A method, device and medium for external connection export of a multi-center network based on SDN
By setting up external exits for multi-center networks in a cloud network environment and outputting based on configuration information and routing priorities, the problems of network congestion and performance degradation in multi-center networks are solved, and flexible network management and security isolation are achieved.
Patent Information
- Application Number
- CN202411326263.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-09-23
AI Technical Summary
Existing technologies lack external connection modes for multi-center networks or cross-network environments in cloud network environments, leading to network congestion or performance degradation.
By acquiring the tenant network's configuration information, synchronizing it to the SDN controller's central and external networks, setting the external network's priority and routing priority, and outputting northwards based on the configuration mode, flexible external connections for multi-center networks are achieved.
It enables flexible external connections for multi-center networks, allowing for real-time adjustment of network configuration and priorities, ensuring network connectivity continuity, reducing security risks, and improving network performance.
Smart Images

Figure CN119324863B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computer network technology, and in particular to an external connection method, device and medium for a multi-center network based on SDN. Background Technology
[0002] In SDN (Software Defined Network) networking, a single network has only one external exit point with a fixed mode. The output mode may be any one of these modes or may include multiple output modes. When multiple central networks are involved, the output method becomes more complex. If the output interface or mode cannot meet the current network requirements and traffic changes, it may lead to network congestion or performance degradation.
[0003] A Chinese invention patent application discloses a method, device, and medium for implementing multiple exits of a tenant network in a cloud network environment. The method involves synchronizing the configuration information of the tenant network in the cloud platform to an SDN controller through a pre-defined project; selecting a border switch in the Spine-Leaf switch network for the tenant network based on the SDN controller; and binding the tenant network to a port on the border switch determined by the SDN controller, enabling the tenant network to achieve northbound traffic output through multiple exits via the border switch ports. While the SDN-based Spine-Leaf architecture supports multiple exits within a single network, it lacks solutions for multi-center, cross-network scenarios.
[0004] Based on the above analysis, the problems and shortcomings of the existing technology are as follows:
[0005] The existing cloud network environment lacks external access modes for multi-center networks or cross-networks, which cannot meet the current network demands and traffic changes, leading to network congestion or performance degradation. Summary of the Invention
[0006] This application provides an external access method, device, and medium for a multi-center network based on SDN, which can solve the problem that the existing cloud network environment lacks external access modes for multi-center networks or cross-networks, which cannot meet the current network needs and traffic changes, resulting in network congestion or performance degradation.
[0007] In a first aspect, embodiments of this application provide an external egress method for a multi-center network based on SDN. The method includes: obtaining configuration information of a tenant network and synchronizing the configuration information to the central network and external network of the SDN controller, wherein the central network includes a first central network and a second central network, and the external network includes a first external network and a second external network; obtaining the priority of the external network according to the configuration information, and correspondingly obtaining the priority of the route, wherein the priority of the first external network is higher than the priority of the second external network, and the route includes local routes and remote routes; and based on the configuration information including a configuration mode, performing northbound output through the central network, the external network, and the route according to the configuration mode, wherein the configuration mode includes specified output.
[0008] In one implementation of this application, configuration information includes a configuration mode. Based on the configuration mode, northbound output is performed through a central network, an external network, and a route. Specifically, this includes: determining whether the second central network is configured with instructions for local specified output and second external network specified output based on the configuration mode; if not configured, northbound output is performed through the first central network and the first external network.
[0009] In one implementation of this application, after northbound output is performed through the first central network and the first external network without configuration, the method further includes: based on the output interface of the central network, if the output interface of the first central network fails, northbound output is performed through the second central network; if the first external network fails, northbound output is performed through the second external network; and in the case of a local route failure, output is performed through a remote route.
[0010] In one implementation of this application, the method further includes: when a local specified output is configured but an external network specified output is not configured, northbound output is performed through a second central network and a first external network; when a local specified output is configured and an external network specified output is configured, northbound output is performed through a second central network and a second external network.
[0011] In one implementation of this application, before obtaining the configuration information of the tenant network and synchronizing the configuration information to the central network and external network of the SDN controller, the method further includes: connecting the bottom layer and the overlay layer of the first central network and the second central network, and setting the first central network as the egress network by default; connecting to the external network through a physical port, and providing configuration information and physical ports in a graphical interface to control the request code to send the corresponding configuration information to the switch.
