Transmission system and method of data

By introducing a first gateway and a second gateway into the data transmission system to encapsulate and decapsulate access messages, the problem of high data transmission costs is solved, and a high-speed, low-latency, stable and secure dedicated connection between the user's local data center and the virtual private cloud in the cloud is realized.

CN118869633BActive Publication Date: 2025-11-21JINAN INSPUR DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411186959.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-27
Publication Date
2025-11-21
Estimated Expiration
2044-08-27

AI Technical Summary

Technical Problem

In existing technologies, when a self-built IDC data center is redundantly interconnected with a cloud dedicated line, the cost of bare optical fiber is high and data exchange is controlled and forwarded by the customer's IDC-side routing equipment, which places high demands on the customer's local equipment, resulting in high data transmission costs.

Method used

The system receives and encapsulates access messages from the physical machine through the first gateway, and then decapsulates them using the dedicated line access switch and the second gateway to establish a tunnel connection from the physical machine to the virtual private cloud, thereby achieving high-speed, low-latency, and stable and secure data transmission.

Benefits of technology

It reduces data transmission costs and establishes a high-speed, low-latency, stable, and secure dedicated connection channel between the user's local data center and the virtual private cloud in the cloud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118869633B_ABST
    Figure CN118869633B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a data transmission system and method, wherein the system comprises: a first gateway configured to receive an access message for accessing a virtual private cloud sent by a physical machine; a private line access switch configured to receive the access message, encapsulate the access message to obtain first encapsulated data, the first encapsulated data comprising the access message, a first tunnel address of the private line access switch and a second tunnel address of a second gateway; and the second gateway configured to decapsulate the first encapsulated data to obtain first decapsulated data, determine a third tunnel address corresponding to the second address included in the first decapsulated data and a tunnel identifier, and send the access data of the physical machine to the virtual private cloud through a target tunnel determined based on the third tunnel address and the tunnel identifier. Through the present application, the problem of high data transmission cost in the related art can be solved, and the effect of reducing data transmission cost is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the computer field, and in particular, to a data transmission system and method. BACKGROUND

[0002] In the related art, to realize the redundant interconnection from a self-built IDC room to a cloud private line transit IDC room, a customer IDC usually pulls a bare optical fiber to a POP node of each room, but the cost of the bare optical fiber is high, and the data interaction is controlled and forwarded by a routing device of the customer IDC, which requires high local device of the customer.

[0003] Therefore, there is a problem of high data transmission cost in the related art.

[0004] To solve the above problems in the related art, no effective solution has been proposed so far. SUMMARY

[0005] Embodiments of the present application provide a data transmission system and method to at least solve the problem of high data transmission cost in the related art.

[0006] According to an embodiment of the present application, a data transmission system is provided, comprising: a first gateway connected with a physical machine, configured to receive an access message for accessing a virtual private cloud sent by the physical machine, wherein the access message comprises a first address of the physical machine and a second address of the virtual private cloud; a private line access switch connected with the first gateway, configured to receive the access message, encapsulate the access message to obtain first encapsulated data, wherein the first encapsulated data comprises the access message, a first tunnel address of the private line access switch, and a second tunnel address of a second gateway; and the second gateway connected with the private line access switch, configured to decapsulate the first encapsulated data to obtain first decapsulated data, determine a third tunnel address and a tunnel identifier corresponding to the second address included in the first decapsulated data, and send access data of the physical machine to the virtual private cloud through a target tunnel determined based on the third tunnel address and the tunnel identifier.

[0007] According to another embodiment of the present application, a data transmission method is provided, comprising: encapsulating a received access message to obtain first encapsulated data, wherein the access message is a message accessed by the first gateway through the virtual private network, the access message comprises a first address of the physical machine and a second address of the virtual private cloud, and the first encapsulated data comprises the access message, a first tunnel address of the dedicated line access switch, and a second tunnel address of the second gateway; sending the first encapsulated data to the second gateway to instruct the second gateway to decapsulate the first encapsulated data to obtain first decapsulated data, determine a third tunnel address corresponding to the second address included in the first decapsulated data and a tunnel identifier, and send access data of the physical machine to the virtual private cloud through a target tunnel determined based on the third tunnel address and the tunnel identifier.

[0008] According to another embodiment of the present application, a data transmission apparatus is provided, comprising: an encapsulation module configured to encapsulate a received access message to obtain first encapsulated data, wherein the access message is a message accessed by the first gateway through the virtual private network, the access message comprises a first address of the physical machine and a second address of the virtual private cloud, and the first encapsulated data comprises the access message, a first tunnel address of the dedicated line access switch, and a second tunnel address of the second gateway; and a transmission module configured to send the first encapsulated data to the second gateway to instruct the second gateway to decapsulate the first encapsulated data to obtain first decapsulated data, determine a third tunnel address corresponding to the second address included in the first decapsulated data and a tunnel identifier, and send access data of the physical machine to the virtual private cloud through a target tunnel determined based on the third tunnel address and the tunnel identifier.

