A high-stability port expansion method and system for a switch

By setting temporary verification ports and operation ports in the switch, combined with data limit allocation mechanism and redundant detection, the problems of insufficient security, load balancing and fault tolerance of the switch expansion ports are solved, and a high stability and secure port expansion effect is achieved.

CN118449921BActive Publication Date: 2025-05-16SHENZHEN HUIZHENJIN IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410606688.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-16
Publication Date
2025-05-16
Estimated Expiration
2044-05-16

AI Technical Summary

Technical Problem

The existing switch expansion ports are insufficiently secure, which can easily transmit viruses, resulting in equipment failure; the port load is unbalanced, resulting in large loads of some ports and shortened service life; and insufficient fault tolerance, which can easily cause disconnection.

Method used

By setting up a temporary verification port, use the network connection between the switch and the network adapter of the virtual machine partition for verification. After the verification is passed, delete the temporary verification port and create an operation port. The operation port continues to use the temporary verification port verification mechanism. At the same time, a data restriction allocation mechanism is carried out to balance the data load between the characteristic port and the operation port, and redundant detection and automatic path switching are performed on the switch port.

Benefits of technology

The virus filtering is realized to ensure the security of data transmission; the port load is balanced, the single port load is avoided and the service life is extended; and the port fault tolerance is enhanced through redundant detection and automatic path switching.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118449921B_ABST
    Figure CN118449921B_ABST
Patent Text Reader

Abstract

The invention discloses a high-stability port expansion method and system for a switch, which relates to the field of communication technology, including: using the network connection setting of the switch and the network adapter of the virtual machine partition to verify the temporary verification port; creating an operation port, using the operation port to replace the verified temporary verification port; performing operation port planning, forming a data restriction allocation mechanism for the operation port; corresponding the MAC address of the connected switch to the operation port, and storing it in the MAC table; establishing a temporary switching path between the initiator and the target receiver of the data frame; performing redundancy detection on the switch port; and forming a path automatic switching mechanism at the switch port. By setting a temporary verification module, a port planning module, a redundancy detection module and a path switching module, the operation port filters viruses, and at the same time, avoids excessive load on a single port, affects the service life, and enhances the fault tolerance of the port.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a high-stability port expansion method and system for a switch. Background Art

[0002] A switch is a common network device, and its main function is to realize the communication within the local area network. Its function is different from that of a traditional hub. The hub simply broadcasts the signals from different nodes to all nodes in the local area network, while the switch can analyze the header of the data packet and realize point-to-point data exchange between different network devices, thereby improving the communication speed and efficiency of the local area network. The switch can expand the port.

[0003] However, the security of the existing switch extension ports is insufficient. When transmitting data, viruses are easily transmitted together, causing failures in devices connected to the switch. At the same time, the loads between the ports are not balanced, which can easily cause the service life of some ports to be reduced due to heavy loads. In addition, the extended ports are not fault-tolerant enough and are prone to disconnection. Summary of the invention

[0004] In order to solve the above technical problems, a high-stability port expansion method and system for a switch are provided. The technical solution solves the problem that the existing switch expansion port proposed in the above background technology is insufficient in security. When transmitting data, viruses are easily transmitted together, causing failures in the equipment connected to the switch. At the same time, the loads between its ports are not balanced, which easily causes the service life of some ports to be reduced due to heavy loads. In addition, the extended port has insufficient fault tolerance and is prone to disconnection.

[0005] In order to achieve the above purpose, the technical solution adopted by the present invention is:

[0006] A high-stability port expansion method for a switch, comprising:

[0007] Setting at least one temporary authentication port, the temporary authentication port adopting a different authentication mechanism, and authenticating the temporary authentication port using the setting of the network connection between the switch and the network adapter of the virtual machine partition;

[0008] After the verification is completed, the temporary verification port is deleted, and at least one operation port is created. The operation port is used to replace the temporary verification port that has passed the verification. The operation port uses the verification mechanism of the temporary verification port.

