A Software-Defined Terminal Access Method and System for Multi-Service Scenarios
By generating network mapping rules, the entity terminal directly accesses the virtual terminal without modifying the IP address and MAC address, solving the problem of inconvenience in access in the software-defined network, improving access convenience and saving floating IP resources.
Patent Information
- Application Number
- CN202211292948.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-21
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-10-21
AI Technical Summary
The existing software-defined network virtualization platform needs to modify the IP address or allocate floating IP when accessing physical terminals, resulting in inconvenient access and limited floating IP resources.
By calculating the associated attributes of the service network and the entity terminal to generate network mapping rules. The entity terminal does not need to modify the IP address and MAC address, but directly connects to the virtual terminal and uses the SDN switch to perform network mapping and packet conversion.
It realizes convenient access to physical terminals and virtual terminals, avoids cumbersome configuration of IP addresses and MAC addresses, and saves floating IP resources.
Smart Images

Figure CN115766665B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software-defined networks, and particularly to a software-defined terminal access method and system for multi-service scenarios. Background Art
[0002] With the increasingly obvious trend of diversified network user requirements, network virtualization technology has emerged and been applied to the realization of diversified requirements, becoming one of the important technologies to promote network innovation. And Software Defined Network (SDN) provides natural advantages for network virtualization due to its architecture characteristics. Therefore, network virtualization based on SDN has become a research hotspot in current computer networks.
[0003] The pure virtualized network application scenario cannot meet the diversified needs of network users. It is necessary to dynamically connect physical terminals to different virtual service networks according to business requirements, and then connect to virtual terminals to realize a network application scenario that combines virtual and physical. And it is required that the connected physical terminals do not change their original IP addresses and MAC addresses, and the virtual service network only receives terminal data from local network segment addresses.
[0004] However, traditional SDN-based network virtualization platforms need to be connected through multiple tunnels, require VPN configuration for connected physical terminals, or configure multiple IP addresses on physical terminals, that is, it is required to modify the IP addresses of physical terminals, or allocate floating IPs to all virtual terminals, and the resources of floating IPs are limited. That is, it is traditionally impossible to conveniently connect physical terminals and virtual terminals.
[0005] Therefore, how to provide a software-defined terminal access method and system for multi-service scenarios to improve the convenience of accessing physical terminals and virtual terminals has become an urgent technical problem to be solved. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to provide a software-defined terminal access method and system for multi-service scenarios to improve the convenience of accessing physical terminals and virtual terminals.
[0007] In a first aspect, the present invention provides a software-defined terminal access method for multi-service scenarios, including the following steps:
[0008] Step S1: Calculate a first correlation attribute for the input service network information, and then generate service network data;
[0009] Step S2: Calculate a second correlation attribute for the input physical terminal information, and then generate physical terminal data;
[0010] Step S3: Based on the received terminal network access request, generate a service access tuple according to the service network data and the entity terminal data;
[0011] Step S4: Based on the service access tuple, formulate a network mapping rule for the access of the entity terminal and the virtual terminal, and send the network mapping rule to the SDN switch;
[0012] Step S5: The SDN switch accesses the entity terminal and the virtual terminal based on the network mapping rule.
[0013] Further, in the step S1, the service network information at least includes a service network number, a network segment, an available IP address pool of the virtual terminal, an available IP address pool of the entity terminal, and a first port number for accessing the SDN switch;
[0014] The first association attribute is the first MAC address corresponding to each IP address in the available IP address pool;
[0015] The first MAC address is in binary, and the 1st - 32nd bits are the same as the binary value of the corresponding IP address, the 33rd - 47th bits are the same as the binary value of the service network number, and the 48th bit has a value of 1.
[0016] Further, in the step S2, the entity terminal information at least includes an entity terminal number, a second port number for accessing the SDN switch, a terminal IP address, a terminal MAC address, and a terminal gateway IP address;
[0017] The second association attribute is the second MAC address corresponding to the terminal gateway IP address;
[0018] The second MAC address is in binary, and the 1st - 32nd bits are the same as the binary value of the entity terminal number, the 33rd - 47th bits have a value of 1, and the 48th bit has a value of 0.
[0019] Further, the step S3 is specifically:
[0020] Based on the received terminal network access request carrying the service network number and the entity terminal number, match the service network data based on the service network number, match the entity terminal data based on the entity terminal number, and generate a service access tuple according to the service network data and the entity terminal data;
[0021] The service access tuple at least includes a service network number, a first port number, an entity terminal number, a second port number, a terminal IP address, a terminal MAC address, a terminal gateway IP address, a second MAC address, a terminal access IP address, a terminal access MAC address, and a corresponding list of the IP addresses and MAC addresses of the virtual terminal;
[0022] The terminal access IP address is allocated based on the available IP address pool of the physical terminal; the terminal access MAC address is generated based on the terminal access IP address.
