Flow rate limiting system, method and device
By monitoring the lifecycle of network element agent units and changes in bandwidth configuration policies in the traffic rate limiting system, and updating IP and bandwidth mapping data, the problem of poor flexibility in the association between IP data and bandwidth data in traditional systems is solved. This enables precise rate limiting management of network bandwidth and meets high-performance requirements, thereby improving the scalability of the system.
Patent Information
- Application Number
- CN202411775462.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-05
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2044-12-05
AI Technical Summary
In traditional traffic limiting systems, the relationship between IP data and bandwidth data is not very flexible, resulting in poor scalability of the traffic limiting system and an inability to effectively solve the problem of bandwidth contention among multiple users.
A traffic rate limiting system is adopted, including a network element agent unit, a rate limiting controller, a rate limiting execution tool, and a filter agent unit. By monitoring the life cycle of the network element agent unit and changes in bandwidth configuration policies, the IP mapping data and bandwidth mapping data in the filter rate limiting program file are updated to enable rate limiting operations where different IPs share the same bandwidth.
It achieves flexible IP and bandwidth association, improves the precise speed limiting management of network bandwidth, supports business scenarios with dedicated bandwidth for a single IP and shared bandwidth for multiple IPs, meets the high bandwidth and high performance requirements of smart network cards and ordinary network cards, and improves the scalability of the traffic limiting system.
Smart Images

Figure CN119484290B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of cloud computing network, in particular to a traffic limiting system, a traffic limiting method and a traffic limiting device. BACKGROUND
[0002] The cloud native environment usually uses virtualization and containerization technology, multiple users share the same network bandwidth, and there is a phenomenon of multi-user bandwidth preemption. In view of the phenomenon of multi-user bandwidth preemption, the traffic limiting system can be used to implement the traffic control strategy, such as setting the bandwidth upper limit for the user, so as to try to ensure the fair distribution of network resources.
[0003] In the traditional traffic limiting system, the ip data and the bandwidth data are stored in the same data structure when the traffic limiting is performed, the association relationship between the ip and the bandwidth is poor in flexibility, and the scalability of the traffic limiting system is poor. SUMMARY
[0004] Therefore, it is necessary to provide a traffic limiting system, a traffic limiting method and a traffic limiting device in view of the above technical problems.
[0005] In a first aspect, the present application provides a traffic limiting system, which comprises a network element proxy unit, a speed limiting controller, a speed limiting execution tool and a filter proxy unit, the speed limiting controller comprises a monitoring unit, a speed limiting configuration unit and a program loading unit, wherein:
[0006] The monitoring unit is configured to monitor the life cycle of the network element proxy unit and whether the bandwidth configuration strategy changes, and when it is monitored that the life cycle of the network element proxy unit or the bandwidth configuration strategy changes, a speed limiting operation starting instruction is issued to the speed limiting configuration unit;
[0007] The speed limiting configuration unit is configured to, when the speed limiting operation starting instruction is received, obtain a bandwidth speed limiting execution mode and a bandwidth information configuration file according to the bandwidth configuration strategy;
[0008] The program loading unit is configured to update the ip mapping data and the bandwidth mapping data in the filter speed limiting program file through the speed limiting execution tool and the bandwidth information configuration file;
[0009] The program loading unit is further configured to obtain and load the filter speed limiting program file to the operating system kernel, so that the speed limiting execution tool performs the speed limiting operation of different ips sharing the same bandwidth size according to the ip mapping data and the bandwidth mapping data in the filter speed limiting program file, and the bandwidth speed limiting execution mode in the operating system kernel, to realize traffic limiting.
[0010] In one of the embodiments, the network element proxy unit is a deployment resource or a stateful set resource in a container orchestration platform, and an annotation field of the deployment resource or the stateful set resource includes a bandwidth configuration policy.
[0011] In one of the embodiments, the monitoring unit is configured to monitor whether the life cycle of the network element proxy unit and the bandwidth configuration policy change through a coordination cycle mechanism of the container orchestration platform.
[0012] In one of the embodiments, the monitoring unit is configured to monitor whether the life cycle of the network element proxy unit and the bandwidth configuration policy change, and the monitoring specifically includes:
[0013] When it is monitored that the hash value of the bandwidth configuration policy is inconsistent with the hash value of the container group in the container orchestration platform, it is determined that the life cycle or the bandwidth configuration policy of the network element proxy unit changes.
[0014] In one of the embodiments, the bandwidth configuration policy includes a bandwidth identifier throttling mode and a bandwidth information identifier throttling scheme, and the throttling configuration unit obtains a bandwidth throttling execution mode and a bandwidth information configuration file according to the bandwidth configuration policy, and the obtaining specifically includes:
[0015] According to the bandwidth identifier throttling mode in the bandwidth configuration policy, a bandwidth throttling execution mode is obtained.
[0016] According to the bandwidth information identifier throttling scheme in the bandwidth configuration policy, a bandwidth information configuration file is obtained.
