Cloud network access management method and device, electronic equipment, and storage medium
By establishing a mapping relationship between access devices and access gateways through the cloud network access management device, the problem of independent network access and cloud services is solved, and unified management and convenient operation are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
- Filing Date
- 2023-07-10
- Publication Date
- 2026-05-19
AI Technical Summary
In existing technologies, when a user has both network access services and cloud services, network access and cloud services are two independent processes, which leads to inconvenience and poor coordination.
The cloud network access management device establishes and maintains node registration for access devices and access gateways, establishes mapping relationships between user information, network access information, and cloud service information, and achieves unified management of access devices and cloud services.
It enables unified management of network access and cloud services, improves the convenience of user operation, simplifies the process of using network access and cloud services, and promotes the development of cloud services.
Smart Images

Figure CN116846651B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of cloud-network convergence technology, and more specifically, to a cloud-network access management method, a cloud-network access management device, an electronic device, and a computer-readable storage medium. Background Technology
[0002] As more and more applications move to the cloud, it is becoming increasingly common for users to have both network access services and cloud services.
[0003] In related technologies, for traditional broadband access, the terminal device initiates access authentication, and the entire network access process is only related to the access service or data channel, without involving cloud resource application and activation, cloud service activation, etc. At the same time, the prerequisite for users to access cloud services is that the access device can access the cloud service platform, but the cloud service access process is usually not directly related to network access.
[0004] In the above approach, for users who have both network access services and cloud services, network access and cloud services are two completely independent processes, which will cause inconvenience to users and result in poor coordination. Summary of the Invention
[0005] The purpose of this disclosure is to provide a cloud network access management method, cloud network access management device, electronic device, and computer-readable storage medium, thereby overcoming, at least to some extent, the problem of poor convenience caused by the limitations and defects of related technologies.
[0006] According to a first aspect of this disclosure, a cloud network access management method is provided, comprising: responding to a registration request to register an access device and an access gateway to a cloud network access management device, performing node registration for the access device and the access gateway based on the node where the access device and the access gateway are located; after completing the node registration, establishing and maintaining a mapping relationship between user information corresponding to the access device, network access information corresponding to the access device and the access gateway, and cloud service information; if the access device goes offline, managing the cloud service information of the access device, and adjusting the node where the access device is located and the mapping relationship.
[0007] In one exemplary embodiment of this disclosure, the step of registering the access device and the access gateway based on the node where the access device and the access gateway are located includes: if the type of the node where the access device and the access gateway are located is a general node, creating a replica of the node by running agent software on the node to complete the node registration; if the type of the node where the access device and the access gateway are located is a non-general node, creating a mirror node for the access device and the access gateway, and completing the node registration through the mirror node.
[0008] In one exemplary embodiment of this disclosure, establishing and maintaining the mapping relationship between user information corresponding to the access device, network access information corresponding to the access device and the access gateway, and cloud service information includes: when the node type is a non-general node, maintaining the mapping relationship between the user information, network access information and cloud service information based on a mirror node.
[0009] In one exemplary embodiment of this disclosure, the method further includes: obtaining cloud network access information corresponding to the access device and obtaining the mapping relationship; updating the cloud network access information based on the mapping relationship in response to changes in the access device, the access gateway, the cloud service information, and the node; the cloud network access information includes one or more of network access information, cloud network access node information, and cloud service information.
[0010] In one exemplary embodiment of this disclosure, the method further includes: determining a user cloud network node based on the node where the access device and the access gateway are located, and the cloud-side working node of the cloud network access management device; monitoring the node status of the user cloud network node; and updating the node status based on the type of the node where the access device and the access gateway are located in response to a change in the node status.
[0011] In one exemplary embodiment of this disclosure, updating the node status based on the type of the node where the access device and the access gateway are located includes: if the node where the access device and the access gateway are located is a general node, updating the node status, reselecting a node, and performing a scheduling operation based on the reselected node; if the node where the access device and the access gateway are located is a non-general node, updating the node status.
[0012] In one exemplary embodiment of this disclosure, adjusting the node where the access device is located and the mapping relationship includes: if the node where the access device is located is a general node, deleting the node corresponding to the access device and deleting the mapping relationship; if the node where the access device is located is a non-general node, deleting the mirror node corresponding to the access device and deleting the mapping relationship.
[0013] According to a second aspect of this disclosure, a cloud network access management device is provided, comprising: a registration module, configured to, in response to a registration request to register an access device and an access gateway to the cloud network access management device, perform node registration for the access device and the access gateway based on the node where the access device and the access gateway are located; a mapping relationship establishment module, configured to, after completing node registration, establish and maintain a mapping relationship between user information corresponding to the access device, network access information corresponding to the access device and the access gateway, and cloud service information; and an offline module, configured to, if the access device is offline, manage the cloud service information of the access device and adjust the node where the access device is located and the mapping relationship.
