Virtualized network migration method and device, equipment and medium
By detecting the network resource shard version information of the source and target nodes and processing the policy dependency chain, the conflict problem in virtualized network migration is solved and the user experience is improved.
Patent Information
- Application Number
- CN202511079536.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-01
- Publication Date
- 2025-09-12
AI Technical Summary
Existing virtualized network migration solutions are prone to conflicts during the migration process, and faults cannot be detected in a timely manner, affecting user experience.
By detecting the network resource shard version information of the source node and the target node, it is determined whether the preset conflict conditions are met. Based on the impact of the conflicting resources on the policy dependency chain, the target conflict handling strategy is determined and corresponding repair measures are executed.
It enables timely detection and repair of conflict issues during virtualized network migration, improving user experience.
Smart Images

Figure CN120639592A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of virtualized network migration, and in particular to a virtualized network migration method, device, equipment and medium. Background Art
[0002] With the development of cloud computing, virtualized network migration has become an important technology. However, due to the complexity of business and network dependencies, existing virtualized network migration solutions are prone to conflicts between the source and destination ends during network migration. Failures during the migration process are not detected and rely on post-process repair, which affects the user experience.
[0003] It can be seen that how to promptly detect and repair conflicts in virtualized network migration to improve user experience is a problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] In view of this, the object of the present invention is to provide a virtualized network migration method, apparatus, device and medium, which can promptly detect and repair conflicts in virtualized network migration, thereby improving user experience.
[0005] In a first aspect, the present invention provides a virtualized network migration method, comprising:
[0006] During virtualized network migration, detecting first version information of a first network resource slice in a source node and second version information of a second network resource slice in a target node, where the first network resource slice and the second network resource slice are the same network resource slice;
[0007] When the first version information and the second version information meet a preset conflict condition, obtaining conflicting resources corresponding to the first network resource slice and the second network resource slice;
[0008] Determining a corresponding target conflict handling strategy based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice;
[0009] The target conflict handling strategy is executed to perform conflict repair.
[0010] Optionally, the first version information and the second version information both include a source node version and a target node version;
[0011] Compare the source node version in the first version information and the source node version in the second version information, the target node version in the first version information and the target node version in the second version information to determine whether the first version information and the second version information meet the preset conflict condition.
[0012] Optionally, the source node version in the first version information is updated when a network resource change event of the source node is captured, and the first version information is updated based on the second version information when the source node obtains a message carrying the second version information sent by the target node;
[0013] The target node version in the second version information is updated when a network resource change event of the target node is captured, and the second version information is updated based on the first version information when the target node obtains a message carrying the first version information sent by the source node.
[0014] Optionally, determining a corresponding target conflict handling strategy based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice includes:
[0015] If the conflicting resource causes the policy dependency chain of the second network resource slice to be incomplete, determining the corresponding target conflict handling strategy to be manual arbitration;
[0016] Accordingly, executing the target conflict handling strategy to perform conflict repair includes:
[0017] Report the conflict information to the target personnel terminal so that the conflict can be repaired based on the target personnel operation of the target personnel terminal.
[0018] Optionally, determining a corresponding target conflict handling strategy based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice further includes:
[0019] If the conflicting resource does not cause the policy dependency chain of the second network resource slice to be incomplete, determining whether the conflicting resource meets a preset no logical contradiction condition;
[0020] If the conflicting resources meet the preset logical contradiction condition, determining the corresponding target conflict handling strategy to be automatic repair based on the preset logic;
[0021] Accordingly, executing the target conflict handling strategy to perform conflict repair includes:
[0022] Executes preset logic to perform conflict repair.
[0023] Optionally, determining a corresponding target conflict handling strategy based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice further includes:
[0024] If the conflicting resource does not cause the policy dependency chain of the second network resource shard to be incomplete, and the conflicting resource does not meet the preset logical contradiction condition, determining that the corresponding target conflict handling strategy is manual arbitration;
[0025] Accordingly, executing the target conflict handling strategy to perform conflict repair includes:
[0026] Report the conflict information to the target personnel terminal so that the conflict can be repaired based on the target personnel operation of the target personnel terminal.
[0027] Optionally, after the first version information and the second version information meet a preset conflict condition, the method further includes:
[0028] Determine whether there is an alarm record corresponding to the same conflict in the alarm database;
[0029] If it does not exist, a new alarm record is added to the alarm library; otherwise, the alarm record corresponding to the same conflict is updated.
[0030] In a second aspect, the present invention provides a virtualized network migration device, comprising:
[0031] A version information detection module is used to detect, during a virtualized network migration process, first version information of a first network resource slice in a source node and second version information of a second network resource slice in a target node, where the first network resource slice and the second network resource slice are the same network resource slice;
[0032] a conflict resource acquisition module, configured to acquire conflicting resources corresponding to the first network resource slice and the second network resource slice when the first version information and the second version information meet a preset conflict condition;
[0033] a processing strategy determination module, configured to determine a corresponding target conflict processing strategy based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice;
[0034] The processing strategy execution module is used to execute the target conflict processing strategy to perform conflict repair.
