Cloud network access method, device and storage medium

CN117478446BActive Publication Date: 2026-08-07TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2022-07-22
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

然而,这种通过运营商专线接入专有云网络的方式不适用于移动场景

Benefits of technology

[0015]第十二方面,本申请实施例提供一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行如第一方面至第四方面中任一方面或其各实现方式中的方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117478446B_ABST
    Figure CN117478446B_ABST
Patent Text Reader

Abstract

The application provides a cloud network access method and device and a storage medium. The method is applied to a target access gateway. The method comprises the following steps: receiving a first cloud network access request sent by a target core network device through a first tunnel between the target core network device and the target access gateway, wherein the first cloud network access request comprises a first IP address of a mobile terminal in an operator network; mapping the first IP address to a second IP address of the mobile terminal in a private cloud network; and sending a second cloud network access request carrying the second IP address to a target cloud gateway through a second tunnel between the target access gateway and the target cloud gateway, so that the target cloud gateway accesses the mobile terminal into the private cloud network based on the second IP address, and the mobile terminal can access the private cloud network by using the operator network accessed by the mobile terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud technology, and in particular to a cloud network access method, device and storage medium. Background Technology

[0002] Private cloud networks, such as Virtual Private Clouds (VPCs), are isolated network environments built on top of enterprise clouds, with complete logical isolation between VPCs. Currently, if a cloud tenant wants to connect its on-premises Internet Data Center (IDC) or network equipment to a VPC and enjoy low latency, high bandwidth, and secure network quality, the cloud tenant needs to establish a dedicated line with its mobile network operator. The IDC or network equipment then connects to the nearest Point of Presence (POP) through this dedicated line, and subsequently connects to the VPC via the POP. However, this method of accessing the VPC via a dedicated line is not suitable for mobile scenarios. Summary of the Invention

[0003] This application provides a cloud network access method, device, and storage medium, enabling mobile terminals to access private cloud networks using the operator network they are connected to.

[0004] In a first aspect, embodiments of this application provide a cloud network access method. This method is applied to a target access gateway and includes: receiving a first cloud network access request sent by a target core network device through a first tunnel between the target core network device and the target access gateway. The first cloud network access request includes: a first IP address of a mobile terminal within an operator network; mapping the first IP address to a second IP address of the mobile terminal within a private cloud network; and sending a second cloud network access request carrying the second IP address to the target cloud gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request instructs the target cloud gateway to access the mobile terminal into the private cloud network based on the second IP address.

[0005] Secondly, embodiments of this application provide a cloud network access method, which is applied to a target core network device. The method includes: receiving a first cloud network access request sent by a mobile terminal, the first cloud network access request including a first IP address of the mobile terminal in an operator network; sending the first cloud network access request to a target access gateway through a first tunnel between the target core network device and a target access gateway, so that the target access gateway maps the first IP address to a second IP address of the mobile terminal in a private cloud network; and sending a second cloud network access request carrying the second IP address to the target cloud gateway through a second tunnel between the target access gateway and a target cloud gateway.

[0006] Thirdly, embodiments of this application provide a cloud network access method, which is applied to a target cloud gateway. The method includes: receiving a second cloud network access request sent by the target access gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request includes: a second IP address of the mobile terminal in the private cloud network; and accessing the mobile terminal into the private cloud network based on the second IP address.

[0007] Fourthly, embodiments of this application provide a cloud network access method. This method is applied to a control unit and includes: obtaining the configuration of a first tunnel and a second tunnel; sending the configuration of the first tunnel to a target core network device and a target access gateway; and sending the configuration of the second tunnel to the target access gateway and a target cloud gateway. This enables the target core network device to send a first cloud network access request to the target access gateway through the first tunnel, and the target access gateway to send a second cloud network access request to the target cloud gateway through the second tunnel. The first tunnel is between the target core network device and the target access gateway, and the second tunnel is between the target access gateway and the target cloud gateway. The first cloud network access request includes a first IP address of the mobile terminal within the operator's network, and the second cloud network access request includes a second IP address of the mobile terminal within a private cloud network.

[0008] Fifthly, embodiments of this application provide an access gateway, which is a target access gateway, comprising: a receiving module, a mapping module, and a sending module. The receiving module is used to receive a first cloud network access request sent by the target core network device through a first tunnel between the target core network device and the target access gateway. The first cloud network access request includes: a first IP address of the mobile terminal within the operator's network. The mapping module is used to map the first IP address to a second IP address of the mobile terminal within a private cloud network. The sending module is used to send a second cloud network access request carrying the second IP address to the target cloud gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request is used to instruct the target cloud gateway to access the mobile terminal into the private cloud network based on the second IP address.

[0009] Sixthly, embodiments of this application provide a core network device, which is a target core network device, including: a receiving module and a sending module. The receiving module is used to receive a first cloud network access request sent by a mobile terminal. The first cloud network access request includes: a first IP address of the mobile terminal in the operator's network. The sending module is used to send the first cloud network access request to the target access gateway through a first tunnel between the target core network device and the target access gateway, so that the target access gateway maps the first IP address to a second IP address of the mobile terminal in the private cloud network, and sends a second cloud network access request carrying the second IP address to the target cloud gateway through a second tunnel between the target access gateway and the target cloud gateway.

[0010] In a seventh aspect, embodiments of this application provide a cloud gateway, which is a target cloud gateway, including: a receiving module and an access module. The receiving module is used to receive a second cloud network access request sent by the target access gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request includes: a second IP address of the mobile terminal in the cloud network. The access module is used to access the mobile terminal into the private cloud network based on the second IP address.

[0011] Eighthly, embodiments of this application provide a control unit, including: an acquisition module and a transmission module. The acquisition module is used to acquire the configuration of a first tunnel and the configuration of a second tunnel. The transmission module is used to send the configuration of the first tunnel to a target core network device and a target access gateway, and to send the configuration of the second tunnel to a target access gateway and a target cloud gateway, so that the target core network device sends a first cloud network access request to the target access gateway through the first tunnel, and the target access gateway sends a second cloud network access request to the target cloud gateway through the second tunnel. The first tunnel is a tunnel between the target core network device and the target access gateway, and the second tunnel is a tunnel between the target access gateway and the target cloud gateway. The first cloud network access request includes: a first IP address of the mobile terminal within the operator's network, and the second cloud network access request includes: a second IP address of the mobile terminal within the private cloud network.

[0012] Ninthly, embodiments of this application provide a cloud network access system, including: a mobile terminal, a target core network device, a target access gateway, a target cloud gateway, and a control unit; the control unit is used to send the configuration of a first tunnel between the target core network device and the target access gateway to the target core network device and the target access gateway, and to send the configuration of a second tunnel between the target access gateway and the target cloud gateway to the target access gateway and the target cloud gateway; the mobile terminal is used to send a first cloud network access request to the target core network device, the first cloud network access request including: a first IP address of the mobile terminal in the operator network; the target core network device is used to send the first cloud network access request to the target access gateway through the first tunnel; the target access gateway is used to map the first IP address to a second IP address of the mobile terminal in the private cloud network, and to send a second cloud network access request carrying the second IP address to the target cloud gateway through the second tunnel; the target cloud gateway is used to access the mobile terminal into the private cloud network based on the second IP address.

