Cloud application access method and apparatus, electronic device, and storage medium
By configuring the target VRF routing table in the POP node, the target response traffic can be obtained in a single traffic interaction, which solves the latency problem caused by multiple traffic interactions in cloud computing and improves the efficiency and accuracy of cloud application access.
Patent Information
- Application Number
- CN202410279148.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-12
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-03-12
AI Technical Summary
In a cloud computing environment, multiple traffic interactions between an enterprise's local client and multiple cloud applications within the cloud resource pool lead to increased business processing latency.
By configuring the target VRF routing table in the POP node, the target response traffic can be obtained in a single traffic interaction. This includes determining the target VRF routing table, forwarding the service access traffic to the first cloud application, obtaining the first response traffic, forwarding it to the second cloud application, and finally forwarding the target response traffic to the target terminal.
It effectively reduces business processing latency, improves the efficiency and accuracy of traffic interaction, and is suitable for cloud application access in multi-tenant scenarios.
Smart Images

Figure CN118827790B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of cloud computing technology, and specifically to a cloud application access method, apparatus, electronic device, and storage medium. Background Technology
[0002] For customers in industries such as education, healthcare, new retail, industry, and SMEs, with the improvement of cloud applications such as PaaS and SaaS in cloud computing technology, and the deep integration of digital technology and production and operation activities in enterprises, we can accelerate the migration of users' business systems and business data to the cloud resource pool by utilizing network resources that can be accessed everywhere, in order to meet the needs of rapid business launch and dynamic capacity expansion.
[0003] Applications within a cloud resource pool are provided externally as services. Typically, each cloud application is independent of the others. When an enterprise's business system is deployed and designed, there are multiple traffic interactions between the enterprise's local client and multiple cloud applications within the cloud resource pool. After the client traffic is processed by the first cloud application, it is returned to the client, and then the client forwards it to the second cloud application, such as cloud security protection and cloud data storage.
[0004] This approach increases the latency of business processing. Summary of the Invention
[0005] This disclosure aims to at least partially address one of the technical problems in the related art.
[0006] Therefore, the purpose of this disclosure is to provide a cloud application access method, apparatus, electronic device and storage medium that enables a target terminal to obtain target response traffic based on a single traffic interaction, thereby effectively reducing business processing latency.
[0007] To achieve the above objectives, the cloud application access method proposed in the first aspect of this disclosure is applied to a POP node, and the method includes:
[0008] When the target terminal receives the service access traffic of the first cloud application, the target VRF routing table corresponding to the target terminal is determined. The target VRF routing table is used to indicate the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The first cloud application and the second cloud application are associated with each other.
[0009] According to the target VRF routing table, the service access traffic is forwarded to the first cloud application via the first interface to obtain the first response traffic fed back by the first cloud application;
[0010] According to the target VRF routing table, the first response traffic is forwarded to the second cloud application via the second interface to obtain the second response traffic fed back by the second cloud application;
[0011] The target response traffic is obtained based on the second response traffic, and the target response traffic is forwarded to the target terminal based on the target VRF routing table.
[0012] To achieve the above objectives, a cloud application access device is proposed in the second aspect of this disclosure and applied to a POP node. The device includes:
[0013] The determination module is used to determine the target VRF routing table corresponding to the target terminal when it receives the service access traffic of the target terminal to the first cloud application. The target VRF routing table is used to indicate the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The first cloud application and the second cloud application are associated with each other.
[0014] The first traffic forwarding module is used to forward the service access traffic to the first cloud application via the first interface according to the target VRF routing table, so as to obtain the first response traffic fed back by the first cloud application.
[0015] The second traffic forwarding module is used to forward the first response traffic to the second cloud application via the second interface according to the target VRF routing table, so as to obtain the second response traffic fed back by the second cloud application;
[0016] The third traffic forwarding module is used to obtain the target response traffic based on the second response traffic, and forward the target response traffic to the target terminal based on the target VRF routing table.