[0017] In one of the embodiments, the program loading unit updates the ip mapping data and the bandwidth mapping data in the filter throttling program file through the throttling execution tool and the bandwidth information configuration file, and the updating specifically includes:
[0018] When the throttling execution tool determines that the bandwidth throttling value changes according to the bandwidth information configuration file, the bandwidth mapping data corresponding to the bandwidth throttling value is updated;
[0019] When the throttling execution tool determines that there is a unique bandwidth configuration identifier that is deleted according to the bandwidth information configuration file, the bandwidth mapping data corresponding to the unique bandwidth configuration identifier is deleted;
[0020] When the throttling execution tool determines that there is a public network ip corresponding to the bandwidth that changes according to the bandwidth information configuration file, the ip mapping data corresponding to the public network ip is updated;
[0021] When the throttling execution tool determines that there is a unique bandwidth configuration identifier that is deleted according to the bandwidth information configuration file, the ip mapping data corresponding to the unique bandwidth configuration identifier is deleted.
[0022] In one of the embodiments, the filter agent unit is configured to provide the filter rate limiting program file and an application programming interface, and the program loading unit is configured to call the application programming interface to obtain the filter rate limiting program file.
[0023] In one of the embodiments, the rate limiting execution tool is configured to perform the rate limiting operation of different IPs sharing the same bandwidth size according to the IP mapping data and the bandwidth mapping data in the filter rate limiting program file and the bandwidth rate limiting execution mode in the operating system kernel, and specifically includes:
[0024] determining the bandwidth rate limiting value corresponding to each IP according to the IP in the IP mapping data and the bandwidth rate limiting value in the bandwidth mapping data;
[0025] performing the rate limiting operation of different IPs sharing the same bandwidth size according to the bandwidth rate limiting execution mode and the bandwidth rate limiting value corresponding to each IP in the tc module of the operating system kernel through a network traffic rate limiting algorithm.
[0026] In a second aspect, the application further provides a traffic rate limiting method, which is applied to a rate limiting controller in a traffic rate limiting system, the traffic rate limiting system further includes a network element agent unit, a rate limiting execution tool and a filter agent unit, and the method includes:
[0027] when the life cycle of the network element agent unit or the bandwidth configuration strategy is monitored to change, obtaining the bandwidth rate limiting execution mode and a bandwidth information configuration file according to the bandwidth configuration strategy;
[0028] updating the IP mapping data and the bandwidth mapping data in the filter rate limiting program file through the rate limiting execution tool and the bandwidth information configuration file;
[0029] obtaining and loading the filter rate limiting program file to the operating system kernel, so that the rate limiting execution tool performs the rate limiting operation of different IPs sharing the same bandwidth size according to the IP mapping data and the bandwidth mapping data in the filter rate limiting program file and the bandwidth rate limiting execution mode in the operating system kernel, to realize the traffic rate limiting.
[0030] In a third aspect, the application further provides a traffic rate limiting device, which is applied to a rate limiting controller in a traffic rate limiting system, the traffic rate limiting system further includes a network element agent unit, a rate limiting execution tool and a filter agent unit, and the device includes:
[0031] a monitoring module configured to, when the life cycle of the network element agent unit or the bandwidth configuration strategy is monitored to change, obtain the bandwidth rate limiting execution mode and a bandwidth information configuration file according to the bandwidth configuration strategy.
[0032] mapping data updating module, configured to update the IP mapping data and the bandwidth mapping data in the filter rate limiting program file by the rate limiting execution tool and the bandwidth information configuration file;
[0033] rate limiting operation module, configured to acquire and load the filter rate limiting program file to the operating system kernel, so that the rate limiting execution tool performs the rate limiting operation on different IPs sharing the same bandwidth size according to the IP mapping data and the bandwidth mapping data in the filter rate limiting program file and the bandwidth rate limiting execution mode, to realize the traffic rate limiting.
[0034] In a fourth aspect, the present application further provides a rate limiting controller. The rate limiting controller comprises a memory and a processor, the memory stores a computer program, and the processor executes the above method.
[0035] In a fifth aspect, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program is executed by a processor to perform the above method.
[0036] In a sixth aspect, the present application further provides a computer program product. The computer program product comprises a computer program, and the computer program is executed by a processor to perform the above method.
[0037] The traffic limiting system comprises a network element proxy unit, a speed limiting controller, a speed limiting execution tool and a filter proxy unit. The speed limiting controller comprises a monitoring unit, a speed limiting configuration unit and a program loading unit. The monitoring unit is configured to monitor the life cycle of the network element proxy unit and whether the bandwidth configuration strategy changes, and send a speed limiting operation starting instruction to the speed limiting configuration unit when the life cycle of the network element proxy unit or the bandwidth configuration strategy changes. The speed limiting configuration unit is configured to obtain a bandwidth speed limiting execution mode and a bandwidth information configuration file according to the bandwidth configuration strategy when receiving the speed limiting operation starting instruction. The program loading unit is configured to update the ip mapping data and the bandwidth mapping data in the filter speed limiting program file through the speed limiting execution tool and the bandwidth information configuration file. The program loading unit is also configured to obtain and load the filter speed limiting program file to the operating system kernel, so that the speed limiting execution tool performs the speed limiting operation of different ips sharing the same bandwidth size according to the ip mapping data and the bandwidth mapping data in the filter speed limiting program file and the bandwidth speed limiting execution mode, to realize traffic limiting. According to the ip data and the bandwidth data in the bandwidth information configuration file, the ip mapping data and the bandwidth mapping data are obtained, the flexible ip and bandwidth association relationship is realized, the network bandwidth accurate speed limiting management is realized, the single-ip exclusive bandwidth and multi-ip shared bandwidth service scenarios are supported, the large bandwidth high performance requirement under the intelligent network card and the ordinary network card can be met, and the scalability of the traffic limiting system is improved. BRIEF DESCRIPTION OF DRAWINGS
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the description of the embodiments of the present application or the related art will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other related drawings can be obtained by those skilled in the art without creative labor.