[0014] According to a third aspect of this disclosure, an electronic device is provided, comprising: a processor; and
[0015] A memory for storing executable instructions of the processor; wherein the processor is configured to execute the cloud network access management method described above by executing the executable instructions.
[0016] According to a fourth aspect of this disclosure, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the cloud network access management method described in any one of the preceding claims.
[0017] In the technical solutions provided in this disclosure, on the one hand, after registering the access devices and access gateways to the cloud network access management device, the mapping relationship between the network access information and cloud service information corresponding to the access devices and access gateways can be established and maintained based on the cloud network access management device. This enables unified management of access devices and cloud service information, thereby achieving unified management of network access and cloud services, establishing the association between access devices and cloud services, and improving the convenience of user operation. On the other hand, since the working nodes of access devices and cloud service information can be managed in a unified manner, the user's network access and cloud service usage process can be simplified, thereby promoting the development of cloud services.
[0018] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0019] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.
[0020] Figure 1 The flowchart illustrates an embodiment of the cloud network access management method of this disclosure.
[0021] Figure 2 The flowchart illustrating data classification in an embodiment of this disclosure is shown schematically.
[0022] Figure 3 The schematic diagram illustrates the specific flowchart of access authentication in an embodiment of this disclosure.
[0023] Figure 4 The schematic diagram illustrates the process of registering a node according to an embodiment of this disclosure.
[0024] Figure 5 This illustration shows a flowchart of the process for managing cloud network access information according to an embodiment of the present disclosure.
[0025] Figure 6 The schematic diagram illustrates a process diagram for cloud network node management according to an embodiment of the present disclosure.
[0026] Figure 7 The schematic diagram illustrates the process flow of the offline stage in an embodiment of this disclosure.
[0027] Figure 8 This diagram illustrates the overall process of cloud network access management according to an embodiment of the present disclosure.
[0028] Figure 9 The schematic diagram illustrates the cloud network access interaction process of an embodiment of this disclosure.
[0029] Figure 10 The diagram illustrates a block diagram of a cloud network access management device according to an embodiment of the present disclosure.
[0030] Figure 11 A schematic block diagram of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation
[0031] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided to make this disclosure more comprehensive and complete, and to fully convey the concept of the example embodiments to those skilled in the art. The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a full understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced with one or more of the specific details omitted, or other methods, components, apparatus, steps, etc., can be employed. In other instances, well-known technical solutions are not shown or described in detail to avoid obscuring various aspects of this disclosure.
[0032] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0033] In some embodiments, access devices and access gateways access the network through an authentication server; cloud resources and cloud services are managed through a cloud service management server. Network access and cloud services are completely independent and lack coordination: network access and cloud services do not communicate with each other, network access has no cloud service information, and the cloud service management side has no access device information; this is inconvenient for users and not conducive to the promotion of cloud network services.
[0034] In this embodiment of the disclosure, to solve the aforementioned technical problems, a cloud network access management method is provided. Next, refer to... Figure 1 The diagram illustrates the cloud network access management method in the embodiments of this disclosure.
[0035] In step S110, in response to the registration request to register the access device and access gateway to the cloud network access management device, node registration is performed on the access device and access gateway based on the node where the access device and access gateway are located.
[0036] In this embodiment of the disclosure, the access device can be any type of smart device capable of accessing the network, such as a mobile phone or a computer. The access gateway generally refers to various IP gateway devices that connect to user hosts at the network edge. These may include, but are not limited to, broadband access gateways, wireless access gateways, home access gateways, and enterprise access gateways.
[0037] A cloud network access management device is a platform used for unified management of network access and cloud services. It can be implemented and built on the Kubernetes management platform. (Reference) Figure 2 As shown, the cloud network access management device may include a node registration module, a cloud network node management module, and a cloud network access information management module.
[0038] The node registration module is responsible for the registration of the nodes where the access gateway and access devices reside. It receives registration requests from access devices and access gateways and completes node registration. When the node is a generic node, the access device or access gateway runs proxy software (such as Kubelet) to achieve node registration. For non-generic nodes, the node registration module creates mirror nodes for the access devices and access gateways and associates the mirror nodes with network access information, enabling node registration through mirror nodes.
[0039] The Cloud Network Access Information Management module is responsible for managing network access and cloud service information, establishing and maintaining the mapping relationship between user information, network access information, and cloud service information. In addition, this module can also manage cloud network access information. Management operations for cloud network access information include adding, deleting, modifying, and querying. When the access device is online, it manages and maintains the mapping relationship (network access information, cloud service information) identified by the user ID. When network access information and cloud service information change, it is responsible for updating the user's cloud network access information. When the access device goes offline, it deletes the mapping relationship associated with the access device.