[0012] In one implementation of this application, the method further includes: obtaining the IP address, gateway, DNS server, and bandwidth of the third external network, and adding corresponding output interfaces and setting the priority of the third external network; testing the connectivity between the third external network and the first and second external networks using traceroute, and determining whether there is packet loss; and deploying the third external network if there is no packet loss.
[0013] In one implementation of this application, the method further includes: collecting the load of the central network, the external network, and the routing in real time, and determining whether the traffic is balanced; and dynamically adjusting the priority of the central network, the external network, and the routing when the traffic of the first central network, the first external network, and the local routing is congested to a preset threshold.
[0014] In one implementation of this application, the method further includes enabling encryption algorithms at boundary devices between the central network and the external network, the boundary devices including switches and routers.
[0015] Secondly, embodiments of this application also provide an external egress device for a multi-center network based on SDN. The device includes at least one processor and a memory communicatively connected to the at least one processor. The memory stores instructions executable by the at least one processor, which, when executed, enable the at least one processor to: obtain configuration information of a tenant network and synchronize the configuration information to the central network and external network of the SDN controller, wherein the central network includes a first central network and a second central network, and the external network includes a first external network and a second external network; obtain the priority of the external network based on the configuration information and obtain the priority of the corresponding route, wherein the priority of the first external network is higher than the priority of the second external network, and the route includes local routes and remote routes; and, based on the configuration information including a configuration mode, perform northbound output through the central network, external network, and route according to the configuration mode, wherein the configuration mode includes specified output.
[0016] Thirdly, embodiments of this application also provide an external non-volatile computer storage medium for an SDN-based multi-center network, storing computer-executable instructions. These computer-executable instructions are configured to: obtain configuration information of a tenant network and synchronize the configuration information to the central network and external networks of the SDN controller, wherein the central network includes a first central network and a second central network, and the external networks include a first external network and a second external network; obtain the priority of the external network based on the configuration information, and correspondingly obtain the priority of the route, wherein the priority of the first external network is higher than the priority of the second external network, and the route includes local routes and remote routes; based on the configuration information including a configuration mode, perform northbound output through the central network, external networks, and routes according to the configuration mode, wherein the configuration mode includes specified output.
[0017] This application provides an SDN-based multi-center network external access method, device, and medium. Multiple network centers are configured with multiple external access points. These centers can share network status information, collaboratively perform routing decisions and traffic scheduling, and the external interfaces and output modes can be flexibly configured and expanded. Network traffic data is collected and analyzed in real time to promptly identify network congestion and performance bottlenecks. Multiple external access points are configured with priorities and failover mechanisms, allowing automatic switching when the main center or main route fails, ensuring network continuity. Independent configuration information and priorities can be set for tenant networks, enabling network isolation between tenants and reducing potential security risks. The graphical configuration is easier to plan than manual configuration. Attached Figure Description
[0018] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0019] Figure 1 A flowchart illustrating an outbound exit method for a multi-center network based on SDN, provided in an embodiment of this application;
[0020] Figure 2 This is a schematic diagram of the internal structure of an external network egress device based on SDN provided in an embodiment of this application. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0022] This application provides an external access method, device, and medium for a multi-center network based on SDN, which solves the problem in the prior art that there is a lack of external access modes for multi-center networks or cross-networks in the cloud network environment, which cannot meet the current network needs and traffic changes, resulting in network congestion or performance degradation.
[0023] The technical solutions proposed in the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0024] Figure 1 This document provides a flowchart of an external access method for a multi-center network based on SDN, as illustrated in an embodiment of this application. Figure 1 As shown in the figure, the outbound exit method of a multi-center network based on SDN provided in this application embodiment specifically includes the following steps:
[0025] Step 10: Obtain the configuration information of the tenant network and synchronize the configuration information to the central network and external network of the SDN controller. The central network includes the first central network and the second central network, and the external network includes the first external network and the second external network.
