Network virtualization system and method
By deploying NVE in containers and using a unified event subscription interface, the problem of module adaptation difficulty in network virtualization systems is solved, and efficient system deployment and adaptation is achieved, especially reducing the dependence conflict between NVE and virtual machine monitors, improving the system adaptability and flexibility.
Patent Information
- Application Number
- CN201910500812.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-06-11
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2039-06-11
AI Technical Summary
In the prior art, the adaptation between different modules in network virtualization systems is difficult, especially the dependence environment conflict between NVE and virtual machine monitors, resulting in low deployment efficiency.
By deploying NVE in the container and making it rely on the runnable software library in the container instead of the same library of the virtual machine monitor, the dependency conflict between NVE and the virtual machine monitor is reduced, and the SDN controller and the virtualization management node are decoupled through a unified event subscription interface, reducing the difficulty of adaptation between the two.
It improves the deployment efficiency of network virtualization systems, reduces the workload of adapting virtual machine monitors from different manufacturers or versions, and improves the adaptability and flexibility of the system.
Smart Images

Figure CN112068924B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing, and particularly relates to a network virtualization system and method. Background Art
[0002] Network virtualization of cloud resource pools is one of the important application scenarios of SDN (Software Defined Network). SDN works in coordination with server virtualization in cloud resource pools to achieve network virtualization of cloud resource pools, so as to adapt to the requirements of expanding network scale, dynamic migration of virtual machines, and large-scale tenant isolation.
[0003] The integration of SDN and server virtualization is the key technology to achieve network virtualization of cloud resource pools. The mainstream integration method is to directly deploy NVE (Network Visible Entities) in the operating system of a virtual machine monitor (such as Hypervisor) as a network traffic processing endpoint. The SDN controller obtains the dynamic changes in the life cycle of virtual machines (VMs for short) from the server virtualization management node through an internal interface, so as to update the flow table of NVE accordingly and maintain network communication between VMs. Summary of the Invention
[0004] After analysis, the inventors found that it is difficult to adapt between different modules in the current network virtualization system.
[0005] One technical problem to be solved by the embodiments of the present invention is: how to reduce the adaptation difficulty between different modules in the network virtualization system.
[0006] According to the first aspect of some embodiments of the present invention, a network virtualization system is provided, including: an SDN controller for sending control information to a network visible entity NVE; NVE, deployed in a container and depending on the NVE runnable software library in the container, for processing the network traffic of the virtual machine corresponding to NVE according to the control information, wherein the container is deployed in a virtual machine monitor.
[0007] In some embodiments, the network virtualization system further includes: a virtual machine monitor for hosting one or more virtual machines and NVE deployed in a container.
[0008] In some embodiments, the virtual machine monitor depends on the monitor runnable software library in the virtual machine monitor.
[0009] In some embodiments, the control information includes at least one of a flow table and configuration information.
[0010] In some embodiments, the network virtualization system further includes: a virtualization management node, configured to send a lifecycle event notification in a preset format to the SDN controller through an event subscription interface.
[0011] In some embodiments, the SDN controller is further configured to, in response to obtaining the lifecycle event notification sent by the virtualization management node through the event subscription interface, parse the lifecycle event notification, and send control information to one or more NVEs in the system according to the parsing result.
[0012] According to a second aspect of some embodiments of the present invention, there is provided a network virtualization method, including: a network visible entity NVE receives control information sent by the SDN controller, where the NVE is deployed in a container, and the container is deployed in a virtual machine monitor; the NVE processes the network traffic of the virtual machine corresponding to the NVE according to the NVE runnable software library in the container and the control information sent by the SDN controller.
[0013] In some embodiments, the virtual machine monitor depends on the monitor runnable software library in the virtual machine monitor.
[0014] In some embodiments, the control information includes at least one of a flow table and configuration information.
[0015] In some embodiments, the network virtualization method further includes: the virtualization management node sends a lifecycle event notification in a preset format to the SDN controller through the event subscription interface.
[0016] In some embodiments, the network virtualization method further includes: the SDN controller, in response to obtaining the lifecycle event notification sent by the virtualization management node through the event subscription interface, parses the lifecycle event notification; the SDN controller sends control information to one or more NVEs in the system according to the parsing result.
