TW201243617A - Cloud computing-based service management system - Google Patents

Cloud computing-based service management system Download PDF

Info

Publication number
TW201243617A
TW201243617A TW101114098A TW101114098A TW201243617A TW 201243617 A TW201243617 A TW 201243617A TW 101114098 A TW101114098 A TW 101114098A TW 101114098 A TW101114098 A TW 101114098A TW 201243617 A TW201243617 A TW 201243617A
Authority
TW
Taiwan
Prior art keywords
security
information
entity
server
object entity
Prior art date
Application number
TW101114098A
Other languages
Chinese (zh)
Other versions
TWI460596B (en
Inventor
xi-cong Zhang
Original Assignee
Tianxuntianwang Fujian Network Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tianxuntianwang Fujian Network Technology Co Ltd filed Critical Tianxuntianwang Fujian Network Technology Co Ltd
Publication of TW201243617A publication Critical patent/TW201243617A/en
Application granted granted Critical
Publication of TWI460596B publication Critical patent/TWI460596B/zh

Links

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

The invention provides a cloud computing-based service management system, which comprises a security object entity device, a database management device and a server entity device. The security object entity device comprises security units and security object entities, wherein security management rights are set in the security units; and each security object entity belongs to corresponding security units. The database management device stores the information of the security units and the information of the security object entities. The server entity device comprises a control center and an updating server cluster, wherein the control center finds the security object entity required to be served and the corresponding security unit from the security object entity device according to the information of the security units and the information of the security object entities from the database management device, and when a manager of the service management system meets the security management rights of the corresponding security unit, calls an updating server from the updating server cluster to provide a service for the security object entity required to be served. The cloud computing-based service management system can schedule security resources in the whole network to provide network security protection for all terminals.

Description

.201243617 六、發明說明: 【發明所屬之技術領域】 本發明是關於電子資訊安全技術,尤指—種基於雲端 運算的服務管理系統β 【先前技術】 隨著人們的資訊化水平不斷提升,對網路的依賴曰趨 加深,網路資訊安全日益成為資訊化健康發展所要考慮的 重要問題。所以資訊安全和網路安全等技術已成為目前研 究和發展的技術熱點。目前的安全技術主要是針對於區域 網路,區域網路是-種覆蓋一座或幾座大樓、一個校園或 者-個廠區等地理區域的小範圍的電腦網,具有很大的局 限性,通過每個區域網路分配一個升級飼服器,那麼這個 區域網路内的所有客戶就都只能到這個祠服器上升級。且 傳統產品銷售模式不僅得支付安全軟體購買的費用,最終 用戶也需要再次採購词服器硬體,除了個人電腦和網際網 路連接之外的其他IT投資不能通過網際網路獲得所需要軟 體和服務。而現在的應用性能管理(AppUcatj〇n.201243617 VI. Description of the Invention: [Technical Field] The present invention relates to electronic information security technology, and more particularly to a cloud computing-based service management system. [Prior Art] As people's informationization level continues to increase, The dependence of the Internet has deepened, and network information security has increasingly become an important issue to be considered for the healthy development of information technology. Therefore, technologies such as information security and network security have become the hotspots of current research and development. The current security technology is mainly for regional networks. The regional network is a small-scale computer network covering one or several buildings, a campus or a geographical area such as a factory. It has great limitations. Each regional network is assigned an upgraded feeder, so all customers in the local area network can only upgrade to this server. And the traditional product sales model not only has to pay for the purchase of secure software, but the end user also needs to purchase the word processor hardware again. Other IT investments other than personal computers and Internet connections cannot obtain the required software through the Internet. service. And now application performance management (AppUcatj〇n

