Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

181 results about "Resource isolation" patented technology

Computing power resource elastic allocation monitoring system

The invention relates to the technical field of computing power resources, and discloses a flexible allocation monitoring system for computing power resources, which defines a clear resource use boundary for different types of tasks through a container-level QoS strategy of a resource isolation unit, and adjusts resource allocation in real time in combination with a dynamic partition management module, thereby avoiding resource waste in a traditional fixed allocation mode, and improving the resource allocation efficiency. The dynamic preemption unit accurately screens low-priority tasks for resource recovery through a multi-factor decision engine and a preemption cost evaluation algorithm, in 50 concurrent task scenes, the resource preemption response time is shortened to 20-35 ms and is improved by 50%-70% compared with 70-100 ms of Docker / K8s, the blocking duration of high-priority tasks is reduced to 15-25 ms from 80-120 ms, and the core service interruption risk is greatly reduced.
Owner:HEBEI MINGWEI DIGITAL TECHNOLOGY CO LTD

Multi-user-oriented smart home resource conflict negotiation and distribution method

The invention discloses a multi-user-oriented smart home resource conflict negotiation and allocation method, which comprises the following steps of: detecting equipment use conflicts caused by at least two users by constructing a structural causal model for representing a causal relationship of a plurality of variables in a smart home environment, generating a candidate decision strategy set comprising resource isolation and alternative compensation, and allocating the candidate decision strategy set to the smart home environment; carrying out anti-fact inference by utilizing a causal model, quantifying the causal effect of each strategy on the user state, and selecting an optimal strategy for execution based on a minimum negative effect and a Pareto optimal principle; besides, the method ensures that the system dynamically adapts to user habit changes through online monitoring of prediction errors and correction of the causal model, and compared with the prior art, the method improves the decision accuracy through causal reasoning, realizes fair and personalized user resource allocation, and improves the user experience and long-term effectiveness of the smart home system.
Owner:NANJING FORESTRY UNIV

Fine-grained slice isolation method in air-sea cross-domain network

The invention discloses a fine-grained slice isolation method in an air-sea cross-domain network, which belongs to the technical field of network communication, and comprises the following steps: firstly collecting resource data to construct a cross-domain heterogeneous resource map; selecting an optimal slice deployment scheme through K shortest path screening and node matching decision; then realizing slice hard isolation by means of a resource data isolation technology, a network resource isolation technology and a wireless link resource isolation technology; and finally, monitoring the operation state, and triggering dynamic adjustment of the scheme when the operation state is abnormal. The system comprises three modules, and seamless switching of slices is guaranteed. Through a deterministic optimization algorithm and a multi-level isolation mechanism, accurate and efficient allocation and strict isolation of heterogeneous resources are realized, and the QoS guarantee capability of services in a high-dynamic cross-domain network and the system stability are remarkably improved.
Owner:HARBIN ENGINEERING UNIVERSITY SANYA NANHAI INNOVATION & DEVELOPMENT BASE

System abnormity intelligent diagnosis and recovery method and system fusing time sequence logs

The invention provides a system abnormity intelligent diagnosis and recovery method and system fusing time sequence logs, and relates to the field of distributed system operation and maintaining.The method comprises the steps that operation logs are collected from a plurality of service nodes of a distributed system, time sequence alignment is conducted, and calling relation and performance measurement data are extracted; time sequence change features are calculated in the sliding time window, dynamic feature vectors are generated through fusion coding, and a cross-service time sequence association graph is constructed; identifying an abnormal service node and matching the abnormal service node with historical fault data to obtain a historical propagation path and a feature vector; calculating a propagation convergence coefficient and a characteristic deviation degree based on a historical propagation path to obtain a causal intensity score; and identifying a fault influence degree according to the score, and adaptively adjusting a resource isolation and flow scheduling strategy. According to the invention, accurate diagnosis and efficient recovery of distributed system faults are realized.
Owner:SMIC WANYE TECHNOLOGY CO LTD