[0023] Further, in step S4, the network mapping rules at least include the terminal gateway ARP proxy response flow rule, the terminal address SNAT and routing conversion flow rule, and the terminal address DNAT and routing conversion flow rule;
[0024] The terminal gateway ARP proxy response flow rule is used to process the ARP request packet sent by the physical terminal to the terminal gateway, construct an ARP response packet of the terminal gateway and send it to the physical terminal;
[0025] The terminal address SNAT and routing conversion flow rule is used to perform SNAT and routing conversion processing on the data packet sent by the physical terminal to the virtual terminal and then send it to the virtual service network;
[0026] The terminal address DNAT and routing conversion flow rule is used to perform DNAT and routing conversion processing on the data packet sent by the virtual terminal to the physical terminal and then send it to the physical terminal.
[0027] In a second aspect, the present invention provides a software-defined terminal access system for multi-service scenarios, including the following modules:
[0028] The service network data generation module is used to calculate the first association attribute for the input service network information, and then generate service network data;
[0029] The physical terminal data generation module is used to calculate the second association attribute for the input physical terminal information, and then generate physical terminal data;
[0030] The service access tuple generation module is used to generate a service access tuple based on the received terminal network access request according to the service network data and the physical terminal data;
[0031] The network mapping rule sending module is used to formulate the network mapping rules for the access of the physical terminal and the virtual terminal based on the service access tuple, and send the network mapping rules to the SDN switch;
[0032] The terminal access module is used for the SDN switch to access the physical terminal and the virtual terminal based on the network mapping rules.
[0033] Further, in the service network data generation module, the service network information at least includes the service network number, network segment, available IP address pool of the virtual terminal, available IP address pool of the physical terminal, and the first port number for accessing the SDN switch;
[0034] The first associated attribute is the first MAC address corresponding to each IP address in the available IP address pool;
[0035] The first MAC address is in binary, and the 1st - 32nd bits are the same as the binary value of the corresponding IP address, the 33rd - 47th bits are the same as the binary value of the service network number, and the 48th bit has a value of 1.
[0036] Further, in the entity terminal data generation module, the entity terminal information at least includes an entity terminal number, a second port number for accessing the SDN switch, a terminal IP address, a terminal MAC address, and a terminal gateway IP address;
[0037] The second associated attribute is the second MAC address corresponding to the terminal gateway IP address;
[0038] The second MAC address is in binary, and the 1st - 32nd bits are the same as the binary value of the entity terminal number, the 33rd - 47th bits have a value of 1, and the 48th bit has a value of 0.
[0039] Further, the service access tuple generation module is specifically configured to:
[0040] Based on the received terminal network access request carrying the service network number and the entity terminal number, match the service network data based on the service network number, match the entity terminal data based on the entity terminal number, and generate a service access tuple based on the service network data and the entity terminal data;
[0041] The service access tuple at least includes a service network number, a first port number, an entity terminal number, a second port number, a terminal IP address, a terminal MAC address, a terminal gateway IP address, a second MAC address, a terminal access IP address, a terminal access MAC address, and a corresponding list of the IP address and MAC address of the virtual terminal;
[0042] The terminal access IP address is allocated based on the available IP address pool of the entity terminal; the terminal access MAC address is generated based on the terminal access IP address.
[0043] Further, in the network mapping rule sending module, the network mapping rules at least include a terminal gateway ARP proxy reply flow rule, a terminal address SNAT and routing conversion flow rule, and a terminal address DNAT and routing conversion flow rule;
[0044] The terminal gateway ARP proxy reply flow rule is used to process the ARP request packet sent by the entity terminal to the terminal gateway, construct an ARP reply packet of the terminal gateway, and send it to the entity terminal;
[0045] The terminal address SNAT and routing conversion flow rules are used to perform SNAT and routing conversion processing on the data packets sent from the physical terminal to the virtual terminal, and then send them to the virtual service network;
[0046] The terminal address DNAT and routing conversion flow rules are used to perform DNAT and routing conversion processing on the data packets sent from the virtual terminal to the physical terminal, and then send them to the physical terminal.
[0047] The advantages of the present invention are as follows:
[0048] By calculating the first association attribute for the input service network information to generate service network data, calculating the second association attribute for the input physical terminal information to generate physical terminal data, then generating service access tuples based on the service network data and the physical terminal data, formulating network mapping rules for the access of the physical terminal and the virtual terminal based on the service access tuples, and finally directly accessing the physical terminal and the virtual terminal based on the network mapping rules, the physical terminal does not need to modify the original IP address and MAC address, eliminating the cumbersome configuration process of the IP address and MAC address. The physical terminal does not need to perform VPN configuration, that is, the physical terminal can access different virtual service networks without any configuration modification, and there is no need to allocate floating IPs for the virtual terminals, saving limited floating IP resources, and ultimately greatly improving the convenience of accessing the physical terminal and the virtual terminal. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] The present invention will be further described below with reference to the accompanying drawings in conjunction with embodiments.
[0050] Figure 1 is a flowchart of a software-defined terminal access method for multi-service scenarios of the present invention.
[0051] Figure 2 is a schematic structural diagram of a software-defined terminal access system for multi-service scenarios of the present invention.