[0039] Figure 1 The application flow chart of the traffic limiting system in one embodiment;
[0040] Figure 2 The cloud native traffic limiting architecture schematic diagram of the traffic limiting system in one embodiment;
[0041] Figure 3 The data structure conversion schematic diagram of the filter speed limiting program in one embodiment;
[0042] Figure 4 The flow chart of the traffic limiting method in one embodiment;
[0043] Figure 5 The structural block diagram of the traffic limiting device in one embodiment. DETAILED DESCRIPTION
[0044] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application.
[0045] The embodiments of the present application provide a traffic rate limiting system, as shown in the accompanying drawings, the traffic rate limiting system comprises a network element agent unit, a rate limiting controller, a rate limiting execution tool and a filter agent unit, the rate limiting controller comprises a monitoring unit, a rate limiting configuration unit and a program loading unit. Wherein the cloud-native traffic rate limiting architecture diagram of the traffic rate limiting system is as shown in the accompanying drawings. Figure 1 Figure 2 The monitoring unit is used for monitoring the life cycle of the network element agent unit and whether the bandwidth configuration strategy changes, and when the life cycle of the network element agent unit or the bandwidth configuration strategy changes is monitored, a rate limiting operation starting instruction is issued to the rate limiting configuration unit; the rate limiting configuration unit is used for obtaining a bandwidth rate limiting execution mode and a bandwidth information configuration file according to the bandwidth configuration strategy when the rate limiting operation starting instruction is received; the program loading unit is used for updating the ip mapping data and the bandwidth mapping data in the filter rate limiting program file through the rate limiting execution tool and the bandwidth information configuration file; the program loading unit is also used for obtaining and loading the filter rate limiting program file to the operating system kernel, so that the rate limiting execution tool performs the rate limiting operation of different ips sharing the same bandwidth size according to the ip mapping data and the bandwidth mapping data in the filter rate limiting program file and the bandwidth rate limiting execution mode in the operating system kernel, so as to realize the traffic rate limiting.
[0046] The traffic rate limiting system takes kubernetes (k8s for short) as a container orchestration platform, the network element agent unit exists in the form of deployment (Deployment) resources or stateful set (stateful set) resources in the container orchestration platform (Kubernetes), and the bandwidth configuration strategy is added to the annotation (Annotations) field of the deployment resources or stateful set resources.
[0047] The monitoring unit in the rate limiting controller can use the reconciliation (Reconcile) function in the reconciliation loop (Reconcile Loop) mechanism of the container orchestration platform to listen to whether the life cycle of the network element agent module (agent) and the bandwidth configuration strategy change. When it is monitored that the hash value of the bandwidth configuration strategy is inconsistent with the hash value of the container group in the container orchestration platform, it is determined that the life cycle of the network element agent unit or the bandwidth configuration strategy changes, at this time, the rate limiting operation starting instruction can be issued to the rate limiting configuration unit.
[0048] The monitoring unit in the rate limiting controller can use the reconciliation (Reconcile) function in the reconciliation loop (Reconcile Loop) mechanism of the container orchestration platform to listen to whether the life cycle of the network element agent module (agent) and the bandwidth configuration strategy change. When it is monitored that the hash value of the bandwidth configuration strategy is inconsistent with the hash value of the container group in the container orchestration platform, it is determined that the life cycle of the network element agent unit or the bandwidth configuration strategy changes, at this time, the rate limiting operation starting instruction can be issued to the rate limiting configuration unit.
[0049] When the speed limit configuration unit in the speed limit controller receives a speed limit operation start instruction, the speed limit mode can be identified according to the bandwidth identifier in the bandwidth configuration strategy, and the bandwidth speed limit execution mode is obtained; the speed limit scheme can be identified according to the bandwidth information identifier in the bandwidth configuration strategy, and the bandwidth information configuration file is obtained.
[0050] The program loading unit in the speed limit controller can call the apply instruction of the speed limit execution tool to make the speed limit execution tool determine the bandwidth speed limit value, the unique bandwidth configuration identifier, and whether the public network ip (Internet Protocol) corresponding to the bandwidth changes according to the bandwidth information configuration file, and when it is determined that the change occurs, the ip mapping data and the bandwidth mapping data in the filter speed limit program file are updated correspondingly.
[0051] The program loading unit in the speed limit controller can call the application program interface of the filter agent unit to obtain the filter speed limit program file, and load the filter speed limit program file into the operating system kernel.
[0052] The program loading unit in the speed limit controller can call the load instruction of the speed limit execution tool to make the speed limit execution tool determine the bandwidth speed limit value corresponding to each ip according to the ip in the ip mapping data and the bandwidth speed limit value in the bandwidth mapping data in the operating system kernel. The speed limit program (tc.c) can be loaded according to the bandwidth speed limit execution mode and the bandwidth speed limit value corresponding to each ip in the tc module of the operating system kernel through the network traffic speed limit algorithm to perform the speed limit operation of different ips sharing the same bandwidth size, so as to make the bandwidth configuration strategy of the network element agent unit effective. The operating system can be a linux system, and the network traffic speed limit algorithm can be an edt (Earlist Departure Time) algorithm.