[0035] In a third aspect, the present invention provides an electronic device, comprising:
[0036] memory for storing computer programs;
[0037] A processor is configured to execute the computer program to implement the steps of the aforementioned virtualized network migration method.
[0038] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the aforementioned virtualized network migration method when executed by a processor.
[0039] In a fifth aspect, the present invention provides a computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the aforementioned disclosed virtualized network migration method.
[0040] From the above scheme, it can be seen that the present invention provides a virtualized network migration method, including: during the virtualized network migration process, detecting the first version information of the first network resource slice in the source node and the second version information of the second network resource slice in the target node, the first network resource slice and the second network resource slice are the same network resource slice; when the first version information and the second version information meet the preset conflict condition, obtaining the conflicting resources corresponding to the first network resource slice and the second network resource slice; based on the impact of the conflicting resources on the policy dependency chain of the second network resource slice, determining the corresponding target conflict handling strategy; executing the target conflict handling strategy to perform conflict repair.
[0041] It can be seen that the beneficial effect of the present invention is that in the process of virtualized network migration, fine-grained version management at the shard level is adopted for network resources, and the version information of the same network resource shards in the source node and the target node is detected to determine whether the preset conflict conditions are met. When the preset conflict conditions are met, the corresponding target conflict handling strategy is determined based on the impact of the conflicting resources on the policy dependency chain to perform conflict repair. In this way, conflict problems in virtualized network migration can be detected and repaired in a timely manner, thereby improving user experience.
[0042] Correspondingly, a virtualized network migration device, equipment and medium provided by the present invention also have the above technical effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the embodiments of the present invention, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0044] Figure 1 A flowchart of a virtualized network migration method provided by an embodiment of the present invention;
[0045] Figure 2 A schematic diagram of a virtualized network migration provided by an embodiment of the present invention;
[0046] Figure 3 A network configuration capture flow chart provided by an embodiment of the present invention;
[0047] Figure 4 A schematic diagram of a network resource dependency chain provided by an embodiment of the present invention;
[0048] Figure 5 A conflict detection flow chart provided by an embodiment of the present invention;
[0049] Figure 6 An alarm flow chart provided by an embodiment of the present invention;
[0050] Figure 7 A schematic diagram of a virtualized network migration device provided by an embodiment of the present invention;
[0051] Figure 8 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0053] The terms "including" and "having," as used in the present description and accompanying drawings, and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements and may include steps or elements that are not listed.
[0054] With the development of cloud computing technology, virtualized network migration has become an important technology, widely used in scenarios such as seamless migration of financial-level services and cross-data center disaster recovery. However, existing virtualized network migration solutions still have some problems. In particular, in large-scale network parallel migration scenarios, problems such as data loss and network connection interruption often occur. Moreover, failures during the migration process cannot be perceived and rely on post-repair, which affects the user experience. Due to the complexity of the business and the complex network dependencies, existing virtualized network migration solutions are prone to data integrity problems during the migration process, and conflicts are very likely to occur between the source and destination ends during the network migration process. The present invention proposes a virtualized network migration solution to solve the problems existing in existing network migration solutions.
[0055] In order to enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0056] Next, a virtualized network migration method provided by an embodiment of the present invention is described in detail. Figure 1A flowchart of a virtualized network migration method provided in an embodiment of the present invention includes:
[0057] Step S11: During the virtualized network migration process, detecting first version information of a first network resource slice in a source node and second version information of a second network resource slice in a target node, wherein the first network resource slice and the second network resource slice are the same network resource slice.
[0058] Virtualized network migration involves migrating network resources from a source node to a target node. This embodiment of the present invention allows for fine-grained segmentation of virtual machine network resources, with each type of network resource serving as a shard. Each shard can record the version numbers and policy dependencies of the source and destination nodes. Examples of network types include security groups, firewalls, and routing policies.
[0059] Furthermore, in an embodiment of the present invention, each network resource shard has a corresponding shard-level version vector. The shard-level version vector includes a shard unique identifier, a vector clock, the last update time, and a policy dependency chain. The shard unique identifier can be composed of the network resource type and a random character. The vector clock, i.e., the aforementioned first and second version information, can include the source and destination node versions. During the initialization of the shard-level vector, the policy dependencies of the corresponding network resource are parsed and a policy dependency chain is generated.
[0060] In an embodiment of the present invention, the first version information and the second version information both include a source node version and a target node version; the source node version in the first version information and the source node version in the second version information, the target node version in the first version information and the target node version in the second version information are compared to determine whether the first version information and the second version information meet a preset conflict condition.
[0061] If the source node version in the first version information is greater than the source node version in the second version information, and the target node version in the first version information is less than the target node version in the second version information, or if the source node version in the first version information is less than the source node version in the second version information, and the target node version in the first version information is greater than the target node version in the second version information, it can be determined that the preset conflict condition is satisfied. That is, the source node version in the source node vector clock > the source node version in the target node vector clock, and the target node version in the source node vector clock < the target node version in the target node vector clock, or the source node version in the source node vector clock < the source node version in the target node vector clock, and the target node version in the source node vector clock > the target node version in the target node vector clock.
