A cloud computing platform virtual private network system and network control method

The cloud computing platform virtual private network system addresses IP address scarcity and communication inefficiencies by using physical network cards and traffic controllers to manage virtual machine communications, enhancing security and efficiency within the network.

CN115811449BActive Publication Date: 2025-05-13GUANGZHOU JUNBO NETWORK TECH INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211390377.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-08
Publication Date
2025-05-13
Estimated Expiration
2042-11-08

AI Technical Summary

Technical Problem

Cloud computing platforms face challenges with IP address scarcity and communication efficiency in virtual private clouds (VPCs) due to increased virtual machine deployment, leading to routing inefficiencies and security vulnerabilities.

Method used

Implementing a cloud computing platform virtual private network system with physical machines equipped with physical network cards and traffic controllers, utilizing route access tables and communication link blocking rules to manage virtual machine communications directly, reducing router load and enhancing security.

Benefits of technology

This approach minimizes router ARP routing traversals, balances router workload, and improves network security by directly specifying next-hop addresses and controlling traffic flows, ensuring efficient and secure communication within the virtual private network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115811449B_ABST
    Figure CN115811449B_ABST
Patent Text Reader

Abstract

The present invention discloses a cloud computing platform virtual private network system and a network control method. The system includes at least two physical machines and a router; each physical machine realizes the connection of a virtual private network through a router; each physical machine includes a physical network card, a flow controller and at least one virtual machine; the physical network card records the network address of each virtual machine in the physical machine, and the virtual machine accesses the virtual private network through the physical network card on the physical machine; the physical network card also includes a routing access table, and the routing access table records the network address of other virtual machines in the virtual private network. The flow controller is used to control the communication initiation and communication reception of each virtual machine on the physical machine. The present invention reduces the number of times the router ARP routing table is traversed and shares the workload of the router through the design of the routing access table and the flow controller; at the same time, the security protection capability of the virtual private network system itself and the ability to quickly cut off the flow when encountering an attack are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of virtual private network communication, and in particular to a cloud computing platform virtual private network system and a network control method. Background Art

[0002] Cloud computing is a network application model that manages and schedules a large number of computing resources connected by the network in a unified manner, forming a computing resource pool and providing services according to demand. A virtual machine is a complete computer system that has complete hardware system functions and runs in a completely isolated environment through software simulation. It can fully share the hardware resources of the host physical machine and is widely used in cloud computing platforms.

[0003] When using virtual machines on cloud computing platforms, enterprises usually consider establishing a virtual private cloud (VPC) for budget costs and data security considerations. However, as the scale of business continues to increase, more and more virtual machines will inevitably be deployed in the virtual private network, resulting in a shortage of IP addresses and difficulty in expansion in the virtual private network. At the same time, the communication request in the virtual private network is addressed by the router through ARP traversal. After finding the target address, the communication request is forwarded to achieve communication. When the number of virtual machines deployed increases, the communication efficiency will become lower and lower, and the load on the router will become heavier; and virtual machines that are not in the same VLAN in the router cannot communicate with each other. Summary of the invention

[0004] In view of this, an embodiment of the present invention provides a cloud computing platform virtual private network system and a network control method.

[0005] A first aspect of the present invention provides a cloud computing platform virtual private network system, comprising at least two physical machines and a router; each of the physical machines realizes a virtual private network connection through a router; each of the physical machines comprises a physical network card, a traffic controller and at least one virtual machine;

[0006] The physical network card records the network addresses of each virtual machine in the physical machine to which it belongs, and the virtual machine accesses the virtual private network through the physical network card on the physical machine; the physical network card also includes a routing access table, and the routing access table records the network addresses of other virtual machines in the virtual private network;

[0007] The flow controller is used to control the communication initiation and communication reception of each virtual machine on the physical machine.

[0008] Furthermore, the physical network card is used to query the network address of the target virtual machine through the routing access table when the virtual machine on the physical machine initiates communication to other virtual machines in the virtual private network; directly specify the next hop address of the router for the communication as the network address of the target virtual machine.