[0053] The traffic speed limit system of the embodiment is based on kubernetes as a container orchestration platform, and is a traffic speed limit system for realizing dynamic ip bandwidth configuration of network cards based on bpf (Berkeley Packet Filter). The traffic speed limit system fuses bpf and k8s application, loads the filter speed limit program file according to dynamic traffic bandwidth configuration, optimizes network resource configuration, realizes speed limit capability, makes high-priority business obtain better network experience, and also makes more ordinary businesses obtain basic network traffic. In addition, when high-bandwidth speed limit occurs, the data transmission can still be ensured to be normal, which meets the allocation of high-performance bandwidth capability and precise speed limit in the cloud native field, avoids the problem of mutual influence of businesses between users, and supports flexible adaptation of multiple network service modes of shared bandwidth and exclusive bandwidth in the cloud native environment.
[0054] The traffic rate limiting system does not need to be interrupted in the process of ip bandwidth configuration change and updating rate limiting function, and does not invade application code, thereby improving the scalability and stability of the system.
[0055] The traffic rate limiting system obtains ip mapping data and bandwidth mapping data according to ip data and bandwidth data in the bandwidth information configuration file, realizes flexible ip and bandwidth association relationship, realizes network bandwidth accurate rate limiting management, supports single ip exclusive bandwidth and multi-ip shared bandwidth service scenarios, can meet the high bandwidth and high performance demand of intelligent network cards and ordinary network cards, and improves the scalability of the traffic rate limiting system.
[0056] In one of the embodiments, the network element proxy unit is a deployment resource or a stateful set resource in the container orchestration platform, and an annotation field of the deployment resource or the stateful set resource includes a bandwidth configuration strategy.
[0057] The network element proxy unit exists in the form of a deployment (Deployment) resource or a stateful set (Statefulsets) resource in a container orchestration platform (Kubernetes), and an annotation (Annotations) field of the deployment resource or the stateful set resource increases a bandwidth configuration strategy. The Deployment or Statefulsets is two commonly used application deployment methods in Kubernetes.
[0058] The specific bandwidth configuration strategy is as follows:
[0059] meta.xxx.io / bw-mode:bpf; indicates that the intelligent network card is used as the rate limiting mode;
[0060] meta.xxx.io / bw-info:>-{"RuleList":[{"OIId":203531,"BwName":"bw-cmoe4o6jga43j9uu6sg0","Limit":4096,"Ips":["45.56.5.12"]},{"OIId":203677,"BwName":"bw-cmp0p36jga426qtqoiag","Limit":50,"Ips":["45.56.5.36"]}]};
[0061] Wherein, the bw-mode is a bandwidth information identifier for a speed limiting scheme, the bpf is a Berkeley packet filter, the bw-info is a bandwidth identifier for a speed limiting mode, the RuleList is a rule list, the Ips is a public network IP corresponding to the bandwidth, one bandwidth value can be shared by multiple IPs, multiple IPs can be filled in the Ips, the Limit is a specific bandwidth limiting value, the OIId and the BwName are unique bandwidth configuration identifiers.
[0062] In the embodiment, according to the deployment resource or the stateful set resource in the container orchestration platform, a network element agent unit is determined, and a bandwidth configuration strategy is added to an annotation field of the network element agent unit.
[0063] In one of the embodiments, the monitoring unit is configured to monitor the life cycle of the network element agent unit and whether the bandwidth configuration strategy changes through a reconciliation loop mechanism of the container orchestration platform.
[0064] The monitoring unit can use a reconciliation function in the reconciliation loop mechanism of the container orchestration platform to listen to whether the life cycle of the network element agent unit and the bandwidth configuration strategy change.
[0065] In the embodiment, the monitoring unit can monitor the life cycle of the network element agent unit and whether the bandwidth configuration strategy changes through the reconciliation loop mechanism of the container orchestration platform.
[0066] In one of the embodiments, the monitoring unit monitors the life cycle of the network element agent unit and whether the bandwidth configuration strategy changes, and the specific steps are as follows: when it is detected that the hash value of the bandwidth configuration strategy is inconsistent with the hash value of the container group in the container orchestration platform, it is determined that the life cycle of the network element agent unit or the bandwidth configuration strategy changes.
[0067] The bandwidth identifier for the speed limiting mode and the bandwidth information identifier for the speed limiting scheme in the bandwidth configuration strategy can be converted into a hash-bash 64 value as the hash value of the bandwidth configuration strategy.
[0068] When the network element agent unit is newly created, reconstructed, or the bandwidth configuration strategy changes, the monitoring unit can monitor that the hash value of the bandwidth configuration strategy is inconsistent with the hash value of the container group in the container orchestration platform. Therefore, when the monitoring unit monitors that the hash value of the bandwidth configuration strategy is inconsistent with the hash value of the container group in the container orchestration platform, it can be determined that the life cycle of the network element agent unit or the bandwidth configuration strategy changes.
[0069] In the embodiment, according to whether the hash value of the bandwidth configuration strategy is consistent with the hash value of the container group in the container orchestration platform, it is determined whether the life cycle of the network element agent unit or the bandwidth configuration strategy changes.
[0070] In one of the embodiments, the bandwidth configuration strategy includes a bandwidth identification throttling mode and a bandwidth information identification throttling scheme, and the throttling configuration unit obtains the bandwidth throttling execution mode and the bandwidth information configuration file according to the bandwidth configuration strategy. The specific steps are as follows: obtaining the bandwidth throttling execution mode according to the bandwidth identification throttling mode in the bandwidth configuration strategy; obtaining the bandwidth information configuration file according to the bandwidth information identification throttling scheme in the bandwidth configuration strategy.