[0062] The source node version in the first version information is updated when a network resource change event of the source node is captured, and the first version information is updated based on the second version information when the source node obtains a message carrying the second version information sent by the target node; the target node version in the second version information is updated when a network resource change event of the target node is captured, and the second version information is updated based on the first version information when the target node obtains a message carrying the first version information sent by the source node.
[0063] Among them, the source node version in the first version information is incremented when a network resource change event of the source node is captured, and the first version information is merged with the second version information when the source node obtains a message carrying the second version information sent by the target node, that is, the source node version and the target node version both take the maximum value of the first version information and the second version information, and then the source node version in the first version information is increased by one; the target node version in the second version information is incremented when a network resource change event of the target node is captured, and the second version information is merged with the first version information when the target node obtains a message carrying the first version information sent by the source node, that is, the source node version and the target node version both take the maximum value of the first version information and the second version information, and then the target node version in the second version information is increased by one.
[0064] In this embodiment of the present invention, network resource change events can be triggered by monitoring changes to network configuration, iptables policies, OVS (Open vSwitch) flow tables, and other information. Regarding network configuration, the initial virtual machine network card and routing configurations are obtained before migration. During the migration process, the virtual machine's network card and routing configurations are cyclically obtained and compared with the initial network card and routing configurations. If any changes occur, the changes are recorded in a log file and backed up. The log file records the timestamp and change event, and the initial virtual machine network card and routing configurations are updated before the next cycle begins. To ensure real-time reporting of change events, the cycle time is set within 3ms. Regarding iptables policies, inotifywait is used to monitor firewall rules. iptables-save initializes firewall rules. Inotifywait -m / etc / iptables / rules.v4 -emodify monitors firewall policy changes. Upon detecting a change, the current firewall rules are compared with the initial firewall rules. Changes are recorded in a log file and backed up. The initial firewall rules are updated with the newly acquired data before the next cycle begins. For OVS flow tables, the OVSDB JSON-RPC interface is used to implement subscription updates. You can subscribe to changes in a specified table and record events in a log file in real time after receiving table changes.
[0065] Step S12: When the first version information and the second version information meet a preset conflict condition, conflicting resources corresponding to the first network resource slice and the second network resource slice are obtained.
[0066] In other words, the first network resource slice conflicts with the second network resource slice. You need to analyze the resources in the first and second network resource slices to identify the conflicting resources. For example, if the network resource slice is a security group, extract the resources in that security group at both the source and target nodes to identify the conflicting resources. For example, the source node has added rule A under security group, while the target node has added rule B under security group.
[0067] Step S13: Determine a corresponding target conflict handling strategy based on the impact of the conflicting resources on the policy dependency chain of the second network resource slice.
[0068] Impacts include causing the policy dependency chain to be incomplete (broken), complete with no logical contradictions, or complete with logical contradictions. Incomplete means deleting a resource breaks the dependency chain, while no logical contradictions means the modified resources on the source and target nodes do not overlap.
[0069] Step S14: executing the target conflict handling strategy to perform conflict repair.
[0070] In an optional embodiment, based on the impact of the conflicting resource on the policy dependency chain of the second network resource shard, a corresponding target conflict handling strategy is determined, including: if the conflicting resource causes the policy dependency chain of the second network resource shard to be incomplete, then the corresponding target conflict handling strategy is determined to be manual arbitration processing; accordingly, the target conflict handling strategy is executed to perform conflict repair, including: reporting conflict information to the target personnel terminal so that the conflict can be repaired based on the target personnel operation of the target personnel terminal. That is, manual repair is required. Reporting the conflict information to the target personnel terminal can be reporting the conflict information to the target personnel terminal via email.
[0071] Furthermore, based on the impact of the conflicting resource on the policy dependency chain of the second network resource shard, a corresponding target conflict handling strategy is determined, which also includes: if the conflicting resource does not cause the policy dependency chain of the second network resource shard to be incomplete, then judging whether the conflicting resource meets the preset no-logical-contradiction condition; if the conflicting resource meets the preset no-logical-contradiction condition, then determining the corresponding target conflict handling strategy to automatically repair based on the preset logic; accordingly, executing the target conflict handling strategy to repair the conflict, including: executing the preset logic to repair the conflict. For example, the preset logic can be a merge, that is, merging the network resource shards, keeping the source node and the target node consistent, and updating the dependency chain to keep the source node and the target node consistent.
[0072] Furthermore, based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice, a corresponding target conflict handling strategy is determined, which also includes: if the conflicting resource does not cause the policy dependency chain of the second network resource slice to be incomplete, and the conflicting resource does not meet the preset logical contradiction condition, then the corresponding target conflict handling strategy is determined to be manual arbitration processing; accordingly, the target conflict handling strategy is executed to perform conflict repair, including: reporting the conflict information to the target personnel terminal so as to perform conflict repair based on the target personnel operation of the target personnel terminal.
