Summary of the invention
Since existing method is there are the above problem, the embodiment of the present invention proposes a kind of universal process method in secure resources pond
And device.
In a first aspect, the embodiment of the present invention proposes a kind of universal process method in secure resources pond, comprising:
The realization details for shielding the different virtualization resource pond of each manufacturer, by unified interface and each virtualization resource pond into
Row connection;
The driving for integrating various virtualization resource ponds is adapted to each virtualization resource pond by the driving after integrated;
The virtualization safety equipment that each virtualization resource pond is created in secure resources pond is operated.
Optionally, the virtualization safety equipment that each virtualization resource pond is created in secure resources pond is operated,
It specifically includes:
Create the virtualization safety equipment in each virtualization resource pond in secure resources pond, and to virtualization safety equipment into
Row starting, stopping, deletion or reboot operation;
Optionally, described pair of virtualization safety equipment is started, is stopped, being deleted or reboot operation passes through unified life
Cycle management interface executes.
Optionally, the method also includes:
The tactful configuration variance for shielding the different virtualization resource pond of each manufacturer configures interface by unified security strategy
The strategy of each virtualization safety equipment is configured.
Optionally, the tactful configuration variance in the different virtualization resource pond of each manufacturer of shielding, passes through unified safety
Strategy configuration interface configures the strategy of each virtualization safety equipment, specifically includes:
The tactful configuration variance for shielding the different virtualization resource pond of each manufacturer configures interface by unified security strategy
Batch configuration is carried out to the strategy of each virtualization safety equipment.
Second aspect, the embodiment of the present invention also propose a kind of general processing unit in secure resources pond, comprising:
Interface connection module passes through unified interface for shielding the realization details in the different virtualization resource pond of each manufacturer
It is attached with each virtualization resource pond;
Integration module is driven, for integrating the driving in various virtualization resource ponds, each void is adapted to by the driving after integrated
Quasi-ization resource pool;
Equipment operation module, the virtualization safety equipment for creating each virtualization resource pond in secure resources pond carry out
Operation.
Optionally, the equipment operation module is specifically used for creating the virtual of each virtualization resource pond in secure resources pond
Change safety equipment, and virtualization safety equipment is started, stops, deleting or reboot operation;
Optionally, described pair of virtualization safety equipment is started, is stopped, being deleted or reboot operation passes through unified life
Cycle management interface executes.
Optionally, described device further include:
Tactful configuration device passes through unification for shielding the tactful configuration variance in the different virtualization resource pond of each manufacturer
Security strategy configuration interface to it is each virtualization safety equipment strategy configure.
Optionally, the tactful configuration device is specifically used for shielding the strategy configuration in the different virtualization resource pond of each manufacturer
Difference configures interface by unified security strategy and carries out batch configuration to the strategy of each virtualization safety equipment.
The third aspect, the embodiment of the present invention also propose a kind of electronic equipment, comprising:
At least one processor;And
At least one processor being connect with the processor communication, in which:
The memory is stored with the program instruction that can be executed by the processor, and the processor calls described program to refer to
Order is able to carry out the above method.
Fourth aspect, the embodiment of the present invention also propose a kind of non-transient computer readable storage medium, the non-transient meter
Calculation machine readable storage medium storing program for executing stores computer program, and the computer program makes the computer execute the above method.
As shown from the above technical solution, the embodiment of the present invention is attached by unified interface and each virtualization resource pond,
It is adapted to each virtualization resource pond by the driving after integrated, and creates the virtualization in each virtualization resource pond in secure resources pond
Safety equipment is operated, and shields the difference of underlying virtual resource pool realization technology and the strategy of safety equipment without legally constituted authority
The problem of one configuration, the realization for the upper layer cloud safe operation platform based on secure resources pond provides beneficial support, reaches
The high quality requirement of the i.e. service of safety.
Specific embodiment
With reference to the accompanying drawing, further description of the specific embodiments of the present invention.Following embodiment is only used for more
Technical solution of the present invention is clearly demonstrated, and not intended to limit the protection scope of the present invention.
Fig. 1 shows a kind of flow diagram of the universal process method in secure resources pond provided in this embodiment, comprising:
The realization details in the different virtualization resource pond of S101, each manufacturer of shielding, is provided by unified interface and each virtualization
Source pond is attached.
Specifically, the virtualization resource pond that different vendor is docked by unified interface, shields different virtualization resource ponds
It realizes details, a resource tank adapter is provided, unified interface is provided upwards, details is realized in shielding underlying resource pond.
S102, the driving for integrating various virtualization resource ponds are adapted to each virtualization resource pond by the driving after integrated.
Specifically, secure resources pond integrates downwards the driving in various virtualization resource ponds, each different virtual to be adapted to
Change resource pool.
S103, the virtualization safety equipment that each virtualization resource pond is created in secure resources pond are operated.
It specifically, can be very square after the virtualization safety equipment that each virtualization resource pond is created in secure resources pond
Just various operations are executed to the virtualization safety equipment of creation.
