A method and device for implementing an isolation group

By dividing independent and cross-isolated group fields in the iNOF networking environment and assigning isolation group identification codes to the hosts, the problem of limited number of ZONE and number of hosts in ZONE is solved, and more efficient host management and resource utilization is achieved.

CN113918504BActive Publication Date: 2025-08-22新华三技术有限公司合肥分公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111283928.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-01
Publication Date
2025-08-22
Estimated Expiration
2041-11-01

AI Technical Summary

Technical Problem

In the prior art, the number of ZONEs and the number of hosts that can be supported in ZONE in the iNOF networking environment are small, resulting in excessive consumption of ACL resources and the inability to effectively manage a large number of hosts.

Method used

By dividing the identification field into independent isolation group fields and cross isolation group fields, use the independent isolation group field to assign independent isolation group identification codes to the host, and dynamically adjust the isolation group identification in the cross isolation group scenario to reduce ACL resource consumption.

Benefits of technology

This significantly increases the number of support for the isolation group and the number of hosts that can be supported in each isolation group, reduces the ACL resource usage, and improves the management efficiency of the iNOF networking environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113918504B_ABST
    Figure CN113918504B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a method and device for implementing an isolation group, the method comprising: determining whether a target isolation group belongs to an independent isolation group, determining an independent isolation group identification code of the target isolation group based on an independent isolation group field in an identification field; for each host in the target isolation group, determining the independent isolation group identification code of the target isolation group as the first-class isolation group identification of the host; and adding a routing table entry containing a first identification relationship, wherein the first identification relationship is: a correspondence between the IP address of each host in the target isolation group and the first-class isolation group identification. This increases the number of isolation groups supported while ensuring that a large number of hosts can be supported in each isolation group.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a method and device for implementing an isolation group. Background Art

[0002] NVMe over RoCE, also known as "NoF," stands for fast non-volatile storage with remote memory access over converged Ethernet. This technology combines NVMe, the latest storage media technology, with RDMA (Remote Direct Memory Access), the latest networking technology. Together, they create a superhighway from high-performance storage to high-performance computing.

[0003] However, in order to store large amounts of data, storage systems often need to manage a large number of hosts, and new hosts are often connected to network devices. In order to make intelligent lossless network technology better serve the storage system, iNOF (Intelligent Lossless NVMe Over Fabric) technology was proposed. iNOF is a technology that applies intelligent lossless networks to storage systems through rapid management and control of connected hosts, realizing the integration of computing and storage networks. Through rapid management and control of connected hosts, new connected hosts can be notified in real time, and the relevant configurations of the intelligent lossless network can be intelligently adjusted. iNOF technology also supports notifying the storage system of host information, which can assist the storage system in managing hosts.

[0004] INOF needs to achieve mutual isolation between different isolation groups (ZONEs) and forward messages between hosts in the same zone. There are two specific implementation methods:

[0005] 1. Host intercommunication within a zone and inter-zone isolation are achieved by issuing a large number of ACLs. However, if a zone contains a large number of hosts, this consumes a significant amount of ACL resources, which have a maximum limit. This results in a limited number of hosts supported within a zone. For example, if a device has 32KB of ACL resources, issuing a large number of ACLs to achieve intra-zone host intercommunication and inter-zone isolation consumes all ACL resources and can only support a maximum of 178 hosts.

[0006] 2. Use the CLASSID (identification field) to identify the zone to which the host belongs, and implement isolation based on the host's zone identification. In this case, each zone can support a large number of hosts, but because a host may belong to multiple zones, each zone can only be identified by a single bit. Typically, the CLASSID is 16 bits, so the maximum number of zones supported in this case is only 16. Summary of the Invention

[0007] The purpose of the embodiments of the present application is to provide a method and device for implementing an isolation group to increase the number of supported isolation groups while ensuring that a large number of hosts can be supported in each isolation group.