[0013] In a tenth aspect, embodiments of this application provide an electronic device, including: a processor and a memory, the memory being used to store a computer program, and the processor being used to call and run the computer program stored in the memory to perform a method as described in any one of the first to fourth aspects or their respective implementations.

[0014] Eleventhly, embodiments of this application provide a computer-readable storage medium for storing a computer program that causes a computer to perform a method as described in any one of the first to fourth aspects or their respective implementations.

[0015] In a twelfth aspect, embodiments of this application provide a computer program product including computer program instructions that cause a computer to perform a method as described in any one of the first to fourth aspects or their respective implementations.

[0016] In a thirteenth aspect, embodiments of this application provide a computer program that causes a computer to perform a method as described in any one of the first to fourth aspects or their respective implementations.

[0017] The technical solution provided in this application allows mobile terminals to access private cloud networks by combining their own access to the operator's network with tunnels between the operator and cloud vendors, as well as tunnels within the cloud vendor's network. In summary, the technical solution provided in this application is not only applicable to mobile scenarios but also fully utilizes the low latency and high bandwidth characteristics of operator networks, thereby reducing the latency of mobile terminals accessing private cloud networks and improving the reliability of network access. Attached Figure Description

[0018] Figure 1 A network architecture diagram provided for an embodiment of this application;

[0019] Figure 2 An interactive flowchart of a cloud network access method provided in an embodiment of this application;

[0020] Figure 3 An interactive flowchart illustrating another cloud network access method provided in an embodiment of this application;

[0021] Figure 4 A flowchart illustrating a method for applying for a SIM card with multi-carrier network access, provided in this application embodiment;

[0022] Figure 5 A schematic diagram of a PBR strategy provided in an embodiment of this application;

[0023] Figure 6 A schematic diagram of a tunnel between network elements is provided in an embodiment of this application;

[0024] Figure 7 A schematic diagram of an access gateway 700 provided in an embodiment of this application;

[0025] Figure 8 A schematic diagram of a core network device 800 provided for an embodiment of this application;

[0026] Figure 9 A schematic diagram of a cloud gateway 900 provided in an embodiment of this application;

[0027] Figure 10 A schematic diagram of a control unit 1000 provided in an embodiment of this application;

[0028] Figure 11 This is a schematic block diagram of the electronic device 1100 provided in the embodiments of this application. Detailed Implementation

[0029] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.

[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0031] This application relates to the field of cloud technology. Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to realize the computation, storage, processing, and sharing of data.

[0032] Cloud technology is a collective term for network technologies, information technologies, integration technologies, management platform technologies, and application technologies applied to the cloud computing business model. It can form resource pools, providing flexible and convenient on-demand access. Cloud computing technology will become a crucial support. Backend services of technical network systems require substantial computing and storage resources, such as video websites, image websites, and many portal websites. With the rapid development and application of the internet industry, every item may have its own identification mark in the future, requiring transmission to backend systems for logical processing. Data at different levels will be processed separately, and various industry data will all require robust system support, which can only be achieved through cloud computing.

[0033] A private cloud is created within a firewall, housing cloud infrastructure and hardware / software resources for various departments within an organization or enterprise to share resources within a data center. In addition to hardware resources, creating a private cloud typically involves cloud equipment and Infrastructure as a Service (IaaS) software.

[0034] Private cloud computing also comprises three layers: cloud hardware, cloud platform, and cloud services. The difference is that cloud hardware consists of the user's own personal computer or server, rather than the cloud computing provider's data center. Cloud computing providers build data centers to provide public cloud services to millions of users, thus requiring hundreds of thousands or even millions of servers. Private cloud computing, for individuals, serves only family and friends; for businesses, it serves only their own employees, customers, and suppliers. Therefore, an individual's or business's own personal computer or server is sufficient to provide cloud services.

[0035] Before introducing the technical solution of this application, the relevant knowledge of this application will be explained below:

[0036] I. Network Functions Virtualization (NFV) refers to the use of virtualization technology to implement various network functions on standardized, general-purpose Internet Technology (IT) equipment (x86 servers, storage devices, and switches). The goal of NFV is to replace private, dedicated, and closed network elements in communication networks, achieving an open architecture of a unified, general-purpose hardware platform plus business logic software.

[0037] NFV integrates various network devices, such as servers, switches, and storage devices, into a data center network. It leverages IT virtualization technology to create virtual machines (VMs), and then deploys traditional communication technology (CT) services onto these VMs. Before NFV, devices were highly specialized, with specific functions implemented by dedicated devices. Now, the control plane is separated from the specific device; different devices use VMs as their control plane, and these VMs use cloud operating systems. This allows enterprises to deploy new services simply by creating the corresponding VMs on an open VM operating platform and installing the relevant software packages. This approach is called Network Functions Virtualization.

[0038] The NFV architecture consists of three parts: basic network function virtualization architecture, virtual network functions, management automation, and network orchestration.

[0039] The basic network virtualization infrastructure (NFVI) is like the mobile phone operating system launched by various mobile phone manufacturers. It provides hardware devices with basic components and supports the software or container management platform required by network applications.

[0040] Virtual Network Functions (VNFs) are software applications that implement network functions, such as forwarding services and IP configuration, much like applications (apps) on a mobile phone. In the NFV architecture, various VNFs are implemented on top of NFVI. Because NFVI is a standardized architecture, different VNFs gain universality and no longer depend on the original black-box devices.

[0041] Management Automation and Network Orchestration (MANO) is a unified framework for managing various VNFs and NFVIs, facilitating service orchestration and device management for operations and maintenance personnel.

[0042] Compared to traditional physical network equipment, NFV has many advantages, as shown in Table 1:

[0043] Table 1

[0044]

[0045]

[0046] II. A private cloud network is an isolated network environment built on top of an enterprise cloud, with complete logical isolation between different private cloud networks. Private cloud networks offer two capabilities: first, users can customize the network topology, including selecting free IP address ranges, dividing network segments, configuring routing tables and gateways; second, they can connect to existing data centers via leased lines or VPNs, using the same network address planning for both cloud and on-premises resources, enabling a smooth migration of applications to the cloud.

[0047] Each private cloud network consists of a private network segment, a router, and at least one switch. The router is the hub of the private cloud network; as a crucial functional component, it connects the various switches within the network and also serves as a gateway connecting the private cloud network to other networks. The switch is the fundamental network equipment that makes up the private cloud network, used to connect different cloud product instances.

[0048] 3. Generic Routing Encapsulation (GRE) encapsulates datagrams from certain network layer protocols, such as IP and the Internet Packet Exchange protocol (IPX), enabling these encapsulated datagrams to be transmitted over another network layer protocol, such as IP. GRE is a Layer 3 tunneling protocol for Virtual Private Networks (VPNs), employing a technology called a tunnel between protocol layers. A tunnel is a virtual point-to-point connection that provides a path for encapsulated datagrams to be transmitted, with encapsulation and decapsulation performed at both ends of a tunnel.

