suite update information. The encryption suite update information is sent to the edge node via a secure channel by a third-party device through secure communication with the edge node. For example, a central management system for the edge node generates the encryption suite update information within the central management system and sends it to the edge node via a secure channel, thereby updating the encryption suite at the edge node.
[0105] The update of the encryption suite includes actively triggered updates and passive updates. The update of the encryption suite further ensures the security of the data.
[0106] In some optional implementations, the above-mentioned routing method for edge nodes in a server cluster further includes:
[0107] In step e1, in a trusted execution environment, the data to be processed is verified, where the verification includes at least one of hash verification, signature verification, and preset checkpoint verification, and the data to be processed includes at least one preset checkpoint.
[0108] In step e2, if the security verification of the data to be processed passes, the routing policy is executed on the data to be processed in the trusted execution environment.
[0109] In a trusted execution environment, further verification is performed on the data being processed to ensure its reliability. Specifically, hash verification can be a double hashing method, including secondary hashing and continuity checking. Secondary hashing involves performing two rounds of hashing on the data being processed, using different hash functions to increase the difficulty of data tampering. Continuity checking involves performing continuity checks on the data stream to ensure the order and integrity of the data being processed.
[0110] Signature verification can be multiple digital signatures, including layered signatures and cross-verification. Among them, layered signatures not only digitally sign the entire data to be processed, but also separately sign the key parts or segments of the data to be processed; cross-verification is to increase the rigor and security of verification by cross-verifying multiple digital signatures.
[0111] The preset checkpoint check can be an integrity checkpoint and a data fingerprint. The integrity checkpoint refers to setting up a checkpoint at each key node of the data to be processed. The data fingerprint refers to generating a fingerprint of the data to be processed, which is used to quickly detect and locate any changes to the data to be processed.
[0112] In some optional implementations, the data to be processed can also be verified using timestamps and sequence numbers. For example, a timestamp can be added to each data packet to ensure the temporal integrity of the data to be processed. Alternatively, sequence numbers can be assigned to each data packet or data end to prevent data replay or loss.
[0113] After the data to be processed is verified, the currently determined routing strategy is obtained to perform routing strategy processing on the data to be processed.
[0114] In a trusted execution environment, the security of routing policies in a trusted execution environment is further guaranteed by performing advanced verification on the data to be processed, such as hash verification, signature verification, and preset checkpoint verification.
[0115] In some optional embodiments, the aforementioned method for routing edge nodes in a server cluster further includes recording an operation log of the trusted execution environment within the trusted execution environment. The operation log records all operations within the trusted execution environment, including data reception, processing, verification, and transmission. Recording the operation log within the trusted execution environment facilitates auditing and subsequent analysis.
[0116] As a specific application example of the embodiments of the present disclosure, in conjunction with the application scenario shown in Figure 1, a client initiates an access service to an application server. This access service is forwarded to an edge node via network devices connected to the client, including but not limited to IoT devices. The edge node monitors the network status in real time and updates the configured routing policy based on the network status to obtain an updated routing policy. The routing policy update is implemented based on a routing adjustment model, which is built on the basis of artificial intelligence and machine learning algorithms. After receiving the access service, the updated routing policy is used to forward traffic from the access service to the application server.
[0117] This approach is an advanced routing decision-making algorithm based on a routing adjustment model. It can significantly enhance the intelligence of network management, optimize network performance, reduce latency, and improve data transmission efficiency. Particularly in dynamically changing network environments, such as those of large enterprises or cloud service providers, this approach can effectively address complex network challenges and provide more reliable and efficient network services. Implementing these functions within the TEE ensures the security of algorithms and data, preventing malicious attacks and data leaks.
[0118] In this embodiment, a routing device for edge nodes in a server cluster is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes. The details that have been described will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and contemplated.
[0119] This embodiment provides a routing device for an edge node in a server cluster, as shown in FIG4 , including:
[0120] The data acquisition module 401 is used to acquire the data to be processed and the current network status.
[0121] The routing policy adjustment module 402 is used to adjust the configured routing policy in the trusted execution environment based on the current network status and the policy adjustment model, and determine the routing policy corresponding to the data to be processed. The policy adjustment model is trained based on the sample network status and the sample routing policy.
[0122] The routing policy execution module 403 is configured to execute the routing policy on the data to be processed in the trusted execution environment.
[0123] In some optional implementations, the routing policy adjustment module 402 includes:
[0124] The preprocessing unit is used to preprocess the data to be processed and determine whether the data to be processed needs to be processed in a trusted execution environment.
[0125] The transmission unit is configured to transmit the data to be processed to the trusted execution environment if the data to be processed needs to be processed in the trusted execution environment.
[0126] The policy adjustment unit is used to adjust the configured routing policy in the trusted execution environment based on the current network status and the policy adjustment model, and determine the routing policy corresponding to the data to be processed.