[0040] The cloud network node management module is responsible for managing the lifecycle of Pods running access devices and access gateways. It schedules Pods to the nodes where these devices and gateways reside via agent software and collects node information through the agent software. The module manages and maintains user cloud network nodes, including the nodes where access devices and gateways reside, as well as the node servers (i.e., cloud-side worker nodes) running user cloud services and their Pod replicas. Specifically, it performs operations such as adding, deleting, modifying, and querying node information, mapping relationships between nodes and Pods, and scheduling Pods. For non-general-purpose nodes, CRUD operations are only performed on the image nodes associated with the non-general-purpose nodes, not on the nodes themselves.
[0041] Based on the modules contained in the cloud network access management device, the entire cloud network access process can include the authentication stage, registration stage, management stage, and offline stage.
[0042] The authentication phase will be explained below. Before registering the access device and access gateway to the cloud network access management device, access authentication can be performed first. Specifically, the access device initiates an authentication request; the access gateway forwards the authentication request sent by the access device to the authentication server; the authentication server completes the authentication and returns the authentication information to the access gateway. That is, the access device completes access authentication through the access gateway, and the access authentication is completed by the authentication server (such as Radius). The authentication server can authenticate the identity and other information of the access device to improve security. After authentication is completed, the authentication server returns the authentication information to the access gateway, and the access gateway further returns the authentication information to the access device. The authentication information includes, but is not limited to: user information, access service information, cloud service information, and endpoint information of the cloud network access management device.
[0043] Figure 3 The diagram illustrates the process of processing authentication information. (Refer to...) Figure 3 As shown, the main steps include:
[0044] In step S310, the authentication information is received and parsed.
[0045] For example, authentication information is returned by the authentication server to the access gateway, and then returned to the access device through the access gateway. The access device and the access gateway independently receive and parse the authentication information. Authentication information includes, but is not limited to, parameters carried through Radius protocol attributes (AVP), and also includes endpoints from the Kubernetes management platform and cloud network access management devices, such as the endpoints exposed by the node registration module and the endpoints exposed by the cloud network node management module within the cloud network access management device. These exposed endpoints may include, but are not limited to, information such as domain names, IP addresses, and ports. These exposed endpoints can be used for connection registration.
[0046] In step S320, network access information is obtained from the authentication information.
[0047] For example, the access gateway directly obtains network access information from the authentication information returned by the access authentication and completes user authorization. The access device obtains network access information from the access gateway. The network access information includes, but is not limited to, parameters such as user ID, access gateway ID, IP address, endpoint of the node registration module, and endpoint of the cloud network node management module.
[0048] In step S330, cloud service information is obtained from the authentication information.
[0049] For example, the access gateway directly obtains cloud service information from the authentication information returned by the access authentication. The access device obtains cloud service information from the access gateway. Cloud service information refers to the business platform provided by a third-party cloud platform, such as an operation platform, communication platform, etc. Cloud service information may include, but is not limited to, parameters such as cloud service type, cloud service endpoint, and cloud service list.
[0050] After access authentication is completed, the access device and access gateway can be registered with the cloud network access management device to enter the registration phase. During the registration phase, the access device and access gateway can each send a registration request to the cloud network access management device. The registration request sent by the access device is used to register the access device with the cloud network access management device, and the registration request sent by the access gateway is used to register the access gateway with the cloud network access management device. For example, in response to the registration requests sent by the access device and access gateway respectively, the cloud network access management device can perform node registration for the access device and access gateway, enabling the access gateway and access device to register their node information with the cloud network access management device, and report the node information and access parameters after successful registration.
[0051] In some embodiments, during node registration, different methods can be selected to register the access device and access gateway based on the type of node where they reside. The node where the access device and access gateway reside refers to the device running the access gateway and access device functions. Node types can include general-purpose nodes and non-general-purpose nodes. General-purpose nodes can be, for example, x86 servers, while non-general-purpose nodes can be, for example, CPEs (Customer Premise Equipment), routers, etc., without specific limitations here.
[0052] For example, when the node containing the access device and the access gateway is a general node, node registration can be completed by running agent software on the node; if the node is a non-general node, a mirror node can be created for the access device and the access gateway, and node registration can be completed through the mirror node.