[0073] Furthermore, when the first version information and the second version information meet a preset conflict condition, the method further includes: determining whether an alarm record corresponding to the same conflict exists in the alarm database; if not, adding a new alarm record to the alarm database; otherwise, updating the alarm record corresponding to the same conflict. The comparison is performed based on resource type, conflict shard, and conflict description to determine whether the conflict is the same.
[0074] It can be seen that in the embodiment of the present invention, during the virtualized network migration process, fine-grained version management at the shard level is adopted for network resources, and the version information of the same network resource shards in the source node and the target node is detected to determine whether the preset conflict conditions are met. When the preset conflict conditions are met, the corresponding target conflict handling strategy is determined based on the impact of the conflicting resources on the policy dependency chain to perform conflict repair. In this way, conflict problems in the virtualized network migration can be detected and repaired in a timely manner, thereby improving the user experience.
[0075] Furthermore, the present invention provides a virtualized network migration solution based on shard-level version vectors, which can solve data consistency, conflict and other problems in virtualized network migration. Shard-level version vectors are used to track network data changes during network migration and ensure network data consistency. A shard-level version vector is a data structure used to record the version information of each network shard. By using shard-level version vectors, the migration and management of virtualized networks can be controlled in a more fine-grained manner, and a full closed-loop conflict management of detection-merge-arbitration-recovery can be implemented, transforming traditional post-conflict repair into real-time resolution during the migration process, thereby improving the efficiency and reliability of virtualized network migration. Figure 2 As shown, Figure 2 A schematic diagram of a virtualized network migration provided by an embodiment of the present invention.
[0076] Among them, the change capture layer is used to capture network changes and version backups during the migration process of the source node or target node virtual machine, including virtual network card configuration, routing table, security policy, etc. The captured data is input into the shard version management unit. The captured data is the network changes of the source and target nodes. In the embodiment of the present invention, the virtual machine network migration includes network card configuration, routing, security policy (security group firewall, etc.). These are all data to be captured. If there is a corresponding change in the change capture layer, an event will be reported. The event carries the specific change content and serves as the input content of the shard version management unit. The change capture table is shown in Table 1:
[0077] Table 1
[0078]
[0079] Network configuration capture method is as follows Figure 3 As shown, Figure 3 A network configuration capture flowchart provided for an embodiment of the present invention: Before migration, the initial virtual machine network card configuration A0 and routing configuration B0 are obtained. During the migration process, the virtual machine's network card configuration and routing configurations A1 and B1 are cyclically obtained and compared with the initial network card routing configuration. If any changes occur, the changes are recorded in a log file and the data is backed up. The log file records the timestamp and change event, and updates the initial virtual machine network card configuration and routing configuration to reassign A1 and B1, and then enters the next cycle. To ensure the real-time reporting of change events, the loop time is set within 3ms.
[0080] iptables policy: inotifywait monitors firewall rules, iptables-save initializes firewall rules, and inotifywait -m / etc / iptables / rules.v4 -e modify monitors firewall policy changes. After detecting changes, the current firewall rules are compared with the initialized firewall rules, the changes are recorded in the log file and backed up, and the initialized firewall rules are updated with the newly obtained data before entering the next cycle.
[0081] OVS flow table: The OVS flow table uses the OVSDB JSON-RPC interface to implement subscription updates. You can subscribe to changes in a specified table and record events in a log file in real time after receiving table changes.
[0082] The present invention divides the network resources of virtual machines into fine-grained divisions. Each type of network resource is a shard. The shard uses a shard-level version vector to record the version number and policy dependencies of the source and target nodes. Network types include security groups, firewalls, and routing policies. The data structure of the shard-level version vector is as follows: Each shard carries a version identifier: FVV =<Shard_ID, VC, Timestamp,PolicyDependencies> . Among them: Shard_ID: Shard unique identifier (for example: NET-POLICY-3a7d, format: network resource type-random letters). VC: Vector clock (for example: {Src:15,Dst:12}). Timestamp: Last update time. If a conflict occurs, the time of the conflict can be obtained through the last update time, which is convenient for the subsequent resolution of conflicting resources. PolicyDependencies: Dependencies of this resource shard. The policy dependency chain is other network resources that the resource depends on. If the source node deletes resource A, and the target node has resource dependency A, it will be determined that the dependency chain of the target node is broken, and manual verification will be introduced. After verification, the dependency chain will be updated. If the source node only modifies resource A, and the modification has no conflict or there is a conflict but the conflict can be automatically merged, the dependency will be updated.