[0052] Figure 3 is a schematic hardware architecture diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0053] Please refer to Figures 1 to 3As shown in the figure, the deployment environment of the present invention includes an SDN controller, an SDN switch, an OVS switch, physical terminals, and a virtual service network constructed by virtual terminals; the SDN controller, as the core part of the system, is used for virtual service network management, physical terminal management, and terminal access control; the SDN switch is connected to the physical terminals and communicates with the OVS switch in the computing node, and is uniformly controlled by the SDN controller; the computing node is a computing server, and there can be multiple; the OVS switch is connected to the virtual terminals and communicates with the SDN switch, and is uniformly controlled by the SDN controller; the virtual service network defines a group of virtual terminals with three-layer isolation, corresponding to a network segment; the virtual terminals are configured with a group of IP addresses and MAC addresses of the virtual service network to which they belong and are connected to the OVS switch.
[0054] A preferred embodiment of a software-defined terminal access method for multi-service scenarios of the present invention includes the following steps:
[0055] Step S1: Calculate the first association attribute for the input service network information, and then generate and store service network data.
[0056] Step S2: Calculate the second association attribute for the input physical terminal information, and then generate and store physical terminal data.
[0057] Step S3: Based on the received terminal network access request, generate a service access tuple according to the service network data and the physical terminal data.
[0058] Step S4: Based on the service access tuple, formulate a network mapping rule for the access of physical terminals and virtual terminals, and send the network mapping rule to the SDN switch.
[0059] Step S5: The SDN switch accesses the physical terminals and virtual terminals based on the network mapping rule.
[0060] During the access process, it is supported to modify the service network number in the terminal network access request. First, dynamically recycle the issued network mapping rule and release the terminal access IP address accessed by the physical terminal, and then allocate a new terminal access IP address, generate and issue a new network mapping rule.
[0061] In the step S1, the service network information at least includes a service network number, a network segment, an available IP address pool of virtual terminals, an available IP address pool of physical terminals, and a first port number for accessing the SDN switch.
[0062] The first association attribute is the first MAC address corresponding to each IP address in the available IP address pool.
[0063] The first MAC address is in binary. The 1st to 32nd bits are the same as the binary values of the corresponding IP address. The 33rd to 47th bits are the same as the binary values of the service network number. The 48th bit has a value of 1.
[0064] For example, if the service network number is 1 and the IP address of the virtual service network is 10.0.0.100, the corresponding first MAC address is 80:01:0a:00:00:64.
[0065] In step S2, the entity terminal information at least includes the entity terminal number, the second port number for accessing the SDN switch, the terminal IP address, the terminal MAC address, and the terminal gateway IP address. The service network number and the entity terminal number are globally unique.
[0066] The second associated attribute is the second MAC address corresponding to the terminal gateway IP address.
[0067] The second MAC address is in binary. The 1st to 32nd bits are the same as the binary values of the entity terminal number. The 33rd to 47th bits have a value of 1. The 48th bit has a value of 0. When the second MAC address is the same as the terminal MAC address, the value of the 33rd to 47th bits is set to 0.
[0068] For example, if the entity terminal number is 1 and the terminal gateway IP address is 192.168.0.1, the corresponding second MAC address is 7f:ff:00:00:00:01.
[0069] Step S3 is specifically as follows:
[0070] Based on the received terminal network access request carrying the service network number and the entity terminal number, match the service network data based on the service network number, match the entity terminal data based on the entity terminal number, and generate a service access tuple based on the service network data and the entity terminal data.
[0071] The service access tuple at least includes the service network number, the first port number, the entity terminal number, the second port number, the terminal IP address, the terminal MAC address, the terminal gateway IP address, the second MAC address, the terminal access IP address, the terminal access MAC address, and the corresponding list of the IP address and MAC address of the virtual terminal.
[0072] The terminal access IP address is allocated based on the available IP address pool of the entity terminal. The terminal access MAC address is generated based on the terminal access IP address.
[0073] In the step S4, the network mapping rules at least include the terminal gateway ARP proxy reply flow rule, the terminal address SNAT and routing conversion flow rule, and the terminal address DNAT and routing conversion flow rule; one virtual terminal IP and MAC address pair in the service access tuple corresponds to one flow rule.
[0074] The terminal gateway ARP proxy reply flow rule is used to process the ARP request packet sent by the physical terminal to the terminal gateway, construct the ARP reply packet of the terminal gateway and send it to the physical terminal.
[0075] The terminal gateway ARP proxy reply flow rule includes two parts: a matching item and an action.
[0076] Matching item:
[0077] In-port = terminal access port number
[0078] Protocol type = ARP
[0079] ARP packet type = Request
[0080] Destination IP address = terminal gateway address
[0081] Action:
[0082] Destination MAC address = source MAC address
[0083] Source MAC address = terminal gateway MAC address
[0084] ARP packet type = Reply
[0085] ARP Reply destination MAC address = ARP Request source MAC address
[0086] ARP Reply source MAC address = terminal gateway MAC address
[0087] ARP Reply destination IP address = ARP Request source IP address
[0088] ARP Reply source IP address = terminal gateway IP address
[0089] Out-port = terminal access port number
[0090] The terminal address SNAT and routing conversion flow rule is used to perform SNAT and routing conversion processing on the data packet sent by the physical terminal to the virtual terminal and then send it to the virtual service network.