Performance Management)系統或者業務服務管理 (Business Service Management)系統雖然可以監控客戶的 應用和業務,但是卻沒有考慮到安全保障方面的因素。 安全管理平台的發展也經歷了一個從分散到集中的過 程。傳統的安全管理平台比較多的將焦點放到了對客戶資 產的安全風險’尤其是隱性的安全風險管理之上,借助安 全事件的分析和處理過程建立起了一套應急回應流程。但 疋’傳統的安全管理卻存在不少管理上的缺失,嚴重影響 201243617 了安管平台的應用效果: 1.傳統的安全管理資訊來源單—,安全分析不全面; 2 _傳統的安全管理片面強調解決隱性安全問題,缺乏 實效性。 基於這種背景,通訊行業提出了能夠實現相容的有網 路結構的網路安全營運與管理平台的理論,該平台又稱資 訊女全官理平σ。s則作為丨下產業核心的電信網路正在朝 多網融合、終端設備智慧化、網路結構丨p化、業務導向等 方向發展,4旦同時資訊#全問題及其造成的影響也在以更 快的速度加劇,安全威脅逐漸從用戶和終端側向網路核心 蔓延,原來認為安全的網路核心管理系統正逐漸面臨著巨 大的安全壓力。 因此迫切需要一個能夠整合網路安全資源的安全營運 及管理的資訊安全管理平台,以便企業或電信等群體性組 織能夠在該平台的基礎上利用現有安全設備提升網路安全 防護和預警能力。 【發明内容】 本發明主要目的在於提供一個能夠整合網路安全資源 的安全營運及管理的資訊安全管理平台,以便企業或電_ 等群體性組織能夠在該平台的基礎上利用現有安全設備提 升網路安全防護和預警能力。 為達成前述目的採取的主要技術手段係令前述基於带 端運算的服務管理系統包括: 安全對象實體裝置,包括安全單元和安全對象實體, 4 .201243617 安全單元上設置有安全管理許可權,其中,每個安全對象 實體從屬於相應的安全單元; 資料庫管理裝置,保存安全單元的資訊、安全對象實 體的資訊; 伺服器實體裝置,包括控制中心和升級伺服器叢集, 控制中心根據來自資料庫管理裝置的安全單元的資訊、安 全對象實體的資訊,在安全對象實體裝置中查找出需求服 務的安全對象實體和其從屬安全單元,並在服務管理系統 的官理員滿足從屬安全單元的安全管理許可權時,從升級 伺服器叢集中調用升級伺服器為需求服務的安全對象實體 提供服務。 在該技術方案中,所提供服務包括但不限於安全服務 ,安全對象實體包括但不限於個人電腦等終端,根據該技 術方案,能夠調度整個網路内的安全資源為所有的終端提 供網路安全防護。 在上述技術方案中,優選地,還包括:平衡伺服器, 獲取升級伺服器叢集的實體資訊,以用於判斷升級伺服器 叢集的負載情況;資料庫管理裝置還儲存升級伺服器叢集 的實體資訊,控制中心根據升級伺服器叢集的實體資訊來 調用升級飼服器,則呆證升級词服器的負載在預定範圍内 0 在上述技術方案令,優選地,平衡伺服器還獲取升級 伺服器叢集的狀態資訊,以用於判斷升級伺服器叢集是否 出現異常,f料庫管理裝置還儲存升級词服器叢集的狀態 資訊,控制中心根據升級祠服器叢集的狀態資訊來調用升 201243617 級伺服器’以保證升級伺服器未出現異常。 在上述技術方案中,優選地,平衡伺服器還獲取升級 飼服器叢集的動態配置資訊,管理員還通過控制中心修改 升級伺服器叢集中任一升級伺服器的動態配置資訊。 在上述技術方案中,優選地,安全單元的資訊包括安 全單元的標識資訊’控制中心根據安全單元的標識資訊, 查找出從屬安全單元。 在上述技術方案中,優選地,安全單元的資訊包括為 安全單元指定的伺服器的資m,控制中心根據為從屬安全 單元指定的升級飼服器的資訊’ €先選擇指定的升級词服 器作為提供服務的升級伺服器。 在上述技術方案中,優選地,安全對象實體的資訊包 括安全對象實體的電腦資訊,以用於判斷安全對象實體: 運行的服務的狀態;控制中心根據安全對象實體的電腦資 訊’查找出需求服務的安全對象實體。 在上述技術方案中’優選地,安全對象實體的資 括安全對象實體的中毒資訊,以用於判斷安全對象實體的 中毒情況;控制中心根據安全對象實體的中毒f訊, 出需求服務的安全對象實體。 在上述技術方案中,優選 :安全辅助伺服器,與安全對 集安全對象實體的中毒資訊, 地,伺服器實體裝置還包括 象實體建立通信通道,以收 並儲存至安全對象實體裝置 在上述技術方案中,優選地,控制中心通過安 祠服器,收集每個安全單元下的安全對象實體的資訊。助 201243617 根據本發明的技術方案,可以提供一種基於雲端運算 的服務管n统,可以整合網路安全資源,以便企業或電 l等群體性組織能夠在該平台的基礎上利用現有安全設備 提升網路安全防護和預警能力。 【實施方式】 為了能夠更清楚地理解本發明的上述目的、特徵和優 點,下面結合附圖和具體實施方式對本發明進行進一步的 洋細述。 在下面的描述中闡述了很多具體細節以便於充分理解 本發明’但是,本發明還可以採用其他不同於在此描述的 其他方式來實施,因此,本發明並不限於下面公開的具體 實施例的限制。 圖1是本發明基於雲端運算的服務管理系統一個實施 例的方塊圖。 如圖1所巾,本發明提供一種基於雲端運算的服務管 理系統100,包括:安全對象實體裝置1〇2,包括安全單 元和安全對象實體,安全單元上設置有安全管理許可權, 其中,每個安全對象實體從屬於相應的安全單元;資料庫 管理裝置1G4’保存安全單元的資訊、安全對象實體的資 訊’词服器實體裝f 1G6 ’包括控制中心、和升級祠服器叢 集,控制中心根據來自資料庫管理裝置1〇4的安全單元的 資訊、女全對象實體的資訊,在安全重子象實體裝I 1〇2中 查找出需求服務的安全對象實體和其從屬安全單元,並在 服務管理系統的管理員滿足從屬安全單元的安全管理許可 201243617 權時,從升級伺服器叢集中調用升級伺服器為需求服務的 安全對象實體提供服務。在該技術方案甲,所提供服務包 括但不限於安全服務’安全對象實體包括但不限於個人電 腦等終端,根據該技術方案’能夠調度整個網路内的安全 資源為所有的終端提供網路安全防護。 在上述技術方案中,還包括:平衡伺服器,獲取升級 伺服器叢集的實體資訊,以用於判斷升級伺服器叢集的負 載it况’資料庫管理裝i i Q4還儲存升級祠服器叢集的實 體資訊’控制中心根據升級飼服器叢集的實體資訊來調用 升級飼服器,以保證升級伺服器的負載在預定範圍内。 在上述技術方案中,平衡飼服器還獲取升級词服器叢 集的狀態資訊,以用於判斷升級伺服器叢集是否出現異常 ’資料庫e理裝置1 (M還儲存升級飼服器叢集的狀態資訊 控制中〜根據升級飼服器叢集的狀態資訊來調用升級祠 服器,以保證升級飼服器未出現異常。 在上述技術方案中,平衡词服器還獲取升級祠服器叢 集的動態配置資訊,管理員還通過控制中心修改升級伺服 器叢集中任一升級伺服器的動態配置資訊。 在上述技術方案中,安全單元的資訊包括安全單元的 標識資訊,控制中心根墟容^^ g , 很髁文全早兀的標識資訊,查找出從 屬安全單元。 在上述技術方案中 指定的伺服器的資訊, 的升級伺服器的資訊, 供服務的升級伺服器。 ’女全單元的資訊包括為安全單元 控制中心根據為從屬安全單元指定 優先選擇指定的升級伺服器作為提The Performance Management system or Business Service Management system can monitor customer applications and services, but does not take into account security factors. The development of the security management platform has also undergone a process from decentralization to concentration. The traditional security management platform has placed more emphasis on the security risks of customer assets, especially implicit security risk management. A set of emergency response processes has been established through the analysis and processing of security incidents. However, there are a lot of management defects in the traditional security management, which seriously affects the application effect of the security management platform in 201243617: 1. The traditional security management information source list—the security analysis is not comprehensive; 2 _Traditional security management one-sided Emphasis on the solution of hidden security issues, lack of effectiveness. Based on this background, the communications industry has proposed a theory that can achieve a compatible network security operation and management platform with a network structure, which is also known as the female full-time official. s, as the core of the industry, the telecommunications network is developing towards multi-network convergence, terminal equipment intelligence, network structure, business orientation, etc. The faster the speed is intensified, the security threat gradually spreads from the user and the terminal side to the core of the network. It is believed that the secure network core management system is gradually facing enormous security pressure. Therefore, there is an urgent need for an information security management platform that can integrate the secure operation and management of network security resources, so that group organizations such as enterprises or telecommunications can use existing security devices to enhance network security protection and early warning capabilities based on the platform. SUMMARY OF THE INVENTION The main objective of the present invention is to provide an information security management platform capable of integrating security operations and management of network security resources, so that enterprises or groups can use existing security devices to upgrade the network based on the platform. Road safety protection and early warning capabilities. The main technical means for achieving the foregoing objective is that the foregoing service management system based on the end-end operation includes: a security object entity device, including a security unit and a security object entity, 4.201243617 security unit is provided with security management permission, wherein Each security object entity is subordinate to the corresponding security unit; the database management device stores the information of the security unit and the information of the security object entity; the server entity device includes the control center and the upgrade server cluster, and the control center is managed according to the database. The information of the security unit of the device, the information of the security object entity, the security object entity of the demand service and its subordinate security unit are found in the security object entity device, and the security management permission of the subordinate security unit is satisfied by the official of the service management system At the time of the right, the upgrade server is called from the upgrade server cluster to provide services for the security object entity of the demand service. In the technical solution, the provided service includes but is not limited to a security service, and the security object entity includes but is not limited to a terminal such as a personal computer. According to the technical solution, the security resources in the entire network can be scheduled to provide network security for all terminals. Protection. In the above technical solution, preferably, the method further includes: balancing the server, obtaining entity information of the upgrade server cluster, for determining the load condition of the upgrade server cluster; and the database management device further storing the entity information of the upgrade server cluster The control center invokes the upgraded feeding device according to the entity information of the upgrade server cluster, and the load of the upgraded word server is within a predetermined range. In the above technical solution, preferably, the balancing server also obtains the upgrade server cluster. The status information is used to judge whether the upgrade server cluster is abnormal. The f library management device also stores the status information of the upgraded word server cluster, and the control center calls the upgraded 201243617 level server according to the status information of the upgrade server cluster. 'To ensure that the upgrade server does not have an exception. In the above technical solution, preferably, the balance server also obtains dynamic configuration information of the upgraded feeder cluster, and the administrator also modifies the dynamic configuration information of any upgrade server in the upgrade server cluster through the control center. In the above technical solution, preferably, the information of the security unit includes the identification information of the security unit, and the control center searches for the dependent security unit according to the identification information of the security unit. In the above technical solution, preferably, the information of the security unit includes the resource of the server specified for the security unit, and the control center selects the designated upgrade word server according to the information of the upgraded feeder designated by the slave security unit. As an upgrade server that provides services. In the above technical solution, preferably, the information of the security object entity includes computer information of the security object entity for determining the security object entity: the status of the running service; and the control center searches for the demand service according to the computer information of the security object entity. Security object entity. In the above technical solution, 'preferably, the security object entity includes the poisoning information of the security object entity for judging the poisoning situation of the security object entity; and the control center according to the poisoning information of the security object entity, the security object of the demand service entity. In the above technical solution, preferably: the security assist server, and the poisoning information of the security object to the security object entity, the server entity device further comprises a communication channel for the entity to collect and store the device to the security object. In the solution, preferably, the control center collects information of the security object entity under each security unit through the security server. Assist 201243617 According to the technical solution of the present invention, a cloud computing-based service management system can be provided, which can integrate network security resources, so that an enterprise or a group of organizations can use the existing security devices to upgrade the network based on the platform. Road safety protection and early warning capabilities. The present invention will be further described in detail below with reference to the drawings and specific embodiments. In the following description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, the invention may be practiced otherwise than as described herein. limit. BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 is a block diagram showing an embodiment of a cloud computing based service management system of the present invention. As shown in FIG. 1 , the present invention provides a cloud computing-based service management system 100, including: a security object entity device 1-2, including a security unit and a security object entity, where security management permissions are set on the security unit, where each The security object entity belongs to the corresponding security unit; the database management device 1G4' stores the information of the security unit, the information of the security object entity 'word server entity f 1G6' includes the control center, and the upgrade server cluster, the control center According to the information from the security unit of the database management device 1.4, the information of the female entity entity, the security object entity and its dependent security unit of the demand service are found in the security bar image entity I 1〇2, and the service is When the administrator of the management system satisfies the security management license 201243617 of the subordinate security unit, the upgrade server is called from the upgrade server cluster to provide services for the security object entity of the demand service. In the technical solution A, the services provided include, but are not limited to, security services. The security object entity includes but is not limited to a terminal such as a personal computer. According to the technical solution, the security resources in the entire network can be scheduled to provide network security for all terminals. Protection. In the above technical solution, the method further includes: balancing the server, obtaining entity information of the upgrade server cluster, and determining the load of the upgrade server cluster. The database management device ii Q4 also stores the entity of the upgrade server cluster. The information 'control center calls the upgraded feeder according to the entity information of the upgraded feeder bundle to ensure that the load of the upgrade server is within the predetermined range. In the above technical solution, the balance feeding device also obtains the status information of the upgraded word server cluster for judging whether the upgrade server cluster is abnormal or not. The database also stores the status of the upgraded feeder cluster. In the information control, the upgrade server is called according to the status information of the upgraded feeder cluster to ensure that there is no abnormality in the upgraded feeder. In the above technical solution, the balanced word server also obtains the dynamic configuration of the upgraded server cluster. Information, the administrator also modifies the dynamic configuration information of any upgrade server in the upgrade server cluster through the control center. In the above technical solution, the information of the security unit includes the identification information of the security unit, and the control center root volume ^^ g , It is very early to identify the subordinate security unit. The information about the server specified in the above technical solution, the information of the upgrade server, the server for upgrading the service. The security unit control center is based on the upgrade server specified for the priority selection of the slave security unit.