[0071] The bandwidth configuration strategy can include a bandwidth identification throttling mode (bw-mode) and a bandwidth information identification throttling scheme (bw-info).
[0072] The throttling configuration unit can obtain the bandwidth throttling execution mode according to the bandwidth identification throttling mode in the bandwidth configuration strategy.
[0073] For example, when the content of the bandwidth identification throttling mode is meta.xxx.io / bw-mode:bpf, it can be determined that the bandwidth throttling execution mode is bpf.
[0074] The throttling configuration unit can obtain the bandwidth data corresponding to each IP address according to the bandwidth information identification throttling scheme in the bandwidth configuration strategy, and obtain the bandwidth information configuration file bw-info.yaml according to the bandwidth data corresponding to each IP address.
[0075] In this embodiment, the bandwidth throttling execution mode and the bandwidth information configuration file are obtained according to the bandwidth identification throttling mode and the bandwidth information identification throttling scheme in the bandwidth configuration strategy, respectively.
[0076] In one of the embodiments, the program loading unit updates the IP mapping data and the bandwidth mapping data in the filter throttling program file through the throttling execution tool and the bandwidth information configuration file. The specific steps are as follows: when the throttling execution tool determines that the bandwidth throttling value changes according to the bandwidth information configuration file, the bandwidth mapping data corresponding to the bandwidth throttling value is updated; when the throttling execution tool determines that there is a unique bandwidth configuration identifier that is deleted according to the bandwidth information configuration file, the bandwidth mapping data corresponding to the unique bandwidth configuration identifier is deleted; when the throttling execution tool determines that there is a change in the public IP corresponding to the bandwidth according to the bandwidth information configuration file, the IP mapping data corresponding to the public IP is updated; when the throttling execution tool determines that there is a unique bandwidth configuration identifier that is deleted according to the bandwidth information configuration file, the IP mapping data corresponding to the unique bandwidth configuration identifier is deleted.
[0077] The rate-limiting execution tool can be a maptool tool. The maptool tool can define a map structure data processing command tool of a load command and an apply command and other filter rate-limiting programs (also referred to as bpf programs). Wherein:
[0078] The maptool load command: load the compiled filter rate-limiting program into the operating system kernel; support the following parameters:
[0079] -c <absolute path of the filter rate-limiting program file>,
[0080] -d <network card name>
[0081] The maptool apply command: according to the bandwidth information configuration file bw-info.yaml, update the ip mapping data ipmap and bandwidth mapping data bwmap of the filter rate-limiting program in the filter agent unit bpf-agent. Wherein the ip mapping data ipmap defines the corresponding relationship between the unique bandwidth configuration identifier OIId and the ip in the public network ip, and the bandwidth mapping data bwmap defines the corresponding relationship between the unique bandwidth configuration identifier OIId and the bandwidth limit value Limit. Different ips can be associated with the same unique bandwidth configuration identifier OIId, and an ip can be associated with only one unique bandwidth configuration identifier OIId, and one network card corresponds to one ip.
[0082] Specifically, when the bandwidth information identifier rate-limiting scheme of the network element agent unit changes, the bandwidth mapping data in the filter rate-limiting program is updated as follows:
[0083] (1) When the unique bandwidth configuration identifier OIId does not change and the bandwidth limit value Limit does not change, the bandwidth mapping data in the filter rate-limiting program is not updated;
[0084] (2) When the unique bandwidth configuration identifier OIId does not change but the bandwidth limit value Limit changes, the bandwidth mapping data corresponding to the bandwidth limit value is updated;
[0085] (3) When the unique bandwidth configuration identifier OIId is deleted, the bandwidth mapping data corresponding to the unique bandwidth configuration identifier is deleted;
[0086] When the bandwidth information identifier rate-limiting scheme of the network element agent unit changes, the ip mapping data in the filter rate-limiting program is updated as follows:
[0087] (1) When the unique bandwidth configuration identifier OIId does not change and the ip in the public network ip does not change, the ip mapping data corresponding to the public network ip is not operated;
[0088] (2) When the unique bandwidth configuration identifier OIId does not change and the public IP changes, update the IP mapping data corresponding to the public IP;
[0089] (3) When the unique bandwidth configuration identifier OIId is deleted, delete the IP mapping data corresponding to the unique bandwidth configuration identifier.
[0090] The maptool apply supports the input parameters: -c <absolute path of the filter speed limiting program file>.
[0091] In this embodiment, the speed limiting execution tool determines the bandwidth limiting value, the unique bandwidth configuration identifier, and whether the public IP corresponding to the bandwidth changes according to the bandwidth information configuration file. When a change is determined, corresponding processing is performed.
[0092] In one embodiment, the filter agent unit provides a filter speed limiting program file and an application programming interface for the program loading unit to call the application programming interface to obtain the filter speed limiting program file.
[0093] The filter agent unit (bpf-Agent) provides a compiled filter speed limiting program file and exposes an internal service application programming interface (Application Programming Interface, api) for the program loading unit to call the application programming interface to obtain the filter speed limiting program file.