Electric automobile instrument testing method based on end-cloud collaboration

The invention relates to the technical field of edge computing, electric automobile testing and the like, and provides an electric automobile instrument testing method based on end-cloud collaboration, which comprises the following steps of: constructing a lightweight virtualized resource isolation environment at an edge computing node, loading signal generation, communication agency and state monitoring micro-service; a test platform with elastic capacity expansion and contraction and fault self-recovery capability is formed; historical test data are collected at a cloud end, and an equipment health degree prediction model is trained and deployed to an edge node to support a local intelligent test; constructing a dynamic test service chain, generating and pre-distorting and compensating an enhanced test signal, and then acting the enhanced test signal on the instrument; through multi-modal signal acquisition and unified preprocessing, in combination with wavelet packet decomposition and a deep neural network, high-dimensional feature extraction is realized, a test report containing a health trend is finally output, and a test process is actively intervened based on a trend prediction result. According to the method, the authenticity of test signals, the health assessment precision and the safety and efficiency of the test process are effectively improved.
Owner:WONYOU INTELLIGENT TECH (SHENZHEN) CO LTD

Security sensing method and system for GPU (Graphic Processing Unit) cluster

The invention relates to the technical field of network security awareness, in particular to a security awareness method and system for a GPU cluster, and the method comprises the steps: collecting multi-source security situation data, and providing basic information for subsequent security analysis; by constructing and updating a cluster security situation map in real time, information timeliness is updated and ensured in real time, and powerful support is provided for risk assessment; a dynamic risk assessment model is utilized to calculate vertex and edge scores, high-risk vertexes and key risk conduction paths are identified, and a basis is provided for resource isolation and scheduling; the targeted instruction is generated according to the security risk score and the preset security policy library, different security risks are effectively handled, and safe and stable operation of the cluster is guaranteed; by converting the instruction into a specific control command and distributing and executing the specific control command, effective implementation of security measures is ensured, and the cluster security protection capability is improved; by setting a finite-state machine monitoring instruction execution state, a recovery mechanism is automatically triggered, and continuous and safe operation of the cluster is guaranteed.
Owner:中科云达(北京)科技有限公司

Document adaptive conversion method and device based on multi-modal large model and medium

The invention provides a document adaptive conversion method and device based on a multi-modal large model and a medium, and belongs to the technical field of data processing. The method comprises the following steps: inputting a multi-modal document into a pre-constructed multi-modal large model, wherein the multi-modal large model comprises a multi-modal joint framework fusing a ViT visual model and an LLM model; using a ViT visual model and an LLM model to respectively extract multi-scale visual features corresponding to non-text content and semantic features corresponding to text content, and using a cross-modal attention mechanism to bidirectionally align the multi-scale visual features and the semantic features to obtain a multi-modal document; carrying out self-adaptive blocking on the multi-modal document by using a self-adaptive blocking strategy, and modeling a relative position relationship between blocks; establishing a dynamic mapping rule from a document element to an HTML tag, and mapping the multi-modal document into a front-end interaction component in combination with a natural language instruction of a user; and dynamically rendering the front-end interaction component in an on-demand mounting and resource isolation mode. The problem of insufficient document restoration capability in the prior art can be solved.
Owner:SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD

Deep learning-based computing power pool intelligent integration and elastic scheduling method

The invention relates to the technical field of distributed computing and deep learning, and discloses a computing power pool intelligent integration and elastic scheduling method based on deep learning, and the method comprises the steps: constructing a multi-level graph convolution network, and carrying out the modeling of a dynamic interaction relation between micro-services; constructing a multi-dimensional scoring model based on the computing power state index and the network state index; dynamically adjusting the micro-service granularity according to the task characteristics and the resource state; predicting a service interaction mode and a resource demand change by utilizing graph reinforcement learning; searching an optimal service deployment scheme by adopting a multi-objective optimization algorithm; according to the method, the resource utilization rate is improved through dynamic service granularity adjustment and computing power aware routing, predictive resource isolation and service capacity expansion are realized based on graph reinforcement learning, dynamic balance of delay, throughput and resource efficiency is realized by adopting multi-objective optimization, the problems of resource fragmentation and performance interference are effectively solved, and the resource utilization rate is improved. And the stability and the reliability of the system are obviously improved.
Owner:SHENZHEN SHUNTIANCHUANG TECHNOLOGY CO LTD