[0009] When creating an operation port, assign a port type to the operation port;

[0010] Acquire the characteristic ports created by the switch, plan the operation ports, and form a data restriction allocation mechanism for the operation ports. The data restriction allocation mechanism balances the data load between the characteristic ports and the operation ports. Both the characteristic ports and the operation ports are switch ports.

[0011] Match the MAC address of the connected switch with the operation port and store it in the MAC table;

[0012] The switch stores the MAC address in the internal address table and establishes at least one temporary switching path between the originator and the target receiver of the data frame. The data frame reaches the address of the target receiver from the address of the originator through the temporary switching path.

[0013] Perform redundancy detection on the switch port, and when the switch includes redundant paths, delete the redundant paths. When the deletion is completed, half of the temporary switching paths are used as backup paths;

[0014] A path automatic switching mechanism is formed at the switch port. When the switch port performs data transmission, a temporary switching path is used for transmission. When the temporary switching path is abnormal, the path automatic switching mechanism switches the transmission path to a backup path.

[0015] Preferably, the verification of the temporary verification port using the setting of the network connection between the switch and the network adapter of the virtual machine partition comprises the following steps:

[0016] Obtain a sample data set for testing, where the sample data set is divided into an illegal data set and a legal data set, wherein the illegal data set consists of virus data;

[0017] Obtaining a ratio of illegal data sets completing network connections between the switch and the network adapter of the virtual machine partition through the temporary verification port as a first ratio;

[0018] Obtaining a ratio of the legitimate data set completing the network connection between the switch and the network adapter of the virtual machine partition through the temporary verification port as a second ratio;

[0019] When the first ratio is less than the first preset ratio and the second ratio is greater than the second preset ratio, the temporary verification port passes the verification; otherwise, the temporary verification port fails the verification.

[0020] Preferably, when creating the operation port, assigning a port type to the operation port includes the following steps:

[0021] Get the data flow upper limit of the operation port;

[0022] Get the data flow range of recognized ports, registered ports and private ports;

[0023] Obtaining a calibrated port including a data flow upper limit of the operation port as the type of the operation port, wherein the calibrated port is one of a recognized port, a registered port, and a private port;

[0024] Assign the type of the calibration port to the operation port.

[0025] Preferably, the forming of a data restriction allocation mechanism for the operation port comprises the following steps:

[0026] Get the data flow upper limit of the operation port;

[0027] Monitor the data flow of the operation port to obtain the real-time data flow of the operation port;

[0028] Get the data flow upper limit of the characteristic port;

[0029] Monitor the data flow of the characteristic port to obtain the real-time data flow of the characteristic port;

[0030] The data flow upper limit is multiplied by a preset value to obtain a check part, wherein the preset value is less than one;

[0031] Acquire a characteristic port whose data real-time flow does not exceed the verification part as the target characteristic port, and acquire the data margin of the target characteristic port, wherein the data margin of the target characteristic port is equal to the verification part of the target characteristic port minus the data real-time flow of the target characteristic port;

[0032] When the proportion of the real-time data flow of the operation port to the upper limit of the data flow is greater than the preset value, the part of the real-time data flow of the operation port that exceeds the check is used as the part to be allocated;

[0033] The part to be allocated is allocated to the target feature port, and the amount of data of the part to be allocated obtained by the target feature port is less than the data margin of the target feature port.

[0034] Preferably, said establishing at least one temporary switching path between the originator and the target receiver of the data frame comprises the following steps:

[0035] Acquire a MAC address consistent with the originator address of the data frame from the MAC address of the connected switch as the first MAC address;

[0036] Obtaining a MAC address consistent with the target receiver address of the data frame from the MAC address of the connected switch as the second MAC address;

[0037] Acquire an operation port corresponding to the first MAC address as a first operation port;

[0038] Acquire an operation port corresponding to the second MAC address as the second operation port;

[0039] A temporary switching path is established in the order of the first MAC address to the first operating port to the second operating port to the second MAC address.

[0040] Preferably, the redundancy detection of the switch port comprises the following steps:

[0041] Acquire a temporary switching path from the first MAC address to the first operating port to the second operating port to the second MAC address as a characteristic temporary switching path from the first MAC address to the second MAC address;

[0042] Obtain the data flow limit from the first MAC address to the second MAC address;

[0043] Obtaining the accumulated data flow of the characteristic temporary switching path;

[0044] When the accumulated data traffic exceeds the preset multiple of the data traffic limit, a redundant path exists on the switch port.