[0053] In some embodiments, the nodes where the access gateway and access device reside can each run agent software. For a cloud network access management device built on a Kubernetes management platform, the corresponding agent software can be a software module such as Kubelet. This agent software is responsible for registering node information with the cloud network access management device and for running Pod replicas and deploying network plugins on the nodes. When the nodes where the access gateway and access device reside are generic nodes, the agent software for the access gateway and access device runs in a Pod on that node, creating a replica based on a container engine and container image. This replica is uniformly scheduled and managed by the cloud network access management device. For non-generic nodes, the cloud network access management device creates mirror nodes for the access device and access gateway in the database and registers nodes based on these mirror nodes. Mirror nodes can be different from the nodes where the access device and access gateway reside. Mirror nodes are used to associate access devices and access gateways and to record device information and user information. For example, when a non-general node such as a CPE goes online and completes access authentication, and obtains user information, cloud service information, etc., the access device notifies the cloud network access management device. After receiving the notification, the cloud network access management device directly creates a mirror node in the database. This mirror node is used to represent the access gateway and access device, and is associated with user information, cloud service information, etc.
[0054] After node registration is completed, the access gateway and access devices report the registration information through the agent software.
[0055] Figure 4 A flowchart illustrating the registration node information is shown below. Figure 4 As shown, the main steps include:
[0056] In step S410, registration information is generated.
[0057] The registration information is generated by the access device and the access gateway respectively. The registration information includes, but is not limited to, the node information running on the access device and the access gateway, such as the node type (general node x86, non-general node), IP address, user ID, access session ID, cloud service information, node registration module endpoint, cloud network node management module endpoint, etc.
[0058] In step S420, the node registration module is connected.
[0059] The access device and access gateway obtain the endpoint information of the node registration module from the network access information contained in the authentication information returned by the authentication server, and connect to the node registration module based on the endpoint information, thereby completing the node registration of the access device and access gateway so that it can connect to the cloud network access management device.
[0060] In step S430, the type of device to be registered, represented by the access device and the access gateway, is determined. If it is a general node, proceed to step S440; otherwise, proceed to step S450.
[0061] The device type refers to the type of node it belongs to, such as a general-purpose node or a non-general-purpose node. A general-purpose node refers to a computer, smart device, or server that can run proxy software like Kubelet, container Pods, and other computing resources. A non-general-purpose node refers to traditional devices (such as CPEs and routers) that cannot run proxy software like Kubelet and cannot work with the Kubernetes management platform.
[0062] In step S440, the node registration is completed directly by the agent software.
[0063] In step S450, a mirror node is generated, and node registration is achieved through the mirror node.
[0064] In step S460, node registration is completed. The access device and access gateway report registration information to the node registration module.
[0065] In this embodiment of the disclosure, by using different methods to register the access device and access gateway according to the type of node they are located in, it is possible to accurately register different types of nodes, thereby improving the efficiency and targeting of node registration.
[0066] Next, in step S120, after completing node registration, a mapping relationship is established and maintained between user information corresponding to the access device, network access information corresponding to the access device and access gateway, and cloud service information.
[0067] In this embodiment of the disclosure, after the access device and access gateway complete registration with the cloud network access management device, the access device can be considered online. When the access device is online, the cloud network access information management module in the cloud network access management device can establish and maintain the mapping relationship between user information, network access information corresponding to the access device and access gateway, and cloud service information to perform the management phase.
[0068] The cloud network access information management module in the cloud network access management device is responsible for managing network access and cloud service information, and establishing and maintaining the mapping relationship between user information, network access information, and cloud service information. User information includes, but is not limited to, user ID and user type. The user ID is globally unique and can uniquely identify the user on the network access and cloud service sides. Network access information includes, but is not limited to, access device, access gateway, access type, account, IP address, and access-related parameters. Cloud service information includes, but is not limited to, cloud service endpoint information, account, cloud service list, etc.
[0069] User information, network access information corresponding to access devices and access gateways, and cloud service information provided by third parties can be bound together to establish a mapping relationship between the three. Furthermore, different methods can be used to establish and maintain this mapping relationship for different types of nodes. Specifically, for non-general-purpose nodes, the mapping relationship between user information, network access information, and cloud service information can be maintained based on mirror nodes.
[0070] During the management phase, users' cloud network access information can be managed, and cloud network node management can be performed through the cloud network node management module. Figure 5 The flowchart of cloud network access information management is illustrated in the diagram. (Refer to...) Figure 5 As shown, the main steps include:
[0071] In step S510, cloud network access information is obtained.
[0072] In this step, cloud network access information includes, but is not limited to, information obtained from the node registration module, cloud network node management module, and external configuration. Cloud network access information includes, but is not limited to, network access information (including access device, access gateway, user ID, etc.), cloud network access node information (including node type, node ID, etc.), and cloud service information.