[0009] According to yet another embodiment of the present application, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program, wherein the computer program is configured to execute the steps in any of the method embodiments described above when running.

[0010] According to yet another embodiment of the present application, an electronic device is provided, comprising a memory and a processor, the memory stores a computer program, and the processor is configured to execute the computer program to perform the steps in any of the method embodiments described above.

[0011] According to yet another embodiment of the present application, a computer program product is provided, comprising a computer program, and the computer program is executed by a processor to implement the steps in any of the method embodiments described above.

[0012] According to the data transmission system, the data transmission system comprises a first gateway, a dedicated line access switch and a second gateway, the access message sent by the physical machine and received by the first gateway connected with the physical machine is sent to the dedicated line access switch connected with the first gateway, the switch encapsulates the access message and sends the encapsulated access message to the second gateway, and then the second gateway connected with the dedicated line access switch decapsulates the encapsulated data, so that the access data of the physical machine can be sent to the virtual private cloud, and a high-speed, low-latency, stable and safe exclusive connection channel between the user local data center and the virtual private cloud on the cloud can be built. Therefore, the problem of high data transmission cost in the related art can be solved, and the effect of reducing the data transmission cost is achieved. BRIEF DESCRIPTION OF DRAWINGS

[0013] Figure 1 is a structural schematic diagram of a data transmission system according to an embodiment of the present application;

[0014] Figure 2 is a flowchart of a data transmission method according to an embodiment of the present application.

[0015] Figure 3 is a process schematic diagram of cloud external network access VPC network according to an embodiment of the present application;

[0016] Figure 4 is a process schematic diagram of VPC network internal virtual machine access cloud external physical machine according to an embodiment of the present application;

[0017] Figure 5 is a hardware structure block diagram of a server device of a data transmission method according to an embodiment of the present application;

[0018] Figure 6 is a flowchart of a data transmission method according to an embodiment of the present application. DETAILED DESCRIPTION

[0019] Hereinafter, the embodiments of the present application will be described in detail with reference to the accompanying drawings and in combination with the embodiments.

[0020] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence.

[0021] In the present embodiment, a data transmission system is provided, Figure 1 is a structural schematic diagram of a data transmission system according to an embodiment of the present application, as Figure 1 shown, the data transmission system comprises:

[0022] A first gateway 102 is connected to a physical machine and is used to receive access messages sent by the physical machine to access the virtual private cloud. The access messages include a first address of the physical machine and a second address of the virtual private cloud.

[0023] A leased line access switch 104 is connected to the first gateway and is used to receive the access message, encapsulate the access message to obtain first encapsulation data, the first encapsulation data including the access message, the first tunnel address of the leased line access switch, and the second tunnel address of the second gateway.

[0024] The second gateway 106 is connected to the leased line access switch and is used to decapsulate the first encapsulated data to obtain the first decapsulated data, determine the third tunnel address and tunnel identifier corresponding to the second address included in the first decapsulated data, and send the access data of the physical machine to the virtual private cloud through the target tunnel determined based on the third tunnel address and the tunnel identifier.

[0025] In the above embodiments, a schematic diagram of the data transmission system flow can be found in the appendix. Figure 2 ,like Figure 2 As shown, the data transmission system can include an external cloud network, a carrier VPN network, a leased line access switch, a leased line gateway, and a VPC network. The external cloud network is the first gateway, and the leased line gateway is the second gateway. The external cloud network can divide different tenants through VLANs (Virtual Local Area Networks) to receive access packets sent from physical machines outside the cloud. Here, "cloud" can be a private cloud or a public cloud, representing an application based on cloud computing and cloud services. The switch can forward data according to the CAM (Context Address Memory) table, which can be understood as a mapping table between MAC addresses and switch ports. The physical machine can be an external physical machine carrying the tenant's local data. The Virtual Private Cloud (VPC) is a logically isolated virtual network environment built for cloud resources such as cloud servers, cloud containers, and cloud databases, configured and managed by the user. It can improve the security of user resources and simplify network deployment.

[0026] In the above embodiments, the leased line access switch can be understood as a device combining a cloud leased line and a switch, used to realize the access and conversion between external cloud networks and cloud computing VPC networks, and is mainly configured and maintained by the data center. The second gateway can be a leased line gateway (DGW), which can be understood as a bridge connecting the private network (VPC) and the physical leased line, used to deliver the packets transmitted by the leased line access switch to the VPC.

[0027] In the above embodiments, since the transmission of the message must have detailed source and destination addresses, the receiving end device will receive the message only after comparing the destination address in the message with its own address, and thus encapsulation and decapsulation will be involved in the transmission process. Encapsulation can be understood as the process of adding a protocol header corresponding to the protocol generating the message when the message is sent from the device interface, which is performed at the sending device end; decapsulation can be understood as the process of removing the protocol header added in the original message when the message is received by the device interface, which is performed by the receiving end. Among them, encapsulation can be vlan encapsulation, or vxlan (virtual extended local area network) encapsulation.