[0045] Preferably, when the switch includes a redundant path, deleting the redundant path includes the following steps:

[0046] At least one characteristic temporary switching path of the switch port is deleted one by one until the accumulated data flow of the characteristic temporary switching path is less than a preset multiple of the data flow limit, and the deleted characteristic temporary switching path is used as a redundant path.

[0047] Preferably, the automatic path switching mechanism formed at the switch port includes the following steps:

[0048] forming a disconnected portion in the backup path, the disconnected portion being a switching path, and the switching path being in a disconnected state;

[0049] Match the backup path and the temporary switching path corresponding to the same MAC address;

[0050] Perform traffic detection at different locations in the temporary switching path;

[0051] When the traffic at different locations in the temporary switching path is different, the temporary switching path is abnormal;

[0052] When the temporary switching path is abnormal, the state of the switching path of the backup path corresponding to the temporary switching path is modified to closed.

[0053] A high-stability port expansion system for a switch, used to implement the above-mentioned high-stability port expansion method for a switch, comprising:

[0054] A temporary verification module, wherein the temporary verification module sets at least one temporary verification port and verifies the temporary verification port using the setting of the network connection between the switch and the network adapter of the virtual machine partition;

[0055] A port creation module, wherein the port creation module deletes the temporary verification port, creates at least one operation port, and uses the operation port to replace the temporary verification port that has passed the verification;

[0056] A port type allocation module, wherein the port type allocation module allocates a port type to an operation port;

[0057] A port planning module, which performs operation port planning and forms a data restriction allocation mechanism for the operation ports;

[0058] An address association module, wherein the address association module associates the MAC address of the connected switch with the operation port and stores the corresponding address in a MAC table;

[0059] a path establishment module, the path establishment module establishing at least one temporary switching path between an originator and a target receiver of a data frame;

[0060] A redundancy detection module, wherein the redundancy detection module performs redundancy detection on the switch port, and when the switch includes a redundant path, deletes the redundant path, and when the deletion is completed, uses half of the temporary switching path as a backup path;

[0061] The path switching module forms an automatic path switching mechanism at the switch port. When the switch port transmits data, a temporary switching path is used for transmission. When the temporary switching path is abnormal, the automatic path switching mechanism switches the transmission path to a backup path.

[0062] Compared with the prior art, the present invention has the following beneficial effects:

[0063] By setting a temporary verification module, a port planning module, a redundant detection module and a path switching module, an operation port is used to replace a verified temporary verification port. The operation port follows the verification mechanism of the temporary verification port, so that the operation port can filter viruses and will not filter useful data, thereby ensuring the security of transmission while ensuring normal data transmission. A data restriction allocation mechanism is formed for the operation port to balance the data load between the feature port and the operation port, so that the data of each port is kept within a reasonable range, avoiding excessive load on a single port and affecting its service life. In addition, redundant detection is performed on the switch port to effectively reduce the redundant paths in the switch port and form a backup path. When an abnormality occurs in the temporary switching path, the backup path is used for assistance, thereby enhancing the fault tolerance of the port. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 A schematic flow chart of a high-stability port expansion method for a switch according to the present invention;

[0065] Figure 2 A schematic diagram of a process of verifying a temporary verification port using a network connection setup of a network adapter of a switch and a virtual machine partition according to the present invention;

[0066] Figure 3 A schematic diagram of a flow chart of assigning a port type to an operation port when creating an operation port of the present invention;

[0067] Figure 4 It is a flow chart of a mechanism for allocating data restrictions on operating ports according to the present invention;

[0068] Figure 5 A schematic diagram of a flow chart of establishing at least one temporary switching path between an originator and a target receiver of a data frame according to the present invention;

[0069] Figure 6 A schematic diagram of a redundancy detection process for a switch port according to the present invention;

[0070] Figure 7 The figure is a flow chart of the automatic path switching mechanism formed at the switch port of the present invention. DETAILED DESCRIPTION

[0071] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are only examples, and those skilled in the art may think of other obvious variations.