[0083] Initialize the shard-level version vector: Event trigger: When the source node registers a new virtualized network resource, the creation of the shard-level version vector is triggered, and its initial vector clock is {Src:0, Dst:0}. Before the virtualized network migration, the script is executed on the source node to batch initialize the network resource shards. If the corresponding network resource shards already exist on the source node, the original data of the shards will be maintained unchanged. Otherwise, a new shard will be added and the initial version will be 0. After the shard resource is changed, the version will be incremented according to the vector clock version increment mechanism. In other words, to process historical data and new data, the virtual machine on the platform has been running stably for a period of time, and now it needs to be migrated, that is, to process historical data and newly registered resources during the execution of the migration plan. In the process of initializing the shard-level vector, it is necessary to parse the policy dependencies of the corresponding network resources and generate a policy dependency chain. By calling the cloud platform API interface, the topology map of the corresponding network resources is obtained, and the network resources it depends on are parsed. The main network resource dependency links of the current cloud platform are as follows Figure 4 As shown, Figure 4 This diagram illustrates a network resource dependency chain provided by an embodiment of the present invention. Taking a virtual machine instance accessing the public network as an example, the process is as follows: the routing table directs outbound traffic to the NAT gateway → the NAT gateway translates the source IP address → the firewall checks the outbound traffic → the security group allows the instance to outbound traffic to the public network's destination port (e.g., port 443). This is the policy dependency chain. From the cloud platform's perspective, the NAT gateway and router are bound, the router and firewall are bound, and the port is bound to the security group. If the NAT gateway exists but the dependent router does not, the link is considered broken.
[0084] This embodiment of the present invention provides a vector clock version increment mechanism: In the vector clock VC, Src represents the version counter of the network migration source node, and Dst represents the version counter of the network migration target node. During virtual machine network migration, each node (source node, target node, etc.) maintains a vector clock to record the latest known versions of itself and other nodes. The rules are as follows: 1. Each node increments its own counter when a local event occurs. 2. When a node sends a message, it includes the current vector clock. 3. When a node receives a message, it first merges the vector clocks in the message (taking the maximum value of each node's counter) before incrementing its own counter. For example, the source node vector clock is: vc_src = {'Src': 5, 'Dst': 3}, and the target node vector clock is: vc_dst = {'Src': 5, 'Dst': 3}. After the source node detects a network change event, it updates its local version to vc_src = {'Src': 6, 'Dst': 3}. After the event is sent to the target node, the target node vector clock receives the data and merges it to take the maximum value vc_dst={'Src': 6, 'Dst': 3}. At the same time, its own version is incremented by one and finally updated to vc_dst={'Src': 6, 'Dst': 4}. The embodiment of the present invention deals with the scenario of source and target conflict, and both the source and the target will trigger rules. Because during the process of source to target migration, the target node may also operate resources at the same time. Taking the maximum value during the merge is equivalent to synchronizing all known latest progress, that is, retaining the highest known event count of the source node shard and the target node shard to avoid information loss.
[0085] In the embodiment of the present invention, a conflict detection engine is used for conflict detection. The essence of conflict detection is that when the source node and the target node make incompatible concurrent modifications to the same shard, irreconcilable contradictions occur in the version vectors. The conflict detection engine collects the states of the same shard from the source node and the target node and compares the vector clocks of the source node and the target node for basic conflict judgment. The vector clock is used to solve the version partial order problem between distributed nodes, and can achieve accurate tracking and conflict judgment of state changes in virtual network migration. The conflict detection formula is: ∃i,j:(Va [i]>Vb [i]) ∧(Va [j]<Vb [j]). Here, i and j are the node indexes in the vector clock (such as the source node Src and the target node Dst). Va[i] represents the version number of node i in the vector clock Va. Vb[i] represents the version number of node i in the vector clock Vb. For example, for the dictionary type A={"src":xx, "dst":yy}, the values are taken as follows: A["src"] = xx; A["dst"] = yy, where "src" and "dst" are called indexes. In the description of this embodiment, i can correspond to src, and j can correspond to dst. Va represents the vector clock, and Va[i] represents the version corresponding to i (i.e., src).
[0086] The conflict determination condition is: if and only if there exists at least one node index i such that Va[i] > Vb[i], and at the same time there exists another node index j such that Va[j] < Vb[j]. This indicates that the two events are concurrent and the order cannot be determined, so conflict resolution is required. That is, if vc_src = {'Src': 5, 'Dst': 3}, vc_dst={'Src': 6, 'Dst':2}, at this time, the Src of the source node < the Src of the target node, and at the same time, the Dst of the source node > the Dst of the target node. That is, the version number of the source node recorded by the vector clock of the source node is 5, and the version number of the source node recorded by the vector clock of the target node is 6, then it is considered that the version on the target node is ahead. The version number of the target node recorded by the vector clock of the source node is 3, and the version number of the target node recorded by the vector clock of the target node is 2, then it is considered that the version on the source node is ahead. The two given conclusions are inconsistent, one considers that the version of the target node is ahead, and the other considers that the version of the source node is ahead, so a conflict occurs. That is, when the source node thinks its modification is the latest and the destination node thinks its modification is the latest, a conflict will occur. After detecting the basic conflict (vector clock comparison), the conflict determination engine triggers the policy dependency analysis module to analyze, confirm the conflict impact, and start the corresponding conflict handling plan.