[0127] In some optional implementations, the determination module of the policy adjustment model includes:
[0128] The sample acquisition unit is used to acquire sample routing information, where the sample routing information includes a sample network state and a sample routing strategy.
[0129] The training unit is used to train an initial policy adjustment model based on sample routing information to obtain a policy adjustment model, wherein the structural complexity of the initial policy adjustment model corresponds to the computing resources of the trusted execution environment.
[0130] In some optional implementations, the determination module of the policy adjustment model further includes:
[0131] The update information acquisition unit is used to acquire the update information of the policy adjustment model from the secure transmission channel.
[0132] The first model updating unit is configured to update the policy adjustment model in the trusted execution environment based on the update information to obtain an updated policy adjustment model.
[0133] In some optional implementations, the determination module of the policy adjustment model further includes:
[0134] The processing performance acquisition unit is used to acquire the processing performance of the trusted execution environment.
[0135] The historical information acquisition unit is used to acquire historical routing information corresponding to the policy adjustment model in the trusted execution environment if the processing performance characterization requires updating the policy adjustment model, where the historical routing information includes historical network status and historical routing policy.
[0136] The second model updating unit is configured to update the policy adjustment model based on the historical routing information in the trusted execution environment to obtain an updated policy adjustment model.
[0137] In some optional implementations, the determination module of the policy adjustment model further includes:
[0138] The model update determination unit is configured to determine that the processing performance representation requires updating the policy adjustment model if the processing performance satisfies a performance threshold condition.
[0139] In some optional implementations, the determination module of the policy adjustment model further includes:
[0140] The prediction unit is used to predict the update timing of the policy adjustment model based on the processing performance and the performance prediction model.
[0141] In some optional implementations, the trusted execution environment determination module includes:
[0142] Environment configuration unit, used to configure the initial trusted execution environment.
[0143] The environment startup unit is used to start the initial trusted execution environment and verify the firmware or software corresponding to the initial trusted execution environment.
[0144] The environment determination unit is configured to determine that the initial trusted execution environment is a trusted execution environment if the firmware or software corresponding to the initial trusted execution environment passes verification.
[0145] In some optional implementations, the routing device of the edge node in the server cluster further includes:
[0146] The encryption module is used to encrypt the data to be processed using an encryption suite in a trusted execution environment if the data to be processed meets the encryption requirements, so as to obtain the encrypted data to be processed, where the encryption suite is generated in the trusted execution environment.
[0147] In some optional implementations, the routing device of the edge node in the server cluster further includes:
[0148] A first update module is configured to update the encryption suite in a trusted execution environment if it is detected that a suite update condition is currently met; or
[0149] The second updating module is configured to obtain update information of the encryption suite and update the encryption suite using the update information of the encryption suite in the trusted execution environment.
[0150] In some optional implementations, the routing device of the edge node in the server cluster further includes:
[0151] The verification module is used to verify the data to be processed in a trusted execution environment, where the verification includes at least one of hash verification, signature verification, and preset checkpoint verification, and the data to be processed includes at least one preset checkpoint.
[0152] The routing execution module is used to execute the routing strategy on the data to be processed in the trusted execution environment if the security verification of the data to be processed passes.
[0153] In some optional implementations, the routing device of the edge node in the server cluster further includes:
[0154] The recording module is used to record the operation log of the trusted execution environment in the trusted execution environment.
[0155] The routing device of the edge node in the server cluster in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0156] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0157] An embodiment of the present disclosure further provides an electronic device having a routing device of an edge node in the server cluster shown in FIG. 4 .
[0158] Please refer to Figure 5, which is a structural diagram of an electronic device provided by an optional embodiment of the present disclosure. As shown in Figure 5, the electronic device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses for communication and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed in the electronic device, including instructions stored in or on the memory to display graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple electronic devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 5 takes a processor 10 as an example.
[0159] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0160] The memory 20 stores instructions that can be executed by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.
[0161] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and applications required for at least one function; the data storage area may store data created based on the use of the electronic device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the electronic device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0162] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0163] The electronic device further includes a communication interface 30 for the electronic device to communicate with other devices or a communication network.
[0164] The embodiments of the present disclosure also provide a computer-readable storage medium. The above-mentioned method according to the embodiments of the present disclosure can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0165] Although the embodiments of the present disclosure have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A routing method for edge nodes in a server cluster, comprising: Get the data to be processed and the current network status; In a trusted execution environment, adjusting a configured routing policy based on the current network state and a policy adjustment model to determine a routing policy corresponding to the data to be processed, wherein the policy adjustment model is trained based on a sample network state and a sample routing policy; executing the routing policy on the data to be processed in the trusted execution environment; The step of adjusting the configured routing policy based on the current network state and the policy adjustment model in the trusted execution environment to determine the routing policy corresponding to the data to be processed includes: Preprocessing the data to be processed to determine whether the data to be processed needs to be processed in a trusted execution environment; If the data to be processed needs to be processed in the trusted execution environment, transferring the data to be processed to the trusted execution environment; In the trusted execution environment, based on the current network state and the policy adjustment model, the configured routing policy is adjusted to determine a routing policy corresponding to the data to be processed.