[0072] Reference Figure 1 As shown, a high-stability port expansion method for a switch includes:

[0073] Setting at least one temporary authentication port, the temporary authentication port adopting a different authentication mechanism, and authenticating the temporary authentication port using the setting of the network connection between the switch and the network adapter of the virtual machine partition;

[0074] After the verification is completed, the temporary verification port is deleted, and at least one operation port is created. The operation port is used to replace the temporary verification port that has passed the verification. The operation port uses the verification mechanism of the temporary verification port.

[0075] When creating an operation port, assign a port type to the operation port;

[0076] Acquire the characteristic ports created by the switch, plan the operation ports, and form a data restriction allocation mechanism for the operation ports. The data restriction allocation mechanism balances the data load between the characteristic ports and the operation ports. Both the characteristic ports and the operation ports are switch ports.

[0077] Match the MAC address of the connected switch with the operation port and store it in the MAC table;

[0078] The switch stores the MAC address in the internal address table and establishes at least one temporary switching path between the originator and the target receiver of the data frame. The data frame reaches the address of the target receiver from the address of the originator through the temporary switching path.

[0079] Perform redundancy detection on the switch port, and when the switch includes redundant paths, delete the redundant paths. When the deletion is completed, half of the temporary switching paths are used as backup paths;

[0080] A path automatic switching mechanism is formed at the switch port. When the switch port performs data transmission, a temporary switching path is used for transmission. When the temporary switching path is abnormal, the path automatic switching mechanism switches the transmission path to a backup path.

[0081] Reference Figure 2 As shown, the setup of a network connection using a switch to a network adapter of a virtual machine partition to verify the temporary verification port includes the following steps:

[0082] Obtain a sample data set for testing, where the sample data set is divided into an illegal data set and a legal data set, wherein the illegal data set consists of virus data;

[0083] Obtaining a ratio of illegal data sets completing network connections between the switch and the network adapter of the virtual machine partition through the temporary verification port as a first ratio;

[0084] Obtaining a ratio of the legitimate data set completing the network connection between the switch and the network adapter of the virtual machine partition through the temporary verification port as a second ratio;

[0085] When the first ratio is less than the first preset ratio and the second ratio is greater than the second preset ratio, the temporary verification port passes the verification, if not, the temporary verification port fails the verification;

[0086] Temporary authentication ports use different authentication mechanisms. Sample data sets are used to test the authentication mechanisms. The authentication mechanism required by the switch is able to filter viruses but hardly filters the rest of the data. Therefore, the authentication mechanism of the verified temporary authentication port is selected. When creating an operation port, the operation port uses the authentication mechanism of the verified temporary authentication port.

[0087] Reference Figure 3 As shown in the figure, when creating an operation port, assigning a port type to the operation port includes the following steps:

[0088] Get the data flow upper limit of the operation port;

[0089] Get the data flow range of recognized ports, registered ports and private ports;

[0090] Obtaining a calibrated port including a data flow upper limit of the operation port as the type of the operation port, wherein the calibrated port is one of a recognized port, a registered port, and a private port;

[0091] Assign the type of the calibration port to the operation port;

[0092] There is an upper limit on the data flow of the operation port. Different types of ports have different upper limits on the data passing through. Therefore, the type of the operation port is determined according to the upper limit of the data flow of the operation port, and the corresponding type is assigned to the operation port.

[0093] Reference Figure 4 As shown, forming a data restriction allocation mechanism for an operation port includes the following steps:

[0094] Get the data flow upper limit of the operation port;

[0095] Monitor the data flow of the operation port to obtain the real-time data flow of the operation port;

[0096] Get the data flow upper limit of the characteristic port;

[0097] Monitor the data flow of the characteristic port to obtain the real-time data flow of the characteristic port;

[0098] The data flow upper limit is multiplied by a preset value to obtain a check part, wherein the preset value is less than one;