[0008] To achieve the above objectives, an embodiment of the present application provides a method for implementing an isolation group, the method comprising:

[0009] A method for implementing an isolation group, the method comprising:

[0010] Determining that the target isolation group belongs to an independent isolation group, and determining an independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field;

[0011] For each host in the target isolation group, determining the independent isolation group identification code of the target isolation group as the first-class isolation group identification of the host;

[0012] Add a routing table entry containing a first identification relationship, where the first identification relationship is: the correspondence between the IP address of each host in the target isolation group and the first type isolation group identifier.

[0013] Optionally, the method further includes:

[0014] Determining that the newly added host in the target isolation group belongs to multiple cross isolation groups, where the cross isolation groups include the target isolation group;

[0015] Allocating bits to the cross isolation groups based on the cross isolation group field in the identification field, wherein each cross isolation group corresponds to one bit in the cross isolation group field;

[0016] Release the independent isolation group identification code of the target isolation group, and based on the bits in the cross isolation group field allocated to the target isolation group, change the first-class isolation group identification of other hosts in the target isolation group except the newly added host to the second-class isolation group identification.

[0017] Optionally, the method further includes:

[0018] Based on the correspondence between the cross-isolation group and the bits in the cross-isolation group field, the second-type isolation group identifier of the newly added host is determined.

[0019] Optionally, also include:

[0020] For the newly added host, a routing table entry containing the correspondence between the second type of isolation group identifier and the host IP address is issued.

[0021] Optionally, also include:

[0022] For other hosts in the target isolation group except the newly added host, the pre-added routing table entry is deleted, and a routing table entry containing the correspondence between the second type isolation group identifier and the host IP address is reissued.

[0023] To achieve the above objectives, an embodiment of the present application further provides a device for implementing an isolation group, the device comprising:

[0024] A first determining module is configured to determine whether the target isolation group belongs to an independent isolation group, and determine an independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field;

[0025] A second determining module is configured to determine, for each host in the target isolation group, the independent isolation group identification code of the target isolation group as the first type isolation group identification of the host;

[0026] The first adding module is used to add a routing table entry containing a first identification relationship, where the first identification relationship is: a correspondence between the IP address of each host in the target isolation group and the first type of isolation group identifier.

[0027] Optionally, the device further includes:

[0028] a third determining module, configured to determine that the newly added host in the target isolation group belongs to a plurality of cross isolation groups, wherein the cross isolation groups include the target isolation group;

[0029] an allocating module, configured to allocate bits to the cross isolation groups based on the cross isolation group field in the identification field, wherein each cross isolation group corresponds to one bit in the cross isolation group field;

[0030] A change module is used to release the independent isolation group identification code of the target isolation group, and based on the bits in the cross isolation group field allocated to the target isolation group, change the first-class isolation group identification of other hosts in the target isolation group except the newly added host to the second-class isolation group identification.

[0031] Optionally, the device further includes:

[0032] The fourth determining module is configured to determine the second type isolation group identifier of the newly added host based on the correspondence between the cross isolation group and the bits in the cross isolation group field.

[0033] Optionally, the device further includes:

[0034] The first issuing module is used to issue a routing table entry containing a correspondence between a second type of isolation group identifier and a host IP address to the newly added host.

[0035] Optionally, the device further includes:

[0036] The second sending module is used to delete the pre-added routing table entries for other hosts in the target isolation group except the newly added host, and re-send the routing table entries containing the correspondence between the second type of isolation group identifier and the host IP address.

[0037] To achieve the above-mentioned object, an embodiment of the present application further provides an electronic device, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;

[0038] Memory for storing computer programs;

[0039] The processor is used to implement the implementation method steps of any of the above isolation groups when executing the program stored in the memory.

[0040] To achieve the above-mentioned purpose, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the implementation method steps of any of the above-mentioned isolation groups are implemented.