[0091] The terminal address SNAT and routing conversion flow rule includes two parts: a matching item and an action.
[0092] Matching item:
[0093] In-port = Terminal access port number
[0094] Source IP address = Terminal IP address
[0095] Destination IP address = Virtual terminal IP address
[0096] Action:
[0097] Source IP address = Terminal access IP address
[0098] Source MAC address = Terminal access MAC address
[0099] Destination MAC address = Virtual terminal MAC address
[0100] Out-port = Service network access port number
[0101] The terminal address DNAT and routing conversion flow rule is used to perform DNAT and routing conversion processing on the data packets sent from the virtual terminal to the physical terminal and then send them to the physical terminal;
[0102] The terminal address DNAT and routing conversion flow rule includes two parts: a matching item and an action:
[0103] Matching item:
[0104] In-port = Service network access port number
[0105] Destination IP address = Terminal access IP address
[0106] Action:
[0107] Destination IP address = Terminal IP address
[0108] Destination MAC address = Terminal MAC address
[0109] Source MAC address = Terminal gateway MAC address
[0110] Out-port = Terminal access port number.
[0111] The following further illustrates the terminal gateway ARP proxy response flow rule, the terminal address SNAT and routing conversion flow rule, and the terminal address DNAT and routing conversion flow rule:
[0112] The service access tuple is:
[0113] (1,1,2,1, "192.168.0.4", "a4:ae:11:12:48:2c", "192.168.0.1", "7f:ff:00:00:00:1", "10.0.0.100", "80:01:0a:00:00:64", [("10.0.0.3", "80:01:0a:00:00:03"), ("10.0.0.4", "80:01:0a:00:00:04"), ("10.0.0.5", "80:01:0a:00:00:05")])
[0114] For the above service access tuples, the following network mapping rules are formulated:
[0115] (1) Terminal gateway ARP proxy response flow rule:
[0116] in_port = 2, arp, arp_tpa = 192.168.0.1, arp_op = 1, actions = move:NXM_OF_ETH_SRC[]->NXM_OF_ETH_DST[], mod_dl_src:7f:ff:00:00:00:1, load:0x02->NXM_OF_ARP_OP[], move:NXM_NX_ARP_SHA[]->NXM_NX_ARP_THA[], load:0x7fff00000001->NXM_NX_ARP_SHA[], move:NXM_OF_ARP_SPA[]->NXM_OF_ARP_TPA[], load:0xc0a80001->NXM_OF_ARP_SPA[], in_port
[0117] Description of matching items:
[0118] in_port = 2, the incoming port is the terminal access port number 2;
[0119] arp, the protocol type is ARP;
[0120] arp_op = 1, the ARP packet type is Request;
[0121] arp_tpa = 192.168.0.1, the destination IP address is the terminal gateway address 192.168.0.1;
[0122] Description of action items (actions):
[0123] move:"NXM_OF_ETH_SRC[]->NXM_OF_ETH_DST[]", set the destination MAC address to the source MAC address;
[0124] mod_dl_src: "7f:ff:00:00:00:01", set the source MAC address to the terminal gateway MAC address 7f:ff:00:00:00:01;
[0125] load: "0x02 -> NXM_OF_ARP_OP[]", set the ARP packet type to Reply;
[0126] move: "NXM_NX_ARP_SHA[] -> NXM_NX_ARP_THA[]", set the ARP Reply destination MAC address to the ARP Request source MAC address;
[0127] load: "0x7fff00000001 -> NXM_NX_ARP_SHA[]", set the ARP Reply source MAC address to the terminal gateway MAC address in hexadecimal format;
[0128] move: "NXM_OF_ARP_SPA[] -> NXM_OF_ARP_TPA[]", set the ARP Reply destination IP address to the ARP Request source IP address;
[0129] load: "0xc0a80001 -> NXM_OF_ARP_SPA[]", set the ARP Reply source IP address to the terminal gateway IP address in hexadecimal format;
[0130] in_port, send it back from the terminal entry port;
[0131] (2) Terminal address SNAT and routing conversion flow rules:
[0132] The virtual terminal ("10.0.0.3", "80:01:0a:00:00:03") corresponds to the flow rule as follows:
[0133] in_port = 2, nw_src = 192.168.0.4, nw_dst = 10.0.0.3, actions = mod_nw_src:10.0.0.100, mod_dl_src:80:01:0a:00:00:64, mod_dl_dst:80:01:0a:00:00:03, output:1
[0134] Explanation of matching items:
[0135] in_port = 2, the incoming port is the terminal access port number;
[0136] nw_src = 192.168.0.4, the source IP address is the terminal IP address;
[0137] nw_dst = 10.0.0.3, the destination IP address is the virtual terminal IP address;
[0138] Description of action items (actions):
[0139] mod_nw_src: 10.0.0.100, set the source IP address to the terminal access IP address;
[0140] mod_dl_src: 80:01:0a:00:00:64, set the source MAC address to the terminal access MAC address;
[0141] mod_dl_dst: 80:01:0a:00:00:03, set the destination MAC address to the virtual terminal MAC address;
[0142] output: 1, set the output port to the service network access port number;
[0143] The flow rule corresponding to the virtual terminal ("10.0.0.4", "80:01:0a:00:00:04") is:
[0144] in_port = 2, nw_src = 192.168.0.4, nw_dst = 10.0.0.4, actions = mod_nw_src: 10.0.0.100, mod_dl_src: 80:01:0a:00:00:64, mod_dl_dst: 80:01:0a:00:00:04, output: 1
[0145] The flow rule corresponding to the virtual terminal ("10.0.0.5", "80:01:0a:00:00:05") is:
[0146] in_port = 2, nw_src = 192.168.0.4, nw_dst = 10.0.0.5, actions = mod_nw_src: 10.0.0.100, mod_dl_src: 80:01:0a:00:00:64, mod_dl_dst: 80:01:0a:00:00:05, output: 1
[0147] (3) Terminal address DNAT and routing conversion flow rules:
[0148] in_port = 1, nw_dst = 10.0.0.100, actions = mod_nw_dst:192.168.0.4, mod_dl_src:7f:ff:00:00:00:01, mod_dl_dst:a4:ae:11:12:48:2c, output:2 Match item description:
[0149] in_port = 1, the ingress port is the service network access port number;
[0150] nw_dst = 10.0.0.100, the destination IP address is the terminal access IP address;
[0151] Description of actions:
[0152] mod_nw_dst:192.168.0.4, set the destination IP address to the terminal IP address;
[0153] mod_dl_src:7f:ff:00:00:00:01, set the source MAC address to the terminal gateway MAC address;
[0154] mod_dl_dst:a4:ae:11:12:48:2c, set the destination MAC address to the terminal MAC address;
[0155] output:2, set the egress port to the terminal access port number.
[0156] A preferred embodiment of a software-defined terminal access system for multi-service scenarios according to the present invention includes the following modules:
[0157] Service network data generation module, used to calculate the first association attribute for the input service network information, and then generate and store the service network data;
[0158] Entity terminal data generation module, used to calculate the second association attribute for the input entity terminal information, and then generate and store the entity terminal data;
[0159] Service access tuple generation module, used to generate service access tuples based on the received terminal network access request according to the service network data and entity terminal data;
[0160] Network mapping rule sending module, used to formulate network mapping rules for entity terminal and virtual terminal access based on the service access tuple, and send the network mapping rules to the SDN switch;
[0161] Terminal access module, used for the SDN switch to access entity terminals and virtual terminals based on the network mapping rules.
[0162] During the access process, it is supported to modify the service network number in the terminal network access request. First, dynamically recycle the issued network mapping rules and release the terminal access IP address accessed by the entity terminal. Then, allocate a new terminal access IP address, generate and issue a new network mapping rule.
[0163] In the service network data generation module, the service network information at least includes a service network number, a network segment, an available IP address pool of virtual terminals, an available IP address pool of entity terminals, and a first port number for accessing the SDN switch;
[0164] The first associated attribute is the first MAC address corresponding to each IP address in the available IP address pool;
[0165] The first MAC address is in binary, and the 1st to 32nd bits are the same as the binary value of the corresponding IP address, the 33rd to 47th bits are the same as the binary value of the service network number, and the 48th bit has a value of 1.
[0166] For example, if the service network number is 1, the IP address of the virtual service network is 10.0.0.100, and the corresponding first MAC address is 80:01:0a:00:00:64.
[0167] In the entity terminal data generation module, the entity terminal information at least includes an entity terminal number, a second port number for accessing the SDN switch, a terminal IP address, a terminal MAC address, and a terminal gateway IP address; the service network number and the entity terminal number are globally unique;
[0168] The second associated attribute is the second MAC address corresponding to the terminal gateway IP address;
[0169] The second MAC address is in binary, and the 1st to 32nd bits are the same as the binary value of the entity terminal number, the 33rd to 47th bits have a value of 1, and the 48th bit has a value of 0. When the second MAC address is the same as the terminal MAC address, the value of the 33rd to 47th bits is set to 0.
[0170] For example, if the entity terminal number is 1 and the terminal gateway IP address is 192.168.0.1, the corresponding second MAC address is 7f:ff:00:00:00:01.
[0171] The service access tuple generation module is specifically used for:
[0172] Based on the received terminal network access request carrying the service network number and the entity terminal number, match the service network data based on the service network number, match the entity terminal data based on the entity terminal number, and generate a service access tuple based on the service network data and the entity terminal data;
[0173] The service access tuple at least includes a service network number, a first port number, an entity terminal number, a second port number, a terminal IP address, a terminal MAC address, a terminal gateway IP address, a second MAC address, a terminal access IP address, a terminal access MAC address, and a correspondence list of the IP address and MAC address of a virtual terminal;
[0174] The terminal access IP address is allocated based on the available IP address pool of the entity terminal; the terminal access MAC address is generated based on the terminal access IP address.