The present embodiment is attached by unified interface and each virtualization resource pond, is adapted to each void by the driving after integrated
Quasi-ization resource pool, and the virtualization safety equipment for creating in secure resources pond each virtualization resource pond is operated, and is shielded
Underlying virtual resource pool realizes that the difference of technology and the strategy of safety equipment can not unify the problem of configuring, for based on safety
The realization of the upper layer cloud safe operation platform of resource pool provides beneficial support, has reached the high quality requirement of the i.e. service of safety.
Further, described that each virtualization resource is created in secure resources pond on the basis of above method embodiment
The virtualization safety equipment in pond is operated, and is specifically included:
Create the virtualization safety equipment in each virtualization resource pond in secure resources pond, and to virtualization safety equipment into
Row starting, stopping, deletion or reboot operation;
Wherein, described pair of virtualization safety equipment is started, is stopped, being deleted or reboot operation passes through unified Life Cycle
Period management interface executes.
Specifically, to the operation of virtualization safety equipment, creation, starting, stopping, deletion including virtualizing safety equipment
With the operation such as restart, secure resources pond provides unified lifecycle management interface upwards, for shielding underlying device operation
Otherness.
Further, on the basis of above method embodiment, the method also includes:
The tactful configuration variance in the different virtualization resource pond of S104, each manufacturer of shielding, is matched by unified security strategy
Interface is set to configure the strategy of each virtualization safety equipment.
Further, on the basis of above method embodiment, S104 is specifically included:
The tactful configuration variance for shielding the different virtualization resource pond of each manufacturer configures interface by unified security strategy
Batch configuration is carried out to the strategy of each virtualization safety equipment.
Specifically, the strategy configuration of secure resources pond unified management inhomogeneity safety equipment, such as the fire prevention of different vendor
Wall, the WAF of different vendor provide unified security strategy upwards and match by shielding the tactful configuration variance of different vendor's equipment
Interface is set, user does not need the firewall which security firm care is, user is it is only necessary to know that this is a firewall box
, while being also able to achieve the batch configuration of multiple firewall boxes.
The present embodiment is able to solve the problem of cloud security resource pool landing adaptation virtualization resource pond and virtualization safety
The problem of security strategy of component centralized and unified configuration, guarantees that cloud security resource pool can be adapted to various virtualization resource ponds, together
The safety equipment of Shi Butong security firm can be unified to configure.
Specifically, referring to fig. 2, the present embodiment on cloud security resource pool by designing a cloud security Centralized Controller
Come solve the problems, such as cloud security resource pool adaptation and security component cannot centralized configuration the problem of, the specific steps are as follows:
A safe centralized controller is designed on secure resources pond, which there are three zones: resource pool pair
Take over reason, security component life cycle management, security strategy configuration management.
Resource pool docking management shields the realization in different virtualization resource ponds for docking different vendor's virtualization resource pond
Details, resource pool docking management provide a resource tank adapter, provide unified interface upwards, and shielding underlying resource pond is realized
Details passes downwardly through and integrates the driving in various virtualization resource ponds and go to adapted resource pond.
Operation of the security component life cycle management for unified each virtualization safety equipment, including virtualization safety equipment
Creation, starting, stopping, the operation such as delete and restart, which provides unified lifecycle management interface upwards, shields bottom
The otherness of layer equipment operation.
Security strategy configuration management is used to be managed collectively the strategy configuration of inhomogeneity safety equipment, provides unified peace upwards
Full strategy configuration interface, user do not have to the firewall which security firm care is, user is it is only necessary to know that this is a fire prevention
Wall equipment, while being also able to achieve the batch configuration of multiple firewall boxes.
A cloud is realized by resource pool docking management, security component life cycle management and security strategy configuration management
The Centralized Controller of safety, the controller provide the dispatch service of unified safety equipment, the life cycle of safety equipment upwards
The configuration orchestrating services of management and security strategy.
For example, there are two cloud platforms for certain enterprise, and corresponding two virtualization resource ponds, two virtualization resource ponds are realized
Technology is different, while user has purchased the firewall of Liang Ge manufacturer, the unified security strategy for configuring firewall is needed, for this
Demand, the drive that the present embodiment passes through resource pool docking management the two virtualization resource ponds of module loading of safe centralized controller
It is dynamic, complete the docking of two resource pools;It is unified by the security component life cycle management module management of safe centralized controller
The life cycle of safety equipment in two secure resources ponds is responsible for the creation of equipment, the operation such as deletes, starts and stops;It is logical
The firewall for crossing the security strategy configuration module docking Liang Ge manufacturer of safe centralized controller, provides unified security strategy upwards
Configuration, user can unify or multiple firewalls of batch configuration Liang Ge manufacturer.
The present embodiment is shielded by devising a kind of cloud security Centralized Controller by three nucleus modules of controller
Underlying virtual resource pool realizes that the difference of technology and the strategy of safety equipment can not unify the problem of configuring, for based on safety
The realization of the upper layer cloud safe operation platform of resource pool provides beneficial support, and cloud security operation platform passes through safe centralized control
Device can dispatch the safety equipment in any secure resources pond, and unified or batch configuration security strategy, be really achieved safety
The high quality requirement serviced.