[0041] Beneficial effects of the embodiments of the present invention:

[0042] Apply the implementation method and device of the isolation group provided in the embodiments of the present application, determine that the target isolation group belongs to an independent isolation group, and determine the independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field; for each host in the target isolation group, determine the independent isolation group identification code of the target isolation group as the first-class isolation group identification of the host; add a routing table entry containing a first identification relationship, and the first identification relationship is: the correspondence between the IP address of each host in the target isolation group and the first-class isolation group identification.

[0043] As can be seen, marking the isolation group to which a host belongs using an identification code eliminates the need to issue a large number of ACLs, which in turn reduces the use of excessive ACL resources. This ensures that each isolation group can support a large number of hosts. Furthermore, by separating the independent isolation group field from the identification field, the independent isolation group field can identify a large number of independent isolation groups, significantly increasing the number of supported isolation groups.

[0044] Of course, it is not necessary to achieve all of the advantages described above simultaneously in order to implement any product or method of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other embodiments can also be obtained based on these drawings.

[0046] Figure 1 A flowchart of a method for implementing an isolation group provided in an embodiment of the present application;

[0047] Figure 2 A schematic diagram of an independent isolation group field and a cross isolation group field in an identification field provided in an embodiment of the present application;

[0048] Figure 3 This is another flowchart of a method for implementing an isolation group provided in an embodiment of the present application;

[0049] Figure 4 A schematic diagram of a structure of a device for implementing an isolation group provided in an embodiment of the present application;

[0050] Figure 5 A schematic structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0051] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field based on this application are within the scope of protection of this application.

[0052] In order to solve the technical problem in the prior art that the INOF networking environment supports a small number of zones or a small number of hosts that can be supported in a zone, an embodiment of the present application provides a method and device for implementing an isolation group.

[0053] See also Figure 1 , Figure 1 A flow chart of a method for implementing an isolation group provided in an embodiment of the present application, which can be applied to network devices in an INOF networking environment, such as Figure 1 As shown, the method may include the following steps:

[0054] S101: Determine whether the target isolation group belongs to an independent isolation group, and determine the independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field.

[0055] The target isolation group may be a newly created isolation group.

[0056] In the embodiment of the present application, the isolation group is a ZONE in the INOF networking environment. As an example, ZONE1 contains two hosts a1 and b1, and ZONE2 contains two hosts c2 and d2. Then, messages can be forwarded between a1 and b1, and messages can be forwarded between c2 and d2, but messages are not allowed to be forwarded between a1 and c2, a1 and d2, b1 and c2, and b1 and d2.

[0057] In the embodiment of the present application, isolation groups are divided into independent isolation groups and cross-isolation groups. An independent isolation group refers to an isolation group that does not have overlapping hosts with other isolation groups. In other words, if all hosts in an isolation group belong only to that isolation group, then the isolation group is an independent isolation group. Conversely, if at least one host in the isolation group also belongs to another isolation group, then the isolation group is a cross-isolation group.

[0058] In an embodiment of the present application, after creating a target isolation group, if it is determined that the target isolation group belongs to an independent isolation group, the independent isolation group identification code of the target isolation group is determined based on the independent isolation group field in the identification field.

[0059] The identification field is a bit field serving as an identification code, also called a CLASSID. Typically, the CLASSID is 16 bits.

[0060] That is, the ZONE is identified by a bit field, and the identification code is also used as the isolation group identifier of the host, that is, the ZONE identifier, to indicate the ZONE to which the host belongs.

[0061] For example, if the identification code of Zone A is 0000 0000 0000 0011, during the packet forwarding process, the switching device searches the routing table and obtains that the Zone identification of a host is 0000 0000 0000 0011, indicating that the host belongs to Zone A.

[0062] In the embodiment of the present application, different from the prior art, the identification field is used in a hierarchical manner. Specifically, the identification field is divided into an independent isolation group field and a cross isolation group field. If the isolation group is an independent isolation group, the independent isolation group field is used to generate the identification code of the isolation group. If the isolation group is a cross isolation group, the cross isolation group field is used to generate the identification code of the isolation group. See below for details.