[0028] In the above embodiments, when creating a network, the user can use CIDR (Classless Inter-Domain Routing) as the IP address specified by the private network, and any one of the following private networks can be supported: 10.0.0.0-10.255.255.255 (mask range needs to be between 12-28); 175.15.0.0-172.31.255.255 (mask range needs to be between 12-28); 192.158.0.0-192.158.255.255 (mask range needs to be between 15-28). The process of accessing the VPC network from the outside network can refer to Figure 3 , for example Figure 3As shown, the cloud external physical machine network segment can be 192.158.10.0 / 24, the accessed VPC network segment can be 172.15.10.0 / 24, and the message is transmitted to the gateway of the cloud external switch (i.e., the first gateway described above, and the network segment can be 192.158.10.1). The message (i.e., the access message described above) includes two addresses: the physical machine network segment 192.158.10.0 / 24 and the Dst (Distination), i.e., the VPC network segment 172.15.10.0 / 24 (i.e., the first address and the second address described above). When the message reaches the switch gateway, the message is sent to the dedicated line access switch by searching for the route nexthop configured by the machine room. The machine room configuration can be operated by an administrator or a user. The nexthop can be understood as the next node that the data packet needs to reach in the routing process, which is used to indicate the next hop path of the data packet, so that the data packet reaches the destination correctly. In the routing table, each destination has a corresponding nexthop, i.e., the address or interface to which the next data packet should be sent. For example, the process of the cloud external physical machine entering the cloud external switch, and the IP address of the cloud external switch is the nexthop of this step. The message enters the dedicated line access switch for vxlan encapsulation, and obtains the encapsulation data (i.e., the first encapsulation data described above) containing the access message, the switch tunnel IP address 2.2.2.2 (i.e., the first tunnel address described above), and the DGW gateway tunnel IP address 3.3.3.3 (i.e., the second tunnel address described above), and sends it to the second gateway DGW dedicated line gateway. When the message reaches the dedicated line gateway, the dedicated line gateway performs decapsulation on it, searches for and determines the tunnel IP (i.e., the third tunnel described above) and the tunnel vni (i.e., the tunnel identifier described above) corresponding to the target VPC address 172.15.10.0 / 24, and performs vxlan encapsulation to send the access data to the VPC. The tunnel vni represents the tunnel identifier, which can also be referred to as a virtual network identifier, and is used as a unique identifier to distinguish different virtual networks, and is usually used to configure and manage tunnel connections in a network.

[0029] In one example embodiment, in the case where the second gateway includes a plurality of transmission tunnels for transmitting data, a main transmission tunnel included in the plurality of transmission tunnels is determined, and a tunnel address of the main transmission tunnel is determined as the second tunnel address.

[0030] In the above embodiment, when the dedicated line DGW gateway is in a high-availability case (i.e., the case described above including multiple transmission tunnels for transmitting data), the tunnel vip address (i.e., the address described above for transmitting data, i.e., the second tunnel address) local to the dedicated line gateway can be sent to the switch through a routing protocol on the DGW dedicated line gateway, forming an ECMP route. The ECMP route (Equal-Cost Multipath Routing) means equal-cost multi-path, which can be understood as the existence of multiple paths with the same cost to reach the same destination address. The routing protocol can be the Interior Gateway Routing Protocol (RIP) or the Open Shortest Path First (OSPF) protocol, or the Border Gateway Protocol (BGP), but is not limited thereto. When the device supports equal-cost routes, the three-layer forwarding traffic to the destination IP or destination network segment can be shared through different paths, which can achieve network load balancing, and when some paths fail, other paths can be used to complete the forwarding processing, achieving route redundancy backup.

[0031] In an example embodiment, the data transmission system further includes a virtual private network, the first gateway is connected with the dedicated line access switch through the virtual private network, configured to receive the access message sent by the first gateway, and send the access message to the dedicated line access switch; and the dedicated line access switch is further configured to encapsulate a tunnel identifier of the virtual private network into the first encapsulated data.

[0032] In the above embodiment, the virtual private network can be an operator VPN network, which is connected with the cloud external switch and the dedicated line access switch respectively, configured to receive the access message sent by the cloud external switch, and send the access message to the dedicated line access switch, and can be directly connected with the physical machine and the private network, ensuring that the data can be transmitted safely and stably. In addition, the first encapsulated data encapsulated by the dedicated line access switch further includes a tunnel identifier tnnnel vni of the operator VPN network, such as Figure 3 Device: vpn-1000 in the above embodiment.

[0033] In an example embodiment, the second gateway is further configured to modify the internal destination media access control address included in the access message to the first peer address of the second gateway.