[0017] The electronic device proposed in the third aspect of this disclosure includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the cloud application access method proposed in the first aspect of this disclosure.
[0018] The fourth aspect of this disclosure provides a non-transitory computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the cloud application access method as proposed in the first aspect of this disclosure.
[0019] A fifth aspect of this disclosure provides a computer program product that, when instructions in the computer program product are executed by a processor, performs a cloud application access method as described in a first aspect of this disclosure.
[0020] The cloud application access method, apparatus, electronic device, and storage medium disclosed herein, when receiving service access traffic from a target terminal for a first cloud application, determine a target VRF routing table corresponding to the target terminal. The target VRF routing table indicates the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application, wherein the first and second cloud applications are service-associated. Based on the target VRF routing table, the service access traffic is forwarded to the first cloud application via the first interface to obtain a first response traffic from the first cloud application. Based on the target VRF routing table, the first response traffic is forwarded to the second cloud application via the second interface to obtain a second response traffic from the second cloud application. Based on the second response traffic, a target response traffic is obtained, and based on the target VRF routing table, the target response traffic is forwarded to the target terminal. Therefore, the target terminal can obtain the target response traffic based on a single traffic interaction, thereby effectively reducing service processing latency.
[0021] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this disclosure. Attached Figure Description
[0022] The above and / or additional aspects and advantages of this disclosure will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, in which:
[0023] Figure 1 This is a flowchart illustrating a cloud application access method according to an embodiment of this disclosure;
[0024] Figure 2 This is a flowchart illustrating a cloud application access method according to another embodiment of this disclosure;
[0025] Figure 3 This is a schematic diagram of the structure of the cloud application access system proposed in this disclosure;
[0026] Figure 4 This is a single-tenant traffic diagram based on the present disclosure;
[0027] Figure 5 This is a multi-tenant traffic diagram based on the present disclosure;
[0028] Figure 6 This is a schematic diagram of tenant service routing design based on the present disclosure;
[0029] Figure 7 This is a schematic diagram of the routing and forwarding rules proposed in this disclosure;
[0030] Figure 8This is a schematic diagram of the structure of a cloud application access device according to an embodiment of this disclosure;
[0031] Figure 9 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation
[0032] Embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are used only to explain this disclosure, and should not be construed as limiting this disclosure. Rather, embodiments of this disclosure include all variations, modifications, and equivalents falling within the spirit and scope of the appended claims.
[0033] Figure 1 This is a flowchart illustrating a cloud application access method proposed in one embodiment of this disclosure.
[0034] It should be noted that the execution subject of the cloud application access method in this embodiment is a cloud application access device. This device can be implemented by software and / or hardware. The device can be configured in an electronic device, which may include, but is not limited to, a terminal, a server, etc. For example, the terminal may be a mobile phone, a PDA, etc.
[0035] like Figure 1 As shown, the cloud application access methods include:
[0036] S101: When the target terminal receives the service access traffic for the first cloud application, determine the target VRF routing table corresponding to the target terminal. The target VRF routing table is used to indicate the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The services of the first cloud application and the second cloud application are associated.
[0037] The target terminal can be a CPE (Customer Premise Equipment) client terminal device, placed on the user side, used to provide broadband Internet access, networking and other services.
[0038] Point of Presence (POP) refers to a device or node that an Internet Service Provider (ISP) sets up within its network. This device or node is typically located at the edge of the ISP's network and is used to aggregate the business traffic of the Customer Premises Equipment (CPE).
[0039] The first cloud application can refer to the first cloud application that the target terminal is about to access. The second cloud application can refer to an application that has a business relationship with the first cloud application.
[0040] Among them, business access traffic can refer to the access traffic of the target terminal to cloud applications.
[0041] Among them, VRF (Virtual Routing and Rorwarding) achieves data or service isolation by creating multiple routing tables on a Layer 3 forwarding device.
[0042] In other words, in this embodiment of the present disclosure, the target VRF routing table corresponding to the target terminal can be pre-configured in the POP node, thereby providing a reliable basis for subsequent traffic forwarding.