[0017] Some embodiments of the above invention have the following advantages or beneficial effects: The embodiments of the present invention enable the NVE to depend on the NVE runnable software library in the container, without depending on the same runnable software library as the virtual machine monitor, thereby reducing the problem of environmental conflicts between the NVE and the virtual machine monitor, and can reduce the workload of the NVE when adapting to different manufacturers or different versions of the virtual machine monitor, improving the deployment efficiency of the network virtualization system.
[0018] Other features and advantages of the present invention will become clear through the following detailed description of the exemplary embodiments of the present invention with reference to the accompanying drawings. Description of the Drawings
[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0020] Figure 1 It is a schematic structural diagram of a virtual machine monitor in the related art.
[0021] Figure 2A It is a schematic structural diagram of a network virtualization system according to some embodiments of the present invention.
[0022] Figure 2B It is a schematic flowchart of a network virtualization method according to some embodiments of the present invention.
[0023] Figure 3 It is a schematic structural diagram of a virtual machine monitor according to some embodiments of the present invention.
[0024] Figure 4A It is a schematic structural diagram of a network virtualization system according to some other embodiments of the present invention.
[0025] Figure 4B It is a schematic flowchart of a network virtualization method according to some other embodiments of the present invention.
[0026] Figure 5A It is a schematic structural diagram of a network virtualization system according to some further embodiments of the present invention.
[0027] Figure 5B It is a schematic flowchart of a network virtualization management method according to some further embodiments of the present invention. Detailed implementation manners
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. The following description of at least one exemplary embodiment is actually only illustrative and in no way limits the present invention and its application or use. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0029] Unless otherwise specifically stated, the relative arrangements, numerical expressions and values of the components and steps described in these embodiments do not limit the scope of the present invention.
[0030] Meanwhile, it should be understood that, for ease of description, the dimensions of the various parts shown in the drawings are not drawn in accordance with actual proportional relationships.
[0031] Technologies, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the said technologies, methods, and devices should be regarded as part of the authorization specification.
[0032] In all the examples shown and discussed here, any specific value should be construed as merely exemplary and not as a limitation. Thus, other examples of the exemplary embodiments may have different values.
[0033] It should be noted that: like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0034] Figure 1 It is a schematic structural diagram of a virtual machine monitor in the related art. As Figure 1 shown, the virtual machine monitor 10 includes a kernel 110, a runnable software library 120, and an NVE 130. Both the virtual machine monitor 10 and the NVE 130 rely on the same runnable software library 120. And when the virtual machine monitor 10 and the NVE 130 belong to different manufacturers or different versions of the same manufacturer, additional development and adaptation are required, increasing the workload of adaptation. To solve this problem, the inventor uses containers to package and deploy the NVE and the runnable software library on which the NVE depends, so as to reduce the adaptation workload and improve the deployment efficiency. The following refers to Figure 2A and 2B to describe embodiments of the network virtualization system and method of the present invention.
[0035] Figure 2A It is a schematic structural diagram of a network virtualization system according to some embodiments of the present invention. As Figure 2A shown, the network virtualization system 20 of this embodiment includes an SDN controller 210 and an NVE 220.
[0036] The SDN controller 210 is used to send control information to the NVE 220. The control information may be, for example, at least one of a flow table and configuration information. The configuration information may be, for example, to start or stop a certain port number to cooperate with the creation or deletion process of a virtual machine.
[0037] The NVE220 is deployed in a container and depends on the NVE runnable software library within the container to process the network traffic of the virtual machine corresponding to the NVE220 according to control information. Herein, the container is deployed in a virtual machine monitor (such as a Hypervisor). And the virtual machine monitor depends on the monitor runnable software library in the virtual machine monitor. That is, the NVE220 and the virtual machine monitor where it is located depend on different runnable software libraries.
[0038] The virtual machine monitor is used to separate the abstraction of the operating system from the hardware for the purpose of running one or more virtual machines simultaneously. The runnable software library can be, for example, a binary library for the user to call the software, packages or functions therein.
[0039] Figure 2B It is a schematic flowchart of a network virtualization method according to some embodiments of the present invention. As Figure 2B shown, the network virtualization method of this embodiment includes steps S202 to S204.
[0040] In step S202, the NVE receives the control information sent by the SDN controller. Herein, the NVE is deployed in a container, and the container is deployed in a virtual machine monitor.
[0041] In step S204, the NVE processes the network traffic of the virtual machine corresponding to the NVE according to the NVE runnable software library within the container and the control information sent by the SDN controller.