[0026] In this embodiment, the concept of dividing the network into multiple regions using an SDN controller is employed. Each region is treated as a central network, with a default setting for unified external connections from a single region (i.e., a single central network). Multiple external connection methods are allowed, and regions outside the default region can have their outbound connections configured to use that region. This flexible and diverse outbound connection method effectively solves the complex external connection problem in multi-center networks based on SDN controllers. It is understood that this multi-center network outbound connection scheme is also applicable to single-center networks.
[0027] For example, Hospital A has a main campus (central network) 1 and branch campuses 2 and 3, and also has a mini-program client (external network), a web client, internet services (remote routing), and intra-campus services (local routing). That is to say, each central network can be configured with n external networks, where n depends on the actual situation, but is capped by the number of routing priority specifications configured on the switches.
[0028] Step 20: Based on the configuration information, obtain the priority of the external network and the corresponding priority of the route. The priority of the first external network is higher than that of the second external network. The routes include local routes and remote routes.
[0029] In this step, in the multi-center network, there is one center network that is the default outgoing center, that is, as mentioned in step 01 below, the first center network is the default outgoing network.
[0030] For example, the main campus 1 is the default exit network, with the priority order being main campus 1, branch campus 2, and branch campus 3. External network 1 can include mobile app registration, online consultation, etc., and is configured with the main route with the highest traffic. External network 2 can be web-based registration, online consultation, etc., and in addition to configuring the main route, a backup route is also configured. External network 3 can include business access within the campus, which can be interconnected through local routes between campuses, or through the main route and the backup route.
[0031] Step 30: Based on the configuration information, including the configuration mode, northbound output is performed through the central network, external network, and routing according to the configuration mode, where the configuration mode includes the specified output.
[0032] In this step, operators can change the configuration mode according to the current situation. If no changes are made, the default priority is used, and output is performed locally if output is specified. External interfaces and output modes can be flexibly configured and expanded, including physical interfaces and virtual interfaces.
[0033] As an optional embodiment, based on configuration information including configuration mode, northbound output is performed through the central network, external network and routing according to the configuration mode. Specifically, it may include: Step 301: According to the configuration mode, determine whether the second central network is configured with instructions for local specified output and second external network specified output; Step 302: If not configured, northbound output is performed through the first central network and the first external network.
[0034] In this step, it is assumed that the two layers can communicate with each other. Layer 2 communication is a basic function that is achieved by multiple centers through routing protocols at the bottom and top layers. If the non-default center network, that is, the second center network (branch area), does not have an external connection configuration in this area, all external connections will default to going out through the first center network.
[0035] For example, the main hospital area 1 and the mini-program have the highest priority, and the patient's operations on the mini-program will by default go through the main hospital area 1 and the main route.
[0036] As an optional embodiment, in the absence of configuration, after northbound output through the first central network and the first external network, the method may further include: step 3021: based on the output interface of the central network, if the output interface of the first central network fails, northbound output is performed through the second central network.
[0037] In this step, if the output interface of the main campus 1 fails, the patient's operations on the mini-program will be output from the external interface of branch campus 2 or branch campus 3. Configuring multiple external interfaces allows for automatic route adjustment based on configuration information and priority in the event of a network failure, ensuring the continuity of critical services.
[0038] Step 3022: If the first external network fails, then northbound output is performed through the second external network.
[0039] In this step, if the mini-program malfunctions, it can automatically redirect to the webpage.
[0040] Step 3023: In the event of a local routing failure, output is provided via a remote routing system.
[0041] In this step, the primary and backup interfaces within a central network are determined by the priority of the default routes configured under the tenant's VRF (Virtual Routing and Forwarding). Traffic will only travel via lower-priority default routes when higher-priority default routes are ineffective, thus achieving primary and backup outbound traffic. Multiple backup routes exist, the number depending on the switch specifications and actual conditions. With the same outbound configuration, local routes take precedence over remote routes, prioritizing traffic from the local pod to avoid detours. Furthermore, when the local outbound address is unreachable from the external network, traffic can be routed through the primary pod without causing inaccessibility.
[0042] In other words, when communicating within the hospital area, the system defaults to using the local route. If the local route fails, communication will be conducted via the remote route.