[0073] In step S520, network access information is obtained from the cloud network access information, and relationship binding is performed based on the network access information to obtain the mapping relationship.
[0074] In this step, user information, network access information, and cloud service information can be bound together to establish a corresponding relationship among them. This allows the cloud network access information management module to create and maintain the following mapping relationship:
[0075] (User information, network access information, cloud service information)
[0076] The user information uniquely identifies the user and supports unique identification of the user's network access and cloud services. Network access information includes, but is not limited to, access device, access device type, access gateway, access gateway ID, IP address, session ID, user ID, cloud services, cloud network access management device endpoint, and access policies. Cloud service information includes, but is not limited to, user ID, account, cloud service list, and resource quotas, and cloud services can be provided by third parties.
[0077] In step S530, target processing operations are performed on the cloud network access information.
[0078] In this step, the target processing operation can be any one or more of the following: adding, deleting, modifying, and querying, depending on the actual needs. For example, when any one or more of the access device, access gateway, cloud service information, and node information change, the corresponding target processing operation can be performed on the cloud network access information. For instance, when the access device changes, the cloud network access information can be modified. When the access device goes offline, the cloud network access information can be deleted.
[0079] Figure 6 The flowchart illustrating cloud network node management is shown in the image. (Refer to...) Figure 6 As shown, the main steps include:
[0080] In step S610, the user cloud network node list is obtained.
[0081] In this step, based on the user ID, the system retrieves the nodes of the access devices and access gateways that are managed and registered by the cloud network access management device, as well as the cloud-side worker nodes managed by the cloud network access management device built on the Kubernetes platform. The user's cloud network node list is then determined based on the access device and access gateway nodes, and the cloud-side worker nodes. Each access device, access gateway, and its associated node is bound to a specific user and uniquely identified by the user ID. The cloud-side worker nodes managed by the cloud network access management device refer to the list of servers running the user's cloud services and Pod replicas, and are bound to the user ID.
[0082] In step S620, the node status of the user's cloud network node is monitored.
[0083] In this step, node status refers to the current state of each node, such as whether it is available or unavailable, the functions it is running, or other states. Node status can be monitored in real time or periodically.
[0084] In step S630, it is determined whether the node state has changed. If yes, proceed to step S640. If no, return to step S620.
[0085] Changes to cloud network nodes can include, but are not limited to, changes in configuration parameters, changes in operating status, and changes in relationships. Specifically, changes to cloud network nodes can include adjusting node configuration parameters; failures or shutdowns of running functions, Pod replicas, or cloud services; changes in the binding relationships between cloud services, Pod replicas, and servers; and changes in the mapping relationships between user information, network access information, and cloud service information.
[0086] In step S640, the node status is updated or scheduled.
[0087] In this step, for general-purpose nodes, when the node state changes, state update and scheduling operations can be performed based on the Kubernetes platform. State update refers to updating the node state, and scheduling operation refers to rescheduling Pod replicas. The scheduling operation for Pod replicas includes reselecting nodes, establishing the binding relationship between Pod replicas and worker nodes (reselected nodes), and distributing them to the reselected nodes, where proxy software such as Kubelet runs the containers and manages the lifecycle of the Pods.
[0088] When selecting a node, the choice can be made based on the application scenario. For example, for a home gateway, the selection scope is a single node, which can then be designated as the reselected node. For network-side access devices, a node can be selected from a group of servers. Based on this, a binding relationship can be established between the replica and the reselected node, and further distributed to the reselected node for easier management. By updating and scheduling node information for general nodes, accurate node management is possible.
[0089] In addition, for non-general nodes, when a change in node status is detected, since there are no replicas, only the node status needs to be updated, and no scheduling operation needs to be performed.
[0090] Updating the nodes corresponding to general nodes and non-general nodes by checking their status can improve the accuracy of node management.
[0091] Next, in step S130, if the access device goes offline, the cloud service information of the access device is managed, and the node where the access device is located and the mapping relationship are adjusted.
[0092] In this embodiment of the disclosure, the cloud network node management module performs a shutdown operation on the access device. During this shutdown phase, reference is made to... Figure 7 As shown, it can mainly include the following steps:
[0093] In step S710, the first step is to detect whether the access device is offline.
[0094] For example, if the access gateway detects and receives offline information reported to the cloud network access management device, or if the cloud network access management device itself detects that the node where the access device is located is offline, the access device can be considered offline.
[0095] In step S720, the node where the access device is located and the corresponding cloud service information are processed.
[0096] For example, when an access device goes offline, to save memory space and reduce power consumption, the cloud service information bound to that access device can be deleted, and the corresponding cloud resources can be released. This includes, but is not limited to, releasing Pod replicas, Persistent Volumes (PVs), and network plugins bound to the user's cloud service. A PV is a resource within the cluster. Simultaneously, the cloud network access information for the user corresponding to that access device can be updated synchronously. For example, the network access information in the cloud network access information can be changed to indicate offline status, node type, and deletion of cloud service information.