[0042] Figure 3 It is a schematic structural diagram of a virtual machine monitor according to some embodiments of the present invention. As Figure 3 shown, the virtual machine monitor 30 of this embodiment includes a kernel 310, a monitor runnable software library 320, and a container 330. The container 330 includes an NVE runnable software library 3310 and an NVE 3320. The NVE 3320 depends on the NVE runnable software library 3310.
[0043] The above embodiments of the present invention enable the NVE to depend on the NVE runnable software library within the container without depending on the same runnable software library as the virtual machine monitor, thereby reducing the problem of environmental conflicts between the NVE and the virtual machine monitor, and can reduce the workload of the NVE when adapting to virtual machine monitors from different manufacturers or different versions, improving the deployment efficiency of the network virtualization system.
[0044] After further analysis, the inventor found that currently, the SDN controller and the virtualization management node cooperate through an internal interface, and the coupling degree between the two is relatively high, which increases the difficulty of adapting the SDN controller to the virtualization management node. The current solution is implemented through customization by the same manufacturer or deeply cooperative manufacturers. To further reduce the adaptation difficulty, the inventor proposed to make the virtualization management node and the SDN controller cooperate through a unified event subscription interface to reduce the adaptation workload. The following refers to Figure 4A and 4B Describe embodiments of the network virtualization system and method of the present invention.
[0045] Figure 4A FIG. is a schematic structural diagram of a network virtualization system according to some other embodiments of the present invention. As Figure 4A shown, the network virtualization system 40 of this embodiment includes an SDN controller 410, an NVE 420, and a virtualization management node 430. The virtualization management node 430 is used to send a lifecycle event notification in a preset format to the SDN controller 410 through an event subscription interface.
[0046] The lifecycle event notification may include, for example, at least one of an event type, a virtual machine identifier, and an event destination. For example, the notification "[Event type: Migration, Virtual machine identifier: Virtual machine A, Destination: Hypervisor2]" indicates that virtual machine A needs to be migrated to the virtual machine monitor Hypervisor2.
[0047] In some embodiments, the SDN controller 410 is further configured to, in response to obtaining the lifecycle event notification sent by the virtualization management node 430 through the event subscription interface, parse the lifecycle event notification, and send control information to one or more NVEs in the system according to the parsing result.
[0048] Figure 4B FIG. is a schematic flowchart of a network virtualization method according to some other embodiments of the present invention. As Figure 4B shown, the network virtualization method of this embodiment includes steps S402 to S406.
[0049] In step S402, the virtualization management node sends a lifecycle event notification in a preset format to the SDN controller through an event subscription interface.
[0050] In step S404, the SDN controller, in response to obtaining the lifecycle event notification sent by the virtualization management node through the event subscription interface, parses the lifecycle event notification.
[0051] In step S406, the SDN controller sends control information to one or more NVEs in the system according to the parsing result.
[0052] Through the above embodiments of the present invention, the transmission process of the life cycle events of the virtual machine can be standardized. Through the event subscription interface, the SDN controller and the virtualization management node can be decoupled, the difficulty of adapting the two can be reduced, and the deployment efficiency can be improved.
[0053] Figure 5A FIG. 1 is a schematic diagram of the structure of a network virtualization system according to some other embodiments of the present invention. Figure 5A As shown, the network virtualization system 50 of this embodiment includes an SDN controller 510, a virtualization management node 520, a virtual machine monitor 530, and a cloud management platform 540. The virtual machine monitor 530 includes a container 5310 and an NVE 5320, and the NVE 5320 is deployed in the container 5310. The NVE 5320 corresponds to the virtual machine 5330 and the virtual machine 5340, and relies on the NVE executable software library 5350 in the container 5310. Figure 5A Only one virtual machine monitor and two virtual machines are shown in FIG. Figure 5A The number of virtual machine monitors and virtual machines is not restrictive, and those skilled in the art can set the number of these devices or modules as needed.
[0054] Reference below Figure 5B An embodiment of the network virtualization management method of the present invention is described. In this embodiment, it is assumed that the SDN controller 510 and NVE 5320 belong to manufacturer A, and the virtualization management node 520 and virtual machine monitor 530 belong to manufacturer B. The network traffic of all virtual machines on each manufacturer B is directed to the NVE of manufacturer A for forwarding processing. The virtualization management node of manufacturer B opens an event subscription interface, and the SDN of manufacturer A subscribes to and monitors the life cycle events of the virtual machines through the interface.