S 8 201243617 在上述技術方案中’安全對象實體的資訊 象實體的電腦資訊,以用於判斷 女全對 抵μ能對象實體上運行的服 務的狀態,㈣中心、根據安全對㈣體的㈣ 出需求服務的安全對象實體。 一 & 訊包括安全對 體的中毒情況 查找出需求服 在上述技術方案中,安全對象實體的資 象實體的中毒資訊’以用於判斷安全對象實 ;控制中心根據安全對象實體的中毒資訊, 務的安全對象實體。 …㈣万累中,飼服器實體裝置1〇6 全輔助伺服器,與安全對象實體建立通信通道,以收集安 全對象實體的中毒資訊,並健存至安全對象實體袭置/、 在上述技術方案中,控制中心通過安全輔助飼服器, 收集每個安全單元下的安全對象實體的資訊。 圖2是根據本發明的一個實施例的基於雲端運算的服 務管理系統的示意圖》 如圖2所不,是一個基於雲端運算的服務管理系統的 示意圖》 首先,對以下概念進行解釋: 1、安全單元: 疋指安全管理抽象和概念化的最小單位,它可以由一 個或多個女全單兀再組合成一個更大的安全單元,它可以 同時屬於多個安全單元;把安全單元看成一個節點,所有 的郎點按照這樣的歸屬關係最終形成了 一個層次關係,越 上層的節點包含的子安全單元個數越多,越下層的節點則 越少,安全單元之間的從屬關係可以如圖3所示; 201243617 2、安全管理許可權: 指的是將—個或多個安 給該管理單位定義-個名/、一個管理單元,並 問密碼的用戶就曰其理吕:問密碼’具有該名稱和訪 管理單位= 理員也就具備了管理這個 點都可以定義-個許可權,::::的能力,任何-個節 問和管理該節點及歸屬它的所、=權的管理員可以訪 3、安全對象實體: ;b疋*全保護抽象和概念化的最小單位 護顆粒,是具體的保護 ^ ’、的保 單%,匕有且僅能屬於具體的某個安 = 體的特徵是具備基本的硬體,…广*全對象實 例的服務管理系統或具備安全管理許可 裝有本=施 ,該pc電腦可以與 了權的個A Pc電腦 耸…-X ^霄現正节的網路通信。它是安全 &理和女㈣護的實際對象,是以單個個體存在的。 本實施例的服務管理系統200包括: 請管理域2Q2:該域用於儲存所有安㈣理對 訊、文全服務對象資訊、安 的安全資訊,它由一定數:二實體“以及其他額外 ^ s ^ 疋數量的女全儲存設備和安全儲存設 實體乒π;:片、儲存軟體等這類儲存資訊資料所必須的 貫體共同組合而成。續眘斗立 成°亥#枓欄儲存的所有資料資訊為安全 提供了基本的後台支援,它是根據词服器 實體域和…元與安全對象的邏輯關係、安全 1Τ以及整個安全平台所必須提供的升級服務、實體對 象S理服務而建立起來的資料欄。 201243617 伺服器實體域204 :該域是所有安全對象和安全實體 得到安全保護和安全管理的服務提供單位,該域所有的伺 服器暴露于任何一個安全對象實體所能訪問的網際網路環 境中,任何一個安全對象實體都從該域中獲取到相應的服 務; 安全對象實體域206 :該域是安全管理和安全保護的 基本單位,所有的安全單元2062和安全對象實體2064構 成了該域。 其中,所述資料庫管理域202包括: 安全單元管理資料庫2022 :儲存安全單元2062的資 訊,安全單元2062具有從屬關係,包含創建與更改時間資 訊,安全單元2062具有唯一標識、同時包含一個描述它的 名稱:安全單元2062是安全管理的最小單位,它管理和包 含具體的安全對象實體2064,以安全單元2062作為保護 單位也就是保護了它所包含的所有安全對象實體2064,做 到安全保護整體化而撇開安全保護個體化。 所述安全單元管理資料庫2022就是儲存這些與安全單 元2062相關的建立與更新時間、從屬關係、標識以及可描 述的名稱等必須的安全管理和安全保護資訊。 安全伺服器實體管理資料庫2024 :儲存安全升級伺服 器叢集的資訊,其中,安全升級伺服器叢集按層次劃分為 安全控制中心伺服器2042、安全升級伺服器2044與安全 辅助伺服器2046三個層面。 其中,控制中心2042是最高管理者管理所有的安全升 級伺服器中心2044、安全輔助伺服器2046,同時負責安 11 201243617 全單元2062的合法性檢驗並調度安全升級伺服器2〇44和 安全輔助伺服器2046的負載平衡;安全升級伺服器2〇44 為安全單το 2062提供保護功能,但基於具體的服務實體具 有最大上限、現有保護狀態與保護數量、服務實體在空間 中的位置這類資訊,安全伺服器實體管理資料庫2〇24儲存 的就是這類資訊;安全控制中心伺服器2〇42與安全輔助伺 服器2046將從安全伺服器實體管理資料庫2〇24和安全單 元管理資料庫2022儲存的資料資訊中實現控制和提供輔助 服務功能。 所述服務實體域204包括: 其中’所述安全控制中心伺服器2042 : 只負責控制雲端安全服務的正常運轉和負載平衡,負 責對保護單元2062的保護合法性驗證,所有服務都是以它 為中心。 其中’所述安全升級伺服器叢集: 它們主要負貴提供給保護單元2〇62安全資訊的更新服 務,我們通過提供一個或多個升級伺服器來解決由於硬體 和軟體的性能極限而導致的升級服務效率低下等性能問題 〇 其中’所述安全輔助伺服器2046 : 安全管理所針對的具體對象是安全對象實體2〇64,安 全管理員最終管理的安全對象實體2064 ,安全輔助伺服器 2046可以辅助安全管理員管理保護單元2062和實際的安 全對象實豸2064’可以幫助安全管理員查看他所能控制的 安全單元2062和安全對象實體2064的安全狀態並幫助解S 8 201243617 In the above technical solution, the information of the security object entity is like the computer information of the entity for judging the state of the service running on the female entity against the μ energy object, (4) the center, according to the security (four) body (four) The security object entity of the demand service. A & information includes a poisoning situation of the security object to find out the demand in the above technical solution, the poisoning information of the image entity of the security object entity is used to determine the security object; the control center according to the poisoning information of the security object entity, Security object entity. ... (4) In the middle of the tens of thousands of cases, the feeding device physical device 1〇6 full auxiliary server establishes a communication channel with the security object entity to collect the poisoning information of the security object entity, and saves to the security object entity attack/, in the above technology In the solution, the control center collects information on the security object entities under each security unit through a security assisted feeder. 2 is a schematic diagram of a cloud computing-based service management system according to an embodiment of the present invention. FIG. 2 is a schematic diagram of a cloud computing-based service management system. First, the following concepts are explained: 1. Security Unit: 最小 refers to the minimum unit of security management abstraction and conception, which can be combined into one larger security unit by one or more female singular units, which can belong to multiple security units at the same time; see security unit as a node According to such a affiliation relationship, all the lang points finally form a hierarchical relationship. The higher the number of sub-security units included in the upper node, the fewer the lower-level nodes, and the affiliation between the security units can be as shown in Fig. 3. 201243617 2. Security management permission: Refers to the definition of one or more security units to the management unit - a name /, a management unit, and the user who asks for the password is ruling: ask the password 'has The name and visit management unit = the administrator also has the ability to manage this point can be defined - a license, :::: ability, any - section And the management of the node and the administrator who belongs to it, the right to access 3, the security object entity: ; b疋 * full protection abstraction and conceptualized minimum unit protection particles, is the specific protection ^ ', the policy%, 匕There is a specific feature of a certain security body that is basic hardware, ... a wide-area instance of the service management system or a security management license installed with this = Shi, the pc computer can be right A Pc computer towers ... - X ^ 霄 now the section of the network communication. It is the actual object of security & and women (4), and exists as a single individual. The service management system 200 of this embodiment includes: Please manage the domain 2Q2: the domain is used to store all security information, security information, security information, and a certain number: two entities "and other extra ^ s ^ 疋 The number of women's full storage devices and safe storage entities ping ping;: tablets, storage software, etc., which are necessary for the storage of information materials. Continued to be cautious. Data information provides basic back-end support for security. It is based on the logical relationship between the lexical entity domain and the meta-objects, security, and the upgrade services and entity objects that the entire security platform must provide. 201243617 Server Entity Domain 204: This domain is a service provider for security and security management of all security objects and security entities. All servers in this domain are exposed to the Internet accessible by any security object entity. In the road environment, any security object entity obtains the corresponding service from the domain; security object entity domain 206: the domain is secure The basic unit of management and security protection, all the security unit 2062 and the security object entity 2064 constitute the domain. The database management domain 202 includes: a security unit management database 2022: information of the storage security unit 2062, the security unit 2062 has a affiliation, including creation and change time information, security unit 2062 has a unique identifier, and includes a name describing it: security unit 2062 is the smallest unit of security management, which manages and contains a specific security object entity 2064 for security. The unit 2062 serves as a protection unit, that is, protects all the security object entities 2064 it contains, so that the security protection is integrated and the security protection is individualized. The security unit management database 2022 stores these establishments related to the security unit 2062. Required security management and security protection information such as update time, affiliation, identification, and descriptive name. Security Server Entity Management Database 2024: Stores information about the security upgrade server cluster, where the security upgrade server clusters are hierarchical Divided into security controls The heart server 2042, the security upgrade server 2044 and the security assistant server 2046 are three levels. Among them, the control center 2042 is the top management manager of all the security upgrade server centers 2044, the security assistant server 2046, and is responsible for the security 11 201243617 The legitimacy of the full unit 2062 verifies and schedules the load balancing of the security upgrade server 2〇44 and the security assistant server 2046; the security upgrade server 2〇44 provides protection for the security ticket το 2062, but has the largest based on the specific service entity The information of the upper limit, the existing protection status and the number of protections, and the location of the service entity in space, the security server entity management database 2〇24 stores such information; the security control center server 2〇42 and the security assistant server 2046 implements control and provides ancillary service functions from the data information stored in the secure server entity management database 2〇24 and the security unit management database 2022. The service entity domain 204 includes: wherein the security control center server 2042 is only responsible for controlling the normal operation and load balancing of the cloud security service, and is responsible for verifying the protection legality of the protection unit 2062. All services are based on it. center. Among them, the security upgrade server clusters: they are mainly provided to the protection unit 2〇62 security information update service, we provide one or more upgrade servers to solve the performance limitations caused by hardware and software. Performance problems such as inefficiency of the upgrade service, wherein the security assistance server 2046: the specific object targeted by the security management is the security object entity 2〇64, the security object entity 2064 finally managed by the security administrator, and the security assistance server 2046 can The secondary security administrator management protection unit 2062 and the actual security object entity 2064' can help the security administrator to view the security status of the security unit 2062 and the security object entity 2064 that he can control and help solve the problem.