[0049] IV. Virtual Extensible LAN (VXLAN) is a network virtualization technology that attempts to improve the scalability issues in large-scale cloud computing deployments. It can be considered an extension of Virtual Local Area Network (VLAN). Because the VLAN header is limited to 12 bits, the number of VLANs is limited to 2^12 = 4096, which cannot meet the ever-increasing demand. Currently, the VXLAN packet header has 24 bits, supporting 2^24 VXLAN instances.

[0050] The technical problem to be solved and the inventive concept of this application will be explained below:

[0051] Currently, if a cloud tenant wants to connect its on-premises data center (IDC) or network equipment to a private cloud network and enjoy low latency, high bandwidth, and secure network quality, the cloud tenant needs to activate a dedicated line with the carrier. The IDC or network equipment then connects to the nearest Point of Presence (POP) via this dedicated line, and finally connects to the private cloud network through the POP. However, this method of accessing the private cloud network via a dedicated carrier line is not suitable for mobile scenarios.

[0052] To address the aforementioned technical issues, this application establishes a tunnel between the operator's network and the cloud network, enabling mobile terminals to access the private cloud network via the operator's network they are connected to.

[0053] The technical solution of this application is applicable to Figure 1 The network architecture shown is not limited to this:

[0054] For example, Figure 1 A network architecture diagram provided for embodiments of this application, such as Figure 1 As shown, this network architecture adopts the NFV's separation of forwarding and control (i.e., separation of forwarding and control) design concept, consisting of a control unit on the cloud and network devices on the cloud. The control unit 10 on the cloud may include: gateway controller 101 and cloud controller 102. The network devices on the cloud may include: mobile terminal 20, operator-side base station 30, core network equipment 40, cloud vendor-side access gateway 50 and cloud vendor-side cloud gateway 60, etc., but are not limited to these.

[0055] Gateway controller 101 can send tunnel configuration information between core network device 40 and access gateway 50 to core network device 40 and access gateway 50, thereby establishing a tunnel path between them. Since the carrier network and the private cloud network use different protocols, access gateway 50 needs to map the IP address of mobile terminal 20 in the carrier network to its IP address in the private cloud network. Gateway controller 101 can also send the mapping relationship between the IP address of mobile terminal 20 in the carrier network and its IP address in the private cloud network to access gateway 50, allowing access gateway 50 to determine the IP address of mobile terminal 20 in the private cloud network based on this mapping relationship.

[0056] The cloud controller 102 can send tunnel configuration between the access gateway 50 and the cloud gateway 60 to the access gateway 50 and the cloud gateway 60, so as to form a tunnel path between the access gateway 50 and the cloud gateway 60.

[0057] Mobile terminal 20 can access the operator network through base station 30 in the operator network, enabling mobile terminal 20 to communicate with the core network equipment 40 on the operator side. The operator network here includes two parts: an access network and a core network. The access network can be a Global System for Mobile Communication (GSM), a Code Division Multiple Access (CDMA) system, a Wideband Code Division Multiple Access (WCDMA) system, a General Packet Radio Service (GPRS) system, a Long Term Evolution (LTE) system, an Advanced Long Term Evolution (LTE-A) system, a New Radio (NR) system, an evolution of the NR system, a next-generation communication system, or other communication systems.

[0058] The core network device 40 can communicate with the access gateway 50 through the tunnel between itself and the access gateway 50, and the access gateway 50 can communicate with the cloud gateway 60 through the tunnel between itself and the cloud gateway 60.

[0059] It should be understood that, Figure 1 The network architecture shown is merely an example. In practice, the control unit 10 may be just a controller that has the functions of both the gateway controller 101 and the cloud controller 102. This application does not limit this.

[0060] The mobile terminal 110 can access the operator's network using second-generation (2G), third-generation (3G), fourth-generation (4G), or fifth-generation (5G) communication methods. The mobile terminal 20 can be a mobile phone, tablet computer, customer premises equipment (CPE), etc., but is not limited to these.

[0061] Base station 30 can be a base station (Base Transceiver Station, BTS) in GSM or CDMA, a base station (NodeB, NB) in WCDMA, an evolved base station (Evolutionary Node B, eNB or eNodeB) in LTE, a base station (gNB) in an NR network, or a base station in a future evolved Public Land Mobile Network (PLMN) network, etc.

[0062] The core network device 40 is mainly responsible for routing and forwarding user plane data packets, identifying data and services, and executing actions and policies. The core network device 40 can be a User Plane Function (UPF) network element in the core network, but is not limited to this.

[0063] Access gateway 50, also known as an internetwork connector or protocol converter, is used to enable interconnection between carrier networks and private cloud networks, which have different high-level protocols.

[0064] The Cloud Gateway 60 is used in scenarios such as hybrid cloud private line access, inter-domain interconnection, and public cloud Black Stone interconnection to achieve high-performance forwarding, support multi-tenant access, support GRE and VXLAN tunnel protocols, and support features such as fragmentation, reassembly, and rate limiting. This Cloud Gateway 60 can be a Next Generation Gateway (NGW), but is not limited to this.

[0065] The technical solution of this application will be described in detail below:

[0066] Figure 2 This application provides an interactive flowchart of a cloud network access method, which can be executed by a mobile terminal, a target core network device, a target access gateway, a target cloud gateway, and a control unit. These components can be... Figure 1 The mobile terminal 20, core network equipment 40, access gateway 50, cloud gateway 60, and control unit 10 are included, but not limited to these. For example... Figure 2As shown, the method may include:

[0067] S210: The control unit sends the configuration of the first tunnel between the target core network device and the target access gateway to the target core network device;

[0068] S220: The control unit sends the configuration of the first tunnel and the configuration of the second tunnel between the target access gateway and the target cloud gateway to the target access gateway;

[0069] S230: The control unit sends the configuration of the second tunnel mentioned above to the target cloud gateway;

[0070] S240: The mobile terminal sends a first cloud network access request to the target core network equipment. The first cloud network access request includes: the mobile terminal's first IP address within the operator's network.

[0071] S250: The target core network device sends a first cloud network access request to the target access gateway through the first tunnel;

[0072] S260: The target access gateway maps the first IP address to the second IP address of the mobile terminal within the private cloud network;

[0073] S270: The target access gateway sends a second cloud network access request carrying the second IP address to the target cloud gateway through the second tunnel;

[0074] S280: The target cloud gateway connects the mobile terminal to the private cloud network based on the second IP address.

[0075] It should be understood that the first tunnel is the tunnel between the target core network device and the target access gateway. This tunnel can be a GRE tunnel, but is not limited to this.