[0009] Furthermore, the traffic controller controls the communication initiation process of each virtual machine on the physical machine to which it belongs, including: the traffic controller writes a communication link blocking rule, and blocks the communication request initiated by the controlled virtual machine on the physical machine to which it belongs through the communication link blocking rule, so that the communication request initiated by the controlled virtual machine cannot reach the physical network card of the physical machine to which it belongs; the traffic controller also sends the communication link blocking rule to the traffic controllers on other physical machines in the virtual private network, so that the communication link blocking rule is loaded onto other traffic controllers.

[0010] Furthermore, the traffic controller controls the communication receiving process of each virtual machine on the physical machine, including: the traffic controller records the network addresses or network address segments of other virtual machines in the virtual private network that the virtual machine on the physical machine refuses to communicate with; when the physical machine receives a communication request from the network address or network address segment corresponding to the virtual machine that refuses communication, the traffic controller discards the communication request.

[0011] Furthermore, the traffic controller controls the communication receiving process of each virtual machine on the physical machine, which also includes: the traffic controller records the public network address or public network address segment allowed to communicate by the virtual machine on the physical machine; when the physical machine receives a communication request sent from the public network address or public network address segment allowed to communicate, the traffic controller transmits the communication request to the virtual machine; when the physical machine receives a communication request sent from a public network address or public network address segment other than the public network address or public network address segment allowed to communicate, the traffic controller discards the communication request.

[0012] Furthermore, the router includes a network address pool, which is used to record the network address of each virtual machine in the virtual private network; the routing access table is regularly updated through the network address pool.

[0013] Furthermore, the virtual private network adds a physical machine in the virtual private network through the following steps:

[0014] Connecting the newly added physical machine to the router;

[0015] Write the network address of the physical network card of the newly added physical machine into the network address pool;

[0016] Send the routing access table to the physical network card of the newly added physical machine.

[0017] A second aspect of an embodiment of the present invention provides a network control method, which is applied to a physical machine on a virtual private network system of a cloud computing platform, and includes the following steps:

[0018] Get the communication request of the virtual machine to which the physical machine belongs;

[0019] Query the network address of the target virtual machine of the communication request through the routing access table;

[0020] The next hop address of the router for the communication is designated as the network address of the target virtual machine.

[0021] Furthermore, the method further comprises the following steps:

[0022] Write communication link blocking rules;

[0023] The communication request initiated by the controlled virtual machine on the physical machine to which it belongs is blocked by the communication link blocking rule, so that the communication request initiated by the controlled virtual machine cannot reach the physical network card of the physical machine to which it belongs;

[0024] The communication link blocking rule is sent to the traffic controllers on other physical machines in the virtual private network, so that the communication link blocking rule is loaded on the other traffic controllers.

[0025] Furthermore, the method further comprises the following steps:

[0026] Record the network addresses or network address segments of other virtual machines in the virtual private network to which the virtual machine on the physical machine refuses to communicate; when receiving a communication request from the network address or network address segment corresponding to the virtual machine that refuses to communicate, discard the communication request;

[0027] Record the public network addresses or public network address segments that the virtual machines on the physical machine are allowed to communicate with; when receiving a communication request sent from a public network address or public network address segment that is allowed to communicate, transmit the communication request to the virtual machine; when receiving a communication request sent from a public network address or public network address segment other than the public network address or public network address segment that is allowed to communicate, discard the communication request.

[0028] The embodiment of the present invention also discloses a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device can read the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the above method.

[0029] The embodiments of the present invention have the following beneficial effects: the present invention reduces the number of times the router ARP routing table is traversed and shares the workload of the router by implementing the placement of the routing access table on the physical network card of the physical machine and using the iptables and routing functions of the physical machine. At the same time, the present invention can realize the flow control of the virtual machine to other virtual machines and the public network in the virtual private network based on the flow controller on the physical machine, greatly improving the security protection capability of the virtual private network system itself and the ability to quickly cut off the flow when encountering an attack.

[0030] Additional aspects and advantages of the present invention will be given in part in the following description, and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0032] Figure 1 It is a schematic diagram of the layout of a virtual private network in the prior art.