Device protocol adaptive analysis and instruction scheduling method of intelligent central control system

The invention relates to the technical field of computers, and discloses an equipment protocol adaptive analysis and instruction scheduling method for an intelligent central control system, and the method comprises the steps: obtaining an original communication data flow of heterogeneous equipment, and extracting a protocol feature fingerprint to recognize a protocol type; calling a corresponding pluggable protocol parser to generate a standardized instruction object; analyzing instruction semantics and dynamically calculating priorities in combination with a system load; and performing non-blocking scheduling and execution monitoring on the instruction based on a resource token bucket mechanism. The system comprises a data acquisition module, a protocol identification module, a self-adaptive analysis module, a semantic analysis module, a priority calculation module, an instruction sorting module, a token management module, a scheduling execution module, an execution monitoring module and a response generation module. According to the method, through protocol self-learning, dynamic priority quantification and multi-dimensional resource isolation scheduling, the response certainty, expansibility and operation stability of the system in a high-concurrency scene are remarkably improved.
Owner:SHENZHEN HAIWEI HENGTAI INTELLIGENT TECH CO LTD

Memory control method, storage device, medium and equipment

The invention belongs to the technical field of cache prefetching optimization of a firmware layer of a computer storage system, and particularly provides a memory control method, a storage device, a medium and equipment.The instantaneous flow is effectively filtered and persistent hotspot data is accurately recognized through a three-layer structure of combining a first-stage hotspot filtering module with a window cache, a view queue and a protection queue; the second-stage continuous access filtering module dynamically judges a continuous access mode by means of mean-variance statistics of an annular buffer area, and accidental continuous triggering of prefetching is avoided; and the third-stage random access judgment module prohibits invalid prefetching and effectively distinguishes access modes. The pre-fetching bandwidth is limited through the token bucket algorithm, the global priority queue of the skip list is combined, it is ensured that the priority of the write task is higher than that of the pre-fetching task, pre-fetching and foreground I / O resources are isolated, delay jitter control over foreground key I / O can be achieved during full-load pre-fetching, and the problem that delay soaring is caused when pre-fetching preempts the resources is solved.
Owner:SHENZHEN XINGHUO SEMICON TECH CO LTD

Intelligent contract automatic execution system and method based on block chain technology

The invention relates to the technical field of block chain smart contracts, and provides a smart contract automatic execution system and method based on a block chain technology. In order to solve the problems that in the prior art, out-of-chain event verification is fragile, cross-contract atomicity is lacked, and resource management and control are insufficient, the system comprises a multi-mode under-chain event verification module, and a tamper-proof data channel is established through an Internet of Things hardware anchor point and an anti-collusion oracle; the autonomous execution engine is integrated with a resource awareness scheduler and an out-of-chain computing adapter; the transaction atomicity guarantee module is used for realizing cross-contract rollback by adopting a global snapshot tree and an intelligent compensation contract; the governance arbitration interface supports anonymous dispute resolution. The method comprises the steps of out-of-chain event multi-level verification, voucher execution queue management and sandbox resource isolation control. Credible collaboration inside and outside the chain is realized, the execution reliability is improved by more than 90%, and the contract development cost is reduced by 40%.
Owner:BEIJING CREDIT MANAGEMENT CO LTD

Cloud data server mixed training method and system

The invention discloses a cloud data server mixed training method and system, which are applied to a cloud data server cluster comprising a plurality of computing resources. According to the method, a model structure, a data set, a time delay constraint and an isolation constraint of a training task are analyzed to generate a task portrait, resource configuration, an operation state and an isolation capability of a calculation node are collected to generate a resource portrait, and a co-located interference degree index table of a task and resource combination is constructed based on historical monitoring data. During scheduling, a heterogeneous computing power utilization rate, an estimated training time delay deviation and a co-located interference degree are taken as indexes, a candidate resource allocation scheme is subjected to weighted evaluation to generate a mixed training scheduling strategy, and resource isolation is implemented through container and accelerator multi-instance division. In the operation process, the training time delay and the actual co-located interference degree are continuously monitored, the scheduling weight and the co-located interference degree index are dynamically adjusted according to the deviation, closed-loop optimization of multi-task mixed training is achieved, the heterogeneous resource utilization rate is increased, and time delay default and co-located interference are reduced.
Owner:SICHUAN HONGZHI YUANDA TECH CO LTD