S 12 201243617 決保護意外發生的問題。 安全輔助伺服器2046 :安全對象實體2064從屬於具 體的某個安全單元2〇62’而且該安全對象實體2064不能 同時屬於兩個或更多個安全單元2062,它是安全保護的最 小顆粒’是具體的安全保護對象,它僅對它所屬的安全單 疋或安全單元2062的父級安全單元可見;安全對象實體 2064的保護和管理是安全單元2〇62根本重視的對象,安 全對象實體2064的當前保護狀態、當前保護的安全層次、 當前保護的安全級別以及安全實體2064自身的資訊(包括 安全對象實體2064的硬體類型、安全對象實體2064的系 統類型與版本、安全對象實體2〇64所屬的安全單元2〇62 、女全對象實體2064所處的空間位置等等),記錄這些資 訊將為安全單元2062和安全管理員查看和分析安全對象實 體2064提供即時依據。 圖4是根據本發明的一個實施例的基於雲端運算的服 務管理系統的示意圖。 如圖4所示,以下對各域模組的功能技術特徵進行說 明: 一 ·資料管理域402技術特徵 由兩大類資料庫組成,分別是平衡負載資訊資料庫 4022和升級服務資訊資料庫4〇24。 其中平衡負載資訊資料庫4022運作于平衡飼服器上, 它主要儲存安全伺服器實體資訊和安全單元資訊(安全伺服 器實體即提供具體病毒和軟體等升級功能的伺服器),安全 伺服器實體資訊為平衡伺服器提供優先選擇升級位址的主 13 201243617 要依據,平衡伺服器還要即時監視各個升級位址上的伺服 器狀態和動態配置資sfl以達到滿足伺服器功能回應的即時 性要求,比如說: 1 ·每個升級伺服器上允許登錄的最大的用戶數量和當 前這個時刻已經登錄的用戶數量資訊已經儲存在安全伺服 器實體作息資料庫表中,平衡伺服器將根據這兩個資訊逐 個比較挑選出當前時刻用戶數量最小的升級伺服器給安全 單元4064使用,這樣將可以減小升級伺服器的升級壓力的 同時可以根據需要適當添加或移除升級伺服器數量; 2.我們採取動態配置的技術方案來解決所有伺服器需 要變更的配置資訊的配置方法,通過把所有可以動態配置 的資訊(例如與伺服器的通信埠號、資料庫訪問的表名和資 料庫名稱等)存放在像丨N丨這樣的文件裡,每個飼服器將即 時掃描這個文件並即時回應這些變化;這樣我們就可以通 過網頁的方式達到管理的目的,即我們不需要到指定的機 器上重新啓動程式來達到重新配置伺服器資訊的目標而只 要在我們的客戶機上直接操作要配置的伺服器資訊就可以 達到目標,特別地當我們的伺服器是架設在離我公司很遠 的地方例如美國的時候,這樣的伺服器管理模式將是很高 效的, 女全單元資訊儲存的是與安全單元4064相關的資訊, 比如說: 1.基本的安全單元標識ID號(丨D號是世界上唯一的不 可重復的標識,我們使用25位元長度的字母來表示它); 2·每個安全單元4064都被固定賦予一個可用的升級 201243617 祠服益’那麼屬於這個安全單元4()64的所有成員的升 訊、中毒資訊以及PC電腦的網路位址、機器型號、、: 版本等重要資訊均儲存在該升級祠服器上,並且我們將以 這個安全單元4064的丨D號命名一個資 員的這些資訊; 料庫來储存所屬成 另一大類資料庫(升級服務資訊資料庫4024)主要 所有安全對象實體4062的PC電腦資訊、安全實體中毒: 訊以及我們的安全用戶端軟體對安全實體做出的安全保: 資訊,以便於我們或者安全單元管理者即時查看和分二 個安全對象實體4〇62的安全保護狀態,每類資訊所起到 作用如下: 叩 電腦資訊主要包括我們 資讯收集,這些客戶機S 12 201243617 Protection against accidents. Security Assistance Server 2046: Security Object Entity 2064 is subordinate to a particular security unit 2〇62' and the security object entity 2064 cannot belong to two or more security units 2062 at the same time, it is the smallest particle of security protection' A specific security protection object, which is only visible to the security unit to which it belongs or the parent security unit of the security unit 2062; the protection and management of the security object entity 2064 is an object that the security unit 2〇62 fundamentally considers, and the security object entity 2064 The current protection status, the security level of the current protection, the security level of the current protection, and the information of the security entity 2064 itself (including the hardware type of the security object entity 2064, the system type and version of the security object entity 2064, and the security object entity 2〇64 belong to The security unit 2〇62, the spatial location of the female full object entity 2064, etc., recording this information will provide an immediate basis for the security unit 2062 and the security administrator to view and analyze the security object entity 2064. 4 is a schematic diagram of a cloud computing based service management system in accordance with one embodiment of the present invention. As shown in FIG. 4, the following describes the functional technical features of each domain module: 1. The data management domain 402 technical features are composed of two types of databases, namely, the balanced load information database 4022 and the upgrade service information database. twenty four. The balanced load information database 4022 operates on a balanced feeding device, which mainly stores secure server entity information and security unit information (a secure server entity is a server that provides upgrade functions such as specific viruses and software), and a secure server entity. Information for the balance server to provide priority to upgrade the address of the main 13 201243617 To be based on, the balance server also needs to monitor the server status and dynamic configuration resources on each upgrade address to meet the immediacy requirements of the server function response For example: 1 · The maximum number of users allowed to log in on each upgrade server and the number of users who have logged in at this moment have been stored in the secure server entity database table, and the balance server will be based on these two The information is compared one by one to select the upgrade server with the smallest number of users at the current moment for use by the security unit 4064. This will reduce the upgrade pressure of the upgrade server and add or remove the number of upgrade servers as needed; 2. We take Dynamically configured technical solution to solve all servers The configuration method of the configuration information that needs to be changed is stored in a file such as 丨N丨 by storing all dynamically configurable information (such as the communication nickname with the server, the table name accessed by the database, and the database name). The feeder will scan the file in real time and respond to these changes in real time; this way we can achieve the purpose of management through the webpage, that is, we do not need to restart the program on the specified machine to achieve the goal of reconfiguring the server information. As long as we directly operate the server information to be configured on our client, we can achieve the goal. Especially when our server is located far away from our company, such as the United States, such a server management mode will be Very efficient, the female unit information store is related to the security unit 4064, for example: 1. The basic security unit identification ID number (丨D number is the only non-repeatable identifier in the world, we use 25-bit The length of the letter to indicate it); 2. Each security unit 4064 is fixed to give an available upgrade 20124 3617 祠 Benefits 'The information about the e-sense and poisoning of all members of this security unit 4 () 64 and the network address, machine model, and version of the PC are stored on the upgrade server. And we will use the 丨D number of this security unit 4064 to name this information for a member of the account; the repository stores the PC information of all the security object entities 4062 belonging to another large class database (upgrade service information database 4024). , security entity poisoning: News and our security client software security protection for security entities: information, so that we or the security unit manager can instantly view and divide the security status of the two security object entities 4〇62, each Class information plays a role as follows: 叩Computer information mainly includes our information collection, these clients