[0076] GRE tunnels are established through tunnel interfaces at both ends of the tunnel, so tunnel interfaces need to be configured on the devices at both ends of the tunnel. For GRE tunnel interfaces, you need to specify the protocol type as GRE, the source address or source interface, the destination address, and the tunnel interface IP address.

[0077] Tunnel source address: The source address configured in the message transmission protocol. When configuring an address type, it is used directly as the source address. When configuring a source interface, the IP address of that interface is used as the source address.

[0078] Tunnel destination address: The destination address configured in the message transmission protocol.

[0079] Tunnel Interface IP Address: To enable dynamic routing protocols on a Tunnel interface, or to advertise a Tunnel interface using static routing protocols, an IP address needs to be assigned to the Tunnel interface. The IP address of the Tunnel interface does not have to be a public IP address; it can even borrow an IP address from another interface to conserve IP addresses.

[0080] It should be understood that in the connection between a private cloud network and a carrier network, the carrier typically provides a generic GRE tunnel for network encapsulation to distinguish its different users. One end of the GRE tunnel is the core network equipment, and the other end is the target access gateway. In the embodiments of this application, for the carrier, a cloud vendor is equivalent to a user; therefore, the target access gateway in the cloud vendor only needs to establish a set of GRE tunnels with the core network equipment.

[0081] It should be noted that, considering that the operator's side may include multiple core network devices, the core network device used to receive the first cloud network access request is referred to as the target core network device.

[0082] Once the control unit successfully sends the configuration of the first tunnel to the target core network device and the target access gateway, it indicates that the first tunnel between the target core network device and the target access gateway has been successfully established.

[0083] In one possible implementation, the control unit can issue the configuration of the first tunnel to the target core network device and the target access gateway during initialization, i.e., before any device accesses the aforementioned private cloud network through the first tunnel.

[0084] In another possible implementation, the control unit can also issue the configuration of the first tunnel to the target core network device and the target access gateway after the mobile terminal sends the first cloud network access request to the target core network device.

[0085] In summary, this application does not restrict the timing of the control unit issuing the first tunnel configuration.

[0086] It should be understood that the second tunnel is a tunnel between the target access gateway and the target cloud gateway. This tunnel can be a Virtual eXtential LAN (VXLAN) tunnel, but is not limited to this.

[0087] It should be understood that VXLAN tunnels are divided into the following two types based on how they are created:

[0088] 1. Static tunnel: This is accomplished by manually configuring the local and remote VXLAN network identifiers (VNI), VXLAN tunnel endpoints (VTEP) IP addresses, and the headend copy list.

[0089] In this context, VNI is a user identifier similar to a VLAN ID (IDentity). One VNI represents one tenant, and virtual machines belonging to different VNIs cannot directly communicate at Layer 2. When encapsulating VXLAN packets, a 24-bit length space is allocated to the VNI, enabling it to support the isolation of a large number of tenants.

[0090] VTEP (VXLAN Tunnel Endpoints) are edge devices of a VXLAN network. They are the start and end points of a VXLAN tunnel. Both the encapsulation and decapsulation of user raw data frames by VXLAN are performed on VTEP.

[0091] The VTEP is the absolute protagonist in a VXLAN network. The VTEP can be a standalone network device, such as the aforementioned target access gateway and target cloud gateway. In this embodiment, the target access gateway encapsulates the second cloud network access request into a VXLAN format packet and transmits it to the target cloud gateway in the IP network. The target cloud gateway can decapsulate the VXLAN format packet, restore the original second cloud network access request, and finally forward it to the private cloud network.

[0092] The target access gateway can determine which peer VTEPs belong to the same VNI based on its peer list, which in turn determines the scope of the same large Layer 2 broadcast domain. When the target access gateway generates the aforementioned second cloud network access request, it will copy the second cloud network access request and send it to all peer VTEPs listed in the Peer List. This will form a table, also known as the headend copy list.

[0093] 2. Dynamic Tunnel: A VXLAN tunnel is dynamically established using Border Gateway Protocol (BGP) Ethernet Virtual Private Network (EVPN). A BGP EVPN peer is established between the two VTEPs, and then the peers use BGP EVPN routing to exchange VNI and VTEP IP address information, thereby realizing the dynamically established VXLAN tunnel.

[0094] It should be understood that, in the embodiments of this application, the second tunnel can be a static tunnel or a dynamic tunnel, and the embodiments of this application do not limit it in this way.

[0095] Once the control unit successfully sends the configuration of the second tunnel to the target access gateway and the target cloud gateway, it indicates that the second tunnel between the target access gateway and the target cloud gateway has been successfully established.

[0096] In one possible implementation, the control unit can send the configuration of the first tunnel to the target access gateway and the target cloud gateway during initialization, i.e., before any device accesses the aforementioned private cloud network through the second tunnel.

[0097] In another possible implementation, the control unit can also send the configuration of the second tunnel to the target access gateway and the target cloud gateway after the mobile terminal sends the first cloud network access request to the target core network device.

[0098] In summary, this application does not restrict the timing of the control unit issuing the second tunnel configuration.

[0099] Optionally, such as Figure 1 As shown, the control unit may include: a gateway controller and a cloud controller. Based on this, such as Figure 3 As shown, S210 may include:

[0100] S310: The gateway controller sends the configuration of the first tunnel to the target core network device;

[0101] S220 may include:

[0102] S320: The gateway controller sends the configuration of the first tunnel to the target access gateway;

[0103] S330: The cloud controller sends the configuration of the second tunnel between the target access gateway and the target cloud gateway to the target access gateway;

[0104] S230 may include:

[0105] S340: The cloud controller sends the configuration of the second tunnel mentioned above to the target cloud gateway.

[0106] It should be understood that the aforementioned first cloud network access request is used to request access to the private cloud network.

[0107] Optionally, the aforementioned first cloud network access request may include, in addition to the mobile terminal's first IP address within the operator's network, at least one of the following: the mobile terminal's ID, the private cloud network's ID, etc.

[0108] Optionally, the first IP address mentioned above can be a static IP address.

[0109] It should be understood that since the carrier network and the private cloud network are two different protocol networks, after the target access network resolves the first IP address of the mobile terminal in the carrier network, it needs to map the first IP address to the second IP address of the mobile terminal in the private cloud network.

[0110] In one possible implementation, for any mobile terminal, each time it requests access to the aforementioned private cloud network, the control unit can send a mapping relationship between a first IP address and a second IP address to the target access network. Based on this, the target access network can determine the second IP address based on the mapping relationship and the first IP address.

[0111] In another possible implementation, for any mobile terminal, when it first requests access to the aforementioned private cloud network, the control unit can send a mapping relationship between a first IP address and a second IP address to the target access network. Based on this, the target access network can determine the second IP address based on the mapping relationship and the first IP address, and store the mapping relationship. When the mobile terminal requests access to the aforementioned private cloud network again, the control unit can check whether it has stored the mapping relationship between the first IP address and the second IP address. If the mapping relationship has been stored, the target access network can determine the second IP address based on the mapping relationship and the first IP address. If the mapping relationship has not been stored, the target access network can request the control unit to send the mapping relationship.