[0043] As an optional embodiment, the method may further include: step 303: when configuring a local specified output and not configuring an external network specified output, performing northbound output through the second central network and the first external network;
[0044] In this step, if most patients need to register at branch 2, then the central network 2 is configured so that if a patient registers at the main hospital 1, the results are output at the main hospital 1; if a patient registers at branch 2, the results are output at branch 2. By default, the results go through the mini-program terminal.
[0045] Step 304: With local specified output and external network specified output configured, northbound output is performed through the second central network and the second external network.
[0046] In this step, if the default center and other centers are both configured with an exit method, they will exit from the local center instead of going to other centers to exit.
[0047] As an optional embodiment, before obtaining the tenant network's configuration information and synchronizing the configuration information to the SDN controller's central network and external networks, the method may further include:
[0048] Step 01: Connect the bottom layer and Ovelray layer of the first and second central networks, and set the first central network as the default egress network; Step 02: Connect to the external network through the physical port, and provide configuration information and physical port information in the graphical interface to control the request code to send the corresponding configuration information to the switch.
[0049] In this step, operators can temporarily change the configuration based on the current load. The interface-based configuration is simple and allows for flexible adjustment of network configuration and priority in the face of rapid changes in business needs, ensuring that the network can quickly adapt to these changes and provide tenants with stable and reliable network services.
[0050] As an optional embodiment, the method may further include: Step 40: Obtain the IP address, gateway, DNS server and bandwidth of the third external network, and add the corresponding output interface and set the priority of the third external network; Step 50: Test the connectivity between the third external network and the first and second external networks through traceroute, and determine whether there is packet loss; Step 60: Deploy the third external network if there is no packet loss.
[0051] In this step, for example, if tenant D wants to add an external network D and exit from physical interface 4, it can be deployed after testing. This includes evaluating network performance, such as the utilization rate of the external connection, traffic distribution, latency, and packet loss rate. Based on the evaluation results, the network configuration and policies are continuously optimized, and the priority of external network D is set to adapt to changes in network demand and traffic.
[0052] As an optional embodiment, the method may further include: step 70: collecting the load of the central network, external network, and routing in real time, and determining whether the traffic is balanced; step 80: when the traffic of the first central network, the first external network, and the local routing is congested to a preset threshold, dynamically adjusting the priority of the central network, the external network, and the routing.
[0053] As an optional embodiment, the method may further include: step 90: enabling encryption algorithms at the boundary devices of the central network and the external network, the boundary devices including switches and routers.
[0054] In summary, the embodiments of this application can realize SDN-based external egress types compatible with single center, single egress, and multiple egress, multiple external egress modes for a single center, external egress scheme with single center backup (default route priority), external egress with a specified egress for a single center (detailed route), scheme with multiple external egress for multiple centers, and external egress scheme with multiple center backup.
[0055] The above are embodiments of the method proposed in this application. Based on the same inventive concept, embodiments of this application also provide an external egress device for a multi-center network based on SDN, the structure of which is as follows: Figure 2 As shown.
[0056] Figure 2 This is a schematic diagram of the internal structure of an external egress device for a multi-center SDN-based network, provided as an embodiment of this application. Figure 2 As shown, the device includes:
[0057] At least one processor 201;
[0058] And a memory 202 that is communicatively connected to at least one processor;
[0059] The memory 202 stores instructions executable by at least one processor. These instructions are executed by at least one processor 201 to enable the at least one processor 201 to: obtain configuration information of the tenant network and synchronize the configuration information to the central network and external networks of the SDN controller, wherein the central network includes a first central network and a second central network, and the external networks include a first external network and a second external network; obtain the priority of the external network based on the configuration information and obtain the corresponding priority of the routes, wherein the priority of the first external network is higher than the priority of the second external network, and the routes include local routes and remote routes; and, based on the configuration information including a configuration mode, perform northbound output through the central network, external networks, and routes according to the configuration mode, wherein the configuration mode includes specified output.