[0033] Figure 2 It is a schematic diagram of the layout of a virtual private network in a cloud computing platform virtual private network system and a network control method of the present invention. DETAILED DESCRIPTION

[0034] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0035] In order to better understand the virtual private network system in the embodiment of the present invention, the common virtual private network system architecture in the prior art is first described below. Figure 1In the prior art, the virtual private network system architecture includes a router and physical machines A, B, and C. The network address of the router is 10.0.0.0 / 8, which means that this router supports the planning of 10 million network addresses. Physical machines A, B, and C are each equipped with several virtual machines. These virtual machines share the computing resources of the physical machine. Each virtual machine has an independent network address and is connected to the router through the physical network card on the physical machine. At the same time, the router needs to divide the network addresses of several virtual machines into VLANs. When the virtual machine needs to communicate in the virtual private network, the communication request will be uniformly aggregated to the router for ARP addressing, causing a network broadcast storm in the virtual private network.

[0036] In order to overcome the disadvantages of the virtual private network architecture in the prior art, an embodiment of the present invention provides a cloud computing platform virtual private network system, such as Figure 2 In this embodiment, the virtual private network system includes a router and physical machines A, B, and C. The router address is 10.0.0.0 / 8, and each physical machine includes a physical network card, a traffic controller, and at least one virtual machine.

[0037] The physical network card records the network address of each virtual machine in the physical machine to which it belongs. The virtual machine accesses the virtual private network through the physical network card on the physical machine. At the same time, the physical network card also includes a routing access table, which records the network addresses of other virtual machines in the virtual private network. The traffic controller is used to control the communication initiation and reception of each virtual machine on the physical machine.

[0038] When the virtual machines in the virtual private network system of this embodiment need to communicate, taking the communication from virtual machine 10.8.1.2 on physical machine A to virtual machine 10.10.2.3 on physical machine C as an example, the network address of the virtual machine on physical machine C is queried in the routing access table of the physical network card on physical machine A. After finding that its network address is 10.10.2.3, the next hop address of 10.8.1.2 is directly assigned to 10.10.2.3 on the router. The physical network card of physical machine A can then communicate and connect to the physical network card of physical machine C, thereby realizing ARP-free addressing and cross-VLAN communication.

[0039] In this embodiment, the routing access table is regularly updated through the network address pool of the router, and the network address pool records the network address of each virtual machine in the virtual private network.

[0040] In this embodiment, the flow control of the virtual private network system includes two parts: internal network flow control and public network flow control; the internal network flow control includes two parts: control communication request initiation and control communication request reception.

[0041] Control the initiation of communication requests: The traffic controller writes communication link blocking rules, and blocks the communication requests initiated by the controlled virtual machines on the physical machine to which it belongs through the communication link blocking rules, so that the communication requests initiated by the controlled virtual machines cannot reach the physical network card of the physical machine to which it belongs; the traffic controller also sends the communication link blocking rules to the traffic controllers on other physical machines in the virtual private network, so that the communication link blocking rules are loaded on other traffic controllers.

[0042] by Figure 2 Taking physical machine B as an example, when physical machine B is maliciously hijacked, the communication link blocking rule can be written into the flow controller of physical machine B by manual writing or importing from the outside, and the flow controller of physical machine B blocks the connection between physical machine B and the rest of the virtual private network according to the communication link blocking rule. At the same time, the flow controller of physical machine B in this embodiment can share the communication link blocking rule with physical machine A and physical machine C, and apply the same communication link blocking rule to the flow controllers of physical machines A and C. When physical machine B is hijacked, the rest of the virtual private network system will not be affected by the attack of physical machine B, and the business can be completed normally.

[0043] In this embodiment, the communication link blocking rule can be based on a single network address, such as 10.10.2.3, 10.8.4.1, 10.10.4.8, etc.; it can also be based on a network address segment. For example, 10.10.2.0 / 24 means that the addresses of the entire network address segment of 10.10.2.1-10.10.2.254 are discarded.

[0044] Control the reception of communication requests: The traffic controller records the network addresses or network address segments of other virtual machines in the virtual private network to which the virtual machine on the physical machine refuses to communicate; when the physical machine receives a communication request from the network address or network address segment corresponding to the virtual machine that refuses communication, the traffic controller discards the communication request.