[0034] In the above embodiment, since the second gateway needs to reply to the arp packet of the requested virtual machine VPC binding ip transmitted on all switches, the arp packet transmitted on all switches is terminated, and the inner layer routing is introduced to reduce the arp storage capacity on the switch, that is, the inner layer routing is replaced by the DGB peer ip to replace the tunnel ip. Among them, the arp protocol can be understood as a process of obtaining the destination MAC address through the destination IP address, and the DGB peer ip represents the peer ip address of the gateway (i.e. the first peer address described above), which is used to establish a peer relationship with other gateways, exchange routing information and forward data.

[0035] In an example embodiment, the virtual private cloud is also configured to encapsulate the transmission packet to obtain second encapsulation data, and send the second encapsulation data to the second gateway, wherein the second encapsulation data includes the transmission packet, a fourth tunnel address of a computing node calculating the transmission packet, the second tunnel address of the second gateway, a tunnel identifier for transmitting the transmission packet, a sending address sending the transmission packet, and a receiving address receiving the transmission packet; the second gateway is also configured to receive the second encapsulation data, and send the transmission packet to the physical machine based on the second encapsulation data.

[0036] In the above embodiment, the process of accessing the physical machine outside the cloud by the virtual machine in the VPC network can refer to Figure 4 As shown in Figure 4 The virtual private cloud VPN encapsulates the transmission packet, the computing node tunnel ip 172.171.0.28 / 32 (i.e. the fourth tunnel address described above), the dedicated line gateway tunnel ip 172.171.0.23 / 23 (i.e. the second tunnel address described above), the tunnel vni 88 (i.e. the tunnel identifier described above), the VPC network ip 172.15.10.0 / 24 (i.e. the sending address of the transmission packet described above), and the physical machine ip 192.158.10.0 / 24 outside the cloud (i.e. the receiving address described above) by vxlan, to obtain the second encapsulation data described above. Considering that the VPC side network segment and the network segment on the far end physical machine cannot be repeated, the virtual machine on the VPC side transmits the packet to the dedicated line gateway DGW by custom route, and the dedicated line gateway DGW sends the encapsulation data to the physical machine outside the cloud after decapsulating the encapsulation data. In addition, the switch and the dedicated line gateway do not run the vxlan protocol, but only need to satisfy the encap / decap vxlan and continue to do the three layer routing lookup after the vxlan encap / decap.

[0037] In an example embodiment, the sending the transmission packet to the physical machine based on the second encapsulation data comprises: decapsulating the second encapsulation data to obtain second decapsulation data; determining a next hop address of the transmission packet based on the receiving address included in the second decapsulation data; modifying an inner destination media access control address included in the transmission packet to a second peer address of the private line access switch to obtain a target transmission packet; encapsulating the target transmission packet, the second tunnel address of the second gateway, and the first tunnel address of the private line access switch to obtain third encapsulation data; sending the third encapsulation data to the private line access switch to instruct the private line access switch to decapsulate the third encapsulation data to obtain third decapsulation data, and send the target transmission packet to a virtual private network indicated by the next hop through the second peer address included in the third decapsulation data; sending the target transmission packet to the first gateway by the virtual private network; and sending the target transmission packet to the physical machine by the first gateway.

[0038] In the above embodiment, as shown in Figure 4 When the private line gateway receives the second encapsulation data, the vtep (virtual tunnel end point) 172.171.0.28, 172.171.0.23 of the intranet tunnel is decapsulated by vxlan to obtain decapsulation data (i.e. the second decapsulation data described above), the receiving address (i.e. the next hop address described above) of the packet is determined by routing lookup according to Dst 192.158.10.0 / 24 in the second encapsulation data. In order to make the packet continue to do three-layer routing lookup after the switch does decapsulation, the inner dstmac (equivalent to the internal destination media access control address described above) of the inner layer packet can be changed to peer_remote_dst mac, that is, the address of the port of the switch peer ip 10.235.100.2 of the extranet switch (equivalent to the second peer address described above).

[0039] In the above embodiment, when the Vpc side virtual machine uses custom route to guide the packet to the dgw gateway, each private line needs a local tunnel ip (local tunnel IP), a remote ip (remote IP) and a vni (unique identifier of virtual network), so the flow table on the private line gateway DGW needs to support setting tun_src, tun_dst and tunnelid (vni). Among them, tun_src can be understood as the Tunnel source address, i.e. the starting address of the tunnel; tundst can be understood as the Tunnel destination address, i.e. the target address of the tunnel; tunnelid (vni) can be understood as the Tunnel identifier. The private line gateway performs outer vxlan encapsulation, including: target transmission packet, vtep local encapsulation 3.3.3.3 (i.e. the second tunnel address described above), vetp remote encapsulation 2.2.2.2 (i.e. the first tunnel address described above), to obtain third encapsulated data.