[0175] In the network mapping rule sending module, the network mapping rule at least includes a terminal gateway ARP proxy reply flow rule, a terminal address SNAT and routing conversion flow rule, and a terminal address DNAT and routing conversion flow rule; one pair of virtual terminal IP and MAC addresses in the service access tuple corresponds to one flow rule;
[0176] The terminal gateway ARP proxy reply flow rule is used to process the ARP request packet sent by the entity terminal to the terminal gateway, construct an ARP reply packet of the terminal gateway, and send it to the entity terminal;
[0177] The terminal gateway ARP proxy reply flow rule includes two parts: a matching item and an action:
[0178] Matching item:
[0179] Inbound port = terminal access port number
[0180] Protocol type = ARP
[0181] ARP packet type = Request
[0182] Destination IP address = terminal gateway address
[0183] Action:
[0184] Destination MAC address = source MAC address
[0185] Source MAC address = terminal gateway MAC address
[0186] ARP packet type = Reply
[0187] ARP Reply destination MAC address = ARP Request source MAC address
[0188] ARP Reply source MAC address = terminal gateway MAC address
[0189] ARP Reply destination IP address = ARP Request source IP address
[0190] ARP Reply Source IP Address = Terminal Gateway IP Address
[0191] Output Port = Terminal Access Port Number
[0192] The terminal address SNAT and routing conversion flow rules are used to perform SNAT and routing conversion processing on the data packets sent from the physical terminal to the virtual terminal, and then send them to the virtual service network;
[0193] The terminal address SNAT and routing conversion flow rules include two parts: a matching item and an action:
[0194] Matching item:
[0195] Input Port = Terminal Access Port Number
[0196] Source IP Address = Terminal IP Address
[0197] Destination IP Address = Virtual Terminal IP Address
[0198] Action:
[0199] Source IP Address = Terminal Access IP Address
[0200] Source MAC Address = Terminal Access MAC Address
[0201] Destination MAC Address = Virtual Terminal MAC Address
[0202] Output Port = Service Network Access Port Number
[0203] The terminal address DNAT and routing conversion flow rules are used to perform DNAT and routing conversion processing on the data packets sent from the virtual terminal to the physical terminal, and then send them to the physical terminal.
[0204] The terminal address DNAT and routing conversion flow rules include two parts: a matching item and an action:
[0205] Matching item:
[0206] Input Port = Service Network Access Port Number
[0207] Destination IP Address = Terminal Access IP Address
[0208] Action:
[0209] Destination IP Address = Terminal IP Address
[0210] Destination MAC Address = Terminal MAC Address
[0211] Source MAC Address = Terminal Gateway MAC Address
[0212] Output Port = Terminal Access Port Number.
[0213] The following further illustrates the ARP proxy response flow rules for the terminal gateway, the SNAT and routing conversion flow rules for the terminal address, and the DNAT and routing conversion flow rules for the terminal address:
[0214] The service access tuple is:
[0215] (1, 1, 2, 1, “192.168.0.4”, “a4:ae:11:12:48:2c”, “192.168.0.1”, “7f:ff:00:00:00:01”, “10.0.0.100”, “80:01:0a:00:00:64”, [(“10.0.0.3”, “80:01:0a:00:00:03”), (“10.0.0.4”, “80:01:0a:00:00:04”), (“10.0.0.5”, “80:01:0a:00:00:05”)])
[0216] For the above service access tuple, the following network mapping rules are formulated:
[0217] (1) ARP proxy response flow rules for the terminal gateway:
[0218] in_port = 2, arp, arp_tpa = 192.168.0.1, arp_op = 1, actions = move:NXM_OF_ETH_SRC[] -> NXM_OF_ETH_DST[], mod_dl_src:7f:ff:00:00:00:01, load:0x02 -> NXM_OF_ARP_OP[], move:NXM_NX_ARP_SHA[] -> NXM_NX_ARP_THA[], load:0x7fff00000001 -> NXM_NX_ARP_SHA[], move:NXM_OF_ARP_SPA[] -> NXM_OF_ARP_TPA[], load:0xc0a80001 -> NXM_OF_ARP_SPA[], in_port
[0219] Description of the matching items:
[0220] in_port = 2, the incoming port is the terminal access port number 2;
[0221] arp, the protocol type is ARP;
[0222] arp_op = 1, the ARP packet type is Request;
[0223] arp_tpa = 192.168.0.1, and the destination IP address is the terminal gateway address 192.168.0.1;
[0224] Description of action items:
[0225] move: "NXM_OF_ETH_SRC[] -> NXM_OF_ETH_DST[]", set the destination MAC address to the source MAC address;
[0226] mod_dl_src: "7f:ff:00:00:00:1", set the source MAC address to the terminal gateway MAC address 7f:ff:00:00:00:1;
[0227] load: "0x02 -> NXM_OF_ARP_OP[]", set the ARP packet type to Reply;