[0094] The filter speed limiting program file initializes the data structure of the IP mapping data and the bandwidth mapping data. In addition, the data structure of the filter speed limiting program can be converted and processed by the speed limiting execution tool maptool according to the content of the bandwidth information configuration file bw-info.yaml to obtain the IP mapping data ipmap and the bandwidth mapping data bwmap. Specifically, the bandwidth mapping data bwmap is obtained according to the unique bandwidth configuration identifier OIId and the bandwidth limiting value Limit corresponding to each unique bandwidth configuration identifier OIId in the bandwidth information configuration file bw-info.yaml. The IP mapping data ipmap is obtained according to the IP and the unique bandwidth configuration identifier OIId corresponding to each IP in the bandwidth information configuration file bw-info.yaml, as shown in Figure 3
[0095] In this embodiment, the filter agent unit provides a filter speed limiting program file and an application programming interface for the program loading unit to call the application programming interface to obtain the filter speed limiting program file.
[0096] In one of the embodiments, the speed limit execution tool performs the speed limit operation of different IPs sharing the same bandwidth size according to the ip mapping data and the bandwidth mapping data in the filter speed limit program file and the bandwidth speed limit execution mode in the operating system kernel, and the specific steps are as follows: determining the bandwidth speed limit value corresponding to each IP according to the IP in the ip mapping data and the bandwidth speed limit value in the bandwidth mapping data; performing the speed limit operation of different IPs sharing the same bandwidth size according to the bandwidth speed limit execution mode and the bandwidth speed limit value corresponding to each IP in the tc module of the operating system kernel through the network traffic speed limit algorithm.
[0097] The speed limit execution tool in the operating system kernel can determine the bandwidth speed limit value corresponding to each IP according to the IP in the ip mapping data and the bandwidth speed limit value in the bandwidth mapping data.
[0098] The speed limit operation of different IPs sharing the same bandwidth size can be performed according to the bandwidth speed limit execution mode and the bandwidth speed limit value corresponding to each IP in the tc module of the operating system kernel through the network traffic speed limit algorithm.
[0099] The operating system can be a Linux system, and the network traffic speed limit algorithm can be an edt (Earlist Departure Time) algorithm.
[0100] In this embodiment, the speed limit execution tool performs the speed limit operation of different IPs sharing the same bandwidth size according to the IP in the ip mapping data and the bandwidth speed limit value in the bandwidth mapping data in the tc module of the operating system kernel.
[0101] The embodiment of the application provides a traffic speed limit method, which can be executed by a speed limit controller in a traffic speed limit system, wherein the traffic speed limit system further comprises a network element proxy unit, a speed limit execution tool and a filter proxy unit, and when it is monitored that the life cycle of the network element proxy unit or the bandwidth configuration strategy changes, the traffic speed limit is realized according to the bandwidth configuration strategy. In this embodiment, the method comprises Figure 4 The steps shown are:
[0102] In step S401, when it is monitored that the life cycle of the network element proxy unit or the bandwidth configuration strategy changes, the bandwidth speed limit execution mode and the bandwidth information configuration file are obtained according to the bandwidth configuration strategy.
[0103] The network element proxy unit exists in the form of a deployment (Deployment) resource or a stateful set (Statefulsets) resource in a container orchestration platform (Kubernetes), and the bandwidth configuration strategy is added to the annotation (Annotations) field of the deployment resource or the stateful set resource.
[0104] The monitoring unit in the rate limiting controller can use a reconciliation function in a reconciliation loop mechanism of the container orchestration platform to monitor the life cycle of the network element agent module and whether the bandwidth configuration strategy changes. When it is detected that the hash value of the bandwidth configuration strategy is inconsistent with the hash value of the container group in the container orchestration platform, it is determined that the life cycle of the network element agent unit or the bandwidth configuration strategy changes. At this time, the bandwidth limiting execution mode can be obtained according to the bandwidth identification limiting mode in the bandwidth configuration strategy; and the bandwidth information configuration file can be obtained according to the bandwidth information identification limiting scheme in the bandwidth configuration strategy.
[0105] In step S402, the ip mapping data and the bandwidth mapping data in the filter rate limiting program file are updated through the rate limiting execution tool and the bandwidth information configuration file.
[0106] The rate limiting execution tool can be a maptool tool. When the rate limiting execution tool maptool determines that the bandwidth limiting value Limit changes according to the bandwidth information configuration file bw-info.yaml, the bandwidth mapping data corresponding to the bandwidth limiting value can be updated; when the rate limiting execution tool maptool determines that the unique bandwidth configuration identifier OIId is deleted according to the bandwidth information configuration file bw-info.yaml, the bandwidth mapping data corresponding to the unique bandwidth configuration identifier OIId is deleted; when the rate limiting execution tool maptool determines that the public ip corresponding to the bandwidth changes according to the bandwidth information configuration file bw-info.yaml, the ip mapping data corresponding to the public ip is updated; and when the rate limiting execution tool maptool determines that the unique bandwidth configuration identifier OIId is deleted according to the bandwidth information configuration file bw-info.yaml, the ip mapping data corresponding to the unique bandwidth configuration identifier is deleted.
[0107] The ip mapping data ipmap defines the correspondence between the unique bandwidth configuration identifier OIId and the ip in the public ip, and the bandwidth mapping data bwmap defines the correspondence between the unique bandwidth configuration identifier OIId and the bandwidth limiting value Limit. Different ips can be associated with the same unique bandwidth configuration identifier OIId, one ip can be associated with only one unique bandwidth configuration identifier OIId, and one network card corresponds to one ip.