[0087] Policy Dependency Analysis: Each shard-level version vector has a unique shard identifier (e.g., NET-POLICY-3a7d). Each shard identifier is associated with a corresponding policy dependency chain. After the conflict determination engine identifies a basic conflict, it triggers the policy dependency analysis unit to further analyze the conflict and determine whether it affects VM network migration and whether it can be automatically compatible or ignored by the system. The policy dependency analysis unit checks the policy dependency chain corresponding to the shard identifier to verify its integrity. If the dependency chain is complete and conflict-free, the destination node automatically merges the source node's changes and updates the merged version. If the destination node detects a broken dependency chain (e.g., missing target security group information or firewall policy), network connectivity or access rules will be affected. If a true conflict occurs, the conflicting resources are resolved and the conflicting resource rules are extracted. If the conflicting rules are logically consistent (e.g., adding rule 1 to the source security group and rule 2 to the target security group), they are merged or automatically repaired to eliminate the impact on target service access and a minor alert is reported. For scenarios that cannot be repaired by themselves, such as IP conflicts between the target and source ends, emergency alarms are reported, and conflicts are resolved in real time through manual arbitration. After the conflicts are resolved, the updated versions are merged.
[0088] In this embodiment of the present invention, after a conflict is detected, the policy dependency analysis unit first checks the policy dependency chain. The PolicyDependencies section of the shard-level version vector stores information about the resources that the shard's resources depend on. If a dependent resource is detected to no longer exist, the dependency chain is considered broken, requiring manual arbitration. If not, the conflict is determined to be harmful: that is, whether the conflict is incompatible with merging or whether it affects virtual machine service communications. If a shard conflict exists, the conflicting shard needs to be analyzed to determine which resources within the shard are inconsistent and at what point (as indicated by the timestamp in the vector). For example, if the shard is a security group, the relevant content within the security group is extracted from the source and target nodes based on the security group to identify the conflicting points. If both the source and target nodes modify security group rule A within the security group, this conflict cannot be automatically merged and requires manual arbitration. If the source node adds security group rule A and the target node adds security group rule B, the modified resources do not overlap, and the changes on the source side can be automatically merged into the target side. This means parsing the conflicting shards and extracting the conflicting resources within the shards. There is no logical contradiction, that is, the resources modified by the source and target nodes do not intersect. If both the source and target nodes modify security group rule A under the security group, then this conflict cannot be automatically merged and requires manual arbitration and modification. If the source node adds security group rule A and the target node adds security group rule B, then the intersection will not affect the situation and the changes on the source side can be automatically merged into the target side. After the solution is resolved, the version is updated according to the shard version update strategy, and the clock is changed. See Figure 5 As shown, Figure 5A conflict detection flow chart provided by an embodiment of the present invention.
[0089] The embodiment of the present invention performs conflict judgment and dependency analysis (i.e., compares the conflicting resources with the current dependency chain of the shard to see whether the conflicting resources have an impact on the current dependency chain), and then manually or automatically repairs and merges the changes (both the source and the destination are merged), and then updates the dependency chain (because the source and the destination are bidirectional, the dependency chain is also updated synchronously. In this way, when a conflict occurs again, the latest dependency chain is detected. The dependency chains of the source and the destination are the same, so the target node can be used directly for dependency analysis. The shards in the source and target nodes have dependency chains. When initializing the shard-level version vector, the source will synchronize the same resource shard to the target node. The dependency chain of the two is completely consistent; during the migration process, it is necessary to ensure that both the source and destination nodes are running stably and transitioning smoothly, and the dependency chains of the two are consistent. Timing of updating the dependency chain If the conflict judgment engine detects a conflict (that is, inconsistent operations have occurred on the same type of network resources at the source and destination): first, it will check the dependency chain of the current target node to see if the conflicting resources have affected the integrity of the current dependency chain. There are two situations: dependency chain is broken - manual intervention; dependency chain is complete - manual intervention / automatic merge conflict; regardless of whether the conflict is handled by manual intervention or automatic merge conflict, the source and destination merge the code, and the dependency chain is updated after the merge, and the dependency chains of the two are consistent.
[0090] For further information, see Figure 6 As shown, Figure 6 This is an alarm flow chart disclosed in an embodiment of the present invention. After the conflict determination engine + policy dependency analysis determines the real conflict, an alarm event is triggered. The alarm event includes: alarm time, alarm level, conflict resource type, conflict fragment information, affected network port, and conflict description. The alarm detection unit workflow is as follows: Figure 6 After the conflict engine detects a conflict, it pushes the event to the alarm processor. The alarm processor determines whether it is a new alarm (alarms corresponding to different conflicts). If it is a new alarm, a new record is generated. Otherwise, the alarm information is updated and the emergency alarm is pushed to the mailbox in real time to achieve rapid response maintenance and reduce business interruption time. The historical alarm library is compared with the conflicting resource type, conflict sharding, and conflict description as dimensions. If it is a known alarm, the trigger time and number are updated, otherwise new alarm data is inserted into the alarm library. This is mainly to avoid repeated reporting of similar alarms. The conflict description refers to the specific alarm content, such as an error code, which indicates an IP conflict.