[0040] In the above embodiment, when the packet enters the private line switch, outer vxlan encapsulation is performed to obtain third encapsulated data. According to the dst mac (i.e. the second peer address described above), the next hop address is found, i.e. the operator VPN network. The operator VPN network transmits the transmission packet to the cloud external switch (first gateway), and the cloud external switch sends the transmission packet to the cloud external physical machine. In the process of three encapsulations, the MAC address is constantly changing, and through layer by layer encapsulation and decapsulation, the data can quickly and correctly enter the destination.

[0041] In an example embodiment, the number of private line access switches is one or more. In the above embodiment, the private line access switch can be one or more, each private line gateway DGW can be connected to one or more private line access switches, and each operator VPN network can also be connected to one or more private line access switches. When some paths fail, network load balancing can be achieved.

[0042] In an example embodiment, the number of second gateways is at least one or more. In the above embodiment, a private line can be bound to multiple private line gateway DGWs, and the traffic of private line access is shared by the bound private line gateway DGWs, and each VPC Network can be bound to multiple private line access instances. By determining the main transmission tunnel, congestion of transmission data can be avoided, and efficient transmission can be achieved.

[0043] In one exemplary embodiment, when there are multiple second gateways, each second gateway can be connected to a leased-line access switch. When the leased-line access switch receives target data sent by the virtual private network (VPN), it can determine the source of the target data, i.e., determine the IP address of the physical machine that sent the target data, obtain a pre-determined correspondence between gateways and physical machines, determine the target gateway corresponding to the physical machine that sent the target data based on the correspondence, and forward the target data to the target gateway. In this embodiment, when there are multiple second gateways, the correspondence between gateways and physical machines can be pre-determined, and one gateway is responsible for forwarding data sent by one or more physical machines. This achieves load balancing for data forwarding and improves the system's transmission efficiency.

[0044] In the above embodiments, when there are multiple second gateways, one of the second gateways may be a main gateway. The main gateway can connect to other gateways included in the second gateway group, and can send target data to the main gateway. The main gateway then determines the transmission gateway among the second gateways for transmitting the target data. When the main gateway fails, it can determine the transmission gateway among the other gateways, thus achieving high availability of the system.

[0045] In the above embodiments, after receiving the target data, the target gateway can further parse the target data to determine the target data type, determine the correspondence between the data types pre-stored in the target gateway and the transmission tunnels, determine the target transmission tunnel corresponding to the target data type based on the correspondence, and send the target data to the virtual private cloud through the target transmission tunnel. One target transmission tunnel transmits one type of target data, which can prevent crosstalk caused by transmitting different types of data in the same tunnel, thus ensuring data security.

[0046] The methods and embodiments provided in this application can be executed on a server device or a similar computing device. Taking running on a server device as an example, Figure 5 This is a hardware structure block diagram of a server device for a data transmission method according to an embodiment of this application. Figure 5 As shown, the server device may include one or more ( Figure 5 Only one is shown in the diagram. A processor 502 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 504 for storing data are also shown. The server device may further include a transmission device 505 for communication functions and an input / output device 508. Those skilled in the art will understand that... Figure 5 The structure shown is for illustrative purposes only and does not limit the structure of the server equipment described above. For example, the server equipment may also include components that are more... Figure 5more or less components than those shown, or configured differently from those shown, as Figure 5

[0047] The memory 504 is used to store a computer program, for example, a software program of application software and a module, such as a computer program corresponding to the data transmission method in the embodiments of the present application. The processor 502 performs various functional applications and data processing, that is, implements the above method, by running the computer program stored in the memory 504. The memory 504 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 504 can further include a memory remotely arranged with respect to the processor 502, which can be connected to a server device through a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0048] The transmission device 505 is used to receive or send data via a network. The specific examples of the above network can include a wireless network provided by a communication provider of the server device. In one example, the transmission device 505 includes a network adapter (Network Interface Controller, NIC) which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 505 can be a radio frequency (Radio Frequency, RF) module used for communicating with the Internet in a wireless manner.

[0049] In the present embodiment, a data transmission method is provided, which is applied to the data transmission system described in any of the above embodiments, Figure 6 is a flowchart of the data transmission method according to the embodiments of the present application, as Figure 6 shown, the flow includes the following steps:

[0050] In step S602, the received access message is encapsulated to obtain first encapsulated data, wherein the access message is a message accessed by the first gateway through the virtual private network, the access message includes a first address of the physical machine and a second address of the virtual private cloud, and the first encapsulated data includes the access message, a first tunnel address of the private line access switch, and a second tunnel address of the second gateway.

[0051] ​Step S604, the first encapsulation data is sent to the second gateway to instruct the second gateway to decapsulate the first encapsulation data to obtain first decapsulation data, determine a third tunnel address and a tunnel identifier corresponding to the second address included in the first decapsulation data, and send the access data of the physical machine to the virtual private cloud through a target tunnel determined based on the third tunnel address and the tunnel identifier.