1_安全對象實體4062的PC 的安全用戶端軟體服務動作狀態的 上 女全服務是保護PC電腦的主要手段所在,監視這些 服務動作的狀態就可以幫助管理員瞭解各個pc機的安: 隱患;特別地我們必須收集pc電腦的網卡號,因為網上 號是世界上唯一的,通過它我們3戈者管理員料以通過我 們提供的軟體功能找到這台客戶貞,以達到通過遠端功炉 來幫助客戶機解決疑難問題和提供相應的服務;我們特2 強調我們所闡述的安全單元4064是指它的所有成員是可以 跨網路、跨區域被管理的,即這些成M可以處在不同的網 路和不同的地理區域中,我們提供的對安全單元4064的管 理功能是基於因特網的、分散式的管理; 2.實體中毒資訊是我們的軟體用戶端對_病毒後的 15 201243617 pc電腦收集起來的,這些資訊包括病毒檔案名稱和存在在 pc電腦上的位置以及中毒的時間等,這些資訊提供了分析 當刚中毒的原因;比如是因為未啓用安全保護服務軟體導 致的還疋因為該病毒是最新類型的病毒’我們將可以在我 們的病毒庫中添加上該病毒類型達到即時防護的作用; 二、伺服器實體域404技術特徵 词服器實體域404包括安全控制中心伺服器4042、安 全升級祠服器4044和安全輔助伺服器4046,其中 安全控制中心伺服器4042技術特徵如下: 1 -安全控制中心伺服器4042只有一個,它是管理中 心也是通信資訊的傳輸仲介; 2·該安全控制中心伺服器4042是用戶端以及管理控 制網頁與升級伺服器之間通信的媒介,伺服器的負載平衡 以及用戶端的合法性(即是否被授予使用權)都是在由它做預 判斷的,匕的特點就是職責輕而且速度快,能夠滿足大量 用戶端的同時訪問,比如說當有一個用戶端申請升級的時 候,安全控制中心伺服器4042主要負責合法性判斷和獲取 升級地址資訊回傳給伺服器,不包含複雜的功能例如傳輸 文件等這類大資料量的操作,它將很快完成此次通話,這 樣决速的通k機制將可以為安全控制中心祠服器4042預留 大量的吞吐空間(呑吐量指的是同一時刻能同時與伺服器通 仏的用戶端數量,數量越大吞吐量越大); 3_安全控制中心伺服器4042即時收集各個安全升級 伺服器4G44的狀態和動態配置資訊,比如某個升級祠服器 4044因為故障原因而導致退出那麼這個升級伺服器 201243617 是不可用的,安全控制中心伺服器4042將馬上得知這一資 訊並把這個通信故障報告給請求升級的客戶和管理員;如 果升級伺服器4044的最大吞吐量被改變,安全控制中心伺 服器4042也將即時地得知這一資訊,並在今後平衡安全升 級伺服器4044的負載時正確地做出回應; 4.安全控制中心伺服器4042還要負責收集安全單元 4064的成員資訊,例如成員個數等,這些安全單元4064 的成員資訊是分佈在安全升級伺服器4044上,因此安全控 制中心伺服器4042必須與安全升級伺服器4044通信來獲 取這些資訊;統計安全單元4064的成員資訊的意義在於為 企業等群體性組織提供相關的被感興趣的資訊,例如企業 需要確切地知道自己公司或者某個部門有具體成員數量; 安全升級伺服器4044的技術特徵如下: 1 ·安全升級伺服器4044可以有一個或多個,它可以 根據需要隨時增加和移除; 2.它直接負責安全對象實體4062的病毒庫和軟體的 升級,以及接收安全對象實體4062關於安全相關資訊的彙 報例如安全實體的中毒資訊、安全實體機上開啓安全保護 服務的狀態資訊等; 安全輔助伺服器4046的技術特徵如下: 1. 安全輔助伺服器4046是為安全升級伺服器4044 提供輔助功能的服務,它不一定要與安全升級伺服器4044 在同一台電腦上,它可以位於其他任何一台能與安全升級 伺服器4044通信的計算上; 2. 安全輔助伺服器4046充當安全升級伺服器4044 17 201243617 與女全控制中心4042通信的媒介,將把安全控制中心 4042的控制操作交給安全輔助中心4〇46去做讓安全升 級祠服器4044只負責處理安全對象實體4Q62的安全升級 等女全功能,例如安全升級控制中心4〇42需要收集安全單 π 4064的成員數量的時候,安全輔助中心4〇46將實際地 收集安全升級飼服器4044上用戶端的數量這一耗時的操作 ’從而為安全升級健器爾4預留出更多時間去處理傳輸 文件這類大資料量的事情; 3.所有的安全對象實體4〇62都將與安全輔助伺服营 4046建立-個長久的通信通道,只要這個安全實體存妇 個通道就將-直存在’它的主要作用是即時搜集安全對奪 實體4062的安全資訊,例如中毒資訊;特別地,通過這低 通k通道管理員可以與安全對象實體彻2進行遠端通信, 幫助或通知安全對象實體4062當前管理員的管理資訊; 4_安全輔助㈣器4G46還提供獲取内網與外網的通 k IP地址和通信槔映射資訊,丨p地址和埠映射在技術指的 是任何-台位於區域網路内的Pc電腦都有—個由區域網 路分配的私有IP和埠資訊,當這台pc電腦在因特網上通 :時這個私有的丨P和蟑就要擁有一個因特網上的丨p和埠 與它對應,這樣它就能在因特網上發送通信資料 個因特網上的丨P和槔就是我們所閣述的外網屮和槔; 三、安全對象實體域406技術特徵 ’ 台具有獨立執行能力的PC 業系統運行平台,能夠運 體的PC電腦。這個實體 安全對象實體4062即是一 電腦’它有自己的硬體設施和作 載我們雲端運算的安全用戶端軟1_ Security object entity 4062 PC security client software service state of the female full service is the main means of protecting PC computers, monitoring the status of these service actions can help administrators understand the security of each PC: hidden dangers; In particular, we must collect the NIC number of the PC, because the online number is the only one in the world. Through it, our 3 ge admins can find this customer through the software function we provide to reach the remote power furnace. To help the client solve difficult problems and provide corresponding services; we especially emphasize that the security unit 4064 that we describe means that all its members can be managed across networks and regions, that is, these Ms can be different. The network and different geographical areas, the management functions we provide for the security unit 4064 are Internet-based, decentralized management; 2. The physical poisoning information is our software client-side after the virus 15 201243617 pc computer Collected, this information includes the name of the virus file and the location on the PC and the time of poisoning, etc. Provides an analysis of the cause of the poisoning; for example, because the security protection software is not enabled, because the virus is the latest type of virus', we will be able to add the virus type to our virus database for immediate protection. Second, the server entity domain 404 technical feature word server entity domain 404 includes a security control center server 4042, a security upgrade server 4044 and a security assistant server 4046, wherein the security control center server 4042 technical features are as follows: 1 - There is only one security control center server 4042, which is the transmission center of the communication center and the communication information; 2. The security control center server 4042 is the medium for communication between the user terminal and the management control webpage and the upgrade server, and the load of the server Balance and the legitimacy of the client (that is, whether it is granted the right to use) are pre-judged by it. The trick is that the responsibility is light and fast, and it can meet the simultaneous access of a large number of clients, for example, when there is a client application. When upgrading, the Security Control Center Server 4042 is mainly responsible for legality judgment. Break and obtain the upgraded address information and send it back to the server. It does not contain complicated functions such as transferring files. It will complete the call very quickly, so that the speed-by-pass mechanism can be used for security control. The central server 4042 reserves a large amount of throughput space (the throughput refers to the number of users that can communicate with the server at the same time, and the larger the number, the greater the throughput); 3_The security control center server 4042 collects immediately The status and dynamic configuration information of each security upgrade server 4G44, such as an upgrade server 4044 due to the failure cause the upgrade server 201243617 is unavailable, the security control center server 4042 will immediately know this Information and report this communication failure to the client and administrator requesting the upgrade; if the maximum throughput of the upgrade server 4044 is changed, the security control center server 4042 will immediately know this information and balance the security upgrade in the future. The load of the server 4044 is correctly responded; 4. The security control center server 4042 is also responsible for collecting the security ticket. 4064 member information, such as the number of members, etc., the member information of these security units 4064 is distributed on the security upgrade server 4044, so the security control center server 4042 must communicate with the security upgrade server 4044 to obtain such information; statistical security The meaning of the member information of the unit 4064 is to provide relevant information of interest to the group organizations such as enterprises, for example, the enterprise needs to know exactly the number of members of the company or a certain department; the technical characteristics of the security upgrade server 4044 are as follows: 1) The security upgrade server 4044 may have one or more, which may be added and removed as needed; 2. it is directly responsible for the upgrade of the virus database and software of the security object entity 4062, and receives the security object entity 4062 for security related The information report, for example, the poisoning information of the security entity, the status information of the security protection service on the security entity, etc.; The technical features of the security assistance server 4046 are as follows: 1. The security assistance server 4046 provides auxiliary functions for the security upgrade server 4044. Service, it does not have to be secure The level server 4044 is on the same computer, and it can be located in any other computer that can communicate with the security upgrade server 4044. 2. The security assistant server 4046 acts as a security upgrade server 4044 17 201243617 and the female full control center 4042 The communication medium will hand over the control operation of the security control center 4042 to the security assistant center 4〇46 to make the security upgrade server 4044 only responsible for handling the security upgrade of the security object entity 4Q62, such as the security upgrade control center. 4〇42 When it is necessary to collect the number of members of the safety order π 4064, the safety assistance center 4〇46 will actually collect the time-consuming operation of the number of users on the security upgrade feeder 4044', thus for the safety upgrade of the health device 4 Reserve more time to deal with the large amount of data such as transferring files; 3. All security object entities 4〇62 will be established with the security assistant server 4046 - a long-term communication channel, as long as this security entity stores The channel will be - straight existence' its main role is to instantly collect security information on the security of the entity 4062, such as poisoning information; The low-pass k-channel administrator can perform remote communication with the security object entity 2 to help or notify the security object entity 4062 of the current administrator's management information; 4_Security Assistant (4) 4G46 also provides access to the intranet and external The network's IP address and communication 槔 mapping information, 丨p address and 埠 mapping in the technology refers to any - the Pc computer located in the regional network has a private IP and 埠 information allocated by the regional network, When the PC is connected to the Internet: the private 丨P and 蟑 have an Internet 丨p and 埠 corresponding to it, so that it can send communication data on the Internet to the Internet.槔 is the external network and 槔 我们 槔 槔 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 三 安全 安全This entity security object entity 4062 is a computer. It has its own hardware facilities and a secure client that loads our cloud computing.