[0112] Optionally, the mapping relationship between the first IP address and the second IP address can be carried in the Policy Based Routing (PBR) command issued by the control unit.

[0113] Optionally, such as Figure 1 As shown, the control unit may include a gateway controller and a cloud controller. Based on this, in these two possible implementations, specifically, the cloud controller in the control unit may send the mapping relationship between the first IP address and the second IP address to the target access network. Of course, it may also be the gateway controller that sends the mapping relationship between the first IP address and the second IP address to the target access network; this application does not limit this.

[0114] It should be understood that the aforementioned second cloud network access request serves the same purpose as the first cloud network access request; both are used to request access to the private cloud network.

[0115] Optionally, the aforementioned second cloud network access request may include, in addition to the mobile terminal's second IP address within the operator's network, at least one of the following: the mobile terminal's ID, the private cloud network's ID, etc.

[0116] It should be understood that after the target cloud gateway receives the second cloud network access request, it can parse the second cloud network access request to obtain the second IP address. Furthermore, the target cloud gateway can connect the mobile terminal to the private cloud network based on the second IP address.

[0117] In summary, in this embodiment, the control unit can send the configuration of a first tunnel between the target core network device and the target access gateway to the target core network device and the target access gateway, and can also send the configuration of a second tunnel between the target access gateway and the target cloud gateway to the target access gateway and the target cloud gateway. This allows the target core network device and the target access gateway to form a tunnel path, and the target access gateway and the target cloud gateway to form a tunnel path. Based on this, the mobile terminal can use its own accessed operator network combined with these two tunnel paths to access the private cloud network. In conclusion, the technical solution provided in this application is not only applicable to mobile scenarios, but also fully utilizes the low latency and high bandwidth characteristics of operator networks, thereby reducing the latency of mobile terminals accessing the private cloud network and improving the reliability of network access.

[0118] Considering the mobility of mobile terminals, and to further improve the reliability of mobile terminals accessing private cloud networks, in this embodiment, a mobile terminal can be equipped with a Subscriber Identification Module (SIM) card that supports multiple operator networks. When a user wants to use the SIM card, they need to apply for it from a cloud provider. The cloud provider is responsible for cooperating with the operators to apply for static IPs from multiple operators for a single SIM card, enabling the mobile terminal to access multiple operator networks using static IPs.

[0119] For example, Figure 4 A flowchart illustrating a method for applying for a SIM card with multi-carrier network access, as provided in this application embodiment, is shown below. Figure 4 As shown, the method includes:

[0120] S410: The control unit stores information about multiple SIM cards that support multiple carrier networks.

[0121] Among them, cloud vendors' operations and maintenance personnel can enter the information of SIM cards that support multiple operator networks into the backend database of the control unit.

[0122] Optionally, the information for each SIM card may include at least one of the following, but is not limited to: the SIM card identifier, and the SIM card number under multiple operator networks.

[0123] S420: The console sends an application request to the control unit so that the tenant can request a SIM card that supports multiple carrier networks;

[0124] The console can be a smartphone, tablet, laptop, or desktop computer, but is not limited to these.

[0125] Optionally, the console may have an application (APP) installed for applying for a SIM card, allowing tenants to apply for a SIM card through the APP. Alternatively, the console may not require an APP for applying for a SIM card; tenants can apply for a SIM card through the web-based client.

[0126] S430: The control unit responds to the request and applies for a static IP address for the SIM card from each operator's core network equipment via API call or email.

[0127] Optionally, the core network equipment here can be a UPF in the operator's network or other core network equipment in the operator's network. If it is other core network equipment, the core network equipment also needs to send the static IP of the SIM card to the UPF in the operator's network so that the UPF can subsequently access the mobile terminal's traffic into the private cloud network based on the static IP.

[0128] It should be understood that for the same operator's network, different SIM cards have different static IPs within the operator's network. In other words, the static IP assigned to each SIM card by the core network equipment on the operator's side is unique.

[0129] S440: The core network equipment on the operator's side sends the static IP of the SIM card to the control unit;

[0130] S450: The control unit writes the static IP of the SIM card into the SIM card and stores the static IP information in the background database.

[0131] Based on this, maintenance personnel can mail the SIM card to the tenant.

[0132] Optionally, when the surrounding wireless network environment of a mobile terminal equipped with a SIM card supporting multiple operator networks changes, the mobile terminal can select the most suitable operator network to access based on the wireless signal quality. Based on this, on the one hand, the target core network device in the above embodiments can be one of the core network devices in the operator network that best selects the wireless signal quality. For example, assuming that the cloud operator network with the best current wireless signal quality is operator A's network, then the above-mentioned target core network device can be a UPF in operator A's network. On the other hand, a mechanism is needed to ensure that when the same mobile terminal accesses a private cloud network through different operator networks, the mobile terminal should be identified as a network node. In the embodiments of this application, the following mechanism can be used to achieve this objective:

[0133] Optionally, the control unit can send a PBR command to the target access gateway. The PBR command includes the mapping relationship between the static IP of the mobile terminal under different operator networks and the IP address of the mobile terminal under the private cloud network. The IP address of the mobile terminal under the private cloud network can also be called a Fake VPC IP. This allows the target access gateway to map the static IP of the mobile terminal under different operator networks to the same virtual IP address, i.e., the IP address of the mobile terminal under the private cloud network, based on the mapping relationship.

[0134] For example, Figure 5 This is a schematic diagram of a PBR strategy provided in an embodiment of this application, as shown below. Figure 5 As shown, the static IP address of the same mobile terminal under operator network A, the static IP address under operator network B, and the static IP address under operator network C are all mapped to the same virtual IP address.

[0135] Optionally, such as Figure 1 As shown, the control unit may include a gateway controller and a cloud controller. Based on this, the cloud controller in the control unit can send the above-mentioned PBR command to the target access gateway.

[0136] Optionally, when downlink traffic from the private cloud network needs to be sent to the mobile terminal, the target access gateway will also use the above mapping relationship to map the mobile terminal's IP address under the private cloud network to the static IP address of the mobile terminal under different operator networks. Based on this, the target access gateway can send downlink traffic from the private cloud network to each operator network according to the static IP address of the mobile terminal under different operator networks, specifically to the core network equipment in each operator network. Furthermore, since a SIM card can only access one operator network at a time, the core network equipment in these different operator networks will send downlink traffic to the mobile terminal based on the mobile terminal's access status. For example, if the mobile terminal is currently accessing operator network A, then operator network A will send downlink traffic to the mobile terminal.

[0137] In this embodiment, the mobile terminal can be equipped with a SIM card that supports multiple operator networks. This allows the mobile terminal to select the most suitable operator network to access based on the wireless signal quality when the surrounding wireless network environment changes, thereby improving the reliability of the mobile terminal's access to the private cloud network. Furthermore, for mobile terminals equipped with SIM cards supporting multiple operator networks, the private cloud network can seamlessly accept the mobile terminal's switching between different operator networks.

[0138] To further improve the reliability of mobile terminal access to the private cloud network, in this embodiment, the operator can set up N core network devices, and the cloud vendor can set up N access gateways and N cloud gateways, where N is an integer greater than 1. Each core network device has a first tunnel with each access gateway, and each access gateway has a second tunnel with each cloud gateway. The target core network device can be any one of the N core network devices. For example, Figure 6 This application provides a schematic diagram of a tunnel between network elements, as shown in the embodiments of the present application. Figure 6 As shown, the operator side is equipped with two UPFs, and the cloud vendor side is equipped with two access gateways and two NGWs. Each UPF is connected to each access gateway via a GRE tunnel, and each access gateway is connected to each cloud gateway via a VXLAN tunnel.

[0139] Optionally, when the operator sets up multiple core network devices and the cloud vendor sets up multiple access gateways and multiple cloud gateways, the configuration of the first tunnel and the second tunnel between these devices can also be issued by the control unit.

[0140] Optionally, after the first cloud network access request reaches the target core network device, the target core network device has N first tunnels. The target core network device can select any one of the first tunnels to transmit the first cloud network access request using the Equal-Cost Multi-Path (ECMP) method. In other words, the underlying GRE tunnels are invisible to tenants, and tenant traffic will be carried on any GRE tunnel.

[0141] Optionally, when the first cloud network access request arrives at the target access gateway and the target access gateway generates a second cloud network access request, the target access network device has N second tunnels. The target access network device can use ECMP to select any of the second tunnels to transmit the second cloud network access request.

[0142] It should be understood that, as mentioned above, the second tunnel can be a VXLAN tunnel, and VXLAN's VNI has 24 bits, which can support more than 16 million tenant accesses, far more than VLAN's 12 bits and 4,000+ tenant accesses. Therefore, VXLAN tunnels are very suitable for cloud vendors to divide tenants when accessing the network.

[0143] In this embodiment, the operator can set up multiple core network devices, and the cloud vendor can set up multiple access gateways and multiple cloud gateways, thus creating multiple first tunnels and multiple second tunnels. When there is a network anomaly, the operator can select the first tunnel and the second tunnel with normal network transmission for data transmission, thereby further improving the reliability of mobile terminal access to the private cloud network.

[0144] Figure 7 This is a schematic diagram of an access gateway 700 provided in an embodiment of this application. The access gateway 700 is a target access gateway, such as... Figure 7 As shown, the access gateway 700 may include a receiving module 710, a mapping module 720, and a sending module 730. The receiving module 710 receives a first cloud network access request sent by the target core network device through a first tunnel between the target core network device and the target access gateway. The first cloud network access request includes a first IP address of the mobile terminal within the operator's network. The mapping module 720 maps the first IP address to a second IP address of the mobile terminal within the private cloud network. The sending module 730 sends a second cloud network access request carrying the second IP address to the target cloud gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request instructs the target cloud gateway to access the mobile terminal into the private cloud network based on the second IP address.

[0145] Optionally, the receiving module 710 is further configured to receive the configuration of the first tunnel issued by the control unit before the receiving module 710 receives the first cloud network access request sent by the target core network device through the first tunnel between the target core network device and the target access gateway.

[0146] Optionally, the receiving module 710 is further configured to receive the configuration of the second tunnel issued by the control unit before the sending module 730 sends the second cloud network access request carrying the second IP address to the target cloud gateway through the second tunnel between the target access gateway and the target cloud gateway.

[0147] Optionally, the receiving module 710 is further configured to receive the mapping relationship between the first IP address and the second IP address issued by the control unit before the mapping module 720 maps the first IP address to the second IP address of the mobile terminal in the private cloud network; correspondingly, the mapping module 720 is specifically configured to: map the first IP address to the second IP address according to the mapping relationship.

[0148] Optionally, the mobile terminal is equipped with a SIM card that supports multiple operator networks, and the target core network equipment is a core network device in the operator network with the best current signal quality among the multiple operator networks.

[0149] Optionally, the target core network device is any one of N core network devices, the target access gateway is any one of N access gateways, and the target cloud gateway is any one of N cloud gateways, where N is an integer greater than 1; each core network device has a first tunnel with each access gateway, and each access gateway has a second tunnel with each cloud gateway.

[0150] Optionally, the first tunnel is a GRE tunnel and the second tunnel is a VXLAN tunnel.

[0151] It should be understood that the device embodiments and method embodiments can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, further details will not be provided here. Specifically, Figure 7 The access gateway 700 shown can execute the method embodiment corresponding to the target access gateway described above, and the aforementioned and other operations and / or functions of each module in the access gateway 700 are respectively for implementing the corresponding process in the method embodiment corresponding to the target access gateway described above. For the sake of brevity, they will not be described in detail here.

[0152] The access gateway 700 of this application embodiment has been described above from the perspective of functional modules in conjunction with the accompanying drawings. It should be understood that this functional module can be implemented in hardware, in software instructions, or in a combination of hardware and software modules. Specifically, the steps of the method embodiments in this application can be completed by integrated logic circuits in the processor's hardware and / or by software instructions. The steps of the method disclosed in this application embodiment can be directly manifested as execution by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps in the above method embodiments.

[0153] Figure 8 This is a schematic diagram of a core network device 800 provided in an embodiment of this application. The core network device 800 is the target core network device, such as... Figure 8 As shown, the system includes a receiving module 810 and a sending module 820. The receiving module 810 is used to receive a first cloud network access request sent by a mobile terminal. The first cloud network access request includes a first IP address of the mobile terminal within the operator's network. The sending module 820 is used to send the first cloud network access request to the target access gateway through a first tunnel between the target core network device and the target access gateway, so that the target access gateway maps the first IP address to a second IP address of the mobile terminal within the private cloud network, and sends a second cloud network access request carrying the second IP address to the target cloud gateway through a second tunnel between the target access gateway and the target cloud gateway.

[0154] Optionally, the receiving module 810 is further configured to receive the configuration of the first tunnel issued by the control unit before the receiving module 810 sends the first cloud network access request to the target access gateway through the first tunnel between the target core network device and the target access gateway.

[0155] Optionally, the mobile terminal is equipped with a SIM card that supports multiple operator networks, and the target core network equipment is a core network device in the operator network with the best current signal quality among the multiple operator networks.

[0156] Optionally, the target core network device is any one of N core network devices, the target access gateway is any one of N access gateways, and the target cloud gateway is any one of N cloud gateways, where N is an integer greater than 1; each core network device has a first tunnel with each access gateway, and each access gateway has a second tunnel with each cloud gateway.

[0157] Optionally, the first tunnel is a GRE tunnel and the second tunnel is a VXLAN tunnel.

[0158] It should be understood that the device embodiments and method embodiments can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, further details will not be provided here. Specifically, Figure 8 The core network device 800 shown can execute the method embodiment corresponding to the target core network device described above, and the aforementioned and other operations and / or functions of each module in the core network device 800 are respectively to implement the corresponding process in the method embodiment corresponding to the target core network device described above. For the sake of brevity, they will not be described in detail here.

[0159] The core network device 800 of this application embodiment has been described above from the perspective of functional modules in conjunction with the accompanying drawings. It should be understood that this functional module can be implemented in hardware, in software instructions, or in a combination of hardware and software modules. Specifically, the steps of the method embodiments in this application can be completed by integrated logic circuits in the processor's hardware and / or by software instructions. The steps of the method disclosed in this application embodiment can be directly manifested as execution by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps in the above method embodiments.

[0160] Figure 9 This is a schematic diagram of a cloud gateway 900 provided in an embodiment of this application. The cloud gateway is a target cloud gateway, such as... Figure 9 As shown, the cloud gateway 900 may include a receiving module 910 and an access module 920. The receiving module 910 is used to receive a second cloud network access request sent by the target access gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request includes a second IP address of the mobile terminal in the cloud network. The access module 920 is used to access the mobile terminal into the private cloud network based on the second IP address.

[0161] Optionally, the receiving module 910 is further configured to receive the configuration of the second tunnel issued by the control unit before the receiving module 910 receives the second cloud network access request sent by the target access gateway through the second tunnel between the target access gateway and the target cloud gateway.

[0162] Optionally, the mobile terminal is equipped with a SIM card that supports multiple operator networks, and the target core network equipment is a core network device in the operator network with the best current signal quality among the multiple operator networks.

[0163] Optionally, the target core network device is any one of N core network devices, the target access gateway is any one of N access gateways, and the target cloud gateway is any one of N cloud gateways, where N is an integer greater than 1; each core network device has a first tunnel with each access gateway, and each access gateway has a second tunnel with each cloud gateway.

[0164] Optionally, the first tunnel is a GRE tunnel and the second tunnel is a VXLAN tunnel.

[0165] It should be understood that the device embodiments and method embodiments can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, further details will not be provided here. Specifically, Figure 9 The cloud gateway 900 shown can execute the method embodiment corresponding to the target cloud gateway described above, and the aforementioned and other operations and / or functions of each module in the cloud gateway 900 are respectively for implementing the corresponding process in the method embodiment corresponding to the target cloud gateway described above. For the sake of brevity, they will not be described in detail here.

[0166] The cloud gateway 900 of this application embodiment has been described above from the perspective of functional modules in conjunction with the accompanying drawings. It should be understood that this functional module can be implemented in hardware, in software instructions, or in a combination of hardware and software modules. Specifically, the steps of the method embodiments in this application can be completed by integrated logic circuits in the processor's hardware and / or by software instructions. The steps of the method disclosed in this application embodiment can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps in the above method embodiments.

[0167] Figure 10 A schematic diagram of a control unit 1000 provided in an embodiment of this application is shown below. Figure 10As shown, the control unit 1000 may include an acquisition module 1010 and a sending module 1020. The acquisition module 1010 is used to acquire the configuration of the first tunnel and the configuration of the second tunnel. The sending module 1020 is used to send the configuration of the first tunnel to the target core network device and the target access gateway, and to send the configuration of the second tunnel to the target access gateway and the target cloud gateway, so that the target core network device sends a first cloud network access request to the target access gateway through the first tunnel, and the target access gateway sends a second cloud network access request to the target cloud gateway through the second tunnel. The first tunnel is the tunnel between the target core network device and the target access gateway, and the second tunnel is the tunnel between the target access gateway and the target cloud gateway. The first cloud network access request includes the first IP address of the mobile terminal in the operator network, and the second cloud network access request includes the second IP address of the mobile terminal in the private cloud network.

[0168] Optionally, the control unit 1000 further includes a distribution module 1030, used to distribute the mapping relationship between the first IP address and the second IP address to the target access gateway.

[0169] Optionally, the mobile terminal is equipped with a SIM card that supports multiple operator networks, and the target core network equipment is a core network device in the operator network with the best current signal quality among the multiple operator networks.

[0170] Optionally, the target core network device is any one of N core network devices, the target access gateway is any one of N access gateways, and the target cloud gateway is any one of N cloud gateways, where N is an integer greater than 1; each core network device has a first tunnel with each access gateway, and each access gateway has a second tunnel with each cloud gateway.

[0171] Optionally, the first tunnel is a GRE tunnel and the second tunnel is a VXLAN tunnel.

[0172] It should be understood that the device embodiments and method embodiments can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, further details will not be provided here. Specifically, Figure 10 The control unit 1000 shown can execute the method embodiment corresponding to the control unit described above. The aforementioned and other operations and / or functions of each module in the control unit 1000 are respectively for implementing the corresponding process in the method embodiment corresponding to the control unit described above. For the sake of brevity, they will not be described in detail here.

[0173] The control unit 1000 of this application embodiment has been described above from the perspective of functional modules in conjunction with the accompanying drawings. It should be understood that this functional module can be implemented in hardware, in software instructions, or in a combination of hardware and software modules. Specifically, the steps of the method embodiments in this application can be completed by integrated logic circuits in the processor's hardware and / or by software instructions. The steps of the method disclosed in this application embodiment can be directly manifested as execution by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps in the above method embodiments.

[0174] This application also provides a cloud network access system, including: a mobile terminal, a target core network device, a target access gateway, a target cloud gateway, and a control unit; the control unit is used to send the configuration of a first tunnel between the target core network device and the target access gateway to the target core network device and the target access gateway, and to send the configuration of a second tunnel between the target access gateway and the target cloud gateway to the target access gateway and the target cloud gateway; the mobile terminal is used to send a first cloud network access request to the target core network device, the first cloud network access request including: a first IP address of the mobile terminal in the operator network; the target core network device is used to send the first cloud network access request to the target access gateway through the first tunnel; the target access gateway is used to map the first IP address to a second IP address of the mobile terminal in the private cloud network, and to send a second cloud network access request carrying the second IP address to the target cloud gateway through the second tunnel; the target cloud gateway is used to access the mobile terminal into the private cloud network based on the second IP address.

[0175] It should be understood that the cloud network access system can be used to execute the above-described cloud network access method. For a detailed explanation, please refer to the method implementation section. This application will not repeat the details here.

[0176] Figure 11 This is a schematic block diagram of the electronic device 1100 provided in this application embodiment. The electronic device may be the aforementioned target core network device, target access gateway, target cloud gateway, and control unit, etc.

[0177] like Figure 11 As shown, the electronic device 1100 may include:

[0178] The system includes a memory 1110 and a processor 1120. The memory 1110 stores computer programs and transfers the program code to the processor 1120. In other words, the processor 1120 can retrieve and run the computer program from the memory 1110 to implement the methods described in the embodiments of this application.

[0179] For example, the processor 1120 can be used to execute the above-described method embodiments according to instructions in the computer program.