[0108] In step S403, the filter rate limiting program file is obtained and loaded into the operating system kernel, so that the rate limiting execution tool performs the rate limiting operation of different ips sharing the same bandwidth size according to the ip mapping data and the bandwidth mapping data in the filter rate limiting program file and the bandwidth limiting execution mode in the operating system kernel, to realize traffic rate limiting.
[0109] The program loading unit in the speed limit controller can obtain the filter speed limit program file from the filter agent unit and load the filter speed limit program file to the operating system kernel.
[0110] The speed limit execution tool in the operating system kernel can determine the bandwidth speed limit value corresponding to each IP according to the IP in the IP mapping data and the bandwidth speed limit value in the bandwidth mapping data. The network traffic speed limit algorithm can be used to perform the speed limit operation of different IPs sharing the same bandwidth size according to the bandwidth speed limit execution mode and the bandwidth speed limit value corresponding to each IP in the tc module of the operating system kernel. The operating system can be a Linux system, and the network traffic speed limit algorithm can be an EDT (Earliest Departure Time) algorithm.
[0111] In the above traffic speed limit method, the IP mapping data and the bandwidth mapping data are obtained according to the IP data and the bandwidth data in the bandwidth information configuration file, the flexible IP and bandwidth association relationship is realized, the network bandwidth accurate speed limit management is realized, the service scenarios of single-IP exclusive bandwidth and multi-IP shared bandwidth are supported, the high-bandwidth and high-performance requirements under the intelligent network card and the ordinary network card can be met, and the scalability of the traffic speed limit system is improved.
[0112] It should be understood that, although each step in the flowchart involved in each embodiment as described above is shown in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.
[0113] Based on the same inventive concept, the embodiments of the present application also provide a traffic speed limit device for implementing the above-mentioned traffic speed limit method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, and therefore the specific limitations in one or more traffic speed limit device embodiments provided below can refer to the limitations of the traffic speed limit method described above, which will not be repeated here.
[0114] In one exemplary embodiment, as shown in Figure 5 a traffic speed limit device is provided, wherein:
[0115] The monitoring module 501 is configured to obtain a bandwidth throttling execution mode and a bandwidth information configuration file according to the bandwidth configuration policy when it is monitored that the life cycle or the bandwidth configuration policy of the network element proxy unit changes.
[0116] The mapping data updating module 502 is configured to update the ip mapping data and the bandwidth mapping data in the filter throttling program file by using the throttling execution tool and the bandwidth information configuration file.
[0117] The throttling operation module 503 is configured to obtain and load the filter throttling program file to the operating system kernel, so that the throttling execution tool performs throttling operation on different ips sharing the same bandwidth size according to the ip mapping data and the bandwidth mapping data in the filter throttling program file and the bandwidth throttling execution mode in the operating system kernel, to realize traffic throttling.
[0118] The above-mentioned modules in the traffic throttling device can be realized by software, hardware and combinations thereof in whole or in part. The above-mentioned modules can be embedded in or independent of the processor in the throttling controller in hardware form, or can be stored in the memory in the throttling controller in software form, so as to be called and executed by the processor to perform the operations corresponding to the above-mentioned modules.
[0119] In an exemplary embodiment, a throttling controller is provided, which can be a server. The throttling controller includes a processor, a memory, an input / output interface (I / O) and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the throttling controller is configured to provide computing and control capabilities. The memory of the throttling controller includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The database of the throttling controller is configured to store data of the embodiments of the traffic throttling method. The input / output interface of the throttling controller is configured to exchange information between the processor and external devices. The communication interface of the throttling controller is configured to communicate with external terminals through network connection. The computer program is executed by the processor to implement a traffic throttling method.
[0120] In an embodiment, a throttling controller is also provided, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps in the above-mentioned method embodiments.
[0121] In an embodiment, a computer readable storage medium is provided, having stored thereon a computer program which, when executed by a processor, implements the steps of any of the method embodiments described above.
[0122] In an embodiment, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the steps of any of the method embodiments described above.
[0123] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.
[0124] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0125] The technical features of the above embodiments can be combined in any manner. To make the description concise, all possible combinations of the technical features in the above embodiments are not described, but as long as the combinations of the technical features do not exist, they should be considered as the scope of the present application.
[0126] The above-described embodiments are merely illustrative of several embodiments of the present application, which are described in more detail and in a specific manner, but should not be construed as limiting the scope of the patent of the present application. It should be noted that, for those of ordinary skill in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A flow rate limiting system, characterized in that, The traffic limiting system includes a network element agent unit, a rate limiting controller, a rate limiting execution tool, and a filter agent unit. The rate limiting controller includes a monitoring unit, a rate limiting configuration unit, and a program loading unit, wherein: The monitoring unit is used to monitor whether the lifecycle and bandwidth configuration policy of the network element agent unit have changed. When the lifecycle or bandwidth configuration policy of the network element agent unit is detected to have changed, a rate limiting operation start command is sent to the rate limiting configuration unit. The rate limiting configuration unit is used to obtain the bandwidth rate limiting execution mode and bandwidth information configuration file according to the bandwidth configuration strategy when it receives the rate limiting operation start command. The program loading unit is used to update the IP mapping data and bandwidth mapping data in the filter rate limiting program file through the rate limiting execution tool and the bandwidth information configuration file; The program loading unit is also used to acquire and load the filter rate limiting program file into the operating system kernel, so that the rate limiting execution tool can perform rate limiting operations on different IPs sharing the same bandwidth size according to the IP mapping data and bandwidth mapping data in the filter rate limiting program file and the bandwidth rate limiting execution mode in the operating system kernel, so as to achieve traffic rate limiting.