[0097] In step S730, the mapping relationship corresponding to the access device and the node information of the access device are deleted.
[0098] For example, depending on the type of node where the access device is located, different methods can be selected to delete the node information corresponding to the access device. The node information can be the node where the access device is located itself, or it can be information about other related nodes, depending on the type of node.
[0099] For general-purpose nodes, delete the registered access devices, the node information of the access gateway node (such as node type), and the Pod information running on the node. In addition, the mapping relationships between user information, network access information, and cloud service information also need to be deleted. For non-general-purpose nodes, only the mirror node and its related status information need to be deleted, including deleting the node information related to the offline access device from the cloud network access information database, as well as the mapping relationships between user information, network access information, and cloud service information.
[0100] By deleting the node information and mapping relationships of offline access devices, the impact on other nodes can be avoided, and memory consumption and memory usage can be reduced.
[0101] Figure 8 The flowchart of cloud network access management is illustrated in the diagram. (Refer to...) Figure 8 As shown, the main steps include:
[0102] In step S810, authentication information returned by the authentication server is received.
[0103] For example, the access device completes access authentication through the access gateway, and the access authentication is performed by the authentication server. The authentication information returned by the authentication server includes, but is not limited to: user information, access service information, cloud service information, and endpoint information of the cloud network access management device.
[0104] In step S820, the node information is registered.
[0105] For example, when the access gateway and access device reside on a generic node, the proxy software of the access gateway and access device runs in a Pod on that node. A replica is created based on the container images of the container engine, access device, and access gateway, and this replica is used for node registration. For non-generic nodes, the Kubernetes management platform creates an image node and completes node registration through the image node. After registration, the access gateway and access device report access-related information through the proxy.
[0106] Specifically, the node registration module is responsible for the registration of the nodes where the access gateway and access devices reside. After the nodes where the access gateway and access devices reside register with the cloud network access management device through the node registration module, the registered node information is shared and managed by the Kubernetes management platform.
[0107] In step S830, cloud network access information is created and managed.
[0108] For example, the cloud network access information management module is responsible for managing network access and cloud service information, and establishing and maintaining the mapping relationship between user information, network access, and cloud service information.
[0109] In step S840, cloud network node management is performed.
[0110] For example, the cloud network node management module is responsible for managing the lifecycle of Pods that run access devices and access gateway functions, and scheduling access devices and access gateways to the nodes through agent software, and collecting node information through agent software.
[0111] For non-general-purpose nodes, the node registration module creates mirror nodes for access devices and access gateways. The cloud network access information management module maintains the mapping relationship between user information, network access, and cloud services based on the mirror nodes. The cloud network node management module is responsible for collecting and processing information during node operation.
[0112] In step S850, the access device is taken offline.
[0113] For example, when an access device goes offline, the access gateway notifies the cloud network node management module through a proxy, updates the cloud network access information, and deletes all nodes, user-managed Pod instances and Kubernetes services, and their binding relationships. It also deletes mapping relationships and the mirror nodes of the access device and access gateway.
[0114] Figure 9 The diagram illustrates the interaction. (See reference) Figure 9 As shown, the interaction process between the access device, access gateway, authentication server, and cloud network access management device specifically includes:
[0115] Authentication Phase: The authentication server completes the authentication and returns the authentication information to the access gateway, which then returns the authentication information to the access device. The authentication information may include cloud network management endpoints and cloud service information, etc.
[0116] Registration phase: Access devices and access gateways register nodes with the cloud network access management device and report node information after successful registration.
[0117] Management phase: The cloud network access management device creates node information, manages cloud network nodes and cloud network access information, manages access devices and access gateways, establishes and maintains the mapping relationship of cloud network access information, and updates node status in real time.
[0118] Offline Phase: The access gateway reports the access device offline, and the cloud network access management device deletes the nodes, services, and mapping relationships created for the access device.
[0119] In this embodiment, the mapping relationship between access devices, access gateways, cloud network access information, and cloud service information is determined through a cloud network access management device. This enables unified management of access devices and cloud service information, improving management convenience and efficiency. When an access device is taken offline, its corresponding nodes, services, and mapping relationships are deleted, reducing resource consumption and resource usage.