[0180] In some embodiments of this application, the processor 1120 may include, but is not limited to:

[0181] General-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0182] In some embodiments of this application, the memory 1110 includes, but is not limited to:

[0183] Volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0184] In some embodiments of this application, the computer program may be divided into one or more modules, which are stored in the memory 1110 and executed by the processor 1120 to complete the method provided in this application. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the electronic device.

[0185] like Figure 11 As shown, the electronic device may also include:

[0186] Transceiver 1130, which can be connected to processor 1120 or memory 1110.

[0187] The processor 1120 can control the transceiver 1130 to communicate with other devices; specifically, it can send information or data to other devices or receive information or data sent by other devices. The transceiver 1130 may include a transmitter and a receiver. The transceiver 1130 may further include antennas, and the number of antennas may be one or more.

[0188] It should be understood that the various components in the electronic device are connected through a bus system, which includes a data bus, a power bus, a control bus, and a status signal bus.

[0189] This application also provides a computer storage medium storing a computer program thereon, which, when executed by a computer, enables the computer to perform the methods of the above-described method embodiments. Alternatively, embodiments of this application also provide a computer program product containing instructions that, when executed by a computer, cause the computer to perform the methods of the above-described method embodiments.

[0190] When implemented using software, it can be implemented entirely or partially as a computer program product. This computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., digital video disc (DVD)), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0191] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0192] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.

[0193] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. For example, the functional modules in the various embodiments of this application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.

[0194] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A cloud network access method, characterized in that, The method is applied to a target access gateway, and the method includes: The first cloud network access request sent by the target core network device is received through the first tunnel between the target core network device and the target access gateway. The first cloud network access request includes the first Internet Protocol IP address of the mobile terminal within the operator network. The first IP address is mapped to the second IP address of the mobile terminal within the private cloud network; A second cloud network access request carrying the second IP address is sent to the target cloud gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request is used to instruct the target cloud gateway to access the mobile terminal into the private cloud network based on the second IP address.

2. The method according to claim 1, characterized in that, Before mapping the first IP address to the second IP address of the mobile terminal within the private cloud network, the method further includes: The mapping relationship between the first IP address and the second IP address sent by the control unit is received; The step of mapping the first IP address to the second IP address of the mobile terminal within the private cloud network includes: The first IP address is mapped to the second IP address according to the mapping relationship.

3. The method according to claim 1 or 2, characterized in that, The mobile terminal is equipped with a user identity SIM card that supports multiple operator networks, and the target core network device is a core network device in the operator network with the best current signal quality among the multiple operator networks.

4. The method according to claim 1 or 2, characterized in that, The target core network device is any one of N core network devices, the target access gateway is any one of N access gateways, and the target cloud gateway is any one of N cloud gateways, where N is an integer greater than 1. Each core network device has a first tunnel with each access gateway, and each access gateway has a second tunnel with each cloud gateway.

5. The method according to claim 1 or 2, characterized in that, The first tunnel is a General Routing Encapsulation (GRE) tunnel, and the second tunnel is a Virtual Extended Local Area Network (VXLAN) tunnel.

6. A cloud network access method, characterized in that, The method is applied to a target core network device, and the method includes: Receive a first cloud network access request sent by a mobile terminal, wherein the first cloud network access request includes: the first IP address of the mobile terminal within the operator's network; The first cloud network access request is sent to the target access gateway through the first tunnel between the target core network device and the target access gateway, so that the target access gateway maps the first IP address to the second IP address of the mobile terminal in the private cloud network, and sends a second cloud network access request carrying the second IP address to the target cloud gateway through the second tunnel between the target access gateway and the target cloud gateway.

7. A cloud network access method, characterized in that, The method is applied to a target cloud gateway, and the method includes: The target access gateway receives a second cloud network access request sent by the target access gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request includes a second IP address of the mobile terminal within the private cloud network. The second IP address is obtained by the target access gateway through the following method: receiving a first cloud network access request sent by the target core network device through a first tunnel between the target core network device and the target access gateway. The first cloud network access request includes a first IP address of the mobile terminal within the operator network. The first IP address is then mapped to the second IP address. The mobile terminal is connected to the private cloud network based on the second IP address.

8. An access gateway, wherein the access gateway is a target access gateway, characterized in that, include: The receiving module is configured to receive a first cloud network access request sent by the target core network device through a first tunnel between the target core network device and the target access gateway. The first cloud network access request includes: the first IP address of the mobile terminal within the operator network. A mapping module is used to map the first IP address to the second IP address of the mobile terminal within the private cloud network; The sending module is configured to send a second cloud network access request carrying the second IP address to the target cloud gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request is used to instruct the target cloud gateway to access the mobile terminal into the private cloud network based on the second IP address.

9. A core network device, wherein the core network device is a target core network device, characterized in that, include: The receiving module is used to receive a first cloud network access request sent by a mobile terminal, wherein the first cloud network access request includes: the first IP address of the mobile terminal in the operator network; The sending module is configured to send the first cloud network access request to the target access gateway through the first tunnel between the target core network device and the target access gateway, so that the target access gateway maps the first IP address to the second IP address of the mobile terminal in the private cloud network, and sends a second cloud network access request carrying the second IP address to the target cloud gateway through the second tunnel between the target access gateway and the target cloud gateway.

10. A cloud gateway, wherein the cloud gateway is a target cloud gateway, characterized in that, include: A receiving module is configured to receive a second cloud network access request sent by the target access gateway through a second tunnel between the target access gateway and the target cloud gateway. The second cloud network access request includes a second IP address of the mobile terminal within the cloud network. The second IP address is obtained by the target access gateway through the following method: receiving a first cloud network access request sent by the target core network device through a first tunnel between the target core network device and the target access gateway. The first cloud network access request includes a first IP address of the mobile terminal within the operator network. The first IP address is then mapped to the second IP address. The access module is used to connect the mobile terminal to the private cloud network based on the second IP address.

11. A cloud network access system, characterized in that, include: Mobile terminal, target core network equipment, target access gateway, target cloud gateway, and control unit; The control unit is used to send the configuration of the first tunnel between the target core network device and the target access gateway to the target core network device and the target access gateway, and to send the configuration of the second tunnel between the target access gateway and the target cloud gateway to the target access gateway and the target cloud gateway; The mobile terminal is used to send a first cloud network access request to the target core network device. The first cloud network access request includes: the first IP address of the mobile terminal in the operator network. The target core network device is used to send the first cloud network access request to the target access gateway through the first tunnel; The target access gateway is used to map the first IP address to the second IP address of the mobile terminal in the private cloud network, and send a second cloud network access request carrying the second IP address to the target cloud gateway through the second tunnel; The target cloud gateway is used to connect the mobile terminal to the private cloud network based on the second IP address.

12. An electronic device, characterized in that, include: A processor and a memory, the memory being used to store a computer program, the processor being used to invoke and run the computer program stored in the memory to perform the method of any one of claims 1 to 7.

13. A computer-readable storage medium, characterized in that, Used to store a computer program that causes a computer to perform the method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Private wire network access method and system

    CN106789527A

  • Network equipment switching method and network equipment

    CN114079981A