[0063] In the embodiment of the present application, the lengths of the independent isolation group field and the cross isolation group field can be set as needed. For example, if the identification field is 16 bits, the independent isolation group field can be set to the lower 8 bits of the 16 bits, and the cross isolation group field can be set to the upper 8 bits of the 16 bits. In addition, if the number of cross isolation groups is large, the length of the cross isolation group field can be appropriately increased, and the length of the independent isolation group field can be correspondingly reduced.

[0064] As an example, see Figure 2 , Figure 2 A schematic diagram of the independent isolation group field and the cross isolation group field in the identification field provided in the embodiment of the present application, such as Figure 2 As shown, the identification field (CLASSID) is divided into an independent isolation group field and a cross isolation group field. The independent isolation group field is the lower 8 bits in the identification field, and the cross isolation group field is the upper 8 bits in the identification field.

[0065] In this step, if it is determined that the target isolation group belongs to the independent isolation group, an independent isolation group identification code is allocated to it based on the independent isolation group field in the identification field.

[0066] As an example, the independent isolation group field is the lower 8 bits, and the lower 8 bits can constitute a resource pool of identification codes. Each bit can be 0 or 1, so there are 2 in the resource pool of the identification code. 8 An independent isolation group identification code, capable of marking 2 8 It can be seen that a large number of independent isolation groups can be identified through the independent isolation group field.

[0067] S102: For each host in the target isolation group, determine the independent isolation group identification code of the target isolation group as the first-type isolation group identification of the host.

[0068] In an embodiment of the present application, for each host in the target isolation group, in order to indicate that these hosts all belong to the target isolation group, the independent isolation group identification code of the target isolation group can be determined as the first-class isolation group identification of the host.

[0069] S103: Add a routing table entry containing a first identification relationship, where the first identification relationship is: a correspondence between the IP address of each host in the target isolation group and the first type of isolation group identifier.

[0070] In an embodiment of the present application, in order to allow forwarding of messages between hosts within an isolation group and not allow forwarding of messages between isolation groups, it is necessary to add a routing table entry containing the correspondence between the host IP address and the isolation group identifier.

[0071] As an example, the first host belongs to the target isolation group, and the independent isolation group identification code of the target isolation group is 0000 0001. The first-class isolation group identification of the first host is also 0000 0001. If the IP address of the first host is 1.1.1.1, a routing table entry containing the first identification relationship is added to the routing table. The first identification relationship is the correspondence between the IP address 1.1.1.1 and the first-class isolation group identification 0000 0001.

[0072] That is, after the forwarding device obtains the message to be forwarded, it can find the isolation group to which the host of the source IP address and destination IP address of the message belongs by reading the routing table, thereby determining whether the message can be forwarded.

[0073] Apply the implementation method of the isolation group provided in the embodiment of the present application, determine that the target isolation group belongs to an independent isolation group, and determine the independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field; for each host in the target isolation group, determine the independent isolation group identification code of the target isolation group as the first-class isolation group identification of the host; add a routing table entry containing a first identification relationship, and the first identification relationship is: the correspondence between the IP address of each host in the target isolation group and the first-class isolation group identification.

[0074] As can be seen, marking the isolation group to which a host belongs using an identification code eliminates the need to issue a large number of ACLs, which in turn reduces the use of excessive ACL resources. This ensures that each isolation group can support a large number of hosts. Furthermore, by separating the independent isolation group field from the identification field, the independent isolation group field can identify a large number of independent isolation groups, significantly increasing the number of supported isolation groups.

[0075] See also Figure 3 , Figure 3 This is another flowchart of the implementation method of the isolation group provided in the embodiment of the present application. Figure 3 As shown, the following steps are included:

[0076] S301: Determine whether the target isolation group belongs to an independent isolation group, and determine the independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field.

[0077] S302: For each host in the target isolation group, determine the independent isolation group identification code of the target isolation group as the first-type isolation group identification of the host.