[0228] move: "NXM_NX_ARP_SHA[] -> NXM_NX_ARP_THA[]", set the ARP Reply destination MAC address to the ARP Request source MAC address;
[0229] load: "0x7fff00000001 -> NXM_NX_ARP_SHA[]", set the ARP Reply source MAC address to the terminal gateway MAC address in hexadecimal format;
[0230] move: "NXM_OF_ARP_SPA[] -> NXM_OF_ARP_TPA[]", set the ARP Reply destination IP address to the ARP Request source IP address;
[0231] load: "0xc0a80001 -> NXM_OF_ARP_SPA[]", set the ARP Reply source IP address to the terminal gateway IP address in hexadecimal format;
[0232] in_port, send it back from the terminal entry port;
[0233] (2) Terminal address SNAT and routing conversion flow rules:
[0234] The flow rule corresponding to the virtual terminal ("10.0.0.3", "80:01:0a:00:00:03") is:
[0235] in_port = 2, nw_src = 192.168.0.4, nw_dst = 10.0.0.3, actions = mod_nw_src:10.0.0.100, mod_dl_src:80:01:0a:00:00:64, mod_dl_dst:80:01:0a:00:00:03, output:1
[0236] Match item description:
[0237] in_port = 2, the ingress port is the terminal access port number;
[0238] nw_src = 192.168.0.4, the source IP address is the terminal IP address;
[0239] nw_dst = 10.0.0.3, the destination IP address is the virtual terminal IP address;
[0240] Action item (actions) description:
[0241] mod_nw_src:10.0.0.100, set the source IP address to the terminal access IP address;
[0242] mod_dl_src:80:01:0a:00:00:64, set the source MAC address to the terminal access MAC address;
[0243] mod_dl_dst:80:01:0a:00:00:03, set the destination MAC address to the virtual terminal MAC address;
[0244] output:1, set the egress port to the service network access port number;
[0245] The flow rule corresponding to the virtual terminal (“10.0.0.4”, “80:01:0a:00:00:04”) is:
[0246] in_port = 2, nw_src = 192.168.0.4, nw_dst = 10.0.0.4, actions = mod_nw_src:10.0.0.100, mod_dl_src:80:01:0a:00:00:64, mod_dl_dst:80:01:0a:00:00:04, output:1
[0247] The flow rule corresponding to the virtual terminal (“10.0.0.5”, “80:01:0a:00:00:05”) is:
[0248] in_port = 2, nw_src = 192.168.0.4, nw_dst = 10.0.0.5, actions = mod_nw_src:10.0.0.100, mod_dl_src:80:01:0a:00:00:64, mod_dl_dst:80:01:0a:00:00:05, output:1
[0249] (3) Terminal address DNAT and routing conversion flow rules:
[0250] in_port = 1, nw_dst = 10.0.0.100, actions = mod_nw_dst:192.168.0.4, mod_dl_src:7f:ff:00:00:00:01, mod_dl_dst:a4:ae:11:12:48:2c, output:2
[0251] Match item description:
[0252] in_port = 1, the input port is the service network access port number;
[0253] nw_dst = 10.0.0.100, the destination IP address is the terminal access IP address;
[0254] Action (actions) description:
[0255] mod_nw_dst:192.168.0.4, set the destination IP address to the terminal IP address;
[0256] mod_dl_src:7f:ff:00:00:00:01, set the source MAC address to the terminal gateway MAC address;
[0257] mod_dl_dst:a4:ae:11:12:48:2c, set the destination MAC address to the terminal MAC address;
[0258] output:2, set the output port to the terminal access port number.
[0259] In summary, the advantages of the present invention are:
[0260] By calculating the first correlation attribute for the input business network information to generate business network data, calculating the second correlation attribute for the input entity terminal information to generate entity terminal data, then generating business access tuples based on the business network data and the entity terminal data, formulating network mapping rules for the access of entity terminals and virtual terminals based on the business access tuples, and finally directly accessing the entity terminals and virtual terminals based on the network mapping rules, the entity terminals do not need to modify the original IP addresses and MAC addresses, eliminating the cumbersome configuration process of IP addresses and MAC addresses. The entity terminals do not need to perform VPN configuration, that is, the entity terminals can access different virtual business networks without any configuration modification, and there is no need to allocate floating IPs for the virtual terminals, saving limited floating IP resources, and ultimately greatly improving the convenience of accessing entity terminals and virtual terminals.
[0261] Although the specific embodiments of the present invention have been described above, those skilled in the art of this technology should understand that the specific embodiments we described are illustrative rather than used to limit the scope of the present invention. Equivalent modifications and variations made by those skilled in the art in accordance with the spirit of the present invention should be covered by the scope protected by the claims of the present invention.