[0052] In the above embodiment, encapsulation can be understood as a process of adding a protocol header of a corresponding protocol generating the packet when the packet is sent from the device interface, which is performed at the sending device end; decapsulation can be understood as a process of removing the protocol header added in the original packet when the packet is received by the device interface, which is performed by the receiving end. Among them, the encapsulation can be vlan encapsulation, or vxlan encapsulation (virtual extended local area network). The first gateway can be a cloud external switch, used to receive the access packet sent from the cloud external physical machine. The virtual private network can be an operator VPN network, connected with the cloud external switch and the dedicated line access switch respectively, used to accept the access packet sent by the cloud external switch and send the access packet to the dedicated line access switch. The virtual private cloud can be a VPC (Virtual Private Cloud), which is a set of logically isolated virtual network environments for cloud servers, cloud containers, cloud databases and other cloud resources, which are configured and managed by users. The second gateway can be a dedicated line gateway DGW, which can be understood as a bridge connecting the private network VPC and the physical dedicated line, used to deliver the packet transmitted by the dedicated line access switch to the VPN.

[0053] In the above embodiment, the process of cloud external network accessing the VPC network can refer to Figure 3 For example Figure 3As shown, the cloud exchange gateway (i.e. the first gateway) receives an access message from the operator VPN network and performs vlan encapsulation on the access message to obtain first encapsulation data, wherein the access message includes the physical machine network segment 192.158.10.0 / 24 and the Dst (destination address Distination) VPC network segment 172.15.10.0 / 24 (i.e. the first address and the second address); the first encapsulation data includes the access message, the switch tunnel ip address 2.2.2.2 (i.e. the first tunnel address) and the DGW gateway tunnel ip address 3.3.3.3 (i.e. the second tunnel address). The first encapsulation data is sent to the second gateway, the dedicated line gateway. When the message reaches the dedicated line gateway, the dedicated line gateway performs decapsulation on the message to obtain first decapsulation data. The tunnel ip corresponding to the target VPC address 172.15.10.0 / 24 (i.e. the third tunnel) and the tunnel vni (i.e. the tunnel identifier) are determined, and the access data of the physical machine is sent to the VPC through the tunnel. The tunnel vni represents a tunnel identifier, which can also be referred to as a virtual network identifier, and is a unique identifier for distinguishing different virtual networks, and is usually used for configuring and managing tunnel connections in a network.

[0054] According to the present application, the access message sent by the physical machine to access the virtual private cloud received by the first gateway connected to the physical machine is sent to the dedicated line access switch connected to the first gateway, the switch encapsulates the message and sends it to the second gateway, and then the second gateway connected to the dedicated line access switch decapsulates the encapsulation data, so that the access data of the physical machine can be sent to the virtual private cloud, and a high-speed, low-latency, stable and secure dedicated connection channel between the user local data center and the virtual private cloud in the cloud can be built. Therefore, the problem of low data transmission performance in the related art can be solved, and the effect of improving the data transmission performance can be achieved.

[0055] The execution subject of the above steps can be a dedicated line access switch, but is not limited thereto.

[0056] In an example embodiment, the method further comprises: decapsulating the received third encapsulation data to obtain third decapsulation data, and sending a target transport message included in the third encapsulation data to a virtual private network through a second peer-to-peer address included in the third decapsulation data, to instruct the virtual private network to send the target transport message to the first gateway, and instruct the first gateway to send the target transport message to the physical machine; wherein the third encapsulation data is obtained by: modifying an internal destination media access control address included in the transport message to a second peer-to-peer address of the private line access switch to obtain a target transport message by the second gateway; and encapsulating the target transport message, the second tunnel address of the second gateway, and the first tunnel address of the private line access switch to obtain the third encapsulation data; and the virtual private network is determined by: decapsulating the second encapsulation data by the second gateway to obtain second decapsulation data; determining a next hop address of the transport message based on a receiving address included in the second decapsulation data; and determining a private network with the next hop address as the virtual private network; wherein the second encapsulation data is obtained by encapsulating the transport message by the virtual private cloud, and the second encapsulation data includes the transport message, a fourth tunnel address of a computing node for computing the transport message, the second tunnel address of the second gateway, a tunnel identifier for transmitting the transport message, a sending address for sending the transport message, and a receiving address for receiving the transport message.