[0120] This disclosure also provides a cloud network access management device. (Reference) Figure 10 As shown, the cloud network access management device 1000 mainly includes the following modules:
[0121] The registration module 1001 is used to respond to the registration request to register the access device and access gateway to the cloud network access management device, and to perform node registration for the access device and access gateway based on the node where the access device and access gateway are located;
[0122] The mapping relationship establishment module 1002 is used to establish and maintain the mapping relationship between user information corresponding to the access device, network access information corresponding to the access device and access gateway, and cloud service information after the node registration is completed.
[0123] The offline module 1003 is used to manage the cloud service information of the access device and adjust the node and mapping relationship of the access device if the access device goes offline.
[0124] In one exemplary embodiment of this disclosure, the registration module is configured to perform the following: if the node where the access device and the access gateway are located is a general node, create a copy of the node by running agent software on the node to complete node registration; if the node where the access device and the access gateway are located is a non-general node, create a mirror node for the access device and the access gateway, and complete node registration through the mirror node.
[0125] In one exemplary embodiment of this disclosure, the mapping relationship establishment module is configured to perform: when the node type is a non-generic node, maintain the mapping relationship between user information, network access information and cloud service information based on the mirror node.
[0126] In one exemplary embodiment of this disclosure, the apparatus further includes: a cloud network access information acquisition module, used to acquire cloud network access information corresponding to the access device and acquire a mapping relationship; and a cloud network access information management module, used to update the cloud network access information based on the mapping relationship in response to changes in the access device, access gateway, cloud service information, and nodes; the cloud network access information includes one or more of network access information, cloud network access node information, and cloud service information.
[0127] In one exemplary embodiment of this disclosure, the apparatus further includes: a node determination module, configured to determine a user cloud network node based on the node where the access device and the access gateway are located, and the cloud-side working node of the cloud network access management device; a node status determination module, configured to monitor the node status of the user cloud network node; and a node status management module, configured to update the node status based on the type of the node where the access device and the access gateway are located in response to a change in the node status.
[0128] In one exemplary embodiment of this disclosure, the node state management module is configured to perform the following: if the node where the access device and the access gateway are located is a general node, update the node state, reselect a node, and perform scheduling operations based on the reselected node; if the node where the access device and the access gateway are located is a non-general node, update the node state.
[0129] In one exemplary embodiment of this disclosure, the offline module is configured to perform the following: if the node where the access device is located is a general node, delete the node corresponding to the access device and delete the mapping relationship; if the node where the access device is located is a non-general node, delete the mirror node corresponding to the access device and delete the mapping relationship.
[0130] It should be noted that the specific details of each module in the cloud network access management device have been described in detail in the corresponding cloud network access management method, so they will not be repeated here.
[0131] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0132] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or a step may be broken down into multiple steps.
[0133] In an exemplary embodiment of this disclosure, an electronic device capable of implementing the above-described method is also provided.
[0134] Those skilled in the art will understand that various aspects of this disclosure can be implemented as a system, method, or program product. Therefore, various aspects of this disclosure can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, collectively referred to herein as a "circuit," "module," or "system."
[0135] The following reference Figure 11 To describe an electronic device 1100 according to such an embodiment of the present disclosure. Figure 11 The electronic device 1100 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.
[0136] like Figure 11 As shown, the electronic device 1100 is manifested in the form of a general-purpose computing device. The components of the electronic device 1100 may include, but are not limited to: at least one processing unit 1110, at least one storage unit 1120, a bus 1130 connecting different system components (including storage unit 1120 and processing unit 1110), and a display unit 1140.
[0137] The storage unit stores program code that can be executed by the processing unit 1110, causing the processing unit 1110 to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure. For example, the processing unit 1110 can perform actions such as... Figure 1 The steps are shown in the figure.
[0138] Storage unit 1120 may include readable media in the form of volatile storage units, such as random access memory (RAM) 11201 and / or cache memory 11202, and may further include read-only memory (ROM) 11203.
[0139] Storage unit 1120 may also include a program / utility 11204 having a set (at least one) program module 11205, such program module 11205 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.
[0140] Bus 1130 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.
[0141] Electronic device 1100 can also communicate with one or more external devices 1200 (e.g., keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with electronic device 1100, and / or any device that enables electronic device 1100 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 1150. Furthermore, electronic device 1100 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1160. As shown, network adapter 1160 communicates with other modules of electronic device 1100 via bus 1130. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1100, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0142] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or electronic device, etc.) to execute the methods according to the embodiments of this disclosure.
[0143] In exemplary embodiments of this disclosure, a computer-readable storage medium is also provided, on which a program product capable of implementing the methods described above is stored. In some possible implementations, various aspects of this disclosure may also be implemented as a program product including program code that, when the program product is run on a terminal device, causes the terminal device to perform the steps of the various exemplary embodiments of this disclosure described in the "Exemplary Methods" section above.