[0099] Acquire a characteristic port whose data real-time flow does not exceed the verification part as the target characteristic port, and acquire the data margin of the target characteristic port, wherein the data margin of the target characteristic port is equal to the verification part of the target characteristic port minus the data real-time flow of the target characteristic port;

[0100] When the proportion of the real-time data flow of the operation port to the upper limit of the data flow is greater than the preset value, the part of the real-time data flow of the operation port that exceeds the check is used as the part to be allocated;

[0101] Allocate the part to be allocated to the target feature port, and the amount of data of the part to be allocated obtained by the target feature port is less than the data surplus of the target feature port;

[0102] The operation port forms a data limit allocation mechanism to balance the load between the operation port and the feature port. The operation port has a data flow upper limit, but the operation port cannot run at full load. Therefore, when the data flow upper limit is not reached, the data needs to be diverted to the feature port with a smaller load, and then the load is balanced to ensure that the load of each port is within a reasonable range.

[0103] Reference Figure 5 As shown, establishing at least one temporary switching path between the originator and the target receiver of the data frame includes the following steps:

[0104] Acquire a MAC address consistent with the originator address of the data frame from the MAC address of the connected switch as the first MAC address;

[0105] Obtaining a MAC address consistent with the target receiver address of the data frame from the MAC address of the connected switch as the second MAC address;

[0106] Acquire an operation port corresponding to the first MAC address as a first operation port;

[0107] Acquire an operation port corresponding to the second MAC address as the second operation port;

[0108] Establishing a temporary switching path in the order of the first MAC address to the first operating port to the second operating port to the second MAC address;

[0109] The purpose of establishing at least one temporary switching path is to perform data transmission. The switch serves as a data transfer device. When the switch is connected to the first MAC address and the second MAC address, a temporary switching path can be formed through transfer to connect the first MAC address and the second MAC address, and data can be transmitted between the first MAC address and the second MAC address.

[0110] Reference Figure 6 As shown in FIG. 1 , redundancy detection of a switch port includes the following steps:

[0111] Acquire a temporary switching path from the first MAC address to the first operating port to the second operating port to the second MAC address as a characteristic temporary switching path from the first MAC address to the second MAC address;

[0112] Obtain the data flow limit from the first MAC address to the second MAC address;

[0113] Obtaining the accumulated data flow of the characteristic temporary switching path;

[0114] When the accumulated data traffic exceeds the preset multiple of the data traffic limit, a redundant path exists on the switch port;

[0115] Since there is a redundant situation in establishing at least one temporary switching path, it is necessary to delete the path, otherwise, the redundant path will increase the operating pressure of the switch. When deleting, it is ensured that the remaining path can complete data transmission.

[0116] When the switch includes a redundant path, performing redundant path deletion includes the following steps:

[0117] At least one characteristic temporary switching path of the switch port is deleted one by one until the accumulated data flow of the characteristic temporary switching path is less than a preset multiple of the data flow limit, and the deleted characteristic temporary switching path is used as a redundant path.

[0118] Reference Figure 7 As shown, forming a path automatic switching mechanism on a switch port includes the following steps:

[0119] forming a disconnected portion in the backup path, the disconnected portion being a switching path, and the switching path being in a disconnected state;

[0120] Match the backup path and the temporary switching path corresponding to the same MAC address;

[0121] Perform traffic detection at different locations in the temporary switching path;

[0122] When the traffic at different locations in the temporary switching path is different, the temporary switching path is abnormal;

[0123] When the temporary switching path is abnormal, the state of the switching path of the backup path corresponding to the temporary switching path is changed to closed;

[0124] The backup path and the temporary switching path are connected to the same MAC address, so both can complete the same data transmission, but the backup path is broken. When the temporary switching path is normal, it remains broken, and when the temporary switching path is abnormal, it is closed to start data transmission. Since the backup path does not usually transmit data, it will not be damaged and can always transmit data normally.

[0125] The principle of temporary switching path detection is that during normal data transmission, the flow rate at each location is consistent, but when the flow rates at different locations are different, it indicates that an abnormality has occurred somewhere.

[0126] A high-stability port expansion system for a switch, used to implement the above-mentioned high-stability port expansion method for a switch, comprising:

[0127] A temporary verification module, wherein the temporary verification module sets at least one temporary verification port and verifies the temporary verification port using the setting of the network connection between the switch and the network adapter of the virtual machine partition;

[0128] A port creation module, wherein the port creation module deletes the temporary verification port, creates at least one operation port, and uses the operation port to replace the temporary verification port that has passed the verification;

[0129] A port type allocation module, wherein the port type allocation module allocates a port type to an operation port;

[0130] A port planning module, which performs operation port planning and forms a data restriction allocation mechanism for the operation ports;

[0131] An address association module, wherein the address association module associates the MAC address of the connected switch with the operation port and stores the corresponding address in a MAC table;

[0132] a path establishment module, the path establishment module establishing at least one temporary switching path between an originator and a target receiver of a data frame;

[0133] A redundancy detection module, wherein the redundancy detection module performs redundancy detection on the switch port, and when the switch includes a redundant path, deletes the redundant path, and when the deletion is completed, uses half of the temporary switching path as a backup path;

[0134] The path switching module forms an automatic path switching mechanism at the switch port. When the switch port transmits data, a temporary switching path is used for transmission. When the temporary switching path is abnormal, the automatic path switching mechanism switches the transmission path to a backup path.

[0135] The working process of the high stability port expansion system for switches is as follows:

[0136] Step 1: The temporary verification module sets at least one temporary verification port, and the temporary verification port adopts different verification mechanisms, and verifies the temporary verification port by using the settings of the network connection between the switch and the network adapter of the virtual machine partition;

[0137] Step 2: After the verification is completed, the port creation module deletes the temporary verification port, creates at least one operation port, and uses the operation port to replace the temporary verification port that has passed the verification. The operation port uses the verification mechanism of the temporary verification port.

[0138] Step 3: When creating an operation port, the port type assignment module assigns a port type to the operation port;

[0139] Step 4: The port planning module obtains the characteristic ports created by the switch, performs operation port planning, and forms a data restriction allocation mechanism for the operation port. The data restriction allocation mechanism balances the data load between the characteristic ports and the operation ports.

[0140] Step 5: The address association module associates the MAC address of the connected switch with the operation port and stores it in the MAC table;

[0141] Step 6: The switch stores the MAC address in the internal address table, and the path establishment module establishes at least one temporary switching path between the originator and the target receiver of the data frame, and the data frame reaches the address of the target receiver from the address of the originator through the temporary switching path;

[0142] Step 7: The redundancy detection module performs redundancy detection on the switch port. When the switch includes a redundant path, the redundant path is deleted. When the deletion is completed, half of the temporary switching paths are used as backup paths.

[0143] Step 8: The path switching module forms an automatic path switching mechanism at the switch port. When the switch port transmits data, a temporary switching path is used for transmission. When the temporary switching path is abnormal, the automatic path switching mechanism switches the transmission path to a backup path.

[0144] Furthermore, the present solution also proposes a storage medium on which a computer-readable program is stored. When the computer-readable program is called, the above-mentioned high-stability port expansion method for a switch is executed.

[0145] It is understandable that the storage medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; an optical medium, such as a DVD; or a semiconductor medium, such as a solid state drive (SSD).

[0146] In summary, the advantages of the present invention are: by setting a temporary verification module, a port planning module, a redundant detection module and a path switching module, an operation port is used to replace a verified temporary verification port, and the operation port follows the verification mechanism of the temporary verification port, so that the operation port can filter viruses and will not filter useful data, thereby ensuring the security of transmission while ensuring normal data transmission, forming a data restriction allocation mechanism for the operation port, balancing the data load between the feature port and the operation port, so that the data of each port is kept within a reasonable range, avoiding excessive load on a single port and affecting the service life, in addition, redundant detection is performed on the switch port, effectively reducing the redundant paths in the switch port, and a backup path can be formed. When an abnormality occurs in the temporary switching path, the backup path is used for assistance, thereby enhancing the fault tolerance of the port.

[0147] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions only describe the principles of the present invention. The present invention may be subject to various changes and improvements without departing from the spirit and scope of the present invention. These changes and improvements fall within the scope of the present invention. The scope of protection claimed by the present invention is defined by the attached claims and their equivalents.

Claims

1. A high-stability port expansion method for a switch, characterized in that: include: Setting at least one temporary authentication port, the temporary authentication port adopting a different authentication mechanism, and authenticating the temporary authentication port using the setting of the network connection between the switch and the network adapter of the virtual machine partition; After the verification is completed, the temporary verification port is deleted, and at least one operation port is created. The operation port is used to replace the temporary verification port that has passed the verification. The operation port uses the verification mechanism of the temporary verification port. When creating an operation port, assign a port type to the operation port; Acquire the characteristic ports created by the switch, plan the operation ports, and form a data restriction allocation mechanism for the operation ports. The data restriction allocation mechanism balances the data load between the characteristic ports and the operation ports. Both the characteristic ports and the operation ports are switch ports. Match the MAC address of the connected switch with the operation port and store it in the MAC table; The switch stores the MAC address in the internal address table and establishes at least one temporary switching path between the originator and the target receiver of the data frame. The data frame reaches the address of the target receiver from the address of the originator through the temporary switching path. Perform redundancy detection on the switch port, and when the switch includes redundant paths, delete the redundant paths. When the deletion is completed, half of the temporary switching paths are used as backup paths; An automatic path switching mechanism is formed at the switch port. When the switch port performs data transmission, a temporary switching path is used for transmission. When the temporary switching path is abnormal, the automatic path switching mechanism switches the transmission path to a backup path. The data restriction allocation mechanism for the operation port includes the following steps: Get the data flow upper limit of the operation port; Monitor the data flow of the operation port to obtain the real-time data flow of the operation port; Get the data flow upper limit of the characteristic port; Monitor the data flow of the characteristic port to obtain the real-time data flow of the characteristic port; The data flow upper limit is multiplied by a preset value to obtain a check part, wherein the preset value is less than one; Acquire a characteristic port whose data real-time flow does not exceed the verification part as the target characteristic port, and acquire the data margin of the target characteristic port, wherein the data margin of the target characteristic port is equal to the verification part of the target characteristic port minus the data real-time flow of the target characteristic port; When the proportion of the real-time data flow of the operation port to the upper limit of the data flow is greater than the preset value, the part of the real-time data flow of the operation port that exceeds the check is used as the part to be allocated; The part to be allocated is allocated to the target feature port, and the amount of data of the part to be allocated obtained by the target feature port is less than the data margin of the target feature port.

2. A high stability port expansion method for a switch according to claim 1, characterized in that: The verification of the temporary verification port using the setting of the network connection between the switch and the network adapter of the virtual machine partition comprises the following steps: Obtain a sample data set for testing, where the sample data set is divided into an illegal data set and a legal data set, wherein the illegal data set consists of virus data; Obtaining a ratio of illegal data sets completing network connections between the switch and the network adapter of the virtual machine partition through the temporary verification port as a first ratio; Obtaining a ratio of the legitimate data set completing the network connection between the switch and the network adapter of the virtual machine partition through the temporary verification port as a second ratio; When the first ratio is less than the first preset ratio and the second ratio is greater than the second preset ratio, the temporary verification port passes the verification; otherwise, the temporary verification port fails the verification.

3. A high stability port expansion method for a switch according to claim 2, characterized in that: When creating the operation port, assigning a port type to the operation port includes the following steps: Get the data flow upper limit of the operation port; Get the data flow range of recognized ports, registered ports and private ports; Obtaining a calibrated port including a data flow upper limit of the operation port as the type of the operation port, wherein the calibrated port is one of a recognized port, a registered port, and a private port; Assign the type of the calibration port to the operation port.

4. A high stability port expansion method for a switch according to claim 3, characterized in that: The step of establishing at least one temporary switching path between the originator and the target receiver of the data frame comprises the following steps: Acquire a MAC address consistent with the originator address of the data frame from the MAC address of the connected switch as the first MAC address; Obtaining a MAC address consistent with the target receiver address of the data frame from the MAC address of the connected switch as the second MAC address; Acquire an operation port corresponding to the first MAC address as a first operation port; Acquire an operation port corresponding to the second MAC address as the second operation port; A temporary switching path is established in the order of the first MAC address to the first operating port to the second operating port to the second MAC address.