S 18 201243617 域的技術特徵如下: 1_安全對象實體4062能夠即時回應安全升級伺服器 實體發來的對安全資料的搜集請求,例如即時收集安全對 象實體4062的中毒資訊、即時通信以判斷安全實體概2 的存在狀態; 2.安全對象實體彻2始終與為安全升㈣服器服務 的安全輔助祠服器建立一個永久通信通道,以保證在安全 對象實體4G62存在的情況下能接受來自于管理員等管理對 象的遠端幫助; 而基於本實施例的服務管理系統的雲端運算安全管理 平台的整體技術特徵如下: 雲端運算安全管理平台分成兩大 :對象實體的用戶端服務平台和以安全單元為基 g理千台’其中’用戶端服務平台的技術特徵即安全對象 實體對象的技術特徵,以安全單元為基本單位的管理平台 技術特徵如下: σ 1. 該Β理平台疋以網站的形式提供給管理員使用的; 2. 所有管理員都被賦予一個獨立的登錄名和登錄密碼 ’予確保只有管理許可權的管理員才能操縱該管理平台; 3. 該管理平台提供樹型層次管理結構為不同㈣的管 理員分配操作許可權; …4.該官理平台提供給管理員關於它所管理的所有安全 '資包括安全單元的基本資訊例如硬體配置資訊、 卡資訊等1¾管理平台以餅狀圖形式提供給管理員觀察 所有安全單元中處於安全狀態的比例數,提供統計受到過 19 201243617 威脅和感染病毒的客戶機比例,提供所有病毒資訊及所在 位置的所有相關資訊;依據這些資訊管理員將可以 防判斷。 综上所述,根據本發明,可以實現一種基於雲端運算 的服務官理系統,其具有以下優點: 1·能夠提供給任何一個獨立的群體性組織(例如某一 個具體企業或者某一個企業分$ )麻始 似止菜刀又)根據管理許可權的高低分 配不同等級管理員的服務; 2·能夠提供給任何—個獨立的群體性組織的某個管理 員管理它的所有群體成員(該成員必須是個人PC電腦)的服 務, 3.能夠提供給任何一個群體性組織的某個管理員根據 需要有組織、按層次地劃分更小的管理單元(例如-個企業 具體劃分出多個事業部,每個事 固爭茶。丨ί又可以具體地劃分出 一個或多個具體部門,部門 门入J以冉具體劃分出子部門)的 服務; 4·能夠提供給任何—個群體性组織跨區域跨網路管理 歸屬于它的群體成員的服務; 5·能夠提供給任何—個群體性組織的某個管理員所有 歸屬于它的群體成員電腦安全資訊,以便於該群體管理者 查看和分析具體PC雷脫糾6 A & 電恥的女全狀態:個人電腦基本資訊( 電腦名等)、病毒升級情沉资 ,* 屏况資訊、中毒情況與病毒類型統計 資訊等; 倉b夠提供給任何—個群體性組織的某個管理員根據 需要遠端控制所屬的群體成員PC電腦:配置%電腦安全The technical features of the S 18 201243617 domain are as follows: 1_ The security object entity 4062 can immediately respond to the collection request of the security data sent by the security upgrade server entity, for example, collecting the poisoning information of the security object entity 4062 and instant communication to determine the security entity. The existence status of the general 2; 2. The security object entity 2 always establishes a permanent communication channel with the security assistant server for the security service (4) to ensure that the security object entity 4G62 can accept the management. The remote technical help of the management object such as the member; and the overall technical features of the cloud computing security management platform based on the service management system of the present embodiment are as follows: The cloud computing security management platform is divided into two major parts: the client-side service platform of the object entity and the security unit The technical characteristics of the management platform based on the security unit are as follows: σ 1. The processing platform is in the form of a website. Provided to the administrator; 2. All administrators are given a single The login name and login password 'ensure that only the administrator who manages the license can manipulate the management platform; 3. The management platform provides a tree-level management structure to assign operational permissions to different (four) administrators; .... The official platform Provides the administrator with all the security information it manages, including basic information about the security unit, such as hardware configuration information, card information, etc. The management platform provides the administrator with a pie chart to observe the security status of all security units. Number, provide statistics on the proportion of clients who have been threatened and infected by 19 201243617, provide all virus information and all relevant information about their location; according to these information administrators will be able to prevent judgment. In summary, according to the present invention, a service computing system based on cloud computing can be realized, which has the following advantages: 1. Can be provided to any independent group organization (for example, a specific enterprise or a certain enterprise) ) The beginning of the kitchen knife and the distribution of different levels of administrator services according to the level of management permissions; 2. Can be provided to any independent group of organizations to manage all its members It is a service of a personal PC. 3. An administrator who can provide it to any group organization to organize smaller and smaller management units according to needs (for example, - an enterprise specifically divides multiple business units, Everything is for tea. 丨ί can be specifically divided into one or more specific departments, the department enters J to specifically divide the sub-sector's services; 4. Can be provided to any group of organizations Regional cross-network management services belonging to its group members; 5. An administrator who can provide it to any group organization Group members computer security information, so that the group managers can view and analyze the PC full state of the specific PC Raytheon 6 A & electric shame: PC basic information (computer name, etc.), virus upgrades, * screen Information, poisoning situation and virus type statistics, etc.; warehouse b is enough for any group of organizations to remotely control the group members PCs as needed: configure % computer security