Security authentication multi-start method for Linux system of development board

The invention discloses a development board Linux system security authentication multi-start method, which comprises the steps of 1, hardware trust root initialization and storage area division, 2, hardware trust root self-inspection and measurement, 3, starting item dynamic loading and multi-stage authentication, 4, security context establishment and system switching, and 5, multi-system isolation and collaboration. Step 6, performing security audit and exception handling; full-link authentication is realized by taking a hardware trust root as an anchor point, malicious mirror startup and inter-system data leakage are effectively resisted in combination with a storage and resource isolation mechanism, scenes such as on-demand dynamic switching, flexible adaptation debugging, upgrading and fault recovery of multiple systems can be realized, and the system reliability is improved by optimizing the lightweight design of an authentication algorithm and resource management. Limited computing power of the development board is adapted, the starting process and abnormal events can be completely recorded, and illegal operation can be traced conveniently.
Owner:BEIJING XUNWEI ELECTRONICS CO LTD

Multi-tenant API key authentication and resource isolation system in containerized environment

The invention discloses a multi-tenant API key authentication and resource isolation system in a containerized environment, and relates to the field of containerized multi-tenant authentication. Comprising an authentication authorization layer, a resource management and control layer and a security isolation layer. The authentication authorization layer comprises a multi-tenant authentication engine, an API key verification sub-module, a tenant identity recognition sub-module, an authority cascade verification sub-module and a dynamic authority calculation sub-module. And the resource management and control layer comprises a resource quota manager, a dynamic quota allocation sub-module, a real-time use monitoring sub-module, a threshold alarm control sub-module and an elastic capacity expansion and contraction sub-module. The security isolation layer comprises a multi-dimensional isolation engine, a container network isolation sub-module, a storage space isolation sub-module, a process permission isolation sub-module and a system call filtering sub-module; deep fusion of API authentication and container resource control is realized, a dynamic resource quota management mechanism based on tenant identities is established, and fine-grained API authority control and resource use limitation are provided.
Owner:CHINA IND INTERNET RES INST

Online interactive programming education system and method based on micro-service architecture

The invention provides an online interactive programming education system based on a micro-service architecture, and the system comprises an infrastructure layer which serves as a bottom layer computing power and provides an elastic computing power through a cross-cloud deployment technology and a dynamic resource scheduling technology; the platform core layer constructs a stateless micro-service cluster through a service registration discovery module, a load balancing module and a fusing mechanism module depending on elastic resources of the infrastructure layer, and the infrastructure layer provides physical resource guarantee for operation of the micro-service cluster of the platform core layer; the platform support layer is used for integrating an authority management component, a workflow engine component and a general service component based on a stateless micro-service cluster constructed on the platform core layer, and providing resource isolation and high-concurrency task scheduling support in a multi-tenant environment for the programming education system; the platform core layer is combined with distributed transaction management to provide stable service scheduling and communication capability for an authority management component, a workflow engine component and a general service component of the platform support layer; and the platform application layer combines service scheduling and communication capabilities, realizes teaching functions such as multi-language development, code debugging visualization, AI personalized suggestion and collaborative learning, and directly serves programming learning of students and teaching management requirements of teachers.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Resilient radio resource provisioning for network slicing

The present disclosure provides a resilient (radio) access network ((R)AN) slicing framework encompassing a resource planning engine and distributed dynamic slice-aware scheduling modules at one or more network access nodes, edge compute nodes, or cloud computing service. The resilient (R)AN slicing framework includes resource planning and slice-aware scheduling, as well as signaling exchanges for provisioning resilient (R)AN slicing. The intelligent (R)AN slicing framework can realize resource isolation in a more efficient and agile manner than existing network slicing technologies. Other embodiments may be described.
Owner:INTEL CORP