[0078] S303: Add a routing table entry containing a first identification relationship, where the first identification relationship is: a correspondence between the IP address of each host in the target isolation group and the first type of isolation group identifier.

[0079] Among them, S301-S303 are consistent with S101-S103 and will not be repeated here.

[0080] S304: Determine whether the newly added host in the target isolation group belongs to multiple cross isolation groups, and the cross isolation groups include the target isolation group.

[0081] In an embodiment of the present application, due to business needs, after the target isolation group is created, a host may be added to the target isolation group.

[0082] If the newly added host has been pre-assigned to another isolation group, the target isolation group will be changed to a cross isolation group because there are overlapping hosts between the target isolation group and the other isolation groups.

[0083] S305: Allocate bits to the cross isolation groups based on the cross isolation group field in the identification field, wherein each cross isolation group corresponds to one bit in the cross isolation group field.

[0084] If at least one host in each cross-isolation group belongs to multiple isolation groups, then if a first-class isolation group identifier is still assigned to a host belonging to multiple isolation groups, then the first-class isolation group identifier can only represent the single isolation group to which the host belongs, not all isolation groups to which the host belongs. This is not permitted. Therefore, a first-class isolation group identifier cannot represent all isolation groups to which a host belongs. In this case, the cross-isolation group field is used to represent the isolation groups to which the host belongs, with each bit in the cross-isolation group field corresponding to a single isolation group.

[0085] S306: Release the independent isolation group identification code of the target isolation group, and based on the bits in the cross isolation group field allocated to the target isolation group, change the first-class isolation group identifications of the other hosts in the target isolation group except the newly added host to the second-class isolation group identification.

[0086] Since the target isolation group is changed from an independent isolation group to a cross-isolation group, it is necessary to release the independent isolation group identification code of the target isolation group, and based on the bits in the cross-isolation group field assigned to the target isolation group, change the first-class isolation group identification of other hosts in the target isolation group except the newly added host to the second-class isolation group identification.

[0087] Among them, the first type of isolation group identifier is determined based on the independent isolation group field, and the second type of isolation group identifier is determined based on the cross isolation group field.

[0088] As an example, the target isolation group is ZONE A. The cross-isolation group field is the upper 8 bits in the identification field. Assuming that the bit assigned to ZONE A is the highest bit in the upper 8 bits, then for all hosts in the target isolation group except the newly added host, the original isolation group identifier can be changed to the second-class isolation group identifier 1000 0000 (the upper 8 bits, the lower 8 bits omitted). This shows that if a host belongs to a cross-isolation group, the bit in the upper 8 bits corresponding to the cross-isolation group is set.

[0089] In one embodiment of the present application, the second type isolation group identifier of the newly added host is determined based on the correspondence between the cross isolation group and the bits in the cross isolation group field.

[0090] As an example, if the target isolation group is ZONE A and the isolation groups to which the new host belongs include ZONE A and ZONE B, and the cross-isolation group field is the upper 8 bits of the identification field, then one bit can be allocated to each of ZONE A and ZONE B. Assuming the bits allocated to ZONE A and ZONE B are the highest and second-highest bits of the upper 8 bits, respectively, since the new host belongs to ZONE A and ZONE B, the second-type isolation group identifier of the new host is determined based on the correspondence between the cross-isolation groups to which the new host belongs (ZONE A and ZONE B) and the bits in the cross-isolation group field. This can be 1100 0000 (the upper 8 bits are omitted). The first bit "1" corresponds to ZONE A, and the second bit "1" corresponds to ZONE B. This second-type isolation group identifier 1100 0000 (the upper 8 bits are omitted) indicates that the new host belongs to both ZONE A and ZONE B.

[0091] In an embodiment of the present application, when the independent isolation group field is used to represent the first type of isolation group identifier, the cross isolation group field can be set to all 0s; when the cross isolation group field is used to represent the second type of isolation group identifier, the independent isolation group field can be set to all 0s.

[0092] In one embodiment of the present application, for a newly added host, a routing table entry containing a correspondence between a second type of isolation group identifier and a host IP address may be issued.