[0091] This approach improves virtualized network migration efficiency by designing shard-level version vectors and implementing a fully closed-loop conflict management process of detection, merging, arbitration, and recovery. Traditional post-event conflict resolution is transformed into real-time resolution during the migration process, minimizing service interruptions.
[0092] See also Figure 7 As shown, a virtualized network migration device includes:
[0093] A version information detection module 71 is configured to detect, during a virtualized network migration process, first version information of a first network resource slice in a source node and second version information of a second network resource slice in a target node, where the first network resource slice and the second network resource slice are the same network resource slice;
[0094] a conflicting resource acquisition module 72, configured to acquire conflicting resources corresponding to the first network resource slice and the second network resource slice when the first version information and the second version information meet a preset conflict condition;
[0095] A processing strategy determination module 73 is configured to determine a corresponding target conflict processing strategy based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice;
[0096] The processing strategy execution module 74 is used to execute the target conflict processing strategy to perform conflict repair.
[0097] Both the first version information and the second version information include a source node version and a target node version; the device is also used to: compare the source node version in the first version information and the source node version in the second version information, the target node version in the first version information and the target node version in the second version information to determine whether the first version information and the second version information meet a preset conflict condition.
[0098] The source node version in the first version information is updated when a network resource change event of the source node is captured, and the first version information is updated based on the second version information when the source node obtains a message carrying the second version information sent by the target node; the target node version in the second version information is updated when a network resource change event of the target node is captured, and the second version information is updated based on the first version information when the target node obtains a message carrying the first version information sent by the source node.
[0099] The processing strategy determination module 73 is specifically used to: if the conflicting resource causes the policy dependency chain of the second network resource fragment to be incomplete, then determine the corresponding target conflict processing strategy as manual arbitration processing; accordingly, the processing strategy execution module 74 is used to report the conflict information to the target personnel terminal so as to perform conflict repair based on the target personnel operation of the target personnel terminal.
[0100] The processing strategy determination module 73 is also used to: if the conflicting resource does not cause the policy dependency chain of the second network resource fragment to be incomplete, then determine whether the conflicting resource meets the preset logical contradiction condition; if the conflicting resource meets the preset logical contradiction condition, then determine the corresponding target conflict processing strategy to be automatic repair based on the preset logic; accordingly, the processing strategy execution module 74 is used to execute the preset logic to perform conflict repair.
[0101] The processing strategy determination module 73 is also used to: if the conflicting resources do not cause the policy dependency chain of the second network resource segment to be incomplete, and the conflicting resources do not meet the preset logical contradiction condition, then determine that the corresponding target conflict processing strategy is manual arbitration processing; accordingly, the processing strategy execution module 74 is used to report the conflict information to the target personnel terminal so as to perform conflict repair based on the target personnel operation of the target personnel terminal.
[0102] The device also includes an alarm record module, which is used to determine whether there is an alarm record corresponding to the same conflict in the alarm library after the first version information and the second version information meet the preset conflict condition; if not, add a new alarm record to the alarm library, otherwise, update the alarm record corresponding to the same conflict.
[0103] It can be seen that in the embodiment of the present invention, during the virtualized network migration process, fine-grained version management at the shard level is adopted for network resources, and the version information of the same network resource shards in the source node and the target node is detected to determine whether the preset conflict conditions are met. When the preset conflict conditions are met, the corresponding target conflict handling strategy is determined based on the impact of the conflicting resources on the policy dependency chain to perform conflict repair. In this way, conflict problems in the virtualized network migration can be detected and repaired in a timely manner, thereby improving the user experience.
[0104] Figure 7 The description of the features in the corresponding embodiment can be found in Figure 1 The relevant descriptions of the corresponding embodiments will not be repeated here one by one.
[0105] Figure 8 A structural diagram of an electronic device provided by an embodiment of the present invention, such as Figure 8 As shown, the electronic device includes: a memory 80 for storing computer programs;
[0106] The processor 81 is configured to implement the steps of the virtual network migration method in the above embodiment when executing a computer program.
[0107] The electronic device provided in this embodiment may include but is not limited to a smart phone, a tablet computer, a laptop or desktop computer, a server, etc.
[0108] The processor 81 may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor 81 may be implemented using at least one of the following hardware forms: a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The processor 81 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 81 may be integrated with a graphics processing unit (GPU), which is responsible for rendering and drawing the content required to be displayed on the display screen. In some embodiments, the processor 81 may also include an artificial intelligence (AI) processor, which is responsible for processing computing operations related to machine learning.
[0109] The memory 80 may include one or more computer-readable storage media, which may be non-transitory. The memory 80 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 80 is at least used to store the following computer program 801, wherein, after the computer program is loaded and executed by the processor 81, it can implement the relevant steps of the virtual network migration method disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory 80 may also include an operating system 802 and data 803, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 802 may include Windows, Unix, Linux, etc. The data 803 may include but is not limited to network change data, etc.
[0110] In some embodiments, the electronic device may further include a display screen 82 , an input / output interface 83 , a communication interface 84 , a power supply 85 , and a communication bus 86 .
[0111] Those skilled in the art will understand that Figure 8 The structure shown in the figure does not constitute a limitation of the electronic device, and may include more or fewer components than shown in the figure.