Cache dynamic allocation method and device for storage hardware equipment

The invention discloses a cache dynamic allocation method and device for a storage hardware device, and relates to the technical field of cache dynamic allocation, and the method comprises the steps: obtaining multi-dimensional perception data corresponding to an RAID card, matching a corresponding dynamic decision engine, and carrying out cache dynamic allocation in combination with a QoS virtual channel and resource isolation and a preemptive resource recovery mechanism, the problems that in the related technology, a single-index offline training model is excessively depended, multi-dimensional perception is lacked, and traffic processing has large delay are solved; besides, during resource allocation competition, service interference is easily caused, the hardware cost for deploying an intelligent algorithm is high, and the cache allocation efficiency is greatly influenced are solved, and the purposes of avoiding write cache full and forced degradation into a write-through mode, remarkably improving I / O response stability, eliminating high-temperature downtime and cache data loss risks and improving the cache allocation efficiency are achieved. And the delay fluctuation and the hardware deployment cost are reduced.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Resource management method and device for operating system kernel, equipment, medium and product

The invention discloses a resource management method and device for an operating system kernel, equipment, a medium and a product, and relates to the technical field of resource management.The resource management method includes the steps that a computing power pool and a memory pool are integrated into a unified initialized resource pool, resource scheduling is achieved through resource allocation primitives, cross coordination among multiple modules is avoided, and coordination efficiency is improved; resource allocation, isolation and recovery are executed through independent primitives, so that the stability of resource adjustment is guaranteed; resource isolation primitives are executed through a hardware isolation mechanism, resource access between different tasks can be blocked from the physical level, and the security isolation effect is guaranteed; the whole resource management process is completed in the kernel mode of the operating system through the native primitive, and a user mode component does not need to be called to participate in scheduling or management, so that the switching overhead of the user mode and the kernel mode and the central processing unit resources occupied by the user mode component during operation are avoided, and the overall consumption is reduced.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Infrastructure and application management system based on cloud native technology

The invention discloses an infrastructure and application management system based on a cloud native technology, and the system comprises a command line tool which is used for carrying out the communication with a server through an MQTT protocol, and executing the cluster management operation; the multi-tenant private cloud cluster module is used for realizing resource isolation and quota management among tenants; the mirror image warehouse module is used for storing and managing application mirror images; the declarative management module is used for defining a resource expectation state through a YAML configuration file; the CI / CD assembly line module is used for automatically constructing, testing and deploying applications; the gateway resource scheduling module is responsible for load balancing and flow control; the user authorization and authentication module is used for realizing authority control based on an RBAC model; the security module comprises data encryption and network isolation; and the asset library management module is used for managing a program component and a platform library. By integrating a cloud native technology stack, a set of efficient, safe and extensible infrastructure and application management system is constructed, and the deployment efficiency and the operation and maintenance capability of enterprise-level applications are remarkably improved.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Multi-task processing method and system based on large model

The invention relates to the technical field of task scheduling, in particular to a multi-task processing method and system based on a large model, and the method comprises the following steps: extracting resource parameters by using the large model to generate a conflict intensity matrix, screening resource coincident node pairs, judging structural conflicts, constructing a dependency graph, calculating complexity, scoring and cutting a dense region, and extracting a high-frequency path division scheduling unit, and generating a task priority sequence. According to the method, the conflict intensity matrix is constructed, the task resource conflict relation is recognized in combination with node aggregation features, the sensitivity and precision of task division to resource distribution are improved, upper and lower bound nodes are divided based on median deviation, structure optimization and recombination are achieved in combination with the resource type mutual difference rate, and the path depth and branch factors form a complexity scoring basis. The method comprises the following steps: dynamically adjusting weight identification and cutting a dense area in combination with an occupation time length, calling a path with the highest frequency to form a main path set, dividing non-main path tasks according to a node coverage relationship, and enhancing scheduling boundary definition and resource isolation capability.
Owner:BEIJING SHENZHOU BANGBANG TECH SERVICE CO LTD