[0144] The program product for implementing the above-described method according to embodiments of the present disclosure may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, the readable storage medium may be any tangible medium containing or storing a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.
[0145] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0146] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.
[0147] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0148] Program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0149] Furthermore, the above figures are merely illustrative of the processes included in the method according to exemplary embodiments of this disclosure and are not intended to be limiting. It is readily understood that the processes shown in the above figures do not indicate or limit the temporal order of these processes. Additionally, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.
[0150] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention described herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not invented by this disclosure. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.
Claims
1. A cloud network access management method, characterized in that, include: In response to a registration request to register the access device and the access gateway to the cloud network access management device, node registration is performed on the access device and the access gateway based on the node where the access device and the access gateway are located; After node registration is completed, a mapping relationship is established and maintained between user information corresponding to the access device, network access information corresponding to the access device and the access gateway, and cloud service information. The user information includes at least a user ID and a user type. The user ID is globally unique and is used to uniquely identify the user on the network access and cloud service sides. The network access information includes at least an access device, access gateway, access type, account, IP address, and access-related parameters. The cloud service information includes at least cloud service endpoint information, account, and cloud service list. If the access device goes offline, the cloud service information of the access device is managed, and the node where the access device is located and the mapping relationship are adjusted. The step of registering the access device and the access gateway as nodes based on the nodes where the access device and the access gateway are located includes: If the access device and the node where the access gateway is located are of the type of general node, the agent software running on the node creates a copy of the node to complete the node registration; If the access device and the access gateway are located on a non-general node, a mirror node is created for the access device and the access gateway, and node registration is completed through the mirror node.
2. The cloud network access management method according to claim 1, characterized in that, The establishment and maintenance of the mapping relationship between user information corresponding to the access device, network access information corresponding to the access device and the access gateway, and cloud service information includes: When the node type is a non-general node, the mapping relationship between the user information, network access information and cloud service information is maintained based on the mirror node.
3. The cloud network access management method according to claim 1, characterized in that, The method further includes: Obtain the cloud network access information corresponding to the access device, and obtain the mapping relationship; In response to changes in the access device, the access gateway, the cloud service information, and the node, the cloud network access information is updated based on the mapping relationship; The cloud network access information includes one or more of the following: network access information, cloud network access node information, and cloud service information.
4. The cloud network access management method according to claim 1, characterized in that, The method further includes: The user's cloud network node is determined based on the node where the access device and access gateway are located, as well as the cloud-side working node of the cloud network access management device. Monitor the node status of the user's cloud network node; In response to a change in the node status, the node status is updated based on the type of the node where the access device and the access gateway are located.
5. The cloud network access management method according to claim 4, characterized in that, The step of updating the node status based on the type of the access device and the node where the access gateway is located includes: If the nodes where the access device and the access gateway are located are general nodes, the node status is updated, a new node is selected, and scheduling operations are performed based on the newly selected node. If the nodes where the access device and the access gateway are located are non-general nodes, the node status is updated.
6. The cloud network access management method according to claim 1, characterized in that, The adjustment of the node where the access device is located and the mapping relationship includes: If the node where the access device is located is a general node, delete the node corresponding to the access device and delete the mapping relationship; If the node where the access device is located is a non-general node, delete the mirror node corresponding to the access device and delete the mapping relationship.
7. A cloud network access management device, characterized in that, include: The registration module is used to respond to a registration request to register the access device and the access gateway to the cloud network access management device, and to perform node registration for the access device and the access gateway based on the node where the access device and the access gateway are located; The mapping relationship establishment module is used to establish and maintain the mapping relationship between user information corresponding to the access device, network access information corresponding to the access device and the access gateway, and cloud service information after the node registration is completed. The user information includes at least a user ID and a user type. The user ID is globally unique and is used to uniquely identify the user on the network access and cloud service sides. The network access information includes at least an access device, access gateway, access type, account, IP address, and access-related parameters. The cloud service information includes at least cloud service endpoint information, account, and cloud service list. The offline module is used to manage the cloud service information of the access device and adjust the node where the access device is located and the mapping relationship if the access device goes offline. The step of registering the access device and the access gateway as nodes based on the nodes where the access device and the access gateway are located includes: If the access device and the node where the access gateway is located are of the type of general node, the agent software running on the node creates a copy of the node to complete the node registration; If the access device and the access gateway are located on a non-general node, a mirror node is created for the access device and the access gateway, and node registration is completed through the mirror node.
8. An electronic device, characterized in that, include: processor; as well as Memory for storing the executable instructions of the processor; The processor is configured to execute the cloud network access management method according to any one of claims 1 to 6 by executing the executable instructions.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the cloud network access management method according to any one of claims 1 to 6.