5. A high stability port expansion method for a switch according to claim 4, characterized in that: The redundancy detection of the switch port comprises the following steps: Acquire a temporary switching path from the first MAC address to the first operating port to the second operating port to the second MAC address as a characteristic temporary switching path from the first MAC address to the second MAC address; Obtain the data flow limit from the first MAC address to the second MAC address; Obtaining the accumulated data flow of the characteristic temporary switching path; When the accumulated data traffic exceeds the preset multiple of the data traffic limit, a redundant path exists on the switch port.

6. A high-stability port expansion method for a switch according to claim 5, characterized in that: When the switch includes a redundant path, deleting the redundant path includes the following steps: At least one characteristic temporary switching path of the switch port is deleted one by one until the accumulated data flow of the characteristic temporary switching path is less than a preset multiple of the data flow limit, and the deleted characteristic temporary switching path is used as a redundant path.

7. A high stability port expansion method for a switch according to claim 6, characterized in that: The automatic path switching mechanism formed on the switch port includes the following steps: forming a disconnected portion in the backup path, the disconnected portion being a switching path, and the switching path being in a disconnected state; Match the backup path and the temporary switching path corresponding to the same MAC address; Perform traffic detection at different locations in the temporary switching path; When the traffic at different locations in the temporary switching path is different, the temporary switching path is abnormal; When the temporary switching path is abnormal, the state of the switching path of the backup path corresponding to the temporary switching path is modified to closed.

8. A high-stability port expansion system for a switch, used to implement the high-stability port expansion method for a switch as claimed in any one of claims 1 to 7, characterized in that: include: A temporary verification module, wherein the temporary verification module sets at least one temporary verification port and verifies the temporary verification port using the setting of the network connection between the switch and the network adapter of the virtual machine partition; A port creation module, wherein the port creation module deletes the temporary verification port, creates at least one operation port, and uses the operation port to replace the temporary verification port that has passed the verification; A port type allocation module, wherein the port type allocation module allocates a port type to an operation port; A port planning module, which performs operation port planning and forms a data restriction allocation mechanism for the operation ports; An address association module, wherein the address association module associates the MAC address of the connected switch with the operation port and stores the corresponding address in a MAC table; a path establishment module, the path establishment module establishing at least one temporary switching path between an originator and a target receiver of a data frame; A redundancy detection module, wherein the redundancy detection module performs redundancy detection on the switch port, and when the switch includes a redundant path, deletes the redundant path, and when the deletion is completed, uses half of the temporary switching path as a backup path; A path switching module, wherein the path switching module forms an automatic path switching mechanism at the switch port. When the switch port performs data transmission, a temporary switching path is used for transmission. When the temporary switching path is abnormal, the automatic path switching mechanism switches the transmission path to a backup path. The data restriction allocation mechanism for the operation port includes the following steps: Get the data flow upper limit of the operation port; Monitor the data flow of the operation port to obtain the real-time data flow of the operation port; Get the data flow upper limit of the characteristic port; Monitor the data flow of the characteristic port to obtain the real-time data flow of the characteristic port; The data flow upper limit is multiplied by a preset value to obtain a check part, wherein the preset value is less than one; Acquire a characteristic port whose data real-time flow does not exceed the verification part as the target characteristic port, and acquire the data margin of the target characteristic port, wherein the data margin of the target characteristic port is equal to the verification part of the target characteristic port minus the data real-time flow of the target characteristic port; When the proportion of the real-time data flow of the operation port to the upper limit of the data flow is greater than the preset value, the part of the real-time data flow of the operation port that exceeds the check is used as the part to be allocated; The part to be allocated is allocated to the target feature port, and the amount of data of the part to be allocated obtained by the target feature port is less than the data margin of the target feature port.

Citation Information

Patent Citations

  • Load sharing mode selecting method, device and system

    CN102447619A

  • Virtual switch extensibility

    CN103095544A