2. The method according to claim 1, wherein The method for determining the strategy adjustment model includes: Acquire sample routing information, where the sample routing information includes the sample network status and the sample routing strategy; An initial policy adjustment model is trained based on the sample routing information to obtain the policy adjustment model, wherein the structural complexity of the initial policy adjustment model corresponds to the computing resources of the trusted execution environment.
3. The method according to claim 1, wherein The method for determining the strategy adjustment model also includes: Obtaining update information of the policy adjustment model from a secure transmission channel; The policy adjustment model in the trusted execution environment is updated based on the update information to obtain an updated policy adjustment model.
4. The method according to claim 1, wherein The method for determining the strategy adjustment model also includes: Obtaining processing performance of the trusted execution environment; If the processing performance characterization requires updating the policy adjustment model, obtaining historical routing information corresponding to the policy adjustment model in the trusted execution environment, the historical routing information including historical network status and historical routing policies; In the trusted execution environment, the policy adjustment model is updated based on the historical routing information to obtain an updated policy adjustment model.
5. The method according to claim 4, wherein The method for determining the strategy adjustment model also includes: If the processing performance satisfies a performance threshold condition, it is determined that the processing performance representation requires updating the policy adjustment model.
6. The method according to claim 4, wherein: The method for determining the strategy adjustment model also includes: Based on the processing performance and the performance prediction model, the update timing of the policy adjustment model is predicted.
7. The method according to claim 1, wherein The method for determining the trusted execution environment includes: Configure the initial trusted execution environment; Starting the initial trusted execution environment and verifying the firmware or software corresponding to the initial trusted execution environment; If the firmware or software corresponding to the initial trusted execution environment passes verification, the initial trusted execution environment is determined to be the trusted execution environment.
8. The method according to claim 1, further comprising: If the data to be processed meets the encryption requirement, the data to be processed is encrypted in the trusted execution environment using an encryption suite to obtain encrypted data to be processed, where the encryption suite is generated in the trusted execution environment.
9. The method according to claim 8, further comprising: If it is detected that the suite update condition is currently met, updating the encryption suite in the trusted execution environment; or, Acquire update information of the encryption suite, and update the encryption suite in the trusted execution environment using the update information of the encryption suite.
10. The method according to claim 1, further comprising: In the trusted execution environment, verifying the data to be processed, wherein the verification includes at least one of hash verification, signature verification, and preset checkpoint verification, and the data to be processed includes at least one of the preset checkpoints; If the security verification of the data to be processed passes, the routing policy is executed on the data to be processed in the trusted execution environment.
11. The method according to any one of claims 1 to 10, further comprising: In the trusted execution environment, an operation log of the trusted execution environment is recorded.
12. A routing device for an edge node in a server cluster, comprising: Data acquisition module, used to obtain data to be processed and current network status; a routing policy adjustment module, configured to adjust the configured routing policy in a trusted execution environment based on the current network state and a policy adjustment model, and determine the routing policy corresponding to the data to be processed, wherein the policy adjustment model is trained based on the sample network state and the sample routing policy; A routing policy execution module, configured to execute the routing policy on the data to be processed in the trusted execution environment; The routing policy adjustment module includes: a preprocessing unit, configured to preprocess the data to be processed and determine whether the data to be processed needs to be processed in the trusted execution environment; a transmitting unit, configured to transmit the data to be processed to the trusted execution environment if the data to be processed needs to be processed in the trusted execution environment; A policy adjustment unit is configured to adjust the configured routing policy in the trusted execution environment based on the current network state and the policy adjustment model, and determine the routing policy corresponding to the data to be processed.
13. An electronic device comprising: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the routing method for edge nodes in a server cluster according to any one of claims 1 to 11 by executing the computer instructions.
14. A computer-readable storage medium having computer instructions stored thereon, wherein the computer instructions are used to enable a computer to execute the routing method for edge nodes in a server cluster according to any one of claims 1 to 11.
Citation Information
Patent Citations
Routing strategy obtaining system based on machine learning
CN107124365A
Data processing method and device of edge device and electronic device
CN113472737A
Intelligent routing decision-making method and system based on deep reinforcement learning, and storage medium
CN116094983A
Internet routing optimization method and device based on graph convolutional neural network
CN116527565A
Traffic forwarding path processing method and device, computer equipment and storage medium
CN117118892A
Cited By
Data processing method, system and equipment and storage medium
CN121691323A