Claims
1. A software-defined terminal access method for multi-service scenarios, characterized in that: It includes the following steps: Step S1: Calculate the first correlation attribute for the input service network information, and then generate service network data; the service network information at least includes a service network number, a network segment, an available IP address pool of a virtual terminal, an available IP address pool of a physical terminal, and a first port number of an access SDN switch; The first correlation attribute is the first MAC address corresponding to each IP address in the available IP address pool; The first MAC address is in binary, and the 1st - 32nd bits are the same as the binary value of the corresponding IP address, the 33rd - 47th bits are the same as the binary value of the service network number, and the 48th bit has a value of 1; Step S2: Calculate the second correlation attribute for the input physical terminal information, and then generate physical terminal data; the physical terminal information at least includes a physical terminal number, a second port number of an access SDN switch, a terminal IP address, a terminal MAC address, and a terminal gateway IP address; Step S3: Based on the received terminal network access request carrying the service network number and the physical terminal number, match the service network data based on the service network number, match the physical terminal data based on the physical terminal number, and generate a service access tuple based on the service network data and the physical terminal data; The service access tuple at least includes a service network number, a first port number, a physical terminal number, a second port number, a terminal IP address, a terminal MAC address, a terminal gateway IP address, a second MAC address, a terminal access IP address, a terminal access MAC address, and a corresponding list of IP addresses and MAC addresses of the virtual terminal; The terminal access IP address is allocated based on the available IP address pool of the physical terminal; the terminal access MAC address is generated based on the terminal access IP address; Step S4: Based on the service access tuple, formulate a network mapping rule for the access of the physical terminal and the virtual terminal, and send the network mapping rule to the SDN switch; the network mapping rule at least includes a terminal gateway ARP proxy reply flow rule, a terminal address SNAT and routing conversion flow rule, and a terminal address DNAT and routing conversion flow rule; Step S5: The SDN switch accesses the physical terminal and the virtual terminal based on the network mapping rule.
2. The software-defined terminal access method for multi-service scenarios according to claim 1, characterized in that: In step S2, the second correlation attribute is the second MAC address corresponding to the terminal gateway IP address; The second MAC address is in binary, and the 1st - 32nd bits are the same as the binary value of the physical terminal number, the 33rd - 47th bits have a value of 1, and the 48th bit has a value of 0.
3. A software-defined terminal access method for multi-service scenarios according to claim 1, characterized in that: In step S4, the terminal gateway ARP proxy reply flow rule is used to process the ARP request packet sent by the physical terminal to the terminal gateway, construct an ARP reply packet of the terminal gateway, and send it to the physical terminal; The terminal address SNAT and routing conversion flow rule is used to perform SNAT and routing conversion processing on the data packet sent by the physical terminal to the virtual terminal, and then send it to the virtual service network; The terminal address DNAT and routing conversion flow rule is used to perform DNAT and routing conversion processing on the data packet sent by the virtual terminal to the physical terminal, and then send it to the physical terminal.
4. A software-defined terminal access system for multi-service scenarios, characterized in that: It includes the following modules: A service network data generation module, which is used to calculate a first association attribute for the input service network information, and then generate service network data; the service network information at least includes a service network number, a network segment, an available IP address pool of a virtual terminal, an available IP address pool of a physical terminal, and a first port number of an access SDN switch; The first association attribute is the first MAC address corresponding to each IP address in the available IP address pool; The first MAC address is in binary, and the 1st - 32nd bits are the same as the binary value of the corresponding IP address, the 33rd - 47th bits are the same as the binary value of the service network number, and the 48th bit has a value of 1; A physical terminal data generation module, which is used to calculate a second association attribute for the input physical terminal information, and then generate physical terminal data; the physical terminal information at least includes a physical terminal number, a second port number of an access SDN switch, a terminal IP address, a terminal MAC address, and a terminal gateway IP address; A service access tuple generation module, which is used to, based on the received terminal network access request carrying the service network number and the physical terminal number, match the service network data based on the service network number, match the physical terminal data based on the physical terminal number, and generate a service access tuple based on the service network data and the physical terminal data; The service access tuple at least includes a service network number, a first port number, a physical terminal number, a second port number, a terminal IP address, a terminal MAC address, a terminal gateway IP address, a second MAC address, a terminal access IP address, a terminal access MAC address, and a corresponding list of IP addresses and MAC addresses of the virtual terminal; The terminal access IP address is allocated based on the available IP address pool of the physical terminal; the terminal access MAC address is generated based on the terminal access IP address; A network mapping rule sending module, which is used to, based on the service access tuple, formulate network mapping rules for the access of the physical terminal and the virtual terminal, and send the network mapping rules to the SDN switch; the network mapping rules at least include a terminal gateway ARP proxy response flow rule, a terminal address SNAT and routing conversion flow rule, and a terminal address DNAT and routing conversion flow rule; A terminal access module, which is used for the SDN switch to access the physical terminal and the virtual terminal based on the network mapping rules.
5. The software-defined terminal access system for multi-service scenarios according to claim 4, wherein: In the physical terminal data generation module, the second association attribute is the second MAC address corresponding to the terminal gateway IP address; The second MAC address is in binary, and the 1st - 32nd bits are the same as the binary value of the physical terminal number, the 33rd - 47th bits have a value of 1, and the 48th bit has a value of 0.
6. The software-defined terminal access system for multi-service scenarios according to claim 4, characterized in that: In the network mapping rule sending module, the terminal gateway ARP proxy response flow rule is used to process the ARP request packet sent by the physical terminal to the terminal gateway, construct an ARP response packet of the terminal gateway and send it to the physical terminal; The terminal address SNAT and routing conversion flow rule is used to perform SNAT and routing conversion processing on the data packet sent by the physical terminal to the virtual terminal and then send it to the virtual service network; The terminal address DNAT and routing conversion flow rules are used to perform DNAT and routing conversion processing on the data packets sent from the virtual terminal to the physical terminal and then send them to the physical terminal.
Citation Information
Patent Citations
Method for realizing communication between OpenStack virtual machine and outside
CN112165432A