Fig. 3 shows a kind of structural schematic diagram of the general processing unit in secure resources pond provided in this embodiment, described
Device includes: interface connection module 301, driving integration module 302 and equipment operation module 303, in which:
The interface connection module 301 is used to shield the realization details in the different virtualization resource pond of each manufacturer, passes through system
One interface is attached with each virtualization resource pond;
The driving integration module 302 is used to integrate the driving in various virtualization resource ponds, suitable by the driving after integrated
With each virtualization resource pond;
The virtualization that the equipment operation module 303 is used to create each virtualization resource pond in secure resources pond is set safely
It is standby to be operated.
Specifically, the interface connection module 301 shields the realization details in the different virtualization resource pond of each manufacturer, passes through
Unified interface is attached with each virtualization resource pond;The driving integration module 302 integrates the drive in various virtualization resource ponds
It is dynamic, each virtualization resource pond is adapted to by the driving after integrated;The equipment operation module 303 creates respectively in secure resources pond
The virtualization safety equipment in virtualization resource pond is operated.
The present embodiment is attached by unified interface and each virtualization resource pond, is adapted to each void by the driving after integrated
Quasi-ization resource pool, and the virtualization safety equipment for creating in secure resources pond each virtualization resource pond is operated, and is shielded
Underlying virtual resource pool realizes that the difference of technology and the strategy of safety equipment can not unify the problem of configuring, for based on safety
The realization of the upper layer cloud safe operation platform of resource pool provides beneficial support, has reached the high quality requirement of the i.e. service of safety.
Further, on the basis of above-mentioned apparatus embodiment, the equipment operation module 303 is specifically used for providing in safety
The virtualization safety equipment in each virtualization resource pond is created in the pond of source, and virtualization safety equipment is started, stops, deleting
Or reboot operation;
Further, on the basis of above-mentioned apparatus embodiment, described pair of virtualization safety equipment started, stopped,
It deletes or reboot operation is executed by unified lifecycle management interface.
Further, on the basis of above-mentioned apparatus embodiment, described device further include:
Tactful configuration device passes through unification for shielding the tactful configuration variance in the different virtualization resource pond of each manufacturer
Security strategy configuration interface to it is each virtualization safety equipment strategy configure.
Further, on the basis of above-mentioned apparatus embodiment, the strategy configuration device is specifically used for shielding each manufacturer
The tactful configuration variance in different virtualization resource ponds configures interface to each virtualization safety equipment by unified security strategy
Strategy carry out batch configuration.
The general processing unit in secure resources pond described in the present embodiment can be used for executing above method embodiment, former
Reason is similar with technical effect, and details are not described herein again.
Referring to Fig. 4, the electronic equipment, comprising: processor (processor) 401, memory (memory) 402 and total
Line 403;
Wherein,
The processor 401 and memory 402 complete mutual communication by the bus 403;
The processor 401 is used to call the program instruction in the memory 402, to execute above-mentioned each method embodiment
Provided method.
The present embodiment discloses a kind of computer program product, and the computer program product includes being stored in non-transient calculating
Computer program on machine readable storage medium storing program for executing, the computer program include program instruction, when described program instruction is calculated
When machine executes, computer is able to carry out method provided by above-mentioned each method embodiment.
The present embodiment provides a kind of non-transient computer readable storage medium, the non-transient computer readable storage medium
Computer instruction is stored, the computer instruction makes the computer execute method provided by above-mentioned each method embodiment.
The apparatus embodiments described above are merely exemplary, wherein described, unit can as illustrated by the separation member
It is physically separated with being or may not be, component shown as a unit may or may not be physics list
Member, it can it is in one place, or may be distributed over multiple network units.It can be selected according to the actual needs
In some or all of the modules achieve the purpose of the solution of this embodiment.Those of ordinary skill in the art are not paying creativeness
Labour in the case where, it can understand and implement.
Through the above description of the embodiments, those skilled in the art can be understood that each embodiment can
It realizes by means of software and necessary general hardware platform, naturally it is also possible to pass through hardware.Based on this understanding, on
Stating technical solution, substantially the part that contributes to existing technology can be embodied in the form of software products in other words, should
Computer software product may be stored in a computer readable storage medium, such as ROM/RAM, magnetic disk, CD, including several fingers
It enables and using so that a computer equipment (can be personal computer, server or the network equipment etc.) executes each implementation
Method described in certain parts of example or embodiment.
It is noted that the above embodiments are merely illustrative of the technical solutions of the present invention, rather than its limitations;Although reference
Invention is explained in detail for previous embodiment, those skilled in the art should understand that: it still can be right
Technical solution documented by foregoing embodiments is modified or equivalent replacement of some of the technical features;And this
It modifies or replaces, the spirit and model of technical solution of various embodiments of the present invention that it does not separate the essence of the corresponding technical solution
It encloses.