[0045] by Figure 2 For example, virtual machine 10.8.1.2 on physical machine A communicates with virtual machine 10.10.2.3 on physical machine C. If the traffic controller in physical machine A records virtual machine 10.10.2.3 on physical machine C as a communication-rejecting virtual machine, virtual machine 10.8.1.2 can send communication requests to virtual machine 10.10.2.3 normally, but the communication request sent by virtual machine 10.10.2.3 will be discarded by the traffic controller on physical machine A, thus achieving unidirectional traffic control. At the same time, if the traffic controllers in the two physical machines simultaneously mark the other virtual machine as a communication-rejecting virtual machine, the communication request sent by each virtual machine will be discarded by the other virtual machine's traffic controller, thus achieving bidirectional traffic control.

[0046] Public network traffic control part: The traffic controller records the public network addresses or public network address segments that the virtual machines on the physical machine are allowed to communicate with; when the physical machine receives a communication request from a public network address or public network address segment that is allowed to communicate, the traffic controller transmits the communication request to the virtual machine; when the physical machine receives a communication request from a public network address or public network address segment other than the public network address or public network address segment that is allowed to communicate, the traffic controller discards the communication request.

[0047] In this embodiment, since the public network address cannot be completely excluded by the communication link blocking rules, the reverse operation can be performed to set the public network address or public network address segment that allows communication to maintain normal business processing of the virtual machine. Taking physical machine A as an example, the traffic controller of physical machine A can set the public network address or public network address segment that allows communication, such as 192.168.2.173, 47.74.64.0 / 17, etc. When physical machine A receives a communication request sent from a public network address or public network address segment that allows communication, it will allow it to pass; for communication requests sent from other addresses in the public network, the traffic controller of physical machine A will intercept and discard them.

[0048] In this embodiment, the virtual private network increases the physical machine in the virtual private network by the following steps:

[0049] Connect the newly added physical machine to the router;

[0050] Write the network address of the physical network card of the newly added physical machine into the network address pool;

[0051] Send the routing access table to the physical network card of the newly added physical machine.

[0052] This embodiment introduces a network control method, which is applied to a physical machine on a virtual private network system of a cloud computing platform, and includes the following steps:

[0053] S1-1. Get the communication request of the virtual machine to which the physical machine belongs;

[0054] S1-2. Query the network address of the target virtual machine through the routing access table;

[0055] S1-3. Specify the next hop address of the router for communication as the network address of the target virtual machine.

[0056] The network control method in this embodiment also includes a method for controlling the initiation of a communication request:

[0057] S2-1. Write communication link blocking rules;

[0058] S2-2. Block the communication request initiated by the controlled virtual machine on the physical machine through the communication link blocking rule, so that the communication request initiated by the controlled virtual machine cannot reach the physical network card of the physical machine;

[0059] S2-3 sends the communication link blocking rule to the traffic controllers on other physical machines in the virtual private network, so that the communication link blocking rule is loaded on the other traffic controllers.

[0060] The network control method in this embodiment also includes a method for controlling the reception of communication requests:

[0061] S3-1 record the network address or network address segment of other virtual machines in the virtual private network of the virtual machine on the physical machine that refuses to communicate; when receiving a communication request from the network address or network address segment corresponding to the virtual machine that refuses communication, the communication request is discarded;

[0062] S3-1. Record the public network addresses or public network address segments that the virtual machines on the physical machine are allowed to communicate with; when receiving a communication request from a public network address or public network address segment that is allowed to communicate, transmit the communication request to the virtual machine; when receiving a communication request from a public network address or public network address segment other than the public network address or public network address segment that is allowed to communicate, discard the communication request.

[0063] It should be noted that the devices in the virtual private network system, virtual private network, and network control method of the embodiments of the present invention can be merged, divided, and deleted according to actual needs, and the structures in the virtual private network system, virtual private network, and network control method of the embodiments of the present invention can be improved and optimized according to actual needs.

[0064] In some selectable embodiments, the function / operation mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the function / operation involved, the two boxes shown in succession can actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiment presented and described in the flow chart of the present invention is provided by way of example, for the purpose of providing a more comprehensive understanding of technology. The disclosed method is not limited to the operation and logic flow presented herein. Selectable embodiments are expected, wherein the order of various operations is changed and the sub-operation of a part for which is described as a larger operation is performed independently.