[0093] As an example, the IP address of the newly added host is 1.1.1.01. After the target isolation group is changed to the cross isolation group, the allocated bit is the highest bit in the cross isolation group field (high 8 bits), and the second-class isolation group identifier is 10000000 (high 8 bits, lower 8 bits omitted). Then, a routing table entry containing the correspondence between the IP address of the newly added host 1.1.1.01 and the second-class isolation group identifier 1000 0000 is added to the routing table.

[0094] Correspondingly, for other hosts in the target isolation group except the newly added host, since the original isolation group identifiers of these hosts have changed, it is necessary to delete the pre-added routing table entries and re-issue the routing table entries containing the correspondence between the second-class isolation group identifier and the host IP address.

[0095] It can be seen that each time a host is added to the target isolation group, it is determined whether the target isolation group is changed to a cross isolation group. If it is changed to a cross isolation group, the identification code of the target isolation group is dynamically changed to be suitable for the situation of the cross isolation group.

[0096] That is, in the embodiment of the present application, the identification field is divided into an independent isolation group field and a cross isolation group field, which are used to mark independent isolation groups and cross isolation groups respectively. Thus, the cross isolation group field can be applied to the situation where a host belongs to multiple isolation groups, and the independent isolation group field can identify a large number of independent isolation groups, thereby significantly increasing the number of isolation groups supported.

[0097] In the embodiment of the present application, the host in the isolation group can also be deleted.

[0098] When a host is deleted from a cross-isolation group, the cross-isolation group is changed to an independent isolation group. The allocated bits in the cross-isolation group field can be released, and a new independent isolation group identification code can be determined for it based on the independent isolation group field in the identification field, thereby ensuring that the bit resources of the cross-isolation group field can be reasonably utilized.

[0099] When all hosts in an isolation group are deleted, the identification resource of the isolation group, that is, the isolation group identification code, can be released to save identification field resources.

[0100] Corresponding to the implementation method of the isolation group provided in the embodiment of the present application, the embodiment of the present application also provides an implementation device of the isolation group, see Figure 4 , Figure 4 A schematic diagram of a structure of a device for implementing an isolation group provided in an embodiment of the present application includes the following modules:

[0101] A first determining module 401 is configured to determine whether the target isolation group belongs to an independent isolation group, and determine an independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field;

[0102] The second determining module 402 is configured to determine, for each host in the target isolation group, the independent isolation group identification code of the target isolation group as the first type isolation group identification of the host;

[0103] The first adding module 403 is used to add a routing table entry containing a first identification relationship, where the first identification relationship is: a correspondence between the IP address of each host in the target isolation group and the first type of isolation group identifier.

[0104] As can be seen, marking the isolation group to which a host belongs using an identification code eliminates the need to issue a large number of ACLs, which in turn reduces the use of excessive ACL resources. This ensures that each isolation group can support a large number of hosts. Furthermore, by separating the independent isolation group field from the identification field, the independent isolation group field can identify a large number of independent isolation groups, significantly increasing the number of supported isolation groups.

[0105] In one embodiment of the present application, the apparatus may further include:

[0106] A third determination module is used to determine whether the newly added host in the target isolation group belongs to multiple cross isolation groups, and the cross isolation groups include the target isolation group;

[0107] an allocation module, configured to allocate bits to the cross isolation groups based on the cross isolation group field in the identification field, wherein each cross isolation group corresponds to one bit in the cross isolation group field;

[0108] The change module is used to release the independent isolation group identification code of the target isolation group, and based on the bits in the cross isolation group field allocated to the target isolation group, change the first-class isolation group identification of other hosts in the target isolation group except the newly added host to the second-class isolation group identification.

[0109] In one embodiment of the present application, the apparatus may further include:

[0110] The fourth determining module is configured to determine the second type isolation group identifier of the newly added host based on the correspondence between the cross isolation group and the bits in the cross isolation group field.