[0112] It is understood that if the virtual network migration method in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the current technology, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and performs all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), an electrically erasable programmable ROM, a register, a hard drive, a removable disk, a CD-ROM, a magnetic disk, or an optical disk, and other media that can store program code.
[0113] Based on this, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the virtual network migration method described above are implemented.
[0114] Furthermore, an embodiment of the present invention provides a computer program product, including a computer program / instruction, which implements the steps of the above-mentioned virtual network migration method when executed by a processor.
[0115] The above describes in detail the virtualized network migration method, apparatus, device, and medium provided by the embodiments of the present invention. The various embodiments are described in a progressive manner throughout this specification, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between the various embodiments can be referenced for reference only. The apparatus disclosed in the embodiments corresponds to the method disclosed in the embodiments, so the description is relatively brief. For relevant details, refer to the method description.
[0116] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0117] The above is a detailed introduction to the virtualized network migration method, device, equipment and medium provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present invention, the present invention can also be improved and modified in several ways, and these improvements and modifications also fall within the scope of protection of the present invention.
Claims
1. A virtualized network migration method, characterized in that: include: During virtualized network migration, detecting first version information of a first network resource slice in a source node and second version information of a second network resource slice in a target node, where the first network resource slice and the second network resource slice are the same network resource slice; When the first version information and the second version information meet a preset conflict condition, obtaining conflicting resources corresponding to the first network resource slice and the second network resource slice; Determining a corresponding target conflict handling strategy based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice; The target conflict handling strategy is executed to perform conflict repair.
2. The virtual network migration method according to claim 1, wherein: The first version information and the second version information both include a source node version and a target node version; Compare the source node version in the first version information and the source node version in the second version information, the target node version in the first version information and the target node version in the second version information to determine whether the first version information and the second version information meet the preset conflict condition.
3. The virtual network migration method according to claim 2, wherein: The source node version in the first version information is updated when a network resource change event of the source node is captured, and the first version information is updated based on the second version information when the source node obtains a message carrying the second version information sent by the target node; The target node version in the second version information is updated when a network resource change event of the target node is captured, and the second version information is updated based on the first version information when the target node obtains a message carrying the first version information sent by the source node.
4. The virtual network migration method according to claim 1, wherein: Determining a corresponding target conflict handling strategy based on an impact of the conflicting resource on the policy dependency chain of the second network resource slice includes: If the conflicting resource causes the policy dependency chain of the second network resource slice to be incomplete, determining the corresponding target conflict handling strategy to be manual arbitration; Accordingly, executing the target conflict handling strategy to perform conflict repair includes: Report the conflict information to the target personnel terminal so that the conflict can be repaired based on the target personnel operation of the target personnel terminal.
5. The virtual network migration method according to claim 4, characterized in that: Determining a corresponding target conflict handling strategy based on an impact of the conflicting resource on the policy dependency chain of the second network resource slice further includes: If the conflicting resource does not cause the policy dependency chain of the second network resource slice to be incomplete, determining whether the conflicting resource meets a preset no logical contradiction condition; If the conflicting resources meet the preset logical contradiction condition, determining the corresponding target conflict handling strategy to be automatic repair based on the preset logic; Accordingly, executing the target conflict handling strategy to perform conflict repair includes: Executes preset logic to perform conflict repair.
6. The virtual network migration method according to claim 5, characterized in that: Determining a corresponding target conflict handling strategy based on an impact of the conflicting resource on the policy dependency chain of the second network resource slice further includes: If the conflicting resource does not cause the policy dependency chain of the second network resource shard to be incomplete, and the conflicting resource does not meet the preset logical contradiction condition, determining that the corresponding target conflict handling strategy is manual arbitration; Accordingly, executing the target conflict handling strategy to perform conflict repair includes: Report the conflict information to the target personnel terminal so that the conflict can be repaired based on the target personnel operation of the target personnel terminal.
7. The virtual network migration method according to any one of claims 1 to 6, characterized in that: After the first version information and the second version information meet a preset conflict condition, the method further includes: Determine whether there is an alarm record corresponding to the same conflict in the alarm database; If it does not exist, a new alarm record is added to the alarm library; otherwise, the alarm record corresponding to the same conflict is updated.
8. A virtualized network migration device, characterized in that: include: A version information detection module is used to detect, during a virtualized network migration process, first version information of a first network resource slice in a source node and second version information of a second network resource slice in a target node, where the first network resource slice and the second network resource slice are the same network resource slice; a conflict resource acquisition module, configured to acquire conflicting resources corresponding to the first network resource slice and the second network resource slice when the first version information and the second version information meet a preset conflict condition; a processing strategy determination module, configured to determine a corresponding target conflict processing strategy based on the impact of the conflicting resource on the policy dependency chain of the second network resource slice; The processing strategy execution module is used to execute the target conflict processing strategy to perform conflict repair.
9. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to execute the computer program to implement the steps of the virtualized network migration method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the virtualized network migration method according to any one of claims 1 to 7.