[0065] In addition, although the present invention is described in the context of functional modules, it should be understood that, unless otherwise specified, one or more of the functions and / or features described may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the present invention. More specifically, in view of the properties, functions, and internal relationships of the various functional modules in the device disclosed herein, the actual implementation of the module will be understood within the conventional skills of the engineer. Therefore, those skilled in the art can implement the present invention set forth in the claims without excessive experimentation using ordinary techniques. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.

[0066] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0067] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.

[0068] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the described embodiments. Those skilled in the art may make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of this application.

Claims

1. A cloud computing platform virtual private network system, characterized in that: It includes at least two physical machines and a router; each of the physical machines realizes the connection of a virtual private network through the router; each of the physical machines includes a physical network card, a flow controller and at least one virtual machine; The physical network card records the network addresses of each virtual machine in the physical machine to which it belongs, and the virtual machine accesses the virtual private network through the physical network card on the physical machine; the physical network card also includes a routing access table, and the routing access table records the network addresses of other virtual machines in the virtual private network; the physical network card is used to query the network addresses of the target virtual machines on other physical machines through the routing access table when the virtual machine on the physical machine to which it belongs initiates communication to the target virtual machines on other physical machines in the virtual private network; directly specify the next hop address of the router for communication with the virtual machine on the physical machine to be the network address of the target virtual machine on the other physical machine; The flow controller is used to control the communication initiation and communication reception of each virtual machine on the physical machine; The flow controller controls the communication initiation process of each virtual machine on the physical machine, including: the flow controller writes a communication link blocking rule, and blocks the communication request initiated by the controlled virtual machine on the physical machine through the communication link blocking rule, so that the communication request initiated by the controlled virtual machine cannot reach the physical network card of the physical machine; the flow controller also sends the communication link blocking rule to the flow controllers on other physical machines in the virtual private network, so that the communication link blocking rule is loaded on other flow controllers; the communication link blocking rule includes blocking according to the network address and blocking according to the network address segment; The traffic controller controls the communication receiving process of each virtual machine on the physical machine, including: the traffic controller records the network addresses or network address segments of other virtual machines in the virtual private network that the virtual machine on the physical machine refuses to communicate with; when the physical machine receives a communication request from the network address or network address segment corresponding to the virtual machine that refuses communication, the traffic controller discards the communication request.

2. A cloud computing platform virtual private network system according to claim 1, characterized in that: The flow controller controls the communication receiving process of each virtual machine on the physical machine, which also includes: the flow controller records the public network address or public network address segment allowed to communicate by the virtual machine on the physical machine; when the physical machine receives a communication request sent from the public network address or public network address segment allowed to communicate, the flow controller transmits the communication request to the virtual machine; when the physical machine receives a communication request sent from a public network address or public network address segment other than the public network address or public network address segment allowed to communicate, the flow controller discards the communication request.

3. A cloud computing platform virtual private network system according to claim 1, characterized in that: The router includes a network address pool, which is used to record the network addresses of each virtual machine in the virtual private network; the routing access table is regularly updated through the network address pool.

4. A cloud computing platform virtual private network system according to claim 3, characterized in that: The virtual private network adds a physical machine in the virtual private network by the following steps: Connecting the newly added physical machine to the router; Write the network address of the physical network card of the newly added physical machine into the network address pool; Send the routing access table to the physical network card of the newly added physical machine.

5. A network control method, applied to a physical machine on a virtual private network system of a cloud computing platform as claimed in any one of claims 1 to 4, characterized in that: The following steps are involved: Get the communication request of the virtual machine to which the physical machine belongs; Query the network address of the target virtual machine on other physical machines through the routing access table; The next hop address of the router for communicating with the virtual machines belonging to the physical machine is specified as the network address of the target virtual machine on other physical machines.

6. A network control method according to claim 5, characterized in that: The following steps are also included: Write communication link blocking rules; The communication request initiated by the controlled virtual machine on the physical machine is blocked by the communication link blocking rule, so that the communication request initiated by the controlled virtual machine cannot reach the physical network card of the physical machine; The communication link blocking rule is sent to the traffic controllers on other physical machines in the virtual private network, so that the communication link blocking rule is loaded on the other traffic controllers.

Citation Information

Patent Citations

  • Virtual machine data exchange method, apparatus and system

    CN103621026A

  • Method and system of data exchange between virtual machines

    CN103905309A