20 S 201243617 屬性、發送消息給所屬群體成員、遠端桌面控制pc電腦 、遠端重啓與關閉PC電腦; 7. 能夠提供給任何一個群體成員(該群體必須被本雲 資訊安全管理服務平台授予使用權限)升級病毒庫和升級天 訊天網雲安全管理用戶端最新版本軟體的服務; 8. 能夠提供即時統計任一群體性組織當前組織内成員 數量的資訊和即時搜集任一個群體成員的安全資訊並提供 給管理員查看和分析的服務。 以上所述僅為本發明的優選實施例而已,並不用於限 制本發明’對於所屬技術領域具有通常知識者來說,本發 明可以有各種更改和變化。凡在本發明的精神和原則之内 ,所作的任何修改、等同替換、改進等,均應包含在本發 明的保護範圍之内。 【圖式簡單說明】 圖1是本發明基於雲端運算的服務管理系統一個實施 例的方塊圖。 圖2是本發明基於雲端運算的服務管理系統一個實施 例的示意圖。 圖3是本發明基於雲端運算的服務管理系統一個實施 例的安全單元之間的關係示意圖; 圖4是本發明基於雲端運算的服務管理系統一個實施 例的示意圖。 【主要元件符號說明】 21 201243617 100基於雲端運算的服務管理系統 102安全對象實體裝置 104資料庫管理裝置 106伺服器實體裝置 200服務管理系統 202資料管理域 2022安全單元管理資料庫 2024安全伺服器實體管理資料庫 2026安全單元實體資訊資料庫 204伺服器實體域 2042安全控制中心伺服器 2044安全升級伺服器 2046安全輔助伺服器 206安全對象實體域 2062安全單元 2064安全對象實體 402資料實體域 4022平衡負載資訊資料庫 4024升級服務資訊資料庫 404伺服器實體域 4042安全控制中心伺服器 4044安全升級伺服器 4046安全輔助伺服器 406安全對象實體域 4062安全對象實體 4064安全單元20 S 201243617 attributes, send messages to members of the group, remote desktop control pc, remote restart and shutdown of PC; 7. Can be provided to any group member (this group must be granted by the cloud information security management service platform) Use permissions) to upgrade the virus database and upgrade the latest version of the software of the Tianxun Cloud Security Management client; 8. Provide real-time statistics on the number of members in the current organization of any group organization and instantly collect the security of any member of the group Information and services provided to administrators for viewing and analysis. The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Various changes and modifications can be made in the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and scope of the present invention are intended to be included within the scope of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS Fig. 1 is a block diagram showing an embodiment of a cloud computing-based service management system of the present invention. 2 is a schematic diagram of an embodiment of a cloud computing based service management system of the present invention. 3 is a schematic diagram showing the relationship between security units of an embodiment of a cloud computing-based service management system according to the present invention; and FIG. 4 is a schematic diagram of an embodiment of a cloud computing-based service management system according to the present invention. [Main component symbol description] 21 201243617 100 cloud computing-based service management system 102 security object entity device 104 database management device 106 server entity device 200 service management system 202 data management domain 2022 security unit management database 2024 security server entity Management database 2026 security unit entity information database 204 server entity domain 2042 security control center server 2044 security upgrade server 2046 security assistance server 206 security object entity domain 2062 security unit 2064 security object entity 402 data entity domain 4022 balance load Information database 4024 upgrade service information database 404 server entity domain 4042 security control center server 4044 security upgrade server 4046 security assistant server 406 security object entity domain 4062 security object entity 4064 security unit

22 S22 S

Claims (1)

201243617 七、申請專利範圍: 1 · 一種基於雲端運算的服務管理系統,包括: 安全對象實體裝置,包括安全單元和安全對象實體, 所述安全單元上設置有安全管理許可權,其中,每個安全 對象實體從屬於相應的安全單元; 資料庫管理裝置,保存所述安全單元的資訊、所述安 全對象實體的資訊; 飼服器實體裝置’包括控制中心和所述升級伺服器叢 集,所述控制中心根據來自所述資料庫管理裝置的所述安 全單元的資訊、所述安全對象實體的資訊,在所述安全對 象實體裝置中查找出需求服務的安全對象實體和其從屬安 全單元,並在所述服務管理系統的管理員滿足所述從屬安 全單元的安全管理許可權時,從所述升級伺服器叢集中調 用所述升級伺服器為所述需求服務的安全對象實體提供服 務0 2 ·如請求項1所述的服務管理系統,還包括: 平衡飼服器,獲取所述升級飼服器叢集的實體資訊, 以用於判斷所述升級伺服器叢集的負載情況; 所述資料庫管理裝置還儲存所述升級飼服器叢集的實 體資訊’所述控财心根據所述升級伺服器叢集的實體資 訊來調用所述升級伺服器, 执 乂保近所述升級伺服器的負載 在預定範圍内。 ' 所述平衡伺服器 以用於判斷所述 3.如請求項2㈣的服務管理系統, 還獲取所述升級伺服器叢集的狀態資訊, 升級词服器叢集是否出現異常. 23 201243617 所述資料庫管理裝置還儲存所述升級伺服器叢集的狀 態資訊,所述控制中心根據所述升級伺服器叢集的狀態資 訊來調用所述升級伺服器’以保證所述升級伺服器未出現 異常。 4 .如請求項2所述的服務管理系統,所述平衡伺服器 還獲取所述升級伺服器叢集的動態配置資訊,所述管理員 還通過所述控制中心修改所述升級伺服器叢集中任一升級 伺服器的動態配置資訊。 5 .如請求項1所述的服務管理系統,所述安全單元的 資訊包括所述安全單元的標識資訊,所述控制中心根據所 述安全單元的標識資訊,查找出所述從屬安全單元。 6 ·如請求項1所述的服務管理系統,所述安全單元的 資訊包括為所述安全單元指定的伺服器的資訊,所述控制 中心根據為從屬安全單元指定的升級伺服器的資訊,優先 選擇所述指定的升級伺服器作為提供服務的所述升級伺服 器。 7 .如請求項1至6中任一項所述的服務管理系統,所 述安全對象實體的資訊包括所述安全對象實體的電腦資訊 ’以用於判斷所述安全對象實體上運行的服務的狀態; 所述控制中心根據所述安全對象實體的電腦資訊,查 找出所述需求服務的安全對象實體。 8 ·如請求項1至6中任一項所述的服務管理系統,所 述安全對象實體的資訊包括所述安全對象實體的中毒資訊 以用於判斷所述安全對象實體的中毒情況; 所述控制中心根據所述安全對象實體的中毒資訊,查 24 S 201243617 找出所述需求服務的安全對象實體 服器實體 9 .如請求項8所述的服務管理系統,所述飼 I置還包括: ° 安全輔助词服器,與所述安全對象實體 ’以收隹祕、+. — ^ ^ 咬正通k通道 全對象實體裝置。 波儲存至所迷安 1〇.如請求項9所述的服務管理系統,所述控制中心 他過所述安令鉍。/卞的安全對 象實體的資Γ司服器,收集每個安全單 圖式:(如次頁) 25201243617 VII. Patent application scope: 1 · A cloud computing-based service management system, comprising: a security object entity device, including a security unit and a security object entity, wherein the security unit is provided with security management permission, wherein each security The object entity is subordinate to the corresponding security unit; the database management device saves the information of the security unit, the information of the security object entity; the feeder device comprises a control center and the upgrade server cluster, the control The center finds the security object entity of the demand service and its subordinate security unit in the security object entity device according to the information from the security unit of the database management device and the information of the security object entity, and When the administrator of the service management system satisfies the security management permission of the slave security unit, the upgrade server is invoked from the upgrade server cluster to provide a service to the security object entity of the demand service. The service management system described in item 1 further includes: a feeding device, which acquires entity information of the upgraded feeder cluster for determining a load condition of the upgrade server cluster; the database management device further stores the entity information of the upgraded feeder cluster The financial controller invokes the upgrade server according to the entity information of the upgrade server cluster, and the load of the upgrade server is within a predetermined range. The balance server is configured to determine the service management system of the request item 2 (4), and obtain status information of the upgrade server cluster, and upgrade whether the word server cluster is abnormal. 23 201243617 The management device also stores status information of the upgrade server cluster, and the control center invokes the upgrade server according to the status information of the upgrade server cluster to ensure that the upgrade server does not have an abnormality. 4. The service management system according to claim 2, wherein the balance server further acquires dynamic configuration information of the upgrade server cluster, and the administrator further modifies the upgrade server cluster by the control center An update to the dynamic configuration information of the server. The service management system of claim 1, wherein the information of the security unit includes identification information of the security unit, and the control center searches for the slave security unit according to the identification information of the security unit. 6. The service management system according to claim 1, wherein the information of the security unit includes information of a server specified for the security unit, and the control center preferentially according to information of an upgrade server specified for the slave security unit. The specified upgrade server is selected as the upgrade server that provides the service. The service management system according to any one of claims 1 to 6, wherein the information of the security object entity includes computer information of the security object entity for determining a service running on the security object entity. The control center searches for the security object entity of the demand service according to the computer information of the security object entity. The service management system according to any one of claims 1 to 6, wherein the information of the security object entity includes poisoning information of the security object entity for determining a poisoning condition of the security object entity; The control center finds the security object entity server entity 9 of the demand service according to the poisoning information of the security object entity. The service management system described in claim 8 is further provided by: ° The security auxiliary word server, with the security object entity 'to receive the secret, +. — ^ ^ bite the positive k-channel full object entity device. The wave is stored in the security service. According to the service management system described in claim 9, the control center passes the security command. /卞The security object of the entity, collect each security ticket. Figure: (such as the next page) 25
TW101114098A 2011-04-21 2012-04-20 Cloud computing-based service management system TW201243617A (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110104323.1A CN102148712B (en) 2011-04-21 2011-04-21 Cloud computing-based service management system