[0111] In one embodiment of the present application, the apparatus may further include:

[0112] The first issuing module is used to issue a routing table entry containing a correspondence between a second type of isolation group identifier and a host IP address for a newly added host.

[0113] In one embodiment of the present application, the apparatus may further include:

[0114] The second sending module is used to delete the pre-added routing table entries for other hosts in the target isolation group except the newly added host, and re-send the routing table entries containing the correspondence between the second type of isolation group identifier and the host IP address.

[0115] It can be seen that each time a host is added to the target isolation group, it is determined whether the target isolation group is changed to a cross isolation group. If it is changed to a cross isolation group, the identification code of the target isolation group is dynamically changed to be suitable for the situation of the cross isolation group.

[0116] That is, in the embodiment of the present application, the identification field is divided into an independent isolation group field and a cross isolation group field, which are used to mark independent isolation groups and cross isolation groups respectively. Thus, the cross isolation group field can be applied to the situation where a host belongs to multiple isolation groups, and the independent isolation group field can identify a large number of independent isolation groups, thereby significantly increasing the number of isolation groups supported.

[0117] The present application also provides an electronic device, such as Figure 5As shown, it includes a processor 501, a communication interface 502, a memory 503 and a communication bus 504, wherein the processor 501, the communication interface 502, and the memory 503 communicate with each other through the communication bus 504.

[0118] Memory 503, used for storing computer programs;

[0119] The processor 501 is configured to execute the program stored in the memory 503, and implement the following steps:

[0120] Determining that the target isolation group belongs to an independent isolation group, and determining an independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field;

[0121] For each host in the target isolation group, determining the independent isolation group identification code of the target isolation group as the first-class isolation group identification of the host;

[0122] Add a routing table entry containing a first identification relationship, where the first identification relationship is: a correspondence between the IP address of each host in the target isolation group and the first type of isolation group identifier.

[0123] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.

[0124] The communication interface is used for communication between the above electronic device and other devices.

[0125] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.

[0126] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0127] Using the electronic device provided in the embodiment of the present application, it is determined that the target isolation group belongs to an independent isolation group, and the independent isolation group identification code of the target isolation group is determined based on the independent isolation group field in the identification field; for each host in the target isolation group, the independent isolation group identification code of the target isolation group is determined as the first-class isolation group identification of the host; a routing table entry containing a first identification relationship is added, and the first identification relationship is: the correspondence between the IP address of each host in the target isolation group and the first-class isolation group identification.

[0128] As can be seen, marking the isolation group to which a host belongs using an identification code eliminates the need to issue a large number of ACLs, which in turn reduces the use of excessive ACL resources. This ensures that each isolation group can support a large number of hosts. Furthermore, by separating the independent isolation group field from the identification field, the independent isolation group field can identify a large number of independent isolation groups, significantly increasing the number of supported isolation groups.

[0129] In another embodiment provided by the present invention, a computer-readable storage medium is also provided, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned isolation group implementation methods are implemented.

[0130] In another embodiment provided by the present invention, a computer program product including instructions is also provided, which, when executed on a computer, enables the computer to execute any of the isolation group implementation methods in the above embodiments.

[0131] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0132] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0133] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the implementation device, electronic device, computer-readable storage medium, and computer program product embodiments of the isolation group, since they are basically similar to the implementation method embodiments of the isolation group, the description is relatively simple. For related parts, please refer to the partial description of the implementation method embodiment of the isolation group.

[0134] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention are included in the scope of protection of the present invention.

Claims

1. A method for implementing an isolation group, characterized in that: The method comprises: Determine that the target isolation group belongs to an independent isolation group, and determine the independent isolation group identification code of the target isolation group based on the independent isolation group field in the identification field; wherein the isolation group includes at least one host, hosts in the same isolation group can forward messages to each other, and hosts included in different isolation groups are isolated from each other; the identification field includes the independent isolation group field; the independent isolation group is an isolation group that has no overlapping hosts with other isolation groups; For each host in the target isolation group, determining the independent isolation group identification code of the target isolation group as the first-class isolation group identification of the host; Add a routing table entry containing a first identification relationship, where the first identification relationship is: the correspondence between the IP address of each host in the target isolation group and the first type isolation group identifier.