[0057] In the above embodiments, as Figure 4As shown, the virtual private cloud VPN encapsulates the transmission message, tunnel ip 172.171.0.28 / 32 (i.e. the fourth tunnel address described above), the dedicated line gateway tunnel ip 172.171.0.23 / 23 (i.e. the second tunnel address described above), tunnel vni 88 (i.e. the tunnel identifier described above), VPC network ip 172.15.10.0 / 24 (and the sending address of the transmission message described above), and cloud-external physical machine ip 192.158.10.0 / 24 (and the receiving address described above) by vxlan to obtain the second encapsulation data described above. When the dedicated line gateway receives the second encapsulation data, it performs vxlan decapsulation on the vtep (virtual tunnel endpoint) 172.171.0.28, 172.171.0.23 of the cloud-internal tunnel to obtain the decapsulation data (i.e. the second decapsulation data described above), performs routing lookup according to the Dst 192.158.10.0 / 24 in the second encapsulation data, and determines the receiving address of the message (i.e. the next hop address described above). In order to enable the message to continue to perform three-layer routing lookup after the switch performs decapsulation, the inner dst mac (equivalent to the internal destination media access control address described above) of the inner message is changed to peer_remote_dst mac, i.e. the address of the port of the cloud-external switch switch peer ip 10.235.100.2 (equivalent to the second peer address described above).

[0058] In the above embodiment, when the Vpc-side virtual machine directs the message to the dgw gateway using customroute, each dedicated line needs a localtunnelip (local tunnel IP), a remoteip (remote IP), and a vni (unique identifier of a virtual network), so the flow table on the dedicated line gateway DGW needs to support setting tunsrc, tun_dst, and tunnelid (vni). Among them, tun_src can be understood as the Tunnel source address, i.e. the starting address of the tunnel; tun_dst can be understood as the Tunnel destination address, i.e. the target address of the tunnel; tunnelid (vni) can be understood as the Tunnel identifier. The dedicated line gateway performs outer vxlan encapsulation, including: target transmission message, vtep local encapsulation 3.3.3.3 (i.e. the second tunnel address described above), vetpremote encapsulation 2.2.2.2 (i.e. the first tunnel address described above), to obtain the third encapsulation data.

[0059] In the above embodiment, when the packet enters the dedicated line switch, outer vxlan decapsulation is performed to obtain third decapsulation data. According to the dstmac (i.e., the second peer address), a next hop address is found, that is, the operator VPN network. The operator VPN network transmits the packet to the cloud external switch (first gateway), and the cloud external switch sends the packet to the cloud external physical machine.

[0060] In the above embodiment, by relying on the communication links of the operators and the DGW dedicated line gateway, a high-speed, low-latency, stable and secure dedicated connection channel between the user local data center and the virtual private cloud (VPC) on the cloud is built. Flexible network connection is the cornerstone of integrating distributed environments. The data service between the VPC on the cloud and the user data center can be connected through the cloud dedicated line. The user can connect the user network, data center and host hosting area on the user side to the VPC dedicated line connection on the cloud through the cloud dedicated line, and enjoy high performance, low latency and secure dedicated data network.

[0061] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and the necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for making a terminal device (which can be a mobile phone, computer, server, or network device, etc.) execute the methods described in various embodiments of the present application.

[0062] It should be noted that the above modules can be realized by software or hardware, and for the latter, the following implementation manners can be used, but are not limited thereto: the above modules are located in the same processor; or the above modules are located in different processors in any combination.

[0063] The embodiments of the present application also provide a computer readable storage medium, which stores a computer program, and the computer program is configured to execute the steps in any of the above method embodiments when running.

[0064] In an example embodiment, the above computer readable storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.

[0065] Embodiments of the present application also provide an electronic device, comprising a memory and a processor, the memory storing a computer program, and the processor being configured to execute the computer program to perform the steps in any of the method embodiments described above.

[0066] In an example embodiment, the electronic device described above can further comprise a transmission device connected to the processor, and an input / output device connected to the processor.

[0067] Embodiments of the present application also provide a computer program product, which comprises a computer program, and the computer program, when executed by a processor, implements the steps in any of the method embodiments described above.

[0068] The specific examples in the present embodiments can refer to the examples described in the above embodiments and example implementations, which will not be repeated here.

[0069] Obviously, those skilled in the art should understand that the modules or steps of the present application described above can be realized by general computing devices, which can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, which can be realized by program codes executable by computing devices, so that they can be stored in storage devices and executed by computing devices, and in some cases, the steps shown or described can be executed in different order, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps can be manufactured into a single integrated circuit module. Thus, the present application is not limited to any particular combination of hardware and software.

[0070] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the principles of the present application shall be included in the protection scope of the present application.

Claims

1. A data transmission system, characterized in that, include: A first gateway, connected to a physical machine, is used to receive access messages sent by the physical machine to access a virtual private cloud, wherein the access message includes a first address of the physical machine and a second address of the virtual private cloud; a leased line access switch, connected to the first gateway, is used to receive the access message, encapsulate the access message to obtain first encapsulation data, wherein the first encapsulation data includes the access message, a first tunnel address of the leased line access switch, and a second tunnel address of the second gateway. The second gateway, which is connected to the leased line access switch, is used to decapsulate the first encapsulated data to obtain the first decapsulated data, determine the third tunnel address and tunnel identifier corresponding to the second address included in the first decapsulated data, and send the access data of the physical machine to the virtual private cloud through the target tunnel determined based on the third tunnel address and the tunnel identifier.