[0043] Optionally, in some embodiments, when multiple target terminals receive service access traffic for the first cloud application, a VRF index is determined based on the tunnel interface between the POP node and the target terminal, and a target VRF routing table corresponding to each target terminal is determined based on the VRF index. Therefore, the target VRF routing table corresponding to each target terminal can be accurately and quickly determined from multiple VRF routing tables, thereby effectively improving the reliability of the cloud application access logic.
[0044] In other words, this embodiment of the disclosure allows for the configuration of a target VRF routing table corresponding to each tenant in the POP node for multi-tenant scenarios. Multi-tenancy refers to a single application running on a server that can simultaneously serve multiple enterprises, with each enterprise's users using a customized version of the application. This involves sharing the application itself as a resource, rather than an enterprise being limited to using only one server or a single application running on a single server.
[0045] S102: Based on the target VRF routing table, forward the service access traffic to the first cloud application via the first interface to obtain the first response traffic from the first cloud application.
[0046] The first response traffic can refer to the traffic that is processed by the first cloud application and then fed back to the POP node.
[0047] In other words, in this embodiment of the disclosure, the target VRF routing table contains forwarding rules that forward service access traffic to the first cloud application, so as to achieve accurate processing of service access traffic.
[0048] S103: Based on the target VRF routing table, forward the first response traffic to the second cloud application via the second interface to obtain the second response traffic fed back by the second cloud application.
[0049] The second response traffic can refer to the traffic fed back after the first response traffic has been processed by the second cloud application.
[0050] In other words, in this embodiment of the present disclosure, the target VRF routing table also includes forwarding rules for forwarding the first response traffic to the second cloud application, so as to achieve accurate processing of service access traffic.
[0051] S104: Obtain the target response traffic based on the second response traffic, and forward the target response traffic to the target terminal based on the target VRF routing table.
[0052] Optionally, in some embodiments, the first VRF routing table and the second VRF routing table are bidirectional routing and forwarding tables for service traffic.
[0053] Five-tuple traffic forwarding rules refer to traffic forwarding rules set up on network devices (such as routers and firewalls) based on five-tuple information. A five-tuple includes the source IP address, destination IP address, source port number, destination port number, and transport protocol (usually TCP or UDP). By analyzing these five elements, network devices can determine how to process data packets flowing through them according to pre-defined rules.
[0054] In this embodiment, upon receiving service access traffic from a target terminal to a first cloud application, a target VRF routing table corresponding to the target terminal is determined. This target VRF routing table indicates the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The first and second cloud applications are associated with each other. Based on the target VRF routing table, the service access traffic is forwarded to the first cloud application via the first interface to obtain first response traffic from the first cloud application. Based on the target VRF routing table, the first response traffic is forwarded to the second cloud application via the second interface to obtain second response traffic from the second cloud application. The target response traffic is then obtained based on the second response traffic and forwarded to the target terminal based on the target VRF routing table. This allows the target terminal to obtain the target response traffic based on a single traffic interaction, effectively reducing service processing latency.
[0055] Optionally, in some embodiments, the first cloud application and the second cloud application belong to a cloud resource pool, and the cloud resource pool contains one or more second cloud applications. The target VRF routing table includes a first VRF routing table and a second VRF routing table, which can be generated as follows: determining the business logic relationship between the first cloud application and the second cloud application; configuring the first VRF routing table corresponding to the first cloud application and the second VRF routing table corresponding to each second cloud application according to the business logic relationship. The first VRF routing table is used to indicate the traffic forwarding rules between the target terminal and the first cloud application, and the second VRF routing table is used to indicate the traffic forwarding rules between the second cloud application and the first cloud application, or between the second cloud application and different second cloud applications. Therefore, VRF routing tables corresponding to the first cloud application and the second cloud application can be generated accurately and quickly based on the business logic relationship, enabling POP nodes to flexibly execute corresponding traffic forwarding rules in multi-cloud application scenarios.
[0056] Figure 2 This is a flowchart illustrating a cloud application access method proposed in another embodiment of this disclosure.
[0057] like Figure 2 As shown, the cloud application access methods include:
[0058] S201: When receiving service access traffic from the target terminal for the first cloud application, determine the target VRF routing table corresponding to the target terminal. The target VRF routing table is used to indicate the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The services of the first cloud application and the second cloud application are associated.
[0059] S202: Based on the target VRF routing table, forward the service access traffic to the first cloud application via the first interface to obtain the first response traffic from the first cloud application.
[0060] S203: Based on the target VRF routing table, forward the first response traffic to the second cloud application via the second interface to obtain the second response traffic fed back by the second cloud application.
[0061] The descriptions of S201-S203 can be found in the above embodiments, and will not be repeated here.
[0062] S204: Based on the business logic relationship, determine whether there is a third cloud application in the cloud resource pool that receives and processes the second response traffic, wherein the third cloud application is either the first cloud application or the second cloud application.
[0063] It is understood that in this embodiment of the present disclosure, after the second response traffic is obtained through the second cloud application, the second response traffic may still need to be processed by other cloud applications to obtain the target response traffic required by the target terminal. Therefore, in this embodiment of the present disclosure, it can be determined whether there is a third cloud application in the cloud resource pool that receives and processes the second response traffic according to the business logic relationship, thereby providing a reliable execution basis for obtaining the target response traffic in the future.
[0064] S205: If a third cloud application exists in the cloud resource pool, the second response traffic is forwarded to the third cloud application according to the second VRF routing table to obtain new second response traffic.
[0065] In other words, in this embodiment of the present disclosure, when there is a third cloud application in the cloud resource pool that receives and processes the second response traffic, the second response traffic can be forwarded to the third cloud application based on the second VRF routing table corresponding to the second cloud application, thereby ensuring the reliability of the business processing logic.
[0066] S206: If no third cloud application exists in the cloud resource pool, the second response traffic will be used as the target response traffic.
[0067] It is understood that in this embodiment of the disclosure, when there is no third cloud application in the cloud resource pool, it indicates that the processing flow of the traffic corresponding to the cloud application has ended. Therefore, the second response traffic can be directly used as the target response traffic.
[0068] In other words, in this embodiment of the present disclosure, after receiving the second response traffic from the second cloud application, it can determine whether a third cloud application exists in the cloud resource pool to receive and process the second response traffic, where the third cloud application is either the first cloud application or the second cloud application, based on the business logic relationship. If a third cloud application exists in the cloud resource pool, the second response traffic is forwarded to the third cloud application according to the second VRF routing table to obtain new second response traffic. If no third cloud application exists in the cloud resource pool, the second response traffic is used as the target response traffic. This ensures the adaptability between the traffic forwarding process and the business logic, thereby guaranteeing the accuracy of the obtained target response traffic.
[0069] S207: Forward the target response traffic to the target terminal based on the target VRF routing table.
[0070] For a detailed description of S207, please refer to the above embodiments, which will not be repeated here.
[0071] In this embodiment, based on business logic relationships, it is determined whether a third cloud application exists in the cloud resource pool to receive and process the second response traffic. This third cloud application can be either the first or second cloud application. If a third cloud application exists in the cloud resource pool, the second response traffic is forwarded to the third cloud application according to the second VRF routing table to obtain new second response traffic. If no third cloud application exists in the cloud resource pool, the second response traffic is used as the target response traffic. This ensures the adaptability between the traffic forwarding process and the business logic, thereby guaranteeing the accuracy of the obtained target response traffic.
[0072] Optionally, in some embodiments, the first VRF routing table and the second VRF routing table are bidirectional routing and forwarding tables for service traffic. This allows for the specification of specific inbound application traffic paths when adding bypass cloud-based industry applications to network nodes, avoiding user service routing conflicts and ensuring normal forwarding of service traffic.
[0073] Based on the above embodiments, such as Figure 3 As shown, Figure 3 This is a schematic diagram of the cloud application access system proposed in this disclosure. During the process of industry customer data entering the cloud, it is divided into two parts: the network side and the cloud side. The network side is responsible for traffic scheduling, while the cloud side is responsible for business processing. Taking cloud security and cloud databases as examples, the CPE devices on the user side and the POP nodes in the metropolitan area network belong to the network side, while the computing power, storage, and other resources provided by the cloud resource pool to support cloud applications belong to the cloud side. The network and cloud are built separately, and their tenant identifiers are also different. The network side typically distinguishes tenants by the dial-up account of the customer device. VPNs (i.e., VRFs) are used on the network devices to isolate tenant routes. Different tenants are planned within different VPN instances. Cloud-side applications use accounts assigned by the cloud management system. Each account corresponds to an independent namespace on the cloud to access the VPC within the cloud. Typically, the VPC within the cloud uses VxLAN technology to distinguish different tenant networks and differentiate the cloud computing resources used by tenants. Most applications do not have the concept of VRF; therefore, the issue of multi-tenant address conflicts is not considered.
[0074] The POP node is configured with a public IP address or a VPN private IP address. The CPE uses PPPoE to access the Internet or VPN network. The CPE connects user traffic to the POP through the operator's network. The POP and cloud applications are connected via static routing. As a network-side device, the POP node can well support network-side capabilities such as IP, routing, QoS, and VPN. The five-tuple is used to implement user traffic scheduling. When a message from a user accessing a cloud application is received through the tunnel, the message is forwarded to the corresponding cloud application according to the pre-configured forwarding rules.
[0075] The SDN controller is responsible for controlling the forwarding policies of POP nodes. Based on the tenant's cloud service requirements, the SDN controller manages the tenant routing tables, ports, and cloud application integration methods on the POP. If there are any changes to the user's cloud applications, the forwarding policies of tenants on the POP can be flexibly adjusted through the SDN controller.
[0076] When a cloud resource pool serves only one tenant, such as Figure 4 As shown, Figure 4 This is based on the single-tenant traffic diagram proposed in this disclosure. In the scenario of an enterprise accessing a private cloud, network-side IP addresses, bandwidth, and other resources, as well as cloud-side applications, only provide services to the current enterprise. The enterprise can plan network and cloud resources in a unified manner. At this time, there is no problem of conflict between network-side and cloud-side IP addresses and other resources. On the POP node, the interface used to access the CPE, as well as the network interface that interfaces with cloud applications, can all be planned in a single routing table. That is, on the POP node, the tunnel interface that communicates with the CPE, the VLAN logical interface or physical interface that connects to different cloud applications, and the BGP routing protocol are all configured in the default routing table of the POP node.
[0077] by Figure 4 For example, consider two cloud applications: cloud security and a database. Using POP nodes, a single inbound traffic from the user's CPE enables secure access to the database. Traffic accessing the cloud security application is routed from the CPE to the POP node. At the POP node, the traffic connects to the cloud security application via a logical interface. The cloud security application filters the traffic before sending it back to the POP node. The POP node, based on the five-tuple traffic forwarding rules, forwards the traffic to the cloud database PaaS application. After processing, the traffic is sent back to the POP node, which then returns the processed data to the user on the CPE side according to the forwarding rules.
[0078] Multi-tenant processing logic: Cloud applications typically run on multiple instances, with different tenants using different cloud application instances to provide services. When multiple tenants access the business flow of the cloud application, the aforementioned forwarding logic cannot be used due to IP address conflicts in the tenant networks.
[0079] POP node data forwarding plane supports multiple VRF routing tables. User traffic is based on VRF to achieve multi-tenant traffic scheduling. Different tenants' traffic is allocated to different VRF routing tables, so that one POP instance can be provided to multiple users at the same time (different users have the same IP address, such as 192.168.0.0 / 24) to access different cloud application services and avoid resource conflicts such as IP addresses within the user network.
[0080] When cloud security and cloud databases built on a cloud resource pool provide services to multiple different tenants, and each tenant's PC uses cloud security services to filter out threatening traffic before requesting data read operations from the cloud database, the user's data flow is shown in the following diagram: [Diagram showing the forwarding traffic of cloud applications in the network-side POP devices and cloud resource pool]. Figure 5 As shown, Figure 5 This is a multi-tenant traffic diagram based on the present disclosure.
[0081] The tenant traffic scheduling scheme on the Point of Premises (POP) involves configuring VRF routing tables for tenants and applications on the POP. The routing table configuration is centrally managed by the SDN controller. When a tenant needs to add or remove cloud applications, only the tenant and service routes on the POP need to be adjusted to establish network connectivity between the user side and the cloud side. Figure 6 As shown, Figure 6 This is a schematic diagram of tenant service routing design proposed in this disclosure. The routing rules of POP nodes and cloud applications are configured and adjusted to enable tenants to access different cloud applications.
[0082] Cloud application, cloud security, and cloud database services are designed for multi-instance deployment, with one instance allocated to each tenant to avoid conflicts between tenants. Routing and forwarding rules on POP and cloud applications are as follows: Figure 7 As shown, Figure 7 According to the routing and forwarding rule diagram proposed in this disclosure, traffic is forwarded in different VRFs corresponding to the tenants, and through the POP node, which is the channel between the user side and different cloud applications, the routing tables of different tenants are isolated to avoid resource planning conflicts.
[0083] In this disclosure, the default routing table can be configured when the POP device is first put into service. Subsequent additions and modifications to the default routing table (VRF-0) will not affect the default routing table. When the CPE accesses the POP via tunnel, a public IP address is usually configured on the G1 / 0 / 1 interface of the POP. The default routing table points to the Internet gateway device connected to the CPE and is used to enable tunnel access for the user CPE. All underlying routes of the CPE connected to the POP use this default routing table.
[0084] In this disclosure, when user services are activated, after the SDN controller receives a work order from the upper-layer business system, it creates a tenant routing table VRF (VRF-1) on the POP through the netconf protocol. All CPE traffic under the tenant enters the tenant's network, generating a routing table to the user-side network that points to the interface of the CPE tunnel.
[0085] In this disclosure, a tunnel can be created for each CPE on the POP, and a tunnel interface can be associated with it. A tenant routing table VRF (VRF-1) can be configured on the tunnel interface, and all traffic accessed by the CPE is forwarded within the tenant's routing table. Configuring the tenant VRF avoids conflicts in network planning between different tenants.
[0086] In this disclosure, a routing table (VRF) corresponding to a service can be created on the POP based on the cloud applications used by the tenant. The creation principle is that the tenant's VRF is associated with the first application, and a new routing table (VRF) is added to the POP for each additional application.
[0087] In this disclosure, the POP communicates with the tenant's cloud applications through a VLAN logical interface. Different applications are configured with different inbound and outbound logical interfaces, each corresponding to a different routing table VRF.
[0088] In this disclosure, the routing table design for tenants on the POP involves receiving CPE traffic through the tunnel interface in VRF-1 and configuring a default route pointing to the first cloud application via the outbound logical interface interconnected with it. After the cloud application finishes processing, a default route is configured to point to the first cloud application's inbound logical interface in VRF-2. A default route is then configured in VRF-2 to point to the second cloud application via the logical interface interconnected with it within VRF-2.
[0089] This disclosure leverages the traffic scheduling capabilities of POP to flexibly connect to various cloud applications, enabling flexible scheduling of user services and meeting the requirements of deep tenant-based integration between the network and the cloud. When POP is configured with multiple tenants, upon receiving a message from the CPE, it looks up the routing table based on the VRF index of the interface to find the routing table corresponding to that tenant and performs the appropriate forwarding processing.
[0090] Based on the above embodiments, this disclosure includes at least the following advantages:
[0091] (1) By scheduling the tenant service routing table on the POP node, without modifying the forwarding packet structure, when users use multiple cloud applications that are related in the cloud, the inbound traffic is prevented from interacting with the user's local network multiple times.
[0092] (2) Establish a bidirectional routing table for business traffic in the POP node. This method can specify the application traffic path to the cloud when adding bypass cloud industry applications in the network node, avoid user business routing conflicts, and realize normal forwarding of business traffic.
[0093] Figure 8 This is a schematic diagram of the structure of a cloud application access device proposed in an embodiment of the present disclosure.
[0094] like Figure 8As shown, the cloud application access device 80 includes:
[0095] The determination module 801 is used to determine the target VRF routing table corresponding to the target terminal when it receives the service access traffic of the target terminal to the first cloud application. The target VRF routing table is used to indicate the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The services of the first cloud application and the second cloud application are associated.
[0096] The first traffic forwarding module 802 is used to forward service access traffic to the first cloud application via the first interface according to the target VRF routing table, so as to obtain the first response traffic fed back by the first cloud application.
[0097] The second traffic forwarding module 803 is used to forward the first response traffic to the second cloud application via the second interface according to the target VRF routing table, so as to obtain the second response traffic fed back by the second cloud application;
[0098] The third traffic forwarding module 804 is used to obtain the target response traffic based on the second response traffic and forward the target response traffic to the target terminal based on the target VRF routing table.
[0099] It should be noted that the foregoing explanation of the cloud application access method also applies to the cloud application access device of this embodiment, and will not be repeated here.
[0100] In this embodiment, upon receiving service access traffic from a target terminal to a first cloud application, a target VRF routing table corresponding to the target terminal is determined. This target VRF routing table indicates the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The first and second cloud applications are associated with each other. Based on the target VRF routing table, the service access traffic is forwarded to the first cloud application via the first interface to obtain first response traffic from the first cloud application. Based on the target VRF routing table, the first response traffic is forwarded to the second cloud application via the second interface to obtain second response traffic from the second cloud application. The target response traffic is then obtained based on the second response traffic and forwarded to the target terminal based on the target VRF routing table. This allows the target terminal to obtain the target response traffic based on a single traffic interaction, effectively reducing service processing latency.
[0101] Figure 9 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown. Figure 9 The electronic device 12 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.
[0102] like Figure 9 As shown, the electronic device 12 is represented in the form of a general-purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and bus 18 connecting different system components (including system memory 28 and processing unit 16).
[0103] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.
[0104] Electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 12, including volatile and non-volatile media, removable and non-removable media.
[0105] Memory 28 may include computer system readable media in the form of volatile memory, such as Random Access Memory (RAM) 30 and / or cache memory 32. Electronic device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media (… Figure 9 Not shown; usually referred to as a "hard drive".
[0106] although Figure 9Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disc drive for reading and writing to a removable non-volatile optical disc (e.g., a compact disc read-only memory (CD-ROM), a digital video disc read-only memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. Memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this disclosure.
[0107] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 typically perform the functions and / or methods described in the embodiments of this disclosure.
[0108] Electronic device 12 can also communicate with one or more external devices 14 (e.g., keyboard, pointing device, display 24, etc.), and with one or more devices that enable human interaction with electronic device 12, and / or with any device that enables electronic device 12 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 22. Furthermore, electronic device 12 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 20. As shown, network adapter 20 communicates with other modules of electronic device 12 via bus 18. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0109] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the cloud application access method mentioned in the foregoing embodiments.
[0110] To implement the above embodiments, this disclosure also proposes a non-transitory computer-readable storage medium storing a computer program that, when executed by a processor, implements the cloud application access method as proposed in the foregoing embodiments of this disclosure.
[0111] To implement the above embodiments, this disclosure also proposes a computer program product that, when executed by an instruction processor, performs the cloud application access method as proposed in the foregoing embodiments of this disclosure.
[0112] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.
[0113] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.
[0114] It should be noted that in the description of this disclosure, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this disclosure, unless otherwise stated, "a plurality of" means two or more.