Secure access method and device for processor resources, equipment, medium and product

The invention relates to the technical field of embedded systems, in particular to a secure access method and device for processor resources, equipment, a medium and a product, and the method comprises the steps: distributing each resource access request to a corresponding target virtual domain according to a matching result of a main equipment process identifier of each resource access request and a corresponding preset mask, injecting the distributed domain identifier into each request to obtain a domain marking request; intercepting and analyzing the domain marking requests to obtain a target address, an operation type and a domain identifier corresponding to each domain marking request; and verifying the operation type of the domain identifier corresponding to each domain marking request on the target address based on preset security policy information, and intercepting the abnormal access request. Therefore, the technical problems of large performance loss, insufficient security isolation granularity and lack of system-level protection in the existing intra-core resource isolation scheme are solved, the real-time performance and security of the system are remarkably improved, and the troubleshooting capability is enhanced.
Owner:INALFA ZHILIAN TECH (BEIJING) CO LTD

Cluster computing resource isolation method and device, electronic equipment and storage medium

The invention provides a cluster computing resource isolation method and device, electronic equipment and a storage medium, and relates to the technical field of cluster computing resource management. And scheduling the containerized task to an adaptive physical graphics processor node based on the information, intercepting a resource access request during task operation, allocating an isolated video memory space and a computing context according to an allocated virtual graphics processor resource limit, and dynamically maintaining an isolated state of multiple tasks, so that the task access efficiency is improved. The problems of inter-task interference, limited hardware compatibility, insufficient resource allocation flexibility and low utilization rate caused by lack of a flexible virtualization scheme for decoupling from hardware and imperfect resource scheduling and isolation mechanisms in the prior art can be solved.
Owner:CHINA UNICOM ONLINE INFORMATION TECHNOLOGY CO LTD

Local communication service resource isolation method and device, storage medium and electronic equipment

The application discloses a local communication service resource isolation method and device, a storage medium and an electronic device, the method calculates resource demand and access value of a communication service based on access information of the communication service, abstracts the problem of resource allocation for the communication service based on the resource demand and the access value into a two-dimensional matrix packing problem based on an orthogonal frequency division multiple access technology, solves the two-dimensional matrix packing problem by using a pointer network and an Actor-Critic algorithm, and obtains a network slice allocation result of the communication service, so that the reasonable use of spectrum resources is realized by technologies such as OFDMA, meanwhile, the transmission of more valuable communication services is ensured by considering the resource demand and the access value during allocation, and finally, the logical isolation between communication services is realized by constructing a network slice during resource allocation of the communication services.
Owner:GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +4

A distributed cloud-native database management method and system

The application relates to the technical field of computers, in particular to a distributed cloud native database management method and system. The method comprises the following steps: deploying multiple distributed database clusters based on a containerized deployment K8S framework; creating a unique database for each database cluster, and performing permission isolation at a user level; providing access to the database in a single cluster based on a memfire-cloud server provided by the K8S framework; performing user access and database access in a load balancing manner; expanding and shrinking the database cluster resources and storage space on demand; when a node fails and cannot be accessed, a K8S framework starts a new node, and database data information of the failed node is restored to the new node. The application can construct multiple distributed clusters on a K8S platform, and can add a database cluster in one key mode; the clusters are isolated from each other and do not interfere with each other, so that resource isolation between users is achieved, and database level isolation is achieved.
Owner:MINBO TECH (WUHAN) CO LTD

Method, apparatus and computer product for managing graphics processing unit device

The invention relates to the technical field of data communication, and provides a method and device for managing graphics processing unit (GPU) equipment and a computer product, and the method comprises the following steps: determining a target container in a target container group (Pod) of a node (Node); entering a resource isolation environment of the target container based on the first related information of the target container; and in the resource isolation environment of the target container, creating GPU equipment or deleting the GPU equipment, and modifying the access authority of the GPU equipment. Therefore, the target container can dynamically mount or unload the GPU equipment during load running, the use flexibility of the GPU equipment is improved, and the GPU equipment is reasonably distributed.
Owner:MOORE THREADS TECH CO LTD