2. The system according to claim 1, characterized in that, In the case where the second gateway includes multiple transmission tunnels for transmitting data, a primary transmission tunnel is identified among the multiple transmission tunnels, and the tunnel address of the primary transmission tunnel is determined as the second tunnel address.

3. The system according to claim 1, characterized in that, The data transmission system also includes: A virtual private network (VPN) is provided, in which the first gateway is connected to the leased line access switch via the VPN, and is used to receive the access message sent by the first gateway and send the access message to the leased line access switch. The leased line access switch is also used to encapsulate the tunnel identifier of the virtual private network into the first encapsulation data.

4. The system according to claim 1, characterized in that, The second gateway is also used to modify the internal destination media access control address included in the access message to the first peer address of the second gateway.

5. The system according to claim 1, characterized in that, The virtual private cloud is also used to encapsulate the transmission message to obtain second encapsulation data, and send the second encapsulation data to the second gateway. The second encapsulation data includes the transmission message, the fourth tunnel address of the computing node that calculates the transmission message, the second tunnel address of the second gateway, the tunnel identifier for transmitting the transmission message, the sending address for sending the transmission message, and the receiving address for receiving the transmission message. The second gateway is also used to receive the second encapsulated data and send the transmission message to the physical machine based on the second encapsulated data.

6. The system according to claim 5, characterized in that, Sending the transmission message to the physical machine based on the second encapsulated data includes: The second encapsulated data is decapsulated to obtain the second decapsulated data; The next-hop address of the transmitted message is determined based on the receiving address included in the second decapsulation data; The internal destination media access control address included in the transmission message is modified to the second peer address of the leased line access switch to obtain the target transmission message; The target transmission message, the second tunnel address of the second gateway, and the first tunnel address of the leased line access switch are encapsulated to obtain third encapsulated data; The third encapsulated data is sent to the leased access switch to instruct the leased access switch to decapsulate the third encapsulated data, obtain the third decapsulated data, and send the target transmission packet to the virtual private network indicated by the next hop through the second peer address included in the third decapsulated data. The virtual private network sends the target transmission message to the first gateway; The first gateway sends the target transmission message to the physical machine.

7. The system according to claim 1, characterized in that, The number of dedicated line access switches is one or more.

8. The system according to claim 1, characterized in that, The number of the second gateway is at least one or more.

9. A data transmission method, characterized in that, Applied to the data transmission system as described in any one of claims 1 to 8, include: The received access message is encapsulated to obtain first encapsulation data, wherein the access message is a message accessed by the first gateway through the virtual private network, the access message includes the first address of the physical machine and the second address of the virtual private cloud, and the first encapsulation data includes the access message, the first tunnel address of the leased line access switch, and the second tunnel address of the second gateway. The first encapsulated data is sent to the second gateway to instruct the second gateway to decapsulate the first encapsulated data to obtain the first decapsulated data. The third tunnel address and tunnel identifier corresponding to the second address included in the first decapsulated data are determined. The access data of the physical machine is sent to the virtual private cloud through the target tunnel determined based on the third tunnel address and the tunnel identifier.

10. The method according to claim 9, characterized in that, The method further includes: The received third encapsulated data is decapsulated to obtain third decapsulated data, and the target transmission packet included in the third encapsulated data is sent to the virtual private network through the second peer address included in the third decapsulated data, so as to instruct the virtual private network to send the target transmission packet to the first gateway, and instruct the first gateway to send the target transmission packet to the physical machine. The third encapsulation data is obtained as follows: the second gateway modifies the internal destination media access control address included in the transmission packet to the second peer address of the leased line access switch to obtain the target transmission packet; the target transmission packet, the second tunnel address of the second gateway, and the first tunnel address of the leased line access switch are encapsulated to obtain the third encapsulation data. The virtual private network (VPN) is determined as follows: the second gateway decapsulates the second encapsulated data to obtain second decapsulated data; the next-hop address of the transmitted message is determined based on the receiving address included in the second decapsulated data; the private network with the address of the next-hop address is determined as the VPN; wherein, the second encapsulated data is the data obtained by the virtual private cloud encapsulating the transmitted message, and the second encapsulated data includes the transmitted message, the fourth tunnel address of the computing node that calculates the transmitted message, the second tunnel address of the second gateway, the tunnel identifier used to transmit the transmitted message, the sending address of the transmitted message, and the receiving address of the transmitted message.

Citation Information

Patent Citations

  • BFD session establishing method, BFD session processing method and related equipment

    CN113225252A

  • Cloud network system and interaction method of cloud network system

    CN116996343A