[0115] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of preferred embodiments of this disclosure includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this disclosure pertain.
[0116] It should be understood that various parts of this disclosure can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0117] Those skilled in the art will understand that all or part of the steps of the methods described in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it includes one or a combination of the steps of the method embodiments.
[0118] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.
[0119] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.
[0120] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0121] Although embodiments of the present disclosure have been shown and described above, it is to be understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present disclosure.
Claims
1. A method for accessing cloud applications, characterized in that, Applied to POP nodes, the method includes: When the target terminal receives the service access traffic of the first cloud application, the target VRF routing table corresponding to the target terminal is determined. The target VRF routing table is used to indicate the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The first cloud application and the second cloud application are associated with each other. According to the target VRF routing table, the service access traffic is forwarded to the first cloud application via the first interface to obtain the first response traffic fed back by the first cloud application; According to the target VRF routing table, the first response traffic is forwarded to the second cloud application via the second interface to obtain the second response traffic fed back by the second cloud application; The target response traffic is obtained based on the second response traffic, and the target response traffic is forwarded to the target terminal based on the target VRF routing table.
2. The method as described in claim 1, characterized in that, Also includes: When multiple target terminals receive service access traffic for the first cloud application, a VRF index is determined based on the tunnel interface between the POP node and the target terminal, and a target VRF routing table corresponding to each target terminal is determined based on the VRF index.
3. The method as described in claim 1, characterized in that, The first cloud application and the second cloud application belong to a cloud resource pool, and the cloud resource pool contains one or more of the second cloud applications. The target VRF routing table includes a first VRF routing table and a second VRF routing table, which are generated based on the following method: Determine the business logic relationship between the first cloud application and the second cloud application; Configure the first VRF routing table corresponding to the first cloud application and the second VRF routing table corresponding to each second cloud application according to the business logic relationship. The first VRF routing table is used to indicate the traffic forwarding rules between the target terminal and the first cloud application, and the second VRF routing table is used to indicate the traffic forwarding rules between the second cloud application and the first cloud application or the traffic forwarding rules between the second cloud application and different second cloud applications.
4. The method as described in claim 3, characterized in that, The step of obtaining the target response traffic based on the second response traffic includes: Based on the business logic relationship, determine whether there is a third cloud application in the cloud resource pool that receives and processes the second response traffic, wherein the third cloud application is the first cloud application or the second cloud application; If the third cloud application exists in the cloud resource pool, the second response traffic is forwarded to the third cloud application according to the second VRF routing table to obtain new second response traffic; If the third cloud application is not present in the cloud resource pool, then the second response traffic will be used as the target response traffic.
5. The method as described in claim 1, characterized in that, The target VRF routing table is constructed based on the five-tuple traffic forwarding rules.
6. The method as described in claim 3, characterized in that, The first VRF routing table and the second VRF routing table are bidirectional routing and forwarding tables for service traffic.
7. A cloud application access device, characterized in that, The device, applied to POP nodes, includes: The determination module is used to determine the target VRF routing table corresponding to the target terminal when it receives the service access traffic of the target terminal to the first cloud application. The target VRF routing table is used to indicate the tunnel interface between the POP node and the target terminal, the first interface between the POP node and the first cloud application, and the second interface between the POP node and the second cloud application. The first cloud application and the second cloud application are associated with each other. The first traffic forwarding module is used to forward the service access traffic to the first cloud application via the first interface according to the target VRF routing table, so as to obtain the first response traffic fed back by the first cloud application. The second traffic forwarding module is used to forward the first response traffic to the second cloud application via the second interface according to the target VRF routing table, so as to obtain the second response traffic fed back by the second cloud application; The third traffic forwarding module is used to obtain the target response traffic based on the second response traffic, and forward the target response traffic to the target terminal based on the target VRF routing table.
8. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-6.
9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, in, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-6.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1-6.
Citation Information
Patent Citations
Routing method and apparatus
CN111630817A
Terminal authority control method and device, electronic equipment and storage medium
CN111953599A