Publications (2)

Publication Number Publication Date
TW201243617A true TW201243617A (en) 2012-11-01
TWI460596B TWI460596B (en) 2014-11-11

Family

ID=44422729

Family Applications (1)

Application Number Title Priority Date Filing Date
TW101114098A TW201243617A (en) 2011-04-21 2012-04-20 Cloud computing-based service management system

Country Status (2)

Country Link
CN (1) CN102148712B (en)
TW (1) TW201243617A (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI499918B (en) * 2014-05-21 2015-09-11 Nat Univ Tsing Hua Cloud management systems and methods for executing applications of android systems
TWI567545B (en) * 2015-12-23 2017-01-21 神雲科技股份有限公司 Method for detecting locations of abnormal hard disks in cluster storage system
CN107102695A (en) * 2016-02-22 2017-08-29 佛山市顺德区顺达电脑厂有限公司 The method of the installation position of the abnormal hard disk of judgement for cluster type stocking system
TWI701562B (en) * 2015-07-08 2020-08-11 香港商阿里巴巴集團服務有限公司 Database flexible scheduling method and device

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102360355B (en) * 2011-09-28 2013-04-24 福州海景科技开发有限公司 Face recognition search comparison engine based on cloud computing environment
CN103763117A (en) * 2011-12-31 2014-04-30 华茂云天科技(北京)有限公司 Service and operation management system
CN104063355B (en) * 2013-03-21 2017-11-03 腾讯科技(北京)有限公司 The method and configuration center server configured to server cluster
CN107612932A (en) * 2017-10-20 2018-01-19 广东电网有限责任公司电力科学研究院 A kind of cloud security Rights Management System
CN110572436B (en) * 2019-08-12 2020-09-22 浙江讯盟科技有限公司 Multi-place cross-cluster server deployment method and system

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7080378B1 (en) * 2002-05-17 2006-07-18 Storage Technology Corporation Workload balancing using dynamically allocated virtual servers
US7558866B2 (en) * 2004-12-08 2009-07-07 Microsoft Corporation Method and system for securely provisioning a client device
CN101527637A (en) * 2009-03-23 2009-09-09 北京安高科技有限公司 Virtual proprietary organization platform system and method thereof
CN101557308B (en) * 2009-05-06 2012-01-18 成都市华为赛门铁克科技有限公司 File upgrading method and terminal device
CN101576915B (en) * 2009-06-18 2011-06-08 北京大学 Distributed B+ tree index system and building method
CN101827104B (en) * 2010-04-27 2013-01-02 南京邮电大学 Multi anti-virus engine-based network virus joint defense method

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI499918B (en) * 2014-05-21 2015-09-11 Nat Univ Tsing Hua Cloud management systems and methods for executing applications of android systems
TWI701562B (en) * 2015-07-08 2020-08-11 香港商阿里巴巴集團服務有限公司 Database flexible scheduling method and device
TWI567545B (en) * 2015-12-23 2017-01-21 神雲科技股份有限公司 Method for detecting locations of abnormal hard disks in cluster storage system
CN107102695A (en) * 2016-02-22 2017-08-29 佛山市顺德区顺达电脑厂有限公司 The method of the installation position of the abnormal hard disk of judgement for cluster type stocking system
CN107102695B (en) * 2016-02-22 2020-07-24 佛山市顺德区顺达电脑厂有限公司 Method for determining mounting position of abnormal hard disk for cluster storage system

Also Published As

Publication number Publication date
CN102148712A (en) 2011-08-10
CN102148712B (en) 2014-05-14
TWI460596B (en) 2014-11-11

Similar Documents

Publication Publication Date Title
TW201243617A (en) Cloud computing-based service management system
CN110535831B (en) Kubernetes and network domain-based cluster security management method and device and storage medium
WO2021017301A1 (en) Management method and apparatus based on kubernetes cluster, and computer-readable storage medium
US10326765B2 (en) System, method, and software for providing access control enforcement capabilities in cloud computing systems
CN111124670B (en) Tactical cloud-oriented microservice platform
US10044550B2 (en) Secure cloud management agent
US8606897B2 (en) Systems and methods for exporting usage history data as input to a management platform of a target cloud-based network
US8589543B2 (en) Virtual data center monitoring
US9838483B2 (en) Methods, systems, and computer readable media for a network function virtualization information concentrator
CN110266716B (en) Unified service platform system of power grid
US8903996B2 (en) Operating cloud computing services and cloud computing information system
EP2423813A2 (en) Systems and methods for a multi-tenant system providing virtual data centers in a cloud configuration
CN106850549B (en) Distributed encryption service gateway and implementation method
Pan et al. Research on dependability of cloud computing systems
KR101506250B1 (en) Connection Dualization System For virtualization service
CN114780214B (en) Task processing method, device, system and equipment
US20130159492A1 (en) Migrating device management between object managers
JP5364070B2 (en) Virtual server management device
CN112068953B (en) Cloud resource fine management traceability system and method
US20150188747A1 (en) Cloud-based data center infrastructure management system and method
CN108322336A (en) Intelligent management and system towards domestic autonomous controllable server
Waqas et al. ReSA: Architecture for resources sharing between clouds
CN108924264A (en) A kind of desktop cloud system
Wang et al. Carrier-grade distributed cloud computing: Demands, challenges, designs, and future perspectives
Yuen et al. Development of the customer centric data visibility framework for the enhancement of the trust of sme customers in cloud services

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees