A virtual communication device, method, apparatus and readable storage medium
By building a virtual network cable to realize the mapping relationship between the system's virtual network card and multiple container virtual network cards, the problem of complex network structure in the redundant container system is solved, and efficient and secure data transmission and attack identification is achieved.
Patent Information
- Application Number
- CN202211617999.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-15
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-12-15
AI Technical Summary
In redundant container systems, network communication between multiple container namespaces and system namespaces requires the construction of complex virtual network structures, resulting in inefficiency and insufficient security.
By building a virtual network cable, the mapping relationship between the system virtual network card and multiple container virtual network cards is realized, data transmission between a system virtual network card and multiple container virtual network cards is realized, including fixed-point transmission in degraded mode and deredundant processing in mimicry mode, and the voting mechanism is used to judge network attacks and improve security.
It realizes efficient data transmission between the redundant container system and the outside world, improves the efficiency and security of network communication, especially in mimicry mode, which can identify and handle network attacks.
Smart Images

Figure CN116112427B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technologies, and in particular, to a virtual communication device, method, equipment, and readable storage medium. Background Art
[0002] A veth-pair (virtual network cable) is a pair of virtual network device interfaces that appears in pairs and is used to connect two virtual network devices. A container provides an operating environment for a program that is isolated from the host system resources and includes network protocol stack resources. The container achieves isolation by using the NET namespace of the Linux system. Usually in a container network, a veth-pair is used to connect the NET namespace of the host and the NET namespace of the container so that the container can access the Internet.
[0003] As Figure 1 shown, a veth-pair includes a virtual network card veth0 and a virtual network card veth1 that are communicatively connected. Among them, one end of veth0 is connected to veth1, and the other end is connected to the system network protocol stack (system namespace). One end of veth1 is connected to veth0, and the other end is connected to the container network protocol stack (container namespace). It can be seen that a veth-pair has the characteristic of "one-to-one", that is, the veth-pair is used as a communication middleware to implement the communication between a system network protocol stack and a container network protocol stack in a container network.
[0004] However, in a redundant container system, the relationship between multiple container namespaces and the system namespace is "many-to-one". Therefore, usually, a complex virtual network structure including multiple pairs of veth-pairs needs to be constructed to achieve the network communication between the redundant container system and the outside world. Summary of the Invention
[0005] This application provides a virtual communication device, method, equipment, and readable storage medium as follows:
[0006] A virtual communication device includes: a virtual network cable, where the virtual network cable includes a system virtual network card and a set of container virtual network cards, and the set of container virtual network cards includes multiple container virtual network cards. Among them, the system virtual network card pre-constructs a mapping relationship with the set of container virtual network cards;
[0007] The first end of the system virtual network card is connected to the system network protocol stack, and the second end is respectively connected to the first ends of the multiple container virtual network cards;
[0008] The second end of each container virtual network card is connected to the corresponding container network protocol stack.
[0009] Optionally, the virtual communication device further includes: a virtual network card management module;
[0010] The virtual network card management module is used to perform preset relationship management on the mapping relationship between the system virtual network card and the container virtual network card set, and the relationship management includes a creation operation, a change operation, and a release operation.
[0011] Optionally, the virtual communication device further comprises: a mode control module and a distribution module;
[0012] The mode control module is used to control the working mode of the virtual communication device to be a degradation mode in response to a first preset command;
[0013] The distribution module is used to select a container virtual network card from the container virtual network card set as a target virtual network card in the degradation mode, and send the data received by the system virtual network card to the target virtual network card.
[0014] Optionally, the mode control module is further used to control the working mode of the virtual communication device to be a mimic mode in response to a second preset command;
[0015] The distribution module is also used to distribute the data received by the system virtual network card to each of the container virtual network cards in the mimic mode.
[0016] Optionally, the virtual communication device further comprises: a redundancy removal module;
[0017] The de-redundancy module is used to perform preset de-redundancy processing on the data received by each container virtual network card in the mimicking mode to obtain de-redundancy data, and send the de-redundancy data to the system virtual network card.
[0018] Optionally, the de-redundancy module is used to perform preset de-redundancy processing on the data received by each container virtual network card in the mimicking mode to obtain de-redundancy data, including: the de-redundancy module is specifically used to:
[0019] Dividing the redundant data packets to obtain at least one equivalent data packet tuple, wherein the equivalent data packet tuple includes at least one redundant data packet with equivalent functions;
[0020] Voting on each of the equivalent data packet tuples according to a preset voting algorithm to obtain a voting result of each of the equivalent data packet tuples, wherein the voting result includes normal or abnormal;
[0021] Deleting abnormal data packet tuples, wherein the abnormal data packet tuples include equivalent data packet tuples whose voting results are abnormal;
[0022] Merge the redundant data packets in each normal data packet tuple to obtain a merged data packet, where the normal data packet tuple includes an equivalent data packet tuple with a normal voting result;
[0023] Obtain the redundancy-removed data, where the redundancy-removed data includes the merged data packet corresponding to each normal data packet tuple.
[0024] A virtual communication method is applied to a virtual communication device. The virtual communication device includes a virtual network cable, and the virtual network cable includes a system virtual network card and a set of container virtual network cards. The set of container virtual network cards includes multiple container virtual network cards. Among them, the system virtual network card pre-constructs a mapping relationship with the set of container virtual network cards; the first end of the system virtual network card is connected to the system network protocol stack, and the second end is respectively connected to the first ends of multiple container virtual network cards; the second end of each container virtual network card is connected to the corresponding container network protocol stack;
[0025] The virtual communication method includes:
[0026] In a preset degradation mode, select a container virtual network card from the set of container virtual network cards as the target virtual network card, and send the data received by the system virtual network card to the target virtual network card;
[0027] In a preset mimicry mode, distribute the data received by the system virtual network card to each container virtual network card, and / or perform preset redundancy removal processing on the data received by each container virtual network card to obtain redundancy-removed data, and send the redundancy-removed data to the system virtual network card.
[0028] Optionally, in the mimicry mode, performing preset redundancy removal processing on the data received by each container virtual network card to obtain redundancy-removed data includes:
[0029] In the mimicry mode, divide the redundant data packets to obtain at least one equivalent data packet tuple, where the equivalent data packet tuple includes at least one redundant data packet with equivalent functions;
[0030] According to a preset voting algorithm, vote on each equivalent data packet tuple to obtain the voting result of each equivalent data packet tuple, where the voting result includes normal or abnormal;
[0031] Delete the abnormal data packet tuple, where the abnormal data packet tuple includes an equivalent data packet tuple with an abnormal voting result;
[0032] Merge the redundant data packets in each normal data packet tuple to obtain a merged data packet, where the normal data packet tuple includes an equivalent data packet tuple with a normal voting result;
[0033] Obtain the redundancy-removed data, where the redundancy-removed data includes merged data packets corresponding to each normal data packet tuple.
[0034] A virtual communication device includes: a memory and a processor;
[0035] The memory is used to store a program;
[0036] The processor is used to execute the program to implement each step of the virtual communication method.
[0037] A readable storage medium stores a computer program, and when the computer program is executed by a processor, each step of the virtual communication method is implemented.
[0038] It can be seen from the above technical solutions that a virtual communication device, method, device, and readable storage medium provided by an embodiment of the present application. The virtual communication device includes a virtual network cable, and the virtual network cable includes a system virtual network card and a container virtual network card set. The container virtual network card set includes multiple container virtual network cards. Among them, the system virtual network card pre-constructs a mapping relationship with the container virtual network card set. The first end of the system virtual network card is connected to the system network protocol stack, and the second end is respectively connected to the first ends of multiple container virtual network cards. The second end of each container virtual network card is connected to the corresponding container network protocol stack. It can be seen that one end of the system virtual network card is respectively connected to one end of multiple container virtual network cards, and the other end is connected to the system network protocol stack. Moreover, the other end of each container virtual network card is connected to a container virtual network card, realizing data transmission between one system virtual network card and multiple container virtual network cards, thereby realizing communication between a redundancy system including multiple container namespaces and the outside (system namespace). Description of the Drawings
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0040] Figure 1 Illustrates a schematic structural diagram of a virtual network card veth-pair;
[0041] Figure 2 Is a schematic structural diagram of a virtual network card provided by an embodiment of the present application;
[0042] Figure 3 Is a schematic structural diagram of a virtual communication device provided by an embodiment of the present application;
[0043] Figure 4a Structural schematic diagram of a middleware provided by an embodiment of the present application;
[0044] Figure 4b Schematic diagram of data interaction of a middleware provided by an embodiment of the present application;
[0045] Figure 5 Flow schematic diagram of a virtual communication method provided by an embodiment of the present application;
[0046] Figure 6 Structural schematic diagram of a virtual communication device provided by an embodiment of the present application. Detailed implementation manners
[0047] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0048] A virtual communication device provided by an embodiment of the present application is applicable to the scenario of communication between a redundant container system and an external network. Specifically, it is applied to the "many-to-one" data transmission between multiple container namespaces and the system namespace in the redundant container system. Compared with the traditional complex virtual network structure, this device realizes the "many-to-one" binding of virtual network cards by constructing the "many-to-one" mapping relationship of virtual network cards, so as to complete the data transmission between multiple container namespaces and the system namespace through the virtual communication device.
[0049] Specifically, a virtual communication device provided by an embodiment of the present application includes a virtual network cable. Figure 2 Illustrates a structural schematic diagram of a virtual network cable, as Figure 2 shown, the virtual network cable includes: a system virtual network card (such as Figure 2 the system virtual network card veth shown) and a set of container virtual network cards. Among them, the set of container virtual network cards includes multiple container virtual network cards (such as Figure 2 the multiple veths within the dashed box shown).
[0050] In this embodiment, the system virtual network card pre-constructs a mapping relationship with the set of container virtual network cards. The first end of the system virtual network card is connected to the system network protocol stack, and the second end is respectively connected to the first ends of multiple container virtual network cards. And, the second end of each container virtual network card is connected to the corresponding container network protocol stack.
[0051] From Figure 2As can be seen from the device shown, for the virtual network cable in a virtual communication device provided in an embodiment of the present application, by constructing a mapping relationship between a system virtual network card and multiple container virtual network cards, one end of the system virtual network card is respectively connected to one end of multiple container virtual network cards. Also, since the other end of the system virtual network card is connected to the system network protocol stack, and the other end of each container virtual network card is connected to a container virtual network card, therefore, data transmission between one system virtual network card and multiple container virtual network cards is realized, thereby realizing communication between a redundant system including multiple container namespaces and the outside world (system namespace).
[0052] It should be noted that Figure 2 the virtual communication device provided in an embodiment of the present application can be applied to multiple application scenarios of communication between a redundant system and the outside world. For example, it can be applied to scenarios of data transmission redundancy and redundancy removal.
[0053] In this embodiment, the functions of containers in the redundant container system are equivalent to each other. For network transmission, it is necessary to realize data redundancy and redundancy removal.
[0054] Specifically, multiple container virtual network cards in the container virtual network cards in the virtual network cable go online simultaneously and process the same data, which is redundancy. When the system virtual network card sends data to multiple container virtual network cards simultaneously, it is redundancy. Therefore, multiple container virtual network cards generate multiple copies of the same data, which is data redundancy. Transmitting the data of multiple container virtual network cards to the system virtual network card requires merging multiple copies of the same data into one copy of data, which is redundancy removal.
[0055] Figure 3 As shown in the specific structural schematic diagram of a virtual communication device provided in an embodiment of the present application, the virtual communication device is presented in the form of a virtual device driver, such as Figure 3 shown, the virtual communication device specifically includes: a virtual network cable, a virtual network card management module, a mode control module, a distribution module, and a redundancy removal module.
[0056] In this embodiment, the virtual network cable includes a system virtual network card Veth(0) and a container virtual network card set. The container virtual network card set includes container virtual network cards Veth(1) to Veth(n), where n is the number of container virtual network cards, that is, the number of container network protocol stacks in the redundant container system.
[0057] Among them, the system virtual network card pre-constructs a mapping relationship with the container virtual network card set. Optionally, the mapping relationship is expressed as [Veth(0), G(0)], where G(0) represents the container virtual network card set corresponding to Veth(0), and G(0) includes Veth(1) to Veth(n).
[0058] The first end of the system virtual network card Veth(0) is connected to the system network protocol stack (system namespace), and the second end is respectively connected to the first ends of multiple container virtual network cards, such as Figure 3 As shown, Veth(0) is connected to the first end of each Veth(i), and the second end of each container virtual network card is connected to the corresponding container network protocol stack, such as Figure 3 As shown, the second end of Veth(i)(1≤i≤n) is connected to a container network protocol stack (container namespace).
[0059] In this embodiment, the virtual network card management module is used to perform preset relationship management on the mapping relationship between the system virtual network card and the container virtual network card set. Optionally, the relationship management includes a creation operation, a change operation, and a release operation, that is, the virtual network card management module is used to create, change, and release the mapping relationship between Veth(0) and G(0).
[0060] In this embodiment, the mode control module is used to control the working mode of the virtual communication device to be a degenerate mode in response to a first preset command, and to control the working mode of the virtual communication device to be a mimic mode in response to a second preset command. Optionally, after receiving a preset command (the first preset command or the second preset command) triggered by a user, the mode control module controls the preset mode parameters based on the preset command, thereby controlling the transition of the working mode.
[0061] In this embodiment, the distribution module is used to select a container virtual network card from the container virtual network card set as the target virtual network card in the degenerate mode, and send the data received by the system virtual network card to the target virtual network card. For example, in the degenerate mode, the distribution module randomly selects Veth(i) from Veth(1) to Veth(n), and transmits the data of the system virtual network card Veth(0) to Veth(i), realizing one-to-one data transmission.
[0062] In this embodiment, the distribution module is also used to distribute the data received by the system virtual network card to each container virtual network card in the mimic mode. For example, in the degenerate mode, the distribution module transmits the data transmission of the system virtual network card Veth(0) to Veth(1)~Veth(n) at the same time, realizing one-to-many data transmission.
[0063] In this embodiment, the de-redundancy module is used to perform preset de-redundancy processing on the data received by each container virtual network card in the mimic mode, obtain de-redundancy data, and send the de-redundancy data to the system virtual network card. For example, in the mimic mode, the de-redundancy module performs de-redundancy processing on the data of Veth(1)~Veth(n) and transmits it to Veth(0), realizing many-to-one transmission of data.
[0064] Specifically, the data of Veth(1) to Veth(n) includes the data packets of each container virtual network card, which are called redundant data packets. For example, if the redundant data packet of Veth(i) is denoted as x(i), when the redundancy removal module is used to obtain the redundancy-removed data, it is specifically used to execute the following processes A1 to A5:
[0065] A1. Divide the redundant data packets to obtain at least one equivalent data packet tuple.
[0066] Among them, the equivalent data packet tuple includes at least one redundant data packet with equivalent functions. For example, for the chaotic redundant data packets x(1) to x(n), they are classified according to whether their functions are equivalent to form m equivalent data packet tuples Y(1) to Y(m). Among them, any equivalent data packet tuple Y(j) includes at least one redundant data packet. For example, the equivalent data packet tuple Y(1) includes redundant data packets x(1) to x(5).
[0067] In this embodiment, the method for determining equivalent functions refers to the prior art.
[0068] A2. Vote on each equivalent data packet tuple according to a preset voting algorithm to obtain the voting result of each equivalent data packet tuple.
[0069] In this embodiment, the voting result includes normal or abnormal. Taking the equivalent data packet tuple Y(1) as an example, the redundant data packets x(1) to x(5) are voted through a preset voting algorithm, and the voting result of Y(1) is normal.
[0070] A3. Delete the abnormal data packet tuples.
[0071] In this embodiment, the abnormal data packet tuples include the equivalent data packet tuples with abnormal voting results.
[0072] It should be noted that if it is determined that the equivalent data packet tuple is abnormal through the voting algorithm, it is considered that the system has been attacked by a network, and the data packets of this equivalent data packet tuple are directly discarded to improve the security of data transmission. For example, if the equivalent data packet tuple Y(m) is an abnormal data packet tuple, then Y(m) is deleted.
[0073] A4. Merge the redundant data packets in the normal data packet tuples to obtain a merged data packet.
[0074] In this embodiment, the normal data packet tuples include the equivalent data packet tuples with normal voting results.
[0075] It should be noted that data merging includes merging redundant data packets in equivalent data packet tuples into one data packet to achieve the purpose of data redundancy elimination. Optionally, in order to ensure uninterrupted connection, factors that affect normal communication (such as inconsistent factors) need to be eliminated. For example, when the ACK fields of the packets in equivalent TCP data packets are inconsistent, the ACK fields need to be eliminated. Specific data merging methods can be referred to the prior art.
[0076] A5. Obtain redundant data elimination data.
[0077] In this embodiment, the redundant data elimination data includes merged data packets corresponding to each normal data packet tuple.
[0078] For example, the redundant data elimination data includes merged data packets X(1) to X(m - 1) obtained by eliminating redundancy from normal equivalent data packet tuples Y(1) to Y(m - 1).
[0079] It can be seen from the above technical solutions that the virtual communication device provided in the embodiment of the present application provides a "one-to-many" virtual network cable structure, realizes data transmission between a system virtual network card and multiple container virtual network cards, and thus realizes communication between a redundant system including multiple container namespaces and the outside world (system namespace), that is, solves the network communication problem of the redundant container system based on the virtual network cable;
[0080] Furthermore, by switching between two working modes of the virtual network cable, data transmission in different working modes is realized.
[0081] Specifically, in the degradation mode, data transmission from the system virtual network card to the set of container virtual network cards is realized, including fixed-point transmission (that is, one-to-one transmission) and data distribution (that is, one-to-many transmission). And, in the mimic mode, redundant data transmission from the set of container virtual network cards to the system virtual network card is realized.
[0082] It can be understood that based on the "one-to-many" virtual network card connection, this device realizes the distribution of "one-end" packets, and realizes the redundancy elimination and voting of "multi-end" packets, thus realizing the network communication of the redundant container system.
[0083] Furthermore, when the set of container virtual network cards transmits redundant data to the system virtual network card in the mimic mode, this device uses a voting mechanism to judge whether the "multi-end" network card data (the set of container virtual network cards) is abnormal, and further judge whether a network attack occurs, improving the security of data transmission.
[0084] It should be noted that Figure 3 Only the specific structure of a virtual communication device provided by the present application is exemplified. In other optional application scenarios, the present application also includes other optional specific structures. One optional application scenario is as follows:
[0085] Variant systems with built - in security as the main technical mechanism have shown great potential in defending against vulnerability attacks. The key idea of variant execution is to synchronously run multiple different container executors, provide them with the same input, and monitor the operation of each container executor to confirm differences. During variant execution, the TCP proxy method is usually used to conduct a distribution vote on data. However, in application scenarios that generate random numbers such as handshake connections or encryption authentication, this method cannot effectively filter random numbers, so the voting effect cannot be achieved. It can be seen that variant systems have always lacked a middleware for distribution proxy and combining - path voting at the underlying level.
[0086] It should be noted that the variant system is a specific redundancy system. Multiple container executors in the variant system are equivalent to redundancy containers in the redundancy system. Based on this, this application is based on the Figure 2 virtual network cable shown below to construct a middleware for distribution proxy and combining - path voting for the variant system to support redundant execution of the variant system. Specifically, the middleware structure is as shown in Figure 4a The middleware includes: a virtual network cable 401, a distribution module 402, and a redundancy - removal module 403. Among them, the virtual network cable is constructed from a virtual network card mveth0 and a set of network cards [virtual network card mimicdevice_1, virtual network card mimicdevice_2, virtual network card mimicdevice_3] that form a path with mveth0.
[0087] In this embodiment, the distribution module is used to divide the data input by the user into multiple parts and distribute them to each container executor through the virtual network cable. The redundancy - removal module is used to judge and vote on the execution results after the multiple container executors received through the virtual network cable. If it is determined that the execution results of all container executors are the same, the execution result is output; otherwise, the output process is truncated. It can be seen that the virtual communication device provided in this application, as a middleware, realizes the distribution proxy and combining - path voting of the variant system.
[0088] As Figure 4a shown, the variant system includes container executor a, container executor b, and container executor c. As Figure 4b shown, the distribution module is used to distribute the multiple parts of data obtained by division to container executor a, container executor b, and container executor c. The redundancy - removal module is used to judge and vote on the multiple execution results received from container executor a, container executor b, and container executor c.
[0089] Next, the structure and functions of the middleware shown in Figure 4a will be further introduced as follows:
[0090] 1. Distribution Module
[0091] The distribution module selects a one - to - three distribution model, copies a network IO request message twice, and distributes it to three container executors. The sender creates an skb at the transport layer, copies the user data to the skb, and finally sends it to the peer by adding TCP headers, IP headers, and MAC headers. The peer processes the received skb through the data link layer, network layer, and transport layer, and finally schedules the user process to receive network IO data.
[0092] 2. Redundancy Removal Module
[0093] The redundancy removal module selects a one - to - three voting and multiplexing model. After the container executor responds with data, it receives three - way data and performs a consistency vote on the data. When voting, it is necessary to identify the message type, which is judged as two types: UDP messages and TCP messages.
[0094] 3. A specific middleware construction process is as follows:
[0095] 3.1 Establish a pair of virtual network cards
[0096] Create mveth0, mimicdevice_1, mimicdevice_2, and mimicdevice_3, and configure their IP and MAC addresses. Bind the four newly created virtual network cards to the docker0 bridge for communication.
[0097] 3.2 Bind the virtual network cards to the container executors
[0098] Specifically, configure mveth0 on the host side, and configure mimicdevice_1, mimicdevice_2, and mimicdevice_3 on container executor a, container executor b, and container executor c respectively, and configure: disable the built - in network card eth0 of the container. At this time, through the ip a network card details, it can be queried that each container executor is configured with a new virtual network card, and the IP addresses of the corresponding three virtual network cards are 172.17.0.101, 172.17.0.102, and 172.17.0.103 respectively.
[0099] 3.3 Perform a Ping test on the middleware (also known as the virtual network card system)
[0100] Specifically, the Ping command tests the connectivity of the virtual network card system. Through the DNS protocol, it converts the domain name after ping into an IP address, and through the ARP resolution service, it resolves the MAC address from the IP address for transmission at the data link layer.
[0101] For the address of mimicdevice_1, the virtual network card system will duplicate the request message twice and distribute it to mimicdevice_2 and mimicdevice_3.
[0102] 3.4 Conduct TCP protocol testing on the virtual network card system
[0103] On the host where the mveth0 network card is located, accessing the nginx homepage of 172.17.0.101 actually accesses the nginx homepage of the three-way container. When the browser requests services from the three-way container and confirms that the nginx page is normally echoed, it can be confirmed that the virtual network card system supports the TCP protocol.
[0104] 3.5 Conduct UDP protocol testing on the virtual network card system
[0105] On the host where the mveth0 network card is located, downloading a file from the 172.17.0.101 container actually accesses the three-way container to download the file, and it can be confirmed that the virtual network card system supports the UDP protocol.
[0106] 3.6 Test the redundancy removal module
[0107] Conduct TCP testing on the network card system, modify the response content of one of the container execution bodies, and test whether the remaining container execution bodies can respond normally under redundancy.
[0108] For example, modify the nginx page in container execution body b, and the page content of the other two container execution bodies remains unchanged. When accessing the server and the pages responded by the three containers are different, verify whether the voting of the redundancy removal module is normal. After modification, re-access the server. If the access fails and the service resources cannot be obtained, it can be confirmed that the redundancy removal module has voted on the response content.
[0109] Further verify the UDP protocol. Specifically, modify the file content under one of the container execution bodies and test whether the remaining container execution bodies can transfer files normally.
[0110] For example, modify the content of 123.txt in the specified directory of the three-way container execution body to inconsistent content. By opening the server and client for file transfer, query the nginx server log to confirm that each container execution body has responded with data. And by querying 123.txt on the host, confirm that the file content is empty and the transfer was not successful. Further confirm through printing the kernel that the voted response data is inconsistent and not sent to the peer.
[0111] In summary, through TCP protocol and UDP protocol testing, it can be confirmed that the redundancy removal module can normally support the transport layer protocol to achieve the normal functions of the middleware.
[0112] Figure 5 The flowchart of a virtual communication method provided by an embodiment of the present application, and this method is applied to a virtual communication device as shown in Figure 2 shown, and as shown in Figure 5 shown, this method includes:
[0113] S501. In response to a first preset command, control the working mode to be a degradation mode.
[0114] S502. In the degradation mode, select a container virtual network card from the container virtual network card set as the target virtual network card, and send the data received by the system virtual network card to the target virtual network card.
[0115] S503. In response to a second preset command, control the working mode to be a mimicry mode.
[0116] S504. In the mimicry mode, distribute the data received by the system virtual network card to each container virtual network card.
[0117] S505. In the mimicry mode, perform a preset redundancy removal process on the data received by each container virtual network card to obtain redundancy-removed data, and send the redundancy-removed data to the system virtual network card.
[0118] In this embodiment, the specific method for performing a preset redundancy removal process on the data received by each container virtual network card to obtain redundancy-removed data includes:
[0119] A1. Divide the redundant data packets to obtain at least one equivalent data packet tuple, and the equivalent data packet tuple includes at least one redundant data packet with equivalent functions.
[0120] A2. According to a preset voting algorithm, vote on each equivalent data packet tuple to obtain the voting result of each equivalent data packet tuple, and the voting result includes normal or abnormal.
[0121] A3. Delete the abnormal data packet tuple, and the abnormal data packet tuple includes the equivalent data packet tuple with a voting result of abnormal.
[0122] A4. Merge the redundant data packets in the normal data packet tuple to obtain a merged data packet, and the normal data packet tuple includes the equivalent data packet tuple with a voting result of normal.
[0123] A5. Obtain the redundancy-removed data, and the redundancy-removed data includes the merged data packets corresponding to each normal data packet tuple.
[0124] As can be seen from the above technical solutions, the virtual communication method provided by the embodiments of the present application for a virtual communication device is based on a "one-to-many" virtual network cable structure to realize data transmission between a system virtual network card and multiple container virtual network cards, thereby realizing communication between a redundant system including multiple container namespaces and the outside world (system namespace). That is, the network communication problem of the redundant container system is solved based on the virtual network cable.
[0125] Furthermore, data transmission from the system virtual network card to the set of container virtual network cards in the degraded mode system is realized, including fixed-point transmission (i.e., one-to-one transmission) and data distribution (i.e., one-to-many transmission). Moreover, in the mimic mode, redundant data transmission from the set of container virtual network cards to the system virtual network card is realized.
[0126] Furthermore, when realizing redundant data transmission from the set of container virtual network cards to the system virtual network card, a voting mechanism is used to determine whether the data of the "multi-end" network cards (the set of container virtual network cards) is abnormal, and then to determine whether a network attack has occurred, thereby improving the security of data transmission.
[0127] Figure 6 The structure diagram of the virtual communication device is shown. The device may include: at least one processor 601, at least one communication interface 602, at least one memory 603, and at least one communication bus 604;
[0128] In the embodiments of the present application, the number of the processor 601, the communication interface 602, the memory 603, and the communication bus 604 is at least one, and the processor 601, the communication interface 602, and the memory 603 complete mutual communication through the communication bus 604;
[0129] The processor 601 may be a central processing unit CPU, or a specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present invention, etc.;
[0130] The memory 603 may include a high-speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory;
[0131] Among them, the memory stores a program, and the processor can execute the program stored in the memory to implement the steps of a virtual communication method provided by the embodiments of the present application, as follows:
[0132] A virtual communication method is applied to a virtual communication device. The virtual communication device includes a virtual network cable, and the virtual network cable includes a system virtual network card and a set of container virtual network cards. The set of container virtual network cards includes multiple container virtual network cards. Among them, the system virtual network card pre - constructs a mapping relationship with the set of container virtual network cards; the first end of the system virtual network card is connected to the system network protocol stack, and the second end is respectively connected to the first ends of multiple container virtual network cards; the second end of each container virtual network card is connected to the corresponding container network protocol stack;
[0133] The virtual communication method includes:
[0134] In a preset degradation mode, select a container virtual network card from the set of container virtual network cards as the target virtual network card, and send the data received by the system virtual network card to the target virtual network card;
[0135] In a preset mimic mode, distribute the data received by the system virtual network card to each of the container virtual network cards, and / or perform preset redundancy removal processing on the data received by each of the container virtual network cards to obtain redundancy - removed data, and send the redundancy - removed data to the system virtual network card.
[0136] Optionally, in the mimic mode, performing preset redundancy removal processing on the data received by each of the container virtual network cards to obtain redundancy - removed data includes:
[0137] In the mimic mode, divide the redundant data packets to obtain at least one equivalent data packet tuple, and the equivalent data packet tuple includes at least one redundant data packet with equivalent functions;
[0138] According to a preset voting algorithm, vote on each of the equivalent data packet tuples to obtain the voting result of each of the equivalent data packet tuples, and the voting result includes normal or abnormal;
[0139] Delete the abnormal data packet tuples, and the abnormal data packet tuples include the equivalent data packet tuples with a voting result of abnormal;
[0140] Merge the redundant data packets in the normal data packet tuples to obtain merged data packets, and the normal data packet tuples include the equivalent data packet tuples with a voting result of normal;
[0141] Obtain the redundancy - removed data, and the redundancy - removed data includes the merged data packets corresponding to each normal data packet tuple.
[0142] The embodiments of the present application further provide a readable storage medium, which can store a computer program suitable for execution by a processor. When the computer program is executed by the processor, the steps of a virtual communication method provided by the embodiments of the present application are implemented as follows:
[0143] A virtual communication method is applied to a virtual communication device. The virtual communication device includes a virtual network cable, and the virtual network cable includes a system virtual network card and a set of container virtual network cards. The set of container virtual network cards includes multiple container virtual network cards. Among them, the system virtual network card pre-constructs a mapping relationship with the set of container virtual network cards; the first end of the system virtual network card is connected to the system network protocol stack, and the second end is respectively connected to the first ends of multiple container virtual network cards; the second end of each container virtual network card is connected to the corresponding container network protocol stack;
[0144] The virtual communication method includes:
[0145] In a preset degradation mode, select a container virtual network card from the set of container virtual network cards as the target virtual network card, and send the data received by the system virtual network card to the target virtual network card;
[0146] In a preset mimicry mode, distribute the data received by the system virtual network card to each container virtual network card, and / or perform preset redundancy removal processing on the data received by each container virtual network card to obtain redundancy-removed data, and send the redundancy-removed data to the system virtual network card.
[0147] Optionally, in the mimicry mode, performing preset redundancy removal processing on the data received by each container virtual network card to obtain redundancy-removed data includes:
[0148] In the mimicry mode, divide the redundant data packets to obtain at least one equivalent data packet tuple, and the equivalent data packet tuple includes at least one redundant data packet with equivalent functions;
[0149] According to a preset voting algorithm, vote on each equivalent data packet tuple to obtain the voting result of each equivalent data packet tuple, and the voting result includes normal or abnormal;
[0150] Delete the abnormal data packet tuple, and the abnormal data packet tuple includes the equivalent data packet tuple with a voting result of abnormal;
[0151] Merge the redundant data packets in the normal data packet tuple to obtain a merged data packet, and the normal data packet tuple includes the equivalent data packet tuple with a voting result of normal;
[0152] Obtain the redundancy-removed data, where the redundancy-removed data includes merged data packets corresponding to each normal data packet tuple.
[0153] It should be noted that a virtual communication device, method, device, and readable storage medium provided by the present invention can be used in the financial field or other fields. The above is only an example and does not limit the application fields of a virtual communication device, method, device, and readable storage medium provided by the present invention.
[0154] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0155] The various embodiments in this specification are described in a progressive manner, and the key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.
[0156] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A virtual communication device, characterized in that, Applicable to many-to-one data transmission between multiple container namespaces and a system namespace in a redundant container system, the virtual communication device comprises: a virtual network cable, the virtual network cable comprises a system virtual network card and a container virtual network card set, the container virtual network card set comprises multiple container virtual network cards, wherein the system virtual network card is pre-mapped with the container virtual network card set; The first end of the system virtual network card is connected to the system network protocol stack, and the second end is respectively connected to the first ends of the plurality of container virtual network cards; The second end of each container virtual network card is connected to the corresponding container network protocol stack.
2. The device according to claim 1, wherein The virtual communication device also includes: a virtual network card management module; The virtual network card management module is used to perform preset relationship management on the mapping relationship between the system virtual network card and the container virtual network card set, and the relationship management includes a creation operation, a change operation, and a release operation.
3. The device according to claim 1 or 2, characterized in that The virtual communication device also includes: a mode control module and a distribution module; The mode control module is used to control the working mode of the virtual communication device to be a degradation mode in response to a first preset command; The distribution module is used to select a container virtual network card from the container virtual network card set as a target virtual network card in the degradation mode, and send the data received by the system virtual network card to the target virtual network card.
4. The device according to claim 3, characterized in that, The mode control module is further used to control the working mode of the virtual communication device to be a mimic mode in response to a second preset command; The distribution module is also used to distribute the data received by the system virtual network card to each of the container virtual network cards in the mimic mode.
5. The device according to claim 4, characterized in that, The virtual communication device further comprises: a redundancy removal module; The de-redundancy module is used to perform preset de-redundancy processing on the data received by each container virtual network card in the mimicking mode to obtain de-redundancy data, and send the de-redundancy data to the system virtual network card.
6. The device according to claim 5, wherein The de-redundancy module is used to perform preset de-redundancy processing on the data received by each container virtual network card in the mimic mode to obtain de-redundancy data, including: the de-redundancy module is specifically used to: Dividing the redundant data packets to obtain at least one equivalent data packet tuple, wherein the equivalent data packet tuple includes at least one redundant data packet with equivalent functions; Voting on each of the equivalent data packet tuples according to a preset voting algorithm to obtain a voting result of each of the equivalent data packet tuples, wherein the voting result includes normal or abnormal; Deleting abnormal data packet tuples, wherein the abnormal data packet tuples include equivalent data packet tuples whose voting results are abnormal; Merging each redundant data packet in a normal data packet tuple to obtain a merged data packet, wherein the normal data packet tuple includes an equivalent data packet tuple whose voting result is normal; The de-redundant data is obtained, where the de-redundant data includes merged data packets corresponding to each normal data packet tuple.
7. A virtual communication method, characterized in that Applied to a virtual communication device, the virtual communication device is applied to the one-to-many data transmission between multiple container namespaces and a system namespace in a redundancy container system. The virtual communication device includes a virtual network cable, and the virtual network cable includes a system virtual network card and a set of container virtual network cards. The set of container virtual network cards includes multiple container virtual network cards. Among them, the system virtual network card pre-establishes a mapping relationship with the set of container virtual network cards; the first end of the system virtual network card is connected to a system network protocol stack, and the second end is respectively connected to the first ends of multiple container virtual network cards; the second end of each container virtual network card is connected to a corresponding container network protocol stack; The virtual communication method includes: In a preset degradation mode, select a container virtual network card from the set of container virtual network cards as a target virtual network card, and send the data received by the system virtual network card to the target virtual network card; In a preset mimicry mode, distribute the data received by the system virtual network card to each container virtual network card, and / or perform preset redundancy removal processing on the data received by each container virtual network card to obtain redundancy-removed data, and send the redundancy-removed data to the system virtual network card.
8. The method according to claim 7, wherein In the mimicry mode, performing preset redundancy removal processing on the data received by each container virtual network card to obtain redundancy-removed data includes: In the mimicry mode, divide redundant data packets to obtain at least one equivalent data packet tuple, and the equivalent data packet tuple includes at least one redundant data packet with equivalent functions; According to a preset voting algorithm, vote on each equivalent data packet tuple to obtain the voting result of each equivalent data packet tuple, and the voting result includes normal or abnormal; Delete abnormal data packet tuples, where the abnormal data packet tuples include equivalent data packet tuples with a voting result of abnormal; Merge the redundant data packets in the normal data packet tuples to obtain a merged data packet, where the normal data packet tuples include equivalent data packet tuples with a voting result of normal; Obtain the redundancy-removed data, and the redundancy-removed data includes the merged data packets corresponding to each normal data packet tuple.
9. A virtual communication device, characterized in that, Includes: A memory and a processor; The memory is used for storing a program; The processor is used for executing the program to implement each step of the virtual communication method as claimed in claim 7 or 8.
10. A readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, each step of the virtual communication method as claimed in claim 7 or 8 is implemented.
Citation Information
Patent Citations
A communication method of a fusion loading module and the fusion loading module
CN109634723A
Correct link judgment method and device for service chain security deployment under mimicry defense, equipment and medium
CN111163070A
Virtual network equipment, virtual overlay network and configuration and message transmission method
CN114448805A