2. The system according to claim 1, characterized in that, The network element proxy unit is a deployment resource or a stateful set resource in the container orchestration platform, and the annotation field of the deployment resource or the stateful set resource includes a bandwidth configuration strategy.
3. The system according to claim 1, characterized in that, The monitoring unit is used to monitor whether the lifecycle and bandwidth configuration policy of the network element agent unit have changed through the coordination and loop mechanism of the container orchestration platform.
4. The system according to claim 1, characterized in that, The monitoring unit monitors whether the lifecycle and bandwidth configuration policy of the network element agent unit have changed, specifically including: When the hash value of the bandwidth configuration policy is found to be inconsistent with the hash value of the container group in the container orchestration platform, it is determined that the lifecycle of the network element agent unit or the bandwidth configuration policy has changed.
5. The system according to claim 1, characterized in that, The bandwidth configuration strategy includes a bandwidth identifier rate limiting mode and a bandwidth information identifier rate limiting scheme. The rate limiting configuration unit, based on the bandwidth configuration strategy, obtains a bandwidth rate limiting execution mode and a bandwidth information configuration file, specifically including: Based on the bandwidth identifier rate limiting mode in the bandwidth configuration strategy, the bandwidth rate limiting execution mode is obtained; Based on the bandwidth information identification rate limiting scheme in the bandwidth configuration strategy, a bandwidth information configuration file is obtained.
6. The system according to claim 1, characterized in that, The program loading unit updates the IP mapping data and bandwidth mapping data in the filter rate limiting program file through the rate limiting execution tool and the bandwidth information configuration file, specifically including: When the rate limiting execution tool determines that the bandwidth rate limiting value has changed according to the bandwidth information configuration file, it updates the bandwidth mapping data corresponding to the bandwidth rate limiting value. When the rate limiting execution tool determines, based on the bandwidth information configuration file, that a unique bandwidth configuration identifier has been deleted, it deletes the bandwidth mapping data corresponding to the unique bandwidth configuration identifier. When the rate limiting execution tool determines, based on the bandwidth information configuration file, that the public IP address corresponding to the bandwidth has changed, it updates the IP mapping data corresponding to the public IP address. When the rate limiting execution tool determines, based on the bandwidth information configuration file, that a unique bandwidth configuration identifier has been deleted, it deletes the IP mapping data corresponding to the unique bandwidth configuration identifier.
7. The system according to claim 1, characterized in that, The filter agent unit is used to provide the filter rate limiting program file and application programming interface, so that the program loading unit can call the application programming interface to obtain the filter rate limiting program file.
8. The system according to claim 1, characterized in that, The rate-limiting execution tool, within the operating system kernel, performs rate-limiting operations on different IPs sharing the same bandwidth based on the IP mapping data and bandwidth mapping data in the filter rate-limiting program file, and the bandwidth rate-limiting execution mode. Specifically, this includes: Based on the IP addresses in the IP mapping data and the bandwidth limit values in the bandwidth mapping data, determine the bandwidth limit value corresponding to each IP address. The network traffic rate limiting algorithm, implemented in the tc module of the operating system kernel, performs rate limiting operations on different IPs sharing the same bandwidth based on the bandwidth rate limiting execution mode and the bandwidth rate limiting value corresponding to each IP.
9. A method for limiting traffic flow, characterized in that, The method is applied to a rate limiting controller in a traffic rate limiting system, which further includes a network element agent unit, a rate limiting execution tool, and a filter agent unit. The method includes: When the lifecycle of the network element agent unit or the bandwidth configuration policy changes, the bandwidth rate limiting execution mode and bandwidth information configuration file are obtained according to the bandwidth configuration policy. The IP mapping data and bandwidth mapping data in the filter rate limiting program file are updated using the rate limiting execution tool and the bandwidth information configuration file. The filter rate limiting program file is acquired and loaded into the operating system kernel, so that the rate limiting execution tool performs rate limiting operations on different IPs sharing the same bandwidth size according to the IP mapping data and bandwidth mapping data in the filter rate limiting program file and the bandwidth rate limiting execution mode, so as to achieve traffic rate limiting.
10. A flow rate limiting device, characterized in that, The device is used in a rate limiting controller in a traffic rate limiting system. The traffic rate limiting system further includes a network element agent unit, a rate limiting execution tool, and a filter agent unit. The device includes: The monitoring module is used to obtain the bandwidth rate limiting execution mode and bandwidth information configuration file according to the bandwidth configuration policy when it detects that the life cycle or bandwidth configuration policy of the network element agent unit has changed. The mapping data update module is used to update the IP mapping data and bandwidth mapping data in the filter rate limiting program file through the rate limiting execution tool and the bandwidth information configuration file; The rate limiting operation module is used to acquire and load the filter rate limiting program file into the operating system kernel, so that the rate limiting execution tool in the operating system kernel performs rate limiting operations on different IPs sharing the same bandwidth according to the IP mapping data and bandwidth mapping data in the filter rate limiting program file, as well as the bandwidth rate limiting execution mode, so as to achieve traffic rate limiting.
Citation Information
Patent Citations
Method and system for realizing shared bandwidth
CN112333112A
Network speed limiting method and device
CN115529274A