2. The method according to claim 1, characterized in that The method further comprises: Determining that the newly added host in the target isolation group belongs to multiple cross isolation groups, where the cross isolation groups include the target isolation group; Based on the cross isolation group field in the identification field, bits are allocated to the cross isolation group, wherein the identification field also includes a cross isolation group field, each cross isolation group corresponds to a bit in the cross isolation group field, and the cross isolation group is an isolation group that has intersecting hosts with other isolation groups; Release the independent isolation group identification code of the target isolation group, and based on the bits in the cross isolation group field allocated to the target isolation group, change the first-class isolation group identification of other hosts in the target isolation group except the newly added host to the second-class isolation group identification.

3. The method according to claim 2, characterized in that The method further comprises: Based on the correspondence between the cross-isolation group and the bits in the cross-isolation group field, the second-type isolation group identifier of the newly added host is determined.

4. The method according to claim 3, characterized in that Also includes: For the newly added host, a routing table entry containing the correspondence between the second type of isolation group identifier and the host IP address is issued.

5. The method according to claim 4, characterized in that Also includes: For other hosts in the target isolation group except the newly added host, the pre-added routing table entry is deleted, and a routing table entry containing the correspondence between the second type isolation group identifier and the host IP address is reissued.

6. A device for implementing an isolation group, characterized in that: The device comprises: A first determination module is configured to determine whether a target isolation group belongs to an independent isolation group, and to determine an independent isolation group identification code of the target isolation group based on an independent isolation group field in an identification field; wherein the isolation group includes at least one host, hosts within the same isolation group can forward messages to each other, and hosts included in different isolation groups are isolated from each other; the identification field includes an independent isolation group field; and the independent isolation group is an isolation group that has no overlapping hosts with other isolation groups; A second determining module is configured to determine, for each host in the target isolation group, the independent isolation group identification code of the target isolation group as the first type isolation group identification of the host; The first adding module is used to add a routing table entry containing a first identification relationship, where the first identification relationship is: a correspondence between the IP address of each host in the target isolation group and the first type of isolation group identifier.

7. The device according to claim 6, characterized in that The device further comprises: a third determining module, configured to determine that the newly added host in the target isolation group belongs to a plurality of cross isolation groups, wherein the cross isolation groups include the target isolation group; An allocation module is configured to allocate bits to the cross isolation group based on the cross isolation group field in the identification field, wherein the identification field also includes a cross isolation group field, each cross isolation group corresponds to a bit in the cross isolation group field, and the cross isolation group is an isolation group that has an intersecting host with other isolation groups; A change module is used to release the independent isolation group identification code of the target isolation group, and based on the bits in the cross isolation group field allocated to the target isolation group, change the first-class isolation group identification of other hosts in the target isolation group except the newly added host to the second-class isolation group identification.

8. The device according to claim 7, characterized in that The device further comprises: The fourth determining module is configured to determine the second type isolation group identifier of the newly added host based on the correspondence between the cross isolation group and the bits in the cross isolation group field.

9. The device according to claim 8, characterized in that The device further comprises: The first issuing module is used to issue a routing table entry containing a correspondence between a second type of isolation group identifier and a host IP address to the newly added host.

10. The device according to claim 9, characterized in that The device further comprises: The second sending module is used to delete the pre-added routing table entries for other hosts in the target isolation group except the newly added host, and re-send the routing table entries containing the correspondence between the second type of isolation group identifier and the host IP address.

11. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; A processor, configured to implement the method steps described in any one of claims 1 to 5 when executing a program stored in a memory.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Virtual machine configuration method and device, equipment and storage medium

    CN111949375A

  • Network queue monitoring method and device, computer equipment and storage medium

    CN113411264A