An open virtual network system, a communication method and device, and a storage medium
By designing the main control plane and execution body group in an open virtual network system, and using database adjudicators to compare and correct translation results, the problem of data translation errors in OVN is solved, and the security and reliability of the network are improved.
Patent Information
- Application Number
- CN202211548444.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-05
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-12-05
AI Technical Summary
Data translation errors in open virtual networks (OVN) lead to virtual network configuration and management errors, which in turn causes serious problems such as network business interruption.
An open virtual network system is designed, including a main control plane and an execution body group. The main control plane includes a main executor, a first and second open virtual switch database protocol agent, and a database adjudicator. The execution body group is composed of multiple heterogeneous execution bodies. The first open virtual switch database protocol agent receives service messages and sends them to the execution body group and the main execution body for translation. The database adjudicator compares the translation results of the execution body group and the main execution body. If abnormal, the translation results of the main execution body are corrected, and the revised results are sent through the second open virtual switch database protocol agent.
It effectively avoids data translation errors, improves the security of open virtual networks, ensures the correctness of virtual network configuration and management, and avoids network business interruption.
Smart Images

Figure CN115987923B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and more specifically, to an open virtual network system, a communication method, an electronic device, and a computer-readable storage medium. Background Art
[0002] With the popularization of network virtualization, more virtual switches need to be deployed. Open Virtual Switch (OVS, OpenvSwitch) is a high-quality, multi-layer virtual switching software that aims to support large-scale network automation through programming extensions, while also supporting standard management interfaces and protocols. The design goal of OVS is to facilitate the management and configuration of virtual machine networks, so OVS has strong flexibility and can run as a software switch in the hypervisor. OVS is mainly deployed on servers. It is a switch that exists in the virtual network in the form of software. Compared with traditional switches, it has good programming scalability. At the same time, it has the network isolation and data forwarding functions implemented by traditional switches. It runs on each physical machine that implements virtualization and provides remote management. It is similar to the role played by physical switches in traditional network deployments, and can perform multiple functions such as dividing LANs, building tunnels, and simulating routing.
[0003] Open Virtual Network (OVN) is an SDN (Software Defined Network) controller developed by the OVS project team for OVS. It is equivalent to the control plane of OVS and provides a native virtualized network solution for OVS, aiming to solve the performance problems of the traditional SDN architecture. In the OVN architecture, Openstack is the most commonly used cloud management system for unified orchestration of data center computing, storage, and network. At the network level, OVN is the master controller of the virtual network and connects to the neutron component of Openstack.
[0004] As a centralized controller, OVN monitors changes in the content of the northbound database and translates the relevant data of the logical network in the northbound database into a logical data flow table format that can be understood by the southbound database. The southbound database then synchronizes the data to multiple OVS distributed controllers, ultimately achieving the management of virtual network-related configurations. When there are security risks in the OVN software, the translation results may be wrong. After that, the southbound database will synchronize the wrong data flow table to multiple OVS distributed controllers, and finally send the wrong flow table to OVS, resulting in errors in the configuration and management of the entire virtual network, which in turn leads to serious problems such as network service interruption.
[0005] Therefore, how to avoid data translation errors and thus improve the security of open virtual networks is a technical problem that technicians in this field need to solve. Summary of the invention
[0006] The purpose of this application is to provide an open virtual network system, a communication method, an electronic device and a computer-readable storage medium, which avoid data translation errors and thus improve the security of the open virtual network.
[0007] To achieve the above-mentioned object, the present application provides an open virtual network system, comprising a main control plane and an executive group, wherein the main control plane comprises a main executive, a first open virtual switch database protocol agent, a second open virtual switch database protocol agent, and a database arbitrator, and the executive group comprises a plurality of heterogeneous executives;
[0008] The first open virtual switch database protocol agent is used to receive a service message sent by a first transmission party, and send the service message to the execution body group and the main execution body;
[0009] The main executive body and the executive bodies in the executive body group are used to translate received service messages;
[0010] The database arbiter is used to determine whether the translation result of the main executable body is abnormal by comparing the translation results of the multiple executable bodies in the executable body group with the translation result of the main executable body; if abnormal, correct the translation result of the main executable body based on the translation results of the multiple executable bodies in the executable body group;
[0011] The second open virtual switch database protocol agent is used to send the translation result of the main executable body to a second transmission party.
[0012] Wherein, the database arbiter comprises:
[0013] A determination module, configured to determine a standard translation result based on the translation results of a plurality of executables in the executable group;
[0014] A comparison module, used to compare the translation result of the main executable body with the standard translation result to see if they are consistent; if not, the workflow of the correction module is started;
[0015] The correction module is used to correct the translation result of the main executable body based on the standard translation result of the determination module.
[0016] Wherein, the determination module is specifically used for:
[0017] The translation result with the largest number among the translation results of the plurality of executable bodies in the executable body group is determined as the standard translation result,
[0018] Or, the weights of the executables in the executable group are determined, and the translation results are weighted based on the weights of the executables to obtain a weighted value for each translation result, and the translation result with the largest weighted value is determined as the standard translation result.
[0019] Wherein, the open virtual network system further includes a feedback control scheduler;
[0020] The feedback control scheduler is used to obtain the state of the executable body in the executable body, and send a management message to the executable body based on the state of the executable body.
[0021] The database arbiter is further used to: determine the state of the target executable body in the executable body group whose translation result is inconsistent with the standard translation result as abnormal.
[0022] The feedback control scheduler is specifically used to obtain the abnormal state of the target execution body from the database arbitrator, and send a management message for controlling the target execution body to go offline to the target execution body.
[0023] The database arbiter is further used to reduce the weight of the target executive.
[0024] Wherein, the feedback control scheduler is further used to: send the state of the executable in the executable to the first open virtual switch database protocol agent;
[0025] The first open virtual switch database protocol agent is specifically used to send the service message to the executable body in the executable body group in a normal state and the main executable body.
[0026] Among them, the main control plane includes a first external interface and a second external interface. The main control plane receives the service message sent by the first transmission party based on a remote procedure call through the first external interface, and the main control plane sends the translation result of the main executable body to the second transmission party based on a remote procedure call through the second external interface.
[0027] Wherein, the open virtual network system also includes a virtual switch;
[0028] The main control plane includes a business message interface and a management message interface isolated by different virtual local area networks, and the executors in the executor group include business message interfaces and management message interfaces isolated by different virtual local area networks. The main control plane sends the business message to the business message interface of the executor in the executor group through its own business message interface and the virtual switch, and the main control plane sends management messages to the management message interface of the executor in the executor group through its own management message interface and the virtual switch.
[0029] The executable body group includes a plurality of different software versions of developed virtual network software.
[0030] To achieve the above objectives, the present application provides a communication method, including:
[0031] Receiving a service message sent by a first transmission party through a first open virtual switch database protocol agent, and sending the service message to an execution body group and a main execution body for translation; wherein the execution body group includes a plurality of heterogeneous execution bodies;
[0032] Comparing the translation results of the plurality of executable bodies in the executable body group with the translation result of the main executable body through a database arbiter to determine whether the translation result of the main executable body is abnormal; if abnormal, correcting the translation result of the main executable body based on the translation results of the plurality of executable bodies in the executable body group;
[0033] The translation result of the main executable body is sent to the second transmission party through the second open virtual switch database protocol agent.
[0034] To achieve the above objectives, the present application provides an electronic device, including:
[0035] Memory for storing computer programs;
[0036] The processor is used to implement the steps performed by the components in the above-mentioned open virtual network system when executing the computer program.
[0037] To achieve the above objectives, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps performed by each component in the above open virtual network system are implemented.
[0038] Through the above scheme, it can be known that an open virtual network system provided by the present application includes a main control plane and an execution body group, the main control plane includes a main execution body, a first open virtual switch database protocol agent, a second open virtual switch database protocol agent, and a database arbitrator, and the execution body group includes multiple heterogeneous execution bodies; the first open virtual switch database protocol agent is used to receive a business message sent by a first transmission party, and send the business message to the execution body group and the main execution body; the main execution body and the execution bodies in the execution body group are used to translate the received business message; the database arbitrator is used to determine whether the translation result of the main execution body is abnormal by comparing the translation results of multiple execution bodies in the execution body group with the translation result of the main execution body; if abnormal, the translation result of the main execution body is corrected based on the translation results of multiple execution bodies in the execution body group; the second open virtual switch database protocol agent is used to send the translation result of the main execution body to the second transmission party.
[0039] The open virtual network system provided by the present application constructs multiple heterogeneous execution bodies for translating business messages that a first transmission party needs to send to a second transmission party, and determines whether the translation result of the main execution body is abnormal by comparing the translation results of the multiple execution bodies with the translation result of the main execution body. If abnormal, the translation result of the main execution body is corrected based on the translation results of the multiple execution bodies to ensure the correctness of the translation result transmitted to the second transmission party, thereby improving the security of the open virtual network.
[0040] The present application also discloses a communication device, an electronic device and a computer-readable storage medium, which can also achieve the above-mentioned technical effects.
[0041] It should be understood that the foregoing general description and the following detailed description are exemplary only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. The drawings are used to provide a further understanding of the present disclosure and constitute a part of the specification. Together with the following specific implementation methods, they are used to explain the present disclosure, but do not constitute a limitation to the present disclosure. In the drawings:
[0043] Figure 1 is an architecture diagram of a first open virtual network system according to an exemplary embodiment;
[0044] Figure 2 is an architecture diagram of a second open virtual network system according to an exemplary embodiment;
[0045] Figure 3 is an architecture diagram of a third open virtual network system according to an exemplary embodiment;
[0046] Figure 4 is a flow chart of a communication method according to an exemplary embodiment;
[0047] Figure 5 is an architecture diagram of a fourth open virtual network system according to an exemplary embodiment;
[0048] Figure 6 A schematic diagram of the interaction relationship between an OVSDB protocol agent and other components according to an exemplary embodiment;
[0049] Figure 7 The figure is a schematic diagram showing the interaction relationship between an OVN executor and other components according to an exemplary embodiment;
[0050] Figure 8 The following is a workflow diagram of an OVN executor and a main executor according to an exemplary embodiment;
[0051] Fig. 9 The figure is a schematic diagram showing the interaction relationship between a main execution body and other components according to an exemplary embodiment;
[0052] Fig.10 A schematic diagram of the interaction relationship between a database arbitrator and other components according to an exemplary embodiment;
[0053] Fig.11 The figure is a structural diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0054] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present application. In addition, in the embodiments of the present application, "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0055] The cyberspace mimicry defense theory focuses on security issues from the system architecture level, and responds to security threats caused by unknown vulnerabilities and backdoors based on the mimicry defense theory of generalized robust control. The core idea is a dynamic heterogeneous redundant structure based on the inherent security mechanism of cyberspace, which provides a universal defense theory and method for responding to unknown threats based on unknown vulnerabilities, backdoors, or viruses and Trojans in cyberspace.
[0056] This embodiment provides an open virtual network system. Figure 1 , Figure 1 FIG. 1 is an architecture diagram of a first open virtual network system according to an exemplary embodiment. Figure 1 As shown, it includes a main control plane 10 and an executive group 20, the main control plane 10 includes a main executive 101, a first open virtual switch database protocol agent 102, a second open virtual switch database protocol agent 103, and a database arbiter 104, and the executive group 20 includes multiple heterogeneous executives 201;
[0057] The first open virtual switch database protocol agent 102 is used to receive the service message sent by the first transmission party, and send the service message to the execution body group 20 and the main execution body 101;
[0058] The main executive body 101 and the executive body 201 in the executive body 20 are used to translate the received service message;
[0059] The database arbiter 104 is used to determine whether the translation result of the main executable body 101 is abnormal by comparing the translation results of the multiple executable bodies 201 in the executable body group 20 with the translation result of the main executable body 101; if abnormal, correct the translation result of the main executable body 101 based on the translation results of the multiple executable bodies 201 in the executable body group 20;
[0060] The second open virtual switch database protocol agent 103 is used to send the translation result of the main execution body 101 to the second transmission party.
[0061] The open virtual network system in this embodiment is a pseudo-OVN. In this embodiment, the first transmission party is any one of the cloud management system and the OVN controller (OVN controller), and the second transmission party is the other of the cloud management system and the OVN controller. This embodiment does not limit the number of OVN controllers, that is, the cloud management system can connect to multiple OVN controllers. The service message transmitted from the cloud management system to the OVN controller is the information of the northbound database, which may include network configuration information, etc. The service message transmitted from the OVN controller to the cloud management system is the information of the southbound database, which may include port information and status information, etc.
[0062] The first open virtual switch database (OVSDB) protocol agent 102 is used to receive the service message sent by the first transmission party, and send it to the execution body group 20 and the main execution body 101 for translation. If the first transmission party is the cloud management system, the first open virtual switch database protocol agent 102 is a northbound OVSDB protocol agent, and if the first transmission party is the OVN controller, the first open virtual switch database protocol agent 102 is a southbound OVSDB protocol agent.
[0063] The execution body group 20 includes multiple heterogeneous execution bodies 201, such as multiple different software versions of the development virtual network software. According to the theory of mimicry defense, different versions of OVN software need to be used as the execution body. Since there are certain differences in the code processing logic between different software versions, the probability of the same vulnerability between different software versions is greatly reduced, which ensures the heterogeneity of the OVN software itself. The software depends on the operating system to run. When deploying the OVN execution body, it can be deployed on different operating system versions to achieve the heterogeneity of the operating environment, and finally ensure the heterogeneity and redundancy of multiple OVN execution bodies. The multiple execution bodies 201 and the main execution body 101 in the execution body group 20 are used to translate the business message. If the first transmission party is the cloud management system and the second transmission party is the OVN controller, the business message is translated into a logical data flow table format that can be understood by the southbound database. If the first transmission party is the OVN controller and the second transmission party is the cloud management system, the business message is translated into a logical data flow table format that can be understood by the northbound database.
[0064] The second open virtual switch database protocol agent 103 is used to receive the translation result of the main execution body 201 and send it to the second transmission party. If the second transmission party is a cloud management system, the second open virtual switch database protocol agent 103 is a northbound OVSDB protocol agent. If the second transmission party is an OVN controller, the second open virtual switch database protocol agent 103 is a southbound OVSDB protocol agent.
[0065] The database arbiter 104 is used to adjudicate the translation results of the multiple executable bodies 201 in the executable body group 20 and the translation result of the main executable body 101, that is, to judge whether the translation result of the main executable body 101 is abnormal by comparing the translation results of the multiple executable bodies 201 in the executable body group 20 with the translation result of the main executable body 101. If abnormal, the translation result of the main executable body 101 is corrected based on the translation results of the multiple executable bodies 201 in the executable body group 20.
[0066] As a feasible implementation, the database arbiter 104 includes: a determination module, used to determine a standard translation result based on the translation results of multiple executable bodies in the executable body group; a comparison module, used to compare whether the translation result of the main executable body is consistent with the standard translation result; if not, starting the workflow of the correction module; the correction module is used to correct the translation result of the main executable body based on the standard translation result of the determination module.
[0067] In a specific implementation, a standard translation result is determined from the translation results of multiple executable bodies by voting. As a feasible implementation, the determination module is specifically used to: determine the translation result with the largest number among the translation results of multiple executable bodies 201 in the executable body group 20 as the standard translation result. As another feasible implementation, the determination module is specifically used to: determine the weight of the executable body 201 in the executable body group 20, perform weighted calculation on the translation results based on the weight of the executable body 201, obtain the weighted value of each translation result, and determine the translation result with the largest weighted value as the standard translation result. Further, determine whether the translation result of the main executable body is consistent with the standard translation result. If so, determine that the translation result of the main executable body 101 is normal; if not, determine that the translation result of the main executable body 101 is abnormal.
[0068] When the translation result of the main executable body 101 is abnormal, it is corrected based on the translation results of multiple executable bodies 201 in the executable body group 20. As a feasible implementation, the correction module is specifically used to correct the translation result of the main executable body 101 to the standard translation result. The second open virtual switch database protocol agent 103 resends the corrected translation result of the main executable body 101 to the second transmission party.
[0069] The open virtual network system provided in the embodiment of the present application constructs multiple heterogeneous execution bodies for translating business messages that a first transmission party needs to send to a second transmission party, and determines whether the translation result of the main execution body is abnormal by comparing the translation results of the multiple execution bodies with the translation result of the main execution body. If abnormal, the translation result of the main execution body is corrected based on the translation results of the multiple execution bodies to ensure the correctness of the translation result transmitted to the second transmission party, thereby improving the security of the open virtual network.
[0070] Based on the above embodiments, as a preferred implementation, the open virtual network system also includes a feedback control scheduler; the feedback control scheduler is used to obtain the status of the executable body in the executable body and send a management message to the executable body based on the status of the executable body.
[0071] See also Figure 2 , Figure 2FIG. 1 is an architecture diagram of a second open virtual network system according to an exemplary embodiment. Figure 2 As shown, it includes a main control plane 10 and an execution body group 20. The main control plane 10 includes a main execution body 101, a first open virtual switch database protocol agent 102, a second open virtual switch database protocol agent 103, a database arbiter 104, and a feedback control scheduler 105. The execution body group 20 includes multiple heterogeneous execution bodies 201.
[0072] In a specific implementation, the core of the feedback control scheduler 105 is composed of a set of pre-set scheduling strategies and intelligent learning algorithms. The feedback control scheduler 105 obtains the state of the executive body 201 in the executive body 20, and promptly notifies other modules of the system, such as the first open virtual switch database protocol agent 102, of changes in the executive body state. That is, the feedback control scheduler 105 is also used to: send the state of the executive body 201 in the executive body 20 to the first open virtual switch database protocol agent 102.
[0073] Furthermore, the database arbiter 104 is further used to: determine the state of the target executable body in the executable body group whose translation result is inconsistent with the standard translation result as abnormal. When the feedback control scheduler 105 receives the information that the database arbiter 104 finds abnormality, the feedback control scheduler 105 is activated.
[0074] As a feasible implementation, the feedback control scheduler 105 is specifically used to obtain the abnormal state of the target executable body from the database arbiter 104, and send a management message to the target executable body for controlling the target executable body to go offline. The target executable body does not participate in the translation work when receiving the service message next time, that is, the first open virtual switch database protocol agent 102 is specifically used to send the service message to the executable body in the normal state in the executable body group 20 and the main executable body 101. After the target executable body is cleaned, it can be put online again.
[0075] As another feasible implementation, the database arbiter 104 is also used to reduce the weight of the target executable body. That is, the translation result of the abnormal executable body has less impact on the standard translation result when the service message is received next time. By adjudicating the data flow tables after translation of multiple OVN executable bodies and correcting and cleaning the abnormal OVN executable body, the security risks of OVN are eliminated.
[0076] It can be seen that the feedback control scheduler 105 realizes unified management and processing scheduling of system abnormal information according to the arbitration result, monitors the state of the OVN executor, promptly notifies other modules of the system of changes in the state of the executor, and replaces, migrates, cleans, reorganizes, and reconstructs the unsafe OVN executor. This process is iteratively executed until the database arbitrator finds that the abnormal situation disappears or the frequency of occurrence is lower than a certain set threshold, which reflects the dynamic nature of the OVN executor and ultimately realizes the security closed loop of mimicry defense.
[0077] Based on the above embodiments, see Figure 3 , Figure 3 FIG. 1 is an architecture diagram of a third open virtual network system according to an exemplary embodiment. Figure 3 As shown, it includes a main control plane 10 and an execution body group 20, the main control plane includes a first external interface G1 and a second external interface G2, the main control plane 10 receives the service message sent by the first transmission party based on a remote procedure call through the first external interface G1, and the main control plane 10 sends the translation result of the main execution body 101 to the second transmission party based on a remote procedure call through the second external interface G2.
[0078] In the specific implementation, the main control plane and each execution body are independently deployed in the host, virtual machine or container. The main control plane opens external interfaces G1 and G2 for interacting with external components. The G1 interface is connected to the first transmission party, and the G2 interface is connected to the second transmission party.
[0079] The external interface of the mimetic OVN is compatible with the original OVN interface, including the interface for docking with the cloud management system and the interface for docking with the distributed OVN controller, all of which use the OVSDB management protocol. The OVSDB management protocol is responsible for managing the open virtual switch database of OVS. It is an SDN management protocol for implementing programmable access and configuration management of virtual switches. The OVSDB management protocol defines a set of RPC interfaces. Users can manage OVSDB through remote procedure calls (RPC), mainly including the communication protocol JSON-RPC method and the supported OVSDB operations. JSON-RPC is a stateless, lightweight RPC protocol. The function of the OVSDB management protocol agent is essentially to implement the JSON-RPC agent. JSON-RPC implements data transmission based on http.
[0080] OVN's external input data is implemented through the OVSDB management protocol. Therefore, the OVSDB management protocol agent is introduced, namely the northbound OVSDB protocol agent and the southbound OVSDB protocol agent, to copy and distribute the input data of the OVSDB management protocol to multiple OVN executors. The OVSDB protocol agent implements an RPC-based agent. The OVSDB management protocol content carried in the RPC message includes UUID random number information. The main OVN and each executor send messages with different UUIDs. When the OVSDB protocol agent receives the RPC request or response from the external component and copies and distributes the message to the main OVN and multiple OVN executors, it implements the UUID replacement function, replacing the UUID field in the RPC message with the UUID corresponding to the main OVN and each executor.
[0081] Furthermore, the open virtual network system also includes a virtual switch 30; the main control plane 10 includes a business message interface A and a management message interface B isolated by different virtual local area networks, and the execution body 201 in the execution body group 20 includes a business message interface A and a management message interface B isolated by different virtual local area networks. The main control plane 10 sends the business message to the business message interface A of the execution body 201 in the execution body group 20 through its own business message interface A and the virtual switch 30, and the main control plane 10 sends the management message to the management message interface B of the execution body 201 in the execution body group 20 through its own management message interface B and the virtual switch 30.
[0082] In the specific implementation, the main control plane and the executor are connected to the virtual switch, and the communication between the internal components of the virtual OVN and each executor is realized through the virtual switch. The main control plane and each executor respectively open and use two interfaces A and B. Interface A is used for the interaction and synchronization of OVN business messages, including RPC messages from the northbound cloud management system and RPC messages from the southbound OVNcontroller; Interface B is used for the interaction and synchronization of OVN management and monitoring messages, including management messages from the main control plane to each executor and status information reported by each executor to the main control plane. The networks of interfaces A and B are not interoperable, and interfaces A and B are isolated using different VLANs.
[0083] Taking the process of OVN controller sending business messages to the cloud management system as an example, the process of the open virtual network system receiving business messages is as follows: the G1 interface of the main control plane receives the business message, the main executor reads the message of the G1 interface, considers that the RPC message is received from the OVN controller and processes it; the southbound OVSDB protocol agent simultaneously monitors the incoming message information of the G1 interface, parses the RPC message received from the OVN controller, and copies and distributes the message to each executor in the executor group for processing.
[0084] The main OVN and each executor in the executor group will send RPC messages to the outside, and finally use the main OVN's message to send to the external component. Taking the open virtual network system sending RPC messages to the OVN controller as an example, the sending process is: the main OVN assembles the message and sends it to the OVN controller through the G1 interface; each OVN executor will also send messages to the outside at the same time, and the message is sent through interface A. Interface A of the main control plane receives the message sent by each executor, and the southbound OVSDB protocol agent of the main control plane monitors the incoming message information of interface A. Since the southbound OVSDB protocol agent saves the status information such as the sequence number of the TCP session between the virtual OVN and the OVNcontroller, the southbound OVSDB protocol agent uses interface A to directly reply to the TCP ACK message to each executor; after each executor receives the ACK message, the status is consistent with the main OVN.
[0085] It can be seen that this embodiment adopts the mimetic defense theory, based on the dynamic heterogeneous redundant architecture, takes multiple heterogeneous OVNs as executors, introduces corresponding input agents, a database arbiter with an iterative mechanism, and a feedback control scheduler, to transform the dynamic heterogeneous redundant architecture of OVN, and arbitrates the translated data flow tables of multiple OVN executors to determine whether there are security risks in the flow tables, and correct and clean them to ensure the repair of security issues.
[0086] The embodiment of the present application discloses a communication method, which avoids data translation errors and thereby improves the security of an open virtual network.
[0087] See also Figure 4 , a flow chart of a communication method according to an exemplary embodiment is shown as follows: Figure 4 As shown, including:
[0088] S101: receiving a service message sent by a first transmission party through a first open virtual switch database protocol agent, and sending the service message to an execution body group and a main execution body for translation; wherein the execution body group includes a plurality of heterogeneous execution bodies;
[0089] S102: comparing the translation results of the plurality of executable bodies in the executable body group with the translation result of the main executable body through a database arbiter to determine whether the translation result of the main executable body is abnormal; if abnormal, correcting the translation result of the main executable body based on the translation results of the plurality of executable bodies in the executable body group;
[0090] S103: Sending the translation result of the main executable body to the second transmission party through the second open virtual switch database protocol agent.
[0091] The execution subject of the embodiment of the present application is the main control plane in the above-mentioned open virtual network system. In the specific implementation, the first open virtual switch database protocol agent receives the service message sent by the first transmission party, and sends it to multiple execution bodies in the execution body group and the main execution body for translation. The database arbitrator compares the translation results of the multiple execution bodies in the execution body group with the translation result of the main execution body to determine whether the translation result of the main execution body is abnormal. If normal, the second open virtual switch database protocol agent directly sends the translation result of the main execution body to the second transmission party; if abnormal, the database arbitrator corrects the translation result of the main execution body based on the translation results of the multiple execution bodies in the execution body group, and the second open virtual switch database protocol agent sends the corrected translation result of the main execution body to the second transmission party.
[0092] It should be noted that, for performance considerations, after the multiple executable bodies in the executable body group and the main executable body translate the service message, before the database arbitrator compares the translation results of the multiple executable bodies in the executable body group with the translation result of the main executable body to determine whether the translation result of the main executable body is abnormal, the second open virtual switch database protocol agent can directly send the translation result of the main executable body to the second transmission party, and wait for the database arbitrator to determine that the translation result of the main executable body is abnormal, and then the second open virtual switch database protocol agent resends the corrected translation result of the main executable body to the second transmission party. This implementation method can ensure that the second transmission party obtains the translation result in time and improves performance.
[0093] It can be seen that this embodiment constructs multiple heterogeneous execution bodies for translating business messages that the first transmission party needs to send to the second transmission party, and determines whether the translation result of the main execution body is abnormal by comparing the translation results of the multiple execution bodies with the translation result of the main execution body. If abnormal, the translation result of the main execution body is corrected based on the translation results of the multiple execution bodies to ensure the correctness of the translation result transmitted to the second transmission party, thereby improving the security of the open virtual network.
[0094] Based on the above embodiment, as a preferred implementation mode, the database arbiter compares the translation results of the multiple executable bodies in the executable body group with the translation result of the main executable body to determine whether the translation result of the main executable body is abnormal; if abnormal, the translation result of the main executable body is corrected based on the translation results of the multiple executable bodies in the executable body group, including:
[0095] A standard translation result is determined based on the translation results of multiple executable bodies in the executable body group by a database arbitrator, and the translation result of the main executable body is compared with the standard translation result to see whether it is consistent; if not, the translation result of the main executable body is corrected based on the translation results of multiple executable bodies in the executable body group.
[0096] Based on the above embodiment, as a preferred implementation, the determining of the standard translation result based on the translation results of multiple executables in the executable group by the database arbitrator includes:
[0097] The database arbiter determines the translation result with the largest number among the translation results of multiple executable bodies in the executable body group as the standard translation result, or determines the weights of the executable bodies in the executable body group, performs weighted calculation on the translation results based on the weights of the executable bodies, obtains the weighted value of each translation result, and determines the translation result with the largest weighted value as the standard translation result.
[0098] Based on the above embodiment, as a preferred implementation, the step of correcting the translation result of the main executable body based on the translation results of multiple executable bodies in the executable body group includes:
[0099] The translation result of the main executable body is corrected to the standard translation result.
[0100] Based on the above embodiment, as a preferred implementation, it also includes:
[0101] The state of the executable body in the executable body is obtained through the feedback control scheduler, and a management message is sent to the executable body based on the state of the executable body.
[0102] Based on the above embodiment, as a preferred implementation, it also includes:
[0103] The feedback control scheduler determines the state of the target executable body in the executable body group whose translation result is inconsistent with the standard translation result as abnormal.
[0104] Based on the above embodiment, as a preferred implementation mode, the obtaining the state of the executable body in the executable body through the feedback control scheduler, and sending a management message to the executable body based on the state of the executable body, includes:
[0105] The feedback control scheduler obtains the abnormal state of the target execution body from the database arbitrator, and sends a management message for controlling the target execution body to go offline to the target execution body.
[0106] Based on the above embodiment, as a preferred implementation, it also includes:
[0107] The weight of the target executable is reduced by the database arbitrator.
[0108] Based on the above embodiment, as a preferred implementation, it also includes:
[0109] sending, by the feedback control scheduler, the state of the executable in the executable to the first open virtual switch database protocol agent;
[0110] Accordingly, the business message is sent to the execution body group and the main execution body for translation, including:
[0111] The service message is sent to the executable bodies in the executable body group that are in normal state and the main executable body.
[0112] The following is an application example provided by the present application. Figure 5 After OVN is transformed into a virtualized executor, the OVSDB protocol agent is divided into two components: northbound and southbound. The northbound OVSDB protocol agent connects to the cloud management system, which sends network configuration information. The southbound OVSDB protocol agent connects to the OVN controller, which reports information such as ports and status. This information is distributed to multiple OVN executors through the OVSDB protocol agent.
[0113] Taking the cloud management system sending network configuration information to OVN as an example, the interaction relationship between the northbound OVSDB protocol agent and other components is as follows: Figure 6As shown in the figure, the feedback control scheduler synchronizes the online status information of the executor to the northbound OVSDB protocol agent, and the northbound OVSDB protocol agent masters the information of all online executors. When the northbound OVSDB protocol agent receives a JSON (JavaScript Object Notation, JS Object Notation)-RPC (Remote Procedure Call) request or response from an external component, it copies and distributes the protocol message to the main OVN and multiple OVN executors. The main OVN and multiple OVN executors will process the protocol message and reply the protocol message to the southbound OVSDB protocol agent. When the southbound OVSDB protocol agent receives an RPC request or response from the main OVN and multiple OVN executors, it determines whether it belongs to the same RPC message based on the content of the message. When it belongs to the request or response of the same RPC message, the southbound OVSDB protocol agent only forwards the message replied by the main OVN, and the reply messages of the other OVN executors are discarded by the southbound OVSDB protocol agent, finally realizing the complete interaction of the OVSDB management protocol.
[0114] The OVSDB protocol agent implements an RPC-based agent. The OVSDB management protocol content carried in the RPC message includes UUID random number information. The messages sent by the main OVN and each executor carry different UUIDs. The OVSDB protocol agent receives RPC requests or responses from external components, copies and distributes the messages to the main OVN and multiple OVN executors, and implements the UUID replacement function, replacing the UUID field in the RPC message with the UUID corresponding to the main OVN and each executor.
[0115] OVN executors are divided into two categories according to their roles: OVN executors and master OVNs, and their functional requirements are different.
[0116] The interaction between each independent OVN executor and other components is as follows Figure 7 As shown in the figure, the workflow of each independent OVN executor is as follows Figure 8 As shown, the steps are as follows:
[0117] 1. Receive the protocol information copied and distributed by the northbound OVSDB protocol agent, parse the protocol to obtain the business flow table configuration data, and save it in the northbound database; receive the protocol information copied and distributed by the southbound OVSDB protocol agent, parse the protocol to obtain the initial information of the logical flow table, and save it in the southbound database;
[0118] 2. The OVN executor translates and converts the database respectively, converting the data into a logical data flow table format that can be understood by the southbound database, that is, the southbound database information;
[0119] 3. Synchronize the southbound database information of each executor to the database arbitrator for arbitration.
[0120] The main OVN workflow interacts with other components as follows: Fig. 9 As shown, the workflow is as follows Figure 8 As shown, the steps are as follows:
[0121] 1. Receive the protocol information copied and distributed by the northbound OVSDB protocol agent, parse the protocol to obtain the business flow table configuration data, and save it in the northbound database; receive the protocol information copied and distributed by the southbound OVSDB protocol agent, parse the protocol to obtain the initial information of the logical flow table, and save it in the southbound database;
[0122] 2. Translate and convert the database to a logical data flow table format that can be understood by the southbound database, that is, the southbound database information;
[0123] 3. Synchronize the southbound database information to the database arbitrator for arbitration;
[0124] 4. After receiving the modified table entry from the database arbitrator, trigger the synchronization of modified data to the OVN controller.
[0125] The northbound OVSDB protocol agent copies the OVSDB protocol message to multiple heterogeneous OVN executors, and after being processed by the main OVN and multiple OVN executors, it is sent to the database arbiter for arbitration. Since the southbound database of OVN exists in the form of OVSDB database files, it is sent to the southbound database arbiter by file copying, and the content of the arbitration is compared by comparing database files. After the arbitration, if it is found that the information sent from the main OVN to the OVNcontroller is abnormal, it will be corrected, and the abnormal database and flow table information will be sent to the feedback control scheduler for alarm, otherwise no correction or alarm will be made.
[0126] The database arbiter decision process is as follows Fig.10 As shown, the general steps are as follows:
[0127] 1. Receive southbound database information synchronized between each OVN executor and the master OVN;
[0128] 2. Put the acquired southbound database information of each OVN executor into the queue for decision;
[0129] 3. Send the pending information in the pending decision queue to the voter for voting, and use the majority decision or weighted decision algorithm to determine the standard translation result. Compare the translation result of the main OVN with the standard translation result to see if it is consistent, and then determine whether the information sent by the main OVN to the OVN controller is abnormal. At the same time, the translation results of each OVN executor can also be compared with the standard translation result to determine the abnormal OVN executor;
[0130] 4. After the decision, if the information sent by the master OVN to the OVN controller is found to be abnormal, a correction entry is sent to the master OVN, and an alarm of abnormal decision is notified to the feedback control scheduler.
[0131] Feedback control scheduler is mainly used for:
[0132] 1. Obtain the OVN executor status information through the push of system status monitoring. When the executor status is detected to have changed, the changed executor status information is first written into the database, and the status change is notified to each module.
[0133] 2. Process the feedback information received from the database arbiter and generate the corresponding scheduling strategy, which is sent to the database arbiter, northbound OVSDB protocol agent and southbound OVSDB protocol agent for pre-scheduling, so that they know which executors are available and establish network connections with the corresponding executors, that is, perform offline cleaning, online and other operations of the OVN executors according to the status of each OVN executor.
[0134] 3. Receive exception information reported by the database arbiter, northbound OVSDB protocol agent, and southbound OVSDB protocol agent, compile statistics, and write them into the database; based on the exception information and the local scheduling policy requirements, process and generate the corresponding scheduling policy.
[0135] It can be seen that this embodiment is based on the theory of mimetic defense and a dynamic heterogeneous redundant architecture to perform mimetic transformation on OVN. By adjudicating the data flow tables after translation of multiple OVN executors, and correcting and cleaning the unsafe OVN executors, the potential safety hazards of OVN are eliminated. The present invention solves the integrity and stability of OVN functions when a single or multiple executors fail. The security and reliability of OVN are improved, and the security issues of unknown vulnerabilities and backdoors that cannot be solved by traditional consistency protocols are solved. Finally, the mimetic defense requirements of OVN are realized, and the inherent security capabilities of OVN are improved.
[0136] Based on the hardware implementation of the above program modules, and in order to implement the steps executed by each component in the open virtual network system provided by the present application, the embodiment of the present application also provides an electronic device, Fig.11FIG. 1 is a structural diagram of an electronic device according to an exemplary embodiment. Fig.11 As shown, the electronic equipment includes:
[0137] Communication interface 1, capable of exchanging information with other devices such as network devices;
[0138] The processor 2 is connected to the communication interface 1 to realize information exchange with other devices, and is used to execute the steps performed by each component in the open virtual network system provided by one or more technical solutions when running a computer program. The computer program is stored in the memory 3.
[0139] Of course, in actual application, the various components in the electronic device are coupled together through the bus system 4. It can be understood that the bus system 4 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 4 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, Fig.11 Various buses are labeled as bus system 4 .
[0140] The memory 3 in the embodiment of the present application is used to store various types of data to support the operation of the electronic device. Examples of such data include: any computer program used to operate on the electronic device.
[0141] It can be understood that the memory 3 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAMbus random access memory (DRRAM, Direct Rambus Random Access Memory).The memory 3 described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memories.
[0142] The steps performed by each component in the open virtual network system disclosed in the above embodiment of the present application can be applied to the processor 2, or implemented by the processor 2. The processor 2 may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps performed by each component in the above open virtual network system can be completed by the hardware integrated logic circuit in the processor 2 or the instructions in the form of software. The above processor 2 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor 2 can implement or execute the steps and logic block diagrams disclosed in the embodiment of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps performed by each component in the open virtual network system disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to perform, or it can be performed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the memory 3. The processor 2 reads the program in the memory 3 and completes the steps performed by each component in the above open virtual network system in combination with its hardware.
[0143] When the processor 2 executes the program, the steps executed by each component in the open virtual network system provided in the embodiment of the present application are implemented, which will not be repeated here for the sake of brevity.
[0144] In an exemplary embodiment, the present application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, a memory 3 storing a computer program, and the computer program can be executed by a processor 2 to complete the steps performed by each component in the aforementioned open virtual network system. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.
[0145] A person of ordinary skill in the art can understand that the steps executed by each component in the above-mentioned open virtual network system can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the execution includes the steps executed by each component in the above-mentioned open virtual network system; and the aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, disks or optical disks.
[0146] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application can essentially or in other words, the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps performed by each component in the open virtual network system described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, disks or optical disks.
[0147] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. An open virtual network system, It is characterized in that It includes a main control plane and an executive body group, wherein the main control plane includes a main executive body, a first open virtual switch database protocol agent, a second open virtual switch database protocol agent, and a database arbitrator, and the executive body group includes a plurality of heterogeneous executive bodies; The first open virtual switch database protocol agent is used to receive a service message sent by a first transmission party, and send the service message to the execution body group and the main execution body; The main executive body and the executive bodies in the executive body group are used to translate received service messages; The database arbiter is used to determine whether the translation result of the main executable body is abnormal by comparing the translation results of multiple executable bodies in the executable body group with the translation result of the main executable body; If abnormal, correct the translation result of the main executable body based on the translation results of multiple executable bodies in the executable body group; The second open virtual switch database protocol agent is used to send the translation result of the main executable body to a second transmission party.
2. According to the open virtual network system of claim 1, It is characterized in that The database arbiter comprises: A determination module, configured to determine a standard translation result based on the translation results of a plurality of executables in the executable group; A comparison module, used to compare the translation result of the main executable body with the standard translation result to see if they are consistent; if not, the workflow of the correction module is started; The correction module is used to correct the translation result of the main executable body based on the standard translation result of the determination module.
3. According to the open virtual network system of claim 2, It is characterized in that The determination module is specifically used for: The translation result with the largest number among the translation results of the plurality of executable bodies in the executable body group is determined as the standard translation result, Or, the weights of the executables in the executable group are determined, and the translation results are weighted based on the weights of the executables to obtain a weighted value for each translation result, and the translation result with the largest weighted value is determined as the standard translation result.
4. The open virtual network system according to claim 2, It is characterized in that The open virtual network system also includes a feedback control scheduler; The feedback control scheduler is used to obtain the state of the executable body in the executable body, and send a management message to the executable body based on the state of the executable body.
5. According to the open virtual network system of claim 4, It is characterized in that The database arbiter is further used to determine the state of the target executable body in the executable body group whose translation result is inconsistent with the standard translation result as abnormal.
6. The open virtual network system according to claim 5, It is characterized in that The feedback control scheduler is specifically used to obtain the abnormal state of the target execution body from the database arbitrator, and send a management message for controlling the target execution body to go offline to the target execution body.
7. The open virtual network system according to claim 5, It is characterized in that The database arbiter is further used to reduce the weight of the target executive.
8. The open virtual network system according to claim 4, It is characterized in that The feedback control scheduler is further used to: send the state of the executable in the executable to the first open virtual switch database protocol agent; The first open virtual switch database protocol agent is specifically used to send the service message to the executable body in the executable body group in a normal state and the main executable body.
9. The open virtual network system according to claim 1, It is characterized in that The main control plane includes a first external interface and a second external interface. The main control plane receives the service message sent by the first transmission party based on a remote procedure call through the first external interface, and the main control plane sends the translation result of the main executable body to the second transmission party based on a remote procedure call through the second external interface.
10. The open virtual network system according to claim 4, It is characterized in that The open virtual network system also includes a virtual switch; The main control plane includes a service message interface and a management message interface isolated by different virtual local area networks, and the executors in the executor group include service message interfaces and management message interfaces isolated by different virtual local area networks. The main control plane sends the service message to the service message interface of the executor in the executor group through its own service message interface and the virtual switch, and the main control plane sends management messages to the management message interface of the executor in the executor group through its own management message interface and the virtual switch.
11. A communication method, It is characterized in that include: Receiving a service message sent by a first transmission party through a first open virtual switch database protocol agent, and sending the service message to an execution body group and a main execution body for translation; wherein the execution body group includes a plurality of heterogeneous execution bodies; Comparing the translation results of the plurality of executable bodies in the executable body group with the translation result of the main executable body through a database arbiter to determine whether the translation result of the main executable body is abnormal; if abnormal, correcting the translation result of the main executable body based on the translation results of the plurality of executable bodies in the executable body group; The translation result of the main executable body is sent to the second transmission party through the second open virtual switch database protocol agent.
12. An electronic device, It is characterized in that include: Memory for storing computer programs; A processor, configured to implement the steps performed by each component in the open virtual network system according to any one of claims 1 to 10 when executing the computer program.
13. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps performed by each component in the open virtual network system according to any one of claims 1 to 10 are implemented.
Citation Information
Patent Citations
Mimicry system based on foreground and background presentation mode
CN115086447A
System and method for realizing message processing based on SNAT resource pool
CN115378868A