[0055] Figure 5B FIG. 1 is a flow chart of a network virtualization management method according to some other embodiments of the present invention. Figure 5B As shown, the network virtualization management method of this embodiment includes steps S502 to S510.
[0056] In step S502, a virtual machine life cycle event occurs on the virtual machine monitor 530: the virtual machine 5330 migrates from the virtual machine monitor 530 to another virtual machine monitor X ( Figure 5A not shown).
[0057] In step S504, in response to monitoring a virtual machine lifecycle event occurring on the virtual machine monitor 530, the virtualization management node 520 sends a lifecycle event notification "[event type: migration, virtual machine identifier: virtual machine 5330, destination: virtual machine monitor X]" to the SDN controller 510 through the event subscription interface.
[0058] In step S506, the SDN controller 510 obtains and parses the lifecycle event notification.
[0059] In step S508, the SDN controller 510 deletes the flow table entries of the virtual machine 5330 in the NVE5320 according to the parsing result.
[0060] In step S510, the SDN controller 510 issues the flow table entries required for the communication between the virtual machine 5330 and the virtual machine 5340 to the NVEx in the virtual machine monitor X. After the virtual machine 5330 completes the migration, for the traffic sent from the virtual machine 5330 to the virtual machine 5340, the NVEx delivers the traffic generated by the virtual machine 5330 to the NVE5320 according to the flow table, and the NVE5320 then delivers the traffic to the virtual machine 5340 according to the flow table.
[0061] Through the method of the above embodiments, the SDN controller can obtain the lifecycle events of the virtual machine by subscribing to the lifecycle event notifications, so as to dynamically adjust the network in a timely manner.
[0062] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable non-transitory storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0063] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0064] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions in the process Figure 1One or more processes and / or blocks Figure 1 The functions specified in one or more blocks.
[0065] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 One or more processes and / or blocks Figure 1 The steps of the functions specified in one or more blocks.
[0066] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A network virtualization system, comprising: An SDN controller for sending control information to a Network Visible Entity (NVE); The NVE is deployed in a container and depends on the NVE executable software library within the container. The NVE and the executable software library on which the NVE depends are packaged and deployed in the container, and are used to process the network traffic of the virtual machine corresponding to the NVE. Wherein, the container is deployed in a virtual machine monitor, and the virtual machine monitor depends on the monitor executable software library in the virtual machine monitor; A virtualization management node for sending a lifecycle event notification in a preset format to the SDN controller through an event subscription interface; The SDN controller is further configured to, in response to obtaining the lifecycle event notification sent by the virtualization management node through the event subscription interface, parse the lifecycle event notification, and send control information to one or more NVEs in the system according to the parsing result.
2. The network virtualization system according to claim 1, further comprising: A virtual machine monitor for hosting one or more virtual machines and the NVE deployed in the container.
3. The network virtualization system according to claim 1 or 2, wherein, The virtual machine monitor depends on the monitor executable software library in the virtual machine monitor.
4. The network virtualization system according to claim 1, wherein The control information includes at least one of a flow table and configuration information.
5. A network virtualization method, comprising: A Network Visible Entity (NVE) receives control information sent by an SDN controller. Wherein, the NVE and the executable software library on which the NVE depends are packaged and deployed in a container, the container is deployed in a virtual machine monitor, and the virtual machine monitor depends on the monitor executable software library in the virtual machine monitor; The NVE processes the network traffic of the virtual machine corresponding to the NVE according to the NVE executable software library within the container and the control information sent by the SDN controller; A virtualization management node sends a lifecycle event notification in a preset format to the SDN controller through an event subscription interface; The SDN controller, in response to obtaining the lifecycle event notification sent by the virtualization management node through the event subscription interface, parses the lifecycle event notification; The SDN controller sends control information to one or more NVEs in the system according to the parsing result.
6. The network virtualization method according to claim 5, wherein, The virtual machine monitor depends on the monitor executable software library in the virtual machine monitor.
7. The network virtualization method according to claim 5, wherein, The control information includes at least one of a flow table and configuration information.
Citation Information
Patent Citations
Mechanism to detect control plane loops in a software defined networking (SDN) network
CN108702326A
Container-aware application dependency identification
US20160380916A1