A roadside unit resource isolation method, device and electronic equipment

The embodiment of the application provides a roadside unit resource isolation method, device and electronic equipment, the method comprises the following steps: creating a security virtual function VF and a business virtual function VF in a roadside unit RSU hardware layer, dividing the infrastructure of the NFV of the RSU hardware layer into a security slice and a business slice, and reserving a minimum resource quota for the security slice; real-time monitoring of monitoring data of a RSU network interface is used to identify an attack risk level, and the resource allocation ratio of the security VF and the business VF is dynamically adjusted, metadata of the business VF is transmitted to the security VF through a unidirectional data sharing channel configured between the security VF and the business VF; and / or direct communication between the security slice and the business slice is blocked through a physical or logical isolation strategy. The attack risk level is identified by real-time monitoring of the monitoring data of the RSU network interface, and the resource allocation ratio of the security VF and the business VF is dynamically adjusted, thereby realizing roadside unit resource isolation.
Owner:BEIJING INFORMATION TECH COLLEGE

Method and apparatus for resource isolation on a communication network

Embodiments of the present disclosure provide a method and apparatus for resource isolation on a communication network. A method (400) performed by a first node for managing resources of a communication network comprises: receiving (S402), from a second node, a first request for a communication resource, the first request comprising: a first parameter indicating an isolation requirement for the communication resource; and transmitting (S404), to the second node, a first response indicating the communication resource that meets the isolation requirement of the communication resource. Exemplary embodiments of the present disclosure propose a mechanism that allows exchanging isolation and security requirements of communication resources in a standard way.
Owner:ALCATEL LUCENT SHANGHAI BELL CO LTD +1

Safety acquisition software plug-in implementation method and system for power monitoring system

The invention discloses a method and a system for realizing a security acquisition software plug-in with dynamic characteristics for an electric power monitoring system, and aims to solve the problems of difficulty in function extension, insufficient security and poor resource isolation of a traditional electric power monitoring system. According to the system, through a plug-in architecture design, a plug-in function module is realized in a dynamic library form, and dynamic loading, unloading and security isolation operation are supported. The plug-in is started through the sub-process, the main program ensures the legality of the plug-in through SM2 certificate verification, and efficient interaction between the main program and the plug-in is achieved through a callback function mechanism. The plug-in supports dynamic memory allocation, and potential safety hazards caused by predefined field length are avoided. Core rights points of the method comprise plug-in expansion capability, sub-process isolation, SM2 certificate verification, a transparent transmission mechanism and dynamic memory management, and the function expansibility, the safety and the operation stability of the power monitoring system can be remarkably improved.
Owner:NARI INFORMATION & COMM TECH

Pulsar deployment method and system of cross-Kubernetes cluster

The invention relates to the technical field of multi-cluster management, in particular to a Pulsar deployment method and system for a cross-Kubernetes cluster, and the method comprises the steps: a user creates a customized resource employing a Pulsar application in a management and control cluster; monitoring and triggering a reconciliation process by adopting a Pulsar multi-operator, and starting to execute reconciliation logic when the Pulsar multi-operator detects the creation of the instance of the custom resource; the method comprises the following steps: creating a propagation strategy by Pulsar multiple operators, and defining resources distributed to each cluster; a multi-cluster management tool Karmada is adopted to monitor a propagation strategy and execute resource distribution, and the Pulsar application is distributed to member clusters meeting conditions; monitoring and processing the self-defined resources of the single cluster by a Pulsar operator in the member cluster; and the Pulsar operators create and manage resources in sequence, and the Pulsar components in the cluster are maintained. According to the method, a more effective resource isolation and a rapid and reliable fault recovery mechanism can be provided, and the management operation of the Pulsar in a multi-cluster environment is greatly simplified, so that the requirements of modern applications on efficient and reliable cloud native infrastructures are met.
Owner:SHANGHAI XILIU TECHNOLOGY CO LTD