[0060] Some embodiments of this application provide corresponding to Figure 1 A non-volatile computer storage medium for the external egress of a multi-center SDN-based network stores computer-executable instructions. These instructions are configured to: obtain configuration information of a tenant network and synchronize this information to the central network and external networks of the SDN controller; wherein the central network includes a first central network and a second central network, and the external networks include a first external network and a second external network; based on the configuration information, determine the priority of the external networks and the corresponding priority of the routes, wherein the priority of the first external network is higher than that of the second external network, and the routes include local routes and remote routes; based on the configuration information including a configuration mode, perform northbound output through the central network, external networks, and routes according to the configuration mode, wherein the configuration mode includes specified output.
[0061] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for IoT devices and media are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0062] The systems, media, and methods provided in this application are one-to-one correspondences. Therefore, the systems and media also have similar beneficial technical effects as their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the systems and media will not be repeated here.
[0063] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0064] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0065] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0066] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0067] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0068] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0069] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0070] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0071] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.
Claims
1. A method for external connections in a multi-center network based on SDN, characterized in that, The method includes: Obtain the configuration information of the tenant network and synchronize the configuration information to the central network and external network of the SDN controller, wherein the central network includes a first central network and a second central network, and the external network includes a first external network and a second external network; Based on the configuration information, the priority of the external network is obtained, and the priority of the corresponding route is obtained, wherein the priority of the first external network is higher than the priority of the second external network, and the route includes local routes and remote routes. Based on the configuration information, including the configuration mode, northbound output is performed through the central network, external network, and routing according to the configuration mode. The configuration mode includes specified output, specifically including: Based on the configuration mode, determine whether the second central network is configured with instructions for local specified output and second external network specified output; In the absence of configuration, northbound output is performed through the first central network and the first external network; When a local designated output is configured but no external network designated output is configured, northbound output is performed through the second central network and the first external network. When configuring local specified output and external network specified output, northbound output is performed through the second central network and the second external network.
2. The outbound exit method for a multi-center network based on SDN according to claim 1, characterized in that, In the absence of configuration, after northbound output via the first central network and the first external network, the method further includes: Since the central network includes an output interface, if the output interface of the first central network fails, northward output will be performed through the second central network. If the first external network fails, northbound output will be performed through the second external network; In the event of a local routing failure, output is provided via the remote routing.
3. The outbound exit method for a multi-center network based on SDN according to claim 1, characterized in that, Before obtaining the configuration information of the tenant network and synchronizing the configuration information to the central network and external network of the SDN controller, the method further includes: Connect the bottom layer of the first central network and the second central network to the ovelray layer, and set the first central network as the default egress network; The system connects to the external network via a physical port and provides configuration information and physical port details through a graphical interface to control request codes to send corresponding configuration information to the switch.
4. The outbound exit method for a multi-center network based on SDN according to claim 1, characterized in that, The method further includes: Obtain the IP address, gateway, DNS server, and bandwidth of the third external network, and add the corresponding output interface and set the priority of the third external network; The connectivity between the third external network and the first and second external networks is tested using traceroute, and it is determined whether packet loss occurs. Deploy the third external network without packet loss.
5. The outbound connection method for a multi-center network based on SDN according to claim 1, characterized in that, The method further includes: The load of the central network, external network, and routing is collected in real time to determine whether the traffic is balanced. When the traffic congestion in the first central network, the first external network, and the local route reaches a preset threshold, the priorities of the central network, the external network, and the route are dynamically adjusted.
6. The outbound exit method for a multi-center network based on SDN according to claim 3, characterized in that, The method further includes: Encryption algorithms are enabled at the boundary devices between the central network and the external network, including the switches and routers.
7. An external network egress device based on SDN for a multi-center network, characterized in that, The device includes: At least one processor; And, a memory communicatively connected to the at least one processor; The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to: Perform the steps of the outbound exit method for a multi-center network based on SDN as described in any one of claims 1-6.
8. A non-volatile computer storage medium for the external interface of a multi-center network based on SDN, storing computer-executable instructions, characterized in that, The computer-executable instructions are set as follows: Perform the steps of the outbound exit method for a multi-center network based on SDN as described in any one of claims 1-6.
Citation Information
Patent Citations
System and method for implementing limitation of north-south traffic of tenants based on SDN controller
CN106059915A
Network processing method, cloud platform and SDN controller
CN108063761A